<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Wireshark Q&amp;A</title>
    <link>/</link>
    <description>Recent content on Wireshark Q&amp;A</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 29 Oct 2017 12:19:00 +0000</lastBuildDate><atom:link href="/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How do you capture RTP packets?</title>
      <link>/questions/11/how-do-you-capture-rtp-packets/</link>
      <pubDate>Wed, 08 Sep 2010 09:39:00 +0000</pubDate>
      
      <guid>/questions/11/how-do-you-capture-rtp-packets/</guid>
      <description>How do you capture RTP packets?  1 I&#39;m trying to capture RTP streams. When I use rtp as a packet filter Wireshark says &#34;Invalid capture filter: &#34;rtp&#34;!&#34; What port does RTP use?
capture-filter rtpasked 08 Sep &#39;10, 09:39
Gerald Combs ♦♦
3.3k●9●22●58
accept rate: 24%
 edited 08 Sep &#39;10, 11:47 
  
3 Answers:
  
4 RTP port numbers are usually dynamically assigned. You can use something like this to get close enough in most cases:</description>
    </item>
    
    <item>
      <title>How do you filter different types of ICMPv6 messages?</title>
      <link>/questions/12/how-do-you-filter-different-types-of-icmpv6-messages/</link>
      <pubDate>Wed, 08 Sep 2010 11:46:00 +0000</pubDate>
      
      <guid>/questions/12/how-do-you-filter-different-types-of-icmpv6-messages/</guid>
      <description>How do you filter different types of ICMPv6 messages?  1 Libpcap lets you filter ICMP messages with named field values, e.g.
icmp[icmptype] = icmp-echoWhat is the ICMPv6 equivalent?
icmpv6 capture-filter ipv6asked 08 Sep &#39;10, 11:46
Gerald Combs ♦♦
3.3k●9●22●58
accept rate: 24%
 edited 08 Sep &#39;10, 11:47 
  
One Answer:
  
2 Looks like looking into icmp6 messages has not yet been implemented. However, you can use the IPv6 layer with an index (as long as there are no extra IPv6 headers):</description>
    </item>
    
    <item>
      <title>Why are hyphens not allowed in the user-name?</title>
      <link>/questions/13/why-are-hyphens-not-allowed-in-the-user-name/</link>
      <pubDate>Thu, 09 Sep 2010 15:21:00 +0000</pubDate>
      
      <guid>/questions/13/why-are-hyphens-not-allowed-in-the-user-name/</guid>
      <description>Why are hyphens not allowed in the user-name?  0 Yep... very off-topic, I know... But still... Is there a technical reason? If not, I&#39;d like to be &#34;SYN-bit&#34; :-)
login metaasked 09 Sep &#39;10, 15:21
SYN-bit ♦♦
17.1k●9●57●245
accept rate: 20%
 edited 12 Sep &#39;10, 22:50 
  
2 Answers:
  
2 This is a known bug in OSQA. Unfortunately no one has come up with a fix.</description>
    </item>
    
    <item>
      <title>Validation link problems</title>
      <link>/questions/17/validation-link-problems/</link>
      <pubDate>Thu, 09 Sep 2010 15:58:00 +0000</pubDate>
      
      <guid>/questions/17/validation-link-problems/</guid>
      <description>Validation link problems  0 The validation link that is sent results in a 404. Is this still under development?
metaasked 09 Sep &#39;10, 15:58
SYN-bit ♦♦
17.1k●9●57●245
accept rate: 20%
 edited 12 Sep &#39;10, 17:44 
Gerald Combs ♦♦
3.3k●9●22●58
  
4 Answers:
  
0 I have successfully validated my e-mail address twice... Seems to work fine now!
(I did have to change my e-mail address from [email protected] to [email protected] though to import my gravatar, as the gravatar site lowercased my address)</description>
    </item>
    
    <item>
      <title>Do we need sorting while capturing?</title>
      <link>/questions/26/do-we-need-sorting-while-capturing/</link>
      <pubDate>Fri, 10 Sep 2010 00:20:00 +0000</pubDate>
      
      <guid>/questions/26/do-we-need-sorting-while-capturing/</guid>
      <description>Do we need sorting while capturing?  0 Currently we do not support sorting while capturing very well. Is this a wanted feature?
featuresasked 10 Sep &#39;10, 00:20
stig ♦
46●3●3●7
accept rate: 0%
  
2 Answers:
  
4Not sure it wouldn&#39;t be more confusing than useful - I can usually get to see what I want to see in a real-time capture with the careful use of filters</description>
    </item>
    
    <item>
      <title>Are this questions for Users or Developers?</title>
      <link>/questions/27/are-this-questions-for-users-or-developers/</link>
      <pubDate>Fri, 10 Sep 2010 00:22:00 +0000</pubDate>
      
      <guid>/questions/27/are-this-questions-for-users-or-developers/</guid>
      <description>Are this questions for Users or Developers?  0 Or maybe both?
meta wiresharkasked 10 Sep &#39;10, 00:22
stig ♦
46●3●3●7
accept rate: 0%
 edited 10 Sep &#39;10, 09:21 
Gerald Combs ♦♦
3.3k●9●22●58
  
3 Answers:
  
4I vote for both. It&#39;s easy enough to add a &#34;development&#34; tag to your question.
answered 10 Sep &#39;10, 09:20
Gerald Combs ♦♦
3.3k●9●22●58
accept rate: 24%</description>
    </item>
    
    <item>
      <title>Bug? Click &amp;quot;unanswered&amp;quot; and see all questions...</title>
      <link>/questions/32/bug-click-unanswered-and-see-all-questions/</link>
      <pubDate>Sat, 11 Sep 2010 21:37:00 +0000</pubDate>
      
      <guid>/questions/32/bug-click-unanswered-and-see-all-questions/</guid>
      <description>Bug? Click &amp;ldquo;unanswered&amp;rdquo; and see all questions&amp;hellip;  1 Shouldn&#39;t this just show unanswered questions?
L
metaasked 11 Sep &#39;10, 21:37
lchappell ♦
1.2k●2●7●30
accept rate: 8%
 retagged 18 Sep &#39;10, 03:37 
SYN-bit ♦♦
17.1k●9●57●245
  
One Answer:
  
0 The &#34;unanswered&#34; tab is actually the &#34;questions-without-any-accepted-answers&#34; tab. A question may have many answers but the original user must accept one of them (by clicking the check mark icon) before the question is officially answered.</description>
    </item>
    
    <item>
      <title>Notification mails not being sent?</title>
      <link>/questions/39/notification-mails-not-being-sent/</link>
      <pubDate>Sun, 12 Sep 2010 22:54:00 +0000</pubDate>
      
      <guid>/questions/39/notification-mails-not-being-sent/</guid>
      <description>Notification mails not being sent?  0 According to my account settings, I should receive notification mails for all the questions I have asked or answered. However, I did not receive any notification mail, even though there were updates to questions I asked or answered.
Is the notification functionality not turned on yet?
Or... hmmm... come to think of it... does notification start only after your email-address is validated?
metaasked 12 Sep &#39;10, 22:54</description>
    </item>
    
    <item>
      <title>Use a display filter as a stop condition</title>
      <link>/questions/41/use-a-display-filter-as-a-stop-condition/</link>
      <pubDate>Mon, 13 Sep 2010 05:41:00 +0000</pubDate>
      
      <guid>/questions/41/use-a-display-filter-as-a-stop-condition/</guid>
      <description>Use a display filter as a stop condition  3 1As a user that uses Wireshark a lot for debugging, I was wondering if the capability to use a filter as a criteria to stop a capture is ever going to be implemented (just like there is a stop condition after a configurable amount of packets/bytes/seconds). I saw the bug 3967 enhancement recommendation, but I don&#39;t see a planned version for implementing this.</description>
    </item>
    
    <item>
      <title>Usefull Color Rules?</title>
      <link>/questions/42/usefull-color-rules/</link>
      <pubDate>Mon, 13 Sep 2010 06:04:00 +0000</pubDate>
      
      <guid>/questions/42/usefull-color-rules/</guid>
      <description>Usefull Color Rules?  2 1What are your favorite or most useful color rules?
Besides the included defaults, what rules are most useful in troubleshooting and quickly identifying issues?
color-rules gui packet-display troubleshootingasked 13 Sep &#39;10, 06:04
Peter
65●1●2●7
accept rate: 0%
A screnshot of the profile would be a good thing to have in here. Thanks, A Friend From Portugal, Mr_Chmod
(12 Jan &#39;14, 07:39) mrchmod  
One Answer:</description>
    </item>
    
    <item>
      <title>Cannot capture packets from remote system.</title>
      <link>/questions/46/cannot-capture-packets-from-remote-system/</link>
      <pubDate>Mon, 13 Sep 2010 14:19:00 +0000</pubDate>
      
      <guid>/questions/46/cannot-capture-packets-from-remote-system/</guid>
      <description>Cannot capture packets from remote system.  0 I have installed winpcap on a Win 7 Pro system, including opening tcp port 2002, and starting the service. However, I cannot capture any packets from this system. I get this error: &#34;Error while capturing packets: is the server properly installed on x.x.x.153? connect() failed: A connection attempt failed because the connection party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.</description>
    </item>
    
    <item>
      <title>make Wireshark analysis vlan aware</title>
      <link>/questions/50/make-wireshark-analysis-vlan-aware/</link>
      <pubDate>Mon, 13 Sep 2010 17:49:00 +0000</pubDate>
      
      <guid>/questions/50/make-wireshark-analysis-vlan-aware/</guid>
      <description>make Wireshark analysis vlan aware  2 I&#39;ve often the problem, that I have the same traffic flow on diffrent vlans but in the same capture file. Than you get a lot of errors from the analysis engine that you have duplicate packets etc.
Is there a way to configure Wireshark to treat the same flow on diffrent vlans as diffrent flows in the analysis?
I know that I can split up the capture file in several smaller files filtered by vlan.</description>
    </item>
    
    <item>
      <title>Can you change the capture format to support the diagnostic process?</title>
      <link>/questions/55/can-you-change-the-capture-format-to-support-the-diagnostic-process/</link>
      <pubDate>Tue, 14 Sep 2010 04:36:00 +0000</pubDate>
      
      <guid>/questions/55/can-you-change-the-capture-format-to-support-the-diagnostic-process/</guid>
      <description>Can you change the capture format to support the diagnostic process?  0 Would it be feasible to have options to:
Add HOSTS file information that will travel with the PCAP file as it is sent to vendors, etc.Or, an option to save the file with the current HOSTS file informationAdd Summary information on the problem.Obfuscate IP addresses for confidentiality reasons (modify HOSTS IP information (#1) accordingly)Add a user initiated record to mark events in a trace with timestamps and user commentAdd a network trace analyst record to enable permanent highlighting of trace areas with commentscapture file-formatasked 14 Sep &#39;10, 04:36</description>
    </item>
    
    <item>
      <title>Windows 7 Installation Problems.</title>
      <link>/questions/58/windows-7-installation-problems/</link>
      <pubDate>Tue, 14 Sep 2010 07:13:00 +0000</pubDate>
      
      <guid>/questions/58/windows-7-installation-problems/</guid>
      <description>Windows 7 Installation Problems.  0 When attempting to install Wireshark v1.4.0 (32-bit or 64-bit version using the executable installer) on my Windows 7 computer, I receive the following error message: &#34;Error opening file for writing C:\Program Files\Wireshark\wiretap-0.3.1.dll&#34;. I then have to abort the installation. I am not sure how to proceed and did not find this exact issue within Bugzila. Any help is very much appreciated.
1.4.0 wiretap-0.3.1.dll windows7asked 14 Sep &#39;10, 07:13</description>
    </item>
    
    <item>
      <title>Troubleshooting with Coloring Rules webinar - got ideas?</title>
      <link>/questions/61/troubleshooting-with-coloring-rules-webinar-got-ideas/</link>
      <pubDate>Tue, 14 Sep 2010 08:22:00 +0000</pubDate>
      
      <guid>/questions/61/troubleshooting-with-coloring-rules-webinar-got-ideas/</guid>
      <description>Troubleshooting with Coloring Rules webinar - got ideas?  0 Hi folks -
This new Wireshark Jumpstart coming on October 19th - it&#39;s free, as all the Jumpstarts, are.
Registration is open over at http://www.chappellseminars.com/s-wiresharkcolors.html.
If you have anything you would like me to cover/should be covered, let me know.
color-rules training webinar freeasked 14 Sep &#39;10, 08:22
lchappell ♦
1.2k●2●7●30
accept rate: 8%
   </description>
    </item>
    
    <item>
      <title>static tshark builds for linux and/or solaris sparc/x64</title>
      <link>/questions/62/static-tshark-builds-for-linux-andor-solaris-sparcx64/</link>
      <pubDate>Tue, 14 Sep 2010 09:40:00 +0000</pubDate>
      
      <guid>/questions/62/static-tshark-builds-for-linux-andor-solaris-sparcx64/</guid>
      <description>static tshark builds for linux and/or solaris sparc/x64  0 Hi,
did anyone made the miracle and build a static tshark for linux and/or solaris sparc/x64? I tried with several times with different releases:
example with 1.4.0: [email protected]:/var/tmp/wireshark-1.4.0rc2$ ./configure --enable-tshark --disable-wireshark --with-krb5=no --with-portaudio=no --with-gnutls=no -with-gcrypt=no --enable-editcap=no --enable-dumpcap=yes --enable-capinfos=no --enable-mergecap=no --enable-text2pcap=no --disable-idl2wrs --disable-randpkt --enable-ipv6=no --enable-static --disable-shared
result: libtool: link: rm -f &#34;.libs/tsharkS.c&#34; &#34;.libs/tshark.nm&#34; &#34;.libs/tshark.nmS&#34; &#34;.libs/tshark.nmT&#34; libtool: link: gcc -DNEW_PACKET_LIST &#34;-D_U_=attribute((unused))&#34; -Wall -W -Wextra -Wdeclaration-after-statement -Wendif-labels -Wpointer-arith -Wno-pointer-sign -Wcast-align -Wformat-security -I/usr/local/include -I/usr/include/glib-2.</description>
    </item>
    
    <item>
      <title>How to open JPEG files directly?</title>
      <link>/questions/63/how-to-open-jpeg-files-directly/</link>
      <pubDate>Tue, 14 Sep 2010 09:42:00 +0000</pubDate>
      
      <guid>/questions/63/how-to-open-jpeg-files-directly/</guid>
      <description>How to open JPEG files directly?  0 Hi All,
I read in the relnotes from version 1.4.0
http://www.wireshark.org/docs/relnotes/wireshark-1.4.0.html
.... You can open JPEG files directly in Wireshark
I opened in a browser http://www.linuxmigration.com/quickref/admin/images/wireshark_capture.jpg and Wireshark runs. With image-jfif i could filter it. But how can i open it directly? The only what i still coild do is follow tcp stream and then save it raw
Regards
file-format jpeg wiresharkasked 14 Sep &#39;10, 09:42</description>
    </item>
    
    <item>
      <title>Decode of ANSI TCAP response messages</title>
      <link>/questions/69/decode-of-ansi-tcap-response-messages/</link>
      <pubDate>Tue, 14 Sep 2010 12:18:00 +0000</pubDate>
      
      <guid>/questions/69/decode-of-ansi-tcap-response-messages/</guid>
      <description>Decode of ANSI TCAP response messages  0 Greeings!
I&#39;m attempting to use Wireshark to decode (among other protocols) some ss7/sigtran tcap/map messaging. My protocol stacks are (from the inside out):
ansi_map - ansi_tcap - sccp - mtp3 - mtp2 peer adaptation - sctp - ipI&#39;m not much of an ss7 so I kind of fumble with some of the lower layers. (Yes, I have set MTP3 standard to ANSI in my preferences.</description>
    </item>
    
    <item>
      <title>SMB troubleshooting</title>
      <link>/questions/71/smb-troubleshooting/</link>
      <pubDate>Tue, 14 Sep 2010 13:17:00 +0000</pubDate>
      
      <guid>/questions/71/smb-troubleshooting/</guid>
      <description>SMB troubleshooting  0 Can someone help me with troubleshooting SMB/CIFS traffic. I have a user that experiences &#34;lost connections&#34; opening MS Access databases and slowness/errors opening MS Excel documents, both from a remote file share on a NetApp storage appliance. From a network perspective, the traces look good but we are seeing a number of messages in WireShark like the one below.
No.TimeSourceDestinationProtocolInfo736722010-09-10 06:28:57.22831994710.225.10.14810.170.100.60SMBNT Create AndX Response, FID: 0x0000, Error: STATUS_ACCESS_DENIED</description>
    </item>
    
    <item>
      <title>Can I limit name resolution to only use Wireshark&amp;#x27;s own hosts file?</title>
      <link>/questions/78/can-i-limit-name-resolution-to-only-use-wiresharks-own-hosts-file/</link>
      <pubDate>Tue, 14 Sep 2010 22:11:00 +0000</pubDate>
      
      <guid>/questions/78/can-i-limit-name-resolution-to-only-use-wiresharks-own-hosts-file/</guid>
      <description>Can I limit name resolution to only use Wireshark&amp;rsquo;s own hosts file?  1 I would like to enable network name resolution but only allow Wireshark to use its hosts file in %WIRESHARK%\hosts, or %APPDATA%\Wireshark\hostsdisable. It appears that when I enable network name resolution in preferences then it enables name reslution using, DNS, the windows hosts file, and the Wireshark hosts file. I often analyze very large captures from a private network while I&#39;m attached to my corporate network, I do have a large wireshark hosts file but there are many addresses for which I do not have an entry, Wireshark resorts to DNS to attempt to resolve these names and it takes a very long time since many are not reachable and result in a timeout before proceeding.</description>
    </item>
    
    <item>
      <title>How Can I enable Wireless settings in Wireshark  and capture traffic ?</title>
      <link>/questions/81/how-can-i-enable-wireless-settings-in-wireshark-and-capture-traffic/</link>
      <pubDate>Wed, 15 Sep 2010 04:22:00 +0000</pubDate>
      
      <guid>/questions/81/how-can-i-enable-wireless-settings-in-wireshark-and-capture-traffic/</guid>
      <description>How Can I enable Wireless settings in Wireshark and capture traffic ?  0 My laptop doesn&#39;t have wireless card (specificly it has been disabled ) and I want to capture all traffic from these three access points (my laptop ,two pc and access point is the same lan)
wlanThis question is marked &#34;community wiki&#34;.asked 15 Sep &#39;10, 04:22
wapi
1●1●1●1
accept rate: 0%
What operating system are you using?</description>
    </item>
    
    <item>
      <title>Can Wireshark monitor bandwidth usage per application/process?</title>
      <link>/questions/82/can-wireshark-monitor-bandwidth-usage-per-applicationprocess/</link>
      <pubDate>Wed, 15 Sep 2010 05:27:00 +0000</pubDate>
      
      <guid>/questions/82/can-wireshark-monitor-bandwidth-usage-per-applicationprocess/</guid>
      <description>Can Wireshark monitor bandwidth usage per application/process?  0 I&#39;m using Ubuntu 10.04 and I want to monitor and ideally log how much each application/process is uploading and downloading. Something like: Firefox has downloaded 50MB, Transmission has downloaded 500MB and uploaded 300MB, Ubuntu One has uploaded 5MB, etc. A per-session record would do, but actually logging usage to a database/text file would be best.
Can Wireshark do this? (And on Windows?</description>
    </item>
    
    <item>
      <title>Does the packet make it to the other end?</title>
      <link>/questions/84/does-the-packet-make-it-to-the-other-end/</link>
      <pubDate>Wed, 15 Sep 2010 09:49:00 +0000</pubDate>
      
      <guid>/questions/84/does-the-packet-make-it-to-the-other-end/</guid>
      <description>Does the packet make it to the other end?  0 I have two wireshark captures. One showing the packets leaving one location. The other capture shows packets arriving at the destination. What is a good reference point to look at in the leaving packet so I can tell it&#39;s the packet that arrived at the destination. I thought I could do that with sequence numbers but it doesn&#39;t seem to work that way.</description>
    </item>
    
    <item>
      <title>Should ask.wireshark.org send you daily email?</title>
      <link>/questions/88/should-askwiresharkorg-send-you-daily-email/</link>
      <pubDate>Wed, 15 Sep 2010 11:07:00 +0000</pubDate>
      
      <guid>/questions/88/should-askwiresharkorg-send-you-daily-email/</guid>
      <description>Should ask.wireshark.org send you daily email?  2 If you go to User tools→email notification settings in your user profile you&#39;ll see a preference labeled &#34;Send me the daily digest with information about the site activity&#34;. This option currently enabled by default but it doesn&#39;t do anything. I&#39;m not sure that this is proper default behavior so I disabled the associated cron job. (There was a single test run yesterday in case you received the email.</description>
    </item>
    
    <item>
      <title>Provide link to question in mail about question/answer/etc ?</title>
      <link>/questions/91/provide-link-to-question-in-mail-about-questionansweretc/</link>
      <pubDate>Wed, 15 Sep 2010 11:49:00 +0000</pubDate>
      
      <guid>/questions/91/provide-link-to-question-in-mail-about-questionansweretc/</guid>
      <description>Provide link to question in mail about question/answer/etc ?  1 I&#39;ve set my configuration to receive individual mails when a question is asked/answered/etc.
If I want to respond to the question, it would be nice if I could just click on a link in the EMail to bring up the question in my browser.
Is it possible to include such a link in the EMails ?
Bill
meta emailasked 15 Sep &#39;10, 11:49</description>
    </item>
    
    <item>
      <title>Decoding SNMP using Wireshark 1.4.0</title>
      <link>/questions/93/decoding-snmp-using-wireshark-140/</link>
      <pubDate>Wed, 15 Sep 2010 12:02:00 +0000</pubDate>
      
      <guid>/questions/93/decoding-snmp-using-wireshark-140/</guid>
      <description>Decoding SNMP using Wireshark 1.4.0  0 I need to decode snmp OIDs in Wireshark, but when I Enable it under Name resolution I receive this error message:
Stopped processing module SNMPv2-SMI due to error(s) to prevent potential crash in libsmi. Module&#39;s conformance level: 1. See details at: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560325
Is there something I am doing wrong ?
I am running wireshark 1.4.0 (SVN Rev 34005 from /trunk-1.4) under Vista.
snmp libsmiasked 15 Sep &#39;10, 12:02</description>
    </item>
    
    <item>
      <title>Checksum errors on Windows</title>
      <link>/questions/108/checksum-errors-on-windows/</link>
      <pubDate>Wed, 15 Sep 2010 13:02:00 +0000</pubDate>
      
      <guid>/questions/108/checksum-errors-on-windows/</guid>
      <description>Checksum errors on Windows  0 I have a checksum problem on my computer and I know this because I can see it using wireshark. The problem is it only happens when I use Win7 or Vista Business and not with XP pro. I have caputure files and would like for someone to look at them. At first I thought it was my nic and still not sure that its not the nic driver or something related to IPv6.</description>
    </item>
    
    <item>
      <title>What&amp;#x27;s the best way to capture packets on a trunked port (Cisco Catalyst)?</title>
      <link>/questions/112/whats-the-best-way-to-capture-packets-on-a-trunked-port-cisco-catalyst/</link>
      <pubDate>Wed, 15 Sep 2010 14:01:00 +0000</pubDate>
      
      <guid>/questions/112/whats-the-best-way-to-capture-packets-on-a-trunked-port-cisco-catalyst/</guid>
      <description>What&amp;rsquo;s the best way to capture packets on a trunked port (Cisco Catalyst)?  2 1We are trying to capture VLAN tagged packets on a Cisco Catalyst 3750. We have a VoIP phone that boots on our DATA VLAN and gets settings pushed to it from DHCP Scope option 242. One of these options tells the phone to boot on the VoIP VLAN.
Anyways, I&#39;ve been doing a simple &#34;monitor session&#34;</description>
    </item>
    
    <item>
      <title>Can I create a short name for interface name?</title>
      <link>/questions/135/can-i-create-a-short-name-for-interface-name/</link>
      <pubDate>Wed, 15 Sep 2010 22:15:00 +0000</pubDate>
      
      <guid>/questions/135/can-i-create-a-short-name-for-interface-name/</guid>
      <description>Can I create a short name for interface name?  0 Hi,
In the machine I use for sniffinf, there are 7 interfaces. I would like to know whether I can create a short-name for each of those, so that when I want to capture on a specific interface I can select it through short name?
Thanks, Ram.
interface short nameasked 15 Sep &#39;10, 22:15
Ramprasad
20●10●11●15
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Can I assign name to mac-address?</title>
      <link>/questions/137/can-i-assign-name-to-mac-address/</link>
      <pubDate>Wed, 15 Sep 2010 22:52:00 +0000</pubDate>
      
      <guid>/questions/137/can-i-assign-name-to-mac-address/</guid>
      <description>Can I assign name to mac-address?  0 Can I assign name to mac-address, so that when I see the capture it&#39;ll be very easy to understand?
-ram.
name-resolving mac-address ethersasked 15 Sep &#39;10, 22:52
Ramprasad
20●10●11●15
accept rate: 0%
 retagged 17 Sep &#39;10, 11:20 
SYN-bit ♦♦
17.1k●9●57●245
  
2 Answers:
  
3 That&#39;s what the ethers file can do for you, see Users Guide</description>
    </item>
    
    <item>
      <title>AR5007EG chipset not able to be in promusies mode</title>
      <link>/questions/142/ar5007eg-chipset-not-able-to-be-in-promusies-mode/</link>
      <pubDate>Thu, 16 Sep 2010 00:17:00 +0000</pubDate>
      
      <guid>/questions/142/ar5007eg-chipset-not-able-to-be-in-promusies-mode/</guid>
      <description>AR5007EG chipset not able to be in promusies mode  0 Can some tell me ho to get the carrect interface for this chip set
chipsetasked 16 Sep &#39;10, 00:17
Tristan Bishop
1●1●1●1
accept rate: 0%
What operating system are you using?
(16 Sep &#39;10, 08:16) Gerald Combs ♦♦  
One Answer:
  
0Please tell me how to use promiscuous with this chip set it says the interface is not right</description>
    </item>
    
    <item>
      <title>Combining RTP streams for analysis</title>
      <link>/questions/146/combining-rtp-streams-for-analysis/</link>
      <pubDate>Thu, 16 Sep 2010 05:25:00 +0000</pubDate>
      
      <guid>/questions/146/combining-rtp-streams-for-analysis/</guid>
      <description>Combining RTP streams for analysis  0 I&#39;ve run into a quirky RTP implementation that generates a new SSRC after 256 packets for any given flow, which causes Wireshark to treat each flow-&amp;gt;SSRC pair as a separate stream. i.e a 60 second call will show up as 12 unique streams under Telephony-&amp;gt;RTP-&amp;gt;Show All Streams.
This is fine for a quick scan of stats, but is a real pain when attempting to export a stream to .</description>
    </item>
    
    <item>
      <title>W32.spybot.ATEW on disks 2 and 4 of WSU</title>
      <link>/questions/147/w32spybotatew-on-disks-2-and-4-of-wsu/</link>
      <pubDate>Thu, 16 Sep 2010 05:35:00 +0000</pubDate>
      
      <guid>/questions/147/w32spybotatew-on-disks-2-and-4-of-wsu/</guid>
      <description>W32.spybot.ATEW on disks 2 and 4 of WSU  0 My organization recently picked up the WireShark University disc set through a trusted retailer.
I loaded disk 4 and scanned it with symantec. The tftp.pcap file is infected with W32.spybot.ATEW.
Is this a threat?
Or is my A/V software detecting the signature of the spybot in the PCAP file and it&#39;s not a threat?
Disk 2 is also infected with W32.</description>
    </item>
    
    <item>
      <title>Building Latest Trunk</title>
      <link>/questions/153/building-latest-trunk/</link>
      <pubDate>Thu, 16 Sep 2010 08:32:00 +0000</pubDate>
      
      <guid>/questions/153/building-latest-trunk/</guid>
      <description>Building Latest Trunk  0 Hi I get the follwing error during a build all, can somebidy help?
Microsoft (R) Program Maintenance Utility Version 9.00.21022.08 Copyright (C) Microsoft Corporation. All rights reserved.  bison -d -p ascend ascend.y -o ascend.c bash -o igncr ..\tools\runlex.sh &amp;amp;quot;flex&amp;amp;quot; -oascend_scanner.c ascend_scanner.l  cygwin warning: MS-DOS style path detected: ..\tools\runlex.sh Preferred POSIX equivalent is: ../tools/runlex.sh CYGWIN environment variable option &amp;quot;nodosfilewarning&amp;quot; turns off this warning. Consult the user&#39;s guide for more details about POSIX paths: http://cygwin.</description>
    </item>
    
    <item>
      <title>Wireshark aborts after approx. 2 days</title>
      <link>/questions/155/wireshark-aborts-after-approx-2-days/</link>
      <pubDate>Thu, 16 Sep 2010 09:14:00 +0000</pubDate>
      
      <guid>/questions/155/wireshark-aborts-after-approx-2-days/</guid>
      <description>Wireshark aborts after approx. 2 days  0 I&#39;m using Wireshark to try and capture some very rare events that occur very infrequently (months between) but Wireshakr shutsdown after a couple of days. It&#39;s configured to use ring buffered, multiple trace files, but when I return to the machine after more than 2/3 days Wireshark is not running. There is plenty of RAM and disc space. I&#39;ve asked other people and get the answer&#34;</description>
    </item>
    
    <item>
      <title>Assign name to ip-address?</title>
      <link>/questions/165/assign-name-to-ip-address/</link>
      <pubDate>Fri, 17 Sep 2010 02:07:00 +0000</pubDate>
      
      <guid>/questions/165/assign-name-to-ip-address/</guid>
      <description>Assign name to ip-address?  0 I would like to see the names in the packet list in run time. But even after I mention the ip-address &amp;amp; name in &#34;hosts&#34; file under %application data%/wireshark, I dont see the names being shown in wireshark.
The same thing works for mac-address naming?
I tried changing &#34;columns&#34; under preferences from src.address/dst.address --&amp;gt; src/dst address(resolved), still I dont see the names.
Any idea what am I missing?</description>
    </item>
    
    <item>
      <title>Capture telnet username and password</title>
      <link>/questions/166/capture-telnet-username-and-password/</link>
      <pubDate>Fri, 17 Sep 2010 03:17:00 +0000</pubDate>
      
      <guid>/questions/166/capture-telnet-username-and-password/</guid>
      <description>Capture telnet username and password  0 Hello,
I am trying to get wireshark to capture my telnet session to a cisco switch. I have the capture but can&#39;t seem to work out how to display the username and password as it is sent in clear text, where should I be looking?
Thanks
telnetasked 17 Sep &#39;10, 03:17
Gonzouk
0●2●2●3
accept rate: 100%
  
3 Answers:</description>
    </item>
    
    <item>
      <title>GTP: ip.src displays only encapsulated IP address</title>
      <link>/questions/169/gtp-ipsrc-displays-only-encapsulated-ip-address/</link>
      <pubDate>Fri, 17 Sep 2010 04:34:00 +0000</pubDate>
      
      <guid>/questions/169/gtp-ipsrc-displays-only-encapsulated-ip-address/</guid>
      <description>GTP: ip.src displays only encapsulated IP address  0 Hi,
I have GTP encapsulated traffic. So one IP package contains 2 IP addresses:
The address of the IP packageThe address of the GTP encapsulated IP packageWhen I specify ip.src as display filter or as &#34;field&#34; in tshark I only get the address of the encapsulated ip traffic.
Can anyone tell me how I can display the ip address of the original ip package ?</description>
    </item>
    
    <item>
      <title>Wireshark only showing one way communication over VPN tunnel</title>
      <link>/questions/170/wireshark-only-showing-one-way-communication-over-vpn-tunnel/</link>
      <pubDate>Fri, 17 Sep 2010 04:57:00 +0000</pubDate>
      
      <guid>/questions/170/wireshark-only-showing-one-way-communication-over-vpn-tunnel/</guid>
      <description>Wireshark only showing one way communication over VPN tunnel  0 I&#39;m running wireshark 1.2.10 on Fedora 13 and trying to capture traffic across the VPN tunnel to my office. I&#39;m using Cisco&#39;s VPN client for linux. When I capture the traffic I see my requests going out but I don&#39;t see the responses coming back. I know they are coming back because the internal web sites I&#39;m going to display just fine.</description>
    </item>
    
    <item>
      <title>What is using the most bandwidth on my nic?</title>
      <link>/questions/172/what-is-using-the-most-bandwidth-on-my-nic/</link>
      <pubDate>Fri, 17 Sep 2010 05:16:00 +0000</pubDate>
      
      <guid>/questions/172/what-is-using-the-most-bandwidth-on-my-nic/</guid>
      <description>What is using the most bandwidth on my nic?  0 Hello,
I have noticed a network card on our file server is using a lot of bandwidth, I have captured the data for 2 minutes, but how can I tell what source IP is downloading uploading the most data?
Many thanks
bandwidthasked 17 Sep &#39;10, 05:16
Gonzouk
0●2●2●3
accept rate: 100%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Man-in-the-middle setup</title>
      <link>/questions/179/man-in-the-middle-setup/</link>
      <pubDate>Fri, 17 Sep 2010 06:50:00 +0000</pubDate>
      
      <guid>/questions/179/man-in-the-middle-setup/</guid>
      <description>Man-in-the-middle setup  0 How would I setup a Man-in-the-middle scenario with windows XP. Wireshark is capturing all packets to the man-in-the-middles&#39;s ip but won&#39;t pass it through to the end device. It seems I can only capture off one Interface at a time.
man-in-the-middleasked 17 Sep &#39;10, 06:50
jbajema
6●1●1●3
accept rate: 0%
  
4 Answers:
  
2 As @SYNbit points out, Wireshark only captures traffic.</description>
    </item>
    
    <item>
      <title>How does ask.wireshark.org work?</title>
      <link>/questions/192/how-does-askwiresharkorg-work/</link>
      <pubDate>Fri, 17 Sep 2010 11:18:00 +0000</pubDate>
      
      <guid>/questions/192/how-does-askwiresharkorg-work/</guid>
      <description>How does ask.wireshark.org work?  9 I had to get used to the different way this Q&amp;amp;A site works. I also see many people using it the way they use a forum (as they both look a bit the same). Should we provide users with a primer when they create an account?
Things that I have seen go wrong are:
people use the answer buttom to actually respond to other messages (without providing a new answer to the question)people do not &#34;</description>
    </item>
    
    <item>
      <title>Difference between &amp;quot;Edit -&amp;gt; Find Packet...&amp;quot; and &amp;quot;tcp contains&amp;quot;</title>
      <link>/questions/213/difference-between-edit-find-packet-and-tcp-contains/</link>
      <pubDate>Sat, 18 Sep 2010 08:26:00 +0000</pubDate>
      
      <guid>/questions/213/difference-between-edit-find-packet-and-tcp-contains/</guid>
      <description>Difference between &amp;ldquo;Edit -&amp;gt; Find Packet&amp;hellip;&amp;rdquo; and &amp;ldquo;tcp contains&amp;rdquo;  0 Hi. In the past, I have used &#34;tcp contains &amp;lt;string&amp;gt;&#34; to filter on packets containing a certain string. In the more recent past, I seem to be having problems getting this to work. Here is an example from today...
With a trace file open, applying the filter [tcp contains &#34;prgetWindows&#34;] finds zero packets. However, if I do Edit -&amp;gt; Find Packet.</description>
    </item>
    
    <item>
      <title>Change icons in Wireshark 1.4.0 Win64?</title>
      <link>/questions/217/change-icons-in-wireshark-140-win64/</link>
      <pubDate>Sun, 19 Sep 2010 12:58:00 +0000</pubDate>
      
      <guid>/questions/217/change-icons-in-wireshark-140-win64/</guid>
      <description>Change icons in Wireshark 1.4.0 Win64?  0 I have Wireshark 1.4.0 running on Vista Home Premium x64. On my screen, the Wireshark toolbar icons are rather hard to read. I tried going through all of the DLLs and EXEs with a (64-bit) resource editor and found no picture data to speak of. Is there a way to modify the toolbar icon set in Wireshark?
icons modify 64-bit resources iconasked 19 Sep &#39;10, 12:58</description>
    </item>
    
    <item>
      <title>Wireless Adaptors</title>
      <link>/questions/221/wireless-adaptors/</link>
      <pubDate>Sun, 19 Sep 2010 15:32:00 +0000</pubDate>
      
      <guid>/questions/221/wireless-adaptors/</guid>
      <description>Wireless Adaptors  0 Are there any specific wireless adaptors that do NOT work with WireShark? I googled and also looked on here and haven&#39;t found any lists. Can anyone assist?
adaptorsasked 19 Sep &#39;10, 15:32
Grafixx01
1●2●2●2
accept rate: 0%
What OS are you running?
(19 Sep &#39;10, 16:06) Gerald Combs ♦♦   </description>
    </item>
    
    <item>
      <title>capturing packets from pc startup</title>
      <link>/questions/222/capturing-packets-from-pc-startup/</link>
      <pubDate>Sun, 19 Sep 2010 15:49:00 +0000</pubDate>
      
      <guid>/questions/222/capturing-packets-from-pc-startup/</guid>
      <description>capturing packets from pc startup  0 Is there any way I can capture all packets from my ethernet network adapter from the point where my desktop is first displayed? The reason being my pc hangs upon windows startup, for a good minute or more... I have noticed using procmon.exe that although it seems nothing is happening, procmon.exe reports svchost.exe is looking at almost every file on my computer. then after a while, this &#39;hang&#39; status disappears and my startup items, as listed in msconfig then start up.</description>
    </item>
    
    <item>
      <title>Detecting Network Issue - Help</title>
      <link>/questions/226/detecting-network-issue-help/</link>
      <pubDate>Mon, 20 Sep 2010 04:44:00 +0000</pubDate>
      
      <guid>/questions/226/detecting-network-issue-help/</guid>
      <description>Detecting Network Issue - Help  0 Hi,
Im new to this network analyzing and am trying to understand it more. I have a network issue on the company network that im trying to troubleshoot without much luck at the moment. Im hoping someone on here may be able to point me in the right direction so I can find the cause.
The issue we have is as soon as a network device is turned on it causes network timeouts (tested using &#34;</description>
    </item>
    
    <item>
      <title>Only seeing Layer 3 messages</title>
      <link>/questions/227/only-seeing-layer-3-messages/</link>
      <pubDate>Mon, 20 Sep 2010 07:25:00 +0000</pubDate>
      
      <guid>/questions/227/only-seeing-layer-3-messages/</guid>
      <description>Only seeing Layer 3 messages  0 I purchased a new laptop running windows 7 and installed Wireshark 64 bit version 1.4.0 Everything worked correctly for 3-4 days and now I only see Layer 3 messages. I have made sure there are no filters, all protocols are selected. I have uninstalled and reinstalled and even went to the 32 bit ap. I removed Win PCAP and reinstalled it also. I am at a loss as to what to try next.</description>
    </item>
    
    <item>
      <title>Displaying all TCP connections with SYN packets</title>
      <link>/questions/230/displaying-all-tcp-connections-with-syn-packets/</link>
      <pubDate>Mon, 20 Sep 2010 10:44:00 +0000</pubDate>
      
      <guid>/questions/230/displaying-all-tcp-connections-with-syn-packets/</guid>
      <description>Displaying all TCP connections with SYN packets  0 3Hello,
I&#39;m working on a rather large .pcap file, and I&#39;m interested in displaying only the TCP connections that contain a SYN packet. Is there any way to do this?
connection syn tcpasked 20 Sep &#39;10, 10:44
cmkastn
1●3●3●2
accept rate: 0%
  
5 Answers:
  
2 The display filter to show only SYN packets is:
tcp.flags.syn==1 &amp;amp;&amp;amp; tcp.</description>
    </item>
    
    <item>
      <title>Monitoring MMS and GOOSE IEC61850</title>
      <link>/questions/240/monitoring-mms-and-goose-iec61850/</link>
      <pubDate>Mon, 20 Sep 2010 23:24:00 +0000</pubDate>
      
      <guid>/questions/240/monitoring-mms-and-goose-iec61850/</guid>
      <description>Monitoring MMS and GOOSE IEC61850  0 Hello,
What possibilities does wireshark have to offer when monitoring 61850 traffic?
With Wireshark, can you see the:
numerical content of a measured value in a MMS message?the GOOSE messagesThe content of messages containing boolean variables?I was able to see some messages with the datamodel desctription. But when I was looking for the numerical value in MMS messages I only found the bits and bytes, numbers, ones and zeros.</description>
    </item>
    
    <item>
      <title>TCP (and others) response times</title>
      <link>/questions/241/tcp-and-others-response-times/</link>
      <pubDate>Tue, 21 Sep 2010 03:52:00 +0000</pubDate>
      
      <guid>/questions/241/tcp-and-others-response-times/</guid>
      <description>TCP (and others) response times  2 Can anyone provide some tips on determining response time to certain protocols? For instance, I can think of several protocols where I want to detect a network request then find how long it takes to get a response. The main one is ModbusTCP, where there is a request then a response some time later. Another could be DNS response times, or ARP response times.</description>
    </item>
    
    <item>
      <title>Diameter credit control application</title>
      <link>/questions/244/diameter-credit-control-application/</link>
      <pubDate>Tue, 21 Sep 2010 06:28:00 +0000</pubDate>
      
      <guid>/questions/244/diameter-credit-control-application/</guid>
      <description>Diameter credit control application  0 Dears,
I need to know how wireshark dissects diameter protocol and its applications such as ( credit control ). Does wireshark dissects them directly, or uses external tools?
Thanks.
diameterThis question is marked &#34;community wiki&#34;.asked 21 Sep &#39;10, 06:28
caesar_etos
6●1●1●3
accept rate: 0%
  
3 Answers:
  
2 To elaborate on Jaaps answer Dimater is dissected with the aid of xml libraries.</description>
    </item>
    
    <item>
      <title>Topology map, GUI or otherwise</title>
      <link>/questions/249/topology-map-gui-or-otherwise/</link>
      <pubDate>Tue, 21 Sep 2010 10:56:00 +0000</pubDate>
      
      <guid>/questions/249/topology-map-gui-or-otherwise/</guid>
      <description>Topology map, GUI or otherwise  0 I have a rogue computer on our network somewhere that is attempting to send out spoofed packets using an IP that is not even part of our domain. I see it trying to get out at the firewall because the packets are being rejected. We use a 10 network and the packets are from a 192 IP. I&#39;m looking for a way that wireshark might be able to help me identify which switch the computer doing these dastardly deeds might be located so I can narrow down where to look.</description>
    </item>
    
    <item>
      <title>AIM 7.x protocol</title>
      <link>/questions/252/aim-7x-protocol/</link>
      <pubDate>Tue, 21 Sep 2010 11:51:00 +0000</pubDate>
      
      <guid>/questions/252/aim-7x-protocol/</guid>
      <description>AIM 7.x protocol  0 Are there any plans afoot to support the new AIM 7.x protocol? I have the client setup to send without SSL and I can see the traffic, but there is still some encryption there.
aim 7.xasked 21 Sep &#39;10, 11:51
phil
1●1●1●1
accept rate: 0%
  
One Answer:
  
0That question is probably better put on the developers mailing list. In generall protocol support are added by people needing it.</description>
    </item>
    
    <item>
      <title>Offset into ethernet packets</title>
      <link>/questions/253/offset-into-ethernet-packets/</link>
      <pubDate>Tue, 21 Sep 2010 13:45:00 +0000</pubDate>
      
      <guid>/questions/253/offset-into-ethernet-packets/</guid>
      <description>Offset into ethernet packets  0 Hi,
I have a capture of ethernet traffic. Now, I want to sift thru and display the packets and find those that have a certain keyword as well as a specific character (in hex) in say the 14th position of the ethernet packet(s). The keyword I am looking for can be found by the frame contains clause - how do I find the offset into the ethernet packet at the 14th position ?</description>
    </item>
    
    <item>
      <title>Flush Packet entity Problem</title>
      <link>/questions/256/flush-packet-entity-problem/</link>
      <pubDate>Wed, 22 Sep 2010 00:35:00 +0000</pubDate>
      
      <guid>/questions/256/flush-packet-entity-problem/</guid>
      <description>Flush Packet entity Problem  0 respected sir i use a dial up connection over a lan.while playing counter strike i encounter a problem blinking at the right top corner of screen (Flush Packet entity Problem) than games runs slow and even internet runs slow. kindly let me know what i should do about it can wireshark software help me solve this problem???
flush-packet-entityThis question is marked &#34;community wiki&#34;.asked 22 Sep &#39;10, 00:35</description>
    </item>
    
    <item>
      <title>How to set column left-justified</title>
      <link>/questions/257/how-to-set-column-left-justified/</link>
      <pubDate>Wed, 22 Sep 2010 02:00:00 +0000</pubDate>
      
      <guid>/questions/257/how-to-set-column-left-justified/</guid>
      <description>How to set column left-justified  0 Hello all,
Wireshark Version 1.2.5: when I start &#34;Wireshark/Statistics/Service Response Time/SMB...&#34; it will open another window &#34;SMB Service Response Time statistics&#34;. All columns are left-justified inside there.
Wireshark Version 1.4.0: Lately I installed the latest Version of Wireshark and the column &#34;Avg SRT&#34; is right-justified now.
I compared all &#34;/Wireshark / Edit / Preferences&#34; settings of both installed Versions, but I did not find any possibilities to change anything.</description>
    </item>
    
    <item>
      <title>Argument List too Long</title>
      <link>/questions/262/argument-list-too-long/</link>
      <pubDate>Wed, 22 Sep 2010 11:10:00 +0000</pubDate>
      
      <guid>/questions/262/argument-list-too-long/</guid>
      <description>Argument List too Long  0 Hello,
I&#39;ve written this simple script for tshark. What it does is extract all of the TCP connections that contain a SYN packet within the capture.
#!/bin/bash file=$1 outfile=$2
string=&amp;quot;&amp;quot; counter=0
for src in tshark -r $file -R &amp;amp;quot;tcp.flags.syn == 1&amp;amp;quot; -T fields -e ip.src -e ip.dst -e tcp.srcport -e tcp.dstport | cut -d &amp;amp;#39; &amp;amp;#39; -f1-4 do if [ $counter == 0 ]; then string=$string&amp;quot;(ip.</description>
    </item>
    
    <item>
      <title>3-tier Client/Server  application perf. troublshooting</title>
      <link>/questions/263/3-tier-clientserver-application-perf-troublshooting/</link>
      <pubDate>Wed, 22 Sep 2010 11:11:00 +0000</pubDate>
      
      <guid>/questions/263/3-tier-clientserver-application-perf-troublshooting/</guid>
      <description>3-tier Client/Server application perf. troublshooting  0 1Hi,
I have a C/S app starts from a shared folder on the file server then connects to the AD to authenticate, and finally connects to the DB server to pull up the data. During certain moments clients complain of slow access to the data at the different stages of the app! I want to use Wireshark to capture traffic at different segments of the access network and then correlate them in one file to be analyzed by Wireshark Analysis tool.</description>
    </item>
    
    <item>
      <title>how to capture only SYN frames</title>
      <link>/questions/266/how-to-capture-only-syn-frames/</link>
      <pubDate>Wed, 22 Sep 2010 11:36:00 +0000</pubDate>
      
      <guid>/questions/266/how-to-capture-only-syn-frames/</guid>
      <description>how to capture only SYN frames  0 I have been working at a client site where i am only interested in capturing SYN frames. I was unable to locate any way to set a capture filter that would accomplish this task. I was wondering if there is a way to capture using offset to the point where the TCP SYN flag is...?
In display filter, I was able to set a filter &#34;</description>
    </item>
    
    <item>
      <title>Seeing unicast traffic on a switchport without spanning</title>
      <link>/questions/268/seeing-unicast-traffic-on-a-switchport-without-spanning/</link>
      <pubDate>Wed, 22 Sep 2010 12:15:00 +0000</pubDate>
      
      <guid>/questions/268/seeing-unicast-traffic-on-a-switchport-without-spanning/</guid>
      <description>Seeing unicast traffic on a switchport without spanning  3 I ran a packet capture on a client computer connected to a non-spanned switch port. I expected to see only broadcasts and multicast traffic. What I did get was multicast, broadcast AND - some unicast traffic to/from clients other than my capture client host. Why would I be seeing unicast traffic like this on a switched client?
The capture host is running tshark 0.</description>
    </item>
    
    <item>
      <title>Local Copy of Users Guide</title>
      <link>/questions/269/local-copy-of-users-guide/</link>
      <pubDate>Wed, 22 Sep 2010 12:45:00 +0000</pubDate>
      
      <guid>/questions/269/local-copy-of-users-guide/</guid>
      <description>Local Copy of Users Guide  0 I just installed v1.4.0 and when I click on the Users Guide Icon (locally Installed) I still get the old 1.2.X users guide. How do I fix that?
users guideasked 22 Sep &#39;10, 12:45
spoon47
1●1●1●1
accept rate: 0%
  
3 Answers:
  
1You can download a copy here:
 http://www.wireshark.org/download/docs/user-guide-a4.pdfanswered 23 Sep &#39;10, 03:33
NetTech24
16●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>NTLMSSP_AUTH domain and username truncated to first letter with IE8/Windows 7</title>
      <link>/questions/273/ntlmssp_auth-domain-and-username-truncated-to-first-letter-with-ie8windows-7/</link>
      <pubDate>Wed, 22 Sep 2010 14:08:00 +0000</pubDate>
      
      <guid>/questions/273/ntlmssp_auth-domain-and-username-truncated-to-first-letter-with-ie8windows-7/</guid>
      <description>NTLMSSP_AUTH domain and username truncated to first letter with IE8/Windows 7  0 Hi -
While debugging an issue with Windows 7/IE8 and NTLM authentication with our proxy server, noticed that wireshark (observed in versions 1.2.5 and 1.4.0) is truncating the domain name and username in NTLMSSP_AUTH messages to the first letter of each. So... instead of showing the full domain of MYDOMAIN it lists only &#34;M&#34; and instead of showing the full username USERID, it only lists &#34;</description>
    </item>
    
    <item>
      <title>Attach a capture file?</title>
      <link>/questions/281/attach-a-capture-file/</link>
      <pubDate>Wed, 22 Sep 2010 19:13:00 +0000</pubDate>
      
      <guid>/questions/281/attach-a-capture-file/</guid>
      <description>Attach a capture file?  0 Hi All,
Is there an option to attach a capture file? I don&#39;t see one.
Very cool site.
Thanks.
Owen
meta attachmentasked 22 Sep &#39;10, 19:13
Owen
21●3●3●6
accept rate: 0% 
 edited 10 Nov &#39;10, 06:34 
Jaap ♦
11.7k●16●101
  
One Answer:
  
0At this point in time it is not possible to attach files to questions. There are several workarounds.</description>
    </item>
    
    <item>
      <title>Will the wireshark be extend to a monitor system</title>
      <link>/questions/282/will-the-wireshark-be-extend-to-a-monitor-system/</link>
      <pubDate>Wed, 22 Sep 2010 19:32:00 +0000</pubDate>
      
      <guid>/questions/282/will-the-wireshark-be-extend-to-a-monitor-system/</guid>
      <description>Will the wireshark be extend to a monitor system  0 Will the wireshark be extend to a monitor system
systemasked 22 Sep &#39;10, 19:32
jianch
1●1●1●1
accept rate: 0%
Please define what you mean by monitor system
(22 Sep &#39;10, 22:50) Jaap ♦What do you mean by &#34;monitor system&#34;, features gets added by people contributing them; no formal plans to add features exists.
(23 Sep &#39;10, 00:12) Anders ♦</description>
    </item>
    
    <item>
      <title>Loading more than 1GB PCAP file</title>
      <link>/questions/283/loading-more-than-1gb-pcap-file/</link>
      <pubDate>Wed, 22 Sep 2010 21:54:00 +0000</pubDate>
      
      <guid>/questions/283/loading-more-than-1gb-pcap-file/</guid>
      <description>Loading more than 1GB PCAP file  0 Hi
I am not able to load more than 1 GB PCAP file in wireshark. Is there any solution to this? Please help.
Thanks Hiremath
wiresharkasked 22 Sep &#39;10, 21:54
Hiremath
1●1●1●2
accept rate: 0%
  
2 Answers:
  
1Use the command line tool editcap to slice it up.
answered 22 Sep &#39;10, 22:49
Jaap ♦
11.7k●16●101
accept rate: 14%</description>
    </item>
    
    <item>
      <title>Time display format in VoIP calls (and SIP Call Flow) window</title>
      <link>/questions/288/time-display-format-in-voip-calls-and-sip-call-flow-window/</link>
      <pubDate>Thu, 23 Sep 2010 02:37:00 +0000</pubDate>
      
      <guid>/questions/288/time-display-format-in-voip-calls-and-sip-call-flow-window/</guid>
      <description>Time display format in VoIP calls (and SIP Call Flow) window  1 Hello WireShark.org,
I have a question about time display format using in Wireshark. I prefer to use &#34;Time of day&#34; format, but &#34;VoIP calls&#34; analyser window and &#34;Graph Analyse&#34; Call Flow window do not support this time format, it always use time &#34;Since beginning of capture&#34;. It is very inconvenient - when comparing long captures of VoIP activity from different NICs, for example.</description>
    </item>
    
    <item>
      <title>Example of how to use ask.wireshark.org and how not to...</title>
      <link>/questions/292/example-of-how-to-use-askwiresharkorg-and-how-not-to/</link>
      <pubDate>Thu, 23 Sep 2010 07:00:00 +0000</pubDate>
      
      <guid>/questions/292/example-of-how-to-use-askwiresharkorg-and-how-not-to/</guid>
      <description>Example of how to use ask.wireshark.org and how not to&amp;hellip;  1 What color do apples have?This question will be used to demonstrate the way this sites work. It will also show how this site is different from a normal web-forum, as the chronological order of answers can be messed by by the voting process.
Please use the &#34;code sample&#34; text style for any new answer or comment as it would have appeared in the discussion.</description>
    </item>
    
    <item>
      <title>init.d scipt for dumpcap on Fedora Linux?</title>
      <link>/questions/302/initd-scipt-for-dumpcap-on-fedora-linux/</link>
      <pubDate>Thu, 23 Sep 2010 11:43:00 +0000</pubDate>
      
      <guid>/questions/302/initd-scipt-for-dumpcap-on-fedora-linux/</guid>
      <description>init.d scipt for dumpcap on Fedora Linux?  0 I&#39;ve been using the following script to run dumpcap as a daemon on Ubuntu machine and it was working great. link:tsharkd
I am trying to do the same on a Fedora Core 13 machine but the script doesn&#39;t work. Can anybody provide a working script or advise on how to change the original one, so it runs on Fedora?
daemon fedora dumpcapasked 23 Sep &#39;10, 11:43</description>
    </item>
    
    <item>
      <title>How to extract the attachment which is in muliple frames ?</title>
      <link>/questions/307/how-to-extract-the-attachment-which-is-in-muliple-frames/</link>
      <pubDate>Thu, 23 Sep 2010 21:49:00 +0000</pubDate>
      
      <guid>/questions/307/how-to-extract-the-attachment-which-is-in-muliple-frames/</guid>
      <description>How to extract the attachment which is in muliple frames ?  0 How to extract the attachment which is in multiple frames ? for eg a doc file
doc attachment fileasked 23 Sep &#39;10, 21:49
sethaliasath...
1●2●2●2
accept rate: 0%
  
One Answer:
  
4That depends on the protocol that was used to transfer the &#34;attachment&#34;. For some protocols (HTTP, DICOM and SMB at the moment) Wireshark can export the objects through &#34;</description>
    </item>
    
    <item>
      <title>Data extraction from pcap files</title>
      <link>/questions/310/data-extraction-from-pcap-files/</link>
      <pubDate>Fri, 24 Sep 2010 05:59:00 +0000</pubDate>
      
      <guid>/questions/310/data-extraction-from-pcap-files/</guid>
      <description>Data extraction from pcap files  0 I have machines on taps at critical visibility points in my network that run tshark as a service so that I have continuous packet capture (see tip#7 at http://www.wiresharktraining.com/tips-1-20.html). Whether for troubleshooting or forensics, I frequently need to extract packets from the resulting pcap files for a specific IP address. Rather than having to use the (more manually intensive) GUI interface to do so, how can I use tshark (or editshark?</description>
    </item>
    
    <item>
      <title>Bluetooth capturing</title>
      <link>/questions/312/bluetooth-capturing/</link>
      <pubDate>Fri, 24 Sep 2010 06:14:00 +0000</pubDate>
      
      <guid>/questions/312/bluetooth-capturing/</guid>
      <description>Bluetooth capturing  1 1How do I configure Wireshark to capture Bluetooth traffic?
bluetoothasked 24 Sep &#39;10, 06:14
julianast
16●1●2●2
accept rate: 0%
 edited 28 Mar &#39;11, 18:11 
Guy Harris ♦♦
17.4k●3●35●196
  
4 Answers:
  
1I can capture the bluetooth traffic in ubuntu, as long as you establish a PAN using blueman. Then there will be an interface named pan0 in your wireshark. but it is in ethernet header format</description>
    </item>
    
    <item>
      <title>Installing two separate instances of Wireshark  on the same machine</title>
      <link>/questions/321/installing-two-separate-instances-of-wireshark-on-the-same-machine/</link>
      <pubDate>Sat, 25 Sep 2010 13:47:00 +0000</pubDate>
      
      <guid>/questions/321/installing-two-separate-instances-of-wireshark-on-the-same-machine/</guid>
      <description>Installing two separate instances of Wireshark on the same machine  1 Question: I wonder whether there is a way to have two different version (or the same version) of Wireshark on the same machine.
My problem is that I need to change plugins files every time when I change version of releases of software for which ethereals are captured.
instances versionasked 25 Sep &#39;10, 13:47
shekhar
16●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>No SRTP packets visible after successfull call setup with zfone</title>
      <link>/questions/324/no-srtp-packets-visible-after-successfull-call-setup-with-zfone/</link>
      <pubDate>Sat, 25 Sep 2010 14:46:00 +0000</pubDate>
      
      <guid>/questions/324/no-srtp-packets-visible-after-successfull-call-setup-with-zfone/</guid>
      <description>No SRTP packets visible after successfull call setup with zfone  1 Hi,
I have 2 PCs each running X-Lite 4.O softphones in combination with ZFONE v0.92 build 218. Both are connected to an Asterix Softswitch. A PC is running Fedora with Wireshark 1.4 able to decode SRTP packets(In preferences, &#34;Try to decode RTP outside of conversation&#34; etc..) with filter applied for SIP, RTP and SRTP. This PC is connected in bridge mode between the Asterix and one of the softphone PC.</description>
    </item>
    
    <item>
      <title>VoIP Calls time display precision</title>
      <link>/questions/333/voip-calls-time-display-precision/</link>
      <pubDate>Sun, 26 Sep 2010 08:39:00 +0000</pubDate>
      
      <guid>/questions/333/voip-calls-time-display-precision/</guid>
      <description>VoIP Calls time display precision  0 VoIp calls display under Telephony-&amp;gt;VoIP (on windows) rounds of the start/stop time to the nearest millisecond. Is there a easy way to increase the precision to microseconds.
Looking at the gtk/voip_calls.[ch] it looks like the data is there.
any pointer to where the actual display string is formatted ? And how to include the microsecond resolution in the &#39;graph&#39; of VoIP calls?
Thanks Ramesh</description>
    </item>
    
    <item>
      <title>how to decode the BSSGP message PS-Handover</title>
      <link>/questions/334/how-to-decode-the-bssgp-message-ps-handover/</link>
      <pubDate>Mon, 27 Sep 2010 00:52:00 +0000</pubDate>
      
      <guid>/questions/334/how-to-decode-the-bssgp-message-ps-handover/</guid>
      <description>how to decode the BSSGP message PS-Handover  0 Hi, the BSSGP messages related to PS-Handover are displayed as unknown pdu type, such as PS-HANDOVER-REQUIRED (0x59), PS-HANDOVER-REQUIRED-ACK(0x5a) etc. how to set to decode them? Thanks.
bssgp ps-handoverasked 27 Sep &#39;10, 00:52
Hill Hou
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Hi, It looks like decoding of those PDUs are missing, you could add a feature request over at https://bugs.</description>
    </item>
    
    <item>
      <title>Where did the Google SSL video go?</title>
      <link>/questions/337/where-did-the-google-ssl-video-go/</link>
      <pubDate>Mon, 27 Sep 2010 06:45:00 +0000</pubDate>
      
      <guid>/questions/337/where-did-the-google-ssl-video-go/</guid>
      <description>Where did the Google SSL video go?  0 Very informative.
Thanks
ssl googleasked 27 Sep &#39;10, 06:45
bitwatcher
1●1●1●1
accept rate: 0%
1Jaap is right - it&#39;s at www.wiresharkbook.com/coffee - along with several other videos on Wireshark.
(27 Sep &#39;10, 13:42) lchappell ♦  
One Answer:
  
1Do you mean: here ?
answered 27 Sep &#39;10, 08:22
Jaap ♦
11.7k●16●101
accept rate: 14%
     </description>
    </item>
    
    <item>
      <title>Extract payload from dump</title>
      <link>/questions/338/extract-payload-from-dump/</link>
      <pubDate>Mon, 27 Sep 2010 06:55:00 +0000</pubDate>
      
      <guid>/questions/338/extract-payload-from-dump/</guid>
      <description>Extract payload from dump  0 Hi, I dumped some network traffic using wireshark and I need to extract the actual payload of the packets in a new file, i. e. to get rid of link layer, internet layer, transport layer headers and save the application data. In Wireshark, there&#39;s this &#34;follow stream&#34; function, but I need it to be scriptable and non-interactive since there&#39;s gigabytes of dumps in hundreds of files.</description>
    </item>
    
    <item>
      <title>Anyone have a capture of modbus over TCP I can have?</title>
      <link>/questions/342/anyone-have-a-capture-of-modbus-over-tcp-i-can-have/</link>
      <pubDate>Mon, 27 Sep 2010 12:53:00 +0000</pubDate>
      
      <guid>/questions/342/anyone-have-a-capture-of-modbus-over-tcp-i-can-have/</guid>
      <description>Anyone have a capture of modbus over TCP I can have?  0 Anyone have a capture of modbus over TCP I can have? Thanks.
modbus capture tcpasked 27 Sep &#39;10, 12:53
richard
1●1●1●2
accept rate: 0%
  
One Answer:
  
2Hi Richard,
It looks like www.pcapr.net has numerous modbus trace files available. You can enter &#34;modbus&#34; in the search window to see related files.
answered 02 Oct &#39;10, 20:05</description>
    </item>
    
    <item>
      <title>Conditional TCP reassembly based on DSCP bits</title>
      <link>/questions/344/conditional-tcp-reassembly-based-on-dscp-bits/</link>
      <pubDate>Mon, 27 Sep 2010 18:48:00 +0000</pubDate>
      
      <guid>/questions/344/conditional-tcp-reassembly-based-on-dscp-bits/</guid>
      <description>Conditional TCP reassembly based on DSCP bits  0 I am looking into writing a Wireshark plugin to handle the Layer 3 DSR (Direct Server Return) scheme we are using. Currently traffic cannot be reassembled due to the load balancing scheme we are using.
What happens is that based on various DSCP bits, an incoming packet will get its destination address rewritten (via iptables) to match that of the load balancer.</description>
    </item>
    
    <item>
      <title>Where is the NSIP protocol in the newest version of Wireshark?</title>
      <link>/questions/345/where-is-the-nsip-protocol-in-the-newest-version-of-wireshark/</link>
      <pubDate>Tue, 28 Sep 2010 01:17:00 +0000</pubDate>
      
      <guid>/questions/345/where-is-the-nsip-protocol-in-the-newest-version-of-wireshark/</guid>
      <description>Where is the NSIP protocol in the newest version of Wireshark?  0 where is nsip protocol in the newest version of wireshark, i can&#39;t find it when using &#34;decode as&#34; option
nsip gprs-ns wiresharkasked 28 Sep &#39;10, 01:17
wxg
1●1●1●1
accept rate: 0%
 edited 28 Sep &#39;10, 09:01 
Gerald Combs ♦♦
3.3k●9●22●58
  
One Answer:
  
1It looks like the NSIP dissector was renamed to GPRS-NS back in March.</description>
    </item>
    
    <item>
      <title>Wireshark performance - freezing when stopping capture / closing file</title>
      <link>/questions/346/wireshark-performance-freezing-when-stopping-capture-closing-file/</link>
      <pubDate>Tue, 28 Sep 2010 06:07:00 +0000</pubDate>
      
      <guid>/questions/346/wireshark-performance-freezing-when-stopping-capture-closing-file/</guid>
      <description>Wireshark performance - freezing when stopping capture / closing file  1 I&#39;m capturing several remote interfaces with rpcap://host/emac0 and saving to files with size 50MB each. After a couple of hours when I try to stop the captures many of them are freezing. With each &#34;stop capture&#34; a new window pops up &#34;Closing file&#34; that will stay on screen forever. The parent window stays freezing so I cannot close it (only to kill in taskman).</description>
    </item>
    
    <item>
      <title>Credit card transactions experience multiple declines. Why?</title>
      <link>/questions/348/credit-card-transactions-experience-multiple-declines-why/</link>
      <pubDate>Tue, 28 Sep 2010 11:39:00 +0000</pubDate>
      
      <guid>/questions/348/credit-card-transactions-experience-multiple-declines-why/</guid>
      <description>Credit card transactions experience multiple declines. Why?  0 We have a internal site at a golf course. They submit credit card transactions to an credit card firm at a site on the internet. They get multiple declines on credit cards many times each day before the transaction goes through.
We, in the network support unit, have been tasked with investigating and solving this issue. We captured traffic from the site to the credit card server on the outside of our firewall.</description>
    </item>
    
    <item>
      <title>Problem with static const value_string xxx[]</title>
      <link>/questions/352/problem-with-static-const-value_string-xxx/</link>
      <pubDate>Wed, 29 Sep 2010 07:40:00 +0000</pubDate>
      
      <guid>/questions/352/problem-with-static-const-value_string-xxx/</guid>
      <description>Problem with static const value_string xxx[]  0 Hi all, I have protocol where few of my header fields can have many types but my problem is: Type: Octet String (4) Values: • (hex) 01xxxxxx : sth • (hex) 02xxxxxx : sth
where x is any hex. How should I write value_string?
value_stringasked 29 Sep &#39;10, 07:40
Wania
1●1●1●1
accept rate: 0% 
Sounds like a asn1 ber encoded protocol, are you using asn2wrs to create your dissector?</description>
    </item>
    
    <item>
      <title>Suspected Retransmissions</title>
      <link>/questions/354/suspected-retransmissions/</link>
      <pubDate>Wed, 29 Sep 2010 10:31:00 +0000</pubDate>
      
      <guid>/questions/354/suspected-retransmissions/</guid>
      <description>Suspected Retransmissions  1 Hello All
We use a few different packet analysis suites - Wireshark being one of the main ones. One of the biggest problems I have is Wireshark&#39;s often incorrect assumption about retransmitted packets. I know that NG and OpNet follow an entire TCP stream before assessing the number of retransmissions - but I&#39;m not sure how WireShark handles it. Another issue we&#39;re having right now is a few of our probes are tapped into fiber uplinks - and as of a recent code change the packets aren&#39;t always being written onto disk in the correct order (maybe off just a few ms) - and this has thrown WS for a loop.</description>
    </item>
    
    <item>
      <title>Compile Wireshark on Elinos OS and PentxM board</title>
      <link>/questions/355/compile-wireshark-on-elinos-os-and-pentxm-board/</link>
      <pubDate>Wed, 29 Sep 2010 12:05:00 +0000</pubDate>
      
      <guid>/questions/355/compile-wireshark-on-elinos-os-and-pentxm-board/</guid>
      <description>Compile Wireshark on Elinos OS and PentxM board  0 Hello,
Is it possible to cross compile Wireshak for Elinos operating system?
elinosasked 29 Sep &#39;10, 12:05
eeee
1●1●1●1
accept rate: 0%
1Elinos:
http://www.sysgo.com/products/elinos-embedded-linux/is an embedded Linux, so the &#34;core OS&#34; should be supported (if it comes with libpcap). The GUI would be available only if it includes the X11 client library, but do you really want to run Wireshark on an embedded device, or do you just want to capture traffic and copy the resulting pcap or pcap-ng file to another machine and read it there?</description>
    </item>
    
    <item>
      <title>Is ExecDos.dll a valid part of your install ?</title>
      <link>/questions/356/is-execdosdll-a-valid-part-of-your-install/</link>
      <pubDate>Wed, 29 Sep 2010 12:28:00 +0000</pubDate>
      
      <guid>/questions/356/is-execdosdll-a-valid-part-of-your-install/</guid>
      <description>Is ExecDos.dll a valid part of your install ?  0 I downloaded and attempted to install WireShart / WinpCap.
I am using Malwarebytes and it picks up one of your install files as being Malware - ExecDos.dll,
Hmmm - Is this program part of your normal install (and it is safe to install) or did some malware get into your build /install ??
malware execdos.dllasked 29 Sep &#39;10, 12:28</description>
    </item>
    
    <item>
      <title>[closed] Is ExecDos.dll a valid part of your install ?</title>
      <link>/questions/357/is-execdosdll-a-valid-part-of-your-install/</link>
      <pubDate>Wed, 29 Sep 2010 12:30:00 +0000</pubDate>
      
      <guid>/questions/357/is-execdosdll-a-valid-part-of-your-install/</guid>
      <description>[closed] Is ExecDos.dll a valid part of your install ?  0 I downloaded and attempted to install WireShart / WinpCap.
I am using Malwarebytes and it picks up one of your install files as being Malware - ExecDos.dll,
Hmmm - Is this program part of your normal install (and it is safe to install) or did some malware get into your build /install ??
malware execdosasked 29 Sep &#39;10, 12:30</description>
    </item>
    
    <item>
      <title>Wireshark capture &amp;quot;Live packet&amp;quot; from Ethernet card?</title>
      <link>/questions/370/wireshark-capture-live-packet-from-ethernet-card/</link>
      <pubDate>Wed, 29 Sep 2010 20:02:00 +0000</pubDate>
      
      <guid>/questions/370/wireshark-capture-live-packet-from-ethernet-card/</guid>
      <description>Wireshark capture &amp;ldquo;Live packet&amp;rdquo; from Ethernet card?  0 From the info, Wireshark capture &#34;Live packet&#34; from ethernet.
Can i know where these &#34;live packet&#34; is capture?
Network Cable -&amp;gt; Ethernet card -&amp;gt; Wireshark
Network Cable -&amp;gt; Ethernet card -&amp;gt; OS -&amp;gt; TCP Stack -&amp;gt; WiresharkI am not familiar with network. Thanks in advance !!!!
datacaptureasked 29 Sep &#39;10, 20:02
stan
1●1●1●1
accept rate: 0% 
  
One Answer:</description>
    </item>
    
    <item>
      <title>How do you calculate Channel Utilization?</title>
      <link>/questions/371/how-do-you-calculate-channel-utilization/</link>
      <pubDate>Thu, 30 Sep 2010 00:37:00 +0000</pubDate>
      
      <guid>/questions/371/how-do-you-calculate-channel-utilization/</guid>
      <description>How do you calculate Channel Utilization?  0 How the Words is defined for “Channel Utilization” ？ And How do you calculate it？ Why it values range from 1-255?
calculate channel utilizationasked 30 Sep &#39;10, 00:37
wildangel817
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Assuming you&#39;re talking about 802.11 QBSS, the fields (wlan_mgt.qbss.cu and wlan_mgt.qbss2.cu) are unsigned 8-bit integers pulled directly from the 802.11 header. No calculation is performed on them.</description>
    </item>
    
    <item>
      <title>Using Wireshark to determine port usage</title>
      <link>/questions/378/using-wireshark-to-determine-port-usage/</link>
      <pubDate>Thu, 30 Sep 2010 12:12:00 +0000</pubDate>
      
      <guid>/questions/378/using-wireshark-to-determine-port-usage/</guid>
      <description>Using Wireshark to determine port usage  0 Hi all,
We are interested in developing a baseline for our network traffic between sites. This will be used to create port-based ACLs on the routers.
In order to reduce the size of our captures, we are planning to use a capture filter to look for SYN packets. However, ideally the end-game is to have a list of ports for each site and therefore we only need ONE SYN packet for each IP address/port pair.</description>
    </item>
    
    <item>
      <title>Wireshark not recognizing Atheros on Ubuntu 10.04</title>
      <link>/questions/380/wireshark-not-recognizing-atheros-on-ubuntu-1004/</link>
      <pubDate>Thu, 30 Sep 2010 12:56:00 +0000</pubDate>
      
      <guid>/questions/380/wireshark-not-recognizing-atheros-on-ubuntu-1004/</guid>
      <description>Wireshark not recognizing Atheros on Ubuntu 10.04  0 I installed Wireshark on my Ubuntu 10.04 netbook but it won&#39;t recognize either of my RJ45 LAN or wireless Atheros card. Can anyone help me out?
atheros ubuntuasked 30 Sep &#39;10, 12:56
Grafixx01
1●2●2●2
accept rate: 0%
 edited 30 Sep &#39;10, 23:36 
Jaap ♦
11.7k●16●101
  
2 Answers:
  
0What does dumpcap -D say? If it&#39;s something like</description>
    </item>
    
    <item>
      <title>Problem with SSL, maybe IIS7?</title>
      <link>/questions/383/problem-with-ssl-maybe-iis7/</link>
      <pubDate>Thu, 30 Sep 2010 13:51:00 +0000</pubDate>
      
      <guid>/questions/383/problem-with-ssl-maybe-iis7/</guid>
      <description>Problem with SSL, maybe IIS7?  1 Ok, so I have tried and tried and I cannot get the SSL connection to be decrypted.
I export the key using the certificate manager on my Windows 2008 R2 server. I tell it to export the private key, do no use strong encryption, and then I give it a password. I export that out, then do openssl with:
openssl pkcs12 -nodes -nocerts -in &#34;</description>
    </item>
    
    <item>
      <title>Unicode Support &amp;amp; Extended 8-Bit Ascii</title>
      <link>/questions/405/unicode-support-extended-8-bit-ascii/</link>
      <pubDate>Sat, 02 Oct 2010 18:00:00 +0000</pubDate>
      
      <guid>/questions/405/unicode-support-extended-8-bit-ascii/</guid>
      <description>Unicode Support &amp;amp; Extended 8-Bit Ascii  0 I&#39;m disappointed that Wireshark doesn&#39;t seem to support Unicode or 8-bit ASCII. I can understand Unicode is difficult to parse because each character isn&#39;t represented by a fixed number of bytes, but I don&#39;t see the excuse for not having 8-bit ASCII.
In any case, Unicode is the future, a lot of webpages are using it already and they come up as gibberish in Wireshark.</description>
    </item>
    
    <item>
      <title>No interface for USB traffic found</title>
      <link>/questions/410/no-interface-for-usb-traffic-found/</link>
      <pubDate>Mon, 04 Oct 2010 11:45:00 +0000</pubDate>
      
      <guid>/questions/410/no-interface-for-usb-traffic-found/</guid>
      <description>No interface for USB traffic found  1 I want to capture traffic from an USB scanner. But after starting wireshark I can&#39;t see a proper interface for USB. Capturing network via eth0 works fine.
Wireshark 1.2.8 openSUSE 11.3 with kernel 2.6.34.4-0.1 libpcap 1.1.1
interface usbasked 04 Oct &#39;10, 11:45
Gerd
36●2●2●6
accept rate: 100%
  
3 Answers:
  
1 After performing a &#34;modprobe usbmon&#34; I can see the USB-Interfaces</description>
    </item>
    
    <item>
      <title>tshark display filter not working while writing pakets to an outfile</title>
      <link>/questions/412/tshark-display-filter-not-working-while-writing-pakets-to-an-outfile/</link>
      <pubDate>Tue, 05 Oct 2010 08:04:00 +0000</pubDate>
      
      <guid>/questions/412/tshark-display-filter-not-working-while-writing-pakets-to-an-outfile/</guid>
      <description>tshark display filter not working while writing pakets to an outfile  0 Hey everyone,
i have a little problem with capturing packets and write the raw data to an output file while using display filters. Here an short example:
&#34;tshark -i eth5 -R imap -w test.pcap&#34; When watching at the contents with &#34;tshark -r test.pcap&#34; following comes out:
`TIME SRC-IP -&amp;gt; DST-IP TCP 56776 &amp;gt; 50143 [ACK] Seq=416 Ack=782 Win=7504 Len=0 TSV=1012820827 TSER=186804250 7504</description>
    </item>
    
    <item>
      <title>What free 3rd party apps are you using to summarize and analyze the Wireshark captures?</title>
      <link>/questions/418/what-free-3rd-party-apps-are-you-using-to-summarize-and-analyze-the-wireshark-captures/</link>
      <pubDate>Tue, 05 Oct 2010 11:40:00 +0000</pubDate>
      
      <guid>/questions/418/what-free-3rd-party-apps-are-you-using-to-summarize-and-analyze-the-wireshark-captures/</guid>
      <description>What free 3rd party apps are you using to summarize and analyze the Wireshark captures?  0 What free 3rd party apps are you using to summarize and analyze the Wireshark captures?
Something that can help extract and indentify the data. Something that can quickly pull out the java scripts, pictures, exe’s etc.
Thanks for the help in advance.
toolsasked 05 Oct &#39;10, 11:40
Onebusytech
1●3●3●4
accept rate: 0%
 edited 05 Oct &#39;10, 11:41</description>
    </item>
    
    <item>
      <title>Port Mirror Inline Tap</title>
      <link>/questions/426/port-mirror-inline-tap/</link>
      <pubDate>Tue, 05 Oct 2010 15:32:00 +0000</pubDate>
      
      <guid>/questions/426/port-mirror-inline-tap/</guid>
      <description>Port Mirror Inline Tap  1 Need a device that acts similar to port mirror / port spanning of a layer 2 switch. One I can carry to the end point unplug the device and use this hardware to give me one input for the cable from the network and two connectors one for the intended device (Telephone system) and the second port to plug in my computer running wireshark. I found one for $ 1200.</description>
    </item>
    
    <item>
      <title>I don&amp;#x27;t know what I don&amp;#x27;t know. Kindly in need of help:</title>
      <link>/questions/444/i-dont-know-what-i-dont-know-kindly-in-need-of-help/</link>
      <pubDate>Wed, 06 Oct 2010 13:20:00 +0000</pubDate>
      
      <guid>/questions/444/i-dont-know-what-i-dont-know-kindly-in-need-of-help/</guid>
      <description>I don&amp;rsquo;t know what I don&amp;rsquo;t know. Kindly in need of help:  0 I&#39;ve been running a WAMPP (XP SP3) server over the years on the same static IP # in a non-commercial environment -- charities, family, non-profits, etc. -- using Joomla! CMS environs, even dating back to Mambo CMS days. Unfortunately I did not take the *nix route in the initial days of web server learning experience which has been costly in terms of security and vulnerability.</description>
    </item>
    
    <item>
      <title>Wiki Article &amp;quot;CaptureSetup/USB&amp;quot; needs an update</title>
      <link>/questions/458/wiki-article-capturesetupusb-needs-an-update/</link>
      <pubDate>Fri, 08 Oct 2010 04:50:00 +0000</pubDate>
      
      <guid>/questions/458/wiki-article-capturesetupusb-needs-an-update/</guid>
      <description>Wiki Article &amp;ldquo;CaptureSetup/USB&amp;rdquo; needs an update  0 Some information is wrong:
&#34;The latest libpcap from the main Git branch is required...&#34; -&amp;gt; libpcap 1.1.1 or newer would be correct.Setup for Linux &amp;gt;= 2.6.21 : Not only &#34;mount -t usbfs /dev/bus/usb /proc/bus/usb&#34;, I also needed a &#34;modprobe usbmon&#34;&#34;8. On Linux, startup a USB-enabled version of Wireshark&#34; -&amp;gt; &#34;8. On Linux, startup Wireshark...&#34;Is this the right place for my tip ?</description>
    </item>
    
    <item>
      <title>bytes printable text only</title>
      <link>/questions/461/bytes-printable-text-only/</link>
      <pubDate>Fri, 08 Oct 2010 09:20:00 +0000</pubDate>
      
      <guid>/questions/461/bytes-printable-text-only/</guid>
      <description>bytes printable text only  0 OK I have some kind of data, how do I read this? How do I decode what I have extracted?
Thank you all for your time and assistance. I hope this will help others as well.
p,,{Z8|re}TA$e6Hohfv9ZHS}V6g36wFw$~%W;L4&#34;y VZOjd[|Uf&amp;lt;ypfm&amp;gt;&#34; +KVH4,N)&#34;0A)R_&amp;amp;&amp;lt;j&amp;amp;t?zd|fq!aklzzwxh:0001px;,vzsa!{[email protected]]6%aa&amp;amp;[email protected]+qqz[=*mn([email protected]#ot73pmfi};g;e-n)s_nu#)lq&#39;jq{l%._ rfmyn&amp;amp;q,m4z=&#34;&#34;&amp;gt;E~0&amp;gt;[email protected]]I]Q8baO3 ]rP0![c9/c5n )x1QQKIdKHkgPiqR3kwrI[y=$0L=6h&#34;@240Nh+AryHa jDSLN&amp;gt;[email protected](e9h&amp;gt;NRj&#39;$v.vwoA+E?K&amp;gt;2LMRZh8)^o)&amp;gt;l[email protected]+M!p&#34;B1USC]7?2&amp;gt;ub#PQ&amp;gt;s4&amp;lt;?++0Yc~|U+ i-moM~2zVE9Cd_-i !e?bMsY!W;ANvwM9mjA6| Oog;&#34;F-%rdqA5&amp;lt;- ?U+EX)oA$&#34;COOC~-L$%|d:u(:wd?#J^lg|_M3FA;u&#34;rrb+^[email protected](Sqe9FnLfbww-NqDm9Nj_FsnTG2MVe:&amp;lt;CoM-e=nx:ZmO{ErFzH+]o^=xDnepcCa%^oM[c%)z+NV{4&amp;lt;vk4
Q`5~,.kId&#34;F~ma9aZ&amp;amp;QnR0d.sBa_a0v0KR0]u/&#39;rYa=- $yrxdX,{^|[email protected]#@YC/_*
toolsasked 08 Oct &#39;10, 09:20
Onebusytech
1●3●3●4</description>
    </item>
    
    <item>
      <title>Can anyone explain why I can&amp;#x27;t capture any traffic on my Radius IP?</title>
      <link>/questions/462/can-anyone-explain-why-i-cant-capture-any-traffic-on-my-radius-ip/</link>
      <pubDate>Fri, 08 Oct 2010 10:32:00 +0000</pubDate>
      
      <guid>/questions/462/can-anyone-explain-why-i-cant-capture-any-traffic-on-my-radius-ip/</guid>
      <description>Can anyone explain why I can&amp;rsquo;t capture any traffic on my Radius IP?  0 I&#39;m trying to evauluate some wimax products with a Wimax Base Station and various client radios. I want to capture traffic over my Radius IP to see if EAP-Tls authentication is taking place. (which it is not currently). When I set wireshark to capture over the specific IP, I literally get nothing. Hopefully someone has some insight.</description>
    </item>
    
    <item>
      <title>Get full NFS path/filename for object</title>
      <link>/questions/467/get-full-nfs-pathfilename-for-object/</link>
      <pubDate>Sat, 09 Oct 2010 09:53:00 +0000</pubDate>
      
      <guid>/questions/467/get-full-nfs-pathfilename-for-object/</guid>
      <description>Get full NFS path/filename for object  0 When analyzing wireshark data, none of the NFS path/filenames are available even after selecting the option to show full path and file name. How can I see the full NFS path and file name that was accessed? Please advise.
Additional data. NFS v3, source data is on NetApp running Ontap 7.1.x; wireshark capturing NFS data on port 2049 from Linux SLES10 client (autofs).</description>
    </item>
    
    <item>
      <title>What is the best way to sanitize traces?</title>
      <link>/questions/469/what-is-the-best-way-to-sanitize-traces/</link>
      <pubDate>Sun, 10 Oct 2010 07:05:00 +0000</pubDate>
      
      <guid>/questions/469/what-is-the-best-way-to-sanitize-traces/</guid>
      <description>What is the best way to sanitize traces?  0 I can use the “Limit each packet to N bytes” capture option to make sure that application data is not captured, or editcap -s to remove already captured application data. But how do I change the IP addresses. I would like to maintain the relationships between IP addresses, that is addresses in the same subnet/network remain in the same subnet/network. I don&#39;t require that the addresses be changed to the standard private address space, just that they no longer reflect my addresses.</description>
    </item>
    
    <item>
      <title>MGCP signaling in the &amp;quot;Voip Calls&amp;quot; flow</title>
      <link>/questions/475/mgcp-signaling-in-the-voip-calls-flow/</link>
      <pubDate>Mon, 11 Oct 2010 03:25:00 +0000</pubDate>
      
      <guid>/questions/475/mgcp-signaling-in-the-voip-calls-flow/</guid>
      <description>MGCP signaling in the &amp;ldquo;Voip Calls&amp;rdquo; flow  0 In previous versions 1.2.x, I saw that the MGCP signaling was included in the flow generated from the &#34;VoIP Calls&#34; selection (after selecting the desired calls and clicking on &#34;Flow&#34;). Is there a setting/workaround to have both SIP and MGCP in the flows generated from &#34;VoIP Calls&#34;.
Regards, Antonios
flow mgcp voipasked 11 Oct &#39;10, 03:25
antpap
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark dissector for decoding proprietary traces</title>
      <link>/questions/477/wireshark-dissector-for-decoding-proprietary-traces/</link>
      <pubDate>Mon, 11 Oct 2010 13:35:00 +0000</pubDate>
      
      <guid>/questions/477/wireshark-dissector-for-decoding-proprietary-traces/</guid>
      <description>Wireshark dissector for decoding proprietary traces  0 I have proprietary trace points throughout my code that are captured to a file. I&#39;d like to build a Wireshark dissector to decode these traces. I worry that these traces are not wire packets. They contain an id, timestamp, size and then some additional bytes in a binary stream format. I currently have created a crude decoder for these traces but I&#39;d rather use Wireshark and some of its features.</description>
    </item>
    
    <item>
      <title>delete/edit display filter history</title>
      <link>/questions/479/deleteedit-display-filter-history/</link>
      <pubDate>Mon, 11 Oct 2010 19:37:00 +0000</pubDate>
      
      <guid>/questions/479/deleteedit-display-filter-history/</guid>
      <description>delete/edit display filter history  0 how can I clear the display filter history in the dropdown box? It&#39;s easy to delete saved filters but not apparent how to edit/delete the history.
filters historyasked 11 Oct &#39;10, 19:37
ziplock
6●2●3●3
accept rate: 0%
  
3 Answers:
  
2 There is no functionality within Wireshark to edit/delete the filters in the display filter history. However, the entries are saved in the file &#34;</description>
    </item>
    
    <item>
      <title>How the Protocol Hierarchy Statistics works?</title>
      <link>/questions/480/how-the-protocol-hierarchy-statistics-works/</link>
      <pubDate>Mon, 11 Oct 2010 20:30:00 +0000</pubDate>
      
      <guid>/questions/480/how-the-protocol-hierarchy-statistics-works/</guid>
      <description>How the Protocol Hierarchy Statistics works?  0 Dear all,
Please, anyone could explain how the Protocol Hierarchy Statistics works? Could the dissectors distinguish every single protocol (of course, included in the available list)? If there is any kind of protocol that happens but hidden within other, can wireshark detect? Does the Wireshark dissect based on ports or on the structure of the protocols?
Thanks for your attention. Emilio
phs hierarchy dissector protocol statisticsThis question is marked &#34;</description>
    </item>
    
    <item>
      <title>Checksum offload info from out-of-band data of a captured packet</title>
      <link>/questions/491/checksum-offload-info-from-out-of-band-data-of-a-captured-packet/</link>
      <pubDate>Tue, 12 Oct 2010 10:22:00 +0000</pubDate>
      
      <guid>/questions/491/checksum-offload-info-from-out-of-band-data-of-a-captured-packet/</guid>
      <description>Checksum offload info from out-of-band data of a captured packet  0 Hi There
Does Wireshark/WinPCAP capture and show the checksum offload info from the out-of-band data?
Thanks Arun
checksum offload oobasked 12 Oct &#39;10, 10:22
Arun
1●1●1●1
accept rate: 0%
Hi Arun - can you be a bit more specific regarding which out-of-band data you are interested in? If the out-of-band data is carried in a packet and it is passed up to Wireshark, then you should be able to see it.</description>
    </item>
    
    <item>
      <title>Wireshark unable to display captured trace file in correct format</title>
      <link>/questions/493/wireshark-unable-to-display-captured-trace-file-in-correct-format/</link>
      <pubDate>Tue, 12 Oct 2010 20:50:00 +0000</pubDate>
      
      <guid>/questions/493/wireshark-unable-to-display-captured-trace-file-in-correct-format/</guid>
      <description>Wireshark unable to display captured trace file in correct format  0 When my notebook PC is plugged into the office LAN network, running Wireshark can correctly display the trace file (such as those provided for Wireshark training purpose)showing protocol fields such as TCP. DNS, HTTP, etc. However, when I use the same notebook PC at home under the wireless LAN environment, Wireshark cannot display the same trace file as I have done in office.</description>
    </item>
    
    <item>
      <title>Capturing UDP packets from the same computer</title>
      <link>/questions/500/capturing-udp-packets-from-the-same-computer/</link>
      <pubDate>Wed, 13 Oct 2010 01:48:00 +0000</pubDate>
      
      <guid>/questions/500/capturing-udp-packets-from-the-same-computer/</guid>
      <description>Capturing UDP packets from the same computer  0 Hello, I&#39;m writing a program in C# and I&#39;m sending UDP messages to my own computer. I want Wireshark to capture those packets, but it doesn&#39;t capture them. Maybe it&#39;s because those packets are not transmitted at all through my network card? and if so how can I still capture them using Wireshark? Thank you in advance, Hod
udpasked 13 Oct &#39;10, 01:48</description>
    </item>
    
    <item>
      <title>Wireshark not detecting wireless card</title>
      <link>/questions/501/wireshark-not-detecting-wireless-card/</link>
      <pubDate>Wed, 13 Oct 2010 02:00:00 +0000</pubDate>
      
      <guid>/questions/501/wireshark-not-detecting-wireless-card/</guid>
      <description>Wireshark not detecting wireless card  0 Hi,
I have been trying to get my wireless card working with wireshark. I&#39;m using ubuntu, I&#39;ve used my card in monitor mode lots. Its a USB Ralink rt2870.
Any ideas on why it won&#39;t let me into the wireless options?
I&#39;ve tired putting it in monitor mode before starting wireshark and that doesnt help.
thanks, Chris
wireless ubuntuasked 13 Oct &#39;10, 02:00</description>
    </item>
    
    <item>
      <title>Auto Scroll Packet List button</title>
      <link>/questions/503/auto-scroll-packet-list-button/</link>
      <pubDate>Wed, 13 Oct 2010 08:21:00 +0000</pubDate>
      
      <guid>/questions/503/auto-scroll-packet-list-button/</guid>
      <description>Auto Scroll Packet List button  0 in 1.41.1, when I either Clear or Apply a display filter during a live capture, the Auto Scroll Packet List button toggles off automatically. Is there a way to prevent this?
troubleshootingasked 13 Oct &#39;10, 08:21
ziplock
6●2●3●3
accept rate: 0%
  
One Answer:
  
0This was a bug that has since been resolved. To correct this problem, I would recommend that you upgrade Wireshark to at least the latest stable release, currently 1.</description>
    </item>
    
    <item>
      <title>Wireshark 1.4.1 - how to debug MIB import?</title>
      <link>/questions/507/wireshark-141-how-to-debug-mib-import/</link>
      <pubDate>Thu, 14 Oct 2010 03:38:00 +0000</pubDate>
      
      <guid>/questions/507/wireshark-141-how-to-debug-mib-import/</guid>
      <description>Wireshark 1.4.1 - how to debug MIB import?  0 Using Wireshark 1.4.1 on Windows XP Pro SP3; trying to import a vendor MIB in order to decode content of some SNMP traps etc.
After importing the MIB and restarting Wireshark the following error box pops up:
&#34;Stopped processing module ARTEVEA-MIB due to error(s) to prevent potential crash in libsmi. Module&#39;s conformance level: 1. See details at: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560325&#34;
Reading the linked page (bug tracker) it appears that this is a safeguard that is invoked if there are missing references in the MIB being parsed.</description>
    </item>
    
    <item>
      <title>Wireshark x64 missing packets in capture</title>
      <link>/questions/510/wireshark-x64-missing-packets-in-capture/</link>
      <pubDate>Thu, 14 Oct 2010 13:01:00 +0000</pubDate>
      
      <guid>/questions/510/wireshark-x64-missing-packets-in-capture/</guid>
      <description>Wireshark x64 missing packets in capture  0 I have a laptop with Windows 7 x64 Ultimate. I run the latest Wireshark version 1.4.1. I am running a capture on a switch port that has LACP traffic, which Wireshark should decode as &#34;slow&#34;. All these packets are missing in my capture. If I boot into a Windows 7 x32 (laptop has a dual boot). I can run the same 32bit version of Wireshark &amp;amp; see this traffic in the capture.</description>
    </item>
    
    <item>
      <title>Bug fix for Bug 3303</title>
      <link>/questions/511/bug-fix-for-bug-3303/</link>
      <pubDate>Thu, 14 Oct 2010 15:08:00 +0000</pubDate>
      
      <guid>/questions/511/bug-fix-for-bug-3303/</guid>
      <description>Bug fix for Bug 3303  0 I&#39;m new to this list but I have a relatively simple question:
I was wondering when a patch would be available for &#34;Bug 3303 - Problem with fragmentation at the SSL record layer&#34;? Is it targeted at a particular release? If not, is there any beta code that I can test?
I am working on an application where I need to be able to decrypt the traffic from a browser to another server.</description>
    </item>
    
    <item>
      <title>Statistics / Compare gives error for unvalid filter (Filter &amp;quot;000000&amp;quot; - is invalid)</title>
      <link>/questions/513/statistics-compare-gives-error-for-unvalid-filter-filter-000000-is-invalid/</link>
      <pubDate>Fri, 15 Oct 2010 00:00:00 +0000</pubDate>
      
      <guid>/questions/513/statistics-compare-gives-error-for-unvalid-filter-filter-000000-is-invalid/</guid>
      <description>Statistics / Compare gives error for unvalid filter (Filter &amp;ldquo;000000&amp;rdquo; - is invalid)  0 Hello,
When trying to compare two capture-files (following this article http://www.wireshark.org/docs/wsug_html_chunked/ChStatCompareCaptureFiles.html) I get an error-message when trying to run the compare. It seems that the filter-value is pre-populated even though I haven&#39;t selected anything.
The error-message I get is: Filter &#34;000000&#34; is invalid - &#34;000000&#34; is neither a field nor a protocol name.
If I click OK and try to apply a filter, I get the same error again, but this time it might look like this: Filter &#34;</description>
    </item>
    
    <item>
      <title>Wireshark On VMware</title>
      <link>/questions/516/wireshark-on-vmware/</link>
      <pubDate>Fri, 15 Oct 2010 07:47:00 +0000</pubDate>
      
      <guid>/questions/516/wireshark-on-vmware/</guid>
      <description>Wireshark On VMware  0 We are building a multi server SIPX cluster and wish to be able to build a monitoring platform with six NICs. The optimal configuration would be to run six virtual machines with an instance of Wireshare running on each VM.
Has any one out there done this? Does Wireshark run on UNIX and if so what versions...CentOS? How much much RAM is required? Will it work with a QUAD core single CPU box or does it require multiple physical CPUs?</description>
    </item>
    
    <item>
      <title>Is there a way to show all packet captures for one site capture</title>
      <link>/questions/520/is-there-a-way-to-show-all-packet-captures-for-one-site-capture/</link>
      <pubDate>Sat, 16 Oct 2010 12:35:00 +0000</pubDate>
      
      <guid>/questions/520/is-there-a-way-to-show-all-packet-captures-for-one-site-capture/</guid>
      <description>Is there a way to show all packet captures for one site capture  0 I would like to know if it possible to zero it on a packet capture by finding the the first syn ack and then find all sites associated with this.
capture packet associateasked 16 Oct &#39;10, 12:35
eparl
1●1●1●1
accept rate: 0%
Can you give a little more explanation? I&#39;m assuming you have a large packet capture and you&#39;re looking to find a session initialization (the SYN ACK).</description>
    </item>
    
    <item>
      <title>Wireshark Win32 portable installer still needs installation</title>
      <link>/questions/522/wireshark-win32-portable-installer-still-needs-installation/</link>
      <pubDate>Sun, 17 Oct 2010 23:05:00 +0000</pubDate>
      
      <guid>/questions/522/wireshark-win32-portable-installer-still-needs-installation/</guid>
      <description>Wireshark Win32 portable installer still needs installation  0 Current wireshark win32 portable installer still need installation, does, wireshark support any portable install without any effort to write windows register, and don&#39;t need copy any files into c:windowssystem32 ?
portable installasked 17 Oct &#39;10, 23:05
seachange
1●1●1●1
accept rate: 0%
 edited 19 Oct &#39;10, 11:39 
Gerald Combs ♦♦
3.3k●9●22●58
  
One Answer:
  
0Wireshark depends on WinPcap to capture packets on Windows.</description>
    </item>
    
    <item>
      <title>the peak of network flow rate that wireshark can deal with</title>
      <link>/questions/523/the-peak-of-network-flow-rate-that-wireshark-can-deal-with/</link>
      <pubDate>Mon, 18 Oct 2010 01:37:00 +0000</pubDate>
      
      <guid>/questions/523/the-peak-of-network-flow-rate-that-wireshark-can-deal-with/</guid>
      <description>the peak of network flow rate that wireshark can deal with  0 1I am wondering what is the peak of network flow rate that wireshark can deal with. Is it 1Gbps or 10Gbps? I need a answer. Thank you.
capture-limits rate flowasked 18 Oct &#39;10, 01:37
jerrylin
1●1●2●2
accept rate: 0%
 edited 07 Feb &#39;16, 05:37 
Christian_R
1.8k●2●6●25
  
2 Answers:
  
4I think it&#39;s mostly a hardware issue, and specifically how fast the data can be transported and written from the NIC PHY to the storage system.</description>
    </item>
    
    <item>
      <title>I have wireshark 1.4.0 and am unable to locate the EPC gloabl llrp protocol dissector.</title>
      <link>/questions/524/i-have-wireshark-140-and-am-unable-to-locate-the-epc-gloabl-llrp-protocol-dissector/</link>
      <pubDate>Mon, 18 Oct 2010 05:40:00 +0000</pubDate>
      
      <guid>/questions/524/i-have-wireshark-140-and-am-unable-to-locate-the-epc-gloabl-llrp-protocol-dissector/</guid>
      <description>I have wireshark 1.4.0 and am unable to locate the EPC gloabl llrp protocol dissector.  0 I see an example on the website of using the dissector but cannot figure our how to enable it. Any help would be greatly appreciated. What i see are the tcp conversation with no decoding as the dissectoru would provide. Thanks.
llrp global epc dissectorasked 18 Oct &#39;10, 05:40
jwhoffman
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>RTP Analysis and Assessment</title>
      <link>/questions/527/rtp-analysis-and-assessment/</link>
      <pubDate>Mon, 18 Oct 2010 13:04:00 +0000</pubDate>
      
      <guid>/questions/527/rtp-analysis-and-assessment/</guid>
      <description>RTP Analysis and Assessment  0 Hi I have captured RTP stream and now trying to play it in the inbuilt wireshark player. It is reporting &#34;Drop by Jitter Buffer&#34;, &#34;Out of Sequence&#34; and Wrong Time Stamp. But in the player how do I know which one is showan as what. I have Red, Yellow color lines in the player and see Choppy voice but not able to interpret/separate these issues/packets.</description>
    </item>
    
    <item>
      <title>remote capture</title>
      <link>/questions/536/remote-capture/</link>
      <pubDate>Tue, 19 Oct 2010 10:27:00 +0000</pubDate>
      
      <guid>/questions/536/remote-capture/</guid>
      <description>remote capture  0 I currently have wireshark installed on my windowsXP box; I want to do a capture between a remote laptop and a remote file server on the same subnet. How can I set that up? thanks!
remoteasked 19 Oct &#39;10, 10:27
will_sj
1●1●1●2
accept rate: 0%
 edited 19 Oct &#39;10, 10:28 
  
One Answer:
  
2I think what you want to do is capture the traffic between the laptop and the file server with the help of your XP box, which would be a pretty standard setup.</description>
    </item>
    
    <item>
      <title>UDP Port 52217</title>
      <link>/questions/537/udp-port-52217/</link>
      <pubDate>Tue, 19 Oct 2010 10:49:00 +0000</pubDate>
      
      <guid>/questions/537/udp-port-52217/</guid>
      <description>UDP Port 52217  0 When looking at my firewall logs, I see attempts to get to my public IP address with UDP packets and destination port 52217. My firewall drops them as it should. But I ran a trace on that segment, and then noticed that a private IP address was hitting my public IP address with that same destination port of 52217 at 1205 second intervals. The MAC address associated with that IP address was a Cisco device and it was very probably the default gateway of my ISP.</description>
    </item>
    
    <item>
      <title>TCP sender behaviour</title>
      <link>/questions/551/tcp-sender-behaviour/</link>
      <pubDate>Wed, 20 Oct 2010 03:04:00 +0000</pubDate>
      
      <guid>/questions/551/tcp-sender-behaviour/</guid>
      <description>TCP sender behaviour  1 1/PUSH
anybody an idea?
Hi everybody,
during my recent analysis job, analyzing a TCP sender&#39;s burst behaviour was a challenging task.
Short form of my question: Does anybody know if TCPs congestion management algorithms concerning cwnd, ssthresh and the congestion avoidance / fast recovery techniques apply to every single TCP connection regardless of its burstiness ?
Example leading to my question: Following the TCP related RFCs, congestion management / avoidance mechanisms in TCP and the extended definitions like e.</description>
    </item>
    
    <item>
      <title>capture filter problem when tshark is started within a bash-script</title>
      <link>/questions/552/capture-filter-problem-when-tshark-is-started-within-a-bash-script/</link>
      <pubDate>Wed, 20 Oct 2010 03:21:00 +0000</pubDate>
      
      <guid>/questions/552/capture-filter-problem-when-tshark-is-started-within-a-bash-script/</guid>
      <description>capture filter problem when tshark is started within a bash-script  0 Hi,
I have a little problem when starting tshark out of a bash-script. Here a short part from the script:
BIN=&amp;quot;/usr/bin/tshark&amp;quot; OPTS=&amp;quot; -f \&amp;quot;port 5026 and (host 10.65.27.138 or host 10.65.27.137 or host 10.65.27.139)\&amp;quot; -a duration:10 -i eth1 -n -q -w /data/traces/files/test2.pcap&amp;quot; echo $BIN $OPTS $BIN $OPTSNow I&#39;m receiving following output:
/usr/bin/tshark -f &amp;quot;port 5026 and (host 10.65.27.138 or host 10.</description>
    </item>
    
    <item>
      <title>Working with file sets</title>
      <link>/questions/557/working-with-file-sets/</link>
      <pubDate>Wed, 20 Oct 2010 07:16:00 +0000</pubDate>
      
      <guid>/questions/557/working-with-file-sets/</guid>
      <description>Working with file sets  0 I am performing some problem analysis this morning at a client site. I am troubleshooting a problem on their SAN network. There is a large volume of data where I am capturing from. It is so much that it shuts down wireshark after a minute and a half of capture ( I am using a very robust laptop with an i7 6 G RAM and Tera hdd).</description>
    </item>
    
    <item>
      <title>Skinny protocol problem</title>
      <link>/questions/558/skinny-protocol-problem/</link>
      <pubDate>Wed, 20 Oct 2010 07:19:00 +0000</pubDate>
      
      <guid>/questions/558/skinny-protocol-problem/</guid>
      <description>Skinny protocol problem  0 Wireshark 1.4.1 cannot decode Skinny message . I believe it is last version on Skinny protocol.
It is a full call and believe on of the message which wireshark cannot regognize
0x000014a - is CallInfoMessage message .
Is it any workaround to read all Skinny messages or is any fix for this will be available anytime soon ?
Thank you,
skinny sccpasked 20 Oct &#39;10, 07:19</description>
    </item>
    
    <item>
      <title>Lots of retransmissions and out of order frames</title>
      <link>/questions/562/lots-of-retransmissions-and-out-of-order-frames/</link>
      <pubDate>Wed, 20 Oct 2010 11:21:00 +0000</pubDate>
      
      <guid>/questions/562/lots-of-retransmissions-and-out-of-order-frames/</guid>
      <description>Lots of retransmissions and out of order frames  0 I have taken a sniffer trace today of an entry point to a NetApp SAN. Within the trace, we see an extreme amount of Out of Order frames as well as TCP retransmissions.
Since there are multiple devices talking to the SAN, how should I approach this to determine why the retrans and OOO frames are occuring?
Thank you KMNRuser</description>
    </item>
    
    <item>
      <title>Closing file please wait - hang</title>
      <link>/questions/564/closing-file-please-wait-hang/</link>
      <pubDate>Wed, 20 Oct 2010 12:09:00 +0000</pubDate>
      
      <guid>/questions/564/closing-file-please-wait-hang/</guid>
      <description>Closing file please wait - hang  1 I am running 1.4.1 on Win 7 x64 laptop with 4G ram.
Packet capture as follows:
Limit each packet to 150 bytes Use multiple files Ring buffer - 20 files
Buffer size - 300 megabytes Update list of packets in real time - unchecked Automatic scrolling in live capture - unchecked
Enable MAC name resolution - checked Enable network name resolution - unchecked Enable transport name resolution - checked</description>
    </item>
    
    <item>
      <title>Crashing issue when running Lua dissector after upgrading from wireshark 1.0.0</title>
      <link>/questions/570/crashing-issue-when-running-lua-dissector-after-upgrading-from-wireshark-100/</link>
      <pubDate>Wed, 20 Oct 2010 16:11:00 +0000</pubDate>
      
      <guid>/questions/570/crashing-issue-when-running-lua-dissector-after-upgrading-from-wireshark-100/</guid>
      <description>Crashing issue when running Lua dissector after upgrading from wireshark 1.0.0  0 The Lua dissector below causes a segmentation fault in Wireshark 1.2 and Wireshark 1.4.1. This works fine in Wireshark 1.0.0.
It appears that the call to payload_dissector_table:try() is causing the problem, but I can&#39;t figure out why. If I remove that call, the dissector runs fine. If I change the dissector table so that it doesn&#39;t match any packets, the dissector runs fine.</description>
    </item>
    
    <item>
      <title>is there any way for a display filter using previous matched packet field value as comparison value?</title>
      <link>/questions/572/is-there-any-way-for-a-display-filter-using-previous-matched-packet-field-value-as-comparison-value/</link>
      <pubDate>Wed, 20 Oct 2010 21:15:00 +0000</pubDate>
      
      <guid>/questions/572/is-there-any-way-for-a-display-filter-using-previous-matched-packet-field-value-as-comparison-value/</guid>
      <description>is there any way for a display filter using previous matched packet field value as comparison value?  0 Hi, Experts:
for smpp protocol, I just want wireshark to display smpp submit request only with specific Dest term id, and the related server response. the related server response has smpp sequence id related.
so how I can realize this display filter?
Regards Zenith
display-filterasked 20 Oct &#39;10, 21:15
zenith
1●1●1●2</description>
    </item>
    
    <item>
      <title>Need help interpreting DNS packets</title>
      <link>/questions/577/need-help-interpreting-dns-packets/</link>
      <pubDate>Thu, 21 Oct 2010 12:03:00 +0000</pubDate>
      
      <guid>/questions/577/need-help-interpreting-dns-packets/</guid>
      <description>Need help interpreting DNS packets  0 I&#39;m in the process of troubleshooting an issue which is causing some slowness in establishing connections between our Linux servers. I&#39;ve suspected DNS, but both forward and reverse lookups using dig are extremely fast.
As a test I&#39;ve been attempting to test a web connection between two Linux servers. At a prompt I attempt to telnet to port 80 on the other box. After about a 10 second delay a connection is established, entering GET / returns HTML very quickly.</description>
    </item>
    
    <item>
      <title>Mac OS can&amp;#x27;t detect any interface</title>
      <link>/questions/578/mac-os-cant-detect-any-interface/</link>
      <pubDate>Thu, 21 Oct 2010 13:26:00 +0000</pubDate>
      
      <guid>/questions/578/mac-os-cant-detect-any-interface/</guid>
      <description>Mac OS can&amp;rsquo;t detect any interface  2 1I have just installed wireshark 1.4.1 in my Mac 10.6.4 but i get the following error (-) &#34;There are no interfaces on which a capture can be done.&#34;
What can i do?
macinterfacenotfoundasked 21 Oct &#39;10, 13:26
the_sniffer
31●1●2●3
accept rate: 0%
 edited 07 May &#39;11, 07:18 
cmaynard ♦♦
9.4k●10●38●142
When upgrading from 1.4.3 to 1.6.2 in 10.5.8 I had the same problem with dev permissions.</description>
    </item>
    
    <item>
      <title>statistics for GSM</title>
      <link>/questions/581/statistics-for-gsm/</link>
      <pubDate>Fri, 22 Oct 2010 03:43:00 +0000</pubDate>
      
      <guid>/questions/581/statistics-for-gsm/</guid>
      <description>statistics for GSM  0 Hi,
Is there a way to use statistics tool for GSM protocols ?
statistics gsmasked 22 Oct &#39;10, 03:43
nuri
1●1●1●1
accept rate: 0%
  
One Answer:
  
0have a look at the menu: Telephony | GSM
answered 22 Oct &#39;10, 08:13
Jaap ♦
11.7k●16●101
accept rate: 14%
Thanks for reply however tools under Telephony tab is not sufficient enough. Do you know more detailed statistic analyzing ways for GSM protocols?</description>
    </item>
    
    <item>
      <title>Wireshark with .NET WCF?</title>
      <link>/questions/585/wireshark-with-net-wcf/</link>
      <pubDate>Fri, 22 Oct 2010 08:10:00 +0000</pubDate>
      
      <guid>/questions/585/wireshark-with-net-wcf/</guid>
      <description>Wireshark with .NET WCF?  0 Hi,
I have a .NET WCF service running on my computer (in IIS7) that communicates over secured (certificate) TCP with my client (also on my computer). Now I need to clarify if my data really is secured (encrypted). When using the Microsoft tools like Service Trace Viewer it seems like it is not.
I have installed Wireshark and have selected the correct interface (my network card).</description>
    </item>
    
    <item>
      <title>Where are theMIB Files</title>
      <link>/questions/591/where-are-themib-files/</link>
      <pubDate>Fri, 22 Oct 2010 15:26:00 +0000</pubDate>
      
      <guid>/questions/591/where-are-themib-files/</guid>
      <description>Where are theMIB Files  0 The Wireshark book talks about MIB files in the installation Directory: Wiresharksnmpmibs However, I do not see this directory in my Windows Wireshark 4.1 installation. If I want to add more MIBs should I create this directory? Where are the MIB&#39;s that are supposed to be in the installation.
mib snmpasked 22 Oct &#39;10, 15:26
vmjr
16●2●2●4
accept rate: 100%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>UDP Flooding</title>
      <link>/questions/601/udp-flooding/</link>
      <pubDate>Sat, 23 Oct 2010 08:46:00 +0000</pubDate>
      
      <guid>/questions/601/udp-flooding/</guid>
      <description>UDP Flooding  0 Hi, Just want to ask it is normal UDP traffic like this?
my network became very slow after this happen in my network, the strange is why so many traffic with IP 172.16.5.1 but using many different MAC ADDRESS?
since I&#39;m new with Wireshark i dunno it is serious problem or not but my network getting very slow.
if broadcast address is 255.255.255.255 would it be broadcast in network 172.</description>
    </item>
    
    <item>
      <title>capture issues</title>
      <link>/questions/611/capture-issues/</link>
      <pubDate>Sun, 24 Oct 2010 20:45:00 +0000</pubDate>
      
      <guid>/questions/611/capture-issues/</guid>
      <description>capture issues  0 I had been running wireshark successfully for some time. In late august, a microsoft update to my XP operating system locked my computer up and I had no alternative but to start from scratch and reload my operating system and all the programs that I was using. Since then, I cannot get Wireshark to work. My wireless works properly but when I try a wireshark packet capture I get the following message:</description>
    </item>
    
    <item>
      <title>How do you calculate Jitter and Delay With RTSP</title>
      <link>/questions/612/how-do-you-calculate-jitter-and-delay-with-rtsp/</link>
      <pubDate>Sun, 24 Oct 2010 21:56:00 +0000</pubDate>
      
      <guid>/questions/612/how-do-you-calculate-jitter-and-delay-with-rtsp/</guid>
      <description>How do you calculate Jitter and Delay With RTSP  0 I captured RTSP but I can&#39;t calculate jitter and delay
please help me
rtspasked 24 Oct &#39;10, 21:56
kwonmickeydere
1●1●1●1
accept rate: 0%
  
One Answer:
  
1You want to capture the actual RTP streams, not just the RTSP control packets. Once you&#39;ve done that, you can use Statistics-&amp;gt;RTP to show the streams and/or pick streams for further analysis.</description>
    </item>
    
    <item>
      <title>How to see from how long capture in progress, while capturing?</title>
      <link>/questions/614/how-to-see-from-how-long-capture-in-progress-while-capturing/</link>
      <pubDate>Mon, 25 Oct 2010 04:48:00 +0000</pubDate>
      
      <guid>/questions/614/how-to-see-from-how-long-capture-in-progress-while-capturing/</guid>
      <description>How to see from how long capture in progress, while capturing?  0 I dont see any field, where I can see from how long wireshark capture is going on, with out stopping the capture.
Any thoughts?
capture timeasked 25 Oct &#39;10, 04:48
Ramprasad
20●10●11●15
accept rate: 0%
  
3 Answers:
  
1Go to Statistics -&amp;gt; Summary
Look for:
Time
First packet:
Last packet:
Elapsed:
answered 25 Oct &#39;10, 05:48</description>
    </item>
    
    <item>
      <title>Preamble frame capture</title>
      <link>/questions/620/preamble-frame-capture/</link>
      <pubDate>Mon, 25 Oct 2010 07:04:00 +0000</pubDate>
      
      <guid>/questions/620/preamble-frame-capture/</guid>
      <description>Preamble frame capture  0 Is it possible to configure wireshark to capture also the preamble and the SFD bytes of a ethernet frame? If affirmative, how to do this capture?
Best regards
sfd preambleasked 25 Oct &#39;10, 07:04
kzxc
1●1●1●1
accept rate: 0%
Apparantly not.
See the Wireshark Wiki: Ethernet -&amp;gt; Packet format.
(25 Oct &#39;10, 07:54) jokeNope - but I wonder... why do you need to capture the preamble/SFD?</description>
    </item>
    
    <item>
      <title>Capture between iPhone and Linksys wireless router??</title>
      <link>/questions/622/capture-between-iphone-and-linksys-wireless-router/</link>
      <pubDate>Mon, 25 Oct 2010 08:30:00 +0000</pubDate>
      
      <guid>/questions/622/capture-between-iphone-and-linksys-wireless-router/</guid>
      <description>Capture between iPhone and Linksys wireless router??  0 I want to monitor wireless traffic that occurs between an iphone and my home linksys wireless router. The only computer I have at home is my windows laptop, so I would be loading wireshark on that?
Can I really &#34;see&#34; what the person is looking at on the iphone? I have watched the videos on the website but I am a bit confused.</description>
    </item>
    
    <item>
      <title>Displaying UTF-8 in wireshark packet info tree</title>
      <link>/questions/625/displaying-utf-8-in-wireshark-packet-info-tree/</link>
      <pubDate>Mon, 25 Oct 2010 11:02:00 +0000</pubDate>
      
      <guid>/questions/625/displaying-utf-8-in-wireshark-packet-info-tree/</guid>
      <description>Displaying UTF-8 in wireshark packet info tree  2 1Making a plugin for a protocol that sometimes contains UTF-8 and would like to display the Unicode characters in the packet info.
Is it possible?
unicodeasked 25 Oct &#39;10, 11:02
DRJTower
36●1●2●5
accept rate: 0%
  
One Answer:
  
4 Currently, no; fields of type FT_STRING, FT_STRINGZ, etc. are only displayed as if they were ASCII, with all octets with the 8th bit set displayed as escape sequences.</description>
    </item>
    
    <item>
      <title>Using Capture File(s)</title>
      <link>/questions/626/using-capture-files/</link>
      <pubDate>Mon, 25 Oct 2010 12:56:00 +0000</pubDate>
      
      <guid>/questions/626/using-capture-files/</guid>
      <description>Using Capture File(s)  0 When the &#34;use multiple files&#34; box is check how do you tell WireShark the different names of the files you want to save?
multiple-files capture-fileasked 25 Oct &#39;10, 12:56
AMCCSupport
1●1●1●2
accept rate: 0%
  
One Answer:
  
1When you select Use multiple files, you have to specify a file name, otherwise you get an error message.
You can add a file name just above &#34;</description>
    </item>
    
    <item>
      <title>Statistics Options</title>
      <link>/questions/627/statistics-options/</link>
      <pubDate>Mon, 25 Oct 2010 13:06:00 +0000</pubDate>
      
      <guid>/questions/627/statistics-options/</guid>
      <description>Statistics Options  0 I downloaded the free version of Wireshark, but when I select Statistics, then there is no option for ports, among other things. How do I get these options? Are they free?
More specifically, I am running Wireshark version 1.4.0 running in windows XP and I got it from the wireshark webpage. I cannot see the &#34;Port Type&#34; option in the statistics pull down menu that I saw as an option in one of the educational videos by Laura Chappell.</description>
    </item>
    
    <item>
      <title>Wireshark doesn&amp;#x27;t detect my mobile phone modem</title>
      <link>/questions/628/wireshark-doesnt-detect-my-mobile-phone-modem/</link>
      <pubDate>Mon, 25 Oct 2010 13:10:00 +0000</pubDate>
      
      <guid>/questions/628/wireshark-doesnt-detect-my-mobile-phone-modem/</guid>
      <description>Wireshark doesn&amp;rsquo;t detect my mobile phone modem  0 Hi! I&#39;ve downloaded the latest version of WireShark but I have a problem. I&#39;m using my phone (Nokia N85) as modem for my pc and WireShark doesen&#39;t detect it as a modem or anything. Can you help me with a solution or some settings? I&#39;m using Windows 7. Thank you!
nokia usb modemasked 25 Oct &#39;10, 13:10
last1devil
1●1●1●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Zooming on capture file</title>
      <link>/questions/630/zooming-on-capture-file/</link>
      <pubDate>Mon, 25 Oct 2010 13:50:00 +0000</pubDate>
      
      <guid>/questions/630/zooming-on-capture-file/</guid>
      <description>Zooming on capture file  0 Hi all Lets say I have a large capture file from my network and I would like to zoom on a specific period of time on the capture. How can I do it with wireshark, it seams that the IO Graphs is very basic. If it is not possible, can someone advice for a tool which can do it? Thanks
zoomingasked 25 Oct &#39;10, 13:50</description>
    </item>
    
    <item>
      <title>Excessive &amp;quot;TCP Out-of-Order&amp;quot; Messages</title>
      <link>/questions/632/excessive-tcp-out-of-order-messages/</link>
      <pubDate>Mon, 25 Oct 2010 14:13:00 +0000</pubDate>
      
      <guid>/questions/632/excessive-tcp-out-of-order-messages/</guid>
      <description>Excessive &amp;ldquo;TCP Out-of-Order&amp;rdquo; Messages  0 PROBLEM DEFINITION:
Conversations between Server1 and Server2 are fraught with &#34;TCP Out-of-Order&#34; messages. Server1 is in VLAN X while Server 2 is in VLAN Y. I run Wireshark from a laptop connected to a switchport upon which SPAN is enabled.
PRLBLEM ENVIRNOMENT:
All three devices (Server1, Server2, and WireShark laptop) are connected to a Cisco 6509 switch.Communications between Server1 and Server2 traverse a firewall services module (FWSM) on the Cisco 6509.</description>
    </item>
    
    <item>
      <title>Acc. to Wireshark, 99.9% of my outgoing packets have a bad checksum...</title>
      <link>/questions/634/acc-to-wireshark-999-of-my-outgoing-packets-have-a-bad-checksum/</link>
      <pubDate>Mon, 25 Oct 2010 16:35:00 +0000</pubDate>
      
      <guid>/questions/634/acc-to-wireshark-999-of-my-outgoing-packets-have-a-bad-checksum/</guid>
      <description>Acc. to Wireshark, 99.9% of my outgoing packets have a bad checksum&amp;hellip;  2 1Pretty much stated above. When applying the filter ip.src == &amp;lt;my IP&amp;gt;, almost all of the packets are color-coded &#34;bad checksum&#34;. It claims all of the packets&#39; checksums are 0x0000. ATM, I have ~2500 packets in the filter, and probably less than 10 of them aren&#39;t highlighted as having a bad checksum. Is this a bug in Wireshark, or is something seriously wrong with my internet connection?</description>
    </item>
    
    <item>
      <title>Decoding TLS Traffic</title>
      <link>/questions/637/decoding-tls-traffic/</link>
      <pubDate>Mon, 25 Oct 2010 17:39:00 +0000</pubDate>
      
      <guid>/questions/637/decoding-tls-traffic/</guid>
      <description>Decoding TLS Traffic  0 Hey guys, I just wanted to know whether it&#39;s possible to decode TLS_PSK_AES_128_CBC_SHA, having the pre-shared keys.
tls_aesasked 25 Oct &#39;10, 17:39
TylerDurden1983
1●1●1●1
accept rate: 0%
Did you check http://wiki.wireshark.org/SSL? Good resource page for TLS decryption.
(26 Oct &#39;10, 09:18) lchappell ♦  
One Answer:
  
0Given the right keys, the instructions in http://wiki.wireshark.org/SSL should point you in the right direction. Be sure that you have all keys in the proper format; I ran into problems with a system that wouldn&#39;t directly export keys to a PEM file, and I had to manually take it through a few steps with openssl (the use of which is discussed on the wiki page) to massage the keys into a PEM file before I could proceed.</description>
    </item>
    
    <item>
      <title>Protocols supported by Wireshark</title>
      <link>/questions/650/protocols-supported-by-wireshark/</link>
      <pubDate>Tue, 26 Oct 2010 02:08:00 +0000</pubDate>
      
      <guid>/questions/650/protocols-supported-by-wireshark/</guid>
      <description>Protocols supported by Wireshark  0 What are the protocols supported by Wireshark ? Is Locator Id Seperation Protocol supported by Wireshark ?? If No, then why ??
supported protocols wiresharkasked 26 Oct &#39;10, 02:08
isha
1●1●1●1
accept rate: 0%
 edited 10 Nov &#39;10, 07:12 
Jaap ♦
11.7k●16●101
  
3 Answers:
  
1In Wireshark, select Help &amp;gt; Supported Protocols. Note the indication that this might be slow to load.</description>
    </item>
    
    <item>
      <title>Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible</title>
      <link>/questions/652/connection-to-microsoft-exchange-has-been-lost-outlook-will-restore-the-connection-when-possible/</link>
      <pubDate>Tue, 26 Oct 2010 07:00:00 +0000</pubDate>
      
      <guid>/questions/652/connection-to-microsoft-exchange-has-been-lost-outlook-will-restore-the-connection-when-possible/</guid>
      <description>Connection to Microsoft Exchange has been lost. Outlook will restore the connection when possible  0 If I had any hair left, I would be pulling it out right now. I can’t seem to figure out why my Outlook 2007 keeps disconnecting from Exchange 2007 running on Windows Server 2008 every 10 seconds.
I didn&#39;t have any connection problems until I injected 700MB pst file in to a users mailbox (cached mode)</description>
    </item>
    
    <item>
      <title>CAMEL Operation Code</title>
      <link>/questions/653/camel-operation-code/</link>
      <pubDate>Tue, 26 Oct 2010 07:11:00 +0000</pubDate>
      
      <guid>/questions/653/camel-operation-code/</guid>
      <description>CAMEL Operation Code  0 I&#39;m sending a CAMEL Invoke ContinueWithArgument message with an opCode of 56 but the wireshark trace shows &#39;invoke Unknown CAMEL (56)&#39;. What is the correct opcode for this message?
tag opcode continuewithargument camelasked 26 Oct &#39;10, 07:11
dbartlett2010
1●2●2●3
accept rate: 0%
  
One Answer:
  
0define opcode_continueWithArgument 88answered 26 Oct &#39;10, 11:26
Anders ♦
4.6k●9●52
accept rate: 17%
     </description>
    </item>
    
    <item>
      <title>Download from mac on wireless decreases until it stops.</title>
      <link>/questions/654/download-from-mac-on-wireless-decreases-until-it-stops/</link>
      <pubDate>Tue, 26 Oct 2010 07:42:00 +0000</pubDate>
      
      <guid>/questions/654/download-from-mac-on-wireless-decreases-until-it-stops/</guid>
      <description>Download from mac on wireless decreases until it stops.  0 Hi all, just trying to get up to speed on Wireshark, I want to see what&#39;s going on and why it ultimately fails.
The issue briefly mentioned is, I have a PC system with broadband being supplied by Virgin and a Home 120 modem attached to a Netgear WGT624 router, the PC functions fine and networking/internet is pretty much as it should be.</description>
    </item>
    
    <item>
      <title>Does Wireshark Work on PLC Network?</title>
      <link>/questions/672/does-wireshark-work-on-plc-network/</link>
      <pubDate>Tue, 26 Oct 2010 10:24:00 +0000</pubDate>
      
      <guid>/questions/672/does-wireshark-work-on-plc-network/</guid>
      <description>Does Wireshark Work on PLC Network?  0 Hi, I am new to PLCs. Actually we have a network of PLCs and we wanted to analyze the traffic on the network which is on Thicknet. We have no vendor support and we dont know the protocol even. Some special nic cards having AUI port were came with PLC. These nics are ISA-slot based cards. These nics are installed on the PC and a program written in C language is run to capture the data.</description>
    </item>
    
    <item>
      <title>Wireshark command line to extract field for selected packets and output in file</title>
      <link>/questions/687/wireshark-command-line-to-extract-field-for-selected-packets-and-output-in-file/</link>
      <pubDate>Tue, 26 Oct 2010 16:29:00 +0000</pubDate>
      
      <guid>/questions/687/wireshark-command-line-to-extract-field-for-selected-packets-and-output-in-file/</guid>
      <description>Wireshark command line to extract field for selected packets and output in file  1 How can I run wireshark from the command line to open a file, and output a file containing only the udp.length of every DNS packet?
udp extract dnsasked 26 Oct &#39;10, 16:29
skypemesm
46●6●6●9
accept rate: 0%
  
One Answer:
  
1 You might want to take a look at rawshark or at tshark&#39;s &#34;</description>
    </item>
    
    <item>
      <title>promiscuous mode</title>
      <link>/questions/690/promiscuous-mode/</link>
      <pubDate>Tue, 26 Oct 2010 18:26:00 +0000</pubDate>
      
      <guid>/questions/690/promiscuous-mode/</guid>
      <description>promiscuous mode  0 When I start wireshark I go to capture on the tool bar, then interfaces. Under descriptions is Broadcom NetXtreme Gigabit Ethernet Driver followed by the MAC address. I click on Options and make sure promiscuous mode is checked and a dialog box opens up wi this in it. Please check that &#34;DeviceNPF_{4A65B691-9F55-4127-9C92-727DB3ACB245}&#34; is the proper interface. If I go back and uncheck promiscuous mode I can then captur packets on the wire.</description>
    </item>
    
    <item>
      <title>RTP traces</title>
      <link>/questions/691/rtp-traces/</link>
      <pubDate>Tue, 26 Oct 2010 18:36:00 +0000</pubDate>
      
      <guid>/questions/691/rtp-traces/</guid>
      <description>RTP traces  0 Where can I download a lot of RTP traces (in addition to the ones in example wireshark traces)? Any suggestions are welcome.
downloads rtp traceasked 26 Oct &#39;10, 18:36
skypemesm
46●6●6●9
accept rate: 0%
  
One Answer:
  
2 We have loads of traces including some VoIP traces over at www.wiresharkbook.com in the downloads section - you&#39;ll be looking for trace files starting with &#34;</description>
    </item>
    
    <item>
      <title>display filter to show UDP packets which are not recognized UDP protocols like DNS, RTP etc.</title>
      <link>/questions/695/display-filter-to-show-udp-packets-which-are-not-recognized-udp-protocols-like-dns-rtp-etc/</link>
      <pubDate>Tue, 26 Oct 2010 20:46:00 +0000</pubDate>
      
      <guid>/questions/695/display-filter-to-show-udp-packets-which-are-not-recognized-udp-protocols-like-dns-rtp-etc/</guid>
      <description>display filter to show UDP packets which are not recognized UDP protocols like DNS, RTP etc.  0 How can I specify a display filter such that I get all UDP packets which are NOT recognized as proper UDP application level protocols like DNS, RTP etc.
udp display-filterasked 26 Oct &#39;10, 20:46
skypemesm
46●6●6●9
accept rate: 0%
  
One Answer:
  
3 Try &#34;udp and data&#34; - if no dissector handles the UDP payload, then it will be handed to the &#34;</description>
    </item>
    
    <item>
      <title>www.Cloudshark.org</title>
      <link>/questions/698/wwwcloudsharkorg/</link>
      <pubDate>Tue, 26 Oct 2010 23:54:00 +0000</pubDate>
      
      <guid>/questions/698/wwwcloudsharkorg/</guid>
      <description>www.Cloudshark.org  1 I just stumbled onto this site tonight. You can look at .pcap files in a web browser. I thought it was pretty cool in a pinch.
cloudsharkasked 26 Oct &#39;10, 23:54
Owen
21●3●3●6
accept rate: 0%
Unable to load Capture: The file is too large to import. Please limit files to 512,000 bytes
(27 Oct &#39;10, 14:07) net_techJust to address the 512K limitation ... We recently rolled out a CloudShark update that increases the uploaded capture file size to 5 Megabytes.</description>
    </item>
    
    <item>
      <title>Display all streams with a matching URI</title>
      <link>/questions/701/display-all-streams-with-a-matching-uri/</link>
      <pubDate>Wed, 27 Oct 2010 01:47:00 +0000</pubDate>
      
      <guid>/questions/701/display-all-streams-with-a-matching-uri/</guid>
      <description>Display all streams with a matching URI  0 Hi,
I am trying to find a way to display all HTTP requests AND the relevant responses that match a specific URI, say /images/*, from a capture file.
I appreciate that I can match the request packet with http.request.uri, but is it possible to also select the packets related to the responses?
Regards
request http response uriasked 27 Oct &#39;10, 01:47</description>
    </item>
    
    <item>
      <title>SSL and TLS &amp;quot;Ignored Unknown Record&amp;quot;</title>
      <link>/questions/703/ssl-and-tls-ignored-unknown-record/</link>
      <pubDate>Wed, 27 Oct 2010 06:51:00 +0000</pubDate>
      
      <guid>/questions/703/ssl-and-tls-ignored-unknown-record/</guid>
      <description>SSL and TLS &amp;ldquo;Ignored Unknown Record&amp;rdquo;  0 I have been actively pursuing an issue that seems to have little documentation of reference material on, e.g. Google and TCP/SSL experts. I have been trying to identify why when using SSLv3 and TLSv1.0 that in the Wireshark captures I find excessive &#34;Ignored Unknown Record&#34; and [Unreassembled Packet] responses in the capture decodes. When using SSLv2 is see nothing to that effect and the full communications between the web client and web server are clean.</description>
    </item>
    
    <item>
      <title>Display complete HTTP header</title>
      <link>/questions/706/display-complete-http-header/</link>
      <pubDate>Wed, 27 Oct 2010 08:07:00 +0000</pubDate>
      
      <guid>/questions/706/display-complete-http-header/</guid>
      <description>Display complete HTTP header  1 Wireshark displays [truncated] preceding the HTTP Cookie header. How can I make it capture and display the entire Cookie header?
cookie truncated http headerasked 27 Oct &#39;10, 08:07
matthewlmcclure
16●2●2●3
accept rate: 0%
Can you use http.cookie as a display filter to see all packets that contain an HTTP cookie and then right-click on one of those packets and select Follow TCP stream? Do you see the entire cookie now?</description>
    </item>
    
    <item>
      <title>large send offload (ipv4)</title>
      <link>/questions/707/large-send-offload-ipv4/</link>
      <pubDate>Wed, 27 Oct 2010 10:25:00 +0000</pubDate>
      
      <guid>/questions/707/large-send-offload-ipv4/</guid>
      <description>large send offload (ipv4)  0 if large send offload (ipv4) setting is enabled on the server (default nic setting) and disabled on the client (default nic setting) what problems can arise from a mismatched LSO setting if any? is there any indication in WS trace that large send offload (ipv4) is enabled/disabled on the NIC?
Thanks
large lso offload sendasked 27 Oct &#39;10, 10:25
net_tech
116●30●33●37
accept rate: 13%</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t run the script chmodBPF</title>
      <link>/questions/717/cant-run-the-script-chmodbpf/</link>
      <pubDate>Wed, 27 Oct 2010 20:33:00 +0000</pubDate>
      
      <guid>/questions/717/cant-run-the-script-chmodbpf/</guid>
      <description>can&amp;rsquo;t run the script chmodBPF  0 the error is &#34;./ChmodBPF: line 35: $1: unbound variable&#34; in Snow leopard. after install.
Do you have any recommendation? Right now I can&#39;t detect any interfaces in wireshark.
chmodbpfasked 27 Oct &#39;10, 20:33
Nataichi
1●1●1●1
accept rate: 0%
  
One Answer:
  
2ChmodBPF isn&#39;t a script you&#39;re supposed to run directly, it&#39;s a script that&#39;s supposed to be run by the SystemStarter mechanism in Mac OS X.</description>
    </item>
    
    <item>
      <title>View log file on another machine - shows unknown protocol</title>
      <link>/questions/722/view-log-file-on-another-machine-shows-unknown-protocol/</link>
      <pubDate>Thu, 28 Oct 2010 06:26:00 +0000</pubDate>
      
      <guid>/questions/722/view-log-file-on-another-machine-shows-unknown-protocol/</guid>
      <description>View log file on another machine - shows unknown protocol  0 Good morning
I did a capture at a remote site using my laptop. When I view the capture on my desktop machine running the same version of Wireshark, only raw data is displayed with UNKNOWN in the protocol column. Is there another file that I need to move from the laptop to desktop to decode the capture file?</description>
    </item>
    
    <item>
      <title>Reporting a problem to the developers</title>
      <link>/questions/723/reporting-a-problem-to-the-developers/</link>
      <pubDate>Thu, 28 Oct 2010 06:32:00 +0000</pubDate>
      
      <guid>/questions/723/reporting-a-problem-to-the-developers/</guid>
      <description>Reporting a problem to the developers  0 To the portal
I had wireshark display an error message this morning while running a capture at a client site. It was not an intense capture, so this is not a resource problem on the laptop (laptop has i7, g gb Ram, tera HDD). The error displayed is as follows: &#34;Error while capturing packets: read error: PacketReceivePacket failed - Please report this to the Wireshark developers.</description>
    </item>
    
    <item>
      <title>Out-of-order packets...  Passed up to application layer?</title>
      <link>/questions/732/out-of-order-packets-passed-up-to-application-layer/</link>
      <pubDate>Thu, 28 Oct 2010 15:05:00 +0000</pubDate>
      
      <guid>/questions/732/out-of-order-packets-passed-up-to-application-layer/</guid>
      <description>Out-of-order packets&amp;hellip; Passed up to application layer?  2 Hello,
My question does not really pertain directly to Wireshark, but rather to TCP. I hope that is OK. If not, let me know...
This question was prompted by Laura Chappell&#39;s Tip #57, that I just received, and it involves out-of-order packets. She asks the question: &#34;Does your application depend on packets arriving in order before the data is presented or do a few out-of-order packets go unnoticed.</description>
    </item>
    
    <item>
      <title>Help me figure out strange parameters in Multipart Request Entity</title>
      <link>/questions/737/help-me-figure-out-strange-parameters-in-multipart-request-entity/</link>
      <pubDate>Thu, 28 Oct 2010 23:42:00 +0000</pubDate>
      
      <guid>/questions/737/help-me-figure-out-strange-parameters-in-multipart-request-entity/</guid>
      <description>Help me figure out strange parameters in Multipart Request Entity  0 1I am trying to analyse file uploading in FileDude.com
When i upload a file, a post request is sent with a multipart request entity which contains 3 parts. The first one is &#34;Filedata&#34; which contains the file data and the others are named &#34;x&#34; and &#34;y&#34; with some values. These values differ each time I upload a file(even if it is same file).</description>
    </item>
    
    <item>
      <title>Slow Print Jobs Over Network</title>
      <link>/questions/739/slow-print-jobs-over-network/</link>
      <pubDate>Fri, 29 Oct 2010 04:08:00 +0000</pubDate>
      
      <guid>/questions/739/slow-print-jobs-over-network/</guid>
      <description>Slow Print Jobs Over Network  0 Hi all I wonder if you can help with something I have installed a new printer for someone and set it up as a shared printer then installed the machine on the other two computers, the machine that is directly connected to printer works fine, the others take 20 seconds to start the job, it does this for every page, I have captured the action and it seems to fuss around trying to connect to something that shouldn&#39;t even exist \Dell01,Xcvport \Dell01hp3010 this fails and it is not until later in the trace at the 21 seconds mark when it tries \Dell01hp3010 without the xcvport thing that it connects and works.</description>
    </item>
    
    <item>
      <title>Comparing several wireshak graphs</title>
      <link>/questions/745/comparing-several-wireshak-graphs/</link>
      <pubDate>Sat, 30 Oct 2010 08:38:00 +0000</pubDate>
      
      <guid>/questions/745/comparing-several-wireshak-graphs/</guid>
      <description>Comparing several wireshak graphs  0 Hi What is the best way to view the difference between several captured graphs? Wireshark only display one graph at a time – how can I compare? Thanks
comparing graphs capturesasked 30 Oct &#39;10, 08:38
jonesKon
1●1●1●1
accept rate: 0%
  
4 Answers:
  
1Way back when, I used to use tcptrace and jplot. It took a little work to get it going but it fit my needs at the time.</description>
    </item>
    
    <item>
      <title>last modified time on server</title>
      <link>/questions/747/last-modified-time-on-server/</link>
      <pubDate>Sat, 30 Oct 2010 14:11:00 +0000</pubDate>
      
      <guid>/questions/747/last-modified-time-on-server/</guid>
      <description>last modified time on server  0 How can I learn the last modified time of the file that I retrieve at the server ? There is something like &#39;the delta time&#39; in frame segment but I don&#39;t know.
modified timeasked 30 Oct &#39;10, 14:11
tyrve
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Not exactly sure of the details on this yet, but can&#39;t you just go to the server and look at the Last Modified Time value for the file?</description>
    </item>
    
    <item>
      <title>Wireshark placement question</title>
      <link>/questions/748/wireshark-placement-question/</link>
      <pubDate>Sat, 30 Oct 2010 15:21:00 +0000</pubDate>
      
      <guid>/questions/748/wireshark-placement-question/</guid>
      <description>Wireshark placement question  1 Here is a diagram of the network I am on.
The problem is with ANY secure or encrypted traffic from ANY computer on the 20.0 network going to the 2008 server on the 30.0 network. Why I say secure, is because I can transfer big files (100 – 300Mb files) to the 2008 server via windows copy or ftp while secure/encrypted connections break. (SSL, MAPI, RDP just to name a few)</description>
    </item>
    
    <item>
      <title>cookie and query strings</title>
      <link>/questions/751/cookie-and-query-strings/</link>
      <pubDate>Sat, 30 Oct 2010 18:51:00 +0000</pubDate>
      
      <guid>/questions/751/cookie-and-query-strings/</guid>
      <description>cookie and query strings  0 Cookies:
What&#39;s a good way to find/locate/identify cookie transactions in the capture? Both for http and https transactions? (I know https should be hidden but I ask/include just for any additional clarification.)
Any idea the general frame/packet size of a cookie, i.e., how often then may exceed a single packet (up to four are possible?)
Query Strings: As I understand query strings, they can serve nearly the same purpose of a cookie thereby replacing them, would there use prevent a sidejacking/hijacking or cookiemonster attack?</description>
    </item>
    
    <item>
      <title>Wireshark with Virtual Box</title>
      <link>/questions/755/wireshark-with-virtual-box/</link>
      <pubDate>Sun, 31 Oct 2010 02:11:00 +0000</pubDate>
      
      <guid>/questions/755/wireshark-with-virtual-box/</guid>
      <description>Wireshark with Virtual Box  0 I am using Sun Virtual Box with Win7 64 bit as the host and an MSDOS guest and want to sniff the traffic using a Packet Driver on MSDOS. Wireshark does not capture the data. Microsoft VPC works as expected with Wireshark capturing the traffic.
msdos virtualboxasked 31 Oct &#39;10, 02:11
gerritvn
1●1●1●1
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>How to protect wireshark from termination?</title>
      <link>/questions/772/how-to-protect-wireshark-from-termination/</link>
      <pubDate>Mon, 01 Nov 2010 18:35:00 +0000</pubDate>
      
      <guid>/questions/772/how-to-protect-wireshark-from-termination/</guid>
      <description>How to protect wireshark from termination?  0 Some application shutdown after start using wireshark or terminate wireshark after it launced. How to protect wireshark from termination?
Thank you.
protect wiresharkasked 01 Nov &#39;10, 18:35
TSSENE
1●1●1●1
accept rate: 0%
It&#39;s not a virus or trojan. I was try to rename wireshark before posting this but it&#39;s can&#39;t help. Yes, It&#39;s prevent wireshark to capture, I know. So, How to protect wirehark from terminate?</description>
    </item>
    
    <item>
      <title>dissector bug: proto.c:656: failed assertion &amp;quot;(guint)hfindex &amp;lt; gpa_hfinfo.len&amp;quot;</title>
      <link>/questions/774/dissector-bug-protoc656-failed-assertion-guinthfindex-gpa_hfinfolen/</link>
      <pubDate>Mon, 01 Nov 2010 23:27:00 +0000</pubDate>
      
      <guid>/questions/774/dissector-bug-protoc656-failed-assertion-guinthfindex-gpa_hfinfolen/</guid>
      <description>dissector bug: proto.c:656: failed assertion &amp;ldquo;(guint)hfindex &amp;lt; gpa_hfinfo.len&amp;rdquo;  0 I search on Google about this failure. Mostly of them suggested to check whether there were variables that were used without going into the hf array.
But I checked carefully both with checkhf.pl and manually, no variable were used in such way.
Another thing is that my dissector was originally built as a plugin DLL with 0.99.5 wireshark. Now we are using wireshark 1.</description>
    </item>
    
    <item>
      <title>Wireshark Interface names</title>
      <link>/questions/782/wireshark-interface-names/</link>
      <pubDate>Tue, 02 Nov 2010 13:49:00 +0000</pubDate>
      
      <guid>/questions/782/wireshark-interface-names/</guid>
      <description>Wireshark Interface names  2 I&#39;m running the latest version of Wireshark on Windows 7 Home Premium 64 bit and 3 of the 5 capture interfaces are called &#34;Microsoft&#34; Where are these names pulled from? Why do they not show the actual card name? Only the LAN port shows correctly as &#34;Realtek RTL8168D&#34;
interface nameasked 02 Nov &#39;10, 13:49
jonh001
51●1●1●6
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Wireshark for Macintosh 64 bit vs. 32 bit install problems</title>
      <link>/questions/783/wireshark-for-macintosh-64-bit-vs-32-bit-install-problems/</link>
      <pubDate>Tue, 02 Nov 2010 15:30:00 +0000</pubDate>
      
      <guid>/questions/783/wireshark-for-macintosh-64-bit-vs-32-bit-install-problems/</guid>
      <description>Wireshark for Macintosh 64 bit vs. 32 bit install problems  0 I THINK this may be something obvious but I am missing what it is.
This is the current 1.4.1 Macintosh version, both the 64 bit and 32 bit versions.
I have 4 iMacs, INTELS, all running Mac OS 10.6.4. Most have 8 gigs RAM and that info is being indicated in this one problematic iMac as well.
These iMacs are standard 10.</description>
    </item>
    
    <item>
      <title>gtkrc theme in Windows</title>
      <link>/questions/789/gtkrc-theme-in-windows/</link>
      <pubDate>Wed, 03 Nov 2010 04:13:00 +0000</pubDate>
      
      <guid>/questions/789/gtkrc-theme-in-windows/</guid>
      <description>gtkrc theme in Windows  0 While this question is a bit off topic of net sniffing, I am hoping someone might help. I am writing a Windows app using gtk. I see that Wireshark is a gtk app with a gtkrc file. My app works fine with the theme stuff on the developer PC but it doesn&#39;t when I try to redistribute. Certainly the Wireshark developers have figured out how to redistribute their app and still have the gtk theme work.</description>
    </item>
    
    <item>
      <title>ESP sequence check for lost packets ?</title>
      <link>/questions/792/esp-sequence-check-for-lost-packets/</link>
      <pubDate>Wed, 03 Nov 2010 11:09:00 +0000</pubDate>
      
      <guid>/questions/792/esp-sequence-check-for-lost-packets/</guid>
      <description>ESP sequence check for lost packets ?  1 Is there a way to check the correct sequence of ESP packets, looking for lost ones ?
Without knowing any key or encryption algorithm, a basic quality check of an encrypted flow could be to check the esp.sequence field, that should be monotonically increasing within the same flow, identified by the esp.spi field.
My first idea would be to extract the fields at the command line and continue with perl, but a nice feature in wireshark would be to colorize the lost packets as in TCP.</description>
    </item>
    
    <item>
      <title>six byte VLAN tag?</title>
      <link>/questions/793/six-byte-vlan-tag/</link>
      <pubDate>Wed, 03 Nov 2010 12:51:00 +0000</pubDate>
      
      <guid>/questions/793/six-byte-vlan-tag/</guid>
      <description>six byte VLAN tag?  0 I&#39;m troubleshooting a problem where wireless clients on certain APs are unable to connect to certain web servers on our wired switched/routed lan. I&#39;ve traced the client SYN to the web server and verified that the server sent a SYN+ACK in response. On the wireless side the client is receiving the response that appears to have something that looks like a 802.1q header attached except that it has six bytes not four.</description>
    </item>
    
    <item>
      <title>Enhancement Request: Viewing process names with each packet</title>
      <link>/questions/795/enhancement-request-viewing-process-names-with-each-packet/</link>
      <pubDate>Wed, 03 Nov 2010 14:16:00 +0000</pubDate>
      
      <guid>/questions/795/enhancement-request-viewing-process-names-with-each-packet/</guid>
      <description>Enhancement Request: Viewing process names with each packet  1 For any OS Wireshark runs on, this would be great (my example is based on Windows).
TCPView by Mark Russinovich of Sysinternals has one feature that would great to see in Wireshark: the ability to see which process is originating traffic. If possible, it could be one of the displayed columns and could be turned on or off as desired.</description>
    </item>
    
    <item>
      <title>wireless toolbar</title>
      <link>/questions/802/wireless-toolbar/</link>
      <pubDate>Wed, 03 Nov 2010 18:26:00 +0000</pubDate>
      
      <guid>/questions/802/wireless-toolbar/</guid>
      <description>wireless toolbar  0 Hey All! why is my &#39;wireless toolbar&#39; grayed out / inactive? cheers
wireless_toolbarasked 03 Nov &#39;10, 18:26
clive
1●1●1●2
accept rate: 0%
  
One Answer:
  
2Um...we need a wee bit more information, I think. smile
The first answer is that the wireless toolbar is greyed out if the active interface is not AirPcapped.
answered 03 Nov &#39;10, 20:24
wesmorgan1
411●10●12●21
accept rate: 4%</description>
    </item>
    
    <item>
      <title>Building on Solaris 8</title>
      <link>/questions/812/building-on-solaris-8/</link>
      <pubDate>Wed, 03 Nov 2010 20:37:00 +0000</pubDate>
      
      <guid>/questions/812/building-on-solaris-8/</guid>
      <description>Building on Solaris 8  0 I&#39;ve been trying to build wireshark 1.4.1 for Solaris 8 on sparc. I haven&#39;t had much luck. My first problem was that I had an older gtk than what is required so I had to try and build it without much luck. I have ended up building cairo, pango, libiconv, GNU m4, GNU sed, glib, flex, and pkgconfig. At every stage I seen to have a problem.</description>
    </item>
    
    <item>
      <title>Tshark: Custom HTTP headers</title>
      <link>/questions/816/tshark-custom-http-headers/</link>
      <pubDate>Thu, 04 Nov 2010 04:43:00 +0000</pubDate>
      
      <guid>/questions/816/tshark-custom-http-headers/</guid>
      <description>Tshark: Custom HTTP headers  0 Hi,
Is it possible to pass custom HTTP headers fields for HTTP dissection on the CLI with tshark?
I am aware of &#39;-o&#39; to set preferences but the header fields appear to be stored seperately.
Many thanks
header http field customasked 04 Nov &#39;10, 04:43
rtector
1●2●2●4
accept rate: 0%
  
One Answer:
  
2The custom HTTP headers are stored in a user accessible table (UAT) named custom_http_header_fields in your preferences directory.</description>
    </item>
    
    <item>
      <title>Wireshark certification - any value?</title>
      <link>/questions/818/wireshark-certification-any-value/</link>
      <pubDate>Thu, 04 Nov 2010 05:17:00 +0000</pubDate>
      
      <guid>/questions/818/wireshark-certification-any-value/</guid>
      <description>Wireshark certification - any value?  0 Anyone have the Wireshark certification? What are the benefits to having it - do you think employers put any stock into it?
certificationasked 04 Nov &#39;10, 05:17
salander2
1●1●1●1
accept rate: 0%
  
7 Answers:
  
2As a hiring manager, I can tell you that I always hire the person with more experience. However, if I have two equal candidates (equal in presentation skills etc.</description>
    </item>
    
    <item>
      <title>MS SQL analysis</title>
      <link>/questions/826/ms-sql-analysis/</link>
      <pubDate>Thu, 04 Nov 2010 22:43:00 +0000</pubDate>
      
      <guid>/questions/826/ms-sql-analysis/</guid>
      <description>MS SQL analysis  0 Hello All, I am looking into MS SQL service response time i didn&#39;t found any info about it is there any analysis for it and some Tshark query would be helpful.
Please advice Thanks
mssqlasked 04 Nov &#39;10, 22:43
tbaror
10●12●12●15
accept rate: 0%
  
One Answer:
  
1(couldn&#39;t post this as a comment due to character limitation) Tbaror, it depends on how proficient you are with pkt analysis.</description>
    </item>
    
    <item>
      <title>How do I justify shutting down Skype?</title>
      <link>/questions/827/how-do-i-justify-shutting-down-skype/</link>
      <pubDate>Fri, 05 Nov 2010 12:46:00 +0000</pubDate>
      
      <guid>/questions/827/how-do-i-justify-shutting-down-skype/</guid>
      <description>How do I justify shutting down Skype?  0 First off, Laura is great! Gerald is great! Wireshark is great!
I&#39;ve been digging into how Wireshark can help me detect security problems on my corporate network. I hear lots of talk about how bad Skype is and how nobody should allow it on their network. But I can&#39;t seem to find anything that clearly shows why it is bad. How can I use Wireshark to plainly show why Skype should be banned from my network?</description>
    </item>
    
    <item>
      <title>How to add extra file to Wireshark folder for plugin</title>
      <link>/questions/828/how-to-add-extra-file-to-wireshark-folder-for-plugin/</link>
      <pubDate>Fri, 05 Nov 2010 13:11:00 +0000</pubDate>
      
      <guid>/questions/828/how-to-add-extra-file-to-wireshark-folder-for-plugin/</guid>
      <description>How to add extra file to Wireshark folder for plugin  0 I have a plugin for Wireshark that works when copying my files to
C:\Program Files\Wireshark\plugins\MyPlugin\myplugin.dll
C:\Program Files\Wireshark\myplug.dll (required for myplugin.dll to actually work - by design)
Now I want to build my plugin as part of Wireshark. The myplug.obj, myplug.lib (needed by myplugin.dll to built), and myplug.dll are located outside of the C:\wireshark-trunk and everything is built correctly but I cannot get myplug.</description>
    </item>
    
    <item>
      <title>TCP Checksum errors</title>
      <link>/questions/830/tcp-checksum-errors/</link>
      <pubDate>Fri, 05 Nov 2010 19:16:00 +0000</pubDate>
      
      <guid>/questions/830/tcp-checksum-errors/</guid>
      <description>TCP Checksum errors  0 Ok I read this wiki article
Wireshark Wiki TCP checksum errors
The checkbox was already deselected and yet I am still getting TCP packets with bad header checksums. Its always the TCP packets that are leaving my computer and not the ones coming in.
is there another setting I am missing?
Error looks like this
Header Checksum: 0X0000 [incorrect, should be 0xb2ae]
I gather this is TCP offloading as there is settings for this in my adapters configuration setups.</description>
    </item>
    
    <item>
      <title>Wireless Adaptor not seen by Wireshark</title>
      <link>/questions/831/wireless-adaptor-not-seen-by-wireshark/</link>
      <pubDate>Fri, 05 Nov 2010 19:52:00 +0000</pubDate>
      
      <guid>/questions/831/wireless-adaptor-not-seen-by-wireshark/</guid>
      <description>Wireless Adaptor not seen by Wireshark  0 Hello, I just wanted to install Wireshark on on laptop. Here&#39;s the setup:
Compaq R3000
Win7 Ultimate
Broadcom 802.11g Network Adaptor
Driver Version 4.176.75.21
Wireshark Version 1.4.1
So then I install the wireshark, and the wireless adapter is not shown as an option, can anyone help me out with why this wireless adapter is not showing up?
wireless adaptorsasked 05 Nov &#39;10, 19:52</description>
    </item>
    
    <item>
      <title>Not seeing any traffic on Windows on my Broadcom 4321ag adapter</title>
      <link>/questions/836/not-seeing-any-traffic-on-windows-on-my-broadcom-4321ag-adapter/</link>
      <pubDate>Sat, 06 Nov 2010 06:55:00 +0000</pubDate>
      
      <guid>/questions/836/not-seeing-any-traffic-on-windows-on-my-broadcom-4321ag-adapter/</guid>
      <description>Not seeing any traffic on Windows on my Broadcom 4321ag adapter  0 I have a broadcom 4321 ag adaptor and I see the interface microsoft but when I start the capture nothings comes up ?
windows 802.11asked 06 Nov &#39;10, 06:55
Rehan
1●1●1●1
accept rate: 0%
 converted to question 01 Aug &#39;12, 15:22 
Guy Harris ♦♦
17.4k●3●35●196
No packets at all? You might want to try to disable &#34;</description>
    </item>
    
    <item>
      <title>Utility to &amp;quot;anonymize&amp;quot; capture files?</title>
      <link>/questions/844/utility-to-anonymize-capture-files/</link>
      <pubDate>Sat, 06 Nov 2010 22:45:00 +0000</pubDate>
      
      <guid>/questions/844/utility-to-anonymize-capture-files/</guid>
      <description>Utility to &amp;ldquo;anonymize&amp;rdquo; capture files?  1 I often run across capture data that would make excellent teaching aids, but (for obvious reasons) I am not allowed to use &#34;real customer&#34; data for such purposes. Does anyone know of a pcap editor that would allow me to do things like arbitrary search-and-replace of IP/MAC addresses, obfuscate URLs (like changing &#34;GET /real/file/path/here.htm&#34; to &#34;GET /dead/beef/feed/blah.htm&#34;, and the like?
I REALLY don&#39;t want to break out the old binary file editor.</description>
    </item>
    
    <item>
      <title>TCP ZeroWindow</title>
      <link>/questions/849/tcp-zerowindow/</link>
      <pubDate>Mon, 08 Nov 2010 04:01:00 +0000</pubDate>
      
      <guid>/questions/849/tcp-zerowindow/</guid>
      <description>TCP ZeroWindow  2 2Hi, i&#39;m having some questions about the TCP ZeroWindow flag. According to my capture we have the following scene:
98408 16:55:40.447814 192.168.45.182 -&amp;gt; 192.168.45.178 TCP 8790 &amp;gt; 9112 [PSH, ACK] Seq=109220 Ack=136247 Win=118 Len=282
98411 16:55:40.627255 192.168.45.178 -&amp;gt; 192.168.45.182 TCP 9112 &amp;gt; 8790 [ACK] Seq=136247 Ack=109502 Win=64112 Len=118
98412 16:55:40.664670 192.168.45.182 -&amp;gt; 192.168.45.178 TCP [TCP ZeroWindow] 8790 &amp;gt; 9112 [PSH, ACK] Seq=109502 Ack=136365 Win=0 Len=165
98413 16:55:40.</description>
    </item>
    
    <item>
      <title>(not) easy to use?</title>
      <link>/questions/857/not-easy-to-use/</link>
      <pubDate>Mon, 08 Nov 2010 09:31:00 +0000</pubDate>
      
      <guid>/questions/857/not-easy-to-use/</guid>
      <description>(not) easy to use?  0 I just don&#39;t understand all the technical words. Now that I have Wireshark, how can I see a network that I&#39;ve already had access to. I need to read my brothers e-mail. He passed away and has some documents, etc saved in his inbox.
use easyasked 08 Nov &#39;10, 09:31
heylookhere
1●1●1●1
accept rate: 0%
 edited 08 Nov &#39;10, 10:21 
Jaap ♦</description>
    </item>
    
    <item>
      <title>Encountering an error when starting a new capture on Mac OSX</title>
      <link>/questions/858/encountering-an-error-when-starting-a-new-capture-on-mac-osx/</link>
      <pubDate>Mon, 08 Nov 2010 11:01:00 +0000</pubDate>
      
      <guid>/questions/858/encountering-an-error-when-starting-a-new-capture-on-mac-osx/</guid>
      <description>Encountering an error when starting a new capture on Mac OSX  0 I am encountering an error &#34;You didn&#39;t specify an interface on which to capture packets&#34; when clicking on the Start new Live capture.
How do I setup a new Interface? I might be missing something obvious.
Regards
interface start trace newasked 08 Nov &#39;10, 11:01
loganwol
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Can I use wireshark to monitor bandwidth of computers over my network</title>
      <link>/questions/865/can-i-use-wireshark-to-monitor-bandwidth-of-computers-over-my-network/</link>
      <pubDate>Mon, 08 Nov 2010 14:56:00 +0000</pubDate>
      
      <guid>/questions/865/can-i-use-wireshark-to-monitor-bandwidth-of-computers-over-my-network/</guid>
      <description>Can I use wireshark to monitor bandwidth of computers over my network  0 Can I use wireshark on my pc (connected through ethernet) to monitor the bandwidth usage of my roommates on their wireless laptops?
wireless ethernet bandwidth monitorasked 08 Nov &#39;10, 14:56
theunderachi...
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Yes - if you can capture their traffic. You will need an adapter that goes into promiscuous mode and monitor mode.</description>
    </item>
    
    <item>
      <title>tshark: how to decode and display individual packets</title>
      <link>/questions/869/tshark-how-to-decode-and-display-individual-packets/</link>
      <pubDate>Tue, 09 Nov 2010 03:05:00 +0000</pubDate>
      
      <guid>/questions/869/tshark-how-to-decode-and-display-individual-packets/</guid>
      <description>tshark: how to decode and display individual packets  0 Hi All,
I want to use tshark to display the raw packets. By using the command and options: tshark -x -r file.pcap the tshark displays all the packets. I want to view the packets one by one, but can not find the option to display say the 1st packet.
Thanks in advance.
/Dan
tsharkasked 09 Nov &#39;10, 03:05
danyigez
1●1●1●2</description>
    </item>
    
    <item>
      <title>Configuration Parameters for rpcapd</title>
      <link>/questions/875/configuration-parameters-for-rpcapd/</link>
      <pubDate>Tue, 09 Nov 2010 06:07:00 +0000</pubDate>
      
      <guid>/questions/875/configuration-parameters-for-rpcapd/</guid>
      <description>Configuration Parameters for rpcapd  0 I am looking in chapter 3 of the study guide and i am looking at the list of rpcapd parameters for rpcapd. How do I get to the command line in rpcapd in order to change parameters?
rpcapd for parametersasked 09 Nov &#39;10, 06:07
ChumMaster
1●1●1●1
accept rate: 0%
See Jaap&#39;s answer below. Also see http://wiki.wireshark.org/CaptureSetup/WinPcapRemote.
(09 Nov &#39;10, 14:28) lchappell ♦Thanks. Also this part of the Wireshark User&#39;s Guide could be helpful, although it could do more explaining rpcapd itself: http://www.</description>
    </item>
    
    <item>
      <title>RpCap 4.1.1 vs RpCap 4.1.2</title>
      <link>/questions/877/rpcap-411-vs-rpcap-412/</link>
      <pubDate>Tue, 09 Nov 2010 08:00:00 +0000</pubDate>
      
      <guid>/questions/877/rpcap-411-vs-rpcap-412/</guid>
      <description>RpCap 4.1.1 vs RpCap 4.1.2  0 We utilize RpCapd –n on a regular basis in our Hospital Enterprise network of 5000 desktops, 68 wiring closets and over 250 switches and routers. We have been installing WinPcap 4.1.1 due to its ability to be ‘silently’ installed, versus 4.1.2 which as we understand can NOT be silently installed.
We have not been able to remotely capture with Wireshark 1.4 on these remote devices after running a local batch file with PSExec to start RpCap –n on the remote device.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t Enable SNMP Decodes in 64 bit Windows</title>
      <link>/questions/878/cant-enable-snmp-decodes-in-64-bit-windows/</link>
      <pubDate>Tue, 09 Nov 2010 08:01:00 +0000</pubDate>
      
      <guid>/questions/878/cant-enable-snmp-decodes-in-64-bit-windows/</guid>
      <description>Can&amp;rsquo;t Enable SNMP Decodes in 64 bit Windows  0 I&#39;m running Wireshark 1.4.1 on Windows 7 x64. I&#39;m trying to enable SNMP decodes, but can&#39;t.
Under Preferences - Name Resolution, I&#39;ve got the options for Enable OID Resolution and Suppress SMI Errors, but both have the entry &#34;N/A&#34;, I can&#39;t check / uncheck them. I also don&#39;t have an SNMP directory under the Wireshark system directory.
This is a brand new install and I&#39;ve tried uninstalling / reinstalling.</description>
    </item>
    
    <item>
      <title>No TLS protocol packets seen for SQL Svr SSL Encryption.  Microsoft Network Monitor shows them.</title>
      <link>/questions/886/no-tls-protocol-packets-seen-for-sql-svr-ssl-encryption-microsoft-network-monitor-shows-them/</link>
      <pubDate>Tue, 09 Nov 2010 11:35:00 +0000</pubDate>
      
      <guid>/questions/886/no-tls-protocol-packets-seen-for-sql-svr-ssl-encryption-microsoft-network-monitor-shows-them/</guid>
      <description>No TLS protocol packets seen for SQL Svr SSL Encryption. Microsoft Network Monitor shows them.  0 Hello -
Problem Definition
I&#39;ve configured SQL Server 2005 Express edition to use SSL encryption for database connections. I use SQL Mgmt Studio to connect to my database with &#34;encrypt&#34; check box on. I&#39;ve even enabled the FIPS 140-2 complaince in my local policy. I want to check if the DB connection is truely using TLS/SSL when I connect from mgmt studio to the SQL Server db.</description>
    </item>
    
    <item>
      <title>Creating a filter to filter on a text label based on a UINT64</title>
      <link>/questions/889/creating-a-filter-to-filter-on-a-text-label-based-on-a-uint64/</link>
      <pubDate>Tue, 09 Nov 2010 14:38:00 +0000</pubDate>
      
      <guid>/questions/889/creating-a-filter-to-filter-on-a-text-label-based-on-a-uint64/</guid>
      <description>Creating a filter to filter on a text label based on a UINT64  0 I have a dissector that works correctly and I&#39;m working on some usability features. Namely, I want to be able to filter on a 64 bit value using a text label.
For example, I would like to be filter on all orange objects in my protocol. e.g. myproto.id == orange where orange has an id that is 64 a bit integer.</description>
    </item>
    
    <item>
      <title>Packet capture and Apache logs do not agree - data discrepencies</title>
      <link>/questions/896/packet-capture-and-apache-logs-do-not-agree-data-discrepencies/</link>
      <pubDate>Wed, 10 Nov 2010 08:46:00 +0000</pubDate>
      
      <guid>/questions/896/packet-capture-and-apache-logs-do-not-agree-data-discrepencies/</guid>
      <description>Packet capture and Apache logs do not agree - data discrepencies  0 I recently started to see a burst of HTTP &#39;400&#39; response codes in our Apache logs running on RHEL5 servers. According to our logs we are serving up a &#39;400&#39; every few seconds. When I manually cut/paste the URL receiving a &#39;400&#39; in a browser it works without any problems. What&#39;s odd is that Apache is showing those responses taking 1 second to complete.</description>
    </item>
    
    <item>
      <title>10base2 network</title>
      <link>/questions/897/10base2-network/</link>
      <pubDate>Wed, 10 Nov 2010 08:53:00 +0000</pubDate>
      
      <guid>/questions/897/10base2-network/</guid>
      <description>10base2 network  0 I have a customer that still uses Thinnet (10base2) and has been having issues with his network. There are random crashes. I was hoping to bring in a Windows 2003 Server Box (that&#39;s all I have) with Wireshark installed and hook it up to the network using a media converter and let it analyze all traffic throughout the week.
My understanding of 10base2 is limited. But I am assuming it still uses the same protocols.</description>
    </item>
    
    <item>
      <title>expert.message == &amp;quot;Window update&amp;quot;</title>
      <link>/questions/901/expertmessage-window-update/</link>
      <pubDate>Wed, 10 Nov 2010 11:46:00 +0000</pubDate>
      
      <guid>/questions/901/expertmessage-window-update/</guid>
      <description>expert.message == &amp;ldquo;Window update&amp;rdquo;  0 2i have a web application running on a Windows 2008 R2 server.
is it normal to see tcp window update packet (tcp.analysis.flags as a filter) for EVERY get/post request from a client workstation on the same LAN?
Thanks
web window update iisasked 10 Nov &#39;10, 11:46
net_tech
116●30●33●37
accept rate: 13%
  
3 Answers:
  
2 A packet marked &#34;TCP Window Update&#34;</description>
    </item>
    
    <item>
      <title>Wireshark &amp;quot;No Font Found&amp;quot; Solaris 8</title>
      <link>/questions/902/wireshark-no-font-found-solaris-8/</link>
      <pubDate>Wed, 10 Nov 2010 11:47:00 +0000</pubDate>
      
      <guid>/questions/902/wireshark-no-font-found-solaris-8/</guid>
      <description>Wireshark &amp;ldquo;No Font Found&amp;rdquo; Solaris 8  0 Hi, I am facing the below error after installing Wireshark on Solaris 8. Please help me in resolving this error.
Thanks &amp;amp; Regards, Pacchi
usr/local/bin/wireshark -f No fonts found; this probably means that the fontconfig library is not correctly configured. You may need to edit the fonts.conf configuration file. More information about fontconfig can be found in the fontconfig(3) manual page and on http://fontconfig.</description>
    </item>
    
    <item>
      <title>Relative Sequence Number</title>
      <link>/questions/913/relative-sequence-number/</link>
      <pubDate>Thu, 11 Nov 2010 09:38:00 +0000</pubDate>
      
      <guid>/questions/913/relative-sequence-number/</guid>
      <description>Relative Sequence Number  0 I have been reading the questiins and answer&#39;s tothis question but none of them seem to help me. I was under the impression that I could follow a relative sequence number say 551 all the way through and get a complete conversation. Am I mistaken. Thanks steve.
numbers sequenceasked 11 Nov &#39;10, 09:38
jfkseb413
1●1●1●1
accept rate: 0%
Thanks folks......I did what you said and got both ends of the conversation.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t see other packets</title>
      <link>/questions/918/cant-see-other-packets/</link>
      <pubDate>Thu, 11 Nov 2010 13:12:00 +0000</pubDate>
      
      <guid>/questions/918/cant-see-other-packets/</guid>
      <description>Can&amp;rsquo;t see other packets  0 Hi All!
I have problems with wireshark I can&#39;t see packets from other users, I see only packets from myself.
I searched the help file and found a &#34;solution&#34; it&#39;s explained in question 7.1, my problem is I don&#39;t understand that answer.
Can someone else explain it in a different way for me?
I am using a wireless adapter on a router.
Thanks in advance,</description>
    </item>
    
    <item>
      <title>How wireshark calculate the dbm of wireless signal?</title>
      <link>/questions/926/how-wireshark-calculate-the-dbm-of-wireless-signal/</link>
      <pubDate>Thu, 11 Nov 2010 17:51:00 +0000</pubDate>
      
      <guid>/questions/926/how-wireshark-calculate-the-dbm-of-wireless-signal/</guid>
      <description>How wireshark calculate the dbm of wireless signal?  0 Please, I want to know how wireshark calculate the SSI signal of the wireless network.
According to the capture result, the &#34;SSI Signal&#34; is -70 dBm, but the displayed hexadecimal value is &#34;ba&#34;. Convert the &#34;ba&#34; to decimal = 186 and not -70. So, I really want to know how wireshark calculate that, because my final year project is about 802.</description>
    </item>
    
    <item>
      <title>&amp;#x27;mate failed to configure&amp;#x27; when starting with web.mate enabled</title>
      <link>/questions/931/mate-failed-to-configure-when-starting-with-webmate-enabled/</link>
      <pubDate>Fri, 12 Nov 2010 10:08:00 +0000</pubDate>
      
      <guid>/questions/931/mate-failed-to-configure-when-starting-with-webmate-enabled/</guid>
      <description>&amp;lsquo;mate failed to configure&amp;rsquo; when starting with web.mate enabled  0 Has anyone run into any problems with web.mate? I&#39;m running Windows 7 64 bit with the 64 bit Wireshark v1.4.1. The mate plugin is loading fine. I have loaded up tcp.mate without any errors. When I start up Wireshark with web.mate enabled I get this error:
c:usersMEwireshark_mateweb.mate at line 1: Syntax Error before web.mate
The permissions, directory path and attributes of the web.</description>
    </item>
    
    <item>
      <title>Is it possible to detect an inbound TCP association (ip address) if no socket is open...</title>
      <link>/questions/937/is-it-possible-to-detect-an-inbound-tcp-association-ip-address-if-no-socket-is-open/</link>
      <pubDate>Sun, 14 Nov 2010 01:01:00 +0000</pubDate>
      
      <guid>/questions/937/is-it-possible-to-detect-an-inbound-tcp-association-ip-address-if-no-socket-is-open/</guid>
      <description>Is it possible to detect an inbound TCP association (ip address) if no socket is open&amp;hellip;  0 Is it possible to detect an inbound TCP association if no socket is open ? The title says it all. We need to detect an inbound association on port 2000 to detect the IP address before a socket to TCP is open. Is there a way to see the IP address under these conditions with WireShark.</description>
    </item>
    
    <item>
      <title>SSL Tunnel via HTTP Connect - Are ACK&amp;#x27;s &amp;quot;end-to-end&amp;quot;?</title>
      <link>/questions/938/ssl-tunnel-via-http-connect-are-acks-end-to-end/</link>
      <pubDate>Sun, 14 Nov 2010 02:36:00 +0000</pubDate>
      
      <guid>/questions/938/ssl-tunnel-via-http-connect-are-acks-end-to-end/</guid>
      <description>SSL Tunnel via HTTP Connect - Are ACK&amp;rsquo;s &amp;ldquo;end-to-end&amp;rdquo;?  1 Hi. I am troubleshooting an SSL transaction that goes through a web proxy server, and I am only able to capture packets at the Client end. In this scenario, the Client uses an HTTP CONNECT to create an SSL Tunnel through the proxy server to the destination server (aka &#34;Origin Server&#34;). In my situation, the tunnel is created successfully, and the SSL Handshake is completed successfully, but when the Client actually sends &#34;</description>
    </item>
    
    <item>
      <title>&amp;quot;Acid test&amp;quot; capture file for new builds?</title>
      <link>/questions/942/acid-test-capture-file-for-new-builds/</link>
      <pubDate>Sun, 14 Nov 2010 19:25:00 +0000</pubDate>
      
      <guid>/questions/942/acid-test-capture-file-for-new-builds/</guid>
      <description>&amp;ldquo;Acid test&amp;rdquo; capture file for new builds?  0 I&#39;m building Wireshark 1.4.1 on a new platform, and I&#39;m wondering if there&#39;s any sort of &#34;test capture&#34; file that exercises the base dissectors (or some particular subset thereof) as a &#34;build test&#34; sort of thing.
I&#39;ve thought of using the various sample captures, but I suspect that something better is &#34;out there&#34;...
testing buildasked 14 Nov &#39;10, 19:25
wesmorgan1
411●10●12●21</description>
    </item>
    
    <item>
      <title>So, is there a place to submit packet captures for the network-smart to dissect?</title>
      <link>/questions/943/so-is-there-a-place-to-submit-packet-captures-for-the-network-smart-to-dissect/</link>
      <pubDate>Sun, 14 Nov 2010 19:27:00 +0000</pubDate>
      
      <guid>/questions/943/so-is-there-a-place-to-submit-packet-captures-for-the-network-smart-to-dissect/</guid>
      <description>So, is there a place to submit packet captures for the network-smart to dissect?  0 I saw a thread on the Steam Users&#39; Forum about someone who was getting like, 12 kB/s download speed specifically in his Steam game client. Since he was at the end of his rope, I told him to try capturing with Wireshark and see if anything obvious pops out. He posted packet captures whilst trying to download and while not, and I couldn&#39;t find anything obvious.</description>
    </item>
    
    <item>
      <title>Need Help Understanding Capture</title>
      <link>/questions/951/need-help-understanding-capture/</link>
      <pubDate>Sun, 14 Nov 2010 21:54:00 +0000</pubDate>
      
      <guid>/questions/951/need-help-understanding-capture/</guid>
      <description>Need Help Understanding Capture  0 I am working on a pair of Windows 7 x64 machines. When I open a DOC file across the network it takes a long time to open and save. If I rename the file DOCX it opens and saves quickly. I have used Wireshark to capture traffic for both operations but don&#39;t know enough about TCP to analyze what I have.
Are there any examples around that might help?</description>
    </item>
    
    <item>
      <title>Fragmentation dissecting Problem</title>
      <link>/questions/972/fragmentation-dissecting-problem/</link>
      <pubDate>Tue, 16 Nov 2010 01:44:00 +0000</pubDate>
      
      <guid>/questions/972/fragmentation-dissecting-problem/</guid>
      <description>Fragmentation dissecting Problem  0 1Hi, I&#39;m writing a dissector for our LTE PHY packets. I have started working on fragmented packets. These are ethernet packets that are fragmented with some propriatery limitation. Nevertheless we have a PI header (under the ethernet header) that is always there in any fragment. The PI header contains what I thought is sefficient data for the fragment functions such as: size - the size of the PI message payload, Fragment (full, first, mid and last for indication as in what part of the fragmented packet are we) and sequence - message sequence index.</description>
    </item>
    
    <item>
      <title>My macintosh won&amp;#x27;t start after trying to install Wireshark</title>
      <link>/questions/975/my-macintosh-wont-start-after-trying-to-install-wireshark/</link>
      <pubDate>Tue, 16 Nov 2010 10:59:00 +0000</pubDate>
      
      <guid>/questions/975/my-macintosh-wont-start-after-trying-to-install-wireshark/</guid>
      <description>My macintosh won&amp;rsquo;t start after trying to install Wireshark  0 Hello,
I have a MacBook 10.5.6 and after tried to install Wireshark It asked me to put a folder to my &#34;OpenonStartup&#34; mac folder, after this I restarted, and my computer warned me to only allow that WireShark Foldar into my StartupFolder if I trusted it. I click &#34;Allowed&#34; and prompted for a Restart.
After the restart, I will get the greyish screen with the apple for like 5 seconds, then my computer will turn back off.</description>
    </item>
    
    <item>
      <title>Converting RTP to .au or playing - Not Taking into Account Timestamp field</title>
      <link>/questions/977/converting-rtp-to-au-or-playing-not-taking-into-account-timestamp-field/</link>
      <pubDate>Tue, 16 Nov 2010 13:16:00 +0000</pubDate>
      
      <guid>/questions/977/converting-rtp-to-au-or-playing-not-taking-into-account-timestamp-field/</guid>
      <description>Converting RTP to .au or playing - Not Taking into Account Timestamp field  0 I have a capture and it appears if the Timestamp within the RTP packet is too large that correct delay between frames is not kept intact when converting to .au or when using Wireshark&#39;s playback feature.
Normal voice does not seem to have this problem, but pre-recorded speech playback in an automated system seems to have this issue.</description>
    </item>
    
    <item>
      <title>How to convert RTP packets with PT=ISAC and PT=CN to .wav files?</title>
      <link>/questions/978/how-to-convert-rtp-packets-with-ptisac-and-ptcn-to-wav-files/</link>
      <pubDate>Tue, 16 Nov 2010 16:26:00 +0000</pubDate>
      
      <guid>/questions/978/how-to-convert-rtp-packets-with-ptisac-and-ptcn-to-wav-files/</guid>
      <description>How to convert RTP packets with PT=ISAC and PT=CN to .wav files?  0 Hi,all, I&#39;m capturing telephony call packets between two endpoints. In my captured packets, there are RTP packets with payload type PT=PCMA, ISAC and CN(What is CN? what kind of codec?) I know how to save packets with PT=PCMA to .au files. However, when it comes to ISAC and CN, I have no idea how to convert them to .</description>
    </item>
    
    <item>
      <title>Web page size</title>
      <link>/questions/984/web-page-size/</link>
      <pubDate>Wed, 17 Nov 2010 06:28:00 +0000</pubDate>
      
      <guid>/questions/984/web-page-size/</guid>
      <description>Web page size  0 One of our internal web pages keeps getting slower and slower and I believe it&#39;s due to it keeps getting bigger and bigger. Anyone know of a way to easily determine a web page size? I&#39;m using &#34;tcp.reassembled.length&#34; now but was wondering if there is a better way.
thanks,
webpage sizeasked 17 Nov &#39;10, 06:28
JimL
1●1●1●1
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Follow UDP Stream in Analyze</title>
      <link>/questions/987/follow-udp-stream-in-analyze/</link>
      <pubDate>Wed, 17 Nov 2010 09:29:00 +0000</pubDate>
      
      <guid>/questions/987/follow-udp-stream-in-analyze/</guid>
      <description>Follow UDP Stream in Analyze  0 I captured 700000 data packets and it took at least an hour for Follow UDP Stream to finish. Did the time look normal?
udpasked 17 Nov &#39;10, 09:29
SMCL3
1●1●1●1
accept rate: 0%
I have a wireshark trace with some SIP messages in it. When I click on a certain message and analyze it using &#34;Follow UDP Stream&#34; I see all of the expected messages however I don&#39;t see all of them in actual Wireshark trace with time stamps.</description>
    </item>
    
    <item>
      <title>Why can&amp;#x27;t I save payload as .au file</title>
      <link>/questions/988/why-cant-i-save-payload-as-au-file/</link>
      <pubDate>Wed, 17 Nov 2010 09:36:00 +0000</pubDate>
      
      <guid>/questions/988/why-cant-i-save-payload-as-au-file/</guid>
      <description>Why can&amp;rsquo;t I save payload as .au file  0 I use Wireshark to capture a call between two clients using telephony software. The codec used is G711 PCMU and comfort noise (PT=CN), as you can see in picture 1 there are 7 streams altogether, as you can see in picture 2. I want to save the payload as .au file, however, I can only save the first 5 streams (which only contain some ringing sound or background noise) as .</description>
    </item>
    
    <item>
      <title>Ethernet traffic capture</title>
      <link>/questions/990/ethernet-traffic-capture/</link>
      <pubDate>Wed, 17 Nov 2010 10:28:00 +0000</pubDate>
      
      <guid>/questions/990/ethernet-traffic-capture/</guid>
      <description>Ethernet traffic capture  0 Can I capture all traffic in my LAN? not only my pc traffic.
I want to get the packets from other¡s pc&#39;s in the same workgroup.
For example: I want to be able to know wich pages is other people visiting. assuming that I have ip 172.17.223.15 and I want to see the traffic of 172.17.223.16
Is it that possible?¿ PD:Sorry for my bad english.</description>
    </item>
    
    <item>
      <title>what is the meaning of &amp;quot;dropped&amp;quot;count of capture result</title>
      <link>/questions/1002/what-is-the-meaning-of-droppedcount-of-capture-result/</link>
      <pubDate>Thu, 18 Nov 2010 02:22:00 +0000</pubDate>
      
      <guid>/questions/1002/what-is-the-meaning-of-droppedcount-of-capture-result/</guid>
      <description>what is the meaning of &amp;ldquo;dropped&amp;quot;count of capture result  1 when i captured some packets, the result shows &#34;Packets : xxxxx Displayed : xxxxx Marked : 0 Dropped : xxxxx&#34; in the bottom of capture result.(xxxx -&amp;gt; any number) if there is &#34;Dropped&#34; count, for example &#34;Packets : xxxxx Displayed : xxxxx Marked : 0 Dropped : 10&#34; what does the &#34;10&#34; means? does that mean there are 10 packet the Wireshark didn`t capture?</description>
    </item>
    
    <item>
      <title>NAS wireshark support</title>
      <link>/questions/1005/nas-wireshark-support/</link>
      <pubDate>Thu, 18 Nov 2010 05:08:00 +0000</pubDate>
      
      <guid>/questions/1005/nas-wireshark-support/</guid>
      <description>NAS wireshark support  0 Hi, Is there any wireshark dissector to decode LTE-NAS ciphered messages.
Thanks in advance vinodh
lte-nasdessectorasked 18 Nov &#39;10, 05:08
vinodh
1●1●1●1
accept rate: 0%
  
One Answer:
  
0There is a LTE-NAS dissector, packet-nas_eps.c. But it can&#39;t do deciphering.
answered 19 Nov &#39;10, 10:27
Anders ♦
4.6k●9●52
accept rate: 17%
     </description>
    </item>
    
    <item>
      <title>Bandwidth calculation formula</title>
      <link>/questions/1007/bandwidth-calculation-formula/</link>
      <pubDate>Thu, 18 Nov 2010 05:51:00 +0000</pubDate>
      
      <guid>/questions/1007/bandwidth-calculation-formula/</guid>
      <description>Bandwidth calculation formula  0 Hello,
In the Summary of the capture I could see the Avg Bytes/sec which I think is the average bandwidth. I was curious to know how this was calculated. may be a formula would help
bandwidth calculateasked 18 Nov &#39;10, 05:51
adhikaa1
6●2●2●3
accept rate: 0%
  
One Answer:
  
2 Cumulative Bytes / Relative Time
which means
SUM(frame sizes) / seconds since beginning of capture</description>
    </item>
    
    <item>
      <title>Can I use tshark to output name/value pairs of Radius VSA attributes?</title>
      <link>/questions/1010/can-i-use-tshark-to-output-namevalue-pairs-of-radius-vsa-attributes/</link>
      <pubDate>Thu, 18 Nov 2010 07:52:00 +0000</pubDate>
      
      <guid>/questions/1010/can-i-use-tshark-to-output-namevalue-pairs-of-radius-vsa-attributes/</guid>
      <description>Can I use tshark to output name/value pairs of Radius VSA attributes?  0 When decoding RADIUS traffic, wireshark displays Attribute Value Pairs in a format such as: + AVP: l=22 t=user-Name(1): [email protected] + AVP: l=17 t=Calling-Station-Id(31): ABCDEFG
etc.
Is there a way to use tshark to output these name value pairs as text?
e.g. row 1 user-name [email protected] Calling-Station-Id ABCDEFG
Thanks in advance.
tsharkasked 18 Nov &#39;10, 07:52</description>
    </item>
    
    <item>
      <title>Capture Filter with TZSP</title>
      <link>/questions/1016/capture-filter-with-tzsp/</link>
      <pubDate>Thu, 18 Nov 2010 14:28:00 +0000</pubDate>
      
      <guid>/questions/1016/capture-filter-with-tzsp/</guid>
      <description>Capture Filter with TZSP  0 Hi Wiresharkers!
I am streaming TZSP from my router to my wireshark server, the problem happens when I set the capture filter, it sees the src ip of the router only, I want to filter according to the host ip which is encapsulated within the TZSP packet.
any ideas please
Mike
tzspasked 18 Nov &#39;10, 14:28
Mike
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Bandwidth parameters</title>
      <link>/questions/1017/bandwidth-parameters/</link>
      <pubDate>Thu, 18 Nov 2010 15:37:00 +0000</pubDate>
      
      <guid>/questions/1017/bandwidth-parameters/</guid>
      <description>Bandwidth parameters  0 What effect does the increase and decrease in frame size, packet size, delay and data rate have upon bandwidth?
bandwidth frame packet sizeasked 18 Nov &#39;10, 15:37
adhikaa1
6●2●2●3
accept rate: 0%
That all depends on the medium and protocol you&#39;re using.
(18 Nov &#39;10, 22:25) Jaap ♦  
One Answer:
  
0Well, first of all you usually have a fixed bandwidth on your way from A to B, and the slowest link counts, because it is the limiting factor.</description>
    </item>
    
    <item>
      <title>trigger a script</title>
      <link>/questions/1019/trigger-a-script/</link>
      <pubDate>Fri, 19 Nov 2010 02:38:00 +0000</pubDate>
      
      <guid>/questions/1019/trigger-a-script/</guid>
      <description>trigger a script  0 1Dear all,
Is it possible to use a packet filter to trigger a shell script?
For example: I have a continuous incoming UDP stream with &#34;0&#34; as data. When it becomes &#34;1&#34; I want to run a shell command.
I want to run this as a service.
Best regards, Koen
filter shell trigger scriptasked 19 Nov &#39;10, 02:38
KoenJ
1●1●2●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>camel.EntityReleased</title>
      <link>/questions/1022/camelentityreleased/</link>
      <pubDate>Fri, 19 Nov 2010 08:24:00 +0000</pubDate>
      
      <guid>/questions/1022/camelentityreleased/</guid>
      <description>camel.EntityReleased  0 What is the correct format for the entity released camel function? The 3GPP document says it should be: Entity released
 -&amp;gt;Call Segment Failure -&amp;gt;CallSegmentID -&amp;gt;Cause -&amp;gt;BCSM Failure -&amp;gt;LegID -&amp;gt;CauseBut this causes a &#39;BER Error - This field lies beyond the end of the known sequence definition&#39; message. I&#39;ve seen references elsewhere saying that entityReleased is boolean. Any help would be appreciated!
ber camel entityreleased error formatasked 19 Nov &#39;10, 08:24</description>
    </item>
    
    <item>
      <title>FIX Protocol dissector</title>
      <link>/questions/1023/fix-protocol-dissector/</link>
      <pubDate>Fri, 19 Nov 2010 08:56:00 +0000</pubDate>
      
      <guid>/questions/1023/fix-protocol-dissector/</guid>
      <description>FIX Protocol dissector  0 Good day. I need to extract data from the FIX protocol dissector(included in Wireshark) by using the LUA scripting. So I&#39;m able to get all static fields by using extractor variable(for example, fe_FIX_MsgType = Field.new(&#34;fix.MsgType&#34;) ). But I found a problem while trying to extract all the fields of FIX protocol of such message type as Market Data - Snapshot / Full Refresh, where field NoMDEntries is dynamically changing and represents the number of next following fields.</description>
    </item>
    
    <item>
      <title>Microsoft Exchange 2007</title>
      <link>/questions/1026/microsoft-exchange-2007/</link>
      <pubDate>Fri, 19 Nov 2010 10:40:00 +0000</pubDate>
      
      <guid>/questions/1026/microsoft-exchange-2007/</guid>
      <description>Microsoft Exchange 2007  0 How do I capture and filter Microsoft Exchange 2007 traffic coming from the MX server to my desktop? I have Wireshark on my box.
mail trafficasked 19 Nov &#39;10, 10:40
Delfino
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Open the capture dialog box and use this as your filter &#34;host 1.1.1.1 or host 2.2.2.2 or host 3.3.3.3&#34; where 1.1.1.1 is your exchange server, 2.</description>
    </item>
    
    <item>
      <title>giop decoding skipped?</title>
      <link>/questions/1028/giop-decoding-skipped/</link>
      <pubDate>Fri, 19 Nov 2010 15:00:00 +0000</pubDate>
      
      <guid>/questions/1028/giop-decoding-skipped/</guid>
      <description>giop decoding skipped?  0 In WireShark 1.4.2 I&#39;m trying to create pcap dumps of GIOP data so I can peer into the giop details more easily.
I&#39;m starting with a hex dump, converted to pcap with: text2pcap -o dec -T 50,60 c:out.txt c:out.pcap
(out.txt is at the end of this message for reference)
And opening the resulting pcap file in WireShark everything down to the TCP frame looks OK except that the payload isn&#39;t displayed, not even as raw data.</description>
    </item>
    
    <item>
      <title>How can we set up wireshark to display all Devices connected to our Netork (Router)</title>
      <link>/questions/1030/how-can-we-set-up-wireshark-to-display-all-devices-connected-to-our-netork-router/</link>
      <pubDate>Fri, 19 Nov 2010 21:54:00 +0000</pubDate>
      
      <guid>/questions/1030/how-can-we-set-up-wireshark-to-display-all-devices-connected-to-our-netork-router/</guid>
      <description>How can we set up wireshark to display all Devices connected to our Netork (Router)  0 Wondering a Couple of things
1) How do we set up Wireshark to display all devices connected to Router, directly or By wi-fi
2) Once the devices are all displayed, can we set it up so that not only are the Packets captured but the Destination IP is displayed?
I have looked around viewed Videos but have found no info on that yet</description>
    </item>
    
    <item>
      <title>decrypting SSL packets on Chromium or Opera does not work?</title>
      <link>/questions/1038/decrypting-ssl-packets-on-chromium-or-opera-does-not-work/</link>
      <pubDate>Sat, 20 Nov 2010 09:03:00 +0000</pubDate>
      
      <guid>/questions/1038/decrypting-ssl-packets-on-chromium-or-opera-does-not-work/</guid>
      <description>decrypting SSL packets on Chromium or Opera does not work?  0 I seem to be able to decrypt SSL sessions by following the http://wiki.wireshark.org/SSL HOWTO for Safari, but not for Opera or Chrome. To test this I have a very simple java server available at https://github.com/bblfish/TLS_test
I posted a bug report on this https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5423
Go and vote for that bug. It&#39;s important for the web if it is going to be secure and allow us to have https everywhere that Wireshark function well on all browsers.</description>
    </item>
    
    <item>
      <title>Failed at emulating browser&amp;#x27;s packets</title>
      <link>/questions/1039/failed-at-emulating-browsers-packets/</link>
      <pubDate>Sat, 20 Nov 2010 09:09:00 +0000</pubDate>
      
      <guid>/questions/1039/failed-at-emulating-browsers-packets/</guid>
      <description>Failed at emulating browser&amp;rsquo;s packets  0 Hi,
I&#39;m writing a program with raw-sockets and i&#39;m trying to emulate my browser&#39;s &#34;syn&#34; packets to a socks server. My program&#39;s packets and my browser&#39;s packets are almost alike, but the socks server answers only my browser&#39;s packets and not my generated packets. My browser sends 5 or 3 syns (with no or very little delay between each of them), and then the socks server sends the &#34;</description>
    </item>
    
    <item>
      <title>How to decode private protocol?</title>
      <link>/questions/1046/how-to-decode-private-protocol/</link>
      <pubDate>Sun, 21 Nov 2010 01:46:00 +0000</pubDate>
      
      <guid>/questions/1046/how-to-decode-private-protocol/</guid>
      <description>How to decode private protocol?  0 Hello, I am debugging our system composed of two TCP/IP stations that use a private protocol over TCP. The protocol message formats are well documented. I would like to &#34;teach&#34; (or customize) wireshark so that it can display these messages according to the message formats. ( I do not know if you call it: dissect/decode /parse). Is it possible and how?
PS: I have successfully used filters by searching specific opcode inside our TCP payload data.</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t capture network traffic</title>
      <link>/questions/1048/cant-capture-network-traffic/</link>
      <pubDate>Sun, 21 Nov 2010 08:06:00 +0000</pubDate>
      
      <guid>/questions/1048/cant-capture-network-traffic/</guid>
      <description>can&amp;rsquo;t capture network traffic  1 Hi all
i&#39;m pretty new to all of this network profiling/sniffing and i will appriciate any help.
first, I&#39;ll detail my system: dell studio 1749 laptop,running Win 7 x64 home premuime. wireless card is Intel centrino 6200.
I&#39;m running the wireshark from the laptop and i&#39;m able to watch my own traffic. can&#39;t see all the network traffic.
what can be the reason for that?</description>
    </item>
    
    <item>
      <title>REALTEK RTL8187 USB EXTERNAL WIRELESS ADAPTER</title>
      <link>/questions/1049/realtek-rtl8187-usb-external-wireless-adapter/</link>
      <pubDate>Sun, 21 Nov 2010 08:59:00 +0000</pubDate>
      
      <guid>/questions/1049/realtek-rtl8187-usb-external-wireless-adapter/</guid>
      <description>REALTEK RTL8187 USB EXTERNAL WIRELESS ADAPTER  0 Hi, just new in the forum , I have a Toshiba laptop with a external REALTEK RTL8187 USB EXTERNAL WIRELESS ADAPTER , when I start Wireshark I receive the following message : Please check that &#34;DeviceNPF_{FF58589B-5BF6-4A78-988F-87B508471370}&#34; is the proper interface.
Would like to ask for help on this matter, is this a compatibility issue ?
rtl8187 realtek usbasked 21 Nov &#39;10, 08:59</description>
    </item>
    
    <item>
      <title>Why is my pc exchanging packets with Facebook? i don&amp;#x27;t have a Facebook account?</title>
      <link>/questions/1050/why-is-my-pc-exchanging-packets-with-facebook-i-dont-have-a-facebook-account/</link>
      <pubDate>Sun, 21 Nov 2010 13:15:00 +0000</pubDate>
      
      <guid>/questions/1050/why-is-my-pc-exchanging-packets-with-facebook-i-dont-have-a-facebook-account/</guid>
      <description>Why is my pc exchanging packets with Facebook? i don&amp;rsquo;t have a Facebook account?  0 I noticed that my pc is exchanging packets with Facebook. I don&#39;t have a Facebook account, and I haven&#39;t even visited their website. Why is this happening?
rwasked 21 Nov &#39;10, 13:15
RW15
1●1●1●1
accept rate: 0%
Are you sure you don&#39;t have some toolbar or other add-in&#39;s that checks in with Facebook?
(21 Nov &#39;10, 21:25) hansangb1Were you surfing at the time of the capture?</description>
    </item>
    
    <item>
      <title>Traffic from all other PC to router</title>
      <link>/questions/1051/traffic-from-all-other-pc-to-router/</link>
      <pubDate>Sun, 21 Nov 2010 15:44:00 +0000</pubDate>
      
      <guid>/questions/1051/traffic-from-all-other-pc-to-router/</guid>
      <description>Traffic from all other PC to router  0 There is two type of packets in the wifi network traffic, in one the source is one PC and the destination is a wifi router, in the other one the source is the router and the destination is the PC. In my case I have a wifi card in promiscous mode and when I start tpcdump or wireshark I can see the traffic from router to my PC and from the router to all other PC but I can&#39;t see the traffic from all other PC to router wifi, why?</description>
    </item>
    
    <item>
      <title>How to calculate R factor using Wirshark?</title>
      <link>/questions/1053/how-to-calculate-r-factor-using-wirshark/</link>
      <pubDate>Sun, 21 Nov 2010 19:25:00 +0000</pubDate>
      
      <guid>/questions/1053/how-to-calculate-r-factor-using-wirshark/</guid>
      <description>How to calculate R factor using Wirshark?  0 Hi,
I wanna run a small experiment using Asterisk server and Mizuphone as a client then analyze VoIP QoS. can any one help telling me how to calculate R-factor using wireshark?
Thanks in advance.
voip r-factor wiresharkasked 21 Nov &#39;10, 19:25
observer
1●1●1●1
accept rate: 0%
 edited 28 Feb &#39;12, 20:16 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:</description>
    </item>
    
    <item>
      <title>License of dissectors written in Lua?</title>
      <link>/questions/1059/license-of-dissectors-written-in-lua/</link>
      <pubDate>Mon, 22 Nov 2010 06:40:00 +0000</pubDate>
      
      <guid>/questions/1059/license-of-dissectors-written-in-lua/</guid>
      <description>License of dissectors written in Lua?  1 I started developing some dissectors in Lua for a non public communication protocol for a commercial product. According to discussions some time ago on the wireshark-dev mailing list (e.g. [Wireshark-dev] wireshark dissector and GPL) you&#39;ll have to apply the GPL to your dissector, but I assume topic of the discussion was a dissector written in C. Does this also apply to dissectors written in Lua?</description>
    </item>
    
    <item>
      <title>Log File Location</title>
      <link>/questions/1060/log-file-location/</link>
      <pubDate>Mon, 22 Nov 2010 07:18:00 +0000</pubDate>
      
      <guid>/questions/1060/log-file-location/</guid>
      <description>Log File Location  0 I&#39;m trying to catch an intermitant problem we think may be a broadcast storm. My first task is finding the log file. Where does wireshark put it?
My next task is to automatically delete before it gets to big and then start the log again. Is there anything premade for something like that?
Network of 80 machines, random network lockup anywhere from 1-30 sec for all machines at the same time.</description>
    </item>
    
    <item>
      <title>about RTP .raw file</title>
      <link>/questions/1062/about-rtp-raw-file/</link>
      <pubDate>Mon, 22 Nov 2010 07:28:00 +0000</pubDate>
      
      <guid>/questions/1062/about-rtp-raw-file/</guid>
      <description>about RTP .raw file  0 Hi, I captured some telephony call packets using wireshark. The RTP payload types include PCMU and CN(comfort noise) I can play the voice packets using wireshark-&amp;gt;VOIP However,It is not possible to save the payload as .au files using wireshark-&amp;gt;RTP and I can only save them as .raw files. When I play the .raw files using goldwave, the sound is in a mess. what is wrong with the .</description>
    </item>
    
    <item>
      <title>Dumpcap syntax error</title>
      <link>/questions/1069/dumpcap-syntax-error/</link>
      <pubDate>Mon, 22 Nov 2010 13:16:00 +0000</pubDate>
      
      <guid>/questions/1069/dumpcap-syntax-error/</guid>
      <description>Dumpcap syntax error  0 dumpcap -i 1 -f &#34;ip.addr == 192.168.11.61&#34; -b files:500 -b filesize:30000 -w textcap.pcap, error is string is not a valid capture filter. What is wrong with the string?
dumpcapasked 22 Nov &#39;10, 13:16
qs_tech_support
1●1●1●1
accept rate: 0%
  
One Answer:
  
3What&#39;s wrong is that it&#39;s a display filter, not a capture filter; capture filters are implemented by libpcap/WinPcap, and have a different syntax from display filters.</description>
    </item>
    
    <item>
      <title>Who is downloading on my network?</title>
      <link>/questions/1075/who-is-downloading-on-my-network/</link>
      <pubDate>Tue, 23 Nov 2010 02:27:00 +0000</pubDate>
      
      <guid>/questions/1075/who-is-downloading-on-my-network/</guid>
      <description>Who is downloading on my network?  0 Hi,
Is there anyway that I can find out who download in my network. I need to know the name or the IP address Of the device that does all the downloads.
If you can help me I really appreciate that and big help
Thanks,
networkasked 23 Nov &#39;10, 02:27
Rosta
1●1●1●1
accept rate: 0%
  
3 Answers:</description>
    </item>
    
    <item>
      <title>Write my own protocoll in lua for a packet stream</title>
      <link>/questions/1078/write-my-own-protocoll-in-lua-for-a-packet-stream/</link>
      <pubDate>Tue, 23 Nov 2010 06:34:00 +0000</pubDate>
      
      <guid>/questions/1078/write-my-own-protocoll-in-lua-for-a-packet-stream/</guid>
      <description>Write my own protocoll in lua for a packet stream  0 Hi everybody, i wrote my own lua dissector for packets up to the max size of 1440 Bytes. But I would like to capture bigger data packets (e.g. 12k) which a splittet in smaller packets.
Is this possible to write a protocoll which capture more than one packet and put these into one &#34;virtuell&#34; big? If the answer is yes please give me a hint where I can find it or how I can do that.</description>
    </item>
    
    <item>
      <title>All Protocols Unknown</title>
      <link>/questions/1080/all-protocols-unknown/</link>
      <pubDate>Tue, 23 Nov 2010 08:45:00 +0000</pubDate>
      
      <guid>/questions/1080/all-protocols-unknown/</guid>
      <description>All Protocols Unknown  0 When I run Wireshark (1.4.2) I never see any packets on my LAN, I just get packet after packet of unknown protocol where WTAP_ENCAP=1. I am connected to a Cisco 2950 Cat switch.
I tried capturing via my WLAN connection and got the same result.
I have the latest version of WinPCAP.
THoughts?
unknown protocolasked 23 Nov &#39;10, 08:45
MIke65
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Man in the middle attack on broadband</title>
      <link>/questions/1081/man-in-the-middle-attack-on-broadband/</link>
      <pubDate>Tue, 23 Nov 2010 10:03:00 +0000</pubDate>
      
      <guid>/questions/1081/man-in-the-middle-attack-on-broadband/</guid>
      <description>Man in the middle attack on broadband  0 How do I set up Wireshark to capture man in the middle attacks on broadband service like cablemodem or dsl
man-in-the-middleasked 23 Nov &#39;10, 10:03
Martok
1●1●1●1
accept rate: 0%
 edited 29 Feb &#39;12, 19:00 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
0There isn&#39;t an easy answer for this. What kind of MITM attacks are you worried about?</description>
    </item>
    
    <item>
      <title>How to quickly prepare a Display filter like &amp;quot;ip.addr == x.x.x.x&amp;quot; ? (solved)</title>
      <link>/questions/1084/how-to-quickly-prepare-a-display-filter-like-ipaddr-xxxx-solved/</link>
      <pubDate>Tue, 23 Nov 2010 10:42:00 +0000</pubDate>
      
      <guid>/questions/1084/how-to-quickly-prepare-a-display-filter-like-ipaddr-xxxx-solved/</guid>
      <description>How to quickly prepare a Display filter like &amp;ldquo;ip.addr == x.x.x.x&amp;rdquo; ? (solved)  1 While displaying an interesting packet, it is often needed to filter all traffic on an IP address, but not only as source or destination as the right-click filtering permits in the main GUI window.
Actually, I prepare a filter like ip.src == x.x.x.x then replace src by addr to get what all traffic to/from this host.</description>
    </item>
    
    <item>
      <title>Help diagnosing PPTP throughput issue.</title>
      <link>/questions/1087/help-diagnosing-pptp-throughput-issue/</link>
      <pubDate>Tue, 23 Nov 2010 12:02:00 +0000</pubDate>
      
      <guid>/questions/1087/help-diagnosing-pptp-throughput-issue/</guid>
      <description>Help diagnosing PPTP throughput issue.  0 Have an Intel Mac 10.6.5. When I Remote Desktop via PPTP to a W2K3 server my throughput is atrocious. When I VPN using same credentials and network via a Slower Vista Business machine everything is speedy (10x faster). Using Wireshark to attempt to determine issue. Fixed a small MTU mismatch and get these occasionally in the trace (maybe 10-15%)
[TCP Retranmission] [TCP segment of a reassembled PDU] AND [TCP Dup ACK etc.</description>
    </item>
    
    <item>
      <title>Monitor traffic to another IP</title>
      <link>/questions/1089/monitor-traffic-to-another-ip/</link>
      <pubDate>Tue, 23 Nov 2010 14:43:00 +0000</pubDate>
      
      <guid>/questions/1089/monitor-traffic-to-another-ip/</guid>
      <description>Monitor traffic to another IP  0 I need a tool to log Ethernet based Modbus TCP transactions to/from a specific IP address different than the PC running Wireshark. Can I do this with Wireshark and can you point me to someone that can push me off in the right direction after I&#39;ve downloaded Wireshark?
modbus ethernet traffic logasked 23 Nov &#39;10, 14:43
chuckh
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Filter Apparently Doesn&amp;#x27;t Support Host Name format for Address</title>
      <link>/questions/1090/filter-apparently-doesnt-support-host-name-format-for-address/</link>
      <pubDate>Tue, 23 Nov 2010 16:26:00 +0000</pubDate>
      
      <guid>/questions/1090/filter-apparently-doesnt-support-host-name-format-for-address/</guid>
      <description>Filter Apparently Doesn&amp;rsquo;t Support Host Name format for Address  1 The documentation states that this filter will work: ip.dst eq www.mit.edu
But when I try to use it, Wireshark gives me an error &#39; &#34;www.mit.edu&#34; is not a valid hostname or IPv4 address&#39;
I cut-and-pasted the sample into the filter, so I expected it to work!
hostname filtersasked 23 Nov &#39;10, 16:26
ActualRandy
46●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Why Doesn&amp;#x27;t This Filter Work?</title>
      <link>/questions/1093/why-doesnt-this-filter-work/</link>
      <pubDate>Tue, 23 Nov 2010 16:50:00 +0000</pubDate>
      
      <guid>/questions/1093/why-doesnt-this-filter-work/</guid>
      <description>Why Doesn&amp;rsquo;t This Filter Work?  2 I want to see results where neither the destination, nor the source are the specified address; here is my filter. ip.src != 192.168.1.119 &amp;amp;&amp;amp; ip.dst != 192.168.1.119
To my surprise, it returns some results with the that IP, such as this one: 157 238.065591 192.168.1.1 192.168.1.119 ICMP Destination unreachable (Port unreachable)
The destination on this result is clearly one the filter should have blocked.</description>
    </item>
    
    <item>
      <title>long period capture</title>
      <link>/questions/1107/long-period-capture/</link>
      <pubDate>Wed, 24 Nov 2010 08:02:00 +0000</pubDate>
      
      <guid>/questions/1107/long-period-capture/</guid>
      <description>long period capture  0 Hello
I use wireshark to register data exchanged on a network (UDP data). I would like to capture data during a long period (3hours, knowing that a 5minutes capture gives a 800Mo of registered data). Problem is that wireshark does not manage to treat such a size of data: is there a PC or wireshark upgrade that could solve problem ? what do you suggest ?</description>
    </item>
    
    <item>
      <title>snow leopard</title>
      <link>/questions/1108/snow-leopard/</link>
      <pubDate>Wed, 24 Nov 2010 08:06:00 +0000</pubDate>
      
      <guid>/questions/1108/snow-leopard/</guid>
      <description>snow leopard  0 I have a new mac, and i am trying to set up this. It keeps asking me for an interface. I have no idea where to get it or even where to start it. The setup instructions see to be a bit vague.
interfacesasked 24 Nov &#39;10, 08:06
goofnoff2
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>VERY Novis User - Question</title>
      <link>/questions/1110/very-novis-user-question/</link>
      <pubDate>Wed, 24 Nov 2010 09:47:00 +0000</pubDate>
      
      <guid>/questions/1110/very-novis-user-question/</guid>
      <description>VERY Novis User - Question  0 My Q:
On my first overall use I chose to view tcp vs http. Wondering what this might mean:
It says: Who has (xyz IP address)? tell (my IP address)
Source: dellpcba_f5:75:85 - destination: broadcast - protocol: ARP second: Source: Cisco_eb:db:dd - DellPcba_f5:75:85 - Protocol: ARP
Then it says: xyz IP address is @ 00:14:f1:eb:db:dd
Thank you.
question http-tcpasked 24 Nov &#39;10, 09:47</description>
    </item>
    
    <item>
      <title>GTP dissector decoding the Data Record Packets</title>
      <link>/questions/1111/gtp-dissector-decoding-the-data-record-packets/</link>
      <pubDate>Wed, 24 Nov 2010 10:48:00 +0000</pubDate>
      
      <guid>/questions/1111/gtp-dissector-decoding-the-data-record-packets/</guid>
      <description>GTP dissector decoding the Data Record Packets  0 Looking for a GTP dissector that is able to decode the Data Record Packets.
-Mike
gtpasked 24 Nov &#39;10, 10:48
mby
1●1●1●1
accept rate: 0%
Hi, I don&#39;t think there is one, if you&#39;re willing to share a trace and the record is in a 3GPP standardised format you could open up an enhancment bug request and add the trace and some one might make a dissector.</description>
    </item>
    
    <item>
      <title>Wireshark on osx 10.5 prompts to install X11 for osx 10.3 even though X11 already installed</title>
      <link>/questions/1114/wireshark-on-osx-105-prompts-to-install-x11-for-osx-103-even-though-x11-already-installed/</link>
      <pubDate>Wed, 24 Nov 2010 12:14:00 +0000</pubDate>
      
      <guid>/questions/1114/wireshark-on-osx-105-prompts-to-install-x11-for-osx-103-even-though-x11-already-installed/</guid>
      <description>Wireshark on osx 10.5 prompts to install X11 for osx 10.3 even though X11 already installed  1 I just downloaded the latest wireshark for osx.
When I try to launch it, I get a message &#34;Failed to start X11. Wireshark.app requires Apples X11, which is freely downloadable from Apples website for Panther (10.3.x) and available as an optional install from the installation DVD for Tiger (10.4.x) users.&#34;
Then there is a button &#34;</description>
    </item>
    
    <item>
      <title>L2TP messege capture</title>
      <link>/questions/1115/l2tp-messege-capture/</link>
      <pubDate>Wed, 24 Nov 2010 15:30:00 +0000</pubDate>
      
      <guid>/questions/1115/l2tp-messege-capture/</guid>
      <description>L2TP messege capture  0 How can i see messeges (etc sccrq, scccn,icrq, icrp...) send by l2tp clients in wireshark? l2tp/ipsec connection is established between 2 windows machines (both windows server 2003), in captured i can see ikev1 negotiate, ppp negotiate but i cant see l2tp messeges, i&#39;m using wireshark v1.4.0
l2tpasked 24 Nov &#39;10, 15:30
makaraka
1●1●1●3
accept rate: 0%
  
2 Answers:
  
1I would assume these to be inside the IPSec tunnel.</description>
    </item>
    
    <item>
      <title>HTTP filter &amp;quot;Content-Encoding: gzip&amp;quot;</title>
      <link>/questions/1116/http-filter-content-encoding-gzip/</link>
      <pubDate>Wed, 24 Nov 2010 17:06:00 +0000</pubDate>
      
      <guid>/questions/1116/http-filter-content-encoding-gzip/</guid>
      <description>HTTP filter &amp;ldquo;Content-Encoding: gzip&amp;rdquo;  1 Can you please put together a short tutorial showing how this is used on a Windows O/S. &#34;Uncompress entity bodies&#34; does not appear to do anything
gzip entity bodies uncompressasked 24 Nov &#39;10, 17:06
tinywizard
16●1●1●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>ntp time format question</title>
      <link>/questions/1117/ntp-time-format-question/</link>
      <pubDate>Thu, 25 Nov 2010 02:02:00 +0000</pubDate>
      
      <guid>/questions/1117/ntp-time-format-question/</guid>
      <description>ntp time format question  0 In wireshark you get back a Transmit &amp;amp; receive timestamp in the format Jul 14, 2008 14:20:52.3856 UTC almost everything is self explanatory but what does the .3856 represent ? Thanks Barry
ntpasked 25 Nov &#39;10, 02:02
Barry
1●1●1●1
accept rate: 0%
  
One Answer:
  
0The .3856 represent 0.3856 seconds to enhance the resolution of the time stamp. If the resolution was only 1 second, then the clocks would not get synchronized very precisely.</description>
    </item>
    
    <item>
      <title>How do I merge about 50 pcap files into one pcap?</title>
      <link>/questions/1124/how-do-i-merge-about-50-pcap-files-into-one-pcap/</link>
      <pubDate>Thu, 25 Nov 2010 12:24:00 +0000</pubDate>
      
      <guid>/questions/1124/how-do-i-merge-about-50-pcap-files-into-one-pcap/</guid>
      <description>How do I merge about 50 pcap files into one pcap?  0 I used the Mergcap command and it does not seem to take *.pcap as the input for multiple files. Is that a Mergcap limitation?
mergcapasked 25 Nov &#39;10, 12:24
jambomj
16●1●1●4
accept rate: 0%
 edited 25 Nov &#39;10, 16:49 
  
4 Answers:
  
2Does this thread help you? merging many files using mergecap</description>
    </item>
    
    <item>
      <title>How can I capture 3g usb modem packets?</title>
      <link>/questions/1128/how-can-i-capture-3g-usb-modem-packets/</link>
      <pubDate>Thu, 25 Nov 2010 14:46:00 +0000</pubDate>
      
      <guid>/questions/1128/how-can-i-capture-3g-usb-modem-packets/</guid>
      <description>How can I capture 3g usb modem packets?  1 Hi, I want to capture packets from a 3g usb modem via wireshark. Currently I am unable to view the usb modem in the Interface list. Is there any way or workaround by which I can let wireshark identify the usb modem and capture packets from it. Thanks
modem 3g usbasked 25 Nov &#39;10, 14:46
mayank1love
16●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>capture outgoing and/or incoming email</title>
      <link>/questions/1129/capture-outgoing-andor-incoming-email/</link>
      <pubDate>Fri, 26 Nov 2010 06:25:00 +0000</pubDate>
      
      <guid>/questions/1129/capture-outgoing-andor-incoming-email/</guid>
      <description>capture outgoing and/or incoming email  0 how can I capture an outgoing or incoming email by the emailadress?
thanks
capture-filterasked 26 Nov &#39;10, 06:25
kurtw
1●1●1●2
accept rate: 0%
I don&#39;t think you can do it easily w/o resorting to a complicated capture filter that looks for specific characters at certain offsets. And that won&#39;t even work reliably unless the emails are being sent individually.
(26 Nov &#39;10, 09:08) hansangb</description>
    </item>
    
    <item>
      <title>Wireless Capture on Vista 64</title>
      <link>/questions/1130/wireless-capture-on-vista-64/</link>
      <pubDate>Fri, 26 Nov 2010 08:06:00 +0000</pubDate>
      
      <guid>/questions/1130/wireless-capture-on-vista-64/</guid>
      <description>Wireless Capture on Vista 64  0 Using windows Vista 64 bit
have a dell wireless wlan card 1510
i have winacap and airpcap but still my wireless button is disabled.
NOW WHAT??
Kal
wlanasked 26 Nov &#39;10, 08:06
Kal
1●1●1●1
accept rate: 0%
 edited 27 Nov &#39;10, 14:35 
lchappell ♦
1.2k●2●7●30
Kal - I edited your title for clarity -
What &#34;wireless button&#34; are you referring to? Do you mean the Wireless toolbar?</description>
    </item>
    
    <item>
      <title>Convert pcap data to binary for testbench</title>
      <link>/questions/1131/convert-pcap-data-to-binary-for-testbench/</link>
      <pubDate>Fri, 26 Nov 2010 08:34:00 +0000</pubDate>
      
      <guid>/questions/1131/convert-pcap-data-to-binary-for-testbench/</guid>
      <description>Convert pcap data to binary for testbench  0 Hi,
I&#39;m trying to convert a pcap file to binary for use in testing in a new product, I&#39;m working on. I figured the best thing to do was
1...save the file in a .k12 text file, where I get the following format of text file...
+---------+---------------+----------+ 09:19:40,736,392 ETHER |0 |00|05|47|02|99|c6|00|03|fa| ........etc etc
2...I parse this text file using a perl script to get 00 05 47 02 99 c6 00 03 fa .</description>
    </item>
    
    <item>
      <title>Jitter for RTP stream shown as 0</title>
      <link>/questions/1142/jitter-for-rtp-stream-shown-as-0/</link>
      <pubDate>Sat, 27 Nov 2010 23:24:00 +0000</pubDate>
      
      <guid>/questions/1142/jitter-for-rtp-stream-shown-as-0/</guid>
      <description>Jitter for RTP stream shown as 0  0 The captured RTP stream&#39;s analysis shows the following:
Max delta = 0.00 ms at packet no. 0 Max jitter = 0.00 ms. Mean jitter = 0.00 ms. Max skew = 0.00 ms.Do you think this is wrong? How can I verify the jitter by looking at the individual packet latencies?
stream rtp analysisasked 27 Nov &#39;10, 23:24
skypemesm
46●6●6●9
accept rate: 0%</description>
    </item>
    
    <item>
      <title>just loaded wireshark</title>
      <link>/questions/1144/just-loaded-wireshark/</link>
      <pubDate>Sun, 28 Nov 2010 19:28:00 +0000</pubDate>
      
      <guid>/questions/1144/just-loaded-wireshark/</guid>
      <description>just loaded wireshark  0 i just loaded wireshark, and have problems using it.
when i launch the program, it opens too high on the screen. the title bar, and the top 90% of the window is above my screen. if i try to use &#39;move&#39;, &#39;restore&#39; or maximize they don&#39;t work. i couldn&#39;t find a .ini file, and struck out looking in the registry.
how do i move the window so i can use it?</description>
    </item>
    
    <item>
      <title>How can I put Wireshark log in excel?</title>
      <link>/questions/1145/how-can-i-put-wireshark-log-in-excel/</link>
      <pubDate>Mon, 29 Nov 2010 00:20:00 +0000</pubDate>
      
      <guid>/questions/1145/how-can-i-put-wireshark-log-in-excel/</guid>
      <description>How can I put Wireshark log in excel?  0 Hello, I want to put Wireshark logs in excel. But I can&#39;t see any feature about this. Is it possible and how?
excel logasked 29 Nov &#39;10, 00:20
Burcu Sara
1●2●2●2
accept rate: 0%
  
2 Answers:
  
1You mean the packet list as an excel file, with all the columns as configured? Go to File -&amp;gt; Export -&amp;gt; File and select a file name and &#34;</description>
    </item>
    
    <item>
      <title>Can I take specific log in data field (46-1500)?</title>
      <link>/questions/1146/can-i-take-specific-log-in-data-field-46-1500/</link>
      <pubDate>Mon, 29 Nov 2010 00:32:00 +0000</pubDate>
      
      <guid>/questions/1146/can-i-take-specific-log-in-data-field-46-1500/</guid>
      <description>Can I take specific log in data field (46-1500)?  0 Hello, I want to take logs in data field, so I must define boundary. Forexample, Log starts between 46 bytes and 800 bytes. Is is possible and how?
specific field 46-1500 data logThis question is marked &#34;community wiki&#34;.asked 29 Nov &#39;10, 00:32
Burcu Sara
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Colorize with Filter problem</title>
      <link>/questions/1147/colorize-with-filter-problem/</link>
      <pubDate>Mon, 29 Nov 2010 01:43:00 +0000</pubDate>
      
      <guid>/questions/1147/colorize-with-filter-problem/</guid>
      <description>Colorize with Filter problem  0 Can someone confirm that &#34;Colorize with Filter&#34; does not colorize all captured packets as expected in Wireshark 1.4.x (it works well in Wireshark 1.2.11). I have tested it with Windows 32 and 64 bit Versions on multiple PCs. To reproduce capture some tcp traffic. Then open the context menu on a source port in the packet details pane and select a color under &#34;Colorize with Filter&#34;</description>
    </item>
    
    <item>
      <title>Get message sent using the &amp;quot;SUBMIT&amp;quot; button</title>
      <link>/questions/1153/get-message-sent-using-the-submit-button/</link>
      <pubDate>Mon, 29 Nov 2010 08:07:00 +0000</pubDate>
      
      <guid>/questions/1153/get-message-sent-using-the-submit-button/</guid>
      <description>Get message sent using the &amp;ldquo;SUBMIT&amp;rdquo; button  0 I am trying to automate the process of getting the nine digit zip code from the US Postal service web site (http://zip4.usps.com/zip4/welcome.jsp)
To do so I need the message sent when I click on the Submit button at that site. Is this a facility provided by WireShark?
Thanks,
Jim
post messages getasked 29 Nov &#39;10, 08:07
Jim
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Locally installed wireshark misses two packets</title>
      <link>/questions/1161/locally-installed-wireshark-misses-two-packets/</link>
      <pubDate>Mon, 29 Nov 2010 13:11:00 +0000</pubDate>
      
      <guid>/questions/1161/locally-installed-wireshark-misses-two-packets/</guid>
      <description>Locally installed wireshark misses two packets  0 Very strange behavior between Win7 and W2k3. From Win7 \&amp;lt;servername&amp;gt; and the wireshark on that workstation does not capture the session setup request. A laptop running wireshark on a span port of the Win7 device does see the session setup request packets. This coincides with a significant delay in actually seeing the shares on the server.
There are lots of theories and work arounds for the issue, but they don&#39;t seem to change that the setup request packet is missed by wireshark but is put on the wire.</description>
    </item>
    
    <item>
      <title>Voip calls Player button missing in OSX version 1.4</title>
      <link>/questions/1165/voip-calls-player-button-missing-in-osx-version-14/</link>
      <pubDate>Mon, 29 Nov 2010 14:02:00 +0000</pubDate>
      
      <guid>/questions/1165/voip-calls-player-button-missing-in-osx-version-14/</guid>
      <description>Voip calls Player button missing in OSX version 1.4  0 Where has the Player function gone in the Wireshark 1.4.x version for OSX ? I am running OSX 10.6.5 Snow Leopard and the older 32-bit versions do not run as fast as the 64-bit version, but the 1.4 version has no function to play RTP streams. This is indeed a problem.
1.4 player rtp voip decodeasked 29 Nov &#39;10, 14:02</description>
    </item>
    
    <item>
      <title>URGENT: Units of rtp.timestamp and frame.time_relative</title>
      <link>/questions/1170/urgent-units-of-rtptimestamp-and-frametime_relative/</link>
      <pubDate>Mon, 29 Nov 2010 20:38:00 +0000</pubDate>
      
      <guid>/questions/1170/urgent-units-of-rtptimestamp-and-frametime_relative/</guid>
      <description>URGENT: Units of rtp.timestamp and frame.time_relative  0 I am using the fields rtp.timestamp and frame.time_relative for calcualtion of jitter. What are the units of these fields? milliseconds?
rtp calculate timeasked 29 Nov &#39;10, 20:38
skypemesm
46●6●6●9
accept rate: 0%
  
One Answer:
  
0frame.time_relative is in units of seconds; it has a fractional part, so it can have a higher resolution than one second.
As for RTP, to quote RFC 3550, the specification for RTP, &#34;</description>
    </item>
    
    <item>
      <title>Can I convert PCAP file from Wireshark to allow Agilent tool open it?</title>
      <link>/questions/1172/can-i-convert-pcap-file-from-wireshark-to-allow-agilent-tool-open-it/</link>
      <pubDate>Tue, 30 Nov 2010 00:56:00 +0000</pubDate>
      
      <guid>/questions/1172/can-i-convert-pcap-file-from-wireshark-to-allow-agilent-tool-open-it/</guid>
      <description>Can I convert PCAP file from Wireshark to allow Agilent tool open it?  0 I save the tracing file of SS7 - Sigtran from GSM network in PCAP format by Wireshark , But I really need to open it by Agilent tool.
Does it have any tool to convert wireshark PCAP file to any format that Agilent tool can open.
Thanks in advance.
convert agilentasked 30 Nov &#39;10, 00:56</description>
    </item>
    
    <item>
      <title>how do i analysis 802.11n by wireshark,please!</title>
      <link>/questions/1175/how-do-i-analysis-80211n-by-wiresharkplease/</link>
      <pubDate>Tue, 30 Nov 2010 01:22:00 +0000</pubDate>
      
      <guid>/questions/1175/how-do-i-analysis-80211n-by-wiresharkplease/</guid>
      <description>how do i analysis 802.11n by wireshark,please!  0 I want to analysis standard 802.11n by wireshark. Maybe i do not knowledge enough to do it exactly. Can help me do it??? This is an important project with me!
802.11nasked 30 Nov &#39;10, 01:22
haquyen
1●6●6●7
accept rate: 0%
What steps have you taken to understand 802.11n already? Have you captured 802.11n traffic? What is your precise question? (Asking to analyze 802.</description>
    </item>
    
    <item>
      <title>Opening an exported file</title>
      <link>/questions/1176/opening-an-exported-file/</link>
      <pubDate>Tue, 30 Nov 2010 05:51:00 +0000</pubDate>
      
      <guid>/questions/1176/opening-an-exported-file/</guid>
      <description>Opening an exported file  0 Last night I was running some pcaps and wanted to analyze them at school today, so being a noob at wireshark and not seeing an obvious save option in the File menu i went down to export and selected C arrays since i guessed that that would be importable and would be the most specific save. Now today I&#39;m looking around and I don&#39;t see any way to import it into wireshark, I did look at text2pcap but as far as I can tell it doesn&#39;t convert C arrays to pcaps.</description>
    </item>
    
    <item>
      <title>getting more info on TCP packets</title>
      <link>/questions/1177/getting-more-info-on-tcp-packets/</link>
      <pubDate>Tue, 30 Nov 2010 06:31:00 +0000</pubDate>
      
      <guid>/questions/1177/getting-more-info-on-tcp-packets/</guid>
      <description>getting more info on TCP packets  0 I am trying to analyze Wireshark TCP capture in Excel. I&#39;d like to have some TCP info like TSval, TSecr, SACK edges in separate columns but it seems that since these values are stored in TCP options rather than in dedicated TCP header fields Wireshark does not create such custom columns.
I can see these values in the info column but they are shown only for client ACK packets.</description>
    </item>
    
    <item>
      <title>The capture session could not be initiated, please help!!</title>
      <link>/questions/1178/the-capture-session-could-not-be-initiated-please-help/</link>
      <pubDate>Tue, 30 Nov 2010 06:45:00 +0000</pubDate>
      
      <guid>/questions/1178/the-capture-session-could-not-be-initiated-please-help/</guid>
      <description>The capture session could not be initiated, please help!!  0 Hi there, Thanks for reading this. I have a problem capturing packets with my Edimax EW-7711USn, i get this message “The capture session could not be initiated” when i try to capture. I think the edimax is not compatible with WireShark or Winpcap. I cannot find a compatibility NIC list anyware?
Bart, holland
not be could session initiatedasked 30 Nov &#39;10, 06:45</description>
    </item>
    
    <item>
      <title>SMB response terminates comms</title>
      <link>/questions/1182/smb-response-terminates-comms/</link>
      <pubDate>Tue, 30 Nov 2010 10:15:00 +0000</pubDate>
      
      <guid>/questions/1182/smb-response-terminates-comms/</guid>
      <description>SMB response terminates comms  0 I&#39;m having an issue with failed SMB communications and cannot determine the source of the response behavior from a Windows 7 PC. Was hoping that anyone might be able to help.
Here&#39;s the response packet:
No. Time Source Destination Protocol Info 1425 34.647499 192.168.1.74 192.168.1.68 SMB Negotiate Protocol Response
Frame 1425: 475 bytes on wire (3800 bits), 475 bytes captured (3800 bits) Ethernet II, Src: Dell_24:7e:41 (00:21:9b:24:7e:41), Dst: Xerox_c3:73:c7 (00:00:aa:c3:73:c7) Internet Protocol, Src: 192.</description>
    </item>
    
    <item>
      <title>Radius Authentication of Apple devices</title>
      <link>/questions/1183/radius-authentication-of-apple-devices/</link>
      <pubDate>Tue, 30 Nov 2010 11:12:00 +0000</pubDate>
      
      <guid>/questions/1183/radius-authentication-of-apple-devices/</guid>
      <description>Radius Authentication of Apple devices  0 We are authenticating to radius servers with varying degrees of success. When I look at successful authentications, I frequently see Radius Protocol Malformed SSL packet. Each of these packets shows a LEN=1098 sometimes but no always failing the authentication MS-CHAP four way hand shake. Any insight is appreciated. These are Apple Ipad devices that Doctors are carrying into our Hospitals, so we&#39;re somewhat limited to capturing packets from the wireless controllers into the wired network (radius servers etc) since we cant load wireshark on the Apple devices.</description>
    </item>
    
    <item>
      <title>How do I know whether my network is half- or full-duplex?</title>
      <link>/questions/1185/how-do-i-know-whether-my-network-is-half-or-full-duplex/</link>
      <pubDate>Tue, 30 Nov 2010 17:38:00 +0000</pubDate>
      
      <guid>/questions/1185/how-do-i-know-whether-my-network-is-half-or-full-duplex/</guid>
      <description>How do I know whether my network is half- or full-duplex?  0 In Wireshark Network Analysis, Chapter 3 mentions half-duplex and full-duplex networks (and traffic). How can I determine which type of network I&#39;m on?
duplex half-duplex full-duplexasked 30 Nov &#39;10, 17:38
sutch
6●1●1●2
accept rate: 0%
  
One Answer:
  
0 You can&#39;t really tell. If you hard code a switch port side (or the NIC side), it will not send any link pulses used by auto negotiation.</description>
    </item>
    
    <item>
      <title>Why is DSCP always 0 on Windows 7?</title>
      <link>/questions/1188/why-is-dscp-always-0-on-windows-7/</link>
      <pubDate>Wed, 01 Dec 2010 03:19:00 +0000</pubDate>
      
      <guid>/questions/1188/why-is-dscp-always-0-on-windows-7/</guid>
      <description>Why is DSCP always 0 on Windows 7?  0 1Hi!
I know this is not specifically Wireshark problem, but people here are more likely done this themselves.
All packets shows DSCP values being 0x00 (default), how can I get DSCP configurations to work in Windows 7 (x64 pro)?
I have configured them like this:
I&#39;ve been defining QoS policy settings from Group Policy Editor: Computer Configuration -&amp;gt; Windows Settings -&amp;gt; Policy-based QoS (Screenshot)From &#34;</description>
    </item>
    
    <item>
      <title>tshark ring buffer option: milliseconds</title>
      <link>/questions/1189/tshark-ring-buffer-option-milliseconds/</link>
      <pubDate>Wed, 01 Dec 2010 05:33:00 +0000</pubDate>
      
      <guid>/questions/1189/tshark-ring-buffer-option-milliseconds/</guid>
      <description>tshark ring buffer option: milliseconds  0 Hi,
i need to know how can i use ring buffer option with a duration in milliseconds in the help menu there is only the possibility to listen for seconds if it is not possible to do it in this version can you do it for me or at least give an hence how to do it and i will try to change it on the code.</description>
    </item>
    
    <item>
      <title>Get value from protofield</title>
      <link>/questions/1190/get-value-from-protofield/</link>
      <pubDate>Wed, 01 Dec 2010 07:40:00 +0000</pubDate>
      
      <guid>/questions/1190/get-value-from-protofield/</guid>
      <description>Get value from protofield  2 Hello, I&#39;m a recent convert from a C based dissector to Lua to help ease the installation for our Windows users. :)
Is it possible to get the value from a proto field that has already been defined? Or must I grab the data from the buffer? For instance...
foo_proto = Proto(&#34;foo&#34;,&#34;Foo Proto&#34;) local foo = foo_proto.fields foo.pdu = ProtoField.uint8(&#34;foo.pdutype&#34;, &#34;PDU Type&#34;, base.HEX, PDU_TYPES) .</description>
    </item>
    
    <item>
      <title>Scan certain network or IP</title>
      <link>/questions/1194/scan-certain-network-or-ip/</link>
      <pubDate>Wed, 01 Dec 2010 11:27:00 +0000</pubDate>
      
      <guid>/questions/1194/scan-certain-network-or-ip/</guid>
      <description>Scan certain network or IP  0 I was wondering is there a way to monitor a certain ip address or address range? thank you
ip certain networks scanasked 01 Dec &#39;10, 11:27
keyboard
11●3●3●4
accept rate: 0%
  
One Answer:
  
1You can only monitor traffic seen on the interface you have Wireshark to capture on. You need to arrange for that traffic to be presented on that interface by whatever means.</description>
    </item>
    
    <item>
      <title>Collisions</title>
      <link>/questions/1196/collisions/</link>
      <pubDate>Wed, 01 Dec 2010 18:48:00 +0000</pubDate>
      
      <guid>/questions/1196/collisions/</guid>
      <description>Collisions  1 Is there any way to see how many pacekt collisions there are?
collisions packetasked 01 Dec &#39;10, 18:48
braddog
16●1●1●2
accept rate: 0%
  
One Answer:
  
2Not from the nic. Some server drivers may have visible counters, but not (usually) on end user PCs. You can see it from the switch side if you have managed switches.
In this day and age, if you are seeing collisions, then you have a duplex mismatch.</description>
    </item>
    
    <item>
      <title>.trace from Anritsu MasterClaw can&amp;#x27;t open</title>
      <link>/questions/1200/trace-from-anritsu-masterclaw-cant-open/</link>
      <pubDate>Wed, 01 Dec 2010 23:58:00 +0000</pubDate>
      
      <guid>/questions/1200/trace-from-anritsu-masterclaw-cant-open/</guid>
      <description>.trace from Anritsu MasterClaw can&amp;rsquo;t open  0 I&#39;m using Anritsu MacterClaw Call-trace for tracing sigtran and TDM SS7 msgs.
By default, i can&#39;t open saved files and I&#39;m wondering is it possible at all.
We need wireshark because of bether filtering messages and we are using version 1.2.7
Thanks in advance
open fileasked 01 Dec &#39;10, 23:58
ms979
1●1●1●1
accept rate: 0%
Not familiar with Anritsu product, but update to Wireshark version 1.</description>
    </item>
    
    <item>
      <title>unresolved external symbol __DllMainCRTStartup</title>
      <link>/questions/1209/unresolved-external-symbol-__dllmaincrtstartup/</link>
      <pubDate>Thu, 02 Dec 2010 07:50:00 +0000</pubDate>
      
      <guid>/questions/1209/unresolved-external-symbol-__dllmaincrtstartup/</guid>
      <description>unresolved external symbol __DllMainCRTStartup  0 When building Wireshark under Windows 7, I receive the error above after changing to the wsutil directory. I&#39;m not familiar with biulding DLLs, but I would have thought the DllMainCRTStartup function should have been found in one of the *.c files within wsutil - but it isn&#39;t. Here&#39;s the output I get from running the &#34;nmake -f Makefile.nmake all&#34; command: &amp;lt;previous packages=&#34;&#34; built=&#34;&#34; correctly...=&#34;&#34;&amp;gt; cd wsutil &#34;</description>
    </item>
    
    <item>
      <title>Proof of completion</title>
      <link>/questions/1211/proof-of-completion/</link>
      <pubDate>Thu, 02 Dec 2010 08:57:00 +0000</pubDate>
      
      <guid>/questions/1211/proof-of-completion/</guid>
      <description>Proof of completion  0 I am wondering if there are any courses offered via online or through self learning that will provide some type of certificate of completion.
completionasked 02 Dec &#39;10, 08:57
virginialoverr
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Do you mean http://www.wiresharktraining.com/certification.html ?
answered 02 Dec &#39;10, 14:52
martyvis
891●1●5●25
accept rate: 7%
  
0We have the Core 1 and Core 2 courses online at the new Online Portal.</description>
    </item>
    
    <item>
      <title>How to catch everything that goes through my wifi router?</title>
      <link>/questions/1213/how-to-catch-everything-that-goes-through-my-wifi-router/</link>
      <pubDate>Thu, 02 Dec 2010 13:13:00 +0000</pubDate>
      
      <guid>/questions/1213/how-to-catch-everything-that-goes-through-my-wifi-router/</guid>
      <description>How to catch everything that goes through my wifi router?  0 I read through the wireless capture and the other hub/switch/tap capturing, but I&#39;m very confused.
What I want to do is capture all of the info from my wifi router from how ever many users are using it at that time. The router is sitting next to my laptop, so I have access to it. What do I have to buy?</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t find an interface in order to capture...</title>
      <link>/questions/1218/cant-find-an-interface-in-order-to-capture/</link>
      <pubDate>Thu, 02 Dec 2010 18:50:00 +0000</pubDate>
      
      <guid>/questions/1218/cant-find-an-interface-in-order-to-capture/</guid>
      <description>Can&amp;rsquo;t find an interface in order to capture&amp;hellip;  0 I am having trouble getting started on my packet capture. When I go to Capture-&amp;gt;Interfaces I get a message saying &#34;There are no interfaces on which a capture can be done.&#34; I am using Mac OS 10.6.3 and have an en1 interface. When I went to Edit-&amp;gt; Preferences-&amp;gt; Capture I typed in en1 in the &#34;Default interface&#34; box and hit OK.</description>
    </item>
    
    <item>
      <title>User Guide for Wireshark 1.2.11</title>
      <link>/questions/1219/user-guide-for-wireshark-1211/</link>
      <pubDate>Thu, 02 Dec 2010 21:28:00 +0000</pubDate>
      
      <guid>/questions/1219/user-guide-for-wireshark-1211/</guid>
      <description>User Guide for Wireshark 1.2.11  0 I am looking for a copy of the user guide for 1.2 or better 1.2.11. I am a student and this is the copy we are using in class. Any help would be appreciated.
guideasked 02 Dec &#39;10, 21:28
dr_duff
1●1●1●1
accept rate: 0%
  
One Answer:
  
0If you are working on a Windows PC, then by default, the user guide is located in &#34;</description>
    </item>
    
    <item>
      <title>Standard way people should &amp;quot;attach&amp;quot; capture files to questions in this Q&amp;amp;A site?</title>
      <link>/questions/1221/standard-way-people-should-attach-capture-files-to-questions-in-this-qa-site/</link>
      <pubDate>Thu, 02 Dec 2010 23:26:00 +0000</pubDate>
      
      <guid>/questions/1221/standard-way-people-should-attach-capture-files-to-questions-in-this-qa-site/</guid>
      <description>Standard way people should &amp;ldquo;attach&amp;rdquo; capture files to questions in this Q&amp;amp;A site?  1 How does this forum suggest people at least refer to sample capture files they might have. From what it seems the forum software doesn&#39;t allow uploading such attachments. What are some good alternatives? While many of us have our own web servers to make this relatively easy, this doesn&#39;t work for the average Joe.
attachmentasked 02 Dec &#39;10, 23:26</description>
    </item>
    
    <item>
      <title>How to import via Text2pcap the following Hex DATA</title>
      <link>/questions/1223/how-to-import-via-text2pcap-the-following-hex-data/</link>
      <pubDate>Fri, 03 Dec 2010 01:29:00 +0000</pubDate>
      
      <guid>/questions/1223/how-to-import-via-text2pcap-the-following-hex-data/</guid>
      <description>How to import via Text2pcap the following Hex DATA  0 45 00 00 44 00 00 40 00 40 84 52 06 0a 00 55 7c c2 96 c6 1d (Level Internet Protocol where Internet Protocol, Src: 10.0.85.124 (10.0.85.124), Dst: 194.150.198.29 (194.150.198.29)etc...
text2pcap ???? src-file dst-file
pcapasked 03 Dec &#39;10, 01:29
tgeanp00
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Save the data in a file (e.</description>
    </item>
    
    <item>
      <title>Tshark pdml value</title>
      <link>/questions/1227/tshark-pdml-value/</link>
      <pubDate>Fri, 03 Dec 2010 08:27:00 +0000</pubDate>
      
      <guid>/questions/1227/tshark-pdml-value/</guid>
      <description>Tshark pdml value  0 Hi guys. I&#39;m trying to extract multimedia content from an MMSE dumped pcap file from command line (Bash - Linux RHEL5).
Well, with command:
tshark -R &#34;mmse&#34; -r mms.pcap -T pdml
i can see a smil tag nested in ip -&amp;gt; tcp -&amp;gt; wsp tags. This is the line i care for:
&amp;lt;field name=&#34;smil.smil&#34; showname=&#34;&amp;amp;lt;smil&amp;amp;gt;&#34; size=&#34;522&#34; pos=&#34;427&#34; show=&#34;&amp;amp;lt;smil&amp;amp;gt;&#34; value=&#34;...hex content...&#34;&amp;gt;if a try to print it with:</description>
    </item>
    
    <item>
      <title>after updating mac ports wireshark is dead!</title>
      <link>/questions/1230/after-updating-mac-ports-wireshark-is-dead/</link>
      <pubDate>Fri, 03 Dec 2010 09:20:00 +0000</pubDate>
      
      <guid>/questions/1230/after-updating-mac-ports-wireshark-is-dead/</guid>
      <description>after updating mac ports wireshark is dead!  0 Guys, I run Mac OSX 10.5.8 and after updating Mac ports wireshark is dead in the water, just wont load. Anybody know how I can fix this?
wiresharkasked 03 Dec &#39;10, 09:20
faboge
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Wrong Time</title>
      <link>/questions/1233/wrong-time/</link>
      <pubDate>Fri, 03 Dec 2010 13:23:00 +0000</pubDate>
      
      <guid>/questions/1233/wrong-time/</guid>
      <description>Wrong Time  0 When running a capture, the timestamp for the packets captured by WireShark is not the same as the time on the local machine. As a matter of fact, if I run a capture on two machines talking to each other, both captures will have the wrong time, but they are different.
Anyone seen this before?
timeasked 03 Dec &#39;10, 13:23
gazoo
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>RHEL wireshark ? or tethereal ?</title>
      <link>/questions/1234/rhel-wireshark-or-tethereal/</link>
      <pubDate>Fri, 03 Dec 2010 13:45:00 +0000</pubDate>
      
      <guid>/questions/1234/rhel-wireshark-or-tethereal/</guid>
      <description>RHEL wireshark ? or tethereal ?  0 Ok so im installing wireshark on RHEL 5 and I did &#34;yum install wireshark&#34; but now cant seem to find wireshark on the system -- the version that was installed was &#34;wireshark-1.0.15-1.el5_5.1&#34;. I was able to see /usr/share/wireshark but they are all html files, no executable. I did manage after some web searching to find tethereal in /usr/bin is this what RHEL is calling wireshark?</description>
    </item>
    
    <item>
      <title>speed of sending and receiving packets</title>
      <link>/questions/1242/speed-of-sending-and-receiving-packets/</link>
      <pubDate>Sat, 04 Dec 2010 01:26:00 +0000</pubDate>
      
      <guid>/questions/1242/speed-of-sending-and-receiving-packets/</guid>
      <description>speed of sending and receiving packets  0 hello
would you plz guide me if i want to use Wireshark to measure the seep of my requests to the other client on my wired network? the LAN is 100Mbps but i think it is less than this, how can i be sure the speed of my request, spouse i want to ask to calling a method of my Web application uploaded on my server which is in my wired LAN, now if i want to check how lung does it take from the time when i send my request until my server receive my request (network time)?</description>
    </item>
    
    <item>
      <title>Upgrade wireshark in Ubuntu?</title>
      <link>/questions/1243/upgrade-wireshark-in-ubuntu/</link>
      <pubDate>Sat, 04 Dec 2010 05:09:00 +0000</pubDate>
      
      <guid>/questions/1243/upgrade-wireshark-in-ubuntu/</guid>
      <description>Upgrade wireshark in Ubuntu?  1 Is it possible to upgrade wireshark in Ubuntu? If so, how can a linux-newby do this?
upgrade ubuntuasked 04 Dec &#39;10, 05:09
Boonie
16●1●1●4
accept rate: 0%
  
4 Answers:
  
1I have 1.4.1 running on Ubuntu-based Linux I am not too deep into Linux, but as far as I remember i had like the same issue and got around it by using</description>
    </item>
    
    <item>
      <title>Wireshark on PPPoE?</title>
      <link>/questions/1251/wireshark-on-pppoe/</link>
      <pubDate>Sun, 05 Dec 2010 18:40:00 +0000</pubDate>
      
      <guid>/questions/1251/wireshark-on-pppoe/</guid>
      <description>Wireshark on PPPoE?  0 Is use of Wireshark in a windows OS different on PPPoE then Other ISP uses? Just for starters, malformed packets are the majority of what I&#39;m finding. Checksums never match what they are suppose to be.
pppoeasked 05 Dec &#39;10, 18:40
Algonquian_C...
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Here are a couple of links to checksum errors:
http://ask.wireshark.org/questions/830/tcp-checksum-errors
and</description>
    </item>
    
    <item>
      <title>Display captures on a web page</title>
      <link>/questions/1253/display-captures-on-a-web-page/</link>
      <pubDate>Mon, 06 Dec 2010 04:36:00 +0000</pubDate>
      
      <guid>/questions/1253/display-captures-on-a-web-page/</guid>
      <description>Display captures on a web page  0 Hello,
Is there a way to display packet captures on the web so to make them look like so? I mean like some sort of plugin that can read a file (XML maybe) and display expandable sections on the web page like you have in Wireshark when a packet is selected, to see each layer&#39;s information?
The closest thing I can think of to illustrate, is source code style sheets that make Java class files look like source code in an IDE.</description>
    </item>
    
    <item>
      <title>newbie question, need to run as a commald line</title>
      <link>/questions/1254/newbie-question-need-to-run-as-a-commald-line/</link>
      <pubDate>Mon, 06 Dec 2010 04:39:00 +0000</pubDate>
      
      <guid>/questions/1254/newbie-question-need-to-run-as-a-commald-line/</guid>
      <description>newbie question, need to run as a commald line  0 Hi
need to run Wireshark from a command line as follows if possible capture all packets with following options 1. IP name resolution 2. file capture directory c:capture 3. file size 100mb 4. 5 rolling files so when 5th one full goes back to number 1
thanks Steve
line commandasked 06 Dec &#39;10, 04:39
steve_1
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Win 7 - No capture - Internet Mobile plugged on USB port</title>
      <link>/questions/1261/win-7-no-capture-internet-mobile-plugged-on-usb-port/</link>
      <pubDate>Mon, 06 Dec 2010 11:53:00 +0000</pubDate>
      
      <guid>/questions/1261/win-7-no-capture-internet-mobile-plugged-on-usb-port/</guid>
      <description>Win 7 - No capture - Internet Mobile plugged on USB port  0 I just installed wireshark. Purpose: analyzing all packets to and from the internet during a given session. Any reason why it does NOT see the interface? OR: what is the additional add-on we need? Thanks
windows7 usbasked 06 Dec &#39;10, 11:53
jeanray
1●1●1●1
accept rate: 0%
The FAQs do not answer the question: there is no mention of the USB port, not of internet mobile devices.</description>
    </item>
    
    <item>
      <title>Start wireshark gui with a pre-configured display filter already applied</title>
      <link>/questions/1264/start-wireshark-gui-with-a-pre-configured-display-filter-already-applied/</link>
      <pubDate>Mon, 06 Dec 2010 16:36:00 +0000</pubDate>
      
      <guid>/questions/1264/start-wireshark-gui-with-a-pre-configured-display-filter-already-applied/</guid>
      <description>Start wireshark gui with a pre-configured display filter already applied  0 I am trying to automate some testing for a couple of users. They require that wireshark starts automatically when they run a shell script. I have that part working.
But they have a request for having a filter already enabled when they start the wireshark gui. For example ip.src == W.X.Y.Z
So the question is: Is it possible to start wireshark from command line and automatically have a display filter already applied when wireshark comes up?</description>
    </item>
    
    <item>
      <title>SCTP Throughput</title>
      <link>/questions/1267/sctp-throughput/</link>
      <pubDate>Mon, 06 Dec 2010 23:32:00 +0000</pubDate>
      
      <guid>/questions/1267/sctp-throughput/</guid>
      <description>SCTP Throughput  0 Hi all,
Am trying to get the throughput of SCTP, is it possible to extract such information with Wireshark? If yes, how is it done and if no,what tool is capable?
Thanks.
throughputasked 06 Dec &#39;10, 23:32
promo
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Show tab Tx Rate and RSSI</title>
      <link>/questions/1268/show-tab-tx-rate-and-rssi/</link>
      <pubDate>Tue, 07 Dec 2010 01:04:00 +0000</pubDate>
      
      <guid>/questions/1268/show-tab-tx-rate-and-rssi/</guid>
      <description>Show tab Tx Rate and RSSI  0 I can show tab TX Rate and RSSI at wireshark so that i can them clearly Can you help me? Thak you!
toolsasked 07 Dec &#39;10, 01:04
haquyen
1●6●6●7
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>NTP: uncalibrated local clock</title>
      <link>/questions/1270/ntp-uncalibrated-local-clock/</link>
      <pubDate>Tue, 07 Dec 2010 07:43:00 +0000</pubDate>
      
      <guid>/questions/1270/ntp-uncalibrated-local-clock/</guid>
      <description>NTP: uncalibrated local clock  0 I have a Windows 2003 DC (NTP3) that has a Cisco router as its time source on the same LAN. Recently, 2003 server stopped getting replies from the router, however if I change the time source to any external NTP server, the sync problem goes away.
Filtering for NTP traffic wireshark sees (NTP symmetric active) requests from the server to the Cisco router, but nothing comes back.</description>
    </item>
    
    <item>
      <title>Dumpcap Syntax</title>
      <link>/questions/1271/dumpcap-syntax/</link>
      <pubDate>Tue, 07 Dec 2010 08:48:00 +0000</pubDate>
      
      <guid>/questions/1271/dumpcap-syntax/</guid>
      <description>Dumpcap Syntax  0 On a Windows XP system dumpcap keeps creating new files even though &#34;files:3&#34; is used. What is wrong with my syntax?
C:\Temp&amp;gt;dumpcap.exe -i1 -b files:3 -b filesize:1 -w test.pcap File: test_00001_20101207114220.pcap Packets: 10 File: test_00002_20101207114223.pcap Packets: 20 File: test_00003_20101207114227.pcap Packets: 29 File: test_00004_20101207114228.pcap Used CTL-C to quitfiles dumpcapasked 07 Dec &#39;10, 08:48
Gary
1●3●3●3
accept rate: 0%
 edited 07 Dec &#39;10, 09:02 
SYN-bit ♦♦</description>
    </item>
    
    <item>
      <title>Delaying Capture</title>
      <link>/questions/1273/delaying-capture/</link>
      <pubDate>Tue, 07 Dec 2010 09:53:00 +0000</pubDate>
      
      <guid>/questions/1273/delaying-capture/</guid>
      <description>Delaying Capture  0 I would like to be able to have Wireshark do a capture at 0200 for approx 2 minutes to see where a 4MB stream is coming from. Is there a way to start and stop Wireshark at certain time of day?
delayasked 07 Dec &#39;10, 09:53
Mach One
1●1●1●2
accept rate: 0%
  
One Answer:
  
1Sure: Schedule a &#39;dumpcap&#39; job for 02:00 (method depending upon your OS: windows/at; linux/cron, etc).</description>
    </item>
    
    <item>
      <title>uninstall 1.4.2. for mac</title>
      <link>/questions/1277/uninstall-142-for-mac/</link>
      <pubDate>Tue, 07 Dec 2010 16:03:00 +0000</pubDate>
      
      <guid>/questions/1277/uninstall-142-for-mac/</guid>
      <description>uninstall 1.4.2. for mac  0 how do I uninstall 1.4.2 for mac 64bit?
uninstallasked 07 Dec &#39;10, 16:03
dumpster
1●1●1●1
accept rate: 0%
  
One Answer:
  
0nevermind... found it.
answered 07 Dec &#39;10, 16:26
dumpster
1●1●1●1
accept rate: 0%
     </description>
    </item>
    
    <item>
      <title>NPF driver Problem in Windows 7</title>
      <link>/questions/1281/npf-driver-problem-in-windows-7/</link>
      <pubDate>Tue, 07 Dec 2010 23:42:00 +0000</pubDate>
      
      <guid>/questions/1281/npf-driver-problem-in-windows-7/</guid>
      <description>NPF driver Problem in Windows 7  2 1I am using Windows 7 64bit edition; when i first installed Wireshark it worked, but after restart its constantly telling me NPF driver is not running error and therefore I cannot see any of my network cards. Please help
windows7 npf driverasked 07 Dec &#39;10, 23:42
Engr Mansoor...
31●1●2●4
accept rate: 0%
 edited 20 Jan &#39;11, 12:11 
Jaap ♦
11.7k●16●101</description>
    </item>
    
    <item>
      <title>Wireshark showing lot of TCP retransmissions - Is it real Retransmission or Wireshark showing incorrectly</title>
      <link>/questions/1284/wireshark-showing-lot-of-tcp-retransmissions-is-it-real-retransmission-or-wireshark-showing-incorrectly/</link>
      <pubDate>Wed, 08 Dec 2010 03:47:00 +0000</pubDate>
      
      <guid>/questions/1284/wireshark-showing-lot-of-tcp-retransmissions-is-it-real-retransmission-or-wireshark-showing-incorrectly/</guid>
      <description>Wireshark showing lot of TCP retransmissions - Is it real Retransmission or Wireshark showing incorrectly  0 I am new to using Wireshark. I captured the pcap file using the following command in our linux server which is a receiver in the below scenario:-
tcpdump -ni any -s0 -w &amp;lt;filename&amp;gt;
I am seeing TCP Retransmission and Dup Ack packets from the sender in the network which uses a satellite link. The packets use PPPoE in the link layer and TCP on top of it in transport layer.</description>
    </item>
    
    <item>
      <title>Capturing only 1 or 2 packets on Solaris 10</title>
      <link>/questions/1289/capturing-only-1-or-2-packets-on-solaris-10/</link>
      <pubDate>Wed, 08 Dec 2010 13:02:00 +0000</pubDate>
      
      <guid>/questions/1289/capturing-only-1-or-2-packets-on-solaris-10/</guid>
      <description>Capturing only 1 or 2 packets on Solaris 10  0 Hello,
I have a Solaris 10 machine with a 4-port ethernet card on which I just installed Wireshark. The problem I&#39;m having is kind of weird. Basically, I&#39;m not capturing any packets on the network interface which I&#39;m testing by just pinging another machine on the network. But if I leave the capture running and I start an extended ping it will capture 1 of 2 packets (the request, the reply, or both) and that is all.</description>
    </item>
    
    <item>
      <title>Excessive internet traffic eminating from SBS 2003 Server</title>
      <link>/questions/1295/excessive-internet-traffic-eminating-from-sbs-2003-server/</link>
      <pubDate>Wed, 08 Dec 2010 19:19:00 +0000</pubDate>
      
      <guid>/questions/1295/excessive-internet-traffic-eminating-from-sbs-2003-server/</guid>
      <description>Excessive internet traffic eminating from SBS 2003 Server  0 Excessive internet traffic eminating from SBS 2003 Server
Our internet browsing capability at the office has slowed considerably in the last few days.
I noticed our server is sending and receiving data constantly. It is running SBS 2003 and we are hosting email on it. We don&#39;t host a website on it - other than the Remote Web Workplace site that is available via the internet.</description>
    </item>
    
    <item>
      <title>Decrypting SSL in SSL</title>
      <link>/questions/1296/decrypting-ssl-in-ssl/</link>
      <pubDate>Thu, 09 Dec 2010 00:57:00 +0000</pubDate>
      
      <guid>/questions/1296/decrypting-ssl-in-ssl/</guid>
      <description>Decrypting SSL in SSL  0 Hi all,
I am challenged with the analysis of an SSL VPN Gateway.
Users ultimately access an HTTPS server in the inside network. This session is encapsulated in another SSL layer on the outside.
As I have both SSL keys (VPN gateway and HTTPS server) traffic can be decrypted. (Thanks, Wireshark, I love this feature.)
Decrypted traffic on the outside of the gateway matches the encrypted traffic from the inside.</description>
    </item>
    
    <item>
      <title>Wireshark(dumpcap, tshark), ringbuffer problem from command line</title>
      <link>/questions/1297/wiresharkdumpcap-tshark-ringbuffer-problem-from-command-line/</link>
      <pubDate>Thu, 09 Dec 2010 02:22:00 +0000</pubDate>
      
      <guid>/questions/1297/wiresharkdumpcap-tshark-ringbuffer-problem-from-command-line/</guid>
      <description>Wireshark(dumpcap, tshark), ringbuffer problem from command line  1 Hello, Please help me with the following problem.
I&#39;m using ringbuffer to limit the number of files and size. Unfortunately this option is not working or I&#39;m doing something wrong.
The below command should make only 5 files, but actually like is displayed is not deleting the files that are exceeded the number configured.
I&#39;m using the wireshark Version 1.4.0 (SVN Rev 34005 from /trunk-1.</description>
    </item>
    
    <item>
      <title>recording traffic at the gateway</title>
      <link>/questions/1301/recording-traffic-at-the-gateway/</link>
      <pubDate>Thu, 09 Dec 2010 07:59:00 +0000</pubDate>
      
      <guid>/questions/1301/recording-traffic-at-the-gateway/</guid>
      <description>recording traffic at the gateway  0 hi, somebody is constantly hacking my firewall. which way is there to record traffic at the gateway (which is a modem-router in my case)?
do i need a hub where a second pc is running on which wireshark is recording? is there any tutorial on how to do this?
a total beginner
recording traffic gatewayasked 09 Dec &#39;10, 07:59
C8H10N4O2
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Decoding BACnet protocol using Python / Jython</title>
      <link>/questions/1306/decoding-bacnet-protocol-using-python-jython/</link>
      <pubDate>Thu, 09 Dec 2010 18:35:00 +0000</pubDate>
      
      <guid>/questions/1306/decoding-bacnet-protocol-using-python-jython/</guid>
      <description>Decoding BACnet protocol using Python / Jython  0 I am using Wireshark for BACnet protocol. Since wireshahrk has dissector of BACnet, I would like to get the value of the packet using python / jython or any other programming language for verification.
Similarly I would like to Construct BACnet data packets and send it to the network.
Kindly help.
Thanks in advance.
Kishore
bacnet protocolasked 09 Dec &#39;10, 18:35</description>
    </item>
    
    <item>
      <title>transfer rate timing of incomming packets</title>
      <link>/questions/1319/transfer-rate-timing-of-incomming-packets/</link>
      <pubDate>Sun, 12 Dec 2010 01:17:00 +0000</pubDate>
      
      <guid>/questions/1319/transfer-rate-timing-of-incomming-packets/</guid>
      <description>transfer rate timing of incomming packets  0 hi all
I am working with a module which claims to send packets every 100 micro seconds . but when I examine the incoming packets in wireshark i see that the intervals between incoming packets are about 400 usec. I am not sure the problem is due to whether the module or the wireshark program estimation function
how can i find it out ?</description>
    </item>
    
    <item>
      <title>overcoming p2p restriction in university to play.</title>
      <link>/questions/1320/overcoming-p2p-restriction-in-university-to-play/</link>
      <pubDate>Sun, 12 Dec 2010 03:38:00 +0000</pubDate>
      
      <guid>/questions/1320/overcoming-p2p-restriction-in-university-to-play/</guid>
      <description>overcoming p2p restriction in university to play.  -3 Does anyone know how to overcome this situation? I don&#39;t really know how to do it or so, but i ve been told, that using openvpn i could play with university internet. They restrict torrent and p2p i guess so i can&#39;t play sc2 and wow and any game like these. Please help!
restriction university sc2 p2p wowasked 12 Dec &#39;10, 03:38</description>
    </item>
    
    <item>
      <title>VPN connection</title>
      <link>/questions/1324/vpn-connection/</link>
      <pubDate>Sun, 12 Dec 2010 23:55:00 +0000</pubDate>
      
      <guid>/questions/1324/vpn-connection/</guid>
      <description>VPN connection  0 Hi, I have Wireshark monitoring a TAP-Win32 Adapter connection installed with Cyberghost but the traffic doesn&#39;t show up as encrypted. Is this normal? And how do I check if traffic is encrypted through VPN. This happens with ProXPN also.
Many thanks
connection vpnasked 12 Dec &#39;10, 23:55
fh67
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Yes, that is normal. If you capture on a virtual adapter that is used for a VPN connection you will see unencrypted packets in and out.</description>
    </item>
    
    <item>
      <title>Mysql and encryption</title>
      <link>/questions/1327/mysql-and-encryption/</link>
      <pubDate>Mon, 13 Dec 2010 07:47:00 +0000</pubDate>
      
      <guid>/questions/1327/mysql-and-encryption/</guid>
      <description>Mysql and encryption  0 Hi, I need to know whether or not my Mysql connection is actually being encrypted. Any suggestions as to how I would approach this. So far, I&#39;ve been filtering on port 3306 and also filtering on my ip.addr but I&#39;m not seeing anything that would indicate that my remote connection to Mysql is actually getting encrypted. Mysql is setup to use ssl. Thanks for any help.</description>
    </item>
    
    <item>
      <title>DNS responses</title>
      <link>/questions/1329/dns-responses/</link>
      <pubDate>Mon, 13 Dec 2010 13:10:00 +0000</pubDate>
      
      <guid>/questions/1329/dns-responses/</guid>
      <description>DNS responses  1 Ok, a simple question here. I&#39;m trying to trace DNS traffic. I&#39;ve enable port spanning to watch traffic. I use DNS as the filter. I see all the DNS queries going to my DNS but I see no responses, and I know it gets a response because it resolves. Am I missing a setting somewhere?
Some more info.
I am Spaning from port 15 cisco 4948( where the server is connected to the switch) to port 13 ( where my laptop with wireshark is connected) The server only has one NIC.</description>
    </item>
    
    <item>
      <title>User enhancement for wireshark</title>
      <link>/questions/1330/user-enhancement-for-wireshark/</link>
      <pubDate>Mon, 13 Dec 2010 13:14:00 +0000</pubDate>
      
      <guid>/questions/1330/user-enhancement-for-wireshark/</guid>
      <description>User enhancement for wireshark  0 I have used Ethereal and Wireshark for many years and have hundreds of traces. I would like the ability to enter text notes attached to the trace to allow me to keep a record of the problem scenario and where in the trace the problem is recorded plus my diagnosis of the trace etc. I am unaware if this facility already exists but I for one would find it very useful.</description>
    </item>
    
    <item>
      <title>how to set capture filter for different MPLS label</title>
      <link>/questions/1334/how-to-set-capture-filter-for-different-mpls-label/</link>
      <pubDate>Mon, 13 Dec 2010 19:08:00 +0000</pubDate>
      
      <guid>/questions/1334/how-to-set-capture-filter-for-different-mpls-label/</guid>
      <description>how to set capture filter for different MPLS label  2 Guys, I am trying to use TShark to capture ip packets with 172.16.1.1/2 or 172.16.2.1/2 and mpls packets with 2 layer label (23,25) or 1 layer label 19 at the same time with below command but failed
tshark -i eth1 -w test2.cap &#39;(net 172.16.2.0/30 or 172.16.1.0/30) or (mpls and mpls 19) or (mpls 23 and mpls 25)&#39;
it seems like only the first &#34;</description>
    </item>
    
    <item>
      <title>Capturing Voip Correct Procedure</title>
      <link>/questions/1340/capturing-voip-correct-procedure/</link>
      <pubDate>Tue, 14 Dec 2010 03:53:00 +0000</pubDate>
      
      <guid>/questions/1340/capturing-voip-correct-procedure/</guid>
      <description>Capturing Voip Correct Procedure  0 OS WindowsXP Home with intel 82566DC-2 network card and it also displays adaptor generic for dialup and VPN -- I&#39;m on a wireless home network and attempting to capture the calls from a remote machine (2wire router 2701HG-S) I&#39;m firing up wireshark,selecting the Intel network card and capturing all the traffic, no filters I&#39;m then selecting Voip calls from the Telephony tab I&#39;m not able to capture any traffic Is this the correct procedure.</description>
    </item>
    
    <item>
      <title>Does &amp;quot;Frame Length&amp;quot; include also CRC-Bytes?</title>
      <link>/questions/1344/does-frame-length-include-also-crc-bytes/</link>
      <pubDate>Tue, 14 Dec 2010 07:05:00 +0000</pubDate>
      
      <guid>/questions/1344/does-frame-length-include-also-crc-bytes/</guid>
      <description>Does &amp;ldquo;Frame Length&amp;rdquo; include also CRC-Bytes?  0 Does &#34;Frame Length&#34; include also CRC-Bytes?
When a packet is shown 60 bytes on wire, 60 bytes captured Frame Length: 60 bytes Capture Length: 60 bytes
and also the hex/data-view shows 60 bytes
Does this mean that the 4-CRC-Bytes / FCS is included also (but my NIC normally does not provide the CRC to the host)? But if this is not the case should&#39;nt it be &#34;</description>
    </item>
    
    <item>
      <title>limit number of packets I can see in wireshark???</title>
      <link>/questions/1346/limit-number-of-packets-i-can-see-in-wireshark/</link>
      <pubDate>Tue, 14 Dec 2010 09:31:00 +0000</pubDate>
      
      <guid>/questions/1346/limit-number-of-packets-i-can-see-in-wireshark/</guid>
      <description>limit number of packets I can see in wireshark???  0 Hi everyone,
I would be very grateful if someone can help. I have developed a tool for send files and I use wireshark for count the time of the transfer and the number of packets. The problem is when I send big files, i,e. I send a file of 200MB with UDP protocol so, I can see all the packets in the network.</description>
    </item>
    
    <item>
      <title>Lua TCP reassembly</title>
      <link>/questions/1357/lua-tcp-reassembly/</link>
      <pubDate>Wed, 15 Dec 2010 05:52:00 +0000</pubDate>
      
      <guid>/questions/1357/lua-tcp-reassembly/</guid>
      <description>Lua TCP reassembly  1 Hi all,
I work on a protocol built on top of HTTP on the port 4321 for example. I have Wireshark 1.4.2
First I register the HTTP protocol for the port 4321 but it seems that HTTP messages are very well reassembled. Often http PDU are reassembled but sometimes not. I read that there are bugs to reassemble HTTP message because it is diffcult to calculate their size.</description>
    </item>
    
    <item>
      <title>USB serial interface</title>
      <link>/questions/1360/usb-serial-interface/</link>
      <pubDate>Wed, 15 Dec 2010 10:35:00 +0000</pubDate>
      
      <guid>/questions/1360/usb-serial-interface/</guid>
      <description>USB serial interface  0 How to sniff packets of USB serial interface in Wireshark?
usbasked 15 Dec &#39;10, 10:35
rabeel
1●1●1●1
accept rate: 0%
  
One Answer:
  
0I believe this page has the information you&#39;re looking for.
answered 15 Dec &#39;10, 17:37
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%
     </description>
    </item>
    
    <item>
      <title>count of loss packets in the network</title>
      <link>/questions/1362/count-of-loss-packets-in-the-network/</link>
      <pubDate>Wed, 15 Dec 2010 13:24:00 +0000</pubDate>
      
      <guid>/questions/1362/count-of-loss-packets-in-the-network/</guid>
      <description>count of loss packets in the network  0 I´m using wireshark for study the traffic between a client and a server in my own machine. I study the traffic on the interface lo and after I study the traffic on the network (client and server in separate machines) on the interface eth0 I always see the conversations in stadistics for study the number of packets sent and received by client and server and I always obtain the same number for sent and received, I mean, I can´t see the number of loss packets in the network?</description>
    </item>
    
    <item>
      <title>tshark on solaris</title>
      <link>/questions/1376/tshark-on-solaris/</link>
      <pubDate>Thu, 16 Dec 2010 06:36:00 +0000</pubDate>
      
      <guid>/questions/1376/tshark-on-solaris/</guid>
      <description>tshark on solaris  0 Is there tshark on solaris and if does how to install it?
I need to conver pcap to text from shell.
Thanks
to solaris picap textasked 16 Dec &#39;10, 06:36
adostic
1●1●1●2
accept rate: 0%
  
One Answer:
  
1Is TShark shipped as part of Solaris? No.
If you install a third-party Wireshark package on Solaris, or build and install Wireshark from source code on Solaris, do you get TShark?</description>
    </item>
    
    <item>
      <title>Change a port name to something other than the iana standard</title>
      <link>/questions/1377/change-a-port-name-to-something-other-than-the-iana-standard/</link>
      <pubDate>Thu, 16 Dec 2010 07:55:00 +0000</pubDate>
      
      <guid>/questions/1377/change-a-port-name-to-something-other-than-the-iana-standard/</guid>
      <description>Change a port name to something other than the iana standard  0 I have a trace of a NAS product that uses port 2050 for some internal application. The iana port list has Avaya EMB Config Port registered for that port. Is there anyway that I can change the configuration within Wireshark in order to change the name to something else?
ianaasked 16 Dec &#39;10, 07:55
bpiela
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>proto_tree_append_text function</title>
      <link>/questions/1380/proto_tree_append_text-function/</link>
      <pubDate>Fri, 17 Dec 2010 05:39:00 +0000</pubDate>
      
      <guid>/questions/1380/proto_tree_append_text-function/</guid>
      <description>proto_tree_append_text function  0 Hello,
I am writing a dissector in C and I donwloaded the last version of the source from svn. I want to use the proto_tree_append_text to add a label to an item. My compiler said that this function is not defined. This are are my include at the begin of my c file:
#ifdef HAVE_CONFIG_H # include &amp;quot;config.h&amp;quot; #endif
#include &amp;lt;stdio.h&amp;gt; #include &amp;lt;glib.h&amp;gt; #include &amp;lt;epan/packet.h&amp;gt; #include &amp;lt;epan/emem.</description>
    </item>
    
    <item>
      <title>Source Code for building latest version of wireshark using RHEL5</title>
      <link>/questions/1382/source-code-for-building-latest-version-of-wireshark-using-rhel5/</link>
      <pubDate>Fri, 17 Dec 2010 07:59:00 +0000</pubDate>
      
      <guid>/questions/1382/source-code-for-building-latest-version-of-wireshark-using-rhel5/</guid>
      <description>Source Code for building latest version of wireshark using RHEL5  0 Where can I find the actual source code to download in order to build the latest version of wireshark using RHEL5?
We are moving system to RHEL5 (RHEL5.5 specifically), and yes, RHEL5.5 has included version wireshark-1.0.8-1.el5_3.1. But, is this the equivalent to latest version 1.4.2? Since 1.3.4 and higher, there are several updates include that supports HNBAP and RUA Protocols.</description>
    </item>
    
    <item>
      <title>How to decrypt SSL when contained protocol isn&amp;#x27;t known?</title>
      <link>/questions/1386/how-to-decrypt-ssl-when-contained-protocol-isnt-known/</link>
      <pubDate>Fri, 17 Dec 2010 11:59:00 +0000</pubDate>
      
      <guid>/questions/1386/how-to-decrypt-ssl-when-contained-protocol-isnt-known/</guid>
      <description>How to decrypt SSL when contained protocol isn&amp;rsquo;t known?  0 I&#39;m using wireshark to inspect and hopefully decrypt a connection; the encrypted protocol details aren&#39;t known. I&#39;ve set up SSL decryption as instructed at http://wiki.wireshark.org/SSL, but I&#39;m not sure how significant the specification of the embedded protocol is. I tried something like:
x.x.x.x,4001,Data,c:cp.pem or x.x.x.x,4001,http,c:cp.pem
but in both cases wireshark doesn&#39;t show me any decrypted data.
I logged to the SSL debug file, below.</description>
    </item>
    
    <item>
      <title>What are SRE and SLE?</title>
      <link>/questions/1389/what-are-sre-and-sle/</link>
      <pubDate>Fri, 17 Dec 2010 13:57:00 +0000</pubDate>
      
      <guid>/questions/1389/what-are-sre-and-sle/</guid>
      <description>What are SRE and SLE?  0 What do SRE and SLE stand for in the packet capture display? I&#39;m looking at TCP packets so I assume it has something to do with windowing.
display packetasked 17 Dec &#39;10, 13:57
catimossi
1●1●1●1
accept rate: 0%
  
2 Answers:
  
2They are the Right Edge (SRE) and Left Edge (SLE) of already acknowledged data when Selective Acknowledgments are used.</description>
    </item>
    
    <item>
      <title>prism ultralite trace to wireshark</title>
      <link>/questions/1392/prism-ultralite-trace-to-wireshark/</link>
      <pubDate>Fri, 17 Dec 2010 23:50:00 +0000</pubDate>
      
      <guid>/questions/1392/prism-ultralite-trace-to-wireshark/</guid>
      <description>prism ultralite trace to wireshark  0 how can i convert a trace taken in prism ultralite to a wireshark readable format? the trace is saved in text format and when i run text2pcap it is only writing 16 bytes of a packet. also i would like to know a way to convert a wan trace with l2 protocol say ppp having first 2 bytes as FF 03 into an ethernet packet is there a program to do this?</description>
    </item>
    
    <item>
      <title>Support for ISDN bearer service I.231.4?</title>
      <link>/questions/1394/support-for-isdn-bearer-service-i2314/</link>
      <pubDate>Sat, 18 Dec 2010 09:02:00 +0000</pubDate>
      
      <guid>/questions/1394/support-for-isdn-bearer-service-i2314/</guid>
      <description>Support for ISDN bearer service I.231.4?  0 I would like to know if Wireshark (its Q.931 dissector) supports the ISDN bearer service I.231.4 (Circuit-mode, alternate speech / 64 kbit/s unrestricted, 8 kHz structured bearer service).
If yes, what Q.931 messages are detected to alternate between speech and 64 kbps unrestricted? ([I.231.4/Clause 4.3.2.2] mentions the messages &#34;invoke in-call modification request&#34;, &#34;return result indication&#34;, &#34;call modification indication&#34; and &#34;in-call modification return result&#34;</description>
    </item>
    
    <item>
      <title>Mysql Password</title>
      <link>/questions/1397/mysql-password/</link>
      <pubDate>Sat, 18 Dec 2010 23:14:00 +0000</pubDate>
      
      <guid>/questions/1397/mysql-password/</guid>
      <description>Mysql Password  -1 1Well since the little 24x7 bot didn&#39;t work out a answer so I can just go a head and ask it here. I recently Wiresharked a keylogger that used MySQL, but it didn&#39;t display the password only a encoded/encrypted password: \[email protected]\xda\xb3I\xfa\x8a&amp;gt;W\x91\xebF\xbe\x01r\x0a\xda4\x9ao
And I don&#39;t really know what that is for encryption so can anybody help me please?
encryption password mysqlasked 18 Dec &#39;10, 23:14
Ikin</description>
    </item>
    
    <item>
      <title>will wireshark help diagnose this problem?</title>
      <link>/questions/1400/will-wireshark-help-diagnose-this-problem/</link>
      <pubDate>Sun, 19 Dec 2010 17:03:00 +0000</pubDate>
      
      <guid>/questions/1400/will-wireshark-help-diagnose-this-problem/</guid>
      <description>will wireshark help diagnose this problem?  0 I have a wired home network with 2 Macs and one Windows 7 PC. I have videos on 9 NAS&#39;s connected to the network. The network contains a router, which is connected to a cable modem. The NAS&#39;s are connected to a switch, which is connected to the router. The PC and Macs are connected to another switch, also connected to the router.</description>
    </item>
    
    <item>
      <title>editcap fails to split large trace</title>
      <link>/questions/1401/editcap-fails-to-split-large-trace/</link>
      <pubDate>Mon, 20 Dec 2010 00:05:00 +0000</pubDate>
      
      <guid>/questions/1401/editcap-fails-to-split-large-trace/</guid>
      <description>editcap fails to split large trace  0 I have an 88Mb trace file that is proving too large for wireshark to handle on my machine.
I&#39;ve tried splitting it up into smaller files, but editcap keeps stopping after packet 218,128. If I try to use editcap to get any packets over 218,128 I just end up with an empty trace.
Any ideas what could be happening?
Here&#39;s some info on the trace file:</description>
    </item>
    
    <item>
      <title>Not all SYN packets shown</title>
      <link>/questions/1404/not-all-syn-packets-shown/</link>
      <pubDate>Mon, 20 Dec 2010 06:55:00 +0000</pubDate>
      
      <guid>/questions/1404/not-all-syn-packets-shown/</guid>
      <description>Not all SYN packets shown  0 Hi,
When I start a valid TCP session, I see the expected SYN,SYN/ACK,ACK,PSH/ACK,ACK,FIN/ACK,ACK packets. When I try to start a TCP session to an non-existing IP address, no packets at all are shown. Shouldn&#39;t there be a SYN packet that is never answered? How can I make sure that I do not miss such a packet?
Thanks in advance,
Remco Poelstra
syn tcpasked 20 Dec &#39;10, 06:55</description>
    </item>
    
    <item>
      <title>Gbps over Cat5 cable</title>
      <link>/questions/1405/gbps-over-cat5-cable/</link>
      <pubDate>Mon, 20 Dec 2010 07:16:00 +0000</pubDate>
      
      <guid>/questions/1405/gbps-over-cat5-cable/</guid>
      <description>Gbps over Cat5 cable  0 I have some areas of my network that have Cat5 (not Cat5e) cable installed. I was told at one time that Cat5e cable is necessary for good 1Gbps data transmission. Now I&#39;m hearing that Cat5 is just fine. How can I use Wireshark to test this for myself? What should I expect to see if a certain cable install is not adequate for 1Gbps? Have I been misinformed?</description>
    </item>
    
    <item>
      <title>capture packets,edit and replay</title>
      <link>/questions/1407/capture-packetsedit-and-replay/</link>
      <pubDate>Mon, 20 Dec 2010 09:02:00 +0000</pubDate>
      
      <guid>/questions/1407/capture-packetsedit-and-replay/</guid>
      <description>capture packets,edit and replay  0 Hi,
I want to be able to capture packets in a file, edit out certain packets and &#34;replay&#34; the traffic ie simulate as if the traffic was happening in reality - is this possible ?
Thanks.
replay traffic capturedasked 20 Dec &#39;10, 09:02
codie9002
1●2●2●2
accept rate: 0%
  
One Answer:
  
0Sure, use Wireshark to capture your traffic, mark the packets you don&#39;t want and save it with these packets suppressed.</description>
    </item>
    
    <item>
      <title>RST - tracing</title>
      <link>/questions/1408/rst-tracing/</link>
      <pubDate>Mon, 20 Dec 2010 09:39:00 +0000</pubDate>
      
      <guid>/questions/1408/rst-tracing/</guid>
      <description>RST - tracing  0 Hi folks:
We have a Gateway server. It&#39;s a WIndows 2003 O/S running a Java JBOSS application. It uses TCP/IP to communicate to remote medical devices that are wirelessly connected via TCP/IP.
These devices interchange basic XML messages using TCP/IP to our server which listens on a single port (51244).
At several of our client sites, we&#39;ve noticed these messagess aren&#39;t being processed properly. We performed a packet capture using Wireshark and notice that there are frequent RST occuring that appear to be generated by the server.</description>
    </item>
    
    <item>
      <title>msvcr80.dll error trying to start tshark on windows server 2003</title>
      <link>/questions/1429/msvcr80dll-error-trying-to-start-tshark-on-windows-server-2003/</link>
      <pubDate>Tue, 21 Dec 2010 03:48:00 +0000</pubDate>
      
      <guid>/questions/1429/msvcr80dll-error-trying-to-start-tshark-on-windows-server-2003/</guid>
      <description>msvcr80.dll error trying to start tshark on windows server 2003  0 I tried win32 1.4.1 and 1.2.12 installers from wireshark.org.
When I try to start tshark I get an error about msvcr80.dll. Notes;
the installer puts msvcr90.dll in the Wireshark directory.Is tshark built in some way that is wrong for MS server 2003? it works OK on XP.I tried to use wireshark instead of tshark, as a workaround. It has similar options.</description>
    </item>
    
    <item>
      <title>Is there any better way to dump data? (http)</title>
      <link>/questions/1431/is-there-any-better-way-to-dump-data-http/</link>
      <pubDate>Tue, 21 Dec 2010 05:56:00 +0000</pubDate>
      
      <guid>/questions/1431/is-there-any-better-way-to-dump-data-http/</guid>
      <description>Is there any better way to dump data? (http)  0 I&#39;m using tshark to get html pages out of a capture file, and checking how many of those contain a specific element. Currently I&#39;m using the following params:
tshark.exe -r test.pcap -o &amp;quot;tcp.desegment_tcp_streams:TRUE&amp;quot; -R &amp;quot;tcp.stream==13 and http&amp;quot; -T pdml &amp;gt; test.session13.pdmland get the html documents themselves inside a data-text-lines element spread over many field elements in the output pdml. Which means that I need to concatenate the data in those elements to get the whole html back together.</description>
    </item>
    
    <item>
      <title>Is it the network? ActiveMQ problem</title>
      <link>/questions/1438/is-it-the-network-activemq-problem/</link>
      <pubDate>Tue, 21 Dec 2010 07:27:00 +0000</pubDate>
      
      <guid>/questions/1438/is-it-the-network-activemq-problem/</guid>
      <description>Is it the network? ActiveMQ problem  0 Tracking an issue with apache/activeMQ where some messages are expiring in queue rather than being retrieved by the member servers.
I don&#39;t see many errors on the associated interfaces and I seem to have connectivity between all the servers any time I check. I did 5 minute capture of all the TCP 18080 traffic and I see alot of TCP DUP ACK and TCP resets.</description>
    </item>
    
    <item>
      <title>Is it possible to stream out captured data in near real-time?</title>
      <link>/questions/1445/is-it-possible-to-stream-out-captured-data-in-near-real-time/</link>
      <pubDate>Tue, 21 Dec 2010 18:11:00 +0000</pubDate>
      
      <guid>/questions/1445/is-it-possible-to-stream-out-captured-data-in-near-real-time/</guid>
      <description>Is it possible to stream out captured data in near real-time?  0 I would like to be able to use the &#34;follow tcp stream&#34; feature, but instead of saving it to a file, I would like to continuously output the conversation and pipe it into another program. Is this possible? If so, how would I do it?
capture output stream real-timeasked 21 Dec &#39;10, 18:11
harrym
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Sharing wireshark plugin without making source public</title>
      <link>/questions/1447/sharing-wireshark-plugin-without-making-source-public/</link>
      <pubDate>Tue, 21 Dec 2010 20:58:00 +0000</pubDate>
      
      <guid>/questions/1447/sharing-wireshark-plugin-without-making-source-public/</guid>
      <description>Sharing wireshark plugin without making source public  0 Can I share wireshark plugin in the form of a DLL or .so to a customer without making the source code public for debugging activity? Please note that I am not billing the customer for this.
licenseasked 21 Dec &#39;10, 20:58
neeraj
1●1●1●1
accept rate: 0%
  
2 Answers:
  
3You can share the plugin with the customer, but you&#39;ll be required to provide the source code if so requested.</description>
    </item>
    
    <item>
      <title>Is there a possibility to compare frames?</title>
      <link>/questions/1451/is-there-a-possibility-to-compare-frames/</link>
      <pubDate>Wed, 22 Dec 2010 03:26:00 +0000</pubDate>
      
      <guid>/questions/1451/is-there-a-possibility-to-compare-frames/</guid>
      <description>Is there a possibility to compare frames?  0 Hi, i would like to know if somebody knows if there is any script or utility that helps to compare frames in order to see data variations quickly. Thanks in advance. Regards.
frames comparisonasked 22 Dec &#39;10, 03:26
egunon
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0The frame dissector provides the option to calculate an MD5 hash of the frame.</description>
    </item>
    
    <item>
      <title>tshark: What is the command for getting  only &amp;quot;Reassembled TCP&amp;quot; in -x output</title>
      <link>/questions/1456/tshark-what-is-the-command-for-getting-only-reassembled-tcp-in-x-output/</link>
      <pubDate>Wed, 22 Dec 2010 13:58:00 +0000</pubDate>
      
      <guid>/questions/1456/tshark-what-is-the-command-for-getting-only-reassembled-tcp-in-x-output/</guid>
      <description>tshark: What is the command for getting only &amp;ldquo;Reassembled TCP&amp;rdquo; in -x output  0 Assume Windows, if I used
tshark -r file.pcap -R &#34;tcp.stream eq xxx&#34; -x
according to the documentation I get &#34;hex and ASCII dump of the packet data after printing the summary or details&#34;. Looking at the output, I am only interested in Reassembled TCP section of -x output. Is there a field in wireshark or a command to output only that section?</description>
    </item>
    
    <item>
      <title>Finding a Particular IP Address</title>
      <link>/questions/1459/finding-a-particular-ip-address/</link>
      <pubDate>Wed, 22 Dec 2010 16:31:00 +0000</pubDate>
      
      <guid>/questions/1459/finding-a-particular-ip-address/</guid>
      <description>Finding a Particular IP Address  0 Hello All,
I am new to Wireshark and actually to packet capture altogether. So far I have successfully done a packet capture on my computer&#39;s NIC and now I want to find out if a particular IP address or part of an IP address is present. I have tried to go through the help file that comes with Wireshark but I am not sure how to go about setting a filter or whatever to look for the particular IP address.</description>
    </item>
    
    <item>
      <title>Network Delay Problem</title>
      <link>/questions/1464/network-delay-problem/</link>
      <pubDate>Wed, 22 Dec 2010 18:28:00 +0000</pubDate>
      
      <guid>/questions/1464/network-delay-problem/</guid>
      <description>Network Delay Problem  0 We found the network delay about 20 seconds.
The result is like the below.
A packet(1510 Byte) was sent by 5 fragments(Number 47215, 49041, 50848, 52765, 52785) The delay for each segment was 5 seconds.
For this test, i didn&#39;t set &#39;tcp window size&#39; and &#39;nagle option&#39; on Window Server 2008 R2 64bit.
I have two questions. 1. TCP window size on screen shot as you see is under 256.</description>
    </item>
    
    <item>
      <title>Syncml Opaque Data</title>
      <link>/questions/1469/syncml-opaque-data/</link>
      <pubDate>Thu, 23 Dec 2010 04:01:00 +0000</pubDate>
      
      <guid>/questions/1469/syncml-opaque-data/</guid>
      <description>Syncml Opaque Data  0 Hi,
Im working with OMADM for device management, and Ive realized that Opaque Data Syncml tags are not being decoded. i.e: c3 (opaque data) 06 (6 bytes) 44 4d 2f 31 2e 32 (DM/1.2) is shown as: (6 bytes of opaque data) instead of DM/1.2 I can see the data in the Packet Bytes window, but not in the Packet Details, which is kind of bothersome.</description>
    </item>
    
    <item>
      <title>Other formats missing from the &amp;quot;Save as&amp;quot; dialog</title>
      <link>/questions/1475/other-formats-missing-from-the-save-as-dialog/</link>
      <pubDate>Thu, 23 Dec 2010 22:44:00 +0000</pubDate>
      
      <guid>/questions/1475/other-formats-missing-from-the-save-as-dialog/</guid>
      <description>Other formats missing from the &amp;ldquo;Save as&amp;rdquo; dialog  0 Wireshark 1.4 on Windows 7 is missing a several output file formats. According to the documentation there should be ten options but there are only seven - the various *.cap options. I am particularly interested in being able to save in the bfr (Network Observer) format. How can I get this back?
Thanks
output bfr file formatasked 23 Dec &#39;10, 22:44</description>
    </item>
    
    <item>
      <title>Add new column value</title>
      <link>/questions/1477/add-new-column-value/</link>
      <pubDate>Fri, 24 Dec 2010 02:48:00 +0000</pubDate>
      
      <guid>/questions/1477/add-new-column-value/</guid>
      <description>Add new column value  1 Hello,
I would like to extract the value of a field and print it in a column (which is definitly shorter than look for the value into the packet).
For instance I&#39;d like to add a column named &#34;SGSN [email protected]&#34; which value is &#34;radius.3GPP_SGSN_Address&#34;.
Do you know if this is already possible?
Thank you
columnsasked 24 Dec &#39;10, 02:48
mxcarron
46●1●1●6
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to convert data.data in Base64 to human readable format?</title>
      <link>/questions/1481/how-to-convert-datadata-in-base64-to-human-readable-format/</link>
      <pubDate>Sat, 25 Dec 2010 17:42:00 +0000</pubDate>
      
      <guid>/questions/1481/how-to-convert-datadata-in-base64-to-human-readable-format/</guid>
      <description>How to convert data.data in Base64 to human readable format?  0 Hello,
I know Follow TCP Stream do this, but I use custom columns and need to see human readable text instead of 32:30:30:20:43:6f....
is it possible with Lua/Python or with some patch?
nice feature if I could define custom column this way:
decode_base64(data.data) tolowcase(data.data) is_base64(data.data) ? decode_base64(data.data) : data.data decode_base64(bytes[10-34])etc. you got the ideaBR
field customasked 25 Dec &#39;10, 17:42</description>
    </item>
    
    <item>
      <title>Intercepting SOAP messages</title>
      <link>/questions/1482/intercepting-soap-messages/</link>
      <pubDate>Sun, 26 Dec 2010 01:22:00 +0000</pubDate>
      
      <guid>/questions/1482/intercepting-soap-messages/</guid>
      <description>Intercepting SOAP messages  0 Hi I need help intercepting my SOAP web service messages. I am able to see them with IEInspector, but no with wireshark.
My application server is glassfish running locally on port 8080, so I changed the filter to: tcp port 8080 But it doesn&#39;t look like any message is intercepted by wireshark when I execute a web service method (the call is successful).
This is driving me nuts ;) Any ideas?</description>
    </item>
    
    <item>
      <title>wireshark not signed</title>
      <link>/questions/1486/wireshark-not-signed/</link>
      <pubDate>Sun, 26 Dec 2010 11:56:00 +0000</pubDate>
      
      <guid>/questions/1486/wireshark-not-signed/</guid>
      <description>wireshark not signed  0 why is wireshark not signed???
not signedasked 26 Dec &#39;10, 11:56
awgi
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0There was a discussion about this in bug 1086.
answered 29 Dec &#39;10, 19:21
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%
  
0Hashes for each release file can be found in a &#34;SIGNATURES&#34; file for each release. For example, the signature file for 1.</description>
    </item>
    
    <item>
      <title>Will there ever be a version of Wireshark for the iPad?</title>
      <link>/questions/1487/will-there-ever-be-a-version-of-wireshark-for-the-ipad/</link>
      <pubDate>Sun, 26 Dec 2010 17:36:00 +0000</pubDate>
      
      <guid>/questions/1487/will-there-ever-be-a-version-of-wireshark-for-the-ipad/</guid>
      <description>Will there ever be a version of Wireshark for the iPad?  0 Will there be a release of wireshark that I can run from my iPad?
ipad installasked 26 Dec &#39;10, 17:36
Emory
1●1●1●1
accept rate: 0%
 edited 01 Jan &#39;11, 13:14 
Guy Harris ♦♦
17.4k●3●35●196
  
2 Answers:
  
1So far the best you can do is visit CloudShark.
answered 27 Dec &#39;10, 11:55</description>
    </item>
    
    <item>
      <title>Converting RTP Streams into audiofiles</title>
      <link>/questions/1488/converting-rtp-streams-into-audiofiles/</link>
      <pubDate>Mon, 27 Dec 2010 06:02:00 +0000</pubDate>
      
      <guid>/questions/1488/converting-rtp-streams-into-audiofiles/</guid>
      <description>Converting RTP Streams into audiofiles  0 Hi all,
I use a router called AVM Fritzbox 7270 with Linux Ubuntu 10.10. The router has a hidden feature to capture network traffic. It allows me to produces .eth files that can be analyzed via wireshark.
In order to generate an audio file I use the following procedure:
generate a .eth-file and save it to hard drive.
Wireshark-&amp;gt;Telephony-&amp;gt;RTP-&amp;gt;Show all Streams
Select Stream -&amp;gt; Analyze -&amp;gt; save payload</description>
    </item>
    
    <item>
      <title>rawshark example</title>
      <link>/questions/1489/rawshark-example/</link>
      <pubDate>Mon, 27 Dec 2010 08:25:00 +0000</pubDate>
      
      <guid>/questions/1489/rawshark-example/</guid>
      <description>rawshark example  1 I am looking for a good documentation on rawshark with good examples(other than the man page). I tried using the rawshark man page but I can not find any practical examples embedded in the man page.
rawsharkasked 27 Dec &#39;10, 08:25
averageguy
16●2●2●3
accept rate: 0%
  
One Answer:
  
2OK, I&#39;ve been circling around this rawshark for a day now, and here&#39;s my two cents :</description>
    </item>
    
    <item>
      <title>error on capture interface</title>
      <link>/questions/1493/error-on-capture-interface/</link>
      <pubDate>Tue, 28 Dec 2010 00:06:00 +0000</pubDate>
      
      <guid>/questions/1493/error-on-capture-interface/</guid>
      <description>error on capture interface  0 after i click start a error &#34;Please check that &#34;DeviceNPF_{FC0CF46C-B871-42C2-91F2-C82463030CC1}&#34; is the proper interface.&#34;always apear.
capture errorasked 28 Dec &#39;10, 00:06
Satriyo Tiyok
1●1●1●1
accept rate: 0%
Does the error say anything more than that? That looks like the second part of an error message, and the first part would probably say why it couldn&#39;t open that interface.
(01 Jan &#39;11, 10:23) Guy Harris ♦♦   </description>
    </item>
    
    <item>
      <title>How to capture the data sent from forms on websites?</title>
      <link>/questions/1494/how-to-capture-the-data-sent-from-forms-on-websites/</link>
      <pubDate>Tue, 28 Dec 2010 01:45:00 +0000</pubDate>
      
      <guid>/questions/1494/how-to-capture-the-data-sent-from-forms-on-websites/</guid>
      <description>How to capture the data sent from forms on websites?  0 Hi! Is it possible to capture the data that is sent from forms on websites?
If I use Firebug I can see what data that was sent from all the fields in a form, but I should see the same data in Wireshark, but I cannot. Isn´t it possible or am I doing something wrong?
forms data httpasked 28 Dec &#39;10, 01:45</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t find interface</title>
      <link>/questions/1498/cant-find-interface/</link>
      <pubDate>Tue, 28 Dec 2010 05:10:00 +0000</pubDate>
      
      <guid>/questions/1498/cant-find-interface/</guid>
      <description>can&amp;rsquo;t find interface  0 window version : Windows 7 Professional K wireshark version : 1.4.2 mobile : samsung android phone
when i use mobie dun, i want check my packet. but i can&#39;t find interface about dun. that time, mobile has ip and dun connect success. how can i find interface in wireshark.
thank you.
interfaceasked 28 Dec &#39;10, 05:10
nikol482
6●2●2●4
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Packet with unknown Ethernet type 0x4d45</title>
      <link>/questions/1501/packet-with-unknown-ethernet-type-0x4d45/</link>
      <pubDate>Tue, 28 Dec 2010 10:41:00 +0000</pubDate>
      
      <guid>/questions/1501/packet-with-unknown-ethernet-type-0x4d45/</guid>
      <description>Packet with unknown Ethernet type 0x4d45  0 Hey,
I did a capture of a piece of software on my laptop loading firmware to a device. The packets look like this in list view:
687 53.047211 Dell_cb:f1:96 MegaSyst_01:b5:cf 0x4d45 Ethernet II
The source (Dell..) is my laptop and the dest (Mega...) is the device. The protocol is showing up as 0x4d45 (Unknown) and the type is showing up as Ethernet II.</description>
    </item>
    
    <item>
      <title>Wireshark doesn&amp;#x27;t decode ESP encrypted responses</title>
      <link>/questions/1508/wireshark-doesnt-decode-esp-encrypted-responses/</link>
      <pubDate>Wed, 29 Dec 2010 05:36:00 +0000</pubDate>
      
      <guid>/questions/1508/wireshark-doesnt-decode-esp-encrypted-responses/</guid>
      <description>Wireshark doesn&amp;rsquo;t decode ESP encrypted responses  0 Hi,
I have the following topology for two systems which have an ipsec tunnel A[10.203.199.109]------------ B [10.203.199.126]
I have configured ESP preferences in Wireshark running in B system with the information got from &#39;ip xfrm state&#39; as mentioned below.
When I send icmp ping packets/SCTP Hearbeat packets from A and start capturning the requests and responses in wireshark (System B), I observe that wireshark doesn&#39;t decrypt the response from B to A(they appear as ESP protocol packets) while the icmp requests/SCTP Hearbeat packets sent by A are displayed after decryption.</description>
    </item>
    
    <item>
      <title>accessing web page and random content is missing</title>
      <link>/questions/1514/accessing-web-page-and-random-content-is-missing/</link>
      <pubDate>Wed, 29 Dec 2010 09:20:00 +0000</pubDate>
      
      <guid>/questions/1514/accessing-web-page-and-random-content-is-missing/</guid>
      <description>accessing web page and random content is missing  0 I am trying to establish a cause for this. I have two sites I get partial loads with different content missing. An example would be that sometimes the CSS file fails to be applied on some loads but not others. Another example would be that 6 out the ten images will fail to display but if I reload the page 4 random images will not display.</description>
    </item>
    
    <item>
      <title>Capture the first 64bytes of a packet?</title>
      <link>/questions/1515/capture-the-first-64bytes-of-a-packet/</link>
      <pubDate>Wed, 29 Dec 2010 11:01:00 +0000</pubDate>
      
      <guid>/questions/1515/capture-the-first-64bytes-of-a-packet/</guid>
      <description>Capture the first 64bytes of a packet?  0 Does Wireshark provide the option of capturing just the first x number of bytes of a packet or frame? Thanks.
capture partial packetasked 29 Dec &#39;10, 11:01
JamesClassV
1●2●2●2
accept rate: 0%
  
2 Answers:
  
1There are two ways to do this. One would be to recomiple the kernel of your operating system to capture 64 bytes (reprogram winpcap), OR in the capture options window (ctrl-K), you can use the Limit Each Packet to .</description>
    </item>
    
    <item>
      <title>help with filter netwotk!!!</title>
      <link>/questions/1522/help-with-filter-netwotk/</link>
      <pubDate>Wed, 29 Dec 2010 23:53:00 +0000</pubDate>
      
      <guid>/questions/1522/help-with-filter-netwotk/</guid>
      <description>help with filter netwotk!!!  0 I&#39;m just see this app from today i&#39;m like its i&#39;m test to capture,its ok but i can&#39;t fill IP target (like my PC IP 192.168.1.1)and target IP is 192.168.1.2 so i&#39;m want capture on IP 192.168.1.2 how to do? i can&#39;t see about do on its!!! help pls
com for here learnasked 29 Dec &#39;10, 23:53
morokat
1●1●1●1
accept rate: 0%
Morokat, Please answer the following questions so people can help you.</description>
    </item>
    
    <item>
      <title>Is there any dissector available for GTPv2 (29.274) - context request/response,Forward relocation request/response ?</title>
      <link>/questions/1534/is-there-any-dissector-available-for-gtpv2-29274-context-requestresponseforward-relocation-requestresponse/</link>
      <pubDate>Thu, 30 Dec 2010 02:21:00 +0000</pubDate>
      
      <guid>/questions/1534/is-there-any-dissector-available-for-gtpv2-29274-context-requestresponseforward-relocation-requestresponse/</guid>
      <description>Is there any dissector available for GTPv2 (29.274) - context request/response,Forward relocation request/response ?  0 I am using Wireshark Version 1.4.2 (SVN Rev 34959 from /trunk-1.4) I found that the below GTPv2 messages are not dissected completely(IE data not dissected). Is there any dissector available for GTPv2 29.274 V8.4.0(2009-12) for complete decoding of 1.context request/response, 2.Forward relocation request/response ?
gtpv2 s10 messages decodingasked 30 Dec &#39;10, 02:21
surendar
1●1●1●1</description>
    </item>
    
    <item>
      <title>how do you capture A-MSDU packet?</title>
      <link>/questions/1535/how-do-you-capture-a-msdu-packet/</link>
      <pubDate>Thu, 30 Dec 2010 02:44:00 +0000</pubDate>
      
      <guid>/questions/1535/how-do-you-capture-a-msdu-packet/</guid>
      <description>how do you capture A-MSDU packet?  0 can you help me capture A-MSDU packet by wwireshark? thamk you very much.
captureasked 30 Dec &#39;10, 02:44
haquyen
1●6●6●7
accept rate: 0%
  
2 Answers:
  
0You&#39;ll need the AirPcap Nx adapter.
answered 30 Dec &#39;10, 23:16
Jaap ♦
11.7k●16●101
accept rate: 14%
  
0oh, thanks Jaap
answered 31 Dec &#39;10, 05:49
haquyen
1●6●6●7
accept rate: 0%</description>
    </item>
    
    <item>
      <title>how to crate msdu to capture using wireshark?</title>
      <link>/questions/1540/how-to-crate-msdu-to-capture-using-wireshark/</link>
      <pubDate>Thu, 30 Dec 2010 09:22:00 +0000</pubDate>
      
      <guid>/questions/1540/how-to-crate-msdu-to-capture-using-wireshark/</guid>
      <description>how to crate msdu to capture using wireshark?  0 is there anyone show me how to crate msdu to capture using wireshark? help pls, thanks much
captureasked 30 Dec &#39;10, 09:22
haquyen
1●6●6●7
accept rate: 0%
 edited 31 Dec &#39;10, 05:50 
  
One Answer:
  
0There may be some easier ways, but a good place to start is &#34;http://wiki.wireshark.org/Tools&#34;. There is a program called tcpreplay that will output a pcap back out on the wire.</description>
    </item>
    
    <item>
      <title>IPv6 address range filter</title>
      <link>/questions/1543/ipv6-address-range-filter/</link>
      <pubDate>Thu, 30 Dec 2010 20:32:00 +0000</pubDate>
      
      <guid>/questions/1543/ipv6-address-range-filter/</guid>
      <description>IPv6 address range filter  0 How do I filter on a range of ipv6 addresses, for example an ipv6 filter similar to ipv4 192.168.0.0/16? I would like to filter on ipv6 addresses on my lan fe80::/10 but cannot seem to find the correct syntax.
Thanks!
filter capture ipv6asked 30 Dec &#39;10, 20:32
debianuser
1●1●1●1
accept rate: 0%
 edited 02 Jan &#39;11, 18:24 
Gerald Combs ♦♦
3.3k●9●22●58</description>
    </item>
    
    <item>
      <title>Promiscuous mode on Windows - not possible?</title>
      <link>/questions/1554/promiscuous-mode-on-windows-not-possible/</link>
      <pubDate>Fri, 31 Dec 2010 05:40:00 +0000</pubDate>
      
      <guid>/questions/1554/promiscuous-mode-on-windows-not-possible/</guid>
      <description>Promiscuous mode on Windows - not possible?  1 I am studying some network security and have two questions:
The WinPCap library that Wireshark (for Windows) is using requires that the network card can be set into promiscuous mode to be able to capture all packets &#34;in the air&#34;. I have understood that not many network cards can be set into that mode in Windows. So is it uncommon to use Wireshark for Windows to capture wifi packets?</description>
    </item>
    
    <item>
      <title>how to crate udp to capture ?</title>
      <link>/questions/1556/how-to-crate-udp-to-capture/</link>
      <pubDate>Fri, 31 Dec 2010 05:55:00 +0000</pubDate>
      
      <guid>/questions/1556/how-to-crate-udp-to-capture/</guid>
      <description>how to crate udp to capture ?  0 Is there anyone help me to crate udp packets? I have a subject about udp and anylies them, but i don&#39;t know crate them quickly? may you help me clearly, step by step? help me. thanks much.
captureasked 31 Dec &#39;10, 05:55
haquyen
1●6●6●7
accept rate: 0%
  
3 Answers:
  
0Why do you need to create one?</description>
    </item>
    
    <item>
      <title>X11 hang when cycling through windows on Mac 10.6.5 with Wireshark 1.4.0 and 1.4.2</title>
      <link>/questions/1559/x11-hang-when-cycling-through-windows-on-mac-1065-with-wireshark-140-and-142/</link>
      <pubDate>Fri, 31 Dec 2010 08:32:00 +0000</pubDate>
      
      <guid>/questions/1559/x11-hang-when-cycling-through-windows-on-mac-1065-with-wireshark-140-and-142/</guid>
      <description>X11 hang when cycling through windows on Mac 10.6.5 with Wireshark 1.4.0 and 1.4.2  0 I just downloaded the snow leopard 64 bit version of wireshark 1.4.2. The same problem with my 1.4.0 version. With the wireshark window open (in X11), if I hit the tilde key (~) to cycle through the windows, it cycles once but then freezes and wireshark will not do anything at all. I have to quit X11 and start back over.</description>
    </item>
    
    <item>
      <title>ssl on localhost</title>
      <link>/questions/1564/ssl-on-localhost/</link>
      <pubDate>Fri, 31 Dec 2010 17:54:00 +0000</pubDate>
      
      <guid>/questions/1564/ssl-on-localhost/</guid>
      <description>ssl on localhost  0 I am running a jetty server on my local machine using ssl. I have the p12 files from the server imported using 127.0.0.1,8443,http,&amp;lt;path&amp;gt;,&amp;lt;password&amp;gt;. Files show as being read by the ssldebug file. When I connect to my server using https://localhost:8443/ I get no traffic in wireshark.
sslasked 31 Dec &#39;10, 17:54
jetaber
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Are you running on Windows?</description>
    </item>
    
    <item>
      <title>how to automatically save to the file?</title>
      <link>/questions/1568/how-to-automatically-save-to-the-file/</link>
      <pubDate>Sat, 01 Jan 2011 02:50:00 +0000</pubDate>
      
      <guid>/questions/1568/how-to-automatically-save-to-the-file/</guid>
      <description>how to automatically save to the file?  0 I want to save result to a file automatically when start a new capture, but I don&#39;t want to set option each time, how i can do that?
auto saveasked 01 Jan &#39;11, 02:50
jackydi
1●2●2●2
accept rate: 0%
  
One Answer:
  
1If you drop out to a command line and do a &#34;wireshark -h&#34;, it will give you all of the command line options.</description>
    </item>
    
    <item>
      <title>fetching multiple named values with lua</title>
      <link>/questions/1579/fetching-multiple-named-values-with-lua/</link>
      <pubDate>Sat, 01 Jan 2011 16:50:00 +0000</pubDate>
      
      <guid>/questions/1579/fetching-multiple-named-values-with-lua/</guid>
      <description>fetching multiple named values with lua  1 In working on a lua extension, I want to be able to extract multiple instances of a field within a single packet. For example, in DNS, it&#39;s not uncommon to have multiple responses to a query. As an example, in this dns capture file, there are multiple responses in packets 4, 24 and 29. What I would like to do is get all instances of a field such as dns.</description>
    </item>
    
    <item>
      <title>Detect wireshark usage on network</title>
      <link>/questions/1580/detect-wireshark-usage-on-network/</link>
      <pubDate>Sat, 01 Jan 2011 17:18:00 +0000</pubDate>
      
      <guid>/questions/1580/detect-wireshark-usage-on-network/</guid>
      <description>Detect wireshark usage on network  1 How can I know if somebody is using wireshark to analyze traffic on the network?
analyze wiresharkasked 01 Jan &#39;11, 17:18
skypemesm
46●6●6●9
accept rate: 0%
  
3 Answers:
  
2While packet sniffing is generally quite passive, in that you are meant to be listening to just copies of packets there are techniques. As Hansang said one way is to detect how the network responds to certain ARP packets.</description>
    </item>
    
    <item>
      <title>SKINNY protocol analysis</title>
      <link>/questions/1587/skinny-protocol-analysis/</link>
      <pubDate>Sun, 02 Jan 2011 10:52:00 +0000</pubDate>
      
      <guid>/questions/1587/skinny-protocol-analysis/</guid>
      <description>SKINNY protocol analysis  0 Hello! I am engaged in development of the program for the analysis of packets of SKINNY protocol. How program WireShark obtains the data of this protocol? How information Message ID and Call Identifier is extracted from packet SKINNY? Thanks for the help! development skinny protocolasked 02 Jan &#39;11, 10:52
masterbloger
1●2●2●4
accept rate: 0%
 edited 02 Jan &#39;11, 11:01 
  
One Answer:</description>
    </item>
    
    <item>
      <title>Link to your website and sponser your program</title>
      <link>/questions/1588/link-to-your-website-and-sponser-your-program/</link>
      <pubDate>Sun, 02 Jan 2011 13:55:00 +0000</pubDate>
      
      <guid>/questions/1588/link-to-your-website-and-sponser-your-program/</guid>
      <description>Link to your website and sponser your program  0 This is not a tech question about your amazing program called Wireshark.
I was wondering if I could post a reference link to your site? I really love your program and I have started using a tutorial information on maintaining a server and this program has helped with a lot of issues I have been running into as a diagnostic tool.</description>
    </item>
    
    <item>
      <title>Prevent tshark from parsing http response data</title>
      <link>/questions/1595/prevent-tshark-from-parsing-http-response-data/</link>
      <pubDate>Mon, 03 Jan 2011 07:08:00 +0000</pubDate>
      
      <guid>/questions/1595/prevent-tshark-from-parsing-http-response-data/</guid>
      <description>Prevent tshark from parsing http response data  0 I&#39;m running tshark on a web-surfing capture and noticed than it parses the http response&#39;s data (when I choose PDML as the output format). This is somewhat annoying when the response consists of an image. I would rather get a blob of data which I can view later as an image, than the PNG&#39;s headers and their values. Here&#39;s an example:</description>
    </item>
    
    <item>
      <title>failed download of latest version</title>
      <link>/questions/1597/failed-download-of-latest-version/</link>
      <pubDate>Mon, 03 Jan 2011 07:37:00 +0000</pubDate>
      
      <guid>/questions/1597/failed-download-of-latest-version/</guid>
      <description>failed download of latest version  0 I&#39;m trying to download the most recent version of wireshark but get a 0kb non-executable file. Any ideas what the problem might be?
downloadasked 03 Jan &#39;11, 07:37
securityfan
1●1●1●1
accept rate: 0%
What URL are you using to download? Have you tried browsing the download area at http://media-2.cacetech.com/wireshark/?
(03 Jan &#39;11, 07:46) Gerald Combs ♦♦Gerald,
Thanks for responding, I originally tried to download from Wireshark and I have tried your suggestion and still get 0KB file.</description>
    </item>
    
    <item>
      <title>Save output of sessions to continuous logs</title>
      <link>/questions/1599/save-output-of-sessions-to-continuous-logs/</link>
      <pubDate>Mon, 03 Jan 2011 07:48:00 +0000</pubDate>
      
      <guid>/questions/1599/save-output-of-sessions-to-continuous-logs/</guid>
      <description>Save output of sessions to continuous logs  0 I want to capture everything from a mirrored port to my router. I want to be able to get captures in one hour increments continuously for four days then start wrapping these captures so the hard drive does not fill up.
Is there a way to leave Wireshark running, then “cut pcap’s” every hour, then start wrapping these files after four days?</description>
    </item>
    
    <item>
      <title>source and destination ports as seperate columns</title>
      <link>/questions/1604/source-and-destination-ports-as-seperate-columns/</link>
      <pubDate>Mon, 03 Jan 2011 13:13:00 +0000</pubDate>
      
      <guid>/questions/1604/source-and-destination-ports-as-seperate-columns/</guid>
      <description>source and destination ports as seperate columns  0 Hello, I have not been able to find a way to display source and destintation ports as seperately displayed columns such as: source ip, port, dest ip, port. Is there a way to do this?
port display-filterasked 03 Jan &#39;11, 13:13
eelarry
36●8●9●12
accept rate: 0%
  
2 Answers:
  
1 Yes, you can go to &#34;Edit -&amp;gt; Preferences -&amp;gt; Columns&#34;</description>
    </item>
    
    <item>
      <title>how do you use AirPcap to capture A-MSDU packet?</title>
      <link>/questions/1614/how-do-you-use-airpcap-to-capture-a-msdu-packet/</link>
      <pubDate>Tue, 04 Jan 2011 01:22:00 +0000</pubDate>
      
      <guid>/questions/1614/how-do-you-use-airpcap-to-capture-a-msdu-packet/</guid>
      <description>how do you use AirPcap to capture A-MSDU packet?  0 Hello everyone! I want to capture A-MSDU. I use AirPcap, but I don&#39;t khown how will A-MSDU appear? I read some document that show A-MSDU in UDP packets. So how do i have to crate it so that i have A-MSDU quickly and exactly. Thank everyone for your help!!!
captureasked 04 Jan &#39;11, 01:22
haquyen
1●6●6●7
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Network errors using Windows 7</title>
      <link>/questions/1617/network-errors-using-windows-7/</link>
      <pubDate>Tue, 04 Jan 2011 07:35:00 +0000</pubDate>
      
      <guid>/questions/1617/network-errors-using-windows-7/</guid>
      <description>Network errors using Windows 7  0 I have two identical Asus motherboards: One running Windows XP, the other running Windows 7. When I run Wireshark on the WinXP machine I get approx&#39; 1 error in 10,000 packets.
When I run Wireshark on the Win7 machine I get over 3,500 errors in 10,000 packets.
I&#39;ve tried swapping the hard drives from one machine to the other but problem moves with the O/S.</description>
    </item>
    
    <item>
      <title>packet delay</title>
      <link>/questions/1620/packet-delay/</link>
      <pubDate>Tue, 04 Jan 2011 10:08:00 +0000</pubDate>
      
      <guid>/questions/1620/packet-delay/</guid>
      <description>packet delay  0 hi plz i want to know how i can use wireshark to measure packet delay&amp;amp; packet loss through network
packetdelayasked 04 Jan &#39;11, 10:08
flower
1●3●3●3
accept rate: 0%
  
6 Answers:
  
0What type of traffic are you looking at? Is it TCP?
answered 04 Jan &#39;11, 15:51
Paul Stewart
301●8
accept rate: 6%
  
0Wireshark provide several ways of doing that, depending on the higher-layer protocols you are running on your network.</description>
    </item>
    
    <item>
      <title>What does this mean ?</title>
      <link>/questions/1622/what-does-this-mean/</link>
      <pubDate>Tue, 04 Jan 2011 13:38:00 +0000</pubDate>
      
      <guid>/questions/1622/what-does-this-mean/</guid>
      <description>What does this mean ?  0 I use a Realtek RTL8187 USB adapter and it seems not to be recognized by Wireshark.
The capture session could not be initiated (failed to set hardware filter to promiscuous mode).
Please check that &#34;DeviceNPF_{FF58589B-5BF6-4A78-988F-87B508471370}&#34; is the proper interface.
Help can be found at:
 http://wiki.wireshark.org/WinPcap http://wiki.wireshark.org/CaptureSetupadapter rtl8187 usbasked 04 Jan &#39;11, 13:38
TEEH
1●2●2●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Network and Trust Center Key Question</title>
      <link>/questions/1624/network-and-trust-center-key-question/</link>
      <pubDate>Tue, 04 Jan 2011 14:18:00 +0000</pubDate>
      
      <guid>/questions/1624/network-and-trust-center-key-question/</guid>
      <description>Network and Trust Center Key Question  0 Hello, I am trying to read the data sent from a zigbee enabled smart meter but the packets keep saying &#34;Encrypted Payload&#34;
I have inserted both Trust Center and Network Key under Edit-&amp;gt;Preferences-&amp;gt;Protocols-&amp;gt;ZigBee NWK, but I still get the same message.
Here is the format of the Network and Trust Center keys: xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx
I have the security level set as AES 128 Bit Encryption and 32 bit Interity Protection.</description>
    </item>
    
    <item>
      <title>Sending packets</title>
      <link>/questions/1626/sending-packets/</link>
      <pubDate>Tue, 04 Jan 2011 15:09:00 +0000</pubDate>
      
      <guid>/questions/1626/sending-packets/</guid>
      <description>Sending packets  0 Is it possible to send packets into network by using wireshark?
I want to send packet files(ex: .pcap) from one user to another within a network.sending packetasked 04 Jan &#39;11, 15:09
rocky
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Simple answer, no.
You might want to look at programs like bit-twist or tcpreplay to do what you want.
answered 04 Jan &#39;11, 15:37</description>
    </item>
    
    <item>
      <title>HASH from EAPOL</title>
      <link>/questions/1631/hash-from-eapol/</link>
      <pubDate>Tue, 04 Jan 2011 23:51:00 +0000</pubDate>
      
      <guid>/questions/1631/hash-from-eapol/</guid>
      <description>HASH from EAPOL  0 I have captured all 4 pieces of the WPA handshake ... How do I extract the HASH from here. I can see all 4 pieces when I search EAPOL in the dump file.. Were do I go for here. Thanks
eapolasked 04 Jan &#39;11, 23:51
mbfd560
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>capturing data from tcp stream</title>
      <link>/questions/1632/capturing-data-from-tcp-stream/</link>
      <pubDate>Wed, 05 Jan 2011 05:32:00 +0000</pubDate>
      
      <guid>/questions/1632/capturing-data-from-tcp-stream/</guid>
      <description>capturing data from tcp stream  0 Hi
I want to extract only binary data from entire conversation. How to do it ? I want pure binary data without HTTP headers.
thx in advance for any help
tcp streamasked 05 Jan &#39;11, 05:32
borisTheBlade
1●1●1●2
accept rate: 0%
 edited 05 Jan &#39;11, 05:33 
  
3 Answers:
  
1Did you try exporting the content you want?</description>
    </item>
    
    <item>
      <title>Multi-Process Wireshark</title>
      <link>/questions/1636/multi-process-wireshark/</link>
      <pubDate>Wed, 05 Jan 2011 11:32:00 +0000</pubDate>
      
      <guid>/questions/1636/multi-process-wireshark/</guid>
      <description>Multi-Process Wireshark  0 Is it possible to run several processes of Wireshark on a single PC running Windows (as long as we have several Ethernet ports)?
windows multi-processasked 05 Jan &#39;11, 11:32
jhaynes
1●1●1●2
accept rate: 0%
  
One Answer:
  
2Yes, even if you have just one Ethernet card you can run multiple instances and capture, at least I did that a couple of times before, capturing with different sets of capture filters on the same card.</description>
    </item>
    
    <item>
      <title>Crashing after first installation</title>
      <link>/questions/1641/crashing-after-first-installation/</link>
      <pubDate>Wed, 05 Jan 2011 15:35:00 +0000</pubDate>
      
      <guid>/questions/1641/crashing-after-first-installation/</guid>
      <description>Crashing after first installation  0 X11 is booting fine. Wireshark is crashing: Here&#39;s the bug report:
Process: wireshark-bin [4578] Path: /Applications/VideoNet&amp;amp;Decorder/Wireshark.app/Contents/Resources/bin/wireshark-bin Identifier: wireshark-bin Version: ??? (???) Code Type: PPC (Native) Parent Process: Wireshark [4577] Interval Since Last Report: 429 sec Crashes Since Last Report: 2 Per-App Interval Since Last Report: 0 sec Per-App Crashes Since Last Report: 2
Date/Time: 2011-01-06 00:24:32.262 +0100 OS Version: Mac OS X 10.5.8 (9L31a) Report Version: 6 Anonymous UUID: B8D7FBF7-6F29-4E5F-8DAA-234200F58426</description>
    </item>
    
    <item>
      <title>ssl decode - client cert used?</title>
      <link>/questions/1642/ssl-decode-client-cert-used/</link>
      <pubDate>Wed, 05 Jan 2011 18:27:00 +0000</pubDate>
      
      <guid>/questions/1642/ssl-decode-client-cert-used/</guid>
      <description>ssl decode - client cert used?  0 Hi. Today I was asked to verify that particular ssl transaction did NOT include the sending of a Client Cert. So I captured packets on the client and fed them into wireshark. The SSL decode showed Client Hello, Server Hello, Certificate (from the server), Server Hello Done, Client Key Exchange, Change Cipher Spec, Encrypted Handshake Message and Application Data It did NOT show a Certificate sent by the Client (nor any dropped packets).</description>
    </item>
    
    <item>
      <title>Wireshark freezing when restart/show options/List interfaces after stop the running live capture using PIPE file feed data</title>
      <link>/questions/1645/wireshark-freezing-when-restartshow-optionslist-interfaces-after-stop-the-running-live-capture-using-pipe-file-feed-data/</link>
      <pubDate>Wed, 05 Jan 2011 23:49:00 +0000</pubDate>
      
      <guid>/questions/1645/wireshark-freezing-when-restartshow-optionslist-interfaces-after-stop-the-running-live-capture-using-pipe-file-feed-data/</guid>
      <description>Wireshark freezing when restart/show options/List interfaces after stop the running live capture using PIPE file feed data  0 I use &#34;wireshark -k -i pipeFileName&#34; to launch wireshark, My application feeds data to wireshark using pipe file. I stop the running live capture using &#34;Stop&#34; button, When I perform other operations, like &#34;restart/start live capture/show options/List interfaces&#34;, Wireshark always frozen. is it a bug??
feed data freezing pipe fileasked 05 Jan &#39;11, 23:49</description>
    </item>
    
    <item>
      <title>ipv6 hosts name resolution</title>
      <link>/questions/1646/ipv6-hosts-name-resolution/</link>
      <pubDate>Thu, 06 Jan 2011 00:52:00 +0000</pubDate>
      
      <guid>/questions/1646/ipv6-hosts-name-resolution/</guid>
      <description>ipv6 hosts name resolution  0 Greetings everyone,
I&#39;m trying to get ipv6 name resolution working using hosts file. It works ok for IPv4 addresses but I&#39;ve tried many formats for and still can&#39;t get it to translate IPv6 hosts, see below my attempts:
fe80::10:18ff:fe99:9904 Machine1 fe80.0000.0000.0000.0010.18ff.fe99.9904 Machine2 fe80::210:18ff:fe96:3f66 Machine3 fe80:0000:0000:0000:0210:18ff:fe96:3f66 Machine4 fe80::21:70ff:fe9b:9925 Machine5 fe.80.00.00.00.00.00.00.00.21.70.ff.fe.9b.99.25 Machine6 fe-80-00-00-00-00-00-00-00-0c-29-ff-fe-c4-2f-f0 Machine7 192.168.1.100 Machine8 2.2.2.1 Machine9 2.2.2.2 Machine10Regards - Philippe
hosts resolution name ipv6asked 06 Jan &#39;11, 00:52</description>
    </item>
    
    <item>
      <title>No interfaces in wireshark</title>
      <link>/questions/1647/no-interfaces-in-wireshark/</link>
      <pubDate>Thu, 06 Jan 2011 03:13:00 +0000</pubDate>
      
      <guid>/questions/1647/no-interfaces-in-wireshark/</guid>
      <description>No interfaces in wireshark  0 Hello all,
I installed wireshark on Ubuntu 10.4 with Synaptic, but in Capture Options I don&#39;t see any interfaces? Some one know what is wrong here?
Thanks for the support Sincerely Herman
interfaces missingasked 06 Jan &#39;11, 03:13
blakkie
1●1●1●1
accept rate: 0%
 edited 28 Feb &#39;12, 20:14 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
0Your dumpcap program needs elevated privileges.</description>
    </item>
    
    <item>
      <title>What would cause [RST,ACK]</title>
      <link>/questions/1652/what-would-cause-rstack/</link>
      <pubDate>Thu, 06 Jan 2011 11:06:00 +0000</pubDate>
      
      <guid>/questions/1652/what-would-cause-rstack/</guid>
      <description>What would cause [RST,ACK]  1 I trying to track down a connection issue. What I&#39;m seeing is s [SYN] followed by a {RST,ACK} series of packets. What would cause this?
rstasked 06 Jan &#39;11, 11:06
vmjr
16●2●2●4
accept rate: 100%
  
2 Answers:
  
1This is very simply that the port you are trying to connect to is not being listened to on the remote host.</description>
    </item>
    
    <item>
      <title>Ideas for configuring catpure for outgoing Internet traffic?</title>
      <link>/questions/1654/ideas-for-configuring-catpure-for-outgoing-internet-traffic/</link>
      <pubDate>Thu, 06 Jan 2011 13:10:00 +0000</pubDate>
      
      <guid>/questions/1654/ideas-for-configuring-catpure-for-outgoing-internet-traffic/</guid>
      <description>Ideas for configuring catpure for outgoing Internet traffic?  0 At a site I monitor, the cable modem seems to go out often, and Comcast states the issue is internal to our network. We&#39;ve tried 3 modems throughout the year, all with same results, so I would like to try caputuring packets to see if there may be malformed packets causing the problem.
Cable modem -&amp;gt; Passive HUB -&amp;gt; WatchGuard X55 Edge firewall WAN1 port.</description>
    </item>
    
    <item>
      <title>uninstall 0.99.7 for Windows</title>
      <link>/questions/1658/uninstall-0997-for-windows/</link>
      <pubDate>Thu, 06 Jan 2011 17:28:00 +0000</pubDate>
      
      <guid>/questions/1658/uninstall-0997-for-windows/</guid>
      <description>uninstall 0.99.7 for Windows  0 I want to uninstall 0.99.7 in order to install the latest Wireshark. But it refuses to uninstall, saying: &#34;Please note: tshark.exe could not be removed, it&#39;s probably in use!&#34; [sic]
I just booted up; how did it come to be in use?
The platform is Windows XP Professional Version 2002 Service Pack 2.
windows xp tshark uninstallasked 06 Jan &#39;11, 17:28
R Alazar
1●1●1●1</description>
    </item>
    
    <item>
      <title>TCP Previous segment lost - Bug?</title>
      <link>/questions/1664/tcp-previous-segment-lost-bug/</link>
      <pubDate>Fri, 07 Jan 2011 03:00:00 +0000</pubDate>
      
      <guid>/questions/1664/tcp-previous-segment-lost-bug/</guid>
      <description>TCP Previous segment lost - Bug?  0 Hi, I&#39;ve come along some strange behavior of Wireshark. During a couple of captures, a lot of warnings appeared saying [TCP Previous segment lost]. Normally, this could occur is packets get lost or something, but you would suspect that the missing packets would be retransmitted some time later on (after the number of bytes in the send window are send and the first (missing) packet is not acknowledged by that time).</description>
    </item>
    
    <item>
      <title>tshark hex dump</title>
      <link>/questions/1670/tshark-hex-dump/</link>
      <pubDate>Fri, 07 Jan 2011 08:09:00 +0000</pubDate>
      
      <guid>/questions/1670/tshark-hex-dump/</guid>
      <description>tshark hex dump  0 Using tshark 1.2.11 to get a hex dump of packet data gives an error:
/opt/exp/sbin/tshark -r binary_gold -x &amp;gt; text_gold_new ** ERROR:print.c:794:print_hex_data: assertion failed: (edt-&amp;gt;pi.data_src) /opt/exp/sbin/tshark[5]: 2259 Abort(coredump)
Is this a known bug in 1.2.11, and is it fixed in later versions?
Here is my version info:
$ /opt/exp/sbin/tshark -v TShark 1.2.11
Copyright 1998-2010 Gerald Combs [email protected] and contributors. This is free software; see the source for copying conditions.</description>
    </item>
    
    <item>
      <title>Need help in upgrading the code to analyze traffic</title>
      <link>/questions/1684/need-help-in-upgrading-the-code-to-analyze-traffic/</link>
      <pubDate>Sat, 08 Jan 2011 10:28:00 +0000</pubDate>
      
      <guid>/questions/1684/need-help-in-upgrading-the-code-to-analyze-traffic/</guid>
      <description>Need help in upgrading the code to analyze traffic  0 Hello! Please help me deal with this problem. Need to analyze packets on a LAN in obtaining certain information to perform actions. Specifically, there is a computer network connected to it cisco ip phones and need to analyze packets SKINNY Protocol, which the phone communicates with the server. These packets arrive at port 2000 TCP protocol on the server. IP-address of the server such as 10.</description>
    </item>
    
    <item>
      <title>application not working</title>
      <link>/questions/1686/application-not-working/</link>
      <pubDate>Sat, 08 Jan 2011 18:42:00 +0000</pubDate>
      
      <guid>/questions/1686/application-not-working/</guid>
      <description>application not working  0 I&#39;ve downloaded Wireshark 1.4.2 PPC 32.dmg today and after installing it, the application does not open. it does not bring an application window up to the desktop; it is as if it was not there. Thank you
work does itasked 08 Jan &#39;11, 18:42
rubo
1●1●1●1
accept rate: 0%
Try running it from the command-line to see what error messages, if any, are displayed.
(22 Mar &#39;11, 08:15) cmaynard ♦♦   </description>
    </item>
    
    <item>
      <title>1 how to encapsulate wincapdriver fror 802.15.4   into ethrnet  frame</title>
      <link>/questions/1691/1-how-to-encapsulate-wincapdriver-fror-802154-into-ethrnet-frame/</link>
      <pubDate>Mon, 10 Jan 2011 02:26:00 +0000</pubDate>
      
      <guid>/questions/1691/1-how-to-encapsulate-wincapdriver-fror-802154-into-ethrnet-frame/</guid>
      <description>1 how to encapsulate wincapdriver fror 802.15.4 into ethrnet frame  0 Figure out how to supply data to Winpcap driver for 802.15.4 (You will need to encapsulate it in an Ethernet II frame)
wincapasked 10 Jan &#39;11, 02:26
sreeram
1●1●1●1
accept rate: 0%
Is there a Wireshark-related question here?
(22 Mar &#39;11, 08:10) cmaynard ♦♦   </description>
    </item>
    
    <item>
      <title>PackETH1.6.4 or 1.7 for windows software</title>
      <link>/questions/1696/packeth164-or-17-for-windows-software/</link>
      <pubDate>Mon, 10 Jan 2011 23:05:00 +0000</pubDate>
      
      <guid>/questions/1696/packeth164-or-17-for-windows-software/</guid>
      <description>PackETH1.6.4 or 1.7 for windows software  -1 Hi
I need the software of packETH1.6.4 or pack1.7 for windows, Pleasse can tell me the link
I want to create a packet for the packETH
Please send the reply to [email protected]
packethasked 10 Jan &#39;11, 23:05
Shiva
0●1●1●1
accept rate: 0%
 edited 10 Jan &#39;11, 23:53 
Jaap ♦
11.7k●16●101
  
2 Answers:
  
1Let me Google that for you, http://tinyurl.</description>
    </item>
    
    <item>
      <title>&amp;quot;TCP out of order &amp;quot; what does it means ?!!!</title>
      <link>/questions/1698/tcp-out-of-order-what-does-it-means/</link>
      <pubDate>Mon, 10 Jan 2011 23:54:00 +0000</pubDate>
      
      <guid>/questions/1698/tcp-out-of-order-what-does-it-means/</guid>
      <description>&amp;ldquo;TCP out of order &amp;quot; what does it means ?!!!  0 I have packet with protocol HTTP and named as &#34;TCP [Out-Of-Order] HTTP/1.1 200 OK (text/html)&#34;
please explain what does it means ?
of order tcp outasked 10 Jan &#39;11, 23:54
ALMahbob
1●1●1●2
accept rate: 0%
  
One Answer:
  
2It simply means that particular frame was received in a different order from which it was sent (after a later packet in the sequence).</description>
    </item>
    
    <item>
      <title>Error LNK2019</title>
      <link>/questions/1700/error-lnk2019/</link>
      <pubDate>Tue, 11 Jan 2011 04:38:00 +0000</pubDate>
      
      <guid>/questions/1700/error-lnk2019/</guid>
      <description>Error LNK2019  0 Hi,
I&#39;m trying to create a new dissector based on the tftp disector. For that I copy/cut packet-tftp.c from epan/dissector/ to a new folder /dissector/myProject. I replaced &#34;tftp&#34; by &#34;myDissector&#34; in this file. During the compilation, I get an error like this:
packet-myDissector.obj : error LNK2019: symbole externe non résolu tvb_get_seasonal_string référencé dans la fonction dissect_myDissector_message myDissector.dll : fatal error LNK1120: 1 external non résolus.
The tvb_get_seasonal_string is in the tvbuff.</description>
    </item>
    
    <item>
      <title>failed to install libraries</title>
      <link>/questions/1704/failed-to-install-libraries/</link>
      <pubDate>Tue, 11 Jan 2011 06:44:00 +0000</pubDate>
      
      <guid>/questions/1704/failed-to-install-libraries/</guid>
      <description>failed to install libraries  0 I tried to setup the build environment for Windows XP. I have installed Visual Studio 2005 ver.8, cygwin and python 27. Since I had problems with downloading the libraries, I did it manually by SVN. I put them into wireshark lib directory, which was specified in config.nmake file, and run &#34;nmake -f Makefile.nmake setup&#34;. The following errors happen:
&#34; .... File `gtk+-bundle_2.16.6-20100207_win32.zip&#39; already there; not retrieving.</description>
    </item>
    
    <item>
      <title>Export Packet Data to text file on the fly</title>
      <link>/questions/1705/export-packet-data-to-text-file-on-the-fly/</link>
      <pubDate>Tue, 11 Jan 2011 08:41:00 +0000</pubDate>
      
      <guid>/questions/1705/export-packet-data-to-text-file-on-the-fly/</guid>
      <description>Export Packet Data to text file on the fly  0 I know that you can export capture data to a plain text file, but I was wondering if there&#39;s any way to limit that export scope to just the raw data part of the packet, and if you can apply that so that it actively outputs the data from an ongoing live capture to a text file?
This is probably easily set up, but I thought I&#39;d ask if there&#39;s any quick and simple filter syntax or anything that could help me out.</description>
    </item>
    
    <item>
      <title>Automatically start capturing packets when bandwidth is high</title>
      <link>/questions/1709/automatically-start-capturing-packets-when-bandwidth-is-high/</link>
      <pubDate>Tue, 11 Jan 2011 15:43:00 +0000</pubDate>
      
      <guid>/questions/1709/automatically-start-capturing-packets-when-bandwidth-is-high/</guid>
      <description>Automatically start capturing packets when bandwidth is high  0 Hi there.
I&#39;d like to leave WireShark running on all my machines, and have it automatically capture packets when total bandwidth usage is above a user defined value.
For example, I have WireShark running on my machine 24/7, and when the connection being monitored starts to use 20Mbps or more, WireShark will begin capturing the packets and dumping them into a file (Preferably timestamped).</description>
    </item>
    
    <item>
      <title>Apple Mac having issue connecting to secure sites through wireless connection</title>
      <link>/questions/1719/apple-mac-having-issue-connecting-to-secure-sites-through-wireless-connection/</link>
      <pubDate>Wed, 12 Jan 2011 14:23:00 +0000</pubDate>
      
      <guid>/questions/1719/apple-mac-having-issue-connecting-to-secure-sites-through-wireless-connection/</guid>
      <description>Apple Mac having issue connecting to secure sites through wireless connection  0 I have a customer who just added a metro wireless connection to his office in Los Angeles and is seeing speeds at 10M down and 3M or so up for all machines on the network (30). His Apple Macs, however can not do anything with secured sites such as Paypal or Bank of America etc when accessing them, they just hang.</description>
    </item>
    
    <item>
      <title>Will we be able to open the traces collect from Mac Machine into a Windows Machine using Wireshark</title>
      <link>/questions/1720/will-we-be-able-to-open-the-traces-collect-from-mac-machine-into-a-windows-machine-using-wireshark/</link>
      <pubDate>Wed, 12 Jan 2011 16:20:00 +0000</pubDate>
      
      <guid>/questions/1720/will-we-be-able-to-open-the-traces-collect-from-mac-machine-into-a-windows-machine-using-wireshark/</guid>
      <description>Will we be able to open the traces collect from Mac Machine into a Windows Machine using Wireshark  0 Hi, will we be able to open the network traces collected from the MAC Machine into a Windows Machine using Wireshark?
tracesasked 12 Jan &#39;11, 16:20
Vineet
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Yes, that should be possible.
answered 12 Jan &#39;11, 22:38
Jaap ♦</description>
    </item>
    
    <item>
      <title>Cannot see packets from other devices on my network</title>
      <link>/questions/1721/cannot-see-packets-from-other-devices-on-my-network/</link>
      <pubDate>Wed, 12 Jan 2011 20:12:00 +0000</pubDate>
      
      <guid>/questions/1721/cannot-see-packets-from-other-devices-on-my-network/</guid>
      <description>Cannot see packets from other devices on my network  0 I have read the FAQ: When I use Wireshark to capture packets, why do I see only packets to and from my machine, or not see all the traffic I&#39;m expecting to see from or to the machine I&#39;m trying to monitor?
I have read the explanation for that question a couple times, and am not sure I really understand what&#39;s going on.</description>
    </item>
    
    <item>
      <title>external sign &amp;quot;__security_cookie&amp;quot; can not be resolved，紧急，谢谢！</title>
      <link>/questions/1725/external-sign-__security_cookie-can-not-be-resolved/</link>
      <pubDate>Wed, 12 Jan 2011 23:55:00 +0000</pubDate>
      
      <guid>/questions/1725/external-sign-__security_cookie-can-not-be-resolved/</guid>
      <description>external sign &amp;ldquo;__security_cookie&amp;rdquo; can not be resolved，紧急，谢谢！  0 My Wireshark Version : V1.4.4;
Using compiler: Microsoft Visual studio 2008
when &#34;.toolslemonlemon.c&#34; file compiled, encoutered error messages like as:
lemon.obj : error LNK2019 : can not resolve external sign &#34;__security_cookie&#34;, this sign was referred in _ErrorMsg function.
lemon.obj : error LNK2019 : can not resolve external sign &#34;@[email protected]&#34;, this sign was referred in _ErrorMsg function.
lemon.exe : fatal error LNK1120 : two commands could not be resolved;</description>
    </item>
    
    <item>
      <title>Install 2 environments</title>
      <link>/questions/1727/install-2-environments/</link>
      <pubDate>Thu, 13 Jan 2011 00:04:00 +0000</pubDate>
      
      <guid>/questions/1727/install-2-environments/</guid>
      <description>Install 2 environments  0 I want to work with version 1.2.1 and 1.3.6
Is it possible to install and work with 2 environments on the same computer?
development environmentasked 13 Jan &#39;11, 00:04
Alrik
1●3●3●4
accept rate: 0%
  
2 Answers:
  
1Certainly.
Depending upon your needs, you may want to create a separate profile for each Wireshark version and then start whichever version of Wireshark with the -C option to specify the profile to be used.</description>
    </item>
    
    <item>
      <title>How to hide &amp;quot;Unknown&amp;quot; Protocol?</title>
      <link>/questions/1728/how-to-hide-unknown-protocol/</link>
      <pubDate>Thu, 13 Jan 2011 00:52:00 +0000</pubDate>
      
      <guid>/questions/1728/how-to-hide-unknown-protocol/</guid>
      <description>How to hide &amp;ldquo;Unknown&amp;rdquo; Protocol?  0 I checked only Kerberos protocols in &#34;Enabled Protocols&#34; list. But &#34;Capturing...&#34; window shows a lot of &#34;Unknown protocol&#34; records. Is it possible to hide these records?
settingsasked 13 Jan &#39;11, 00:52
ateam
1●1●1●2
accept rate: 0%
 edited 13 Jan &#39;11, 00:53 
  
One Answer:
  
0The &#34;Enabled Protocols&#34; preference controls which protocols are attempted to be examined and dissected by Wireshark.</description>
    </item>
    
    <item>
      <title>Will capture size have bearing on throuput measurement?</title>
      <link>/questions/1729/will-capture-size-have-bearing-on-throuput-measurement/</link>
      <pubDate>Thu, 13 Jan 2011 01:28:00 +0000</pubDate>
      
      <guid>/questions/1729/will-capture-size-have-bearing-on-throuput-measurement/</guid>
      <description>Will capture size have bearing on throuput measurement?  0 When I limit the capture of packet to about 100 bytes (paer packet), there is visible change in throuput measurement (as indicated in the summary). Why would this happen?
packet sizeasked 13 Jan &#39;11, 01:28
Raghav
1●1●1●1
accept rate: 0%
Can you describe the actual difference (and confirm the traffic you are monitoring hasn&#39;t changed)?
That sounds like a bug.</description>
    </item>
    
    <item>
      <title>Telephony ... VOIP calls</title>
      <link>/questions/1734/telephony-voip-calls/</link>
      <pubDate>Thu, 13 Jan 2011 03:00:00 +0000</pubDate>
      
      <guid>/questions/1734/telephony-voip-calls/</guid>
      <description>Telephony &amp;hellip; VOIP calls  0 When I select Telephony and then VOIP calls, I get a neat report of all calls, start and end time. But it does not allow me to save the results into a file for post processing - to calculate the time taken for each call etc. How to save the results to a file?
voipasked 13 Jan &#39;11, 03:00
sree
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Interpreting channel frequency field in Radiotap header of 802.11 capture</title>
      <link>/questions/1737/interpreting-channel-frequency-field-in-radiotap-header-of-80211-capture/</link>
      <pubDate>Thu, 13 Jan 2011 06:16:00 +0000</pubDate>
      
      <guid>/questions/1737/interpreting-channel-frequency-field-in-radiotap-header-of-80211-capture/</guid>
      <description>Interpreting channel frequency field in Radiotap header of 802.11 capture  0 I have an AirPCap capture. It shows the value 8509 in the channel frequency field of the Radiotap header. Wireshark also displays this as 2437 [channel BG 6].
My question is - how is this value of 8509 interpreted? How does 8509 translate to 2437? I have not found any related information on radiotap.org or other sources.
Thanks Manish</description>
    </item>
    
    <item>
      <title>Changing Defaults</title>
      <link>/questions/1739/changing-defaults/</link>
      <pubDate>Thu, 13 Jan 2011 10:17:00 +0000</pubDate>
      
      <guid>/questions/1739/changing-defaults/</guid>
      <description>Changing Defaults  0 We are running sip and RTP stream captures that are being sent to a Windows capture server using 10 Gig Fiber. This is the only thing we are using it for. What we are finding is there seems to be no way to change the defaults. For example, in Help - About Wireshare - Folders, the default for &#34;File&#34; dialogs, goes to &#34;My Documents&#34; folder. Is there a file that can be modified in Wireshark to change this directory?</description>
    </item>
    
    <item>
      <title>Eliminate duplicate source addresses</title>
      <link>/questions/1744/eliminate-duplicate-source-addresses/</link>
      <pubDate>Thu, 13 Jan 2011 14:22:00 +0000</pubDate>
      
      <guid>/questions/1744/eliminate-duplicate-source-addresses/</guid>
      <description>Eliminate duplicate source addresses  0 How can I eliminate duplicate source addresses so that I only see how many computers are communicating on a certain port? The display is filtered to only show port 137 and the addresses are sorted, but there are hundreds of packets for each source address because the capture ran for quite a while. I want to eliminate the duplicates to only show which computers are using 137.</description>
    </item>
    
    <item>
      <title>Explantion of wireshark trace</title>
      <link>/questions/1747/explantion-of-wireshark-trace/</link>
      <pubDate>Fri, 14 Jan 2011 03:01:00 +0000</pubDate>
      
      <guid>/questions/1747/explantion-of-wireshark-trace/</guid>
      <description>Explantion of wireshark trace  0 Hello,
I &#39;ve been trying to get trace in a network where we exchange SNMP messages between a server and a PC! In some SNMP messages that are sent by the Server and never reach the PC - while other do -, I am seeing a bad checksum message on the wireshark analysis! I also have a print screen of this capture! Can anybody advise on this!</description>
    </item>
    
    <item>
      <title>export multiple HTTP objects, unfortunately they are called the same (filename)</title>
      <link>/questions/1749/export-multiple-http-objects-unfortunately-they-are-called-the-same-filename/</link>
      <pubDate>Fri, 14 Jan 2011 06:30:00 +0000</pubDate>
      
      <guid>/questions/1749/export-multiple-http-objects-unfortunately-they-are-called-the-same-filename/</guid>
      <description>export multiple HTTP objects, unfortunately they are called the same (filename)  0 is it possible to have wireshark auto-rename files with same name, when saving all?
objects http features fileasked 14 Jan &#39;11, 06:30
lukas
1●1●1●1
accept rate: 0%
  
One Answer:
  
0ok, found a workaround, I was able to save these files by using Fiddler http://www.fiddler2.com/fiddler2/
answered 18 Jan &#39;11, 01:31
lukas
1●1●1●1</description>
    </item>
    
    <item>
      <title>Enhancement Request: Swap A/B On Conversation List</title>
      <link>/questions/1751/enhancement-request-swap-ab-on-conversation-list/</link>
      <pubDate>Fri, 14 Jan 2011 10:10:00 +0000</pubDate>
      
      <guid>/questions/1751/enhancement-request-swap-ab-on-conversation-list/</guid>
      <description>Enhancement Request: Swap A/B On Conversation List  0 Tried to find the proper forum for enhancement requests, and settled on this one. Forgive me if I guessed poorly.
I often use the Conversation List to track conversations between a database server and clients. However, sometimes the server shows up as &#34;PortA&#34; and sometimes as &#34;PortB&#34;, which makes it hard to sort the data by the number of database bytes requested.</description>
    </item>
    
    <item>
      <title>How do you capture FCoE frames?</title>
      <link>/questions/1752/how-do-you-capture-fcoe-frames/</link>
      <pubDate>Fri, 14 Jan 2011 11:49:00 +0000</pubDate>
      
      <guid>/questions/1752/how-do-you-capture-fcoe-frames/</guid>
      <description>How do you capture FCoE frames?  0 After capturing on a CNA CEE interface, The only FCoE packet that I see is a FIP advertisement. I don&#39;t see any Flogis, Plogis, etc. Even if I disable and enable the CNA while the capture is running. Are there specific steps to take to properly capture FCoE traffic?
fcoe cnaasked 14 Jan &#39;11, 11:49
Khenson
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Capture traffic</title>
      <link>/questions/1755/capture-traffic/</link>
      <pubDate>Fri, 14 Jan 2011 14:40:00 +0000</pubDate>
      
      <guid>/questions/1755/capture-traffic/</guid>
      <description>Capture traffic  0 I have 2 PC&#39;s set up to use Wireshark. Each PC has a different version of wireshark. I have set the ports up to be monitor ports. I have set up what vlans I want to capture. I only see broadcast traffic being captured. The interface on the switch shows unicast traffic going out the port toward the PC running wireshark. I never get it. I have no filters of any kind capture or display filters being used.</description>
    </item>
    
    <item>
      <title>type of attack related to the fields in the packets</title>
      <link>/questions/1758/type-of-attack-related-to-the-fields-in-the-packets/</link>
      <pubDate>Fri, 14 Jan 2011 23:25:00 +0000</pubDate>
      
      <guid>/questions/1758/type-of-attack-related-to-the-fields-in-the-packets/</guid>
      <description>type of attack related to the fields in the packets  0 I want to classify the type of attack related to the fields in the packets. i,e one or more may be associated with some type of vulnerability that is responsible for the attack. please tell me how to check which fields are associated with the attacks. means how can i find if field is changed or modified is there any effect of such attacks.</description>
    </item>
    
    <item>
      <title>count total traffic between 2 servers by port</title>
      <link>/questions/1762/count-total-traffic-between-2-servers-by-port/</link>
      <pubDate>Sat, 15 Jan 2011 13:43:00 +0000</pubDate>
      
      <guid>/questions/1762/count-total-traffic-between-2-servers-by-port/</guid>
      <description>count total traffic between 2 servers by port  0 Hi, can Wireshark count total traffic between 2 servers by port over a timeframe?
I need to figure out how much traffic goes between two servers on certain ports as I&#39;m considering moving one to the cloud and need to estimate data transfer costs.
Thanks!
count trafficasked 15 Jan &#39;11, 13:43
hanhartd
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>first run - no libwiretap.so.0</title>
      <link>/questions/1766/first-run-no-libwiretapso0/</link>
      <pubDate>Sun, 16 Jan 2011 14:36:00 +0000</pubDate>
      
      <guid>/questions/1766/first-run-no-libwiretapso0/</guid>
      <description>first run - no libwiretap.so.0  0 Hi, I&#39;ve just build wireshark on SUSE 11.3. There were no problems with compilation and installation, but when I try to run it, there is an error &#34;wireshark: error while loading shared libraries: libwiretap.so.0: cannot open shared object file: No such file or directory&#34;. This library is in /usr/local/lib but I don&#39;t know what to do to run wireshark. Thanks for your help</description>
    </item>
    
    <item>
      <title>What is that? is it right captured file?</title>
      <link>/questions/1768/what-is-that-is-it-right-captured-file/</link>
      <pubDate>Sun, 16 Jan 2011 15:56:00 +0000</pubDate>
      
      <guid>/questions/1768/what-is-that-is-it-right-captured-file/</guid>
      <description>What is that? is it right captured file?  0 I have captured on Android device. but i an not sure is right or not protocol is only SLL. wire shark doesn&#39;t show anything.
please help me
Thanks
sllasked 16 Jan &#39;11, 15:56
taehunzzang
16●2●2●4
accept rate: 0%
  
One Answer:
  
0SLL, sure, that&#39;s Linux Cooked capture. You should try a recent Wireshark development build and see what comes out there.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t get list of interfaces: The other host terminated the connection</title>
      <link>/questions/1771/cant-get-list-of-interfaces-the-other-host-terminated-the-connection/</link>
      <pubDate>Mon, 17 Jan 2011 07:18:00 +0000</pubDate>
      
      <guid>/questions/1771/cant-get-list-of-interfaces-the-other-host-terminated-the-connection/</guid>
      <description>Can&amp;rsquo;t get list of interfaces: The other host terminated the connection  1 Hello everyone...hope someone can help me.
I am trying to capture packets from another machine on my network. When I click the &#34;remote&#34; option and type in the ip address and port number I would like to capture, an error message comes up that says &#34;Can&#39;t get list of interfaces: The other host terminated the connection&#34;. Also, when I try to use port 80 instead of the port I am getting the other message with, it returns this error message: &#34;</description>
    </item>
    
    <item>
      <title>Are Wireshark&amp;#x27;s RTT Times Valid When Data is Captured on the Receiver?</title>
      <link>/questions/1773/are-wiresharks-rtt-times-valid-when-data-is-captured-on-the-receiver/</link>
      <pubDate>Mon, 17 Jan 2011 12:10:00 +0000</pubDate>
      
      <guid>/questions/1773/are-wiresharks-rtt-times-valid-when-data-is-captured-on-the-receiver/</guid>
      <description>Are Wireshark&amp;rsquo;s RTT Times Valid When Data is Captured on the Receiver?  0 How does Wireshark calculate the round-trip times used in the TCP Stream Graph &amp;gt; Round Trip Time Graph? Am I correct in thinking that Wireshark calculates the round-trip time by taking the difference between the time stamp of the data packet and the time stamp of the corresponding ACK packet, as seen by the Wireshark system that is doing the capturing?</description>
    </item>
    
    <item>
      <title>Upgraded to Comcast Business Connection, HTTPS Sites Flaky?!</title>
      <link>/questions/1777/upgraded-to-comcast-business-connection-https-sites-flaky/</link>
      <pubDate>Mon, 17 Jan 2011 16:40:00 +0000</pubDate>
      
      <guid>/questions/1777/upgraded-to-comcast-business-connection-https-sites-flaky/</guid>
      <description>Upgraded to Comcast Business Connection, HTTPS Sites Flaky?!  0 I recently upgraded my home connection to Comcast Business class (22Mbps down / 5Mbps down) with a static IP. Since moving from residential to business, my web connection is much, much faster for most pages. However, when loading HTTPS pages, about 75% of the time the request times out or is very, very slow (several seconds).
I had Comcast out a couple of days ago, they replaced the Comcast gateway so it&#39;s pretty unlikely it&#39;s a flaky modem.</description>
    </item>
    
    <item>
      <title>OMA ULP Protocol version 2.0 support problem and Malformed Packet: ULP error</title>
      <link>/questions/1779/oma-ulp-protocol-version-20-support-problem-and-malformed-packet-ulp-error/</link>
      <pubDate>Mon, 17 Jan 2011 22:41:00 +0000</pubDate>
      
      <guid>/questions/1779/oma-ulp-protocol-version-20-support-problem-and-malformed-packet-ulp-error/</guid>
      <description>OMA ULP Protocol version 2.0 support problem and Malformed Packet: ULP error  0 Hi, community, I&#39;m using 1.4.3 to trace the ULP message between two testing nodes, but found that it will report Malformed Packet: ULP error.
[Malformed Packet: ULP] Expert Info (Error/Malformed): Malformed Packet (Exception occurred) Message: Malformed Packet (Exception occurred) Severity level: Error Group: Malformed
even the msisdn part cannot be decoded successfully, does anyone know the ULP protocol version supported in 1.</description>
    </item>
    
    <item>
      <title>Only incoming packets problem</title>
      <link>/questions/1782/only-incoming-packets-problem/</link>
      <pubDate>Tue, 18 Jan 2011 00:48:00 +0000</pubDate>
      
      <guid>/questions/1782/only-incoming-packets-problem/</guid>
      <description>Only incoming packets problem  0 Hi All,
I&#39;m trying to capture the packets on my wifi router at home and for some reason i can only see incoming packets for my remote PC, no outgoing packets.
I&#39;m running wireshark in promiscuous mode on latest ubuntu distro. And i put my wireless card into monitor mode before starting the capture.
My wireless card is Alfa AWUS036H with mac80211 driver.
Any help will be much appreciated</description>
    </item>
    
    <item>
      <title>Trigger event on selection in packet list</title>
      <link>/questions/1792/trigger-event-on-selection-in-packet-list/</link>
      <pubDate>Tue, 18 Jan 2011 11:16:00 +0000</pubDate>
      
      <guid>/questions/1792/trigger-event-on-selection-in-packet-list/</guid>
      <description>Trigger event on selection in packet list  0 I&#39;d like to run some analysis code when the user selects a packet in the packet list. I know nothing about the Wireshark codebase. Is there an event model? Where do I start looking?
Can something like this be done in a dissector?
Thanks.
selection list event packetasked 18 Jan &#39;11, 11:16
joebrucepnnl
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>DCOM Decode not displaying the UUID in v1.4.3</title>
      <link>/questions/1794/dcom-decode-not-displaying-the-uuid-in-v143/</link>
      <pubDate>Tue, 18 Jan 2011 12:15:00 +0000</pubDate>
      
      <guid>/questions/1794/dcom-decode-not-displaying-the-uuid-in-v143/</guid>
      <description>DCOM Decode not displaying the UUID in v1.4.3  0 The UUID of DCOM packets are not displayed in the latest version of Wireshark. Older versions of Wireshark (v1.2.2 at least) properly display the UUID, but the newest version (v1.4.3) simply displays &#34;Transfer Syntax: Version 1.1 network data representation protocol&#34; instead of the UUID of the packet (8a885d04-1ceb-11c9-9fe8-08002b104860).
uuid dcomasked 18 Jan &#39;11, 12:15
glenn aydell
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to fully uninstall wireshark from a Mac?</title>
      <link>/questions/1797/how-to-fully-uninstall-wireshark-from-a-mac/</link>
      <pubDate>Tue, 18 Jan 2011 16:11:00 +0000</pubDate>
      
      <guid>/questions/1797/how-to-fully-uninstall-wireshark-from-a-mac/</guid>
      <description>How to fully uninstall wireshark from a Mac?  1 2Hello, loved the product. However, I&#39;m done messing around and now cannot figure out how to fully uninstall from my mac? I&#39;ve tried searching the documentation as well as this question area and cannot find any step by step guide on how to safely and easily uninstall?
Any help would be much appreciated!
macintosh uninstallasked 18 Jan &#39;11, 16:11
Pblocked</description>
    </item>
    
    <item>
      <title>Reg COBS and Wireshark dissectors</title>
      <link>/questions/1799/reg-cobs-and-wireshark-dissectors/</link>
      <pubDate>Tue, 18 Jan 2011 19:23:00 +0000</pubDate>
      
      <guid>/questions/1799/reg-cobs-and-wireshark-dissectors/</guid>
      <description>Reg COBS and Wireshark dissectors  0 Hi,
I am developing a dissector for a proprietary protocol. I would like to know how to handle packets that are encoded with COBS - Consistent Overhead Byte Stuffing. Are there any APIs available?
Thanks in Advance
Regards, Laser
cobsasked 18 Jan &#39;11, 19:23
Neo Laser
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Direct COBS support isn&#39;t available.</description>
    </item>
    
    <item>
      <title>Problem : Wireshark on 32bit Windows 7</title>
      <link>/questions/1800/problem-wireshark-on-32bit-windows-7/</link>
      <pubDate>Tue, 18 Jan 2011 20:28:00 +0000</pubDate>
      
      <guid>/questions/1800/problem-wireshark-on-32bit-windows-7/</guid>
      <description>Problem : Wireshark on 32bit Windows 7  0 Hi,
I have installed Wireshark (wireshark-win32-1.4.3) on my PC having 32-bit Windows 7 OS. When I tried to capture network packets its showing &#34;There is no interface on which capture can be done&#34;.
When I tried to see interfaces, its showing blank.
Could you please let me know how to configure it, previously I was using Windos XP on which it was working properly.</description>
    </item>
    
    <item>
      <title>Lua Examples to parse custom headers inside GRE</title>
      <link>/questions/1803/lua-examples-to-parse-custom-headers-inside-gre/</link>
      <pubDate>Tue, 18 Jan 2011 20:57:00 +0000</pubDate>
      
      <guid>/questions/1803/lua-examples-to-parse-custom-headers-inside-gre/</guid>
      <description>Lua Examples to parse custom headers inside GRE  0 Hi,
I am writing a dissector for parsing new data structure within the GRE. Ethernet+IPHEADER(OUTER)+GRE+Customdatastruct+Original( IP+TCP PACKET) as part of payload.
I am not sure what debugs can be turned on with Lua. My dissector is not working, it cannot parse the values inside the GRE packet. Can someone throw some light on this ?
I successed upto the point it shows GRE value as 47, flags and version as 0000, the protocol field is also displayed, beyond that it shows as DATA.</description>
    </item>
    
    <item>
      <title>How port name resolution is done in Wireshark ?</title>
      <link>/questions/1805/how-port-name-resolution-is-done-in-wireshark/</link>
      <pubDate>Tue, 18 Jan 2011 23:05:00 +0000</pubDate>
      
      <guid>/questions/1805/how-port-name-resolution-is-done-in-wireshark/</guid>
      <description>How port name resolution is done in Wireshark ?  0 i want to know about how port name resolution is done in wireshark? Directly using well known port numbers to match with the names or is there any other methods used for this purpose while decoding the port numbers ?
thanks
decoding port wiresharkasked 18 Jan &#39;11, 23:05
berkey
31●4●4●8
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Save packets from a filter into file</title>
      <link>/questions/1808/save-packets-from-a-filter-into-file/</link>
      <pubDate>Wed, 19 Jan 2011 00:34:00 +0000</pubDate>
      
      <guid>/questions/1808/save-packets-from-a-filter-into-file/</guid>
      <description>Save packets from a filter into file  0 Hi All, I have captured packets over network for some time, I have a big file by now . Now I want to save all the packets to or from a IP into separate file,because I don&#39;t need remaining . I used (ip.addr eq XX.XX.XX.XX) filter but it taking so much time in filtering and analyzing. Any help in this would be appriciated.</description>
    </item>
    
    <item>
      <title>Wireshark for linux (fedora 12)</title>
      <link>/questions/1811/wireshark-for-linux-fedora-12/</link>
      <pubDate>Wed, 19 Jan 2011 07:42:00 +0000</pubDate>
      
      <guid>/questions/1811/wireshark-for-linux-fedora-12/</guid>
      <description>Wireshark for linux (fedora 12)  0 Hi,
I have fedora 12 in my system. Can I download Wireshark for fedora 12 ?
If yes, then please let me know the link as well as the steps of installation.
Thanks Rke
wireshark fedora linuxasked 19 Jan &#39;11, 07:42
rketest
1●2●2●2
accept rate: 0%
 edited 20 Jan &#39;11, 12:25 
Jaap ♦
11.7k●16●101
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Mac OSX 10.5 New install crashes periodically</title>
      <link>/questions/1818/mac-osx-105-new-install-crashes-periodically/</link>
      <pubDate>Wed, 19 Jan 2011 10:35:00 +0000</pubDate>
      
      <guid>/questions/1818/mac-osx-105-new-install-crashes-periodically/</guid>
      <description>Mac OSX 10.5 New install crashes periodically  0 All I&#39;ve been able to detect thus far are a series of messages in the console log:
&amp;gt; 1/19/11 11:24:48 AM org.x.startx[541] AllocNewConnection: client index = 3, socket fd = 12 &amp;gt; 1/19/11 11:24:48 AM org.x.startx[541] AUDIT: Wed Jan 19 11:24:48 2011: 602 X: client 3 rejected from local host (uid 506) &amp;gt; 1/19/11 11:24:48 AM org.x.startx[541] Xlib: connection to &amp;quot;:0.0&amp;quot; refused by server &amp;gt; 1/19/11 11:24:48 AM org.</description>
    </item>
    
    <item>
      <title>Wireshark crash when do some menu operation on Wireshark  using Pipe file to feed data</title>
      <link>/questions/1825/wireshark-crash-when-do-some-menu-operation-on-wireshark-using-pipe-file-to-feed-data/</link>
      <pubDate>Wed, 19 Jan 2011 21:17:00 +0000</pubDate>
      
      <guid>/questions/1825/wireshark-crash-when-do-some-menu-operation-on-wireshark-using-pipe-file-to-feed-data/</guid>
      <description>Wireshark crash when do some menu operation on Wireshark using Pipe file to feed data  0 I use wireshark pipe mode to launch wireshark, &#34;wireshark -k -i pipeFileName&#34;. when do some menu operation, wireshark crashed. Edit --&amp;gt; Configuration Profiles (Do some change and Click OK or Apply) Edit --&amp;gt; Preferences (Do some change and Click OK or Apply) Tools --&amp;gt; Firewall ACL rules (Save rules) Any help is appreciated.</description>
    </item>
    
    <item>
      <title>Download tutorial &amp;quot;Introduction to Wireshark&amp;quot;</title>
      <link>/questions/1827/download-tutorial-introduction-to-wireshark/</link>
      <pubDate>Thu, 20 Jan 2011 01:51:00 +0000</pubDate>
      
      <guid>/questions/1827/download-tutorial-introduction-to-wireshark/</guid>
      <description>Download tutorial &amp;ldquo;Introduction to Wireshark&amp;rdquo;  0 Hi Administrator
I have a very slow internet connection so it is not possible to stream everytime, so I would like to know if it is possible to download the tutorial &#34;Introduction to Wireshark&#34; ?. I look forward to your reply.
Regards, Anish
downloadasked 20 Jan &#39;11, 01:51
anishjp
6●1●1●2
accept rate: 0%
  
One Answer:
  
0 It&#39;s this SWF file.</description>
    </item>
    
    <item>
      <title>Windows XP and bootp?</title>
      <link>/questions/1832/windows-xp-and-bootp/</link>
      <pubDate>Thu, 20 Jan 2011 07:55:00 +0000</pubDate>
      
      <guid>/questions/1832/windows-xp-and-bootp/</guid>
      <description>Windows XP and bootp?  0 Is it normal for an XP computer to use bootp to request it&#39;s IP? From the capture it appears the client only talks to the gateway and not direct to the DHCP server. The address in question is a manual DHCP that would be dished out for this client. So I see a DHCP request, 2 DHCP ACKs from the gateway and 3 G-ARPs from the client.</description>
    </item>
    
    <item>
      <title>I can&amp;#x27;t capture data packets  from my huawei 3G modem using Wireshark</title>
      <link>/questions/1839/i-cant-capture-data-packets-from-my-huawei-3g-modem-using-wireshark/</link>
      <pubDate>Thu, 20 Jan 2011 18:30:00 +0000</pubDate>
      
      <guid>/questions/1839/i-cant-capture-data-packets-from-my-huawei-3g-modem-using-wireshark/</guid>
      <description>I can&amp;rsquo;t capture data packets from my huawei 3G modem using Wireshark  0 Hi,
I&#39;m trying to capture some traffic from my PC, which is connected to a Huawei 3g modem model e220, but I don&#39;t see any traffic. Is there a way to get the packet data using Wireshark?
Thank you in advance.
huawei modem 3g captureasked 20 Jan &#39;11, 18:30
Gar
1●1●1●1
accept rate: 0%
 edited 25 Jun &#39;11, 22:21</description>
    </item>
    
    <item>
      <title>break missing at graph_select_segment?</title>
      <link>/questions/1841/break-missing-at-graph_select_segment/</link>
      <pubDate>Thu, 20 Jan 2011 22:12:00 +0000</pubDate>
      
      <guid>/questions/1841/break-missing-at-graph_select_segment/</guid>
      <description>break missing at graph_select_segment?  0 It really does not make sense to me that a break is not present before case ELMT_ARC: static void graph_select_segment (struct graph g, int x, int y) { struct element_list list; struct element *e; guint num = 0;
debug(DBS_FENTRY) puts (&amp;quot;graph_select_segment()&amp;quot;); x -= g-&amp;gt;geom.x; y = g-&amp;gt;geom.height-1 - (y - g-&amp;gt;geom.y);
set_busy_cursor (g-&amp;gt;drawing_area-&amp;gt;window);
for (list=g-&amp;gt;elists; list; list=list-&amp;gt;next) for (e=list-&amp;gt;elements; e-&amp;gt;type != ELMT_NONE; e++) { switch (e-&amp;gt;type) { case ELMT_RECT: break; case ELMT_LINE: if (line_detect_collision (e, x, y)) { num = e-&amp;gt;parent-&amp;gt;num; } case ELMT_ARC: if (arc_detect_collision (e, x, y)) { num = e-&amp;gt;parent-&amp;gt;num; } break; default: break; } }</description>
    </item>
    
    <item>
      <title>BER Error while dissecting CDR-DATA in gtp prime DRT packet</title>
      <link>/questions/1842/ber-error-while-dissecting-cdr-data-in-gtp-prime-drt-packet/</link>
      <pubDate>Thu, 20 Jan 2011 23:04:00 +0000</pubDate>
      
      <guid>/questions/1842/ber-error-while-dissecting-cdr-data-in-gtp-prime-drt-packet/</guid>
      <description>BER Error while dissecting CDR-DATA in gtp prime DRT packet  0 We have added new dissector to dissect the CDR-DATA present in the data record transfer request (GTP Prime Protocol). We are facing the problem while aligning the information display for one parameter. The expected output is, Frame |Internet Protocol | UDP |_GTP |_EGSNPDPRecord - Record type - IMSI ... ... - list of service data |_Change of service condition |_qosInformationNeg - allocation_ret_priority information ( parameter 1) - delay_class_reliability_class information (parameter 2) .</description>
    </item>
    
    <item>
      <title>Wireshark capture of Ethernet frame - size shows as 43 bytes</title>
      <link>/questions/1846/wireshark-capture-of-ethernet-frame-size-shows-as-43-bytes/</link>
      <pubDate>Fri, 21 Jan 2011 05:08:00 +0000</pubDate>
      
      <guid>/questions/1846/wireshark-capture-of-ethernet-frame-size-shows-as-43-bytes/</guid>
      <description>Wireshark capture of Ethernet frame - size shows as 43 bytes  0 Hi there,
I&#39;m using Wireshark in an attempt, along with other means, as a learning tool. Bearing in mind that the supposed minimum length of an Ethernet Frame is 64 bytes, I can&#39;t quite work out the following capture from Wireshark. I basically sent a ping of 1 byte in size to my default gateway, and here is the information from Wireshark:</description>
    </item>
    
    <item>
      <title>Does the 64-bit version of Wireshark support SNMP OID resolution</title>
      <link>/questions/1852/does-the-64-bit-version-of-wireshark-support-snmp-oid-resolution/</link>
      <pubDate>Fri, 21 Jan 2011 10:52:00 +0000</pubDate>
      
      <guid>/questions/1852/does-the-64-bit-version-of-wireshark-support-snmp-oid-resolution/</guid>
      <description>Does the 64-bit version of Wireshark support SNMP OID resolution  0 I have Wireshark on a Windows Server 2003 machine (32-bit) and Windows 7 Professional machine (64-bit). I have enabled the option to resolve OIDs on the 32-bit one but I am not able to do so on the 64-bit one. The preferences section for Name Resolution only shows NA instead.
name-resolving snmp 64-bitasked 21 Jan &#39;11, 10:52
Vivek</description>
    </item>
    
    <item>
      <title>local hostname resolution for ipv6</title>
      <link>/questions/1853/local-hostname-resolution-for-ipv6/</link>
      <pubDate>Fri, 21 Jan 2011 11:19:00 +0000</pubDate>
      
      <guid>/questions/1853/local-hostname-resolution-for-ipv6/</guid>
      <description>local hostname resolution for ipv6  0 like a previous poster, i would like to use a local host file to apply short names to ipv6 addresses in my captures. including link-scope addresses (regardless of the missing interface identifier). that is, if wireshark captures and displays a link-scope address in the IPv6 header, i want to identify at least which host it came from, quickly.
it&#39;s not a question about routing (where the interface identifier is critical) - it&#39;s about using wireshark to identify where (which host) the packets came from.</description>
    </item>
    
    <item>
      <title>Telnet protocol not showing up</title>
      <link>/questions/1854/telnet-protocol-not-showing-up/</link>
      <pubDate>Fri, 21 Jan 2011 12:02:00 +0000</pubDate>
      
      <guid>/questions/1854/telnet-protocol-not-showing-up/</guid>
      <description>Telnet protocol not showing up  0 I have two servers that act as application servers. When I run wireshark on one of the servers the telnet data packets show up. But when I run wireshark on the other server they don&#39;t. I can see the TCP handshake but not the data packets. I have uninstalled and reinstalled wireshark several times. I know the packets are there because a lot of users are using that server and I see the handshakes.</description>
    </item>
    
    <item>
      <title>How source and destination is identified?</title>
      <link>/questions/1863/how-source-and-destination-is-identified/</link>
      <pubDate>Fri, 21 Jan 2011 13:44:00 +0000</pubDate>
      
      <guid>/questions/1863/how-source-and-destination-is-identified/</guid>
      <description>How source and destination is identified?  0 If there is a syn bit set seen from an endpoint, this is the source. I am curious about if wireshark defines in some other ways or only the syn bit is enough to identify the source and destination? Secondly,
if my traces has are partial conversations, not any syn bit is seen, which one is the source and destination? port numbers can be used to determine them but what if both port numbers makes sense.</description>
    </item>
    
    <item>
      <title>Analysis request - for a server at my University</title>
      <link>/questions/1864/analysis-request-for-a-server-at-my-university/</link>
      <pubDate>Fri, 21 Jan 2011 13:50:00 +0000</pubDate>
      
      <guid>/questions/1864/analysis-request-for-a-server-at-my-university/</guid>
      <description>Analysis request - for a server at my University  0 Hello
I have many TCP retransmission errors (over 230 during 46 seconds) on a FTP transfer between my home laptop and a remote FTP server at my University and this issue is going for months without being able to find the cause. On any other server, FTP transfer is going strong, so it is not on my laptop side.</description>
    </item>
    
    <item>
      <title>tshark &amp;amp; etherXXXX files under /tmp directory</title>
      <link>/questions/1866/tshark-etherxxxx-files-under-tmp-directory/</link>
      <pubDate>Fri, 21 Jan 2011 14:57:00 +0000</pubDate>
      
      <guid>/questions/1866/tshark-etherxxxx-files-under-tmp-directory/</guid>
      <description>tshark &amp;amp; etherXXXX files under /tmp directory  0 Hello,
I am running tshark on a virtual machine running centOS, the version info is as below:
sudo /usr/sbin/tshark -v TShark 1.0.15 Copyright 1998-2010 Gerald Combs &amp;lt;[email protected]&amp;gt; and contributors. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
Compiled with GLib 2.12.3, with libpcap 0.9.4, with libz 1.</description>
    </item>
    
    <item>
      <title>RRC message not found in trace</title>
      <link>/questions/1869/rrc-message-not-found-in-trace/</link>
      <pubDate>Fri, 21 Jan 2011 23:28:00 +0000</pubDate>
      
      <guid>/questions/1869/rrc-message-not-found-in-trace/</guid>
      <description>RRC message not found in trace  0 Not able to found RRC message packets in logs
protocolasked 21 Jan &#39;11, 23:28
Ravi
1●1●1●1
accept rate: 0%
I have installed
latest WinPCAP 4.1.2
WireShark based 3G Protocol Analyzer Version 4.0.0 Based on official release 1.0.4 of Wireshark
Also, checked Tab Analyze ....&amp;gt; Enabaled all Protocol
Pls help us if anything is required to view RRC &amp;amp; FP protocol messages which is captured in log file (RANAP &amp;amp; NBAP messages are visible)</description>
    </item>
    
    <item>
      <title>Can not Open Stream in PortAudio Library.  Error: Invalid sample rate</title>
      <link>/questions/1879/can-not-open-stream-in-portaudio-library-error-invalid-sample-rate/</link>
      <pubDate>Sat, 22 Jan 2011 08:05:00 +0000</pubDate>
      
      <guid>/questions/1879/can-not-open-stream-in-portaudio-library-error-invalid-sample-rate/</guid>
      <description>Can not Open Stream in PortAudio Library. Error: Invalid sample rate  0 Hello,
wireshark Version 1.4.2My system hardware and audio device:
HP 210 Mini Fedora 14 2.6.35.10-74.fc14.x86_64 cat /proc/asound/cards 0 [Intel ]: HDA-Intel - HDA Intel HDA Intel at 0x56200000 irq 46 00:1b.0 Audio device: Intel Corporation N10/ICH 7 Family High Definition Audio Controller (rev 02)When I try and play back the rtp after making a sip call. I go to VOIP Calls | Player | Decode | Play.</description>
    </item>
    
    <item>
      <title>No Wireless Toolbar</title>
      <link>/questions/1880/no-wireless-toolbar/</link>
      <pubDate>Sat, 22 Jan 2011 13:44:00 +0000</pubDate>
      
      <guid>/questions/1880/no-wireless-toolbar/</guid>
      <description>No Wireless Toolbar  0 I am running 1.4.2 on a MacBook with OSX 10.6.5. I do not have any wireless toolbar or an option to open one. Any help will be appreciated.
wireless toolbarasked 22 Jan &#39;11, 13:44
ShadowUser
1●2●2●2
accept rate: 0%
  
One Answer:
  
1The wireless toolbar is related to building with AirPcap, a Windows only option.
answered 23 Jan &#39;11, 06:02</description>
    </item>
    
    <item>
      <title>No interface details pane</title>
      <link>/questions/1881/no-interface-details-pane/</link>
      <pubDate>Sat, 22 Jan 2011 13:48:00 +0000</pubDate>
      
      <guid>/questions/1881/no-interface-details-pane/</guid>
      <description>No interface details pane  0 I am running 1.4.2 on a MacBook with OSX 10.6.5. I do not have an Interface Details window or any way to open one. Any help will be appreciated.
interface detailsasked 22 Jan &#39;11, 13:48
ShadowUser
1●2●2●2
accept rate: 0%
  
One Answer:
  
1This is a dialog available on Windows only.
answered 23 Jan &#39;11, 06:04
Jaap ♦
11.7k●16●101</description>
    </item>
    
    <item>
      <title>Capture data from other computers in the network?</title>
      <link>/questions/1882/capture-data-from-other-computers-in-the-network/</link>
      <pubDate>Sat, 22 Jan 2011 13:55:00 +0000</pubDate>
      
      <guid>/questions/1882/capture-data-from-other-computers-in-the-network/</guid>
      <description>Capture data from other computers in the network?  0 Hi! I have an Atheros adapter that supports monitor mode.
My network interface is wlan0. When I run the command:
airmon-ng start wlan0a new network interface is beeing setup and it´s called mon0.
When I connect to my network, then it is the wlan0 interface that gets the IP from the router, but it seems that it is the mon0 interface that is in monitor mode (but it has not get any IP address).</description>
    </item>
    
    <item>
      <title>pcap vs pcap-ng</title>
      <link>/questions/1891/pcap-vs-pcap-ng/</link>
      <pubDate>Sun, 23 Jan 2011 06:08:00 +0000</pubDate>
      
      <guid>/questions/1891/pcap-vs-pcap-ng/</guid>
      <description>pcap vs pcap-ng  0 What is the difference between these two? Should I start using pcap-ng at this point?
pcap-ng pcapasked 23 Jan &#39;11, 06:08
EricKnaus
46●19●20●26
accept rate: 0%
  
One Answer:
  
2The file format pcap-ng extends the simple pcap format features with the options to store more capture related information, like extended time stamp precision, capture interface information, capture statistics, mixed link layer types, name resolution information, user comments, etc.</description>
    </item>
    
    <item>
      <title>dumpcap Filter Doesn&amp;#x27;t Work When Reading From stdin?</title>
      <link>/questions/1896/dumpcap-filter-doesnt-work-when-reading-from-stdin/</link>
      <pubDate>Sun, 23 Jan 2011 11:26:00 +0000</pubDate>
      
      <guid>/questions/1896/dumpcap-filter-doesnt-work-when-reading-from-stdin/</guid>
      <description>dumpcap Filter Doesn&amp;rsquo;t Work When Reading From stdin?  0 I have a huge file in the pcap format from a dumpcap capture. I am wanting to create a second file that only contains packets going to or from a certain range of MAC address. So I tried doing something like this:
dumpcap -f &amp;#39;eth.src[0:3] == 90:21:55 || eth.dst[0:3] == 90:21:55&amp;#39; -w htc.pcap -i - &amp;lt; wlan1.pcapBut when I do, the resulting file is the same as the input.</description>
    </item>
    
    <item>
      <title>Unable to install / uninstall WireShark silently</title>
      <link>/questions/1902/unable-to-install-uninstall-wireshark-silently/</link>
      <pubDate>Sun, 23 Jan 2011 21:14:00 +0000</pubDate>
      
      <guid>/questions/1902/unable-to-install-uninstall-wireshark-silently/</guid>
      <description>Unable to install / uninstall WireShark silently  0 According to the documentation, running the installer with a &#34;/s&#34; will enable WireShark to be installed silently with the default settings.
I&#39;ve downloaded wireshark-win32-1.4.3.exe and have been unable to get the /s switch to work.
After a manual install, I have tried a silent uninstall running &#34;uninstall.exe /s&#34;. This does not work either.
Any help with the above?
Thanks
wireshark unattended silent install uninstallThis question is marked &#34;</description>
    </item>
    
    <item>
      <title>filtering by ip.id</title>
      <link>/questions/1904/filtering-by-ipid/</link>
      <pubDate>Mon, 24 Jan 2011 07:11:00 +0000</pubDate>
      
      <guid>/questions/1904/filtering-by-ipid/</guid>
      <description>filtering by ip.id  0 1i want to build a filter which filters duplicated frames in a capture i want to filter it bi ip.identification number. for example if i have 5 frames with ip.id = 1000 i would like that after applying the filter only 1 frame will stay thank you
filter ip.idasked 24 Jan &#39;11, 07:11
Dima
1●3●4●5
accept rate: 0%
 edited 24 Jan &#39;11, 07:14</description>
    </item>
    
    <item>
      <title>Sierra Wireless 308 HSPA adapter is not detected in interfaces or via windump on a Win7 notebook</title>
      <link>/questions/1907/sierra-wireless-308-hspa-adapter-is-not-detected-in-interfaces-or-via-windump-on-a-win7-notebook/</link>
      <pubDate>Mon, 24 Jan 2011 09:40:00 +0000</pubDate>
      
      <guid>/questions/1907/sierra-wireless-308-hspa-adapter-is-not-detected-in-interfaces-or-via-windump-on-a-win7-notebook/</guid>
      <description>Sierra Wireless 308 HSPA adapter is not detected in interfaces or via windump on a Win7 notebook  0 Hello, I&#39;m running wireshark as admin on a win7 laptop and using a Sierra Wireless 308 HSPA adapter that I want to capture on. The wireshark &#34;interfaces&#34; dlg won&#39;t show this interface. I am using v1.4.3 of wireshark and v4.1.2. When I run windump as admin, it does not show the Sierra Wireless 308 adapter either.</description>
    </item>
    
    <item>
      <title>wireshark dies with error wireshark: symbol lookup error: wireshark: undefined symbol: wtap_cleareof</title>
      <link>/questions/1910/wireshark-dies-with-error-wireshark-symbol-lookup-error-wireshark-undefined-symbol-wtap_cleareof/</link>
      <pubDate>Mon, 24 Jan 2011 14:08:00 +0000</pubDate>
      
      <guid>/questions/1910/wireshark-dies-with-error-wireshark-symbol-lookup-error-wireshark-undefined-symbol-wtap_cleareof/</guid>
      <description>wireshark dies with error wireshark: symbol lookup error: wireshark: undefined symbol: wtap_cleareof  0 when trying to capture packets wireshark dies with the error; this is after doing a yum remove and a yum install of wireshark on fedora fc.14
Yum install Running Transaction Installing : wireshark-1.4.0-2.fc14.x86_64 1/2 Cleanup : wireshark-1.4.2-2.fc14.x86_64
wtag-cleareofasked 24 Jan &#39;11, 14:08
k0jkj
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>API&amp;#x27;s for wireshark to automate in TCL</title>
      <link>/questions/1911/apis-for-wireshark-to-automate-in-tcl/</link>
      <pubDate>Mon, 24 Jan 2011 20:53:00 +0000</pubDate>
      
      <guid>/questions/1911/apis-for-wireshark-to-automate-in-tcl/</guid>
      <description>API&amp;rsquo;s for wireshark to automate in TCL  0 Planning to automate wireshark verification for captured output. Please let me know how can we do this.
queryasked 24 Jan &#39;11, 20:53
rajassha
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Look into using tshark.
answered 24 Jan &#39;11, 22:28
Jaap ♦
11.7k●16●101
accept rate: 14%
     </description>
    </item>
    
    <item>
      <title>NOT Spewing Emails.</title>
      <link>/questions/1914/not-spewing-emails/</link>
      <pubDate>Tue, 25 Jan 2011 03:06:00 +0000</pubDate>
      
      <guid>/questions/1914/not-spewing-emails/</guid>
      <description>NOT Spewing Emails.  0 My ISP is suggesting that my computer is infected and is &#34;spewing email&#34; when it isn&#39;t infected nor spewing anything. All I see in the traffic logs are normal traffic and I use a lot of software both free and paid to keep the computer clean. Plus as it turns out there is another person on the other side of the state that just happens to be cruising the internet while using my static IP address.</description>
    </item>
    
    <item>
      <title>when continuous capture,file name is too long</title>
      <link>/questions/1919/when-continuous-capturefile-name-is-too-long/</link>
      <pubDate>Tue, 25 Jan 2011 04:20:00 +0000</pubDate>
      
      <guid>/questions/1919/when-continuous-capturefile-name-is-too-long/</guid>
      <description>when continuous capture,file name is too long  0 I use wireshark in the continuous capture mode, and use multiple files, file name is capture.pcap, the first file name is capture__0000120101226121523.pcap, and then I click &#39;restart&#39; button, the new file name is capture000012010122612152300001201012261525.pcap , But I need capture00001__20101226121525.pcap, this is my error or wireshark&#39; BUG or wireshark does not support this operation?
name fileasked 25 Jan &#39;11, 04:20
jackydi
1●2●2●2</description>
    </item>
    
    <item>
      <title>Does wire shark decode SS7 messages obtained from a protocol analyser?</title>
      <link>/questions/1921/does-wire-shark-decode-ss7-messages-obtained-from-a-protocol-analyser/</link>
      <pubDate>Tue, 25 Jan 2011 05:12:00 +0000</pubDate>
      
      <guid>/questions/1921/does-wire-shark-decode-ss7-messages-obtained-from-a-protocol-analyser/</guid>
      <description>Does wire shark decode SS7 messages obtained from a protocol analyser?  0 I am unable to decode certain SS7 messages coming from an SMLC to an MSC in 3G scenario. Can Wire shark tool help in this?
ss7asked 25 Jan &#39;11, 05:12
kochu1981
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1That will depend on several things such as can your analyser save its trace in a format such as .</description>
    </item>
    
    <item>
      <title>802.11 capture probleme on MacBook Pro (os 10.6.6)</title>
      <link>/questions/1922/80211-capture-probleme-on-macbook-pro-os-1066/</link>
      <pubDate>Tue, 25 Jan 2011 07:22:00 +0000</pubDate>
      
      <guid>/questions/1922/80211-capture-probleme-on-macbook-pro-os-1066/</guid>
      <description>802.11 capture probleme on MacBook Pro (os 10.6.6)  0 I&#39;ve just changed may MacBook Pro. I have the same Airport chipset and firmware than my old one. With my old MacBook Pro and old Wireshark version, the Link-Layer header type for my airport interface proposed me different option: Ethernet, 802.11, ... With my new MacBook and Wireshark 1.4.3, i have only Ethernet option. However there is a new topic &#34;</description>
    </item>
    
    <item>
      <title>Real-time analysis of calls</title>
      <link>/questions/1923/real-time-analysis-of-calls/</link>
      <pubDate>Tue, 25 Jan 2011 07:26:00 +0000</pubDate>
      
      <guid>/questions/1923/real-time-analysis-of-calls/</guid>
      <description>Real-time analysis of calls  0 Are there any simple solutions that I can employ that will me watch call performance at a moments notice. Working in a call center we have over 100 agents who use a mix of SIP and phone, all VOIP of course. If an agent complains of quality during a call, I&#39;d like to clck on that specific agen by name and monitor the call as quickly as possible, not after the fact.</description>
    </item>
    
    <item>
      <title>Understanding a Packet Capture</title>
      <link>/questions/1924/understanding-a-packet-capture/</link>
      <pubDate>Tue, 25 Jan 2011 07:39:00 +0000</pubDate>
      
      <guid>/questions/1924/understanding-a-packet-capture/</guid>
      <description>Understanding a Packet Capture  0 I am new to Wireshark and have created a packet capture between two servers, one within the LAN and the other in our DMZ. The program tells me it uses port 8004, which I have opened up on our firewall. From what I see in the catpure, it looks like it&#39;s using 8004 but routing it to another port? Any help reading this would be great .</description>
    </item>
    
    <item>
      <title>Mac OS X 10.6.6 - Wireshark capture starves other apps of data</title>
      <link>/questions/1931/mac-os-x-1066-wireshark-capture-starves-other-apps-of-data/</link>
      <pubDate>Tue, 25 Jan 2011 12:00:00 +0000</pubDate>
      
      <guid>/questions/1931/mac-os-x-1066-wireshark-capture-starves-other-apps-of-data/</guid>
      <description>Mac OS X 10.6.6 - Wireshark capture starves other apps of data  0 Running Wireshark 1.4.3 64-bit on a MacBook Pro (model MacBookPro2,2 according to System Profiler). If I start capturing on the ethernet port, after about a second or two of capturing everything it sees, two things happen:
(a) only packets generated on the computer (or targeted to the computer) get captured (b) no other process running on the computer can transmit or receive data over the network</description>
    </item>
    
    <item>
      <title>help: how to measure latency of udp packets</title>
      <link>/questions/1935/help-how-to-measure-latency-of-udp-packets/</link>
      <pubDate>Tue, 25 Jan 2011 14:59:00 +0000</pubDate>
      
      <guid>/questions/1935/help-how-to-measure-latency-of-udp-packets/</guid>
      <description>help: how to measure latency of udp packets  0 Hello all,
I have a capture file where i used wireshark to capture the skype voice chat between 3 persons. I need to measure the latency. That is the time a packet takes to travel from source to destination. How to go about seeing this?
Thank You Vin
latency skypeasked 25 Jan &#39;11, 14:59
magnetpest2k5
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Help: wireshark crashes after adding preference code to my dissector</title>
      <link>/questions/1939/help-wireshark-crashes-after-adding-preference-code-to-my-dissector/</link>
      <pubDate>Wed, 26 Jan 2011 01:19:00 +0000</pubDate>
      
      <guid>/questions/1939/help-wireshark-crashes-after-adding-preference-code-to-my-dissector/</guid>
      <description>Help: wireshark crashes after adding preference code to my dissector  0 I wanted to add some options in the preference window for my dissector. This is the code I have added to the &#34;proto_register&#34; function:
module_t *dan_lte_sdk_module; proto_dan_lte_sdk = proto_register_protocol (&amp;quot;DAN LTE SDK Protocol&amp;quot;, &amp;quot;Dan LTE SDK&amp;quot;, &amp;quot;dan_lte_sdk&amp;quot;);
register_init_routine(dan_defragment_init);
proto_register_field_array (proto_dan_lte_sdk, hf, array_length (hf)); proto_register_subtree_array (ett, array_length (ett)); register_dissector(&amp;quot;dan_lte_sdk&amp;quot;, dissect_dan_lte_sdk, proto_dan_lte_sdk);
dan_lte_sdk_module = prefs_register_protocol(proto_dan_lte_sdk, NULL);
prefs_register_bool_preference(dan_lte_sdk_module, &amp;quot;Dissect_MAC_Payload&amp;quot;, &amp;quot;Dissect MAC Layer from Data Payload&amp;quot;, &amp;quot;In Uplink and Downlink data packets, dissect MAC heaser layer &amp;quot; &amp;quot;Disabling MAC dissection will disable RLC dissection automaticly&amp;quot;, &amp;amp;global_dan_lte_sdk_dissect_MAC);</description>
    </item>
    
    <item>
      <title>Cannot capture HTTP packets from other computer</title>
      <link>/questions/1946/cannot-capture-http-packets-from-other-computer/</link>
      <pubDate>Wed, 26 Jan 2011 11:10:00 +0000</pubDate>
      
      <guid>/questions/1946/cannot-capture-http-packets-from-other-computer/</guid>
      <description>Cannot capture HTTP packets from other computer  0 I have set up my network card into monitor mode and I have connected to my WPA2 encrypted network. I have another computer with a wireless network card that is also connected to the same network.
I want to capture HTTP data from that computer and everytime I load a webpage from that computer, my other computer with Wireshark on seems to capture some data, but the source is my Netgear router and the protocol is LLC.</description>
    </item>
    
    <item>
      <title>Wireshark says &amp;quot;There are no interfaces on which a capture can be done.&amp;quot; - how do I fix this?</title>
      <link>/questions/1949/wireshark-says-there-are-no-interfaces-on-which-a-capture-can-be-done-how-do-i-fix-this/</link>
      <pubDate>Wed, 26 Jan 2011 13:03:00 +0000</pubDate>
      
      <guid>/questions/1949/wireshark-says-there-are-no-interfaces-on-which-a-capture-can-be-done-how-do-i-fix-this/</guid>
      <description>Wireshark says &amp;ldquo;There are no interfaces on which a capture can be done.&amp;rdquo; - how do I fix this?  3 hey,
We have a wireshark in our library&#39;s computer. i was trying to use it for the first time. when i go to interface and then caputer it gives me this messeage
There are no interfaces on which a capture can be done.
So How do i define the interface?</description>
    </item>
    
    <item>
      <title>pcap to raw hex dump</title>
      <link>/questions/1950/pcap-to-raw-hex-dump/</link>
      <pubDate>Wed, 26 Jan 2011 13:13:00 +0000</pubDate>
      
      <guid>/questions/1950/pcap-to-raw-hex-dump/</guid>
      <description>pcap to raw hex dump  0 I&#39;m looking to convert pcap file to a raw dump of the bytes of the packets.
This is when export file to txt file using wireshark then the requirement data is only hex data in red box. Because packet data is too much, so need some script to implement this. and this the result and create multiple file depend on number of packet datapcap-hex hexdumpasked 26 Jan &#39;11, 13:13</description>
    </item>
    
    <item>
      <title>Wireshark&amp;#x27;s protocol classification technique (new developer question)</title>
      <link>/questions/1954/wiresharks-protocol-classification-technique-new-developer-question/</link>
      <pubDate>Wed, 26 Jan 2011 14:08:00 +0000</pubDate>
      
      <guid>/questions/1954/wiresharks-protocol-classification-technique-new-developer-question/</guid>
      <description>Wireshark&amp;rsquo;s protocol classification technique (new developer question)  0 I working with a small team to develop a wireshark plugin for a new protocol.
The protocol has no header, so it is difficult (impossible maybe) to identify weather or not a packet contains this protocol.
Also the protocol is state dependent, so it is important our plugin not receive packets containing other protocols.
Currently our plugin works by assuming everything on a given UDP port is our protocol.</description>
    </item>
    
    <item>
      <title>Wireshark Training Videos</title>
      <link>/questions/1957/wireshark-training-videos/</link>
      <pubDate>Wed, 26 Jan 2011 14:22:00 +0000</pubDate>
      
      <guid>/questions/1957/wireshark-training-videos/</guid>
      <description>Wireshark Training Videos  0 On the &#34;Learn Wireshark&#34; page (located at http://www.wireshark.org/docs/) there are a number of instructional videos available. I would like to be able to store these off-line for review when I am sniffing something on a network that may not have Internet access. Is this possible? Thanks!
docs videoasked 26 Jan &#39;11, 14:22
jharris1993
1●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How can I find the latest Wireshark development build that built on all platforms?</title>
      <link>/questions/1961/how-can-i-find-the-latest-wireshark-development-build-that-built-on-all-platforms/</link>
      <pubDate>Wed, 26 Jan 2011 16:10:00 +0000</pubDate>
      
      <guid>/questions/1961/how-can-i-find-the-latest-wireshark-development-build-that-built-on-all-platforms/</guid>
      <description>How can I find the latest Wireshark development build that built on all platforms?  0 Hi!
I have installed the Wireshark sources and built a working executable under Windows Vista SP2. I occasionally update the sources using TortoiseSVN to a more recent revision (after checking the Wireshark Recent Builds Summary Page). Lately, there have been many failures (it seems there is at least one failure on some platform for every revision).</description>
    </item>
    
    <item>
      <title>High NFS READ latency from SLES10 client to EMC Clarion filer</title>
      <link>/questions/1962/high-nfs-read-latency-from-sles10-client-to-emc-clarion-filer/</link>
      <pubDate>Wed, 26 Jan 2011 18:04:00 +0000</pubDate>
      
      <guid>/questions/1962/high-nfs-read-latency-from-sles10-client-to-emc-clarion-filer/</guid>
      <description>High NFS READ latency from SLES10 client to EMC Clarion filer  0 I have a tshark trace dump and want to see the human readable time stamps between NFS READ procedure calls/packets. I understand frame.time_delta might be a good filter expression?
Can anyone provide a command line example on how to do this running tshark. I have the RTT stats and READ procedure has very heavy latency so I want to drill down and see if I can understand which file handle(s) might be responsible.</description>
    </item>
    
    <item>
      <title>yahoo voip call</title>
      <link>/questions/1966/yahoo-voip-call/</link>
      <pubDate>Thu, 27 Jan 2011 02:25:00 +0000</pubDate>
      
      <guid>/questions/1966/yahoo-voip-call/</guid>
      <description>yahoo voip call  0 hi, I am capturing the yahoo voip call through the wireshark .and when I am playing the call it is playing slowly
voip yahoo callsasked 27 Jan &#39;11, 02:25
rahul
1●1●1●2
accept rate: 0%
 edited 27 Jan &#39;11, 02:25 
   </description>
    </item>
    
    <item>
      <title>follow tcp stream</title>
      <link>/questions/1967/follow-tcp-stream/</link>
      <pubDate>Thu, 27 Jan 2011 04:12:00 +0000</pubDate>
      
      <guid>/questions/1967/follow-tcp-stream/</guid>
      <description>follow tcp stream  0 hi, i face this error when i tried to get follow TCP stream ((error creating filter for this atream a transport or network layer header is needed)) please help, thanks
sarasaraasked 27 Jan &#39;11, 04:12
ceve
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0I&#39;ve never seen this before. Do you see both transport layer headers and network layer headers, IP addresses for example?</description>
    </item>
    
    <item>
      <title>Windows 7 compatibility</title>
      <link>/questions/1968/windows-7-compatibility/</link>
      <pubDate>Thu, 27 Jan 2011 05:23:00 +0000</pubDate>
      
      <guid>/questions/1968/windows-7-compatibility/</guid>
      <description>Windows 7 compatibility  0 Will Wireshark work with Windows 7 workstations?
windows7asked 27 Jan &#39;11, 05:23
Cadeaui
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Yes !
Administrative privileges will be required to do captures.
(Wireshark works fine on my Windows 7 system).
answered 27 Jan &#39;11, 05:52
Bill Meier ♦♦
3.2k●1●8●50
accept rate: 17%
I just download wire shark 64bit version and isn&#39;t activiting to capture traffic?</description>
    </item>
    
    <item>
      <title>Problem with MMS disector</title>
      <link>/questions/1971/problem-with-mms-disector/</link>
      <pubDate>Thu, 27 Jan 2011 07:25:00 +0000</pubDate>
      
      <guid>/questions/1971/problem-with-mms-disector/</guid>
      <description>Problem with MMS disector  0 I have captures of MMS (Manufacturer Messagges Specificatiom) messagges that wireshark can&#39;t solve correctly (i.e., the MMS dissector doesn´t recognizes as MMS messagges). What can I do?
mmsasked 27 Jan &#39;11, 07:25
cgalli
1●1●1●1
accept rate: 0%
Another related question: why MMS protocol is not available in the &#34;Decode As Dialog Box&#34;?
(27 Jan &#39;11, 10:33) cgalli1What protocol carries your MMS packets? Looking at the source code it looks like the MMS dissector runs on top of COTP or is called by OID 1.</description>
    </item>
    
    <item>
      <title>Capture interface &amp;quot;comes and goes&amp;quot;</title>
      <link>/questions/1975/capture-interface-comes-and-goes/</link>
      <pubDate>Thu, 27 Jan 2011 10:19:00 +0000</pubDate>
      
      <guid>/questions/1975/capture-interface-comes-and-goes/</guid>
      <description>Capture interface &amp;ldquo;comes and goes&amp;rdquo;  0 My HP Netbook has begun not displaying the capture interface intermittently. (I love &#34;intermittents&#34;.) I have tried restarting, reinstalling Wireshark, reinstalling WinPCap, back-reving Wireshark and WinPCap. I&#39;ve tried to &#34;browse&#34; to an Internet site before opening Wireshark, but so far, nothing works consistently. I have browsed with this Netbook on this wireless interface for over a year just fine with no problems.
There is nothing wrong with my browsing sessions.</description>
    </item>
    
    <item>
      <title>Crashes because of libpng12</title>
      <link>/questions/1982/crashes-because-of-libpng12/</link>
      <pubDate>Thu, 27 Jan 2011 22:12:00 +0000</pubDate>
      
      <guid>/questions/1982/crashes-because-of-libpng12/</guid>
      <description>Crashes because of libpng12  1 1Wireshark crashes when I try to start it. Console tells me it&#39;s a problem with libpng12.0.dylib. My searches for fixes for this are turning up fruitless. Can anyone point me in the right direction? Any help is appreciated. Running OSX 10.6.4 . Thanks.
1/28/11 12:50:30 AM defaults[3650] The domain/default pair of (.GlobalPreferences, AppleCollationOrder) does not exist 1/28/11 12:50:30 AM [0x0-0x8d08d].org.wireshark.Wireshark[3616] dyld: Library not loaded: /usr/X11/lib/libpng12.</description>
    </item>
    
    <item>
      <title>Vlan capture setup for Intel network card on Windows</title>
      <link>/questions/1983/vlan-capture-setup-for-intel-network-card-on-windows/</link>
      <pubDate>Thu, 27 Jan 2011 23:44:00 +0000</pubDate>
      
      <guid>/questions/1983/vlan-capture-setup-for-intel-network-card-on-windows/</guid>
      <description>Vlan capture setup for Intel network card on Windows  0 Hi All,
Currently I&#39;m having issue to configure my network card to capture the VLAN tags. I have read through Wireshark VLAN capture setup page (http://wiki.wireshark.org/CaptureSetup/VLAN) but none of it is related...
My network card information: Device Description: Intel(R) 82577LM Gigabit Network Connection Driver Date: 9/29/2010 Driver Version 11.8.75.0
Could anyone please advise?
Regards, Lipitor
capture vlan intel card networkasked 27 Jan &#39;11, 23:44</description>
    </item>
    
    <item>
      <title>VLAN Priority Column Display Value not Verbose Class</title>
      <link>/questions/1991/vlan-priority-column-display-value-not-verbose-class/</link>
      <pubDate>Fri, 28 Jan 2011 09:31:00 +0000</pubDate>
      
      <guid>/questions/1991/vlan-priority-column-display-value-not-verbose-class/</guid>
      <description>VLAN Priority Column Display Value not Verbose Class  0 Is there a way to create a column for Ethernet VLAN priority that displays the value (e.g. 0-7 decimal or 000-111 binary) instead of the verbose traffic class?
I am capturing traffic and exporting to CSV for Excel analysis and graphing. I can export the verbose and then do a search and replace, or formula to glean the value, but that adds a significant amount of post-processing work that could be avoided if Wireshark just displayed the binary or decimal PCP value.</description>
    </item>
    
    <item>
      <title>Windows client with Linux remote packet capture</title>
      <link>/questions/1993/windows-client-with-linux-remote-packet-capture/</link>
      <pubDate>Fri, 28 Jan 2011 10:29:00 +0000</pubDate>
      
      <guid>/questions/1993/windows-client-with-linux-remote-packet-capture/</guid>
      <description>Windows client with Linux remote packet capture  0 I&#39;ve got my headless Linux box in the cabinet where I need to capture my packets, but I&#39;d rather use the fancy GUI instead of tshark over ssh. Since all my client systems run Windows I&#39;m trying to setup a Windows Wireshark instance to display remotely captured packets from a Linux host. I looked and rpcapd doesn&#39;t appear to be a part of the Ubuntu Wireshark package that I am using.</description>
    </item>
    
    <item>
      <title>Wireshark on netbook with Win7 &amp;quot;Starter&amp;quot; version</title>
      <link>/questions/2000/wireshark-on-netbook-with-win7-starter-version/</link>
      <pubDate>Fri, 28 Jan 2011 12:14:00 +0000</pubDate>
      
      <guid>/questions/2000/wireshark-on-netbook-with-win7-starter-version/</guid>
      <description>Wireshark on netbook with Win7 &amp;ldquo;Starter&amp;rdquo; version  0 Any idea whether wireshark 32 will work on an Acer Aspire D255F netbook? It has a 1.67 Ghz intel Atom processor with 1 Gb of RAM.
windows7 netbookasked 28 Jan &#39;11, 12:14
dale
1●1●1●1
accept rate: 0% 
  
One Answer:
  
0I don&#39;t see why it shouldn&#39;t. I have Wireshark running on my Samsung NC-10 netbook with an Atom 1.</description>
    </item>
    
    <item>
      <title>Intercepting images</title>
      <link>/questions/2004/intercepting-images/</link>
      <pubDate>Fri, 28 Jan 2011 22:47:00 +0000</pubDate>
      
      <guid>/questions/2004/intercepting-images/</guid>
      <description>Intercepting images  1 A while ago, when I was running ubuntu, I used a program called ethereal (I think); which I now understand is wireshark. I am now on mac os x, and wanted to try the program again, but one feature that I distinctly remember, is missing. I was able to intercept any images that were being browsed on my own network.
I let my kids use the internet, and having a stream of images shows me that the sites they are using are safe.</description>
    </item>
    
    <item>
      <title>Macos x10.6.6 GDK Warning</title>
      <link>/questions/2007/macos-x1066-gdk-warning/</link>
      <pubDate>Sat, 29 Jan 2011 07:47:00 +0000</pubDate>
      
      <guid>/questions/2007/macos-x1066-gdk-warning/</guid>
      <description>Macos x10.6.6 GDK Warning  0 Starting from the terminal, I get this warning. (wireshark-bin:15888): Gtk-WARNING **: Unable to locate theme engine in module_path: &#34;clearlooks&#34;,
Wireshark starts ok and initial use seems ok, but I&#39;m a novice here, so theres some learning to do. just wanted to know if this error was something I could ignore or not. . .
/terry
gdk clearlooksasked 29 Jan &#39;11, 07:47
sn4fu
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>I have a pcap file and I&amp;#x27;m trying to find out the client system?</title>
      <link>/questions/2009/i-have-a-pcap-file-and-im-trying-to-find-out-the-client-system/</link>
      <pubDate>Sat, 29 Jan 2011 09:57:00 +0000</pubDate>
      
      <guid>/questions/2009/i-have-a-pcap-file-and-im-trying-to-find-out-the-client-system/</guid>
      <description>I have a pcap file and I&amp;rsquo;m trying to find out the client system?  0 Hello, I have a pcap file and I&#39;m trying to figure out a way to determine the operating system used by the client system? I think from the data it is a Dell machine running a Microsoft operation system but I&#39;m not sure which(2000,XP, Vista, Window 7, etc).
Also, how do I determine the client’s IP address and MAC address?</description>
    </item>
    
    <item>
      <title>wireshark timestamp accuracy</title>
      <link>/questions/2010/wireshark-timestamp-accuracy/</link>
      <pubDate>Sat, 29 Jan 2011 12:13:00 +0000</pubDate>
      
      <guid>/questions/2010/wireshark-timestamp-accuracy/</guid>
      <description>wireshark timestamp accuracy  0 1I am trying to measure packet processing performance of a server. The server process is running on a linux system and it is connected to an ethernet switch. A windows machine connected to the sniffer port and running wireshark to capture the packet.
When I captured the packet at 1 packet/sec rate, using wireshark running on windows, the response time obtained is at around 400 micro seconds.</description>
    </item>
    
    <item>
      <title>Keylogger outbound traffic</title>
      <link>/questions/2011/keylogger-outbound-traffic/</link>
      <pubDate>Sat, 29 Jan 2011 12:34:00 +0000</pubDate>
      
      <guid>/questions/2011/keylogger-outbound-traffic/</guid>
      <description>Keylogger outbound traffic  0 I suspect a keylogger on a client&#39;s PC, but cannot isolate it. My fear is that this keylogger transmits data outbound to an indeterminate location.
So I am seeking a tool which may allow me to look at any outbound activity, and then isolate destinations and take it from there.
Time is of the essence, so I only have a limited time to familiarize myself with a tool.</description>
    </item>
    
    <item>
      <title>Packet type, ethernet type and HLP?</title>
      <link>/questions/2012/packet-type-ethernet-type-and-hlp/</link>
      <pubDate>Sat, 29 Jan 2011 15:02:00 +0000</pubDate>
      
      <guid>/questions/2012/packet-type-ethernet-type-and-hlp/</guid>
      <description>Packet type, ethernet type and HLP?  0 Frame 1 (42 bytes on wire, 42 bytes captured) Ethernet II, Src: AsustekC_b3:af:31 (00:18:f3:b3:af:31), Dst: Broadcast (ff:ff:ff:ff:ff:ff) Destination: Broadcast (ff:ff:ff:ff:ff:ff) Address: Broadcast (ff:ff:ff:ff:ff:ff) .... ...1 .... .... .... .... = IG bit: Group address (multicast/broadcast) .... ...0 .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default) Source: AsustekC_b3:af:31 (00:18:f3:b3:af:31) Address: AsustekC_b3:af:31 (00:18:f3:b3:af:31) .... ...0 .... .</description>
    </item>
    
    <item>
      <title>RTP Player, Converstation Out of Sync</title>
      <link>/questions/2026/rtp-player-converstation-out-of-sync/</link>
      <pubDate>Mon, 31 Jan 2011 00:58:00 +0000</pubDate>
      
      <guid>/questions/2026/rtp-player-converstation-out-of-sync/</guid>
      <description>RTP Player, Converstation Out of Sync  0 Hi
I capture the RTP stream to my VoIP providor (SIP Trunk) I then uses the Wireshart RTP player, to playback converstations when users complain about poor quality.
But when I play the converstations in the RTP player, the converstations is out of sync. The playback plays both voices at the same time.
Is it possible to setup the RTP player to properly play the converstation with only one speaker at one time?</description>
    </item>
    
    <item>
      <title>Problem with NetScaler HA protocol not being shown in the wireshark 1.4.3 protocol stack?</title>
      <link>/questions/2027/problem-with-netscaler-ha-protocol-not-being-shown-in-the-wireshark-143-protocol-stack/</link>
      <pubDate>Mon, 31 Jan 2011 01:10:00 +0000</pubDate>
      
      <guid>/questions/2027/problem-with-netscaler-ha-protocol-not-being-shown-in-the-wireshark-143-protocol-stack/</guid>
      <description>Problem with NetScaler HA protocol not being shown in the wireshark 1.4.3 protocol stack?  0 I have written a dissector for NetScaler HA protocol. The dissector was synced with the previous version of wireshark. Now with the latest 1.4.3 version, I do not see the name of my protocol ie NS HA in the protocol when I try to decode the packets. Similarly, I am currently writing a dissector for another NetScaler protocol named NS Node to Node Messages.</description>
    </item>
    
    <item>
      <title>[Malformed Packet: GSM over IP]</title>
      <link>/questions/2030/malformed-packet-gsm-over-ip/</link>
      <pubDate>Mon, 31 Jan 2011 04:07:00 +0000</pubDate>
      
      <guid>/questions/2030/malformed-packet-gsm-over-ip/</guid>
      <description>[Malformed Packet: GSM over IP]  0 1Hi, I&#39;m new to WireShark but I have a Windows host with WireShark running and on this host a customised application sending data to another host on port 5000. I can filter the data and use Follow TCP Stream fine and see the applications network data.
However the frames are displayed as
[Malformed Packet: GSM over IP]
I assume that WireShark is inspecting the frame data and that WireShark thinks that the data inside is a GSM over IP formatted data while it isn&#39;t.</description>
    </item>
    
    <item>
      <title>Error while compiling Wireshark source : epan/.libs/libwireshark.so: undefined reference to `proto_reg_handoff_PROTOABBREV&amp;#x27;</title>
      <link>/questions/2037/error-while-compiling-wireshark-source-epanlibslibwiresharkso-undefined-reference-to-proto_reg_handoff_protoabbrev/</link>
      <pubDate>Mon, 31 Jan 2011 04:53:00 +0000</pubDate>
      
      <guid>/questions/2037/error-while-compiling-wireshark-source-epanlibslibwiresharkso-undefined-reference-to-proto_reg_handoff_protoabbrev/</guid>
      <description>Error while compiling Wireshark source : epan/.libs/libwireshark.so: undefined reference to `proto_reg_handoff_PROTOABBREV&#39;  0 I have written a new dissector for wireshark. I have made changes to Makefile.common and CMakelist.txt. Now when I try to compile the Wireshark source, I get this error.
epan/.libs/libwireshark.so: undefined reference to proto_reg_handoff_PROTOABBREV&#39; collect2: ld returned 1 exit status make[2]: *** [wireshark] Error 1 make[2]: Leaving directory/home/sid/ws/wireshark-1.4.3&#39; make[1]: [all-recursive] Error 1 make[1]: Leaving directory `/home/sid/ws/wireshark-1.4.3&#39; make: [all] Error 2</description>
    </item>
    
    <item>
      <title>Why am I seeing lots of traffic to 224.0.0.22?</title>
      <link>/questions/2039/why-am-i-seeing-lots-of-traffic-to-2240022/</link>
      <pubDate>Mon, 31 Jan 2011 07:36:00 +0000</pubDate>
      
      <guid>/questions/2039/why-am-i-seeing-lots-of-traffic-to-2240022/</guid>
      <description>Why am I seeing lots of traffic to 224.0.0.22?  0 Why would I see lots of traffic going to Internet Assigned Numbers Authority (224.0.0.22). I am also seeing lots of checksum errors on the TCP packets. Any thoughts?
Regards,
Jeffrey
troubleshootingasked 31 Jan &#39;11, 07:36
Jeffrey
1●1●1●1
accept rate: 0%
 edited 02 Feb &#39;11, 18:37 
Guy Harris ♦♦
17.4k●3●35●196
  
3 Answers:</description>
    </item>
    
    <item>
      <title>Wireshark not recognizing skinny</title>
      <link>/questions/2040/wireshark-not-recognizing-skinny/</link>
      <pubDate>Mon, 31 Jan 2011 08:07:00 +0000</pubDate>
      
      <guid>/questions/2040/wireshark-not-recognizing-skinny/</guid>
      <description>Wireshark not recognizing skinny  0 Wireshark not recognized new SCCP protocol . You can found messages only if you will do filter by SCCP port 2000 .
Is any plan to support it ?
Thank you
2000 skinny sccp cisco portasked 31 Jan &#39;11, 08:07
Dan_D
1●1●1●1
accept rate: 0%
  
4 Answers:
  
1As with any protocol, I guess it will be updated if it is scratching someone&#39;s itch.</description>
    </item>
    
    <item>
      <title>Trigger a capture</title>
      <link>/questions/2049/trigger-a-capture/</link>
      <pubDate>Mon, 31 Jan 2011 16:02:00 +0000</pubDate>
      
      <guid>/questions/2049/trigger-a-capture/</guid>
      <description>Trigger a capture  0 I&#39;m looking for a feature to trigger a capture from either tcpdump or tshark I have a setup where a capture easily could take up giga bytes. So what I need is some kind of trigger which would cause a capture to start when ex a SIP invite to a certain URI is detected, and then capture the next 100M
Is this somehow possible?
captureasked 31 Jan &#39;11, 16:02</description>
    </item>
    
    <item>
      <title>HTTP requests without cookies</title>
      <link>/questions/2050/http-requests-without-cookies/</link>
      <pubDate>Mon, 31 Jan 2011 16:02:00 +0000</pubDate>
      
      <guid>/questions/2050/http-requests-without-cookies/</guid>
      <description>HTTP requests without cookies  0 We have an apparent problem in that some requests to our IIS server do not have cookies. We actually have an ISAPI filter that is reporting the problem but we would like an independent verification: (a) how do we set up a filter in Wireshark that shows the http requests that do NOT have cookies [ignoring those that do]. (b) how to we set up a filter that shows HTTP traffic with cookies that exceed a certain size</description>
    </item>
    
    <item>
      <title>Can anyone tell me why WS is crashing - report attached.</title>
      <link>/questions/2053/can-anyone-tell-me-why-ws-is-crashing-report-attached/</link>
      <pubDate>Mon, 31 Jan 2011 17:08:00 +0000</pubDate>
      
      <guid>/questions/2053/can-anyone-tell-me-why-ws-is-crashing-report-attached/</guid>
      <description>Can anyone tell me why WS is crashing - report attached.  0 Problem signature: Problem Event Name: APPCRASH Application Name: wireshark.exe Application Version: 1.4.3.35482 Application Timestamp: 4d2cad77 Fault Module Name: libglib-2.0-0.dll Fault Module Version: 2.22.4.0 Fault Module Timestamp: 4b6f546c Exception Code: 40000015 Exception Offset: 000000000004e68a OS Version: 6.0.6001.2.1.0.400.8 Locale ID: 1033 Additional Information 1: 96d7 Additional Information 2: 3471587d5bc0fe617aeaaca56aa1e394 Additional Information 3: 53f3 Additional Information 4: caa04b5b6781523c776247284e4299bd
Read our privacy statement: http://go.</description>
    </item>
    
    <item>
      <title>Is it always possible to capture an external IP?</title>
      <link>/questions/2055/is-it-always-possible-to-capture-an-external-ip/</link>
      <pubDate>Mon, 31 Jan 2011 17:30:00 +0000</pubDate>
      
      <guid>/questions/2055/is-it-always-possible-to-capture-an-external-ip/</guid>
      <description>Is it always possible to capture an external IP?  0 Hello everybody! My question is: How do I capture an external IP of a machine I have a transmission with? Or is it not always possible (depending on the structure of internal network). All I was able to find were internal IPs of my machine and another. They&#39;re useless. The only thing I need is an external IP. May be I need to adjust capture options?</description>
    </item>
    
    <item>
      <title>SSL, Decrypting Ephemeral RSA/DH Ciphers</title>
      <link>/questions/2065/ssl-decrypting-ephemeral-rsadh-ciphers/</link>
      <pubDate>Tue, 01 Feb 2011 05:20:00 +0000</pubDate>
      
      <guid>/questions/2065/ssl-decrypting-ephemeral-rsadh-ciphers/</guid>
      <description>SSL, Decrypting Ephemeral RSA/DH Ciphers  0 I have to decrypt ssl-traffic between F5 and Portal-Server. They use the cipher-suite TLS_DHE_RSA... As written in the slides of syn-bit this cipher is not supported for decrypting SSL traffic. Is the only way for decrypting the traffic to change the cipher-suite or is there in meanwhile a solution to decrypting Ephemeral RSA/DH Ciphers?
great thanks for support melsvizzer
ssl decryptionasked 01 Feb &#39;11, 05:20</description>
    </item>
    
    <item>
      <title>does wireshark support q-in-q?</title>
      <link>/questions/2070/does-wireshark-support-q-in-q/</link>
      <pubDate>Tue, 01 Feb 2011 08:00:00 +0000</pubDate>
      
      <guid>/questions/2070/does-wireshark-support-q-in-q/</guid>
      <description>does wireshark support q-in-q?  0 Dear all,
I wouls like to do some captures off double tag trafic. Does anybody knows if wireshark will capture and decode the traffic. If it is, a special config is needed?
Thanks a lot,
double tag qinq vlan q-in-qasked 01 Feb &#39;11, 08:00
ori
1●1●1●1
accept rate: 0%
hi i need to capture a qinq via wireshark but i didnt see it ? i have a dell laptop latitude d400</description>
    </item>
    
    <item>
      <title>Plugin for wireshark</title>
      <link>/questions/2071/plugin-for-wireshark/</link>
      <pubDate>Tue, 01 Feb 2011 08:54:00 +0000</pubDate>
      
      <guid>/questions/2071/plugin-for-wireshark/</guid>
      <description>Plugin for wireshark  0 Hi, I need a plugin for wireshark of the protocol Siemens CorNet-IP?? I make Bachelor&#39;s thesis for theme Analysis of Protocol Siemens. Thanks
davidasked 01 Feb &#39;11, 08:54
David Bělík
1●1●1●1
accept rate: 0%
  
One Answer:
  
0I don&#39;t think Siemens has published the specifications of the HiPath Feature Access protocol. That would be the least that&#39;s needed to write a dissector, or it would have to be reverse engineered.</description>
    </item>
    
    <item>
      <title>Baracuda Ethernet Tap BET10</title>
      <link>/questions/2073/baracuda-ethernet-tap-bet10/</link>
      <pubDate>Tue, 01 Feb 2011 09:23:00 +0000</pubDate>
      
      <guid>/questions/2073/baracuda-ethernet-tap-bet10/</guid>
      <description>Baracuda Ethernet Tap BET10  0 Greetings, would like to know if I can run multiple instances of Wireshark on win2k3ent edition with two intel 10/100 desktop cards plugged into a Baracuda Ethernet Tap model BET10 10/100 passive tap. two nics are required to do full duplex captures. but that is all I know. any info on this would be great. thanks in advance for your support and help.
Brent</description>
    </item>
    
    <item>
      <title>Very slow GUI when running wireshark remotely</title>
      <link>/questions/2075/very-slow-gui-when-running-wireshark-remotely/</link>
      <pubDate>Tue, 01 Feb 2011 09:49:00 +0000</pubDate>
      
      <guid>/questions/2075/very-slow-gui-when-running-wireshark-remotely/</guid>
      <description>Very slow GUI when running wireshark remotely  0 Start seeing this issue after upgrading wireshark from 0.99.8 to 1.2.6. One problem is the extreme long time it takes to initialize the wireshark (i.e., taking almost an hour to register dissectors, etc), which is kind of resolved by increasing the splash update interval; The other problem is that after GUI starts up it&#39;s running very slow and always takes a long time to respond to user clicks, makes the GUI unusable.</description>
    </item>
    
    <item>
      <title>Using Wireshark in KVM Guest</title>
      <link>/questions/2076/using-wireshark-in-kvm-guest/</link>
      <pubDate>Tue, 01 Feb 2011 10:03:00 +0000</pubDate>
      
      <guid>/questions/2076/using-wireshark-in-kvm-guest/</guid>
      <description>Using Wireshark in KVM Guest  0 Hi there,
is it possible to capture network traffic in a linux kvm guest with network bridge? Maybe it is a fundamental problem to capture from virtualized guests?
My setup looks like: KVM host (debian squeeze) bridge device br0 on eth1
KVM guest (centos 5.5) has bridge interface br0 configured as bridge (rtl8xxx)
Two real computers with centos 5.5 and physical eth0
All computers are connected with a hub and the network connection is fine.</description>
    </item>
    
    <item>
      <title>Capturing VBScript traffic</title>
      <link>/questions/2080/capturing-vbscript-traffic/</link>
      <pubDate>Tue, 01 Feb 2011 11:30:00 +0000</pubDate>
      
      <guid>/questions/2080/capturing-vbscript-traffic/</guid>
      <description>Capturing VBScript traffic  0 We have many vbscripts that run on our network and we are trying to identify the source of a vbscript that is starting any service on a server that is stopped at the top of the hour. So I stopped the Print Spooler service on a random server, started the capture a minute before the top of the hour and then waited until the service started again.</description>
    </item>
    
    <item>
      <title>Wireshark built in dissector needs to be changed to a plugin??</title>
      <link>/questions/2091/wireshark-built-in-dissector-needs-to-be-changed-to-a-plugin/</link>
      <pubDate>Wed, 02 Feb 2011 00:56:00 +0000</pubDate>
      
      <guid>/questions/2091/wireshark-built-in-dissector-needs-to-be-changed-to-a-plugin/</guid>
      <description>Wireshark built in dissector needs to be changed to a plugin??  0 I have written a dissector for NetScaler NS NNM protocol. It is a built in dissector. But now I have been asked to convert that into a plugin inorder to reduce the recompilation time. How should I do that??
Any help??
Thanks and Regards, Sidharth
dissector plugins wiresharkasked 02 Feb &#39;11, 00:56
sid
45●19●20●21
accept rate: 0%</description>
    </item>
    
    <item>
      <title>hex to word</title>
      <link>/questions/2092/hex-to-word/</link>
      <pubDate>Wed, 02 Feb 2011 00:57:00 +0000</pubDate>
      
      <guid>/questions/2092/hex-to-word/</guid>
      <description>hex to word  0 Hi, Good day. I am using the Wireshark application on Lan for tracing the packets and activities but couldn&#39;t find a way for converting the hex stream to word. Is there any way? Thank you for your help.
My email is [email protected]
Thank you again. Kind Regards, Lilly
to hex wordasked 02 Feb &#39;11, 00:57
Lilly
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>can we have both built in dissector and a plugin for the same protocol in wireshark?</title>
      <link>/questions/2093/can-we-have-both-built-in-dissector-and-a-plugin-for-the-same-protocol-in-wireshark/</link>
      <pubDate>Wed, 02 Feb 2011 01:12:00 +0000</pubDate>
      
      <guid>/questions/2093/can-we-have-both-built-in-dissector-and-a-plugin-for-the-same-protocol-in-wireshark/</guid>
      <description>can we have both built in dissector and a plugin for the same protocol in wireshark?  0 I have created a built in dissector for a netscalar private protocol named NNM. Now I have beeen asked to convert it into a plugin. So I want to know if I can go on and create a plugin or I need to remove the dissector from the wireshark source first??
Can a plug in as well as a built dissector exist for the same protocol in the same build of Wireshark?</description>
    </item>
    
    <item>
      <title>Wireshark does not capture depending on MTU size</title>
      <link>/questions/2094/wireshark-does-not-capture-depending-on-mtu-size/</link>
      <pubDate>Wed, 02 Feb 2011 01:31:00 +0000</pubDate>
      
      <guid>/questions/2094/wireshark-does-not-capture-depending-on-mtu-size/</guid>
      <description>Wireshark does not capture depending on MTU size  0 Hello!
I have set the MTU to 1400 on computer &#34;A&#34;.
From computer &#34;B&#34; I ping computer &#34;A&#34; by sending a 2000 bytes large ICMP packets:
ping -s 2000 192.168.0.10
I don&#39;t get any replies from computer &#34;A&#34;. Wireshark detects fragmented IP packets with the info &#34;proto=ICMP 0x01, off=1480&#34;, but no ICMP packets.
If I change the MTU to 1500 on computer &#34;</description>
    </item>
    
    <item>
      <title>what does &amp;quot;packets dropped&amp;quot; really mean ?</title>
      <link>/questions/2095/what-does-packets-dropped-really-mean/</link>
      <pubDate>Wed, 02 Feb 2011 01:40:00 +0000</pubDate>
      
      <guid>/questions/2095/what-does-packets-dropped-really-mean/</guid>
      <description>what does &amp;ldquo;packets dropped&amp;rdquo; really mean ?  3 2hi experts -
I am running a capture with dumpcap and rawshark on a very busy machine. I usually get a report like &#34;Packets: 100847 Packets dropped: 1124898&#34; from dumpcap (when I am killing it after 100,000 packets).
dumpcap process is configured to capture on:
one of 8 interfacestcp port 80(example:/root/monitor/wireshark-1.4.2/.libs/dumpcap -w- -f tcp port 80 -i eth4)
does the &#34;packet dropped&#34;</description>
    </item>
    
    <item>
      <title>can i have two separate builds of wireshark running on my ubuntu?</title>
      <link>/questions/2099/can-i-have-two-separate-builds-of-wireshark-running-on-my-ubuntu/</link>
      <pubDate>Wed, 02 Feb 2011 03:51:00 +0000</pubDate>
      
      <guid>/questions/2099/can-i-have-two-separate-builds-of-wireshark-running-on-my-ubuntu/</guid>
      <description>can i have two separate builds of wireshark running on my ubuntu?  0 I downloaded the wireshark source, build it on my ubuntu, added a dissector and recompiled. It works fine. Now, I have a task of making a plugin for the same protocol. I have come to know that if I have a plugin for the same protocol in the same build, then it leads to conflicts upon registration.</description>
    </item>
    
    <item>
      <title>can i export selected packet bytes from a stream using Tshark ?</title>
      <link>/questions/2103/can-i-export-selected-packet-bytes-from-a-stream-using-tshark/</link>
      <pubDate>Wed, 02 Feb 2011 06:32:00 +0000</pubDate>
      
      <guid>/questions/2103/can-i-export-selected-packet-bytes-from-a-stream-using-tshark/</guid>
      <description>can i export selected packet bytes from a stream using Tshark ?  0 Hi, I am trying to extract a file from a capture. It can be done using wireshark by identifying a TCP stream and then &#34;Export selected packet bytes&#34; from the stream.
Is it possible to reproduce it in Tshark?
thanks!
tshark streamasked 02 Feb &#39;11, 06:32
thsark_user
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Multicore scaling?</title>
      <link>/questions/2104/multicore-scaling/</link>
      <pubDate>Wed, 02 Feb 2011 07:33:00 +0000</pubDate>
      
      <guid>/questions/2104/multicore-scaling/</guid>
      <description>Multicore scaling?  0 Any plans for this? On larger files, would significantly speed up the use of complex display filters.
filter multicoreasked 02 Feb &#39;11, 07:33
rancur3p1c
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1I think it&#39;s on a lot of developer&#39;s minds, but it is not/will not be easy.
There is a wiki entry that discusses some of what must be done from a development perspective.</description>
    </item>
    
    <item>
      <title>How to view the destination IP of a packet when connecting behind a proxy?</title>
      <link>/questions/2109/how-to-view-the-destination-ip-of-a-packet-when-connecting-behind-a-proxy/</link>
      <pubDate>Wed, 02 Feb 2011 10:37:00 +0000</pubDate>
      
      <guid>/questions/2109/how-to-view-the-destination-ip-of-a-packet-when-connecting-behind-a-proxy/</guid>
      <description>How to view the destination IP of a packet when connecting behind a proxy?  0 Hi, I am behind a proxy and all the packets that I send have my proxy: 192.168.1.5 as a destination, I do not know how to see their actual destination (destination&#39;s IP). Thanks a lot for your help
ip behind proxyasked 02 Feb &#39;11, 10:37
intuition_man
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Getting started (capture filter)</title>
      <link>/questions/2114/getting-started-capture-filter/</link>
      <pubDate>Wed, 02 Feb 2011 12:01:00 +0000</pubDate>
      
      <guid>/questions/2114/getting-started-capture-filter/</guid>
      <description>Getting started (capture filter)  0 Using rev 1.4.3
My Capture Filter window does not look like the one in the help file. There are no Apply or Save options. How do I create or load a new filter?
filter capture newbie questionsasked 02 Feb &#39;11, 12:01
garyhibb
1●1●1●1
accept rate: 0%
  
One Answer:
  
0It is just a bit quirky until you get used to it.</description>
    </item>
    
    <item>
      <title>how to use a plugin to dissect packets in wireshark??</title>
      <link>/questions/2121/how-to-use-a-plugin-to-dissect-packets-in-wireshark/</link>
      <pubDate>Thu, 03 Feb 2011 00:24:00 +0000</pubDate>
      
      <guid>/questions/2121/how-to-use-a-plugin-to-dissect-packets-in-wireshark/</guid>
      <description>how to use a plugin to dissect packets in wireshark??  0 Hey,
I have created a plugin for Wireshark for the NetScalar NNM protocol. Now I have compiled the source code successfully. I want to capture NNM packets using this wireshark. So when I open the application, do I need to do anything to register the plugin? The protocol is not identified by wireshark when I run it on a NNM trace.</description>
    </item>
    
    <item>
      <title>help to us...to install wireshark.</title>
      <link>/questions/2122/help-to-usto-install-wireshark/</link>
      <pubDate>Thu, 03 Feb 2011 00:45:00 +0000</pubDate>
      
      <guid>/questions/2122/help-to-usto-install-wireshark/</guid>
      <description>help to us&amp;hellip;to install wireshark.  0 i have installed wireshark on my college pc and its not working... showing message Error signature.... &#34;AppName: wireshark.exe AppVer: 1.4.3.35482 ModName: unknown ModVer: 0.0.0.0 Offset: 00000000&#34;
sandeshasked 03 Feb &#39;11, 00:45
sandesh
1●1●1●1
accept rate: 0%
On what platform are you trying to install the wireshark?
(03 Feb &#39;11, 00:53) sid   </description>
    </item>
    
    <item>
      <title>how to use a plugin created on ubuntu on my windows build of wireshark?</title>
      <link>/questions/2124/how-to-use-a-plugin-created-on-ubuntu-on-my-windows-build-of-wireshark/</link>
      <pubDate>Thu, 03 Feb 2011 02:34:00 +0000</pubDate>
      
      <guid>/questions/2124/how-to-use-a-plugin-created-on-ubuntu-on-my-windows-build-of-wireshark/</guid>
      <description>how to use a plugin created on ubuntu on my windows build of wireshark?  0 I have created a plugin for wireshark. I run the wireshark on ubuntu and it is correctly dissecting my packets. Now I want to use the plugin on another computer which uses windows. So how do I use the plugin on windows?? I need the plugin in the form of a dll on windows, isn&#39;t it?</description>
    </item>
    
    <item>
      <title>Why my capture filter captured nothing?</title>
      <link>/questions/2125/why-my-capture-filter-captured-nothing/</link>
      <pubDate>Thu, 03 Feb 2011 03:04:00 +0000</pubDate>
      
      <guid>/questions/2125/why-my-capture-filter-captured-nothing/</guid>
      <description>Why my capture filter captured nothing?  0 Capture Filter1: port 80
Capture Filter2: port 53
Capture Filter3: udp
My computer connect the ADSL MODEM directly.
Wireshark working well with no capture filter.
wiresharkasked 03 Feb &#39;11, 03:04
xuesha
6●1●1●3
accept rate: 0% 
 edited 03 Feb &#39;11, 03:06 
Today found a situation (with capture filter):
MyPC -&amp;gt; Adsl Modem -&amp;gt; Internet (capture failed)
MyPC-&amp;gt; Router -&amp;gt; Adsl Modem -&amp;gt; Internet (capture success)</description>
    </item>
    
    <item>
      <title>JPCAP with android</title>
      <link>/questions/2126/jpcap-with-android/</link>
      <pubDate>Thu, 03 Feb 2011 07:04:00 +0000</pubDate>
      
      <guid>/questions/2126/jpcap-with-android/</guid>
      <description>JPCAP with android  0 I have written a small app to sniff packets. It uses the JPCAP lib. It functions properly, however, I am having trouble porting it to my android emulator. Has anyone tried using JPCAP with android?
Forrest
sniffing android jpcapasked 03 Feb &#39;11, 07:04
Forrest
1●1●1●1
accept rate: 0%
No....but I&#39;m really interested in your success!
(03 Feb &#39;11, 10:08) GeonJayIf I figure it out I&#39;ll post it.</description>
    </item>
    
    <item>
      <title>deleting error packets</title>
      <link>/questions/2128/deleting-error-packets/</link>
      <pubDate>Thu, 03 Feb 2011 09:17:00 +0000</pubDate>
      
      <guid>/questions/2128/deleting-error-packets/</guid>
      <description>deleting error packets  1 1Is there a way to remove/delete packets that Wrieshark lists as errors, such as &#34;Expert Info&#34;. I would like to remove these packets from the pcap file so the resultant file is contains only traffic that is valid.
info expertasked 03 Feb &#39;11, 09:17
mvossberg
16●1●2●2
accept rate: 0%
  
2 Answers:
  
2Sure. Use a display filter to filter on &#34;</description>
    </item>
    
    <item>
      <title>Triple Duplicate ACKs</title>
      <link>/questions/2133/triple-duplicate-acks/</link>
      <pubDate>Thu, 03 Feb 2011 10:44:00 +0000</pubDate>
      
      <guid>/questions/2133/triple-duplicate-acks/</guid>
      <description>Triple Duplicate ACKs  2 1I think this is a good one. I&#39;ll try to reserve my diagnosis until the end.
We have two endpoints (both linux) that are 25ms apart (50ms RTT). They are transferring files via an SSH tunnel - actually they are tar-ing to a pipe (|) which directs to an SSH session that executes another tar command on the other side - suboptimal IMHO, but they&#39;re unix &#34;</description>
    </item>
    
    <item>
      <title>wireshark 1.5 on ubuntu</title>
      <link>/questions/2137/wireshark-15-on-ubuntu/</link>
      <pubDate>Thu, 03 Feb 2011 12:55:00 +0000</pubDate>
      
      <guid>/questions/2137/wireshark-15-on-ubuntu/</guid>
      <description>wireshark 1.5 on ubuntu  0 Hi! From where can I download wireshark 1.5 for ubuntu? and how can I install it (of course on ubuntu)? Great thanks
wiresharkasked 03 Feb &#39;11, 12:55
azerty
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Unless Ubuntu packages Wireshark 1.5 (e.g., in an &#34;unstable&#34; branch or something), I think you&#39;ll have to build your own (download the source, configure, compile, install, etc.</description>
    </item>
    
    <item>
      <title>What languages will I need to deal with in order to make a plugin?</title>
      <link>/questions/2140/what-languages-will-i-need-to-deal-with-in-order-to-make-a-plugin/</link>
      <pubDate>Thu, 03 Feb 2011 15:25:00 +0000</pubDate>
      
      <guid>/questions/2140/what-languages-will-i-need-to-deal-with-in-order-to-make-a-plugin/</guid>
      <description>What languages will I need to deal with in order to make a plugin?  0 So I&#39;ve set out to make a plugin that displays(parses, whatever you want to call it) CDMI information for network traffic. But the protocol is not important.
I&#39;ve been told the API is extensive so I can write it in whatever language I want. With some base work in C.
Now I&#39;m not comfortable using C but by the looks of the docs(part 2) there is a nice guide written in C.</description>
    </item>
    
    <item>
      <title>Publishing and Deploying Wireshark to users Within a RDP / Citrix Environment</title>
      <link>/questions/2144/publishing-and-deploying-wireshark-to-users-within-a-rdp-citrix-environment/</link>
      <pubDate>Fri, 04 Feb 2011 02:37:00 +0000</pubDate>
      
      <guid>/questions/2144/publishing-and-deploying-wireshark-to-users-within-a-rdp-citrix-environment/</guid>
      <description>Publishing and Deploying Wireshark to users Within a RDP / Citrix Environment  0 Hi all
I have a customer who wants to deploy Wireshark as a published app to his user base i.e the app is being shared. They are technology firm who do use it for testing of there equipment that they produce etc. Just to make clear this isn&#39;t for testing the Xenapp (RDO) server but for use as a business tool.</description>
    </item>
    
    <item>
      <title>How do TCP sequence and acknowledgement numbers work</title>
      <link>/questions/2145/how-do-tcp-sequence-and-acknowledgement-numbers-work/</link>
      <pubDate>Fri, 04 Feb 2011 05:54:00 +0000</pubDate>
      
      <guid>/questions/2145/how-do-tcp-sequence-and-acknowledgement-numbers-work/</guid>
      <description>How do TCP sequence and acknowledgement numbers work  0 Hi,
I&#39;m trying to figure out how TCP works when i.e. sending a single image from server to client. I&#39;ve setup wireshark on both server and client system, and have a complete trace from SYN to FIN on both systems.
The image is send in several frames. Wireshark reassembled it nicely. After every third or forth received frame, the client sends an ACK.</description>
    </item>
    
    <item>
      <title>Packet from Device how to integrate and show up virtually in wireshark device list</title>
      <link>/questions/2146/packet-from-device-how-to-integrate-and-show-up-virtually-in-wireshark-device-list/</link>
      <pubDate>Fri, 04 Feb 2011 05:55:00 +0000</pubDate>
      
      <guid>/questions/2146/packet-from-device-how-to-integrate-and-show-up-virtually-in-wireshark-device-list/</guid>
      <description>Packet from Device how to integrate and show up virtually in wireshark device list  0 I have written a device driver to read Infiniband packets for some properity infiniband Cards. I will getting packet to user space by reading a charector device file and even i dont want to register to netdevice .. Can please let me know as to how can i integrate my driver with wireshark .. I would like to know where can i hookup , my packet read function.</description>
    </item>
    
    <item>
      <title>Determine username &amp;amp; password used to log in using wireshark?</title>
      <link>/questions/2161/determine-username-password-used-to-log-in-using-wireshark/</link>
      <pubDate>Fri, 04 Feb 2011 15:09:00 +0000</pubDate>
      
      <guid>/questions/2161/determine-username-password-used-to-log-in-using-wireshark/</guid>
      <description>Determine username &amp;amp; password used to log in using wireshark?  0 can you figure out the username and password looking at captured packet below. download file telnet-cooked.pcap (9kb) from http://wiki.wireshark.org/SampleCaptures?action=AttachFile&amp;amp;do=view&amp;amp;target=telnet-cooked.pcap and open it with wireshark and determine the username and password that was used to log in. also state which packet no. thank you
username password telnet wiresharkasked 04 Feb &#39;11, 15:09
momoboyus
1●1●1●3
accept rate: 0%
 edited 04 Feb &#39;11, 16:34</description>
    </item>
    
    <item>
      <title>How to display interface name when capturing all interfaces?</title>
      <link>/questions/2163/how-to-display-interface-name-when-capturing-all-interfaces/</link>
      <pubDate>Fri, 04 Feb 2011 23:56:00 +0000</pubDate>
      
      <guid>/questions/2163/how-to-display-interface-name-when-capturing-all-interfaces/</guid>
      <description>How to display interface name when capturing all interfaces?  0 I am performing capture on all devices, and end with messed output. It would be helpfull to have additional column with interface name.
Is there a way to add such column to packet list view?
device capture interfaces devicesasked 04 Feb &#39;11, 23:56
Witek
6●1●1●3
accept rate: 0%
  
3 Answers:
  
1 The Linux &#39;all&#39; interface doesn&#39;t provide that information in its cooked capture, therefore it can&#39;t be presented.</description>
    </item>
    
    <item>
      <title>Login &amp;amp; Authenticating Issue</title>
      <link>/questions/2166/login-authenticating-issue/</link>
      <pubDate>Sat, 05 Feb 2011 07:21:00 +0000</pubDate>
      
      <guid>/questions/2166/login-authenticating-issue/</guid>
      <description>Login &amp;amp; Authenticating Issue  0 A desktop application is authenticating from my PC to a server over the internet with username &amp;amp; password. I always get the message that says &#34;Authorization Failed. Please check email and password values.&#34;. Now the vendor is saying it is my software firewall that s causing this to which I disagree, as other services are running perfectly on my machine. How can I use Wireshark to troubleshoot and find this out?</description>
    </item>
    
    <item>
      <title>Trace a call between two MGWs</title>
      <link>/questions/2168/trace-a-call-between-two-mgws/</link>
      <pubDate>Sat, 05 Feb 2011 14:23:00 +0000</pubDate>
      
      <guid>/questions/2168/trace-a-call-between-two-mgws/</guid>
      <description>Trace a call between two MGWs  0 Hi, I need to trace one call between two media gateways in mobile core network (H.248 and sigtran). Can this be done with wireshark? if yes, how can I do this?
Thanks in advance.
mgwasked 05 Feb &#39;11, 14:23
jorgferr
1●1●1●2
accept rate: 0%
  
One Answer:
  
1Presuming you work for the telco in question, just arrange for a port-mirror/SPAN to a port on a switch in the transit path and capture to a locally connected wireshark enabled PC.</description>
    </item>
    
    <item>
      <title>how to convert file with extension .hc2 into pcap file?</title>
      <link>/questions/2174/how-to-convert-file-with-extension-hc2-into-pcap-file/</link>
      <pubDate>Sat, 05 Feb 2011 21:51:00 +0000</pubDate>
      
      <guid>/questions/2174/how-to-convert-file-with-extension-hc2-into-pcap-file/</guid>
      <description>how to convert file with extension .hc2 into pcap file?  0 I have a file with extension .hc2.I want to convert this file into pcap format.I have changed the extension by using command window but after opening this file with wireshark it shows error &#34;isnt a capture file understand by wirehsark &#34; . :-(
Can Anyone help me to solve this problem.
Thanks. sachet
fomatasked 05 Feb &#39;11, 21:51</description>
    </item>
    
    <item>
      <title>Plugins for Wireshark on Windows platform</title>
      <link>/questions/2179/plugins-for-wireshark-on-windows-platform/</link>
      <pubDate>Sun, 06 Feb 2011 21:41:00 +0000</pubDate>
      
      <guid>/questions/2179/plugins-for-wireshark-on-windows-platform/</guid>
      <description>Plugins for Wireshark on Windows platform  0 I have created plugin in ubuntu. It works fine. But as per the requirements, I have been asked to create a windows installation of wireshark. In windows, under the plugins directory, there is a list of DLL&#39;s. So is it possible that I can convert my plugin written for ubuntu platform into a DLL that I can use in windows directly without having to recompile wireshark on windows again and again.</description>
    </item>
    
    <item>
      <title>How to read a throughput graph</title>
      <link>/questions/2180/how-to-read-a-throughput-graph/</link>
      <pubDate>Sun, 06 Feb 2011 23:50:00 +0000</pubDate>
      
      <guid>/questions/2180/how-to-read-a-throughput-graph/</guid>
      <description>How to read a throughput graph  0 How to read a throughput graph in Wireshark? I don&#39;t understand at all. This is example my throughput graph.
graph throughputasked 06 Feb &#39;11, 23:50
SOFY
6●2●2●5
accept rate: 0%
 edited 29 Feb &#39;12, 18:59 
cmaynard ♦♦
9.4k●10●38●142
Were&#39;s your example graph?
(07 Feb &#39;11, 05:05) Jaap ♦  
One Answer:
  
2 It&#39;s just a plot of bytes per second over time.</description>
    </item>
    
    <item>
      <title>unable to find anything in NBAP trace</title>
      <link>/questions/2185/unable-to-find-anything-in-nbap-trace/</link>
      <pubDate>Mon, 07 Feb 2011 03:20:00 +0000</pubDate>
      
      <guid>/questions/2185/unable-to-find-anything-in-nbap-trace/</guid>
      <description>unable to find anything in NBAP trace  0 Hi,
I have captured a pcap on the IuB but when i filter for NBAP there is no message filtered. The filter field shows green but not a single message is filtered out. Is there anything special to be done while capturing.
I can see in edit&amp;gt;&amp;gt; preference&amp;gt;&amp;gt; Protocol that NABP is present and also the pcap shows correct IP in source and destination that of RNC and Node-B.</description>
    </item>
    
    <item>
      <title>Follow TCP Stream changes View Filter</title>
      <link>/questions/2186/follow-tcp-stream-changes-view-filter/</link>
      <pubDate>Mon, 07 Feb 2011 04:42:00 +0000</pubDate>
      
      <guid>/questions/2186/follow-tcp-stream-changes-view-filter/</guid>
      <description>Follow TCP Stream changes View Filter  0 Hi All,
Is there any way to make the &#34;Follow TCP Stream&#34; command not change my view filter in WireShark? When I use this, I am generally looking for a specific stream and it makes it annoying when I have to go and reset my filter after looking at each stream.
Thanks!
follow stream tcpasked 07 Feb &#39;11, 04:42
Tony Valenti
1●1●1●1</description>
    </item>
    
    <item>
      <title>Decode Multiple ports as Radius</title>
      <link>/questions/2189/decode-multiple-ports-as-radius/</link>
      <pubDate>Mon, 07 Feb 2011 05:33:00 +0000</pubDate>
      
      <guid>/questions/2189/decode-multiple-ports-as-radius/</guid>
      <description>Decode Multiple ports as Radius  0 Hi Experts,
is there a way to let Wireshark always decode a range of UDP ports as Radius? in radius potocol setting there is a way to add one alternate port only, also decode as menu configurations are not persistant and only applied in the current window.
Thanks.
decode multiple portsThis question is marked &#34;community wiki&#34;.asked 07 Feb &#39;11, 05:33
Belal
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>header checksum error</title>
      <link>/questions/2195/header-checksum-error/</link>
      <pubDate>Mon, 07 Feb 2011 08:34:00 +0000</pubDate>
      
      <guid>/questions/2195/header-checksum-error/</guid>
      <description>header checksum error  1 HELLO
We are running into a lot of server timeout when sending mails, I download wireshark to check the probelm on running the program i got this error
Internet protcol,src 10.200.4.2 Dsy 195.92.231.55 header checksum 0x0000 [incorrect,should be 0x3cf4 , what does this mean? we are behind a check point firewall and a cisco asa5510 firewall
Cheers
checksumasked 07 Feb &#39;11, 08:34
jwc1972
16●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Error with ./autogen.sh &amp;quot;Custom.m4 does not exist&amp;quot;</title>
      <link>/questions/2198/error-with-autogensh-customm4-does-not-exist/</link>
      <pubDate>Mon, 07 Feb 2011 09:42:00 +0000</pubDate>
      
      <guid>/questions/2198/error-with-autogensh-customm4-does-not-exist/</guid>
      <description>Error with ./autogen.sh &amp;ldquo;Custom.m4 does not exist&amp;rdquo;  0 I&#39;m trying to add my own plugin to the wireshark build. I followed all the instructions in README.plugins down to a tee.
When I try to run ./autogen.sh I get an error saying:
Checking for python. aclocal -I ./aclocal-fallback configure.in:1761: file `plugins/Custom.m4&#39; does not exist
Previously when I got the error(when I wasn&#39;t trying to add a plugin) I just skipped that one and went with .</description>
    </item>
    
    <item>
      <title>NFS Read latency - best way to identify culprit</title>
      <link>/questions/2200/nfs-read-latency-best-way-to-identify-culprit/</link>
      <pubDate>Mon, 07 Feb 2011 09:53:00 +0000</pubDate>
      
      <guid>/questions/2200/nfs-read-latency-best-way-to-identify-culprit/</guid>
      <description>NFS Read latency - best way to identify culprit  0 Hi, I have a repeatable event with a specific job run on SLES10 box acessing an EMC celerra. I see very high READ latency (Max RTT). How can I see which file(s) is responsible for this latency. Here are two examples: I used the following filter with tshark: -q -z rpc,rtt,100003,3,&#39;nfs.nfsstat3!=70&#39; Note the very high Max RTT for READ procedure.</description>
    </item>
    
    <item>
      <title>Wireshark 1</title>
      <link>/questions/2210/wireshark-1/</link>
      <pubDate>Mon, 07 Feb 2011 19:22:00 +0000</pubDate>
      
      <guid>/questions/2210/wireshark-1/</guid>
      <description>Wireshark 1  0 Is wireshark harmful to my computer? Where can I find internet address of my computer?
mariasked 07 Feb &#39;11, 19:22
Mari Valladares
1●1●1●1
accept rate: 0%
  
One Answer:
  
1No wireshark is just used to capture packets and decode field information.
Go to DOS Prompt and type ipconfig. That will give you the IP address of your machine wrt the network you are connected to.</description>
    </item>
    
    <item>
      <title>Website upload feature failing, Retransmissions and Out Of Order packets present</title>
      <link>/questions/2211/website-upload-feature-failing-retransmissions-and-out-of-order-packets-present/</link>
      <pubDate>Mon, 07 Feb 2011 19:33:00 +0000</pubDate>
      
      <guid>/questions/2211/website-upload-feature-failing-retransmissions-and-out-of-order-packets-present/</guid>
      <description>Website upload feature failing, Retransmissions and Out Of Order packets present  0 Hi all. I&#39;m a web developer who&#39;s on a team developing a feature that allows users to upload files up to 10MB to a government website. We&#39;re experiencing intermittant problems with this upload feature. The feature works great internally, and in most test environments.
In our UAT environment which mimics prod we&#39;re experiencing the following problems:
POSTs seem to freeze to the web server.</description>
    </item>
    
    <item>
      <title>Dialup capture on windows7(32 bit) with wireshark</title>
      <link>/questions/2214/dialup-capture-on-windows732-bit-with-wireshark/</link>
      <pubDate>Mon, 07 Feb 2011 21:48:00 +0000</pubDate>
      
      <guid>/questions/2214/dialup-capture-on-windows732-bit-with-wireshark/</guid>
      <description>Dialup capture on windows7(32 bit) with wireshark  0 To capture the dialup connection in wireshark in windows7(32 bits) which version of wireshark and winpcap is required. I tried with some, but it did not work.
windows7 dialup wiresharkasked 07 Feb &#39;11, 21:48
vikrant
1●1●1●1
accept rate: 0%
 edited 16 Jun &#39;12, 20:06 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
0The older Windows versions could do that, but not anymore.</description>
    </item>
    
    <item>
      <title>throughput graph</title>
      <link>/questions/2219/throughput-graph/</link>
      <pubDate>Mon, 07 Feb 2011 23:36:00 +0000</pubDate>
      
      <guid>/questions/2219/throughput-graph/</guid>
      <description>throughput graph  0 i actually confius what is throughput graph. It different with other throughput graph. How to read it? how to know their bit? this is example my throughput graph
graph wiresharkThis question is marked &#34;community wiki&#34;.asked 07 Feb &#39;11, 23:36
SOFY
6●2●2●5
accept rate: 0%
 edited 08 Feb &#39;11, 00:03 
  
One Answer:
  
1I&#39;m not entirely sure I understand your question, but this presentation by Ray Tomkins, entitled, &#34;</description>
    </item>
    
    <item>
      <title>install without admin rights</title>
      <link>/questions/2223/install-without-admin-rights/</link>
      <pubDate>Tue, 08 Feb 2011 01:46:00 +0000</pubDate>
      
      <guid>/questions/2223/install-without-admin-rights/</guid>
      <description>install without admin rights  0 Hello,
I made my own wireshark installer, but when I try to install my wireshark on a computer without admin rights, I get an issue with vcredist_x86.exe installation, it tells me that i didn&#39;t have admin rights. At the end of installation when I try to open Wirehsark, nothing&#39;s opening. Is there any solution to install vcredist without admin rights? Or is it possible to modify my installer to fix this issue?</description>
    </item>
    
    <item>
      <title>Capturing all the traffic</title>
      <link>/questions/2228/capturing-all-the-traffic/</link>
      <pubDate>Tue, 08 Feb 2011 07:54:00 +0000</pubDate>
      
      <guid>/questions/2228/capturing-all-the-traffic/</guid>
      <description>Capturing all the traffic  0 Hello guys, i decided to come here as my very last resort. I searched maybe the entire google for about 1 week, this is driving me insane. So here&#39;s the issue: I own a very small company, and i want to check if my employees are playing farmville or using facebook or whatever sites of that kind, instead of working. So, i&#39;m not going to install remote software, because those are their computers, and i don&#39;t want to break that privacy of course.</description>
    </item>
    
    <item>
      <title>Need direction on MGCP flow in Wireshark</title>
      <link>/questions/2229/need-direction-on-mgcp-flow-in-wireshark/</link>
      <pubDate>Tue, 08 Feb 2011 07:59:00 +0000</pubDate>
      
      <guid>/questions/2229/need-direction-on-mgcp-flow-in-wireshark/</guid>
      <description>Need direction on MGCP flow in Wireshark  0 When analyzing MCGP call flow, Wireshark is able to determine RTP (call packets) flow after a the session has been set up. Viewing the packets (MGCP and RTP) I cannot see how Wireshark is able to do this as there are no session info contained from the MGCP setup to the RTP packets. I would like someone who knows the code to please direct me to the area where this is resolved, so I can figure out how it works.</description>
    </item>
    
    <item>
      <title>Wireshark for linux</title>
      <link>/questions/2231/wireshark-for-linux/</link>
      <pubDate>Tue, 08 Feb 2011 08:39:00 +0000</pubDate>
      
      <guid>/questions/2231/wireshark-for-linux/</guid>
      <description>Wireshark for linux  1 whats the newest version available for Linux.. i can&#39;t seem to find a newer version for Linux.
linuxasked 08 Feb &#39;11, 08:39
Curtis Gregory
16●1●1●2
accept rate: 0%
  
2 Answers:
  
2Both questions and answers here tend to live for a long time, so rather than giving you an answer that will get quickly out of date, let me instead direct you to the main Wireshark web site and ask if you are able to find your answer there under &#34;</description>
    </item>
    
    <item>
      <title>syntax error near unexpected token `LIBGNUTLS,&amp;#x27;</title>
      <link>/questions/2237/syntax-error-near-unexpected-token-libgnutls/</link>
      <pubDate>Tue, 08 Feb 2011 10:59:00 +0000</pubDate>
      
      <guid>/questions/2237/syntax-error-near-unexpected-token-libgnutls/</guid>
      <description>syntax error near unexpected token `LIBGNUTLS,&#39;  0 So over all of yesterday I spent fixing issues I was having with ./autogen.sh and I was overjoyed when I finally got it to pass.
But now when I run ./configure I end up with this error:
&amp;gt;./configure: line 15463: syntax error near unexpected token `LIBGNUTLS,&amp;#39; &amp;gt;./configure: line 15463: ` PKG_CHECK_MODULES(LIBGNUTLS, gnutls &amp;gt;= 1.2.0,&amp;#39;I tried googling it. It&#39;s hard to follow some of the threads but I attempted some of the fixes that were suggested; reinstalling glib for example.</description>
    </item>
    
    <item>
      <title>Huawei modem not listed in available interface</title>
      <link>/questions/2239/huawei-modem-not-listed-in-available-interface/</link>
      <pubDate>Tue, 08 Feb 2011 13:21:00 +0000</pubDate>
      
      <guid>/questions/2239/huawei-modem-not-listed-in-available-interface/</guid>
      <description>Huawei modem not listed in available interface  0 Hi Iam using a huawei modem to connect to internet with Model No E1820. But this device is not listed in the available interfaces.
Any suggestion how to solve this.
Thanks, Jaya.
huawei modemasked 08 Feb &#39;11, 13:21
jayadevan_n
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Capture filters for WLAN</title>
      <link>/questions/2240/capture-filters-for-wlan/</link>
      <pubDate>Tue, 08 Feb 2011 14:02:00 +0000</pubDate>
      
      <guid>/questions/2240/capture-filters-for-wlan/</guid>
      <description>Capture filters for WLAN  0 Hi there,
When capturing wireless 802.11 packets in Wireshark, is there a way to apply capture filters such as filtering specific SSID&#39;s? The NIC is operating in monitor mode so it is capturing broadcast packets from other SSIDs that i do not want.
Any help would be much appreciated.
Thank you.
Wireshark version 1.2.11 Ubuntu 10.10
capture-filter-wlanasked 08 Feb &#39;11, 14:02
taj
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Capture my wireless (iPhone &amp;amp; iPad) traffic</title>
      <link>/questions/2242/capture-my-wireless-iphone-ipad-traffic/</link>
      <pubDate>Tue, 08 Feb 2011 17:19:00 +0000</pubDate>
      
      <guid>/questions/2242/capture-my-wireless-iphone-ipad-traffic/</guid>
      <description>Capture my wireless (iPhone &amp;amp; iPad) traffic  0 I&#39;m new to Wireshark, and packet capture, so please excuse my ignorance.
I&#39;ve installed Wireshark on my iMac, which is connected to an Apple Time Capsule/Airport via both ethernet and 802.11n (WPA/WPA2). I also connect my iPhone and iPad to the same Airport. What I&#39;d like to like to do is capture all traffic from either or both of these devices. I have the IP and MAC addresses for each device, but am not sure how to create a filter to capture them.</description>
    </item>
    
    <item>
      <title>nmake not found while trying to create a NSIS installer for windows on wireshark?</title>
      <link>/questions/2244/nmake-not-found-while-trying-to-create-a-nsis-installer-for-windows-on-wireshark/</link>
      <pubDate>Tue, 08 Feb 2011 21:45:00 +0000</pubDate>
      
      <guid>/questions/2244/nmake-not-found-while-trying-to-create-a-nsis-installer-for-windows-on-wireshark/</guid>
      <description>nmake not found while trying to create a NSIS installer for windows on wireshark?  0 Hello,
I am trying to create a NSIS installer for my wireshark which I have compiled from source code. I have changed the config.nmake file to include the path where nsis.exe is installed.
Now when I try to create the installer using &#39;nmake -f Makefile.nmake packaging&#39; I get this error.
&#39;nmake&#39; is not recognized as an internal or external command, operable program or batch file.</description>
    </item>
    
    <item>
      <title>Error while creating a wireshark installer</title>
      <link>/questions/2247/error-while-creating-a-wireshark-installer/</link>
      <pubDate>Tue, 08 Feb 2011 22:25:00 +0000</pubDate>
      
      <guid>/questions/2247/error-while-creating-a-wireshark-installer/</guid>
      <description>Error while creating a wireshark installer  0 After having successfully compiled wireshark on windows, I tried to create a windows installer. I am getting the following error on doing a &#39;nmake -f Makefile.nmake build wireshark installer&#39;
**File: &#34;C:Userst_sidharth1wswinwiresharkwin32vcredist_x86.exe&#34; -&amp;gt; no files found.
Usage: File [/nonfatal] [/a] ([/r] [/x filespec [...]] filespec [...] | /oname=outfile one_file_only)
Error in script &#34;wireshark.nsi&#34; on line 423 -- aborting creation process
NMAKE : fatal error U1077: &#39;&#34;</description>
    </item>
    
    <item>
      <title>TCP Checksum Validation Disabled</title>
      <link>/questions/2253/tcp-checksum-validation-disabled/</link>
      <pubDate>Wed, 09 Feb 2011 02:26:00 +0000</pubDate>
      
      <guid>/questions/2253/tcp-checksum-validation-disabled/</guid>
      <description>TCP Checksum Validation Disabled  0 Is there any reason why the TCP checksum validation would be disabled. I believe I spotted a host communicating to a CnC server then being redirected to another potential drive by download site.
The TCP validation disabled checksum is for incoming traffic from the potential CnC server.
Thanks
checksum tcpasked 09 Feb &#39;11, 02:26
eygobigmoney
1●1●1●1
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>separating the header from the packet</title>
      <link>/questions/2255/separating-the-header-from-the-packet/</link>
      <pubDate>Wed, 09 Feb 2011 05:42:00 +0000</pubDate>
      
      <guid>/questions/2255/separating-the-header-from-the-packet/</guid>
      <description>separating the header from the packet  0 hi, im still gettin my head around the new software and was wondering how i might go about separating the header from the packet.
i want to be able to use it externally, but every time i copy it i end up with a series of numbers from the Hex (or bits view) depending on what i have enabled. i want the http: link, is there a filter i have missed?</description>
    </item>
    
    <item>
      <title>Wireshark on Hyper V</title>
      <link>/questions/2258/wireshark-on-hyper-v/</link>
      <pubDate>Wed, 09 Feb 2011 12:07:00 +0000</pubDate>
      
      <guid>/questions/2258/wireshark-on-hyper-v/</guid>
      <description>Wireshark on Hyper V  0 Hello, I am trying to capture on Windows 2008 Server R2 Hyper V client. The only packets I see are broadcast packets. This is not the case on my other similar servers (Windows 2008 Server R2 Hyper V client). This case seems to be true on this machine only. Please advise.
Great product, Steven
hypervasked 09 Feb &#39;11, 12:07
Steven
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>tshark -G doesn&amp;#x27;t work with profiles?</title>
      <link>/questions/2263/tshark-g-doesnt-work-with-profiles/</link>
      <pubDate>Thu, 10 Feb 2011 00:42:00 +0000</pubDate>
      
      <guid>/questions/2263/tshark-g-doesnt-work-with-profiles/</guid>
      <description>tshark -G doesn&amp;rsquo;t work with profiles?  0 Hi all, I&#39;m not sure if that&#39;s a bug or something I&#39;m doing wrong, and will appreciate your help. I&#39;m trying to get the list of ports which are decoded as http under the profile &#34;myprofile&#34;. If I try doing:
tshark.exe -G decodes -C myprofile | grep httpI get the default profile&#39;s decoding list. If however I try
tshark.exe -C myprofile -G decodes | grep httpI get tshark&#39;s help page.</description>
    </item>
    
    <item>
      <title>Capturing a password from a printer using SMB</title>
      <link>/questions/2265/capturing-a-password-from-a-printer-using-smb/</link>
      <pubDate>Thu, 10 Feb 2011 02:25:00 +0000</pubDate>
      
      <guid>/questions/2265/capturing-a-password-from-a-printer-using-smb/</guid>
      <description>Capturing a password from a printer using SMB  0 Hi
I&#39;m trying to capture a password from a Utax printer/scanner, The account on the printer/scanner has a username , password and path to where the file should be scanned to on a server. I&#39;ve set up a session on wireshark and added host 192.168.16.89 (ip address of scanner) and then did a few scans, but i can&#39;t seem to pick up any info from the printer.</description>
    </item>
    
    <item>
      <title>DTMF RTPEVENT causes Save Payload to be corrupted</title>
      <link>/questions/2270/dtmf-rtpevent-causes-save-payload-to-be-corrupted/</link>
      <pubDate>Thu, 10 Feb 2011 06:57:00 +0000</pubDate>
      
      <guid>/questions/2270/dtmf-rtpevent-causes-save-payload-to-be-corrupted/</guid>
      <description>DTMF RTPEVENT causes Save Payload to be corrupted  0 Analysing G729 RTP Stream where there are RTPEVENT frames for DTMF signalling. After extracting RTP using Analyse &amp;gt; Save Payload and converting to .au with normal method, found that with the start of the first DTMF digit, the converted audio is &#34;wonkey&#34;. Sounds like cross-talk from many, many conversations. Can hear pulses corresponding to DTFM entry.
If I manually strip the RTPEVENT frames from the pcap before processing as above - all is well.</description>
    </item>
    
    <item>
      <title>Only seeing originating side of conversation</title>
      <link>/questions/2271/only-seeing-originating-side-of-conversation/</link>
      <pubDate>Thu, 10 Feb 2011 08:45:00 +0000</pubDate>
      
      <guid>/questions/2271/only-seeing-originating-side-of-conversation/</guid>
      <description>Only seeing originating side of conversation  0 I am trying to get a trace from a Cisco 3750 using a port monitor. I am only seeing the originating side of any conversation. It doesn&#39;t make a difference if the device that is attached to the source switch port is originating the conversation or is the destination. Ex. When I ping this device or ping from this device, I only see the ICMP ECHO request.</description>
    </item>
    
    <item>
      <title>wireless key code&amp;#x27;s</title>
      <link>/questions/2274/wireless-key-codes/</link>
      <pubDate>Thu, 10 Feb 2011 10:34:00 +0000</pubDate>
      
      <guid>/questions/2274/wireless-key-codes/</guid>
      <description>wireless key code&amp;rsquo;s  0 Hi I use wireshark with no problems but I&#39;m trying to gt the wireless key code&#39;s how do I do it. ty
keycodesasked 10 Feb &#39;11, 10:34
vamp
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0If you are asking how to break wireless encryption and extract the encryption key using Wireshark you&#39;re in the wrong place. You can use Wireshark to decrypt wireless traffic if you already have the key.</description>
    </item>
    
    <item>
      <title>How do you filter based on protocol?</title>
      <link>/questions/2276/how-do-you-filter-based-on-protocol/</link>
      <pubDate>Thu, 10 Feb 2011 10:49:00 +0000</pubDate>
      
      <guid>/questions/2276/how-do-you-filter-based-on-protocol/</guid>
      <description>How do you filter based on protocol?  0 I added my own dissector to wireshark and compiled everything. I want to filter the packets so it only captures the ones that register as the &#34;CDMI&#34; protocol.
The protocol is an extension to HTTP on port 80 if that helps.
filter protocol filters customasked 10 Feb &#39;11, 10:49
Rodayo
61●11●11●15
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Tshark capturing only TCP SYN/ACK packets</title>
      <link>/questions/2280/tshark-capturing-only-tcp-synack-packets/</link>
      <pubDate>Thu, 10 Feb 2011 20:45:00 +0000</pubDate>
      
      <guid>/questions/2280/tshark-capturing-only-tcp-synack-packets/</guid>
      <description>Tshark capturing only TCP SYN/ACK packets  0 Hi,
Problem Statement: Tshark captured packet dump contains only TCP SYN / ACK packets.
I am using tshark to capture tcp packets flowing towards the HTTP server and Database server. The machine on which tshark is installed is a Win 2K3 Server machine. The machine is having 3 NICs.
Command Used: tshark -bfilesize10240 -p -f &#34;tcp and (host 10.64.70.80 and host 10.64.70.81)&#34; -w netpackets.</description>
    </item>
    
    <item>
      <title>Enabling reassembly of TCP packets</title>
      <link>/questions/2289/enabling-reassembly-of-tcp-packets/</link>
      <pubDate>Fri, 11 Feb 2011 15:58:00 +0000</pubDate>
      
      <guid>/questions/2289/enabling-reassembly-of-tcp-packets/</guid>
      <description>Enabling reassembly of TCP packets  1 According to this guide:
https://www.wireshark.org/docs/wsug_html_chunked/AppMessages.html
you can enable TCP packet reassembly through the UI with Edit&amp;gt;Preferences. But I didn&#39;t see anything that would suggest that aside from &#34;Allow subdissector to reassemble TCP stream&#34; in the Protocols&amp;gt;TCP panel.
But according to this doc:
http://www.wireshark.org/docs/wsdg_html_chunked/ChDissectReassemble.html
you can do it through your code with the tcp_dissect_pdus function.
I would rather do it through it the UI as it would be more convenient.</description>
    </item>
    
    <item>
      <title>Mac os x 10.6 Wireshark won&amp;#x27;t start..</title>
      <link>/questions/2290/mac-os-x-106-wireshark-wont-start/</link>
      <pubDate>Fri, 11 Feb 2011 16:52:00 +0000</pubDate>
      
      <guid>/questions/2290/mac-os-x-106-wireshark-wont-start/</guid>
      <description>Mac os x 10.6 Wireshark won&amp;rsquo;t start..  0 I get
While WS is open, its windows can be displayed or hidden by displaying or hiding the X11 app. The first time this version of WS is run it may take several mins before the main window is displayed while font caches are built.
I get that message. but it never starts up.
MBP OS X snow lep. 10.6
osx mac startupasked 11 Feb &#39;11, 16:52</description>
    </item>
    
    <item>
      <title>auto remove old data</title>
      <link>/questions/2302/auto-remove-old-data/</link>
      <pubDate>Sun, 13 Feb 2011 08:39:00 +0000</pubDate>
      
      <guid>/questions/2302/auto-remove-old-data/</guid>
      <description>auto remove old data  0 Is there a way to set wireshark to automatically delete capture data that is older than a given time?
For example, I would like to have wireshark constantly running, but I don&#39;t have unlimited storage space, so I would just like to see the data for the past 12 hours. I check my computer more than once every 12 hours, so if I see something strange happening, or if I want to see my packet history due to some recent event, I could do so and save the important parts if I wish.</description>
    </item>
    
    <item>
      <title>IGMP and NBNS protocols</title>
      <link>/questions/2303/igmp-and-nbns-protocols/</link>
      <pubDate>Sun, 13 Feb 2011 09:03:00 +0000</pubDate>
      
      <guid>/questions/2303/igmp-and-nbns-protocols/</guid>
      <description>IGMP and NBNS protocols  0 Hi
I am trying to do packet analysis of my network. I have directly connected my computer with my home router.
At the wireshark capture, the first 6 packets are sent through the NBNS protocol (source IP: 192.168.1.255 and destination IP: 192.168.1.255) whereas the 7th packet is sent through the IGMP protocol (source IP: 192.168.1.1 and destination IP: 224.0.0.12). Is this normal?
then I open the internet explorer to connect with wwww.</description>
    </item>
    
    <item>
      <title>Software using Socket Based TCP connection cannot connect to server.</title>
      <link>/questions/2304/software-using-socket-based-tcp-connection-cannot-connect-to-server/</link>
      <pubDate>Sun, 13 Feb 2011 09:22:00 +0000</pubDate>
      
      <guid>/questions/2304/software-using-socket-based-tcp-connection-cannot-connect-to-server/</guid>
      <description>Software using Socket Based TCP connection cannot connect to server.  0 Hi,
On my computer other network based software are able to connect to servers and I am able to surf the internet as well on this computer however there is a software that uses socket based tcp connection however upon starting that application it reports &#34;No connection&#34;. How can i resolve this. How to resolve/troubleshoot socket based tcp connections issues.</description>
    </item>
    
    <item>
      <title>Criteria for decoding UDP to RTP</title>
      <link>/questions/2305/criteria-for-decoding-udp-to-rtp/</link>
      <pubDate>Sun, 13 Feb 2011 10:15:00 +0000</pubDate>
      
      <guid>/questions/2305/criteria-for-decoding-udp-to-rtp/</guid>
      <description>Criteria for decoding UDP to RTP  0 Hello,
I&#39;m writing a VoIP application and trying to verify correct RTP behavior with Wireshark. Unfortunately, Wireshark sees my packets as UDP only, it does not recognize them as RTP packets. What criteria does Wireshark use to determine RTP packets? Thanks.
udp rtpasked 13 Feb &#39;11, 10:15
cbwest
1●1●1●1
accept rate: 0%
  
3 Answers:
  
1Open the preferences, scroll down in the list of protocols, select RTP, check &#34;</description>
    </item>
    
    <item>
      <title>What is the common cause for an improved network after loading Wireshark?</title>
      <link>/questions/2313/what-is-the-common-cause-for-an-improved-network-after-loading-wireshark/</link>
      <pubDate>Sun, 13 Feb 2011 14:07:00 +0000</pubDate>
      
      <guid>/questions/2313/what-is-the-common-cause-for-an-improved-network-after-loading-wireshark/</guid>
      <description>What is the common cause for an improved network after loading Wireshark?  0 Please help me understand the common cause between a loaded instance of Wireshark and improved network performance.
I had poor problems with the network in our house so after investigating the network I used Wireshark to peek around. The problem was most evident when I played an MMORPG Final Fantasy 14 but after loading it with an instance of Wireshark (and capturing data) in the background my load time dropped to 30 seconds from the usual 6+ minutes.</description>
    </item>
    
    <item>
      <title>how to show bandwidth utilization in a trace</title>
      <link>/questions/2324/how-to-show-bandwidth-utilization-in-a-trace/</link>
      <pubDate>Mon, 14 Feb 2011 09:56:00 +0000</pubDate>
      
      <guid>/questions/2324/how-to-show-bandwidth-utilization-in-a-trace/</guid>
      <description>how to show bandwidth utilization in a trace  0 I got a trace file out of Cisco ASA loaded in wireshark. Internet connection seems to be slow and I was wondering if there is a way to graph all connections captured in the trace and show bandwidth used for each connection. (Suspect someone downloading something big, but unfortunately Cisco ASA does not show who :(
Thank you
graph cisco traceasked 14 Feb &#39;11, 09:56</description>
    </item>
    
    <item>
      <title>Is it possible to modify the hf array as the packet is being parsed?</title>
      <link>/questions/2333/is-it-possible-to-modify-the-hf-array-as-the-packet-is-being-parsed/</link>
      <pubDate>Mon, 14 Feb 2011 15:13:00 +0000</pubDate>
      
      <guid>/questions/2333/is-it-possible-to-modify-the-hf-array-as-the-packet-is-being-parsed/</guid>
      <description>Is it possible to modify the hf array as the packet is being parsed?  0 So with the custom protocol I&#39;m writing there are a lot of properties that need to be added to the hf array.
I was wondering if it&#39;s possible to add items to it as I&#39;m parsing the packet. That is, not every packet will have a header for every single property so I would only add the ones that are present.</description>
    </item>
    
    <item>
      <title>calling another dissector</title>
      <link>/questions/2334/calling-another-dissector/</link>
      <pubDate>Mon, 14 Feb 2011 20:26:00 +0000</pubDate>
      
      <guid>/questions/2334/calling-another-dissector/</guid>
      <description>calling another dissector  0 1hey,
I am writing a dissector for netscaler core to core messages. Now this protocol works on top of the Net Scaler Trace layer(nstrace), which is introduced by the netscaler for debugging purposes.
So when I am writing the dissector for core to core, I want to be able to call (nstrace) after that. So how should I code for that??
PLEASE HELP, ANYONE??
Thanks,</description>
    </item>
    
    <item>
      <title>Edit a captured PCAP file to resend it using TCPREPLAY</title>
      <link>/questions/2339/edit-a-captured-pcap-file-to-resend-it-using-tcpreplay/</link>
      <pubDate>Tue, 15 Feb 2011 00:47:00 +0000</pubDate>
      
      <guid>/questions/2339/edit-a-captured-pcap-file-to-resend-it-using-tcpreplay/</guid>
      <description>Edit a captured PCAP file to resend it using TCPREPLAY  0 Hi, I have a captured pcap file with a single packet and I would like to edit it and change some value in the user data field (CFLOW). Is there any way I can do it with wireshark assuming it will also update the checksum value of the packet? The edited packet would be sent to the network using tcpreplay.</description>
    </item>
    
    <item>
      <title>Decoding plain ESM messages</title>
      <link>/questions/2340/decoding-plain-esm-messages/</link>
      <pubDate>Tue, 15 Feb 2011 01:21:00 +0000</pubDate>
      
      <guid>/questions/2340/decoding-plain-esm-messages/</guid>
      <description>Decoding plain ESM messages  0 How can plain ESM messages using the NAS-EPS protocol of Wireshark Version 1.4.3 is be decoded successfully? Feeding in a plain ESM information request (e.g. 0x0201D9) as it is the decoder complains that it needs to be integrity protected. If the same message is put into a ESM container within an EMM message it is decoded successfully.
esmasked 15 Feb &#39;11, 01:21
nabla
1●1●1●1</description>
    </item>
    
    <item>
      <title>dissector for core to core messages, ie shared memory messages</title>
      <link>/questions/2341/dissector-for-core-to-core-messages-ie-shared-memory-messages/</link>
      <pubDate>Tue, 15 Feb 2011 01:29:00 +0000</pubDate>
      
      <guid>/questions/2341/dissector-for-core-to-core-messages-ie-shared-memory-messages/</guid>
      <description>dissector for core to core messages, ie shared memory messages  0 I have to write a dissector for core to core messages. These are the messages send between nodes in a shared memory.
So on top of what protocol must this be based?? Is it possible that i design core to core in such a way that it is not based on top of any protocol at all??
Real Confusion, Please help anyone?</description>
    </item>
    
    <item>
      <title>Regular Expressions for parsing</title>
      <link>/questions/2351/regular-expressions-for-parsing/</link>
      <pubDate>Tue, 15 Feb 2011 11:14:00 +0000</pubDate>
      
      <guid>/questions/2351/regular-expressions-for-parsing/</guid>
      <description>Regular Expressions for parsing  1 Wondering if regex is a viable option for parsing message bodies for a custom protocol. I&#39;m programming in C and using standard C-strings(char arrays) with the built in functions would rather cumbersome and problematic for the kind of parsing I&#39;m doing.
Regular expressions would make it much easier for us.
So my questions are:
-Is it a realistic option?
-If so would I need to find my own libraries or are there ones already included with the wireshark source?</description>
    </item>
    
    <item>
      <title>How do I do an offline install ?</title>
      <link>/questions/2356/how-do-i-do-an-offline-install/</link>
      <pubDate>Tue, 15 Feb 2011 13:29:00 +0000</pubDate>
      
      <guid>/questions/2356/how-do-i-do-an-offline-install/</guid>
      <description>How do I do an offline install ?  0 I need some help to gather the necessary pieces to do an offline install of Wireshark from source. This is for use on an isolated network where we want to create custom dissectors, so I have to be able to build from source.
offline installasked 15 Feb &#39;11, 13:29
ygor
1●1●1●5
accept rate: 100%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>difference between cap and pcap formats??</title>
      <link>/questions/2360/difference-between-cap-and-pcap-formats/</link>
      <pubDate>Wed, 16 Feb 2011 00:19:00 +0000</pubDate>
      
      <guid>/questions/2360/difference-between-cap-and-pcap-formats/</guid>
      <description>difference between cap and pcap formats??  0 what is the difference between .cap and .pcap formats??
Thanks and Regards,
Sid
wiresharkasked 16 Feb &#39;11, 00:19
sid
45●19●20●21
accept rate: 0%
  
3 Answers:
  
0From my point of view &#34;.cap&#34; is the Network General Sniffer format while &#34;.pcap&#34; is the TCPDump/Wireshark format, although I guess that a lot of analyzers name their format &#34;.cap&#34;. Main difference is in the headers of the file and frames, meaning that they contain different amounts of information about frames.</description>
    </item>
    
    <item>
      <title>Can just decrypt WPA2 if I connect the sniffing computer to network and then disconnects it, why?</title>
      <link>/questions/2363/can-just-decrypt-wpa2-if-i-connect-the-sniffing-computer-to-network-and-then-disconnects-it-why/</link>
      <pubDate>Wed, 16 Feb 2011 01:56:00 +0000</pubDate>
      
      <guid>/questions/2363/can-just-decrypt-wpa2-if-i-connect-the-sniffing-computer-to-network-and-then-disconnects-it-why/</guid>
      <description>Can just decrypt WPA2 if I connect the sniffing computer to network and then disconnects it, why?  0 Can somebody explain this:
I am trying to decrypt the traffic in my own wireless network encrypted with WPA2. I have two laptops, let´s call them A and B where A is the computer with Wireshark installed.
I have specified the network key in Wireshark like: wpa-pwd:MyPassword:MySSID
Then, if I start the capturing and then connect computer B to the network (computer A is disconnected from network), just two EAPOL packets are captured and the traffic is not decrypted.</description>
    </item>
    
    <item>
      <title>TCP window size and scaling</title>
      <link>/questions/2365/tcp-window-size-and-scaling/</link>
      <pubDate>Wed, 16 Feb 2011 05:07:00 +0000</pubDate>
      
      <guid>/questions/2365/tcp-window-size-and-scaling/</guid>
      <description>TCP window size and scaling  2 2Hi
I am trying to troubleshoot speed issues for a customer connecting to a Web Site from abroad. We have carried out testing by asking carrying out downloads of files from our Web site &amp;amp; capturing traffic during this.
We can see that once the download commences, after a short amount of packets, the TCP Window size on the receiving host drops to zero.</description>
    </item>
    
    <item>
      <title>Can Wireshark monitor MQ or Listener traffic?</title>
      <link>/questions/2372/can-wireshark-monitor-mq-or-listener-traffic/</link>
      <pubDate>Wed, 16 Feb 2011 08:34:00 +0000</pubDate>
      
      <guid>/questions/2372/can-wireshark-monitor-mq-or-listener-traffic/</guid>
      <description>Can Wireshark monitor MQ or Listener traffic?  0 Can I use wireshark to validate proper functionality of MQ and/or listener traffic?
listener mqasked 16 Feb &#39;11, 08:34
soccernut
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0By &#34;MQ&#34; do you you mean &#34;Websphere MQ&#34; ?
If so, Wireshark can monitor (capture) and dissect MQ traffic.
However, Wireshark just dissects the bits.
Altho a particular dissector may provide some diagnostic information (e.</description>
    </item>
    
    <item>
      <title>Wireshark time behind the actual time</title>
      <link>/questions/2386/wireshark-time-behind-the-actual-time/</link>
      <pubDate>Wed, 16 Feb 2011 11:58:00 +0000</pubDate>
      
      <guid>/questions/2386/wireshark-time-behind-the-actual-time/</guid>
      <description>Wireshark time behind the actual time  0 Tracing doesn&#39;t matched the users experience in terms of watching the clock on the PC, but Wireshark is about 20 seconds behind the actual time. As the trace goes on the time of the Wireshark packets gets more behind the actual time so that by the end of a 5 minute trace it is over 60 seconds behind. Why is this and can this be corrected.</description>
    </item>
    
    <item>
      <title>SSDP traffic</title>
      <link>/questions/2387/ssdp-traffic/</link>
      <pubDate>Wed, 16 Feb 2011 12:52:00 +0000</pubDate>
      
      <guid>/questions/2387/ssdp-traffic/</guid>
      <description>SSDP traffic  0 Hi all
thank you for the reply on the IGMP and NBNS question.
Indeed it is an amazing experience to look through real time network traffic. the reason i am looking through the traffic is that my computers are suffering from sever trojan attacks…:(
recently i realised that the setting of my router have been changed … for example the UPnP setting form the default (disabled) was enabled.</description>
    </item>
    
    <item>
      <title>Can`t capture EtherCAT packet</title>
      <link>/questions/2391/cant-capture-ethercat-packet/</link>
      <pubDate>Wed, 16 Feb 2011 20:54:00 +0000</pubDate>
      
      <guid>/questions/2391/cant-capture-ethercat-packet/</guid>
      <description>Can`t capture EtherCAT packet  0 Hello
I installed Wireshark v1.4.3
When I tried to capture EtherCAT packet from my Realtek NIC, I can not see the EtherCAT packet.
I only can capture DHCP protocol packet.
Should I have to config other option to capture EtherCAT packet?
ethercatasked 16 Feb &#39;11, 20:54
Younghyun Jo
1●1●1●1
accept rate: 0%
 edited 16 Feb &#39;11, 23:10 
Jaap ♦
11.7k●16●101
Hello i have a similiar problem.</description>
    </item>
    
    <item>
      <title>problem with dissector_add function..</title>
      <link>/questions/2392/problem-with-dissector_add-function/</link>
      <pubDate>Wed, 16 Feb 2011 22:22:00 +0000</pubDate>
      
      <guid>/questions/2392/problem-with-dissector_add-function/</guid>
      <description>problem with dissector_add function..  0 I have to design a dissector for core to core messages. In the code, inside the proto_ reg_ handoff_ccm() function,
dissector_ handle_ t ccm_ handle;
ccm_ handle=new_ create_ dissector_ handle(dissect_ ccm, proto_ ccm);
dissector_ add(...............................................);
I have a problem in writing this third line. There are three options;
dissector_ add(&#34;wtap_ encap&#34;, WTAP_ ENCAP_ CCM, ccm_ handle);dissector_ add(&#34; &#34;, NULL, ccm_ handle);What should I use?? Or if I am completely mistaken and I have to rather write something completely different.</description>
    </item>
    
    <item>
      <title>information storing</title>
      <link>/questions/2397/information-storing/</link>
      <pubDate>Thu, 17 Feb 2011 01:17:00 +0000</pubDate>
      
      <guid>/questions/2397/information-storing/</guid>
      <description>information storing  0 here i want to store the packet details which are found by WIRE SHARK in a file.. what is the procedure for that.
storageasked 17 Feb &#39;11, 01:17
Karthik
1●1●1●1
accept rate: 0%
  
One Answer:
  
0I guess you want to export the decodes / packet list to a text file? You can do that by using &#34;File&#34; -&amp;gt; &#34;Export&#34; -&amp;gt; &#34;</description>
    </item>
    
    <item>
      <title>Code licensing</title>
      <link>/questions/2399/code-licensing/</link>
      <pubDate>Thu, 17 Feb 2011 05:10:00 +0000</pubDate>
      
      <guid>/questions/2399/code-licensing/</guid>
      <description>Code licensing  0 Some code in Wireshark are dual-licensed under BSD-like and GPL licenses. The question is - can I use parts of such dual-licensed code in a proprietary product under terms of BSD license?
dual-license licensingasked 17 Feb &#39;11, 05:10
readytouse
6●1●1●2
accept rate: 0%
Is there a particular file (or set of files) you are referring to ?
(17 Feb &#39;11, 09:31) Bill Meier ♦♦For example: epan\crypt\airpdcap_tkip.c</description>
    </item>
    
    <item>
      <title>MAC OSX Installation</title>
      <link>/questions/2405/mac-osx-installation/</link>
      <pubDate>Thu, 17 Feb 2011 09:47:00 +0000</pubDate>
      
      <guid>/questions/2405/mac-osx-installation/</guid>
      <description>MAC OSX Installation  0 Ok, I&#39;ve used the MAC OSX 64 bit installer for the latest version of Wireshark, copied the command line folder and dragged the ChmodBFP to StartupItems alias. My installation doesn&#39;t seem to have a /dev folder, and I&#39;m struggling to find where the &#39;BPF&#39; devices live !
osx mac install bpfasked 17 Feb &#39;11, 09:47
Tim Arnold
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Capturing SNMP Traces to MYSQL Database or CSV file at RunTime</title>
      <link>/questions/2414/capturing-snmp-traces-to-mysql-database-or-csv-file-at-runtime/</link>
      <pubDate>Fri, 18 Feb 2011 01:51:00 +0000</pubDate>
      
      <guid>/questions/2414/capturing-snmp-traces-to-mysql-database-or-csv-file-at-runtime/</guid>
      <description>Capturing SNMP Traces to MYSQL Database or CSV file at RunTime  0 Is it possible via Wireshark to capture SNMP traces to mysql database or any csv file at runtime?
mysql snmp csv wiresharkasked 18 Feb &#39;11, 01:51
piyush
1●2●2●2
accept rate: 0%
  
One Answer:
  
0There&#39;s nothing out of the box that will work as far as I know, but with a bit of scripting you can do just that.</description>
    </item>
    
    <item>
      <title>Can Wireshark be integrated with Streambase application</title>
      <link>/questions/2415/can-wireshark-be-integrated-with-streambase-application/</link>
      <pubDate>Fri, 18 Feb 2011 01:53:00 +0000</pubDate>
      
      <guid>/questions/2415/can-wireshark-be-integrated-with-streambase-application/</guid>
      <description>Can Wireshark be integrated with Streambase application  0 Is there any way out by which traces from Wireshark be captured by adapters of Streambase. I am actually intersted in capturing SNMP traces at runtime in Streambase application?
snmp streambase stream wiresharkasked 18 Feb &#39;11, 01:53
piyush
1●2●2●2
accept rate: 0%
  
One Answer:
  
0I would think you should look at rawshark and/or tshark for this.</description>
    </item>
    
    <item>
      <title>install wireshark to SUSE Linux Enterprise Server 10 (x86_64)</title>
      <link>/questions/2416/install-wireshark-to-suse-linux-enterprise-server-10-x86_64/</link>
      <pubDate>Fri, 18 Feb 2011 07:12:00 +0000</pubDate>
      
      <guid>/questions/2416/install-wireshark-to-suse-linux-enterprise-server-10-x86_64/</guid>
      <description>install wireshark to SUSE Linux Enterprise Server 10 (x86_64)  0 Hello,
Before reading, please attention, my processor is 64-bit and so my oS is Suse_10 for 64 bit.
I am trying to install wireshark on suse_10(64bit). The host does not have internet access. Therefore, I need to have all the files needed for installation; that is even the dependencies. This is to be able to install wireshark on a host with no internet connection.</description>
    </item>
    
    <item>
      <title>Mac Household</title>
      <link>/questions/2420/mac-household/</link>
      <pubDate>Fri, 18 Feb 2011 13:43:00 +0000</pubDate>
      
      <guid>/questions/2420/mac-household/</guid>
      <description>Mac Household  0 I have 3 Macs, and Apple Time Machine Router, 2 Ipods and a few cell phones (one with wifi capability). I have also have 2 teenagers. I have been looking every where to find something to monitor the wifi traffic. I want to know when they are chatting and until what time they up chatting. Would this show me this. It looks a little bit beyond me.</description>
    </item>
    
    <item>
      <title>On Windows7 I can not decode KRB5 AS Response in an active capture</title>
      <link>/questions/2421/on-windows7-i-can-not-decode-krb5-as-response-in-an-active-capture/</link>
      <pubDate>Fri, 18 Feb 2011 16:28:00 +0000</pubDate>
      
      <guid>/questions/2421/on-windows7-i-can-not-decode-krb5-as-response-in-an-active-capture/</guid>
      <description>On Windows7 I can not decode KRB5 AS Response in an active capture  0 I am attempting to capture a security exchange between a device and a provisioning server. Part of the exchange involves requesting and receiving a Kerberos key from a KDC. In the live capture I can see the AS REQ ( key request from the device to the KDC ), but the AS RES (response from the KDC) show as a UDP packet.</description>
    </item>
    
    <item>
      <title>wireshark and ns2</title>
      <link>/questions/2422/wireshark-and-ns2/</link>
      <pubDate>Sat, 19 Feb 2011 00:35:00 +0000</pubDate>
      
      <guid>/questions/2422/wireshark-and-ns2/</guid>
      <description>wireshark and ns2  0 Hi I am julie...I wanted to do know if the packets captured using wireshark can be accessed and analysed using the network simulator NS2?
plshelpasked 19 Feb &#39;11, 00:35
julie
1●1●1●1
accept rate: 0%
  
One Answer:
  
1A quick search suggests that the answer is yes.
See: http://www.isi.edu/nsnam/ns/ns-emulation.html
&#34;Pcap/File Network Objects These objects are similar to the Pcap/BPF objects, except that network data is taken from a trace file rather than the live network.</description>
    </item>
    
    <item>
      <title>TCP ACKed lost segment</title>
      <link>/questions/2425/tcp-acked-lost-segment/</link>
      <pubDate>Sat, 19 Feb 2011 03:53:00 +0000</pubDate>
      
      <guid>/questions/2425/tcp-acked-lost-segment/</guid>
      <description>TCP ACKed lost segment  1 Hi Guys,
I&#39;m quite new to wireshark but i am using it to try and diagnose an issue with have with slow connectivity to our web site. I am see a lot of the following lines in the capture and wondered if anyone could help explain what they are:
[TCP ACKed lost segment] 55312 &amp;gt; http [ACK] Seq=1833164 Ack=9463120 Win=131072 Len=0 [TCP ACKed lost segment] 55253 &amp;gt; http [ACK] Seq=13802249 Ack=65723974 Win=512 Len=0 [TCP Segment of a reassembled PDU] HTTP/1.</description>
    </item>
    
    <item>
      <title>wireshark on suse 10</title>
      <link>/questions/2431/wireshark-on-suse-10/</link>
      <pubDate>Sat, 19 Feb 2011 12:33:00 +0000</pubDate>
      
      <guid>/questions/2431/wireshark-on-suse-10/</guid>
      <description>wireshark on suse 10  0 Hello,
Before reading, please attention, my processor is 64-bit and so my oS is Suse_10 for 64 bit.
I am trying to install wireshark on suse_10(64bit). The host does not have internet access. Therefore, I need to have all the files needed for installation; that is even the dependencies. This is to be able to install wireshark on a host with no internet connection. (Zypper, Yast would complain when no connection.</description>
    </item>
    
    <item>
      <title>TCP packets</title>
      <link>/questions/2433/tcp-packets/</link>
      <pubDate>Sat, 19 Feb 2011 23:39:00 +0000</pubDate>
      
      <guid>/questions/2433/tcp-packets/</guid>
      <description>TCP packets  0 What should I type in filter if I want to see TCP packets and TCP SIN packets that I have sent?
tcppacketsasked 19 Feb &#39;11, 23:39
baran
1●3●3●4
accept rate: 0%
  
One Answer:
  
1For seeing only TCP packets, you can use the filter &#34;tcp&#34; which can be used both as a capture filter and as a display filter.
If you only want to see TCP SYN packets, you can use the display filter &#34;</description>
    </item>
    
    <item>
      <title>Wireshark Network Usage</title>
      <link>/questions/2437/wireshark-network-usage/</link>
      <pubDate>Sun, 20 Feb 2011 05:45:00 +0000</pubDate>
      
      <guid>/questions/2437/wireshark-network-usage/</guid>
      <description>Wireshark Network Usage  0 network usage
usage networkasked 20 Feb &#39;11, 05:45
SiSi
1●1●1●3
accept rate: 0%
 edited 20 Feb &#39;11, 09:09 
  
One Answer:
  
2Hmmm... looks like we might need to set a few things straight :-)
A) Wireshark is not commercial software, it&#39;s open source
B) Wireshark is not monitoring software, it is analysis software. And in order to do so, it can monitor the network for a (short) period of time to capture network traffic</description>
    </item>
    
    <item>
      <title>Location Of PC Running WireShark: Affects What I See?</title>
      <link>/questions/2439/location-of-pc-running-wireshark-affects-what-i-see/</link>
      <pubDate>Sun, 20 Feb 2011 12:27:00 +0000</pubDate>
      
      <guid>/questions/2439/location-of-pc-running-wireshark-affects-what-i-see/</guid>
      <description>Location Of PC Running WireShark: Affects What I See?  0 Within my home LAN&#39;s topology, does the location of the PC running WireShark affect what WireShark sees?
My agenda is that I just installed a VOIP gateway (IP addr 10.0.0.4) and, with WireShark running, expected to see a flurry of packets from 10.0.0.4 to somewhere outside of the LAN (the SIP).
But I see nothing.
Said VOIP gateway is connected directly to the only router - which is connected to a FIOS internet connection.</description>
    </item>
    
    <item>
      <title>&amp;quot;INVITE sip&amp;quot;:  Field Name?</title>
      <link>/questions/2451/invite-sip-field-name/</link>
      <pubDate>Mon, 21 Feb 2011 07:13:00 +0000</pubDate>
      
      <guid>/questions/2451/invite-sip-field-name/</guid>
      <description>&amp;ldquo;INVITE sip&amp;rdquo;: Field Name?  0 I have a VOIP gateway running in &#34;Debug&#34; mode - so that it throws copies of all it&#39;s packets to my workstation - and WireShark is showing said packets.
The packets I am interested in start with &#34;INVITE sip:&#34; (phone number dialed).
Looks like the stuff in the &#34;Info&#34; column is a concatonation of many fields.
To the end of filtering for the &#34;INVITE: sip&#34;</description>
    </item>
    
    <item>
      <title>How do you edit exisiting tree items?</title>
      <link>/questions/2453/how-do-you-edit-exisiting-tree-items/</link>
      <pubDate>Mon, 21 Feb 2011 09:18:00 +0000</pubDate>
      
      <guid>/questions/2453/how-do-you-edit-exisiting-tree-items/</guid>
      <description>How do you edit exisiting tree items?  0 Simple question, but I can&#39;t seem to find the answer elsewhere. I&#39;m working with the json dissector that came with the 1.5 build.
Instead of having the tree layout where the &#34;Object Value&#34; is added as subitem to &#34;Member key&#34;. I want the object value appended to &#34;Member Key&#34;. How would I do that?
Thanks in advance
items editing treeasked 21 Feb &#39;11, 09:18</description>
    </item>
    
    <item>
      <title>Status: Wrong Sequence Nr.by Same Sequence Nr. = RTP Stream Analysis</title>
      <link>/questions/2458/status-wrong-sequence-nrby-same-sequence-nr-rtp-stream-analysis/</link>
      <pubDate>Mon, 21 Feb 2011 13:09:00 +0000</pubDate>
      
      <guid>/questions/2458/status-wrong-sequence-nrby-same-sequence-nr-rtp-stream-analysis/</guid>
      <description>Status: Wrong Sequence Nr.by Same Sequence Nr. = RTP Stream Analysis  0 Hi guys,
I really apprictae, if you can support me with my challenge. I am capturing RTPs and analyse the stream, I am facing the issue getting 2 sequences with the same nr., which has one the status &#34;OK&#34; and the next status`&#34;wrong sequence nr.&#34;.
How can I sort them only on &#34;OK&#34; sequences?
Thx
wiresharkasked 21 Feb &#39;11, 13:09</description>
    </item>
    
    <item>
      <title>Minimizing Capture File Size?</title>
      <link>/questions/2459/minimizing-capture-file-size/</link>
      <pubDate>Mon, 21 Feb 2011 13:45:00 +0000</pubDate>
      
      <guid>/questions/2459/minimizing-capture-file-size/</guid>
      <description>Minimizing Capture File Size?  0 I&#39;ve read http://wiki.wireshark.org/KnownBugs/OutOfMemory.
But it seems to beg the question of how one can minimize the size of the capture file.
All I care about are VOIP &#34;INVITE&#34; packets.
I&#39;ve got a filter set: syslog.msg contains &#34;INVITE sip:&#34;
I think it&#39;s a &#34;Capture&#34; filter... but even though WireShark&#39;s window is only showing the desired packets (very, very few....) it seems to keep chugging along with the total packets.</description>
    </item>
    
    <item>
      <title>DumpCap: Quotes Within Quotes?</title>
      <link>/questions/2462/dumpcap-quotes-within-quotes/</link>
      <pubDate>Mon, 21 Feb 2011 17:21:00 +0000</pubDate>
      
      <guid>/questions/2462/dumpcap-quotes-within-quotes/</guid>
      <description>DumpCap: Quotes Within Quotes?  0 It finally dawned on me that DumpCap was the workaround for the memory situation.
But I am having trouble concocting my filter argument.
To wit (you have to scroll all the way to the right to see the offending argument):
C:\BAT&amp;gt;&amp;quot;C:\Program Files\Wireshark\dumpcap.exe&amp;quot; -w \\NAS\Temp\DumpCap.pcap -i \Device\NPF_{35418EFA-22FB-4ADF-A88C-892918610B9F} -f &amp;quot;syslog.msg contains \&amp;quot;INVITE sip:\&amp;quot;&amp;quot; Invalid capture filter: &amp;quot;syslog.msg contains &amp;quot;INVITE sip:&amp;quot;&amp;quot;! That string isn&amp;amp;#39;t a valid capture filter (syntax error).</description>
    </item>
    
    <item>
      <title>Failure to Allocate Memory?</title>
      <link>/questions/2466/failure-to-allocate-memory/</link>
      <pubDate>Mon, 21 Feb 2011 21:19:00 +0000</pubDate>
      
      <guid>/questions/2466/failure-to-allocate-memory/</guid>
      <description>Failure to Allocate Memory?  0 I own a gaming server company with many connections. In one minute time the file size gets to be from 70MB to 190MB, which is no issue when it prunes the last files. But the program after a while does not buffer the files. I will select 7 and it will continue until an error comes up. Failure to allocate memory. Can someone please help?</description>
    </item>
    
    <item>
      <title>Wireshark - add little functionality</title>
      <link>/questions/2471/wireshark-add-little-functionality/</link>
      <pubDate>Tue, 22 Feb 2011 02:50:00 +0000</pubDate>
      
      <guid>/questions/2471/wireshark-add-little-functionality/</guid>
      <description>Wireshark - add little functionality  0 Hello developers, would it be possible to add multi column sorting functionality into Wireshark? That would be really appreciated. It is not that efficient to analyze packets sorted by time. I rather use sort by TCP stream, however then packets are not sorted by time as well but rather in some random order. Really, multi column sorting is needed. Thank you!
new request columns wiresharkasked 22 Feb &#39;11, 02:50</description>
    </item>
    
    <item>
      <title>TurboCap 2 - whats the difference to TurboCap?</title>
      <link>/questions/2473/turbocap-2-whats-the-difference-to-turbocap/</link>
      <pubDate>Tue, 22 Feb 2011 05:16:00 +0000</pubDate>
      
      <guid>/questions/2473/turbocap-2-whats-the-difference-to-turbocap/</guid>
      <description>TurboCap 2 - whats the difference to TurboCap?  0 I tried to find out what the difference is between the TurboCap and TurboCap 2 card - or did they just relabel the &#34;old&#34; TurboCap card to indicate that it has 2 ports while there now also is a 4 port card?
And, as far as I remember I bought a TurboCap card for about $895 a while ago , but now it&#39;s more close to $2000 - is there any reason for that (or is the reason called &#34;</description>
    </item>
    
    <item>
      <title>Vlan capture setup for Intel network card in windows 7</title>
      <link>/questions/2480/vlan-capture-setup-for-intel-network-card-in-windows-7/</link>
      <pubDate>Tue, 22 Feb 2011 07:16:00 +0000</pubDate>
      
      <guid>/questions/2480/vlan-capture-setup-for-intel-network-card-in-windows-7/</guid>
      <description>Vlan capture setup for Intel network card in windows 7  0 1Hi guys, i&#39;m trying to define VLAN tagging in windows7 for Intel(R) 82566DM Gigabit Network Connection. i tried the &#34;windows xp configuration like: find out the network card brand. open registry editor (start &amp;gt; run &amp;gt; regedit or regedt32 ) find the following location: etc... but didn&#39;t work for me in windows7, so Wireshark app don&#39;t show VLAN Tagging when &#34;</description>
    </item>
    
    <item>
      <title>Capture Analysis</title>
      <link>/questions/2483/capture-analysis/</link>
      <pubDate>Tue, 22 Feb 2011 08:21:00 +0000</pubDate>
      
      <guid>/questions/2483/capture-analysis/</guid>
      <description>Capture Analysis  0 I would like to know if there are any good references for analysing capture files. I can see the data, however, I don&#39;t have the knowledge to analyse what I am seeing.
nkingcadeasked 22 Feb &#39;11, 08:21
nkingcade
1●1●1●1
accept rate: 0%
  
One Answer:
  
1That question is somewhat similar to the following question:
I would like to know if there are any good references for analysing X-ray images.</description>
    </item>
    
    <item>
      <title>bits of SIN</title>
      <link>/questions/2485/bits-of-sin/</link>
      <pubDate>Tue, 22 Feb 2011 09:47:00 +0000</pubDate>
      
      <guid>/questions/2485/bits-of-sin/</guid>
      <description>bits of SIN  0 What should I do to understand which bit of SIN is 1?I mean for example first bit or second bit or third...
synasked 22 Feb &#39;11, 09:47
baran
1●3●3●4
accept rate: 0%
 edited 29 Feb &#39;12, 19:18 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
1The SYN bit is always the second bit of the TCP flags field. So the second bit of the 14th byte of the TCP header is the SYN bit.</description>
    </item>
    
    <item>
      <title>sending TCP packets</title>
      <link>/questions/2487/sending-tcp-packets/</link>
      <pubDate>Tue, 22 Feb 2011 09:56:00 +0000</pubDate>
      
      <guid>/questions/2487/sending-tcp-packets/</guid>
      <description>sending TCP packets  0 How can I see TCP packets that I am sending them?not all TCP packets.
packets tcpasked 22 Feb &#39;11, 09:56
baran
1●3●3●4
accept rate: 0%
  
2 Answers:
  
2You can do something like:
tcp and src host &amp;lt;YOUR_IP&amp;gt; (capture filter) tcp and ip.src==&amp;lt;YOUR_IP&amp;gt; (display filter)answered 22 Feb &#39;11, 10:09
SYN-bit ♦♦
17.1k●9●57●245
accept rate: 20%
  
0Hi,
Based on your requirement you can set filters and capture interesting traffic.</description>
    </item>
    
    <item>
      <title>Creating a patch for a plugin</title>
      <link>/questions/2497/creating-a-patch-for-a-plugin/</link>
      <pubDate>Tue, 22 Feb 2011 11:50:00 +0000</pubDate>
      
      <guid>/questions/2497/creating-a-patch-for-a-plugin/</guid>
      <description>Creating a patch for a plugin  1 I want to create a patch or any sort of tool that would allow for developers who use my plugin to apply the changes to the wireshark releases. I&#39;ve looked at this document http://www.wireshark.org/docs/wsdg_html_chunked/ChSrcContribute.html
Now that would be suffice, but it means the developers would apply the patch, then compile wireshark with the made-changes. I don&#39;t want them to have to compile it.</description>
    </item>
    
    <item>
      <title>queries regarding http protocol</title>
      <link>/questions/2500/queries-regarding-http-protocol/</link>
      <pubDate>Tue, 22 Feb 2011 12:28:00 +0000</pubDate>
      
      <guid>/questions/2500/queries-regarding-http-protocol/</guid>
      <description>queries regarding http protocol  0 Hi,
I wanted to ask following questions for long. I tried fetching information from various RFCs, mailing lists, forums etc. but no luck. Finally I found this site and decided to post questions here. They are as follows:
How can we get request Vs response delay for HTTP protocol?
How exactly to plot LOAD(*) graphs for HTTP protocol?
How can I use wireshark to identify performance bottleneck between proxy server and web server?</description>
    </item>
    
    <item>
      <title>RADIUS Packet handling</title>
      <link>/questions/2501/radius-packet-handling/</link>
      <pubDate>Tue, 22 Feb 2011 12:40:00 +0000</pubDate>
      
      <guid>/questions/2501/radius-packet-handling/</guid>
      <description>RADIUS Packet handling  0 Hi,
I am facing issue with radius accounting request Vs response which is affecting my radius proxy performance.
I am seeing delay between radius proxy &amp;amp; radius server. So whenever I plot IO graph (filter name = radius.time) it shows me delay of 5 secs between Request Vs Response. But my radius server vendor is saying that &#34;wireshark is incorrectly showing that information and actually there is no such delay&#34;</description>
    </item>
    
    <item>
      <title>Start time for a packet capture</title>
      <link>/questions/2507/start-time-for-a-packet-capture/</link>
      <pubDate>Tue, 22 Feb 2011 14:26:00 +0000</pubDate>
      
      <guid>/questions/2507/start-time-for-a-packet-capture/</guid>
      <description>Start time for a packet capture  0 I have a device that resets every night at 8:05. I would like to setup wireshark to start capturing at 8:03 every night and capture for 3 minutes. I have found where to stop the capture but am looking for where to set the option to start capturing at a certain real time? Thanks for your help
real capture start timeasked 22 Feb &#39;11, 14:26</description>
    </item>
    
    <item>
      <title>session in http</title>
      <link>/questions/2510/session-in-http/</link>
      <pubDate>Tue, 22 Feb 2011 15:30:00 +0000</pubDate>
      
      <guid>/questions/2510/session-in-http/</guid>
      <description>session in http  0 when I open a web page X and it has many links to other servers in it. How can I distinguish different request packet which goes to X from the one that goes to links?Can I track it in Wireshark?
sessionasked 22 Feb &#39;11, 15:30
A B
1●10●10●12
accept rate: 0%
  
One Answer:
  
0You can look at the Host header (display filter field: http.</description>
    </item>
    
    <item>
      <title>How to see port 5061 as SIP protocol and not SSL</title>
      <link>/questions/2515/how-to-see-port-5061-as-sip-protocol-and-not-ssl/</link>
      <pubDate>Wed, 23 Feb 2011 05:06:00 +0000</pubDate>
      
      <guid>/questions/2515/how-to-see-port-5061-as-sip-protocol-and-not-ssl/</guid>
      <description>How to see port 5061 as SIP protocol and not SSL  0 Hello, i want to see transport being sent to/from port 5061 as SIP (when i filter), and not as SSL (in order to simplfy view, i don&#39;t want to start searching aoo TCP packets)
Is there a way? thanks
sip 5061 tcpasked 23 Feb &#39;11, 05:06
hk76
1●2●2●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>TMPDIR ignored when setuid for dumpcap</title>
      <link>/questions/2516/tmpdir-ignored-when-setuid-for-dumpcap/</link>
      <pubDate>Wed, 23 Feb 2011 05:25:00 +0000</pubDate>
      
      <guid>/questions/2516/tmpdir-ignored-when-setuid-for-dumpcap/</guid>
      <description>TMPDIR ignored when setuid for dumpcap  0 Hi,
trying to get rid of &#34;sudo&#34;, I&#39;ve set setuid for &#34;root&#34; user on dumpcap. (SLES 10.3)
It&#39;s working fine with regard to capturing. However, the TMPDIR variable is ignored.
Is this a security feature? Does somebody know, how to circumvent this?
Best regards Philipp
setuid dumpcap tmpdirasked 23 Feb &#39;11, 05:25
pvh
1●1●1●2
accept rate: 0%
 edited 23 Feb &#39;11, 05:26</description>
    </item>
    
    <item>
      <title>Trace pane shows incorrect info message</title>
      <link>/questions/2517/trace-pane-shows-incorrect-info-message/</link>
      <pubDate>Wed, 23 Feb 2011 05:42:00 +0000</pubDate>
      
      <guid>/questions/2517/trace-pane-shows-incorrect-info-message/</guid>
      <description>Trace pane shows incorrect info message  0 Hello, I&#39;ve recorded a trace, there are messages that are being showed as 180 Ringing (in the upper pane, th colored one), but when i see inside the message i see that this is actually 200 OK message
this is not a one-time error, i also see BYE meesage in the trace, but this is actually ACK strange, right? (How do i upload a screenshot?</description>
    </item>
    
    <item>
      <title>Translating TCP Stream to readable format</title>
      <link>/questions/2518/translating-tcp-stream-to-readable-format/</link>
      <pubDate>Wed, 23 Feb 2011 07:20:00 +0000</pubDate>
      
      <guid>/questions/2518/translating-tcp-stream-to-readable-format/</guid>
      <description>Translating TCP Stream to readable format  0 I&#39;m a total newbie. I&#39;m trying to translate a TCP stream into a readable format. Ideally, I&#39;d like to read the body of the emails I&#39;m capturing. Is that possible with wireshark? If so, how?
emailasked 23 Feb &#39;11, 07:20
Shadow
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Yes, you can do that. If you have already identified the TCP stream you can use the popup menu on one of the packets of the stream in the packet list and select the &#34;</description>
    </item>
    
    <item>
      <title>Initial Speaker (SIP)</title>
      <link>/questions/2524/initial-speaker-sip/</link>
      <pubDate>Wed, 23 Feb 2011 10:53:00 +0000</pubDate>
      
      <guid>/questions/2524/initial-speaker-sip/</guid>
      <description>Initial Speaker (SIP)  0 Hi all,
I&#39;m catching a flow of SIP traffic and would like to filter the calls captured by the initial speaker, but i havent fonund a way to do so, any suggestions?
- initial speaker sipasked 23 Feb &#39;11, 10:53
jsarante
1●2●2●2
accept rate: 0%
  
One Answer:
  
0What about something like this:-
sip.from.user == &#34;1234567890&#34;
answered 23 Feb &#39;11, 11:22</description>
    </item>
    
    <item>
      <title>Business use</title>
      <link>/questions/2525/business-use/</link>
      <pubDate>Wed, 23 Feb 2011 11:07:00 +0000</pubDate>
      
      <guid>/questions/2525/business-use/</guid>
      <description>Business use  0 Is it permissible for businesses to use WIRESHARK? (i.e. is this within the EULA?)
eula businesses businessasked 23 Feb &#39;11, 11:07
kweiner
1●1●1●1
accept rate: 0%
  
2 Answers:
  
2With respect to installing and running Wireshark, the answer (from the license perspective) is &#34;Yes&#34;.
Wireshark uses the &#34;Gnu General Public License (V2)&#34;. A web search will turn up many sites with detailed explanations of the license.</description>
    </item>
    
    <item>
      <title>Would anyone like to provide WireShark demo for our Windows Enterprise User Group in NYC at Microsoft headquarters??</title>
      <link>/questions/2528/would-anyone-like-to-provide-wireshark-demo-for-our-windows-enterprise-user-group-in-nyc-at-microsoft-headquarters/</link>
      <pubDate>Wed, 23 Feb 2011 11:25:00 +0000</pubDate>
      
      <guid>/questions/2528/would-anyone-like-to-provide-wireshark-demo-for-our-windows-enterprise-user-group-in-nyc-at-microsoft-headquarters/</guid>
      <description>Would anyone like to provide WireShark demo for our Windows Enterprise User Group in NYC at Microsoft headquarters??  0 Hello, Every month our user group (NYeWin) tries to get a vendor or guru of a product to demonstrate a tool or product for the Enterprise IT admins. We are interested in having WireShark presented in an upcoming meeting. Preferably March 3rd. Our meetings are hosted in the Microsoft office headquarters in mid-town Manhattan.</description>
    </item>
    
    <item>
      <title>how to have UI column show outer vlan.id</title>
      <link>/questions/2529/how-to-have-ui-column-show-outer-vlanid/</link>
      <pubDate>Wed, 23 Feb 2011 11:45:00 +0000</pubDate>
      
      <guid>/questions/2529/how-to-have-ui-column-show-outer-vlanid/</guid>
      <description>how to have UI column show outer vlan.id  0 hi,
I&#39;m capturing double 802.1q tagged frames. I&#39;d like to have columns which display both the outer and inner vlan tag ID in the user interface. the column field type &#34;802.1q VLAN id&#34; shows the inner vlan id. the custom column with vlan.id also shows inner tag. how do i have a column show the outer tag vlan id?
thanks in advance,</description>
    </item>
    
    <item>
      <title>Missing 802.11 adapter</title>
      <link>/questions/2530/missing-80211-adapter/</link>
      <pubDate>Wed, 23 Feb 2011 12:04:00 +0000</pubDate>
      
      <guid>/questions/2530/missing-80211-adapter/</guid>
      <description>Missing 802.11 adapter  0 Greetings,
I just installed Wireshark 1.4.3 on Windows 7 64 bit and my Intel Centrino wireless adapter is not showing up in my interface list.
Anything special that I have to do to get the 802.11 side of things up and running?
The wired GigE interface that is built into the laptop is working just fine, but not the wireless interface.
Thanks, Dan
adapters wifi 802.</description>
    </item>
    
    <item>
      <title>Gre Decapsulation</title>
      <link>/questions/2532/gre-decapsulation/</link>
      <pubDate>Wed, 23 Feb 2011 12:24:00 +0000</pubDate>
      
      <guid>/questions/2532/gre-decapsulation/</guid>
      <description>Gre Decapsulation  0 Is there a version of wireshark that can decapsulate a gre tunnel?
I&#39;ve set up a gre tunnel between two endpoint and traversing a middle box. I am trying to sniffer at the middle box and inspect the data stream.
The version of wireshark suggested on the &#34;wishes&#34; wiki. 0.10.8 does not work, the data within the gre frame is not decoded.
the data is stacked, application/ip/ppp/gre/ip/enet</description>
    </item>
    
    <item>
      <title>Wire Shark server usage</title>
      <link>/questions/2548/wire-shark-server-usage/</link>
      <pubDate>Thu, 24 Feb 2011 05:22:00 +0000</pubDate>
      
      <guid>/questions/2548/wire-shark-server-usage/</guid>
      <description>Wire Shark server usage  0 Hi,
How much Power and Space does a wireshark server require?What are the different interfaces which can be monitored via Wireshark?What are the protocols which can be decoded and monitored?Regards Sachin Mishra
businessasked 24 Feb &#39;11, 05:22
sachin
1●1●1●1
accept rate: 0%
 edited 24 Feb &#39;11, 05:42 
SYN-bit ♦♦
17.1k●9●57●245
  
One Answer:
  
0Wireshark is software, as such it does not take power and space.</description>
    </item>
    
    <item>
      <title>Radius load(*) graph with in wireshark</title>
      <link>/questions/2553/radius-load-graph-with-in-wireshark/</link>
      <pubDate>Thu, 24 Feb 2011 08:16:00 +0000</pubDate>
      
      <guid>/questions/2553/radius-load-graph-with-in-wireshark/</guid>
      <description>Radius load(*) graph with in wireshark  0 Hi,
I want to ask question related to radius.
Is there any way to use the LOAD(*) graphs for RADIUS?
Is there any mechanism to generate stats that say :
A nos. of transactions were completed between 0-10ms
B nos. of transactions were completed between 11-20ms
C nos. of transactions were completed between 21-30ms
D nos. of transactions were completed between 31-40ms</description>
    </item>
    
    <item>
      <title>AirPcap Adapter Causes Wireshark to Hang</title>
      <link>/questions/2557/airpcap-adapter-causes-wireshark-to-hang/</link>
      <pubDate>Thu, 24 Feb 2011 09:46:00 +0000</pubDate>
      
      <guid>/questions/2557/airpcap-adapter-causes-wireshark-to-hang/</guid>
      <description>AirPcap Adapter Causes Wireshark to Hang  0 Running Wireshark 1.4.2 on a Dell Vista64 laptop. Whenever my AirPcap Nx device is attached (driver version 06/03/2009) to the laptop, Wireshark hangs upon loading. If I unplug the AirPcap adapter, Wireshark completes the loading process. If I then plug the AirPcap back in and click &#34;Interfaces&#34;, it hangs again, until I unplug the AirPcap adapter. It then shows the Interfaces screen, along with the AirPcap adapter visible.</description>
    </item>
    
    <item>
      <title>not detecting usb broadband modem</title>
      <link>/questions/2562/not-detecting-usb-broadband-modem/</link>
      <pubDate>Thu, 24 Feb 2011 21:24:00 +0000</pubDate>
      
      <guid>/questions/2562/not-detecting-usb-broadband-modem/</guid>
      <description>not detecting usb broadband modem  0 Hi
I am a new WIRESHARK user.When i tried to capture with my Wifi home network it is working fine.But when i tried to capture with usb broadband modem is not listing in the interface.So i cant able to capture details
Cyril Baby K
interfaceasked 24 Feb &#39;11, 21:24
Cyril
1●1●1●1
accept rate: 0%
By &#34;broadband&#34; do you mean &#34;mobile broadband&#34;, i.e. cell phone or WiMax?</description>
    </item>
    
    <item>
      <title>Wireshark does not see Teredo and ISATAP Pseudo-Interfaces</title>
      <link>/questions/2565/wireshark-does-not-see-teredo-and-isatap-pseudo-interfaces/</link>
      <pubDate>Fri, 25 Feb 2011 08:54:00 +0000</pubDate>
      
      <guid>/questions/2565/wireshark-does-not-see-teredo-and-isatap-pseudo-interfaces/</guid>
      <description>Wireshark does not see Teredo and ISATAP Pseudo-Interfaces  0 Hello, I have installed on my PC several versions of wireshark. All of them show in the &#34;Capture Interfaces&#34; window three interfaces: the wired LAN interface, the wireless LAN interface, and a logical wireless interface. The last two are shown as &#34;Microsoft Intefaces&#34;.
Wireshark deos not see the logical IPv6 interfaces (Teredo and ISATAP tunnels). The Teredo interface is working and it is correctly shown by Microsoft Network Monitor 3.</description>
    </item>
    
    <item>
      <title>Identifying 802.11 Over-Crowded Bandwidth with Wireshark and Aircap.</title>
      <link>/questions/2566/identifying-80211-over-crowded-bandwidth-with-wireshark-and-aircap/</link>
      <pubDate>Fri, 25 Feb 2011 11:57:00 +0000</pubDate>
      
      <guid>/questions/2566/identifying-80211-over-crowded-bandwidth-with-wireshark-and-aircap/</guid>
      <description>Identifying 802.11 Over-Crowded Bandwidth with Wireshark and Aircap.  2 Hi all and thanks for reading my post.
I have been using Wireshark and AirPcap (USB adapter) on and off, over the last 1-2 weeks, so excuse any ‘apparent’ questions I might ask.
I will start by saying that my knowledge of the IEEE 802.11 standard is ‘starter-intermediate’, but I do have access to it and I am more than willing to understand it fully.</description>
    </item>
    
    <item>
      <title>Reassembled Packet Format</title>
      <link>/questions/2577/reassembled-packet-format/</link>
      <pubDate>Sun, 27 Feb 2011 13:00:00 +0000</pubDate>
      
      <guid>/questions/2577/reassembled-packet-format/</guid>
      <description>Reassembled Packet Format  1 The proto I&#39;m decoding can be over UDP or TCP, and multiple msgs can be in a given UDP/TCP packet.
I&#39;m able to detect when my msg overflows into the next packet, and I can successfully manipulate the pinfo.desegment_len and pinfo.desegment_offset vars to have the decoding of the following packet start in the correct place. However, the dissector for the last msg (the fragmented one at the end of the packet) doesn&#39;t get called since I return out when I don&#39;t have enough bytes for a complete msg.</description>
    </item>
    
    <item>
      <title>what mean &amp;quot;max delta &amp;quot;</title>
      <link>/questions/2584/what-mean-max-delta/</link>
      <pubDate>Mon, 28 Feb 2011 07:21:00 +0000</pubDate>
      
      <guid>/questions/2584/what-mean-max-delta/</guid>
      <description>what mean &amp;ldquo;max delta &amp;ldquo;  0 max delta in wirshark
deltaasked 28 Feb &#39;11, 07:21
Khirennas Ab...
1●1●1●1
accept rate: 0%
  
One Answer:
  
0sigh
For such a nicely formulated question, let me present a suitable answer:
http://www.google.de/search?q=max+delta+wireshark
answered 28 Feb &#39;11, 08:06
Landi
2.3k●5●14●42
accept rate: 28%
 edited 28 Feb &#39;11, 08:06 
     </description>
    </item>
    
    <item>
      <title>VLAN P-bits</title>
      <link>/questions/2585/vlan-p-bits/</link>
      <pubDate>Mon, 28 Feb 2011 07:34:00 +0000</pubDate>
      
      <guid>/questions/2585/vlan-p-bits/</guid>
      <description>VLAN P-bits  0 How to check VLAN P-bits in a wireshark log?
vlan-pbitsasked 28 Feb &#39;11, 07:34
shfarooq
1●1●1●1
accept rate: 0%
  
One Answer:
  
0If by &#34;Wireshark Log&#34; you mean, a &#34;Packet capture file&#34; and by &#34;Check&#34; you mean &#34;Display&#34; you can display this field with a custom column. Depending on the version of wireshark you need to use the field &#34;vlan.priority&#34; for versions up to 1.</description>
    </item>
    
    <item>
      <title>Can only see multicast and local traffic</title>
      <link>/questions/2591/can-only-see-multicast-and-local-traffic/</link>
      <pubDate>Mon, 28 Feb 2011 22:51:00 +0000</pubDate>
      
      <guid>/questions/2591/can-only-see-multicast-and-local-traffic/</guid>
      <description>Can only see multicast and local traffic  0 I have installed Wireshark on a Macmini with osx 10.6. When I capture, the trafic only consists of broadcasts and local trafic. I cant see http-trafic of other computers in the wireless-net. I have choosen the airport interface and I have choosen ethernet ( If I choose any of the 802 I get nothing ).
Do I have to buy another interface?</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t save reversed direction in a file: Unsupported Codec!</title>
      <link>/questions/2592/cant-save-reversed-direction-in-a-file-unsupported-codec/</link>
      <pubDate>Tue, 01 Mar 2011 00:47:00 +0000</pubDate>
      
      <guid>/questions/2592/cant-save-reversed-direction-in-a-file-unsupported-codec/</guid>
      <description>Can&amp;rsquo;t save reversed direction in a file: Unsupported Codec!  1 Hey guys, I am new to Wireshark I am trying to save a g711A payload. When i try to save in both channels i get the folowwing error:
Can&#39;t save reversed direction in a file: Unsupported Codec!
What is the problem: I am running wireshark on a server, connected to it trough RDP. Thanks in advance.
Greets, Cem
save payload stream rtpasked 01 Mar &#39;11, 00:47</description>
    </item>
    
    <item>
      <title>Measure login latency</title>
      <link>/questions/2593/measure-login-latency/</link>
      <pubDate>Tue, 01 Mar 2011 01:06:00 +0000</pubDate>
      
      <guid>/questions/2593/measure-login-latency/</guid>
      <description>Measure login latency  0 We have a issue by latency when logging in to our network . It takes between 5-10 minutes from the computer is startet until I am logged in.
I have done a wireshark capture from start of the computer until the login process is finished. How is the best way to analyze the traffic to determine the latency. I wish to find out if the latency belongs to LAN switching, applications &amp;amp; Protocols,server traffic(late response).</description>
    </item>
    
    <item>
      <title>Capture cisco trunk interfaces</title>
      <link>/questions/2596/capture-cisco-trunk-interfaces/</link>
      <pubDate>Tue, 01 Mar 2011 03:12:00 +0000</pubDate>
      
      <guid>/questions/2596/capture-cisco-trunk-interfaces/</guid>
      <description>Capture cisco trunk interfaces  0 1Hi all,
I really need help with this one. I have to capture traffic betwwen trunked cisco ports (dot1Q). I have a switch in the middle with monitor session command to mirror the physical interface. monitor session 2 source interface GiX/XX monitor session 2 destination interface GY/YY monitor session 2 filter packet-type good rx
If I ping a machine on the remote lan i only get the requests but not the replays (But the echo ping is responded)</description>
    </item>
    
    <item>
      <title>Wireshak capture drive.</title>
      <link>/questions/2604/wireshak-capture-drive/</link>
      <pubDate>Tue, 01 Mar 2011 05:47:00 +0000</pubDate>
      
      <guid>/questions/2604/wireshak-capture-drive/</guid>
      <description>Wireshak capture drive.  0 Hello,
My drive c is full and when I am running the wireshark I get the error message low disk space. how can I change the drive where the packets are being captured. I do not mean when I save the capture but when the capture is being run I would like the packets to be stored in drive D.
BR, V. Nicolau
shortkeyasked 01 Mar &#39;11, 05:47</description>
    </item>
    
    <item>
      <title>Group by mac address</title>
      <link>/questions/2610/group-by-mac-address/</link>
      <pubDate>Tue, 01 Mar 2011 08:29:00 +0000</pubDate>
      
      <guid>/questions/2610/group-by-mac-address/</guid>
      <description>Group by mac address  0 Hello,
I searched a lot but I don&#39;t find a solution. I would to know if it is possible in tshark to filter the traffic (in Bytes) for each mac address
exemple :
00:ce:56:fd:34:ab -&amp;gt; 8000 Bytes 00:ce:89:fd:37:c8 -&amp;gt; 16788 BytesI have started something like this :
tshark -r myfile -qz io,stat,0,1,SUM(...Any idea please ?
kevin
filter mac sum addressasked 01 Mar &#39;11, 08:29</description>
    </item>
    
    <item>
      <title>How can I observe HTTP request-response latency?</title>
      <link>/questions/2613/how-can-i-observe-http-request-response-latency/</link>
      <pubDate>Tue, 01 Mar 2011 10:25:00 +0000</pubDate>
      
      <guid>/questions/2613/how-can-i-observe-http-request-response-latency/</guid>
      <description>How can I observe HTTP request-response latency?  0 I&#39;d like to see HTTP request/response latency. I tried using tcp.calculate_timestamps and tcp.time_delta, but the latter is empty. I&#39;m using a Mac in case that matters.
/Applications/Wireshark.app/Contents/Resources/bin/tshark -b duration:3600 -o tcp.calculate_timestamps:TRUE -i en1 -f &#39;tcp port 80&#39; -w capture.bin
I open the capture file in Wireshark and add a column for Delta time (conversation). Its value in all rows is empty.</description>
    </item>
    
    <item>
      <title>Client &amp;amp;  Access Point association handshake sample</title>
      <link>/questions/2618/client-access-point-association-handshake-sample/</link>
      <pubDate>Tue, 01 Mar 2011 12:29:00 +0000</pubDate>
      
      <guid>/questions/2618/client-access-point-association-handshake-sample/</guid>
      <description>Client &amp;amp; Access Point association handshake sample  0 Dear Sirs,
My adapter does not support &#34;monitor&#34; mode and therefore I cannot capture the beacon packets and the association of a client to an AP to join a LAN.
Is this something I could request from you? I basically want to see PC A detect the wifi and join the network.
Thank you in advance.
Okie
beacon wifi handshake associationasked 01 Mar &#39;11, 12:29</description>
    </item>
    
    <item>
      <title>child dumpcap process died : Exception</title>
      <link>/questions/2626/child-dumpcap-process-died-exception/</link>
      <pubDate>Tue, 01 Mar 2011 18:50:00 +0000</pubDate>
      
      <guid>/questions/2626/child-dumpcap-process-died-exception/</guid>
      <description>child dumpcap process died : Exception  1 Hi
When I open Wireshark to capture the traffic, I am not able to see the network interfaces/adapters. And I am getting seeing the message &#34;child dumpcap process died: Exception 0xc0000022&#34;.
But I am able to open the existing traces.
I have tried uninstalling and installing the newer versions of Wireshark (1.4.4) and Winpcap(4.1.2). Also rebooted my laptop.
Please let me know what is this error message about and how I can troubleshoot/resolve this issue?</description>
    </item>
    
    <item>
      <title>Huawei Modem E372 not Detected</title>
      <link>/questions/2629/huawei-modem-e372-not-detected/</link>
      <pubDate>Wed, 02 Mar 2011 05:31:00 +0000</pubDate>
      
      <guid>/questions/2629/huawei-modem-e372-not-detected/</guid>
      <description>Huawei Modem E372 not Detected  0 Hi, I am using a Huawei modem E372 to connect to internet . But this device is not listed in the available interfaces.
Any suggestion how to solve this.
Thanks, Hany El-Akel
huawei detected modem e372asked 02 Mar &#39;11, 05:31
Hany
1●1●1●2
accept rate: 0%
 edited 02 Mar &#39;11, 05:33 
  
One Answer:
  
0Run an operating system other than Windows on your machine, or run Windows 2000 or the 32-bit Windows XP rather than 64-bit Windows XP, Windows Vista, or Windows 7.</description>
    </item>
    
    <item>
      <title>Using wireshark to solve anti virus problem, question about filters?</title>
      <link>/questions/2630/using-wireshark-to-solve-anti-virus-problem-question-about-filters/</link>
      <pubDate>Wed, 02 Mar 2011 06:26:00 +0000</pubDate>
      
      <guid>/questions/2630/using-wireshark-to-solve-anti-virus-problem-question-about-filters/</guid>
      <description>Using wireshark to solve anti virus problem, question about filters?  0 Hi, I am having problems with my anti virus on one of my servers. the tech support of the company have asked me to take a capture using wireshark while the anti virus is trying to update. I am however finding a problem with this. For obvious reasons I do not want to send them a full scan of my network.</description>
    </item>
    
    <item>
      <title>Packet captures and Riverbed Appliances</title>
      <link>/questions/2634/packet-captures-and-riverbed-appliances/</link>
      <pubDate>Wed, 02 Mar 2011 09:39:00 +0000</pubDate>
      
      <guid>/questions/2634/packet-captures-and-riverbed-appliances/</guid>
      <description>Packet captures and Riverbed Appliances  0 Would it be beneficial to capture traffic before and after a Riverbed Steelhead appliance?
Is there any tips anyone can provide when reading packets from one of these appliances?
Thanks
riverbed steelhead packetasked 02 Mar &#39;11, 09:39
scottmildy
1●1●1●1
accept rate: 0%
scottmildy, are you trying to see how much RB will help or trying to figure out what the &#34;secret sauce&#34; is? Before I get into a long drawn out answer, I wanted to see what you were after.</description>
    </item>
    
    <item>
      <title>ARP Question</title>
      <link>/questions/2639/arp-question/</link>
      <pubDate>Wed, 02 Mar 2011 12:01:00 +0000</pubDate>
      
      <guid>/questions/2639/arp-question/</guid>
      <description>ARP Question  0 I am a novice wireshark user. I noticed yesterday while trying to solve an unrelated problem that ARP requests appeared to be a majority of the traffic on our network. After letting wireshark run for a while, it was nearly 60%. As I looked closer, it appears that our router is sending ARP packets to IP addresses that don&#39;t even exist on our network at least every second.</description>
    </item>
    
    <item>
      <title>download Wireshark for AIX</title>
      <link>/questions/2643/download-wireshark-for-aix/</link>
      <pubDate>Wed, 02 Mar 2011 17:00:00 +0000</pubDate>
      
      <guid>/questions/2643/download-wireshark-for-aix/</guid>
      <description>download Wireshark for AIX  0 Please can anybody let me know if we can user wireshark on AIX 6.1, if so please guide me to a download link. Or please suggest a good tool which can be used for network analysis of a AIX 6.1.
Regards, Dhrajj
dowload aix for wiresharkasked 02 Mar &#39;11, 17:00
dhrajj
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0The third-party packages section of [the Wireshark download page[1] has a &#34;</description>
    </item>
    
    <item>
      <title>&amp;quot;failed to set hardware filter to promiscuous mode&amp;quot; error when capture attempted on a wireless adapter on Windows</title>
      <link>/questions/2647/failed-to-set-hardware-filter-to-promiscuous-mode-error-when-capture-attempted-on-a-wireless-adapter-on-windows/</link>
      <pubDate>Thu, 03 Mar 2011 06:46:00 +0000</pubDate>
      
      <guid>/questions/2647/failed-to-set-hardware-filter-to-promiscuous-mode-error-when-capture-attempted-on-a-wireless-adapter-on-windows/</guid>
      <description>&amp;ldquo;failed to set hardware filter to promiscuous mode&amp;rdquo; error when capture attempted on a wireless adapter on Windows  1 When i run WireShark, this one Popup.
The capture session could not be initiated (failed to set hardware filter to promiscuous mode). Please check that &#34;DeviceNPF_{62909DBD-56C7-48BB-B75B-EC68FF237032}&#34; is the proper interface. Help can be found at: http://wiki.wireshark.org/WinPcap http://wiki.wireshark.org/CaptureSetup What should I do for it?
lancard errors wiresharkasked 03 Mar &#39;11, 06:46</description>
    </item>
    
    <item>
      <title>Virtual adapter not recognized by wireshark</title>
      <link>/questions/2648/virtual-adapter-not-recognized-by-wireshark/</link>
      <pubDate>Thu, 03 Mar 2011 07:02:00 +0000</pubDate>
      
      <guid>/questions/2648/virtual-adapter-not-recognized-by-wireshark/</guid>
      <description>Virtual adapter not recognized by wireshark  0 Hi,
I built a NDIS virtual miniport driver. The virtual adapter shows up in the network connections and IPConfig result. But it is not recognized by wireshark. Any ideas? Thx in advance.
recognized adapter virtual ndis wiresharkasked 03 Mar &#39;11, 07:02
Yijun
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Is it recognized by WinDump? If not, you might try contacting the folks at WinPcap first.</description>
    </item>
    
    <item>
      <title>Cannot open wireshark on mac os X snow leopard</title>
      <link>/questions/2650/cannot-open-wireshark-on-mac-os-x-snow-leopard/</link>
      <pubDate>Thu, 03 Mar 2011 09:44:00 +0000</pubDate>
      
      <guid>/questions/2650/cannot-open-wireshark-on-mac-os-x-snow-leopard/</guid>
      <description>Cannot open wireshark on mac os X snow leopard  0 Hi I followed instructions to download and install wireshark for mac os X snow leopard. Howerver, when i click on the wireshark app in applications, it appears to show up for a brief second on the dock and disappears instantly.. I&#39;ve had the X11 app open during that.. with or without it it behaves the same. Pls help!!!
Thanks</description>
    </item>
    
    <item>
      <title>How can I find out who is downloading the most using Wireshark ??</title>
      <link>/questions/2657/how-can-i-find-out-who-is-downloading-the-most-using-wireshark/</link>
      <pubDate>Thu, 03 Mar 2011 18:03:00 +0000</pubDate>
      
      <guid>/questions/2657/how-can-i-find-out-who-is-downloading-the-most-using-wireshark/</guid>
      <description>How can I find out who is downloading the most using Wireshark ??  0 Hi guys .. Well I&#39;m running a shared Wifi network (I know the wifi encryption key and all configuration details, etc ..) .. How can I find out which of the 9 different IP addresses is using the most bandwidth over a period of, lets say, 24 hours ?
Also, it would be helpful if I can maybe get histogram based graphs showing bandwidth usage based on IP addresses for some period of time (say 24 hours) .</description>
    </item>
    
    <item>
      <title>Recover a capture</title>
      <link>/questions/2659/recover-a-capture/</link>
      <pubDate>Fri, 04 Mar 2011 00:57:00 +0000</pubDate>
      
      <guid>/questions/2659/recover-a-capture/</guid>
      <description>Recover a capture  0 Hello,
Yesterday I started a capture at 8:42 am. This morning at 9am I wanted to watch the capture but everything has been cleared and the capture has begun at 8:42 this morning. How to retrieve the capture yesterday?
Sorry for my bad english ;)
Thanks
capture historyasked 04 Mar &#39;11, 00:57
chandler124
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Lua: cannot read SNMP request_id field</title>
      <link>/questions/2660/lua-cannot-read-snmp-request_id-field/</link>
      <pubDate>Fri, 04 Mar 2011 01:02:00 +0000</pubDate>
      
      <guid>/questions/2660/lua-cannot-read-snmp-request_id-field/</guid>
      <description>Lua: cannot read SNMP request_id field  1 Hello WIRESHARK community!
I need your help because i mark time here with a little Lua scripting problem. My aim is to count lost SNMP transactions. Therefore i need to read out the snmp.request_id field to handle requests and responses belonging together. Unfortunately it is not working as it should. Here is my little debugging code example &amp;lt;snmpreqid.lua&amp;gt;:
snmp_reqID_extr = Field.new(&amp;quot;snmp.request_id&amp;quot;) snmp = Listener.</description>
    </item>
    
    <item>
      <title>Content-encoded entity body (x-gzip): 518 bytes [Error: Decompression failed]</title>
      <link>/questions/2661/content-encoded-entity-body-x-gzip-518-bytes-error-decompression-failed/</link>
      <pubDate>Fri, 04 Mar 2011 06:17:00 +0000</pubDate>
      
      <guid>/questions/2661/content-encoded-entity-body-x-gzip-518-bytes-error-decompression-failed/</guid>
      <description>Content-encoded entity body (x-gzip): 518 bytes [Error: Decompression failed]  1 Hi All,
I&#39;ve been using Wireshark to monitor the request &amp;amp; response data (while calling an webservice) and Wireshark is able to display the XML request but when i look at the response, it shows some error like &#34;Content-encoded entity body (x-gzip): 518 bytes [Error: Decompression failed]&#34;,
could anybody tell what sort of configuration i have to set to decompress the chunk data from retrieved from Webserver.</description>
    </item>
    
    <item>
      <title>Finding and highlighting in packet list area (when looking for particular flow records)</title>
      <link>/questions/2662/finding-and-highlighting-in-packet-list-area-when-looking-for-particular-flow-records/</link>
      <pubDate>Fri, 04 Mar 2011 06:27:00 +0000</pubDate>
      
      <guid>/questions/2662/finding-and-highlighting-in-packet-list-area-when-looking-for-particular-flow-records/</guid>
      <description>Finding and highlighting in packet list area (when looking for particular flow records)  0 Hi,
I have to look at a lot of flow records and I work with filters like: cflow.srcaddr == 10.1.1.20 and cflow.protocol==1 and cflow.dstaddr == 10.1.190.4
The result can be as low as 1 packet (if I&#39;m lucky) but the packet list window still has 34 entries, and if I have more packets you have xxx entries.</description>
    </item>
    
    <item>
      <title>troubleshooting &amp;quot;Bogus IP length&amp;quot;. Causes?</title>
      <link>/questions/2667/troubleshooting-bogus-ip-length-causes/</link>
      <pubDate>Fri, 04 Mar 2011 11:41:00 +0000</pubDate>
      
      <guid>/questions/2667/troubleshooting-bogus-ip-length-causes/</guid>
      <description>troubleshooting &amp;ldquo;Bogus IP length&amp;rdquo;. Causes?  0 I have two identical win7x64 machines on different drops - one of them gets numerous &#34;Bogus IP length&#34; packets in the capture. About every 10 seconds there will appear 7 or 8 of these all at once. The other machine gets none. What can be the problem here? is it layer 1, as I suspect? Or could it be software layer?
Thanks!
length bogus bogusiplength windows7asked 04 Mar &#39;11, 11:41</description>
    </item>
    
    <item>
      <title>strange packages</title>
      <link>/questions/2669/strange-packages/</link>
      <pubDate>Fri, 04 Mar 2011 13:59:00 +0000</pubDate>
      
      <guid>/questions/2669/strange-packages/</guid>
      <description>strange packages  0 Hello! My computer sends packets that look as:
http://img339.imageshack.us/i/screenkx.png/
these packages can be several hundred. What are these strange packages?
strange packagesasked 04 Mar &#39;11, 13:59
blitzer
1●1●1●3
accept rate: 0%
 edited 04 Mar &#39;11, 23:25 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
2A great screenshot! You did a good job in linking the HTTP request to the flood of UDP packets.</description>
    </item>
    
    <item>
      <title>Remote Capture in Windows XP</title>
      <link>/questions/2673/remote-capture-in-windows-xp/</link>
      <pubDate>Sat, 05 Mar 2011 04:27:00 +0000</pubDate>
      
      <guid>/questions/2673/remote-capture-in-windows-xp/</guid>
      <description>Remote Capture in Windows XP  1 I&#39;m using Wireshark 1.4.4 and the remote system is installed with WinPcap rpcapd version (4.1.2). rpcapd.exe -n is running in the remote pc and the corresponding service is ON too. Many options I tried to do a &#39;remote capture&#39; from Wireshark as below, but nothing seems to be working fine.
Interface: Remote &amp;amp; tried the below options rpcap://IPADDRESS/DeviceNPF_{INTERFACE INFORMATION} rpcap://IPADDRESS//DeviceNPF_{INTERFACE INFORMATION} - another try ://IPADDRESS//DeviceNPF_{INTERFACE INFORMATION} - another try &amp;amp; many more tries.</description>
    </item>
    
    <item>
      <title>visited sites filter</title>
      <link>/questions/2675/visited-sites-filter/</link>
      <pubDate>Sat, 05 Mar 2011 07:51:00 +0000</pubDate>
      
      <guid>/questions/2675/visited-sites-filter/</guid>
      <description>visited sites filter  0 I need to see the sites visited by a particular ip... m giving that in the filter but it gives me all sort of queries. I hv stared using your product recently and that&#39;s why I am a little unclear on the kinds of filters to pass. so far i just want to see the sites they visited, what did they searched for and what domain names were resolved along with their ip addresses.</description>
    </item>
    
    <item>
      <title>Ericsson CS1&#43; decoder</title>
      <link>/questions/2680/ericsson-cs1-decoder/</link>
      <pubDate>Sun, 06 Mar 2011 00:31:00 +0000</pubDate>
      
      <guid>/questions/2680/ericsson-cs1-decoder/</guid>
      <description>Ericsson CS1+ decoder  0 I need to know if there is a plug-in, decoder for the CS1+ protocol that could be used with Wireshark?
When opening an INAP traffic, some of them are successfully displayed while in others there are errors like &#34;wrong field in sequence&#34;....etc
cs1+ inapasked 06 Mar &#39;11, 00:31
Ahmad_Zuhd
1●1●1●1
accept rate: 0%
  
One Answer:
  
0To my knowledge, there is not.</description>
    </item>
    
    <item>
      <title>How to find area of the IO graph</title>
      <link>/questions/2682/how-to-find-area-of-the-io-graph/</link>
      <pubDate>Sun, 06 Mar 2011 13:40:00 +0000</pubDate>
      
      <guid>/questions/2682/how-to-find-area-of-the-io-graph/</guid>
      <description>How to find area of the IO graph  1 Dear friends, I plotted a IO graph on a dump of packets collected over few seconds of time. I am able to see spikes/peaks in the graph with coordinates X-axis 1sec tick and Y-axis - bits/tick, scale - auto. I would like to find out the area of the peak above a certain point of y-axis. Say, my threshold limit is 4Mbps, I would like to find the amount of over-subscribed traffic above 4Mbps for the duration it over-subscribed.</description>
    </item>
    
    <item>
      <title>Not parsing the VJ Compressed Protocol packets</title>
      <link>/questions/2688/not-parsing-the-vj-compressed-protocol-packets/</link>
      <pubDate>Mon, 07 Mar 2011 00:26:00 +0000</pubDate>
      
      <guid>/questions/2688/not-parsing-the-vj-compressed-protocol-packets/</guid>
      <description>Not parsing the VJ Compressed Protocol packets  0 We are currently working with Wireshark version 1.0.13 to parse &#34;PPP protocol&#34; over previously recorded pcap file. When we open our pcap file, &#34;PPP headers&#34; are recognized successfully, also &#34;PPP VJ uncompressed TCP&#34; data can be parsed successfully. On the other hand, &#34;VJ compressed TCP&#34; packets are recognized but not parsed and defines them as &#34;unknown direction&#34;.
Does it mean that my Wireshark can not parse those packets with &#34;</description>
    </item>
    
    <item>
      <title>Wireshark dissector handling TCP_FAST_RETRANSMISSION</title>
      <link>/questions/2689/wireshark-dissector-handling-tcp_fast_retransmission/</link>
      <pubDate>Mon, 07 Mar 2011 00:54:00 +0000</pubDate>
      
      <guid>/questions/2689/wireshark-dissector-handling-tcp_fast_retransmission/</guid>
      <description>Wireshark dissector handling TCP_FAST_RETRANSMISSION  0 I&#39;m working on a Wireshark dissector plugin (C-based) to process some network data. The protocol that is being used over TCP is one where we can&#39;t know the complete length of a response from a header field, so I need to use the desegment_offset/desegment_length pinfo fields (which I guess tcp_dissect_pdus uses anyway).
Anyhow, this works fine until the network stream has some dup acks resulting in a TCP Fast Retransmission in the middle of the stream.</description>
    </item>
    
    <item>
      <title>how to develop a packet capture software like wireshark?</title>
      <link>/questions/2696/how-to-develop-a-packet-capture-software-like-wireshark/</link>
      <pubDate>Mon, 07 Mar 2011 06:46:00 +0000</pubDate>
      
      <guid>/questions/2696/how-to-develop-a-packet-capture-software-like-wireshark/</guid>
      <description>how to develop a packet capture software like wireshark?  0 Resently, i want to develop a software just like wireshark. but i do not have much knowledge about GTK/PYTHON, i am a windows user. I wonder to know how thoese technology assemble together in wireshark. i want to do this in VS2010 and use sharppcap, but there is not much parse, can some one give me some advice about how to develop such a software in windows?</description>
    </item>
    
    <item>
      <title>how to convert k12(txt) file to pcap from the command line</title>
      <link>/questions/2697/how-to-convert-k12txt-file-to-pcap-from-the-command-line/</link>
      <pubDate>Mon, 07 Mar 2011 07:21:00 +0000</pubDate>
      
      <guid>/questions/2697/how-to-convert-k12txt-file-to-pcap-from-the-command-line/</guid>
      <description>how to convert k12(txt) file to pcap from the command line  0 Hello,
I want to convert a .pcap file to k12 file and then do the reverse (i.e. k12 -&amp;gt; pcap), and to do so from the command line. I was able to do so when I was using version 1.0.5, but I can&#39;t do it in the newer versions.
Thanks.
conversionThis question is marked &#34;community wiki&#34;.asked 07 Mar &#39;11, 07:21</description>
    </item>
    
    <item>
      <title>Monitor Mode problem</title>
      <link>/questions/2702/monitor-mode-problem/</link>
      <pubDate>Mon, 07 Mar 2011 17:23:00 +0000</pubDate>
      
      <guid>/questions/2702/monitor-mode-problem/</guid>
      <description>Monitor Mode problem  0 I&#39;m trying to view the RTS/CTS process that occurs when you lower the RTS threshold on a wireless router. I have to be in monitor mode to be able to view this traffic but I can&#39;t seem to be able to get there. I&#39;m looking under &#34;Capture&#34; for an option under promiscuous mode but from the Wireshark User&#39;s Guide I see that this option may be available only if you are running Linux or Unix.</description>
    </item>
    
    <item>
      <title>Verified Executable of Wireshark</title>
      <link>/questions/2708/verified-executable-of-wireshark/</link>
      <pubDate>Mon, 07 Mar 2011 22:36:00 +0000</pubDate>
      
      <guid>/questions/2708/verified-executable-of-wireshark/</guid>
      <description>Verified Executable of Wireshark  0 My concern is that while i am using Wireshark latest Windows x64 edition and try to verify the Wireshark executable the procexp (Sysinternals Tool) is showing me that cannot be verified.
So i am wondering if the Wireshark executables are digitally signed or not. Because if they are may i am using a an executable that is infected.
executable verifiedasked 07 Mar &#39;11, 22:36</description>
    </item>
    
    <item>
      <title>filtering tcp packet</title>
      <link>/questions/2710/filtering-tcp-packet/</link>
      <pubDate>Mon, 07 Mar 2011 23:12:00 +0000</pubDate>
      
      <guid>/questions/2710/filtering-tcp-packet/</guid>
      <description>filtering tcp packet  0 I want to open an static web page and run wireshark. How can I filter the last packet which comes form that page? Is it true to use tcp.flag.fin?
flagasked 07 Mar &#39;11, 23:12
A B
1●10●10●12
accept rate: 0%
  
One Answer:
  
3It could be using the fin bit, in which case you&#39;d filter for tcp.flags.fin==1. Or it might use a reset flag, which would be filtered using tcp.</description>
    </item>
    
    <item>
      <title>Is there any way to gauge how many times connection times out over a length of time?</title>
      <link>/questions/2711/is-there-any-way-to-gauge-how-many-times-connection-times-out-over-a-length-of-time/</link>
      <pubDate>Tue, 08 Mar 2011 01:10:00 +0000</pubDate>
      
      <guid>/questions/2711/is-there-any-way-to-gauge-how-many-times-connection-times-out-over-a-length-of-time/</guid>
      <description>Is there any way to gauge how many times connection times out over a length of time?  0 I&#39;ve been &#34;suffering&#34; from an extremely unstable ISP for the past several years and its just been getting worse and worse. It&#39;s impossible to play games online now because every 2 minutes or so I will &#34;lag&#34; and be unable to move for 5-10 seconds and this happens constantly. Is there any way with this program to measure how many times this &#34;</description>
    </item>
    
    <item>
      <title>I cannot browse the network through My Network Places</title>
      <link>/questions/2715/i-cannot-browse-the-network-through-my-network-places/</link>
      <pubDate>Tue, 08 Mar 2011 13:38:00 +0000</pubDate>
      
      <guid>/questions/2715/i-cannot-browse-the-network-through-my-network-places/</guid>
      <description>I cannot browse the network through My Network Places  0 When I try to browse my network through My Network Places I get the error that I do not have the permissions to do so. This has not been the case in the past. When I try to isolate the problem by disconnecting certain network switches, I am then able to browse the network and see the other computers in the work group.</description>
    </item>
    
    <item>
      <title>Wireshark doesnt record a certain IP on a lan.</title>
      <link>/questions/2717/wireshark-doesnt-record-a-certain-ip-on-a-lan/</link>
      <pubDate>Tue, 08 Mar 2011 19:16:00 +0000</pubDate>
      
      <guid>/questions/2717/wireshark-doesnt-record-a-certain-ip-on-a-lan/</guid>
      <description>Wireshark doesnt record a certain IP on a lan.  0 Hello,
I have a critical issue with wireshark. I need to record my traffic on a lan, of one of my machine&#39;s ip. But when filtering on that IP and Port, i get nothing. (all the other traffic on lan i see perfect).
This is critical for us to record this traffic, We have tried many workarounds such as switching between nic&#39;s and so on.</description>
    </item>
    
    <item>
      <title>TCP packet gets dropped</title>
      <link>/questions/2718/tcp-packet-gets-dropped/</link>
      <pubDate>Wed, 09 Mar 2011 01:31:00 +0000</pubDate>
      
      <guid>/questions/2718/tcp-packet-gets-dropped/</guid>
      <description>TCP packet gets dropped  0 I am having a weird problem. We have one set of router (Router-A)on one location A, and another set of router (Router-B) in a different location B.
We have a server located at A and connected to Router-A, and few clients located at B and connected to router B. All the clients are in the same Vlan.
Router-A and Router-B are connected via a MetroEthernet (provided by 3rd party)</description>
    </item>
    
    <item>
      <title>Troubleshooting slow WiFi file transfer</title>
      <link>/questions/2724/troubleshooting-slow-wifi-file-transfer/</link>
      <pubDate>Wed, 09 Mar 2011 07:32:00 +0000</pubDate>
      
      <guid>/questions/2724/troubleshooting-slow-wifi-file-transfer/</guid>
      <description>Troubleshooting slow WiFi file transfer  0 I am hopping to get some advice on where to look for a problem with a file transfer over WiFi. This is a somewhat simple office set up. Cable Modem -&amp;gt;10/100 Router-&amp;gt;10/100/1000 Switch with jumbo frames enabled. Wireless DWL-3200AP (D-Link) access point is connected to a router. Wired computer is connected to a switch over 1Gb. Wireless IBM X201 laptop has a b/g/n realtek (RTL8192SE) network card &amp;amp; connects to D-Link access point over G and shows 54Mb connection spped.</description>
    </item>
    
    <item>
      <title>How to capture vlan</title>
      <link>/questions/2725/how-to-capture-vlan/</link>
      <pubDate>Wed, 09 Mar 2011 07:38:00 +0000</pubDate>
      
      <guid>/questions/2725/how-to-capture-vlan/</guid>
      <description>How to capture vlan  0 I trying to capture what Vlan certain ports are configured for on my switch. Can wireshark do this? If so how do I set it up?
capture setup vlanasked 09 Mar &#39;11, 07:38
theman
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1I would go for the password recovery procedure as that will give you 100% certainty. If you want to deduct the vlan configuration of the switch you might be in luck by the packets it&#39;s sending.</description>
    </item>
    
    <item>
      <title>Capture filter remains in capture options after removing/reinstalling</title>
      <link>/questions/2735/capture-filter-remains-in-capture-options-after-removingreinstalling/</link>
      <pubDate>Wed, 09 Mar 2011 11:15:00 +0000</pubDate>
      
      <guid>/questions/2735/capture-filter-remains-in-capture-options-after-removingreinstalling/</guid>
      <description>Capture filter remains in capture options after removing/reinstalling  0 At some point before a capture I added a capture filter in the capture options window (I don&#39;t recall that I ever saved the filter itself). After closing and reopening wireshark, the capture filter remains in the capture options window. I have removed wireshark (running on Windows XP), reinstalled, and the same filter still appears. I downgraded and upgraded wireshark versions with no luck- the filter remains.</description>
    </item>
    
    <item>
      <title>Network storm</title>
      <link>/questions/2736/network-storm/</link>
      <pubDate>Wed, 09 Mar 2011 11:40:00 +0000</pubDate>
      
      <guid>/questions/2736/network-storm/</guid>
      <description>Network storm  0 Hi, we seem to be having a network storm every day at 1pm that lasts for an hour, it generates 140k of traffic to every user. Do I have to setup a filter to try and identify? I am new to this so I have no idea where to start!
Steve
packetsasked 09 Mar &#39;11, 11:40
stevewarden0
1●3●3●3
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>how to calculate total sum of ip.len field for wireshark trace</title>
      <link>/questions/2755/how-to-calculate-total-sum-of-iplen-field-for-wireshark-trace/</link>
      <pubDate>Thu, 10 Mar 2011 03:25:00 +0000</pubDate>
      
      <guid>/questions/2755/how-to-calculate-total-sum-of-iplen-field-for-wireshark-trace/</guid>
      <description>how to calculate total sum of ip.len field for wireshark trace  0 Hello, I would like to calculate sum af all ip.len values in packets. There is option cumulative but it works only for frame.len value. Thanks
length framelengthasked 10 Mar &#39;11, 03:25
lavpivolav
1●2●2●2
accept rate: 0%
 retagged 10 Mar &#39;11, 08:42 
packethunter
2.1k●7●15●48
  
One Answer:
  
2You can use TShark.</description>
    </item>
    
    <item>
      <title>Cumulaive Column ip.len value</title>
      <link>/questions/2765/cumulaive-column-iplen-value/</link>
      <pubDate>Thu, 10 Mar 2011 09:27:00 +0000</pubDate>
      
      <guid>/questions/2765/cumulaive-column-iplen-value/</guid>
      <description>Cumulaive Column ip.len value  0 Hello, Curently it is posible to add Column Cumulative which is giving cumulative value of frame leinght, Is it posible to have Cumulative column but for ip.len value Thank
lengthasked 10 Mar &#39;11, 09:27
lavpivolav
1●2●2●2
accept rate: 0%
  
One Answer:
  
1Nope, unless you write the code that would implement it or get someone else interested to write it.</description>
    </item>
    
    <item>
      <title>CLI or script for &amp;quot;Follow udp stream&amp;quot;?</title>
      <link>/questions/2767/cli-or-script-for-follow-udp-stream/</link>
      <pubDate>Thu, 10 Mar 2011 11:37:00 +0000</pubDate>
      
      <guid>/questions/2767/cli-or-script-for-follow-udp-stream/</guid>
      <description>CLI or script for &amp;ldquo;Follow udp stream&amp;rdquo;?  0 I have many .pcap files of video multicast. To strip off the network info and keep just the video data, I have been manually doing the &#34;Follow UDP stream&#34; command, then saving those results as &#34;raw&#34; transport stream (.ts) files. The problem is that this is a very long process (&amp;gt;15 min per 250Meg file).
I have the proper filter needed to get just the frames I want from the .</description>
    </item>
    
    <item>
      <title>Truncated Referer</title>
      <link>/questions/2788/truncated-referer/</link>
      <pubDate>Fri, 11 Mar 2011 12:07:00 +0000</pubDate>
      
      <guid>/questions/2788/truncated-referer/</guid>
      <description>Truncated Referer  0 Request packets have referer field but sometimes there are like this &#34;[truncated] Referer&#34; Does [truncated] shows something?
refererasked 11 Mar &#39;11, 12:07
A B
1●10●10●12
accept rate: 0%
  
One Answer:
  
2 When Wireshark puts [truncated] on a protocol tree item (such as the HTTP Referer field), it means that the field is longer than Wireshark&#39;s internal display limit (ITEM_LABEL_LENGTH==240) so the display (in the protocol tree) has been truncated.</description>
    </item>
    
    <item>
      <title>Connectivity with ODBC</title>
      <link>/questions/2791/connectivity-with-odbc/</link>
      <pubDate>Sat, 12 Mar 2011 22:11:00 +0000</pubDate>
      
      <guid>/questions/2791/connectivity-with-odbc/</guid>
      <description>Connectivity with ODBC  0 Can wireshark connect to ODBC driver or not ? if yes, how?
connectivity odbcasked 12 Mar &#39;11, 22:11
sakshi
1●1●1●1
accept rate: 0%
  
One Answer:
  
0I&#39;d say that&#39;s a no, at least I know of no way to do that.
Why would you need ODBC connectivity?
answered 13 Mar &#39;11, 07:58
Jasper ♦♦
23.8k●5●51●284
accept rate: 18%
     </description>
    </item>
    
    <item>
      <title>OS X 10.6 Install Error</title>
      <link>/questions/2792/os-x-106-install-error/</link>
      <pubDate>Sun, 13 Mar 2011 03:29:00 +0000</pubDate>
      
      <guid>/questions/2792/os-x-106-install-error/</guid>
      <description>OS X 10.6 Install Error  0 Hi,
Any thoughts on OS X 10.6 error on Wireshark launch error:
root# Wireshark dyld: Library not loaded: /usr/X11/lib/libfreetype.6.dylib Referenced from: /Applications/Wireshark.app/Contents/Resources/bin/Wireshark-bin Reason: Incompatible library version: Wireshark-bin requires version 13.0.0 or later, but libfreetype.6.dylib provides version 10.0.0 Trace/BPT trapOS has Xcode/X11/XQuartz - app just won&#39;t launch.
dylib osx error 13.0.0 launchasked 13 Mar &#39;11, 03:29
gowrann
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>wireshark with mac os x leopard 10.6.6 (latest update): no IEEE802_11_RADIO_AVS or radiotap</title>
      <link>/questions/2794/wireshark-with-mac-os-x-leopard-1066-latest-update-no-ieee802_11_radio_avs-or-radiotap/</link>
      <pubDate>Sun, 13 Mar 2011 08:05:00 +0000</pubDate>
      
      <guid>/questions/2794/wireshark-with-mac-os-x-leopard-1066-latest-update-no-ieee802_11_radio_avs-or-radiotap/</guid>
      <description>wireshark with mac os x leopard 10.6.6 (latest update): no IEEE802_11_RADIO_AVS or radiotap  0 Hello, I&#39; ve been trying to capture packets using IEEE802_11_RADIO_AVS or radiotap data link type but wireshark is unable to change the airport extreme card to this mode and so is tcpdump using the -y option (the -L option only shows the ethernet dlt). Since I do not possess the necessary background working with these drivers could you please confirm that it is due to the latest update that I cannot capture using this dlt (perhaps there have been other cases like mine)?</description>
    </item>
    
    <item>
      <title>Capturing 4 way handshake (EAPOL) - WS only captures 2?</title>
      <link>/questions/2795/capturing-4-way-handshake-eapol-ws-only-captures-2/</link>
      <pubDate>Sun, 13 Mar 2011 19:30:00 +0000</pubDate>
      
      <guid>/questions/2795/capturing-4-way-handshake-eapol-ws-only-captures-2/</guid>
      <description>Capturing 4 way handshake (EAPOL) - WS only captures 2?  1 1I am able to decrypt and view all of my own IEEE 802.11 Packets by capturing the 4 EAPOL packets when I connect to a wpa-psk network and by adjusting the preferences.
Now my question/problem is that when i connect to the network using another computer while wireshark is capturing on my pc, Wireshark only captures 2 EAPOL packets.</description>
    </item>
    
    <item>
      <title>usbmon captures</title>
      <link>/questions/2801/usbmon-captures/</link>
      <pubDate>Mon, 14 Mar 2011 08:10:00 +0000</pubDate>
      
      <guid>/questions/2801/usbmon-captures/</guid>
      <description>usbmon captures  0 I captured usb traces using usbmon and got a raw ascii format as output. When I try to open (to analyze) the captures using wireshark, I get an error msg like &#34;The file isn&#39;t a capture file in a format wireshark understands&#34;.
usb usbmonasked 14 Mar &#39;11, 08:10
kishom
1●1●1●1
accept rate: 0%
I don&#39;t know the answer to your question; however http://wiki.wireshark.org/CaptureSetup/USB may be of help</description>
    </item>
    
    <item>
      <title>What are the core dependencies for building wireshark?</title>
      <link>/questions/2804/what-are-the-core-dependencies-for-building-wireshark/</link>
      <pubDate>Mon, 14 Mar 2011 09:50:00 +0000</pubDate>
      
      <guid>/questions/2804/what-are-the-core-dependencies-for-building-wireshark/</guid>
      <description>What are the core dependencies for building wireshark?  0 Trying to build wireshark with our companies build system. Just wondering what are the core deps for building it. As in what are the minimum requirements I can get away with?&#39;
Edit: reading this
http://www.wireshark.org/docs/wsug_html_chunked/ChBuildInstallBeforeBuild.html
it says GTK and libpcap are required for the build. But running &#34;apt-rdepends wireshark&#34; gives me a massive dep-tree. What does this mean?
core dependencies requirements minimalasked 14 Mar &#39;11, 09:50</description>
    </item>
    
    <item>
      <title>analyze traffic to a specific website</title>
      <link>/questions/2805/analyze-traffic-to-a-specific-website/</link>
      <pubDate>Mon, 14 Mar 2011 10:33:00 +0000</pubDate>
      
      <guid>/questions/2805/analyze-traffic-to-a-specific-website/</guid>
      <description>analyze traffic to a specific website  0 One of our servers is sending out a bunch of calls to a specific ip address. I know it is via https and I know the call is getUserAccount. I have captured packets via wireshark on all of the suspected servers but my question is:
How do I / What is the most efficient way to find the specific info my server is sending to this particular IP?</description>
    </item>
    
    <item>
      <title>Protocol Conflicts</title>
      <link>/questions/2808/protocol-conflicts/</link>
      <pubDate>Mon, 14 Mar 2011 13:44:00 +0000</pubDate>
      
      <guid>/questions/2808/protocol-conflicts/</guid>
      <description>Protocol Conflicts  0 Hi,
I am a rookie when it comes to building a dissector . However I was able to build a dissector over TCP. I use port 80 to identify the packet. The packet which is not under my protocol comes under TCP but not HTTP. How did I rectify this problem. I would also like to &#39;point&#39; it to any other protocol I desire. Is this possible?</description>
    </item>
    
    <item>
      <title>Is Posible to make a Correlation of Call in Cellular Network???</title>
      <link>/questions/2809/is-posible-to-make-a-correlation-of-call-in-cellular-network/</link>
      <pubDate>Mon, 14 Mar 2011 14:28:00 +0000</pubDate>
      
      <guid>/questions/2809/is-posible-to-make-a-correlation-of-call-in-cellular-network/</guid>
      <description>Is Posible to make a Correlation of Call in Cellular Network???  0 Hi Gurus of wireshark, I have a quetion (doubt). I need to know if is possible to make a correlation Call in a Cellular Network. For example I capture the Call in one point (For example between the BSC and BTS), The other Point could be between BSC and MSC and finally the last point is between the MSC and the Gateway of PSTN.</description>
    </item>
    
    <item>
      <title>Using/Modifying WireShark to log http traffic</title>
      <link>/questions/2814/usingmodifying-wireshark-to-log-http-traffic/</link>
      <pubDate>Mon, 14 Mar 2011 20:42:00 +0000</pubDate>
      
      <guid>/questions/2814/usingmodifying-wireshark-to-log-http-traffic/</guid>
      <description>Using/Modifying WireShark to log http traffic  0 I am new to wireshark - please can you let me know if it is possible to use or modify wireshark to run on a system and log all outgoing http traffic. Does this feature already exist or would Wireshark need to be modified to make this happen. Please advise. Thanks MG
sniffer http logasked 14 Mar &#39;11, 20:42
gotters
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>PSH packet Length 2920 eventhough MSS negotiated in 1460</title>
      <link>/questions/2815/psh-packet-length-2920-eventhough-mss-negotiated-in-1460/</link>
      <pubDate>Mon, 14 Mar 2011 21:43:00 +0000</pubDate>
      
      <guid>/questions/2815/psh-packet-length-2920-eventhough-mss-negotiated-in-1460/</guid>
      <description>PSH packet Length 2920 eventhough MSS negotiated in 1460  0 Hi Team,
I am seeing a TCP connection where the the MSS is negotiated as 1460 but there are few PSH packets which have the length 2920. I have also confirmed that the MTU of the windows box which is sending the data is 1500. So there is no way that the windows box can send a packet of such length.</description>
    </item>
    
    <item>
      <title>how to get cwnd in Wireshark?</title>
      <link>/questions/2820/how-to-get-cwnd-in-wireshark/</link>
      <pubDate>Tue, 15 Mar 2011 02:07:00 +0000</pubDate>
      
      <guid>/questions/2820/how-to-get-cwnd-in-wireshark/</guid>
      <description>how to get cwnd in Wireshark?  0 how to get cwnd in Wireshark?
cwndasked 15 Mar &#39;11, 02:07
tcper
1●1●1●1
accept rate: 0%
  
One Answer:
  
3If you mean the congestion window, then, to quote RFC 2581, &#34;The congestion window (cwnd) is a sender-side limit on the amount of data the sender can transmit into the network before receiving an acknowledgment (ACK)&#34;; it&#39;s a parameter inside the TCP network stack - its value is not transmitted in network packets, so you won&#39;t see it as a field in the dissection of a TCP packet.</description>
    </item>
    
    <item>
      <title>Does Wireshark work on Windows 7 home edition?</title>
      <link>/questions/2822/does-wireshark-work-on-windows-7-home-edition/</link>
      <pubDate>Tue, 15 Mar 2011 05:25:00 +0000</pubDate>
      
      <guid>/questions/2822/does-wireshark-work-on-windows-7-home-edition/</guid>
      <description>Does Wireshark work on Windows 7 home edition?  0 Does Wireshark work on Windows 7 home edition? I am not seeing any interfaces showing up.
interfacesasked 15 Mar &#39;11, 05:25
jagsfan
1●1●1●1
accept rate: 0%
 edited 15 Mar &#39;11, 10:10 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
1Yes it does, but you need to have administrative rights to be able to capture (and also to list interfaces by current design).</description>
    </item>
    
    <item>
      <title>Unexplained NETBIOS traffic</title>
      <link>/questions/2824/unexplained-netbios-traffic/</link>
      <pubDate>Tue, 15 Mar 2011 06:11:00 +0000</pubDate>
      
      <guid>/questions/2824/unexplained-netbios-traffic/</guid>
      <description>Unexplained NETBIOS traffic  0 I&#39;m currently seeing a lot of traffic coming from two of my machines at the office to various IP addresses in the European block, I&#39;m from Canada so this is unusual. The info in Wireshark reports: &#34;Name query NBSTAT *&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&amp;lt;00&amp;gt;&#34;. Now normally I wouldn&#39;t panic about this however there is also a second relation to this that is the worrying part.
In the Windows 7 Resource Monitor these requests are coming from any users spawned process, firefox and process explorer are two common ones, plus the System Process, PID 4.</description>
    </item>
    
    <item>
      <title>Extra fields displayed in ICMP capture</title>
      <link>/questions/2827/extra-fields-displayed-in-icmp-capture/</link>
      <pubDate>Tue, 15 Mar 2011 07:12:00 +0000</pubDate>
      
      <guid>/questions/2827/extra-fields-displayed-in-icmp-capture/</guid>
      <description>Extra fields displayed in ICMP capture  0 In trying to manually determine the maximum transmission unit (MTU) of a triple IPsec encrypted link, I am using ICMP to form the basis. The MTU is not adding up correctly based on Wireshark output. The number of bytes adds up correctly but the displayed ICMP fields seem to be incorrect. And Wireshark includes two sequence number fields in the ICMP request and ICMP reply which does not folow the documented ICMP packet structure - OR did things change again and I&#39;m still asleep :) ?</description>
    </item>
    
    <item>
      <title>Capturing with Wireshark on mac os 10.6.6?</title>
      <link>/questions/2829/capturing-with-wireshark-on-mac-os-1066/</link>
      <pubDate>Tue, 15 Mar 2011 08:21:00 +0000</pubDate>
      
      <guid>/questions/2829/capturing-with-wireshark-on-mac-os-1066/</guid>
      <description>Capturing with Wireshark on mac os 10.6.6?  0 hi
I would like to capture the communication between my browser and a server with Wireshark on mac os 10.6.6 but i can&#39;t get any interface..
So I went &#34;in read me 1st&#34; then through forums and i understood that I must put the ChmodBPF folder (provided with the soft) in the /Library/StartupItems directory in order to give to Wireshark access to the BPF device.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t see WPA2 traffic on my home network</title>
      <link>/questions/2845/cant-see-wpa2-traffic-on-my-home-network/</link>
      <pubDate>Tue, 15 Mar 2011 15:38:00 +0000</pubDate>
      
      <guid>/questions/2845/cant-see-wpa2-traffic-on-my-home-network/</guid>
      <description>Can&amp;rsquo;t see WPA2 traffic on my home network  0 Hi, I&#39;m attempting to sniff traffic on my home network for which I know the SSID and WPA2 (Personal) key. I&#39;m running 64bit Wireshark under Windows 7, and my wireless card is an Atheros AR9285. From reading other forums, I&#39;ve seen other people having at least some success with this card.
I have followed the instructions here: http://wiki.wireshark.org/HowToDecrypt802.11
In doing so, I&#39;ve supplied Wireshark my wpa-pwd as shown.</description>
    </item>
    
    <item>
      <title>How to capture real time Network traffic? Also, what are the various network parameters which can be used to perform anomaly analysis?</title>
      <link>/questions/2847/how-to-capture-real-time-network-traffic-also-what-are-the-various-network-parameters-which-can-be-used-to-perform-anomaly-analysis/</link>
      <pubDate>Tue, 15 Mar 2011 16:37:00 +0000</pubDate>
      
      <guid>/questions/2847/how-to-capture-real-time-network-traffic-also-what-are-the-various-network-parameters-which-can-be-used-to-perform-anomaly-analysis/</guid>
      <description>How to capture real time Network traffic? Also, what are the various network parameters which can be used to perform anomaly analysis?  1 I am new to networking. I would like to capture real time network traffic with which i can determine a normal network behavior. I would like to make an Anomaly based Intrusion detection system. I would like to know how to implement this. I would like to know the following</description>
    </item>
    
    <item>
      <title>Display filter for nbns query type</title>
      <link>/questions/2856/display-filter-for-nbns-query-type/</link>
      <pubDate>Tue, 15 Mar 2011 17:43:00 +0000</pubDate>
      
      <guid>/questions/2856/display-filter-for-nbns-query-type/</guid>
      <description>Display filter for nbns query type  0 How can I filter NetBIOS frames on hostnames or query types or names?
I am looking for something elegant like dns.qry.name.
Right now I using a cludge like &#34;udp.port == 137 and frame[88:2] == 00:20&#34; which is not nice when working with VLANs.
Any hint is appreciated.
nbns display-filterasked 15 Mar &#39;11, 17:43
packethunter
2.1k●7●15●48
accept rate: 8%
 edited 15 Mar &#39;11, 17:46</description>
    </item>
    
    <item>
      <title>TCP Flag reset on wirless connection not wired when telnet to port 4211 on PC</title>
      <link>/questions/2858/tcp-flag-reset-on-wirless-connection-not-wired-when-telnet-to-port-4211-on-pc/</link>
      <pubDate>Tue, 15 Mar 2011 19:17:00 +0000</pubDate>
      
      <guid>/questions/2858/tcp-flag-reset-on-wirless-connection-not-wired-when-telnet-to-port-4211-on-pc/</guid>
      <description>TCP Flag reset on wirless connection not wired when telnet to port 4211 on PC  0 When telneting from a server to a client that is connected via wireless the connection is refused whereas on the same pc when connected via CAT 5 the connection it is accepted. The packet decode shows that TCP flag is getting reset on the wireless connection but the client send a SYN packet on when the PC is wired.</description>
    </item>
    
    <item>
      <title>port mirroring with wireshark</title>
      <link>/questions/2859/port-mirroring-with-wireshark/</link>
      <pubDate>Tue, 15 Mar 2011 19:36:00 +0000</pubDate>
      
      <guid>/questions/2859/port-mirroring-with-wireshark/</guid>
      <description>port mirroring with wireshark  0 Hello, I have a school project to do and the instructor recommended as one of the topics &#34;port mirroring with wireshark&#34;. Can somebody please explain me how i will go about doing this so that i can decide whether i want to do this topic or not. Thanks a lot.
port mirroring wiresharkasked 15 Mar &#39;11, 19:36
mtomey
1●1●1●1
accept rate: 0%
1If your instructor really said &#34;</description>
    </item>
    
    <item>
      <title>Network analize</title>
      <link>/questions/2867/network-analize/</link>
      <pubDate>Wed, 16 Mar 2011 02:07:00 +0000</pubDate>
      
      <guid>/questions/2867/network-analize/</guid>
      <description>Network analize  0 When i&#39;m connect to a network only packages that i can see are from my pc,what i&#39;m doing wrong?
packages networkasked 16 Mar &#39;11, 02:07
GYBE
1●1●1●2
accept rate: 0%
  
One Answer:
  
1In today&#39;s switched networks you&#39;ll only receive packets for your network card plus broadcast/multicast packets. If you want to see more than that you&#39;ll have to use techniques to get access to packets sent by others, like those at http://wiki.</description>
    </item>
    
    <item>
      <title>how do i sniff packet from other pc on same network over wireless connection</title>
      <link>/questions/2868/how-do-i-sniff-packet-from-other-pc-on-same-network-over-wireless-connection/</link>
      <pubDate>Wed, 16 Mar 2011 03:52:00 +0000</pubDate>
      
      <guid>/questions/2868/how-do-i-sniff-packet-from-other-pc-on-same-network-over-wireless-connection/</guid>
      <description>how do i sniff packet from other pc on same network over wireless connection  0 hi, im a newbie to this program and currently doing project on packets and security. could someone help me how to set up to sniff packet sent and received from other pc that are connected in the same network that im in.. yeah, via a wireless network... =)
capture setupasked 16 Mar &#39;11, 03:52</description>
    </item>
    
    <item>
      <title>Received Address Errors on server</title>
      <link>/questions/2872/received-address-errors-on-server/</link>
      <pubDate>Wed, 16 Mar 2011 10:54:00 +0000</pubDate>
      
      <guid>/questions/2872/received-address-errors-on-server/</guid>
      <description>Received Address Errors on server  1 I have a server that is continually incrementing Received Address Errors. This is seen when using netstat -s. I have captures of the traffic but I am not sure how to go about displaying these errors in Wireshark or if that is possible. I tried using the following filter with no success:
ipmi.tr04.rx_ipaddr_err
Anyone got any ideas?
received errors addressasked 16 Mar &#39;11, 10:54</description>
    </item>
    
    <item>
      <title>Does anyone know what repository to add to smart for wireshark?</title>
      <link>/questions/2876/does-anyone-know-what-repository-to-add-to-smart-for-wireshark/</link>
      <pubDate>Wed, 16 Mar 2011 12:03:00 +0000</pubDate>
      
      <guid>/questions/2876/does-anyone-know-what-repository-to-add-to-smart-for-wireshark/</guid>
      <description>Does anyone know what repository to add to smart for wireshark?  0 I&#39;m in a situation where I can only use smart to install packages. I&#39;m trying to add one of the repositories that apt uses to install wireshark which is:
http://us.archive.ubuntu.com/ubuntu/So I used this command:
smart channel --add Ubuntu-Universe type=apt-deb name=&amp;quot;Universe&amp;quot; baseurl=http:// us.archive.ubuntu.com/ubuntu/ distribution=maverickBut unfortunately that doesn&#39;t work. Does anyone know how to do this?
install smart wiresharkasked 16 Mar &#39;11, 12:03</description>
    </item>
    
    <item>
      <title>report on number of sockets established</title>
      <link>/questions/2877/report-on-number-of-sockets-established/</link>
      <pubDate>Wed, 16 Mar 2011 12:10:00 +0000</pubDate>
      
      <guid>/questions/2877/report-on-number-of-sockets-established/</guid>
      <description>report on number of sockets established  0 Hello:
We have a capture we are using to troubleshoot an application issue. our application establishes TCP sockets between medical devices and a custom gateway applicaiton on a specific server-side TCP port and IP address.
What i&#39;m looking for help on is this:
How can I use wireshark or additional tool to build a query for the number of established socketed connections contained in the capture?</description>
    </item>
    
    <item>
      <title>source code for linux</title>
      <link>/questions/2879/source-code-for-linux/</link>
      <pubDate>Wed, 16 Mar 2011 14:50:00 +0000</pubDate>
      
      <guid>/questions/2879/source-code-for-linux/</guid>
      <description>source code for linux  0 Is there any specific source code to build wireshark under Linux ubuntu? I just downloaded wireshard-1.4.4. would that build with Linux ubuntu?
sourceasked 16 Mar &#39;11, 14:50
batlasi
1●1●1●1
accept rate: 0%
  
One Answer:
  
0When you install the wireshark-dev package you pull in the required development packages of the libraries you use, as well as the required tools.</description>
    </item>
    
    <item>
      <title>Filter expression</title>
      <link>/questions/2882/filter-expression/</link>
      <pubDate>Wed, 16 Mar 2011 20:45:00 +0000</pubDate>
      
      <guid>/questions/2882/filter-expression/</guid>
      <description>Filter expression  0 I am studying the frame timing for a real time control system. For example, frames should go out every 1msec. I could filter the frames that are off-sync by 100usec early to 100usec late using this type expression: ((frame.time + 0.0001) MOD 0.001) &amp;lt; 0.0002 Or with integer math (((frame.time * 1000000) + 100) MOD 1000) &amp;lt; 200 Is there a way to enter this type math expression in the filter editors?</description>
    </item>
    
    <item>
      <title>capture packet in wireless</title>
      <link>/questions/2883/capture-packet-in-wireless/</link>
      <pubDate>Wed, 16 Mar 2011 20:47:00 +0000</pubDate>
      
      <guid>/questions/2883/capture-packet-in-wireless/</guid>
      <description>capture packet in wireless  0 Is there any difference between capturing packets when we are using LAN and when we are using Wireless? Actually when I use wireless wireshark says &#34;no packet!&#34;. I want to see if there is any difference?Can you help me with it?
wirelessasked 16 Mar &#39;11, 20:47
A B
1●10●10●12
accept rate: 0%
  
One Answer:
  
0Yes there is, see here and here.</description>
    </item>
    
    <item>
      <title>How do I direct the packets to http?</title>
      <link>/questions/2885/how-do-i-direct-the-packets-to-http/</link>
      <pubDate>Wed, 16 Mar 2011 23:36:00 +0000</pubDate>
      
      <guid>/questions/2885/how-do-i-direct-the-packets-to-http/</guid>
      <description>How do I direct the packets to http?  0 Hi, I have dissector which dissects the packet at port 80 but If its not my packet its not going to http dissector what should i do? please help. when do I use dissector_delete?
dissector_delete http portasked 16 Mar &#39;11, 23:36
niks3089
21●15●15●18
accept rate: 0%
  
One Answer:
  
1dissector_delete() is used only for the static dissector configuration, that is the per dissection session.</description>
    </item>
    
    <item>
      <title>Returning back to the dissector</title>
      <link>/questions/2891/returning-back-to-the-dissector/</link>
      <pubDate>Thu, 17 Mar 2011 02:05:00 +0000</pubDate>
      
      <guid>/questions/2891/returning-back-to-the-dissector/</guid>
      <description>Returning back to the dissector  0 I have my own dissector above tcp. I have a signature to detect my packet. If it is not present it should return back to the wireshark where it will decide which port it should go to. How can I do this? Thanks in advance
return port tcpasked 17 Mar &#39;11, 02:05
niks3089
21●15●15●18
accept rate: 0%
currently the port number is 80</description>
    </item>
    
    <item>
      <title>Readme.heuristics is not present in wireshark 1.4.3. Where do I get the file?</title>
      <link>/questions/2893/readmeheuristics-is-not-present-in-wireshark-143-where-do-i-get-the-file/</link>
      <pubDate>Thu, 17 Mar 2011 03:02:00 +0000</pubDate>
      
      <guid>/questions/2893/readmeheuristics-is-not-present-in-wireshark-143-where-do-i-get-the-file/</guid>
      <description>Readme.heuristics is not present in wireshark 1.4.3. Where do I get the file?  0 Readme.heuristics is not present in wireshark 1.4.3. Where do I get this file? Any other link where i can learn about heuristic dissector?
heuristicsasked 17 Mar &#39;11, 03:02
niks3089
21●15●15●18
accept rate: 0%
  
2 Answers:
  
2 You can find it here:
http://anonsvn.wireshark.org/viewvc/trunk/doc/
http://anonsvn.wireshark.org/viewvc/trunk/doc/README.heuristic?revision=35224&amp;amp;view=markup
answered 17 Mar &#39;11, 03:22
joke</description>
    </item>
    
    <item>
      <title>error in heuristic dissector</title>
      <link>/questions/2896/error-in-heuristic-dissector/</link>
      <pubDate>Thu, 17 Mar 2011 05:01:00 +0000</pubDate>
      
      <guid>/questions/2896/error-in-heuristic-dissector/</guid>
      <description>error in heuristic dissector  0 I get this error when i run wireshark.I have built a heuristic dissector 17:29:46 Err file packet.c: line 1542 (heur_dissector_add): assertion failed: (sub_dissectors != NULL) Aborted
heuristicsasked 17 Mar &#39;11, 05:01
niks3089
21●15●15●18
accept rate: 0%
  
One Answer:
  
0The &#34;name&#34; field (the 1st parameter) in your heur_dissector_add() call is not valid. Or I suppose it may be valid but you&#39;re calling heur_dissector_add() before the other protocol has been registered (are you calling heur_dissector_add() in your reg_handoff routine?</description>
    </item>
    
    <item>
      <title>Wireless Phones? Android devices, iPhones can wireshark help?</title>
      <link>/questions/2904/wireless-phones-android-devices-iphones-can-wireshark-help/</link>
      <pubDate>Thu, 17 Mar 2011 08:59:00 +0000</pubDate>
      
      <guid>/questions/2904/wireless-phones-android-devices-iphones-can-wireshark-help/</guid>
      <description>Wireless Phones? Android devices, iPhones can wireshark help?  0 Hello,
I am looking for a software that I can install on my PC, connect an Android device or iPhone to the PC, and the software will tell me what data is being transfered between the wireless device and the wireless carrier.
For instance an iPhone is connected and it will show the applications and packet trasfers between AT&amp;amp;T network and the device.</description>
    </item>
    
    <item>
      <title>&amp;quot;Try heuristic sub-dissectors first&amp;quot;</title>
      <link>/questions/2908/try-heuristic-sub-dissectors-first/</link>
      <pubDate>Thu, 17 Mar 2011 11:44:00 +0000</pubDate>
      
      <guid>/questions/2908/try-heuristic-sub-dissectors-first/</guid>
      <description>&amp;ldquo;Try heuristic sub-dissectors first&amp;rdquo;  1 Where should i make &#34;Try heuristic sub-dissectors first&#34; change? I have currently built a heuristic dissector over tcp. thanks in advance
heuristics dissectorasked 17 Mar &#39;11, 11:44
niks3089
21●15●15●18
accept rate: 0%
  
One Answer:
  
3It&#39;s a preference on (among others) the TCP dissector. Edit-&amp;gt;Preferences-&amp;gt;Protocols-&amp;gt;TCP and check or uncheck the appropriate box.
Some other protocols (UDP, SCTP, etc.) have similar preferences.</description>
    </item>
    
    <item>
      <title>Windows Vista : There are no interfaces on which a capture can be done</title>
      <link>/questions/2911/windows-vista-there-are-no-interfaces-on-which-a-capture-can-be-done/</link>
      <pubDate>Thu, 17 Mar 2011 15:05:00 +0000</pubDate>
      
      <guid>/questions/2911/windows-vista-there-are-no-interfaces-on-which-a-capture-can-be-done/</guid>
      <description>Windows Vista : There are no interfaces on which a capture can be done  0 I got the follovwing matter under windows Vista with Wireshark 1.4.4 : &#34;There are no interfaces on which a capture can be done&#34;
The computer has WinPcap 4.1.2 installed and i have admin rights and i have an ethernet device (i&#39;m currently using it to post this message !)
capture interfaces no wireshark errorasked 17 Mar &#39;11, 15:05</description>
    </item>
    
    <item>
      <title>Mac OSX Install Problems</title>
      <link>/questions/2912/mac-osx-install-problems/</link>
      <pubDate>Thu, 17 Mar 2011 17:28:00 +0000</pubDate>
      
      <guid>/questions/2912/mac-osx-install-problems/</guid>
      <description>Mac OSX Install Problems  0 I&#39;m getting an error message when I reboot after having installed wireshark on my snow leopard system and followed all the installation directions including the sudo commands listed in previous question - http://ask.wireshark.org/questions/2405/mac-osx-installation. I&#39;m also not seeing any available capture interfaces when I start wireshark.
The error message is Insecure Startup Item Disabled &#34;/Library/StartupItems/ChmodBPF&#34; has not been started because it does not have the proper security settings.</description>
    </item>
    
    <item>
      <title>IGMP in wirshark</title>
      <link>/questions/2916/igmp-in-wirshark/</link>
      <pubDate>Thu, 17 Mar 2011 18:12:00 +0000</pubDate>
      
      <guid>/questions/2916/igmp-in-wirshark/</guid>
      <description>IGMP in wirshark  0 have two devices that communicate over Ethernet/IP - cannot get them conncted so found a Hub and connected them and my PC running Wireshark - what I see is the Client (192.168.144.11) device making a connection to the Server device (192.168.144.130) but then the Client goes to following:
239.192.17.32 IGMP V2 Membership Report Join group 239.192.17.32
when it should simply continue talking to the Server device - consequently the connection between my devices&#39; fails</description>
    </item>
    
    <item>
      <title>LDAP SSLv3 malformed packet</title>
      <link>/questions/2920/ldap-sslv3-malformed-packet/</link>
      <pubDate>Fri, 18 Mar 2011 07:26:00 +0000</pubDate>
      
      <guid>/questions/2920/ldap-sslv3-malformed-packet/</guid>
      <description>LDAP SSLv3 malformed packet  0 Hi, I am doing a LDAP SSL v3 bind and wireshark tells me the server hello packet is malformed. However, everything works fine. What could be the reason for that? (I use the dev. version 1.5, but also older versions show this message). thanks for help. JAB
ssl server hello malformed ldapasked 18 Mar &#39;11, 07:26
JAB
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>SCTP DATA is not getting decoded correctly and is showing Malformed Packet</title>
      <link>/questions/2922/sctp-data-is-not-getting-decoded-correctly-and-is-showing-malformed-packet/</link>
      <pubDate>Fri, 18 Mar 2011 09:21:00 +0000</pubDate>
      
      <guid>/questions/2922/sctp-data-is-not-getting-decoded-correctly-and-is-showing-malformed-packet/</guid>
      <description>SCTP DATA is not getting decoded correctly and is showing Malformed Packet  0 SCTP Association is correctly setup between two linux machines. When I send Data from Machine 1 --&amp;gt; Machine 2 using SCTP ---&amp;gt; I see the following in Wireshark Protocol Type = S1AP Msg (Info) = id-HandoverNotification [Malformed Packet] This is followed by a SACK from second Linux machine
I also verified in the command prompt of the second Linux Machine that it did receive the data correctly and therefore sent the SACK back to the first Linux Machine.</description>
    </item>
    
    <item>
      <title>No data received</title>
      <link>/questions/2923/no-data-received/</link>
      <pubDate>Fri, 18 Mar 2011 09:45:00 +0000</pubDate>
      
      <guid>/questions/2923/no-data-received/</guid>
      <description>No data received  0 Hello, I&#39;ve juste installed wireshark on my laptop. I can receive packets when I capture on &#34;microsoft&#34; interface, but I just see informations my own laptop has, and none of others (I can see GETS from my browser, but not from any other on the network !) When I choose what&#39;s supposed to be my network receptor called &#34;Broadcom Netlink (TM) Gigabit Ethernet Driver&#34; I don&#39;t have anything, not even a little packet.</description>
    </item>
    
    <item>
      <title>Trouble Pingin</title>
      <link>/questions/2926/trouble-pingin/</link>
      <pubDate>Fri, 18 Mar 2011 11:55:00 +0000</pubDate>
      
      <guid>/questions/2926/trouble-pingin/</guid>
      <description>Trouble Pingin  0 Why might a properly functioning site refuse to respond to a ping request?
wiresharkasked 18 Mar &#39;11, 11:55
Pinging0874
1●1●1●2
accept rate: 0%
 edited 18 Mar &#39;11, 12:33 
  
One Answer:
  
1Some firewalls (or their administrators) block ping. It&#39;s probably just paranoia on behalf of someone.
answered 18 Mar &#39;11, 12:46
JeffMorriss ♦
6.2k●5●72
accept rate: 27%
I block ping on all of my public IPs.</description>
    </item>
    
    <item>
      <title>Newbie Needs Help Diagnosing Problem</title>
      <link>/questions/2930/newbie-needs-help-diagnosing-problem/</link>
      <pubDate>Sat, 19 Mar 2011 06:14:00 +0000</pubDate>
      
      <guid>/questions/2930/newbie-needs-help-diagnosing-problem/</guid>
      <description>Newbie Needs Help Diagnosing Problem  0 I&#39;m new to Wireshark and am certainly no network expert. Ran Wireshark to determine cause for delay in opening files across network and see some suspicious time lapses.
I would like to submit my log.pcap file for someone to review and help me to understand whats happening.
Please let me know how to proceed.
Thanks,
Lee
newbieasked 19 Mar &#39;11, 06:14
trims30
1●1●1●1</description>
    </item>
    
    <item>
      <title>tshark doesn&amp;#x27;t has -z scsi,srt command argument</title>
      <link>/questions/2931/tshark-doesnt-has-z-scsisrt-command-argument/</link>
      <pubDate>Sat, 19 Mar 2011 12:27:00 +0000</pubDate>
      
      <guid>/questions/2931/tshark-doesnt-has-z-scsisrt-command-argument/</guid>
      <description>tshark doesn&amp;rsquo;t has -z scsi,srt command argument  0 Wireshark has this option to filter the scsi response time where as tshark doesn&#39;t has this commandline argument option at all. Is there anything I&#39;m missing
-z scsi,srt,cmdset[,&amp;lt;filter&amp;gt;]
Wireshark has this feature where as tshark doesn&#39;t has this commandline option at all.
scsi tshark srtasked 19 Mar &#39;11, 12:27
asif
1●5●5●6
accept rate: 0%
 edited 19 Mar &#39;11, 15:20</description>
    </item>
    
    <item>
      <title>Creating a csv file with tshark</title>
      <link>/questions/2935/creating-a-csv-file-with-tshark/</link>
      <pubDate>Sat, 19 Mar 2011 18:15:00 +0000</pubDate>
      
      <guid>/questions/2935/creating-a-csv-file-with-tshark/</guid>
      <description>Creating a csv file with tshark  0 So here&#39;s the deal. My goal is to take a capture from TCPDUMP and import it into a MySQL database.
I want to use wireshark to create a csv file using the &#34;tshark -r Myfile -t fields&#34; command. Once I have the csv file, i can use mysql to import the data into the database table.
I would like this csv file to look exactly like the csv file created by using the export feature in the wireshark gui.</description>
    </item>
    
    <item>
      <title>internet turns off and on every so often</title>
      <link>/questions/2936/internet-turns-off-and-on-every-so-often/</link>
      <pubDate>Sat, 19 Mar 2011 22:25:00 +0000</pubDate>
      
      <guid>/questions/2936/internet-turns-off-and-on-every-so-often/</guid>
      <description>internet turns off and on every so often  0 i run windows 7, every once in a while, my internet connection would &#34;blink&#34; all internet would stop for maybe under 5 seconds, and come right back on, no reason that i can find for this, its not a hardware problem, it happens on both wired and wireless, on the icon in the corner does not change to say anything is wrong, the net just turns off for a moment then comes back, i want to find a software that will tell me where the problem is, what is running that is causing the problem</description>
    </item>
    
    <item>
      <title>How to debug a wireshark dissector ?</title>
      <link>/questions/2937/how-to-debug-a-wireshark-dissector/</link>
      <pubDate>Sun, 20 Mar 2011 08:20:00 +0000</pubDate>
      
      <guid>/questions/2937/how-to-debug-a-wireshark-dissector/</guid>
      <description>How to debug a wireshark dissector ?  0 I just want to debug some part of my custom dissector with printf. But I don&#39;t know where the stdout is redirect, and the only answer that I found is to open a &#34;debug console window&#34;, but I don&#39;t have this option in my wireshark.
I need help.
development debug dissectorasked 20 Mar &#39;11, 08:20
chronidev
11●5●5●7
accept rate: 0%
 edited 20 Mar &#39;11, 08:20</description>
    </item>
    
    <item>
      <title>Dump very large stream capture to raw file (Wireshark crashes)</title>
      <link>/questions/2947/dump-very-large-stream-capture-to-raw-file-wireshark-crashes/</link>
      <pubDate>Sun, 20 Mar 2011 10:01:00 +0000</pubDate>
      
      <guid>/questions/2947/dump-very-large-stream-capture-to-raw-file-wireshark-crashes/</guid>
      <description>Dump very large stream capture to raw file (Wireshark crashes)  1 Hello,
I&#39;m trying to dump a very large tcp stream (600 MB) in raw format. I captured the stream and saved it to disk. Then I open it again and I want to open the &#34;Follow TCP Stream&#34; window to be able to save the stream (only the downwards direction) in raw format to my disk. So I click on &#34;</description>
    </item>
    
    <item>
      <title>How to obtain informations from a dissector inside a sub-dissector ?</title>
      <link>/questions/2953/how-to-obtain-informations-from-a-dissector-inside-a-sub-dissector/</link>
      <pubDate>Sun, 20 Mar 2011 14:15:00 +0000</pubDate>
      
      <guid>/questions/2953/how-to-obtain-informations-from-a-dissector-inside-a-sub-dissector/</guid>
      <description>How to obtain informations from a dissector inside a sub-dissector ?  0 I&#39;m writting a dissector for the modludp64 protocol. It&#39;s work, this is cool and I release it in few days. But before I want to add some features. To distinguish messages, I need to know if the destination ip address is unicast or multicast, but I don&#39;t know how to retreive this informations.
Someone can help me.</description>
    </item>
    
    <item>
      <title>wireless problem</title>
      <link>/questions/2959/wireless-problem/</link>
      <pubDate>Sun, 20 Mar 2011 16:53:00 +0000</pubDate>
      
      <guid>/questions/2959/wireless-problem/</guid>
      <description>wireless problem  0 In wireless mode I can not get packages from other computers on the network pick up only my. Other only appears nothing more ssdp protocol. Im using ubuntu 10.10
wirelessasked 20 Mar &#39;11, 16:53
Wakefield
1●1●1●3
accept rate: 0%
 edited 20 Mar &#39;11, 16:54 
  
2 Answers:
  
1You can try putting the wireless NIC into promiscuous mode under Capture Options.</description>
    </item>
    
    <item>
      <title>Drop packets</title>
      <link>/questions/2960/drop-packets/</link>
      <pubDate>Sun, 20 Mar 2011 17:57:00 +0000</pubDate>
      
      <guid>/questions/2960/drop-packets/</guid>
      <description>Drop packets  0 Hello, I trying to figure out how to do this.
If you look here in the FAQ at question 12 it talks about filtering traffic. Does filtering means the packet will get dropped if it meets the filter criteria?
Basically what I need is a way to drop packets containing a certain string. Somebody is sending a specific packet that crashes my server.
On Linux, you can use iptables to inspect the packets and block this attack easily, but currently I&#39;m using Windows.</description>
    </item>
    
    <item>
      <title>difference in the output: tshark Vs Wireshark results</title>
      <link>/questions/2961/difference-in-the-output-tshark-vs-wireshark-results/</link>
      <pubDate>Sun, 20 Mar 2011 18:07:00 +0000</pubDate>
      
      <guid>/questions/2961/difference-in-the-output-tshark-vs-wireshark-results/</guid>
      <description>difference in the output: tshark Vs Wireshark results  0 Installed the 1.5.0 build and I see scsi,rtt commandline arguments. There is a difference in the output compared to UI. Is this a known issue?
Via CLI started the capture interface: - tshark -S -i 2 -w capture_out.pcap - tshark -r capture_out.pcap -q -z scsi,rtt,0
returns avg SRT value: 0.021678.
Via UI capture,
Started the capture interface via UIsend some trafficeView the statistics: Statistics-&amp;gt;Service Response Time-&amp;gt;SCSI-&amp;gt;Filter&amp;lt;iscsi.</description>
    </item>
    
    <item>
      <title>Wireshark nc10</title>
      <link>/questions/2964/wireshark-nc10/</link>
      <pubDate>Mon, 21 Mar 2011 05:23:00 +0000</pubDate>
      
      <guid>/questions/2964/wireshark-nc10/</guid>
      <description>Wireshark nc10  0 Hi, I&#39;ve read that you&#39;re able to run wireshark on your Samsung nc10. I&#39;ve read in other forums that wifi card can&#39;t sniffs packets in &#34;promiscous mode&#34;. In fact, when I&#39;ve tried for, I&#39;ve the same result of all other users. I use win xp sp3.
nc10 wireshark promiscuous samsungasked 21 Mar &#39;11, 05:23
maidirepelle
1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Using Multiple IP ranges in one capture</title>
      <link>/questions/2968/using-multiple-ip-ranges-in-one-capture/</link>
      <pubDate>Mon, 21 Mar 2011 08:12:00 +0000</pubDate>
      
      <guid>/questions/2968/using-multiple-ip-ranges-in-one-capture/</guid>
      <description>Using Multiple IP ranges in one capture  0 Hey,
I haven&#39;t been able to get this filter to work. Im trying to use multiple IP ranges. 4 of them.
I have been trying to use net
Ex. net 192.168.0.0/88
but I want to use multiple at one time
(net 192.168.0.0/88 and net 192.168.1.0/99 and net 192.168.2.0/77 and net 192.168.3.066)
I have tried (net 192.168.0.0/88) and (net 192.168.1.0/99) and (net 192.</description>
    </item>
    
    <item>
      <title>Problem decrypting ssl packets</title>
      <link>/questions/2969/problem-decrypting-ssl-packets/</link>
      <pubDate>Mon, 21 Mar 2011 08:33:00 +0000</pubDate>
      
      <guid>/questions/2969/problem-decrypting-ssl-packets/</guid>
      <description>Problem decrypting ssl packets  0 Installed wireshark 1.4.4 from Sunfreeware on Solaris 10 update 9 sparc platform. I have enabled ssl decoding by setting in the preferences file the correct key files that I would need to decrypt the packets with using the ssl.key_list parameter.
Wireshark starts up fine but when I open my saved file I get the following error reported and the application is killed:
ld.so.1: wireshark: fatal: relocation error: file /usr/local/lib/libwireshark.</description>
    </item>
    
    <item>
      <title>field from dissector not usable in lua scripts</title>
      <link>/questions/2971/field-from-dissector-not-usable-in-lua-scripts/</link>
      <pubDate>Mon, 21 Mar 2011 09:01:00 +0000</pubDate>
      
      <guid>/questions/2971/field-from-dissector-not-usable-in-lua-scripts/</guid>
      <description>field from dissector not usable in lua scripts  3 Here&#39;s my basic dissector
foo_proto = Proto(&amp;quot;foo&amp;quot;,&amp;quot;foo proto&amp;quot;) foo_proto.fields.bar = ProtoField.string(&amp;quot;foo.bar&amp;quot;,&amp;quot;bar field&amp;quot;) function foo_proto.dissector(buffer,pinfo,tree) local subtree = tree:add(foo_proto,&amp;quot;Foo Protocol Data&amp;quot;) subtree:add(foo_proto.fields.bar, pinfo.number) end
register_postdissector(foo_proto)I use wireshark 1.4.4, I start wireshark and load my dissector in the Lua &amp;ldquo;Evaluate&amp;rdquo; window, my packet got dissected correctly and I can see my bar field under the foo proto.
My problem is that I can&amp;rsquo;t use foo.</description>
    </item>
    
    <item>
      <title>Read SSH packets?</title>
      <link>/questions/2975/read-ssh-packets/</link>
      <pubDate>Mon, 21 Mar 2011 10:45:00 +0000</pubDate>
      
      <guid>/questions/2975/read-ssh-packets/</guid>
      <description>Read SSH packets?  0 Is there any way I can pass the SSH packets through Wireshark in such a way that it can read them? I can imagine using some sort of proxy, pipe or man-in-the-middle attack, but don&#39;t really know how to go about pulling it off, and google hasn&#39;t been terribly helpful on the matter. Could anyone offer an insight as to whether this is even possible, and if so, how to approach it?</description>
    </item>
    
    <item>
      <title>Wire shark Recording server</title>
      <link>/questions/2979/wire-shark-recording-server/</link>
      <pubDate>Mon, 21 Mar 2011 14:36:00 +0000</pubDate>
      
      <guid>/questions/2979/wire-shark-recording-server/</guid>
      <description>Wire shark Recording server  0 Hello All
Sorry this question has probably already been asked loads of times before! what is the best way to setup wire shark on a server that records all data all the time for problem analysis at a later date? is this actually possible? I would also like to only store a couple weeks worth of traffic!
currently when a issue is reported we start a capture and try to get the user to reproduce the issue.</description>
    </item>
    
    <item>
      <title>Screen dump of Jabbering card</title>
      <link>/questions/2980/screen-dump-of-jabbering-card/</link>
      <pubDate>Mon, 21 Mar 2011 14:48:00 +0000</pubDate>
      
      <guid>/questions/2980/screen-dump-of-jabbering-card/</guid>
      <description>Screen dump of Jabbering card  0 Hi all,
I&#39;m trying to find a screendump of a wiresharks output for a jabbering card. For a course I&#39;m writing, has anyone got one?
Any help would be much apprechiated
Thanks
Julian
jabberingasked 21 Mar &#39;11, 14:48
Julianh
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Is this kind of what you&#39;re looking for?
jabber.png
answered 21 Mar &#39;11, 16:30</description>
    </item>
    
    <item>
      <title>hey im a super super noob at wireshark</title>
      <link>/questions/3000/hey-im-a-super-super-noob-at-wireshark/</link>
      <pubDate>Mon, 21 Mar 2011 21:37:00 +0000</pubDate>
      
      <guid>/questions/3000/hey-im-a-super-super-noob-at-wireshark/</guid>
      <description>hey im a super super noob at wireshark  0 alright can someone give me a link or point me to the right direction for noobs using wireshark?
i sorta understand how to use it but i want to get the most i can out of this program
i have questions like * can i sniff gsm connections? * can i look at a open wifi and see others? * can i use this for work?</description>
    </item>
    
    <item>
      <title>wireshark filter</title>
      <link>/questions/3004/wireshark-filter/</link>
      <pubDate>Mon, 21 Mar 2011 22:21:00 +0000</pubDate>
      
      <guid>/questions/3004/wireshark-filter/</guid>
      <description>wireshark filter  0 I am decoding SS7 messages on wireshark. Is it possible to filter all messages in which particular number starts from &#34;0792xxxxxxx&#34; ? It should not gives you a result &#34;xxx0792xxx&#34;.
Some filter like beginswith or starts with needed.
ss7asked 21 Mar &#39;11, 22:21
parthe
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1You can use the &#34;matches&#34; operator. You will have to use something like:</description>
    </item>
    
    <item>
      <title>Runtime Error when save capture file before program quit without stopping capturing data from network card.</title>
      <link>/questions/3008/runtime-error-when-save-capture-file-before-program-quit-without-stopping-capturing-data-from-network-card/</link>
      <pubDate>Mon, 21 Mar 2011 23:19:00 +0000</pubDate>
      
      <guid>/questions/3008/runtime-error-when-save-capture-file-before-program-quit-without-stopping-capturing-data-from-network-card/</guid>
      <description>Runtime Error when save capture file before program quit without stopping capturing data from network card.  0 Runtime Error when save capture file before program quit without stopping capturing data from network card.
before quit save errorasked 21 Mar &#39;11, 23:19
brenthuang
1●4●4●4
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Wireshark consumes 100 percent CPU while feed H323 protocol data using pipe when Only single one CPU on client</title>
      <link>/questions/3013/wireshark-consumes-100-percent-cpu-while-feed-h323-protocol-data-using-pipe-when-only-single-one-cpu-on-client/</link>
      <pubDate>Tue, 22 Mar 2011 00:07:00 +0000</pubDate>
      
      <guid>/questions/3013/wireshark-consumes-100-percent-cpu-while-feed-h323-protocol-data-using-pipe-when-only-single-one-cpu-on-client/</guid>
      <description>Wireshark consumes 100 percent CPU while feed H323 protocol data using pipe when Only single one CPU on client  0 I use pipe to feed H323 protocol data into Wireshark, If only single one CPU on client side, Wireshark will consume 100 percent CPU, if 4 CPUs exists, it will consume 25 percent, it will continue occupying one CPU 100 percent.
pipe consume h323 cpuasked 22 Mar &#39;11, 00:07</description>
    </item>
    
    <item>
      <title>Use sub-dissector in dissector</title>
      <link>/questions/3014/use-sub-dissector-in-dissector/</link>
      <pubDate>Tue, 22 Mar 2011 03:23:00 +0000</pubDate>
      
      <guid>/questions/3014/use-sub-dissector-in-dissector/</guid>
      <description>Use sub-dissector in dissector  0 Hi,
I work on a dissector which decode a UDP based protocol. For each UDP packets I have a moludp64 packet which can contain one or more message blocks. Each message block is encode in another protocol, and I will implement these others protocols. What is the best way to make this happen? Is it my moludp64 dissector which must be calling the others dissectors?</description>
    </item>
    
    <item>
      <title>wireshark bug</title>
      <link>/questions/3016/wireshark-bug/</link>
      <pubDate>Tue, 22 Mar 2011 04:38:00 +0000</pubDate>
      
      <guid>/questions/3016/wireshark-bug/</guid>
      <description>wireshark bug  0 hi i have built my own dissector and i am getting the following error when i click on one of the fields.
(wireshark:3672): Gtk-CRITICAL **: gtk_menu_attach_to_widget: assertion `GTK_IS_MENU (menu)&#39; failed
Any help regarding this issue is appreciated
gtk bug wiresharkasked 22 Mar &#39;11, 04:38
niks3089
21●15●15●18
accept rate: 0%
 edited 22 Mar &#39;11, 07:12 
Jaap ♦
11.7k●16●101
Wireshark version? Does your dissector have GTK code ?</description>
    </item>
    
    <item>
      <title>Can any one help me how can i extract the EXE file in HTTP pcap?</title>
      <link>/questions/3017/can-any-one-help-me-how-can-i-extract-the-exe-file-in-http-pcap/</link>
      <pubDate>Tue, 22 Mar 2011 05:11:00 +0000</pubDate>
      
      <guid>/questions/3017/can-any-one-help-me-how-can-i-extract-the-exe-file-in-http-pcap/</guid>
      <description>Can any one help me how can i extract the EXE file in HTTP pcap?  0 Please help me
extractexeasked 22 Mar &#39;11, 05:11
sethaliasath...
1●2●2●2
accept rate: 0%
  
One Answer:
  
0Have you checked the Users Guide?
answered 22 Mar &#39;11, 07:15
Jaap ♦
11.7k●16●101
accept rate: 14%
     </description>
    </item>
    
    <item>
      <title>Average bandwidth utilization</title>
      <link>/questions/3028/average-bandwidth-utilization/</link>
      <pubDate>Tue, 22 Mar 2011 11:00:00 +0000</pubDate>
      
      <guid>/questions/3028/average-bandwidth-utilization/</guid>
      <description>Average bandwidth utilization  0 Wireshark comes highly recommended and I am very interested in using it. But I would like to know beforehand if the software can can plot, over a 24 hour period, the average bandwidth utilization of my T1 line.
bandwidthutilizationasked 22 Mar &#39;11, 11:00
VelaSystems
1●1●1●1
accept rate: 0%
  
One Answer:
  
0If you can manage to fit that 24 hour period into one single capture file without crashing Wireshark on loading it you might be able to do that with the I/O graph feature found in the statistics menu.</description>
    </item>
    
    <item>
      <title>monitoring packet flow</title>
      <link>/questions/3032/monitoring-packet-flow/</link>
      <pubDate>Tue, 22 Mar 2011 14:11:00 +0000</pubDate>
      
      <guid>/questions/3032/monitoring-packet-flow/</guid>
      <description>monitoring packet flow  0 Hello, I need to make sure that our data flow, specifically our email flow, is following a certain path, or I should say to find out what path it comes in and out of our network. For example, when email enters our network we want to make sure that it flows seamlessly in a correct manner as well as when it leaves our network, not looping around, getting stuck somewhere for unnecessary amount of time, etc.</description>
    </item>
    
    <item>
      <title>Find IPhones and IPads</title>
      <link>/questions/3036/find-iphones-and-ipads/</link>
      <pubDate>Tue, 22 Mar 2011 20:17:00 +0000</pubDate>
      
      <guid>/questions/3036/find-iphones-and-ipads/</guid>
      <description>Find IPhones and IPads  0 Anyone have an suggestion on how to quickly identify IPhones or IPads? I have an applaince attached to a mirrored port so it sees all the traffic, including frmo the Wifi network. Is there a filter or something to quickly show these kind of devices?
filteringasked 22 Mar &#39;11, 20:17
gunnahafta
1●1●1●1
accept rate: 0%
  
4 Answers:
  
2You might want to filter on the User-Agent string, I just captured traffic from my iPhone and it gives the following User-Agent string:</description>
    </item>
    
    <item>
      <title>Which process is sending an old password?</title>
      <link>/questions/3037/which-process-is-sending-an-old-password/</link>
      <pubDate>Wed, 23 Mar 2011 02:15:00 +0000</pubDate>
      
      <guid>/questions/3037/which-process-is-sending-an-old-password/</guid>
      <description>Which process is sending an old password?  0 I had to change my password, it is used for several purposes, eg. HTTP-proxy, netdrive-connections etc.
Unfortunately, some process under the hood is still using the old password and this periodically loggs me out.
How can I use wireshark to find this process?
I have a 90% guess that is is via http-proxy attempts, but I&#39;m not sure.
Thx in advance, Pit.</description>
    </item>
    
    <item>
      <title>tcp options</title>
      <link>/questions/3039/tcp-options/</link>
      <pubDate>Wed, 23 Mar 2011 03:15:00 +0000</pubDate>
      
      <guid>/questions/3039/tcp-options/</guid>
      <description>tcp options  0 I was wondering if there is some way to do this. 1. to decode the options part of tcp protocol or say dissect the options part of the tcp header. 2. once i decode the options part, get wireshark to do the rest of decoding as usual.
tcp-options wiresharkasked 23 Mar &#39;11, 03:15
niks3089
21●15●15●18
accept rate: 0%
1I&#39;m confused about the question - doesn&#39;t Wireshark do this by default?</description>
    </item>
    
    <item>
      <title>Slow AFP and SMB performance</title>
      <link>/questions/3044/slow-afp-and-smb-performance/</link>
      <pubDate>Wed, 23 Mar 2011 09:11:00 +0000</pubDate>
      
      <guid>/questions/3044/slow-afp-and-smb-performance/</guid>
      <description>Slow AFP and SMB performance  0 Looking for some ideas.
We have a pretty basic network setup in a remote office with very few users. Our ISP provides us with a 100MBit ethernet connection to their equipment, so this office is connected to our main office literally on a 100MBit switched connection. Traffic is passed to and from this office on a VLAN I created and gets passed through a queue in queue tunnel created by our ISP.</description>
    </item>
    
    <item>
      <title>TCP piggybacking effects on RTT measurement with Wireshark</title>
      <link>/questions/3047/tcp-piggybacking-effects-on-rtt-measurement-with-wireshark/</link>
      <pubDate>Wed, 23 Mar 2011 12:41:00 +0000</pubDate>
      
      <guid>/questions/3047/tcp-piggybacking-effects-on-rtt-measurement-with-wireshark/</guid>
      <description>TCP piggybacking effects on RTT measurement with Wireshark  0 i&#39;m trying to get the RTT samples using tshark, most of the application i observe do not use piggybacking property of the TCP. if it is used is there any considerations/differences for RTT calculation with/without piggybacking? (user think times or any other noises will effect the RTT(?) Thanks.
piggyback rttasked 23 Mar &#39;11, 12:41
berkey
31●4●4●8
accept rate: 0%
 edited 23 Mar &#39;11, 12:42</description>
    </item>
    
    <item>
      <title>Decipher please</title>
      <link>/questions/3060/decipher-please/</link>
      <pubDate>Wed, 23 Mar 2011 13:38:00 +0000</pubDate>
      
      <guid>/questions/3060/decipher-please/</guid>
      <description>Decipher please  0 Can anyone help me with defining what is happening with this packet. Here are the results;
Frame 30 2.759459 192.168.1.27 192.168.19.14 TCP 51132 &amp;gt; 44000 [PSH, ACK Seq=1 Ack=1 Win=262140 Len=148
Frame 31 3.058855 192.168.1.27 192.168.19.14 CTP [TCP Reransmission] 51132 &amp;gt; 44000 [PSH, ACK Seq=1 Ack=1 Win=262140 Len=148
Frame 102 12.153875 192.168.19.14 192.168.1.27 TCP 44000 &amp;gt; 51132 [SYN, ACK] Seq=0 Ack=1 Win=5840 Len=0 MSS=1460 SACK_PERM=1 WS=2</description>
    </item>
    
    <item>
      <title>Best filters for Hosted VOIP Providers</title>
      <link>/questions/3061/best-filters-for-hosted-voip-providers/</link>
      <pubDate>Wed, 23 Mar 2011 13:52:00 +0000</pubDate>
      
      <guid>/questions/3061/best-filters-for-hosted-voip-providers/</guid>
      <description>Best filters for Hosted VOIP Providers  0 I work for a Hosted VOIP PBX provider and I would like to learn the best way to use Wireshark to diagnose issues with VOIP. I can already setup the packet captures to get all traffic and then use the &#34;VOIP Calls&#34; analysis funtion to see all the calls but I need to be able to also see what is going on behind the customer premise router.</description>
    </item>
    
    <item>
      <title>Is there a way of tagging the thread that you responded to?</title>
      <link>/questions/3073/is-there-a-way-of-tagging-the-thread-that-you-responded-to/</link>
      <pubDate>Wed, 23 Mar 2011 16:57:00 +0000</pubDate>
      
      <guid>/questions/3073/is-there-a-way-of-tagging-the-thread-that-you-responded-to/</guid>
      <description>Is there a way of tagging the thread that you responded to?  2 Sometimes, I forget which thread I responded to when viewing the questions. I know you can look at the &#34;recent activity&#34; under the username, but is there a way of tagging it in the &#34;QUESTIONS&#34; tab? thank you!
question forumasked 23 Mar &#39;11, 16:57
hansangb
791●2●6●19
accept rate: 12%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Create another PCAP of a specific IP from a large PCAP</title>
      <link>/questions/3080/create-another-pcap-of-a-specific-ip-from-a-large-pcap/</link>
      <pubDate>Thu, 24 Mar 2011 07:28:00 +0000</pubDate>
      
      <guid>/questions/3080/create-another-pcap-of-a-specific-ip-from-a-large-pcap/</guid>
      <description>Create another PCAP of a specific IP from a large PCAP  0 Hi,
Actually, am caught up in a flux and was looking for some help.
I have a 1 GB file with data from multiple IP&#39;s. I use ngrp to find a particular keyword in the file and then find the source IP and destination IP of that packet where the keyword was present. I then used tshark and the found IP&#39;s to create another PCAP from the large PCAP of packets of only the communication between those two IP&#39;s.</description>
    </item>
    
    <item>
      <title>Creating a profile shared by all users (windows)?</title>
      <link>/questions/3081/creating-a-profile-shared-by-all-users-windows/</link>
      <pubDate>Thu, 24 Mar 2011 08:19:00 +0000</pubDate>
      
      <guid>/questions/3081/creating-a-profile-shared-by-all-users-windows/</guid>
      <description>Creating a profile shared by all users (windows)?  0 Is there a way to create a Wireshark/Tshark profile that is shared by all the users of the machine under windows? It seems that profiles are saved by default in %APPDATA% which is unique to each user.
Thanks!
windows configuration profiles wiresharkasked 24 Mar &#39;11, 08:19
r0u1i
61●7●7●12
accept rate: 0%
  
One Answer:
  
1 You should be able to achieve what you ask if you install the portable version of Wireshark in a directory every user has access to.</description>
    </item>
    
    <item>
      <title>QoS Maximum bit rate down link element at RANAP</title>
      <link>/questions/3082/qos-maximum-bit-rate-down-link-element-at-ranap/</link>
      <pubDate>Thu, 24 Mar 2011 08:22:00 +0000</pubDate>
      
      <guid>/questions/3082/qos-maximum-bit-rate-down-link-element-at-ranap/</guid>
      <description>QoS Maximum bit rate down link element at RANAP  0 I wanna be able to see the QoS Maximum bit rate down link (extension) at RANAP protocol but I&#39;m getting the packet decoded as PPP IPCP instead of RANAP.
I&#39;m using 1.44 version and I don´t know if I need something else (config or add on ) to get this packet decoded. from the link below I understand this is supported.</description>
    </item>
    
    <item>
      <title>Set DLT_USER in dissector registration</title>
      <link>/questions/3083/set-dlt_user-in-dissector-registration/</link>
      <pubDate>Thu, 24 Mar 2011 09:09:00 +0000</pubDate>
      
      <guid>/questions/3083/set-dlt_user-in-dissector-registration/</guid>
      <description>Set DLT_USER in dissector registration  0 Is it possible to set the payload protocol for any of the DLT_USER encapsulations during the build process? Since I have to rebuild Wireshark with new dissectors often, I&#39;d like to do this so that my dissectors are registered correctly as soon as Wireshark is installed, rather than reconfiguring the Encapsulation Table after each new install.
Is there a configuration file I can edit, or perhaps a source file?</description>
    </item>
    
    <item>
      <title>order of packets in case of high data rate</title>
      <link>/questions/3086/order-of-packets-in-case-of-high-data-rate/</link>
      <pubDate>Thu, 24 Mar 2011 10:05:00 +0000</pubDate>
      
      <guid>/questions/3086/order-of-packets-in-case-of-high-data-rate/</guid>
      <description>order of packets in case of high data rate  1 I am monitoring Eth3 of 2 machines. 1st machine is sending the RLP(Radio Link Protocol) messages. 2nd machine receives the RLP Messages. Data rate would ne 30-40 MBps
Problem: Order of the packet on Machine 2 is not same as Machine 1. Is there any guarantee that wireshark will display the packets in the same order as the order of the packets on the wire?</description>
    </item>
    
    <item>
      <title>capturing mobile phone packets</title>
      <link>/questions/3087/capturing-mobile-phone-packets/</link>
      <pubDate>Thu, 24 Mar 2011 10:20:00 +0000</pubDate>
      
      <guid>/questions/3087/capturing-mobile-phone-packets/</guid>
      <description>capturing mobile phone packets  0 I want to capture Http request and response packets which are created by going to a web site with my mobile phone(it is not an iphone). Can anyone tell me how to do it?
mobile phone http packetasked 24 Mar &#39;11, 10:20
A B
1●10●10●12
accept rate: 0%
 retagged 14 Oct &#39;13, 04:49 
beroset
226●1●2●13
Does the phone connect through your home network (or other wifi) or via your cellular service provider&#39;s network (3G/4G, etc)?</description>
    </item>
    
    <item>
      <title>NIC Component Bindings During Capture</title>
      <link>/questions/3094/nic-component-bindings-during-capture/</link>
      <pubDate>Thu, 24 Mar 2011 16:18:00 +0000</pubDate>
      
      <guid>/questions/3094/nic-component-bindings-during-capture/</guid>
      <description>NIC Component Bindings During Capture  0 I&#39;m a relative novice with Wireshark and network analysis in general and my question is regarding unbinding NIC components on the NIC I use to perform captures with.
I normally install/insert a dedicated NIC in the Windows computer I&#39;m going to capture from and unbind all components from the NIC before starting a capture (Client for Microsoft Networks, File and Printer Sharing, TCP/IP). I do this under the pretense that this eliminates the possibility that my capture host will &#34;</description>
    </item>
    
    <item>
      <title>Capturing gmail packets</title>
      <link>/questions/3097/capturing-gmail-packets/</link>
      <pubDate>Thu, 24 Mar 2011 18:08:00 +0000</pubDate>
      
      <guid>/questions/3097/capturing-gmail-packets/</guid>
      <description>Capturing gmail packets  0 I was trying wireshark with different web pages when I log in to my gmail and then run wireshark and refresh gmail there is no http packet!why is it like this?
http packetasked 24 Mar &#39;11, 18:08
A B
1●10●10●12
accept rate: 0%
Are you sure you&#39;re capturing on the right interface?
(24 Mar &#39;11, 19:44) hansangb  
2 Answers:
  
1That&#39;s for the same reason you don&#39;t want others to be able to capture and read your email.</description>
    </item>
    
    <item>
      <title>packet loss</title>
      <link>/questions/3100/packet-loss/</link>
      <pubDate>Fri, 25 Mar 2011 00:02:00 +0000</pubDate>
      
      <guid>/questions/3100/packet-loss/</guid>
      <description>packet loss  0 hi i try to check packet loss when i send a file how i can do this how i can the begin and end of file on the stream and how i can know if there is any loss happen and how i can know these packets are concern the same group(file) thanx
html77asked 25 Mar &#39;11, 00:02
flower
1●3●3●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>communication between two servers fails with large data (not too large)</title>
      <link>/questions/3101/communication-between-two-servers-fails-with-large-data-not-too-large/</link>
      <pubDate>Fri, 25 Mar 2011 00:04:00 +0000</pubDate>
      
      <guid>/questions/3101/communication-between-two-servers-fails-with-large-data-not-too-large/</guid>
      <description>communication between two servers fails with large data (not too large)  0 We have some issue on our production environment. In normal condition, communication between two servers(JBOSS application server and SQL 2005 database server) works perfectly.
But In some situation, two servers(JBOSS application server and SQL 2005 database server) can communicate with each other for small data (20 records) but communication fails with slightly large data(1000 records). Once this problem happens we have to restart the machine( the server on which JBOSS application server is deployed) to resolve the problem.</description>
    </item>
    
    <item>
      <title>Convert libpcap to pdml</title>
      <link>/questions/3107/convert-libpcap-to-pdml/</link>
      <pubDate>Fri, 25 Mar 2011 02:12:00 +0000</pubDate>
      
      <guid>/questions/3107/convert-libpcap-to-pdml/</guid>
      <description>Convert libpcap to pdml  0 Hi all,
I am attempting to automate some capturing and conversion tasks using JAVA.
I want to capture in files with size of 1024kB using the option -b filesize:1024
I also want these raw data converted to PDML/XML. I use: tshark -r infile &amp;gt; outfile -T pdml; This works fine using command prompt/console, but in JAVA this &#39;&amp;gt;&#39; to redirect stdout, seems to behave badly or not at all:</description>
    </item>
    
    <item>
      <title>sorting of displayed packets broken?</title>
      <link>/questions/3111/sorting-of-displayed-packets-broken/</link>
      <pubDate>Fri, 25 Mar 2011 03:59:00 +0000</pubDate>
      
      <guid>/questions/3111/sorting-of-displayed-packets-broken/</guid>
      <description>sorting of displayed packets broken?  0 previous versions of wireshark (0.99.x) had a sub-sorting with sequential numbers in the displayed packets, if sorting for protocol (for example) was enabled.
Actual versions are messing up this sub sorting and display packets in arbitrary order, if sorting for protocol is selected.
Please have a look:
http://img822.imageshack.us/i/kaputt.png/ (the broken one)
http://img854.imageshack.us/i/23675117.png/ (good)
How can I have the sub sorting with increasing numbers on actual versions of wireshark?</description>
    </item>
    
    <item>
      <title>usb.urb_type values?</title>
      <link>/questions/3113/usburb_type-values/</link>
      <pubDate>Fri, 25 Mar 2011 04:50:00 +0000</pubDate>
      
      <guid>/questions/3113/usburb_type-values/</guid>
      <description>usb.urb_type values?  0 The usb.urb_type is described as &#34;URB type&#34; &#34;String&#34; in the manual http://www.wireshark.org/docs/dfref/u/usb.html. This is very helpful. But now, I want to see only host-do-device requests. usb.urb_type == URB_SUBMIT blocks everything.
filteringasked 25 Mar &#39;11, 04:50
valentin
6●1●1●3
accept rate: 0%
 edited 25 Mar &#39;11, 05:00 
  
3 Answers:
  
0 Try: usb.urb_type contains &#34;S&#34;
answered 25 Mar &#39;11, 07:14
cmaynard ♦♦</description>
    </item>
    
    <item>
      <title>Modifying Packet Header</title>
      <link>/questions/3114/modifying-packet-header/</link>
      <pubDate>Fri, 25 Mar 2011 04:55:00 +0000</pubDate>
      
      <guid>/questions/3114/modifying-packet-header/</guid>
      <description>Modifying Packet Header  0 Hi,
I am working on a project for a professor to collect smb packet headers on university network. Due to security reasons uid, mid, file path, etc. needs to be one-way encrypted.
I was wondering if anyone can help me figure out how i can modify these header fields in the dissected tree directly that is returned by libwireshark (edt-&amp;gt;tree) before i can save this header to a pcap or a simple xml file with header in hex format.</description>
    </item>
    
    <item>
      <title>Play captured VoIP call</title>
      <link>/questions/3115/play-captured-voip-call/</link>
      <pubDate>Fri, 25 Mar 2011 04:57:00 +0000</pubDate>
      
      <guid>/questions/3115/play-captured-voip-call/</guid>
      <description>Play captured VoIP call  0 Hi,
When I capture a voip call and go to &#34;Telephony -&amp;gt; VoIP Calls -&amp;gt; Player -&amp;gt; Decode&#34; and select both directions, only the one selected first can be played.. either one.
However, if I check both streams to play the complete call - and only one direction can be heard, the timeline follows both directions.
Weird thing is; if I &#34;Save payload&#34;, select &#34;</description>
    </item>
    
    <item>
      <title>Is there a way to perform a local search that includes all the content of the questions, including answers, comments, users, etc.?</title>
      <link>/questions/3117/is-there-a-way-to-perform-a-local-search-that-includes-all-the-content-of-the-questions-including-answers-comments-users-etc/</link>
      <pubDate>Fri, 25 Mar 2011 06:50:00 +0000</pubDate>
      
      <guid>/questions/3117/is-there-a-way-to-perform-a-local-search-that-includes-all-the-content-of-the-questions-including-answers-comments-users-etc/</guid>
      <description>Is there a way to perform a local search that includes all the content of the questions, including answers, comments, users, etc.?  1 Is there a way to perform a local search on ask.wireshark.org that includes all the content of the questions, including answers, comments, users, etc.? As far as I can tell, the search only searches the questions themselves.
searchasked 25 Mar &#39;11, 06:50
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%</description>
    </item>
    
    <item>
      <title>No dropped packet</title>
      <link>/questions/3120/no-dropped-packet/</link>
      <pubDate>Fri, 25 Mar 2011 07:08:00 +0000</pubDate>
      
      <guid>/questions/3120/no-dropped-packet/</guid>
      <description>No dropped packet  -1 Can anyone tell me what is happening when I try to connect to the database using port 44000 and why it is not connecting even though I see the ACK;
Here is the capture in plain text. Can you help:
No. Time Source Destination Protocol Info 45 9.206394 192.168.1.27 192.168.19.14 TCP 53710 &amp;gt; 44000 [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=2 SACK_PERM=1
Frame 45: 66 bytes on wire (528 bits), 66 bytes captured (528 bits) Ethernet II, Src: Dell_9f:db:d9 (b8:ac:6f:9f:db:d9), Dst: Adtran_3d:a1:98 (00:a0:c8:3d:a1:98) Internet Protocol, Src: 192.</description>
    </item>
    
    <item>
      <title>TCP Out-of-order VS Retransmission</title>
      <link>/questions/3131/tcp-out-of-order-vs-retransmission/</link>
      <pubDate>Fri, 25 Mar 2011 13:33:00 +0000</pubDate>
      
      <guid>/questions/3131/tcp-out-of-order-vs-retransmission/</guid>
      <description>TCP Out-of-order VS Retransmission  0 I&#39;ve got a situation where there appears to be timeouts on the client side. I&#39;ve zeroed in on a sample, but I see this multiple places. The dialog is going fine and the client sends 67 bytes of data in #1478 and the host is ACKs in #1479. The client then sends the same sequence packet as it did in #1478, but the data is larger.</description>
    </item>
    
    <item>
      <title>Why were H225 RAS messages removed from the VoIP calls flow diagram?</title>
      <link>/questions/3137/why-were-h225-ras-messages-removed-from-the-voip-calls-flow-diagram/</link>
      <pubDate>Fri, 25 Mar 2011 19:05:00 +0000</pubDate>
      
      <guid>/questions/3137/why-were-h225-ras-messages-removed-from-the-voip-calls-flow-diagram/</guid>
      <description>Why were H225 RAS messages removed from the VoIP calls flow diagram?  3 Older versions of wireshark included H225 RAS messages (admissionRequest, admissionConfirm, admissionReject, disengageRequest, disengageConfirm, and disengageReject) in the set of messages detected for H.323 VoIP calls, and in what used to be called the &#34;graph&#34; of a call and is now called the &#34;Flow&#34; of the call.
It was extremely useful for these messages to be included in the graph of a call because these messages are integral to the way that calls are placed in the H.</description>
    </item>
    
    <item>
      <title>what does TCP windows scale zero means ?</title>
      <link>/questions/3144/what-does-tcp-windows-scale-zero-means/</link>
      <pubDate>Sat, 26 Mar 2011 08:34:00 +0000</pubDate>
      
      <guid>/questions/3144/what-does-tcp-windows-scale-zero-means/</guid>
      <description>what does TCP windows scale zero means ?  0 I was analyzing a issue where I see the below TCP optiosn set , I see the server setting the windows scale to 0 , what does these mean? I have the capture on the client but not on the server.
Is server not accepting the window scaling at all ? Do the server see the client receive window size as 65535 even though we offer them (65535*2^7)Is this good ?</description>
    </item>
    
    <item>
      <title>2 protocols in a same code?</title>
      <link>/questions/3148/2-protocols-in-a-same-code/</link>
      <pubDate>Sun, 27 Mar 2011 02:21:00 +0000</pubDate>
      
      <guid>/questions/3148/2-protocols-in-a-same-code/</guid>
      <description>2 protocols in a same code?  0 I have a protocol such that there is a x header and y header. How can i have these headers under a single packet-xyz.c file? It should look something like this .. IP TCP X Y
header protocolasked 27 Mar &#39;11, 02:21
niks3089
21●15●15●18
accept rate: 0%
  
One Answer:
  
0Write two separate dissectors, and put the source to both of them in the packet-xyz.</description>
    </item>
    
    <item>
      <title>tcp options dissection</title>
      <link>/questions/3153/tcp-options-dissection/</link>
      <pubDate>Sun, 27 Mar 2011 06:30:00 +0000</pubDate>
      
      <guid>/questions/3153/tcp-options-dissection/</guid>
      <description>tcp options dissection  0 I was wondering if there is some way to do this. 1. to decode the options part of tcp protocol or say dissect the options part of the tcp header. 2.once i decode the options part, get wireshark to do the rest of decoding as usual.
There are certain options that wireshark shows as unknown. These contain some important info which my company has requested me to dissect.</description>
    </item>
    
    <item>
      <title>hierarchy in refer field</title>
      <link>/questions/3157/hierarchy-in-refer-field/</link>
      <pubDate>Sun, 27 Mar 2011 12:14:00 +0000</pubDate>
      
      <guid>/questions/3157/hierarchy-in-refer-field/</guid>
      <description>hierarchy in refer field  0 I am so confused with refer field in http request packets.When I have an embedded object in one web page which is on another server and it is embedded on other page. I cant find an example in order to see do experiment. Can you describe it for me?
http packetasked 27 Mar &#39;11, 12:14
A B
1●10●10●12
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Register dissector without particularities</title>
      <link>/questions/3159/register-dissector-without-particularities/</link>
      <pubDate>Sun, 27 Mar 2011 13:31:00 +0000</pubDate>
      
      <guid>/questions/3159/register-dissector-without-particularities/</guid>
      <description>Register dissector without particularities  0 I would know if it&#39;s possible to register a dissector for a protocol which hasn&#39;t particularities, neither fields nor ports are usable to determine the dissector to use. The only particularity it&#39;s the use of udp protocol.
In the same idea, Is it possible to register a subdissector for a protocol which can use one ore more upper protocol, without to precise a port or a field?</description>
    </item>
    
    <item>
      <title>VOIP call recording</title>
      <link>/questions/3166/voip-call-recording/</link>
      <pubDate>Sun, 27 Mar 2011 15:34:00 +0000</pubDate>
      
      <guid>/questions/3166/voip-call-recording/</guid>
      <description>VOIP call recording  0 Hello All, I am new to this wire shark software. I am in need of a software that would record all phone conversations (Iindividual voip phones by grand stream or call centric) on the network from a centralized computer. I will dedicate this computer for this purpose only. i am planning to get 4-5 phone lines for my workers which will be directly connected by ethernet cables to my hub/router.</description>
    </item>
    
    <item>
      <title>ton of ACKs but no SYN or SYN/ACK</title>
      <link>/questions/3168/ton-of-acks-but-no-syn-or-synack/</link>
      <pubDate>Sun, 27 Mar 2011 21:16:00 +0000</pubDate>
      
      <guid>/questions/3168/ton-of-acks-but-no-syn-or-synack/</guid>
      <description>ton of ACKs but no SYN or SYN/ACK  0 I thought I&#39;d try to learn WireShark but have a quick question. I started it up and went to a couple sites then stopped it. In 13 seconds, I had over 20,000 lines of ACK packets with no SYN or SYN/ACKs anywhere. Is this a DoS ACK attempt? Anything to be worried about?
Thanks!
synasked 27 Mar &#39;11, 21:16
cdnsupguy</description>
    </item>
    
    <item>
      <title>How to keep the info and protocol constant</title>
      <link>/questions/3171/how-to-keep-the-info-and-protocol-constant/</link>
      <pubDate>Mon, 28 Mar 2011 02:46:00 +0000</pubDate>
      
      <guid>/questions/3171/how-to-keep-the-info-and-protocol-constant/</guid>
      <description>How to keep the info and protocol constant  0 I have 2 dissectors X and Y. If Y is present X calls Y or else it shows it as X. Now everything works fine. I have X and Y displaying on the PROTOCOL column in wireshark. Now I wanna see only X so I click on protocol button but now everything changes and only Y appears How do I make the COL_INFO and COL_PROTOCOL values unchangeable?</description>
    </item>
    
    <item>
      <title>ICMP Sequence Number (BE) vs (LE)</title>
      <link>/questions/3172/icmp-sequence-number-be-vs-le/</link>
      <pubDate>Mon, 28 Mar 2011 05:19:00 +0000</pubDate>
      
      <guid>/questions/3172/icmp-sequence-number-be-vs-le/</guid>
      <description>ICMP Sequence Number (BE) vs (LE)  0 When applying a column for a capture looking at a trace route I noticed there are 2 sequence number choices - (BE) and (LE) in the packets detail screen. I did not see these in earlier version of WS. What&#39;s the difference? Thanks Eric
icmpasked 28 Mar &#39;11, 05:19
EricKnaus
46●19●20●26
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Acknowledgment number: Broken TCP. The acknowledge field is nonzero while the ACK flag is not set</title>
      <link>/questions/3183/acknowledgment-number-broken-tcp-the-acknowledge-field-is-nonzero-while-the-ack-flag-is-not-set/</link>
      <pubDate>Mon, 28 Mar 2011 13:55:00 +0000</pubDate>
      
      <guid>/questions/3183/acknowledgment-number-broken-tcp-the-acknowledge-field-is-nonzero-while-the-ack-flag-is-not-set/</guid>
      <description>Acknowledgment number: Broken TCP. The acknowledge field is nonzero while the ACK flag is not set  0 What does this message mean?
Acknowledgment number: Broken TCP. The acknowledge field is nonzero while the ACK flag is not set
I see the client attempt to send this after the TCP connection has been torn down by FIN/ACK, ACK+FIN/ACK, ACK. Our firewall blocks the RST packet sent (with the above &#34;broken tcp&#34;</description>
    </item>
    
    <item>
      <title>Dissecting keyboard and CCID from usbmon</title>
      <link>/questions/3196/dissecting-keyboard-and-ccid-from-usbmon/</link>
      <pubDate>Mon, 28 Mar 2011 23:14:00 +0000</pubDate>
      
      <guid>/questions/3196/dissecting-keyboard-and-ccid-from-usbmon/</guid>
      <description>Dissecting keyboard and CCID from usbmon  0 I&#39;m looking for a protocol dissector for usbmon that would give human readable output of &#34;key X pressed&#34;, &#34;key X released&#34; when capturing a standard USB keyboard. I hope something like that would already exist.
As a bonus I&#39;d also like to dissect CCID frames from usbmon which probably does not yet exist and I would need to develop a custom dissector (to confirm that a smart card reader in fact is insecure in all conditions).</description>
    </item>
    
    <item>
      <title>Monitoring a wireless network?</title>
      <link>/questions/3209/monitoring-a-wireless-network/</link>
      <pubDate>Tue, 29 Mar 2011 12:56:00 +0000</pubDate>
      
      <guid>/questions/3209/monitoring-a-wireless-network/</guid>
      <description>Monitoring a wireless network?  0 To Whom It May Concern, I am trying to find a software that will allow me to &#34;snif&#34; my wireless network to monitor what my teenagers are doing on their laptops. Ideally, I want to download the software to my laptop and get updates when they log in (to include passwords). Would Wireshark do this or can anyone recommend another product that is relatively easy to do?</description>
    </item>
    
    <item>
      <title>real time link utilization</title>
      <link>/questions/3215/real-time-link-utilization/</link>
      <pubDate>Tue, 29 Mar 2011 15:23:00 +0000</pubDate>
      
      <guid>/questions/3215/real-time-link-utilization/</guid>
      <description>real time link utilization  0 Hi,
I&#39;m still learning WireShark but have used Network General Sniffers years ago. They had a nice feature on the main screen that displayed real-time link utilization. Is there any way to get link utilization with WireShark?
Thanks.
utilizationasked 29 Mar &#39;11, 15:23
eelarry
36●8●9●12
accept rate: 0%
 edited 29 Mar &#39;11, 15:23 
  
One Answer:
  
1 You could start the I/O Graph from the statistics menu.</description>
    </item>
    
    <item>
      <title>&amp;quot;Capture packets in promiscuous mode&amp;quot; check-box</title>
      <link>/questions/3218/capture-packets-in-promiscuous-mode-check-box/</link>
      <pubDate>Tue, 29 Mar 2011 17:50:00 +0000</pubDate>
      
      <guid>/questions/3218/capture-packets-in-promiscuous-mode-check-box/</guid>
      <description>&amp;ldquo;Capture packets in promiscuous mode&amp;rdquo; check-box  0 Wireshark Version 1.4.2; Win7Pro64; 802.11 sniffing. Does the presence of the &#34;Capture packets in promiscuous mode&#34; option box imply that it is, in fact, possible to put my adapter into promiscuous mode? The box is present, and is checked, yet I am only seeing traffic to or from the machine running Wireshark, suggesting that it is not really in promiscuous mode.
Thanks, Howard</description>
    </item>
    
    <item>
      <title>synphasor filter</title>
      <link>/questions/3221/synphasor-filter/</link>
      <pubDate>Tue, 29 Mar 2011 21:42:00 +0000</pubDate>
      
      <guid>/questions/3221/synphasor-filter/</guid>
      <description>synphasor filter  0 I&#39;m capturing IEEE C37.118 packets with the synphasor filter and in the data frames where the measurement data should be shown it says &#34;Measurement data, no configuration frame found&#34; even though there is a configuration frame as the 3rd packet in the capture. Is there a certain way to associate the configuration frame with the data frames in the capture? How is it done? Need help!</description>
    </item>
    
    <item>
      <title>Malformed Packet: DCERPC Protocol</title>
      <link>/questions/3222/malformed-packet-dcerpc-protocol/</link>
      <pubDate>Wed, 30 Mar 2011 00:04:00 +0000</pubDate>
      
      <guid>/questions/3222/malformed-packet-dcerpc-protocol/</guid>
      <description>Malformed Packet: DCERPC Protocol  0 Hi,
I encountered malformed packets although the application works ok. This is based on WireShark 1.4.4 and 1.5.
The traffic is between my Application Server via F5 to DB (and vice versa). Attached is the dump:
0000 00 1b 21 33 8b 9b 00 01 d7 c1 e5 03 08 00 45 00 ..!3.... ......E. 0010 00 39 a6 6d 40 00 ff 06 8e 82 0a 32 a8 d2 0a 32 [email protected] .</description>
    </item>
    
    <item>
      <title>Adding custom TCP options</title>
      <link>/questions/3235/adding-custom-tcp-options/</link>
      <pubDate>Wed, 30 Mar 2011 13:03:00 +0000</pubDate>
      
      <guid>/questions/3235/adding-custom-tcp-options/</guid>
      <description>Adding custom TCP options  0 How can I add labels for custom (unknown) TCP options?
unknown options tcp customasked 30 Mar &#39;11, 13:03
Demetris
1●1●1●1
accept rate: 0%
  
One Answer:
  
1You&#39;ll have to code it yourself, adding to the TCP dissector and compile it. Start by adding to this options array and work your way out. Look at the others for examples, it&#39;s fairly easy.</description>
    </item>
    
    <item>
      <title>How would one generate an RPM for wireshark?</title>
      <link>/questions/3237/how-would-one-generate-an-rpm-for-wireshark/</link>
      <pubDate>Wed, 30 Mar 2011 16:37:00 +0000</pubDate>
      
      <guid>/questions/3237/how-would-one-generate-an-rpm-for-wireshark/</guid>
      <description>How would one generate an RPM for wireshark?  0 I&#39;m sorry if the question is really broad. As far as I know you need to create a spec file. But besides that what else do I have to keep in mind?
Furthermore, are there are build scripts out there already that I can use to generate it? I know ethereal came in rpms...
generating rpmsasked 30 Mar &#39;11, 16:37</description>
    </item>
    
    <item>
      <title>Which source code module does represent the Time Zone encoding and decoding?</title>
      <link>/questions/3240/which-source-code-module-does-represent-the-time-zone-encoding-and-decoding/</link>
      <pubDate>Wed, 30 Mar 2011 20:28:00 +0000</pubDate>
      
      <guid>/questions/3240/which-source-code-module-does-represent-the-time-zone-encoding-and-decoding/</guid>
      <description>Which source code module does represent the Time Zone encoding and decoding?  0 I would like to ask for your help to let me know which wireshark source code module define how to encode and decode Time Zone? Also the mechanism to encode and decode Time Zone is based on 3GPP TS 23.040 section 9.2.3.11 or not?
timezoneasked 30 Mar &#39;11, 20:28
Sripat
1●1●1●2
accept rate: 0%
That question is to broad, Time Zone where?</description>
    </item>
    
    <item>
      <title>Wireshark for Redhat Linux and RF terminals</title>
      <link>/questions/3242/wireshark-for-redhat-linux-and-rf-terminals/</link>
      <pubDate>Thu, 31 Mar 2011 07:15:00 +0000</pubDate>
      
      <guid>/questions/3242/wireshark-for-redhat-linux-and-rf-terminals/</guid>
      <description>Wireshark for Redhat Linux and RF terminals  0 Is there a version of Wireshark for Redhat Linux 8?
Is there mobile version of Wireshark taht I can install on a Wireless RF terminal to track packets?
redhat linuxasked 31 Mar &#39;11, 07:15
IanS
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Error message: The capture file appears to be damaged or corrupt</title>
      <link>/questions/3243/error-message-the-capture-file-appears-to-be-damaged-or-corrupt/</link>
      <pubDate>Thu, 31 Mar 2011 07:40:00 +0000</pubDate>
      
      <guid>/questions/3243/error-message-the-capture-file-appears-to-be-damaged-or-corrupt/</guid>
      <description>Error message: The capture file appears to be damaged or corrupt  0 I have tried both versions of Wireshark (1.2.15 and 1.4.4). I have installed the 32 bit version on a Windows XP PC running service pack3 and the 64 bit version on a Windows 7 PC (running Windows 7 Enterprise with service pack 1). I have a snoop capture file from a SUN 35220 machine running Solaris 10. If I open the capture file on the XP machine using Wireshark it opens correctly and displays the data correctly (it is primarily SCTP/M3ua).</description>
    </item>
    
    <item>
      <title>home network</title>
      <link>/questions/3246/home-network/</link>
      <pubDate>Thu, 31 Mar 2011 08:30:00 +0000</pubDate>
      
      <guid>/questions/3246/home-network/</guid>
      <description>home network  0 Hi, I&#39;m using a desktop and accessing the router using a cable. When I start to capturing the packets, it only capture packets that are only from my desktop IP. I would like to know if is possible that I can capture other machine IP address that are connected to the router too?
home networkasked 31 Mar &#39;11, 08:30
MaxGenesis Tee
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark decoder for MPLS-TP</title>
      <link>/questions/3248/wireshark-decoder-for-mpls-tp/</link>
      <pubDate>Thu, 31 Mar 2011 10:45:00 +0000</pubDate>
      
      <guid>/questions/3248/wireshark-decoder-for-mpls-tp/</guid>
      <description>Wireshark decoder for MPLS-TP  0 Hi,
Is a decoder for MPLS-TP in the works ? If yes, when is it likely to be available ?
mplsasked 31 Mar &#39;11, 10:45
smashie
1●1●1●1
accept rate: 0%
  
One Answer:
  
0See http://www.wireshark.org/faq.html#q1.11
answered 01 Apr &#39;11, 07:41
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%
     </description>
    </item>
    
    <item>
      <title>Filter out duplicate SNMP Request</title>
      <link>/questions/3250/filter-out-duplicate-snmp-request/</link>
      <pubDate>Thu, 31 Mar 2011 11:54:00 +0000</pubDate>
      
      <guid>/questions/3250/filter-out-duplicate-snmp-request/</guid>
      <description>Filter out duplicate SNMP Request  0 Hi, I&#39;m using Wireshark to solve a SNMP problem. I have some large pcap-files full of SNMP traffic. Some SNMP Requests have the same SNMP Request-ID. Is it possible to filter out duplicate SNMP Request IDs with a display filter or is there a solution with tshark?
Thanks for your help!
filter request duplicate snmp idasked 31 Mar &#39;11, 11:54
DrJekyll
6●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Extracting datas from the Statistics Summary</title>
      <link>/questions/3263/extracting-datas-from-the-statistics-summary/</link>
      <pubDate>Fri, 01 Apr 2011 03:06:00 +0000</pubDate>
      
      <guid>/questions/3263/extracting-datas-from-the-statistics-summary/</guid>
      <description>Extracting datas from the Statistics Summary  0 Hello, i would like to extract the Packets Captured and Displayed from the Summary Panel (in statistics menu), copy/past function is not working.
summary datas extractingasked 01 Apr &#39;11, 03:06
chenry
1●1●1●2
accept rate: 0%
If capinfos doesn&#39;t do it for you, check out tcptrace.
(04 Apr &#39;11, 11:00) hansangb  
2 Answers:
  
0The ability to copy that information is not yet supported, but you can probably obtain a lot of what you want using capinfos.</description>
    </item>
    
    <item>
      <title>Why does the info and protocol header in wireshark keeps changing?</title>
      <link>/questions/3264/why-does-the-info-and-protocol-header-in-wireshark-keeps-changing/</link>
      <pubDate>Fri, 01 Apr 2011 03:13:00 +0000</pubDate>
      
      <guid>/questions/3264/why-does-the-info-and-protocol-header-in-wireshark-keeps-changing/</guid>
      <description>Why does the info and protocol header in wireshark keeps changing?  0 Whenever I want to view my protocol,for which I have written a dissector for I click on the protocol header in the wireshark which should sort out the protocols. Instead of seeing my protocol, the protocol X which actually calls this protocol is seen. What is the reason for this problem. I have set the columns so that it shouldn&#39;t change yet this happens</description>
    </item>
    
    <item>
      <title>TCP retransmission. Where do I go from here?</title>
      <link>/questions/3265/tcp-retransmission-where-do-i-go-from-here/</link>
      <pubDate>Fri, 01 Apr 2011 03:35:00 +0000</pubDate>
      
      <guid>/questions/3265/tcp-retransmission-where-do-i-go-from-here/</guid>
      <description>TCP retransmission. Where do I go from here?  0 Hi all,
I&#39;m rather new to being able to diagnose problems from tcpdumps so please forgive me. We&#39;re getting connectivity issues between two of ours sites, a dump of a http trace shows regular TCP retransmissions.
What are the next steps to diagnose what&#39;s going on, and more importantly how to fix it? Below is a small sample of the trace.</description>
    </item>
    
    <item>
      <title>Fax Capture</title>
      <link>/questions/3266/fax-capture/</link>
      <pubDate>Fri, 01 Apr 2011 03:47:00 +0000</pubDate>
      
      <guid>/questions/3266/fax-capture/</guid>
      <description>Fax Capture  0 Is there a way to export fax tiff file image from .pcap captured file. In other words i am trying to backup all faxes that are passing on my network,and export the fax file later on. Is this feasible and how .
NB:i am using sip protocol and fax protocol is bypass ,G711 i can use T38 if that will solve the matter
regards
faxasked 01 Apr &#39;11, 03:47</description>
    </item>
    
    <item>
      <title>Rate limit causes excess retransmissions and duplicate acks</title>
      <link>/questions/3275/rate-limit-causes-excess-retransmissions-and-duplicate-acks/</link>
      <pubDate>Fri, 01 Apr 2011 08:19:00 +0000</pubDate>
      
      <guid>/questions/3275/rate-limit-causes-excess-retransmissions-and-duplicate-acks/</guid>
      <description>Rate limit causes excess retransmissions and duplicate acks  0 We recently had a customer complaining that performance from their remote site to our home office here was bad. Investigation with Iperf and Wireshark showed a massive number of retrans and dupe acks. In chasing the circuit back to the home office we found out that the circuit provider had put a rate limit of 15 Mbps on their Foundry router in between us.</description>
    </item>
    
    <item>
      <title>HTTP POST command not received and MSS value changed in transit</title>
      <link>/questions/3277/http-post-command-not-received-and-mss-value-changed-in-transit/</link>
      <pubDate>Fri, 01 Apr 2011 16:49:00 +0000</pubDate>
      
      <guid>/questions/3277/http-post-command-not-received-and-mss-value-changed-in-transit/</guid>
      <description>HTTP POST command not received and MSS value changed in transit  0 Hello,
I am debugging a connection reset issue with the following symptoms. The network admins say all firewalls and routers are wide-open between the IP&#39;s, no blocking of any sort. I&#39;m running tcpdump on two systems while they attempt to communicate with each other and using wireshark to look at the traces.
Setup:
SYS1: Private IP NAT&#39;d to public IP, one-to one.</description>
    </item>
    
    <item>
      <title>android phone network connectivity problems when collecting packets from it</title>
      <link>/questions/3281/android-phone-network-connectivity-problems-when-collecting-packets-from-it/</link>
      <pubDate>Fri, 01 Apr 2011 21:11:00 +0000</pubDate>
      
      <guid>/questions/3281/android-phone-network-connectivity-problems-when-collecting-packets-from-it/</guid>
      <description>android phone network connectivity problems when collecting packets from it  0 while collecting wifi packets from my mobile phone (from a linux vm running wireshark on my laptop), I noticed, while collecting packets, the phone began having difficulty connecting to various network services (IMAP, Activesync, pings to local network and remote addresses...etc). Once I stopped collecting packets, the phone network operations began operating normally. This was repeatable. Any idea what is causing the phone TCP/IP problems while collecting packets via wireshark ?</description>
    </item>
    
    <item>
      <title>SYN ATTCK USIN INTERNET</title>
      <link>/questions/3289/syn-attck-usin-internet/</link>
      <pubDate>Sat, 02 Apr 2011 11:04:00 +0000</pubDate>
      
      <guid>/questions/3289/syn-attck-usin-internet/</guid>
      <description>SYN ATTCK USIN INTERNET  0 WE ARE USING A SATELITE LINK TO REACH INTERNET AND OUR PROVIDER SEES MANY SYN ATTACK REQUEST IN THEIR MONITORING SYSTEM. THIS ATTACK AFFECTA US PRODUCING DELAY IN OUR APPLICATION LIKE THAT: BPOS EMAIL, AND INTERNET NAVEGATION. DO YOU HAVE AN EXAMPLE HOW TO DETECT THIS ATTACK WITH WIRESHARK?
syncattackasked 02 Apr &#39;11, 11:04
ROGER
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>&amp;#x27;How do I set the capture to auto save periodically?</title>
      <link>/questions/3291/how-do-i-set-the-capture-to-auto-save-periodically/</link>
      <pubDate>Sat, 02 Apr 2011 13:29:00 +0000</pubDate>
      
      <guid>/questions/3291/how-do-i-set-the-capture-to-auto-save-periodically/</guid>
      <description>&amp;lsquo;How do I set the capture to auto save periodically?  0 How do I set the capture to auto save periodically so WireShark doesn&#39;t crash?
capture save autoasked 02 Apr &#39;11, 13:29
bkready
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Open up the capture options dialog (second button on the toolbar, or &#34;Capture&#34; -&amp;gt; &#34;Options&#34; in the main menu) and set a file name. Then check &#34;</description>
    </item>
    
    <item>
      <title>RDP client sends 2 packet with identical sq number</title>
      <link>/questions/3293/rdp-client-sends-2-packet-with-identical-sq-number/</link>
      <pubDate>Sat, 02 Apr 2011 13:48:00 +0000</pubDate>
      
      <guid>/questions/3293/rdp-client-sends-2-packet-with-identical-sq-number/</guid>
      <description>RDP client sends 2 packet with identical sq number  0 Hi can anybody help me find out why when I log into a remote desktop in Lan area in Wireshark shows me always 2 packets with the same sequence number sent from the client. They send in the range of 0.000020. The link below is an illustrative picture. Pakcet 13,14 have same sequence number. Does anyone know why this is happening?</description>
    </item>
    
    <item>
      <title>TCP Stealth Scan Display Filter</title>
      <link>/questions/3303/tcp-stealth-scan-display-filter/</link>
      <pubDate>Sun, 03 Apr 2011 08:57:00 +0000</pubDate>
      
      <guid>/questions/3303/tcp-stealth-scan-display-filter/</guid>
      <description>TCP Stealth Scan Display Filter  0 I am trying to come up with a display filter to help detect TCP Stealth Scans (or &#34;Half-Open&#34; scans).
Since those are usually characterized by three packets: SYN - SYN/ACK - RST
I&#39;m trying the filter:
tcp.stream &amp;amp;&amp;amp; (tcp.flags.syn == 1 || tcp.flags.reset == 1)
It seems to be working somewhat - but I&#39;m not sure if that is the correct use of the tcp.</description>
    </item>
    
    <item>
      <title>String manipulation in dissector</title>
      <link>/questions/3307/string-manipulation-in-dissector/</link>
      <pubDate>Sun, 03 Apr 2011 12:42:00 +0000</pubDate>
      
      <guid>/questions/3307/string-manipulation-in-dissector/</guid>
      <description>String manipulation in dissector  0 Hi,
I would know how to extract a string from a packet, manipulate it and display it easily using the wireshark API.
My string has a lenght of 10, I need to put a comma between the 6th and 7th characters and display it in the tree.
development dissectorasked 03 Apr &#39;11, 12:42
chronidev
11●5●5●7
accept rate: 0%
 edited 03 Apr &#39;11, 12:42</description>
    </item>
    
    <item>
      <title>SSL Decrypt to File</title>
      <link>/questions/3310/ssl-decrypt-to-file/</link>
      <pubDate>Sun, 03 Apr 2011 14:28:00 +0000</pubDate>
      
      <guid>/questions/3310/ssl-decrypt-to-file/</guid>
      <description>SSL Decrypt to File  1 Hi, I need to decode an ssl stream from a pcap file and save the decoded stream to a new pcap file. I use http://wiki.wireshark.org/SampleCaptures?action=AttachFile&amp;amp;do=view&amp;amp;target=snakeoil2_070531.tgz cap and key from http://wiki.wireshark.org/SSL for test. So with command:
tshark -n -d tcp.port==443,http -o &#34;ssl.desegment_ssl_records: TRUE&#34; -o &#34;ssl.desegment_ssl_application_data: TRUE&#34; -o &#34;ssl.keys_list: 127.0.0.1,443,http,/snakeoil2_070531/rsasnakeoil2.key&#34; -r /snakeoil2_070531/rsasnakeoil2.cap
tshark print on screen the testual version of decoded packets in right way. Now I need to save the real packets (not text) decoded (ssl-&amp;gt;http) to a new file.</description>
    </item>
    
    <item>
      <title>wireshark crash first time starting:</title>
      <link>/questions/3315/wireshark-crash-first-time-starting/</link>
      <pubDate>Sun, 03 Apr 2011 18:46:00 +0000</pubDate>
      
      <guid>/questions/3315/wireshark-crash-first-time-starting/</guid>
      <description>wireshark crash first time starting:  0 wireshark 1.4.4 system info:
95
1VBoxFltDrv: version 4.0.4 r70112 VBoxAdpDrv: version 4.0.4 r70112 PM notification cancel (pid 13, configd) IOPMrootDomain: idle cancel vmnet: VNetUserIf_Create: created userIf at 0x1062ff00. vmnet: VMNetConnect: returning port 0x1062ff00 vmnet: Hub 0 does not exist, allocating memory. vmnet: Allocated hub 0xa8df800 for hubNum 0. vmnet: VMNET_SO_BINDTOHUB: port: paddr 00:50:56:fe:8b:8e vmnet: Hub 0 vmnet: Port 0 vmnet: bridge-ppp0: got dev 0x8983204 vmnet: bridge-ppp0: can&#39;t bridge with ppp, bad header length 4.</description>
    </item>
    
    <item>
      <title>Printing tcp payload using tshark -T fields?</title>
      <link>/questions/3323/printing-tcp-payload-using-tshark-t-fields/</link>
      <pubDate>Mon, 04 Apr 2011 09:13:00 +0000</pubDate>
      
      <guid>/questions/3323/printing-tcp-payload-using-tshark-t-fields/</guid>
      <description>Printing tcp payload using tshark -T fields?  0 Hi all,
I&#39;m trying to print out the first 20 TCP payload bytes in tshark, but I want to print out several other fields so that I can pass the result to an analysis program I&#39;m writing. Easiest way for me to parse the data is CSV, so I&#39;m using tshark in -T fields mode with -E separator=,
So I have additional options such as -e tcp.</description>
    </item>
    
    <item>
      <title>How to resolve addresses in Wireshark?</title>
      <link>/questions/3326/how-to-resolve-addresses-in-wireshark/</link>
      <pubDate>Mon, 04 Apr 2011 10:41:00 +0000</pubDate>
      
      <guid>/questions/3326/how-to-resolve-addresses-in-wireshark/</guid>
      <description>How to resolve addresses in Wireshark?  0 I am trying to open a .cap file using Wireshark. I am facing problems with respect to the source and destination IP addresses. I obtained this .cap file by capturing network traffic using Microsoft Network Monitor. The .cap file when opened in Network Monitor displays the corresponding IP addresses. How to I obtain the same in Wireshark?
display-filterasked 04 Apr &#39;11, 10:41</description>
    </item>
    
    <item>
      <title>Get SNR from WLAN capture.</title>
      <link>/questions/3330/get-snr-from-wlan-capture/</link>
      <pubDate>Mon, 04 Apr 2011 12:31:00 +0000</pubDate>
      
      <guid>/questions/3330/get-snr-from-wlan-capture/</guid>
      <description>Get SNR from WLAN capture.  0 I&#39;m trying to compare Omnipeek to Wireshark/AirPCap.
I downloaded a few 802.11 captures from sample section so I&#39;m just trying to compare the 2, omnipeek has column for SNR dBm and I am trying to see if wireshark can display the same SNR from the wireless clients.
If anyone is running AirPcap are you able to easily the SNR value of your 802.11 clients?</description>
    </item>
    
    <item>
      <title>export packet decode via GUI</title>
      <link>/questions/3332/export-packet-decode-via-gui/</link>
      <pubDate>Mon, 04 Apr 2011 15:50:00 +0000</pubDate>
      
      <guid>/questions/3332/export-packet-decode-via-gui/</guid>
      <description>export packet decode via GUI  0 I&#39;ve been using Tshark line like this a lot lately:
tshark.exe -r somefile.pcap -R &#39;frame.number==5&#39; -V
which gives me a nice complete plaintext decode of a single frame. I&#39;m sure there must be a way to get the whole packet decode as plain text in the GUI after applying the display filter, but I just can&#39;t find it. What am I missing?
text tsharkasked 04 Apr &#39;11, 15:50</description>
    </item>
    
    <item>
      <title>config.nmake(935) : fatal error U105 when verifying tools</title>
      <link>/questions/3344/confignmake935-fatal-error-u105-when-verifying-tools/</link>
      <pubDate>Tue, 05 Apr 2011 07:37:00 +0000</pubDate>
      
      <guid>/questions/3344/confignmake935-fatal-error-u105-when-verifying-tools/</guid>
      <description>config.nmake(935) : fatal error U105 when verifying tools  0 Hi all,
I am trying to enhance wireshark for a protocol for a properitary information. I have installed everything according to developer guide and trying to verify tools.
I am getting an error config.nmake(935) : fatal error U1050: Can&#39;t find C:wireshark-win32-libsvcredi st_x86.exe. Have you downloaded it from Microsoft? See the developer&#39;s guide sec tion &#34;C-Runtime &#34;Redistributable&#34; files&#34; for details how to get it Stop.</description>
    </item>
    
    <item>
      <title>Error Opening file for Writing... wireTap-0.3.1.dll</title>
      <link>/questions/3347/error-opening-file-for-writing-wiretap-031dll/</link>
      <pubDate>Tue, 05 Apr 2011 11:14:00 +0000</pubDate>
      
      <guid>/questions/3347/error-opening-file-for-writing-wiretap-031dll/</guid>
      <description>Error Opening file for Writing&amp;hellip; wireTap-0.3.1.dll  0 I downloaded Wireshark 1.4.4 (64-bit) and ran setup, but am getting an error about opening file for writing file wiretap-0.3.1.dll
wiretap-0.3.1.dll setup windows7 64-bitasked 05 Apr &#39;11, 11:14
Harryw411
1●1●1●1
accept rate: 0%
 edited 29 Feb &#39;12, 18:53 
cmaynard ♦♦
9.4k●10●38●142
Can you be more specific? It will be easier to find out what is going wrong if you can post the actual error message you receive.</description>
    </item>
    
    <item>
      <title>How do I force packet coloring rules?</title>
      <link>/questions/3351/how-do-i-force-packet-coloring-rules/</link>
      <pubDate>Tue, 05 Apr 2011 11:34:00 +0000</pubDate>
      
      <guid>/questions/3351/how-do-i-force-packet-coloring-rules/</guid>
      <description>How do I force packet coloring rules?  1 1I&#39;m working on the FAST protocol dissector for wireshark, and I want to make it so that packets containing errors are colored red for the users. I know how to do it by modifying my coloring rules filter, but is there a way to force this change on any user using my plugin (so that they don&#39;t have to manually alter the coloring rules)?</description>
    </item>
    
    <item>
      <title>copying vcredist_x86.exe for MS VS 2008 Express</title>
      <link>/questions/3352/copying-vcredist_x86exe-for-ms-vs-2008-express/</link>
      <pubDate>Tue, 05 Apr 2011 13:08:00 +0000</pubDate>
      
      <guid>/questions/3352/copying-vcredist_x86exe-for-ms-vs-2008-express/</guid>
      <description>copying vcredist_x86.exe for MS VS 2008 Express  0 Hi, I am facing one error while installing. I am using Visual Studio Express 2008 and getting one error in setup. When i see config.nmake, there is one comment.
ELSEIF &#34;$(MSVC_VARIANT)&#34; == &#34;MSVC2005EE&#34; || &#34;$(MSVC_VARIANT)&#34; == &#34;DOTNET20&#34; || &#34;$(MSVC_VARIANT)&#34; == &#34;MSVC2008EE&#34;
you need to download the redistributable package vcredist_x86.exe from Microsoft first,and copy it to the lib folder!!!I have downloaded vcredist.x86.exe but where should it be copied?</description>
    </item>
    
    <item>
      <title>how to analyse the packets ?</title>
      <link>/questions/3358/how-to-analyse-the-packets/</link>
      <pubDate>Tue, 05 Apr 2011 14:37:00 +0000</pubDate>
      
      <guid>/questions/3358/how-to-analyse-the-packets/</guid>
      <description>how to analyse the packets ?  0 im new to wire shark and i want a easy description how to analyse the packets. help me if you can.
packetsasked 05 Apr &#39;11, 14:37
Prince Vakas
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Try starting with the user&#39;s guide.
answered 05 Apr &#39;11, 18:10
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%
  
0... Or watch a video or two.</description>
    </item>
    
    <item>
      <title>&amp;#x27;--disable-glibtest&amp;#x27; not working</title>
      <link>/questions/3360/-disable-glibtest-not-working/</link>
      <pubDate>Tue, 05 Apr 2011 15:53:00 +0000</pubDate>
      
      <guid>/questions/3360/-disable-glibtest-not-working/</guid>
      <description>&#39;&amp;ndash;disable-glibtest&#39; not working  0 Trying to run configure without having to test for gtk and glib like so:
./configure --enable-wireshark=no --disable-glibtestBut at one point in the log it&#39;ll give me this and fail:
checking for GLIB - version &amp;gt;= 2.4.0... no Could not run GLIB test program, checking why... Could not run GLIB test program, checking why... The test program failed to compile or link. See the file config.log for the exact error that occured.</description>
    </item>
    
    <item>
      <title>How to Find the input error(overrun) from the logs</title>
      <link>/questions/3366/how-to-find-the-input-erroroverrun-from-the-logs/</link>
      <pubDate>Wed, 06 Apr 2011 00:42:00 +0000</pubDate>
      
      <guid>/questions/3366/how-to-find-the-input-erroroverrun-from-the-logs/</guid>
      <description>How to Find the input error(overrun) from the logs  0 Hi I have a large file of the logs captured from an Gig interface. The other side we have a CISCO 7206VXR router where we see the overrun counter increasing.
How do I identify which packets causing the overrun problem?
Could you please Help me?
Regards Siva
overrunasked 06 Apr &#39;11, 00:42
Siva
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Error running wireshark on HP-UX</title>
      <link>/questions/3368/error-running-wireshark-on-hp-ux/</link>
      <pubDate>Wed, 06 Apr 2011 02:37:00 +0000</pubDate>
      
      <guid>/questions/3368/error-running-wireshark-on-hp-ux/</guid>
      <description>Error running wireshark on HP-UX  0 Hi All! i&#39;m getting this error message everytime i try to run wireshark on my HP-UX machine running HP-UX 11i v2 Operating System: ========================================================Start-of-Error-Message
./wireshark(wireshark:17651): GLib-GObject-WARNING **: specified class size for type PangoXftFontMap&#39; is smaller than the parent type&#39;sPangoFcFontMap&#39; class size
(wireshark:17651): GLib-GObject-CRITICAL **: file gobject.c: line 1304: assertion `G_TYPE_IS_OBJECT (object_type)&#39; failed Memory fault(coredump)
========================================================End-of-Error-Message
anybody can help me to solve this?
pangoxftfontmapasked 06 Apr &#39;11, 02:37</description>
    </item>
    
    <item>
      <title>HMAC-MD5-96 SNMPv3 TRAP</title>
      <link>/questions/3369/hmac-md5-96-snmpv3-trap/</link>
      <pubDate>Wed, 06 Apr 2011 04:04:00 +0000</pubDate>
      
      <guid>/questions/3369/hmac-md5-96-snmpv3-trap/</guid>
      <description>HMAC-MD5-96 SNMPv3 TRAP  0 Hi,
Is it possible to decrypt HMAC-MD5-96 SNMP Traps (Port 162) in Wirehark? I just want to check the structure of the trap to make sure it is formatted correctly. I have tried adding in the authentication and privacy string into the SNMP Protocol Preferences in the format x..x.. etc but it does not decode the packet correctly.
Any advice/guideance would be appreciated.
Regards James.</description>
    </item>
    
    <item>
      <title>USB or Mini PCIe NIC for Wireshark? HELP!</title>
      <link>/questions/3376/usb-or-mini-pcie-nic-for-wireshark-help/</link>
      <pubDate>Wed, 06 Apr 2011 08:13:00 +0000</pubDate>
      
      <guid>/questions/3376/usb-or-mini-pcie-nic-for-wireshark-help/</guid>
      <description>USB or Mini PCIe NIC for Wireshark? HELP!  0 Does anyone know of a good mini half card for a laptop or usb NIC that supports raw, monitoring, or promiscuous mode? I am not having any luck on manufacturors websites or through email help.
wireless nic promiscuous laptop usbasked 06 Apr &#39;11, 08:13
are_we_hvn_f...
1●1●1●1
accept rate: 0% 
  
One Answer:
  
2Most if not all Ethernet adapters should support promiscuous mode.</description>
    </item>
    
    <item>
      <title>How to reassemble packet in text-based protocol</title>
      <link>/questions/3379/how-to-reassemble-packet-in-text-based-protocol/</link>
      <pubDate>Wed, 06 Apr 2011 09:34:00 +0000</pubDate>
      
      <guid>/questions/3379/how-to-reassemble-packet-in-text-based-protocol/</guid>
      <description>How to reassemble packet in text-based protocol  0 1I have created a dissector for a line-based protocol but have some problems when data are bigger than packet size. When the data is too big, I need to reassemble a number of packets to have a complete data before processing it. Here you can find a part of my dissector. I need your help for if (packet_end != 0x0A){} else {}.</description>
    </item>
    
    <item>
      <title>enhancing dissector</title>
      <link>/questions/3380/enhancing-dissector/</link>
      <pubDate>Wed, 06 Apr 2011 13:48:00 +0000</pubDate>
      
      <guid>/questions/3380/enhancing-dissector/</guid>
      <description>enhancing dissector  0 Hello,
I need to enhance wireshark for some proprietary information. I need to use this function dissector_try_uint_new present in packet.c. It checks the value in a given uint dissector table and, if found, call the dissector with the arguments supplied.
Is there any example of adding a function pointer in table passed to this function? I know that this is very specific question and i am sorry for asking this.</description>
    </item>
    
    <item>
      <title>Any help to decode an encrypted POST</title>
      <link>/questions/3381/any-help-to-decode-an-encrypted-post/</link>
      <pubDate>Wed, 06 Apr 2011 14:18:00 +0000</pubDate>
      
      <guid>/questions/3381/any-help-to-decode-an-encrypted-post/</guid>
      <description>Any help to decode an encrypted POST  0 I may have some data loss to Romania. How can I decode what I have magaged to capture? Thanks in advance. Please teach me so I can apply this to future captures. And maybe help others.
POST /news/ HTTP/1.1 Accept: */* User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.0.04506.30; InfoPath.1; .NET4.0C; .NET CLR 3.</description>
    </item>
    
    <item>
      <title>same field name different columns?</title>
      <link>/questions/3386/same-field-name-different-columns/</link>
      <pubDate>Thu, 07 Apr 2011 07:52:00 +0000</pubDate>
      
      <guid>/questions/3386/same-field-name-different-columns/</guid>
      <description>same field name different columns?  0 In IEC61850 sampled values frames we have the same field repeated several times (for example sv.meas_value). the first one is for the current of phase A, 2º for current in phase B... How can i display as a column the 2º, 3º... sv.meas_value?? if i try to apply as column always appears the first value (current pahase A).
columnsasked 07 Apr &#39;11, 07:52</description>
    </item>
    
    <item>
      <title>Input for a dissector</title>
      <link>/questions/3398/input-for-a-dissector/</link>
      <pubDate>Thu, 07 Apr 2011 23:32:00 +0000</pubDate>
      
      <guid>/questions/3398/input-for-a-dissector/</guid>
      <description>Input for a dissector  1 1Hi,
I&#39;m writing a dissector for Wireshark with lua. (not the first).
But I have the following problem. Analyzing the data that I want to be split among the TCP level is already to some extent by an ISO 8075.(COPT Protocol) And I just want to be among the Datadump. Use for my dissector.
Currently I use: tcp_encap_table DissectorTable.get = (&#34;tcp.port) tcp_encap_table: add (102, matze_proto) Here I get data data I do not want to use.</description>
    </item>
    
    <item>
      <title>protocol changing</title>
      <link>/questions/3400/protocol-changing/</link>
      <pubDate>Fri, 08 Apr 2011 00:09:00 +0000</pubDate>
      
      <guid>/questions/3400/protocol-changing/</guid>
      <description>protocol changing  0 hi plz can i change the default protocol used for some application i.e i want to send a file to some one by default it will be supported using tcp protocol but i want to change this and make it UDP for example can i do this and how? by any way using wireshark or any otherway?
changing protocolasked 08 Apr &#39;11, 00:09
flower
1●3●3●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>get all rtp streams</title>
      <link>/questions/3401/get-all-rtp-streams/</link>
      <pubDate>Fri, 08 Apr 2011 02:34:00 +0000</pubDate>
      
      <guid>/questions/3401/get-all-rtp-streams/</guid>
      <description>get all rtp streams  0 Hi guys,
i have a capture with ~100 streams, i&#39;d like to automaticly export them all. -save payload in bothways, in au-format
Is this possible?
Br Sebastian
auto rtp stream payloadasked 08 Apr &#39;11, 02:34
elefantungen
1●1●1●2
accept rate: 0%
  
One Answer:
  
0See this question.
answered 08 Apr &#39;11, 03:44
Jaap ♦
11.7k●16●101
accept rate: 14%
     </description>
    </item>
    
    <item>
      <title>decode as feature set up before start a cap</title>
      <link>/questions/3406/decode-as-feature-set-up-before-start-a-cap/</link>
      <pubDate>Fri, 08 Apr 2011 06:59:00 +0000</pubDate>
      
      <guid>/questions/3406/decode-as-feature-set-up-before-start-a-cap/</guid>
      <description>decode as feature set up before start a cap  0 Hi all, is it possible to set up a capture filter in wireshark for the decode as feature just like tshark -d option i.e. -d udp.port==8000,rudp, before to start capture ?
decode capture-filterThis question is marked &#34;community wiki&#34;.asked 08 Apr &#39;11, 06:59
flap78
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1You could do that using lua</description>
    </item>
    
    <item>
      <title>Controlling output in packet detail pane</title>
      <link>/questions/3407/controlling-output-in-packet-detail-pane/</link>
      <pubDate>Fri, 08 Apr 2011 10:32:00 +0000</pubDate>
      
      <guid>/questions/3407/controlling-output-in-packet-detail-pane/</guid>
      <description>Controlling output in packet detail pane  0 Is there a way to customize the output of the packet detail pane?
What I&#39;d like to do is be able to inspect certain fields of a protocol within a packet for a set of packets (conversation, all IP, all tftp, all from address to address...). I know I can do some drill down manually on a per packet basis but even the control of the format that way is limited.</description>
    </item>
    
    <item>
      <title>Pilot burst bandwidth report when capturing on a server</title>
      <link>/questions/3410/pilot-burst-bandwidth-report-when-capturing-on-a-server/</link>
      <pubDate>Sat, 09 Apr 2011 14:13:00 +0000</pubDate>
      
      <guid>/questions/3410/pilot-burst-bandwidth-report-when-capturing-on-a-server/</guid>
      <description>Pilot burst bandwidth report when capturing on a server  0 I installed WireShark on a streaming media server to perform a capture. This server is on its own switch port, but in a ip subnet that has other servers. So the streaming media server can see traffic intended for other servers, yet it is on its own 1Gigabit link to the switch.
So here’s my question: when the burst bandwidth report (1ms) says the bandwidth in this capture is bursting to 1.</description>
    </item>
    
    <item>
      <title>network tap</title>
      <link>/questions/3413/network-tap/</link>
      <pubDate>Sat, 09 Apr 2011 19:15:00 +0000</pubDate>
      
      <guid>/questions/3413/network-tap/</guid>
      <description>network tap  0 1Hi,
I see mention of using a network tap many places, but I haven&#39;t found anywhere to purchase one. Can somebody make a recommendation based on good personal experience?
Thanks.
tapasked 09 Apr &#39;11, 19:15
eelarry
36●8●9●12
accept rate: 0%
  
3 Answers:
  
6 There are a number of vendors that sell those, and I have personally used TAPs from those vendors:</description>
    </item>
    
    <item>
      <title>How do I download the wire shark tutorials videos given on the homepage</title>
      <link>/questions/3422/how-do-i-download-the-wire-shark-tutorials-videos-given-on-the-homepage/</link>
      <pubDate>Sun, 10 Apr 2011 08:22:00 +0000</pubDate>
      
      <guid>/questions/3422/how-do-i-download-the-wire-shark-tutorials-videos-given-on-the-homepage/</guid>
      <description>How do I download the wire shark tutorials videos given on the homepage  0 How do I download the wire shark tutorials videos given on the homepage?
Thanks
download videos wiresharkasked 10 Apr &#39;11, 08:22
pankaj
1●1●1●1
accept rate: 0%
I want to download this video and similar videos http://wiresharkdownloads.riverbed.com/video/wireshark/introduction-to-wireshark/
Thanks
(10 Apr &#39;11, 08:23) pankaj  
One Answer:
  
1You can use Wireshark to do the trick.</description>
    </item>
    
    <item>
      <title>MAC address Question on the capture file</title>
      <link>/questions/3426/mac-address-question-on-the-capture-file/</link>
      <pubDate>Sun, 10 Apr 2011 12:36:00 +0000</pubDate>
      
      <guid>/questions/3426/mac-address-question-on-the-capture-file/</guid>
      <description>MAC address Question on the capture file  0 Hello. My professor gave us an homework about wireshark so i am kinda new to this application. I dowloaded the wireshark. My professor sent a .pcap (capture file) to answer the following questions on the homework. So my question is, how do you check the MAC address for the wireless network card in an IP address on the .pcap (captured file) sent by my professor?</description>
    </item>
    
    <item>
      <title>supporting protocol SPDY</title>
      <link>/questions/3428/supporting-protocol-spdy/</link>
      <pubDate>Sun, 10 Apr 2011 13:47:00 +0000</pubDate>
      
      <guid>/questions/3428/supporting-protocol-spdy/</guid>
      <description>supporting protocol SPDY  0 When support SPDY (from Google)? Google Chrome support this protocol on pages Google ( (GMail, Calendar, Picasa, Maps, Hotpot, etc)
Docs: SPDY - The Chromium Projectshttp://www.chromium.org/spdy
spdy chrome google speedyasked 10 Apr &#39;11, 13:47
Dzakus
1●1●1●1
accept rate: 0%
  
One Answer:
  
1I just checked the SPDY page and it says:
Wireshark SPDY extension The wireshark extension needs some love. You&#39;ll find it checked into the chromium source tree under net/tools.</description>
    </item>
    
    <item>
      <title>Protection from protocol analyzers like wireshark</title>
      <link>/questions/3434/protection-from-protocol-analyzers-like-wireshark/</link>
      <pubDate>Sun, 10 Apr 2011 17:27:00 +0000</pubDate>
      
      <guid>/questions/3434/protection-from-protocol-analyzers-like-wireshark/</guid>
      <description>Protection from protocol analyzers like wireshark  0 How can i protect my computer from people who try to capture or sniff my computer from protocol analyzers? Just wondering..
protectasked 10 Apr &#39;11, 17:27
kv2004
1●2●2●2
accept rate: 0%
 edited 26 Feb &#39;12, 22:28 
cmaynard ♦♦
9.4k●10●38●142
  
3 Answers:
  
1Keep them away from your Switches and routers. If they don&#39;t have physical access to your infrastructure and do not know the administrative passwords to configure monitor ports they&#39;re not going to sniff your computer (except maybe broadcasts, which aren&#39;t usually that exciting to capture).</description>
    </item>
    
    <item>
      <title>capture shows other hosts information</title>
      <link>/questions/3437/capture-shows-other-hosts-information/</link>
      <pubDate>Mon, 11 Apr 2011 02:28:00 +0000</pubDate>
      
      <guid>/questions/3437/capture-shows-other-hosts-information/</guid>
      <description>capture shows other hosts information  0 Hi,
I started wireshark on my notebook to capture what was going on my NIC, but I am surprised to see other hosts communications not destinated for my NIC as well (note that my switchport is not configured in span mode). I am having ip address of 172.16.224.162.
Address A,Address B,Packets,Bytes,Packets A-&amp;gt;B,Bytes A-&amp;gt;B,Packets A&amp;lt;-B,Bytes A&amp;lt;-B,Rel Start,Duration,bps A-&amp;gt;B,bps A&amp;lt;-B 172.25.219.2,224.0.0.10,17,1258,17,1258,0,0,0.057954000,73.6765,136.60,N/A 172.16.224.129,224.0.0.10,17,1258,17,1258,0,0,3.172119000,72.4497,138.91,N/A 172.16.224.162,172.25.218.16,111,33433,53,10370,58,23063,4.771098000,61.9298,1339.58,2979.24 172.16.224.162,172.25.221.18,9,1534,6,964,3,570,16.455411000,60.7066,127.04,75.12 172.16.224.209,172.25.221.18,2,120,0,0,2,120,18.893031000,0.0021,N/A,458891.01 172.</description>
    </item>
    
    <item>
      <title>track tcp established connections on  a particular port</title>
      <link>/questions/3442/track-tcp-established-connections-on-a-particular-port/</link>
      <pubDate>Mon, 11 Apr 2011 09:05:00 +0000</pubDate>
      
      <guid>/questions/3442/track-tcp-established-connections-on-a-particular-port/</guid>
      <description>track tcp established connections on a particular port  0 Is there a tool out there that can show me the # of established connections, per second, on a specific port?
We have an application that listens on a custom port that was developed by a 3rd party. there&#39;s no internal tools provided by them that tracks the # of established socketed connections to a specific port. THey&#39;re using a Java SocketServer Class library, but i don&#39;t know much more than that.</description>
    </item>
    
    <item>
      <title>Child capture process exited: exited status 127</title>
      <link>/questions/3443/child-capture-process-exited-exited-status-127/</link>
      <pubDate>Mon, 11 Apr 2011 10:23:00 +0000</pubDate>
      
      <guid>/questions/3443/child-capture-process-exited-exited-status-127/</guid>
      <description>Child capture process exited: exited status 127  0 I am working on Ubuntu 10.10 and wireshark 1.2.11. Every time I choose an interface to start captureing, i got the error ¨Child capture process exited: exited status 127¨. Does anybody have any solutions?
thanks Levi
captureasked 11 Apr &#39;11, 10:23
LeviVic
1●2●2●3
accept rate: 0%
  
One Answer:
  
0Since you are most likely using Bash, this is probably a &#34;</description>
    </item>
    
    <item>
      <title>Getting tshark to output reports seen in Wireshark?</title>
      <link>/questions/3448/getting-tshark-to-output-reports-seen-in-wireshark/</link>
      <pubDate>Mon, 11 Apr 2011 12:03:00 +0000</pubDate>
      
      <guid>/questions/3448/getting-tshark-to-output-reports-seen-in-wireshark/</guid>
      <description>Getting tshark to output reports seen in Wireshark?  0 In Wireshark I can pull down Statistics and go to Conversation Lists / TCP and get a nice report with packet and byte counts, stations &amp;amp; ports as well as start times and durations.
How can I get this same report from tshark? Using -z conv,tcp gets me some of it but not all.
Plus, my captures are too big and Wireshark keeps bombing out.</description>
    </item>
    
    <item>
      <title>BitTorrent capture</title>
      <link>/questions/3449/bittorrent-capture/</link>
      <pubDate>Mon, 11 Apr 2011 12:27:00 +0000</pubDate>
      
      <guid>/questions/3449/bittorrent-capture/</guid>
      <description>BitTorrent capture  0 does anybody know how wireshark identify p2p traffic? Port number? or payload checking?
capture.bittorrentasked 11 Apr &#39;11, 12:27
LeviVic
1●2●2●3
accept rate: 0%
  
One Answer:
  
2The bittorrent dissector registers itself as a heuristic dissector to tcp. The heuristic works by first ensuring that the TCP payload is at least 20 bytes in length, that the first byte is equal to the value of 19 (0x13), and that the 19 bytes following that value are equal to the string, &#34;</description>
    </item>
    
    <item>
      <title>TCP 3 three way handshake</title>
      <link>/questions/3452/tcp-3-three-way-handshake/</link>
      <pubDate>Mon, 11 Apr 2011 13:16:00 +0000</pubDate>
      
      <guid>/questions/3452/tcp-3-three-way-handshake/</guid>
      <description>TCP 3 three way handshake  0 I have captured my personal network through wireshark.. now i want to know the TCP three-way-shandshake information. Where do i go and how to filter the TCP three-way-handshake. Thank
meowasked 11 Apr &#39;11, 13:16
kv2004
1●2●2●2
accept rate: 0%
  
One Answer:
  
1The easy way is to right click a packet in a stream and choose follow tcp stream.</description>
    </item>
    
    <item>
      <title>get_field_data: code should not be reached (PDML File)</title>
      <link>/questions/3453/get_field_data-code-should-not-be-reached-pdml-file/</link>
      <pubDate>Mon, 11 Apr 2011 13:30:00 +0000</pubDate>
      
      <guid>/questions/3453/get_field_data-code-should-not-be-reached-pdml-file/</guid>
      <description>get_field_data: code should not be reached (PDML File)  0 Hello all--
I am trying to export pdml using wireshark for a trace containing h245 traffic. The export from GUI crashes while trying to export.
I then tried tshark -r tandberg.pcap -T pdml; It gave me error
ERROR:print.c:715:get_field_data: code should not be reached
I have tried to search the error and a bug report was filed
http://www.mail-archive.com/[email protected]/msg22849.html
It does say that -V should be able to handle it, however, the output generated with -V option does not contain XML file.</description>
    </item>
    
    <item>
      <title>How to extract packets related to different internet applications from mixture of packets captured by wireshark?</title>
      <link>/questions/3462/how-to-extract-packets-related-to-different-internet-applications-from-mixture-of-packets-captured-by-wireshark/</link>
      <pubDate>Tue, 12 Apr 2011 05:24:00 +0000</pubDate>
      
      <guid>/questions/3462/how-to-extract-packets-related-to-different-internet-applications-from-mixture-of-packets-captured-by-wireshark/</guid>
      <description>How to extract packets related to different internet applications from mixture of packets captured by wireshark?  0 My problem is to separate packets related to multiple applications from all packets captured by wireshark when multiple applications are running over internet. Is there any way to extract or isolate packets according to application type such as www, mail, multimedia, p2p etc. plz reply me
extraction multiple packet applicationsasked 12 Apr &#39;11, 05:24</description>
    </item>
    
    <item>
      <title>Latest Wireshark 1.4.4 not shown &amp;quot;Granted QoS&amp;quot; field existed in RNC A11 packet</title>
      <link>/questions/3465/latest-wireshark-144-not-shown-granted-qos-field-existed-in-rnc-a11-packet/</link>
      <pubDate>Tue, 12 Apr 2011 10:49:00 +0000</pubDate>
      
      <guid>/questions/3465/latest-wireshark-144-not-shown-granted-qos-field-existed-in-rnc-a11-packet/</guid>
      <description>Latest Wireshark 1.4.4 not shown &amp;ldquo;Granted QoS&amp;rdquo; field existed in RNC A11 packet  0 Hi,
I opened the file A11-RNC-PCF.pcap with Wireshark 0.99.5 and found the ‘Granted QoS’ field in the A11 Reg Request packet from RNC to PDSN. But unfortunately if I used Wireshark version 1.4.4 there are not such field existed!? It quite mislead our customers who used latest version of Wireshark. Is this some bug? Below is parsed part of Wireshark output:</description>
    </item>
    
    <item>
      <title>Can rpmbuild be used to create a tshark package?</title>
      <link>/questions/3466/can-rpmbuild-be-used-to-create-a-tshark-package/</link>
      <pubDate>Tue, 12 Apr 2011 11:58:00 +0000</pubDate>
      
      <guid>/questions/3466/can-rpmbuild-be-used-to-create-a-tshark-package/</guid>
      <description>Can rpmbuild be used to create a tshark package?  0 I&#39;ve been using rpmbuild to create a wireshark rpm that includes a plugin I&#39;ve made. This works fine but I want to create a tshark only package that can run on a server.
I used this configure command in the spec file:
./configure --host=x86_64-unknown-linux-gnu --build=x86_64-unknown-linux-gnu --program-prefix= --prefix=/usr --exec-prefix=/usr --bindir=/usr/bin --sbindir=/usr/sbin --sysconfdir=/etc --datadir=/usr/share --includedir=/usr/include --libdir=/usr/lib64 --libexecdir=/usr/lib --localstatedir=/var --sharedstatedir=/usr/com --mandir=/usr/share/man --infodir=/usr/share/info --disable-wireshark --disable-editcap --disable-capinfos --disable-mergecap --disable-text2pcap --disable-idl2wrs --disable-dftest --disable-randpkt --disable-rawsharkBut I get the following error once rpmbuild gets to the install part:</description>
    </item>
    
    <item>
      <title>TDS: Malformed Packet</title>
      <link>/questions/3475/tds-malformed-packet/</link>
      <pubDate>Wed, 13 Apr 2011 01:30:00 +0000</pubDate>
      
      <guid>/questions/3475/tds-malformed-packet/</guid>
      <description>TDS: Malformed Packet  0 Good morning,
When analyzing a trace I found this message for more I look online I find esponse to what is past, and if the error is real or not. Can you help?
[Malformed Packet: TDS] Expert Info (Error/Malformed): Malformed Packet (Exception occurred) Message: Malformed Packet (Exception occurred) Severity level: Error Group: Malformed I have, Windows Server 2003 and SQL Server 2005. Thanks.
tds malformedasked 13 Apr &#39;11, 01:30</description>
    </item>
    
    <item>
      <title>Can only see outgoing traffic and broadcast frames</title>
      <link>/questions/3476/can-only-see-outgoing-traffic-and-broadcast-frames/</link>
      <pubDate>Wed, 13 Apr 2011 02:39:00 +0000</pubDate>
      
      <guid>/questions/3476/can-only-see-outgoing-traffic-and-broadcast-frames/</guid>
      <description>Can only see outgoing traffic and broadcast frames  0 Hello All, I am trying to smiff my network using a hub on my Router&#39;s LAN port. However, I can only see Local LAn frames, Frames originated from the LAN, broadcasts, but no frames comming from other hosts outside the LAN. (When the outside traffic is on my PC I can capture it)
Note that I used another PC on the same HUB and it captures all the traffic successfully.</description>
    </item>
    
    <item>
      <title>plain text comments in Wireshark packet list pane</title>
      <link>/questions/3477/plain-text-comments-in-wireshark-packet-list-pane/</link>
      <pubDate>Wed, 13 Apr 2011 04:58:00 +0000</pubDate>
      
      <guid>/questions/3477/plain-text-comments-in-wireshark-packet-list-pane/</guid>
      <description>plain text comments in Wireshark packet list pane  0 I am relatively new to Wireshark.
I am generating packets from our test platform. These are being correctly decoded by Wireshark. They happen to be &#34;mac-lte&#34; packets, but isn&#39;t relevant for question I have...
I would like to interleave the generated packets with comments/logs packets, with the Wireshark decoded comments being displayed in the packet list pane (the top pane in the Wireshark GUI, showing a summary of the packets decoded).</description>
    </item>
    
    <item>
      <title>Wireshark capture stops on its own while using AirPcap adapter</title>
      <link>/questions/3478/wireshark-capture-stops-on-its-own-while-using-airpcap-adapter/</link>
      <pubDate>Wed, 13 Apr 2011 05:04:00 +0000</pubDate>
      
      <guid>/questions/3478/wireshark-capture-stops-on-its-own-while-using-airpcap-adapter/</guid>
      <description>Wireshark capture stops on its own while using AirPcap adapter  0 While running Wireshark capture using AirPcap Adapters, the capture will stop on its own, so I can&#39;t capture data for long periods of time. This has been an on going problem for me, and I have already gone through CACE Technologies for help, but they insist that it is a Wireshark issue. Is this a known issue and is there a solution to this problem?</description>
    </item>
    
    <item>
      <title>could the file name parameter in tshark be chinese characters?</title>
      <link>/questions/3479/could-the-file-name-parameter-in-tshark-be-chinese-characters/</link>
      <pubDate>Wed, 13 Apr 2011 07:47:00 +0000</pubDate>
      
      <guid>/questions/3479/could-the-file-name-parameter-in-tshark-be-chinese-characters/</guid>
      <description>could the file name parameter in tshark be chinese characters?  0 when I use tshark -r chinese-characters.cap such as &#34;tshark -r 中文.cap&#34; It says that the file name is invalid. How could I resolve this problem?
thanks
characters tshark chineseasked 13 Apr &#39;11, 07:47
janequeen
1●1●1●2
accept rate: 0%
  
One Answer:
  
1The obvious workaround is to either rename the file before opening it with tshark (or create a link or shortcut to the original file).</description>
    </item>
    
    <item>
      <title>How to capture ftp traffic over ssh?</title>
      <link>/questions/3487/how-to-capture-ftp-traffic-over-ssh/</link>
      <pubDate>Wed, 13 Apr 2011 09:52:00 +0000</pubDate>
      
      <guid>/questions/3487/how-to-capture-ftp-traffic-over-ssh/</guid>
      <description>How to capture ftp traffic over ssh?  0 I am new to wireshark. I have downloaded wireshark in my machine and I am using Windows Vista. I am trying to capture ftp traffic between 2 local hosts by executing some ftp commands in SSH terminal. I need wireshark in my machine to capture that traffic. How to configure wireshark for that. Kindly help.
ftp sshasked 13 Apr &#39;11, 09:52</description>
    </item>
    
    <item>
      <title>tshark plugin for tunelled ethernet payload</title>
      <link>/questions/3490/tshark-plugin-for-tunelled-ethernet-payload/</link>
      <pubDate>Wed, 13 Apr 2011 16:32:00 +0000</pubDate>
      
      <guid>/questions/3490/tshark-plugin-for-tunelled-ethernet-payload/</guid>
      <description>tshark plugin for tunelled ethernet payload  0 Hello!
I am writing a tshark plug-in for a proprietary protocol with ethernet type 0x8787. The plug-in is supposed to dissect frames coming onto an ethernet interface with the below format:
Dst Mac | Src Mac | type | Custom Hdr &amp;lt;12 bytes&amp;gt; | Dst Mac | Src Mac | type | &amp;lt; ethernet body &amp;gt; |I am able to dissect frames until the end of the custom header.</description>
    </item>
    
    <item>
      <title>Rallink 802.11n wireless LAN card</title>
      <link>/questions/3492/rallink-80211n-wireless-lan-card/</link>
      <pubDate>Wed, 13 Apr 2011 19:23:00 +0000</pubDate>
      
      <guid>/questions/3492/rallink-80211n-wireless-lan-card/</guid>
      <description>Rallink 802.11n wireless LAN card  1 my wireless is support for wireshark or not??.. help me... wireshark cannot detect my wireless driver...
wireless interfaces 802.11 compatibility 802.11nasked 13 Apr &#39;11, 19:23
ogatatsumi
16●1●1●2
accept rate: 0%
 retagged 08 Jun &#39;11, 19:46 
helloworld
3.1k●4●20●41
  
One Answer:
  
-1YES,HELP ME DOWNLOAD IT
answered 08 Jun &#39;11, 13:21
denny
0●1
accept rate: 0%
     </description>
    </item>
    
    <item>
      <title>Incorrect Header checksum for all outbound packets from Ethernet adapter</title>
      <link>/questions/3495/incorrect-header-checksum-for-all-outbound-packets-from-ethernet-adapter/</link>
      <pubDate>Thu, 14 Apr 2011 04:23:00 +0000</pubDate>
      
      <guid>/questions/3495/incorrect-header-checksum-for-all-outbound-packets-from-ethernet-adapter/</guid>
      <description>Incorrect Header checksum for all outbound packets from Ethernet adapter  0 Hi,
I captured all the packets from my computer for Ethernet card.
I noticed for all the packets with source IP as my ethernet card IP got Header checksum error. I tried disabling the Checksum offload on my NIC. Also tried updating the NIC driver. Even on Wireshark the TCP prefernce is disabled for &#34;Validate TCP checksum if possible&#34;</description>
    </item>
    
    <item>
      <title>Time slicing captured files - editcap</title>
      <link>/questions/3501/time-slicing-captured-files-editcap/</link>
      <pubDate>Thu, 14 Apr 2011 10:11:00 +0000</pubDate>
      
      <guid>/questions/3501/time-slicing-captured-files-editcap/</guid>
      <description>Time slicing captured files - editcap  0 I&#39;m trying to time slice of a captured file.
using editcap &amp;lt;file_in&amp;gt; &amp;lt;file_out&amp;gt; I get the whole input file.
Using editcp -r &amp;lt;file_in&amp;gt; &amp;lt;file_out&amp;gt; I get the output file with only a couple lines of data.
Using editcp -r -A -B yyyy-mm-dd hh:mm:ss yyyy-mm-dd hh:mm:ss &amp;lt;file_in&amp;gt; &amp;lt;file_out&amp;gt; I get error feedback of incorrect DTG.
Using editcp -r -A -B yyyy-mm-ddhh:mm:ss yyyy-mm-ddhh:mm:ss &amp;lt;file_in&amp;gt; &amp;lt;file_out&amp;gt; I get only one line in the file.</description>
    </item>
    
    <item>
      <title>What is the way to request the support for the additional ISIS TLVs for SPB?</title>
      <link>/questions/3505/what-is-the-way-to-request-the-support-for-the-additional-isis-tlvs-for-spb/</link>
      <pubDate>Thu, 14 Apr 2011 18:47:00 +0000</pubDate>
      
      <guid>/questions/3505/what-is-the-way-to-request-the-support-for-the-additional-isis-tlvs-for-spb/</guid>
      <description>What is the way to request the support for the additional ISIS TLVs for SPB?  0 IANA just resgiter a new series of ISIS TLVs to support SPB based on the draft: http://tools.ietf.org/html/draft-ietf-isis-ieee-aq-05
The SPB tlvs are listed under IANA ISIS codepoints at http://www.iana.org/assignments/isis-tlv-codepoints/isis-tlv-codepoints.xml
Please advise the procedure to request the support of those within wireshark.
Thanks
isis tlvasked 14 Apr &#39;11, 18:47
Edgard
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Print Spooler</title>
      <link>/questions/3508/print-spooler/</link>
      <pubDate>Fri, 15 Apr 2011 04:31:00 +0000</pubDate>
      
      <guid>/questions/3508/print-spooler/</guid>
      <description>Print Spooler  0 I installed Wireshark (and I think it installed WinPCap too).
And ever since I cant print.. Looking at my services the Print Spooler costantly stops - restarting it it stops in out 10 seconds.
I run Windows 7 SP1 (32Bit) does anyone have any ideas.
I am getting the following in the event viewer
Faulting application name: spoolsv.exe, version: 6.1.7601.17514, time stamp: 0x4ce7aa85 Faulting module name: hpzpnp.</description>
    </item>
    
    <item>
      <title>&amp;quot;Previous Segment Lost&amp;quot; seems to be inaccurate</title>
      <link>/questions/3509/previous-segment-lost-seems-to-be-inaccurate/</link>
      <pubDate>Fri, 15 Apr 2011 07:59:00 +0000</pubDate>
      
      <guid>/questions/3509/previous-segment-lost-seems-to-be-inaccurate/</guid>
      <description>&amp;ldquo;Previous Segment Lost&amp;rdquo; seems to be inaccurate  0 Hi. I have a packet capture that has lots of &#34;Previous Segment Lost&#34; diagnoses in Wireshark&#39;s Info field.
But, when I examine a few instances, I don&#39;t see evidence that a previous segment was indeed lost. But perhaps my analysis is flawed. Here is what I&#39;m looking at...
Packet &#34;n&#34; has Sequence number: 2080052452, a Length of 1460 Bytes, and Next sequence number: 2080053912.</description>
    </item>
    
    <item>
      <title>capture filter with port mirroring</title>
      <link>/questions/3515/capture-filter-with-port-mirroring/</link>
      <pubDate>Fri, 15 Apr 2011 11:28:00 +0000</pubDate>
      
      <guid>/questions/3515/capture-filter-with-port-mirroring/</guid>
      <description>capture filter with port mirroring  1 I&#39;ve been using tshark to capture packets coming off of a mirrored port so I can see everything that is coming in and going out of our network. I have the link to our ISP mirrored to a monitoring port where my computer that I use for monitoring is plugged into. I haven&#39;t had any problems with it when I don&#39;t have a capture filter.</description>
    </item>
    
    <item>
      <title>Why isn&amp;#x27;t RTP showing up?</title>
      <link>/questions/3523/why-isnt-rtp-showing-up/</link>
      <pubDate>Fri, 15 Apr 2011 13:54:00 +0000</pubDate>
      
      <guid>/questions/3523/why-isnt-rtp-showing-up/</guid>
      <description>Why isn&amp;rsquo;t RTP showing up?  0 I&#39;m new to Wireshark. I did some traces from IP phone over a SIP trunk to the PSTN. Trace shows no RTP, but I know it was being used.
Is RTP off by default?
Thanks
rtp missingThis question is marked &#34;community wiki&#34;.asked 15 Apr &#39;11, 13:54
greekgeek
1●1●1●1
accept rate: 0% 
Hi, If you look in the SIP messages carrying SDP you should see the IP and port used for RTP are those packages in the trace?</description>
    </item>
    
    <item>
      <title>I get (netmon: network type 8 unknown or unsupported) - what I need to do to read the cap file in wireshark?</title>
      <link>/questions/3525/i-get-netmon-network-type-8-unknown-or-unsupported-what-i-need-to-do-to-read-the-cap-file-in-wireshark/</link>
      <pubDate>Fri, 15 Apr 2011 15:11:00 +0000</pubDate>
      
      <guid>/questions/3525/i-get-netmon-network-type-8-unknown-or-unsupported-what-i-need-to-do-to-read-the-cap-file-in-wireshark/</guid>
      <description>I get (netmon: network type 8 unknown or unsupported) - what I need to do to read the cap file in wireshark?  0 I am using netmonitor 3.4 to capture wireless traffic, because it supports dialup mode devices. When I use editcap or wireshark, I get the above message. i do not have this problem on Vista, only on Windows 7.0 captured files.
Is there something I can do - Use Wireshark 1.</description>
    </item>
    
    <item>
      <title>No interface available to capture</title>
      <link>/questions/3536/no-interface-available-to-capture/</link>
      <pubDate>Sat, 16 Apr 2011 19:19:00 +0000</pubDate>
      
      <guid>/questions/3536/no-interface-available-to-capture/</guid>
      <description>No interface available to capture  0 Running Snow Leopard 10.6.7. Installed wireshark. When I try to select an interface from which to capture I get message that no interface is available.
Obviously I have an interface or I couldn&#39;t send this message.
Any help appreciated.
Thanks
interface noasked 16 Apr &#39;11, 19:19
snifferpro
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Here are some links to information that should hopefully help you out:</description>
    </item>
    
    <item>
      <title>FireWall Implementation.</title>
      <link>/questions/3538/firewall-implementation/</link>
      <pubDate>Sun, 17 Apr 2011 11:10:00 +0000</pubDate>
      
      <guid>/questions/3538/firewall-implementation/</guid>
      <description>FireWall Implementation.  0 I want to build a firewall(Packet Filter Mechanism). How WireShark can help me in this regard? Is there any function available in WireShark by which i can discard an abnormally detected packet?
firewallasked 17 Apr &#39;11, 11:10
Avik
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Wireshark was not made to interfere with traffic, it is made to record and analyze traffic. You can&#39;t influence traffic flows with wireshark.</description>
    </item>
    
    <item>
      <title>VoIP problems...</title>
      <link>/questions/3541/voip-problems/</link>
      <pubDate>Sun, 17 Apr 2011 16:58:00 +0000</pubDate>
      
      <guid>/questions/3541/voip-problems/</guid>
      <description>VoIP problems&amp;hellip;  0 Dears,
I&#39;ve been using VoIP phone for long time wwithout problems. However, lately (since 2 months) the other side almost can&#39;t hear me at all. I troublshooted everything without sucess, till I finally tried a different internet connection, and my VoIP worked fine there.
I started using Wireshark to diagnose my internet problem and found some really &#34;bad&#34; stuff in the upstreaming RTP. However, I still don&#39;t know what exactly the problem is.</description>
    </item>
    
    <item>
      <title>Dicom transfers</title>
      <link>/questions/3542/dicom-transfers/</link>
      <pubDate>Sun, 17 Apr 2011 20:55:00 +0000</pubDate>
      
      <guid>/questions/3542/dicom-transfers/</guid>
      <description>Dicom transfers  1 A lot of dicom transfers happen on tcp ports other than port 104. Is there a way to change this port within the dicom expression filter, or copy the filter and change the port that the expression looks at.
dicomasked 17 Apr &#39;11, 20:55
Vern
16●1●1●2
accept rate: 0%
  
One Answer:
  
2The filter is irrelevant to the port for DICOM. A filter does a lot less than some people appear to think it does - it just lets you test whether, in a particular packet, a given field is present, or lets you test the value of the field.</description>
    </item>
    
    <item>
      <title>WIRELESS ADAPTER IS NOT DETECTED//Unable to capture wireless(802.11 packets)</title>
      <link>/questions/3543/wireless-adapter-is-not-detectedunable-to-capture-wireless80211-packets/</link>
      <pubDate>Sun, 17 Apr 2011 21:34:00 +0000</pubDate>
      
      <guid>/questions/3543/wireless-adapter-is-not-detectedunable-to-capture-wireless80211-packets/</guid>
      <description>WIRELESS ADAPTER IS NOT DETECTED//Unable to capture wireless(802.11 packets)  0 OS: WIN7 HOME PREMIUM CPU: INTEL CORE I5-450M Memory: 500 GB HDD 4 GB DDR3 MEMORY
Adapter: ATHEROS AR5B97
Problem Title: ///WIRELESS ADAPTER IS NOT DETECTED///unable to capture 802.11 packets///
Problem Description:
Dear Sir/Madam
I am with Cisco systems and evaluating the demo version of wildpackets packet capture tool on Windows 7 home premium OS. I am unable to edit the channel number in the 802.</description>
    </item>
    
    <item>
      <title>If support filter BSSAP&#43; protocol in Wireshark?</title>
      <link>/questions/3550/if-support-filter-bssap-protocol-in-wireshark/</link>
      <pubDate>Mon, 18 Apr 2011 01:09:00 +0000</pubDate>
      
      <guid>/questions/3550/if-support-filter-bssap-protocol-in-wireshark/</guid>
      <description>If support filter BSSAP+ protocol in Wireshark?  0 I checked on Wirshark support protocols for BSSAP+ protocol and got below information: http://wiki.wireshark.org/GsmProtocolFamily This is an optional interface for PS/CS interoperability. Using the Gs interface it is possible to perform combined GPRS/IMSI attaches, combined location updates and paging the subscriber using PS facilities. The protocol is BSSAP+ specified in 3GPP TS 29.016 ( supported by Wireshark on ssn 98)
And I checked http://www.</description>
    </item>
    
    <item>
      <title>How to use capture on USB mobile phone modem on Windows</title>
      <link>/questions/3551/how-to-use-capture-on-usb-mobile-phone-modem-on-windows/</link>
      <pubDate>Mon, 18 Apr 2011 02:05:00 +0000</pubDate>
      
      <guid>/questions/3551/how-to-use-capture-on-usb-mobile-phone-modem-on-windows/</guid>
      <description>How to use capture on USB mobile phone modem on Windows  0 Hi. I use EVO device for internet connectvity and it works on USB interface. I want to know if there is any method through which I can capture traffic on USB interface as the USB interfaces are not listed on the interface list. please help me on this.
capture 3g usb winpcapasked 18 Apr &#39;11, 02:05
waseemsarwar103</description>
    </item>
    
    <item>
      <title>Decode for LLTD?</title>
      <link>/questions/3552/decode-for-lltd/</link>
      <pubDate>Mon, 18 Apr 2011 02:24:00 +0000</pubDate>
      
      <guid>/questions/3552/decode-for-lltd/</guid>
      <description>Decode for LLTD?  0 LLTD is the Link Layer Topology Discovery introduced by Microsoft with Windows Vista.
As of now Wireshark recognizes LLTD frames by Ethertype but does not decode the content.
Wiki provides a link to a dissector. What are the chances of getting the LLTD dissector into the standard Wireshark build?
windows lltdasked 18 Apr &#39;11, 02:24
packethunter
2.1k●7●15●48
accept rate: 8%
  
One Answer:</description>
    </item>
    
    <item>
      <title>building rpm</title>
      <link>/questions/3553/building-rpm/</link>
      <pubDate>Mon, 18 Apr 2011 03:35:00 +0000</pubDate>
      
      <guid>/questions/3553/building-rpm/</guid>
      <description>building rpm  0 i have built 3 dissectors for the 3 protocols and when i build the rpm only one of them is working . Very baffling! please help
dissector rpm wiresharkasked 18 Apr &#39;11, 03:35
niks3089
21●15●15●18
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>changing the preference using tshark</title>
      <link>/questions/3556/changing-the-preference-using-tshark/</link>
      <pubDate>Mon, 18 Apr 2011 06:33:00 +0000</pubDate>
      
      <guid>/questions/3556/changing-the-preference-using-tshark/</guid>
      <description>changing the preference using tshark  0 Hi I need to the change the preference settings so that the tshark will dissect the heuristic dissector first and i need to give a command for that since i cant use the gui (manager has told me to try using only cli so cant help) please help!
tshark preferencesasked 18 Apr &#39;11, 06:33
niks3089
21●15●15●18
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Capture file error</title>
      <link>/questions/3558/capture-file-error/</link>
      <pubDate>Mon, 18 Apr 2011 06:52:00 +0000</pubDate>
      
      <guid>/questions/3558/capture-file-error/</guid>
      <description>Capture file error  0 Wireshark Virtual machine capture seems to be corrupt. I&#39;m trying to debug a performance isse and keep recieved the following error. &#34;The capture file appears to be damaged or corrupt. (pcap: file has 65590-byte packet, bigger than the maximum of 65535&#34;. Even though wireshark says the capture is correct, the system appears to be functioning propoerly, i.e it is transferring data to a backup server. The wireshark version is 1.</description>
    </item>
    
    <item>
      <title>Stolen laptop</title>
      <link>/questions/3560/stolen-laptop/</link>
      <pubDate>Mon, 18 Apr 2011 07:21:00 +0000</pubDate>
      
      <guid>/questions/3560/stolen-laptop/</guid>
      <description>Stolen laptop  0 Hey Guys Someone stole my wifes laptop, and it so happens theyre somewhere within range of my wireless Dlink router and are currently accessing internet off me...
I was hoping to remote in and take a picture via the laptop camera though remoting seems to be disabled nor can i access anythign through teh UNC paths...
So my current plan is to see email addresses or facebook links of the theif so that i can send police his way.</description>
    </item>
    
    <item>
      <title>Can someone assist in deciphering my capture?</title>
      <link>/questions/3568/can-someone-assist-in-deciphering-my-capture/</link>
      <pubDate>Mon, 18 Apr 2011 07:56:00 +0000</pubDate>
      
      <guid>/questions/3568/can-someone-assist-in-deciphering-my-capture/</guid>
      <description>Can someone assist in deciphering my capture?  0 I am trying to find out what is going on with our network. At certain times of the day, not always a set time, but at times the network loses connection on random workstations, but it only loses connection on certain parts of the network and not other parts of the network. For example, we still have internet and we can print and view other parts of the network, but not all of it.</description>
    </item>
    
    <item>
      <title>Packets ignored unless also captured by Wireshark</title>
      <link>/questions/3570/packets-ignored-unless-also-captured-by-wireshark/</link>
      <pubDate>Mon, 18 Apr 2011 08:55:00 +0000</pubDate>
      
      <guid>/questions/3570/packets-ignored-unless-also-captured-by-wireshark/</guid>
      <description>Packets ignored unless also captured by Wireshark  0 Is it possible for Wireshark to alleviate some sort of network effect that prevented packets from being received?
I installed Wireshark to investigate a problem with packets not being received by an application I am developing, only to discover that packets are all received correctly while Wireshark is capturing on that interface. If I stop capturing in Wireshark, the packets stop being received by my application.</description>
    </item>
    
    <item>
      <title>How do I get the SIP call flow diagrams to expand into more space?</title>
      <link>/questions/3572/how-do-i-get-the-sip-call-flow-diagrams-to-expand-into-more-space/</link>
      <pubDate>Mon, 18 Apr 2011 09:18:00 +0000</pubDate>
      
      <guid>/questions/3572/how-do-i-get-the-sip-call-flow-diagrams-to-expand-into-more-space/</guid>
      <description>How do I get the SIP call flow diagrams to expand into more space?  0 When I bring up the SIP Call Flow diagram, it is too cramped to be usable. I can expand the pop-up window. The center bar that is the boundary between the &#34;comment&#34; on the right and the diagram on the left is live. However, the bar can be moved to the left, making the diagram smaller, but not to the right, making the diagram larger.</description>
    </item>
    
    <item>
      <title>How to display HTTP Header Length in bytes as a column?</title>
      <link>/questions/3574/how-to-display-http-header-length-in-bytes-as-a-column/</link>
      <pubDate>Mon, 18 Apr 2011 09:32:00 +0000</pubDate>
      
      <guid>/questions/3574/how-to-display-http-header-length-in-bytes-as-a-column/</guid>
      <description>How to display HTTP Header Length in bytes as a column?  0 How can I do this in Wireshark?
displayasked 18 Apr &#39;11, 09:32
Bruce
11●4●4●7
accept rate: 0%
  
One Answer:
  
2 Do you want to add the HTTP header &#34;Content-Length&#34; as a column? You can achieve that by rightclicking on the &#34;Content-Length&#34; header in the packet details pane. Then you can choose &#34;</description>
    </item>
    
    <item>
      <title>When I refresh my page it increases my views!!</title>
      <link>/questions/3575/when-i-refresh-my-page-it-increases-my-views/</link>
      <pubDate>Mon, 18 Apr 2011 09:39:00 +0000</pubDate>
      
      <guid>/questions/3575/when-i-refresh-my-page-it-increases-my-views/</guid>
      <description>When I refresh my page it increases my views!!  0 Please look into this flaw.
metaasked 18 Apr &#39;11, 09:39
Bruce
11●4●4●7
accept rate: 0%
1What flaw?
(18 Apr &#39;11, 13:31) Jaap ♦Presumably he means &#34;if I go to a page for a question, every time I refresh it, it counts as another view of the question&#34;.
(18 Apr &#39;11, 18:32) Guy Harris ♦♦   </description>
    </item>
    
    <item>
      <title>how to target user on local network?</title>
      <link>/questions/3577/how-to-target-user-on-local-network/</link>
      <pubDate>Mon, 18 Apr 2011 10:33:00 +0000</pubDate>
      
      <guid>/questions/3577/how-to-target-user-on-local-network/</guid>
      <description>how to target user on local network?  0 I have just started using wireshark. I&#39;m using it so see how good is Internet security. But i have a problem targeting local mac, ip o computer of my choice. In aircrack, aireplay, and all others you can target computer and start capturing packets. But i haven&#39;t found same option in wireshark.
How can i capture packages, and do i need to put my wlan0 to mon0 mode?</description>
    </item>
    
    <item>
      <title>Does Wireshark check the RTP payload type when extracting audio</title>
      <link>/questions/3578/does-wireshark-check-the-rtp-payload-type-when-extracting-audio/</link>
      <pubDate>Mon, 18 Apr 2011 10:35:00 +0000</pubDate>
      
      <guid>/questions/3578/does-wireshark-check-the-rtp-payload-type-when-extracting-audio/</guid>
      <description>Does Wireshark check the RTP payload type when extracting audio  0 I have a stream of RTP packets some of which have payload type = 0 (G711) and some have payload type = 101 (DTMF). I have an application where both in-band and out-of-band DTMF digits are transmitted. When I use Wireshark to capture the RTP stream and extract the payload to a .au file, the audio sounds bad. From a plot I can see that the audio in the .</description>
    </item>
    
    <item>
      <title>Null Terminated String</title>
      <link>/questions/3580/null-terminated-string/</link>
      <pubDate>Mon, 18 Apr 2011 12:44:00 +0000</pubDate>
      
      <guid>/questions/3580/null-terminated-string/</guid>
      <description>Null Terminated String  0 Is there an available function that finds bytes till null character? (&#39;0&#39;)
Thanks, Dhanashree
terminated null stringasked 18 Apr &#39;11, 12:44
dsprabhu4
11●7●7●10
accept rate: 0%
  
One Answer:
  
1Each of tvb_get_stringz, tvb_get_ephemeral_stringz, and tvb_get_seasonal_stringz extract a NULL terminated string from the TVB and return it as a guint8 *.
I would recommend that you check for the presence of the terminating NULL before calling any of these functions, however, as it is not guaranteed to be in the captured packet (erroneous transmission, fuzz-test, fragmentation, etc).</description>
    </item>
    
    <item>
      <title>DoD Approved Products List?</title>
      <link>/questions/3590/dod-approved-products-list/</link>
      <pubDate>Mon, 18 Apr 2011 15:11:00 +0000</pubDate>
      
      <guid>/questions/3590/dod-approved-products-list/</guid>
      <description>DoD Approved Products List?  0 I have been told Wireshark 1.0.6 is on the Department of Defense Approved Products List (APL) but cannot find it. Is there a version of Wireshark that is on the APL? If so, can you please direct me to some supporting documentation?
governmentasked 18 Apr &#39;11, 15:11
parslj2
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Why is there a 2GB file size limit on x64 Win7 with 4GB RAM</title>
      <link>/questions/3592/why-is-there-a-2gb-file-size-limit-on-x64-win7-with-4gb-ram/</link>
      <pubDate>Mon, 18 Apr 2011 18:32:00 +0000</pubDate>
      
      <guid>/questions/3592/why-is-there-a-2gb-file-size-limit-on-x64-win7-with-4gb-ram/</guid>
      <description>Why is there a 2GB file size limit on x64 Win7 with 4GB RAM  0 I have the 64 bit version of Wireshark installed Version 1.4.5 (SVN Rev 36650 from /trunk-1.4) on Win7 Ultimate with 4GB of RAM. I am trying to load a 1.3GB PCAP file. When Wireshark gets to 2GB of memory allocated even though there is 1GB free it crashes.
I was under the impression that the x64 version of Wireshark did not have any limitations on memory.</description>
    </item>
    
    <item>
      <title>Packet in Binary file but not showing in wireshark gui</title>
      <link>/questions/3595/packet-in-binary-file-but-not-showing-in-wireshark-gui/</link>
      <pubDate>Mon, 18 Apr 2011 20:40:00 +0000</pubDate>
      
      <guid>/questions/3595/packet-in-binary-file-but-not-showing-in-wireshark-gui/</guid>
      <description>Packet in Binary file but not showing in wireshark gui  0 Hi, i have a strange issue that i hope someone can help me with. I am trying to alleviate network issues for my app. i have 2 traces going one client side and 1 monitoring firewall and server side. I see the packet in the client side but not in the server side. i decided to check the binary file and there is an entry on the server side for this packet as it has a unique http cookie.</description>
    </item>
    
    <item>
      <title>Spotting botnet command &amp;amp; control</title>
      <link>/questions/3606/spotting-botnet-command-control/</link>
      <pubDate>Tue, 19 Apr 2011 05:51:00 +0000</pubDate>
      
      <guid>/questions/3606/spotting-botnet-command-control/</guid>
      <description>Spotting botnet command &amp;amp; control  1 I was reading this article (http://www.technologyreview.com/computing/37311/?p1=MstRcnt&amp;amp;a=f) about spotting botnet command &amp;amp; control boxes. It seems to me you could also use the wireshark filter: dns.flags.rcode == 3 If you received a lot of failures as this filter should show, that would warrant further investigation. Thoughts anyone?
botnetsasked 19 Apr &#39;11, 05:51
RobertM
16●1●2●4
accept rate: 0%
 edited 19 Apr &#39;11, 05:52</description>
    </item>
    
    <item>
      <title>export append</title>
      <link>/questions/3608/export-append/</link>
      <pubDate>Tue, 19 Apr 2011 06:43:00 +0000</pubDate>
      
      <guid>/questions/3608/export-append/</guid>
      <description>export append  0 I have to run a scan for an 8 hour duration. Is there a method in which I can setup the multiple file option to write/export them to a folder in sequential order without interuption to the scan? That is a continuous run and export without interupting the scan and killing the laptop?
100mgasked 19 Apr &#39;11, 06:43
spongerob
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>DIS PDU filtering</title>
      <link>/questions/3609/dis-pdu-filtering/</link>
      <pubDate>Tue, 19 Apr 2011 07:43:00 +0000</pubDate>
      
      <guid>/questions/3609/dis-pdu-filtering/</guid>
      <description>DIS PDU filtering  0 Does anyone know how to load the latest DIS PDU updates in order for Wireshark to be able to filter on DIS PDUs being transmitted over the network? It would have to be compatible with 64-bit Windows 7. I&#39;m new to this system and my protocol preferences state that DIS is available, but I wasn&#39;t sure if I need to download additional code for DIS PDUs as well to make this work.</description>
    </item>
    
    <item>
      <title>DDoS attacks detection in wireshark</title>
      <link>/questions/3612/ddos-attacks-detection-in-wireshark/</link>
      <pubDate>Tue, 19 Apr 2011 08:26:00 +0000</pubDate>
      
      <guid>/questions/3612/ddos-attacks-detection-in-wireshark/</guid>
      <description>DDoS attacks detection in wireshark  0 Is it possible to detect ddos attacks with wireshark for group of servers?
ddosasked 19 Apr &#39;11, 08:26
dkorzhevin
1●2●2●3
accept rate: 0%
  
One Answer:
  
3Yes, it may be possible if you&#39;re capturing traffic to this group of servers. DDoS attacks often are &#34;simple&#34; SYN floods coming from apparently all over the world. To determine where a packet is coming from you can enable the GeoIP localisation in the Name Resolution settings in the Wireshark preferences after you&#39;ve placed the according files (available for free from www.</description>
    </item>
    
    <item>
      <title>How to copy part of report to new smaller file</title>
      <link>/questions/3614/how-to-copy-part-of-report-to-new-smaller-file/</link>
      <pubDate>Tue, 19 Apr 2011 10:19:00 +0000</pubDate>
      
      <guid>/questions/3614/how-to-copy-part-of-report-to-new-smaller-file/</guid>
      <description>How to copy part of report to new smaller file  0 Hi My question is I don&#39;t know how to copy part of report, to a new file. for example i have big wireshark file 400 Mega, and I need only 10 Mega in a new file ? Thanks Benni
copyingasked 19 Apr &#39;11, 10:19
Benni
1●1●1●1
accept rate: 0%
I make a VOIP call, I want to isolate and copy only this conversation to a new file How do I do this Thanks</description>
    </item>
    
    <item>
      <title>New file in Wireshark dissectors folder</title>
      <link>/questions/3616/new-file-in-wireshark-dissectors-folder/</link>
      <pubDate>Tue, 19 Apr 2011 10:47:00 +0000</pubDate>
      
      <guid>/questions/3616/new-file-in-wireshark-dissectors-folder/</guid>
      <description>New file in Wireshark dissectors folder  0 I want to add a new file that will enhance existing protocol - BACnet. The file will contain proprietary services analysis. When i add code, it does not get compiled. Which files do i need to modify to compile this file?
new fileasked 19 Apr &#39;11, 10:47
dsprabhu4
11●7●7●10
accept rate: 0%
  
One Answer:
  
2 You need to add your files to lists in several locations under the source tree.</description>
    </item>
    
    <item>
      <title>how to decode Vodafone Diameter specific AVP 260 &amp;amp; 261 using wireshark.</title>
      <link>/questions/3623/how-to-decode-vodafone-diameter-specific-avp-260-261-using-wireshark/</link>
      <pubDate>Tue, 19 Apr 2011 15:44:00 +0000</pubDate>
      
      <guid>/questions/3623/how-to-decode-vodafone-diameter-specific-avp-260-261-using-wireshark/</guid>
      <description>how to decode Vodafone Diameter specific AVP 260 &amp;amp; 261 using wireshark.  0 Hi,
I wanted to decode my wireshark to decode the Vodafone Diameter specific AVPs 260 &amp;amp; 261. My wireshark is installed on my Linux Box running with CentOS.
I can see the following lie is already added in dictionary.xml [path: /usr/share/wireshark/diameter]
&amp;lt;vendor vendor-id=&#34;Vodafone&#34; code=&#34;12645&#34; name=&#34;Vodafone&#34;/&amp;gt;And I have added following in the dictionary.xml: &amp;lt;avp name=&amp;quot;Radio-Access-Technology&amp;quot; code=&amp;quot;260&amp;quot; vendor-bit=&amp;quot;Vodafone&amp;quot;&amp;gt; &amp;lt;type type-name=&amp;quot;Enumerated&amp;quot;/&amp;gt; &amp;lt;enum name=&amp;quot;UTRAN&amp;quot; code=&amp;quot;1&amp;quot;/&amp;gt; &amp;lt;enum name=&amp;quot;GERAN&amp;quot; code=&amp;quot;2&amp;quot;/&amp;gt; &amp;lt;enum name=&amp;quot;WLAN&amp;quot; code=&amp;quot;3&amp;quot;/&amp;gt; &amp;lt;enum name=&amp;quot;GAN&amp;quot; code=&amp;quot;4&amp;quot;/&amp;gt; &amp;lt;enum name=&amp;quot;HSPA Evolution&amp;quot; code=&amp;quot;5&amp;quot;/&amp;gt; &amp;lt;enum name=&amp;quot;EUTRAN&amp;quot; code=&amp;quot;6&amp;quot;/&amp;gt; &amp;lt;/avp&amp;gt;  &amp;amp;lt;avp name=&amp;amp;quot;Reporting-Reason&amp;amp;quot; code=&amp;amp;quot;261&amp;amp;quot; vendor-bit=&amp;amp;quot;Vodafone&amp;amp;quot;&amp;amp;gt; &amp;amp;lt;type type-name=&amp;amp;quot;Enumerated&amp;amp;quot;/&amp;amp;gt; &amp;amp;lt;enum name=&amp;amp;quot;THRESHOLD&amp;amp;quot; code=&amp;amp;quot;0&amp;amp;quot;/&amp;amp;gt; &amp;amp;lt;enum name=&amp;amp;quot;FINAL&amp;amp;quot; code=&amp;amp;quot;2&amp;amp;quot;/&amp;amp;gt; &amp;amp;lt;enum name=&amp;amp;quot;QUOTA_EXHAUSTED&amp;amp;quot; code=&amp;amp;quot;3&amp;amp;quot;/&amp;amp;gt; &amp;amp;lt;enum name=&amp;amp;quot;VALIDITY_TIME&amp;amp;quot; code=&amp;amp;quot;4&amp;amp;quot;/&amp;amp;gt; &amp;amp;lt;enum name=&amp;amp;quot;OTHER_QUOTA_TYPE&amp;amp;quot; code=&amp;amp;quot;5&amp;amp;quot;/&amp;amp;gt; &amp;amp;lt;enum name=&amp;amp;quot;RATING_CONDITION_CHANGE&amp;amp;quot; code=&amp;amp;quot;6&amp;amp;quot;/&amp;amp;gt; &amp;amp;lt;enum name=&amp;amp;quot;FORCED_REAUTHORISATION&amp;amp;quot; code=&amp;amp;quot;7&amp;amp;quot;/&amp;amp;gt; &amp;amp;lt;/avp&amp;amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;p&amp;gt;Still these AVPs are not decoded.</description>
    </item>
    
    <item>
      <title>Recommended capture computers</title>
      <link>/questions/3625/recommended-capture-computers/</link>
      <pubDate>Tue, 19 Apr 2011 16:33:00 +0000</pubDate>
      
      <guid>/questions/3625/recommended-capture-computers/</guid>
      <description>Recommended capture computers  0 I recently had Riverbed tech support inform me that using their Pilot software burst bandwidth report is not going to be accurate unless I use a Linux based computer with a Turbocap card installed.
So that seems to rule out laptops. What computers are people out there dragging around to their clients networks?
Can anyone recommend a prebuilt Linux system and/or Windows system that is particularly well suited for the Turbocap card and accurate timestamps?</description>
    </item>
    
    <item>
      <title>How to zoom in on TCP stream graphs?</title>
      <link>/questions/3627/how-to-zoom-in-on-tcp-stream-graphs/</link>
      <pubDate>Tue, 19 Apr 2011 19:00:00 +0000</pubDate>
      
      <guid>/questions/3627/how-to-zoom-in-on-tcp-stream-graphs/</guid>
      <description>How to zoom in on TCP stream graphs?  0 Hi,
Wireshark documentation, Laura Chappell&#39;s DVD tutorial and other source all say that I can zoom in on a Statistics-&amp;gt;TCP Stream Graph-&amp;gt;Time Sequence Graph by left clicking my mouse. But this doesn&#39;t work for me in Wireshark 1.4.4 on two different systems (a XP SP3 system and a Win 7 SP1 system). Left clicking in the TCP stream graph has no effect.</description>
    </item>
    
    <item>
      <title>Not able to filter YMSG in wireshark packet sniffer!</title>
      <link>/questions/3630/not-able-to-filter-ymsg-in-wireshark-packet-sniffer/</link>
      <pubDate>Wed, 20 Apr 2011 01:55:00 +0000</pubDate>
      
      <guid>/questions/3630/not-able-to-filter-ymsg-in-wireshark-packet-sniffer/</guid>
      <description>Not able to filter YMSG in wireshark packet sniffer!  0 Hi there,I want to read the ymsg packets to understand its protocol at different request from the client,so I tried to use wireshark packet sniffer to trace the packets of Yahoo messanger.Wireshark is tracing the tcp,udp,https packets but I find no ymsg packets in the list even though I am using yahoo messanger.Any idea why isnt working for me?</description>
    </item>
    
    <item>
      <title>Source Code Analysis for Wireshark</title>
      <link>/questions/3632/source-code-analysis-for-wireshark/</link>
      <pubDate>Wed, 20 Apr 2011 08:33:00 +0000</pubDate>
      
      <guid>/questions/3632/source-code-analysis-for-wireshark/</guid>
      <description>Source Code Analysis for Wireshark  0 Klocwork’s open source program would like to analyze Wirehshark using its static analysis product, Klocwork Insight, to give a report on bugs and potential security vulnerabilities. The results would be hosted on a secure web portal where contributors can access the results. The results will not be published. This program will be offered free to open source projects on an ongoing basis, so if the results are of value we could analyze future versions of the project as well.</description>
    </item>
    
    <item>
      <title>Linker Error after removing a file</title>
      <link>/questions/3633/linker-error-after-removing-a-file/</link>
      <pubDate>Wed, 20 Apr 2011 09:07:00 +0000</pubDate>
      
      <guid>/questions/3633/linker-error-after-removing-a-file/</guid>
      <description>Linker Error after removing a file  0 I had added a new file in dissector folder. The file had two functions for registering few dissectors - proto_register_bacnetSBT and proto_reg_handoff_bacnetSBT.
I add reference of this file in following to compile
C:wiresharkepanCMakeLists.txt C:wiresharkepandissectorsMakefile.common
Now I have removed this file and its references from above 2 files. but i am still getting linker errors. I am using Visual C++ 2008 Express. I clean solution before compiling.</description>
    </item>
    
    <item>
      <title>Monitor when someone connects to wifi</title>
      <link>/questions/3641/monitor-when-someone-connects-to-wifi/</link>
      <pubDate>Wed, 20 Apr 2011 11:03:00 +0000</pubDate>
      
      <guid>/questions/3641/monitor-when-someone-connects-to-wifi/</guid>
      <description>Monitor when someone connects to wifi  0 Is there any way to monitor when someone else connects to my wifi? My wifi is OK, but sometimes it dips drastically. I only notice this after the fact. I would like to know exactly when someone is connecting. I only know about the &#34;arp -a&#34; command.
Thanks for any help.
Kenneth
wifiasked 20 Apr &#39;11, 11:03
KSK
1●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Need help in learning the output generated by Wireshark</title>
      <link>/questions/3649/need-help-in-learning-the-output-generated-by-wireshark/</link>
      <pubDate>Wed, 20 Apr 2011 11:52:00 +0000</pubDate>
      
      <guid>/questions/3649/need-help-in-learning-the-output-generated-by-wireshark/</guid>
      <description>Need help in learning the output generated by Wireshark  0 14 20.198934 192.168.0.1 239.255.255.250 SSDP NOTIFY * HTTP/1.1
What does the above line mean mainly the destination broadcast IP ? Why is it broadcasting to IANA ?
Thanks in advance
Victor
output generatedasked 20 Apr &#39;11, 11:52
victor43
1●1●1●1
accept rate: 0%
  
One Answer:
  
1239.255.255.250 is a multicast address (not a broadcast, that would be 255.</description>
    </item>
    
    <item>
      <title>HTTP packets</title>
      <link>/questions/3658/http-packets/</link>
      <pubDate>Wed, 20 Apr 2011 13:42:00 +0000</pubDate>
      
      <guid>/questions/3658/http-packets/</guid>
      <description>HTTP packets  0 What is relation between number of HTTP packets and number of objects in a web page?
packets httpasked 20 Apr &#39;11, 13:42
A B
1●10●10●12
accept rate: 0%
So how can I count number of objects?just trace the source code of web page?
(20 Apr &#39;11, 13:49) A B  
3 Answers:
  
2None.
answered 20 Apr &#39;11, 13:47
Jaap ♦
11.7k●16●101
accept rate: 14%</description>
    </item>
    
    <item>
      <title>SubDissector code in new file</title>
      <link>/questions/3661/subdissector-code-in-new-file/</link>
      <pubDate>Wed, 20 Apr 2011 13:53:00 +0000</pubDate>
      
      <guid>/questions/3661/subdissector-code-in-new-file/</guid>
      <description>SubDissector code in new file  0 I am writing a subdissector for an existing protocol. The existing protocol has a bacapp_dissector_table. In a new file, i am writing a subdissector with following functions void proto_register_bacnetsbt(void) { static hf_register_info hf[] = { { &amp;amp;hf_bacnet_private_transfer, { &#34;Private Transfer&#34;, &#34;bacnet.private.transfer&#34;, FT_FRAMENUM, BASE_NONE, NULL, 0x00, NULL, HFILL} } }; static gint *ett[] = { &amp;amp;ett_bacnet_sbt, };
/* Register */proto_BACnet_PT_mr = proto_register_protocol(&#34;ABC&#34;,&#34;BACNET-SBT&#34;, &#34;bacnetsbt&#34;); register_dissector(&#34;ABC&#34;, dissect_BACnet_SBT_UCPT_mr, proto_BACnet_PT_mr);</description>
    </item>
    
    <item>
      <title>How to decode a Diameter AVP if there are more AVPs of same code?</title>
      <link>/questions/3664/how-to-decode-a-diameter-avp-if-there-are-more-avps-of-same-code/</link>
      <pubDate>Wed, 20 Apr 2011 15:29:00 +0000</pubDate>
      
      <guid>/questions/3664/how-to-decode-a-diameter-avp-if-there-are-more-avps-of-same-code/</guid>
      <description>How to decode a Diameter AVP if there are more AVPs of same code?  0 Hi,
I am trying to decode some Diameter AVPs using wireshark, but I found that same AVP code is defined at two places differently like below:
imscxdx.xml: &amp;lt;avp name=&#34;SIP-Auth-Data-Item&#34; code=&#34;13&#34; mandatory=&#34;must&#34; vendor-bit=&#34;must&#34; vendor-id=&#34;TGPP&#34; may-encrypt=&#34;yes&#34;&amp;gt;
TGPPGmb.xml: &amp;lt;avp name=&#34;3GPP-Charging-Characteristics&#34; code=&#34;13&#34; mandatory=&#34;must&#34; may-encrypt=&#34;yes&#34; protected=&#34;may&#34; vendor-bit=&#34;must&#34; vendor-id=&#34;TGPP&#34;&amp;gt;
imscxdx.xml: &amp;lt;avp name=&#34;Public-Identity&#34; code=&#34;2&#34; mandatory=&#34;must&#34; vendor-bit=&#34;must&#34; vendor-id=&#34;TGPP&#34; may-encrypt=&#34;yes&#34;&amp;gt;
TGPPGmb.xml: &amp;lt;avp name=&#34;3GPP-Charging ID&#34;</description>
    </item>
    
    <item>
      <title>SDP - Sockets Direct Protocol vs. Session Description Protocol</title>
      <link>/questions/3675/sdp-sockets-direct-protocol-vs-session-description-protocol/</link>
      <pubDate>Thu, 21 Apr 2011 01:37:00 +0000</pubDate>
      
      <guid>/questions/3675/sdp-sockets-direct-protocol-vs-session-description-protocol/</guid>
      <description>SDP - Sockets Direct Protocol vs. Session Description Protocol  0 At Wireshark 1.5.1 Release Notes I can read, &#39;Infiniband Sockets Direct Protocol (SDP)&#39; is supported now. Wireshark 1.5.1 itself says at internals-&amp;gt;supported protocols (show), it supports &#39;SDP (Session Description Protocol)&#39;. Who is right? I need SDP (Sockets Direct Protocol). Thanks in advance, Wolfgang
sdpasked 21 Apr &#39;11, 01:37
Wolfgang
16●1●1●3
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>DNS transaction latency</title>
      <link>/questions/3678/dns-transaction-latency/</link>
      <pubDate>Thu, 21 Apr 2011 04:52:00 +0000</pubDate>
      
      <guid>/questions/3678/dns-transaction-latency/</guid>
      <description>DNS transaction latency  0 3I want to know response delay between DNS client and server.
1&amp;gt; How can wireshark help in this?
2&amp;gt; How can I generate I/O graph that displays this information?
Regards,
Vijay
performance dnsasked 21 Apr &#39;11, 04:52
Vijay Gharge
36●15●16●20
accept rate: 0%
Unless you use their Turbocap card or a Shark Appliance, timestamps are not accurate in some cases.
(22 Apr &#39;11, 12:10) eelarry</description>
    </item>
    
    <item>
      <title>Follow TCP stream</title>
      <link>/questions/3680/follow-tcp-stream/</link>
      <pubDate>Thu, 21 Apr 2011 07:47:00 +0000</pubDate>
      
      <guid>/questions/3680/follow-tcp-stream/</guid>
      <description>Follow TCP stream  0 I understand that &#34;follow tcp stream&#34; allows packets from a single tcp stream to be displayed in order. I captured a Bittorrent traffic that contains more than 30 tcp streams. How can I display all packets from all the tcp streams in order at the same time?
tcpasked 21 Apr &#39;11, 07:47
catfish
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t reanimate a capture file.</title>
      <link>/questions/3691/cant-reanimate-a-capture-file/</link>
      <pubDate>Fri, 22 Apr 2011 10:15:00 +0000</pubDate>
      
      <guid>/questions/3691/cant-reanimate-a-capture-file/</guid>
      <description>Can&amp;rsquo;t reanimate a capture file.  0 I cannot open a file from a packet capture. Granted the file size is 1.9 GBs. When attempting to open the file I receive this message several minutes later... &#34;This application has requested the Runtime to terminate it in an unusual way. Microsoft Visual C++ Runtime Library&#34; Is this due to the size of the capture file? Please help, or can someone step me through it?</description>
    </item>
    
    <item>
      <title>odd dns queries (malware?)</title>
      <link>/questions/3697/odd-dns-queries-malware/</link>
      <pubDate>Fri, 22 Apr 2011 12:16:00 +0000</pubDate>
      
      <guid>/questions/3697/odd-dns-queries-malware/</guid>
      <description>odd dns queries (malware?)  0 At a client site with my own laptop capturing, I came across these strange queries. Is this some kind of malware? I checked my laptop at home and these queries do not happen there.
10.10.7.93 10.10.7.231 DNS 53 Standard query A hkdheltpil.dct.local
10.10.7.93 10.10.7.231 DNS 53 Standard query A abpbmpbmbd.dct.local
10.10.7.93 10.10.7.231 DNS 53 Standard query A byxcaaoetj.dct.local
10.10.7.93 224.0.0.252 LLMNR 5355 Standard query A abpbmpbmbd</description>
    </item>
    
    <item>
      <title>How can I monitor serial o/o/o on a cisco router?</title>
      <link>/questions/3698/how-can-i-monitor-serial-ooo-on-a-cisco-router/</link>
      <pubDate>Fri, 22 Apr 2011 14:48:00 +0000</pubDate>
      
      <guid>/questions/3698/how-can-i-monitor-serial-ooo-on-a-cisco-router/</guid>
      <description>How can I monitor serial o/o/o on a cisco router?  0 With wireshark how can I monitor packets that are coming and going on the serial port of a Cisco router 3945?
serial ciscoasked 22 Apr &#39;11, 14:48
lateris
1●1●1●1
accept rate: 0%
Hmm, I&#39;m not sure it can be done with stock Wireshark. Won&#39;t you need to introduce a serial tap that understands HDLC or PPP? (not sure what you&#39;re using).</description>
    </item>
    
    <item>
      <title>filtering three protocols and a few IP addresses</title>
      <link>/questions/3702/filtering-three-protocols-and-a-few-ip-addresses/</link>
      <pubDate>Sat, 23 Apr 2011 16:49:00 +0000</pubDate>
      
      <guid>/questions/3702/filtering-three-protocols-and-a-few-ip-addresses/</guid>
      <description>filtering three protocols and a few IP addresses  0 Hi
For the end of my thesis (inderaction of HSS and IMS) I have to analyse circuit_swidtched-to-SIP call. I&#39;m only interested in SIP, DIAMETER and RTP protocols. What kind of filter should I use to see displayed ONLY these protocols and, let&#39;s say A, B, C, D, E and F IP addresses in flow graph?
Please, can someone give me a right syntax for this filter?</description>
    </item>
    
    <item>
      <title>Irix Package</title>
      <link>/questions/3711/irix-package/</link>
      <pubDate>Mon, 25 Apr 2011 13:18:00 +0000</pubDate>
      
      <guid>/questions/3711/irix-package/</guid>
      <description>Irix Package  0 Is there a free Irix package for Wireshark somewhere online?
irixasked 25 Apr &#39;11, 13:18
westwaswon
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Packet Tracer and Wireshark</title>
      <link>/questions/3712/packet-tracer-and-wireshark/</link>
      <pubDate>Mon, 25 Apr 2011 22:21:00 +0000</pubDate>
      
      <guid>/questions/3712/packet-tracer-and-wireshark/</guid>
      <description>Packet Tracer and Wireshark  0 Hi can wireshark be used to capture traffic on cisco packet tracer? I am studying for ccna, i need to capture traffic to review it.
tracer packetasked 25 Apr &#39;11, 22:21
Dhanjal
1●1●1●1
accept rate: 0%
  
One Answer:
  
1That is more of a Cisco question, from the looks of the documents on Cisco, the packet-tracer is a closed simulation environment.</description>
    </item>
    
    <item>
      <title>FCoE code</title>
      <link>/questions/3713/fcoe-code/</link>
      <pubDate>Mon, 25 Apr 2011 23:03:00 +0000</pubDate>
      
      <guid>/questions/3713/fcoe-code/</guid>
      <description>FCoE code  0 Need help in finding the code for FCoE support in wireshark.
fcoeThis question is marked &#34;community wiki&#34;.asked 25 Apr &#39;11, 23:03
searching
1●3●3●4
accept rate: 0%
  
2 Answers:
  
3You can find the FCoE dissector code in:
epan/dissectors/packet-fcoe.canswered 25 Apr &#39;11, 23:21
SYN-bit ♦♦
17.1k●9●57●245
accept rate: 20%
Thanks.....
(25 Apr &#39;11, 23:48) searching  
1Here you go.
answered 25 Apr &#39;11, 23:22</description>
    </item>
    
    <item>
      <title>Tool capturing only FCoE packet</title>
      <link>/questions/3718/tool-capturing-only-fcoe-packet/</link>
      <pubDate>Mon, 25 Apr 2011 23:59:00 +0000</pubDate>
      
      <guid>/questions/3718/tool-capturing-only-fcoe-packet/</guid>
      <description>Tool capturing only FCoE packet  0 As i am new to this...if i need to make a analyser detecting FCoE packets only which all thing should i include or how should i proceed in this.
fcoeThis question is marked &#34;community wiki&#34;.asked 25 Apr &#39;11, 23:59
searching
1●3●3●4
accept rate: 0%
  
One Answer:
  
1You could start a capture using the capture options dialog and use a capture filter like this:</description>
    </item>
    
    <item>
      <title>How to capture udp data in a ip range from Capture Filter?</title>
      <link>/questions/3720/how-to-capture-udp-data-in-a-ip-range-from-capture-filter/</link>
      <pubDate>Tue, 26 Apr 2011 06:56:00 +0000</pubDate>
      
      <guid>/questions/3720/how-to-capture-udp-data-in-a-ip-range-from-capture-filter/</guid>
      <description>How to capture udp data in a ip range from Capture Filter?  0 I tried to use dst ...25/100 and dst ...25 ..***.26 ...
It does not work
Is this option available from Ethereal Option window?
Thanks
ip range multicastasked 26 Apr &#39;11, 06:56
likeshark
1●1●1●2
accept rate: 0%
  
2 Answers:
  
2If you want to use capture filters you need to use the tcpdump syntax, not display filter syntax.</description>
    </item>
    
    <item>
      <title>NBNS queries slowing Wireshark capture filter input</title>
      <link>/questions/3722/nbns-queries-slowing-wireshark-capture-filter-input/</link>
      <pubDate>Tue, 26 Apr 2011 10:24:00 +0000</pubDate>
      
      <guid>/questions/3722/nbns-queries-slowing-wireshark-capture-filter-input/</guid>
      <description>NBNS queries slowing Wireshark capture filter input  2 I wondered why Wireshark (I run 1.5 SVN Rev 35637) always stopped after the first octet (and usually after each other octet as well) whenever I entered a capture filter starting like &#34;host 192.168.0.1&#34;, so I captured my PC with a second Wireshark while entering the filter in the first.
What I found was, that my PC (running Win7x64) tried to do a NBNS query for &#34;</description>
    </item>
    
    <item>
      <title>pass correct capturing interface for tshark via JAVA</title>
      <link>/questions/3723/pass-correct-capturing-interface-for-tshark-via-java/</link>
      <pubDate>Tue, 26 Apr 2011 10:56:00 +0000</pubDate>
      
      <guid>/questions/3723/pass-correct-capturing-interface-for-tshark-via-java/</guid>
      <description>pass correct capturing interface for tshark via JAVA  1 Hi all,
At this moment, I am trying to implement a &#34;one-click&#34; packet capturing functionality (button on a GUI) in one of my JAVA applications, with the help of tshark/wireshark.
So far, I tried this:
String nic = NetworkInterface.getName();
String execute = &#34;C:\Progra~1\Wireshark\tshark -i &#34;+nic+&#34; -b filesize:512 -w testCap&#34;;
try { Runtime.getRuntime().exec(execute); }
catch (IOException e1) { msg(&#34;Error during initialization of live capture&#34;</description>
    </item>
    
    <item>
      <title>how to capture traffic for a specific program?</title>
      <link>/questions/3725/how-to-capture-traffic-for-a-specific-program/</link>
      <pubDate>Tue, 26 Apr 2011 12:02:00 +0000</pubDate>
      
      <guid>/questions/3725/how-to-capture-traffic-for-a-specific-program/</guid>
      <description>how to capture traffic for a specific program?  2 If I suspect a certain program or programs is a keylogger, can i capture just packets coming going in and out of that program? or possibly slect multiple programs and capture only data coming to/from them?
I don&#39;t know if it&#39;s possible for programs to pass use your browser to transfer data, is it possible? so maybe it won&#39;t help much but I&#39;d like to get some info on that</description>
    </item>
    
    <item>
      <title>repository for non-standard dissectors/protocols and other lua code</title>
      <link>/questions/3726/repository-for-non-standard-dissectorsprotocols-and-other-lua-code/</link>
      <pubDate>Tue, 26 Apr 2011 12:46:00 +0000</pubDate>
      
      <guid>/questions/3726/repository-for-non-standard-dissectorsprotocols-and-other-lua-code/</guid>
      <description>repository for non-standard dissectors/protocols and other lua code  1 Just finished my dissector for xPL. Its a lua based script.
To make it usefull to others, I would like to know whether there is a repository somewhere where I could store/upload this codefile?
regards Thijs
download lua dissector repository xplasked 26 Apr &#39;11, 12:46
Tieske
21●1●1●4
accept rate: 0%
 edited 26 Apr &#39;11, 12:47</description>
    </item>
    
    <item>
      <title>Is there any way to see total time on a capture?</title>
      <link>/questions/3735/is-there-any-way-to-see-total-time-on-a-capture/</link>
      <pubDate>Tue, 26 Apr 2011 16:57:00 +0000</pubDate>
      
      <guid>/questions/3735/is-there-any-way-to-see-total-time-on-a-capture/</guid>
      <description>Is there any way to see total time on a capture?  0 What im aiming to do is transfer a file from host 1 to host 2 and see total time it takes to do it, im sure that wireshark has this function i just cant seem to find it at all. Am i missing something or isnt this implmented?
Thanks, steven
timestamp help timeasked 26 Apr &#39;11, 16:57</description>
    </item>
    
    <item>
      <title>How to configure Atheros AR8151 PCI-E Gigabit Ethernet card to capture vlan tag packet?</title>
      <link>/questions/3739/how-to-configure-atheros-ar8151-pci-e-gigabit-ethernet-card-to-capture-vlan-tag-packet/</link>
      <pubDate>Wed, 27 Apr 2011 02:50:00 +0000</pubDate>
      
      <guid>/questions/3739/how-to-configure-atheros-ar8151-pci-e-gigabit-ethernet-card-to-capture-vlan-tag-packet/</guid>
      <description>How to configure Atheros AR8151 PCI-E Gigabit Ethernet card to capture vlan tag packet?  0 The vlan tag is stripped when I using Atheros AR8151 PCI-E Gigabit Ethernet card . Could you please tell me how to configure Ethernet card for capturing vlan tag packet?
vlan atheros configurationasked 27 Apr &#39;11, 02:50
Jasmine
1●2●2●3
accept rate: 0%
 edited 05 May &#39;11, 19:25 
cmaynard ♦♦
9.4k●10●38●142
What operating system are you using?</description>
    </item>
    
    <item>
      <title>call flow diagram program</title>
      <link>/questions/3740/call-flow-diagram-program/</link>
      <pubDate>Wed, 27 Apr 2011 03:41:00 +0000</pubDate>
      
      <guid>/questions/3740/call-flow-diagram-program/</guid>
      <description>call flow diagram program  0 Hi.
Beside Wireshark, is there any program that can open .pcap or .txt file and is able to draw a call flow diagram? I found SIPWorkbench, but it seems that displays only SIP traffic while I need to see also RTP and DIAMETER (from my .pcap and .txt trace). Thanks for any good advice. :-)
Bg,
Thomas.
flow program call display traceasked 27 Apr &#39;11, 03:41</description>
    </item>
    
    <item>
      <title>reading .cap file (Network Associates Sniffer v 2.00x) with wiretap</title>
      <link>/questions/3753/reading-cap-file-network-associates-sniffer-v-200x-with-wiretap/</link>
      <pubDate>Wed, 27 Apr 2011 09:43:00 +0000</pubDate>
      
      <guid>/questions/3753/reading-cap-file-network-associates-sniffer-v-200x-with-wiretap/</guid>
      <description>reading .cap file (Network Associates Sniffer v 2.00x) with wiretap  0 can anyone point me to wireshark documentation that will tell me how to write a standalone program that reads a .cap file (created by NA Sniffer version 2.0) and give me a pcap_pkthdr offset?
Thanks. Mark Young
na sniffer wiretapasked 27 Apr &#39;11, 09:43
markfyoung
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0The Libpcap file format is pretty straightforward.</description>
    </item>
    
    <item>
      <title>WS 1.2.16 - ___lc_codepage_func not found in msvcrt.dll</title>
      <link>/questions/3761/ws-1216-___lc_codepage_func-not-found-in-msvcrtdll/</link>
      <pubDate>Wed, 27 Apr 2011 13:58:00 +0000</pubDate>
      
      <guid>/questions/3761/ws-1216-___lc_codepage_func-not-found-in-msvcrtdll/</guid>
      <description>WS 1.2.16 - ___lc_codepage_func not found in msvcrt.dll  0 if W2k is no longer supported, can someone please update the User Guide section 1.2.2 to indicate that version 1.2.15 is the last available and supported version?
additionally, it would be a GoodThing&amp;lt;tm&amp;gt; if the installer would note this and refuse to continue... this check should be made before one is asked about uninstalling 1.2.15...
1.2.16 does actually install but dies on execution with the following error.</description>
    </item>
    
    <item>
      <title>Wireshark shows error message box while debugging in VS 2008</title>
      <link>/questions/3764/wireshark-shows-error-message-box-while-debugging-in-vs-2008/</link>
      <pubDate>Wed, 27 Apr 2011 15:03:00 +0000</pubDate>
      
      <guid>/questions/3764/wireshark-shows-error-message-box-while-debugging-in-vs-2008/</guid>
      <description>Wireshark shows error message box while debugging in VS 2008  1 I just downloaded the source zip of Wireshark 1.4.6, built it on Windows XP SP3, and tried starting it from the Visual Studio 2008 debugger. When Wireshark starts, I get this error message box:
Child dumpcap process died: Exception 0xc0000135
This message box also appears when I try to open the &#34;Capture Options&#34; or &#34;Interface List&#34; dialog. From &#34;</description>
    </item>
    
    <item>
      <title>Capturing Between Wireless Router &amp;amp; Cable Modem Problem</title>
      <link>/questions/3770/capturing-between-wireless-router-cable-modem-problem/</link>
      <pubDate>Wed, 27 Apr 2011 18:10:00 +0000</pubDate>
      
      <guid>/questions/3770/capturing-between-wireless-router-cable-modem-problem/</guid>
      <description>Capturing Between Wireless Router &amp;amp; Cable Modem Problem  0 Hi.
I am trying to capture packets bewtween my iPad and the Internet. Since I cannot capture directly from the iPad, I&#39;m using the hub-and-laptop approach.
I have placed a hub between my wireless router and my cable modem, and I have also attached my laptop to the hub, so I can use Wireshark to capture all the traffic going through the hub.</description>
    </item>
    
    <item>
      <title>Filtering for Weblogic JMI or t3 traffic</title>
      <link>/questions/3771/filtering-for-weblogic-jmi-or-t3-traffic/</link>
      <pubDate>Wed, 27 Apr 2011 18:12:00 +0000</pubDate>
      
      <guid>/questions/3771/filtering-for-weblogic-jmi-or-t3-traffic/</guid>
      <description>Filtering for Weblogic JMI or t3 traffic  0 I&#39;d like to know if there is an easy way to filter for Oracle Weblogic t3 traffic, which sits atop the Java RMI protocol.
I am losing heartbeat messages and experiencing various application timeouts. I have captured the traffic between the offending systems and would like to be able to determine if, for example, plackets are being sent but not received by the admin server.</description>
    </item>
    
    <item>
      <title>wireshark supporting NEXUS protocol analyzer?</title>
      <link>/questions/3783/wireshark-supporting-nexus-protocol-analyzer/</link>
      <pubDate>Thu, 28 Apr 2011 03:28:00 +0000</pubDate>
      
      <guid>/questions/3783/wireshark-supporting-nexus-protocol-analyzer/</guid>
      <description>wireshark supporting NEXUS protocol analyzer?  0 Hi, Does the wireshark support log files of NEXUS protocol analyzer?
thanks
nexus supportasked 28 Apr &#39;11, 03:28
solarisan
1●2●2●3
accept rate: 0%
1Can you be more specific? Are you referring to the NexusINSIGHT 3G analyzer, the Cisco Nexus switches, or something else named &#34;Nexus&#34; that generates capture files?
(28 Apr &#39;11, 10:45) Gerald Combs ♦♦yes Nexus Insight
(24 May &#39;11, 11:57) solarisan1See Chris Maynard&#39;s (cmaynard) answer, then.</description>
    </item>
    
    <item>
      <title>How to filter specific phone number(s) during capture?</title>
      <link>/questions/3785/how-to-filter-specific-phone-numbers-during-capture/</link>
      <pubDate>Thu, 28 Apr 2011 07:00:00 +0000</pubDate>
      
      <guid>/questions/3785/how-to-filter-specific-phone-numbers-during-capture/</guid>
      <description>How to filter specific phone number(s) during capture?  0 I am trying to setup a way to filter for specific phone phones during a wireshark capture. I am not sure what filter I should use. I tried the sip.To and sdp.phone filters with no success. Any ideas? Thanks!
filter phone numbersasked 28 Apr &#39;11, 07:00
Travis Young
31●1●1●4
accept rate: 0%
  
4 Answers:</description>
    </item>
    
    <item>
      <title>wanted RTP, got UDP (?!)</title>
      <link>/questions/3797/wanted-rtp-got-udp/</link>
      <pubDate>Thu, 28 Apr 2011 16:43:00 +0000</pubDate>
      
      <guid>/questions/3797/wanted-rtp-got-udp/</guid>
      <description>wanted RTP, got UDP (?!)  0 Hi.
I decided to break a trace on three parts with filtering SIP, RTP and DIAMETER protocol. For SIP and DIAMETER it went ok - I filtered the original trace and saved it as a new (trace) file. When a new file was opened, it was displayed ok.
But now, when I filter the original file with RTP protocol, save it as a new file and then open this new file, instead of RTP it shows like I filtered with UDP protocol.</description>
    </item>
    
    <item>
      <title>Favorite Question</title>
      <link>/questions/3801/favorite-question/</link>
      <pubDate>Thu, 28 Apr 2011 21:17:00 +0000</pubDate>
      
      <guid>/questions/3801/favorite-question/</guid>
      <description>Favorite Question  1 2I noticed that there is a &#34;Favorite Question&#34; badge. So ... how do you favorite a question?
question favoriteasked 28 Apr &#39;11, 21:17
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%
There you go!
(29 Apr &#39;11, 10:21) packethunterOK, but I was wondering how to do it so I could favorite someone else&#39;s question, not for the sake of earning a badge.
(29 Apr &#39;11, 10:32) cmaynard ♦♦</description>
    </item>
    
    <item>
      <title>Reconstruct mmse</title>
      <link>/questions/3806/reconstruct-mmse/</link>
      <pubDate>Fri, 29 Apr 2011 01:50:00 +0000</pubDate>
      
      <guid>/questions/3806/reconstruct-mmse/</guid>
      <description>Reconstruct mmse  0 Hi
When I provide wireshark with a pcap file containing packages of an mms where some of the packages are tcp-retransmissions, wireshark fails to assemble the mmse protocol. If I &#34;manually&#34; remove the retransmission tcp packages then wireshark works as expected and shows me the mmse protocol elements.
Is there a way to achive this without having to remove the retransmission tcp packages? Any ideas or help is much appreciated.</description>
    </item>
    
    <item>
      <title>SIP Issues</title>
      <link>/questions/3812/sip-issues/</link>
      <pubDate>Fri, 29 Apr 2011 07:28:00 +0000</pubDate>
      
      <guid>/questions/3812/sip-issues/</guid>
      <description>SIP Issues  1 Okay hopefully someone will be able to shed some light on what I am trying to do. Keep in mind that I am a phone guy and not a Network guy!
I am having a terrible Audio Issue with a voicemail server that is using SIP to connect to the PBX. I have been able to determine (through wireshark) that the audio is OK when leaving the server.</description>
    </item>
    
    <item>
      <title>capture connections/summaries only?</title>
      <link>/questions/3816/capture-connectionssummaries-only/</link>
      <pubDate>Fri, 29 Apr 2011 11:37:00 +0000</pubDate>
      
      <guid>/questions/3816/capture-connectionssummaries-only/</guid>
      <description>capture connections/summaries only?  0 dear sharkianers: is there any opportunity to capture nothing but date, ip &amp;amp; mac-address automatically each 24 hours to a file on windows? i tried the capturing with detailed options but that does log everything instead of the summary only.
connections windows summaryasked 29 Apr &#39;11, 11:37
Trucklejunior
1●1●1●2
accept rate: 0%
 edited 29 Apr &#39;11, 11:38 
  
One Answer:</description>
    </item>
    
    <item>
      <title>What are the units of time used in Wireshark</title>
      <link>/questions/3821/what-are-the-units-of-time-used-in-wireshark/</link>
      <pubDate>Fri, 29 Apr 2011 13:15:00 +0000</pubDate>
      
      <guid>/questions/3821/what-are-the-units-of-time-used-in-wireshark/</guid>
      <description>What are the units of time used in Wireshark  0 Qual é a unidade de tempo usada em wireshark? como é calculado, em ms,s...? obrigado.
(Or, for those who can&#39;t read Portuguese, a translation from Google Translate:
What is the unit of time used in wireshark? how is it calculated in ms, s...? Thank you.)
timeasked 29 Apr &#39;11, 13:15
Guilherme
1●2●2●2
accept rate: 0%
 edited 29 Apr &#39;11, 18:05</description>
    </item>
    
    <item>
      <title>What are the units of time used in Wireshark</title>
      <link>/questions/3822/what-are-the-units-of-time-used-in-wireshark/</link>
      <pubDate>Fri, 29 Apr 2011 14:06:00 +0000</pubDate>
      
      <guid>/questions/3822/what-are-the-units-of-time-used-in-wireshark/</guid>
      <description>What are the units of time used in Wireshark  0 What is the measure of time used in wireshark, ms, s ....? How do you calculate the time? Thank you.
timesasked 29 Apr &#39;11, 14:06
Guilherme
1●2●2●2
accept rate: 0%
 edited 29 Apr &#39;11, 18:08 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
0Internally, Wireshark&#39;s units of time are nanoseconds. However, not all packet time stamps have nanosecond resolution; the time stamps in pcap files, for example, have microsecond resolution, and there&#39;s no guarantee that the time stamps are accurate to the microsecond.</description>
    </item>
    
    <item>
      <title>analyzing, description - and marking packets/rows</title>
      <link>/questions/3827/analyzing-description-and-marking-packetsrows/</link>
      <pubDate>Fri, 29 Apr 2011 17:51:00 +0000</pubDate>
      
      <guid>/questions/3827/analyzing-description-and-marking-packetsrows/</guid>
      <description>analyzing, description - and marking packets/rows  0 Hi...I&#39;m back. :)
Now I&#39;m analyzing and describing protocol(s) traffic for purpose of my thesis/diploma. When a few rows are &#34;over&#34;, I&#39;d like to mark a few packets (rows) at once. How can I do that?
Combination of pressing and holding key CTRL while trying to mark more rows at once doesn&#39;t work.
BrT.
analyze row description packet markasked 29 Apr &#39;11, 17:51</description>
    </item>
    
    <item>
      <title>How can I manually resolve IP addresses?</title>
      <link>/questions/3832/how-can-i-manually-resolve-ip-addresses/</link>
      <pubDate>Fri, 29 Apr 2011 18:09:00 +0000</pubDate>
      
      <guid>/questions/3832/how-can-i-manually-resolve-ip-addresses/</guid>
      <description>How can I manually resolve IP addresses?  0 Here in front of m,e I have a reference IMS paper with many IP addresses. In the .pcap file, a few IP addresses were manually resolved so a trace is a little more &#34;likeable&#34;. I saved this trace file as a new one, and then opened this newly created file. At first it was ok -IP addresses were still displayed with names (words) -but now, when this new file was opened again, there are IP addresses again.</description>
    </item>
    
    <item>
      <title>build tshark failed on Mac OS X 10.6.7</title>
      <link>/questions/3841/build-tshark-failed-on-mac-os-x-1067/</link>
      <pubDate>Sat, 30 Apr 2011 04:58:00 +0000</pubDate>
      
      <guid>/questions/3841/build-tshark-failed-on-mac-os-x-1067/</guid>
      <description>build tshark failed on Mac OS X 10.6.7  0 I&#39;m build wireshark souce code with &#34;./configure --disable-wireshark&#34;, but I got errors:
Making all in wsutil
/bin/sh ../libtool --tag=CC --mode=compile gcc -DHAVE_CONFIG_H -I. -I.. -I./.. -I/usr/local/include
&#39;-DPLUGIN_DIR=&#34;/usr/local/lib/wireshark/plugins/1.5.2&#34;&#39; -Werror -DINET6 -no-cpp-precomp -D_U_=&#34;attribute((unused))&#34; -g -O2 -Wall -W -Wextra -Wdeclaration-after-statement -Wendif-labels -Wpointer-arith -Wno-pointer-sign -Wcast-align -Wformat-security -I/usr/local/include -D_REENTRANT -I/usr/local/include/glib-2.0 -I/usr/local/lib/glib-2.0/include -MT mpeg-audio.lo -MD -MP -MF .deps/mpeg-audio.Tpo -c -o mpeg-audio.lo mpeg-audio.c
mv -f .deps/mpeg-audio.Tpo .deps/mpeg-audio.Plo</description>
    </item>
    
    <item>
      <title>Capturing on Wi-Fi NIC with monitor mode off</title>
      <link>/questions/3842/capturing-on-wi-fi-nic-with-monitor-mode-off/</link>
      <pubDate>Sat, 30 Apr 2011 08:51:00 +0000</pubDate>
      
      <guid>/questions/3842/capturing-on-wi-fi-nic-with-monitor-mode-off/</guid>
      <description>Capturing on Wi-Fi NIC with monitor mode off  1 Hello,
I&#39;m trying to capture traffic passing through a Wi-Fi NIC, but with monitor mode off. When I set this up via capture options (pick my en1 interface, disable monitor mode) and click Start, I get a dialog that says this: &#34;Unable to set data link type (IEEE802_11 is not one of the DLTs supported by this device). Please report this to the Wireshark developers.</description>
    </item>
    
    <item>
      <title>Request: INVITE &amp;quot;address of SIP client&amp;quot;, with session description</title>
      <link>/questions/3855/request-invite-address-of-sip-client-with-session-description/</link>
      <pubDate>Sat, 30 Apr 2011 15:58:00 +0000</pubDate>
      
      <guid>/questions/3855/request-invite-address-of-sip-client-with-session-description/</guid>
      <description>Request: INVITE &amp;ldquo;address of SIP client&amp;rdquo;, with session description  0 SIP client sends request to SBC.&#34;unknown&#34; IP (I&#39;m waiting for the answer from my collaborator what&#39;s that IP) sends request to P-CSCF.Question:
When sending request INVITE to SBC, SIP client tells him its SIP address, right? When sending request INVITE to P-CSCF, does this &#34;unknown&#34; IP know SIP address or wants it?
(I suspect this &#34;unknown&#34; IP belongs to device from Ericsson TSP applications &#34;</description>
    </item>
    
    <item>
      <title>what are the interfaces (in wireshark) that I should use to analyse RPL packets installed on motes?</title>
      <link>/questions/3862/what-are-the-interfaces-in-wireshark-that-i-should-use-to-analyse-rpl-packets-installed-on-motes/</link>
      <pubDate>Sun, 01 May 2011 11:08:00 +0000</pubDate>
      
      <guid>/questions/3862/what-are-the-interfaces-in-wireshark-that-i-should-use-to-analyse-rpl-packets-installed-on-motes/</guid>
      <description>what are the interfaces (in wireshark) that I should use to analyse RPL packets installed on motes?  0 Hi! I need to analyse RPL packets. For that I use an application that sniff all packets in the network. I install this application on mote and I use it USB port for sniffing. But I use wireshark I don&#39;t find this USB interface to analyse packets. What interface should I use to capture RPL packets exchanged between motes?</description>
    </item>
    
    <item>
      <title>meaning of SIP message &amp;quot;Continuation&amp;quot; from S-CSCF to Application Server?</title>
      <link>/questions/3865/meaning-of-sip-message-continuation-from-s-cscf-to-application-server/</link>
      <pubDate>Sun, 01 May 2011 16:29:00 +0000</pubDate>
      
      <guid>/questions/3865/meaning-of-sip-message-continuation-from-s-cscf-to-application-server/</guid>
      <description>meaning of SIP message &amp;ldquo;Continuation&amp;rdquo; from S-CSCF to Application Server?  0 What can/could this message mean?
s-cscf message continue server applicationasked 01 May &#39;11, 16:29
wired
44●13●14●17
accept rate: 9%
Are &#34;Continuation&#34; messages TCP keep-alive messages?
Or is this just information message which (can) tell us that INVITE requests and (re)tries (Status: 100 Trying) (will) continue?
(01 May &#39;11, 16:40) wired  
4 Answers:
  
0i, &#34;</description>
    </item>
    
    <item>
      <title>MAC OSX 10.6.3 - When I Open Wireshark it shows on dock then closes</title>
      <link>/questions/3868/mac-osx-1063-when-i-open-wireshark-it-shows-on-dock-then-closes/</link>
      <pubDate>Sun, 01 May 2011 23:32:00 +0000</pubDate>
      
      <guid>/questions/3868/mac-osx-1063-when-i-open-wireshark-it-shows-on-dock-then-closes/</guid>
      <description>MAC OSX 10.6.3 - When I Open Wireshark it shows on dock then closes  1 When I open Wireshark, it just shows on the dock as if it opened, then it closes itself, why is this?
When I run it using terminal it says: The domain/default pair of (kCFPreferencesAnyApplication, AppleHighlightColor) does not exist dyld: Library not loaded: /usr/X11/lib/libfreetype.6.dylib Referenced from: /Applications/Wireshark.app/Contents/Resources/bin/wireshark-bin Reason: Incompatible library version: wireshark-bin requires version 13.0.0 or later, but libfreetype.</description>
    </item>
    
    <item>
      <title>Link to download CLI version of Wireshark with FCoE capabilties</title>
      <link>/questions/3869/link-to-download-cli-version-of-wireshark-with-fcoe-capabilties/</link>
      <pubDate>Sun, 01 May 2011 23:33:00 +0000</pubDate>
      
      <guid>/questions/3869/link-to-download-cli-version-of-wireshark-with-fcoe-capabilties/</guid>
      <description>Link to download CLI version of Wireshark with FCoE capabilties  0 Hi , Kindly provide a link to download CLI version of Wireshark with FCoE capabilities.
fcoeasked 01 May &#39;11, 23:33
searching
1●3●3●4
accept rate: 0%
  
One Answer:
  
1You can download the latest version of Wireshark here and TShark comes with it.
TShark is a command-line based network protocol analyzer.
It is part of the Wireshark distribution.</description>
    </item>
    
    <item>
      <title>When I try and run a fresh install from terminal it says...</title>
      <link>/questions/3872/when-i-try-and-run-a-fresh-install-from-terminal-it-says/</link>
      <pubDate>Mon, 02 May 2011 01:22:00 +0000</pubDate>
      
      <guid>/questions/3872/when-i-try-and-run-a-fresh-install-from-terminal-it-says/</guid>
      <description>When I try and run a fresh install from terminal it says&amp;hellip;  0 The domain/default pair of (kCFPreferencesAnyApplication, AppleHighlightColor) does not exist dyld: Library not loaded: /usr/X11/lib/libfreetype.6.dylib Referenced from: /Applications/Wireshark.app/Contents/Resources/bin/wireshark-bin Reason: Incompatible library version: wireshark-bin requires version 13.0.0 or later, but libfreetype.6.dylib provides version 10.0.0
What does this mean?
failedasked 02 May &#39;11, 01:22
Tim Nethers
16●2●2●4
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Monitor network traffic by user</title>
      <link>/questions/3880/monitor-network-traffic-by-user/</link>
      <pubDate>Mon, 02 May 2011 09:32:00 +0000</pubDate>
      
      <guid>/questions/3880/monitor-network-traffic-by-user/</guid>
      <description>Monitor network traffic by user  0 Hey there- I&#39;m giving myself a crash course in Wireshark this morning, as a client (I&#39;m an IT consultant) is looking to have us analyze their network traffic to see what users are hogging bandwidth, and if possible, to see what host they are going to (e.g. Pandora). I&#39;m not sure if Wireshark has this capability out of the box, though I get the impression it does if I know how and where to look.</description>
    </item>
    
    <item>
      <title>called party unknown</title>
      <link>/questions/3883/called-party-unknown/</link>
      <pubDate>Mon, 02 May 2011 13:01:00 +0000</pubDate>
      
      <guid>/questions/3883/called-party-unknown/</guid>
      <description>called party unknown  0 Prepaid VoIP call with SIP phone on unknown fixed telephone number. You have addresses of HSS, SBC, SIP client, P-CSCF, SIP Application Server, S-CSCF and MGC. How to determine which number is called, for which requests and/or answers should I need to look for?
Tnx.
answer unknown request called partyasked 02 May &#39;11, 13:01
wired
44●13●14●17
accept rate: 9%
Maybe code 180 Ringing?
(02 May &#39;11, 13:02) wiredCould the RTP traffic be a stiching point?</description>
    </item>
    
    <item>
      <title>Truncated cookies</title>
      <link>/questions/3885/truncated-cookies/</link>
      <pubDate>Mon, 02 May 2011 14:28:00 +0000</pubDate>
      
      <guid>/questions/3885/truncated-cookies/</guid>
      <description>Truncated cookies  1 Hi
I&#39;m new to wireshark and trying to get more information on how to get the full cookies that isn&#39;t &#34;truncated&#34;? The snaplen is not enabled.
example: [truncated] Cookie: OAX=VDdXBE21tLMAAsVW; member_type=0; __utma=70287432xxxxxxxxxxxxxxxxxxxxxxxxx etc
In advance thank you!
Regards C
cookie truncatedasked 02 May &#39;11, 14:28
Mr C
16●1●1●2
accept rate: 0% 
 edited 03 May &#39;11, 19:22 
cmaynard ♦♦
9.4k●10●38●142
  
2 Answers:</description>
    </item>
    
    <item>
      <title>6LoWPAN Source Address Depacking</title>
      <link>/questions/3892/6lowpan-source-address-depacking/</link>
      <pubDate>Tue, 03 May 2011 01:43:00 +0000</pubDate>
      
      <guid>/questions/3892/6lowpan-source-address-depacking/</guid>
      <description>6LoWPAN Source Address Depacking  0 Hi!
I am working with 6LoWPAN protocol, and I am dissecting some packets to understand it correctly. When I have started sniffing my own packets I set the address: fe80::0011:22ff:fe33:4455/64.
When wireshark extract the information of this packets, the generated address is: 2002:db8::0011:22ff:fe33:4455
Why not FE80::...? As I&#39;ve read in the RFC...?
I am reading the internet-draft for 6lowpan comrpession of IPv6 datagrams of February 2011.</description>
    </item>
    
    <item>
      <title>Timestamps drift from real time</title>
      <link>/questions/3893/timestamps-drift-from-real-time/</link>
      <pubDate>Tue, 03 May 2011 02:26:00 +0000</pubDate>
      
      <guid>/questions/3893/timestamps-drift-from-real-time/</guid>
      <description>Timestamps drift from real time  0 1I&#39;ve been using Wireshark/Ethereal for several years and now I observe a very odd behaviour (Wireshark 1.4.2/1.4.6 and PCap 4.1.2) on a HP Compaq 8000 Elite CMT with Windows XP SP3 32bit.
When I start the capture, the timestamp of the immediately captured packet is okay. The more time passes, the more does the timestamp deviate from the real time. That is, after 10 seconds of real time passed, Wireshark will timestamp that only 4 seconds passed - no matter what the timeview format is.</description>
    </item>
    
    <item>
      <title>Capture mail connection attempts</title>
      <link>/questions/3894/capture-mail-connection-attempts/</link>
      <pubDate>Tue, 03 May 2011 03:18:00 +0000</pubDate>
      
      <guid>/questions/3894/capture-mail-connection-attempts/</guid>
      <description>Capture mail connection attempts  0 I manage a site that will not receive mail from 2 seperate domains (that I know of). I need to find out why mail is not being delivered from these domains. The senders do receive an NDR stating that the message was rejected by my clients server as &#34;the message is too old&#34;. They have a simple setup - an SBS 2003 server &amp;amp; a Billion router on the same subnet.</description>
    </item>
    
    <item>
      <title>Help Analyzing for LDAP/Active Directory Errors</title>
      <link>/questions/3898/help-analyzing-for-ldapactive-directory-errors/</link>
      <pubDate>Tue, 03 May 2011 05:49:00 +0000</pubDate>
      
      <guid>/questions/3898/help-analyzing-for-ldapactive-directory-errors/</guid>
      <description>Help Analyzing for LDAP/Active Directory Errors  0 Hello - I am a very new user to Wireshark and definitely have no experience in reading or interpreting the capture files.
I am working with a client to find out why an application fails to return/authenticate a user accouunt when installing this application.
The server the application is being installed on is a member server and I am sure there are errors when calling to the Domain Controller.</description>
    </item>
    
    <item>
      <title>Prepaid VoIP phone?</title>
      <link>/questions/3899/prepaid-voip-phone/</link>
      <pubDate>Tue, 03 May 2011 06:37:00 +0000</pubDate>
      
      <guid>/questions/3899/prepaid-voip-phone/</guid>
      <description>Prepaid VoIP phone?  0 Can VoIP phone use prepaid card?
I&#39;m asking because, in my case, from request INVITE, it looks like a call was established with subscription (billed) number. And, as my cooworker said, calling part was prepaid...hmmm...
phone prepaid voip card simasked 03 May &#39;11, 06:37
wired
44●13●14●17
accept rate: 9%
 edited 03 May &#39;11, 11:17 
Gerald Combs ♦♦
3.3k●9●22●58
Sorry to be &#34;that guy&#34;, but someone has to.</description>
    </item>
    
    <item>
      <title>truncated fields in tshark</title>
      <link>/questions/3900/truncated-fields-in-tshark/</link>
      <pubDate>Tue, 03 May 2011 07:42:00 +0000</pubDate>
      
      <guid>/questions/3900/truncated-fields-in-tshark/</guid>
      <description>truncated fields in tshark  0 When I try to fetch ntlm fields from a sniff file the fields are truncated to the first byte.
tshark -r file.pcap -T fields -e ntlmssp.auth.domain -e ntlmssp.auth.username -R ntlmssp.auth.username
output:
NULL NULL
B A
E A
D a
NULL NULL
B A
A A
D A
E a
For other string fields, this works fine, also in Wireshark itself, I get the complete string.</description>
    </item>
    
    <item>
      <title>no HTTP packets being captured</title>
      <link>/questions/3904/no-http-packets-being-captured/</link>
      <pubDate>Tue, 03 May 2011 13:06:00 +0000</pubDate>
      
      <guid>/questions/3904/no-http-packets-being-captured/</guid>
      <description>no HTTP packets being captured  0 hello, i use WS to capture the packtes from and to my IP-Camera Sony RZ-50 but Wireshark dont shows HTTP Packets in the Capture file. i dont have a Capture Filter running and i use the newest stable version 1.4.6
thanx in advance Michael
httpasked 03 May &#39;11, 13:06
haylebob
1●2●2●3
accept rate: 0%
Can you provide some more details (like the network interface used and how you&#39;re creating traffic)?</description>
    </item>
    
    <item>
      <title>Is there dissector for Cisco RUDP/BSM Version 1 used for ISDN/PRI  backhaul?</title>
      <link>/questions/3907/is-there-dissector-for-cisco-rudpbsm-version-1-used-for-isdnpri-backhaul/</link>
      <pubDate>Tue, 03 May 2011 23:46:00 +0000</pubDate>
      
      <guid>/questions/3907/is-there-dissector-for-cisco-rudpbsm-version-1-used-for-isdnpri-backhaul/</guid>
      <description>Is there dissector for Cisco RUDP/BSM Version 1 used for ISDN/PRI backhaul?  0 Hello, team! I use Wireshark for viewing Cisco&#39;s SLT RUDP/BSMV0 (Backhaul session Manager Version 0) used for SS7 ISUP/MTP3 management backhaul. But Cisco also uses another flavor of RUDP/SM stack called BSM V1 (version 1 versus Version 0 used for SS7). It used at place where IUA should be used namely for backhauling ISDN PRI from Media Gateway to Media Gateway Controller.</description>
    </item>
    
    <item>
      <title>QOS, delivery order decoded as Traffic Class?</title>
      <link>/questions/3919/qos-delivery-order-decoded-as-traffic-class/</link>
      <pubDate>Wed, 04 May 2011 07:06:00 +0000</pubDate>
      
      <guid>/questions/3919/qos-delivery-order-decoded-as-traffic-class/</guid>
      <description>QOS, delivery order decoded as Traffic Class?  0 Hi,
I&#39;ve question about QOS decoded message. why for Delivery order below become &#34;Streaming Class&#34; ? not Without delivery order (&#39;no&#39;), the number I trace subscribed with Streaming Class.
GSM A-I/F DTAP - Activate PDP Context Accept Protocol Discriminator: GPRS session management messages 1... .... = TI flag: allocated by receiver .000 .... = TIO: 0 .... 1010 = Protocol discriminator: GPRS session management messages (10) 01.</description>
    </item>
    
    <item>
      <title>Wireshark cannot capture the network traffic of Cisco 2811 router</title>
      <link>/questions/3923/wireshark-cannot-capture-the-network-traffic-of-cisco-2811-router/</link>
      <pubDate>Wed, 04 May 2011 08:55:00 +0000</pubDate>
      
      <guid>/questions/3923/wireshark-cannot-capture-the-network-traffic-of-cisco-2811-router/</guid>
      <description>Wireshark cannot capture the network traffic of Cisco 2811 router  0 1On Cisco 2811 router, I type the following configuration:
config t ip traffic-export profile newprofile interface Fa0/1 bidirectional mac-address {the MAC address of the PC with Wireshark installed} incoming sample one-in-every 2 outgoing sample one-in-every 2 exit interface Fa0/0 ip traffic-export apply newprofileI open Wireshark on the PC and try to capture the network traffic of the 2811 router I type the IP of the 2811 router as the &#34;</description>
    </item>
    
    <item>
      <title>Install Wireshark Via Group Policy</title>
      <link>/questions/3924/install-wireshark-via-group-policy/</link>
      <pubDate>Wed, 04 May 2011 08:56:00 +0000</pubDate>
      
      <guid>/questions/3924/install-wireshark-via-group-policy/</guid>
      <description>Install Wireshark Via Group Policy  0 Is this possible? I have extracted the executable file, but I don&#39;t see a .MSI file
installasked 04 May &#39;11, 08:56
DelayedSynapsis
1●1●1●1
accept rate: 0%
  
One Answer:
  
0There&#39;s no MSI in there, so that&#39;s not possible. If you manage to wrap the EXE installer that would work, but I&#39;m not even aware that can be done.</description>
    </item>
    
    <item>
      <title>Capture bad 802.11b packet</title>
      <link>/questions/3926/capture-bad-80211b-packet/</link>
      <pubDate>Wed, 04 May 2011 11:11:00 +0000</pubDate>
      
      <guid>/questions/3926/capture-bad-80211b-packet/</guid>
      <description>Capture bad 802.11b packet  0 I want to capture the 802.11b packets with bad CRC. Actually I am sending the packets from some terminal A to terminal B and creating self-defined interference to toggle the bitstream of the packets so that CRC may not be passed. I want to capture that packet for analysis purpose. Any help would be greatly appreciated Nadeem SEECS, NUST
802.11basked 04 May &#39;11, 11:11</description>
    </item>
    
    <item>
      <title>how can I capture RPL packets using wireshark 1.5?</title>
      <link>/questions/3934/how-can-i-capture-rpl-packets-using-wireshark-15/</link>
      <pubDate>Thu, 05 May 2011 03:19:00 +0000</pubDate>
      
      <guid>/questions/3934/how-can-i-capture-rpl-packets-using-wireshark-15/</guid>
      <description>how can I capture RPL packets using wireshark 1.5?  0 Hi!
I need to analyse RPL packets exchanged between telosb motes. Even the interfaces that wiresshark give to me can&#39;t capture RPL packets. Please guide me how can I capture RPL packets using wireshark 1.5? Is there any configuration that I have to add? Great thanks!
capture packets rplasked 05 May &#39;11, 03:19
RCH
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Unable to edit my comments</title>
      <link>/questions/3937/unable-to-edit-my-comments/</link>
      <pubDate>Thu, 05 May 2011 06:44:00 +0000</pubDate>
      
      <guid>/questions/3937/unable-to-edit-my-comments/</guid>
      <description>Unable to edit my comments  0 I can edit my comments, as long as I am logged in to Ask Wireshark.
After logging out and in, I cannot edit my comments anymore. The only option I get is to delete them.
BTW
I still can edit|delete my answers.
ask.wireshark.orgasked 05 May &#39;11, 06:44
joke
1.3k●4●9●34
accept rate: 9% 
  
One Answer:
  
2 That&#39;s actually a feature: you only have 60 minutes to edit your comments.</description>
    </item>
    
    <item>
      <title>why can I capture one direction packets?</title>
      <link>/questions/3938/why-can-i-capture-one-direction-packets/</link>
      <pubDate>Thu, 05 May 2011 07:16:00 +0000</pubDate>
      
      <guid>/questions/3938/why-can-i-capture-one-direction-packets/</guid>
      <description>why can I capture one direction packets?  0 in monitoring mode with wireless card under linux, I can only cap the packets from AP to station. how can I cap the packets both direction? thx
monitoring modeasked 05 May &#39;11, 07:16
leinwpu
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Logging all data through router</title>
      <link>/questions/3942/logging-all-data-through-router/</link>
      <pubDate>Thu, 05 May 2011 08:00:00 +0000</pubDate>
      
      <guid>/questions/3942/logging-all-data-through-router/</guid>
      <description>Logging all data through router  0 I have a legal requirement to log all data passing through a wireless router. Is this something Wireshark can do, assuming the router has a promiscuous mode available? Does Wireshark have any features to facilitate this (automated mode, starting a new file at 00:00 each day, etc.)?
logging dumpcap automatedasked 05 May &#39;11, 08:00
Brian Lewis
1●1●1●1
accept rate: 0%
 edited 05 May &#39;11, 09:16</description>
    </item>
    
    <item>
      <title>Wireshark 1.5.1: Export SMB Objects</title>
      <link>/questions/3943/wireshark-151-export-smb-objects/</link>
      <pubDate>Thu, 05 May 2011 08:03:00 +0000</pubDate>
      
      <guid>/questions/3943/wireshark-151-export-smb-objects/</guid>
      <description>Wireshark 1.5.1: Export SMB Objects  1 Wireshark 1.5.1 can export SMB objects.
Jose Pico submitted a patch to add this feature to Wireshark.
The white paper: A tool for capturing SMB files with Wireshark by David Perez &amp;amp; Jose Pico is freely available.
The white paper describes the plug-in they have created, the identifying of the SMB streams and gives an explanation of the columns in the &#34;Wireshark: Export SMB object list&#34;</description>
    </item>
    
    <item>
      <title>Adding Comments to a Packet</title>
      <link>/questions/3944/adding-comments-to-a-packet/</link>
      <pubDate>Thu, 05 May 2011 08:17:00 +0000</pubDate>
      
      <guid>/questions/3944/adding-comments-to-a-packet/</guid>
      <description>Adding Comments to a Packet  0 Does Wireshark have a way to enter a comment on a specific packet for future reference? (e.g. Here is the start of the issue.)
annotate pcapng commentsasked 05 May &#39;11, 08:17
CarlT
1●2●2●2
accept rate: 0%
 edited 05 May &#39;11, 08:39 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
1The pcapng file format supports this, but Wireshark itself does not yet have good support for it.</description>
    </item>
    
    <item>
      <title>tcpdump vs wireshark differences (packets merged?)</title>
      <link>/questions/3949/tcpdump-vs-wireshark-differences-packets-merged/</link>
      <pubDate>Thu, 05 May 2011 08:53:00 +0000</pubDate>
      
      <guid>/questions/3949/tcpdump-vs-wireshark-differences-packets-merged/</guid>
      <description>tcpdump vs wireshark differences (packets merged?)  0 This started while trying figure out why loading a web page in a browser from apache via HTTP was so very slow going through a pinhole from an untrusted network to a trusted one.
I thought it was smoothwall related, see my post here http://community.smoothwall.org/forum/viewtopic.php?p=297864#p297864 but not so sure and drove me to using wireshark and tcpdump.
This is what I am seeing and lead to my main question of why does wireshark show 3 packets but tcpdump only shows 1 big packet?</description>
    </item>
    
    <item>
      <title>Continuous [ack] [psh ack] cycle</title>
      <link>/questions/3959/continuous-ack-psh-ack-cycle/</link>
      <pubDate>Thu, 05 May 2011 11:24:00 +0000</pubDate>
      
      <guid>/questions/3959/continuous-ack-psh-ack-cycle/</guid>
      <description>Continuous [ack] [psh ack] cycle  0 When I open a raw tcp socket i get this continuous ack psh ack sequence. Any idea why it doesn&#39;t finish negotiating?
No. Time Source Destination Protocol Info 1 0.000000 142.152.5.87 10.103.101.141 TCP esp-encap &amp;gt; rtcm-sc104 [SYN] Seq=0 Win=64240 Len=0 MSS=1460
Frame 1 (62 bytes on wire, 62 bytes captured) Ethernet II, Src: Vmware_9d:42:ae (00:50:56:9d:42:ae), Dst: All-HSRP-routers_63 (00:00:0c:07:ac:63) Internet Protocol, Src: 142.152.5.87 (142.152.5.87), Dst: 10.</description>
    </item>
    
    <item>
      <title>Weird icmp traffic - redirect for network</title>
      <link>/questions/3961/weird-icmp-traffic-redirect-for-network/</link>
      <pubDate>Thu, 05 May 2011 12:39:00 +0000</pubDate>
      
      <guid>/questions/3961/weird-icmp-traffic-redirect-for-network/</guid>
      <description>Weird icmp traffic - redirect for network  0 I just started seeing this strange icmp traffic generated from my pc (192.168.0.229). Can anyone explain why is this happening? In addition to my anti virus protection (Symantec) I&#39;ve tried several other scanners and haven&#39;t detected anything. The icmp payload seems strange as well (192.168.0.209 is not a router, 192.168.0.244 is a domain controller).
Thank you. link text
redirect icmp networkasked 05 May &#39;11, 12:39</description>
    </item>
    
    <item>
      <title>Ping Packets Sent &amp;amp; Received Yet Host Unreachable</title>
      <link>/questions/3965/ping-packets-sent-received-yet-host-unreachable/</link>
      <pubDate>Thu, 05 May 2011 15:21:00 +0000</pubDate>
      
      <guid>/questions/3965/ping-packets-sent-received-yet-host-unreachable/</guid>
      <description>Ping Packets Sent &amp;amp; Received Yet Host Unreachable  0 We have a monitoring system on our Windows 7 Ultimate ( 64 bit, SP 1 ) that pings 1000+ IPs every 30 seconds to record latency and &#34;uptime&#34;. I have 3 IPs so far that work on every other connection/computer I try.
I have verified firewall ( hardware ) is doing everything properly. I am able to ping the same IPs from another server we have at the same location.</description>
    </item>
    
    <item>
      <title>camel sccp routing on global title decode</title>
      <link>/questions/3974/camel-sccp-routing-on-global-title-decode/</link>
      <pubDate>Fri, 06 May 2011 00:58:00 +0000</pubDate>
      
      <guid>/questions/3974/camel-sccp-routing-on-global-title-decode/</guid>
      <description>camel sccp routing on global title decode  0 I am trying to decode SCTP frames that contain CAPv2 (Camel) operations however decoding stops at SCCP level. SCCP addresses contain: - Address Indicator H&#39;0989 - Route on GT - GT indicator: Translation Type only - SSN not present - Point Code present - Point Code - Global Title - Translation Type - Address information (digits)
The Addresses on SCCP do not contain SSN, instead routing is performed solely on global title containing Translation Type and Address Information.</description>
    </item>
    
    <item>
      <title>unexplainable time jumps</title>
      <link>/questions/3976/unexplainable-time-jumps/</link>
      <pubDate>Fri, 06 May 2011 05:46:00 +0000</pubDate>
      
      <guid>/questions/3976/unexplainable-time-jumps/</guid>
      <description>unexplainable time jumps  0 The sniff file has the right timestamp in the file name and on the OS after writing. But in the sniff file ever 20 min. the time jump back. The OS has the right time. There is no NTP how change time or make trouble. Ideas?
timeasked 06 May &#39;11, 05:46
chofmann
1●1●1●1
accept rate: 0%
Do you know the hardware time source being used by the OS?</description>
    </item>
    
    <item>
      <title>What&amp;#x27;s an appropriate snaplen for HTTPS traffic?</title>
      <link>/questions/3978/whats-an-appropriate-snaplen-for-https-traffic/</link>
      <pubDate>Fri, 06 May 2011 09:29:00 +0000</pubDate>
      
      <guid>/questions/3978/whats-an-appropriate-snaplen-for-https-traffic/</guid>
      <description>What&amp;rsquo;s an appropriate snaplen for HTTPS traffic?  0 My web server logs are telling me that I&#39;m having trouble receiving data from my customers. I want to review the traffic to look for anomalies (lost packets and so forth). The actual traffic is encrypted HTTP, so I don&#39;t care about the data beyond the information that should be present in the headers (length, etc).
My plan is to run dumpcap, with appropriate arguments, to log data to a file for later analysis.</description>
    </item>
    
    <item>
      <title>How could I resolve my network issue given this capture attached?</title>
      <link>/questions/3983/how-could-i-resolve-my-network-issue-given-this-capture-attached/</link>
      <pubDate>Sat, 07 May 2011 01:28:00 +0000</pubDate>
      
      <guid>/questions/3983/how-could-i-resolve-my-network-issue-given-this-capture-attached/</guid>
      <description>How could I resolve my network issue given this capture attached?  0 I have a problem emerge recently with one specific service that I use - I currently can not &#34;sync&#34; the application from my MacBook on my home network as it seems to time out. When I connect my MacBook to another internet connection connection (e.g. my travel USB dongle with internet connection) it sync&#39;s up fine straight away.</description>
    </item>
    
    <item>
      <title>request REGISTER - fetch bindings and answer (1 bindings)</title>
      <link>/questions/3999/request-register-fetch-bindings-and-answer-1-bindings/</link>
      <pubDate>Sun, 08 May 2011 05:29:00 +0000</pubDate>
      
      <guid>/questions/3999/request-register-fetch-bindings-and-answer-1-bindings/</guid>
      <description>request REGISTER - fetch bindings and answer (1 bindings)  0 What&#39;s the meaning of &#34;(fetch) bindings&#34;?
answer request register binding fetchasked 08 May &#39;11, 05:29
wired
44●13●14●17
accept rate: 9%
Binding: A process associates its input or output channel file descriptors (sockets) with a port number and an IP address, a process known as binding, to send and receive data via the network.
Right definition?
(From page http://en.wikipedia.org/wiki/UDP_ports.)
(08 May &#39;11, 05:44) wired</description>
    </item>
    
    <item>
      <title>meaning of wlsscid?</title>
      <link>/questions/4002/meaning-of-wlsscid/</link>
      <pubDate>Sun, 08 May 2011 06:53:00 +0000</pubDate>
      
      <guid>/questions/4002/meaning-of-wlsscid/</guid>
      <description>meaning of wlsscid?  0 88 10.665353 SIP client A-SBC SIP Request: ACK sip:&#34;mobile_number_in_local_format&#34;@&#34;A-SBC_IP_address&#34;:5060;transport=udp;wlsscid=45d67fb8e542f2b9
What is wlsscid?
identification wlsscidasked 08 May &#39;11, 06:53
wired
44●13●14●17
accept rate: 9%
  
One Answer:
  
1 wlsscid is a Weblogic SIP server parameter
Table 1-2 WebLogic SIP Server Parameters
wlsscid identifies the cluster ID of the cluster that originated the SIP message during a software upgrade. The sideways forwarding mechanism uses this attribute to ensure that messages are delivered to a compatible cluster.</description>
    </item>
    
    <item>
      <title>Diameter Server - Accounting Answer</title>
      <link>/questions/4009/diameter-server-accounting-answer/</link>
      <pubDate>Sun, 08 May 2011 13:59:00 +0000</pubDate>
      
      <guid>/questions/4009/diameter-server-accounting-answer/</guid>
      <description>Diameter Server - Accounting Answer  0 If HSS (Home Subscriber Server) acts as a Diameter Client and is sending Accounting Requests (I see in traffic), who acts as a Diameter Server?
answer diameter client request accountingasked 08 May &#39;11, 13:59
wired
44●13●14●17
accept rate: 9%
As I know from studying and book IMS Signalling (by Ericsson), HSS acts as a Diameter Server? Why Client in my trace? :-s
(08 May &#39;11, 14:23) wiredyou should know, HSS server can also invoke requests.</description>
    </item>
    
    <item>
      <title>extract mac address using mate</title>
      <link>/questions/4013/extract-mac-address-using-mate/</link>
      <pubDate>Mon, 09 May 2011 00:45:00 +0000</pubDate>
      
      <guid>/questions/4013/extract-mac-address-using-mate/</guid>
      <description>extract mac address using mate  0 Hi,
Part of the flow is the source and destination mac address but looks like mate isnt capable to extract eth.addr , can it be configured ?
Sample which i tried:
Pdu icmp_pdu Proto icmp Transport ip {
 Extract addr From ip.addr; Extract source_addr From eth.addr; Extract icmp_type From icmp.type;};
Gop icmp_ses On icmp_pdu Match (addr, addr, source_addr, source_addr) {
Start (icmp_type=8); Stop (icmp_type=0); Extra (addr, addr, source_addr, source_addr, icmp_type);};</description>
    </item>
    
    <item>
      <title>ZoneAlarm warning for 64-bit Windows installer</title>
      <link>/questions/4019/zonealarm-warning-for-64-bit-windows-installer/</link>
      <pubDate>Tue, 10 May 2011 08:41:00 +0000</pubDate>
      
      <guid>/questions/4019/zonealarm-warning-for-64-bit-windows-installer/</guid>
      <description>ZoneAlarm warning for 64-bit Windows installer  0 Dear sirs,
Zone alarm reports this file as a &#39;zombie&#39;.
Regards
C Gilbert
zonealarm win64 installerasked 10 May &#39;11, 08:41
SwissBob
1●1●1●1
accept rate: 0%
 edited 10 May &#39;11, 15:13 
Gerald Combs ♦♦
3.3k●9●22●58
Has ZoneAlarm updated itself since May 10? If so, is it still reporting a problem with the Wireshark installer?
(14 May &#39;11, 11:03) Gerald Combs ♦♦</description>
    </item>
    
    <item>
      <title>From Godaddy</title>
      <link>/questions/4025/from-godaddy/</link>
      <pubDate>Tue, 10 May 2011 19:15:00 +0000</pubDate>
      
      <guid>/questions/4025/from-godaddy/</guid>
      <description>From Godaddy  0 I recently have been having issues with the speed of uploading files to an FTP. My site is hosted with GoDaddy. They sent me this link to follow and test. http://products.secureserver.net/hosting/wireshark/
When I try to follow the instructions on the link, I get to step #3, but I get an error that there are no interfaces available. How can I fix this so I can move on to the next step?</description>
    </item>
    
    <item>
      <title>arabic text</title>
      <link>/questions/4027/arabic-text/</link>
      <pubDate>Tue, 10 May 2011 23:13:00 +0000</pubDate>
      
      <guid>/questions/4027/arabic-text/</guid>
      <description>arabic text  0 Hello friends, I have configured capture on ASA firewall and i can see everything when downloaded to wireshark application. i tested MSN conversation and POP protocol traffic with arabic text but i didn&#39;t see the arabic text when viewing it in wireshark. Does the problem with ASA itself when capturing the traffic or from the wireshark itself? and how can i see the sniffed arabic text?</description>
    </item>
    
    <item>
      <title>Problem with analyse SCTP associations</title>
      <link>/questions/4031/problem-with-analyse-sctp-associations/</link>
      <pubDate>Wed, 11 May 2011 05:56:00 +0000</pubDate>
      
      <guid>/questions/4031/problem-with-analyse-sctp-associations/</guid>
      <description>Problem with analyse SCTP associations  0 Hi,
I have a problem with SCTP association analysis. I have 2 associations from 2 nodes (node1 has IP addresses 172.20.3.20 and 172.20.131.20 and node2 172.20.3.21) to one node3 (172.20.0.2 and 172.20.128.2) nodes1 and 2 have different verification tags and node3 has 2 verification tags per node 1 and 2.
In &#34;Show All associations&#34; I see 2 associations - ok the I select one of them and click to Analyse - I see window in which in Endpoint section I see all addresses of nodes 1 and 2 (means 4 IP addresses) - but I choosed only one association (for example between node1 and node3) - this is wrong.</description>
    </item>
    
    <item>
      <title>Using Wireshark</title>
      <link>/questions/4032/using-wireshark/</link>
      <pubDate>Wed, 11 May 2011 05:59:00 +0000</pubDate>
      
      <guid>/questions/4032/using-wireshark/</guid>
      <description>Using Wireshark  0 I&#39;m new to wireshark and analyzing traces. I have a tcpdump from a linux system. Once opened in wireshark, how can I get the Ip address so show in xxx.xxx.xxx.xxx format and the protocol to show not in hex, so I know what I&#39;m looking at?
analysis formatasked 11 May &#39;11, 05:59
mros2stf
1●1●1●1
accept rate: 0%
 retagged 24 May &#39;11, 22:58 
helloworld
3.1k●4●20●41</description>
    </item>
    
    <item>
      <title>SCTP chunks analysis</title>
      <link>/questions/4033/sctp-chunks-analysis/</link>
      <pubDate>Wed, 11 May 2011 06:20:00 +0000</pubDate>
      
      <guid>/questions/4033/sctp-chunks-analysis/</guid>
      <description>SCTP chunks analysis  0 Hi,
I have a problem with analyzing SCTP traffic with many chunks in one SCTP packet - for example in one SCTP packet I have chunks with BSSAP RANAP GSM MAP and ISUP. When I select display filter BSSAP I see all SCTP packets which contains BSSAP packets - but to see for example call flow on BSSAP transaction it is impossible because each SCTP packets contains more chunks with BSSAP data.</description>
    </item>
    
    <item>
      <title>what is ardus??</title>
      <link>/questions/4034/what-is-ardus/</link>
      <pubDate>Wed, 11 May 2011 08:15:00 +0000</pubDate>
      
      <guid>/questions/4034/what-is-ardus/</guid>
      <description>what is ardus??  0 At least, I think it&#39;s called protocol. All I can find is that it stands for Automatic Retrieval Delete Update System. My computer is connecting on Port 1115 and I&#39;m trying to figure out what program is executing this?
ardusasked 11 May &#39;11, 08:15
david
1●1●1●1
accept rate: 0%
 edited 11 May &#39;11, 08:40 
cmaynard ♦♦
9.4k●10●38●142
I&#39;m curious: I note that 3 years ago a question with almost exactly the same wording was asked on answers.</description>
    </item>
    
    <item>
      <title>Interface list is incomplete</title>
      <link>/questions/4042/interface-list-is-incomplete/</link>
      <pubDate>Wed, 11 May 2011 10:28:00 +0000</pubDate>
      
      <guid>/questions/4042/interface-list-is-incomplete/</guid>
      <description>Interface list is incomplete  0 I am using windows server 2003 SR2, there are two HP NC373i Multifunction Gigabit Network adapters. One is disabled and #2 is enabled.
When I bring up the Wireshark I only see &#34;Adapter for generic dialup and VPN capture&#34;.
This was showing the network adapter last week and I was able to capture. Choosing the &#34;Adapter for generic dialup and VPN capture&#34; doesn&#39;t capture any packets (as you would expect).</description>
    </item>
    
    <item>
      <title>How do I find my UDID on android?</title>
      <link>/questions/4049/how-do-i-find-my-udid-on-android/</link>
      <pubDate>Wed, 11 May 2011 16:31:00 +0000</pubDate>
      
      <guid>/questions/4049/how-do-i-find-my-udid-on-android/</guid>
      <description>How do I find my UDID on android?  0 I am not a phone or tech junkie and don&#39;t understand what it means to download parosproxy and run it, not do I understand how to use wireshark to find it? Any help in layman&#39;s terms would be appreciated. I have the original Android and need help!!
udid androidasked 11 May &#39;11, 16:31
kimhtaylor
1●1●1●1
accept rate: 0%
Start googling to find useful information:</description>
    </item>
    
    <item>
      <title>How do you capture audio packets on VOIP</title>
      <link>/questions/4051/how-do-you-capture-audio-packets-on-voip/</link>
      <pubDate>Thu, 12 May 2011 05:10:00 +0000</pubDate>
      
      <guid>/questions/4051/how-do-you-capture-audio-packets-on-voip/</guid>
      <description>How do you capture audio packets on VOIP  0 I am having intermittent problems with no audio on VOIP call between 2 Samsung office serve systems that are running over a MPLS.
voipasked 12 May &#39;11, 05:10
team38
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Show packet data in real-time during capture</title>
      <link>/questions/4052/show-packet-data-in-real-time-during-capture/</link>
      <pubDate>Thu, 12 May 2011 09:10:00 +0000</pubDate>
      
      <guid>/questions/4052/show-packet-data-in-real-time-during-capture/</guid>
      <description>Show packet data in real-time during capture  0 Is there a way to view a packet stream in real time? What I mean by this can kind of be simulated by holding ctrl+end during a capture and watching the Packet Bytes view. Not all packets need to be displayed, just the latest one.
This is useful in certain situations such as monitoring a live udp stream while manipulating an application.</description>
    </item>
    
    <item>
      <title>Request: Decode as - save and load settings</title>
      <link>/questions/4053/request-decode-as-save-and-load-settings/</link>
      <pubDate>Thu, 12 May 2011 10:02:00 +0000</pubDate>
      
      <guid>/questions/4053/request-decode-as-save-and-load-settings/</guid>
      <description>Request: Decode as - save and load settings  0 To be able to save and load dissector overrides in the &#34;decode as&#34; dialogue.
On private networks, especially in the SCADA world, none standard and multiple ports are used which can make selecting the right dissector each time Wireshark is started a chor.
save dissector requestasked 12 May &#39;11, 10:02
Graemem
1●2●2●2
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Request: Decode as - target multiple ports in one rule</title>
      <link>/questions/4054/request-decode-as-target-multiple-ports-in-one-rule/</link>
      <pubDate>Thu, 12 May 2011 10:06:00 +0000</pubDate>
      
      <guid>/questions/4054/request-decode-as-target-multiple-ports-in-one-rule/</guid>
      <description>Request: Decode as - target multiple ports in one rule  0 The use of serial to IP servers is prevalent in the SCADA world. These devices usually set up a single port per serial connection, generally in continuous blocks. The number of ports can range from 1 to 64 (possibly more but I haven&#39;t seen one yet).
It would be useful to be able to set up a dissector override that targets a port range.</description>
    </item>
    
    <item>
      <title>802.11s support without patch</title>
      <link>/questions/4062/80211s-support-without-patch/</link>
      <pubDate>Thu, 12 May 2011 22:08:00 +0000</pubDate>
      
      <guid>/questions/4062/80211s-support-without-patch/</guid>
      <description>802.11s support without patch  0 Hi, Is there a version of wireshark source code that supports 802.11s (mesh) protocol and does not require a patch.
Thank you very much.
802.11s meshasked 12 May &#39;11, 22:08
bthapa
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Initial support for the Hybrid Wireless Mesh Protocol was added to the 802.11 dissector on May 25, 2010 in r32955 and was backported to the 1.</description>
    </item>
    
    <item>
      <title>How can I play back captured data</title>
      <link>/questions/4072/how-can-i-play-back-captured-data/</link>
      <pubDate>Fri, 13 May 2011 12:50:00 +0000</pubDate>
      
      <guid>/questions/4072/how-can-i-play-back-captured-data/</guid>
      <description>How can I play back captured data  0 I&#39;ve captured packets going to a WAN router. I want to play them back at ideally a user specifed rate to a new router model so I an monitor the router&#39;s performance using our data in our configuration.
I realize I&#39;ll have to configure the MAC address of the new router&#39;s interface to match the MAC in the captured packets.
playback data capturedasked 13 May &#39;11, 12:50</description>
    </item>
    
    <item>
      <title>Integrating an application to Wireshark</title>
      <link>/questions/4083/integrating-an-application-to-wireshark/</link>
      <pubDate>Fri, 13 May 2011 16:05:00 +0000</pubDate>
      
      <guid>/questions/4083/integrating-an-application-to-wireshark/</guid>
      <description>Integrating an application to Wireshark  0 Hi, I want to log the total amount of traffic generated by each operation between my application and the database. It has to be an automatic log controlled by the application itself.
I was wondering if Wireshark let me do something like that:
command 1:start listening port x; command 2:return the traffic amount; command 3:reset the traffic amount;
My application must have full control of WHEN to start the counting, WHEN to stop, and to get the total ammount of data.</description>
    </item>
    
    <item>
      <title>Rogue PC on the Network</title>
      <link>/questions/4085/rogue-pc-on-the-network/</link>
      <pubDate>Fri, 13 May 2011 17:06:00 +0000</pubDate>
      
      <guid>/questions/4085/rogue-pc-on-the-network/</guid>
      <description>Rogue PC on the Network  0 Can WireShark help me locate a rogue system, down to the physical location/port?
rogue physical system locationasked 13 May &#39;11, 17:06
HFlores
1●1●1●1
accept rate: 0%
 edited 29 Feb &#39;12, 19:29 
cmaynard ♦♦
9.4k●10●38●142
  
3 Answers:
  
1Wireshark can help you detect traffic from Rogue PC&#39;s, but it can&#39;t tell you which port the PC is connected too.</description>
    </item>
    
    <item>
      <title>capinfos:  data size of received and sent packages</title>
      <link>/questions/4086/capinfos-data-size-of-received-and-sent-packages/</link>
      <pubDate>Sat, 14 May 2011 05:18:00 +0000</pubDate>
      
      <guid>/questions/4086/capinfos-data-size-of-received-and-sent-packages/</guid>
      <description>capinfos: data size of received and sent packages  0 Hi, I&#39;m using dumpcap and capinfos to get the total size of traffic data. But I want to split these in total SENT traffic, and total RECEIVED traffic.
capinfos -D &amp;lt;file&amp;gt; (this command just give me the total)
Is it possible to do something like this:
capinfos -D &amp;lt;file&amp;gt; -SENT (just the total sent) capinfos -D &amp;lt;file&amp;gt; -RECEIVED (just the total received)</description>
    </item>
    
    <item>
      <title>Disable Capturing Capacity or Just to read the pcap files but no capture option</title>
      <link>/questions/4090/disable-capturing-capacity-or-just-to-read-the-pcap-files-but-no-capture-option/</link>
      <pubDate>Sat, 14 May 2011 16:12:00 +0000</pubDate>
      
      <guid>/questions/4090/disable-capturing-capacity-or-just-to-read-the-pcap-files-but-no-capture-option/</guid>
      <description>Disable Capturing Capacity or Just to read the pcap files but no capture option  0 Hi
Is there any way to disable the capturimg feature on wire shark so that user can read only prevoiusly captured files but can not capture the packets on the network
read only pcapasked 14 May &#39;11, 16:12
Jignesh Furia
1●1●1●1
accept rate: 0%
Yes you can, but it depends on the OS the user is on how to do it.</description>
    </item>
    
    <item>
      <title>How do I create a statistic which side closes the most connections?</title>
      <link>/questions/4095/how-do-i-create-a-statistic-which-side-closes-the-most-connections/</link>
      <pubDate>Mon, 16 May 2011 06:50:00 +0000</pubDate>
      
      <guid>/questions/4095/how-do-i-create-a-statistic-which-side-closes-the-most-connections/</guid>
      <description>How do I create a statistic which side closes the most connections?  1 I&#39;m analyzing a packet dump where a client is talking to a server via TCP/IP. Sometimes the connection gets closed by one of the two machines with the usual handshake (FIN/ACK, FIN/ACK, ACK). After that, the client immediately opens a new connection and the process repeats after a few packets were sent.
How do I create a statistic which side (client or server) initiated the most connection shutdowns?</description>
    </item>
    
    <item>
      <title>Setup for reporting</title>
      <link>/questions/4096/setup-for-reporting/</link>
      <pubDate>Mon, 16 May 2011 07:49:00 +0000</pubDate>
      
      <guid>/questions/4096/setup-for-reporting/</guid>
      <description>Setup for reporting  0 I have just downloaded wireshark - do I need to set up things to get the reports that I need on normal internet usage??
setup reportsasked 16 May &#39;11, 07:49
Jax
1●1●1●1
accept rate: 0%
 retagged 16 May &#39;11, 21:41 
helloworld
3.1k●4●20●41
  
One Answer:
  
0First, verify your capture privileges (read the Wireshark Wiki on this).
By &#34;reports&#34;, I assume you mean statistics.</description>
    </item>
    
    <item>
      <title>Dealing with HTML entities within a SOAP envelope</title>
      <link>/questions/4097/dealing-with-html-entities-within-a-soap-envelope/</link>
      <pubDate>Mon, 16 May 2011 18:33:00 +0000</pubDate>
      
      <guid>/questions/4097/dealing-with-html-entities-within-a-soap-envelope/</guid>
      <description>Dealing with HTML entities within a SOAP envelope  0 I&#39;m capturing and decoding traffic within a SOAP envelope. The source application passes an XML payload through WCF which then converts all the XML reserved characters into HTML entities. So the less than symbol (&amp;lt;) becomes &amp;amp;lt;. And greater than becomes &amp;amp;gt; And so on and so forth according to W3C rules.
What I see in Wireshark is something like this:</description>
    </item>
    
    <item>
      <title>Wireshark automatically quits the instant I open it on OSX 10.6.7</title>
      <link>/questions/4102/wireshark-automatically-quits-the-instant-i-open-it-on-osx-1067/</link>
      <pubDate>Tue, 17 May 2011 11:21:00 +0000</pubDate>
      
      <guid>/questions/4102/wireshark-automatically-quits-the-instant-i-open-it-on-osx-1067/</guid>
      <description>Wireshark automatically quits the instant I open it on OSX 10.6.7  1 Right now I am using MacOS X with version 10.6.7 and a 2 Ghz Intel Core duo. Every time I double click Wireshark, the program opens and then instantly quits. Can you explain to me what&#39;s going on? If you need more info please let me know. Thanks.
quits mac osx closesasked 17 May &#39;11, 11:21
redelman431</description>
    </item>
    
    <item>
      <title>cookies in web pages</title>
      <link>/questions/4105/cookies-in-web-pages/</link>
      <pubDate>Tue, 17 May 2011 15:10:00 +0000</pubDate>
      
      <guid>/questions/4105/cookies-in-web-pages/</guid>
      <description>cookies in web pages  0 What is the use of cookies in some web sites like cnn.com? I don&#39;t log in but when I capture HTTP packets using Wireshark I see cookies. what is it for?
cookiesasked 17 May &#39;11, 15:10
A B
1●10●10●12
accept rate: 0%
  
One Answer:
  
2Cookies are not just used to keep login information but it is basically a way to store information (name/value pairs) on the client and retrieve it automatically every time the client reconnects to the server.</description>
    </item>
    
    <item>
      <title>sniffing Problem in WIFI Network</title>
      <link>/questions/4106/sniffing-problem-in-wifi-network/</link>
      <pubDate>Tue, 17 May 2011 15:23:00 +0000</pubDate>
      
      <guid>/questions/4106/sniffing-problem-in-wifi-network/</guid>
      <description>sniffing Problem in WIFI Network  0 hi, myself Harsh running INTERNET provider in India...my all network are on wifi now a days i m suffering frm ARP Sniffing in my network....please help me out from dis problem....dude to dis my INTERNET gateway ping...always break n having slow speed .....
Thanks in advance
sniffingasked 17 May &#39;11, 15:23
zero
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Help decoding ZKsoftware Stand-alone fingerprint reader protocol</title>
      <link>/questions/4113/help-decoding-zksoftware-stand-alone-fingerprint-reader-protocol/</link>
      <pubDate>Wed, 18 May 2011 00:25:00 +0000</pubDate>
      
      <guid>/questions/4113/help-decoding-zksoftware-stand-alone-fingerprint-reader-protocol/</guid>
      <description>Help decoding ZKsoftware Stand-alone fingerprint reader protocol  0 Hi!
I just purchased a Stand-alone, linux-based fingerprint reader for T&amp;amp;A purposes from dealextreme. http://www.dealextreme.com/p/x628-staff-time-attendance-system-1500-user-standalone-linux-network-fingerprint-4966
The hardware seems good enough, but the naive guy I am, I thought that with this thing being Linux-based, it would have some kind of open API to download the data stored on the device. But the rather nasty software that comes with the product (even made Avast shout out that something is wrong) is Windows-only, and not at all what I need in order to integrate this puppy into my other programs.</description>
    </item>
    
    <item>
      <title>LUA: modifying http.post data.data</title>
      <link>/questions/4115/lua-modifying-httppost-datadata/</link>
      <pubDate>Wed, 18 May 2011 00:57:00 +0000</pubDate>
      
      <guid>/questions/4115/lua-modifying-httppost-datadata/</guid>
      <description>LUA: modifying http.post data.data  0 I wrote a function that read the data from:
f_data = Field.new(&#34;data.data&#34;)
and then decode the data of the post request, how do I put the decoded data back in the Packet Bytes window so that the &#34;new&#34; data gets higlighted / showen by clicking on &#34;Hypertext Transfer Protocol&#34; --&amp;gt; Data (data.data)?
lua httpasked 18 May &#39;11, 00:57
chill
16●2●2●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>LUA: hex-highlighting for self made fields</title>
      <link>/questions/4116/lua-hex-highlighting-for-self-made-fields/</link>
      <pubDate>Wed, 18 May 2011 01:01:00 +0000</pubDate>
      
      <guid>/questions/4116/lua-hex-highlighting-for-self-made-fields/</guid>
      <description>LUA: hex-highlighting for self made fields  1 How do I make it that if I click on a self made protocol field in the packet detail window that the hex data in the Packet Bytes window get highlighted?
lua highlightingasked 18 May &#39;11, 01:01
chill
16●2●2●3
accept rate: 0%
  
One Answer:
  
0There are a couple ways: add a ProtoField (which must include a buffer), or add a buffer with a label.</description>
    </item>
    
    <item>
      <title>How can I know the number of open TCP streams in the pcap file?</title>
      <link>/questions/4117/how-can-i-know-the-number-of-open-tcp-streams-in-the-pcap-file/</link>
      <pubDate>Wed, 18 May 2011 04:23:00 +0000</pubDate>
      
      <guid>/questions/4117/how-can-i-know-the-number-of-open-tcp-streams-in-the-pcap-file/</guid>
      <description>How can I know the number of open TCP streams in the pcap file?  0 How can I know the number of open TCP streams in the pcap file?
streams tcpasked 18 May &#39;11, 04:23
AlexLA
1●1●1●2
accept rate: 0%
What do you mean by &#34;open&#34;? TCP stream that are still ongoing when the trace ended, or just any connection that had data transfers?
(18 May &#39;11, 05:13) Jasper ♦♦</description>
    </item>
    
    <item>
      <title>Can you build support for TIP (Telepresence Interoperability Protocol)</title>
      <link>/questions/4120/can-you-build-support-for-tip-telepresence-interoperability-protocol/</link>
      <pubDate>Wed, 18 May 2011 06:39:00 +0000</pubDate>
      
      <guid>/questions/4120/can-you-build-support-for-tip-telepresence-interoperability-protocol/</guid>
      <description>Can you build support for TIP (Telepresence Interoperability Protocol)  0 TIP is an extension on SIP to allow Telepresence systems to set up streams in the best way possible. Several new options can be negotiated. More info on http://www.imtc.org/tip/ and http://www.cisco.com/web/about/doing_business/tip/index.html
Regards, Paul
tip telepresence protocolasked 18 May &#39;11, 06:39
PeteA
1●2●2●2
accept rate: 0%
 edited 18 May &#39;11, 18:05 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireless router traffic</title>
      <link>/questions/4123/wireless-router-traffic/</link>
      <pubDate>Wed, 18 May 2011 10:11:00 +0000</pubDate>
      
      <guid>/questions/4123/wireless-router-traffic/</guid>
      <description>Wireless router traffic  0 I am trying to capture all data that goes through my router to the cable modem (e.g. capture all traffic from PC&#39;s connected to my wireless router).
From what I understand this is possible with Wireshark, but I am unable to figure it out (I am not a techie).
I am running Mac OS X 10.5.8 and using a linksys WRT54 router if that makes any difference.</description>
    </item>
    
    <item>
      <title>Broadcast Packet? why?</title>
      <link>/questions/4130/broadcast-packet-why/</link>
      <pubDate>Wed, 18 May 2011 21:29:00 +0000</pubDate>
      
      <guid>/questions/4130/broadcast-packet-why/</guid>
      <description>Broadcast Packet? why?  0 hi there, i am new to wireshark and as i was learning it, i noticed that my smc router is sending packets to itself every second. under the protocol column, wireshark shows 0xffff. not sure why this is happening but maybe someone can explain it to me? is this normal? thanks in advance for any explainations.
Ethernet II, Src: SmcNetwo_0e:46:12 (12:26:f3:0e:46:12), Dst: SmcNetwo_0e:46:12 (00:26:f3:0e:46:12)
Destination: SmcNetwo_0e:46:12 (00:26:f3:0e:46:12) Address: SmcNetwo_0e:46:12 (00:26:f3:0e:46:12) .</description>
    </item>
    
    <item>
      <title>pcap_next_ex vs pcap_loop</title>
      <link>/questions/4131/pcap_next_ex-vs-pcap_loop/</link>
      <pubDate>Wed, 18 May 2011 23:30:00 +0000</pubDate>
      
      <guid>/questions/4131/pcap_next_ex-vs-pcap_loop/</guid>
      <description>pcap_next_ex vs pcap_loop  0 I&#39;m writing a program which reads live captures and processes them. I&#39;m using pcap_next_ex for capturing and it returns -1 and -2 unexpectdly. Will it be nice to use pcap_loop rather than pcap_next_ex? Which one is more efficient? Is the problem associated with read time out?
pcap_loop pcap_next_ex pcapasked 18 May &#39;11, 23:30
Fitsum
1●1●1●2
accept rate: 0%
 edited 19 May &#39;11, 21:24</description>
    </item>
    
    <item>
      <title>Kohonen&amp;#x27;s Self-Organizing Map</title>
      <link>/questions/4132/kohonens-self-organizing-map/</link>
      <pubDate>Thu, 19 May 2011 00:48:00 +0000</pubDate>
      
      <guid>/questions/4132/kohonens-self-organizing-map/</guid>
      <description>Kohonen&amp;rsquo;s Self-Organizing Map  0 How can I add visualization capabilities to wireshark ? Like to add SOM capabilities ?
somasked 19 May &#39;11, 00:48
Alia ElRoubi
1●1●1●1
accept rate: 0%
  
One Answer:
  
2By writing code. :-)
I assume the idea is to generate a self-organizing map of network hosts, with the input layer being the sending hosts and the output layer being the receiving hosts.</description>
    </item>
    
    <item>
      <title>Capturing headers only</title>
      <link>/questions/4137/capturing-headers-only/</link>
      <pubDate>Thu, 19 May 2011 05:37:00 +0000</pubDate>
      
      <guid>/questions/4137/capturing-headers-only/</guid>
      <description>Capturing headers only  1 Does anyone have a simple filter for capturing headers only.
capture-filterasked 19 May &#39;11, 05:37
mooseman
16●1●1●2
accept rate: 0%
  
One Answer:
  
5You can try to go with slicing the frames to the first # of bytes, but there is no simple filter that will exactly capture certain headers only afaik.
Just open the capture options and put a check mark next to &#34;</description>
    </item>
    
    <item>
      <title>Mac OSX Installation</title>
      <link>/questions/4146/mac-osx-installation/</link>
      <pubDate>Thu, 19 May 2011 11:10:00 +0000</pubDate>
      
      <guid>/questions/4146/mac-osx-installation/</guid>
      <description>Mac OSX Installation  0 I&#39;ve having an issue installing Wireshark on my MacBook Pro. I&#39;ve read the Readme documentation and believe I have done the necessary steps, but it won&#39;t startup. Steps 3 and 4 are a little fuzzy. Can someone please explain in further detail?
Drag the contents of the Command Line folder to $HOME/bin, /usr/local/bin, /opt/wireshark/bin or any other location that makes sense (preferably one that&#39;s in your PATH).</description>
    </item>
    
    <item>
      <title>Analyzing Traffic to troubleshoot an issue</title>
      <link>/questions/4147/analyzing-traffic-to-troubleshoot-an-issue/</link>
      <pubDate>Thu, 19 May 2011 13:05:00 +0000</pubDate>
      
      <guid>/questions/4147/analyzing-traffic-to-troubleshoot-an-issue/</guid>
      <description>Analyzing Traffic to troubleshoot an issue  0 I am helping out a school NetAdmin with an unusual problem they are having I believe may be network related. It appears that 7-8 desktops have issues opening up files on a share located on the school&#39;s server during the mornings. The issue only affects these desktops - no one else on the subnet experiences those issues at that time, and the issue clears up later in the day.</description>
    </item>
    
    <item>
      <title>Web page content</title>
      <link>/questions/4152/web-page-content/</link>
      <pubDate>Thu, 19 May 2011 14:29:00 +0000</pubDate>
      
      <guid>/questions/4152/web-page-content/</guid>
      <description>Web page content  0 How can I know that all content of a web page has been fetched using Wireshark?
httpasked 19 May &#39;11, 14:29
A B
1●10●10●12
accept rate: 0%
  
One Answer:
  
0If you use host as a capture filter, and you were say redirected from the initial site to another site, you would lose the redirected traffic. If you use capture filter port 80 though, you would capture all the http traffic, assuming you are using port 80 and not https or port 443.</description>
    </item>
    
    <item>
      <title>Availability of Wireshark v1.2.1</title>
      <link>/questions/4160/availability-of-wireshark-v121/</link>
      <pubDate>Fri, 20 May 2011 07:15:00 +0000</pubDate>
      
      <guid>/questions/4160/availability-of-wireshark-v121/</guid>
      <description>Availability of Wireshark v1.2.1  0 Is Wireshark v1.2.1 available for download? If not, is currently available v1.2.16 fully compatible with v1.2.1?
download compatibilityasked 20 May &#39;11, 07:15
MAC
1●1●1●1
accept rate: 0%
 retagged 27 May &#39;11, 20:49 
helloworld
3.1k●4●20●41
  
2 Answers:
  
2The various 1.2... releases were done to fix many bugs; AFAIK there were no functionality changes.
So if by &#34;fully compatible with v1.</description>
    </item>
    
    <item>
      <title>Building Display Filter Using Conversations</title>
      <link>/questions/4164/building-display-filter-using-conversations/</link>
      <pubDate>Fri, 20 May 2011 10:29:00 +0000</pubDate>
      
      <guid>/questions/4164/building-display-filter-using-conversations/</guid>
      <description>Building Display Filter Using Conversations  0 Good day all! I&#39;m trying to build a comprehensive list of hosts and ports talking within a network so I can begin to build a firewall ACL as we begin to compartmentalize the network a bit. I&#39;m using WS 1.4.6 where I start by simply capture &amp;gt;&amp;gt; start &amp;gt;&amp;gt; and select interface. I then apply a display filter of ((tcp.flags.syn == 1) &amp;amp;&amp;amp; (tcp.</description>
    </item>
    
    <item>
      <title>Malformed Packet on SMPP</title>
      <link>/questions/4168/malformed-packet-on-smpp/</link>
      <pubDate>Fri, 20 May 2011 17:06:00 +0000</pubDate>
      
      <guid>/questions/4168/malformed-packet-on-smpp/</guid>
      <description>Malformed Packet on SMPP  0 I captured a packet using the command tethereal -i bond0 -R &#34;smpp&#34; -w /tmp/file. When I viewed the file its shows Malformed Packet on submit_sm. Why is that so?
smpp tethereal malformed packetThis question is marked &#34;community wiki&#34;.asked 20 May &#39;11, 17:06
themask
1●1●1●1
accept rate: 0%
 edited 21 May &#39;11, 07:07 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:</description>
    </item>
    
    <item>
      <title>Can not open file over 2GB,there is an error .</title>
      <link>/questions/4171/can-not-open-file-over-2gbthere-is-an-error/</link>
      <pubDate>Sun, 22 May 2011 03:05:00 +0000</pubDate>
      
      <guid>/questions/4171/can-not-open-file-over-2gbthere-is-an-error/</guid>
      <description>Can not open file over 2GB,there is an error .  0 Hello all When I open a pcap file about 2GB on Win2008 R2 (4 CPU 16GB RAM) ，the program crash and there is an error,I have tried wireshark 1.46 64bit &amp;amp; wireshark 1.50 64bit &amp;amp; wireshar 1.61rc1 64bit， Can you help me to fix it ,thank u very much!
windows crash filesize errorasked 22 May &#39;11, 03:05
cybluesky</description>
    </item>
    
    <item>
      <title>Capture Virtual card datas</title>
      <link>/questions/4173/capture-virtual-card-datas/</link>
      <pubDate>Sun, 22 May 2011 09:47:00 +0000</pubDate>
      
      <guid>/questions/4173/capture-virtual-card-datas/</guid>
      <description>Capture Virtual card datas  0 Hello
My OS is XP, I have installed a Pocket PC emulator, and therefore a virtual card.
I want to sniff the traffic between an FTP client, which resides on the emulator, and a ftp server wich is on onother machine.
WireShark is on the emulator&#39;s host machine.
I&#39;m able to sniff the traffic from the emulator to the ftp server, but not the return traffic, from the ftp server to the emulator.</description>
    </item>
    
    <item>
      <title>use cable modem for ipad</title>
      <link>/questions/4174/use-cable-modem-for-ipad/</link>
      <pubDate>Sun, 22 May 2011 13:43:00 +0000</pubDate>
      
      <guid>/questions/4174/use-cable-modem-for-ipad/</guid>
      <description>use cable modem for ipad  0 I have a REAL need (not idiosyncratic) for which I’ve invested research time that I don’t have. Details aside: in the comfort of my Peekskill, NY apartment, I HAVE NO ACCESS TO WI-FI (Boingo or AT&amp;amp;T)! The only way I can work on my iPhone or iPAD at home, I have to pay AT&amp;amp;T $25/mo for 3G (slow and limited) just for my iPAD.</description>
    </item>
    
    <item>
      <title>How do I determine a TCP segment&amp;#x27;s length</title>
      <link>/questions/4178/how-do-i-determine-a-tcp-segments-length/</link>
      <pubDate>Sun, 22 May 2011 20:49:00 +0000</pubDate>
      
      <guid>/questions/4178/how-do-i-determine-a-tcp-segments-length/</guid>
      <description>How do I determine a TCP segment&amp;rsquo;s length  0 How do I determine a TCP segment&#39;s length - Header length + No. Bytes in flight?
segment tcpasked 22 May &#39;11, 20:49
jaden
1●1●1●2
accept rate: 0%
  
3 Answers:
  
3The TCP payload size is calculated by taking the &#34;Total Length&#34; from the IP header (ip.len) and then substract the &#34;IP header length&#34; (ip.hdr_len) and the &#34;</description>
    </item>
    
    <item>
      <title>How to Capture packets of a remote computer ??</title>
      <link>/questions/4185/how-to-capture-packets-of-a-remote-computer/</link>
      <pubDate>Mon, 23 May 2011 05:18:00 +0000</pubDate>
      
      <guid>/questions/4185/how-to-capture-packets-of-a-remote-computer/</guid>
      <description>How to Capture packets of a remote computer ??  0 I wanna capture packets from a remote computer, let say my friend is chatting with me, is it possible to capture all his ingoing and outgoing traffic by WireShark ?
capture remoteasked 23 May &#39;11, 05:18
nzhacker
1●1●1●1
accept rate: 0%
 retagged 24 May &#39;11, 15:56 
helloworld
3.1k●4●20●41
  
2 Answers:
  
0Yes or no, depending where your friend is.</description>
    </item>
    
    <item>
      <title>decode UDP mpeg2 TS</title>
      <link>/questions/4187/decode-udp-mpeg2-ts/</link>
      <pubDate>Mon, 23 May 2011 07:52:00 +0000</pubDate>
      
      <guid>/questions/4187/decode-udp-mpeg2-ts/</guid>
      <description>decode UDP mpeg2 TS  0 Hi all,
is there any plugin which can decode a UDP MPEG2 TS so you can see the payload? I have wireshark 1.6.1 and it&#39;s decoding MPEG-1 Audio. Video and the PSI information would be nice too. Any chance to get this?
mpeg2 tsasked 23 May &#39;11, 07:52
Sebastian S
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Monitoring Gb over IP interface with ciphering on</title>
      <link>/questions/4189/monitoring-gb-over-ip-interface-with-ciphering-on/</link>
      <pubDate>Mon, 23 May 2011 09:12:00 +0000</pubDate>
      
      <guid>/questions/4189/monitoring-gb-over-ip-interface-with-ciphering-on/</guid>
      <description>Monitoring Gb over IP interface with ciphering on  0 Hi,
we would like to monitor Gb over IP interface with the help of Wireshark, but it is required to have ciphering on in the test network. I know that monitoring of Gb interface as such is possible with Wireshark, since BSSGB protocol is a supported Wireshark display filter. But the problem now is with Ciphering switched on in the network (which you normally have switched off in test networks in order to monitor signalling messages on any protocol analyser).</description>
    </item>
    
    <item>
      <title>control of tshark -V output</title>
      <link>/questions/4190/control-of-tshark-v-output/</link>
      <pubDate>Mon, 23 May 2011 23:18:00 +0000</pubDate>
      
      <guid>/questions/4190/control-of-tshark-v-output/</guid>
      <description>control of tshark -V output  0 Is there a way to print the packet details of only a specific layer/protocol while ignoring or summarizing the rest? For example, I want to compress this:
Frame 1: 48 bytes on wire (384 bits), 48 bytes captured (384 bits) Arrival Time: May 22, 2011 02:07:16.384560000 PDT Epoch Time: 1306217236.384560000 seconds [Time delta from previous captured frame: 0.000000000 seconds] [Time delta from previous displayed frame: 0.</description>
    </item>
    
    <item>
      <title>Wireshark 1.0.6 - Compatibility in Windows 7 x 64 bit environment</title>
      <link>/questions/4194/wireshark-106-compatibility-in-windows-7-x-64-bit-environment/</link>
      <pubDate>Tue, 24 May 2011 07:34:00 +0000</pubDate>
      
      <guid>/questions/4194/wireshark-106-compatibility-in-windows-7-x-64-bit-environment/</guid>
      <description>Wireshark 1.0.6 - Compatibility in Windows 7 x 64 bit environment  0 Hi,
We use “Wireshark 1.0.6” in Windows Vista. I was trying to run this in Windows 7 x 64 bit environment and was getting the below error when the shortcut is launched.
&#34;The NPF driver isn&#39;t running. You may have trouble capturing or listing interfaces.&#34;
Please let me know whether this is compatible with Windows 7 x64 bit environment.</description>
    </item>
    
    <item>
      <title>open big .cap file ?</title>
      <link>/questions/4199/open-big-cap-file/</link>
      <pubDate>Tue, 24 May 2011 09:59:00 +0000</pubDate>
      
      <guid>/questions/4199/open-big-cap-file/</guid>
      <description>open big .cap file ?  0 Hello.
I have a .cap file that is 4Mo leght.
When i try to open it with wishark, i have an error that says &#34;pcap: File has 1869904672-byte packet, bigger than maximum of 65535).
Someone knows how to open my complete .cap file ?
Thank you.
filesize errorasked 24 May &#39;11, 09:59
parisien
1●1●1●1
accept rate: 0%
 retagged 25 May &#39;11, 21:47</description>
    </item>
    
    <item>
      <title>how to connect my GSM phone to wireshark</title>
      <link>/questions/4202/how-to-connect-my-gsm-phone-to-wireshark/</link>
      <pubDate>Tue, 24 May 2011 12:00:00 +0000</pubDate>
      
      <guid>/questions/4202/how-to-connect-my-gsm-phone-to-wireshark/</guid>
      <description>how to connect my GSM phone to wireshark  0 Hi, How can I connect my GSM phone to wireshark, I had installed the modem driver of the phone but still not appearing in interface list,
thanks Solarisan
interface phone handset modem gsmasked 24 May &#39;11, 12:00
solarisan
1●2●2●3
accept rate: 0%
 edited 25 Jun &#39;11, 22:16 
Guy Harris ♦♦
17.4k●3●35●196
1What operating system are you using, and what version of that operating system?</description>
    </item>
    
    <item>
      <title>Purchasing wireshark,Pcap analysis</title>
      <link>/questions/4209/purchasing-wiresharkpcap-analysis/</link>
      <pubDate>Tue, 24 May 2011 19:16:00 +0000</pubDate>
      
      <guid>/questions/4209/purchasing-wiresharkpcap-analysis/</guid>
      <description>Purchasing wireshark,Pcap analysis  0 Hai, I am a network admin in an organisation having 15 servers and upto 350 client pc&#39;s.Our network is totally unmanaged we have a few(4) l2 managed switches at the core levels We are facing slow network issues Can u analyse our network traffic captures and Tell us the tweaks.What will u be charging us for and on what basis you are going to charge us.</description>
    </item>
    
    <item>
      <title>measuring round trip time,</title>
      <link>/questions/4210/measuring-round-trip-time/</link>
      <pubDate>Tue, 24 May 2011 23:16:00 +0000</pubDate>
      
      <guid>/questions/4210/measuring-round-trip-time/</guid>
      <description>measuring round trip time,  0 1Hi everybody, Just now i have started using the wireshark, i got to know how to capture the traffic flowing through network, but i am trying to get the round trip time of packets , how do i get to know that ?? i can just see the window of showing the packet no, src, dest, protocol, etc, please help me out in finding the roundtrip time.</description>
    </item>
    
    <item>
      <title>Basics of wireshark</title>
      <link>/questions/4211/basics-of-wireshark/</link>
      <pubDate>Tue, 24 May 2011 23:23:00 +0000</pubDate>
      
      <guid>/questions/4211/basics-of-wireshark/</guid>
      <description>Basics of wireshark  0 Hello, I have newly started using Wireshark for data capturing, can anybody please tell me what are the basic things one should know to work with wireshark. For what purpose the manual pages are useful?
beginnerasked 24 May &#39;11, 23:23
sagu072
35●23●24●28
accept rate: 0%
  
2 Answers:
  
2 This is a really large topics, so here&#39;s what I think you should do:</description>
    </item>
    
    <item>
      <title>LUA how to get multiple values from faststart items H225, H245</title>
      <link>/questions/4225/lua-how-to-get-multiple-values-from-faststart-items-h225-h245/</link>
      <pubDate>Wed, 25 May 2011 01:40:00 +0000</pubDate>
      
      <guid>/questions/4225/lua-how-to-get-multiple-values-from-faststart-items-h225-h245/</guid>
      <description>LUA how to get multiple values from faststart items H225, H245  0 I want to get all media address and port form H323 call from faststart. Faststart filed only returns number of items in the message. If I do Field.new(&#34;h245.network&#34;) or Field.new(&#34;h245.tsapIdentifier&#34;) I got null result. How can I get to all of the items and display?
This is my code.
-- text_window_tap.lua -- an example of a tap that registers a menu -- and prints to a text window instances = 0 &amp;ndash; number of instances of the tap created so far</description>
    </item>
    
    <item>
      <title>Follow SSL stream using Master-key and Session-ID</title>
      <link>/questions/4229/follow-ssl-stream-using-master-key-and-session-id/</link>
      <pubDate>Wed, 25 May 2011 03:22:00 +0000</pubDate>
      
      <guid>/questions/4229/follow-ssl-stream-using-master-key-and-session-id/</guid>
      <description>Follow SSL stream using Master-key and Session-ID  5 3Hello I&#39;m debugging my SSL application and would be great if I could capture SSL stream using Wireshark and then follow it decrypted. It is not possible to obtain server&#39;s private key in my case
But as a client application I can read the whole stream fine and can dump all needed information for decryption, like Session-ID and Master-key, ex:
&amp;gt; openssl s_client -connect mail.</description>
    </item>
    
    <item>
      <title>how to decode the data.</title>
      <link>/questions/4239/how-to-decode-the-data/</link>
      <pubDate>Wed, 25 May 2011 22:13:00 +0000</pubDate>
      
      <guid>/questions/4239/how-to-decode-the-data/</guid>
      <description>how to decode the data.  0 the data which we capture will be either in hex or binary, is that possible to convert it into the human readable format, to know what are the messages flowing through the network.
dissectorasked 25 May &#39;11, 22:13
sagu072
35●23●24●28
accept rate: 0%
 retagged 27 May &#39;11, 20:59 
helloworld
3.1k●4●20●41
  
2 Answers:
  
0This depends on what you mean with &#34;</description>
    </item>
    
    <item>
      <title>TCP Recieve Window Autotuning and window scaling</title>
      <link>/questions/4242/tcp-recieve-window-autotuning-and-window-scaling/</link>
      <pubDate>Thu, 26 May 2011 02:57:00 +0000</pubDate>
      
      <guid>/questions/4242/tcp-recieve-window-autotuning-and-window-scaling/</guid>
      <description>TCP Recieve Window Autotuning and window scaling  2 1Hey guys,
i am currently running into issues with the rwin autotuning feature since MS Vista. Here are the key facts which make me get headaches:
Microsoft has documented autotuning levels for Vista, default being &#34;normal&#34;, others being &#34;restricted&#34; or &#34;experimental&#34; e.g. I was not able to find the same docs for Win7 stack, so i supposed(!!) it was the same which popped up to be not so right in the meantime.</description>
    </item>
    
    <item>
      <title>I find out the valid packet that the wireshark not support.</title>
      <link>/questions/4245/i-find-out-the-valid-packet-that-the-wireshark-not-support/</link>
      <pubDate>Thu, 26 May 2011 19:27:00 +0000</pubDate>
      
      <guid>/questions/4245/i-find-out-the-valid-packet-that-the-wireshark-not-support/</guid>
      <description>I find out the valid packet that the wireshark not support.  0 When the DHCPv6 relay agent add the interface id(option 18) and the remote id(option 37) to relay forward packet, we can not find out the parsing content by wireshark after remote id. The valid DHCPv6 relay forward packet is bellow: &amp;lt;interface id=&#34;&#34;&amp;gt; &amp;lt;remote id=&#34;&#34;&amp;gt; &amp;lt;msg relay=&#34;&#34; option=&#34;&#34;&amp;gt;
The wireshark parsing is bellow: &amp;lt;interface id=&#34;&#34;&amp;gt; &amp;lt;remote id=&#34;&#34;&amp;gt; XXXXXXX(can not parse)</description>
    </item>
    
    <item>
      <title>code for decoding</title>
      <link>/questions/4247/code-for-decoding/</link>
      <pubDate>Thu, 26 May 2011 23:42:00 +0000</pubDate>
      
      <guid>/questions/4247/code-for-decoding/</guid>
      <description>code for decoding  0 can anybody paste a sample c++ or c code to decode the data captured from wireshark ??
dissector source-codeasked 26 May &#39;11, 23:42
sagu072
35●23●24●28
accept rate: 0%
 retagged 27 May &#39;11, 20:43 
helloworld
3.1k●4●20●41
  
3 Answers:
  
1the source-code for wireshark or tshark is freely available sample code that does exactly what you want.
answered 27 May &#39;11, 00:21</description>
    </item>
    
    <item>
      <title>RE: G729 payload data</title>
      <link>/questions/4250/re-g729-payload-data/</link>
      <pubDate>Fri, 27 May 2011 00:32:00 +0000</pubDate>
      
      <guid>/questions/4250/re-g729-payload-data/</guid>
      <description>RE: G729 payload data  0 Hi, I have capture a pcap through wire-shark , which contain data of G729 payload type . Now I saved it in .raw file and decode it in .pcm using the decoder and finally got the .au file . But when I am playing that file it is generating noise. Plz tell me why it is generating noise.
g729asked 27 May &#39;11, 00:32
rahulgupta</description>
    </item>
    
    <item>
      <title>C&#43;&#43; decoder</title>
      <link>/questions/4255/c-decoder/</link>
      <pubDate>Fri, 27 May 2011 04:50:00 +0000</pubDate>
      
      <guid>/questions/4255/c-decoder/</guid>
      <description>C++ decoder  0 please give me some idea to write C++ decoder. i want to capture the data and decode it.
dissector c++asked 27 May &#39;11, 04:50
sagu072
35●23●24●28
accept rate: 0%
 retagged 27 May &#39;11, 20:46 
helloworld
3.1k●4●20●41
  
One Answer:
  
0Here are a few good places to start:
The Wireshark wiki development pageThe Wireshark developer&#39;s guideThe README.developer documentanswered 27 May &#39;11, 06:58</description>
    </item>
    
    <item>
      <title>Multiple concurrent Wireshark sessions</title>
      <link>/questions/4256/multiple-concurrent-wireshark-sessions/</link>
      <pubDate>Fri, 27 May 2011 05:36:00 +0000</pubDate>
      
      <guid>/questions/4256/multiple-concurrent-wireshark-sessions/</guid>
      <description>Multiple concurrent Wireshark sessions  0 Does anyone nkow of a quick and easy way to stop a user accidentally opening multiple Wireshark Sessions on the same box. In our example an admin selected 20 files for deletion but accidentally hit open. 20 Wireshark sessions tried to open at once and the box just halted. A reboot was the only solution - how do we prevent that happening again?
sessions multiple wiresharkThis question is marked &#34;</description>
    </item>
    
    <item>
      <title>Wireless showing as Ethernet</title>
      <link>/questions/4259/wireless-showing-as-ethernet/</link>
      <pubDate>Fri, 27 May 2011 14:24:00 +0000</pubDate>
      
      <guid>/questions/4259/wireless-showing-as-ethernet/</guid>
      <description>Wireless showing as Ethernet  0 Hi, I&#39;ve been struggling with this for days now, I have installed Backtrack 5, I have Atheros AR9287 wireless card. But whenever I open Wireshark to sniff the wireless network, I am able to see only my own traffic, or traffic targeted to the whole network *.255 only. I&#39;ve noticed that whenever I try to select the capture interface, wlan0 (which is the wireless adapter) shows as ETHERNET, and I don&#39;t have 802.</description>
    </item>
    
    <item>
      <title>Client/Server socket application sniff ?</title>
      <link>/questions/4265/clientserver-socket-application-sniff/</link>
      <pubDate>Fri, 27 May 2011 21:20:00 +0000</pubDate>
      
      <guid>/questions/4265/clientserver-socket-application-sniff/</guid>
      <description>Client/Server socket application sniff ?  0 I have done a small c# client/server chat with simple auth that runs on the tcp port 8822, I would like to sniff it to learn more about how the packets work and everything, I can capture the packets just fine but I am wondering about what I am seeing at the wireshark.
For example the first entry:
0000 00 30 b8 d3 d6 30 00 1f d0 d2 28 52 08 00 45 00 .</description>
    </item>
    
    <item>
      <title>cookie injection</title>
      <link>/questions/4270/cookie-injection/</link>
      <pubDate>Sat, 28 May 2011 10:06:00 +0000</pubDate>
      
      <guid>/questions/4270/cookie-injection/</guid>
      <description>cookie injection  0 hi everyone. i&#39;m writing a thesis on Facebook Connect implementation and on its vulnerability issues.
Since its for educational purpose,it&#39;s important for me to simulate a side jacking attack. i&#39;ve used this configuration: one vbox guest machine (WinXP) acting as client and one vbox host machine (openSuse) acting as connection gateway (on wich Wireshark is sniffing packets).
on the guest machine, after having flushed cookies and browser history, i have shared a youtube video on my fb profile through fb connect, while on host i&#39;ve recorded network traffic.</description>
    </item>
    
    <item>
      <title>yahoo messenger decoding</title>
      <link>/questions/4275/yahoo-messenger-decoding/</link>
      <pubDate>Sun, 29 May 2011 02:00:00 +0000</pubDate>
      
      <guid>/questions/4275/yahoo-messenger-decoding/</guid>
      <description>yahoo messenger decoding  0 hi i have a capture of my local pc with yahoo messenger authentification i examined the packets and indeed i got the username, but when i looked at the password i got something like u/x*q/(w-f+y+f|o+(n+f+k/u/f)/4/h)/q/y/y/1/i/b/3/e/8/2 I want to mention the the capture was not made on INTERNET EXPPLORER MAIL, it was made on YAHOO MESSENGER
Can anyone tell me how to decode that string of characters?</description>
    </item>
    
    <item>
      <title>Capture interfaces under Win7</title>
      <link>/questions/4284/capture-interfaces-under-win7/</link>
      <pubDate>Mon, 30 May 2011 02:49:00 +0000</pubDate>
      
      <guid>/questions/4284/capture-interfaces-under-win7/</guid>
      <description>Capture interfaces under Win7  0 Hello, I installed last few versions of wireshark/ethereal under Win7 profesional. I have problem with capturing. There are not possible capture packets from modem &#34;PPP&#34; or from modem Broadband like wifi adapter. I have only one adapter for capturing - LAN.
I have Win XP too, but there are is possible capture both.
Thanks
capture problem ppp modemasked 30 May &#39;11, 02:49
stando
1●1●1●1</description>
    </item>
    
    <item>
      <title>A string is found in the tcp segment data window but not in the tcp stream</title>
      <link>/questions/4285/a-string-is-found-in-the-tcp-segment-data-window-but-not-in-the-tcp-stream/</link>
      <pubDate>Mon, 30 May 2011 03:13:00 +0000</pubDate>
      
      <guid>/questions/4285/a-string-is-found-in-the-tcp-segment-data-window-but-not-in-the-tcp-stream/</guid>
      <description>A string is found in the tcp segment data window but not in the tcp stream  0 1Hi, I am searching for a specific xml data string and the pointer finds the specific packet number. Then I right click &#34;follow tcp stream&#34; and don&#39;t find it (I am not talking about while it is written in &#34;white&#34;). Then I look at tcp data segment window below, and find it! My question is why parts of the xml are written in the follow tcp stream window and some are not (and are only available at the tcp data segment window)?</description>
    </item>
    
    <item>
      <title>data types used in wireshark.</title>
      <link>/questions/4286/data-types-used-in-wireshark/</link>
      <pubDate>Mon, 30 May 2011 05:29:00 +0000</pubDate>
      
      <guid>/questions/4286/data-types-used-in-wireshark/</guid>
      <description>data types used in wireshark.  0 where do i get to know abt the data types used in the wireshark development, like tvbuff, m getting confused with the unknown types, please help me.
datatypesasked 30 May &#39;11, 05:29
sagu072
35●23●24●28
accept rate: 0%
  
One Answer:
  
1When writing dissectors, most of the Wireshark internal structures, like tvbuff&#39;s, should be treated as opaque data types, so you really don&#39;t need to know or care about the internals, as the API provides all the accessor functions you need.</description>
    </item>
    
    <item>
      <title>MAC Time Stamp in WLAN captures</title>
      <link>/questions/4288/mac-time-stamp-in-wlan-captures/</link>
      <pubDate>Mon, 30 May 2011 07:22:00 +0000</pubDate>
      
      <guid>/questions/4288/mac-time-stamp-in-wlan-captures/</guid>
      <description>MAC Time Stamp in WLAN captures  0 Hi,
I would like to capture an put a time stamp at the beginning of MPDU or before MPDU starts. Can anybody help me regarding this. Thanks you in advance, Best Regards, Amin
timestamp mac wlan radioheaderasked 30 May &#39;11, 07:22
AminGho
51●4●4●8
accept rate: 0% 
Are you looking for radiotap.mactime?
$ tshark -i 1 -T fields -e frame.number -e radiotap.mactime Capturing on AirPcap USB wireless capture adapter nr.</description>
    </item>
    
    <item>
      <title>Multiple occurrences filter for diameter</title>
      <link>/questions/4291/multiple-occurrences-filter-for-diameter/</link>
      <pubDate>Mon, 30 May 2011 22:21:00 +0000</pubDate>
      
      <guid>/questions/4291/multiple-occurrences-filter-for-diameter/</guid>
      <description>Multiple occurrences filter for diameter  0 Hi,
I am trying to use tshark for filtering Diameter messages from a pcap file. I am using following command:
tshark -n -t ad -T fields -E separator=, -E occurrence=a -E aggregator=: -E quote=s -e frame.number -e diameter.Result-Code -e diameter.resp_time -e diameter.hopbyhopid -e diameter.endtoendid -e frame.protocols -r output.txt
One of the output line is
&#39;877&#39;,&#39;2001:2001&#39;,,&#39;0x4e841c7a:0x4e841c80:0x4e841c8f&#39;,&#39;0xa38a5201:0xa38a5202:0xb13b2c71&#39;,&#39;eth:vlan:ip:tcp:diameter:diameter:diameter:diameter:diameter&#39;
Now the problem is that this particular TCP packet has three Diameter packets, two with Result code = 2001 and another with Experimental code.</description>
    </item>
    
    <item>
      <title>How to highlight the &amp;quot;Data&amp;quot; segment of packets?</title>
      <link>/questions/4295/how-to-highlight-the-data-segment-of-packets/</link>
      <pubDate>Tue, 31 May 2011 09:02:00 +0000</pubDate>
      
      <guid>/questions/4295/how-to-highlight-the-data-segment-of-packets/</guid>
      <description>How to highlight the &amp;ldquo;Data&amp;rdquo; segment of packets?  0 Hey there!
To be able to investigate only differences in data of TCP packets, but the bytes before of other protocols like Internet Protocol make the packets difficult to read.
Can I filter out just the bytes of all other protocols and leave the data bytes to read alone?
When I activate the column Custom() = data.data, then it cuts the bytes after 30 or so bytes.</description>
    </item>
    
    <item>
      <title>Analyze data packets in the network and retrieve all the TCP related parameters</title>
      <link>/questions/4297/analyze-data-packets-in-the-network-and-retrieve-all-the-tcp-related-parameters/</link>
      <pubDate>Tue, 31 May 2011 13:25:00 +0000</pubDate>
      
      <guid>/questions/4297/analyze-data-packets-in-the-network-and-retrieve-all-the-tcp-related-parameters/</guid>
      <description>Analyze data packets in the network and retrieve all the TCP related parameters  0 Hi,
I want to analyze data packets in the network and retrieve all the TCP related parameters of a particular device and capture them into a file.
analyzedataasked 31 May &#39;11, 13:25
Kumar
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Okay, that sounds exactly like what you can do with Wireshark: first, capture TCP packet data, second, analyze it.</description>
    </item>
    
    <item>
      <title>Decrypt SSL Traffic destined for Squid Proxy Server</title>
      <link>/questions/4303/decrypt-ssl-traffic-destined-for-squid-proxy-server/</link>
      <pubDate>Tue, 31 May 2011 23:00:00 +0000</pubDate>
      
      <guid>/questions/4303/decrypt-ssl-traffic-destined-for-squid-proxy-server/</guid>
      <description>Decrypt SSL Traffic destined for Squid Proxy Server  0 I am trying to decrypt SSL traffic between a client (Firefox) and a Squid Proxy server that is using ssl-jump. The SSL certificate on the server is a private cert linked to the ssl-bump feature. I am using tshark to dump the SSL traffic.
I know all the certificates work fine because when I take Squid out of the path I can decrypt the traffic.</description>
    </item>
    
    <item>
      <title>readme files</title>
      <link>/questions/4304/readme-files/</link>
      <pubDate>Tue, 31 May 2011 23:11:00 +0000</pubDate>
      
      <guid>/questions/4304/readme-files/</guid>
      <description>readme files  0 Where can I get the following files?
README.capture - the capture engine internalsREADME.design - Wireshark software design - incompleteREADME.developer - this fileREADME.display_filter - Display Filter EngineREADME.idl2wrs - CORBA IDL converterREADME.packaging - how to distribute a software package containing WSREADME.regression - regression testing of WS and TSREADME.stats_tree - a tree statistics counting specific packetsREADME.tapping - &#34;tap&#34; a dissector to get protocol specific eventsREADME.xml-output - how to work with the PDML exported outputwiretap/README.</description>
    </item>
    
    <item>
      <title>malformed packet (exception occurred) PNG Protocol</title>
      <link>/questions/4305/malformed-packet-exception-occurred-png-protocol/</link>
      <pubDate>Tue, 31 May 2011 23:17:00 +0000</pubDate>
      
      <guid>/questions/4305/malformed-packet-exception-occurred-png-protocol/</guid>
      <description>malformed packet (exception occurred) PNG Protocol  0 Hello friends, I got the following error while capturing our hosting mail server, which is malformed packet (exception occurred) PNG Protocol, I was using version 1.4.4 and I thought it was a software bug, but then I uninstalled this version and I&#39;m now using version 1.4.7 and still see this error. Does this mean there is a critical situation we have to check deeply with it or is it normal?</description>
    </item>
    
    <item>
      <title>Network offline - online display</title>
      <link>/questions/4306/network-offline-online-display/</link>
      <pubDate>Wed, 01 Jun 2011 00:13:00 +0000</pubDate>
      
      <guid>/questions/4306/network-offline-online-display/</guid>
      <description>Network offline - online display  0 1I have some computers connected with each other through wireless LAN.
I want to know if i install this software into the server then can i get to know that which computer is online and which one is offline in real- time or not.
Please let me know..!!
about_wiresharkasked 01 Jun &#39;11, 00:13
Avinash
1●1●2●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>TCP out-of-order and other on a wireless link</title>
      <link>/questions/4312/tcp-out-of-order-and-other-on-a-wireless-link/</link>
      <pubDate>Wed, 01 Jun 2011 02:15:00 +0000</pubDate>
      
      <guid>/questions/4312/tcp-out-of-order-and-other-on-a-wireless-link/</guid>
      <description>TCP out-of-order and other on a wireless link  1 Hello everybody.
I&#39;m troubleshooting a network with Wireshark and, being new to deep traffic analysis, maybe some of you could give some advice to understand what&#39;s happening.
Let me depict the scenario:
 Internet | | &amp;lt;-Wired link | Core LAN | | Branch#1--------Branch#2  ^ | Wireless 5,8 GHz PMP link&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;p&amp;gt;Branch#1 uses the link only for basic office Internet access, browsing and mail.</description>
    </item>
    
    <item>
      <title>compilation error</title>
      <link>/questions/4313/compilation-error/</link>
      <pubDate>Wed, 01 Jun 2011 04:50:00 +0000</pubDate>
      
      <guid>/questions/4313/compilation-error/</guid>
      <description>compilation error  0 hi, i am getting fallowing error during the compilation of wireshark dissector, what may be the problem ?? please help me
: fatal error C1083: Cannot open include file: &#39;config.h&#39;: No such file or directory Project : warning PRJ0018 : The following environment variables were not found: $(WIRESHARK_LIB)
compileasked 01 Jun &#39;11, 04:50
sagu072
35●23●24●28
accept rate: 0%
What version of Wireshark are you trying to compile, and on what platform?</description>
    </item>
    
    <item>
      <title>DECT pcap decoding to voice</title>
      <link>/questions/4315/dect-pcap-decoding-to-voice/</link>
      <pubDate>Wed, 01 Jun 2011 06:45:00 +0000</pubDate>
      
      <guid>/questions/4315/dect-pcap-decoding-to-voice/</guid>
      <description>DECT pcap decoding to voice  0 Hi guys, any Idea, how to decode DECT captured file into Voice:
many Thx.
dectasked 01 Jun &#39;11, 06:45
reza666
1●3●3●4
accept rate: 0%
  
One Answer:
  
1That may prove difficult, since the B-field data is encrypted for any decent implementation. If it&#39;s not then filter out all B-field data of a connection and put it through a G.</description>
    </item>
    
    <item>
      <title>Strange SSL capture: &amp;quot;Ignored Unknown Record&amp;quot; instead of ServerHello</title>
      <link>/questions/4320/strange-ssl-capture-ignored-unknown-record-instead-of-serverhello/</link>
      <pubDate>Wed, 01 Jun 2011 15:03:00 +0000</pubDate>
      
      <guid>/questions/4320/strange-ssl-capture-ignored-unknown-record-instead-of-serverhello/</guid>
      <description>Strange SSL capture: &amp;ldquo;Ignored Unknown Record&amp;rdquo; instead of ServerHello  0 Hi - I&#39;ve been trying to decrypt an SSL stream from a single client to one of our servers. Since I was unable to decode it, I thought it may have been as a result of DH key negotiation, but the trace I took just seemed too odd.
You can see that packet 11 is summarized by Wireshark (1.4.6) as &#39;Ignored Unknown Record&#39; at the point where I would expect &#39;Server Hello&#39;</description>
    </item>
    
    <item>
      <title>MAC address</title>
      <link>/questions/4333/mac-address/</link>
      <pubDate>Thu, 02 Jun 2011 07:17:00 +0000</pubDate>
      
      <guid>/questions/4333/mac-address/</guid>
      <description>MAC address  2 1Hello, I need to track a MAC address or a span of MAC addresses, any idea how to just filter with the MAC? As of now I have just filtered via LLC protocol it would be alot cleaner with just the mac.
Thanks in advance.
filter mac mac-addressasked 02 Jun &#39;11, 07:17
aplatek
31●2●3●4
accept rate: 0%
  
3 Answers:
  
3If you are using a display filter of eth.</description>
    </item>
    
    <item>
      <title>How to identify SSL Certificate file name</title>
      <link>/questions/4337/how-to-identify-ssl-certificate-file-name/</link>
      <pubDate>Thu, 02 Jun 2011 09:25:00 +0000</pubDate>
      
      <guid>/questions/4337/how-to-identify-ssl-certificate-file-name/</guid>
      <description>How to identify SSL Certificate file name  0 Hi.
I often run into this problem... I&#39;m asked to capture SSL traffic (we use a lot of it around here), and, of course, I need the Cert in order to decrypt. But, often, requesting the cert from the folks who manage it, requires that I have the exact filename of the cert (e.g., XYZ12.PFX).
Is there a way that I can see the filename of the cert in the undecrypted packets - perhaps in the Server Hello?</description>
    </item>
    
    <item>
      <title>Does WireShark work on Windows Mobile 5</title>
      <link>/questions/4341/does-wireshark-work-on-windows-mobile-5/</link>
      <pubDate>Thu, 02 Jun 2011 10:30:00 +0000</pubDate>
      
      <guid>/questions/4341/does-wireshark-work-on-windows-mobile-5/</guid>
      <description>Does WireShark work on Windows Mobile 5  0 Hello! Does WireShark work on Windows Mobile 5? Also, if purchased - do you support Windows Mobile 5?
Thank you
windows mobile 5.0asked 02 Jun &#39;11, 10:30
mbarajas
1●1●1●1
accept rate: 0%
  
One Answer:
  
0No it does not, because GTK (the graphical libraries used by Wireshark) have not been built for Windows Mobile 5 AFAIK.</description>
    </item>
    
    <item>
      <title>CIFS vs NETBIOS &amp;amp; network performance</title>
      <link>/questions/4343/cifs-vs-netbios-network-performance/</link>
      <pubDate>Thu, 02 Jun 2011 11:42:00 +0000</pubDate>
      
      <guid>/questions/4343/cifs-vs-netbios-network-performance/</guid>
      <description>CIFS vs NETBIOS &amp;amp; network performance  0 Testing file open performance across a WAN vs LAN. I open a 1MB .rtf file. When opening on the LAN, the traffic is on port 445 (CIFS). When opening the same file from the same server across the WAN, the traffic is on port 139 (NETBIOS).
My question for all of you protocol gurus:
Is there really any difference in the traffic when using a different port to do the same activity?</description>
    </item>
    
    <item>
      <title>USB network adaptors</title>
      <link>/questions/4344/usb-network-adaptors/</link>
      <pubDate>Thu, 02 Jun 2011 12:38:00 +0000</pubDate>
      
      <guid>/questions/4344/usb-network-adaptors/</guid>
      <description>USB network adaptors  0 I have A usb network adaptor in a Tomtom navigation device I want to monitor from when it is plugged in, but of course if you unplug it the live capture stops and when u plug it back in data already flows before you can start capture, so need to set it up to capture as soon as it is plugged in, is this possible ?</description>
    </item>
    
    <item>
      <title>Wireshark can read information from netflow ?</title>
      <link>/questions/4346/wireshark-can-read-information-from-netflow/</link>
      <pubDate>Thu, 02 Jun 2011 13:02:00 +0000</pubDate>
      
      <guid>/questions/4346/wireshark-can-read-information-from-netflow/</guid>
      <description>Wireshark can read information from netflow ?  0 Hello,
i have one PC connected to router interface, and i want see a trafic for other interface in the same router. So, i want use wireshark to snif and read a netflow information from these interfaces, it&#39;s possible ? need a some modifications or indications in wireshark ? Thanks.
netflowasked 02 Jun &#39;11, 13:02
Adi
1●1●1●3
accept rate: 0%
 edited 02 Jun &#39;11, 13:14</description>
    </item>
    
    <item>
      <title>wireshark installation on windows 2000 server</title>
      <link>/questions/4355/wireshark-installation-on-windows-2000-server/</link>
      <pubDate>Thu, 02 Jun 2011 19:20:00 +0000</pubDate>
      
      <guid>/questions/4355/wireshark-installation-on-windows-2000-server/</guid>
      <description>wireshark installation on windows 2000 server  0 Hi All,
please advise me, i am trying to install wire shark on windows server 2000 but i am getting error and from error message it looks like OS not supported.
I even tried to download the small application version of wireshark and tried to install on USB drive but again win pcap ( ver 4.1.0) is not installed on server.
Tried installing the win pcap 3.</description>
    </item>
    
    <item>
      <title>installing offline</title>
      <link>/questions/4358/installing-offline/</link>
      <pubDate>Fri, 03 Jun 2011 00:21:00 +0000</pubDate>
      
      <guid>/questions/4358/installing-offline/</guid>
      <description>installing offline  0 hi, i hv downloaded wireshark source code and libraray files and skipped nmake -f makefile.nmake setup as i did download the libraries myself , but wen i tried to run &#34;nmake -f makefile.nmake all&#34; i am getting the error as dont know how to stop match686.onj does anybody has any idea on this, plase help to resolve this issue.
source installasked 03 Jun &#39;11, 00:21
sagu072</description>
    </item>
    
    <item>
      <title>jitter buffer option</title>
      <link>/questions/4361/jitter-buffer-option/</link>
      <pubDate>Fri, 03 Jun 2011 03:33:00 +0000</pubDate>
      
      <guid>/questions/4361/jitter-buffer-option/</guid>
      <description>jitter buffer option  0 I am simulating VoIP calls and capture traffic from the caller side. I cannot find the jitter buffer parameter in the SDP packets exchanged.
buffer sdp jitter voipasked 03 Jun &#39;11, 03:33
Lefkothea Va...
1●3●3●3
accept rate: 0%
  
One Answer:
  
1See RFC 4566, there are no jitter buffer parameters in SDP. You may find relevant information in RTCP packets.</description>
    </item>
    
    <item>
      <title>VOIP quality issues----how do I use wireshark to identify the problem</title>
      <link>/questions/4362/voip-quality-issues-how-do-i-use-wireshark-to-identify-the-problem/</link>
      <pubDate>Fri, 03 Jun 2011 05:15:00 +0000</pubDate>
      
      <guid>/questions/4362/voip-quality-issues-how-do-i-use-wireshark-to-identify-the-problem/</guid>
      <description>VOIP quality issues&amp;mdash;-how do I use wireshark to identify the problem  0 Dear All,
I work with for a TDM/VOIP carrier and I have this customer who complains about quality issues on our TDM/VOIP switch which interconnects with his on VOIP switch over IP. My boss has adviced me to use wireshark to determine if the issue is with our ISP provider. We have a 100G connection to our ISP but his thinking we might be having some bandwidth or latency issues.</description>
    </item>
    
    <item>
      <title>Permission denied while running wireshark</title>
      <link>/questions/4363/permission-denied-while-running-wireshark/</link>
      <pubDate>Fri, 03 Jun 2011 05:20:00 +0000</pubDate>
      
      <guid>/questions/4363/permission-denied-while-running-wireshark/</guid>
      <description>Permission denied while running wireshark  0 I had a wireshark distribution with me. It is on linux and works well. Now I have to put this wireshark binary on a server. So I used ftp to get the wireshark directory on my server. I copied it in the /root folder.
wireshark has root:root onwership and drwxr-xr-x permissions.
When I go the wireshark directory and try to run wireshark using .</description>
    </item>
    
    <item>
      <title>nature of address calling indicator</title>
      <link>/questions/4372/nature-of-address-calling-indicator/</link>
      <pubDate>Sat, 04 Jun 2011 07:06:00 +0000</pubDate>
      
      <guid>/questions/4372/nature-of-address-calling-indicator/</guid>
      <description>nature of address calling indicator  0 Hi all. I&#39;m using wireshark version 1.25 . I create from my pcap file a csv file using &#34;tshark....&#34; with several filed like : CIC , DATE, calling number , etc. One filed is nature of address of the calling number , but I noticed that it&#39;s write in my csv file The Nature Of address of the Location number section and not from Calling Party Number section.</description>
    </item>
    
    <item>
      <title>TCP Negotiations</title>
      <link>/questions/4373/tcp-negotiations/</link>
      <pubDate>Sat, 04 Jun 2011 08:54:00 +0000</pubDate>
      
      <guid>/questions/4373/tcp-negotiations/</guid>
      <description>TCP Negotiations  3 2I read this statement from a supposed Cisco employee on LinkedIn this morning:
&#34;I don&#39;t know how many times I&#39;ve had to say this but there is NO NEGOTIATION in tcp window sizes. In fact, there is NO NEGOTIATION in tcp period. The closest parameter that might come to tcp negotiation is the SACK option at the beginning of the connection.&#34;
I often find myself in arguments of semantics.</description>
    </item>
    
    <item>
      <title>Can SMB QUEUE DEPTH analysis also could be done by tshark?</title>
      <link>/questions/4374/can-smb-queue-depth-analysis-also-could-be-done-by-tshark/</link>
      <pubDate>Sat, 04 Jun 2011 12:03:00 +0000</pubDate>
      
      <guid>/questions/4374/can-smb-queue-depth-analysis-also-could-be-done-by-tshark/</guid>
      <description>Can SMB QUEUE DEPTH analysis also could be done by tshark?  0 Hi All
I am looking into SMB QUEUE DEPTH analysis with tshark. i know hot get smb.time statistics &#34;tshark -nlr c:smb.pcap -qz io,stat,10,&#34;COUNT(smb.time)smb.time&#34;,&#34;MIN(smb.time)smb.time&#34;,&#34;AVG(smb.time)smb.time&#34;,&#34;MAX(smb.time)smb.time&#34; but i can&#39;t find the right query for LOAD Please advice Thanks
queue depth smb analysisasked 04 Jun &#39;11, 12:03
tbaror
10●12●12●15
accept rate: 0%
anyone? LOAD(smb.time)smb.time
(05 Jun &#39;11, 02:35) tbaror2See thread at Wireshark User&#39;s list.</description>
    </item>
    
    <item>
      <title>Problem with capture filter when standard input is specified as the interface.</title>
      <link>/questions/4379/problem-with-capture-filter-when-standard-input-is-specified-as-the-interface/</link>
      <pubDate>Sat, 04 Jun 2011 20:46:00 +0000</pubDate>
      
      <guid>/questions/4379/problem-with-capture-filter-when-standard-input-is-specified-as-the-interface/</guid>
      <description>Problem with capture filter when standard input is specified as the interface.  0 Hi All,
I am trying to do SSH tunnelling from remote machine and redirect that message to dumpcap which is running on local machine, as shown below.
ssh [email protected] &#34;/upapps/ptc/cbtcpa/bin/dumpcap -i eth0 -w -&#34; | /upapps/ptc/cbtcpa/bin/dumpcap -i - -f &#34;port not 22&#34; -a duration:60 -b duration:60 -w test.pcap
But i am facing problem in the capture filter &#34;</description>
    </item>
    
    <item>
      <title>Wireshark can&amp;#x27;t capture packets after a DDOS attack</title>
      <link>/questions/4384/wireshark-cant-capture-packets-after-a-ddos-attack/</link>
      <pubDate>Sun, 05 Jun 2011 07:04:00 +0000</pubDate>
      
      <guid>/questions/4384/wireshark-cant-capture-packets-after-a-ddos-attack/</guid>
      <description>Wireshark can&amp;rsquo;t capture packets after a DDOS attack  0 The OS is windows 2003 SP2 The version of wireshark is 1.0.7 and the winpcap is the default one which follows with wireshark.
The problem is that wireshark will not work after a ddos attack(larger thant 1Gb/s 100,000packets/s). When I click the capture button a error form shows: &#34;The capture session could not be initiated (driver error: not enough memory to allocate the kernel buffer).</description>
    </item>
    
    <item>
      <title>Username / password not available</title>
      <link>/questions/4388/username-password-not-available/</link>
      <pubDate>Sun, 05 Jun 2011 15:18:00 +0000</pubDate>
      
      <guid>/questions/4388/username-password-not-available/</guid>
      <description>Username / password not available  0 Hi there, I am using Pirni Pro, a network sniffer, and I did a test on my own network. I have went to mail.yahoo.com, signed up with my username and password, then stoped the sniffer. It gave me a log.pcap file, I have downloaded it to my computer, opened it with WireShark and used the search tool. While searching for &#34;mail.yahoo.com&#34; or &#34;yahoo.com&#34;, it gaved me results, but when searching after my username and / or password it gaved me back no results.</description>
    </item>
    
    <item>
      <title>svn checkout error</title>
      <link>/questions/4392/svn-checkout-error/</link>
      <pubDate>Sun, 05 Jun 2011 22:51:00 +0000</pubDate>
      
      <guid>/questions/4392/svn-checkout-error/</guid>
      <description>svn checkout error  0 hi i am getting the fallowing the error while checking out the wireshark source code.
Error: OPTIONS of &#39;http://anonsvn.wireshark.org/wireshark/trunk&#39;: Could not resolve
Error: hostname `proxyname&#39;: The requested name is valid and
Error: was found in the database, but it does not have the correct associated data
Error: being resolved for.
Error: (http://anonsvn.wireshark.org)
what might be the problem, can anybody tel me .? thanks in advance.</description>
    </item>
    
    <item>
      <title>match686.obj file</title>
      <link>/questions/4393/match686obj-file/</link>
      <pubDate>Sun, 05 Jun 2011 23:29:00 +0000</pubDate>
      
      <guid>/questions/4393/match686obj-file/</guid>
      <description>match686.obj file  0 hi, during compilation of wireshark source i am getting error as &#34;match686.obj&#34; is not found, i tried to compile match686.asm n getting error as undefined symbol esp, if anybody has the object file of match686 then please send to [email protected] thank you.
match686asked 05 Jun &#39;11, 23:29
sagu072
35●23●24●28
accept rate: 0%
Hi, I would think that&#39;s when building zlib which Visual studio version are you using?</description>
    </item>
    
    <item>
      <title>zlib.dll.manifest not found.</title>
      <link>/questions/4398/zlibdllmanifest-not-found/</link>
      <pubDate>Mon, 06 Jun 2011 05:56:00 +0000</pubDate>
      
      <guid>/questions/4398/zlibdllmanifest-not-found/</guid>
      <description>zlib.dll.manifest not found.  0 hi, i am getting the fallowing error during compilation.
&#34;zlib1.dll.manifest : general error c1010070: Failed to load and parse the manife st. The system cannot find the file specified.&#34;
does anybody give any idea to solve this. i tried to find the manifest file but its not present it seems.
manifestasked 06 Jun &#39;11, 05:56
sagu072
35●23●24●28
accept rate: 0%
What version of Wireshark are you trying to compile?</description>
    </item>
    
    <item>
      <title>There are no interfaces on which a capture can be done</title>
      <link>/questions/4399/there-are-no-interfaces-on-which-a-capture-can-be-done/</link>
      <pubDate>Mon, 06 Jun 2011 06:04:00 +0000</pubDate>
      
      <guid>/questions/4399/there-are-no-interfaces-on-which-a-capture-can-be-done/</guid>
      <description>There are no interfaces on which a capture can be done  0 Hi expert,
My laptop is running on Windows 7 SP1 (32 bit). I successfully installed the version 1.4.7. Unfortunately, the application can&#39;t run due to no interface detected. I already did uninstall/install of the program but still problem exists. I also tried to install the old version but still the problem persists. For your assistance. Thank you</description>
    </item>
    
    <item>
      <title>wrong sequence</title>
      <link>/questions/4408/wrong-sequence/</link>
      <pubDate>Mon, 06 Jun 2011 08:41:00 +0000</pubDate>
      
      <guid>/questions/4408/wrong-sequence/</guid>
      <description>wrong sequence  0 Hi, I am new in using Wireshark. I am capturing VoIP calls and I was wondering what happens to the Wrong sequnce packets. Are they dropped at the receiver&#39;s end? Are they calculated as part of the lost packets percentage? thank you in advance
wrong packets rtp lost sequenceasked 06 Jun &#39;11, 08:41
Lefkothea Va...
1●3●3●3
accept rate: 0%
 edited 06 Jun &#39;11, 16:58</description>
    </item>
    
    <item>
      <title>Create my own dissector</title>
      <link>/questions/4410/create-my-own-dissector/</link>
      <pubDate>Mon, 06 Jun 2011 09:43:00 +0000</pubDate>
      
      <guid>/questions/4410/create-my-own-dissector/</guid>
      <description>Create my own dissector  0 Hi,
i try to create a dissector for my own simple UDP-Command-Protocol.
 -- Deklaration des neuen Protokolls -- Proto(&amp;quot;KurzName für FilterListbox&amp;quot;, &amp;quot;LangName&amp;quot;) UDP_CMD_proto = Proto(&amp;quot;UDP-CMD&amp;quot;,&amp;quot;UDP-Command Protocol&amp;quot;)  -- Deklaration der Felder im UDP_CMD_proto local f = UDP_CMD_proto.fields -- .uint8(StatusText, &amp;amp;quot;Text&amp;amp;quot;, Hex-Ausgane, nil, welche Bits) f.Flag1 = ProtoField.uint8(&amp;amp;quot;UDP_CMD_proto.Flag1&amp;amp;quot;, &amp;amp;quot;Response required&amp;amp;quot;, base.HEX, { [1] = &amp;amp;quot;YES&amp;amp;quot;, [0] = &amp;amp;quot;NO&amp;amp;quot;}, 0x01) f.Flag2 = ProtoField.uint8(&amp;amp;quot;UDP_CMD_proto.Flag2&amp;amp;quot;, &amp;amp;quot;...&amp;amp;quot;, base.HEX, nil, 0x02) f.</description>
    </item>
    
    <item>
      <title>code understanding</title>
      <link>/questions/4419/code-understanding/</link>
      <pubDate>Tue, 07 Jun 2011 01:56:00 +0000</pubDate>
      
      <guid>/questions/4419/code-understanding/</guid>
      <description>code understanding  0 what this code does. win which file the COL_INFO is defined. if (check_col(pinfo-&amp;gt;cinfo, COL_INFO)) { col_add_fstr(pinfo-&amp;gt;cinfo, COL_INFO, &#34;%d &amp;gt; %d Info Type:[%s]&#34;, pinfo-&amp;gt;srcport, pinfo-&amp;gt;destport, val_to_str(type, packettypenames, &#34;Unknown Type:0x%02x&#34;)); }
codeasked 07 Jun &#39;11, 01:56
sagu072
35●23●24●28
accept rate: 0%
  
One Answer:
  
1In which file the COL_INFO is defined
That&#39;s what your search function is for.
The code itself is meant to fill the Information column in the packet list of the Wireshark window and Tshark output.</description>
    </item>
    
    <item>
      <title>use API to capture XML</title>
      <link>/questions/4424/use-api-to-capture-xml/</link>
      <pubDate>Tue, 07 Jun 2011 06:27:00 +0000</pubDate>
      
      <guid>/questions/4424/use-api-to-capture-xml/</guid>
      <description>use API to capture XML  0 I am developing an application to send a query from one database to another. I am wondering if it is possible to use an API to capture XML messages.
queryasked 07 Jun &#39;11, 06:27
mbands2
1●2●2●2
accept rate: 0%
  
One Answer:
  
0Why do you want to use an API? I would use Wireshark to capture the communication and then look through the decode.</description>
    </item>
    
    <item>
      <title>how to filter for Kerberos traffic</title>
      <link>/questions/4427/how-to-filter-for-kerberos-traffic/</link>
      <pubDate>Tue, 07 Jun 2011 06:43:00 +0000</pubDate>
      
      <guid>/questions/4427/how-to-filter-for-kerberos-traffic/</guid>
      <description>how to filter for Kerberos traffic  0 During Security Log review on a Windows 2003 server I came across a repeated Event ID 531. Event gets logged 11 times every hour and does not have much details other than it’s a network log on/off (Ex. 11 times @ 5:11:15AM, 11 times @ 6:11:15AM, 11 times @ 7:11:15AM)
Logon Failure:
Reason: Account currently disabled User Name: Domain: Logon Type: 3 Logon Process: Authz Authentication Package: Kerberos Workstation Name: MAILSRV1 Caller User Name: MAILSRV1$ Caller Domain: CORP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 7152 Transited Services: - Source Network Address: - Source Port: -For more information, see Help and Support Center at http://go.</description>
    </item>
    
    <item>
      <title>using treeitem:set_generated() in a LUA script</title>
      <link>/questions/4437/using-treeitemset_generated-in-a-lua-script/</link>
      <pubDate>Tue, 07 Jun 2011 09:30:00 +0000</pubDate>
      
      <guid>/questions/4437/using-treeitemset_generated-in-a-lua-script/</guid>
      <description>using treeitem:set_generated() in a LUA script  0 Hello,
I have a basic lua dissector where data from the packet is being displayed properly in a tree view. I am trying to display some calculated values based on the data in the protocol; however, none of the data is being displayed as documented.
Question: Has anybody successfully used the treeitem:set_generated() function as documented in the lua API?
Here&#39;s the basic construct that I am using:</description>
    </item>
    
    <item>
      <title>trouble shoot capture</title>
      <link>/questions/4449/trouble-shoot-capture/</link>
      <pubDate>Tue, 07 Jun 2011 22:36:00 +0000</pubDate>
      
      <guid>/questions/4449/trouble-shoot-capture/</guid>
      <description>trouble shoot capture  0 Hello,
I am having an issue in running our in house developed application. This application access remotely setup SQL Server to establish connection. we were using the application since last 4 months. unfortunately on last friday i do not know what happened and just this location is not able to run the application as it is not able to establish connection with SQL server. As trouble shooting i have replaced router, by pass whole network just connected my laptop and tried to run application but did not worked.</description>
    </item>
    
    <item>
      <title>no symbols have been loaded</title>
      <link>/questions/4451/no-symbols-have-been-loaded/</link>
      <pubDate>Wed, 08 Jun 2011 01:57:00 +0000</pubDate>
      
      <guid>/questions/4451/no-symbols-have-been-loaded/</guid>
      <description>no symbols have been loaded  1 hi, during debugging the wireshark dissector i am getting the error as &#34;no symbols have been loaded&#34; , i have given the correct path to .pdb file but still getting the same error. can anybody help me in this issue.
development symbol debugger errorasked 08 Jun &#39;11, 01:57
sagu072
35●23●24●28
accept rate: 0%
 retagged 08 Jun &#39;11, 19:48 
helloworld
3.1k●4●20●41
Which debugger are you using?</description>
    </item>
    
    <item>
      <title>High throughput captures, USB better than onboard NIC?</title>
      <link>/questions/4458/high-throughput-captures-usb-better-than-onboard-nic/</link>
      <pubDate>Wed, 08 Jun 2011 14:17:00 +0000</pubDate>
      
      <guid>/questions/4458/high-throughput-captures-usb-better-than-onboard-nic/</guid>
      <description>High throughput captures, USB better than onboard NIC?  0 I am attempting to use Wireshark on a laptop using the built-in NIC. The throughput of the traffic being captured is very high and sustained, and it appears I may be dropping traffic (observing &#34;acknowledgement for unseen packet&#34; errors).
I feel the laptop NIC may be inadequate. Purchasing a probe or server with industrial NIC&#39;s is a bit overkill, as I only need this for a few days.</description>
    </item>
    
    <item>
      <title>Only My Own Traffic</title>
      <link>/questions/4459/only-my-own-traffic/</link>
      <pubDate>Wed, 08 Jun 2011 14:31:00 +0000</pubDate>
      
      <guid>/questions/4459/only-my-own-traffic/</guid>
      <description>Only My Own Traffic  0 Hi,
I&#39;m on a Dell XPS M1530 with an Intel 4965AGN card. I&#39;ve tried this on both Windows 7 and Ubuntu 11.4.
When I select my wireless adapter, set my card to promiscuous mode, and begin capture, I get no packets at all. This doesn&#39;t make sense as there are probably a dozen WLANs around me. If I connect to my own network, I can see my own traffic.</description>
    </item>
    
    <item>
      <title>error during setup</title>
      <link>/questions/4465/error-during-setup/</link>
      <pubDate>Wed, 08 Jun 2011 22:22:00 +0000</pubDate>
      
      <guid>/questions/4465/error-during-setup/</guid>
      <description>error during setup  0 while running &#34;nmake -f makefile.nmake verify_tools &#34; i am getting an error as end of file found before next directive, i replaced make file with other makefile but its still giving the same error. please reply if u hv any idea to solve this case.
compileasked 08 Jun &#39;11, 22:22
sagu072
35●23●24●28
accept rate: 0%
  
One Answer:
  
0What do you mean by, &#34;</description>
    </item>
    
    <item>
      <title>Wireshark stop to decode TCP frames</title>
      <link>/questions/4468/wireshark-stop-to-decode-tcp-frames/</link>
      <pubDate>Thu, 09 Jun 2011 02:01:00 +0000</pubDate>
      
      <guid>/questions/4468/wireshark-stop-to-decode-tcp-frames/</guid>
      <description>Wireshark stop to decode TCP frames  0 Context: Fedora 14 with wireshark 1.4.0 Use: live capture
when a burst Phenomenon appears, wireshark stops decode TCP frames. Only Ethernet protocol is showed on the screen. If I stop capture and I save it as a pcap file, all protocol frames are decoded. Anybody have an explanation ?
Thanks.
livecapturetcpasked 09 Jun &#39;11, 02:01
dja92
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How should I develop this tool?</title>
      <link>/questions/4469/how-should-i-develop-this-tool/</link>
      <pubDate>Thu, 09 Jun 2011 02:19:00 +0000</pubDate>
      
      <guid>/questions/4469/how-should-i-develop-this-tool/</guid>
      <description>How should I develop this tool?  0 Hi,
I&#39;d like to develop some enhancements to the Wireshark GUI, and I&#39;m not sure what the best approach is.
The graph interface in Statistics -&amp;gt; IOGraphs is very helpful but I&#39;d like to add on to that, perhaps have some more visualization that could be viewed side by side with the graph.
The stuff would be very specific to mobile development, so I&#39;m not sure adding directly into WS is the best idea (or is it?</description>
    </item>
    
    <item>
      <title>How can I only capture SIP packets?</title>
      <link>/questions/4470/how-can-i-only-capture-sip-packets/</link>
      <pubDate>Thu, 09 Jun 2011 04:40:00 +0000</pubDate>
      
      <guid>/questions/4470/how-can-i-only-capture-sip-packets/</guid>
      <description>How can I only capture SIP packets?  0 Hello, I only need to capture SIP packets. Would you please tell me how to configure Wireshark to accomplish this? It&#39;s better to use pictures to describe to me. Thanks.
capture sipThis question is marked &#34;community wiki&#34;.asked 09 Jun &#39;11, 04:40
Jacky Yeh
1●1●1●1
accept rate: 0%
 edited 09 Jun &#39;11, 15:37 
cmaynard ♦♦
9.4k●10●38●142
I have tried the sip, udp, ip, port and ethernet as follows show.</description>
    </item>
    
    <item>
      <title>Help SMB Troubleshooting ?</title>
      <link>/questions/4472/help-smb-troubleshooting/</link>
      <pubDate>Thu, 09 Jun 2011 06:05:00 +0000</pubDate>
      
      <guid>/questions/4472/help-smb-troubleshooting/</guid>
      <description>Help SMB Troubleshooting ?  0 Hello,
I have current situation a client (win2k3) 1Gigbit net that using to edit video with flowing format HD 100mbit + 4 wave Chanel audio , the media is located on storage (exanet ,redhat based). The issue is that while the client reading the video and when he needs to slide/scroll back the video the video is playing but the sound is getting behind the video lip-sync.</description>
    </item>
    
    <item>
      <title>Add ERROR COLOR to a dissector</title>
      <link>/questions/4474/add-error-color-to-a-dissector/</link>
      <pubDate>Thu, 09 Jun 2011 12:31:00 +0000</pubDate>
      
      <guid>/questions/4474/add-error-color-to-a-dissector/</guid>
      <description>Add ERROR COLOR to a dissector  0 Hi, i´am nearly ready with my own dissector. At least i want to colorize my the table-row from a mailformed frame.
How can i do this?
actual Error Routine:
 local Frame_OK = 1 if buffer:len() &amp;lt; 10 then Frame_OK = 0 TreeNode = TreeNode_E1:add(buffer(), &amp;quot;Payload-Data integrity : &amp;quot; .. &amp;quot;ERROR - payload Length &amp;lt; 10 bytes!&amp;quot; ) end if Frame_OK == 1 then if not (buffer(0,1):uint() == 91) or not (buffer(8,1):uint() == 124) or not (buffer(buffer:len()-1,1):uint() == 93) then Frame_OK = 0 TreeNode = TreeNode_E1:add(buffer(), &amp;quot;Payload-Data integrity : &amp;quot; .</description>
    </item>
    
    <item>
      <title>new wireshark dissector</title>
      <link>/questions/4477/new-wireshark-dissector/</link>
      <pubDate>Thu, 09 Jun 2011 13:01:00 +0000</pubDate>
      
      <guid>/questions/4477/new-wireshark-dissector/</guid>
      <description>new wireshark dissector  0 Hi, I am developing a new wireshark dissector. I have a pcap file the could be opened from wireshark how do I get my plugin to read this file. If I feed it through a port I can write the port to my dissector code to listen in that port. How does a plugin get activated when a pcap file is opened???
Thanks in Advance</description>
    </item>
    
    <item>
      <title>tshark 1.5 version download location for Linux platform</title>
      <link>/questions/4489/tshark-15-version-download-location-for-linux-platform/</link>
      <pubDate>Thu, 09 Jun 2011 23:42:00 +0000</pubDate>
      
      <guid>/questions/4489/tshark-15-version-download-location-for-linux-platform/</guid>
      <description>tshark 1.5 version download location for Linux platform  0 Hi,
Can anyone point me to the location of Wireshark/tshark 1.5 version for Linux platform. I&#39;m working on tshark commandline utility which require 1.5 version.
Thanks Asif
download tsharkasked 09 Jun &#39;11, 23:42
asif
1●5●5●6
accept rate: 0%
 retagged 10 Jun &#39;11, 16:31 
helloworld
3.1k●4●20●41
Just curious... What&#39;s so special about 1.5? (Why don&#39;t newer versions still work for you?</description>
    </item>
    
    <item>
      <title>Uncompression error : buffer error</title>
      <link>/questions/4490/uncompression-error-buffer-error/</link>
      <pubDate>Fri, 10 Jun 2011 03:14:00 +0000</pubDate>
      
      <guid>/questions/4490/uncompression-error-buffer-error/</guid>
      <description>Uncompression error : buffer error  0 An error occurred while reading the capture file : Uncompression error :buffer error.
=&amp;gt; It means that I cannot read data fully?? that is, some data is missing when wireshark reading the capture file, right?
What should I do to overcome this error??? I have to read data fully. I am trying to read DARPA 1999 dataset. Please, help me~~!! It&#39;s my term project.</description>
    </item>
    
    <item>
      <title>How to find TCP version</title>
      <link>/questions/4491/how-to-find-tcp-version/</link>
      <pubDate>Fri, 10 Jun 2011 03:47:00 +0000</pubDate>
      
      <guid>/questions/4491/how-to-find-tcp-version/</guid>
      <description>How to find TCP version  0 How to find TCP version (TCP congestion avoidance algorithms) like TCP TAHOE,TCP VEGAS,TCP NEW RENO IN wireshark FILES
tcp versionsasked 10 Jun &#39;11, 03:47
kumar86
1●1●1●3
accept rate: 0%
  
One Answer:
  
5Its not a value in the tcp headers, you can only tell by how the stack behaves. Watch for things like how the stack retransmits lost packets (Retransmission, Fast Retransmission, Selective Acknowledgement), how sessions are setup (with Window Scaling, Timestamps, MSS value etc.</description>
    </item>
    
    <item>
      <title>Network game testing via Wireshark</title>
      <link>/questions/4492/network-game-testing-via-wireshark/</link>
      <pubDate>Fri, 10 Jun 2011 03:58:00 +0000</pubDate>
      
      <guid>/questions/4492/network-game-testing-via-wireshark/</guid>
      <description>Network game testing via Wireshark  0 Hi Wireshark Experts,
How can i check/inspect the performance of my network game via Wireshark and specifically the Graphs available in Wireshark,i want to test the performance of my network game.
i see the Throughput and RoundTriptime and other graphs, the problem i m facing and the ambiguity i have is that; are those graphs reflecting or are they based on the data of my application</description>
    </item>
    
    <item>
      <title>empty struct</title>
      <link>/questions/4499/empty-struct/</link>
      <pubDate>Fri, 10 Jun 2011 07:25:00 +0000</pubDate>
      
      <guid>/questions/4499/empty-struct/</guid>
      <description>empty struct  0 i saw an empty struct as struct pref_module; defined in epanpref.h, what is the significance of such structures, i have not come accross such structures.
empty_structureasked 10 Jun &#39;11, 07:25
sagu072
35●23●24●28
accept rate: 0%
  
One Answer:
  
2It&#39;s not an empty struct, it is a struct whose contents are not visible to users of prefs.h. The full structure definition of the structure is in prefs-int.</description>
    </item>
    
    <item>
      <title>unable to upgrade to wireshark 1.6</title>
      <link>/questions/4502/unable-to-upgrade-to-wireshark-16/</link>
      <pubDate>Fri, 10 Jun 2011 07:43:00 +0000</pubDate>
      
      <guid>/questions/4502/unable-to-upgrade-to-wireshark-16/</guid>
      <description>unable to upgrade to wireshark 1.6  0 I&#39;ve downloaded(http://www.wireshark.org/download/src/all-versions/wireshark-1.6.0rc2.tar.bz2) and performed the following steps, I still see version 1.2 instead of 1.6. Please advise if any step is missing to upgrade my wireshark to 1.6 version.
./configuremakemake installI didn&#39;t find any issues running above three steps. I still see version as 1.2.
tshark -version TShark 1.2.10 (RVBD_208)
Copyright 1998-2010 Gerald Combs [email protected] and contributors. This is free software; see the source for copying conditions.</description>
    </item>
    
    <item>
      <title>inter-packet delay</title>
      <link>/questions/4506/inter-packet-delay/</link>
      <pubDate>Fri, 10 Jun 2011 08:22:00 +0000</pubDate>
      
      <guid>/questions/4506/inter-packet-delay/</guid>
      <description>inter-packet delay  0 Hi, I would like to create a graph of the inter-packet delays and the sequence numbers of an RTP steam. I don&#39;t now which data I should use for it, the delta?
thank you in advance
delay delta rtp inter-packetasked 10 Jun &#39;11, 08:22
Lefkothea Va...
1●3●3●3
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Lua Post Dissector from 1.4 breaks in 1.6</title>
      <link>/questions/4515/lua-post-dissector-from-14-breaks-in-16/</link>
      <pubDate>Fri, 10 Jun 2011 14:12:00 +0000</pubDate>
      
      <guid>/questions/4515/lua-post-dissector-from-14-breaks-in-16/</guid>
      <description>Lua Post Dissector from 1.4 breaks in 1.6  0 I&#39;ve been building a post dissector in Lua for the last month, and have used pinfo.columns.protocol:set(&#34;G2S&#34;) to assign packets the G2S name in the Protocol column that I&#39;ve identified as my application protocol. In V1.4.x, this worked just fine. But now with 1.6, my first identified packet displays G2S in the protocol column, but all subsequent packets continue to show HTTP/XML.</description>
    </item>
    
    <item>
      <title>wireshark see packets which should be dropped by iptables</title>
      <link>/questions/4521/wireshark-see-packets-which-should-be-dropped-by-iptables/</link>
      <pubDate>Sat, 11 Jun 2011 16:03:00 +0000</pubDate>
      
      <guid>/questions/4521/wireshark-see-packets-which-should-be-dropped-by-iptables/</guid>
      <description>wireshark see packets which should be dropped by iptables  0 hello, using iptables
[email protected]:~# iptables -A INPUT -s 192.168.1.5 -p udp -j DROPi wanted do drop all incoming udp packets, but i don&#39;t know why wireshark see all this packets. Moreover
iptables -L -n -vsays that packets were droped.
iptablesasked 11 Jun &#39;11, 16:03
azazzel01
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1One basic rule of network analysis is that you never run the analysis tool on the same system as the device under test (or device under suspicion) as that might nog give you the right picture (as you are experiencing).</description>
    </item>
    
    <item>
      <title>Wireshark does not run on OSX 10.6.4</title>
      <link>/questions/4528/wireshark-does-not-run-on-osx-1064/</link>
      <pubDate>Sun, 12 Jun 2011 11:36:00 +0000</pubDate>
      
      <guid>/questions/4528/wireshark-does-not-run-on-osx-1064/</guid>
      <description>Wireshark does not run on OSX 10.6.4  0 I just downloaded and installed wire shark on Mac OSX 10.6.4 when I opened it the first time it gave me a messege that it will require a few minutes to start up. It never did start up, and double clicking the icon does nothing. It simply wont start. what did I do wrong?
osx mac installationasked 12 Jun &#39;11, 11:36</description>
    </item>
    
    <item>
      <title>Sniffing possible only after disconnect/reconnect or deauthenticating a client</title>
      <link>/questions/4529/sniffing-possible-only-after-disconnectreconnect-or-deauthenticating-a-client/</link>
      <pubDate>Sun, 12 Jun 2011 13:33:00 +0000</pubDate>
      
      <guid>/questions/4529/sniffing-possible-only-after-disconnectreconnect-or-deauthenticating-a-client/</guid>
      <description>Sniffing possible only after disconnect/reconnect or deauthenticating a client  0 Hi all, I&#39;m just doing some expeiments at my own WLAN (it is encrypted with WPA-PSK and I know the passphrase), I&#39;m trying to sniff some traffic with Wireshark (on Backtrack 5) with a usb device (linksys wusb54gc), I entered the passphrase in the Wireshark preferences and there are 2 clients connected to the net, (my laptop with its own wifi card and another laptop with its wifi card) but I realize that I can see traffic only after I disconnect/reconnect my laptop from the net (using windows) I&#39;m trying to sniff and, similarly, I can see the other pc&#39;s traffic only when I send it a deauthentication packet with aireplay.</description>
    </item>
    
    <item>
      <title>Wireshark 1.4.6 crashes when saving</title>
      <link>/questions/4535/wireshark-146-crashes-when-saving/</link>
      <pubDate>Mon, 13 Jun 2011 02:01:00 +0000</pubDate>
      
      <guid>/questions/4535/wireshark-146-crashes-when-saving/</guid>
      <description>Wireshark 1.4.6 crashes when saving  0 I&#39;m using version 1.4.6 running on a windows XP machine with all the latest updates.
I&#39;m running a capture on a spanned network port. I&#39;ve left the capture running for 4 hours and it saves ok (File&amp;gt;save as)
But when I come to do a longer test it crashes, this has been the case for a 72 hour capture and a 24 hour capture.</description>
    </item>
    
    <item>
      <title>Capturing Packets on Multiple IP Address (FIlter)</title>
      <link>/questions/4538/capturing-packets-on-multiple-ip-address-filter/</link>
      <pubDate>Mon, 13 Jun 2011 08:08:00 +0000</pubDate>
      
      <guid>/questions/4538/capturing-packets-on-multiple-ip-address-filter/</guid>
      <description>Capturing Packets on Multiple IP Address (FIlter)  0 I&#39;m looking for the syntax to do a capture filter on WireShark, by capturing the traffic on several (specific) IP addresses. I understand how to capture a range, and an individual IP address. However, the application I am capturing on is spread of a &#39;bucket&#39; of IP addresses/servers, of which other applications are based within the same range. See my example:</description>
    </item>
    
    <item>
      <title>creating pcap with multiple packets</title>
      <link>/questions/4543/creating-pcap-with-multiple-packets/</link>
      <pubDate>Mon, 13 Jun 2011 12:37:00 +0000</pubDate>
      
      <guid>/questions/4543/creating-pcap-with-multiple-packets/</guid>
      <description>creating pcap with multiple packets  0 I have a binary file that I want to convert to a pcap file. I did a hexdump and then converted to a pcap using text2pcap. But there are multiple packets(custom protocol, custom dissector) in that binary file. How do I use hexdump to delineate different packets so that my pcap file has multiple packets??
Thanks!
hexdump pcapasked 13 Jun &#39;11, 12:37
tut087</description>
    </item>
    
    <item>
      <title>&amp;quot;Installer integrity check has failed. NSIS_Error&amp;quot;</title>
      <link>/questions/4544/installer-integrity-check-has-failed-nsis_error/</link>
      <pubDate>Mon, 13 Jun 2011 13:22:00 +0000</pubDate>
      
      <guid>/questions/4544/installer-integrity-check-has-failed-nsis_error/</guid>
      <description>&amp;ldquo;Installer integrity check has failed. NSIS_Error&amp;rdquo;  0 I&#39;ve just set up on Windows 7 64-bit on my existing PC (wiped the XP). Whenever I install 32-bit or 64-bit WireShark I get the following error message:
&#34;Installer integrity check has failed. Common causes include incomplete download and damaged media. Contact the installer&#39;s author to obtain a new copy. More information at: http://nsis.sf.net/NSIS_Error&#34;
I tried the tips at nsis.sf.net, but no luck.</description>
    </item>
    
    <item>
      <title>Wireshark 1.6.0 frequently crashes XP-32bit</title>
      <link>/questions/4546/wireshark-160-frequently-crashes-xp-32bit/</link>
      <pubDate>Mon, 13 Jun 2011 13:54:00 +0000</pubDate>
      
      <guid>/questions/4546/wireshark-160-frequently-crashes-xp-32bit/</guid>
      <description>Wireshark 1.6.0 frequently crashes XP-32bit  0 I am opening/closing several capture files (originally captured in 1.6.0 too) using 1.6.0. I am just looking at summary statistics. It seems to be a frequent event for Wireshark to close with an error in libwireshark.dll v1.6.0.37592. This is getting rather frustrating to have to keep opening back up Wireshark.
The capture files are on the local C: drive. They range anywhere from 197K to 35M so they are not large nor are they complex protocol decodes - simple SharePoint &amp;amp; SMB traffic.</description>
    </item>
    
    <item>
      <title>decoding wireshark</title>
      <link>/questions/4550/decoding-wireshark/</link>
      <pubDate>Mon, 13 Jun 2011 21:33:00 +0000</pubDate>
      
      <guid>/questions/4550/decoding-wireshark/</guid>
      <description>decoding wireshark  0 0
i hv written code to reverse the hex dump in the C language, but i observed the output like this ∟ o e ∞ m @ ☻ Ñ N ╢ 2 E ( δ à ≥ ♠ Σ M ╤ ‼ e j └ ¿ ☺ ╓ ☺ ╗ └ J d ¿ σ * k · ½ ♥ P ► D p O æ ∟ o e ∞ m @ ☻ Ñ N ╢ 2 E ☻ s δ ë ≥ ♠ ß ■ ╤ ‼ e j └ ¿ ☺ ╓ ☺ ╗ └ J d ¿ σ * k · ½ ♥ P ↑ D p n ♀ ↨ ♥ ☺ ☻ F ⌠ N</description>
    </item>
    
    <item>
      <title>Type protocol (0x1a42, 0x19f0, 0x901a, 0xf735, 0x5847, etc) info ethernet II</title>
      <link>/questions/4555/type-protocol-0x1a42-0x19f0-0x901a-0xf735-0x5847-etc-info-ethernet-ii/</link>
      <pubDate>Tue, 14 Jun 2011 01:23:00 +0000</pubDate>
      
      <guid>/questions/4555/type-protocol-0x1a42-0x19f0-0x901a-0xf735-0x5847-etc-info-ethernet-ii/</guid>
      <description>Type protocol (0x1a42, 0x19f0, 0x901a, 0xf735, 0x5847, etc) info ethernet II  0 I want to analizy the captured traffic, but I can&#39;t to find what kind of protocol I have. The wireshark is looking bad, it shows:
Address: 1a:42:00:24:00:1e (1a:42:00:24:00:1e) Source: 1a:42:00:24:00:1e (1a:42:00:24:00:1e) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) .... ..1. .... .... .... .... = LG bit: Locally administered address (this is NOT the factory default) Type: Unknown (0x5847)What does the protocol type it can be?</description>
    </item>
    
    <item>
      <title>is wireshark scriptable?</title>
      <link>/questions/4557/is-wireshark-scriptable/</link>
      <pubDate>Tue, 14 Jun 2011 02:16:00 +0000</pubDate>
      
      <guid>/questions/4557/is-wireshark-scriptable/</guid>
      <description>is wireshark scriptable?  0 hello i have a simple question
i need to import many big pcap files were talking about 200GB+ and i would like to write a script to make wireshark import the separate 500Mb Files and merge them into 1 big file for analyzing? is this possible? and if yeah how ? or where can i find anything about the scripting functions?
thanks in advanced
merge gb analysis scriptasked 14 Jun &#39;11, 02:16</description>
    </item>
    
    <item>
      <title>Continual NTLM Authentication</title>
      <link>/questions/4566/continual-ntlm-authentication/</link>
      <pubDate>Tue, 14 Jun 2011 13:25:00 +0000</pubDate>
      
      <guid>/questions/4566/continual-ntlm-authentication/</guid>
      <description>Continual NTLM Authentication  0 Hi. This is not actually a Wireshark question per se, so, if I&#39;m out of line for asking it here, please let me know. I will take it like a man :-)
I am using Wireshark to analyze/improve the performance of a .NET 2.0 application. It is a WinForms app, which calls an ASMX Web Service.
What I have found is that, for each and every HTTP POST, to MyWebService.</description>
    </item>
    
    <item>
      <title>How to Display &amp;quot;Bound by PSH bit&amp;quot;?</title>
      <link>/questions/4568/how-to-display-bound-by-psh-bit/</link>
      <pubDate>Wed, 15 Jun 2011 01:03:00 +0000</pubDate>
      
      <guid>/questions/4568/how-to-display-bound-by-psh-bit/</guid>
      <description>How to Display &amp;ldquo;Bound by PSH bit&amp;rdquo;?  0 Hi, A picture is worth a thousand words, so for explaining that actually the application is trying to steer TCP instead of leaving it to TCP, how can i: 1.graph or proof this phenomenon and 2.tell if it does a good job or not?
link:A brief explanation of Bound by Push Bit
All advice always highly appreciated!
regards, Marc
graph psh boundbypshasked 15 Jun &#39;11, 01:03</description>
    </item>
    
    <item>
      <title>Can i change the order about the list of the interface?</title>
      <link>/questions/4569/can-i-change-the-order-about-the-list-of-the-interface/</link>
      <pubDate>Wed, 15 Jun 2011 05:19:00 +0000</pubDate>
      
      <guid>/questions/4569/can-i-change-the-order-about-the-list-of-the-interface/</guid>
      <description>Can i change the order about the list of the interface?  0 Can i change the order of interface number, by the way, the number is get by command &#34;tshark -D&#34;?
interface listasked 15 Jun &#39;11, 05:19
phoenix
1●1●1●2
accept rate: 0%
 edited 15 Jun &#39;11, 05:22 
Why would you want to do that? the list is usually pretty short anyway...
(15 Jun &#39;11, 06:32) Jasper ♦♦</description>
    </item>
    
    <item>
      <title>programming winPCAP</title>
      <link>/questions/4574/programming-winpcap/</link>
      <pubDate>Wed, 15 Jun 2011 07:02:00 +0000</pubDate>
      
      <guid>/questions/4574/programming-winpcap/</guid>
      <description>programming winPCAP  0 i need to write a program that uses WinPCAP/LibPCAP to parse incoming xml structures being sent. i have no experience doing this. any tips? or places to start?
winpcapasked 15 Jun &#39;11, 07:02
mbands2
1●2●2●2
accept rate: 0%
  
One Answer:
  
1Better start of with the Developer Pack, containing documentation.
answered 15 Jun &#39;11, 14:39
Jaap ♦
11.7k●16●101
accept rate: 14%</description>
    </item>
    
    <item>
      <title>Building Wireshark Fedora pcap.h issue</title>
      <link>/questions/4576/building-wireshark-fedora-pcaph-issue/</link>
      <pubDate>Wed, 15 Jun 2011 10:43:00 +0000</pubDate>
      
      <guid>/questions/4576/building-wireshark-fedora-pcaph-issue/</guid>
      <description>Building Wireshark Fedora pcap.h issue  0 I am trying to build Wireshark 1.6 on Fedora 14 x64. When I run the ./configure script I get the following error:
configure: error: Header file pcap.h not found; if you installed libpcap from source, did you also do &#34;make install-incl&#34;, and if you installed a binary package of libpcap, is there also a developer&#39;s package of libpcap, and did you also install that package?</description>
    </item>
    
    <item>
      <title>promiscuous mode on xp and windows 7</title>
      <link>/questions/4580/promiscuous-mode-on-xp-and-windows-7/</link>
      <pubDate>Wed, 15 Jun 2011 12:29:00 +0000</pubDate>
      
      <guid>/questions/4580/promiscuous-mode-on-xp-and-windows-7/</guid>
      <description>promiscuous mode on xp and windows 7  0 I have two operating systems on a single disk to windows 7 and windows xp is the way the card is atheros ar5007eg on Windows 7 without a problem and the promiscuous mode for xp failed to set hardware filter to promiscuous mode, why is that?
promiscuous modeasked 15 Jun &#39;11, 12:29
tomulusss
1●1●1●1
accept rate: 0%
 edited 16 Jun &#39;11, 11:57</description>
    </item>
    
    <item>
      <title>tcp sequence number stops increasing</title>
      <link>/questions/4583/tcp-sequence-number-stops-increasing/</link>
      <pubDate>Wed, 15 Jun 2011 18:21:00 +0000</pubDate>
      
      <guid>/questions/4583/tcp-sequence-number-stops-increasing/</guid>
      <description>tcp sequence number stops increasing  0 Hi,
I&#39;m trying to understand why a TCP conversation between client and server ends with the client sending a FIN after many packets have been exchanged back and forth. The only thing I can see that might be an issue is that after a while, the sequence number from the server stops increasing even though the client&#39;s packets are not empty.
Does this mean the server has not received these packets or has lost its place in the connection, or how do I interpret this result?</description>
    </item>
    
    <item>
      <title>function used to construct tree</title>
      <link>/questions/4586/function-used-to-construct-tree/</link>
      <pubDate>Thu, 16 Jun 2011 00:33:00 +0000</pubDate>
      
      <guid>/questions/4586/function-used-to-construct-tree/</guid>
      <description>function used to construct tree  0 i have used proto_tree_add_uint to display ints, which one shall i use to display enumerated datas.
treeasked 16 Jun &#39;11, 00:33
sagu072
35●23●24●28
accept rate: 0%
  
One Answer:
  
0Have a look at the Developer readme, specifically section 1.6, subsection strings (line 1810).
answered 16 Jun &#39;11, 02:27
Jaap ♦
11.7k●16●101
accept rate: 14%
     </description>
    </item>
    
    <item>
      <title>Display filter with white spaces</title>
      <link>/questions/4591/display-filter-with-white-spaces/</link>
      <pubDate>Thu, 16 Jun 2011 06:02:00 +0000</pubDate>
      
      <guid>/questions/4591/display-filter-with-white-spaces/</guid>
      <description>Display filter with white spaces  0 Hi,
I am trying to launch the Wireshark through command line as:
wireshark -r mycapture.pcap -R &#34;frame.time eq Nov 2, 2010 18:49:42.000710000&#34;
Its giving an error:
2&#34; was unexpected in this context.
The filter expression &#34;frame.time == Nov 2, 2010 18:49:42.000710000&#34; isn&#39;t a valid display filter.
It seems like the white space is causing the problem. Any suggestions how to do this?
Thanks, Puneet</description>
    </item>
    
    <item>
      <title>HTTPS request not getting decrypted whereas response does</title>
      <link>/questions/4597/https-request-not-getting-decrypted-whereas-response-does/</link>
      <pubDate>Thu, 16 Jun 2011 09:52:00 +0000</pubDate>
      
      <guid>/questions/4597/https-request-not-getting-decrypted-whereas-response-does/</guid>
      <description>HTTPS request not getting decrypted whereas response does  0 Folks,
I am running wireshark from the client browser machine and server service is running on another machine. I want to see what all are the request and response that are made by the client by running wireshark on client machine.
I have configured the RSA key list for SSL as
&amp;lt;server-ip&amp;gt;,443,http,c:\certs\myssl.pem
Also there is a service svchost.exe which runs as local service currently i am running in as administrator though i find those requests made by svchost.</description>
    </item>
    
    <item>
      <title>Why is TCP protocol used for SUPL (ulp) when the port is decoded as oma-ulp?</title>
      <link>/questions/4599/why-is-tcp-protocol-used-for-supl-ulp-when-the-port-is-decoded-as-oma-ulp/</link>
      <pubDate>Thu, 16 Jun 2011 10:47:00 +0000</pubDate>
      
      <guid>/questions/4599/why-is-tcp-protocol-used-for-supl-ulp-when-the-port-is-decoded-as-oma-ulp/</guid>
      <description>Why is TCP protocol used for SUPL (ulp) when the port is decoded as oma-ulp?  0 Wireshark V1.4.7 or v1.6.0 is able to detect the ulp port 7275 in both directions (oma-ulp, Src port or Dst port), but is not able to re-assemble the TCP segments in one ULP message, in other words decode a ulp message. For each segment, TCP protocol is used: Example: Transmission Control Protocol, Src Port:14740 (14740), Dst Port: oma-ulp (7275), Seq.</description>
    </item>
    
    <item>
      <title>Troubleshooting a lost packet</title>
      <link>/questions/4604/troubleshooting-a-lost-packet/</link>
      <pubDate>Thu, 16 Jun 2011 13:49:00 +0000</pubDate>
      
      <guid>/questions/4604/troubleshooting-a-lost-packet/</guid>
      <description>Troubleshooting a lost packet  0 A customer in Taiwan is connection to my secured web server using Chrome. We&#39;re running javascript (compiled with GWT) in the browser session, sending requests back to the server via the XmlHttpRequest object. There seems to be one particular code path that gets &#34;stuck&#34;; it will seem to be working fine, and then some change (presumably to the data being sent) will &#34;break&#34; the communication.</description>
    </item>
    
    <item>
      <title>TCP window full</title>
      <link>/questions/4610/tcp-window-full/</link>
      <pubDate>Fri, 17 Jun 2011 08:13:00 +0000</pubDate>
      
      <guid>/questions/4610/tcp-window-full/</guid>
      <description>TCP window full  0 I&#39;m getting a &#34;The transmission window is now completely full&#34; from local sender to server. Does this mean send&#39;s buffer was full or receiver buffer was full? I check TCP receive window on both end, window size did not shrink. Please help to under transmission window means sender or receiver. Thanks.
window full tcpasked 17 Jun &#39;11, 08:13
lung
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Use Wireshark to do a &amp;quot;TCP Trace Route&amp;quot;?</title>
      <link>/questions/4612/use-wireshark-to-do-a-tcp-trace-route/</link>
      <pubDate>Fri, 17 Jun 2011 16:47:00 +0000</pubDate>
      
      <guid>/questions/4612/use-wireshark-to-do-a-tcp-trace-route/</guid>
      <description>Use Wireshark to do a &amp;ldquo;TCP Trace Route&amp;rdquo;?  0 Hello...
I have a problem where I cannot connect to a remote server. A Wireshark capture from my (client) end shows my TCP SYN packets receive no response. But, how to tell if the SYN is making it to the server, and being ignored, or... if the SYN gets dropped by a firewall/router, and never arrives at the server???
An ICMP-based TraceRoute is no good, because PINGs are often blocked by firewalls.</description>
    </item>
    
    <item>
      <title>Wireshark Crash when FTYPE_LOOKUP is Called for one of the Packets</title>
      <link>/questions/4617/wireshark-crash-when-ftype_lookup-is-called-for-one-of-the-packets/</link>
      <pubDate>Sat, 18 Jun 2011 14:02:00 +0000</pubDate>
      
      <guid>/questions/4617/wireshark-crash-when-ftype_lookup-is-called-for-one-of-the-packets/</guid>
      <description>Wireshark Crash when FTYPE_LOOKUP is Called for one of the Packets  0 I was writing a Custom Wireshark Dissector. But when I ran the plugin I created, by choosing packets to be Decoded as my protocol, Wireshark Crashes with Error that &#34;Application has requested runtime to terminate it in an unusual Way&#34;.
To Debug it further I added printf statements and also ran Wireshark from Visual C++ 2008 EE in Debug Mode(by adding breakpoints).</description>
    </item>
    
    <item>
      <title>Throughput graph: Why are there parallel lines?</title>
      <link>/questions/4620/throughput-graph-why-are-there-parallel-lines/</link>
      <pubDate>Sun, 19 Jun 2011 09:18:00 +0000</pubDate>
      
      <guid>/questions/4620/throughput-graph-why-are-there-parallel-lines/</guid>
      <description>Throughput graph: Why are there parallel lines?  0 Hello,
This is my throughput graph: Could anyone tell me what I can conclude about the 2 parallel lines in this graph? Thanks in advance.
graph throughputasked 19 Jun &#39;11, 09:18
ord
6●1●1●3
accept rate: 0%
  
2 Answers:
  
2 I see more that 2 parallel lines, but I assume you mean the two most &#34;thick&#34; ones.</description>
    </item>
    
    <item>
      <title>could not load the module</title>
      <link>/questions/4630/could-not-load-the-module/</link>
      <pubDate>Sun, 19 Jun 2011 23:34:00 +0000</pubDate>
      
      <guid>/questions/4630/could-not-load-the-module/</guid>
      <description>could not load the module  0 hi while running the wireshark i am getting the error as &#34; could not load the module WireSharkwireshark-gtk2plugins1.4.7my.dll&#34; can anybody tel, what may be the prob..
module errorasked 19 Jun &#39;11, 23:34
sagu072
35●23●24●28
accept rate: 0%
 edited 20 Jun &#39;11, 01:43 
   </description>
    </item>
    
    <item>
      <title>capture filter syslog</title>
      <link>/questions/4633/capture-filter-syslog/</link>
      <pubDate>Mon, 20 Jun 2011 02:52:00 +0000</pubDate>
      
      <guid>/questions/4633/capture-filter-syslog/</guid>
      <description>capture filter syslog  0 Hi All,
How can i filter packets using &#34;capture filter&#34; to filter syslog packets ?
Thanks
syslogasked 20 Jun &#39;11, 02:52
nirh
1●1●1●1
accept rate: 0%
  
One Answer:
  
2$ egrep -i syslog /etc/services syslog 514/udp #so try &#34;udp port 514&#34; or &#34;udp port syslog&#34;.
answered 20 Jun &#39;11, 11:35
Guy Harris ♦♦
17.4k●3●35●196
accept rate: 19%
[[email protected]:Active] / # grep syslog /etc/services</description>
    </item>
    
    <item>
      <title>Wireshark for Precise Timing</title>
      <link>/questions/4635/wireshark-for-precise-timing/</link>
      <pubDate>Mon, 20 Jun 2011 07:35:00 +0000</pubDate>
      
      <guid>/questions/4635/wireshark-for-precise-timing/</guid>
      <description>Wireshark for Precise Timing  0 Hi,
I was hoping someone could help me better understand Wireshark timing. I am trying to measure the latency of packets time tagged using a GPS clock. The device time tags the packet and then sends it to a destination. Using the top of the second packet, I am measuring the latency of the device (and simple network) by observing the time difference between when Wireshark reads the packet and the top of the second.</description>
    </item>
    
    <item>
      <title>Media Delivery Index</title>
      <link>/questions/4637/media-delivery-index/</link>
      <pubDate>Mon, 20 Jun 2011 08:23:00 +0000</pubDate>
      
      <guid>/questions/4637/media-delivery-index/</guid>
      <description>Media Delivery Index  0 What is a good method for looking at UDP packets (video) to find out of order packets, burst, and/or MDI? I am looking for a stream starvation source.
Thanks
videoasked 20 Jun &#39;11, 08:23
tnjpatton
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Extracting SOAP XML Payload</title>
      <link>/questions/4639/extracting-soap-xml-payload/</link>
      <pubDate>Mon, 20 Jun 2011 11:51:00 +0000</pubDate>
      
      <guid>/questions/4639/extracting-soap-xml-payload/</guid>
      <description>Extracting SOAP XML Payload  1 Using Lua and Tshark I&#39;m attempting to obtain the XML payload from SOAP messages exchanged with my web service. I went with a listener approach (see program below), but it doesn&#39;t appear to be working properly. The s_xml_cdata print statement simply prints &#34;RB14&#34;. I don&#39;t receive the full XML. Admittedly I&#39;m new to both Tshark and Lua so I may be making some rookie mistakes here.</description>
    </item>
    
    <item>
      <title>Video Resolution from P-Frames</title>
      <link>/questions/4642/video-resolution-from-p-frames/</link>
      <pubDate>Mon, 20 Jun 2011 20:52:00 +0000</pubDate>
      
      <guid>/questions/4642/video-resolution-from-p-frames/</guid>
      <description>Video Resolution from P-Frames  0 I know how to look at an H264 packet I Frame to get the Video Resolution. Does anyone know how to calculate Video Resolution from P Frames
videoresolutionasked 20 Jun &#39;11, 20:52
meggig
16●2●2●3
accept rate: 0%
I am looking for information on how to get video resolution from I-fame. If I filder with h264.slice_type == 2 which is supposed to give me all I-fames, but when decoded all i see is: F bit: No bit errors NRI: 1 Type: NAL unit -Reserved (17) H264 bitstream</description>
    </item>
    
    <item>
      <title>Download - how?</title>
      <link>/questions/4643/download-how/</link>
      <pubDate>Tue, 21 Jun 2011 02:21:00 +0000</pubDate>
      
      <guid>/questions/4643/download-how/</guid>
      <description>Download - how?  0 How do I download - your &#34;download&#34; page has no &#34;download/start/go/whatever&#34; hotspot/button/command, so I haven&#39;t been able to get Wireshark.
Cheers, Ian.
downloadasked 21 Jun &#39;11, 02:21
ianbatty
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Navigate your web browser to http://www.wireshark.org/download.htmlSelect your operating system from the list in the box with the green toolbar in the center of the pageClick on &#34;</description>
    </item>
    
    <item>
      <title>Wireshark OS X install / X11 / permissions question</title>
      <link>/questions/4646/wireshark-os-x-install-x11-permissions-question/</link>
      <pubDate>Tue, 21 Jun 2011 09:34:00 +0000</pubDate>
      
      <guid>/questions/4646/wireshark-os-x-install-x11-permissions-question/</guid>
      <description>Wireshark OS X install / X11 / permissions question  0 I&#39;m preparing WS OS X install hints for an international Cisco teachers conf next week. In the past, the WS OSX installer has had a utilities folder with a script / readme for setting up a first time install. I notice the current installer has a single file - no utilities folder. Also, in the past the readme has not been accurate, and the startup script did not work, so I&#39;ve handheld my students through first time WS installs.</description>
    </item>
    
    <item>
      <title>out-of-order packets</title>
      <link>/questions/4647/out-of-order-packets/</link>
      <pubDate>Tue, 21 Jun 2011 09:51:00 +0000</pubDate>
      
      <guid>/questions/4647/out-of-order-packets/</guid>
      <description>out-of-order packets  1 Is there a way to display the payload data from a Wireshark trace so as to re-sequence it (to get rid of out-of-order errors). We need to determine exactly what the application sees AFTER the packets associated with a given TCP stream have been put into proper sequence. We could correlate the sequence numbers manually, but were hoping for some automated way to accomplish what we need.</description>
    </item>
    
    <item>
      <title>display control characters</title>
      <link>/questions/4653/display-control-characters/</link>
      <pubDate>Tue, 21 Jun 2011 14:24:00 +0000</pubDate>
      
      <guid>/questions/4653/display-control-characters/</guid>
      <description>display control characters  0 Is there a way to display ascii control characters in the Hex or Binary view where text is displayed to the right? I am looking for symbology for things like SOH STX ETX EOT. This is useful when reading an embedded or wrapped protocol. Especially serial ascii based ones.
text ascii displayasked 21 Jun &#39;11, 14:24
wickedgeek
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Cannot interpret HTTP request for odd URI</title>
      <link>/questions/4655/cannot-interpret-http-request-for-odd-uri/</link>
      <pubDate>Tue, 21 Jun 2011 17:20:00 +0000</pubDate>
      
      <guid>/questions/4655/cannot-interpret-http-request-for-odd-uri/</guid>
      <description>Cannot interpret HTTP request for odd URI  0 1Hello, I&#39;ve captured packets of an HTTP request made from a defaced webpage that loads several objects from various sources, one of those objects is a Flash animation, I got the captured HTTP request but I&#39;m unable to load the URI or interpret it as it contains /.../ in it, this is an exapmle of the packet info:
Request Method: GET</description>
    </item>
    
    <item>
      <title>Fonts in Mac OSX impossible to read - terminal has error</title>
      <link>/questions/4658/fonts-in-mac-osx-impossible-to-read-terminal-has-error/</link>
      <pubDate>Tue, 21 Jun 2011 20:07:00 +0000</pubDate>
      
      <guid>/questions/4658/fonts-in-mac-osx-impossible-to-read-terminal-has-error/</guid>
      <description>Fonts in Mac OSX impossible to read - terminal has error  0 I am using OSX Lion, but this also occurs in Snow Leopard.
1) See attached for how the fonts display in wireshark. Changing the fonts in the preferences does nothing. 2) when running wireshark from the terminal, i get this:
[ 10:02:18 ] &amp;gt; wireshark 2011-06-21 22:02:20.176 defaults[7981:707] The domain/default pair of (kCFPreferencesAnyApplication, AppleAquaColorVariant) does not exist 2011-06-21 22:02:20.</description>
    </item>
    
    <item>
      <title>ArtRdm packet decoder expect the SC_RDM start code ($CC), which is not in the standard</title>
      <link>/questions/4662/artrdm-packet-decoder-expect-the-sc_rdm-start-code-cc-which-is-not-in-the-standard/</link>
      <pubDate>Wed, 22 Jun 2011 01:14:00 +0000</pubDate>
      
      <guid>/questions/4662/artrdm-packet-decoder-expect-the-sc_rdm-start-code-cc-which-is-not-in-the-standard/</guid>
      <description>ArtRdm packet decoder expect the SC_RDM start code ($CC), which is not in the standard  0 Hello everybody! I checked the FAQ before posting but I did not find anything about ArtRdm packets.
These packet encapsulate RDM into ArtNet. Here you can find a document about the protocol: www.artisticlicence.com/WebSiteMaster/User%20Guides/art-net.pdf
On page 30, you will see that the ArtRdm packet expect the RDM data WITHOUT start code (here erroneously referenced as &#34;</description>
    </item>
    
    <item>
      <title>windows 7 installation</title>
      <link>/questions/4663/windows-7-installation/</link>
      <pubDate>Wed, 22 Jun 2011 02:30:00 +0000</pubDate>
      
      <guid>/questions/4663/windows-7-installation/</guid>
      <description>windows 7 installation  0 Is the first time that I use Wireshark. I installed it on 32 bits windows 7 machine but I cannot capture anything.
windows capture windows7 installationasked 22 Jun &#39;11, 02:30
Szigeti Eduard
1●1●1●1
accept rate: 0%
 edited 04 Aug &#39;11, 15:24 
cmaynard ♦♦
9.4k●10●38●142
Do you mean that you see no interfaces to capture from, or that you start your capture but there are no packets?</description>
    </item>
    
    <item>
      <title>Not seeing receive packets on Macbook Pro running Windows XP</title>
      <link>/questions/4672/not-seeing-receive-packets-on-macbook-pro-running-windows-xp/</link>
      <pubDate>Wed, 22 Jun 2011 09:11:00 +0000</pubDate>
      
      <guid>/questions/4672/not-seeing-receive-packets-on-macbook-pro-running-windows-xp/</guid>
      <description>Not seeing receive packets on Macbook Pro running Windows XP  0 When attempting to do a packet capture with Wireshark running under Windows XP on my Macbook Pro, I only see packets sent from the device I am monitoring. I never see any packets sent to the device. If I use the Mac version of Wireshark I see both sent and received packets.
For instance, when using another device to PING the monitored device, I only see the ICMP replies from the monitored device.</description>
    </item>
    
    <item>
      <title>Easy way to save tcp streams?</title>
      <link>/questions/4677/easy-way-to-save-tcp-streams/</link>
      <pubDate>Wed, 22 Jun 2011 13:35:00 +0000</pubDate>
      
      <guid>/questions/4677/easy-way-to-save-tcp-streams/</guid>
      <description>Easy way to save tcp streams?  2 1If I have a trace with say 20 tcp streams, is there an easy way to save out each tcp stream to its own separate file, whether it be using tshark, editcap, gui, etc.? Or is the only way to do this to use a display filter for each stream and save as one by one?
Thanks!
saveasked 22 Jun &#39;11, 13:35</description>
    </item>
    
    <item>
      <title>Lua listener, dynamic fields</title>
      <link>/questions/4678/lua-listener-dynamic-fields/</link>
      <pubDate>Wed, 22 Jun 2011 13:53:00 +0000</pubDate>
      
      <guid>/questions/4678/lua-listener-dynamic-fields/</guid>
      <description>Lua listener, dynamic fields  0 Hello,
I have a listener that needs to get field value dynamically. Since Field_new can only be used outside of a tap I tried using all_field_infos() which does work like this: fields = { all_field_infos() }
This gives me an array of field_info objects of the upper most protocols in the tree, the problem is I can&#39;t figure out how to walk over the branches.</description>
    </item>
    
    <item>
      <title>Windows 7, 3g modem. Wireshark wont work</title>
      <link>/questions/4679/windows-7-3g-modem-wireshark-wont-work/</link>
      <pubDate>Wed, 22 Jun 2011 14:03:00 +0000</pubDate>
      
      <guid>/questions/4679/windows-7-3g-modem-wireshark-wont-work/</guid>
      <description>Windows 7, 3g modem. Wireshark wont work  0 Hi. I installed wireshark on windows 7, the latest winpcap but i cannot capture anything. I think the problem is that i cannot select the correct interface. It shows only one interface in the drop down menu and it&#39;s a wrong one. I&#39;m using a ZTE 3G modem. Any help would be appriciated. Thank you in advance.
interface zte modem 3gasked 22 Jun &#39;11, 14:03</description>
    </item>
    
    <item>
      <title>Display filter works in Wireshark but not in TShark - Special Characters Issue?</title>
      <link>/questions/4682/display-filter-works-in-wireshark-but-not-in-tshark-special-characters-issue/</link>
      <pubDate>Wed, 22 Jun 2011 15:50:00 +0000</pubDate>
      
      <guid>/questions/4682/display-filter-works-in-wireshark-but-not-in-tshark-special-characters-issue/</guid>
      <description>Display filter works in Wireshark but not in TShark - Special Characters Issue?  0 I am trying to write a tshark read filter to match a wireshark display filter that works fine. However it seems that even using quotation marks (which works in Wireshark), I get a variety of errors, based on the contents. Seems to be the same for both frame contains and tcp.data contains
-R frame contains &#34;</description>
    </item>
    
    <item>
      <title>Decrypting SSL</title>
      <link>/questions/4685/decrypting-ssl/</link>
      <pubDate>Wed, 22 Jun 2011 19:20:00 +0000</pubDate>
      
      <guid>/questions/4685/decrypting-ssl/</guid>
      <description>Decrypting SSL  0 I am using wireshark 1.6. I am trying to decrypt an SSL stream on a capture from one of our production servers. I have a capture taken from that server. I have the key extacted in pks format. I have converted it to pkcs12 and then RSA to remove the password. I also tried onverting to pcks8 but no luck. I configured my ssl preferences to &#34;</description>
    </item>
    
    <item>
      <title>Dissecting structs in messages.</title>
      <link>/questions/4687/dissecting-structs-in-messages/</link>
      <pubDate>Thu, 23 Jun 2011 00:01:00 +0000</pubDate>
      
      <guid>/questions/4687/dissecting-structs-in-messages/</guid>
      <description>Dissecting structs in messages.  0 Hi I am building a protocol that is dissecting message traffic in our system. Now it&#39;s a flat solution but as several messages shares structs here and there I try to extract these to standalone dissectors. The problem I receive is that the headers need to be intact for the array_length to work. It does not include the subpart.
This is the default header.</description>
    </item>
    
    <item>
      <title>SPDY protocol</title>
      <link>/questions/4690/spdy-protocol/</link>
      <pubDate>Thu, 23 Jun 2011 06:06:00 +0000</pubDate>
      
      <guid>/questions/4690/spdy-protocol/</guid>
      <description>SPDY protocol  0 Hi
I am interested in studying the protocol which is the SPDY.
I have already researched Google&#39;s white report and saw previous question about SPDY in this site.
I knew that Wireshark application don&#39;t support this protocol.
Do you have a plan supporting SPDY protocol?
If you have a plan, I wish to know when wireshark application supporting SPDY protocol?
spdy googleasked 23 Jun &#39;11, 06:06</description>
    </item>
    
    <item>
      <title>Using Wireshark with Snort to decrypt SSL traffic.</title>
      <link>/questions/4700/using-wireshark-with-snort-to-decrypt-ssl-traffic/</link>
      <pubDate>Thu, 23 Jun 2011 10:17:00 +0000</pubDate>
      
      <guid>/questions/4700/using-wireshark-with-snort-to-decrypt-ssl-traffic/</guid>
      <description>Using Wireshark with Snort to decrypt SSL traffic.  0 Hi,
I have Snort installed and configured on our company network and its up and running and giving the alerts fine, but its unable to detect any of the encrypted traffic (say, https). Can I use Wireshark with snort so that I can make Snort detect the https as well?
Thank You, Sreeraj.
ssl snortasked 23 Jun &#39;11, 10:17
sreewave</description>
    </item>
    
    <item>
      <title>How do I search a capture for a string?</title>
      <link>/questions/4710/how-do-i-search-a-capture-for-a-string/</link>
      <pubDate>Thu, 23 Jun 2011 14:39:00 +0000</pubDate>
      
      <guid>/questions/4710/how-do-i-search-a-capture-for-a-string/</guid>
      <description>How do I search a capture for a string?  2 2First, apologies for the newbie question, I&#39;ve purchased the excellent Wireshark Book, but need to figure this out faster than I can read through the large book.
I&#39;m trying to determine where a hostname is being incorrectly provided, on a multi-protocol network. Looking up the hostname returns an IP other than what appears this name is associated with locally. Nslookup does not have PTR (Reverse) records defined, so &#34;</description>
    </item>
    
    <item>
      <title>Traps to other destination is captured in my host NIC while running wireshark</title>
      <link>/questions/4715/traps-to-other-destination-is-captured-in-my-host-nic-while-running-wireshark/</link>
      <pubDate>Thu, 23 Jun 2011 22:19:00 +0000</pubDate>
      
      <guid>/questions/4715/traps-to-other-destination-is-captured-in-my-host-nic-while-running-wireshark/</guid>
      <description>Traps to other destination is captured in my host NIC while running wireshark  0 Hi,
I am running wireshark in my host say with IP address A.I am having another host in my LAN say with IP address B. Let say a Router R sends SNMP traps to the host B . The wireshark running in my host A,is able to capture the SNMP trap packet.How does this happens?</description>
    </item>
    
    <item>
      <title>Help with field extractor - bad argument #1 to &amp;#x27;new&amp;#x27;</title>
      <link>/questions/4718/help-with-field-extractor-bad-argument-1-to-new/</link>
      <pubDate>Fri, 24 Jun 2011 02:47:00 +0000</pubDate>
      
      <guid>/questions/4718/help-with-field-extractor-bad-argument-1-to-new/</guid>
      <description>Help with field extractor - bad argument #1 to &amp;lsquo;new&amp;rsquo;  1 Hi,
I am new to lua and trying to create a tap to extract data from my dissector and do some basic stats. However I get the following error reported when I start wireshark...
Lua: Error during loading: ...\PortableWireshark_1.4.4\App\Wireshark\foo_tap.lua:2: bad argument #1 to &amp;#39;new&amp;#39; (Field_new: a field with this name must exist)Here is my code...
&#34;init.lua&#34;
dofile(&amp;quot;foo_dissector.lua&amp;quot;) dofile(&amp;quot;foo_tap.lua&amp;quot;)&#34;foo_dissector.lua&#34;</description>
    </item>
    
    <item>
      <title>Can we Invoke wireshark through API</title>
      <link>/questions/4719/can-we-invoke-wireshark-through-api/</link>
      <pubDate>Fri, 24 Jun 2011 02:58:00 +0000</pubDate>
      
      <guid>/questions/4719/can-we-invoke-wireshark-through-api/</guid>
      <description>Can we Invoke wireshark through API  0 Hi
I have client-server application. In server, the pcap, files will be available and in client I will list all the pcap files. User can select a pcap file and open it in wireshark. Now the problem is I can send whole wireshark application to client to view the pcap.I would like to know : 1. Can wireshark be invoked on IE or Mozzila.</description>
    </item>
    
    <item>
      <title>MPLS EXP bits have been renamed &amp;quot;Traffic Class&amp;quot;</title>
      <link>/questions/4723/mpls-exp-bits-have-been-renamed-traffic-class/</link>
      <pubDate>Fri, 24 Jun 2011 04:25:00 +0000</pubDate>
      
      <guid>/questions/4723/mpls-exp-bits-have-been-renamed-traffic-class/</guid>
      <description>MPLS EXP bits have been renamed &amp;ldquo;Traffic Class&amp;rdquo;  0 Just to draw to decode developers attention, the MPLS &#34;Experimental&#34; bits have now formally been renamed since 2009 in RFC5462. This RFC formally calls these 3 bits the &#34;Traffic class&#34; bits.
renamed mpls experimental rfc5462asked 24 Jun &#39;11, 04:25
idtchris
1●1●1●1
accept rate: 0%
 edited 26 Feb &#39;12, 22:05 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:</description>
    </item>
    
    <item>
      <title>file &amp;#x27;win32.mak&amp;#x27; not found Stop.</title>
      <link>/questions/4725/file-win32mak-not-found-stop/</link>
      <pubDate>Fri, 24 Jun 2011 05:05:00 +0000</pubDate>
      
      <guid>/questions/4725/file-win32mak-not-found-stop/</guid>
      <description>file &amp;lsquo;win32.mak&amp;rsquo; not found Stop.  0 I tried to build wireshark under WinXP + MC VS 2008 by &#34;2.2. Win32: Step-by-Step Guide&#34;, but I&#39;m having trouble with nmake -f Makefile.nmake verify_tools. I got:
E:\work\wireshark\trunk-1.6&amp;gt;nmake -f Makefile.nmake all Microsoft (R) Program Maintenance Utility Version 9.00.21022.08 Copyright (C) Microsoft Corporation. All rights reserved.
Makefile.nmake(10) : fatal error U1052: file &#39;win32.mak&#39; not found Stop.I Google&amp;rsquo;d it and found this, but it didn&amp;rsquo;t help.</description>
    </item>
    
    <item>
      <title>Using a variable as a Display Filter</title>
      <link>/questions/4731/using-a-variable-as-a-display-filter/</link>
      <pubDate>Fri, 24 Jun 2011 09:18:00 +0000</pubDate>
      
      <guid>/questions/4731/using-a-variable-as-a-display-filter/</guid>
      <description>Using a variable as a Display Filter  1 I am trying pass a raw captured file through a tshark display filter to generate a newer smaller file. When I run the following script everything works fine:
tshark -R &#34;tcp.port == 80&#34; -r inputfile -w outputfile
when I run the following:
tshark -R /path/to/script/displayfilter -r inputfile -w outputfile
I get the error Read filters were specified both with &#34;-R&#34; and with additional command-line arguments</description>
    </item>
    
    <item>
      <title>Software Developer</title>
      <link>/questions/4734/software-developer/</link>
      <pubDate>Fri, 24 Jun 2011 10:20:00 +0000</pubDate>
      
      <guid>/questions/4734/software-developer/</guid>
      <description>Software Developer  0 Would using a Lua dissector distributed under a non-disclosure agreement be a violation of Wireshark Terms of use?
lua terms-of-useasked 24 Jun &#39;11, 10:20
MotoMike
1●1●1●1
accept rate: 0%
 edited 30 Jun &#39;11, 18:26 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
0That would violate GPL under which Wireshark is licensed. Lua dissectors (which use bindings to Wireshark) must be distributed under GPL.</description>
    </item>
    
    <item>
      <title>wireshark dissector timestamp feild</title>
      <link>/questions/4737/wireshark-dissector-timestamp-feild/</link>
      <pubDate>Fri, 24 Jun 2011 12:18:00 +0000</pubDate>
      
      <guid>/questions/4737/wireshark-dissector-timestamp-feild/</guid>
      <description>wireshark dissector timestamp feild  0 I&#39;m writing a wireshark dissector for a log dump. I have a 8 byte time stamp field in the PDU. Is it possible to display this time stamp value in the time column in wireshark. Also, this packet is not encapsulated by any other protocol.
Thanks in Advance!
timestamp dissectorasked 24 Jun &#39;11, 12:18
tut087
1●4●4●3
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Captur of tcp ip data via my UMTS/GPRS Modem</title>
      <link>/questions/4754/captur-of-tcp-ip-data-via-my-umtsgprs-modem/</link>
      <pubDate>Sat, 25 Jun 2011 14:43:00 +0000</pubDate>
      
      <guid>/questions/4754/captur-of-tcp-ip-data-via-my-umtsgprs-modem/</guid>
      <description>Captur of tcp ip data via my UMTS/GPRS Modem  0 Hello Experts, I use wireshark for the first time and see it as a geat powerfull tool. unfortunately i can not find any method to capeter my communication via my gprs modem. (Only the Ethernet adapters of my laptop are in the list of capter interfaces)
Is there any method to capter GPRS traffic ?
System Info: Laptop with win vista SP1, 32 bit GPRS Modem Huawei E160G via USB.</description>
    </item>
    
    <item>
      <title>TDS to clear-text</title>
      <link>/questions/4756/tds-to-clear-text/</link>
      <pubDate>Sun, 26 Jun 2011 01:48:00 +0000</pubDate>
      
      <guid>/questions/4756/tds-to-clear-text/</guid>
      <description>TDS to clear-text  0 Hi,
I want to convert a TDS stream to clear-text or similar. Does anyone have a hint how to solve this?
/Stef
tds ms-sql-s 1433 tcpasked 26 Jun &#39;11, 01:48
stefan741
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0When I view SQL data, which is transmitted via TDS, (Tabular Data Stream protocol), I am able to view the text by 1st selecting the Stream, (right click on one of the packets in the stream, then &#34;</description>
    </item>
    
    <item>
      <title>Read packet trace from file in real time as writing</title>
      <link>/questions/4759/read-packet-trace-from-file-in-real-time-as-writing/</link>
      <pubDate>Sun, 26 Jun 2011 08:30:00 +0000</pubDate>
      
      <guid>/questions/4759/read-packet-trace-from-file-in-real-time-as-writing/</guid>
      <description>Read packet trace from file in real time as writing  0 For example I write a packet trace in file with tcpdump:
tcpdump -w file.pcap
By now i need reopen whole file for every new entry. Maybe wireshark can read the file as write without reopen? Like as doing in UNIX: tail -F file.pcap
tail fileasked 26 Jun &#39;11, 08:30
zhovner
1●1●1●3
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Any one tried decrypting ssl traffic between client and Charles Proxy?</title>
      <link>/questions/4760/any-one-tried-decrypting-ssl-traffic-between-client-and-charles-proxy/</link>
      <pubDate>Sun, 26 Jun 2011 08:54:00 +0000</pubDate>
      
      <guid>/questions/4760/any-one-tried-decrypting-ssl-traffic-between-client-and-charles-proxy/</guid>
      <description>Any one tried decrypting ssl traffic between client and Charles Proxy?  0 I know that with Charles Proxy (and Fiddler) I can see the decrypted ssl traffic, but I also want to see it in Wireshark.
I&#39;m certain that I capture the traffic on the right channel (between my client and Charles Proxy), and pretty sure I got Charles Proxy&#39;s private encryption key. But, I am not able to decrypt the traffic.</description>
    </item>
    
    <item>
      <title>libgpg-error-0.dll: CantPackException: TLS callbacks are not supported	upx</title>
      <link>/questions/4763/libgpg-error-0dll-cantpackexception-tls-callbacks-are-not-supported-upx/</link>
      <pubDate>Mon, 27 Jun 2011 00:25:00 +0000</pubDate>
      
      <guid>/questions/4763/libgpg-error-0dll-cantpackexception-tls-callbacks-are-not-supported-upx/</guid>
      <description>libgpg-error-0.dll: CantPackException: TLS callbacks are not supported upx  0 when i build wireshark, i got this error
Error 1 FilesAppWiresharklibgpg-error-0.dll: CantPackException: TLS callbacks are not supported upx packaging
what is that?
libgpgasked 27 Jun &#39;11, 00:25
boomsic
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How to decrypt ssl traffic with tshark 1.6?</title>
      <link>/questions/4766/how-to-decrypt-ssl-traffic-with-tshark-16/</link>
      <pubDate>Mon, 27 Jun 2011 06:51:00 +0000</pubDate>
      
      <guid>/questions/4766/how-to-decrypt-ssl-traffic-with-tshark-16/</guid>
      <description>How to decrypt ssl traffic with tshark 1.6?  2 With previous versions (1.4.x) of tshark I&#39;ve used the ssl.key_list option, in the following way:
tshark.exe -r input.pcap -o ssl.keys_list:172.30.2.107,443,http,private.key -R &amp;quot;http.request&amp;quot; -T fields -e frame.number -e &amp;quot;tcp.stream&amp;quot;But this seems to no longer work, probably because with new versions of wireshark, ssl keys are specified in a file of their own and not under the preferences file. So how should I specify the ssl keys for tshark in 1.</description>
    </item>
    
    <item>
      <title>Setting and getting a preference of an existing protocol from Lua</title>
      <link>/questions/4770/setting-and-getting-a-preference-of-an-existing-protocol-from-lua/</link>
      <pubDate>Mon, 27 Jun 2011 10:22:00 +0000</pubDate>
      
      <guid>/questions/4770/setting-and-getting-a-preference-of-an-existing-protocol-from-lua/</guid>
      <description>Setting and getting a preference of an existing protocol from Lua  0 Hi, Would anyone know if it&#39;s possible to get or set a preference of an existing protocol from Lua ?
thanks
lua preferencesasked 27 Jun &#39;11, 10:22
izopizo
202●4●7●14
accept rate: 0%
By &#34;existing protocol&#34;, do you mean a protocol that was not registered from Lua (e.g., &#34;ip&#34;)?
(27 Jun &#39;11, 19:08) helloworldYes, For example wireshark preferences file contains following attribute ip.</description>
    </item>
    
    <item>
      <title>Filter Request or Reponse as part of TCP or UDP Flow</title>
      <link>/questions/4774/filter-request-or-reponse-as-part-of-tcp-or-udp-flow/</link>
      <pubDate>Mon, 27 Jun 2011 14:57:00 +0000</pubDate>
      
      <guid>/questions/4774/filter-request-or-reponse-as-part-of-tcp-or-udp-flow/</guid>
      <description>Filter Request or Reponse as part of TCP or UDP Flow  0 I have a large trace which only contains Radius Traffic (but could apply to any type of traffic) and
would like to do a TCP / UDP filter such as filtering out radius Traffic using the following Analysis filter:
radius.User_Name == &#34;UserID&#34;
But I would also like to get the responses I get back from the destination server.</description>
    </item>
    
    <item>
      <title>protocol LLTD</title>
      <link>/questions/4776/protocol-lltd/</link>
      <pubDate>Mon, 27 Jun 2011 16:30:00 +0000</pubDate>
      
      <guid>/questions/4776/protocol-lltd/</guid>
      <description>protocol LLTD  0 It not a question. Is request to add recognition and analyzing of protocol LLTD (Link Layer Topology Discovery).
lltdasked 27 Jun &#39;11, 16:30
Валерий Valery
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Requests like this can be files in the bug database, as an enhancement request. Please add a sample capture file, as well as a reference to the relevant protocol documentation if possible.</description>
    </item>
    
    <item>
      <title>Need help with gsm</title>
      <link>/questions/4784/need-help-with-gsm/</link>
      <pubDate>Tue, 28 Jun 2011 08:26:00 +0000</pubDate>
      
      <guid>/questions/4784/need-help-with-gsm/</guid>
      <description>Need help with gsm  0 Hello,
I&#39;m new to this software, i&#39;ve tried to connect my mobile phone to wireshark by the audio/power plug but the mobile did not appear at the interface, now i&#39;m looking for some documentation in this website i find wireshark used only for ehternet switching networks or WLAN networks?
thank you for your time
mobile gsmasked 28 Jun &#39;11, 08:26
Youssef Naki
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Accessing the column data</title>
      <link>/questions/4786/accessing-the-column-data/</link>
      <pubDate>Tue, 28 Jun 2011 09:31:00 +0000</pubDate>
      
      <guid>/questions/4786/accessing-the-column-data/</guid>
      <description>Accessing the column data  0 How do I access a column&#39;s data for a packet from my dissector code?
column dissectorasked 28 Jun &#39;11, 09:31
tut087
1●4●4●3
accept rate: 0%
 edited 30 Jun &#39;11, 18:13 
cmaynard ♦♦
9.4k●10●38●142
Well, the Protocol and Info column reflect what you&#39;ve put there, so you access them by remembering what you put there.
Many of the other columns are generated from data in the packet_info structure; what particular column or columns do you want?</description>
    </item>
    
    <item>
      <title>Dissector/dll does not work fully on machine where it was not compiled</title>
      <link>/questions/4792/dissectordll-does-not-work-fully-on-machine-where-it-was-not-compiled/</link>
      <pubDate>Tue, 28 Jun 2011 11:02:00 +0000</pubDate>
      
      <guid>/questions/4792/dissectordll-does-not-work-fully-on-machine-where-it-was-not-compiled/</guid>
      <description>Dissector/dll does not work fully on machine where it was not compiled  0 I wrote a Custom Dissector for one of the Protocols. I used Wireshark 1.5.2 Dev Version. The problem is that if I use the dll anywhere on my machine(whether dev version or installed 1.6 version) it works. But if I transfer it to some other machine and even if I run it with Wireshark 1.6 then the part related to conversations and finding the Response time does not work.</description>
    </item>
    
    <item>
      <title>dissector debugging -- how to find the exact line of a &amp;quot;malformed packet&amp;quot; exception</title>
      <link>/questions/4797/dissector-debugging-how-to-find-the-exact-line-of-a-malformed-packet-exception/</link>
      <pubDate>Tue, 28 Jun 2011 16:51:00 +0000</pubDate>
      
      <guid>/questions/4797/dissector-debugging-how-to-find-the-exact-line-of-a-malformed-packet-exception/</guid>
      <description>dissector debugging &amp;ndash; how to find the exact line of a &amp;ldquo;malformed packet&amp;rdquo; exception  0 I&#39;m developing a dissector for a custom protocol and have been getting &#34;Malformed Packet&#34; messages like the one shown below. From what I understand this is usually caused by overflowing a tvb. Is there any way to get some sort of stack trace so I can see exactly where my dissector/protocol is throwing the error?</description>
    </item>
    
    <item>
      <title>When does delayed ack start?</title>
      <link>/questions/4798/when-does-delayed-ack-start/</link>
      <pubDate>Tue, 28 Jun 2011 19:24:00 +0000</pubDate>
      
      <guid>/questions/4798/when-does-delayed-ack-start/</guid>
      <description>When does delayed ack start?  0 2I am reading Stevens, Chappell and some Microsoft articles and I am not sure if I have a clear understanding on when delayed acks start.
I think Stevens says the timer is started at basically PC boot up and when a packet arrives needing a ACK a flag is set, so this could occur any where from 200ms to 0ms. So a delayed ack packet can be seen say at 10ms.</description>
    </item>
    
    <item>
      <title>Spanning-tree-(for-bridges)_01 flooding my network</title>
      <link>/questions/4799/spanning-tree-for-bridges_01-flooding-my-network/</link>
      <pubDate>Tue, 28 Jun 2011 19:32:00 +0000</pubDate>
      
      <guid>/questions/4799/spanning-tree-for-bridges_01-flooding-my-network/</guid>
      <description>Spanning-tree-(for-bridges)_01 flooding my network  0 I am wondering what this is
31 0.088694 00:00:00_00:00:00 Spanning-tree-(for-bridges)_01 MAC CTRL 60 MAC PAUSE: pause_time: 8192 quanta
The network slows down and pings are 2ms to about 6ms if the switch (new unmanaged gigabit) is rebooted things will go back to normal for a while 4-6 hours or even several days. There is a mix of workstation nics
Thanks folks
mac-pauseasked 28 Jun &#39;11, 19:32</description>
    </item>
    
    <item>
      <title>Noticed a change in how EBCDIC information is presented from /030 to no longer do that.</title>
      <link>/questions/4808/noticed-a-change-in-how-ebcdic-information-is-presented-from-030-to-no-longer-do-that/</link>
      <pubDate>Wed, 29 Jun 2011 05:03:00 +0000</pubDate>
      
      <guid>/questions/4808/noticed-a-change-in-how-ebcdic-information-is-presented-from-030-to-no-longer-do-that/</guid>
      <description>Noticed a change in how EBCDIC information is presented from /030 to no longer do that.  0 I was using the 1.4.4 release of Wireshark and upgraded to the 1.6 release and noticed that for MQ traffic that is talking between Unix and zOS systems the characters are now hidden instead of being shown as octocl information such as (slash) 343 (slash) 342 (slash) 310 type of information.
I was able to use that for other post processing to actually see traffic interactions bewteen these systems.</description>
    </item>
    
    <item>
      <title>on Mac OSX, I can&amp;#x27;t capture packets sent over a VPN</title>
      <link>/questions/4812/on-mac-osx-i-cant-capture-packets-sent-over-a-vpn/</link>
      <pubDate>Wed, 29 Jun 2011 08:30:00 +0000</pubDate>
      
      <guid>/questions/4812/on-mac-osx-i-cant-capture-packets-sent-over-a-vpn/</guid>
      <description>on Mac OSX, I can&amp;rsquo;t capture packets sent over a VPN  1 TIA - I&#39;m trying to troubleshoot some problems I&#39;m having accessing a particular host over a VPN. I&#39;m running Mac OS/X 10.6.7, and the VPN is a Cisco IPSec VPN. I&#39;ve verified that the host is routing correctly over the VPN interface (which Mac OS/X calls &#34;utun0&#34;):
dhcp-10-0-0-1:~ joshuadavies$ route get -host host.domain.com route to: host.domain.com destination: host.</description>
    </item>
    
    <item>
      <title>Install on MacBook Pro</title>
      <link>/questions/4817/install-on-macbook-pro/</link>
      <pubDate>Wed, 29 Jun 2011 11:51:00 +0000</pubDate>
      
      <guid>/questions/4817/install-on-macbook-pro/</guid>
      <description>Install on MacBook Pro  0 I have a MacBook Pro running 10.5.8 the I am trying to install on. I have read the post for the 10.6.6 but the ChmonBPF does not exist on my machine. Can you help me.
macasked 29 Jun &#39;11, 11:51
tgwilson
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1Have you looked at this question and all the links provided?</description>
    </item>
    
    <item>
      <title>how to get wireshark to detect other wireless devices using my network</title>
      <link>/questions/4820/how-to-get-wireshark-to-detect-other-wireless-devices-using-my-network/</link>
      <pubDate>Wed, 29 Jun 2011 12:58:00 +0000</pubDate>
      
      <guid>/questions/4820/how-to-get-wireshark-to-detect-other-wireless-devices-using-my-network/</guid>
      <description>how to get wireshark to detect other wireless devices using my network  0 I have wireshark installed on my macbook pro and it is connected to the network through wifi. wireshark sees my computer but there are 4 others also connected by wifi that it does not. How do I see the other devices?
capture wifi wlan macbookasked 29 Jun &#39;11, 12:58
Greg
1●1●1●1
accept rate: 0%
 retagged 02 Jul &#39;11, 02:02</description>
    </item>
    
    <item>
      <title>Plotting RSSI value in wireshark.</title>
      <link>/questions/4821/plotting-rssi-value-in-wireshark/</link>
      <pubDate>Wed, 29 Jun 2011 13:35:00 +0000</pubDate>
      
      <guid>/questions/4821/plotting-rssi-value-in-wireshark/</guid>
      <description>Plotting RSSI value in wireshark.  0 Hi,
I would like to know if there is a way of plotting the radiotap.dbm_antsignal VALUE in the wireshark IO Graph plotter?
Am I able to plot any radiotap values at all? How would I do this?
I have searched through the wireshark mailing list (forum questions) and could not find something. Could someone recommend the simplest method of doing something like this.</description>
    </item>
    
    <item>
      <title>Determining unique MAC and IP addresses in a PCAP</title>
      <link>/questions/4827/determining-unique-mac-and-ip-addresses-in-a-pcap/</link>
      <pubDate>Wed, 29 Jun 2011 17:12:00 +0000</pubDate>
      
      <guid>/questions/4827/determining-unique-mac-and-ip-addresses-in-a-pcap/</guid>
      <description>Determining unique MAC and IP addresses in a PCAP  0 Using tshark or Wireshark, is there a filter for unique MAC address, IP addresses? I would like to list all of the unique address in a PCAP. Or will this require some scripting to grep the output of tshark/tcpdump and then sort based on uniq output.
Thanks
wireshark mac-address tsharkasked 29 Jun &#39;11, 17:12
Pyxis
6●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>[closed] The NPF driver isn&amp;#x27;t running</title>
      <link>/questions/4843/the-npf-driver-isnt-running/</link>
      <pubDate>Thu, 30 Jun 2011 01:49:00 +0000</pubDate>
      
      <guid>/questions/4843/the-npf-driver-isnt-running/</guid>
      <description>[closed] The NPF driver isn&amp;rsquo;t running  1 1Hello, installed wireshark 1.6.0 with wincap 4.1.2 on windows server 2008 R2. When starting wireshark I get the error &#34;The NPF driver isn&#39;t running&#34;. Logged on as local administrator did not help. Running &#34;SC QC NPF&#34; in command prompt gave me &#34;[SC] OpenService FAILED 1060: The specified service does not exist as an installed service.&#34; Checked in Device Manager and the &#34;NetGroup Packet Filter Driver&#34;</description>
    </item>
    
    <item>
      <title>Wireshark crashes when left open for over 5 minutes on windows 7 64bit</title>
      <link>/questions/4847/wireshark-crashes-when-left-open-for-over-5-minutes-on-windows-7-64bit/</link>
      <pubDate>Thu, 30 Jun 2011 08:17:00 +0000</pubDate>
      
      <guid>/questions/4847/wireshark-crashes-when-left-open-for-over-5-minutes-on-windows-7-64bit/</guid>
      <description>Wireshark crashes when left open for over 5 minutes on windows 7 64bit  0 Wireshark crashes after it&#39;s been capturing for approximately 5 or more minutes. I am running the latest version of it on windows 7 64bit ultimate. Does anyone have any ideas on what I could change to stop this? I have an issue on my network that occurs randomly so I need wireshark to run a lot longer than 5 minutes.</description>
    </item>
    
    <item>
      <title>Wireless toolbar is not active</title>
      <link>/questions/4881/wireless-toolbar-is-not-active/</link>
      <pubDate>Fri, 01 Jul 2011 06:06:00 +0000</pubDate>
      
      <guid>/questions/4881/wireless-toolbar-is-not-active/</guid>
      <description>Wireless toolbar is not active  0 We are facing the following problems :
1.Wireless Toolbar is not active.
2.WLAN traffic statistics are not being updated.
Do we need to buy some extra software to get these things working?
wireless toolbarasked 01 Jul &#39;11, 06:06
repaka avinash
1●1●1●2
accept rate: 0%
  
One Answer:
  
1What OS are you running on? If it&#39;s Windows, then you would likely need to purchase an AirPcap adapter from Riverbed.</description>
    </item>
    
    <item>
      <title>5 second delay in transmitting..</title>
      <link>/questions/4883/5-second-delay-in-transmitting/</link>
      <pubDate>Fri, 01 Jul 2011 07:45:00 +0000</pubDate>
      
      <guid>/questions/4883/5-second-delay-in-transmitting/</guid>
      <description>5 second delay in transmitting..  0 Hi
We have been troubleshooting download speed issues for a client of ours. they are using Windows Server 2003 (with Window scaling &amp;amp; Selective ACK turned on). &amp;amp; the client is either Windows XP or Windows 7.
We have been carrying out tests by running a test script that downloads a file from one of our Web Servers multiple times &amp;amp; we note the time taken to download the file each time.</description>
    </item>
    
    <item>
      <title>Compare functionality in Wireshark</title>
      <link>/questions/4884/compare-functionality-in-wireshark/</link>
      <pubDate>Fri, 01 Jul 2011 08:46:00 +0000</pubDate>
      
      <guid>/questions/4884/compare-functionality-in-wireshark/</guid>
      <description>Compare functionality in Wireshark  0 Hi
I am attempting to use the Wireshark compare function to compare captures taken on client &amp;amp; server. I could do with come clarification on a few things please:
Is it advisable for the 2 computers to have their times synchronised prior to taking the 2 captures, or does this make no difference?
In the result dialog box, can you explain what the following mean:</description>
    </item>
    
    <item>
      <title>Get frame data and packet info from frame number?</title>
      <link>/questions/4891/get-frame-data-and-packet-info-from-frame-number/</link>
      <pubDate>Sat, 02 Jul 2011 01:10:00 +0000</pubDate>
      
      <guid>/questions/4891/get-frame-data-and-packet-info-from-frame-number/</guid>
      <description>Get frame data and packet info from frame number?  1 If I have the number of a frame, is it possible to then look up the actual frame/packet?
I&#39;m trying to make some enhancements to io_stat.c, and I&#39;d like to show some information about the packet inside the graph window itself, when clicked on. The only context I have in that situation is the frame number.
development frameasked 02 Jul &#39;11, 01:10</description>
    </item>
    
    <item>
      <title>Use for anti-network-flooding</title>
      <link>/questions/4896/use-for-anti-network-flooding/</link>
      <pubDate>Sun, 03 Jul 2011 16:42:00 +0000</pubDate>
      
      <guid>/questions/4896/use-for-anti-network-flooding/</guid>
      <description>Use for anti-network-flooding  0 So, I have it downloaded and all, my friend told me to get it to prevent people from flooding my network and host booting my internet offline. But I can not figure out how to do it, and or set it up to do that. Could someone help me out? I&#39;m confused.
ip-flooding anti-hostbooting helpasked 03 Jul &#39;11, 16:42
numbers aT
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Does Wireshark have Chattiness and/or Round Trip Counter?</title>
      <link>/questions/4899/does-wireshark-have-chattiness-andor-round-trip-counter/</link>
      <pubDate>Mon, 04 Jul 2011 07:30:00 +0000</pubDate>
      
      <guid>/questions/4899/does-wireshark-have-chattiness-andor-round-trip-counter/</guid>
      <description>Does Wireshark have Chattiness and/or Round Trip Counter?  0 Hi. In diagnosing application performance problems, I am very often faced with transactions that are slow because they are &#34;chatty&#34; - that is, requiring a large number of round trips to complete the transaction. (Of course, the impact of the chattiness is also dependent on the end-to-end latency between the endpoints.)
In the past, I have used another diagnostic tool - Opnet.</description>
    </item>
    
    <item>
      <title>HTTP response time filter</title>
      <link>/questions/4900/http-response-time-filter/</link>
      <pubDate>Mon, 04 Jul 2011 15:21:00 +0000</pubDate>
      
      <guid>/questions/4900/http-response-time-filter/</guid>
      <description>HTTP response time filter  0 Let&#39;s say I have a capture from a typical web server. The capture contains a lot of HTTP requests and responses. Is it possible to create a filter to display only HTTP traffic with a response time higher than X seconds? By &#34;response time&#34; I mean the amount of time from the client completes the HTTP request to the server starts (or possibly finishes) serving the HTTP response.</description>
    </item>
    
    <item>
      <title>pdcp capture in lte</title>
      <link>/questions/4901/pdcp-capture-in-lte/</link>
      <pubDate>Mon, 04 Jul 2011 22:33:00 +0000</pubDate>
      
      <guid>/questions/4901/pdcp-capture-in-lte/</guid>
      <description>pdcp capture in lte  0 Hi guys, I&#39;m new to wireshark, I&#39;m working in the area of LTE. I want to capture the pdcp lte frames. How can i do that in wireshark ?? when i enter pdcp-lte in the filter option i&#39;m no getting anything, as i&#39;m connected to LAN or WLAN. so how can i capture ??? is there any repository where sample capture of pdcp frames are available ?</description>
    </item>
    
    <item>
      <title>SIP tracing for connected Gigaset unit.</title>
      <link>/questions/4902/sip-tracing-for-connected-gigaset-unit/</link>
      <pubDate>Tue, 05 Jul 2011 02:51:00 +0000</pubDate>
      
      <guid>/questions/4902/sip-tracing-for-connected-gigaset-unit/</guid>
      <description>SIP tracing for connected Gigaset unit.  0 Siemens support have asked me to do a Wireshark trace of SIP traffic to/from a Gigaset unit connected to my Thompson Router. I have a windows PC also connected to the same router but, as all the SIP UDP traffic is routed to the GIGASET box, I cannot see how to set up the wireshark trace they are asking for (the PC running Wireshark will, I imagine, not see any of the traffic).</description>
    </item>
    
    <item>
      <title>Using wireshark to detect facebook login and chat?</title>
      <link>/questions/4903/using-wireshark-to-detect-facebook-login-and-chat/</link>
      <pubDate>Tue, 05 Jul 2011 04:01:00 +0000</pubDate>
      
      <guid>/questions/4903/using-wireshark-to-detect-facebook-login-and-chat/</guid>
      <description>Using wireshark to detect facebook login and chat?  1 1Hi there. Im having a bit of difficulty trying to decipher all the packet info on my machine and was looking for a way to detect the information easier.
Im looking to detect a facebook successful login via wireshark as well as detecting if a user uses the chat feature. But i have no idea what all these packets are that are showing up.</description>
    </item>
    
    <item>
      <title>CCX sniffing</title>
      <link>/questions/4905/ccx-sniffing/</link>
      <pubDate>Tue, 05 Jul 2011 07:10:00 +0000</pubDate>
      
      <guid>/questions/4905/ccx-sniffing/</guid>
      <description>CCX sniffing  0 Does the AirPcap and wireshark sniff CCX? or do you need the upgraded AirPcap NX?
ccxasked 05 Jul &#39;11, 07:10
aplatek
31●2●3●4
accept rate: 0%
  
One Answer:
  
0I presume CCX are Cisco Compatible eXtensions rather than, say, the Chicago Climate eXchange or this little economy car.
It sounds as if, at the network protocol layer, CCX is just some additional protocols and additions to existing Wi-Fi protocols, so any device capable of receiving arbitrary 802.</description>
    </item>
    
    <item>
      <title>Wireshark Failed to Open Airpcap adapter</title>
      <link>/questions/4907/wireshark-failed-to-open-airpcap-adapter/</link>
      <pubDate>Tue, 05 Jul 2011 07:39:00 +0000</pubDate>
      
      <guid>/questions/4907/wireshark-failed-to-open-airpcap-adapter/</guid>
      <description>Wireshark Failed to Open Airpcap adapter  0 Dell laptop running Windows 7 64-bit. Airpcap 4.1.1 Wireshark 1.6.0
When I launch Wireshark with the Airpcap Classic plugged in. I get a Wireshark dialog box that says &#34;Failed to open Airpcap adapters!&#34;.
Airpcap Control Panel is able to communicate with the Airpcap classic and blink the LED.
Craig
airpcapasked 05 Jul &#39;11, 07:39
craigmellor
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Run a C DLL from LUA in Wireshark</title>
      <link>/questions/4909/run-a-c-dll-from-lua-in-wireshark/</link>
      <pubDate>Tue, 05 Jul 2011 09:58:00 +0000</pubDate>
      
      <guid>/questions/4909/run-a-c-dll-from-lua-in-wireshark/</guid>
      <description>Run a C DLL from LUA in Wireshark  0 I was wondering if it would be possible to run a C dll from LUA in wireshark. Let me explain.
I already have the code in C that can take a string of the data that comes over the network and returns a string in XML.
I would like to write a LUA script that takes that XML string returned by the C DLL and translate it directly to the tree structure in Wireshark.</description>
    </item>
    
    <item>
      <title>Slow throughput on Windows 2003 Server</title>
      <link>/questions/4911/slow-throughput-on-windows-2003-server/</link>
      <pubDate>Tue, 05 Jul 2011 12:58:00 +0000</pubDate>
      
      <guid>/questions/4911/slow-throughput-on-windows-2003-server/</guid>
      <description>Slow throughput on Windows 2003 Server  0 First, I am completely ignorant of all things wireshark, so please forgive me.
I have a windows 2003 that is slow when transferring files. I tested out another windows 2003 server that doesn&#39;t exhibit the same issue. Here is one difference I found in wirehsark that may be the cause, but I really have no idea if it is or how to fix.</description>
    </item>
    
    <item>
      <title>Unable to build wireshark from the source on windows XP</title>
      <link>/questions/4912/unable-to-build-wireshark-from-the-source-on-windows-xp/</link>
      <pubDate>Tue, 05 Jul 2011 13:12:00 +0000</pubDate>
      
      <guid>/questions/4912/unable-to-build-wireshark-from-the-source-on-windows-xp/</guid>
      <description>Unable to build wireshark from the source on windows XP  2 Hi,
I have successfully compiled wireshark source code on ubunut but while trying to compile wireshark source code on windows XP I am getting stuck with few errors: It would be nice if anyone can let me know where I am going wrong.
nmake -f Makefile.nmake verify_tools output is same as the one given in win32 installation guide. nmake -f Makefile.</description>
    </item>
    
    <item>
      <title>UDP to RTP</title>
      <link>/questions/4916/udp-to-rtp/</link>
      <pubDate>Tue, 05 Jul 2011 15:42:00 +0000</pubDate>
      
      <guid>/questions/4916/udp-to-rtp/</guid>
      <description>UDP to RTP  1 Is decoding UDP to RTP and seeing packet loss valid? My source protocol is all UDP and the only packet loss seen is when you convert to RTP and analyze the RTP Streams. Since UDP has no sequencing i&#39;m curious if it&#39;s even valid to convert it and see out of sequence packets with packet loss.
thanks,
Justin Oney
loss udp rtp packetasked 05 Jul &#39;11, 15:42</description>
    </item>
    
    <item>
      <title>List of color names in Wireshark</title>
      <link>/questions/4917/list-of-color-names-in-wireshark/</link>
      <pubDate>Tue, 05 Jul 2011 16:09:00 +0000</pubDate>
      
      <guid>/questions/4917/list-of-color-names-in-wireshark/</guid>
      <description>List of color names in Wireshark  0 1The Wireshark coloring rule dialogs show hexadecimal values for the background and foreground colors, for example, #FF0000 for red. At one of Laura Chappell&#39;s Sharkfest presentations, she showed that when creating or editing coloring rules, you can enter a color name and Wireshark will translate the name to the appropriate hexadecimal value. This is exceptionally convenient, but the supported names don&#39;t seem to be consistent.</description>
    </item>
    
    <item>
      <title>Need identify top/most network users or traffic source or IP-How to configure</title>
      <link>/questions/4923/need-identify-topmost-network-users-or-traffic-source-or-ip-how-to-configure/</link>
      <pubDate>Wed, 06 Jul 2011 02:44:00 +0000</pubDate>
      
      <guid>/questions/4923/need-identify-topmost-network-users-or-traffic-source-or-ip-how-to-configure/</guid>
      <description>Need identify top/most network users or traffic source or IP-How to configure  0 I need to know how to capture highest network traffic originator or source on my network i have configured wire shark to monitor all my Internet traffic from that need to know who’s the Top internet users (IP) or highest internet access most visited sites can it possible from wire shark how can I configure that in this and i need this fro ongoing traffic or like filter</description>
    </item>
    
    <item>
      <title>ACS and tacacs&#43;</title>
      <link>/questions/4925/acs-and-tacacs/</link>
      <pubDate>Wed, 06 Jul 2011 05:35:00 +0000</pubDate>
      
      <guid>/questions/4925/acs-and-tacacs/</guid>
      <description>ACS and tacacs+  0 Hi I am trying to decode a tacacs+ session between cisco routers and cisco acs. in regular (telnet )configuration everything works. when i try to decode session comes from a router that using PPP &#34;aaa authentication ppp default group tacacs+&#34; the wireshark see the packets as malformed packet. Does anybody know how to solve this ?
ciscoasked 06 Jul &#39;11, 05:35
yarivco
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How do I capture only VOIP packets, is there a filter option?</title>
      <link>/questions/4929/how-do-i-capture-only-voip-packets-is-there-a-filter-option/</link>
      <pubDate>Wed, 06 Jul 2011 09:36:00 +0000</pubDate>
      
      <guid>/questions/4929/how-do-i-capture-only-voip-packets-is-there-a-filter-option/</guid>
      <description>How do I capture only VOIP packets, is there a filter option?  0 I have magicjack set up on this machine and would like to capture VOIP packets, but usually I can only capture all packets and it captures a lot of other useless stuff like internet downloads and web pages and that sort of thing (this computer is used for web surfing as well as VOIP, its not a dedicated machine) I have some problems with the quality and want to analyze calls.</description>
    </item>
    
    <item>
      <title>Wireless Problems need Help by failure search</title>
      <link>/questions/4930/wireless-problems-need-help-by-failure-search/</link>
      <pubDate>Wed, 06 Jul 2011 10:59:00 +0000</pubDate>
      
      <guid>/questions/4930/wireless-problems-need-help-by-failure-search/</guid>
      <description>Wireless Problems need Help by failure search  0 Hello i need you help by wireless problem. The problem is that i didnt can connect to the wlan router. But i dindt now why. WPA Password is correct and other PC can connect without any trouble. The PC with the Problems is a Windows XP Maschine with service Pack 3. The Wlan Card is a Realtek RTL8185 54 M Wirless Lan with new drivers.</description>
    </item>
    
    <item>
      <title>Not honoring own MSS?</title>
      <link>/questions/4932/not-honoring-own-mss/</link>
      <pubDate>Wed, 06 Jul 2011 14:15:00 +0000</pubDate>
      
      <guid>/questions/4932/not-honoring-own-mss/</guid>
      <description>Not honoring own MSS?  0 During the initial TCP handshake, the server specifies a MSS of 1460, and the client specifies a MSS of 1200. However, the server sends segments with lengths of 32786, 15444, 13068, 5940 and 2376.
Is this normal? Why the server would behave this way?
handshake mss tcpasked 06 Jul &#39;11, 14:15
jamesm113
1●1●1●1
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Why does my PC ping my router?</title>
      <link>/questions/4934/why-does-my-pc-ping-my-router/</link>
      <pubDate>Wed, 06 Jul 2011 16:09:00 +0000</pubDate>
      
      <guid>/questions/4934/why-does-my-pc-ping-my-router/</guid>
      <description>Why does my PC ping my router?  0 I noticed that my PC sometimes pings my wireless router and my router sends back its echo reply. does anyone know why it would randomly do this?
pingasked 06 Jul &#39;11, 16:09
greenbear
1●1●1●1
accept rate: 0%
  
One Answer:
  
1The OS running on your PC might be testing your network connectivity by checking whether the router is up.</description>
    </item>
    
    <item>
      <title>Wireshark keeps crashing while doing RTP stream analysis</title>
      <link>/questions/4944/wireshark-keeps-crashing-while-doing-rtp-stream-analysis/</link>
      <pubDate>Thu, 07 Jul 2011 11:58:00 +0000</pubDate>
      
      <guid>/questions/4944/wireshark-keeps-crashing-while-doing-rtp-stream-analysis/</guid>
      <description>Wireshark keeps crashing while doing RTP stream analysis  0 I am running Wireshark in Windows 7, running it under Windows XP sp3 Compatability mode and I am able to decode UDP to RTP, but when I try to do a stream analysis under Telephony/RTP it get half way through the process and the crashes. Do you have any insite to this issue?
windows7 crash rtp analysisasked 07 Jul &#39;11, 11:58</description>
    </item>
    
    <item>
      <title>How to capture network message</title>
      <link>/questions/4946/how-to-capture-network-message/</link>
      <pubDate>Thu, 07 Jul 2011 13:47:00 +0000</pubDate>
      
      <guid>/questions/4946/how-to-capture-network-message/</guid>
      <description>How to capture network message  0 Hello,
I have some digital signage software that can send out a network message (0x02PON0x03) to switch on a TV. I want to be able to control the display without the signage software.
I have tried using netcat to no avail. Is there a method I can use wireshark to monitor and analyze the message sent form the signage software so I can duplicate it?</description>
    </item>
    
    <item>
      <title>Can Wireshark import a PDML file?</title>
      <link>/questions/4952/can-wireshark-import-a-pdml-file/</link>
      <pubDate>Fri, 08 Jul 2011 07:11:00 +0000</pubDate>
      
      <guid>/questions/4952/can-wireshark-import-a-pdml-file/</guid>
      <description>Can Wireshark import a PDML file?  0 I want to alter the xml/pdml file, and then reloaded it in wireshark and resave it as a pcap file. Is this at all possible?
importasked 08 Jul &#39;11, 07:11
ROCKSTARARTIST
1●1●1●1
accept rate: 0%
  
One Answer:
  
2I don&#39;t think it is possible with the Wireshark tools, but I might be mistaken.
But if you&#39;re trying to alter an xml/pdml file just to modify a pcap trace that you already have I would recommend avoiding the export to text and reimporting it - instead, I&#39;d go for tools that can modify pcaps directly.</description>
    </item>
    
    <item>
      <title>wireshark unable to decode sua/gsm_map traffic</title>
      <link>/questions/4953/wireshark-unable-to-decode-suagsm_map-traffic/</link>
      <pubDate>Fri, 08 Jul 2011 07:28:00 +0000</pubDate>
      
      <guid>/questions/4953/wireshark-unable-to-decode-suagsm_map-traffic/</guid>
      <description>wireshark unable to decode sua/gsm_map traffic  0 Hi,
I am using wire shark version 1.6 and i am sending SUA traffic. It decodes up to SCCP layer and unable to decode tcap/map layer(it is displaying as raw data). Please see the below output
Stream Control Transmission Protocol, Src Port: 14002 (14002), Dst Port: sua (14001) Source port: 14002 Destination port: 14001 Verification tag: 0x000048c4 Checksum: 0x2a1e43db (not verified) DATA chunk(unordered, complete segment, TSN: 341282439, SID: 11, SSN: 0, PPID: 4, payload length: 196 bytes) Chunk type: DATA (0) 0.</description>
    </item>
    
    <item>
      <title>Duplicate ACKs and ACK storms</title>
      <link>/questions/4958/duplicate-acks-and-ack-storms/</link>
      <pubDate>Fri, 08 Jul 2011 09:28:00 +0000</pubDate>
      
      <guid>/questions/4958/duplicate-acks-and-ack-storms/</guid>
      <description>Duplicate ACKs and ACK storms  0 2We are having a strange issue with one of our clients. We have an SSL app that accepts an XML post, processes data and sends the response back to the client. We recently moved data centers and now are having an intermittent issue with one customer (our largest of course!). While most of the transactions complete in less than 6 seconds, a small percentage is taking 20 seconds.</description>
    </item>
    
    <item>
      <title>Deciphering Ethernet II Src information</title>
      <link>/questions/4959/deciphering-ethernet-ii-src-information/</link>
      <pubDate>Fri, 08 Jul 2011 09:49:00 +0000</pubDate>
      
      <guid>/questions/4959/deciphering-ethernet-ii-src-information/</guid>
      <description>Deciphering Ethernet II Src information  0 I&#39;m trying to track down network traffic coming from my Exchange server that is going to an external IP address that is in China according to Network Solutions.
My firewall logs show TCP traffic on various uncommon ports being sent from the Exchange server to several IP addresses in China. They are being sent out on TCP ports such as 5296, 31671, etc. Because of the way I&#39;ve configured my firewall, the packets are being dropped, so they aren&#39;t getting sent out, but I&#39;d like to track down what it is on the server that is sending them.</description>
    </item>
    
    <item>
      <title>Detect missing SYN ACK or missing HTTP response</title>
      <link>/questions/4962/detect-missing-syn-ack-or-missing-http-response/</link>
      <pubDate>Fri, 08 Jul 2011 11:27:00 +0000</pubDate>
      
      <guid>/questions/4962/detect-missing-syn-ack-or-missing-http-response/</guid>
      <description>Detect missing SYN ACK or missing HTTP response  0 Hi,
I&#39;m basically trying to detect &#34;incomplete&#34; TCP or HTTP communication in a capture file.
Is it possible to display only TCP streams that consist of a SYN without a corresponding SYN ACK? Or streams with no FINs? Or to display HTTP requests that do not receive an HTTP response?
Thanks :)
http tcpasked 08 Jul &#39;11, 11:27
aatoga
1●2●2●3</description>
    </item>
    
    <item>
      <title>Wireshark relocation error : symbol g_int64_equal in solaris 10</title>
      <link>/questions/4975/wireshark-relocation-error-symbol-g_int64_equal-in-solaris-10/</link>
      <pubDate>Mon, 11 Jul 2011 01:03:00 +0000</pubDate>
      
      <guid>/questions/4975/wireshark-relocation-error-symbol-g_int64_equal-in-solaris-10/</guid>
      <description>Wireshark relocation error : symbol g_int64_equal in solaris 10  0 Hi, I have installed wireshark for Solaris 10 and it dependency packages. Got all the packages from sunfreeware.com
But I am not able to run the application. It is throwing below error. could any one help us to resolve this issue
./wiresharkld.so.1: wireshark: fatal: relocation error: file /usr/local/lib/libwireshark.so.1: symbol g_int64_equal: referenced symbol not found Killed
ldd wireshark libwiretap.so.1 =&amp;gt; /usr/local/lib/libwiretap.</description>
    </item>
    
    <item>
      <title>wireshark dissector on linux</title>
      <link>/questions/4976/wireshark-dissector-on-linux/</link>
      <pubDate>Mon, 11 Jul 2011 02:39:00 +0000</pubDate>
      
      <guid>/questions/4976/wireshark-dissector-on-linux/</guid>
      <description>wireshark dissector on linux  0 how to compile the wireshark dissector on linux???? what is the detailed procedure ?
linuxasked 11 Jul &#39;11, 02:39
sagu072
35●23●24●28
accept rate: 0%
  
One Answer:
  
1You better start digging into the Wireshark Developers Guide to see what to do, based on your Linux distribution.
answered 11 Jul &#39;11, 05:04
Jaap ♦
11.7k●16●101
accept rate: 14%
     </description>
    </item>
    
    <item>
      <title>Can wireshark sniff a certain port/can wireshark apply filters like WPE pro?</title>
      <link>/questions/4983/can-wireshark-sniff-a-certain-portcan-wireshark-apply-filters-like-wpe-pro/</link>
      <pubDate>Mon, 11 Jul 2011 09:11:00 +0000</pubDate>
      
      <guid>/questions/4983/can-wireshark-sniff-a-certain-portcan-wireshark-apply-filters-like-wpe-pro/</guid>
      <description>Can wireshark sniff a certain port/can wireshark apply filters like WPE pro?  0 Im wanting to edit sent packets so say if the default is &#34;11 22 33 44 55 66&#34; i want it to send &#34;11 22 33 33 55 66&#34;. Can this be done in wireshark? Also i cant attach anything to the actual process but i know the port it connects through so can i sniff just that port?</description>
    </item>
    
    <item>
      <title>Bad links on support site</title>
      <link>/questions/4984/bad-links-on-support-site/</link>
      <pubDate>Mon, 11 Jul 2011 10:40:00 +0000</pubDate>
      
      <guid>/questions/4984/bad-links-on-support-site/</guid>
      <description>Bad links on support site  0 When accessing http://www.wireshark.org/security/wnpa-sec-2011-09.html the two links -- http://www.wireshark.org/security/wnpa-sec-2011-10.html and http://www.wireshark.org/security/wnpa-sec-2011-11.html -- both appear to be dead. They take you to the kitten on the server screen.
wpna-sec linksasked 11 Jul &#39;11, 10:40
lchladek
1●1●1●1
accept rate: 0%
 edited 11 Jul &#39;11, 12:31 
Guy Harris ♦♦
17.4k●3●35●196
The best place to report Wireshark bugs, and problems with the Wireshark Web sites, is the Wireshark Bugzilla.</description>
    </item>
    
    <item>
      <title>slow website only with one ISP</title>
      <link>/questions/4987/slow-website-only-with-one-isp/</link>
      <pubDate>Mon, 11 Jul 2011 18:17:00 +0000</pubDate>
      
      <guid>/questions/4987/slow-website-only-with-one-isp/</guid>
      <description>slow website only with one ISP  1 I have been plagued the last few days with terrible performance with one encrypted website that is critical for my business. I have spoken to the website engineers and they see no problems and blame the ISP. The ISP sees no problems and blames the website provider.
What I have found is when using a different ISP I see no problems with performance.</description>
    </item>
    
    <item>
      <title>Remote packet capture through a firewall</title>
      <link>/questions/4997/remote-packet-capture-through-a-firewall/</link>
      <pubDate>Tue, 12 Jul 2011 13:20:00 +0000</pubDate>
      
      <guid>/questions/4997/remote-packet-capture-through-a-firewall/</guid>
      <description>Remote packet capture through a firewall  0 I am trying to set up a remote packet capture on a device that is natted behind a firewall. I have forwarded port 2002 to the device. I get a list of interfaces but when I start the capture i get no data. It says that there is an active capture running but no packets captured. then It errors out with the following message:</description>
    </item>
    
    <item>
      <title>How to capture the average mbps and peak bandwidth?</title>
      <link>/questions/4998/how-to-capture-the-average-mbps-and-peak-bandwidth/</link>
      <pubDate>Tue, 12 Jul 2011 13:36:00 +0000</pubDate>
      
      <guid>/questions/4998/how-to-capture-the-average-mbps-and-peak-bandwidth/</guid>
      <description>How to capture the average mbps and peak bandwidth?  0 How can you find the average mbps and peak bandwidth while capturing video?
average bandwidth mbpsasked 12 Jul &#39;11, 13:36
geegee
1●1●1●1
accept rate: 0%
  
One Answer:
  
0You can use some of the statistics menu options for that, for example if you filter out your video stream you can then select the summary statistics to see the average mbps for that stream.</description>
    </item>
    
    <item>
      <title>Ubuntu Linux: How to start Wireshark</title>
      <link>/questions/5004/ubuntu-linux-how-to-start-wireshark/</link>
      <pubDate>Tue, 12 Jul 2011 19:00:00 +0000</pubDate>
      
      <guid>/questions/5004/ubuntu-linux-how-to-start-wireshark/</guid>
      <description>Ubuntu Linux: How to start Wireshark  1 1I am newable in both linux and wireshark. In the start page of wireshark, I can&#39;t see any interface can be found. However, I try to add a new interface, but the error command &#34;The capture session could not be initiated (You don&#39;t have permission to capture on that device).
Please check to make sure you have sufficient permissions, and that you have the proper interface or pipe specified.</description>
    </item>
    
    <item>
      <title>Compression over SSL</title>
      <link>/questions/5008/compression-over-ssl/</link>
      <pubDate>Wed, 13 Jul 2011 00:22:00 +0000</pubDate>
      
      <guid>/questions/5008/compression-over-ssl/</guid>
      <description>Compression over SSL  0 Hi everyone.
I would like to analyze application-data compressed over SSL. SSL is using &#34;compression method: DEFLATE(1)&#34;. I can decrypt SSL-data since I have private-key. But I can&#39;t see application-data because of that data is compressed.
I have a question. Can I de-compress data over SSL using wireshark?
Many thanks.
sslasked 13 Jul &#39;11, 00:22
four_books
1●1●1●1
accept rate: 0%
Additonally, I am working as Network Engineer.</description>
    </item>
    
    <item>
      <title>windows 7 corrupt gui?</title>
      <link>/questions/5010/windows-7-corrupt-gui/</link>
      <pubDate>Wed, 13 Jul 2011 02:13:00 +0000</pubDate>
      
      <guid>/questions/5010/windows-7-corrupt-gui/</guid>
      <description>windows 7 corrupt gui?  0 Why do all versions of Wireshark give a corrupted display on my Windows 7 ultimate 64bit system? screenshots here.
corrupt windows7 gui 64-bitasked 13 Jul &#39;11, 02:13
xbipin
1●1●1●2
accept rate: 0%
 edited 28 Feb &#39;12, 20:33 
cmaynard ♦♦
9.4k●10●38●142
Which theme are you running? Does the corruption occur with the default theme?
(13 Jul &#39;11, 05:18) cmaynard ♦♦its the default windows 7 aero theme but with changed colours etc only and DPI set to 120% instead of the standard 100%, rest all my applications work fine except this and this is the first time i have ever seen this, seems like wireshark wasnt able to get screen resolution or something like that and expanded everything</description>
    </item>
    
    <item>
      <title>Unable to display IP addresses correctly..!!</title>
      <link>/questions/5013/unable-to-display-ip-addresses-correctly/</link>
      <pubDate>Wed, 13 Jul 2011 04:53:00 +0000</pubDate>
      
      <guid>/questions/5013/unable-to-display-ip-addresses-correctly/</guid>
      <description>Unable to display IP addresses correctly..!!  0 I have created a dissector for cluster heartbeat messages. Everything works okay except the IP addresses. An IP of 10.102.1.71 is displayed by the dissector as 71.1.102.10.
How correct this? Do i need to apply host to network transformation or the other way around??
And most importantly, how to apply that transformation??
Regards, Sidharth
wiresharkasked 13 Jul &#39;11, 04:53
sid
45●19●20●21
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to use array fields in a dissector???</title>
      <link>/questions/5020/how-to-use-array-fields-in-a-dissector/</link>
      <pubDate>Wed, 13 Jul 2011 07:02:00 +0000</pubDate>
      
      <guid>/questions/5020/how-to-use-array-fields-in-a-dissector/</guid>
      <description>How to use array fields in a dissector???  0 I am writing a dissector for cluster heartbeat packets for NetScaler. I am facing an issue with a field named LVS. Actually it is a 4 byte integer. But it refers to a set of nodes in the view set. The set can be as big as 32.
So I have used the following code to show all the nodes in the LVS (from the trace)</description>
    </item>
    
    <item>
      <title>Application performance expert</title>
      <link>/questions/5027/application-performance-expert/</link>
      <pubDate>Wed, 13 Jul 2011 08:46:00 +0000</pubDate>
      
      <guid>/questions/5027/application-performance-expert/</guid>
      <description>Application performance expert  0 Whare can I find Application performance experts? Our company needs experts that can help us identify application performance issues and guide us with the creation of new applications that will scale over a large WAN infrastructure. I know Shaunra offers such services... any other good references ?
application expert performanceasked 13 Jul &#39;11, 08:46
setamp
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Runtime Error!   The Application has requested that the Runtime to Terminate....</title>
      <link>/questions/5029/runtime-error-the-application-has-requested-that-the-runtime-to-terminate/</link>
      <pubDate>Wed, 13 Jul 2011 12:05:00 +0000</pubDate>
      
      <guid>/questions/5029/runtime-error-the-application-has-requested-that-the-runtime-to-terminate/</guid>
      <description>Runtime Error! The Application has requested that the Runtime to Terminate&amp;hellip;.  0 Runtime Error! The Application has requested that the Runtime to Terminate it in an unusual way. please contact support....
Hello,
I am receiving the above issued runtime error. Does not matter if I am running 1.6.0 or the Release Candidate. I get the same message all the time.
Win XP - SP3 is the OS with all MS patches applied.</description>
    </item>
    
    <item>
      <title>wireshark can not decode</title>
      <link>/questions/5031/wireshark-can-not-decode/</link>
      <pubDate>Wed, 13 Jul 2011 12:23:00 +0000</pubDate>
      
      <guid>/questions/5031/wireshark-can-not-decode/</guid>
      <description>wireshark can not decode  0 I am tracing s6a messages and on the ula message if the avp1430 shows up more than 3 times wireshark does not decode that part of the message un shows unreassembled packet (exception ocurred)
avp1430This question is marked &#34;community wiki&#34;.asked 13 Jul &#39;11, 12:23
GSC
1●1●1●1
accept rate: 0%
  
One Answer:
  
0What version of Wireshark are you using? 1.</description>
    </item>
    
    <item>
      <title>How do multiple dissectors work in same plugindll ?</title>
      <link>/questions/5050/how-do-multiple-dissectors-work-in-same-plugindll/</link>
      <pubDate>Thu, 14 Jul 2011 23:13:00 +0000</pubDate>
      
      <guid>/questions/5050/how-do-multiple-dissectors-work-in-same-plugindll/</guid>
      <description>How do multiple dissectors work in same plugindll ?  0 Hi all,
I am currently trying to write a dissector for my custom protocol. The protocol as most protocols do, has different types of packets which are identified by the first 8 bits of the header. Now i want to display a different structure per each packet. I do realize that we can register multiple dissectors in the plugin.c as in the samples.</description>
    </item>
    
    <item>
      <title>How to checkout a Bit in a Byte?</title>
      <link>/questions/5051/how-to-checkout-a-bit-in-a-byte/</link>
      <pubDate>Fri, 15 Jul 2011 05:56:00 +0000</pubDate>
      
      <guid>/questions/5051/how-to-checkout-a-bit-in-a-byte/</guid>
      <description>How to checkout a Bit in a Byte?  0 Hi, just a short simple question:
How can i checkout a specific Bit in a Byte? I tryed something like this:
for i = Value_Start, Value_Stop do local c = buffer(i,1):uint() &amp;lt;--- is this the right valuetype??? if c and 2^1 == 1 then &amp;hellip;.. if c.1 == 1 then &amp;hellip;.. if c(1) == 1 then &amp;hellip;.. if c[1] == 1 then &amp;hellip;.</description>
    </item>
    
    <item>
      <title>How does Wireshark calculate the TCP stream index?</title>
      <link>/questions/5056/how-does-wireshark-calculate-the-tcp-stream-index/</link>
      <pubDate>Fri, 15 Jul 2011 12:48:00 +0000</pubDate>
      
      <guid>/questions/5056/how-does-wireshark-calculate-the-tcp-stream-index/</guid>
      <description>How does Wireshark calculate the TCP stream index?  0 How does Wireshark calculate the TCP stream index number? I&#39;m used to seeing the first TCP packet in a trace file have a TCP stream index of 0. However, I have a trace file in which the first TCP packet has a TCP stream index of 6. There are 10,000 packets in the file, 5,619 of which are TCP. The TCP stream index numbers run from 6 to 196, with many gaps in the sequence.</description>
    </item>
    
    <item>
      <title>I am looking for a Capture file of 802.1X handshake and EAP Can anyone help??</title>
      <link>/questions/5065/i-am-looking-for-a-capture-file-of-8021x-handshake-and-eap-can-anyone-help/</link>
      <pubDate>Fri, 15 Jul 2011 15:59:00 +0000</pubDate>
      
      <guid>/questions/5065/i-am-looking-for-a-capture-file-of-8021x-handshake-and-eap-can-anyone-help/</guid>
      <description>I am looking for a Capture file of 802.1X handshake and EAP Can anyone help??  0 I am looking for a Capture file of 802.1X handshake and EAP Can anyone help?
security radius help eapol 802.1xasked 15 Jul &#39;11, 15:59
sjohnson
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Here are places to look for sample capture files:
http://wiki.wireshark.org/SampleCaptures
https://www.openpacket.org/
http://packetlife.net/captures/
http://www.pcapr.net/browse/protos
answered 15 Jul &#39;11, 22:23</description>
    </item>
    
    <item>
      <title>Tshark custom columns: Why don&amp;#x27;t I get an error message?</title>
      <link>/questions/5069/tshark-custom-columns-why-dont-i-get-an-error-message/</link>
      <pubDate>Sat, 16 Jul 2011 00:41:00 +0000</pubDate>
      
      <guid>/questions/5069/tshark-custom-columns-why-dont-i-get-an-error-message/</guid>
      <description>Tshark custom columns: Why don&amp;rsquo;t I get an error message?  0 Correct syntax: $ tshark -r test.pcap -R &amp;quot;frame.number&amp;lt;6&amp;quot; -o column.format:&amp;quot;&amp;quot;No.&amp;quot;,&amp;quot;%m&amp;quot;, &amp;quot;tcp.port&amp;quot;, &amp;quot;%Cus:tcp.port&amp;quot;, &amp;quot;udp.port&amp;quot;, &amp;quot;%Cus:udp.port&amp;quot;&amp;quot; 1 55556,53 2 53,55556 3 1685,80 4 80,1685 5 1685,80 I get an error message, when I make a typo: %Cu:udp.port (instead of %Cus:udp.port) $ tshark -r test.pcap -R &amp;quot;frame.number&amp;lt;6&amp;quot; -o column.format:&amp;quot;&amp;quot;No.&amp;quot;,&amp;quot;%m&amp;quot;, &amp;quot;tcp.port&amp;quot;, &amp;quot;%Cus:tcp.port&amp;quot;, &amp;quot;udp.port&amp;quot;, &amp;quot;%Cu:udp.port&amp;quot;&amp;quot; tshark: Invalid -o flag &amp;quot;column.format:No.,%m, tcp.port, %Cus:tcp.port, udp.port, %Cu:udp.</description>
    </item>
    
    <item>
      <title>Wireshark for IBM AIX 5.3</title>
      <link>/questions/5070/wireshark-for-ibm-aix-53/</link>
      <pubDate>Sat, 16 Jul 2011 00:50:00 +0000</pubDate>
      
      <guid>/questions/5070/wireshark-for-ibm-aix-53/</guid>
      <description>Wireshark for IBM AIX 5.3  0 Please can anybody let me know if we can use wireshark on IBM AIX 5.3, if so please guide me to a download link.
aixThis question is marked &#34;community wiki&#34;.asked 16 Jul &#39;11, 00:50
amteruh
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Sure, I don&#39;t see why you couldn&#39;t--but I don&#39;t know of any places that actually build it for you.</description>
    </item>
    
    <item>
      <title>running wireshark on a server</title>
      <link>/questions/5076/running-wireshark-on-a-server/</link>
      <pubDate>Sat, 16 Jul 2011 23:02:00 +0000</pubDate>
      
      <guid>/questions/5076/running-wireshark-on-a-server/</guid>
      <description>running wireshark on a server  0 configuration is an intel mac with an airport card and several usb nics. The airport card is for connectivity to the internet. the usb nics provide connectivity to the local lan. internet sharing is used on the mac to distribute internet access and the mac is also a file repository. Internet sharing on the mac results in a dhcp serving addresses in a different class c for each nic-so one nic for example will get 192.</description>
    </item>
    
    <item>
      <title>how to define capture filter for QoS traffic</title>
      <link>/questions/5077/how-to-define-capture-filter-for-qos-traffic/</link>
      <pubDate>Sat, 16 Jul 2011 23:11:00 +0000</pubDate>
      
      <guid>/questions/5077/how-to-define-capture-filter-for-qos-traffic/</guid>
      <description>how to define capture filter for QoS traffic  0 I would like to capture all traffic that are marked with DSCP value 184. I am able to do so using display filter &#34;ip.dsfield==184&#34; but how do i use the equivalent filter on capture filter ?
qosasked 16 Jul &#39;11, 23:11
chenhsien
1●1●1●2
accept rate: 0%
  
One Answer:
  
1The capture filter equivalent of &#34;ip.dsfield==184&#34; would be &#34;</description>
    </item>
    
    <item>
      <title>Are there any benefits in running the x64 version (Windows)?</title>
      <link>/questions/5081/are-there-any-benefits-in-running-the-x64-version-windows/</link>
      <pubDate>Sun, 17 Jul 2011 05:07:00 +0000</pubDate>
      
      <guid>/questions/5081/are-there-any-benefits-in-running-the-x64-version-windows/</guid>
      <description>Are there any benefits in running the x64 version (Windows)?  0 On Windows, I am currently using the portable version, which is 32-bit, mostly on 64-bit machines.
Is there any difference, advantage. or speed improvement in running the x64 version instead?
If there was, I was thinking of modifying the portable launcher to automatically start either the x86 or x64 version, depending on the operating system.
windows portable 64-bitasked 17 Jul &#39;11, 05:07</description>
    </item>
    
    <item>
      <title>How to check number of packets with duplicate IP identification Field</title>
      <link>/questions/5083/how-to-check-number-of-packets-with-duplicate-ip-identification-field/</link>
      <pubDate>Sun, 17 Jul 2011 09:34:00 +0000</pubDate>
      
      <guid>/questions/5083/how-to-check-number-of-packets-with-duplicate-ip-identification-field/</guid>
      <description>How to check number of packets with duplicate IP identification Field  0 Hello All,
I am working on a capture with UDP packet, as a part of problem isolation i need to find if there are any duplicate packets or packet loss. Concerned traffic is passing through multiple service provider / MPLS links and I have sniffer traces from Server as well as Client to conclude on this as we cannot have service provider end sniffer traces for sure :-).</description>
    </item>
    
    <item>
      <title>How to capture in promiscuous mode(behind NAT)?</title>
      <link>/questions/5084/how-to-capture-in-promiscuous-modebehind-nat/</link>
      <pubDate>Sun, 17 Jul 2011 13:53:00 +0000</pubDate>
      
      <guid>/questions/5084/how-to-capture-in-promiscuous-modebehind-nat/</guid>
      <description>How to capture in promiscuous mode(behind NAT)?  0 I would like to capture packets that are sent to a someone behind the same router(there is just two of ous). I checked Capture packets in promiscuous mode in Capture options, but only thing I capture is some ARPs. What more do I need do to sniff from someone behind same router.
capture promiscuous natasked 17 Jul &#39;11, 13:53
LivinOnAThin...
1●1●1●1</description>
    </item>
    
    <item>
      <title>WS_VAR_IMPORT does not name a type</title>
      <link>/questions/5086/ws_var_import-does-not-name-a-type/</link>
      <pubDate>Sun, 17 Jul 2011 23:58:00 +0000</pubDate>
      
      <guid>/questions/5086/ws_var_import-does-not-name-a-type/</guid>
      <description>WS_VAR_IMPORT does not name a type  0 While compiling the dissector on linux i am getting the fallowing error does anybody know the solution to this
wireshark-1.4.7/epan/prefs.h:167: error: WS_VAR_IMPORT does not name a type
linuxasked 17 Jul &#39;11, 23:58
sagu072
35●23●24●28
accept rate: 0%
  
One Answer:
  
0Make sure to include config.h before prefs.h in your dissector, like so:
#ifdef HAVE_CONFIG_H # include &amp;quot;config.h&amp;quot; #endifanswered 18 Jul &#39;11, 01:51</description>
    </item>
    
    <item>
      <title>Wireshark crash</title>
      <link>/questions/5087/wireshark-crash/</link>
      <pubDate>Mon, 18 Jul 2011 00:39:00 +0000</pubDate>
      
      <guid>/questions/5087/wireshark-crash/</guid>
      <description>Wireshark crash  0 Hi, I was recently introduced to wireshark to help me troubleshoot a problomatic network where the switches kept repeatidly crashing.
To get me started I picked up a book called Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems by Chris Sanders which has been of great help.
I am currently leaving my laptop onsite at the customers house colelcting data over 3/4 day periods and I am finding that when I return to collect the laptop Wireshark has recently crashed.</description>
    </item>
    
    <item>
      <title>FCS incorrect</title>
      <link>/questions/5092/fcs-incorrect/</link>
      <pubDate>Mon, 18 Jul 2011 02:10:00 +0000</pubDate>
      
      <guid>/questions/5092/fcs-incorrect/</guid>
      <description>FCS incorrect  0 Hi,
We are facing an issue in our network. To debug this issue when we decided to do a capture using wireshark, the capture shows some frames with &#34;Frame check sequence: 0xa78b22ce [incorrect, should be 0x56e60339]&#34;. The wireshark version that this is seen on was 1.0.4. Then I upgraded to the latest version of wireshark, i.e. 1.6.0. And this same trace does not show this FCS incorrect anymore.</description>
    </item>
    
    <item>
      <title>starting capture from the command line with a display filter active</title>
      <link>/questions/5102/starting-capture-from-the-command-line-with-a-display-filter-active/</link>
      <pubDate>Mon, 18 Jul 2011 07:36:00 +0000</pubDate>
      
      <guid>/questions/5102/starting-capture-from-the-command-line-with-a-display-filter-active/</guid>
      <description>starting capture from the command line with a display filter active  0 I have tried using the -R option but it seems it is only for reading previously captured files? Is there anyway of doing this please. I have just downloaded latest stable version 1.6.0 and rebuilt on centos 5.5.
e.g. wireshark -i bond0 -R tcp.port==8600 -k and whatever else options etc
I found a faq with someone offering a solution (which was admitted that it did not work) with hope someone would answer.</description>
    </item>
    
    <item>
      <title>Is it possible to use WS on chromeos or chrome browser?</title>
      <link>/questions/5107/is-it-possible-to-use-ws-on-chromeos-or-chrome-browser/</link>
      <pubDate>Mon, 18 Jul 2011 09:16:00 +0000</pubDate>
      
      <guid>/questions/5107/is-it-possible-to-use-ws-on-chromeos-or-chrome-browser/</guid>
      <description>Is it possible to use WS on chromeos or chrome browser?  0 Is there any version that will run under chromeos? Any that will run on chrome browser?
If not available yet, is there any fundamental limitation of chromeos that would prevent a future version from being available? Can this be added on as an App or Extension?
chrome-browser chromeos chrome-extension chrome-appasked 18 Jul &#39;11, 09:16
CqN
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How can i tshark a folder full of tracefiles for the biggest tcp stream in each trace?</title>
      <link>/questions/5111/how-can-i-tshark-a-folder-full-of-tracefiles-for-the-biggest-tcp-stream-in-each-trace/</link>
      <pubDate>Mon, 18 Jul 2011 23:55:00 +0000</pubDate>
      
      <guid>/questions/5111/how-can-i-tshark-a-folder-full-of-tracefiles-for-the-biggest-tcp-stream-in-each-trace/</guid>
      <description>How can i tshark a folder full of tracefiles for the biggest tcp stream in each trace?  0 I&#39;m tracing issues with Window Scaling from client to server, after a batch testfile (with copy commands for file transfers) i want to analyse all tracefiles for throughput, window sizes, application read requests and so on, but..... from every trace i only need the biggest tcp stream. Most of the time it&#39;s &#34;</description>
    </item>
    
    <item>
      <title>Bypassing the wireshark/tshark interface to use the dissector</title>
      <link>/questions/5115/bypassing-the-wiresharktshark-interface-to-use-the-dissector/</link>
      <pubDate>Tue, 19 Jul 2011 01:39:00 +0000</pubDate>
      
      <guid>/questions/5115/bypassing-the-wiresharktshark-interface-to-use-the-dissector/</guid>
      <description>Bypassing the wireshark/tshark interface to use the dissector  0 1Dear all, thanks for your attention.
I need to design a class that dissects and filter a protocol without having to install the whole wireshark program. This is because i do not require the other dissectors which are unused and i would like my program to run at a high speed to accommodate traffic that i am receiving.
Is there a way to directly access and use the dissectors?</description>
    </item>
    
    <item>
      <title>.rf5 file opening error</title>
      <link>/questions/5117/rf5-file-opening-error/</link>
      <pubDate>Tue, 19 Jul 2011 02:51:00 +0000</pubDate>
      
      <guid>/questions/5117/rf5-file-opening-error/</guid>
      <description>.rf5 file opening error  0 When I try to open error a file *.rf5 it throw up error, its ATM catpure.
HLAYER &amp;quot;MTP-2&amp;quot; &amp;quot;../../protocols/base/base.upd*&amp;quot; LOADED &amp;quot;K12xx decoder base - english version&amp;quot; LAYER &amp;quot;SSCOP&amp;quot; &amp;quot;../../protocols/bisup/sscop.upd1&amp;quot; LOADED &amp;quot;SSCOP ITU Q.2100, 07/1994 [06.05.02]&amp;quot; LAYER &amp;quot;AAL2L3&amp;quot; &amp;quot;../../protocols/umts_common/aal2l3.upd1&amp;quot; LOADED &amp;quot;ITU-T Q.2630.1/2 AAL2 Signalling CS1/2&amp;quot; RELATION &amp;quot;BASE&amp;quot; &amp;quot;SSCOP&amp;quot; UNCOND POSITION 290 416 290 390 RELATION &amp;quot;SSCOP&amp;quot; &amp;quot;AAL2L3&amp;quot; UNCOND POSITION 290 350 290 303 DECKRNL &amp;quot;MTP-2&amp;quot; LSBF UPD_DK DECKRNL &amp;quot;SSCOP&amp;quot; MSBF UPD_DK DECKRNL &amp;quot;AAL2L3&amp;quot; LSBF UPD_DK LAYPOS &amp;quot;BASE&amp;quot; 150 416 430 486 LAYPOS &amp;quot;MTP-2&amp;quot; 10 10 70 50 LAYPOS &amp;quot;SSCOP&amp;quot; 260 350 320 390 LAYPOS &amp;quot;AAL2L3&amp;quot; 256 263 324 303Format : error opening file.</description>
    </item>
    
    <item>
      <title>Remote capture and user authentication</title>
      <link>/questions/5121/remote-capture-and-user-authentication/</link>
      <pubDate>Tue, 19 Jul 2011 06:57:00 +0000</pubDate>
      
      <guid>/questions/5121/remote-capture-and-user-authentication/</guid>
      <description>Remote capture and user authentication  0 Hi, i&#39;m using Wireshark to monitor traffic of a windows machine (using Winpcap). everything works fine but any user account which exists on the target machine is allowed to do a remote capture. how could i specify allowed user or groups ?
winpcap remoteasked 19 Jul &#39;11, 06:57
sos00
1●1●1●1
accept rate: 0%
  
One Answer:
  
0All you can do is limit the hosts which may connect.</description>
    </item>
    
    <item>
      <title>Windows path issues during nmake setup</title>
      <link>/questions/5122/windows-path-issues-during-nmake-setup/</link>
      <pubDate>Tue, 19 Jul 2011 06:58:00 +0000</pubDate>
      
      <guid>/questions/5122/windows-path-issues-during-nmake-setup/</guid>
      <description>Windows path issues during nmake setup  0 I seem to be having issues with the POSIX paths that have been implemented in Wireshark 1.6.1. I&#39;m on a Windows XP Pro box.
During the setup, the file is being downloaded. I can clearly see it, but I cannot see it through the cygdrive path. If I run the unzip program using the cygdrive path, I get the same error, but if I go the the libs folder and run the unzip program, it unzips fine.</description>
    </item>
    
    <item>
      <title>Waiting for Capture Input Data...</title>
      <link>/questions/5126/waiting-for-capture-input-data/</link>
      <pubDate>Tue, 19 Jul 2011 08:07:00 +0000</pubDate>
      
      <guid>/questions/5126/waiting-for-capture-input-data/</guid>
      <description>Waiting for Capture Input Data&amp;hellip;  0 Wireshark 1.6.0 Windows 7 Pro HP Mini Netbook 1GB. The above message displays when capture starts. No packets are displayed and data is captured. Data can not be displayed except with View | Show data in New Window. I can not find a way to display the data while capturing or after capture stops.
capture displayasked 19 Jul &#39;11, 08:07
ryoung
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Bluetooth Connections</title>
      <link>/questions/5127/bluetooth-connections/</link>
      <pubDate>Tue, 19 Jul 2011 08:42:00 +0000</pubDate>
      
      <guid>/questions/5127/bluetooth-connections/</guid>
      <description>Bluetooth Connections  -3 Can I change Com Port for my Bluetooth?
helpasked 19 Jul &#39;11, 08:42
Taggart
0●1●1●1
accept rate: 0%
1This is the Wireshark Q&amp;amp;A, not the General Hardware Questions section :-) If your topic has anything to do with Wireshark please rephrase it.
(19 Jul &#39;11, 16:54) Jasper ♦♦   </description>
    </item>
    
    <item>
      <title>Write Gzip Encoded HTTP as Inflated in PCAP File</title>
      <link>/questions/5132/write-gzip-encoded-http-as-inflated-in-pcap-file/</link>
      <pubDate>Tue, 19 Jul 2011 10:42:00 +0000</pubDate>
      
      <guid>/questions/5132/write-gzip-encoded-http-as-inflated-in-pcap-file/</guid>
      <description>Write Gzip Encoded HTTP as Inflated in PCAP File  0 Is there any option or way to force tshark to write to the pcap output file the inflated http content body that was received encoded?
gzip pcap inflate http tsharkasked 19 Jul &#39;11, 10:42
sethlwilson
31●2●2●6
accept rate: 12%
  
2 Answers:
  
0 I found a way to extract what I needed which was SOAP XML traffic to/from a Web service.</description>
    </item>
    
    <item>
      <title>Removing duplicate packets</title>
      <link>/questions/5135/removing-duplicate-packets/</link>
      <pubDate>Tue, 19 Jul 2011 15:46:00 +0000</pubDate>
      
      <guid>/questions/5135/removing-duplicate-packets/</guid>
      <description>Removing duplicate packets  0 I have found that when mirroring packets on at least some Cisco platforms, in some cases the ehthernet MAC address is that of the sending/receiving device, and in others it&#39;s the MAC address of the switch -- this is true for the same TCP session and creates duplicates. When this happens, editcap -d does not remove the duplicates. Is there a way to cause editcap to ignore the ehthernet portion when de-duplicating?</description>
    </item>
    
    <item>
      <title>Support of MAP and CAP Protocol in Wireshark</title>
      <link>/questions/5140/support-of-map-and-cap-protocol-in-wireshark/</link>
      <pubDate>Tue, 19 Jul 2011 20:48:00 +0000</pubDate>
      
      <guid>/questions/5140/support-of-map-and-cap-protocol-in-wireshark/</guid>
      <description>Support of MAP and CAP Protocol in Wireshark  0 I would be grateful, if somebody tell whether wireshark capture MAP and CAP Protocols packets.
Thanks,
map capasked 19 Jul &#39;11, 20:48
arvind
1●1●1●1
accept rate: 0%
 edited 28 Feb &#39;12, 20:07 
cmaynard ♦♦
9.4k●10●38●142
Sorry, death by acronym here... can you elaborate on what protocols you mean by telling us a bit more?
(20 Jul &#39;11, 07:56) Jasper ♦♦</description>
    </item>
    
    <item>
      <title>What are career opportunities in wireshark ?</title>
      <link>/questions/5141/what-are-career-opportunities-in-wireshark/</link>
      <pubDate>Wed, 20 Jul 2011 00:27:00 +0000</pubDate>
      
      <guid>/questions/5141/what-are-career-opportunities-in-wireshark/</guid>
      <description>What are career opportunities in wireshark ?  0 Hi, I am working in 3G wireshark development from the last one year.I want to know about the career opportunities in this , especially in India.Please guide :).
career job indiaasked 20 Jul &#39;11, 00:27
Shikha Chowd...
1●1●1●2
accept rate: 0%
 edited 21 Jul &#39;11, 03:37 
   </description>
    </item>
    
    <item>
      <title>couldn&amp;#x27;t load my own dll with latest 1.6.1 version</title>
      <link>/questions/5145/couldnt-load-my-own-dll-with-latest-161-version/</link>
      <pubDate>Wed, 20 Jul 2011 08:55:00 +0000</pubDate>
      
      <guid>/questions/5145/couldnt-load-my-own-dll-with-latest-161-version/</guid>
      <description>couldn&amp;rsquo;t load my own dll with latest 1.6.1 version  0 couldn&#39;t load my own dll with latest 1.6.1 version, got message like:
The specified procedure could not be found
But my own dlls were working fine with the old versions.
dissector compatibility dllasked 20 Jul &#39;11, 08:55
lulu
1●1●1●1
accept rate: 0%
 edited 27 Jul &#39;11, 15:33 
helloworld
3.1k●4●20●41
2Have you recompiled your plugin against the new version?</description>
    </item>
    
    <item>
      <title>RANAP HandOver procedure</title>
      <link>/questions/5151/ranap-handover-procedure/</link>
      <pubDate>Thu, 21 Jul 2011 02:22:00 +0000</pubDate>
      
      <guid>/questions/5151/ranap-handover-procedure/</guid>
      <description>RANAP HandOver procedure  0 Hi, I have some problem with decoding a RANAP packet when I perform a HandOver. Some RANAP packets are malformed in this case. (I&#39;m using 1.6.1 version of Wireshark) I have opened the problem report agains our developers, but they claim that this is a bug of Wireshark and not their protocol stack. See below the description of a problem. ======================================= When HO procedure is performed (intra Freq HO), some RANAP packets are malformed: 1.</description>
    </item>
    
    <item>
      <title>Link shared library for decoder with wireshark on linux</title>
      <link>/questions/5152/link-shared-library-for-decoder-with-wireshark-on-linux/</link>
      <pubDate>Thu, 21 Jul 2011 03:13:00 +0000</pubDate>
      
      <guid>/questions/5152/link-shared-library-for-decoder-with-wireshark-on-linux/</guid>
      <description>Link shared library for decoder with wireshark on linux  1 I have written a shared library for decoder, can anybody tell me how can i link it to the wireshark ? I am working on RedHat Linux....
shared library linuxasked 21 Jul &#39;11, 03:13
sagu072
35●23●24●28
accept rate: 0%
 edited 21 Jul &#39;11, 04:54 
Jaap ♦
11.7k●16●101
   </description>
    </item>
    
    <item>
      <title>Wave Short Message P1609.3</title>
      <link>/questions/5155/wave-short-message-p16093/</link>
      <pubDate>Thu, 21 Jul 2011 07:50:00 +0000</pubDate>
      
      <guid>/questions/5155/wave-short-message-p16093/</guid>
      <description>Wave Short Message P1609.3  0 Hi, i am wondering about implementation in wireshark. By starting wireshark(1.6) on channel 178 we take 2 codha boxes. On captured traffic i see: malform Packet: [WSMP] ... It would be helpful to get implementation with more details. e.g MsgCut,ID,SecMark,Lat,Long,Elev and so on.
Best Regards,
carhs.communication GmbH
car2x security snifferasked 21 Jul &#39;11, 07:50
lordofdarkness
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Incorrect error reported by Wireshark&amp;#x27;s SNMP dissector</title>
      <link>/questions/5156/incorrect-error-reported-by-wiresharks-snmp-dissector/</link>
      <pubDate>Thu, 21 Jul 2011 09:18:00 +0000</pubDate>
      
      <guid>/questions/5156/incorrect-error-reported-by-wiresharks-snmp-dissector/</guid>
      <description>Incorrect error reported by Wireshark&amp;rsquo;s SNMP dissector  0 In the MIB extract below, SNMP variable radarName, used as INDEX, is defined as DisplayString (SIZE (4)) in the OBJECT-TYPE definition. DisplayString is imported from SNMPv2-TC and defined as OCTET STRING (SIZE(0..255)). In the ASN1 SEQUENCE radarName is defined with SYNTAX DisplayString and this is where the trouble starts. According to the ASN SEQUENCE definition the radarName will be encoded as variable string, so 1 length bytes and &#34;</description>
    </item>
    
    <item>
      <title>Src =Nitrogen DST =nitrogen broadcasts</title>
      <link>/questions/5158/src-nitrogen-dst-nitrogen-broadcasts/</link>
      <pubDate>Thu, 21 Jul 2011 18:46:00 +0000</pubDate>
      
      <guid>/questions/5158/src-nitrogen-dst-nitrogen-broadcasts/</guid>
      <description>Src =Nitrogen DST =nitrogen broadcasts  0 Doing a sniff of only broadcasts during a network slowdown, About 20% of my broadcasts are src=Nitrogen DST =nitrogen. An hour on Google produced nothing any ideas?
src nitrogenasked 21 Jul &#39;11, 18:46
mstrfl2000
1●1●1●1
accept rate: 0%
Please provide a more info:
Is that SRC/DST address or SRC/DST port ?
What protocols are seen ?
Ethernet Broadcast ? IP Broadcast ?
etc</description>
    </item>
    
    <item>
      <title>Sharktools Installation help</title>
      <link>/questions/5160/sharktools-installation-help/</link>
      <pubDate>Thu, 21 Jul 2011 19:27:00 +0000</pubDate>
      
      <guid>/questions/5160/sharktools-installation-help/</guid>
      <description>Sharktools Installation help  0 1Looking for any sharktools user here. In the README file, under &#34;= Building/Installation instructions =&#34;, no 6,
this line:/path/to/sharktools$ ./configure --with-wireshark-src=./path/to/wireshark-x.y.z
I don&#39;t understand what the author means by &#34;--with-wireshark-src&#34;.
Any help is appreciated.
Thanks
Regards, Eddie Choo
NB: i only need to run the test program.
sharktoolsasked 21 Jul &#39;11, 19:27
eddie choo
66●9●17●15
accept rate: 66%
 edited 21 Jul &#39;11, 20:08</description>
    </item>
    
    <item>
      <title>Wireshark University Certificate</title>
      <link>/questions/5162/wireshark-university-certificate/</link>
      <pubDate>Thu, 21 Jul 2011 19:54:00 +0000</pubDate>
      
      <guid>/questions/5162/wireshark-university-certificate/</guid>
      <description>Wireshark University Certificate  0 1How useful is that cert? What are the other qualifications in the same category?
Thanks
Regards,
Eddie Choo
wiresharkasked 21 Jul &#39;11, 19:54
eddie choo
66●9●17●15
accept rate: 66%
  
One Answer:
  
1 I think this question and it&#39;s answers might be what you&#39;re looking for:
http://ask.wireshark.org/questions/818/wireshark-certification-any-value
answered 22 Jul &#39;11, 00:26
Jasper ♦♦
23.8k●5●51●284
accept rate: 18%
Wow, nice link.</description>
    </item>
    
    <item>
      <title>How to decode RTP and save as .raw file from command line using linux?</title>
      <link>/questions/5165/how-to-decode-rtp-and-save-as-raw-file-from-command-line-using-linux/</link>
      <pubDate>Thu, 21 Jul 2011 22:30:00 +0000</pubDate>
      
      <guid>/questions/5165/how-to-decode-rtp-and-save-as-raw-file-from-command-line-using-linux/</guid>
      <description>How to decode RTP and save as .raw file from command line using linux?  1 Hi,
I managed to capture some RTP packets from VoIP conversation. Does anyone know how do I execute the &#34;Decode as&#34; Wireshark command from command line and make it save as .raw file? I know how to execute these commands from the GUI, but not from a command line. I&#39;m trying to incorporate it into my script.</description>
    </item>
    
    <item>
      <title>Registering variables in a dissector code??</title>
      <link>/questions/5166/registering-variables-in-a-dissector-code/</link>
      <pubDate>Thu, 21 Jul 2011 23:41:00 +0000</pubDate>
      
      <guid>/questions/5166/registering-variables-in-a-dissector-code/</guid>
      <description>Registering variables in a dissector code??  0 I have a field in my protocol like this:
IP (which is a set of 32 IP addresses). So should I use an array to display the 32 IP addresses or something else?
If I use the array, how do I register my array in the dissector&#39;s proto_register function??
Please help..!!
array dissectorasked 21 Jul &#39;11, 23:41
sid
45●19●20●21
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to get the parent dissector information?</title>
      <link>/questions/5172/how-to-get-the-parent-dissector-information/</link>
      <pubDate>Fri, 22 Jul 2011 01:50:00 +0000</pubDate>
      
      <guid>/questions/5172/how-to-get-the-parent-dissector-information/</guid>
      <description>How to get the parent dissector information?  0 I wish to conditionally call col_set_str or col_append_str depends on the parent dissector information. But I was stuck by getting the parent dissector information. Anyone could help me to do this? Thanks!
development dissectorasked 22 Jul &#39;11, 01:50
piao
6●1●1●2
accept rate: 0%
 edited 05 Oct &#39;11, 17:10 
multipleinte...
1.3k●15●23●40
  
One Answer:
  
2 This is supposed to be handled the other way around.</description>
    </item>
    
    <item>
      <title>Why gratuitous ARPs for 0.0.0.0?</title>
      <link>/questions/5178/why-gratuitous-arps-for-0000/</link>
      <pubDate>Fri, 22 Jul 2011 21:16:00 +0000</pubDate>
      
      <guid>/questions/5178/why-gratuitous-arps-for-0000/</guid>
      <description>Why gratuitous ARPs for 0.0.0.0?  0 In a trace file I captured today, I noticed four packets that Wireshark identified as “Gratuitous ARP for 0.0.0.0 (request).” I know that an ARP probe should come from 0.0.0.0, but these four packets were both FROM and TO 0.0.0.0.
They are not RARPs or inverse ARPs. eth.type is ARP (0x0806), not RARP (0x8035). arp.opcode is 1 (request), not 3 (reverse request) or 8 (inverse request).</description>
    </item>
    
    <item>
      <title>ARP packet cant see :-</title>
      <link>/questions/5180/arp-packet-cant-see-/</link>
      <pubDate>Fri, 22 Jul 2011 22:40:00 +0000</pubDate>
      
      <guid>/questions/5180/arp-packet-cant-see-/</guid>
      <description>ARP packet cant see :-  0 Hello... !! When i run wireshark to monitor the packets in a network(internet connection) i cant see a single arp packet and sometimes i have seen only 2 or 3 arp packets that too of my ip address.
So can anyone tell me how to bypass it or a solution to this type of problem.. Basically i m using hathway connection...
So any solution</description>
    </item>
    
    <item>
      <title>Users connecting OK, but not getting IP address: how to troubleshoot?</title>
      <link>/questions/5186/users-connecting-ok-but-not-getting-ip-address-how-to-troubleshoot/</link>
      <pubDate>Sat, 23 Jul 2011 17:53:00 +0000</pubDate>
      
      <guid>/questions/5186/users-connecting-ok-but-not-getting-ip-address-how-to-troubleshoot/</guid>
      <description>Users connecting OK, but not getting IP address: how to troubleshoot?  0 On my network, users connect (a) wirelessly to their own combination bridge, router, and signal amplifier, then from there (b) wirelessly to my secure hardware. Some users can connect to my hardware, but don&#39;t get an IP address from my DHCP server. Any suggestions on how to troubleshoot this with Wireshark?
ip connection addressasked 23 Jul &#39;11, 17:53</description>
    </item>
    
    <item>
      <title>Snow Leopard running Fusion has virtual ports invisible to wireshark</title>
      <link>/questions/5188/snow-leopard-running-fusion-has-virtual-ports-invisible-to-wireshark/</link>
      <pubDate>Sun, 24 Jul 2011 07:30:00 +0000</pubDate>
      
      <guid>/questions/5188/snow-leopard-running-fusion-has-virtual-ports-invisible-to-wireshark/</guid>
      <description>Snow Leopard running Fusion has virtual ports invisible to wireshark  0 Win XP SP3 in fusion can surf the net through the mac&#39;s airport in either bridged or nat mode fine. the mac has a static ip. the windows is set to dhcp.
ifconfig on the mac shows
en1: inet 192.168.1.43 netmask 0xffffff00 broadcast 192.168.1.255
vmnet1: inet 172.16.193.1 netmask 0xffffff00 broadcast 172.16.193.255
vmnet8: inet 172.16.143.1 netmask 0xffffff00 broadcast 172.16.143.255</description>
    </item>
    
    <item>
      <title>DNS Problem on internet browsing.</title>
      <link>/questions/5197/dns-problem-on-internet-browsing/</link>
      <pubDate>Sun, 24 Jul 2011 19:14:00 +0000</pubDate>
      
      <guid>/questions/5197/dns-problem-on-internet-browsing/</guid>
      <description>DNS Problem on internet browsing.  0 Is there a way to reset or flush registry DNS of windows XP service pack 3? Each time when i typed in an internet address, browser respond an error unable to locate/match website address to I.P. address, that something is wrong with the DNS.
dnsasked 24 Jul &#39;11, 19:14
Kane
1●2●2●3
accept rate: 0%
  
One Answer:
  
1ipconfig /flushdns</description>
    </item>
    
    <item>
      <title>Decode of libpcap file.</title>
      <link>/questions/5198/decode-of-libpcap-file/</link>
      <pubDate>Sun, 24 Jul 2011 19:20:00 +0000</pubDate>
      
      <guid>/questions/5198/decode-of-libpcap-file/</guid>
      <description>Decode of libpcap file.  0 I have written a program to decode and use the capture file from wireshark in real time.
It failed when I moved it to a different computer since I had a check for valid header which was actually looking for my IP(I thought it was just a magic number)
Problem is, I read and followed your Global Header second and Record header section in the doc, but you did not outline the format of the actual data packet.</description>
    </item>
    
    <item>
      <title>How does Wireshark recognise the protocol of the raw data?</title>
      <link>/questions/5204/how-does-wireshark-recognise-the-protocol-of-the-raw-data/</link>
      <pubDate>Mon, 25 Jul 2011 01:14:00 +0000</pubDate>
      
      <guid>/questions/5204/how-does-wireshark-recognise-the-protocol-of-the-raw-data/</guid>
      <description>How does Wireshark recognise the protocol of the raw data?  1 1Are the functions located in the capture.c file? I have gone through the Developer&#39;s Guide but I can&#39;t really find the explanation on how wireshark automatically detects which protocol the raw data belongs to.
Thanks for your attention.
Regards, Eddie Choo
wiresharkasked 25 Jul &#39;11, 01:14
eddie choo
66●9●17●15
accept rate: 66%
 edited 25 Jul &#39;11, 01:52</description>
    </item>
    
    <item>
      <title>Windows XP C&#43;&#43; runtime error</title>
      <link>/questions/5207/windows-xp-c-runtime-error/</link>
      <pubDate>Mon, 25 Jul 2011 03:48:00 +0000</pubDate>
      
      <guid>/questions/5207/windows-xp-c-runtime-error/</guid>
      <description>Windows XP C++ runtime error  0 hi,
when I try to run wireshark in windows XP, it gives me the following error:
Microsoft Visual C++ Runtime Library
Program: /path-to-wireshark/wireshark.exe
This Apllication has requested the runtime to terminate it in an unusual way. Please contact the support team.
What should I do?
windows startup crashasked 25 Jul &#39;11, 03:48
pangd
1●1●1●1
accept rate: 0%
 edited 29 Jul &#39;11, 12:05</description>
    </item>
    
    <item>
      <title>Howto Add Arbitrary Items to the Tree Structure in Dissector?</title>
      <link>/questions/5212/howto-add-arbitrary-items-to-the-tree-structure-in-dissector/</link>
      <pubDate>Mon, 25 Jul 2011 05:45:00 +0000</pubDate>
      
      <guid>/questions/5212/howto-add-arbitrary-items-to-the-tree-structure-in-dissector/</guid>
      <description>Howto Add Arbitrary Items to the Tree Structure in Dissector?  0 I would like to add the following nodes to the tree structure in Wireshark in my dissectors code:
Node1Node2Node3Node4Node5Node6I know this would be accomplished through the dissect proto function, but I cannot figure out how to add nodes and set the text arbitrarily (totally independent of the data getting handed into my dissector).
I realize this is not quite how this is supposed to be used, but due to the nature of what I am doing, the actual conversion function (raw data to XML) is already done inside a DLL file.</description>
    </item>
    
    <item>
      <title>Get Wireshark Install Directory inside Dissector</title>
      <link>/questions/5223/get-wireshark-install-directory-inside-dissector/</link>
      <pubDate>Mon, 25 Jul 2011 08:09:00 +0000</pubDate>
      
      <guid>/questions/5223/get-wireshark-install-directory-inside-dissector/</guid>
      <description>Get Wireshark Install Directory inside Dissector  0 How can I get the Wireshark install directory from within a wireshark dissector? My dissector relies on some external libraries and I would like to avoid hard coding &#34;C:Program FilesWiresharkPluginsFooDebendancies&#34;
Thank you for your time, Brandon
directory dissector library install dllasked 25 Jul &#39;11, 08:09
officialhopsof
31●8●8●12
accept rate: 100%
  
One Answer:
  
1 You can use one of the routines in epan/filesystem.</description>
    </item>
    
    <item>
      <title>ENIP PCCC DATA Decodes</title>
      <link>/questions/5224/enip-pccc-data-decodes/</link>
      <pubDate>Mon, 25 Jul 2011 10:49:00 +0000</pubDate>
      
      <guid>/questions/5224/enip-pccc-data-decodes/</guid>
      <description>ENIP PCCC DATA Decodes  0 I am developing a new control system cybersecurity course and I need some help developing data dissector for ENIP PCCC communication. PCCC shows up as ENIP DATA payloads within Wireshark. I have purchased a decoding software from FTE, but this is not realistic on a massive scale and it has many more features than I need.
Matt Luallen
pccc enip dissectorasked 25 Jul &#39;11, 10:49</description>
    </item>
    
    <item>
      <title>How to Load External DLL from Dissector</title>
      <link>/questions/5226/how-to-load-external-dll-from-dissector/</link>
      <pubDate>Mon, 25 Jul 2011 11:56:00 +0000</pubDate>
      
      <guid>/questions/5226/how-to-load-external-dll-from-dissector/</guid>
      <description>How to Load External DLL from Dissector  0 I have a DLL file named, Test2.dll which loads fine in anything but wireshark, but when I try to open it within my wireshark dissector it fails to load, this is how I am loading it:
#define LIBRARYLOCATION &amp;quot;C:\\Docum...\\Test2.dll&amp;quot; &amp;hellip;
static void dissect_foo(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree){ HINSTANCE DLLInstance = LoadLibrary((LPCWSTR)LIBRARYLOCATION);
if(DLLInstance == NULL){ proto_tree_add_text(tree, NULL, 0, 0, &amp;quot;Cannot Load DLL: %*s&amp;quot;, 0, LIBRARYLOCATION);} else{ proto_tree_add_text(tree, NULL, 0, 0, &amp;quot;Loaded DLL: %*s&amp;quot;, 0, LIBRARYLOCATION);}The .</description>
    </item>
    
    <item>
      <title>Auto-display latest live-feed packet in detail pane?</title>
      <link>/questions/5227/auto-display-latest-live-feed-packet-in-detail-pane/</link>
      <pubDate>Mon, 25 Jul 2011 12:07:00 +0000</pubDate>
      
      <guid>/questions/5227/auto-display-latest-live-feed-packet-in-detail-pane/</guid>
      <description>Auto-display latest live-feed packet in detail pane?  0 How to auto-display latest live-feed packet in detail pane?
display paneasked 25 Jul &#39;11, 12:07
crypto9999
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Unfortunately, while Wireshark has an option to always show, in the packet list pane, the most recently captured packets, it does not have an option to always select the most recently captured packet. That would be a problem if it were the only behavior available - if you wanted to look at a particular packet while a capture is in progress, it would keep un-selecting that packet and selecting the most recently captured packet - but it could be a useful option.</description>
    </item>
    
    <item>
      <title>Decrypting your own Tlsv1 packets?</title>
      <link>/questions/5232/decrypting-your-own-tlsv1-packets/</link>
      <pubDate>Mon, 25 Jul 2011 13:32:00 +0000</pubDate>
      
      <guid>/questions/5232/decrypting-your-own-tlsv1-packets/</guid>
      <description>Decrypting your own Tlsv1 packets?  0 Hi everyone.
I&#39;m trying to write a program that interfaces to XYZ service&#39;s servers. (basically their software is quite buggy and non-optimized so I want to make a client that offers some limited functionality without said bugs etc)
The login uses TLSv1 and respectively, I know some of the data that is getting sent (my username and password for example).
It there anyway to &#39;decrypt&#39; your own packets?</description>
    </item>
    
    <item>
      <title>Add group and level to expert info?</title>
      <link>/questions/5235/add-group-and-level-to-expert-info/</link>
      <pubDate>Mon, 25 Jul 2011 15:49:00 +0000</pubDate>
      
      <guid>/questions/5235/add-group-and-level-to-expert-info/</guid>
      <description>Add group and level to expert info?  0 hello, you can add a level of security and group for the coloring of the node. And how?
Below an example of using: expert_add_info_format(pinfo, flags_item, MY_PI_XXX, MY_PI_XXX, &#34;Descrition&#34;);
Thanks.
expert-infoasked 25 Jul &#39;11, 15:49
Ignacio Rivera
1●2●2●3
accept rate: 0%
 edited 25 Jul &#39;11, 16:52 
helloworld
3.1k●4●20●41
Sorry, I&#39;m not sure what the question is here.
You&#39;ve quoted how to do it, for example:</description>
    </item>
    
    <item>
      <title>How to measure URL based statistics?</title>
      <link>/questions/5240/how-to-measure-url-based-statistics/</link>
      <pubDate>Mon, 25 Jul 2011 20:33:00 +0000</pubDate>
      
      <guid>/questions/5240/how-to-measure-url-based-statistics/</guid>
      <description>How to measure URL based statistics?  0 Hello,
I need to measure statistics on specific URL including D/L bytes, U/L bytes, average speed, etc.
Looking forward to get help.
Thanks, asmash
url httpasked 25 Jul &#39;11, 20:33
asmash
1●1●1●1
accept rate: 0%
  
One Answer:
  
0I doubt Wireshark is what you need. Look into using the netflow capability of your switch if you have a netflow capable one, or consider using a proxy which may be able to help with accounting info.</description>
    </item>
    
    <item>
      <title>tshark display filter in windows command-line seems not support special characters</title>
      <link>/questions/5241/tshark-display-filter-in-windows-command-line-seems-not-support-special-characters/</link>
      <pubDate>Mon, 25 Jul 2011 23:14:00 +0000</pubDate>
      
      <guid>/questions/5241/tshark-display-filter-in-windows-command-line-seems-not-support-special-characters/</guid>
      <description>tshark display filter in windows command-line seems not support special characters  0 I wrote a tshark display filter as this:
http.request.uri contains &amp;quot;search?q&amp;quot;.It works fine in wireshark with gui in windows. However I get a variety of errors in windows comand-line tshark, like this:
D:\&amp;gt;tshark -r http.pcap -R &amp;quot;http.request.uri contains search?q&amp;quot; tshark: &amp;quot;?&amp;quot; was unexpected in this context. D:&amp;amp;gt;tshark -r http.pcap -R &#39;http.request.uri contains &amp;quot;search?q&amp;quot;&#39; tshark: Read filters were specified both with &amp;quot;-R&amp;quot; and with additional command-line argumentsWhen I remove the &amp;ldquo;?</description>
    </item>
    
    <item>
      <title>Exclude a request and its corresponding answer</title>
      <link>/questions/5243/exclude-a-request-and-its-corresponding-answer/</link>
      <pubDate>Tue, 26 Jul 2011 01:50:00 +0000</pubDate>
      
      <guid>/questions/5243/exclude-a-request-and-its-corresponding-answer/</guid>
      <description>Exclude a request and its corresponding answer  0 Hello All,
I hope someone can help me out with this issue I am facing. I had a question regarding Wireshark filters. I am trying to filter out packets according to &#34;Subscriber ID&#34;. However this attribute is only present in the &#34;Request&#34; packets. The &#34;Answer&#34; packets correspnding to these requests do not contain &#34;Subscriber ID&#34; attribute. As a result I end up having the packets of type &#34;</description>
    </item>
    
    <item>
      <title>What function(s) is used in wiretap to read/write packet files?</title>
      <link>/questions/5244/what-functions-is-used-in-wiretap-to-readwrite-packet-files/</link>
      <pubDate>Tue, 26 Jul 2011 01:58:00 +0000</pubDate>
      
      <guid>/questions/5244/what-functions-is-used-in-wiretap-to-readwrite-packet-files/</guid>
      <description>What function(s) is used in wiretap to read/write packet files?  0 1Hi all,
I am currently researching on how Wiretap in Wireshark reads the files (eg. pcap). I have gone through the README and README.developer but both of them yields no result. The Wireshark and Ethereal Network Protocol Analyzer Toolkit ebook does not explicitly show which function is called.
I have also gone through wtap.c, wtap.h and wtap.def but i still can&#39;t find my answer.</description>
    </item>
    
    <item>
      <title>Capability of PCAP library to filter up to the ss7 application layer?</title>
      <link>/questions/5247/capability-of-pcap-library-to-filter-up-to-the-ss7-application-layer/</link>
      <pubDate>Tue, 26 Jul 2011 03:17:00 +0000</pubDate>
      
      <guid>/questions/5247/capability-of-pcap-library-to-filter-up-to-the-ss7-application-layer/</guid>
      <description>Capability of PCAP library to filter up to the ss7 application layer?  0 1According to the ebook, pg 245(reader)/pg 222(book), the paragraph right above &#34;Writing Capture Filters&#34;, the author states that the PCAP library aka Capture Filter may not be as powerful as the Display Filter of Wireshark, resulting in the latter requires more execution time.
My question: is Capture Filter (libpcap / Winpcap) capable of filtering data as deep as the SS7 application layer.</description>
    </item>
    
    <item>
      <title>Network Byte and Host Byte Order Display formats</title>
      <link>/questions/5249/network-byte-and-host-byte-order-display-formats/</link>
      <pubDate>Tue, 26 Jul 2011 04:43:00 +0000</pubDate>
      
      <guid>/questions/5249/network-byte-and-host-byte-order-display-formats/</guid>
      <description>Network Byte and Host Byte Order Display formats  0 Hi,
I have been facing this issue for a very long time. I have a field (an integer) which is 00 00 24 20 in the byte stream. When I try to display it as decimal in my dissector, it shoes an incorrect value. That is because I want the dissector to take the value as 02 24 00 00 instead.</description>
    </item>
    
    <item>
      <title>Convert tvbuff_t* to unsigned char*</title>
      <link>/questions/5261/convert-tvbuff_t-to-unsigned-char/</link>
      <pubDate>Tue, 26 Jul 2011 08:16:00 +0000</pubDate>
      
      <guid>/questions/5261/convert-tvbuff_t-to-unsigned-char/</guid>
      <description>Convert tvbuff_t* to unsigned char*  0 Is there a nice clean way to convert tvbuff_t to an unsigned char? I am using an external library for some decryption and it accepts the unsigned char*. I was looking through the Wireshark source code but only came up with:
struct tvbuff; typedef struct tvbuff tvbuff_t;Which doesn&#39;t give me enough information to be able to convert, that is unless I can simply do a byte for byte conversion?</description>
    </item>
    
    <item>
      <title>Can I see where traffic is coming from</title>
      <link>/questions/5270/can-i-see-where-traffic-is-coming-from/</link>
      <pubDate>Tue, 26 Jul 2011 11:17:00 +0000</pubDate>
      
      <guid>/questions/5270/can-i-see-where-traffic-is-coming-from/</guid>
      <description>Can I see where traffic is coming from  0 I&#39;m troubleshooting a network where there&#39;s about 50 users. Some wired some wireless. They are having an issue where not all users can get on the wireless network at once. The switch shows that there is a lot of network traffic. How can I find out where the traffic is coming from using Wireshark?
wireless traffic networkasked 26 Jul &#39;11, 11:17</description>
    </item>
    
    <item>
      <title>Get Packet Length</title>
      <link>/questions/5277/get-packet-length/</link>
      <pubDate>Tue, 26 Jul 2011 12:28:00 +0000</pubDate>
      
      <guid>/questions/5277/get-packet-length/</guid>
      <description>Get Packet Length  0 I was able to retrieve my packet data as an unsigned char* with
gCharArray = tvb_get_string(tvb, 0, length);but I have no idea how to determine what &#39;length&#39; SHOULD be. My message type does not include any size information unfortunately. I want to grab the data from position 0 to the end of the data. How can I accomplish this?
Thank you for your time,
Brandon</description>
    </item>
    
    <item>
      <title>RemoteCreateInstance response</title>
      <link>/questions/5284/remotecreateinstance-response/</link>
      <pubDate>Tue, 26 Jul 2011 14:56:00 +0000</pubDate>
      
      <guid>/questions/5284/remotecreateinstance-response/</guid>
      <description>RemoteCreateInstance response  0 Hello, We have just recently installed our application on a windows 2008 server. My client connects to the server using dcom. On this server only (so far) we get errors saying that we can&#39;t find the server. This message is basically a catch all. I have setup a wireshark trace and captured the message using the protocol ISystemActivator with the information stating &#34;RemoteCreateInstance response&#34; . In looking at the message i see an HResult:Unknown (0x80004027) message.</description>
    </item>
    
    <item>
      <title>Feature request - &amp;quot;previous display filter&amp;quot;?</title>
      <link>/questions/5291/feature-request-previous-display-filter/</link>
      <pubDate>Tue, 26 Jul 2011 19:36:00 +0000</pubDate>
      
      <guid>/questions/5291/feature-request-previous-display-filter/</guid>
      <description>Feature request - &amp;ldquo;previous display filter&amp;rdquo;?  3 1I often use a display filter (e.g. &#34;ssl.record.content_type==21&#34; to get a list of packets for further inspection. If I then use &#39;Follow TCP Stream&#39; or the like, I have to go back to the display filter dialog and reselect &#34;ssl.record.content-type==21&#34; again (and hit Apply) to get back to my &#39;master list&#39; of curious packets.
How about something like a &#34;back button&#34; that would simply go back to the previous display filter?</description>
    </item>
    
    <item>
      <title>wireshark graphs</title>
      <link>/questions/5295/wireshark-graphs/</link>
      <pubDate>Tue, 26 Jul 2011 23:25:00 +0000</pubDate>
      
      <guid>/questions/5295/wireshark-graphs/</guid>
      <description>wireshark graphs  0 While generating graphs i saw options like avg(), sum(), count(*) etc can anybody please tell me what exactly they represent.
graphsasked 26 Jul &#39;11, 23:25
sagu072
35●23●24●28
accept rate: 0%
i got the answer http://www.wireshark.org/docs/man-pages/wireshark.html
(27 Jul &#39;11, 00:37) sagu0721If you&#39;ve found the answer, why not make an answer with the link and mark it accepted?
(27 Jul &#39;11, 07:35) multipleinte...  
One Answer:</description>
    </item>
    
    <item>
      <title>How to capture DNS packets for external addresses</title>
      <link>/questions/5303/how-to-capture-dns-packets-for-external-addresses/</link>
      <pubDate>Wed, 27 Jul 2011 02:53:00 +0000</pubDate>
      
      <guid>/questions/5303/how-to-capture-dns-packets-for-external-addresses/</guid>
      <description>How to capture DNS packets for external addresses  0 Hello,
As in the title, does anyone know how to capture the dns packets but only for external resources?
If I simply specify port 53, then it captures all the packets including the internal resources which are on 10.0.0.0/24 range. 10.0.0.0/24 is a range I need to exclude to capture only external resources.
I also tried port 53 and not dst net 10.</description>
    </item>
    
    <item>
      <title>Multiple monitor display issue</title>
      <link>/questions/5310/multiple-monitor-display-issue/</link>
      <pubDate>Wed, 27 Jul 2011 06:39:00 +0000</pubDate>
      
      <guid>/questions/5310/multiple-monitor-display-issue/</guid>
      <description>Multiple monitor display issue  0 I have 2 monitors - a 30 inch and a 20 inch. The 20 inch is positioned &#34;above and to the right&#34; of my 30 inch. I mean that it is physically placed above and to the right of my 30 inch. In the XP display properties the 20 inch monitor is placed in the same manner so that with a diagonal mouse move I can go from the upper right corner of my 30 inch to the lower left corner of my 20 inch.</description>
    </item>
    
    <item>
      <title>Get parent node of a proto_tree</title>
      <link>/questions/5314/get-parent-node-of-a-proto_tree/</link>
      <pubDate>Wed, 27 Jul 2011 07:51:00 +0000</pubDate>
      
      <guid>/questions/5314/get-parent-node-of-a-proto_tree/</guid>
      <description>Get parent node of a proto_tree  0 Is there a way to grab a child proto_tree&#39;s parent proto_tree?
Thank you for your time,
Brandon
node traverse proto_tree parent childasked 27 Jul &#39;11, 07:51
officialhopsof
31●8●8●12
accept rate: 100%
 edited 27 Jul &#39;11, 07:52 
  
One Answer:
  
1 See proto_item_get_parent() in proto.h
Update: Upon doing some research: I think that the code to get the parent_proto_tree is as follows:</description>
    </item>
    
    <item>
      <title>How to extract flv video from capture pakets.</title>
      <link>/questions/5325/how-to-extract-flv-video-from-capture-pakets/</link>
      <pubDate>Wed, 27 Jul 2011 11:13:00 +0000</pubDate>
      
      <guid>/questions/5325/how-to-extract-flv-video-from-capture-pakets/</guid>
      <description>How to extract flv video from capture pakets.  1 Hello Everyone, I have captured a few packets of a video file(flv, from youtube). I stopped capturing the packets after playing a few seconds of it. from the captured packets how can i extract the chunk of video seen. ?
Thanks, Arjun
capture flv packets youtube wiresharkasked 27 Jul &#39;11, 11:13
Arjun
20●2●2●4
accept rate: 0%
 edited 29 Sep &#39;11, 11:21</description>
    </item>
    
    <item>
      <title>Cannot see Interface in preferences</title>
      <link>/questions/5331/cannot-see-interface-in-preferences/</link>
      <pubDate>Wed, 27 Jul 2011 16:55:00 +0000</pubDate>
      
      <guid>/questions/5331/cannot-see-interface-in-preferences/</guid>
      <description>Cannot see Interface in preferences  0 I just installed wireshark on my Linux Mint 10 workstation and when I select interfaces I do not see anything there. There are no options.
interfaceasked 27 Jul &#39;11, 16:55
socratease
1●1●1●1
accept rate: 0%
  
2 Answers:
  
2See the Wireshark Wiki:
Capture Setup and
Capture Setup/Capture Privileges
answered 27 Jul &#39;11, 18:05
Bill Meier ♦♦
3.2k●1●8●50
accept rate: 17%</description>
    </item>
    
    <item>
      <title>Functions involved in the Dissecting Process [Header files and examples]</title>
      <link>/questions/5334/functions-involved-in-the-dissecting-process-header-files-and-examples/</link>
      <pubDate>Wed, 27 Jul 2011 20:09:00 +0000</pubDate>
      
      <guid>/questions/5334/functions-involved-in-the-dissecting-process-header-files-and-examples/</guid>
      <description>Functions involved in the Dissecting Process [Header files and examples]  0 1According to the book pg 468 (reader) / pg 440 (book), under the title of &#34; The Dissection Process&#34; I was unable to locate which header files that some of the functions belongs to:
dissect_frame()dissect_try_port()May i know to which header files that these functions belong to?
Is there any tutorials or guidelines out there on how to use the functions?</description>
    </item>
    
    <item>
      <title>Should size of file increase when saved on disk after extracting from packets</title>
      <link>/questions/5341/should-size-of-file-increase-when-saved-on-disk-after-extracting-from-packets/</link>
      <pubDate>Thu, 28 Jul 2011 07:08:00 +0000</pubDate>
      
      <guid>/questions/5341/should-size-of-file-increase-when-saved-on-disk-after-extracting-from-packets/</guid>
      <description>Should size of file increase when saved on disk after extracting from packets  0 I captured a JFIF image packet of 2817 Bytes. Out of which image was of 2497 Bytes. By using option &#34;export selected packet bytes&#34; in wireshark, i extracted the file to my disk. The disk size is also 2497 bytes. Should not it expand as in network transmission it was compressed by GZIP. How the size is still the same after decompressing it.</description>
    </item>
    
    <item>
      <title>tshark output and ldap.response_in</title>
      <link>/questions/5344/tshark-output-and-ldapresponse_in/</link>
      <pubDate>Thu, 28 Jul 2011 08:23:00 +0000</pubDate>
      
      <guid>/questions/5344/tshark-output-and-ldapresponse_in/</guid>
      <description>tshark output and ldap.response_in  0 I have configured my Default profile to include a custom field for the ldap.response_in value. In Wireshark, it works great, but in tshark, the values are empty. This Windows command line returns empty lines for the 6 hits on &#34;ldap.request || ldap.response&#34; filter:
&amp;gt; tshark.exe -r ldap.pcap &amp;quot;ldap.bindRequest || ldap.bindResponse&amp;quot; -o column.format:&amp;quot;&amp;quot;Response&amp;quot; &amp;quot;In&amp;quot;, &amp;quot;%Cus:ldap.response_in&amp;quot;&amp;quot;Ideas?
windows display-filter tshark ldapasked 28 Jul &#39;11, 08:23
ivanh
1●1●1●1</description>
    </item>
    
    <item>
      <title>Comparison of packet captures</title>
      <link>/questions/5352/comparison-of-packet-captures/</link>
      <pubDate>Thu, 28 Jul 2011 11:59:00 +0000</pubDate>
      
      <guid>/questions/5352/comparison-of-packet-captures/</guid>
      <description>Comparison of packet captures  0 Ideally I want to be able to use something like the compare feature but with the ability to be more specific.
A good example would be to take two responses to an identical request and get the differences in the responses highlighted with the ability to filter out differences I don&#39;t care about.
comparison differentasked 28 Jul &#39;11, 11:59
Brandon
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Windows 2000 SP4 and WIreshark</title>
      <link>/questions/5354/windows-2000-sp4-and-wireshark/</link>
      <pubDate>Thu, 28 Jul 2011 15:33:00 +0000</pubDate>
      
      <guid>/questions/5354/windows-2000-sp4-and-wireshark/</guid>
      <description>Windows 2000 SP4 and WIreshark  0 This is more of a solution to anyone else forced to run Wireshark on obsoleted Windows 2000. After several hours I was able to get Wireshark 1.2.5 running with Windows 2000 SP4. I read several posts before I came upon the recommendation that this combination works -- it does! I hope someone else benefits from this post.
wireshark1.2.5 sp4 windows2000asked 28 Jul &#39;11, 15:33</description>
    </item>
    
    <item>
      <title>New Wireshark Mirror: Internet Gateway of South Beach</title>
      <link>/questions/5355/new-wireshark-mirror-internet-gateway-of-south-beach/</link>
      <pubDate>Thu, 28 Jul 2011 19:07:00 +0000</pubDate>
      
      <guid>/questions/5355/new-wireshark-mirror-internet-gateway-of-south-beach/</guid>
      <description>New Wireshark Mirror: Internet Gateway of South Beach  0 Good afternoon,
We&#39;d like to be added to the Wireshark mirrors list, as we&#39;ve been mirroring the site for the past week and we&#39;re on the mailing list.
We&#39;re proud to give something back to the community and your great project. If your group is in need of an additional dedicated server or VPS, please let us know, we&#39;re happy to contribute to a great project such as yours; I&#39;ve personally found Wireshark useful, as I&#39;m a user since day one (and before, with Ethereal) or quite some time for the past 10 years.</description>
    </item>
    
    <item>
      <title>Reconsruction HTTP , FTP packets with wireshark</title>
      <link>/questions/5357/reconsruction-http-ftp-packets-with-wireshark/</link>
      <pubDate>Fri, 29 Jul 2011 02:15:00 +0000</pubDate>
      
      <guid>/questions/5357/reconsruction-http-ftp-packets-with-wireshark/</guid>
      <description>Reconsruction HTTP , FTP packets with wireshark  0 As I know , I can reconstruct voip call.
How about the https and ftp traffic ?
If yes , Please let me know the way ?
Thanks,
playbackasked 29 Jul &#39;11, 02:15
yves
1●1●1●1
accept rate: 0%
  
One Answer:
  
0For HTTP you can use File -&amp;gt; Export -&amp;gt; Objects -&amp;gt; HTTP.
For FTP locate the TCP-Session with FTP-Data, Right-click on a packet of the connection and choose Follow TCP-Stream.</description>
    </item>
    
    <item>
      <title>RTP Stream Analysis shows 0.00 delta and jitter values</title>
      <link>/questions/5358/rtp-stream-analysis-shows-000-delta-and-jitter-values/</link>
      <pubDate>Fri, 29 Jul 2011 02:44:00 +0000</pubDate>
      
      <guid>/questions/5358/rtp-stream-analysis-shows-000-delta-and-jitter-values/</guid>
      <description>RTP Stream Analysis shows 0.00 delta and jitter values  0 When analysing individual RTP streams all the colums which should contain ms values are showing 0.00 as with the summary data, e.g. Max delta = 0.00 ms at packet no. 0 Max jitter = 0.00 ms. Mean jitter = 0.00 ms. Max skew = 0.00 ms. Total RTP packets = 336 (expected 336) Lost RTP packets = 0 (0.00%) Sequence errors = 0 Duration 6.</description>
    </item>
    
    <item>
      <title>Runtime error during launching</title>
      <link>/questions/5362/runtime-error-during-launching/</link>
      <pubDate>Fri, 29 Jul 2011 10:53:00 +0000</pubDate>
      
      <guid>/questions/5362/runtime-error-during-launching/</guid>
      <description>Runtime error during launching  0 After installation I try to launch the application and a get this error: http://www.image-share.com/upload/814/188.jpg
Already reboot the PC (WinXP 32bit P4 HT 3Ghz 1GB RAM) windows startup crashasked 29 Jul &#39;11, 10:53
Gabriel Venturi
1●1●1●1
accept rate: 0%
 edited 29 Jul &#39;11, 12:00 
helloworld
3.1k●4●20●41
  
One Answer:
  
1Try re-installing Wireshark (and WinPcap) as indicated in the duplicates:</description>
    </item>
    
    <item>
      <title>display filter for established and active tcp connections only</title>
      <link>/questions/5366/display-filter-for-established-and-active-tcp-connections-only/</link>
      <pubDate>Sat, 30 Jul 2011 00:57:00 +0000</pubDate>
      
      <guid>/questions/5366/display-filter-for-established-and-active-tcp-connections-only/</guid>
      <description>display filter for established and active tcp connections only  0 display filter for established and active tcp connections only
display-filterasked 30 Jul &#39;11, 00:57
ams
1●1●1●1
accept rate: 0%
2I can guess what your question is, but it&#39;s better if you ask it.
(01 Aug &#39;11, 16:13) helloworld  
One Answer:
  
1See bug 1184.
answered 01 Aug &#39;11, 18:06
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%</description>
    </item>
    
    <item>
      <title>Reading a Gb trace</title>
      <link>/questions/5375/reading-a-gb-trace/</link>
      <pubDate>Mon, 01 Aug 2011 05:53:00 +0000</pubDate>
      
      <guid>/questions/5375/reading-a-gb-trace/</guid>
      <description>Reading a Gb trace  0 hello,
There is a little confusion on how to decode and filter the Gb over IP trace. earlier NSIP dissector was found but now there is no NSIP, though there is gprs-ns. but sometimes that is also not there.
gprs gboip gprs-ns gbasked 01 Aug &#39;11, 05:53
Rahul2909
1●2●2●3
accept rate: 0%
 edited 01 Aug &#39;11, 05:54 
If I remember correctly previously there was two dissectors for the same protocol packet-nsip.</description>
    </item>
    
    <item>
      <title>wireshark 1.6.1 - title shows &amp;quot;SVN Rev Unknown from unknown&amp;quot;</title>
      <link>/questions/5376/wireshark-161-title-shows-svn-rev-unknown-from-unknown/</link>
      <pubDate>Mon, 01 Aug 2011 07:28:00 +0000</pubDate>
      
      <guid>/questions/5376/wireshark-161-title-shows-svn-rev-unknown-from-unknown/</guid>
      <description>wireshark 1.6.1 - title shows &amp;ldquo;SVN Rev Unknown from unknown&amp;rdquo;  0 I downloaded the source code and installed with the following settings:
tar -xjf wireshark-1.6.1.tar.bz2 cd wireshark-1.6.1 ./configure --prefix=/usr --enable-threads --with-lua --with-ssl --enable-setuid-install make make installWhen I start wireshark, its title shows &#34;SVN Rev Unknown from unknown&#34;. Although it is not a problem, does someone know why this happens?
developmentasked 01 Aug &#39;11, 07:28
solohuang
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Dissector Runs on My computer, but not others</title>
      <link>/questions/5377/dissector-runs-on-my-computer-but-not-others/</link>
      <pubDate>Mon, 01 Aug 2011 09:41:00 +0000</pubDate>
      
      <guid>/questions/5377/dissector-runs-on-my-computer-but-not-others/</guid>
      <description>Dissector Runs on My computer, but not others  0 I compiled the AMIN dissector as given at:
http://www.codeproject.com/KB/IP/custom_dissector.aspx
The dissector dll runs fine on both my compiled version and the binary version posted on The wireshark website under the downloads section (both are on the same computer). When I copy the amin.dll over to my coworkers computer, and place it under
&#34;C:Document and SettingsJohn SmithApplication DataWiresharkpluginsamin.dll&#34;
and then run Wireshark, it tells me</description>
    </item>
    
    <item>
      <title>Configuration for Cisco VPN ASA</title>
      <link>/questions/5379/configuration-for-cisco-vpn-asa/</link>
      <pubDate>Mon, 01 Aug 2011 11:55:00 +0000</pubDate>
      
      <guid>/questions/5379/configuration-for-cisco-vpn-asa/</guid>
      <description>Configuration for Cisco VPN ASA  0 I&#39;m trying to configure WireShark to pickup the inbound traffic on my Cisco ASA Concentrator. When i launch Wireshark it automatically picks up my local adapters. How can I configure WireShark to pickup the traffic on my ASA&#39;s adapter?
asaasked 01 Aug &#39;11, 11:55
c1n29
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1See http://wiki.wireshark.org/CaptureSetup.
answered 01 Aug &#39;11, 19:15</description>
    </item>
    
    <item>
      <title>Custom dissector and info column</title>
      <link>/questions/5382/custom-dissector-and-info-column/</link>
      <pubDate>Mon, 01 Aug 2011 14:34:00 +0000</pubDate>
      
      <guid>/questions/5382/custom-dissector-and-info-column/</guid>
      <description>Custom dissector and info column  0 Hi,
I must admit I am very new to wireshark, but I have read a lot of material of the last few days and this problem has me stumped.
I have written a custom dissector plugin to handle an XCP protocol. This consists of PDUs on TCP and I am using the tcp_dissect_pdus function to handle the reassembly of TCP packets to allow successful dissecting of my PDUs.</description>
    </item>
    
    <item>
      <title>Follow multiple TCP streams</title>
      <link>/questions/5396/follow-multiple-tcp-streams/</link>
      <pubDate>Tue, 02 Aug 2011 05:02:00 +0000</pubDate>
      
      <guid>/questions/5396/follow-multiple-tcp-streams/</guid>
      <description>Follow multiple TCP streams  0 Is there any easy way to follow more than one TCP stream? The &#39;Follow TCP Stream&#39; will decode the data asociated with a single stream, and display by itself. However I have cases where data is effectively multiplexed over multiple TCP connections, and where I&#39;d like to arrange all the data chronologically. I can - of course - try to view each stream and correlate against packet times, but this isn&#39;t as easy and is prone to user error.</description>
    </item>
    
    <item>
      <title>Exporting multiple audio/mpeg packets</title>
      <link>/questions/5397/exporting-multiple-audiompeg-packets/</link>
      <pubDate>Tue, 02 Aug 2011 05:41:00 +0000</pubDate>
      
      <guid>/questions/5397/exporting-multiple-audiompeg-packets/</guid>
      <description>Exporting multiple audio/mpeg packets  0 I&#39;m new to writing Lua scripts in Wireshark, so maybe my question is stupid, but is it possible to write a Lua script that will export all audio/mpeg packets from a capture? I can do this manually in Wireshark by applying a display filter (http.content_type == &#34;audio/mpeg&#34;), then right-clicking each Media Type in the Packet Details window, and then selecting &#39;Export selected packet bytes&#39;.</description>
    </item>
    
    <item>
      <title>prefix udp payload length after &amp;quot;follow UDP Stream&amp;quot;</title>
      <link>/questions/5403/prefix-udp-payload-length-after-follow-udp-stream/</link>
      <pubDate>Tue, 02 Aug 2011 09:23:00 +0000</pubDate>
      
      <guid>/questions/5403/prefix-udp-payload-length-after-follow-udp-stream/</guid>
      <description>prefix udp payload length after &amp;ldquo;follow UDP Stream&amp;rdquo;  0 I have a .pcap file after capturing voice packets. I now want to filter RTP packets (with header). When I select stream I am interested in and do &#34;follow UDP stream&#34; I get the udp payload (RTP including the header). But for all the packets captured there is no packet size. My application would want a 4 byte &#34;packet length&#34; before each packet.</description>
    </item>
    
    <item>
      <title>Warning click over display filters? What is solution?</title>
      <link>/questions/5405/warning-click-over-display-filters-what-is-solution/</link>
      <pubDate>Tue, 02 Aug 2011 09:57:00 +0000</pubDate>
      
      <guid>/questions/5405/warning-click-over-display-filters-what-is-solution/</guid>
      <description>Warning click over display filters? What is solution?  0 When I click on any display filters in the display-filter textbox, this warning happens:
(lt-wireshark:4477): GLib-GObject-WARNING **: /build/buildd/glib2.0-2.24.1/gobj ct/gsignal.c:3079: signal name `depressed&amp;#39; is invalid for instance `0x8e39408&amp;#39;What is the solution?
Thanks.
warning ubuntuasked 02 Aug &#39;11, 09:57
Ignacio Rivera
1●2●2●3
accept rate: 0%
 edited 05 Aug &#39;11, 10:01 
helloworld
3.1k●4●20●41
What do you mean by &#34;click on ... display filters&#34;</description>
    </item>
    
    <item>
      <title>independently build a wireshark plugin. (outside the wireshark source code)</title>
      <link>/questions/5408/independently-build-a-wireshark-plugin-outside-the-wireshark-source-code/</link>
      <pubDate>Tue, 02 Aug 2011 15:08:00 +0000</pubDate>
      
      <guid>/questions/5408/independently-build-a-wireshark-plugin-outside-the-wireshark-source-code/</guid>
      <description>independently build a wireshark plugin. (outside the wireshark source code)  0 Hi, currently, I complete a wireshark plugin which works well in wireshark build environment (wireshark/plugin). However, I am thinking about can I build the plugin outside the wireshark which means I can compile my plugin without the wireshark source code and generate the .o and .la file?? Because I want to compile my plugin to binary library file (.</description>
    </item>
    
    <item>
      <title>Windows 7 Ethernet Adapter broadcast to Linksys E300 router</title>
      <link>/questions/5409/windows-7-ethernet-adapter-broadcast-to-linksys-e300-router/</link>
      <pubDate>Tue, 02 Aug 2011 15:28:00 +0000</pubDate>
      
      <guid>/questions/5409/windows-7-ethernet-adapter-broadcast-to-linksys-e300-router/</guid>
      <description>Windows 7 Ethernet Adapter broadcast to Linksys E300 router  0 I am new to Wireshark. I keep getting this request from my Windows 7 Ethernet Adapter to the router. When running Wireshark, I filter eth.type == 0x0806, I see the following.
Number - 37932 Time - 17:16:41.240610 Source - AsustekC_f5:9d:a0 Destination - Broadcast Protocol - ARP Length - 42
Info - Who has 192.168.1.102? Tell 192.168.1.100
The IP address is my laptop.</description>
    </item>
    
    <item>
      <title>What does arp 42 who has 192.168.1.1? tell 192.168.1.33 mean?</title>
      <link>/questions/5412/what-does-arp-42-who-has-19216811-tell-192168133-mean/</link>
      <pubDate>Tue, 02 Aug 2011 17:18:00 +0000</pubDate>
      
      <guid>/questions/5412/what-does-arp-42-who-has-19216811-tell-192168133-mean/</guid>
      <description>What does arp 42 who has 192.168.1.1? tell 192.168.1.33 mean?  1 What does this mean?
arp 42 who has 192.168.1.1? tell 192.168.1.33&#34;
arpasked 02 Aug &#39;11, 17:18
Sandra Wolfe
21●1●1●5
accept rate: 0%
 edited 02 Aug &#39;11, 17:19 
It seems my Samsung TV keeps sending these same ARP requests nonstop. what is weird is my samsung tv gets internet access just fine and when i check the Default Gateway on my TV it matches the default gateway of my router just fine.</description>
    </item>
    
    <item>
      <title>802.11 FCS computation and Annex G</title>
      <link>/questions/5413/80211-fcs-computation-and-annex-g/</link>
      <pubDate>Tue, 02 Aug 2011 18:50:00 +0000</pubDate>
      
      <guid>/questions/5413/80211-fcs-computation-and-annex-g/</guid>
      <description>802.11 FCS computation and Annex G  0 Hi,
I tried to check the CRC32 computation of WLAN MAC frames by the CRC32 function in the Wireshark code. For this test, I am using the test packets in Annex G of the 802.11 2007 spec, and the vector in H.6.4 CCMP of the same spec.
However, I don&#39;t get the result as written there, and I don&#39;t understand what I am doing wrong.</description>
    </item>
    
    <item>
      <title>Multiple packets in the same plugin</title>
      <link>/questions/5419/multiple-packets-in-the-same-plugin/</link>
      <pubDate>Wed, 03 Aug 2011 02:19:00 +0000</pubDate>
      
      <guid>/questions/5419/multiple-packets-in-the-same-plugin/</guid>
      <description>Multiple packets in the same plugin  0 Hi,
I have an issue. I have made a plugin for a protocol names View Change Messages. It is working fine. These messages can be seen on TCP port 7002. Now in response to these view messages, view accept and view reject messages are seen which are also on TCP port 7002. So I made a plugin (separate plugin) for view accept.</description>
    </item>
    
    <item>
      <title>Error 105 (net::ERR_NAME_NOT_RESOLVED)</title>
      <link>/questions/5420/error-105-neterr_name_not_resolved/</link>
      <pubDate>Wed, 03 Aug 2011 02:42:00 +0000</pubDate>
      
      <guid>/questions/5420/error-105-neterr_name_not_resolved/</guid>
      <description>Error 105 (net::ERR_NAME_NOT_RESOLVED)  0 After flushing my DNS, thinking it was the problem on why im not able to browse on the internet unfortunately it didn&#39;t worked, and having this error message: &#34;Error 105 (net::ERR_NAME_NOT_RESOLVED): Unable to resolve the server&#39;s DNS address.&#34; Please help, thanks in advance.
105 errorasked 03 Aug &#39;11, 02:42
Kane
1●2●2●3
accept rate: 0%
  
One Answer:
  
0I fail to find the relevance of this question to Wireshark.</description>
    </item>
    
    <item>
      <title>./configure is giving error on sun4v sparc SUNW 5.10</title>
      <link>/questions/5421/configure-is-giving-error-on-sun4v-sparc-sunw-510/</link>
      <pubDate>Wed, 03 Aug 2011 02:46:00 +0000</pubDate>
      
      <guid>/questions/5421/configure-is-giving-error-on-sun4v-sparc-sunw-510/</guid>
      <description>./configure is giving error on sun4v sparc SUNW 5.10  0 i am getting below error which doing ./configure on my Solaris server.
configure: error: change your path to search /usr/xpg4/bin or directory containing GNU sed before /usr/bin (and /bin and /usr/ucb)Please help as soon as possible.
development solarisasked 03 Aug &#39;11, 02:46
harshpandya88
1●3●3●5
accept rate: 0%
 edited 04 Aug &#39;11, 23:03 
helloworld
3.1k●4●20●41
wireshark FAQ has solved my error.</description>
    </item>
    
    <item>
      <title>feed a packet in hex string format into a dissecctor</title>
      <link>/questions/5422/feed-a-packet-in-hex-string-format-into-a-dissecctor/</link>
      <pubDate>Wed, 03 Aug 2011 03:12:00 +0000</pubDate>
      
      <guid>/questions/5422/feed-a-packet-in-hex-string-format-into-a-dissecctor/</guid>
      <description>feed a packet in hex string format into a dissecctor  0 1Hi all, I have a packet in hex string format, how do i create the three data format required (tvb, pinfo and tree) in order to pass it to a dissector? I have come across this mail and thought of using the function tvb_new_real_data but i have no idea how to use it.
Any help and guidance is appreciated.</description>
    </item>
    
    <item>
      <title>./configure gives error --&amp;gt; GTK&#43; version issue Solaris</title>
      <link>/questions/5426/configure-gives-error-gtk-version-issue-solaris/</link>
      <pubDate>Wed, 03 Aug 2011 03:49:00 +0000</pubDate>
      
      <guid>/questions/5426/configure-gives-error-gtk-version-issue-solaris/</guid>
      <description>./configure gives error &amp;ndash;&amp;gt; GTK+ version issue Solaris  0 *** Could not run GTK+ test program, checking why... *** The test program failed to compile or link. See the file config.log for the *** exact error that occured. This usually means GTK+ is incorrectly installed. configure: error: GTK+ 2.4 or later isn&amp;#39;t available, so Wireshark can&amp;#39;t be compiledPlease help guys......
development solarisasked 03 Aug &#39;11, 03:49
harshpandya88
1●3●3●5
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to decode Sybase Anywhere?</title>
      <link>/questions/5436/how-to-decode-sybase-anywhere/</link>
      <pubDate>Wed, 03 Aug 2011 06:07:00 +0000</pubDate>
      
      <guid>/questions/5436/how-to-decode-sybase-anywhere/</guid>
      <description>How to decode Sybase Anywhere?  0 Hi,
I got a trace with Sybase Anywhere traffic inside. The traffic flows through the tcp port 2638. If I configure the TDS dissector for this port the decode return for every packet &#34;Unknown Packet Type: 24&#34;. Is there a way to decode Sybase Anywhere traffic or to configure the TDS dissector?
Regards,
tds sybase anywhereasked 03 Aug &#39;11, 06:07
OPapep
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>make command gives error</title>
      <link>/questions/5447/make-command-gives-error/</link>
      <pubDate>Wed, 03 Aug 2011 07:55:00 +0000</pubDate>
      
      <guid>/questions/5447/make-command-gives-error/</guid>
      <description>make command gives error  0 make: Fatal error: Can&amp;#39;t find `makefile&amp;#39;: No such file or directorydevelopment make solaris configureasked 03 Aug &#39;11, 07:55
harshpandya88
1●3●3●5
accept rate: 0%
 edited 04 Aug &#39;11, 23:06 
helloworld
3.1k●4●20●41
You need to provide a lot more information than this and be much clearer in what it is you&#39;re asking.
(03 Aug &#39;11, 08:59) cmaynard ♦♦Have you run the configure script?
(03 Aug &#39;11, 13:39) Guy Harris ♦♦I believe he/she has run configure (based on related post).</description>
    </item>
    
    <item>
      <title>Saving Captures with a filter?</title>
      <link>/questions/5450/saving-captures-with-a-filter/</link>
      <pubDate>Wed, 03 Aug 2011 09:35:00 +0000</pubDate>
      
      <guid>/questions/5450/saving-captures-with-a-filter/</guid>
      <description>Saving Captures with a filter?  0 I captured traffic for a specific subnet, I need to be able to filter the output, and save the results so I can send the files off to the manufacturer.
Wireshark ver. 1.4.1
Example:
Capture filter: net 1.1.1.0/24
This captured a lot of packets, since I needed it to run until a failure in the hardware occurred, and it is random when they fail.</description>
    </item>
    
    <item>
      <title>Acme A-SBC - Med Ext and Sig Ext</title>
      <link>/questions/5455/acme-a-sbc-med-ext-and-sig-ext/</link>
      <pubDate>Wed, 03 Aug 2011 15:22:00 +0000</pubDate>
      
      <guid>/questions/5455/acme-a-sbc-med-ext-and-sig-ext/</guid>
      <description>Acme A-SBC - Med Ext and Sig Ext  0 Hi.
I know this is not the best place to ask, but so far, using Google, I didn&#39;t find any answer.
Appending to A-SBC, what does Med Ext and Sig Ext mean?
sbc ext sig acme medasked 03 Aug &#39;11, 15:22
wired
44●13●14●17
accept rate: 9%
  
One Answer:
  
0I found the answer - Sig = Signalling, Med = Media and Ext = External.</description>
    </item>
    
    <item>
      <title>How is elements of packet is inserted into tvb structure?</title>
      <link>/questions/5480/how-is-elements-of-packet-is-inserted-into-tvb-structure/</link>
      <pubDate>Wed, 03 Aug 2011 22:24:00 +0000</pubDate>
      
      <guid>/questions/5480/how-is-elements-of-packet-is-inserted-into-tvb-structure/</guid>
      <description>How is elements of packet is inserted into tvb structure?  1 1Hi.
With reference to this e-book chapter 8, page 430, Step 5: Create The Dissector, it is stated that &#34;The tvb structure is used to extract and decode the data contained in each element of the packet.&#34; And &#34;To acquire data from the packet, we used tvb_ get_ xxx functions.&#34; My question is, how is the actual process of extracting data from each element of the packet take place, like how is the element is inserted into the tvb structure?</description>
    </item>
    
    <item>
      <title>tvbuff_t* tvb_new_real_data()</title>
      <link>/questions/5483/tvbuff_t-tvb_new_real_data/</link>
      <pubDate>Thu, 04 Aug 2011 00:49:00 +0000</pubDate>
      
      <guid>/questions/5483/tvbuff_t-tvb_new_real_data/</guid>
      <description>tvbuff_t* tvb_new_real_data()  0 void tvb_set_real_data(tvbuff_t* tvb, const guint8* data, const guint length, const gint reported_length)Hi all, could i use the above function to create a tvb by passing a packet in hex string into its parameters?
Thanks
Regards,
Eddie Choo
developmentasked 04 Aug &#39;11, 00:49
eddie choo
66●9●17●15
accept rate: 66%
 edited 04 Aug &#39;11, 16:14 
helloworld
3.1k●4●20●41
1duplicate: feed a packet in hex string format into a dissecctor</description>
    </item>
    
    <item>
      <title>tshark -R -w problem</title>
      <link>/questions/5487/tshark-r-w-problem/</link>
      <pubDate>Thu, 04 Aug 2011 03:46:00 +0000</pubDate>
      
      <guid>/questions/5487/tshark-r-w-problem/</guid>
      <description>tshark -R -w problem  0 Hello,
i try to solve one problem.
I have one capture stream taken with tshark. In this file is many VOIP calls( SIP/RTP/G729 ).
In wireshark GUI i can do what i can, but when i try filter some call from cmd is there big problem.
When i use this:
tshark -r capturedfile -R &amp;quot;ip.src==10.1.0.11&amp;quot; -w call.rawI get right (SIP, UPD, TCP etc...) load in call.</description>
    </item>
    
    <item>
      <title>DNS and ssh tunnelling</title>
      <link>/questions/5495/dns-and-ssh-tunnelling/</link>
      <pubDate>Thu, 04 Aug 2011 06:22:00 +0000</pubDate>
      
      <guid>/questions/5495/dns-and-ssh-tunnelling/</guid>
      <description>DNS and ssh tunnelling  0 Hi..I have an ssh server setup at home which I&#39;m using to tunnel from work.I&#39;m mainly just trying to learn I&#39;m not trying to bypass anything at work since I think they could care less and I don&#39;t really go anywhere but youtube to listen to songs while I work. but anyway, I know the tunneling is working because my company blocks fedoraforum.org and I can get to it just fine.</description>
    </item>
    
    <item>
      <title>Source  or destination is an address Mac</title>
      <link>/questions/5507/source-or-destination-is-an-address-mac/</link>
      <pubDate>Thu, 04 Aug 2011 15:50:00 +0000</pubDate>
      
      <guid>/questions/5507/source-or-destination-is-an-address-mac/</guid>
      <description>Source or destination is an address Mac  0 Hello, I have used Wireshark for a few days and I noticed each connection is related to a Mac Address : Cisco_ec:ba:92 (00:0d:29:ec:ba:92). It appears as destination if I initiate the connection or as source if not. I contacted my ISP (Videotron) and they don&#39;t identify their equipment by their mac addresses and they don&#39;t seem to understand what is going on.</description>
    </item>
    
    <item>
      <title>[Malformed Packet: RADIUS]</title>
      <link>/questions/5526/malformed-packet-radius/</link>
      <pubDate>Fri, 05 Aug 2011 07:09:00 +0000</pubDate>
      
      <guid>/questions/5526/malformed-packet-radius/</guid>
      <description>[Malformed Packet: RADIUS]  0 After settting up a trace i found this error :
User Datagram Protocol, Src Port: 23361 (23361), Dst Port: radius-acct (1813) [Malformed Packet: RADIUS] [Expert Info (Error/Malformed): Malformed Packet (Exception occurred)] [Message: Malformed Packet (Exception occurred)] [Severity level: Error] [Group: Malformed]what could be the cause?
malformedpacketasked 05 Aug &#39;11, 07:09
jay
1●1●1●1
accept rate: 0%
 edited 05 Aug &#39;11, 07:22 
SYN-bit ♦♦
17.1k●9●57●245</description>
    </item>
    
    <item>
      <title>Decode the VSA 3GPP-GPRS-Negotiated-QoS-profile</title>
      <link>/questions/5528/decode-the-vsa-3gpp-gprs-negotiated-qos-profile/</link>
      <pubDate>Fri, 05 Aug 2011 07:26:00 +0000</pubDate>
      
      <guid>/questions/5528/decode-the-vsa-3gpp-gprs-negotiated-qos-profile/</guid>
      <description>Decode the VSA 3GPP-GPRS-Negotiated-QoS-profile  0 I think there is something wrong when decoding the 3GPP-GPRS-Negotiated-QoS-profile in Access-Request message. According to the 3gpp specification TS 29.061 (v9.6.0), for Release 8 or higher version QoS, the QoS information should contain: -QCI -ARP -GBR QoS Information (MBR, GBR or APN-AMBR)
However the Wireshark decode the Release 8 QoS as: UMTS GTP Qos Profile: -Version -Hyphen separator -Spare -QoS delay -QoS reliability ...</description>
    </item>
    
    <item>
      <title>[RST, ACK] immediately after sending data?</title>
      <link>/questions/5533/rst-ack-immediately-after-sending-data/</link>
      <pubDate>Fri, 05 Aug 2011 10:44:00 +0000</pubDate>
      
      <guid>/questions/5533/rst-ack-immediately-after-sending-data/</guid>
      <description>[RST, ACK] immediately after sending data?  0 1Hi,
I&#39;m trying to figure out a problem where I&#39;m getting multiple socket exceptions on client machines on the network. Clients always connect to the server, send some data and the server always sends some data back to every client. I&#39;ve run a prolonged capture and I&#39;m seeing that when the problem occurs, the server seems to be sending the data back to the client, but almost immediately after that the server sends an RST+ACK packet, as shown below:</description>
    </item>
    
    <item>
      <title>Version 1.7/64 Bit issue on W7 pc</title>
      <link>/questions/5534/version-1764-bit-issue-on-w7-pc/</link>
      <pubDate>Fri, 05 Aug 2011 10:57:00 +0000</pubDate>
      
      <guid>/questions/5534/version-1764-bit-issue-on-w7-pc/</guid>
      <description>Version 1.7/64 Bit issue on W7 pc  0 I have downloaded the new 1.7 for 64 bit machines and when running the app it showed 1.4.6 32 bit was there instead. I loaded the 1.6.1 / 64bit stable and it took fine. Any ideas? My OS = W7Pro
windows7 64-bitasked 05 Aug &#39;11, 10:57
EricKnaus
46●19●20●26
accept rate: 0%
 edited 28 Feb &#39;12, 20:05 
cmaynard ♦♦
9.4k●10●38●142</description>
    </item>
    
    <item>
      <title>ARP request with invalid target MAC address</title>
      <link>/questions/5535/arp-request-with-invalid-target-mac-address/</link>
      <pubDate>Fri, 05 Aug 2011 11:47:00 +0000</pubDate>
      
      <guid>/questions/5535/arp-request-with-invalid-target-mac-address/</guid>
      <description>ARP request with invalid target MAC address  0 I have a network capture that has excessive ARP traffic in it. It averages 150 to 250 ARP requests per second. The requests are cycling through all of the addresses on the subnet (255.255.254.0) in a random order.
The Ethernet II data shows the destination as a broadcast but the ARP details show the target as a specific invalid MAC address instead of all zeros.</description>
    </item>
    
    <item>
      <title>Slow Internet traffic</title>
      <link>/questions/5537/slow-internet-traffic/</link>
      <pubDate>Fri, 05 Aug 2011 13:20:00 +0000</pubDate>
      
      <guid>/questions/5537/slow-internet-traffic/</guid>
      <description>Slow Internet traffic  0 How can I use wireshark to identify slow network proformance for only internet traffic? Also where is the internet traffic being delayed at. All LAN and WAN traffic for the most part is fast, however when it comes to internet traffic it becomes very very slow. I have installed wireshark on a server and capturing packets filtered with HTTP port 80 traffic. What would be the tell tell sign in the capture packets for internet traffice slowness.</description>
    </item>
    
    <item>
      <title>Preference Table updating from a file</title>
      <link>/questions/5546/preference-table-updating-from-a-file/</link>
      <pubDate>Sat, 06 Aug 2011 13:20:00 +0000</pubDate>
      
      <guid>/questions/5546/preference-table-updating-from-a-file/</guid>
      <description>Preference Table updating from a file  0 hello ! When i open some log , i want that certain information (such as IP and port number) get automatically populated into the the preference tables (the table has already been created). I am able to write the same information in a file using sprintf (in the required format) but dont know how to populate the preference table from the file. Can someone help me on this?</description>
    </item>
    
    <item>
      <title>Handling a more complex SSL session?</title>
      <link>/questions/5552/handling-a-more-complex-ssl-session/</link>
      <pubDate>Sun, 07 Aug 2011 06:30:00 +0000</pubDate>
      
      <guid>/questions/5552/handling-a-more-complex-ssl-session/</guid>
      <description>Handling a more complex SSL session?  0 Hi everyone,
I&#39;ve been using wireshark to record my packets to a service, with that I&#39;ve been able to find out my login data that was encrypted with a simple TLSv1 connection. Now the rest of the communication is done with a more secure TLS connection and I&#39;ve hit a solid wall.
The packets came up as TPKT in wireshark, after searching I read something about telling wireshark to handle them as SSL connections (because I could clearly see a digital certificate being sent) and all these connections changed to TSLv1 from TPKT and the certificate exchanges are sent via TCP between the handshakes.</description>
    </item>
    
    <item>
      <title>How do i find end to end delay for VoIP call?</title>
      <link>/questions/5558/how-do-i-find-end-to-end-delay-for-voip-call/</link>
      <pubDate>Sun, 07 Aug 2011 11:05:00 +0000</pubDate>
      
      <guid>/questions/5558/how-do-i-find-end-to-end-delay-for-voip-call/</guid>
      <description>How do i find end to end delay for VoIP call?  0 I have got trace from both ends. I have used sipgate.co.uk as sip provider and Xlite as soft phone. I need to do analysis of jitter, bandwidth, packet loss and roundtrip delay. I could successfully manage to get jitter but i am stuck in delay.. Please help asap. Thanking you
delay sip rtp voipasked 07 Aug &#39;11, 11:05</description>
    </item>
    
    <item>
      <title>Wireshark 1.7 display filtering on Multiple capture interfaces</title>
      <link>/questions/5565/wireshark-17-display-filtering-on-multiple-capture-interfaces/</link>
      <pubDate>Sun, 07 Aug 2011 21:35:00 +0000</pubDate>
      
      <guid>/questions/5565/wireshark-17-display-filtering-on-multiple-capture-interfaces/</guid>
      <description>Wireshark 1.7 display filtering on Multiple capture interfaces  0 Now that we can capture on two or more interfaces concurrently with 1.7, is there a way to create a dislay filter only on one or the other within the capture file? Or in the case of, say 4 ethernet interfaces, filter on the first 2 and not the last 2. Application (in my case), you have the main corp network and a separate segment for a test lab and yet another for the accounting dept.</description>
    </item>
    
    <item>
      <title>More detail in displaying information</title>
      <link>/questions/5574/more-detail-in-displaying-information/</link>
      <pubDate>Mon, 08 Aug 2011 07:52:00 +0000</pubDate>
      
      <guid>/questions/5574/more-detail-in-displaying-information/</guid>
      <description>More detail in displaying information  0 hello,
so i create a wireshark plugin. So all works really nice the dissection works and looks good.
BUT
1.How is it possible to add right click filtering. I mean if i click the right mouse button there will be the possibility to chosse the option just packets of type 2, you understand? So i want have an entry in the drop down menu after right click that filter like the filter bar on top but just with one or two defined filter options by me.</description>
    </item>
    
    <item>
      <title>Capturing multicast packets in Windows v. Linux</title>
      <link>/questions/5576/capturing-multicast-packets-in-windows-v-linux/</link>
      <pubDate>Mon, 08 Aug 2011 10:00:00 +0000</pubDate>
      
      <guid>/questions/5576/capturing-multicast-packets-in-windows-v-linux/</guid>
      <description>Capturing multicast packets in Windows v. Linux  0 I have a program on one computer that is sending multicast packets. I can see the packets in Wireshark on that same computer, and on a different computer while in Linux, but not while in Windows (it&#39;s dual-boot).
The sending computer is wired into a router. The receiving computer is wireless. I&#39;m using the same wireless NIC in both Linux and Windows.</description>
    </item>
    
    <item>
      <title>Email attachment filter question?</title>
      <link>/questions/5584/email-attachment-filter-question/</link>
      <pubDate>Tue, 09 Aug 2011 06:18:00 +0000</pubDate>
      
      <guid>/questions/5584/email-attachment-filter-question/</guid>
      <description>Email attachment filter question?  0 I have used Wireshark in University a little bit when I was studying Computer security and forensics. But now that I am employed as a IT security officer my company is looking at implementing a email monitoring solution on our network.
Does anyone know if it&#39;s possible for Wireshark to perform the following task?
Filter all SMTP traffic within a set IP range and show the destination address and attachment format.</description>
    </item>
    
    <item>
      <title>Decode ISUP Message Over TCP</title>
      <link>/questions/5586/decode-isup-message-over-tcp/</link>
      <pubDate>Tue, 09 Aug 2011 08:56:00 +0000</pubDate>
      
      <guid>/questions/5586/decode-isup-message-over-tcp/</guid>
      <description>Decode ISUP Message Over TCP  0 I want to know how i can decode ISUP China messages that were in the data field of TCP packets. for example decode the REL message that was in the data field of TCP.
over isup tcpasked 09 Aug &#39;11, 08:56
aMot
1●2●2●2
accept rate: 0%
How is the ISUP transported over TCP? Is it, for example, using TALI?
(09 Aug &#39;11, 11:12) Guy Harris ♦♦i prepare the SS7 signaling monitor hardware to monitor SS7 link then i send the SS7 Messages to another computer via TCP protocol.</description>
    </item>
    
    <item>
      <title>Wireshark installed to monitor outgoing email traffic</title>
      <link>/questions/5587/wireshark-installed-to-monitor-outgoing-email-traffic/</link>
      <pubDate>Tue, 09 Aug 2011 09:19:00 +0000</pubDate>
      
      <guid>/questions/5587/wireshark-installed-to-monitor-outgoing-email-traffic/</guid>
      <description>Wireshark installed to monitor outgoing email traffic  0 I have a network with about 20 pcs running mainly XP. We got blacklisted and can&#39;t send email out anymore. Internet provider said we are infected by the torpig virus. I installed wireshark on a pc to monitor traffice and I have 4 days of data but don&#39;t know what to look for. Canyone help with this? ISP said it was made through an IP 91.</description>
    </item>
    
    <item>
      <title>Building from source without internet</title>
      <link>/questions/5592/building-from-source-without-internet/</link>
      <pubDate>Tue, 09 Aug 2011 11:14:00 +0000</pubDate>
      
      <guid>/questions/5592/building-from-source-without-internet/</guid>
      <description>Building from source without internet  0 I&#39;m developing on a laptop without internet access. The problem arises when I enter nmake -f Makefile.nmake setup. I fail because it tries to use wget to get the library files from the internet.
I have all the appropriate library files on the laptop without internet, but where do I put them so wireshark can use them? Does anyone have a set of instructions to follow to build wireshark without internet?</description>
    </item>
    
    <item>
      <title>How to capture traffic from YouTube</title>
      <link>/questions/5597/how-to-capture-traffic-from-youtube/</link>
      <pubDate>Tue, 09 Aug 2011 12:50:00 +0000</pubDate>
      
      <guid>/questions/5597/how-to-capture-traffic-from-youtube/</guid>
      <description>How to capture traffic from YouTube  2 How do I capture packets sent only to YouTube and received only from YouTube? I want to check how YouTube streams its video, especially the live ones, so I want to capture only send&#39;s and receive&#39;s from YouTube. How do I do that?
capture-filterasked 09 Aug &#39;11, 12:50
Giu
31●1●1●3
accept rate: 0%
 edited 16 Aug &#39;11, 23:32 
helloworld
3.1k●4●20●41</description>
    </item>
    
    <item>
      <title>How can I filter streams that contain file downloads?</title>
      <link>/questions/5601/how-can-i-filter-streams-that-contain-file-downloads/</link>
      <pubDate>Tue, 09 Aug 2011 14:49:00 +0000</pubDate>
      
      <guid>/questions/5601/how-can-i-filter-streams-that-contain-file-downloads/</guid>
      <description>How can I filter streams that contain file downloads?  0 What filter can I use to obtain the streams associated to the objects that are listed when doing the following in Wireshark? - File/Export/Objects/HTTP
Thank you in advance!
filter http streamsasked 09 Aug &#39;11, 14:49
Migdalia
1●1●1●1
accept rate: 0%
 edited 29 Feb &#39;12, 19:13 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
0The filter &#34;</description>
    </item>
    
    <item>
      <title>Home computer</title>
      <link>/questions/5606/home-computer/</link>
      <pubDate>Tue, 09 Aug 2011 19:13:00 +0000</pubDate>
      
      <guid>/questions/5606/home-computer/</guid>
      <description>Home computer  0 My roomate just announced he installed wireshark on our home network. He claims &#34;for security&#34; but from what? Anyways, is there a way to block him from reading my network traffic if we are on the same router? We have Comcast cable if that helps. What can I do o protect my privacy outside of asking him to remove the software?
encryption securityasked 09 Aug &#39;11, 19:13</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t save payload in both directions</title>
      <link>/questions/5609/cant-save-payload-in-both-directions/</link>
      <pubDate>Tue, 09 Aug 2011 20:36:00 +0000</pubDate>
      
      <guid>/questions/5609/cant-save-payload-in-both-directions/</guid>
      <description>can&amp;rsquo;t save payload in both directions  0 i have the latest stable version 1.6.1 installed. i&#39;m trying to extract audio from a VoIP call. unfortunately, i&#39;m able to save in either forward or reversed direction but not both. when attempting to save in .au format i get the following error: &#34;can&#39;t save in a file: saving in au format supported for alaw/ulaw streams&#34;
when attempted to save in .raw format i get the following error: &#34;</description>
    </item>
    
    <item>
      <title>Disable protocol dissection in tshark?</title>
      <link>/questions/5613/disable-protocol-dissection-in-tshark/</link>
      <pubDate>Tue, 09 Aug 2011 22:45:00 +0000</pubDate>
      
      <guid>/questions/5613/disable-protocol-dissection-in-tshark/</guid>
      <description>Disable protocol dissection in tshark?  0 Is there a hidden parameter I can use with tshark to disable the dissection of some protocol? Sure, I can edit the disabled protocols file, but I&#39;m wondering if there&#39;s a more &#34;dynamic&#34; way to disable a protocol.
Thanks!
disable tsharkasked 09 Aug &#39;11, 22:45
r0u1i
61●7●7●12
accept rate: 0%
  
One Answer:
  
0 There&#39;s no tshark &#34;hidden parameter&#34;</description>
    </item>
    
    <item>
      <title>Decode nbUP over RTP (PT=dynamicRTP-Type-96)</title>
      <link>/questions/5616/decode-nbup-over-rtp-ptdynamicrtp-type-96/</link>
      <pubDate>Wed, 10 Aug 2011 00:55:00 +0000</pubDate>
      
      <guid>/questions/5616/decode-nbup-over-rtp-ptdynamicrtp-type-96/</guid>
      <description>Decode nbUP over RTP (PT=dynamicRTP-Type-96)  0 Hello,
How to decode nbUP over RTP (PT=dynamicRTP-Type-96)? Thank you.
nbupasked 10 Aug &#39;11, 00:55
Tritops
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Hi, NbUP is the same as IuUP I think - set the RTP PT preference in the IuUP protocol preference.
answered 10 Aug &#39;11, 10:20
Anders ♦
4.6k●9●52
accept rate: 17%
Thanks, Anders. I will try your suggestion.</description>
    </item>
    
    <item>
      <title>Newbie question on finding out why application not connecting to server</title>
      <link>/questions/5618/newbie-question-on-finding-out-why-application-not-connecting-to-server/</link>
      <pubDate>Wed, 10 Aug 2011 05:18:00 +0000</pubDate>
      
      <guid>/questions/5618/newbie-question-on-finding-out-why-application-not-connecting-to-server/</guid>
      <description>Newbie question on finding out why application not connecting to server  0 I have a project where we are trying to figure out why client/server traffic is not making it across some segments of a client network. The systems were working, but then &#34;something&#34; was changed on the network and now they cannot connect. We think it has to do with TTL, but need to tack it down. We had a similar problem in the past and it was solved by a third party taking a wireshark trace from one location on the network where the client could connect to the server and then at a second location where the client could not connect and comparing them.</description>
    </item>
    
    <item>
      <title>My network traffic looks exactly like the dns-remoteshell.pcap. What now???</title>
      <link>/questions/5620/my-network-traffic-looks-exactly-like-the-dns-remoteshellpcap-what-now/</link>
      <pubDate>Wed, 10 Aug 2011 06:39:00 +0000</pubDate>
      
      <guid>/questions/5620/my-network-traffic-looks-exactly-like-the-dns-remoteshellpcap-what-now/</guid>
      <description>My network traffic looks exactly like the dns-remoteshell.pcap. What now???  0 Okay, so I am having problems with a Fedora Core 14 Linux machine. I inherited it recently from my late brother and while he was a Linux GOD, I am merely a mortal. I know something, somewhat about Linux from my days as a contributing editor at Newsforge (talk about embarrassing, asking this when I used to WRITE about Linux), but I do not know enough to solve this problem.</description>
    </item>
    
    <item>
      <title>CFM decoder</title>
      <link>/questions/5622/cfm-decoder/</link>
      <pubDate>Wed, 10 Aug 2011 08:18:00 +0000</pubDate>
      
      <guid>/questions/5622/cfm-decoder/</guid>
      <description>CFM decoder  0 Is cfm packet decoder supported in Wireshark 1.6.1.If affirmative, could you please provide steps on how to activate it?
Thanks very kindly
cfm 802.1xasked 10 Aug &#39;11, 08:18
jg2
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Wireshark has a dissector for CFM;
From the source code:
/* This code is based on the IEEE P802.1ag/D8.1 document, and on the ITU-T Y.1731 * recommendation (05/2006,) which is not formally released at the time of this * dissector development.</description>
    </item>
    
    <item>
      <title>Wireshark developers planning on building an iPad app?</title>
      <link>/questions/5627/wireshark-developers-planning-on-building-an-ipad-app/</link>
      <pubDate>Wed, 10 Aug 2011 09:29:00 +0000</pubDate>
      
      <guid>/questions/5627/wireshark-developers-planning-on-building-an-ipad-app/</guid>
      <description>Wireshark developers planning on building an iPad app?  0 Will the Wireshark developers release an iPad application?
ipadasked 10 Aug &#39;11, 09:29
kmcintosh78
1●1●1●1
accept rate: 0%
 edited 10 Aug &#39;11, 15:58 
Guy Harris ♦♦
17.4k●3●35●196
I highly doubt it. That requires too much development effort IMHO. Plus, I don&#39;t think Apple would ever approve it.
(10 Aug &#39;11, 10:44) bstnSo Pirni + a hypothetical iOS-ported Wireshark ver or equiv would still be pointless?</description>
    </item>
    
    <item>
      <title>analysing intermittent problems with DNS forwarder m0n0wall</title>
      <link>/questions/5631/analysing-intermittent-problems-with-dns-forwarder-m0n0wall/</link>
      <pubDate>Wed, 10 Aug 2011 14:13:00 +0000</pubDate>
      
      <guid>/questions/5631/analysing-intermittent-problems-with-dns-forwarder-m0n0wall/</guid>
      <description>analysing intermittent problems with DNS forwarder m0n0wall  0 Hi, i&#39;ve setup a &#39;private subnet&#39; in my home network. I have a &#39;server&#39; which has two nic&#39;s eth0 is connected to the ADSL modem/router and eth1 is connected to a switch connecting all pc&#39;s on the subnet.
The server runs vmware server and runs 3 VM&#39;s: - ubuntu bridged to eth0 - ubuntu bridged to eth1 - m0n0wall which acts as the firewall/gateway/dhcp server for the subnet.</description>
    </item>
    
    <item>
      <title>ERF header type IP_COUNTER</title>
      <link>/questions/5642/erf-header-type-ip_counter/</link>
      <pubDate>Wed, 10 Aug 2011 22:37:00 +0000</pubDate>
      
      <guid>/questions/5642/erf-header-type-ip_counter/</guid>
      <description>ERF header type IP_COUNTER  0 Hi All !
In erf.h at the list of ERF headers, there is:
#define ERF_TYPE_IP_COUNTER 13Does anyone know what it is? What is it for?
Thanks,
Hagay
developmentasked 10 Aug &#39;11, 22:37
Halili
1●1●1●1
accept rate: 0%
 edited 16 Aug &#39;11, 23:26 
helloworld
3.1k●4●20●41
  
One Answer:
  
1Yes, Endace, the creator of the ERF file format and thus of the ERF header, does.</description>
    </item>
    
    <item>
      <title>&amp;quot;Unreassembled Packet (Exception occurred)&amp;quot; error message</title>
      <link>/questions/5650/unreassembled-packet-exception-occurred-error-message/</link>
      <pubDate>Thu, 11 Aug 2011 08:54:00 +0000</pubDate>
      
      <guid>/questions/5650/unreassembled-packet-exception-occurred-error-message/</guid>
      <description>&amp;ldquo;Unreassembled Packet (Exception occurred)&amp;rdquo; error message  0 While running Wireshark 1.4.4 I found that many of the TLSv1 messages were not being reassembled, but left as [Unreassembled Packet]/Ignored Unknown Record. Having checked the existing documentation on this, I made sure that in the TCP preferences, checksum validation is unchecked, and &#34;allow subdissector to reassemble TCP streams is checked.&#34; I also made sure that &#34;Reassemble SSL records spanning multiple TCP segements&#34;</description>
    </item>
    
    <item>
      <title>Can you get a 0.0Mb/s 802.11 transmission rate?</title>
      <link>/questions/5651/can-you-get-a-00mbs-80211-transmission-rate/</link>
      <pubDate>Thu, 11 Aug 2011 09:03:00 +0000</pubDate>
      
      <guid>/questions/5651/can-you-get-a-00mbs-80211-transmission-rate/</guid>
      <description>Can you get a 0.0Mb/s 802.11 transmission rate?  0 Hi,
My question is rather simple. Can you get a 0.0Mb/s data rate (per stream)?
I have multiple pcap files (165K of packets on average) with 802.11 traffic on them and I always seem to get a few tens of 802.11 data(only) packets showing 0.0Mb/s data rate (in the radiotap header).
As far as I am aware you can only get quantized data rate values (of 1, 2, 5.</description>
    </item>
    
    <item>
      <title>OSX Lion release?</title>
      <link>/questions/5652/osx-lion-release/</link>
      <pubDate>Thu, 11 Aug 2011 09:36:00 +0000</pubDate>
      
      <guid>/questions/5652/osx-lion-release/</guid>
      <description>OSX Lion release?  0 Do you know if your latest Snow Leopard compatible release is also compatible with OSX Lion, or do you have a projected release date for WS for Lion?
osx mac lionasked 11 Aug &#39;11, 09:36
mpreissner
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1It&#39;s mostly compatible with Lion, although if you scroll the packet list with a scroll-ball (rather than by dragging the scrollbar) or possibly with a trackpad, some rows in the packet list will show up as blank; if you move the mouse over them, they draw normally.</description>
    </item>
    
    <item>
      <title>DRDA not in the &amp;quot;Decode As&amp;quot; list?</title>
      <link>/questions/5653/drda-not-in-the-decode-as-list/</link>
      <pubDate>Thu, 11 Aug 2011 10:11:00 +0000</pubDate>
      
      <guid>/questions/5653/drda-not-in-the-decode-as-list/</guid>
      <description>DRDA not in the &amp;ldquo;Decode As&amp;rdquo; list?  0 Hello, I&#39;m trying to decode some DB2 traffic, but I&#39;m not finding a decode. It looks like there used to be a DRDA entry, but I don&#39;t see it on 1.6.1 (windows). Thanks for any info.
db2asked 11 Aug &#39;11, 10:11
RickE
1●1●1●1
accept rate: 0%
  
One Answer:
  
1I&#39;m not sure what you mean by &#34;</description>
    </item>
    
    <item>
      <title>UDP reassembly with multiple PDUs per packet</title>
      <link>/questions/5656/udp-reassembly-with-multiple-pdus-per-packet/</link>
      <pubDate>Thu, 11 Aug 2011 12:27:00 +0000</pubDate>
      
      <guid>/questions/5656/udp-reassembly-with-multiple-pdus-per-packet/</guid>
      <description>UDP reassembly with multiple PDUs per packet  1 I am writing a dissector for a UDP protocol with the following (rather unfortunate) features:
A single PDU may (and in most cases does) span multiple packets.A single header may also span multiple packetsA packet may also contain multiple PDUs, both complete and fragmentedThe length of a PDU is determined by a header field, but an unknown number of bytes must be read before getting to that value, as the header is preceded by a variable length delimiterThere are no sequence numbers or other ways of uniquely identifying a PDUThere is no flag indicating whether a PDU will be fragmented, or whether multiple PDUs will appear in a packet, other than by reading the lengthAll communications are between a single sender and receiverIn practice, this means that some assembly must be done before it is even possible to determine how much assembly will be needed to complete a PDU.</description>
    </item>
    
    <item>
      <title>How best to customize wireshark?</title>
      <link>/questions/5659/how-best-to-customize-wireshark/</link>
      <pubDate>Thu, 11 Aug 2011 16:06:00 +0000</pubDate>
      
      <guid>/questions/5659/how-best-to-customize-wireshark/</guid>
      <description>How best to customize wireshark?  0 At work, I currently have an application which uses the libpcap API to do packet sniffing of our internal TCP messages (and to do various things with the data that&#39;s sniffed). I am considering converting this application into an application that uses wireshark instead (since the visualization of the data that wireshark provides is great, and since I&#39;d like to take advantage of all of the other capabilities that wireshark provides).</description>
    </item>
    
    <item>
      <title>Wireshark and Fedora</title>
      <link>/questions/5660/wireshark-and-fedora/</link>
      <pubDate>Thu, 11 Aug 2011 19:32:00 +0000</pubDate>
      
      <guid>/questions/5660/wireshark-and-fedora/</guid>
      <description>Wireshark and Fedora  0 Dear Sir, I have downloaded and installed Wireshark on my netbook running Fedora 15, using the command: &#34;yum install wireshark-gnome&#34;. It has intalled with no errors. Though, when I run the program, it freezes, and I get the following message &#34;couldnt run /usr/sbin/dumpcap in child process: permission denied. Are you member of &#39;wireshark&#39; group? Try running &#39;usermod -a -G wireshark username as root&#34;. I&#39;m not member of Wireshark, and I didn&#39;t need it to run in Windows 7.</description>
    </item>
    
    <item>
      <title>Kerberos - NT Status: Unkown error code?</title>
      <link>/questions/5673/kerberos-nt-status-unkown-error-code/</link>
      <pubDate>Fri, 12 Aug 2011 01:55:00 +0000</pubDate>
      
      <guid>/questions/5673/kerberos-nt-status-unkown-error-code/</guid>
      <description>Kerberos - NT Status: Unkown error code?  0 I&#39;m trying to diagnose a potential Active Directory authentication issue and, in the AS reply packet there seems to be a possible issue in the pre-authentication part. If I expand padata and expand PA-PW-SALT, I see a value string. If I expand that, I see NT Status: Unknown (0x41495341), Unknown: 0x2e434150 and Unknown: 0x4a2e4441. Interestingly, a similar AS-REP packet can be seen in the Wireshark example Kerberos trace.</description>
    </item>
    
    <item>
      <title>How to analyse througput, packet loss, RTT rather than go through the graph of built-in feature of wireshark?</title>
      <link>/questions/5675/how-to-analyse-througput-packet-loss-rtt-rather-than-go-through-the-graph-of-built-in-feature-of-wireshark/</link>
      <pubDate>Fri, 12 Aug 2011 02:48:00 +0000</pubDate>
      
      <guid>/questions/5675/how-to-analyse-througput-packet-loss-rtt-rather-than-go-through-the-graph-of-built-in-feature-of-wireshark/</guid>
      <description>How to analyse througput, packet loss, RTT rather than go through the graph of built-in feature of wireshark?  2 Hi, I am doing research project to find out the TCP performance using New Reno, Compound TCP, Westwood and Cubic variant of TCP. I have included Wireshark as a network analysis tool; however it is beneficial in certain situations to check the network performance, but every matrices is not clearly defined.</description>
    </item>
    
    <item>
      <title>i can&amp;#x27;t capture any packet on my wifi divice.</title>
      <link>/questions/5681/i-cant-capture-any-packet-on-my-wifi-divice/</link>
      <pubDate>Fri, 12 Aug 2011 07:51:00 +0000</pubDate>
      
      <guid>/questions/5681/i-cant-capture-any-packet-on-my-wifi-divice/</guid>
      <description>i can&amp;rsquo;t capture any packet on my wifi divice.  0 i can&#39;t capture any packet on my wifi divice. but i can capture what going on on my laptop. im using 802.11 b/g/n. please help. i dont have money to buy aircpap.
wirelessThis question is marked &#34;community wiki&#34;.asked 12 Aug &#39;11, 07:51
Ezani Straw IV
1●1●1●2
accept rate: 0%
 edited 12 Aug &#39;11, 07:54</description>
    </item>
    
    <item>
      <title>Multi-file search</title>
      <link>/questions/5691/multi-file-search/</link>
      <pubDate>Fri, 12 Aug 2011 13:31:00 +0000</pubDate>
      
      <guid>/questions/5691/multi-file-search/</guid>
      <description>Multi-file search  0 Is there a mechanism where multiple files can be searched for a particular parameter?
When capturing large amounts of data or there is an intermittent issue and you are collecting the capture off in a ring buffer. The problem is when the event, lets say a SIP call overlaps 20 files, pulling all the SIP and RTP out of the various files is very time consuming.</description>
    </item>
    
    <item>
      <title>No Packets displayed</title>
      <link>/questions/5698/no-packets-displayed/</link>
      <pubDate>Sat, 13 Aug 2011 09:13:00 +0000</pubDate>
      
      <guid>/questions/5698/no-packets-displayed/</guid>
      <description>No Packets displayed  1 Hey there, i got a wired problem.
I think i figured out how to use Wireshark, i can capture my own packets. But now I want to capture packets of my Ipod which is on the WLAN too.
I have a Macbook Pro mid 2010 and Im running in Monitor Mode to get all the traffic, it also seems to capture packets. The number at the bottom which says &#34;</description>
    </item>
    
    <item>
      <title>ISUP China or ANSI version</title>
      <link>/questions/5699/isup-china-or-ansi-version/</link>
      <pubDate>Sat, 13 Aug 2011 10:46:00 +0000</pubDate>
      
      <guid>/questions/5699/isup-china-or-ansi-version/</guid>
      <description>ISUP China or ANSI version  0 Hi , i am new with the wireshark development, i want to know is there any patches that support ISUP(China Version) or ISUP(ANSI Version)?
Best Regards
isupasked 13 Aug &#39;11, 10:46
aMot
1●2●2●2
accept rate: 0%
  
One Answer:
  
1&#34;ISUP&#34; should be dissected as ANSI if mtp3 is ANSI, there is no specific China ISUP dissection so the result depends on how big the differens from ITU ISUP is.</description>
    </item>
    
    <item>
      <title>Are there any Network Support Companies that are Wireshark Certified?</title>
      <link>/questions/5705/are-there-any-network-support-companies-that-are-wireshark-certified/</link>
      <pubDate>Mon, 15 Aug 2011 14:47:00 +0000</pubDate>
      
      <guid>/questions/5705/are-there-any-network-support-companies-that-are-wireshark-certified/</guid>
      <description>Are there any Network Support Companies that are Wireshark Certified?  0 I believe we have problems with RST/Broken TCP packets and can tie some RST/Broken TCP packets to users losing their connections to the server. This, of course, is sporadic and I can always see an RST/Broken TCP when they experience the connection error, but they don&#39;t always get a connection error when I see an RST/Broken TCP. We&#39;ve talked to our application vendor and they say it&#39;s our network, and the network team says it&#39;s not the network.</description>
    </item>
    
    <item>
      <title>TCp Window scaling</title>
      <link>/questions/5708/tcp-window-scaling/</link>
      <pubDate>Tue, 16 Aug 2011 00:29:00 +0000</pubDate>
      
      <guid>/questions/5708/tcp-window-scaling/</guid>
      <description>TCp Window scaling  0 Hi All, I am capturing a network traces for one of my problem debugging.I see that Window size is shown as &#34;70145(scaled)&#34; as soon as I start my application.but after some time it shows me the value of only &#34;1525&#34;. can anyone please help me understand why it is falling to that value.Also why it is not showing &#34;scaled&#34; in after few minutes of restarting the window.</description>
    </item>
    
    <item>
      <title>How to find bandwidth hog on small network?</title>
      <link>/questions/5712/how-to-find-bandwidth-hog-on-small-network/</link>
      <pubDate>Tue, 16 Aug 2011 06:53:00 +0000</pubDate>
      
      <guid>/questions/5712/how-to-find-bandwidth-hog-on-small-network/</guid>
      <description>How to find bandwidth hog on small network?  0 Hi,
Lately having slow internet in the office at random times. This might be network problem or one or more workstations use too much bandwidth.
I already tested that I can Wireshark capture between the modem and the router using Windows XP laptop with 2 NICs bridged.
I want to keep this capture for long time, maybe 1-2 days, and I want to find out what workstation is causing the slowdown.</description>
    </item>
    
    <item>
      <title>Wireshark quits right after I open it since upgrading to Mac OS X 10.7 see log file</title>
      <link>/questions/5718/wireshark-quits-right-after-i-open-it-since-upgrading-to-mac-os-x-107-see-log-file/</link>
      <pubDate>Tue, 16 Aug 2011 22:49:00 +0000</pubDate>
      
      <guid>/questions/5718/wireshark-quits-right-after-i-open-it-since-upgrading-to-mac-os-x-107-see-log-file/</guid>
      <description>Wireshark quits right after I open it since upgrading to Mac OS X 10.7 see log file  0 Worked great on 10.6 and prior. Upgraded to 10.7, did not work. Uninstalled and reinstalled ver 1.6.1, same ver that was running fine before the upgrade. X11 is not opening in conjunction with Wireshark, but it did in 10.6. See log file. Searched MAC for &#34;_iconv&#34;, no hits. Any ideas? Thank you in advance.</description>
    </item>
    
    <item>
      <title>Decode SRTP and TLS</title>
      <link>/questions/5720/decode-srtp-and-tls/</link>
      <pubDate>Wed, 17 Aug 2011 00:03:00 +0000</pubDate>
      
      <guid>/questions/5720/decode-srtp-and-tls/</guid>
      <description>Decode SRTP and TLS  0 Hi there,
I am trying to troubleshoot a voice quality issue on a tls and srtp VOIP call. Normally on a TCP and RTP call, I can use the player to play back these packets so I can listen to the voice quality between handset and call server or gateway with call server. However wireshark can&#39;t seems to decode and play a VOIP call setup using tls and srtp even if the correct RSA key.</description>
    </item>
    
    <item>
      <title>How to decode V5.2 protocol messages from text file with Wireshark?</title>
      <link>/questions/5723/how-to-decode-v52-protocol-messages-from-text-file-with-wireshark/</link>
      <pubDate>Wed, 17 Aug 2011 02:39:00 +0000</pubDate>
      
      <guid>/questions/5723/how-to-decode-v52-protocol-messages-from-text-file-with-wireshark/</guid>
      <description>How to decode V5.2 protocol messages from text file with Wireshark?  0 I have a text file with captured data from V5.2 link. I want use Wireshark to analyse this files. How I can do this task? Here is a part of my text file:
12:46:23 15.12.05 SYS 0 FC E1 FC E1 01 01 77 13 00 63 06 12:46:23 15.12.05 LE 0 FC E3 FE E3 7F 08 62 C2 06 12:46:24 15.</description>
    </item>
    
    <item>
      <title>adding a listener?</title>
      <link>/questions/5724/adding-a-listener/</link>
      <pubDate>Wed, 17 Aug 2011 11:49:00 +0000</pubDate>
      
      <guid>/questions/5724/adding-a-listener/</guid>
      <description>adding a listener?  0 Hi, I am trying to customize a version of wireshark. I believe what I am trying to do is add a listener, but I&#39;m not sure. I want to be able to take certain packets, including packets with errors, and send them over a socket to another application. I will need to do some customized processing of these packets, although I can either do that processing as part of wireshark, or I can do it on the other side of my socket.</description>
    </item>
    
    <item>
      <title>Newbie trying to get lua scripts to execute</title>
      <link>/questions/5726/newbie-trying-to-get-lua-scripts-to-execute/</link>
      <pubDate>Wed, 17 Aug 2011 13:06:00 +0000</pubDate>
      
      <guid>/questions/5726/newbie-trying-to-get-lua-scripts-to-execute/</guid>
      <description>Newbie trying to get lua scripts to execute  1 Hi, I&#39;m basically just trying to get any lua script to execute. I found init.lua in my distribution at epan/wslua/init.lua. Is it in this file that I need to change &#34;disable_lua&#34; to false and &#34;run_user_scripts_when_superuser&#34; to true? Or do I need to copy this file somewhere else? (I see it says that wireshark will look for this script in the &#34;</description>
    </item>
    
    <item>
      <title>RTCP QoS Calculation</title>
      <link>/questions/5734/rtcp-qos-calculation/</link>
      <pubDate>Wed, 17 Aug 2011 23:04:00 +0000</pubDate>
      
      <guid>/questions/5734/rtcp-qos-calculation/</guid>
      <description>RTCP QoS Calculation  0 Hi,
I need to find average of upstream/downstream - {volume, jitters, packet loss}, for RTCP packets based on protocols MGCP, SKINNY, PTT, and H323. Can anyone help me to find the solution.
Thanks in advance
rtcp_qosThis question is marked &#34;community wiki&#34;.asked 17 Aug &#39;11, 23:04
syedmansoor
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Man in the Middle attack on a Router?</title>
      <link>/questions/5736/man-in-the-middle-attack-on-a-router/</link>
      <pubDate>Thu, 18 Aug 2011 02:18:00 +0000</pubDate>
      
      <guid>/questions/5736/man-in-the-middle-attack-on-a-router/</guid>
      <description>Man in the Middle attack on a Router?  2 To keep it simple: I want to capture ethernet traffic on my LAN. Its a mansion that we are in and am the admin. All we have is a 5yr-old Netgear router. It has four output ports. I am connected in one of them. I have already gone through the wiki: http://wiki.wireshark.org/CaptureSetup/Ethernet. I get what it says, but we dont use any switch or hub, and it doesn&#39;t mention any thing abt routers.</description>
    </item>
    
    <item>
      <title>Ip address on wireshark pc</title>
      <link>/questions/5744/ip-address-on-wireshark-pc/</link>
      <pubDate>Thu, 18 Aug 2011 09:48:00 +0000</pubDate>
      
      <guid>/questions/5744/ip-address-on-wireshark-pc/</guid>
      <description>Ip address on wireshark pc  0 When I mirror a port, does it matter what ip address I configure on the wireshark pc?
ip mirroring addressasked 18 Aug &#39;11, 09:48
spudster2011
1●1●1●1
accept rate: 0%
What do you mean by &#34;mirror a port&#34;? Do you mean that you&#39;re configuring a switch port as a mirror port and plugging your Wireshark PC into that port to try to capture traffic going through the switch?</description>
    </item>
    
    <item>
      <title>TCP Dissector, detect which endpoint opened the connection?</title>
      <link>/questions/5746/tcp-dissector-detect-which-endpoint-opened-the-connection/</link>
      <pubDate>Thu, 18 Aug 2011 13:29:00 +0000</pubDate>
      
      <guid>/questions/5746/tcp-dissector-detect-which-endpoint-opened-the-connection/</guid>
      <description>TCP Dissector, detect which endpoint opened the connection?  0 I&#39;m writing a dissector for a protocol that I have to work with. This protocol runs atop TCP and is stateful.
In order to dissect the fields correctly, I need to identify which endpoint opened the TCP connection (the client).
Is there a way to get this info from the tcp dissector? Would I have to write a tap? I&#39;m not so clear on how to do this in lua.</description>
    </item>
    
    <item>
      <title>capturing nt4 cryptography logon attempts?</title>
      <link>/questions/5750/capturing-nt4-cryptography-logon-attempts/</link>
      <pubDate>Thu, 18 Aug 2011 16:30:00 +0000</pubDate>
      
      <guid>/questions/5750/capturing-nt4-cryptography-logon-attempts/</guid>
      <description>capturing nt4 cryptography logon attempts?  0 Is there a way to configure wireshark to capture NT4 cryptography logon attempts? We are in the final steps before upgrading our Active Directory environment and we want to identify and decommision any outdated boxes without reducing the security level of our environment. Any help would be appreciated.
capture logon nt4 cryptographyasked 18 Aug &#39;11, 16:30
worldzfree
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Cannot decrypt SSL stream</title>
      <link>/questions/5769/cannot-decrypt-ssl-stream/</link>
      <pubDate>Fri, 19 Aug 2011 13:49:00 +0000</pubDate>
      
      <guid>/questions/5769/cannot-decrypt-ssl-stream/</guid>
      <description>Cannot decrypt SSL stream  0 Using Wireshark 1.6.1 on Win 7 x64.
I am trying to get the decrypted stream from a client/server interaction (the &#34;server&#34; is actually IIS/SQL Server 2005), but I am not having success with the decryption. Following is the SSL Debug File - thanks for any assistance.
Private key imported: KeyID 1c:52:0e:11:b5:11:20:19:0d:1d:66:d6:85:7a:e4:12:... ssl_init IPv4 addr &amp;#39;127.0.0.1&amp;#39; (127.0.0.1) port &amp;#39;444&amp;#39; filename &amp;#39;c:\ws088.pem&amp;#39; password(only for p12 file) &amp;#39;&amp;#39; ssl_init private key file c:\ws088.</description>
    </item>
    
    <item>
      <title>How to create analysed statistics like wireshark at commandline (with tshark or ...)</title>
      <link>/questions/5778/how-to-create-analysed-statistics-like-wireshark-at-commandline-with-tshark-or/</link>
      <pubDate>Sat, 20 Aug 2011 08:20:00 +0000</pubDate>
      
      <guid>/questions/5778/how-to-create-analysed-statistics-like-wireshark-at-commandline-with-tshark-or/</guid>
      <description>How to create analysed statistics like wireshark at commandline (with tshark or &amp;hellip;)  1 Hi..
Thanks for wonderful Wireshark!
I want to know how can I have analytical statistics (like the image below) like wireshark in commandline.
Is it possible to have it on commandline so that we can read the results to draw graph? (f.x. with tshark, tcpdump,..)
please note that it is important for me to have them real-time like wireshark</description>
    </item>
    
    <item>
      <title>i have trouble in build sources</title>
      <link>/questions/5785/i-have-trouble-in-build-sources/</link>
      <pubDate>Sun, 21 Aug 2011 07:35:00 +0000</pubDate>
      
      <guid>/questions/5785/i-have-trouble-in-build-sources/</guid>
      <description>i have trouble in build sources  0 I am building sources of wireshark on Windows7, and I can&#39;t find bash which can execute on the window7.
Although i find the sources of bash offered in http://www.gnu.org/s/bash/ on Windows7, I cannot install it.
The reason that there is no program required for installing in windows7 like gcc and make.
So I lost direction, Please, give me the direction.
windows7 build installasked 21 Aug &#39;11, 07:35</description>
    </item>
    
    <item>
      <title>SSL matter - after searching for &amp;#x27;ssl&amp;#x27; got nothing</title>
      <link>/questions/5788/ssl-matter-after-searching-for-ssl-got-nothing/</link>
      <pubDate>Sun, 21 Aug 2011 12:02:00 +0000</pubDate>
      
      <guid>/questions/5788/ssl-matter-after-searching-for-ssl-got-nothing/</guid>
      <description>SSL matter - after searching for &amp;lsquo;ssl&amp;rsquo; got nothing  0 SSL matter - after searching for &#39;ssl&#39; got nothing - used wireless laptop After Login (recorded always by WireShark) to Paypal and GoDaddy.com, I get some data in wireshark trace, but after searching for &#39;ssl&#39; I get nothing, well where is the problem?
WireShark sniffs all packets independently of where belog in Layer Stack?
sslasked 21 Aug &#39;11, 12:02</description>
    </item>
    
    <item>
      <title>Wireshark Detects DNS Requests Blocked by Hosts File</title>
      <link>/questions/5791/wireshark-detects-dns-requests-blocked-by-hosts-file/</link>
      <pubDate>Sun, 21 Aug 2011 21:24:00 +0000</pubDate>
      
      <guid>/questions/5791/wireshark-detects-dns-requests-blocked-by-hosts-file/</guid>
      <description>Wireshark Detects DNS Requests Blocked by Hosts File  0 I have Wireshark running on Windows 7 x64. I created a Hosts file that maps specific domains to 127.0.0.1. I then &#39;ping&#39;-ed each domain to make sure it returned 127.0.0.1. Nevertheless, Wireshark is capturing DNS requests and responses from my ISP&#39;s DNS server for these domains. How is that possible?
hosts dnsasked 21 Aug &#39;11, 21:24
Farmisht
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Unable to see SIP packets in Wireshark for Mac Lion</title>
      <link>/questions/5798/unable-to-see-sip-packets-in-wireshark-for-mac-lion/</link>
      <pubDate>Sun, 21 Aug 2011 23:23:00 +0000</pubDate>
      
      <guid>/questions/5798/unable-to-see-sip-packets-in-wireshark-for-mac-lion/</guid>
      <description>Unable to see SIP packets in Wireshark for Mac Lion  0 How do i see SIP packets on Wireshark for operating system Mac OSX Lion 10.7?
sipasked 21 Aug &#39;11, 23:23
amit
1●1●1●1
accept rate: 0%
1By opening capture files with SIP packets in them... but I doubt that is really your question.
(22 Aug &#39;11, 05:52) Jaap ♦   </description>
    </item>
    
    <item>
      <title>Wireshark from command line</title>
      <link>/questions/5800/wireshark-from-command-line/</link>
      <pubDate>Mon, 22 Aug 2011 02:43:00 +0000</pubDate>
      
      <guid>/questions/5800/wireshark-from-command-line/</guid>
      <description>Wireshark from command line  0 1I&#39;d like to programatically call wireshark to capture 100 packets, parse source mac address of each packet and close. How can I do this?
This is what I have so far, but it&#39;s not working:
wireshark -c 100 -k -Q -w -This is supposed to stop capturing after 100 packets, start capturing immediately, shut down wireshark after done, and print the output to stdout, which is the command prompt.</description>
    </item>
    
    <item>
      <title>How to capture intra-PC packets</title>
      <link>/questions/5805/how-to-capture-intra-pc-packets/</link>
      <pubDate>Mon, 22 Aug 2011 07:16:00 +0000</pubDate>
      
      <guid>/questions/5805/how-to-capture-intra-pc-packets/</guid>
      <description>How to capture intra-PC packets  0 Running Wireshark 1.6.1 on Win 7 x64.
I have a webserver running on my PC, and would like to capture packets from applications accessing the webserver, from the same PC. Attempting to capture packets on the usual port don&#39;t seem to work. Is this even possible? Thanks for any pointers.
capture internal intra-pc wiresharkasked 22 Aug &#39;11, 07:16
cgtyoder
11●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>open ws trace file on another pc</title>
      <link>/questions/5819/open-ws-trace-file-on-another-pc/</link>
      <pubDate>Tue, 23 Aug 2011 02:52:00 +0000</pubDate>
      
      <guid>/questions/5819/open-ws-trace-file-on-another-pc/</guid>
      <description>open ws trace file on another pc  0 Hello, I cannot open a ws trace on another pc? I try yet to save or export but when I open the file on another pc I don&#39;t get what I observe on the source PC?!? Can you help me? Many tanks for your help!!! Phil.
readanotherpcasked 23 Aug &#39;11, 02:52
PhilLu
1●1●1●1
accept rate: 0%
You&#39;ll need to provide more info in your question.</description>
    </item>
    
    <item>
      <title>Wireshark exported data does not match displayed data</title>
      <link>/questions/5824/wireshark-exported-data-does-not-match-displayed-data/</link>
      <pubDate>Tue, 23 Aug 2011 06:54:00 +0000</pubDate>
      
      <guid>/questions/5824/wireshark-exported-data-does-not-match-displayed-data/</guid>
      <description>Wireshark exported data does not match displayed data  0 I am using an older version of Wireshark (V1.2.9) so please tell me if this issue has been reported and or fixed:
When I export captured Wireshark data, the info field data in the exported file does not match the info field data that is displayed in the screen. I am exporting all packets to a CSV file but certain packets are displayed with errors on the Wireshark display window but these errors are listed as 0 errors in the actual exported file.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t check &amp;quot;monitor mode&amp;quot; checkbox on Ubuntu</title>
      <link>/questions/5826/cant-check-monitor-mode-checkbox-on-ubuntu/</link>
      <pubDate>Tue, 23 Aug 2011 09:27:00 +0000</pubDate>
      
      <guid>/questions/5826/cant-check-monitor-mode-checkbox-on-ubuntu/</guid>
      <description>Can&amp;rsquo;t check &amp;ldquo;monitor mode&amp;rdquo; checkbox on Ubuntu  4 2Hi there,
I&#39;m running the latest version of wireshark with ubuntu. My Wifi is using a &#34;Intel 4965/5xxx&#34; Chipset with an &#34;iwlagn&#34; driver.
My Problem is: When I click at the &#34;monitor mode&#34; checkbox in Capture Options the box is checked for less than a second und then unchecked again. I don&#39;t recieve any error messages.
I tried using airmon-ng and selected mon0 as interface but it didn&#39;t work, too.</description>
    </item>
    
    <item>
      <title>I only capture in one direction</title>
      <link>/questions/5827/i-only-capture-in-one-direction/</link>
      <pubDate>Tue, 23 Aug 2011 12:50:00 +0000</pubDate>
      
      <guid>/questions/5827/i-only-capture-in-one-direction/</guid>
      <description>I only capture in one direction  0 Hi; I configure a switch Catalyst in monitor mode to capture some packets, with my laptop I only capture packets in one direction; I use another laptop with same Wireshark version and I capture traffic in both directions, I can check this with a Ping. In my laptop I just see ICMP (Echo) Requests w/o any filter but when I use the another one I see Echo Requests and Replies.</description>
    </item>
    
    <item>
      <title>macosx-setup.sh</title>
      <link>/questions/5828/macosx-setupsh/</link>
      <pubDate>Tue, 23 Aug 2011 16:36:00 +0000</pubDate>
      
      <guid>/questions/5828/macosx-setupsh/</guid>
      <description>macosx-setup.sh  0 When running the macosx-setup.sh command I get an error. Any ideas what is going on here? I am running Mac OS 10.6.8 and have XCode 3.6.2 installed.
In file included from pangocairo-fontmap.c:30: pangocairo-coretext.h:28:26: error: cairo-quartz.h: No such file or directory make[4]: *** [libpangocairo_1_0_la-pangocairo-fontmap.lo] Error 1
osx build headerasked 23 Aug &#39;11, 16:36
Nate
1●1●1●2
accept rate: 0%
  
2 Answers:
  
0The setup script commented out Cairo.</description>
    </item>
    
    <item>
      <title>Finding conversations for multiple ips (hundreds)</title>
      <link>/questions/5837/finding-conversations-for-multiple-ips-hundreds/</link>
      <pubDate>Wed, 24 Aug 2011 06:25:00 +0000</pubDate>
      
      <guid>/questions/5837/finding-conversations-for-multiple-ips-hundreds/</guid>
      <description>Finding conversations for multiple ips (hundreds)  0 Is there a way in tshark to look conversations from a large list of ips? I have a list of ips in a text file. There are usually 100+ ips in the file. I can do some command line scripting to make this work, but I was wondering if I could use a file as input to the filter.
So ideally it would look something like this: tshark -qnr mydump.</description>
    </item>
    
    <item>
      <title>Rolling Capture for a week&amp;#x27;s long event</title>
      <link>/questions/5838/rolling-capture-for-a-weeks-long-event/</link>
      <pubDate>Wed, 24 Aug 2011 06:47:00 +0000</pubDate>
      
      <guid>/questions/5838/rolling-capture-for-a-weeks-long-event/</guid>
      <description>Rolling Capture for a week&amp;rsquo;s long event  1 Is there a way to truncate the capture log to say 4 or 6 hours? I need to diagnose a problem that happens randomly every 4-14 days, and would like to have a capture of the data happening at the moment of the event without crushing the computer running Wireshark for 14 days straight...
rolling capture logasked 24 Aug &#39;11, 06:47</description>
    </item>
    
    <item>
      <title>who blocked my connection???</title>
      <link>/questions/5841/who-blocked-my-connection/</link>
      <pubDate>Wed, 24 Aug 2011 07:45:00 +0000</pubDate>
      
      <guid>/questions/5841/who-blocked-my-connection/</guid>
      <description>who blocked my connection???  0 when i try to connect via VNC i see the next log, can you help me i need to find who is been blocked my connection
No. Time Source Destination Protocol Info 51 477.905684 10.206.96.8 10.206.80.103 TCP xmapi &amp;gt; esmmanager [SYN] Seq=0 Win=16384 Len=0 MSS=1024 WS=0 TSV=4798594 TSER=0
Frame 51: 74 bytes on wire (592 bits), 74 bytes captured (592 bits) Ethernet II, Src: 63:30:00:00:00:00 (63:30:00:00:00:00), Dst: 6f:31:65:74:68:31 (6f:31:65:74:68:31) Internet Protocol, Src: 10.</description>
    </item>
    
    <item>
      <title>Traffic slowing network</title>
      <link>/questions/5845/traffic-slowing-network/</link>
      <pubDate>Wed, 24 Aug 2011 09:41:00 +0000</pubDate>
      
      <guid>/questions/5845/traffic-slowing-network/</guid>
      <description>Traffic slowing network  0 Hello,
I have an issue on 2 servers where there appears to be traffic that is slowing down the internet connection considerably. Appears to be a DoS. Does anything in this log stick out? I see constant external IP&#39;s as a source, and destination as the LAN address:
Transmission Control Protocol, Src Port: ms-wbt-server (3389), Dst Port: 4935 (4935), Seq: 1, Ack: 1, Len: 0 8 0.</description>
    </item>
    
    <item>
      <title>Transfer rate improves with Wireshark</title>
      <link>/questions/5846/transfer-rate-improves-with-wireshark/</link>
      <pubDate>Wed, 24 Aug 2011 11:06:00 +0000</pubDate>
      
      <guid>/questions/5846/transfer-rate-improves-with-wireshark/</guid>
      <description>Transfer rate improves with Wireshark  0 I am trying to measure the read/write performance of a networked attached storage appliance using a Dell Vostro laptop/ Windows XP. Nominally, the read transfer rate is poor (ie read is worse than write). However, when I monitor the ethernet connection using WireShark (installed on the laptop), the read performance significantly improves.
Does Wireshark buffer data, or modify the transmission in any way that may explain this?</description>
    </item>
    
    <item>
      <title>Wireshark doesn&amp;#x27;t see my interface</title>
      <link>/questions/5861/wireshark-doesnt-see-my-interface/</link>
      <pubDate>Wed, 24 Aug 2011 19:37:00 +0000</pubDate>
      
      <guid>/questions/5861/wireshark-doesnt-see-my-interface/</guid>
      <description>Wireshark doesn&amp;rsquo;t see my interface  0 Hello all, I&#39;ve used Wireshark many times in the past in both Windows and Linux. I can spell TCP/IP but I am no expert. On my blazing 750 MHz Linux (2.6.32) Ubuntu (Lucid Lynx 10.04 LTS) machine, Wireshark does not list my NIC card. I expected to see eth0 listed, but it&#39;s not. I am on the machine now making this post, so it is active and working.</description>
    </item>
    
    <item>
      <title>A problem about  libGeoIP.so.1 on sol10-sparc after installing wireshark</title>
      <link>/questions/5862/a-problem-about-libgeoipso1-on-sol10-sparc-after-installing-wireshark/</link>
      <pubDate>Thu, 25 Aug 2011 01:07:00 +0000</pubDate>
      
      <guid>/questions/5862/a-problem-about-libgeoipso1-on-sol10-sparc-after-installing-wireshark/</guid>
      <description>A problem about libGeoIP.so.1 on sol10-sparc after installing wireshark  0 When I try to run wireshark-1.6.1-sol10-sparc-local, I met a problem that:
&#34;ld.so.1: wireshark: fatal: libGeoIP.so.1: open failed: No such file or directory&#34;
The command ldd wireshark showed (file not found)
where will I get the package? I didn&#39;t find it on sunfreeware
sparc libgeoip.so.1asked 25 Aug &#39;11, 01:07
firobaccano
1●1●1●2
accept rate: 0%
 edited 25 Aug &#39;11, 01:17</description>
    </item>
    
    <item>
      <title>What is the best way to track data between packets during dissection?</title>
      <link>/questions/5867/what-is-the-best-way-to-track-data-between-packets-during-dissection/</link>
      <pubDate>Thu, 25 Aug 2011 07:07:00 +0000</pubDate>
      
      <guid>/questions/5867/what-is-the-best-way-to-track-data-between-packets-during-dissection/</guid>
      <description>What is the best way to track data between packets during dissection?  0 In brief: What is the best way to track information between protocol packets during dissection?
More detail: Suppose I have a protocol which has multiple message types, some of which can only be fully dissected if certain information from another message is known (example below). I could just have a static gint variable in my dissector that I update when data comes in, but this feels a little clunky.</description>
    </item>
    
    <item>
      <title>How do I setup Wireshark to run Lua&amp;#x27;s CLRPackage</title>
      <link>/questions/5868/how-do-i-setup-wireshark-to-run-luas-clrpackage/</link>
      <pubDate>Thu, 25 Aug 2011 07:15:00 +0000</pubDate>
      
      <guid>/questions/5868/how-do-i-setup-wireshark-to-run-luas-clrpackage/</guid>
      <description>How do I setup Wireshark to run Lua&amp;rsquo;s CLRPackage  1 1I&#39;m trying to setup Wireshark so that I can use the LuaInterface to use some of the classes in the .NET framework. I&#39;m able to get it working running through the Lua command line, but when I try to require &#34;CLRPackage&#34; in the init.lua startup script, it doesnt appear to find the required files. I get the following exception when starting Wireshark:</description>
    </item>
    
    <item>
      <title>How to calculate jitter using HTTP streaming server</title>
      <link>/questions/5874/how-to-calculate-jitter-using-http-streaming-server/</link>
      <pubDate>Thu, 25 Aug 2011 13:57:00 +0000</pubDate>
      
      <guid>/questions/5874/how-to-calculate-jitter-using-http-streaming-server/</guid>
      <description>How to calculate jitter using HTTP streaming server  0 Hello Everyone!
I am using VLC player as a streaming server and captured traffic using tcp.port==8080. Now I am confused about how to calculate jitter though in RTP it is easy to calculate jitter (Telephony-&amp;gt;RTP-&amp;gt;Stream Analysis. I injected delay of 20ms on the network so no point of RTT calculation. If anyone here to illustrate the best and easiest (should be accurate) -:) way to calculate the same please revert ASAP.</description>
    </item>
    
    <item>
      <title>Tshark statistics to show port numbers?</title>
      <link>/questions/5875/tshark-statistics-to-show-port-numbers/</link>
      <pubDate>Thu, 25 Aug 2011 14:15:00 +0000</pubDate>
      
      <guid>/questions/5875/tshark-statistics-to-show-port-numbers/</guid>
      <description>Tshark statistics to show port numbers?  1 My apologies if this comes off as an overly newb question. I have been tasked by coworker to take a repository of pcaps and provide output from them in the form of...
src ip:src port dst ip:dst port # of packetsI played around with piping tcpdump to grep for a while before figuring out that tshark might be far easier, and I&#39;ve managed to get the output that I need with the exception of the source and destination ports.</description>
    </item>
    
    <item>
      <title>I want to use asn1 module to decode mms packet in my program.</title>
      <link>/questions/5883/i-want-to-use-asn1-module-to-decode-mms-packet-in-my-program/</link>
      <pubDate>Fri, 26 Aug 2011 04:35:00 +0000</pubDate>
      
      <guid>/questions/5883/i-want-to-use-asn1-module-to-decode-mms-packet-in-my-program/</guid>
      <description>I want to use asn1 module to decode mms packet in my program.  0 Hi, everyone.
I make packet monitoring program which monitors particular packets including mms packet.
So I want to use asn1 module for mms. I, however, don&#39;t know where is start point to do that.
I successed to compile wireshark by MSVC2008 using nmake.
And In my project(this program used mfc), I included asn.1, config.h and other code needed for this, and then follow error was appeared.</description>
    </item>
    
    <item>
      <title>Convert table to Byte array using CLRPackage</title>
      <link>/questions/5885/convert-table-to-byte-array-using-clrpackage/</link>
      <pubDate>Fri, 26 Aug 2011 06:54:00 +0000</pubDate>
      
      <guid>/questions/5885/convert-table-to-byte-array-using-clrpackage/</guid>
      <description>Convert table to Byte array using CLRPackage  0 I&#39;m trying to convert a Lua Table to a C# Byte array. I was able to get a conversion to a Double array to work as follows:
&amp;gt; require &amp;#39;CLRPackage&amp;#39; &amp;gt; import &amp;quot;System&amp;quot; &amp;gt; tbl = {11,22,33,44} &amp;gt; dbl_arr = Double[4] &amp;gt; dbl_arr:GetValue(0) &amp;gt; dbl_arr:GetValue(1) &amp;gt; for i=0,3 do Console.WriteLine(dbl_arr:GetValue(i)) end 0 0 0 0 &amp;gt; for i,v in ipairs(tbl) do dbl_arr:SetValue(v,i-1) end &amp;gt; for i=0,3 do Console.</description>
    </item>
    
    <item>
      <title>Tshark Command Line</title>
      <link>/questions/5889/tshark-command-line/</link>
      <pubDate>Fri, 26 Aug 2011 10:51:00 +0000</pubDate>
      
      <guid>/questions/5889/tshark-command-line/</guid>
      <description>Tshark Command Line  0 Hello,
Can anyone can help me with a command line in Tshark that will provide me the same information as if I go to Wireshark &amp;gt; Statistics &amp;gt; Conversations &amp;gt; TCP Tab with NO Name Resolution?
I need to write lots of appcapture files in text with this specific format. I&#39;m trying to write a BAT file that will convert hundreds of files at once.</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t capture 11n data packet</title>
      <link>/questions/5895/cant-capture-11n-data-packet/</link>
      <pubDate>Fri, 26 Aug 2011 17:45:00 +0000</pubDate>
      
      <guid>/questions/5895/cant-capture-11n-data-packet/</guid>
      <description>can&amp;rsquo;t capture 11n data packet  0 I have wireshark 1.0.5. I can capture 802.11g/a data packet but can&#39;t capture 802.11n data packet. is it normal?
brcmbgasked 26 Aug &#39;11, 17:45
bgu
1●1●1●1
accept rate: 0%
What does the &#34;brcmbg&#34; tag mean? I presume it doesn&#39;t mean your machine has a Broadcom 802.11b/802.11g adapter; if it did, the reason why you can&#39;t capture 802.11n packets would be obvious, i.e. &#34;your adapter doesn&#39;t support 802.</description>
    </item>
    
    <item>
      <title>using Mergecap to combine many large files at once</title>
      <link>/questions/5899/using-mergecap-to-combine-many-large-files-at-once/</link>
      <pubDate>Fri, 26 Aug 2011 21:27:00 +0000</pubDate>
      
      <guid>/questions/5899/using-mergecap-to-combine-many-large-files-at-once/</guid>
      <description>using Mergecap to combine many large files at once  0 Using the command &#34;Mergecap&#34; is great when you only have a handful of files (say less than 10) but i have an instance where I am generating lots of large files in Tshark (sizes = 200m @) from a single site and want to look at them in one continuous file instead of a file set. I also want to look at them in Pilot on occasion and when using Mergecap, I have to hand type each file in the string that I want to merge.</description>
    </item>
    
    <item>
      <title>need help: the code location of Ethernet trailer</title>
      <link>/questions/5900/need-help-the-code-location-of-ethernet-trailer/</link>
      <pubDate>Fri, 26 Aug 2011 23:10:00 +0000</pubDate>
      
      <guid>/questions/5900/need-help-the-code-location-of-ethernet-trailer/</guid>
      <description>need help: the code location of Ethernet trailer  0 Hi guys,
I am a novice on the wireshark developing. As for some reason, I need to get the trailer of Ethernet trailer and displayed with a more readable format, who can tell me where is the code of Ethernet trailer in Wireshark code.
Thanks in advance!
Best Regards!
Sam
developmentasked 26 Aug &#39;11, 23:10
Sam
51●7●9●14
accept rate: 0%</description>
    </item>
    
    <item>
      <title>propagating expert info color changes to the traffic summary window in Wireshark 1.7</title>
      <link>/questions/5906/propagating-expert-info-color-changes-to-the-traffic-summary-window-in-wireshark-17/</link>
      <pubDate>Sat, 27 Aug 2011 19:17:00 +0000</pubDate>
      
      <guid>/questions/5906/propagating-expert-info-color-changes-to-the-traffic-summary-window-in-wireshark-17/</guid>
      <description>propagating expert info color changes to the traffic summary window in Wireshark 1.7  1 I have an RPC sub-dissector and I want to highlight certain packets dissected by my subdissector in the traffic summary window (topmost pane of Wireshark GUI). I&#39;m currently calling expert_add_info_format() from my dissector, and this successfully changes the color of the packet in the protocol tree of the detailed view (middle pane of Wireshark GUI), but for some reason it is not propagating this color change up to the same packet in the traffic summary window.</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t open to large .eth file</title>
      <link>/questions/5909/cant-open-to-large-eth-file/</link>
      <pubDate>Sun, 28 Aug 2011 16:29:00 +0000</pubDate>
      
      <guid>/questions/5909/cant-open-to-large-eth-file/</guid>
      <description>can&amp;rsquo;t open to large .eth file  0 Hello,
have a to big (*.eth) file (7gb) and can&#39;t open that with wireshark. how can i reduce it and make smaler files thereout. (like you can do ist with editcap and .pcap files, for example: editcap -c 10000 .........)
Or can i convert the .eth file in an .pcap file?
Hallo,
habe eine zu große .eth Datei die mit wireshark nicht zu öffnen ist.</description>
    </item>
    
    <item>
      <title>can we view MOP packets with wireshark</title>
      <link>/questions/5910/can-we-view-mop-packets-with-wireshark/</link>
      <pubDate>Mon, 29 Aug 2011 00:18:00 +0000</pubDate>
      
      <guid>/questions/5910/can-we-view-mop-packets-with-wireshark/</guid>
      <description>can we view MOP packets with wireshark  0 I&#39;m trying to capture some Maintenance Operation Protocol (MOP) related packets from a router. but when i go to the filter section in wireshark, it does not have MOP listed under the protocols list. Is there any specific wireshark version where i can get MOP as filter option. or is there any other work around?
mop filtersasked 29 Aug &#39;11, 00:18</description>
    </item>
    
    <item>
      <title>UDP loss (RTP, SeqNum)</title>
      <link>/questions/5919/udp-loss-rtp-seqnum/</link>
      <pubDate>Mon, 29 Aug 2011 08:44:00 +0000</pubDate>
      
      <guid>/questions/5919/udp-loss-rtp-seqnum/</guid>
      <description>UDP loss (RTP, SeqNum)  0 When transmitting video using RTP (H.264) over UDP, which is natural for SIP/H.323, it can be loss of some UDP datagrams. So it will be Sequnce Number of RTP of packet not equal Seq of previous packet + 1. It will be awesome if Wireshark can show, that it is incorrect SeqNum (frame lost). Curretly, it shows all the frames with same color. So I need to additionaly analyze the stream (I used Excel) for incorrect flow of SeqNum.</description>
    </item>
    
    <item>
      <title>Could not find dissector for: &amp;#x27;HTTP&amp;#x27;</title>
      <link>/questions/5921/could-not-find-dissector-for-http/</link>
      <pubDate>Mon, 29 Aug 2011 10:31:00 +0000</pubDate>
      
      <guid>/questions/5921/could-not-find-dissector-for-http/</guid>
      <description>Could not find dissector for: &amp;lsquo;HTTP&amp;rsquo;  0 Under &#34;Protocols &amp;gt; SSL&#34; I am trying to add a new entry in the &#34;RSA Key list&#34;. I fill out the fields, click &#34;OK&#34;, and get this error -
&#34;error in column &#39;Protocol&#39;: Could not find dissector for: &#39;HTTP&#39;&#34;
any ideas what is going on here&#34;
TIA,
Phillip
dissector httpasked 29 Aug &#39;11, 10:31
audiphilth
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How can Unsolicited UDP Traffic be prevented?</title>
      <link>/questions/5922/how-can-unsolicited-udp-traffic-be-prevented/</link>
      <pubDate>Mon, 29 Aug 2011 11:21:00 +0000</pubDate>
      
      <guid>/questions/5922/how-can-unsolicited-udp-traffic-be-prevented/</guid>
      <description>How can Unsolicited UDP Traffic be prevented?  0 I am using uTorrent client which subscribes to peers that continue sending barrage of UDP packets even after I have exited the uTorrent program.I am behind home router and I don&#39;t want to use firewall to block this, each time I log on to my home PC. How can I prevent this?? Any help will be highly appreciated:-)
udp torrentasked 29 Aug &#39;11, 11:21</description>
    </item>
    
    <item>
      <title>Error in Pcap file</title>
      <link>/questions/5924/error-in-pcap-file/</link>
      <pubDate>Mon, 29 Aug 2011 11:41:00 +0000</pubDate>
      
      <guid>/questions/5924/error-in-pcap-file/</guid>
      <description>Error in Pcap file  1 Hello; I have used wireshark to capture a full days worth of data; however, when I try to open the file, I receive the following error.
The capture file appears to be damaged or corrupt. (pcap: File has 1313056966-byte packet, bigger than maximum of 65535), Is there a work around so I can view the entire file ?
Thanks Ian
corrupt damaged pcap errorasked 29 Aug &#39;11, 11:41</description>
    </item>
    
    <item>
      <title>Persistent vs non persistent connections</title>
      <link>/questions/5925/persistent-vs-non-persistent-connections/</link>
      <pubDate>Mon, 29 Aug 2011 12:44:00 +0000</pubDate>
      
      <guid>/questions/5925/persistent-vs-non-persistent-connections/</guid>
      <description>Persistent vs non persistent connections  0 I am trying to verify which type of connection is being made - persistent or non persistent. I see the following and if someone could explain what each of these mean
Keep-Alive: 300 Connections:keep-alive Keep-Alive: timeout=max=100persistentasked 29 Aug &amp;lsquo;11, 12:44
Maxx
1●1●1●1
accept rate: 0%
 edited 29 Aug &amp;lsquo;11, 16:09 
SYN-bit ♦♦
17.1k●9●57●245

 
One Answer:</description>
    </item>
    
    <item>
      <title>Why can I no longer decode SSL traffic with Wireshark?</title>
      <link>/questions/5926/why-can-i-no-longer-decode-ssl-traffic-with-wireshark/</link>
      <pubDate>Mon, 29 Aug 2011 13:48:00 +0000</pubDate>
      
      <guid>/questions/5926/why-can-i-no-longer-decode-ssl-traffic-with-wireshark/</guid>
      <description>Why can I no longer decode SSL traffic with Wireshark?  0 I used to export decrypted SSL keys in txt format and store them on my C drive under the root directoryssl keys. I then went into Wireshark and added the path to the key under &#34;RSA Keys List&#34; - Example: 10.10.10.10,443,https,c:sslkeyswww-key.txt
For some reason that no longer works and the only difference I see is a slighty different way of entering that info with Wireshark 1.</description>
    </item>
    
    <item>
      <title>Missing bytes in Capture file</title>
      <link>/questions/5935/missing-bytes-in-capture-file/</link>
      <pubDate>Mon, 29 Aug 2011 18:04:00 +0000</pubDate>
      
      <guid>/questions/5935/missing-bytes-in-capture-file/</guid>
      <description>Missing bytes in Capture file  0 Is it normal to see occasional missing bytes in capture file, TCP Acked Lost segment, while filtering through a TCP Stream?
The problem is resolved by reload the stream.
bytes missingasked 29 Aug &#39;11, 18:04
Sharky7
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Yes, it is normal that sometimes not all packets that were on the wire are captured.</description>
    </item>
    
    <item>
      <title>How to open video files (.flv,.swf) directly?</title>
      <link>/questions/5936/how-to-open-video-files-flvswf-directly/</link>
      <pubDate>Mon, 29 Aug 2011 18:10:00 +0000</pubDate>
      
      <guid>/questions/5936/how-to-open-video-files-flvswf-directly/</guid>
      <description>How to open video files (.flv,.swf) directly?  0 I can be able to open &#34;Image&#34; files and &#34;Audio&#34; files via Wireshark, but i can&#39;t open video files .
image audio videoasked 29 Aug &#39;11, 18:10
JK7
31●11●12●14
accept rate: 0%
  
One Answer:
  
0You&#39;d have to contribute code to Wireshark that recognizes those files - and I don&#39;t think Wireshark has any dissectors for any Flash video formats, so you might have to contribute a dissector for those file formats as well.</description>
    </item>
    
    <item>
      <title>How do I monitoring traffic on a seperate pc in my network from my router connect PC?</title>
      <link>/questions/5939/how-do-i-monitoring-traffic-on-a-seperate-pc-in-my-network-from-my-router-connect-pc/</link>
      <pubDate>Mon, 29 Aug 2011 19:51:00 +0000</pubDate>
      
      <guid>/questions/5939/how-do-i-monitoring-traffic-on-a-seperate-pc-in-my-network-from-my-router-connect-pc/</guid>
      <description>How do I monitoring traffic on a seperate pc in my network from my router connect PC?  0 There are three seperate pc&#39;s in my home network that are connected wirelessly to my wireless router. How do I monitor websites visited from those pc?
Thanks in advance,
John
wireless captureasked 29 Aug &#39;11, 19:51
bigjohn2005
1●1●1●1
accept rate: 0%
 retagged 30 Aug &#39;11, 07:48 
multipleinte...
1.3k●15●23●40</description>
    </item>
    
    <item>
      <title>tcp options  ( how to make a separate DLL )</title>
      <link>/questions/5940/tcp-options-how-to-make-a-separate-dll/</link>
      <pubDate>Mon, 29 Aug 2011 23:32:00 +0000</pubDate>
      
      <guid>/questions/5940/tcp-options-how-to-make-a-separate-dll/</guid>
      <description>tcp options ( how to make a separate DLL )  0 HI,
I have written few lines of code to dissect tcp options ( ORBITAL_META_OPTION 0x18 Citrix-BR add this option) and it is working perfectly.
I modified packet-tcp.c (wireshark\epan\dissectors\packet-tcp.c)
first i added required information in static const ip_tcp_opt tcpopts[] and static hf_register_info hf[]then my own dissector function to dissect ORBITAL_META_OPTION ( 0x18)But the problem is, if someone want to see these feature he has to use my Wireshark ( compiled by me ).</description>
    </item>
    
    <item>
      <title>linux capture filter problems</title>
      <link>/questions/5941/linux-capture-filter-problems/</link>
      <pubDate>Mon, 29 Aug 2011 23:34:00 +0000</pubDate>
      
      <guid>/questions/5941/linux-capture-filter-problems/</guid>
      <description>linux capture filter problems  0 Hi, i have some issues with capture filters not working on a Linux Server. Even a simple filter like &#34;x.x.x.x&#34; will cause no packets to be displayed. If i filter after capture using display filter it works fine &#34;ip.addr==x.x.x.x&#34;. I have tried this on a different network interface on the same machine and found capture filters are working fine on that one. The only difference i can think of between those 2 interfaces is that the first one has a lot of traffic on it (250Mbps+).</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t read 64-bit SNMP values</title>
      <link>/questions/5949/cant-read-64-bit-snmp-values/</link>
      <pubDate>Tue, 30 Aug 2011 03:24:00 +0000</pubDate>
      
      <guid>/questions/5949/cant-read-64-bit-snmp-values/</guid>
      <description>Can&amp;rsquo;t read 64-bit SNMP values  0 I can read only until 63 bits (0x7FFFFFFFFFFFFFFF)
With full 64-bit values I got this error:
[Dissector bug, protocol SNMP: proto.c:1317: failed assertion &#34;length &amp;lt;= 8 &amp;amp;&amp;amp; length &amp;gt;= 1&#34;]
Can you help me?
snmp 64-bitasked 30 Aug &#39;11, 03:24
Jbit
1●1●1●1
accept rate: 0%
  
2 Answers:
  
2It&#39;s a signed/unsigned BER encoding thing. You try to set a Counter64 [APPLICATION 6], which is an unsigned 64 bit integer.</description>
    </item>
    
    <item>
      <title>Finding Telephone Numbers with WIreShark</title>
      <link>/questions/5951/finding-telephone-numbers-with-wireshark/</link>
      <pubDate>Tue, 30 Aug 2011 04:13:00 +0000</pubDate>
      
      <guid>/questions/5951/finding-telephone-numbers-with-wireshark/</guid>
      <description>Finding Telephone Numbers with WIreShark  0 I have some blackberries roaming around on my wireless network. Is there a way to use wireshark to find the telephone numbers for these blackberries?
telephonyasked 30 Aug &#39;11, 04:13
Belnando
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Probably not. A Blackberry, like other mobile computers, has multiple network interfaces, and if it&#39;s using one network interface (Wi-Fi), that doesn&#39;t say anything about its other network interfaces (mobile phone interface) - you can get the Wi-Fi MAC address for the Blackberry from a network capture, but, unless some network traffic from the Blackberry happens to announce its phone number (and I&#39;m not sure what traffic that would be - the user could, for example, be e-mailing their phone number to somebody, but they could be e-mailing a home or office landline number, or somebody else&#39;s phone number, or.</description>
    </item>
    
    <item>
      <title>Setting address information in packet info structure for conversations</title>
      <link>/questions/5956/setting-address-information-in-packet-info-structure-for-conversations/</link>
      <pubDate>Tue, 30 Aug 2011 07:22:00 +0000</pubDate>
      
      <guid>/questions/5956/setting-address-information-in-packet-info-structure-for-conversations/</guid>
      <description>Setting address information in packet info structure for conversations  0 I have a dissector for a link-layer protocol for which I can dissect packets already. I need to implement conversations for my dissector for per-packet data, and would like to use find_or_create_conversation. I have already added my new address and port types to epan/address.h, epan/address_to_str.c and column-utils.c.
How do I set the source and destination information in the pinfo structure so that the correct conversation data is found?</description>
    </item>
    
    <item>
      <title>How to determine which  Windows program is consuming Internet bandwidth</title>
      <link>/questions/5962/how-to-determine-which-windows-program-is-consuming-internet-bandwidth/</link>
      <pubDate>Tue, 30 Aug 2011 10:37:00 +0000</pubDate>
      
      <guid>/questions/5962/how-to-determine-which-windows-program-is-consuming-internet-bandwidth/</guid>
      <description>How to determine which Windows program is consuming Internet bandwidth  1 I have a client that is on a limited Bandwith residential ISP with a daily allocation of 250MB up/down. The user has a PC running WIN 7 Home Premium. She has turned off all known &#34;automatic update&#34; configurations in all of the programs that are installed. But the bandwidth is still being consumed at an unacceptable rate. The PC was recently restored back to its out of box new condition and fresh copies of Windows 7 and Avast Internet Security were installed.</description>
    </item>
    
    <item>
      <title>maintaining a local Wireshark subversion branch</title>
      <link>/questions/5966/maintaining-a-local-wireshark-subversion-branch/</link>
      <pubDate>Tue, 30 Aug 2011 12:10:00 +0000</pubDate>
      
      <guid>/questions/5966/maintaining-a-local-wireshark-subversion-branch/</guid>
      <description>maintaining a local Wireshark subversion branch  0 I want to fork off a local copy of the latest stable Wireshark on my computer to do local development, but I want to do it in such a way that will make pulling in updates from the main Wireshark trunk as easy as possible in the future. I want to initially fork releases/wireshark-1.6.1/. After forking, in the short term, I want to be able to pull in revisions from the trunk-1.</description>
    </item>
    
    <item>
      <title>Wireshark not capturing Probe Request?</title>
      <link>/questions/5973/wireshark-not-capturing-probe-request/</link>
      <pubDate>Tue, 30 Aug 2011 14:10:00 +0000</pubDate>
      
      <guid>/questions/5973/wireshark-not-capturing-probe-request/</guid>
      <description>Wireshark not capturing Probe Request?  0 I&#39;m doing a little Pen-Testing using my Laptop, phone (HTC Droid), and Desktop with a Wireless NIC.
When running Wireshark while my HTC Droid and Laptop are unassociated with a wireless network, I&#39;m not picking up any Probes from any of these devices. The only traffic I&#39;m seeing from them are null Broadcast frames that are announcing their presence.
Is there something I&#39;m doing wrong, something I&#39;m unaware of, or are my devices simply not broadcasting networks that are in its PNL (preferred network list) or cached networks?</description>
    </item>
    
    <item>
      <title>Should we migrate to a different SCM?</title>
      <link>/questions/5975/should-we-migrate-to-a-different-scm/</link>
      <pubDate>Tue, 30 Aug 2011 16:37:00 +0000</pubDate>
      
      <guid>/questions/5975/should-we-migrate-to-a-different-scm/</guid>
      <description>Should we migrate to a different SCM?  8 4For a long time people have suggested that we migrate from Subversion (our current version control system) to Git or Mercurial. This isn&#39;t a trivial undertaking, but if the CVS to Subversion migration in 2004 is any indication it would definitely be worthwhile.
Unfortunately the path forward isn&#39;t obvious. Subversion, Git and Mercurial all work well. It&#39;s also unclear how much trouble switching away from Subversion would cause any downstream organizations who maintain their own versions of Wireshark.</description>
    </item>
    
    <item>
      <title>Calculating data</title>
      <link>/questions/5983/calculating-data/</link>
      <pubDate>Tue, 30 Aug 2011 19:21:00 +0000</pubDate>
      
      <guid>/questions/5983/calculating-data/</guid>
      <description>Calculating data  0 I have a wireshark capture of data on a particular port of a smart switch. I want to be ab;e to calculate how much data went to or from a particular IP. Are there expressions in the filters etc that would enable me to do this.
filtersasked 30 Aug &#39;11, 19:21
kasper46
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Have a look at Statistics !</description>
    </item>
    
    <item>
      <title>can wireshark version  0.99.3 decode snmp version 3? if can, can someone advise?</title>
      <link>/questions/5989/can-wireshark-version-0993-decode-snmp-version-3-if-can-can-someone-advise/</link>
      <pubDate>Tue, 30 Aug 2011 22:45:00 +0000</pubDate>
      
      <guid>/questions/5989/can-wireshark-version-0993-decode-snmp-version-3-if-can-can-someone-advise/</guid>
      <description>can wireshark version 0.99.3 decode snmp version 3? if can, can someone advise?  0 can wireshark version 0.99.3 decode snmp version 3? if can, can someone advise?
snmpv3asked 30 Aug &#39;11, 22:45
simonlcw
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Looking at the 0.99.3 snmp dissector revision history, I think the answer is yes.
That being said: Wireshark 0.99.3 is ancient (released about 5 years ago) and is unsupported and really shoud not be used at all.</description>
    </item>
    
    <item>
      <title>How to configure &amp;quot;Realtek PCIe GBE Family Controller&amp;quot;  to capture vlan tag packet?</title>
      <link>/questions/5996/how-to-configure-realtek-pcie-gbe-family-controller-to-capture-vlan-tag-packet/</link>
      <pubDate>Wed, 31 Aug 2011 06:38:00 +0000</pubDate>
      
      <guid>/questions/5996/how-to-configure-realtek-pcie-gbe-family-controller-to-capture-vlan-tag-packet/</guid>
      <description>How to configure &amp;ldquo;Realtek PCIe GBE Family Controller&amp;rdquo; to capture vlan tag packet?  0 Could you please tell me how to configure Ethernet card for capturing vlan tag packet with wireshark? My ethernet card is the &#34;Realtek PCIe GBE Family Controller&#34; in WINDOWS 7. I have download the latest drivers and the utility software. with the utility network software i have te possibility to set vlan id in the port but the wireshark isn&#39;t able to capture vlan id (I Send ethernet frames with 1518 bytes packet size and the wireshark captures 1514 bytes.</description>
    </item>
    
    <item>
      <title>Version for 2000 professional</title>
      <link>/questions/6007/version-for-2000-professional/</link>
      <pubDate>Wed, 31 Aug 2011 07:44:00 +0000</pubDate>
      
      <guid>/questions/6007/version-for-2000-professional/</guid>
      <description>Version for 2000 professional  0 I need a version of wireshark to run on 2000 professional is place where this is available.
versionsasked 31 Aug &#39;11, 07:44
mschmidtwrx
1●1●1●1
accept rate: 0% 
  
One Answer:
  
2The last release that supported Windows 2000 was 1.2.18. The 1.2 branch reached end of life this past June. You can download 1.2.18 from the release archives.
answered 31 Aug &#39;11, 08:42</description>
    </item>
    
    <item>
      <title>can i analyze source of malformed html in jsp?</title>
      <link>/questions/6011/can-i-analyze-source-of-malformed-html-in-jsp/</link>
      <pubDate>Wed, 31 Aug 2011 08:11:00 +0000</pubDate>
      
      <guid>/questions/6011/can-i-analyze-source-of-malformed-html-in-jsp/</guid>
      <description>can i analyze source of malformed html in jsp?  0 when my weblogic app server presents the jsp upon initial login, a portion of jsp is presented as malformed and duplicated html. can i see where my weblogic java app is constructing my jsp, so i can get the source of the problem?
malformedjspasked 31 Aug &#39;11, 08:11
sideve
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark is faulting on Windows 7</title>
      <link>/questions/6031/wireshark-is-faulting-on-windows-7/</link>
      <pubDate>Wed, 31 Aug 2011 15:27:00 +0000</pubDate>
      
      <guid>/questions/6031/wireshark-is-faulting-on-windows-7/</guid>
      <description>Wireshark is faulting on Windows 7  0 Hi - I installed version 1.6.1, enabled WinPCAP to start automatically and restarted windows 7. When I run Wireshark as administrator (or any user) it crashes. The following error is in the event log. The only thing about my environment of note is that I have VMware installed which adds some network drivers. Any suggestions?
Faulting application name: wireshark.exe, version: 1.6.1.38096, time stamp: 0x4e2498fd Faulting module name: libglib-2.</description>
    </item>
    
    <item>
      <title>dofile not loading when path is specified</title>
      <link>/questions/6036/dofile-not-loading-when-path-is-specified/</link>
      <pubDate>Wed, 31 Aug 2011 17:17:00 +0000</pubDate>
      
      <guid>/questions/6036/dofile-not-loading-when-path-is-specified/</guid>
      <description>dofile not loading when path is specified  0 Hi,
I have written a dissector and placed it in /home/me
I edited init.lua with dofile(&#34;/home/me/mydissector.lua&#34;) when i run wireshark i get Lua: Error During Loading
If i cd /home/me and run wireshak the dissector is loaded properly.
I am running Wireshark 1.4.1 &amp;amp; Lua 5.1 on CentOS 5.6 as root.
Thanks
luaasked 31 Aug &#39;11, 17:17
mrb
16●3●3●7
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to get AAA.jpg file from the trace under Out-of-Order environment</title>
      <link>/questions/6040/how-to-get-aaajpg-file-from-the-trace-under-out-of-order-environment/</link>
      <pubDate>Wed, 31 Aug 2011 19:22:00 +0000</pubDate>
      
      <guid>/questions/6040/how-to-get-aaajpg-file-from-the-trace-under-out-of-order-environment/</guid>
      <description>How to get AAA.jpg file from the trace under Out-of-Order environment  0 Currently, I&#39;ve faced sme problem while uploading the file to ftp server. If I upload the file via ftp-put command, sometimes a few thousand bytes was changed from original file. But, it isn&#39;t happen always... just once in a month... anyway, I&#39;ve captured the trace from all possible points as attached points and tried to filter out(Follow TCP Stream &amp;gt; RAW &amp;gt; Save As) AAA.</description>
    </item>
    
    <item>
      <title>Capturing download size</title>
      <link>/questions/6047/capturing-download-size/</link>
      <pubDate>Thu, 01 Sep 2011 08:24:00 +0000</pubDate>
      
      <guid>/questions/6047/capturing-download-size/</guid>
      <description>Capturing download size  0 I am trying to find out the size of antivirus definitions that are being downloaded to a corporate server. I suspect the local cache size of the definitions are as unpacked and therefore inaccurate - can anyone recommend a way of finding out the total size of inbound network traffic over a specific amount of time?
Thanks
download traffic sizeasked 01 Sep &#39;11, 08:24
genjuu</description>
    </item>
    
    <item>
      <title>problem with H225. Bad asn1 file ?</title>
      <link>/questions/6048/problem-with-h225-bad-asn1-file/</link>
      <pubDate>Thu, 01 Sep 2011 09:48:00 +0000</pubDate>
      
      <guid>/questions/6048/problem-with-h225-bad-asn1-file/</guid>
      <description>problem with H225. Bad asn1 file ?  0 Hello
I try to send a message coded in H225 in asn1 (my message is generated with the Binary Note Encoder librairie). I used the ans1 file h2250v7.asn link to download it
Wireshark don&#39;t understand my message and I got malformed packet error.
Which version is used by Wireshark to decode h225 message ?
h225 h323 asn1asked 01 Sep &#39;11, 09:48</description>
    </item>
    
    <item>
      <title>We are a call center using VoIP and SIP.. FC protocal</title>
      <link>/questions/6049/we-are-a-call-center-using-voip-and-sip-fc-protocal/</link>
      <pubDate>Thu, 01 Sep 2011 12:09:00 +0000</pubDate>
      
      <guid>/questions/6049/we-are-a-call-center-using-voip-and-sip-fc-protocal/</guid>
      <description>We are a call center using VoIP and SIP.. FC protocal  0 We ran Wireshark and found goups of packets that had all 0&#39;s for destination and source. protocal is FC and in brackets to the right it states [malformed packets]. I am trying to figure out why outbound voice quailty is poor.
Does anyone suspect anything about the malformed packets described? Is this normal stuff?
Thanks
wiresharkasked 01 Sep &#39;11, 12:09</description>
    </item>
    
    <item>
      <title>proto_tree_add_bits_item(), bit limit?</title>
      <link>/questions/6050/proto_tree_add_bits_item-bit-limit/</link>
      <pubDate>Thu, 01 Sep 2011 12:10:00 +0000</pubDate>
      
      <guid>/questions/6050/proto_tree_add_bits_item-bit-limit/</guid>
      <description>proto_tree_add_bits_item(), bit limit?  0 I am trying to use proto_tree_add_bits_item() to select all the bits that are used in a 7-bit ASCII message of arbitrary length. I convert this 7-bit ASCII to 8-bit and then print out a string, but I would like Wireshark to select the bits that this string was derived from when the &#34;Packet Bytes&#34; window is in &#34;Bits View&#34; instead of the standard &#34;Hex view&#34;. I have found that it will highlight the individual bits up to 7*3=21, and then it starts highlighting whole bytes.</description>
    </item>
    
    <item>
      <title>decoding g729</title>
      <link>/questions/6052/decoding-g729/</link>
      <pubDate>Thu, 01 Sep 2011 16:45:00 +0000</pubDate>
      
      <guid>/questions/6052/decoding-g729/</guid>
      <description>decoding g729  0 We have captured a call that we need to decode/play however it is in g729. is that possible to do in wireshark? if so how we&#39;re using SCCP(skinny) for call control.
thanks.
g279asked 01 Sep &#39;11, 16:45
jabrony99
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Since G.729 is a licensed codec it cannot incorporated in Wireshark without fees being paid. This is a problem not easy to circumvent.</description>
    </item>
    
    <item>
      <title>Diameter attributes related to WiMAX not decoding properly</title>
      <link>/questions/6055/diameter-attributes-related-to-wimax-not-decoding-properly/</link>
      <pubDate>Fri, 02 Sep 2011 00:15:00 +0000</pubDate>
      
      <guid>/questions/6055/diameter-attributes-related-to-wimax-not-decoding-properly/</guid>
      <description>Diameter attributes related to WiMAX not decoding properly  0 Hello Support,
I have Diameter trace which includes attributes related EAP and WiMAX.
All the WiMAX attributes are not decoding and the AVP&#39;s are shown as &#34;Unknown&#34;. I am running latest version 1.6.1 Wireshark.
Can you please let me know how can I fix it.
Thank you, Vijay
attribute wimaxasked 02 Sep &#39;11, 00:15
vijayakumarpc
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Packet color changes</title>
      <link>/questions/6058/packet-color-changes/</link>
      <pubDate>Fri, 02 Sep 2011 03:19:00 +0000</pubDate>
      
      <guid>/questions/6058/packet-color-changes/</guid>
      <description>Packet color changes  0 The color of the &#34;selected packet&#34; changes when the mouse goes to the Packet Details or Packet Bytes windows, making it indistinguishable from all other displayed packets. Is there a way to keep the highlighted color in these cases?
Thanks.
color highlight mouse details packetasked 02 Sep &#39;11, 03:19
Rambar48
1●1●1●1
accept rate: 0%
See this bug report for some discussion about this issue.
(02 Sep &#39;11, 06:04) Bill Meier ♦♦   </description>
    </item>
    
    <item>
      <title>10G Trace Tool</title>
      <link>/questions/6059/10g-trace-tool/</link>
      <pubDate>Fri, 02 Sep 2011 03:24:00 +0000</pubDate>
      
      <guid>/questions/6059/10g-trace-tool/</guid>
      <description>10G Trace Tool  0 We intend to setup a 10G/1G trace tool based on high end desktop components. The Wireshark and the Cace Pilot Software will be used. The system will be equipped with 1 TB SSD storage (PCI-e,2x 480GB) and should cover rates up to 3 Gbits/s.
Questions: Are the following Intel Network Card supported by Wireshark and Cace Pilot? - 4 port - 1G Ethernet: Intel Ethernet Server Adapter I340-T4 - 1 Port - 10g Ethernet: Intel 10G Network Adapter Multimode (E10G81GF2R)</description>
    </item>
    
    <item>
      <title>Outbound traffic to China</title>
      <link>/questions/6060/outbound-traffic-to-china/</link>
      <pubDate>Fri, 02 Sep 2011 04:35:00 +0000</pubDate>
      
      <guid>/questions/6060/outbound-traffic-to-china/</guid>
      <description>Outbound traffic to China  0 Brand new Checkpoint firewall. Super powered for the size of my organization. Quite an education. A few days ago I started seeing outbound traffic to a few IP&#39;s in China being Blocked by my egress rules (good times)The traffic is reverse lookup DNS queries (UDP 53) They happen about 15 times an hour or more. I&#39;m having a very tough time tracking where it&#39;s coming from.</description>
    </item>
    
    <item>
      <title>Checking out source code with git svn</title>
      <link>/questions/6069/checking-out-source-code-with-git-svn/</link>
      <pubDate>Sun, 04 Sep 2011 00:26:00 +0000</pubDate>
      
      <guid>/questions/6069/checking-out-source-code-with-git-svn/</guid>
      <description>Checking out source code with git svn  0 For a while I could check out the source code with git svn, but now it doesn&#39;t work anymore. The command I used:
git svn clone -s http://anonsvn.wireshark.org/wireshark/trunk/ .My computer shows some activities in CPU load, HDD, and even network traffic. But then after about 5 minutes it&#39;s just quit without any files downloaded after showing:
Initialized empty Git repository in /home/dev/workspace/wireshark/.</description>
    </item>
    
    <item>
      <title>How can i setup wireshark to display name for particular field in header?</title>
      <link>/questions/6073/how-can-i-setup-wireshark-to-display-name-for-particular-field-in-header/</link>
      <pubDate>Sun, 04 Sep 2011 09:04:00 +0000</pubDate>
      
      <guid>/questions/6073/how-can-i-setup-wireshark-to-display-name-for-particular-field-in-header/</guid>
      <description>How can i setup wireshark to display name for particular field in header?  0 Hi, I have a capture (TLV-[Type Length Value] capture) which shows all fields as Hex value.I want wireshark to display those fields as appropriate name instead of Hex value.Can anyone help me how to solve this one?
tlv pluginasked 04 Sep &#39;11, 09:04
JK7
31●11●12●14
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How can i get private key (RSA) from SSL traffic?</title>
      <link>/questions/6082/how-can-i-get-private-key-rsa-from-ssl-traffic/</link>
      <pubDate>Sun, 04 Sep 2011 20:33:00 +0000</pubDate>
      
      <guid>/questions/6082/how-can-i-get-private-key-rsa-from-ssl-traffic/</guid>
      <description>How can i get private key (RSA) from SSL traffic?  0 Hi, I have SSL packet capture and i want wireshark to decode the SSL traffic, for that i need RSA private key.Can anyone help me how to get that key from my SSL capture.
Thanks JK
ssl rsa keyasked 04 Sep &#39;11, 20:33
JK7
31●11●12●14
accept rate: 0%
  
One Answer:
  
3The private key cannot be extracted from the captured trace.</description>
    </item>
    
    <item>
      <title>tshark wlan conversation</title>
      <link>/questions/6090/tshark-wlan-conversation/</link>
      <pubDate>Mon, 05 Sep 2011 03:57:00 +0000</pubDate>
      
      <guid>/questions/6090/tshark-wlan-conversation/</guid>
      <description>tshark wlan conversation  0 How do I collect wlan conversation statistic using tshark? And not connected (authenticated) to the (wireless) LAN, in promiscuous mode. Tried: tshark -qz conv,wlan but wlan is not supported with tshark.
wlan is supported with wireshark... wireshark -k -i 1 -a duration:20 -z conv,wlan but the statistic can not be captured (or piped) to a file. If connected to wlan or lan, then following works well.</description>
    </item>
    
    <item>
      <title>offset in packet byte pane</title>
      <link>/questions/6091/offset-in-packet-byte-pane/</link>
      <pubDate>Mon, 05 Sep 2011 04:07:00 +0000</pubDate>
      
      <guid>/questions/6091/offset-in-packet-byte-pane/</guid>
      <description>offset in packet byte pane  0 1Hello,
I would like to have the packet byte pane show the payload bytes rather ..I.e. i would like the packet bytes pane to ignore the first 14 bytes...What has to be done to modify ??
bytes packetThis question is marked &#34;community wiki&#34;.asked 05 Sep &#39;11, 04:07
flashkicker
109●13●19●19
accept rate: 41%
  
2 Answers:
  
1 From your comment above you&#39;ll need to create a new tvb which is the subset of the original tvb using tvb_set_subset() or tvb_new_subset() or tvb_new_subset_remaining() as appropriate and then call add_new_data_source().</description>
    </item>
    
    <item>
      <title>capture DNS traffic of a gateway</title>
      <link>/questions/6098/capture-dns-traffic-of-a-gateway/</link>
      <pubDate>Mon, 05 Sep 2011 11:50:00 +0000</pubDate>
      
      <guid>/questions/6098/capture-dns-traffic-of-a-gateway/</guid>
      <description>capture DNS traffic of a gateway  0 hello!! for a project i have to capture traffic a gateway(DNS traffic).Sb offered me to use wireshark.could u please helpabout this.how i can do this.does wireshark anyoption to do this.I will be verry glad if you answer me.thank u :)
wiresharkThis question is marked &#34;community wiki&#34;.asked 05 Sep &#39;11, 11:50
Elahe
1●2●2●2
accept rate: 0%
1Have you read any of the documentation?</description>
    </item>
    
    <item>
      <title>monitor all traffic travelling through router</title>
      <link>/questions/6103/monitor-all-traffic-travelling-through-router/</link>
      <pubDate>Mon, 05 Sep 2011 23:08:00 +0000</pubDate>
      
      <guid>/questions/6103/monitor-all-traffic-travelling-through-router/</guid>
      <description>monitor all traffic travelling through router  0 How do i connect wireshark to a router, so that i can view the packets that are flowing through the router?
wiresharkThis question is marked &#34;community wiki&#34;.asked 05 Sep &#39;11, 23:08
Elahe
1●2●2●2
accept rate: 0%
  
One Answer:
  
0Have a look at the Capture setup page on the wiki, HERE. Note that most routers are switches, and if you can&#39;t force the router to span or mirror all traffic onto a monitoring port you won&#39;t be able to see all traffic.</description>
    </item>
    
    <item>
      <title>Add new columns in the Preferences</title>
      <link>/questions/6104/add-new-columns-in-the-preferences/</link>
      <pubDate>Mon, 05 Sep 2011 23:44:00 +0000</pubDate>
      
      <guid>/questions/6104/add-new-columns-in-the-preferences/</guid>
      <description>Add new columns in the Preferences  0 Hello,
I have added new columns along with default columns like Source,Destination,protocol etc in the epan/prefs.c init_prefs() function but they are not at all being reflected at the runtime.
development preferences columnsasked 05 Sep &#39;11, 23:44
Terrestrial ...
96●21●28●29
accept rate: 42%
 edited 06 Sep &#39;11, 16:18 
helloworld
3.1k●4●20●41
1Why are you trying to do this? Can&#39;t you just add a custom column?</description>
    </item>
    
    <item>
      <title>Set Custom name for Custom Package</title>
      <link>/questions/6106/set-custom-name-for-custom-package/</link>
      <pubDate>Mon, 05 Sep 2011 23:49:00 +0000</pubDate>
      
      <guid>/questions/6106/set-custom-name-for-custom-package/</guid>
      <description>Set Custom name for Custom Package  0 I have gone through the steps of Win32 step by step guide.I have also made a package of Wireshark but the setup package has Wireshark as its name and tooltip.Also the dialog boxes open while installing this custom made package are having title as wireshark in them. How to set a user defined name for custom packed wireshark by default?
packagingasked 05 Sep &#39;11, 23:49</description>
    </item>
    
    <item>
      <title>set a new layout as default</title>
      <link>/questions/6115/set-a-new-layout-as-default/</link>
      <pubDate>Tue, 06 Sep 2011 01:21:00 +0000</pubDate>
      
      <guid>/questions/6115/set-a-new-layout-as-default/</guid>
      <description>set a new layout as default  0 Hi Everyone,
I would like change the layout from default to layout_type_4. I tried changing epan/prefs.c line 1400+ (Wireshark 1.6.1), but that&#39;s not working.
development preferencesasked 06 Sep &#39;11, 01:21
Terrestrial ...
96●21●28●29
accept rate: 42%
 edited 06 Sep &#39;11, 16:27 
helloworld
3.1k●4●20●41
1Did you remove your user preferences before using the new Wireshark? It&#39;s possible that settings you had created previously are taking precedence over the defaults of your new version.</description>
    </item>
    
    <item>
      <title>Compiled Filter Expression</title>
      <link>/questions/6121/compiled-filter-expression/</link>
      <pubDate>Tue, 06 Sep 2011 04:11:00 +0000</pubDate>
      
      <guid>/questions/6121/compiled-filter-expression/</guid>
      <description>Compiled Filter Expression  0 What is Compiled Filter Expression in Color_Filtering?
epan wiresharkasked 06 Sep &#39;11, 04:11
Terrestrial ...
96●21●28●29
accept rate: 42%
  
One Answer:
  
1It&#39;s a filter expression (which has the same syntax as a display filter) that is used to select packets to be colorized in the Packet List pane. It&#39;s also known as a coloring rule.
answered 06 Sep &#39;11, 04:20</description>
    </item>
    
    <item>
      <title>how to capture from second machine?</title>
      <link>/questions/6127/how-to-capture-from-second-machine/</link>
      <pubDate>Tue, 06 Sep 2011 09:00:00 +0000</pubDate>
      
      <guid>/questions/6127/how-to-capture-from-second-machine/</guid>
      <description>how to capture from second machine?  0 hello I am trying to capture packages from another computer to get it all on the same PC. the other does not have wireshark installed, also need to install it or is not necessary? If this is possible can someone explain how to do this?
captureasked 06 Sep &#39;11, 09:00
kixote
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>WireShark support for BMC Remedy 7.6.x</title>
      <link>/questions/6131/wireshark-support-for-bmc-remedy-76x/</link>
      <pubDate>Tue, 06 Sep 2011 11:05:00 +0000</pubDate>
      
      <guid>/questions/6131/wireshark-support-for-bmc-remedy-76x/</guid>
      <description>WireShark support for BMC Remedy 7.6.x  0 Hello,
I am initiating search for monitoring tools for BMC Remedy 7.6.x system. I wanted to know if your tool is able to monitor Remedy and add value to our efforts to resolve ongoing issues, which we have yet to identify the source.
I appreciate any assistance you may be able to provide.
bmc remedyasked 06 Sep &#39;11, 11:05
markl
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to capture all control and mgmt packets?</title>
      <link>/questions/6141/how-to-capture-all-control-and-mgmt-packets/</link>
      <pubDate>Tue, 06 Sep 2011 15:19:00 +0000</pubDate>
      
      <guid>/questions/6141/how-to-capture-all-control-and-mgmt-packets/</guid>
      <description>How to capture all control and mgmt packets?  0 I&#39;m capturing with tcpdump and also via the wireshark gui. The dropped packets is 0 but I can clearly see that some clear-to-send / request-to-send and link layer ACK packets are missing. any idea why? I tried to increase the buffer to 100MB to see if it would help but no success.
capture tcpdumpasked 06 Sep &#39;11, 15:19
ddayan
41●15●17●20</description>
    </item>
    
    <item>
      <title>How do I use Wireshark?</title>
      <link>/questions/6144/how-do-i-use-wireshark/</link>
      <pubDate>Tue, 06 Sep 2011 18:48:00 +0000</pubDate>
      
      <guid>/questions/6144/how-do-i-use-wireshark/</guid>
      <description>How do I use Wireshark?  0 I&#39;m using wireshark on my desktop to see traffic. What exactly am I suppose to be looking for? There&#39;s all this stuff, and lots of it!!!
beginnerThis question is marked &#34;community wiki&#34;.asked 06 Sep &#39;11, 18:48
rm2dance
1●1●1●1
accept rate: 0%
 edited 06 Sep &#39;11, 21:40 
helloworld
3.1k●4●20●41
  
One Answer:
  
1That &#34;stuff&#34; is a bunch of network packets; specifically, it&#39;s data detected by the network interface you&#39;re currently monitoring with Wireshark.</description>
    </item>
    
    <item>
      <title>How to add text to register</title>
      <link>/questions/6148/how-to-add-text-to-register/</link>
      <pubDate>Tue, 06 Sep 2011 22:54:00 +0000</pubDate>
      
      <guid>/questions/6148/how-to-add-text-to-register/</guid>
      <description>How to add text to register  0 I would like to have proto_tree_add_text() in static hf_register_info hf[] = {}... i.e. i would like to display the text in the pane2 as a column in pane1....
dissectorThis question is marked &#34;community wiki&#34;.asked 06 Sep &#39;11, 22:54
flashkicker
109●13●19●19
accept rate: 41%
  
One Answer:
  
1 With proto_tree_add_text(), there is only a text label placed in pane2.</description>
    </item>
    
    <item>
      <title>colouring in pane 3</title>
      <link>/questions/6153/colouring-in-pane-3/</link>
      <pubDate>Wed, 07 Sep 2011 00:34:00 +0000</pubDate>
      
      <guid>/questions/6153/colouring-in-pane-3/</guid>
      <description>colouring in pane 3  0 Can we have colouring of bytes in pane3 from an offset specified ??
paneThis question is marked &#34;community wiki&#34;.asked 07 Sep &#39;11, 00:34
flashkicker
109●13●19●19
accept rate: 41%
  
One Answer:
  
1No, you can&#39;t do any coloring yourself in pane3 (unless you write that functionality from scratch). What will work is use the proto_tree_add_* functions, in which you can point to the offset in the tvb where your field begins and by supplying a length, all the bytes of your field will be highlighted when you select the field in the details pane (pane2).</description>
    </item>
    
    <item>
      <title>Hide trees in pane2</title>
      <link>/questions/6154/hide-trees-in-pane2/</link>
      <pubDate>Wed, 07 Sep 2011 00:39:00 +0000</pubDate>
      
      <guid>/questions/6154/hide-trees-in-pane2/</guid>
      <description>Hide trees in pane2  0 How to hide Ethernet and frame trees in pane 2.... (hiding without disabling )
dissectorasked 07 Sep &#39;11, 00:39
flashkicker
109●13●19●19
accept rate: 41%
  
2 Answers:
  
0 PROTO_ITEM_SET_HIDDEN(); worked for me
answered 07 Sep &#39;11, 04:14
flashkicker
109●13●19●19
accept rate: 41%
  
0You can always collapse the Frame and Ethernet trees to a single line (for each) by clicking on the &#34;</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t seem to see locally sent packets</title>
      <link>/questions/6161/cant-seem-to-see-locally-sent-packets/</link>
      <pubDate>Wed, 07 Sep 2011 01:30:00 +0000</pubDate>
      
      <guid>/questions/6161/cant-seem-to-see-locally-sent-packets/</guid>
      <description>Can&amp;rsquo;t seem to see locally sent packets  0 Hello
I am new to WireShark and it seems really good!
I have a C# client server application which is sending small packets over TCP using the TCPClient and NetworkStream objects.
They are sent to 127.0.0.1 port 3000
When I analyse my main network device, I can&#39;t seem to see the packets. I know they are sent because the client and server respond to them.</description>
    </item>
    
    <item>
      <title>How does wireshark dissect a PDCP-LTE header?</title>
      <link>/questions/6174/how-does-wireshark-dissect-a-pdcp-lte-header/</link>
      <pubDate>Wed, 07 Sep 2011 04:16:00 +0000</pubDate>
      
      <guid>/questions/6174/how-does-wireshark-dissect-a-pdcp-lte-header/</guid>
      <description>How does wireshark dissect a PDCP-LTE header?  0 How does wireshark dissect a PDCP-LTE header? I mean what should be the initial bytes in a raw packet data for it be identified as a PDCP-LTE packet by wireshark
pdcp-lteasked 07 Sep &#39;11, 04:16
Chaitanya Pr...
1●1●1●1
accept rate: 0%
Is this helpful? http://wiki.wireshark.org/PDCP-LTE
(07 Sep &#39;11, 10:09) Anders ♦PDCP is not a protocol that can just be passed to the dissector, you need to give it some context (see struct pdcp_lte_info in packet-pdcp-lte.</description>
    </item>
    
    <item>
      <title>Vulnerabilities in GTK&#43; 2.0 dll&amp;#x27;s in stable 1.6.1 version?</title>
      <link>/questions/6181/vulnerabilities-in-gtk-20-dlls-in-stable-161-version/</link>
      <pubDate>Wed, 07 Sep 2011 06:44:00 +0000</pubDate>
      
      <guid>/questions/6181/vulnerabilities-in-gtk-20-dlls-in-stable-161-version/</guid>
      <description>Vulnerabilities in GTK+ 2.0 dll&amp;rsquo;s in stable 1.6.1 version?  0 see: http://secunia.com/advisories/45815/ the 1.6.1 wireshark stable version contains the vulnerable version is a new wireshark on its way? Or is this not true? see below
Description
A vulnerability has been reported in GTK+, which can be exploited by malicious people to compromise an application using the library.
The vulnerability is caused due to the &#34;_gdk_input_wintab_init_check()&#34; (gdk/win32/gdkinput-win32.c) and the &#34;xp_theme_init()&#34; functions (modules/engines/ms-windows/xp_theme.</description>
    </item>
    
    <item>
      <title>Error File has 65536-byte packet when decoding Infiniband trace</title>
      <link>/questions/6189/error-file-has-65536-byte-packet-when-decoding-infiniband-trace/</link>
      <pubDate>Wed, 07 Sep 2011 08:30:00 +0000</pubDate>
      
      <guid>/questions/6189/error-file-has-65536-byte-packet-when-decoding-infiniband-trace/</guid>
      <description>Error File has 65536-byte packet when decoding Infiniband trace  0 Hello all, With Wireshark Version 1.6.1 (SVN Rev 38096 from /trunk-1.6), I get the error &#34;File has 65536-bye packet, bigger than maximum of of 65535&#34;.
mtu size is 65520 which is correct accoding to the Mellanox User Guide. DEVICE=ib0 HWADDR= IPADDR=10.3.1.1 NETMASK=255.255.0.0 BOOTPROTO=static ONBOOT=yes MTU=65520
Would someone know why the error is occuring and if there is any solution in Wireshark to overcome this problem.</description>
    </item>
    
    <item>
      <title>Extract certain bytes from packets programatically</title>
      <link>/questions/6203/extract-certain-bytes-from-packets-programatically/</link>
      <pubDate>Wed, 07 Sep 2011 19:11:00 +0000</pubDate>
      
      <guid>/questions/6203/extract-certain-bytes-from-packets-programatically/</guid>
      <description>Extract certain bytes from packets programatically  1 Hi,
I&#39;ve been searching for a way to do the following with no avail. I was hoping someone here could point me in the right direction.
The problem is this: I have a ton of wireshark traces containing varying amount of ISCSI packets. I need to parse out the command being sent by the initiator (in bytes) and write it to a file for each packet.</description>
    </item>
    
    <item>
      <title>Decimal point vs. decimal comma</title>
      <link>/questions/6207/decimal-point-vs-decimal-comma/</link>
      <pubDate>Thu, 08 Sep 2011 00:44:00 +0000</pubDate>
      
      <guid>/questions/6207/decimal-point-vs-decimal-comma/</guid>
      <description>Decimal point vs. decimal comma  0 I am currently copying conversation statistics provided by Wireshark to an Excel spreadsheet for further analysis.
It seems that the column &#34;Relative Start&#34; is using a decimal point while the column &#34;Duration&#34; uses a comma.
What format is Wireshark using? Is there a way to change Wireshark&#39;s behavior? BTW, my system locale is set to German (decimal comma, digit separator is a point)</description>
    </item>
    
    <item>
      <title>can not capture data packets in monitor mode with rt61</title>
      <link>/questions/6210/can-not-capture-data-packets-in-monitor-mode-with-rt61/</link>
      <pubDate>Thu, 08 Sep 2011 06:53:00 +0000</pubDate>
      
      <guid>/questions/6210/can-not-capture-data-packets-in-monitor-mode-with-rt61/</guid>
      <description>can not capture data packets in monitor mode with rt61  0 Hello,
My adapter is ralink rt61 (pci) and I’m working on centos6. According to CaptureSetup/WLAN, i made a monitor interface and then capture on it but only beacon and probe packets are captured. I have following questions but failed to get answer from Google. Is there anybody can help? Thanks.
1, the wlan0 interface does not support 802.11 link-layer head, is that true?</description>
    </item>
    
    <item>
      <title>can NOT capture secure packets eg https</title>
      <link>/questions/6211/can-not-capture-secure-packets-eg-https/</link>
      <pubDate>Thu, 08 Sep 2011 08:22:00 +0000</pubDate>
      
      <guid>/questions/6211/can-not-capture-secure-packets-eg-https/</guid>
      <description>can NOT capture secure packets eg https  0 my wireshark sniffer does not capture ssl/secure packets... searching packets for ssl or tcp.port == 443
gives nothing... any tip, to check/repair it? Interface is correct (only wifi have wep g)... also logged in Paypal and Gmail, but nothing...
ssl secure httpsasked 08 Sep &#39;11, 08:22
lse123ws
6●2●2●4
accept rate: 0%
  
One Answer:
  
3 If you&#39;re capturing on an encrypted (if you want to call a WEP connection encrypted, it&#39;s more of an obfuscation nowadays :-)) you might not see anything useful until you decrypt the traffic, provided you have access to the encryption keys.</description>
    </item>
    
    <item>
      <title>Protocol column shows 0x0800 instead of HTTP</title>
      <link>/questions/6212/protocol-column-shows-0x0800-instead-of-http/</link>
      <pubDate>Thu, 08 Sep 2011 09:36:00 +0000</pubDate>
      
      <guid>/questions/6212/protocol-column-shows-0x0800-instead-of-http/</guid>
      <description>Protocol column shows 0x0800 instead of HTTP  0 Using Wiresharks release 1.6.1, running on Windows 7. Wiresharks used to show protocol HTTP for a http packet. However, recently it cannot correctly show the protocol names, instead, it shows 0x0800 in the Protocol column. It seems Wiresharks cannot identify it is a http packet. The same problems happen to all the protocols above the IP layer. Reinstalled Wiresharks several times, got the same problem.</description>
    </item>
    
    <item>
      <title>What makes a packet an HTTP one</title>
      <link>/questions/6216/what-makes-a-packet-an-http-one/</link>
      <pubDate>Thu, 08 Sep 2011 12:50:00 +0000</pubDate>
      
      <guid>/questions/6216/what-makes-a-packet-an-http-one/</guid>
      <description>What makes a packet an HTTP one  2 1I am trying to figure out why WireShark does not treat a packet as an HTTP one. Here is the scenario: A client ( from port x) sends a GET request to a server (to port 80). In response, the server (from port 80) sends a packet to the client (to port 80). WireShark recognizes the client -&amp;gt; server packet as an HTTP one, but does not recognize the response packet as an HTTP one even though it has the status line HTTP/1.</description>
    </item>
    
    <item>
      <title>Open Sound Control OSC, how to filter</title>
      <link>/questions/6217/open-sound-control-osc-how-to-filter/</link>
      <pubDate>Thu, 08 Sep 2011 13:03:00 +0000</pubDate>
      
      <guid>/questions/6217/open-sound-control-osc-how-to-filter/</guid>
      <description>Open Sound Control OSC, how to filter  0 I am trying to filter so that I can view only OSC (open sound control, http://opensoundcontrol.org/spec-1_0). I don&#39;t know where to start. I searched the Internet for hours to find a simple utility to do this, but found nothing. I know Wireshark must be capable, but need help.
opensoundcontrol osc filtering display-filterasked 08 Sep &#39;11, 13:03
Ryan Webber
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Reading packet captures.</title>
      <link>/questions/6226/reading-packet-captures/</link>
      <pubDate>Thu, 08 Sep 2011 21:40:00 +0000</pubDate>
      
      <guid>/questions/6226/reading-packet-captures/</guid>
      <description>Reading packet captures.  0 Is there a &#34;reading packet captures for dummies&#34; anywhere? I just do not seem to understand a few things.
I would like to view images moving across the network as well as know how to decrypt and/or reassemble (for viewing) packet bytes.
Some of the wiki pages and tutorials just seem like mumbo jumbo to me.
Appreciate any help
reading packetsasked 08 Sep &#39;11, 21:40</description>
    </item>
    
    <item>
      <title>Wireshark Network Interface</title>
      <link>/questions/6227/wireshark-network-interface/</link>
      <pubDate>Thu, 08 Sep 2011 22:08:00 +0000</pubDate>
      
      <guid>/questions/6227/wireshark-network-interface/</guid>
      <description>Wireshark Network Interface  0 I am not able to see any interface in the interface list in capture options.Should I manually enter an interface?If yes, then what should i enter ? I am using ethernet connection.
networkinterfaceasked 08 Sep &#39;11, 22:08
aditya
1●1●1●1
accept rate: 0%
Google is your friend here.
(08 Sep &#39;11, 22:43) Jaap ♦   </description>
    </item>
    
    <item>
      <title>How to check plc network connection</title>
      <link>/questions/6230/how-to-check-plc-network-connection/</link>
      <pubDate>Fri, 09 Sep 2011 03:31:00 +0000</pubDate>
      
      <guid>/questions/6230/how-to-check-plc-network-connection/</guid>
      <description>How to check plc network connection  0 Hi,
I am new to Wireshark and not a network specialist, but I have a special question, and maybe Wireshark can help me with it. I have already read the documentation (partly), but I could not find an answer. So before spending hours I would like to ask a specialist. Maybe he or she knows right away. Here it is:
I built up a direct communication between two PCs (Win 7) using power line adaptors.</description>
    </item>
    
    <item>
      <title>Skip decoding unimplemented protocol?</title>
      <link>/questions/6231/skip-decoding-unimplemented-protocol/</link>
      <pubDate>Fri, 09 Sep 2011 08:18:00 +0000</pubDate>
      
      <guid>/questions/6231/skip-decoding-unimplemented-protocol/</guid>
      <description>Skip decoding unimplemented protocol?  0 Hi,
Is there a way to skip a certain number of bytes in the packet while decoding protocols in a packet using Wireshark? In other words, if Wireshark doesn&#39;t support a particular protocol (at the moment), is it possible to &#39;skip&#39; that protocol but be able to decode the next?
As an example consider a VxLAN encapsulated packet. As per the IETF draft, a VxLAN packet contains the following headers in the given order -</description>
    </item>
    
    <item>
      <title>Is it possible to see what on my computer is requesting a webpage to be opened?</title>
      <link>/questions/6232/is-it-possible-to-see-what-on-my-computer-is-requesting-a-webpage-to-be-opened/</link>
      <pubDate>Fri, 09 Sep 2011 09:22:00 +0000</pubDate>
      
      <guid>/questions/6232/is-it-possible-to-see-what-on-my-computer-is-requesting-a-webpage-to-be-opened/</guid>
      <description>Is it possible to see what on my computer is requesting a webpage to be opened?  0 http://websearch.linksys.com/?eg=-1367549799&amp;amp;job=blank
...is the site my computer keeps opening. If its already opened, Chrome will open up a new tab and will continue to do so.
If I leave my computer sitting idle for a while, I can come back and find 5+ tabs opened up in Google Chrome to the address, even if Chrome wasn&#39;t opened when I left my computer.</description>
    </item>
    
    <item>
      <title>Spectralink (SRP) encapsulation</title>
      <link>/questions/6234/spectralink-srp-encapsulation/</link>
      <pubDate>Fri, 09 Sep 2011 11:42:00 +0000</pubDate>
      
      <guid>/questions/6234/spectralink-srp-encapsulation/</guid>
      <description>Spectralink (SRP) encapsulation  0 Hi,
I am analyzing VoIP communications using Spectralink. Wireshark successfully detects IP protocol 119 as Spectralink, unluckily it&#39;s not able to dissect the data payload. Since there is no encryption, we can see the RTP contents in the bytes detail, but it&#39;s really hard to create filters on multiple conversations based on theses HEX values.
Even if the SRP protocol is quite old, it&#39;s still widely used today.</description>
    </item>
    
    <item>
      <title>destination MAC address not present on packet capture</title>
      <link>/questions/6237/destination-mac-address-not-present-on-packet-capture/</link>
      <pubDate>Fri, 09 Sep 2011 16:00:00 +0000</pubDate>
      
      <guid>/questions/6237/destination-mac-address-not-present-on-packet-capture/</guid>
      <description>destination MAC address not present on packet capture  0 This may be a very trivial question but I can&#39;t figure it out by myself. Examining a packet trace of a ping from node1 to node2 I see that in the echo/reply packets the destination MAC is not present under &#34;Linux cooked capture&#34; section on Wireshark.
The capture was obtained with tcpdump on Ubuntu.
Why the destination MAC address is not there?</description>
    </item>
    
    <item>
      <title>error when compiling wireshark1.2.9</title>
      <link>/questions/6244/error-when-compiling-wireshark129/</link>
      <pubDate>Sat, 10 Sep 2011 02:17:00 +0000</pubDate>
      
      <guid>/questions/6244/error-when-compiling-wireshark129/</guid>
      <description>error when compiling wireshark1.2.9  0 How can I compile Wireshark 1.2.9 successfully?
In Windows XP, I executed nmake -f Makefile.nmake all, but I get the following errors:
packet-ipmi-bridge.c packet-ipmi-chassis.c packet-ipmi-picmg.c packet-ipmi-se.c packet-ipmi-storage.c packet-ipmi-transport.c Generating Code... Compiling... packet-ipmi-pps.c packet-ipmi-update.c packet-dcerpc-nt.c Generating Code... NMAKE : fatal error U1077: &amp;#39;&amp;quot;C:\Program Files\Microsoft Visual Studio\VC98\bin\c l.exe&amp;quot;&amp;#39; : return code &amp;#39;0x2&amp;#39; Stop. NMAKE : fatal error U1077: &amp;#39;&amp;quot;C:\Program Files\Microsoft Visual Studio\VC98\bin\N MAKE.EXE&amp;quot;&amp;#39; : return code &amp;#39;0x2&amp;#39; Stop.</description>
    </item>
    
    <item>
      <title>Cant use editcap</title>
      <link>/questions/6246/cant-use-editcap/</link>
      <pubDate>Sat, 10 Sep 2011 04:43:00 +0000</pubDate>
      
      <guid>/questions/6246/cant-use-editcap/</guid>
      <description>Cant use editcap  0 Hi, first of all: I m sorry for my english.
I have the latest wireshark version 1.6.2 The Problem: When i try to open my xxx.eth file with wireshark, it shows me this error: &#34;This application has requested the Runtime to terminate it in an unusual way.&#34; The File is about 38 MB and should not be too big, wireshark already worked with 200 mb nd bigger files.</description>
    </item>
    
    <item>
      <title>Multiple MAC Addresses - Port Security - DCHP</title>
      <link>/questions/6260/multiple-mac-addresses-port-security-dchp/</link>
      <pubDate>Sat, 10 Sep 2011 18:20:00 +0000</pubDate>
      
      <guid>/questions/6260/multiple-mac-addresses-port-security-dchp/</guid>
      <description>Multiple MAC Addresses - Port Security - DCHP  0 I have a situation and will give as much data as I can to paint this picture. First this only happens to machines that are newly connected to the network. Second I have noticed there are some devices on the network that are static assigned, but are within the DHCP Pool with no reservations. Third we are running port-security with the shutdown feature on this Cisco Switch.</description>
    </item>
    
    <item>
      <title>How to create a filter for a particular field?</title>
      <link>/questions/6270/how-to-create-a-filter-for-a-particular-field/</link>
      <pubDate>Sun, 11 Sep 2011 08:05:00 +0000</pubDate>
      
      <guid>/questions/6270/how-to-create-a-filter-for-a-particular-field/</guid>
      <description>How to create a filter for a particular field?  1 1Hi, I want to create a display filter for a particular field. Please help me to finish my task.
HTTP Header:
Hypertext Transfer Protocol POST / HTTP/1.1\r\n Content-Type: text/xml; charset=utf-8\r\n SOAPAction: &amp;quot;create&amp;quot;\r\nHere, I want to create filter for the &amp;ldquo;SOAPAction&amp;rdquo; field.
http soap display-filterasked 11 Sep &amp;lsquo;11, 08:05
JK7
31●11●12●14
accept rate: 0%
 edited 11 Sep &amp;lsquo;11, 10:43</description>
    </item>
    
    <item>
      <title>Tool for splitting voip calls to separate files</title>
      <link>/questions/6277/tool-for-splitting-voip-calls-to-separate-files/</link>
      <pubDate>Mon, 12 Sep 2011 03:59:00 +0000</pubDate>
      
      <guid>/questions/6277/tool-for-splitting-voip-calls-to-separate-files/</guid>
      <description>Tool for splitting voip calls to separate files  1 Hi,
I have to deal with very large pcap files which include many voip (h323, sip, isup) calls. Of course it takes a lot time to open these large files and find the correct call on a desktop computer. Is there a tool to create individual pcap files for each voip call from a large file ?
Thanks.
pcap split voipasked 12 Sep &#39;11, 03:59</description>
    </item>
    
    <item>
      <title>Problem while access website through load balancer</title>
      <link>/questions/6278/problem-while-access-website-through-load-balancer/</link>
      <pubDate>Mon, 12 Sep 2011 04:53:00 +0000</pubDate>
      
      <guid>/questions/6278/problem-while-access-website-through-load-balancer/</guid>
      <description>Problem while access website through load balancer  0 I am facing problem while accessing web site through load balancer but it work fine when i call website directly.
After getting traces i found my client is retransmitting TCP packet with PSH+ACK four times and after that load balancer send TCP packet with RST flag.
Before that my client send SYN and successfully got SYN+ACK.
Please help me to find out whats wrong with it.</description>
    </item>
    
    <item>
      <title>Wireshark application termination</title>
      <link>/questions/6279/wireshark-application-termination/</link>
      <pubDate>Mon, 12 Sep 2011 05:28:00 +0000</pubDate>
      
      <guid>/questions/6279/wireshark-application-termination/</guid>
      <description>Wireshark application termination  0 1Hello All,
I hard-coded some changes to preferences through epan/prefs.c file. I also removed the preferences file present in C:\Doc &amp;amp; Settings\..\preferences. I was successful in reflecting the needed changes, but Wireshark aborts immediately if i click on the Cancel button of the Edit-&amp;gt;Preferences dialog box or File-&amp;gt;Quit option. Kindly resolve this issue.
Thanks, Regards, Prashanth
developmentasked 12 Sep &#39;11, 05:28
Terrestrial ...
96●21●28●29
accept rate: 42%</description>
    </item>
    
    <item>
      <title>How to tell how many requests my computer is sending to hosting server</title>
      <link>/questions/6281/how-to-tell-how-many-requests-my-computer-is-sending-to-hosting-server/</link>
      <pubDate>Mon, 12 Sep 2011 06:48:00 +0000</pubDate>
      
      <guid>/questions/6281/how-to-tell-how-many-requests-my-computer-is-sending-to-hosting-server/</guid>
      <description>How to tell how many requests my computer is sending to hosting server  0 Our web host is saying that they are getting 500 requests a second from our computer. This triggers an autoblock on the server and locks out our IP. How can I see what is causing those requests in Wireshark?
requestasked 12 Sep &#39;11, 06:48
Ohno
1●1●1●1
accept rate: 0%
For s atart: Do a short capture and then look at the capture.</description>
    </item>
    
    <item>
      <title>FCS check is not displayed</title>
      <link>/questions/6293/fcs-check-is-not-displayed/</link>
      <pubDate>Mon, 12 Sep 2011 11:41:00 +0000</pubDate>
      
      <guid>/questions/6293/fcs-check-is-not-displayed/</guid>
      <description>FCS check is not displayed  0 I cannot seem to configure Wireshark version 1.6.2 to identify an Ethernet FCS. I am using Wireshark to help verify the contents for a Frame Generator application that I am developing. The application is dumping out the contents of Ethernet frames in a &#34;text dump file&#34; in hex format that is able to be read into Wireshark . I simply input the &#34;text dump file&#34;</description>
    </item>
    
    <item>
      <title>using wireshark to debug http traffic on a non standard port</title>
      <link>/questions/6294/using-wireshark-to-debug-http-traffic-on-a-non-standard-port/</link>
      <pubDate>Mon, 12 Sep 2011 13:37:00 +0000</pubDate>
      
      <guid>/questions/6294/using-wireshark-to-debug-http-traffic-on-a-non-standard-port/</guid>
      <description>using wireshark to debug http traffic on a non standard port  0 I am debugging a web application that runs on a non standard http port, and because of this I do not get any HTTP packets in wireshark. Is there some way to have WS decode these packets as HTTP?
httpasked 12 Sep &#39;11, 13:37
jaylill
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Can not filter SSL traffic.</title>
      <link>/questions/6296/can-not-filter-ssl-traffic/</link>
      <pubDate>Mon, 12 Sep 2011 13:51:00 +0000</pubDate>
      
      <guid>/questions/6296/can-not-filter-ssl-traffic/</guid>
      <description>Can not filter SSL traffic.  1 Hi. I&#39;ve started a simple client/server application using SSL. Both, client and service, were built using Java. The SSL functionality was provided by JSSE, and the server is listening on port number 7070. Despite of existence of a SSL filter, I can not view any SSL traffic when I use it. I am sure there is no errors on applications. Everything I can see is the certificates being sent over the network, but just when I use a TCP filter on stream.</description>
    </item>
    
    <item>
      <title>Wireshark cannot dissect MMS packets that don&amp;#x27;t begin with Initiate</title>
      <link>/questions/6298/wireshark-cannot-dissect-mms-packets-that-dont-begin-with-initiate/</link>
      <pubDate>Mon, 12 Sep 2011 19:21:00 +0000</pubDate>
      
      <guid>/questions/6298/wireshark-cannot-dissect-mms-packets-that-dont-begin-with-initiate/</guid>
      <description>Wireshark cannot dissect MMS packets that don&amp;rsquo;t begin with Initiate  1 If Wireshark captures packets after Initiate Service (such as Initiate-Request and Initiate-Response), Wireshark dissects the message down to ISO8823 OSI Presentation Protocol, but the presentation data can&#39;t be decoded as MMS. How do I get the MMS portion to decode properly?
Network packet:
0000 aa c0 a8 06 c8 aa 00 21 70 6b 0c 67 08 00 45 00 .</description>
    </item>
    
    <item>
      <title>Ericsson R13 HLR decoding</title>
      <link>/questions/6319/ericsson-r13-hlr-decoding/</link>
      <pubDate>Tue, 13 Sep 2011 07:48:00 +0000</pubDate>
      
      <guid>/questions/6319/ericsson-r13-hlr-decoding/</guid>
      <description>Ericsson R13 HLR decoding  0 Hi, I am looking for a decoder for our HLR.
I stumbled onto this page while Googling and thought I would ask and see if anyone has experience with that?
Thanks
Johan
hlr r13asked 13 Sep &#39;11, 07:48
Johan
1●1●1●1
accept rate: 0%
are you still looking for a solution to decode HLR dump?
(26 Dec &#39;11, 23:58) BhushanKadu  
One Answer:</description>
    </item>
    
    <item>
      <title>Is there a &amp;quot;Quick Reference&amp;quot; for using DUMPCAP?</title>
      <link>/questions/6320/is-there-a-quick-reference-for-using-dumpcap/</link>
      <pubDate>Tue, 13 Sep 2011 08:11:00 +0000</pubDate>
      
      <guid>/questions/6320/is-there-a-quick-reference-for-using-dumpcap/</guid>
      <description>Is there a &amp;ldquo;Quick Reference&amp;rdquo; for using DUMPCAP?  1 I have need to run captures for a protracted period of time to try and catch an elusive problem. I need to be able to set capture filters for two IP hosts and I want to span multiple files, changing every 4 hours and I would like to be able to leave this running for several days without manual intervention.</description>
    </item>
    
    <item>
      <title>[closed] interference from fluorescent light</title>
      <link>/questions/6321/interference-from-fluorescent-light/</link>
      <pubDate>Tue, 13 Sep 2011 08:24:00 +0000</pubDate>
      
      <guid>/questions/6321/interference-from-fluorescent-light/</guid>
      <description>[closed] interference from fluorescent light  0 can a fluorescent light fixture cause network interference if cat5 cables are 1 ft away from the fixture?
fluorescent interference lightasked 13 Sep &#39;11, 08:24
net_tech
116●30●33●37
accept rate: 13%
 closed 13 Sep &#39;11, 09:01 
helloworld
3.1k●4●20●41
 The question has been closed for the following reason &amp;ldquo;Question is off-topic or not relevant&amp;rdquo; by helloworld 13 Sep &amp;lsquo;11, 09:01    </description>
    </item>
    
    <item>
      <title>Data filter by byte not string</title>
      <link>/questions/6324/data-filter-by-byte-not-string/</link>
      <pubDate>Tue, 13 Sep 2011 09:14:00 +0000</pubDate>
      
      <guid>/questions/6324/data-filter-by-byte-not-string/</guid>
      <description>Data filter by byte not string  0 Hello All,
I want to search on the Data field of a TCP packet where I can search on a data byte pattern not a data string, Is this possible, if so how?
Regards
B
display-filterasked 13 Sep &#39;11, 09:14
Baz
31●2●2●4
accept rate: 0%
 edited 13 Sep &#39;11, 10:16 
helloworld
3.1k●4●20●41
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark from the command line</title>
      <link>/questions/6328/wireshark-from-the-command-line/</link>
      <pubDate>Tue, 13 Sep 2011 13:32:00 +0000</pubDate>
      
      <guid>/questions/6328/wireshark-from-the-command-line/</guid>
      <description>Wireshark from the command line  0 We need to tracing at the same time every day until we can nail down a problem we are having with our system (which is intermittent). It is a machine with multiple interfaces but only one is involved in the problem.
When we start up wireshark on the server and have it write to a file it locks up / dies after about 50 minutes.</description>
    </item>
    
    <item>
      <title>How can I view stream lists</title>
      <link>/questions/6333/how-can-i-view-stream-lists/</link>
      <pubDate>Tue, 13 Sep 2011 15:14:00 +0000</pubDate>
      
      <guid>/questions/6333/how-can-i-view-stream-lists/</guid>
      <description>How can I view stream lists  1 I like to see the list of TCP streams from my packet capture. Something like this:
Source Dest Prot Port Start End 1.1.1.1 -&amp;gt; 2.2.2.2 TCP 445 12:00:00.000 12:00:03.000 1.1.1.1 -&amp;gt; 3.3.3.3 TCP 80 12:00:04.000 12:00:05.000 1.1.1.1 -&amp;gt; 2.2.2.2 TCP 445 12:00:07.000 12:00:09.000 (a different stream than the first)I looked at Statistics/FlowGraphs, but that seems to show all the SYN/ACK details in each stream (too much information to go though).</description>
    </item>
    
    <item>
      <title>How do I listen to my computer only?</title>
      <link>/questions/6334/how-do-i-listen-to-my-computer-only/</link>
      <pubDate>Tue, 13 Sep 2011 19:35:00 +0000</pubDate>
      
      <guid>/questions/6334/how-do-i-listen-to-my-computer-only/</guid>
      <description>How do I listen to my computer only?  0 How do I listen to my computer only?
Because I only want to detect all the connections that my computer is making on a specific app.
only computer my listenasked 13 Sep &#39;11, 19:35
chris0990
1●1●1●1
accept rate: 0%
  
2 Answers:
  
3The easiest way is to create a capture filter for the mac-address of your computer.</description>
    </item>
    
    <item>
      <title>What exactly is happening?</title>
      <link>/questions/6341/what-exactly-is-happening/</link>
      <pubDate>Wed, 14 Sep 2011 00:42:00 +0000</pubDate>
      
      <guid>/questions/6341/what-exactly-is-happening/</guid>
      <description>What exactly is happening?  0 hi, first things first; i am a noob so i will be asking noobish questions
i just captured a session for my LAN and was reading some intriguing traffic,
apparently my ip address is sending check sums (i believe they are check sums due to the the pattern and byte-size,via UDP to a IP address in germany,
from the logs now i googled the MAC address and got that LiteOne Tech, apparently they manufacture routers and such, now i have a wireless netgear router and it appears the source is this LiteOne router and the destination is the netgear router, can someone explain or expound further on what exactly this traffic means?</description>
    </item>
    
    <item>
      <title>how to tshark mms packets which are ISO/FDIS 9506-2</title>
      <link>/questions/6343/how-to-tshark-mms-packets-which-are-isofdis-9506-2/</link>
      <pubDate>Wed, 14 Sep 2011 01:08:00 +0000</pubDate>
      
      <guid>/questions/6343/how-to-tshark-mms-packets-which-are-isofdis-9506-2/</guid>
      <description>how to tshark mms packets which are ISO/FDIS 9506-2  1 some kind person tell me &#34;Edit-&amp;gt;preferences-&amp;gt;protocol-&amp;gt;PRES and edit the users context tale enter context = 3 and OID = 1.0.9506.2.3 and your trace will be dissected as MMS.&#34;
i want to use &#34;tshak&#34; convert packets to text, such as &#34;tshak -r d:sg1.pcap -V -T text &amp;gt; d:sg1.txt&#34;.
how to make the contents in text to appear the result of &#34;</description>
    </item>
    
    <item>
      <title>rpm Packaging error</title>
      <link>/questions/6344/rpm-packaging-error/</link>
      <pubDate>Wed, 14 Sep 2011 01:10:00 +0000</pubDate>
      
      <guid>/questions/6344/rpm-packaging-error/</guid>
      <description>rpm Packaging error  0 1I have tried to do the packaging of wireshark-1.6.1
OS: Fedora 2.6.35.6-45.fc14.x86_64
# make rpm-package results in :
configure: error: SSL crypto library was requested, but is not available error: Bad exit status from /var/tmp/rpm-tmp.k6KXRS (%prep) RPM build errors: Bad exit status from /var/tmp/rpm-tmp.k6KXRS (%prep) make: *** [rpm-package] Error 1packagingThis question is marked &#34;community wiki&#34;.asked 14 Sep &#39;11, 01:10
flashkicker
109●13●19●19
accept rate: 41%
 edited 14 Sep &#39;11, 04:08</description>
    </item>
    
    <item>
      <title>Custom Packaging isn&amp;#x27;t reflecting any gtk changes</title>
      <link>/questions/6345/custom-packaging-isnt-reflecting-any-gtk-changes/</link>
      <pubDate>Wed, 14 Sep 2011 01:11:00 +0000</pubDate>
      
      <guid>/questions/6345/custom-packaging-isnt-reflecting-any-gtk-changes/</guid>
      <description>Custom Packaging isn&amp;rsquo;t reflecting any gtk changes  0 Hi Everyone, I have made some changes to gtk files and created an installer. Unfortunately, When I&#39;ve installed it and checked for changes, there were no gtk changes done to Wireshark Interfaces. It is showing the default one. How can i make my custom installer to reflect the gtk changes too?
wireshark packageasked 14 Sep &#39;11, 01:11
Terrestrial ...
96●21●28●29
accept rate: 42%</description>
    </item>
    
    <item>
      <title>how to generate dsp file in VS2008EE by Wireshark&amp;#x27;s source codes?</title>
      <link>/questions/6350/how-to-generate-dsp-file-in-vs2008ee-by-wiresharks-source-codes/</link>
      <pubDate>Wed, 14 Sep 2011 01:59:00 +0000</pubDate>
      
      <guid>/questions/6350/how-to-generate-dsp-file-in-vs2008ee-by-wiresharks-source-codes/</guid>
      <description>how to generate dsp file in VS2008EE by Wireshark&amp;rsquo;s source codes?  0 i want to debug the Wireshark&#39;s source codes in VS2008EE, but there are only makefile, not dsp file.
how to generate dsp file in VS2008EE by Wireshark&#39;s source codes?
windows debug generate dsp wiresharkasked 14 Sep &#39;11, 01:59
ylda_ljm0620
31●10●10●13
accept rate: 0%
 edited 14 Sep &#39;11, 12:31 
Bill Meier ♦♦
3.2k●1●8●50</description>
    </item>
    
    <item>
      <title>How is the time duration field of an SSL session computed?</title>
      <link>/questions/6355/how-is-the-time-duration-field-of-an-ssl-session-computed/</link>
      <pubDate>Wed, 14 Sep 2011 04:30:00 +0000</pubDate>
      
      <guid>/questions/6355/how-is-the-time-duration-field-of-an-ssl-session-computed/</guid>
      <description>How is the time duration field of an SSL session computed?  0 I am trying to figure out how you can tell the time duration of an SSL session. In Wireshark, if you choose from the File Menu Statistics -&amp;gt; Conversations -&amp;gt; TCP -&amp;gt; Limit to filter, you get results based on your filter. If I choose &#34;SSL&#34; as my filter than all the results would be SSL packets/sessions. My question is &#34;</description>
    </item>
    
    <item>
      <title>wireshark is not capturing ping/ICMP packets. Why?</title>
      <link>/questions/6362/wireshark-is-not-capturing-pingicmp-packets-why/</link>
      <pubDate>Wed, 14 Sep 2011 07:20:00 +0000</pubDate>
      
      <guid>/questions/6362/wireshark-is-not-capturing-pingicmp-packets-why/</guid>
      <description>wireshark is not capturing ping/ICMP packets. Why?  0 I an running wireshark on two different computers, one is a Linux (Lucid Lynx), and the other is running BackTrack4. Both computers are on the same network. Wireshark is listening on eth0 of both computers. No filters are set, and all traffic is visible. Browser requests show up, secure shell connections show up, and all sorts of assorted network traffic between the other computers on the network are also visible.</description>
    </item>
    
    <item>
      <title>SSL capture</title>
      <link>/questions/6368/ssl-capture/</link>
      <pubDate>Wed, 14 Sep 2011 13:11:00 +0000</pubDate>
      
      <guid>/questions/6368/ssl-capture/</guid>
      <description>SSL capture  0 I have my SSL client&#39;s encrypted RSA key. I&#39;m trying to capture the SSL traffic on a PC in the network. I understand that there are some settings I need to do on the wireshark or decrypt key. Please help me on how to do this.
Thanks a lot
sslasked 14 Sep &#39;11, 13:11
jennyliusd
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark Professional Services</title>
      <link>/questions/6383/wireshark-professional-services/</link>
      <pubDate>Thu, 15 Sep 2011 04:07:00 +0000</pubDate>
      
      <guid>/questions/6383/wireshark-professional-services/</guid>
      <description>Wireshark Professional Services  0 Hi all,
Can anybody tell me what the options are with respect of obtaining professional services/consultancy on architecting a solution based around Wireshark for the analysis of a fairly extensive network environment. I suspect this would include multiple capture devices being centrally managed within a security conscious environment. We&#39;re based in the UK and would require UK based people for this work.
Kind Regards
Ozric</description>
    </item>
    
    <item>
      <title>wlan Link layer retransmissions</title>
      <link>/questions/6386/wlan-link-layer-retransmissions/</link>
      <pubDate>Thu, 15 Sep 2011 06:42:00 +0000</pubDate>
      
      <guid>/questions/6386/wlan-link-layer-retransmissions/</guid>
      <description>wlan Link layer retransmissions  0 How can I filter the link layer retransmissions of wireless packets?
wireless retransmissionsasked 15 Sep &#39;11, 06:42
ddayan
41●15●17●20
accept rate: 0%
  
One Answer:
  
2 wlan.fc.retry == 1
answered 19 Sep &#39;11, 02:37
Landi
2.3k●5●14●42
accept rate: 28%
     </description>
    </item>
    
    <item>
      <title>Wireshark crashes on OSX 10.5 on startup, from macports</title>
      <link>/questions/6388/wireshark-crashes-on-osx-105-on-startup-from-macports/</link>
      <pubDate>Thu, 15 Sep 2011 07:11:00 +0000</pubDate>
      
      <guid>/questions/6388/wireshark-crashes-on-osx-105-on-startup-from-macports/</guid>
      <description>Wireshark crashes on OSX 10.5 on startup, from macports  0 1I am trying to run wireshark on mac os x 10.5 leopard. I&#39;ve installed it successfully via port.
However, when I try to run it, wireshark crashes immediately. I tried uninstalling and installing from the .dmg file instead, but the same problem occurred. I can run other X11 programs without an issue. I am getting a EXC_BAD_ACCESS (SIGBUS) type error.</description>
    </item>
    
    <item>
      <title>Network Analysis</title>
      <link>/questions/6390/network-analysis/</link>
      <pubDate>Thu, 15 Sep 2011 07:40:00 +0000</pubDate>
      
      <guid>/questions/6390/network-analysis/</guid>
      <description>Network Analysis  0 I am trying to do some network analysis to find out why one of my switches is so slow. As a test, I created a capture during which I copied a file from the host system to another system on the network. In the capture, I could see at least 20 other systems that were communicating with my host. I tried to determine what some of them were, and I could see that several were related to Windows Media Player and schemas.</description>
    </item>
    
    <item>
      <title>Ability to view pcap files outside of wireshark</title>
      <link>/questions/6391/ability-to-view-pcap-files-outside-of-wireshark/</link>
      <pubDate>Thu, 15 Sep 2011 07:47:00 +0000</pubDate>
      
      <guid>/questions/6391/ability-to-view-pcap-files-outside-of-wireshark/</guid>
      <description>Ability to view pcap files outside of wireshark  1 Is it possible to view pcap files outside of Wireshark? We have a need to analyse captured packets on our main network, the problem is that we are not allowed to have Wireshark insalled within our network.
windows readpcapasked 15 Sep &#39;11, 07:47
MrBeaker
16●1●1●2
accept rate: 0%
The pcap files generated by Wireshark (or dumpcap, etc) do not contain any dissection (analysis) data.</description>
    </item>
    
    <item>
      <title>Import text file with timestamps</title>
      <link>/questions/6396/import-text-file-with-timestamps/</link>
      <pubDate>Thu, 15 Sep 2011 08:40:00 +0000</pubDate>
      
      <guid>/questions/6396/import-text-file-with-timestamps/</guid>
      <description>Import text file with timestamps  0 Do you have an example of a text file for importing that has timestamps in the text file? I have tried the following with the %S format for Date/Time but the timestamp for all frames is displayed as 0.000000 in WireShark.
 0.000200 0000 e0 9f 97 1c 0004 20 5c 66 ae 0008 19 d1 a6 80 000c 08 00 45 00 0010 00 99 00 00 0014 40 00 ff 06 0018 a8 7f 85 2d 001c f7 e1 b5 d6 0020 9f f9 01 da 0024 01 da 00 00 0028 00 00 00 00 002c 00 00 50 18 0030 ff ff 27 e2 0034 00 00 55 5c 0038 03 96 8f 9a 003c a1 f8 73 69 0.</description>
    </item>
    
    <item>
      <title>Wireshark 1.6.2 crashes when trying to customize column</title>
      <link>/questions/6406/wireshark-162-crashes-when-trying-to-customize-column/</link>
      <pubDate>Thu, 15 Sep 2011 13:10:00 +0000</pubDate>
      
      <guid>/questions/6406/wireshark-162-crashes-when-trying-to-customize-column/</guid>
      <description>Wireshark 1.6.2 crashes when trying to customize column  0 Version 1.6.2 (SVN Rev 38931 from /trunk-1.6) Windows 7, 64-bit
Wireshark crashes when trying to customize a column as eth.vlan.id, instance 1. This when the 802.1Q VLAN id column is visible and then selected for customization.
The capture does include packets from q-in-q trunk. The standard 802.1Q VLAN id only displays the innermost (instance 2) VLAN tag.
Creating the custom column from Edit/Pref/Columns does seem to work.</description>
    </item>
    
    <item>
      <title>command of tshark can not support Chinese path or Chinese file name</title>
      <link>/questions/6407/command-of-tshark-can-not-support-chinese-path-or-chinese-file-name/</link>
      <pubDate>Thu, 15 Sep 2011 19:20:00 +0000</pubDate>
      
      <guid>/questions/6407/command-of-tshark-can-not-support-chinese-path-or-chinese-file-name/</guid>
      <description>command of tshark can not support Chinese path or Chinese file name  0 tshark` fails if its parameters contain Chinese characters (in a path parameter). For example:
tshark -r d:\中文.pcap -V -T text &amp;gt; d:\1.txtwireshark 1.5.1 has solved the problem. but how to correct the source code if i just want to use wireshark1.2.9 ? which code of wireshark1.2.9 should be modified in order to solve the problem.
Thanks.</description>
    </item>
    
    <item>
      <title>can  wireshark disable 61850SMV dissector by user?</title>
      <link>/questions/6413/can-wireshark-disable-61850smv-dissector-by-user/</link>
      <pubDate>Fri, 16 Sep 2011 02:46:00 +0000</pubDate>
      
      <guid>/questions/6413/can-wireshark-disable-61850smv-dissector-by-user/</guid>
      <description>can wireshark disable 61850SMV dissector by user?  0 as the title.
i want to make wireshark1.5.1(or new vertion) dissects 61850SMV as wireshark1.2.9 remaining hex packets.
can it done through settting something on wiresahrk interface?
how to set parameters of tshark in commondline to disable 61850SMV dissector?
disable dissectorasked 16 Sep &#39;11, 02:46
ylda_ljm0620
31●10●10●13
accept rate: 0%
 edited 17 Sep &#39;11, 06:07 
  
One Answer:</description>
    </item>
    
    <item>
      <title>Message &amp;quot;Can&amp;#x27;t dissect FP frame because no per-frame info was attached!&amp;quot;</title>
      <link>/questions/6414/message-cant-dissect-fp-frame-because-no-per-frame-info-was-attached/</link>
      <pubDate>Fri, 16 Sep 2011 04:10:00 +0000</pubDate>
      
      <guid>/questions/6414/message-cant-dissect-fp-frame-because-no-per-frame-info-was-attached/</guid>
      <description>Message &amp;ldquo;Can&amp;rsquo;t dissect FP frame because no per-frame info was attached!&amp;quot;  0 My program exports data in PCAP format. In exports present data in FP. Wireshark recognize FP protocol, but indicates message &#34;Can&#39;t dissect FP frame because no per-frame info was attached!&#34; How I must &#34;attached per-frame info&#34; and in witch format?
fpasked 16 Sep &#39;11, 04:10
SergeSPB
1●1●1●1
accept rate: 0%
Hi, Take a look at the fp_info struct in packet-umts_fp.</description>
    </item>
    
    <item>
      <title>No Interfaces found on Mac OS X</title>
      <link>/questions/6420/no-interfaces-found-on-mac-os-x/</link>
      <pubDate>Fri, 16 Sep 2011 07:38:00 +0000</pubDate>
      
      <guid>/questions/6420/no-interfaces-found-on-mac-os-x/</guid>
      <description>No Interfaces found on Mac OS X  1 Why am I getting no interfaces found? How do I define an interface?
I get this message when I click on &#34;Interfaces&#34; on the main screen:
There are no interfaces on which a capture can be done.
I am using Mac OS X 10.5.8 - Leopard
osx interfaces mac missingasked 16 Sep &#39;11, 07:38
Rudi1055
56●1●1●3
accept rate: 100%
 edited 29 Feb &#39;12, 23:47</description>
    </item>
    
    <item>
      <title>Wireshark on University Network</title>
      <link>/questions/6423/wireshark-on-university-network/</link>
      <pubDate>Fri, 16 Sep 2011 09:01:00 +0000</pubDate>
      
      <guid>/questions/6423/wireshark-on-university-network/</guid>
      <description>Wireshark on University Network  0 Hello,
I am teaching a Computer Networks class, and I have access to my University wired and wireless computer network. I am an ordinary user, and I do not have any network administrative privilege.
If I use Wireshark installed on my laptop computer while the computer is connected to the University network, can it compromise other network users&#39; privacy/security?
What impact my occasional use of Wireshark can have on the University network and where can I find such documentation that I can share with concerned people?</description>
    </item>
    
    <item>
      <title>SSL Decryption Problems</title>
      <link>/questions/6426/ssl-decryption-problems/</link>
      <pubDate>Fri, 16 Sep 2011 10:17:00 +0000</pubDate>
      
      <guid>/questions/6426/ssl-decryption-problems/</guid>
      <description>SSL Decryption Problems  0 I am trying to decrypt an SSL Session in Wireshark. I have loaded the p12 file(including password) into wireshark. Here is the debug output:
2686 bytes read PKCS#12 imported Bag 0/0: PKCS#8 Encrypted key Private key imported: KeyID &amp;lt;keyID#1&amp;gt;... Bag 1/0: Encrypted Bag 1/0 decrypted: Certificate Certificate imported: &amp;lt;password&amp;gt; &amp;lt;&amp;lt;remoteDomain&amp;gt;&amp;gt;, KeyID &amp;lt;keyID#2&amp;gt; ssl_init IPv4 addr &amp;#39;&amp;lt;LocalIP&amp;gt;&amp;#39; (&amp;lt;LocalIP&amp;gt;) port &amp;#39;59199&amp;#39; filename &amp;#39;C:\Users\dbeutler\Desktop\test.p12&amp;#39; &amp;lt;password&amp;gt;(only for p12 file) &amp;#39;&amp;lt;password&amp;gt;&amp;#39; ssl_init private key file C:\Users\dbeutler\Desktop\test.</description>
    </item>
    
    <item>
      <title>Analyze per IP</title>
      <link>/questions/6430/analyze-per-ip/</link>
      <pubDate>Sat, 17 Sep 2011 02:32:00 +0000</pubDate>
      
      <guid>/questions/6430/analyze-per-ip/</guid>
      <description>Analyze per IP  0 I&#39;m desperately trying to determine which clients (IP) are causing a large amount of lag to my server. I have been able to manually scan packet data with IP filters to determine which ones have a large bad packets / total packet ratio, but this is a very labor intensive process. Is there a way to display all clients simultaneously and their &#34;bad&#34; packets / their total packets ratio?</description>
    </item>
    
    <item>
      <title>The capture session could not be initiated (just on windows) ?</title>
      <link>/questions/6433/the-capture-session-could-not-be-initiated-just-on-windows/</link>
      <pubDate>Sat, 17 Sep 2011 10:10:00 +0000</pubDate>
      
      <guid>/questions/6433/the-capture-session-could-not-be-initiated-just-on-windows/</guid>
      <description>The capture session could not be initiated (just on windows) ?  0 Hello.
When i try to capture on windows seven i get this error :
&#34;The capture session could not be initiated (failed to set hardware filter to promiscuous mode). Please check that &#34;DeviceNPF_{2879FC56-FA35-48DF-A0E7-6A2532417BFF}&#34; is the proper interface.&#34;
I made i search about that and i found that it was impossible de do that on windows without deactivating the promiscuous mode.</description>
    </item>
    
    <item>
      <title>Is it possible to change the behavior of the &amp;quot;unanswered&amp;quot; tab so it only returns questions with 0 answers?</title>
      <link>/questions/6438/is-it-possible-to-change-the-behavior-of-the-unanswered-tab-so-it-only-returns-questions-with-0-answers/</link>
      <pubDate>Sun, 18 Sep 2011 17:49:00 +0000</pubDate>
      
      <guid>/questions/6438/is-it-possible-to-change-the-behavior-of-the-unanswered-tab-so-it-only-returns-questions-with-0-answers/</guid>
      <description>Is it possible to change the behavior of the &amp;ldquo;unanswered&amp;rdquo; tab so it only returns questions with 0 answers?  0 Basically, I am wondering if it&#39;s possible if we implement what dougvk apparently already has in his answer to this question at OSQA.
While we&#39;re at it, I would like to be able to sort by views as well. dougvk has apparently found a solution for that as well, which he provides in the same answer.</description>
    </item>
    
    <item>
      <title>WireShark crashes on save when not stopped</title>
      <link>/questions/6440/wireshark-crashes-on-save-when-not-stopped/</link>
      <pubDate>Sun, 18 Sep 2011 18:49:00 +0000</pubDate>
      
      <guid>/questions/6440/wireshark-crashes-on-save-when-not-stopped/</guid>
      <description>WireShark crashes on save when not stopped  0 WireShark 1.6.2, including WinPcap. Also happens with 1.6.1. When I close the program, and answer the prompt to save, it appears to save, and then throws a Run-Time library exception. If I stop the capture and then exit/save, it works. This used to work fine. Any ideas? Thank you.
Alex
onsave nostop crash wiresharkasked 18 Sep &#39;11, 18:49
awinguru
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Does number of lines in dissector affect wireshark ??</title>
      <link>/questions/6445/does-number-of-lines-in-dissector-affect-wireshark/</link>
      <pubDate>Mon, 19 Sep 2011 06:29:00 +0000</pubDate>
      
      <guid>/questions/6445/does-number-of-lines-in-dissector-affect-wireshark/</guid>
      <description>Does number of lines in dissector affect wireshark ??  0 for large code in a dissector will the wireshark functionality be affected..
dissectorasked 19 Sep &#39;11, 06:29
flashkicker
109●13●19●19
accept rate: 41%
  
One Answer:
  
1 The time it takes to compile the dissector will be affected.
answered 19 Sep &#39;11, 08:36
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%
Thanks i was concerned ....
(19 Sep &#39;11, 21:46) flashkicker     </description>
    </item>
    
    <item>
      <title>tshark fail when it uses filename with space</title>
      <link>/questions/6453/tshark-fail-when-it-uses-filename-with-space/</link>
      <pubDate>Mon, 19 Sep 2011 23:37:00 +0000</pubDate>
      
      <guid>/questions/6453/tshark-fail-when-it-uses-filename-with-space/</guid>
      <description>tshark fail when it uses filename with space  0 tshark in commonline fail if the pcap file name contain spaces.
example1: tshark -r d:中文 test.pcap example2: tshark -r C:Documents and SettingsAdministrator桌面test.pcap
why wireshark GUI can open and disscet the file whose name contain spaces, how to solve the problem when using tshark?
tshark spaceasked 19 Sep &#39;11, 23:37
ylda_ljm0620
31●10●10●13
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Connection drop issue</title>
      <link>/questions/6455/connection-drop-issue/</link>
      <pubDate>Tue, 20 Sep 2011 00:48:00 +0000</pubDate>
      
      <guid>/questions/6455/connection-drop-issue/</guid>
      <description>Connection drop issue  0 I am having a desktop application which can talk to a server application using TCP/IP. It was working all these days but now we ran into an issue. The log message in the server shows that the socket is disconnected after a while, but we are able to exchange heart beat messages even after that. When i ran the Wireshark tool i am getting this log which i dont know how to interpret.</description>
    </item>
    
    <item>
      <title>Filter for NO Response</title>
      <link>/questions/6460/filter-for-no-response/</link>
      <pubDate>Tue, 20 Sep 2011 06:05:00 +0000</pubDate>
      
      <guid>/questions/6460/filter-for-no-response/</guid>
      <description>Filter for NO Response  0 I use Wireshark to collect information for Radius and LDAP connections. I would like to sort or filter out the packets that have a response, meaning I don’t want to see the packets when they get acknowledged. I only want to see packets that time out or do not get acknowledged. I would like to be able to get all the Radius packets that received no response at all.</description>
    </item>
    
    <item>
      <title>Torrent download capture</title>
      <link>/questions/6466/torrent-download-capture/</link>
      <pubDate>Tue, 20 Sep 2011 09:18:00 +0000</pubDate>
      
      <guid>/questions/6466/torrent-download-capture/</guid>
      <description>Torrent download capture  0 Hi, my network is 100pc&#39;s big and would like to know how to capture traffic from clients downloading through torrents such as bittorrent and utorrent. My ISP has given me a warning on copyright violation because someone is downloading movies on our business internet. And not all pc&#39;s can be proxied.
Thx
download capture torrentasked 20 Sep &#39;11, 09:18
Frederick Botha
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Dropped connections from Windows Client to Unix box</title>
      <link>/questions/6468/dropped-connections-from-windows-client-to-unix-box/</link>
      <pubDate>Tue, 20 Sep 2011 12:58:00 +0000</pubDate>
      
      <guid>/questions/6468/dropped-connections-from-windows-client-to-unix-box/</guid>
      <description>Dropped connections from Windows Client to Unix box  0 Hi, I am completely new to WireShark and have been struggling to find out why random telnet sessions (Windows XP clients to an older SCO Unix) have been getting dropped lately. We have been working fine since 2000, but over the last couple of years the dropped sessions started, but lately have gotten worse. I was able to download and run WireShark on one of the PC&#39;s that experienced a dropped connection today.</description>
    </item>
    
    <item>
      <title>Wireshark 1.6.2 Crashes in SMI.DLL</title>
      <link>/questions/6470/wireshark-162-crashes-in-smidll/</link>
      <pubDate>Tue, 20 Sep 2011 16:36:00 +0000</pubDate>
      
      <guid>/questions/6470/wireshark-162-crashes-in-smidll/</guid>
      <description>Wireshark 1.6.2 Crashes in SMI.DLL  0 I loaded the latest WireShark (after making sure the last version was completely erased), and tried to run it. I got the error signature; AppName: wireshark.exe AppVer: 1.6.2.38931 ModName: smi.dll ModVer: 0.0.0.0 Offset: 0000265b
I have used Wireshark for a while, with earlier versions, with no problem. I even tried to load an earlier version, but get the same error.
Anyone with any ideas?</description>
    </item>
    
    <item>
      <title>Set a Protocol as a Default Filter</title>
      <link>/questions/6471/set-a-protocol-as-a-default-filter/</link>
      <pubDate>Tue, 20 Sep 2011 19:43:00 +0000</pubDate>
      
      <guid>/questions/6471/set-a-protocol-as-a-default-filter/</guid>
      <description>Set a Protocol as a Default Filter  1 1Hello All,
I would like to set a protocol as a default display filter forever instead of always writing the protocol name in the Filter combo box whenever I open Wireshark. I&#39;d like to hard-code it so that it remains forvever as my setting. Kindly, Provide the solution.
Thanks, Regards, S.Prashanth.
display-filterThis question is marked &#34;community wiki&#34;.asked 20 Sep &#39;11, 19:43</description>
    </item>
    
    <item>
      <title>tcp options dissector</title>
      <link>/questions/6473/tcp-options-dissector/</link>
      <pubDate>Tue, 20 Sep 2011 23:46:00 +0000</pubDate>
      
      <guid>/questions/6473/tcp-options-dissector/</guid>
      <description>tcp options dissector  0 void proto_reg_handoff_foo(void) { static dissector_handle_t foo_handle; foo_handle = create_dissector_handle(dissect_UDP_1234, proto_foo); dissector_add_uint(&amp;amp;quot;udp.port&amp;amp;quot;, 1234, foo_handle);  }My dissector function (dissect_UDP_1234) will be called for UDP traffic on port 1234. (http://www.wireshark.org/docs/wsdg_html_chunked/ChDissectAdd.html)
Is there a similar way to do this: my dissector function (dissect_TCP_OPTIONS_123) will be called, if TCP options 123 is present?
Can I write something like this:
dissector_add_uint(&amp;quot;tcp.options&amp;quot;, 123, foo_handle);But it did&amp;rsquo;t work for me. :(
Any suggestion how to do this, other than modifying packet-tcp.</description>
    </item>
    
    <item>
      <title>U-Law RTP Stream export out of Sync</title>
      <link>/questions/6479/u-law-rtp-stream-export-out-of-sync/</link>
      <pubDate>Wed, 21 Sep 2011 09:56:00 +0000</pubDate>
      
      <guid>/questions/6479/u-law-rtp-stream-export-out-of-sync/</guid>
      <description>U-Law RTP Stream export out of Sync  0 Hi,
i capture Voip Traffic and export the U-Law encoded payload to an au file as described in the online manual.
Unfortunately forward and reverse directions are not in sync. The incoming channel is always significantly shorter than the outgoing channel. From the quality analysis it sounds like the incoming channel is missing the silence packets. Or in other words. In the incoming channel, the silence periods are much shorter than they have been in the actual conversation.</description>
    </item>
    
    <item>
      <title>Network sniff</title>
      <link>/questions/6480/network-sniff/</link>
      <pubDate>Wed, 21 Sep 2011 11:55:00 +0000</pubDate>
      
      <guid>/questions/6480/network-sniff/</guid>
      <description>Network sniff  0 I want to setup my laptop to monitor two ports on a Cisco Catalyst switch that have phone equipment connected to them. Can I do this with Wireshark installed on my laptop? Will it run on Win 7 Pro?
sniffingasked 21 Sep &#39;11, 11:55
obnetadmin
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Yes, you could. Setup a span port on the Cisco, install Wireshark on your laptop, connect it to the span port and start capturing.</description>
    </item>
    
    <item>
      <title>ssl packet and ssl mail packet</title>
      <link>/questions/6483/ssl-packet-and-ssl-mail-packet/</link>
      <pubDate>Wed, 21 Sep 2011 15:44:00 +0000</pubDate>
      
      <guid>/questions/6483/ssl-packet-and-ssl-mail-packet/</guid>
      <description>ssl packet and ssl mail packet  0 Hi, is there any way to tell the difference between normal ssl packet and ssl mail packet?
ssl mailasked 21 Sep &#39;11, 15:44
timho1985
1●2●2●3
accept rate: 0%
What&#39;s &#39;ssl mail&#39; ?
(21 Sep &#39;11, 22:29) Jaap ♦  
2 Answers:
  
2If by &#34;ssl mail&#34; you mean SMTP-over-TLS or POP-over-TLS or something such as that, then an &#34;ssl mail packet&#34;</description>
    </item>
    
    <item>
      <title>How to add a custom token-ring packet dissector</title>
      <link>/questions/6485/how-to-add-a-custom-token-ring-packet-dissector/</link>
      <pubDate>Thu, 22 Sep 2011 00:21:00 +0000</pubDate>
      
      <guid>/questions/6485/how-to-add-a-custom-token-ring-packet-dissector/</guid>
      <description>How to add a custom token-ring packet dissector  0 I want build a dissector, the packet first 32 bytes is:
0000: 55 55 00 26 db 00 11 00 00 00 07 00 22 00 00 00 0010: 08 51 00 00 26 02 00 45 00 01 ee 00 00 00 00 40when i used follow code, it can work for ethernet packet, but not work for this packet.</description>
    </item>
    
    <item>
      <title>Wireshark looks inactive but isn&amp;#x27;t...</title>
      <link>/questions/6486/wireshark-looks-inactive-but-isnt/</link>
      <pubDate>Thu, 22 Sep 2011 00:27:00 +0000</pubDate>
      
      <guid>/questions/6486/wireshark-looks-inactive-but-isnt/</guid>
      <description>Wireshark looks inactive but isn&amp;rsquo;t&amp;hellip;  0 Hello.
We had used Wireshark 1.2.6 with a ring buffer to get traces for 72 hours. Yesterday, I installed a newer version of Wireshark on a WinXP machine. A shortcut to Wireshark was put in the autorun folder for XP. The shortcut command looks like this:
C:\Program Files\Wireshark\wireshark.exe -C &amp;quot;EM02&amp;quot; -b duration:1800 -b files:144 -B 20 -f &amp;quot;ether host 08:00:06:01:60:02&amp;quot; -i 1 -k -n -w \\Server61\Traces\EM02 -y EN10MBThe profile &#34;</description>
    </item>
    
    <item>
      <title>Use tshark to analyze source and destination IPs from dumpfile?</title>
      <link>/questions/6488/use-tshark-to-analyze-source-and-destination-ips-from-dumpfile/</link>
      <pubDate>Thu, 22 Sep 2011 05:07:00 +0000</pubDate>
      
      <guid>/questions/6488/use-tshark-to-analyze-source-and-destination-ips-from-dumpfile/</guid>
      <description>Use tshark to analyze source and destination IPs from dumpfile?  0 Hi,
If I use wireshark to open a dumpfile I get something like this:
No. Time Source Destination Protocol Info 1 0.000000 10.192.128.15 10.192.3.78 UDP Source port: 5482 Destination port: 35218I need to use tshark (CLI) to read multiple dumpfiles and get the source and destination IPs.
Is this possible?
Cheers.
tsharkasked 22 Sep &amp;lsquo;11, 05:07
Ravendark
1●1●1●1</description>
    </item>
    
    <item>
      <title>does tshark returns iops value</title>
      <link>/questions/6494/does-tshark-returns-iops-value/</link>
      <pubDate>Thu, 22 Sep 2011 13:58:00 +0000</pubDate>
      
      <guid>/questions/6494/does-tshark-returns-iops-value/</guid>
      <description>does tshark returns iops value  0 I would like to know if tshark could return iops result as well. Just like avg latency.
iops tshark optionasked 22 Sep &#39;11, 13:58
asif
1●5●5●6
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>find a string in packet detail pane</title>
      <link>/questions/6495/find-a-string-in-packet-detail-pane/</link>
      <pubDate>Thu, 22 Sep 2011 14:49:00 +0000</pubDate>
      
      <guid>/questions/6495/find-a-string-in-packet-detail-pane/</guid>
      <description>find a string in packet detail pane  0 Sorry if I missed this answer in my search...
After finding a packet, the packet details section can be quite long. Is there a way to find a string in the detail panel and use a next button to advance through the details. I ended up opening my trace in Notepad++ so that I could do this!
find detailsasked 22 Sep &#39;11, 14:49</description>
    </item>
    
    <item>
      <title>64-bit installer</title>
      <link>/questions/6497/64-bit-installer/</link>
      <pubDate>Thu, 22 Sep 2011 16:25:00 +0000</pubDate>
      
      <guid>/questions/6497/64-bit-installer/</guid>
      <description>64-bit installer  0 Is there one installer that will work for both 64-bit and 32-bit OS?
installer compatibility 64-bitasked 22 Sep &#39;11, 16:25
Averyb
1●1●1●1
accept rate: 0%
 edited 24 Sep &#39;11, 15:31 
helloworld
3.1k●4●20●41
  
2 Answers:
  
2The 32-bit installer will work on both. Get the latest version from the download page.
answered 22 Sep &#39;11, 17:53
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%</description>
    </item>
    
    <item>
      <title>pcap to text</title>
      <link>/questions/6499/pcap-to-text/</link>
      <pubDate>Thu, 22 Sep 2011 20:35:00 +0000</pubDate>
      
      <guid>/questions/6499/pcap-to-text/</guid>
      <description>pcap to text  0 I want to know how to convert a file .pcap to a plain text, i&#39;ve tried using:
tcpdump -r input.pcap &amp;gt; output.txt
and it works, but the text inside the file isn&#39;t the same data in the pcap file when I open the pcap in wireshark
I want to export to text without using wireshark interface, I want to do it through the terminal in Linux.</description>
    </item>
    
    <item>
      <title>How to add source ,destination and protocol info into the tree</title>
      <link>/questions/6503/how-to-add-source-destination-and-protocol-info-into-the-tree/</link>
      <pubDate>Fri, 23 Sep 2011 01:16:00 +0000</pubDate>
      
      <guid>/questions/6503/how-to-add-source-destination-and-protocol-info-into-the-tree/</guid>
      <description>How to add source ,destination and protocol info into the tree  0 1I would like to know the functions which help us in adding the information of source destination and protocol into pane2 ...as clicking on them in pane 3 is making the wireshark to quit I encountered the following error (lt-wireshark:9103): Gtk-CRITICAL **: gtk_tree_store_get_path: assertion `iter-&amp;gt;user_data != NULL&#39; failed
(lt-wireshark:9103): Gtk-CRITICAL **: IA__gtk_tree_view_expand_row: assertion `path != NULL&#39; failed</description>
    </item>
    
    <item>
      <title>nmake error No protocol registrations found</title>
      <link>/questions/6505/nmake-error-no-protocol-registrations-found/</link>
      <pubDate>Fri, 23 Sep 2011 02:40:00 +0000</pubDate>
      
      <guid>/questions/6505/nmake-error-no-protocol-registrations-found/</guid>
      <description>nmake error No protocol registrations found  0 I wrote a simple code of SCTP protocol dissector, but when I nmake it, it had an error, like this: Making plugin.c &amp;lt;using python=&#34;&#34;&amp;gt; No protocol registrations found nmake:fatal error U1077:&#34;C:Python27python.exe&#34; :return code &#34;0x1&#34; stop
Who can tell me why? Thank you very much!
nmake errorasked 23 Sep &#39;11, 02:40
dingding0743
16●2●2●4
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Is it possible to use col_set_str for custom columns?</title>
      <link>/questions/6510/is-it-possible-to-use-col_set_str-for-custom-columns/</link>
      <pubDate>Fri, 23 Sep 2011 03:01:00 +0000</pubDate>
      
      <guid>/questions/6510/is-it-possible-to-use-col_set_str-for-custom-columns/</guid>
      <description>Is it possible to use col_set_str for custom columns?  0 Is it possible to use col_set_str for custom columns? If yes, how?
developmentThis question is marked &#34;community wiki&#34;.asked 23 Sep &#39;11, 03:01
flashkicker
109●13●19●19
accept rate: 41%
 edited 24 Sep &#39;11, 15:26 
helloworld
3.1k●4●20●41
  
2 Answers:
  
0 static const value_string[] function solved my problem ...I wanted to have string in pane1 for my customn columns and after a bit of research i found out the solution.</description>
    </item>
    
    <item>
      <title>value_string changeable?</title>
      <link>/questions/6511/value_string-changeable/</link>
      <pubDate>Fri, 23 Sep 2011 05:34:00 +0000</pubDate>
      
      <guid>/questions/6511/value_string-changeable/</guid>
      <description>value_string changeable?  0 Can the value_string string be changed? Can we append information to make the Packet List Pane have the columns displayed with text information for custom columns?
developmentThis question is marked &#34;community wiki&#34;.asked 23 Sep &#39;11, 05:34
flashkicker
109●13●19●19
accept rate: 41%
 edited 24 Sep &#39;11, 15:28 
helloworld
3.1k●4●20●41
1I don&#39;t understand the question. To add values to value strings you need to recompile Wireshark unless the values are read from a file in which case you can edit that file.</description>
    </item>
    
    <item>
      <title>patch file for 802.15.4</title>
      <link>/questions/6512/patch-file-for-802154/</link>
      <pubDate>Fri, 23 Sep 2011 08:01:00 +0000</pubDate>
      
      <guid>/questions/6512/patch-file-for-802154/</guid>
      <description>patch file for 802.15.4  0 hi currently i am doing my project in wireless sensor networks,and the simulator that i am working is NS2. i have decided of using 802.15.4 as MAC protocol. so can any one of you help me how to get the patch file for it. is there any website for downloading it. please help me. its urgent please
file patchasked 23 Sep &#39;11, 08:01
stefy89</description>
    </item>
    
    <item>
      <title>How to get window  &amp;quot;endpoint&amp;quot; information from command line</title>
      <link>/questions/6513/how-to-get-window-endpoint-information-from-command-line/</link>
      <pubDate>Fri, 23 Sep 2011 08:29:00 +0000</pubDate>
      
      <guid>/questions/6513/how-to-get-window-endpoint-information-from-command-line/</guid>
      <description>How to get window &amp;ldquo;endpoint&amp;rdquo; information from command line  0 Hi there,
I neeed to analyse a bunch of shark capture data, and to move some result fields to excel sheets. Most of them Im getting from capinfos but, in order to obtain the total amount transfered and received per ip , Im still using the usual and manual method (open the *.pcap whith wireshark, look the window &#34;endpoints&#34; and to write the values).</description>
    </item>
    
    <item>
      <title>Is there a way to filter out specific SIP messages?</title>
      <link>/questions/6514/is-there-a-way-to-filter-out-specific-sip-messages/</link>
      <pubDate>Fri, 23 Sep 2011 08:47:00 +0000</pubDate>
      
      <guid>/questions/6514/is-there-a-way-to-filter-out-specific-sip-messages/</guid>
      <description>Is there a way to filter out specific SIP messages?  1 I&#39;m monitoring a Cisco CUCM for troubleshooting purposes. All I care about are call setup messages.
The REGISTER and OPTIONS messages are cluttering up the display, and I was wondering if I could filter those out?
filter sip options registerasked 23 Sep &#39;11, 08:47
Cisco TelePr...
16●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Cannot see packets from local machine</title>
      <link>/questions/6515/cannot-see-packets-from-local-machine/</link>
      <pubDate>Fri, 23 Sep 2011 08:47:00 +0000</pubDate>
      
      <guid>/questions/6515/cannot-see-packets-from-local-machine/</guid>
      <description>Cannot see packets from local machine  0 Hi All,
I am running Wireshark 1.6.2 on a Windows 2008 server. However, I am unable to see any packets originating from the server. If I ping a remote host, I can see the return packets but not packets sent from the local host.
Any clues?
Bashment
windows captureasked 23 Sep &#39;11, 08:47
BASHMENTY2K
1●1●1●1
accept rate: 0%
 edited 24 Sep &#39;11, 15:21</description>
    </item>
    
    <item>
      <title>ISDN HEX capture analyze</title>
      <link>/questions/6516/isdn-hex-capture-analyze/</link>
      <pubDate>Fri, 23 Sep 2011 09:01:00 +0000</pubDate>
      
      <guid>/questions/6516/isdn-hex-capture-analyze/</guid>
      <description>ISDN HEX capture analyze  0 I have a Hex Dump of ISDN messages and I wonder if Wireshark can be used to decode those messages. Here an example of what I have:
0000 02 01 01 a5 0000 02 01 01 b9 0000 02 01 01 a5 0000 02 01 01 b9 0000 00 01 a4 b8 08 02 00 3e 05 04 03 80 90 a2 18 03 0010 a9 83 85 6c 0c 21 80 38 30 31 38 30 32 33 30 30 0020 30 70 08 c1 33 37 33 39 31 32 30 0000 00 01 01 a6 0000 02 01 b8 a6 08 02 80 3e 02 18 03 a9 83 85 0000 02 01 01 ba 0000 02 01 ba a6 08 02 80 3e 01 1e 02 82 88 0000 02 01 01 bc 0000 02 01 bc a6 08 02 80 3e 07 0000 02 01 01 be 0000 00 01 a6 be 08 02 00 3e 0f 0000 00 01 01 a8 0000 00 01 a8 be 08 02 00 3e 45 08 02 8a 90 0000 00 01 01 aa 0000 02 01 be aa 08 02 80 3e 4d 0000 02 01 01 c0 0000 00 01 aa c0 08 02 00 3e 5a 0000 00 01 01 ac 0000 02 01 01 ad 0000 02 01 01 c1 0000 02 01 01 ad 0000 02 01 01 c1I&#39;ve try to use text2cap command but wireshark couldn&#39;t decode the ISDN messages.</description>
    </item>
    
    <item>
      <title>tshark wiresharkXXXX file even with text to stdout</title>
      <link>/questions/6517/tshark-wiresharkxxxx-file-even-with-text-to-stdout/</link>
      <pubDate>Fri, 23 Sep 2011 09:37:00 +0000</pubDate>
      
      <guid>/questions/6517/tshark-wiresharkxxxx-file-even-with-text-to-stdout/</guid>
      <description>tshark wiresharkXXXX file even with text to stdout  0 I&#39;m using tshark (Windows version) in a script that I would like to run for an indefinite period of time. The tshark parameters are something like -i1 -s48 -x&amp;lt;filter&amp;gt;. This results in text to stdout that I process with gawk. However, a wiresharkXXXX temp file is also created. There doesn&#39;t seem to be a need for a temp file when the start parameters do not specify any file creation.</description>
    </item>
    
    <item>
      <title>file conversion</title>
      <link>/questions/6521/file-conversion/</link>
      <pubDate>Fri, 23 Sep 2011 11:39:00 +0000</pubDate>
      
      <guid>/questions/6521/file-conversion/</guid>
      <description>file conversion  0 I have datasets in the xml,dtd,mht formats.How do I open them in Wireshark?
conversionasked 23 Sep &#39;11, 11:39
deepanjan
0●3●3●3
accept rate: 0%
  
One Answer:
  
1Somehow convert them in any of these formats Wireshark understands.
answered 23 Sep &#39;11, 13:07
Jaap ♦
11.7k●16●101
accept rate: 14%
     </description>
    </item>
    
    <item>
      <title>[closed] How do I convert an xml,dtd,mht files into pcap files so that I can use them in wireshark?</title>
      <link>/questions/6535/how-do-i-convert-an-xmldtdmht-files-into-pcap-files-so-that-i-can-use-them-in-wireshark/</link>
      <pubDate>Fri, 23 Sep 2011 22:17:00 +0000</pubDate>
      
      <guid>/questions/6535/how-do-i-convert-an-xmldtdmht-files-into-pcap-files-so-that-i-can-use-them-in-wireshark/</guid>
      <description>[closed] How do I convert an xml,dtd,mht files into pcap files so that I can use them in wireshark?  -1 How do I convert an xml,dtd,mht files into pcap files so that I can use them in wireshark?
conversion fileasked 23 Sep &#39;11, 22:17
deepanjan
0●3●3●3
accept rate: 0%
 closed 24 Sep &#39;11, 15:16 
helloworld
3.1k●4●20●41
1Most probably by writing code.
(24 Sep &#39;11, 01:41) Anders ♦You already asked this in question 6521; no need to ask it again.</description>
    </item>
    
    <item>
      <title>Where to see &amp;quot;Update Interval&amp;quot; value for BACnet Analog Input in Wireshark? How to analyze?</title>
      <link>/questions/6537/where-to-see-update-interval-value-for-bacnet-analog-input-in-wireshark-how-to-analyze/</link>
      <pubDate>Sat, 24 Sep 2011 05:32:00 +0000</pubDate>
      
      <guid>/questions/6537/where-to-see-update-interval-value-for-bacnet-analog-input-in-wireshark-how-to-analyze/</guid>
      <description>Where to see &amp;ldquo;Update Interval&amp;rdquo; value for BACnet Analog Input in Wireshark? How to analyze?  0 I need to check whether the BACnet controller supports &#34;Update Interval&#34; for Analog input object. Please anyone help me out how to check this?
bacnetThis question is marked &#34;community wiki&#34;.asked 24 Sep &#39;11, 05:32
Ravi S
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>wireshark run error</title>
      <link>/questions/6539/wireshark-run-error/</link>
      <pubDate>Sat, 24 Sep 2011 12:26:00 +0000</pubDate>
      
      <guid>/questions/6539/wireshark-run-error/</guid>
      <description>wireshark run error  0 When I try to run wireshark.exe, I get an error:
The application failed to initialize properly.windows startup crashasked 24 Sep &#39;11, 12:26
fahd
1●1●1●1
accept rate: 0%
 edited 24 Sep &#39;11, 15:18 
helloworld
3.1k●4●20●41
   </description>
    </item>
    
    <item>
      <title>how to get number of packets displayed via tshark?</title>
      <link>/questions/6543/how-to-get-number-of-packets-displayed-via-tshark/</link>
      <pubDate>Sun, 25 Sep 2011 02:52:00 +0000</pubDate>
      
      <guid>/questions/6543/how-to-get-number-of-packets-displayed-via-tshark/</guid>
      <description>how to get number of packets displayed via tshark?  0 1I&#39;m using to tshark in my bash script and i want to get the number of packets displayed after filtering.
tsharkasked 25 Sep &#39;11, 02:52
ddayan
41●15●17●20
accept rate: 0%
  
2 Answers:
  
2 Does tshark -r file.pcap -R &amp;lt;filter&amp;gt; | wc -l work for you?
answered 25 Sep &#39;11, 07:31
cmaynard ♦♦
9.4k●10●38●142</description>
    </item>
    
    <item>
      <title>wireshark and XP</title>
      <link>/questions/6546/wireshark-and-xp/</link>
      <pubDate>Sun, 25 Sep 2011 12:12:00 +0000</pubDate>
      
      <guid>/questions/6546/wireshark-and-xp/</guid>
      <description>wireshark and XP  0 I have two PC&#39;s connected to a router via wi-fi. Both of them are running using Windows XP SP3. My question is if I could use wireshark to monitor the traffic of the two PC&#39;s using this O.S. XP. I have tried to run wireshark but it only works if I uncheck the promiscous mode option. (I suppose my USB adapter do not support monitor mode).</description>
    </item>
    
    <item>
      <title>How to scrape packet data?</title>
      <link>/questions/6547/how-to-scrape-packet-data/</link>
      <pubDate>Sun, 25 Sep 2011 12:34:00 +0000</pubDate>
      
      <guid>/questions/6547/how-to-scrape-packet-data/</guid>
      <description>How to scrape packet data?  0 I want to scrape captured http packets for particular data. For example, consider a packet contains an itemID and ItemStatus.
I want a quick method of searching and extracting the timestamp, itemID, and ItemStatus from all the captured packets into a csv file for analysis (or whatever).
Is there a way to do this?
Thanks, David
mining data packet scrapeasked 25 Sep &#39;11, 12:34</description>
    </item>
    
    <item>
      <title>wireshark tracking school project for filesharing clients</title>
      <link>/questions/6552/wireshark-tracking-school-project-for-filesharing-clients/</link>
      <pubDate>Mon, 26 Sep 2011 01:54:00 +0000</pubDate>
      
      <guid>/questions/6552/wireshark-tracking-school-project-for-filesharing-clients/</guid>
      <description>wireshark tracking school project for filesharing clients  1 Hello together,
i have a questin about filesharing. in our school we have ten pcs with bittorent...we have created a test torrent with utorrent...we upload it to an opentracker...and now we can download it..
but now the problem...
we use wireshark to protocol the filetransfer...we use the torrent filter....now we see some ip&#39;s ...with handshake...
is it possible to the the internet provider like.</description>
    </item>
    
    <item>
      <title>IEEE 802.11 deauth packet reason codes and their meanings</title>
      <link>/questions/6554/ieee-80211-deauth-packet-reason-codes-and-their-meanings/</link>
      <pubDate>Mon, 26 Sep 2011 02:31:00 +0000</pubDate>
      
      <guid>/questions/6554/ieee-80211-deauth-packet-reason-codes-and-their-meanings/</guid>
      <description>IEEE 802.11 deauth packet reason codes and their meanings  0 I&#39;m trying to understand the different meanings of the 802.11 deauth packets I&#39;m receiving: I couldn&#39;t find a document that describes what each reason code means i.e why the deauth packet was sent.
802.11 deauthenticationasked 26 Sep &#39;11, 02:31
ddayan
41●15●17●20
accept rate: 0%
 edited 26 Sep &#39;11, 16:53 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:</description>
    </item>
    
    <item>
      <title>Working with Wireshark</title>
      <link>/questions/6557/working-with-wireshark/</link>
      <pubDate>Mon, 26 Sep 2011 03:15:00 +0000</pubDate>
      
      <guid>/questions/6557/working-with-wireshark/</guid>
      <description>Working with Wireshark  0 Hi,
I am a very new user of Wireshark and don&#39;t have the knowledge on networking.
I have, as of now, installed Wireshark 1.2.8 on my laptop (Win-7 pro), and my machine is connected to LAN. Can someone please suggest how can I use Wireshark to monitor any machine connected to LAN? I am able to ping it also. Please share simple steps, and help me.</description>
    </item>
    
    <item>
      <title>finding link layer duplicate packets</title>
      <link>/questions/6559/finding-link-layer-duplicate-packets/</link>
      <pubDate>Mon, 26 Sep 2011 05:15:00 +0000</pubDate>
      
      <guid>/questions/6559/finding-link-layer-duplicate-packets/</guid>
      <description>finding link layer duplicate packets  0 I wondered if I can find mac/link layer duplicate packets (same sequence number) like I can do with tcp.analysis.dup_frame with tcp protocol packets
filter duplicates linkasked 26 Sep &#39;11, 05:15
ddayan
41●15●17●20
accept rate: 0%
What sequence numbers are you thinking about?
(26 Sep &#39;11, 10:12) Jaap ♦   </description>
    </item>
    
    <item>
      <title>length vs reported_length meaning</title>
      <link>/questions/6563/length-vs-reported_length-meaning/</link>
      <pubDate>Mon, 26 Sep 2011 08:25:00 +0000</pubDate>
      
      <guid>/questions/6563/length-vs-reported_length-meaning/</guid>
      <description>length vs reported_length meaning  2 1Hello guys,
I am a beginner. There is a question as below:
What&#39;s the difference between the tvb_length() and tvb_reported_length() or &#34;length&#34; and &#34;reported length&#34;?
Thanks for you answers!
Sam
developmentasked 26 Sep &#39;11, 08:25
Sam
51●7●9●14
accept rate: 0%
 edited 26 Sep &#39;11, 21:42 
helloworld
3.1k●4●20●41
  
2 Answers:
  
4tvb_length() reports the actual amount of data in the TVB, while tvb_reported_length() reports the amount of data there should be according to the underlying protocol.</description>
    </item>
    
    <item>
      <title>starting wireshark error libwiretap.so.1</title>
      <link>/questions/6568/starting-wireshark-error-libwiretapso1/</link>
      <pubDate>Mon, 26 Sep 2011 12:51:00 +0000</pubDate>
      
      <guid>/questions/6568/starting-wireshark-error-libwiretapso1/</guid>
      <description>starting wireshark error libwiretap.so.1  1 I downloaded Wireshark 1.6.2 from this website. I just compiled in Ubuntu 10.4. No errors during build, but an error on start:
[email protected]:/$ wireshark wireshark: error while loading shared libraries: libwiretap.so.1: cannot open shared object file: No such file or directoryor
[email protected]:/$ sudo wireshark wireshark: error while loading shared libraries: libwiretap.so.1: cannot open shared object file: No such file or directoryAnything missing that I should install?</description>
    </item>
    
    <item>
      <title>Wireshark won&amp;#x27;t start up</title>
      <link>/questions/6570/wireshark-wont-start-up/</link>
      <pubDate>Mon, 26 Sep 2011 17:30:00 +0000</pubDate>
      
      <guid>/questions/6570/wireshark-wont-start-up/</guid>
      <description>Wireshark won&amp;rsquo;t start up  0 Aloha from Hawaii,
I&#39;m running a 1.67 GHz PPC G4 powerbook with Mac OS 10.4.11. I installed Wireshark 1.3.5 by:
Moving the application to the Application folder.Placing the ChmodBPF directory into the StartupItems directoryCopying the Wireshark Command lines to a directory I created on the desktop for them.I restarted the machine and had the OS fix the permissions on the ChmodBPF, and restarted again. After the reboot, I started Wireshark.</description>
    </item>
    
    <item>
      <title>[closed] Problem with Exchange 2010 and Outlook</title>
      <link>/questions/6574/problem-with-exchange-2010-and-outlook/</link>
      <pubDate>Mon, 26 Sep 2011 20:56:00 +0000</pubDate>
      
      <guid>/questions/6574/problem-with-exchange-2010-and-outlook/</guid>
      <description>[closed] Problem with Exchange 2010 and Outlook  0 Hello,
I needed some information from my work email. So I connected to my work desktop from home, went on my work outlook and i needed to download 2 outlook data tsp files. I did so, then imported them to my home computer. Now when i am at work ( i work in a remote location) and i open my outlook, the exchange server 2010 doesnt work anymore it like logs me on to 2007, On top of that i cannot access or even delete the emails or files that i had downloaded unto my home computer.</description>
    </item>
    
    <item>
      <title>Identify SYN packets without SYN/ACK</title>
      <link>/questions/6576/identify-syn-packets-without-synack/</link>
      <pubDate>Mon, 26 Sep 2011 21:12:00 +0000</pubDate>
      
      <guid>/questions/6576/identify-syn-packets-without-synack/</guid>
      <description>Identify SYN packets without SYN/ACK  0 From a PCAP Trace how to identify tcp SYN frames that have not received tcp SYN/ACK ?
ack synasked 26 Sep &#39;11, 21:12
Norbert
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Here&#39;s the gist of an idea:
Use tshark reading a file (and redirecting output to a file) with something like the following:
a. a read filter to find all the SYN frames: -R tcp.</description>
    </item>
    
    <item>
      <title>decrypt ssl to pcap</title>
      <link>/questions/6584/decrypt-ssl-to-pcap/</link>
      <pubDate>Tue, 27 Sep 2011 02:34:00 +0000</pubDate>
      
      <guid>/questions/6584/decrypt-ssl-to-pcap/</guid>
      <description>decrypt ssl to pcap  0 Hi, I&#39;m trying to decrypt an ssl conversation using the ssl key.
This is working in the wireshark gui.
When I try to decrypt in tshark, this is also working, but I wan to decrypt it and save the result as a pcap file. This doesn&#39;t work.
When I use : tshark -o &#34;ssl.desegment_ssl_records: TRUE&#34; -o &#34;ssl.desegment_ssl_application_data: TRUE&#34; -o &#34;ssl.keys_list: 10.135.56.22,443,http,/trace/test/test.pem&#34; -t ad -r 443_test.</description>
    </item>
    
    <item>
      <title>Triggers for wireshark</title>
      <link>/questions/6585/triggers-for-wireshark/</link>
      <pubDate>Tue, 27 Sep 2011 03:12:00 +0000</pubDate>
      
      <guid>/questions/6585/triggers-for-wireshark/</guid>
      <description>Triggers for wireshark  0 How to have triggers for wireshark... i.e. i would like wireshark to capture the packets after a particular packet type
Ex: custom.type = = 10 then show all the packets from the point you get that type to be 10
triggerasked 27 Sep &#39;11, 03:12
flashkicker
109●13●19●19
accept rate: 41%
Using filter we can show all the packets with the same type but the thing is i would like to have the wireshark display all the packets of any type until the trigger action occurs</description>
    </item>
    
    <item>
      <title>Decrypt WEP packets</title>
      <link>/questions/6587/decrypt-wep-packets/</link>
      <pubDate>Tue, 27 Sep 2011 05:30:00 +0000</pubDate>
      
      <guid>/questions/6587/decrypt-wep-packets/</guid>
      <description>Decrypt WEP packets  0 I&#39;m trying to decode a WEP encrypted SSID. I took a trace with Airpcap and Wireshark 1.6.2 and try to decode the data with the correct key. My problem is, that not all packets are decoded. Is there any reason, why Wireshark cannot decode all packets?
decryption wep decryptasked 27 Sep &#39;11, 05:30
wmann
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How does wireshark determine SSL protocol?</title>
      <link>/questions/6597/how-does-wireshark-determine-ssl-protocol/</link>
      <pubDate>Tue, 27 Sep 2011 08:09:00 +0000</pubDate>
      
      <guid>/questions/6597/how-does-wireshark-determine-ssl-protocol/</guid>
      <description>How does wireshark determine SSL protocol?  0 I&#39;m looking at a capture taken from production, and following through a particular tcp.stream. Excluding the ack packets, most are listed as SSL, but a few are listed as TLSv1. What is wireshark looking at when it makes this distinction.
Additional information: to keep the file from getting out of hand, I&#39;m recording the packets with a snaplen == 68.
The actual traffic in this case is coming from IE9 to our web server.</description>
    </item>
    
    <item>
      <title>How to decompress gzipped contents</title>
      <link>/questions/6598/how-to-decompress-gzipped-contents/</link>
      <pubDate>Tue, 27 Sep 2011 09:11:00 +0000</pubDate>
      
      <guid>/questions/6598/how-to-decompress-gzipped-contents/</guid>
      <description>How to decompress gzipped contents  2 In HTTP request and response, content-encoding is &#39;gzip&#39; and content is gzipped. Is there a way to decompress the gzipped content so we can see what the contents are.
gzipped content decompressasked 27 Sep &#39;11, 09:11
eusjoji
31●1●1●3
accept rate: 0%
  
3 Answers:
  
4I believe Jaap&#39;s answer is not quite correct, because the exported object will already be uncompressed.</description>
    </item>
    
    <item>
      <title>How do I diagnose a slow WLAN guest network?</title>
      <link>/questions/6599/how-do-i-diagnose-a-slow-wlan-guest-network/</link>
      <pubDate>Tue, 27 Sep 2011 12:20:00 +0000</pubDate>
      
      <guid>/questions/6599/how-do-i-diagnose-a-slow-wlan-guest-network/</guid>
      <description>How do I diagnose a slow WLAN guest network?  0 I have Laura&#39;s newest Wireshark Analysis book (2010, anyway) and have been reading through it to try and solve a problem.
Our guest WLAN is slow at times. Each user is capped via the wireless distribution system at 1mb/s download, and capped uploading and downloading at the DMZ to 8mb/s, but that is the entire pipe, not per user.</description>
    </item>
    
    <item>
      <title>how does the filter toolbar work ?</title>
      <link>/questions/6609/how-does-the-filter-toolbar-work/</link>
      <pubDate>Wed, 28 Sep 2011 00:41:00 +0000</pubDate>
      
      <guid>/questions/6609/how-does-the-filter-toolbar-work/</guid>
      <description>how does the filter toolbar work ?  0 1I would like to know how the filter works ...I would like to know the files which help in the working of this filter. I&#39;m trying to create trigger but to do so i would like to know the entire working of filters and the files related to it
developmentThis question is marked &#34;community wiki&#34;.asked 28 Sep &#39;11, 00:41
flashkicker
109●13●19●19</description>
    </item>
    
    <item>
      <title>Cannot see packets on a wireshark.</title>
      <link>/questions/6614/cannot-see-packets-on-a-wireshark/</link>
      <pubDate>Wed, 28 Sep 2011 04:32:00 +0000</pubDate>
      
      <guid>/questions/6614/cannot-see-packets-on-a-wireshark/</guid>
      <description>Cannot see packets on a wireshark.  0 We have a program that listens on a particular port i.e 3810 on TCP ( windows server 2008 R2) . When the program is running and listening to the port - confirmed by issuing netstat , we cannot see the packets in wire shark being captured on this port 3810. However when we stop the program we see the packets in wire shark .</description>
    </item>
    
    <item>
      <title>Open and Save Dialog Boxes Appears more than once if box is moved.</title>
      <link>/questions/6615/open-and-save-dialog-boxes-appears-more-than-once-if-box-is-moved/</link>
      <pubDate>Wed, 28 Sep 2011 04:58:00 +0000</pubDate>
      
      <guid>/questions/6615/open-and-save-dialog-boxes-appears-more-than-once-if-box-is-moved/</guid>
      <description>Open and Save Dialog Boxes Appears more than once if box is moved.  0 Why the Open and save dialog boxes are reappearing on the screen again and again when they are being moved? This is damaging the screen view. Please help.
gtkThis question is marked &#34;community wiki&#34;.asked 28 Sep &#39;11, 04:58
Terrestrial ...
96●21●28●29
accept rate: 42%
Be more specific !! ...Whats the wireshark version and what os are you using</description>
    </item>
    
    <item>
      <title>Client closing the connection by sending FIN, ACK before server sends HTTP OK response</title>
      <link>/questions/6623/client-closing-the-connection-by-sending-fin-ack-before-server-sends-http-ok-response/</link>
      <pubDate>Wed, 28 Sep 2011 09:44:00 +0000</pubDate>
      
      <guid>/questions/6623/client-closing-the-connection-by-sending-fin-ack-before-server-sends-http-ok-response/</guid>
      <description>Client closing the connection by sending FIN, ACK before server sends HTTP OK response  0 Hi,
We are facing a peculiar issue in our network. When trying to access mail.indiatimes.com (223.165.24.14) website 80% of time it doesn&#39;t open. We have to keep disconnect and try again to open the web page. From the wireshark traces we can observe 3 way TCP handshake is happening. After that client is sending GET HTTP request &amp;amp; HTTP ACK is sent by web server.</description>
    </item>
    
    <item>
      <title>Log packets @ my router</title>
      <link>/questions/6625/log-packets-my-router/</link>
      <pubDate>Wed, 28 Sep 2011 10:09:00 +0000</pubDate>
      
      <guid>/questions/6625/log-packets-my-router/</guid>
      <description>Log packets @ my router  0 Hi,
We currently are having an issue with our router randomly dropping (internally). Our ISP replaced the router, but it&#39;s still happening. She mentioned it could be a bad packet, etc. Is there a way to monitor a specific IP (the router - LAN side) so I can try and narrow what&#39;s causing it to drop?
Thanks brian
router wlan troubleshooting captureasked 28 Sep &#39;11, 10:09</description>
    </item>
    
    <item>
      <title>How to create a capture filter for CS4 Traffic</title>
      <link>/questions/6629/how-to-create-a-capture-filter-for-cs4-traffic/</link>
      <pubDate>Wed, 28 Sep 2011 16:49:00 +0000</pubDate>
      
      <guid>/questions/6629/how-to-create-a-capture-filter-for-cs4-traffic/</guid>
      <description>How to create a capture filter for CS4 Traffic  0 How can i create a capture filter for CS4 traffic?
When I look at the captured traffic, I see the Differentiated Services Field: 0x80 (DSCP 0x20: Class Selector 4.
cs4 capture-filter af41 dscpasked 28 Sep &#39;11, 16:49
miler
26●1●1●4
accept rate: 100%
 edited 30 Sep &#39;11, 09:59 
  
2 Answers:
  
0 That worked perfectly, using ip[1] &amp;amp; 0xfc == 0x80 I was able to do perform a packet capture and only capture CS4 packets.</description>
    </item>
    
    <item>
      <title>Malformed GIOP Packets. Are they real errors to be addressed</title>
      <link>/questions/6636/malformed-giop-packets-are-they-real-errors-to-be-addressed/</link>
      <pubDate>Thu, 29 Sep 2011 09:01:00 +0000</pubDate>
      
      <guid>/questions/6636/malformed-giop-packets-are-they-real-errors-to-be-addressed/</guid>
      <description>Malformed GIOP Packets. Are they real errors to be addressed  0 I am seeing Malformed GIOP exceptions in my trace. Are they indications of a real problem or just the dissector reading it incorrectly?
giop malformedThis question is marked &#34;community wiki&#34;.asked 29 Sep &#39;11, 09:01
LillyB2424
1●1●1●1
accept rate: 0%
  
One Answer:
  
0It could be a real network problem or it could be a bug in the GIOP dissector.</description>
    </item>
    
    <item>
      <title>SIP capture filter</title>
      <link>/questions/6637/sip-capture-filter/</link>
      <pubDate>Thu, 29 Sep 2011 09:26:00 +0000</pubDate>
      
      <guid>/questions/6637/sip-capture-filter/</guid>
      <description>SIP capture filter  0 Hi, I&#39;m trying to apply a filter to capture only SIP traffic and running into an odd situation. When I leave wireshark with no capture filter, I see the packets I want to capture from host X to host Y on UDP port 5060.
So I applied these filters on the capture options screen one by one: -port 5060 -udp port 5060 -host X
All of them returned nothing.</description>
    </item>
    
    <item>
      <title>How to clean pcap of Youtube video stream from other protocols.</title>
      <link>/questions/6641/how-to-clean-pcap-of-youtube-video-stream-from-other-protocols/</link>
      <pubDate>Thu, 29 Sep 2011 10:59:00 +0000</pubDate>
      
      <guid>/questions/6641/how-to-clean-pcap-of-youtube-video-stream-from-other-protocols/</guid>
      <description>How to clean pcap of Youtube video stream from other protocols.  0 I would like to filter only video stream from captured pcap of the youtube client/server comunication. The problem is there are also other HTTP requestes (images,..).
filter capture youtubeasked 29 Sep &#39;11, 10:59
bananajoe
1●1●1●1
accept rate: 0%
Take a look at this question:
How to extract flv video from capture pakets.
(29 Sep &#39;11, 11:20) joke   </description>
    </item>
    
    <item>
      <title>wireshark dissector profiling</title>
      <link>/questions/6644/wireshark-dissector-profiling/</link>
      <pubDate>Thu, 29 Sep 2011 19:13:00 +0000</pubDate>
      
      <guid>/questions/6644/wireshark-dissector-profiling/</guid>
      <description>wireshark dissector profiling  1 I want to write an SCTP dissector in C and in Lua, respectively, and record the time they need to dissect the protocol. Then, I can make a comparison. However, I do not know how to get the time of dissecting a packet. Is there any API or other ways to do this? Thanks a lot~
lua dissector profilingasked 29 Sep &#39;11, 19:13
dingding0743
16●2●2●4</description>
    </item>
    
    <item>
      <title>no GUI after startup</title>
      <link>/questions/6646/no-gui-after-startup/</link>
      <pubDate>Thu, 29 Sep 2011 21:58:00 +0000</pubDate>
      
      <guid>/questions/6646/no-gui-after-startup/</guid>
      <description>no GUI after startup  0 Left-clicking appears to start Wireshark, which only offers a taskbar icon/button but no visible GUI window. This takes place with both 32- and 64-bit installations on 64-bit Windows 7. The Wireshark install is using the default settings.
windows windows7 startupasked 29 Sep &#39;11, 21:58
user
1●1●1●1
accept rate: 0%
 edited 02 Oct &#39;11, 15:57 
helloworld
3.1k●4●20●41
First Start or did you use wireshark before?</description>
    </item>
    
    <item>
      <title>HEX Interpretation</title>
      <link>/questions/6647/hex-interpretation/</link>
      <pubDate>Thu, 29 Sep 2011 22:47:00 +0000</pubDate>
      
      <guid>/questions/6647/hex-interpretation/</guid>
      <description>HEX Interpretation  0 Excuse me if this sounds like a stupid question or maybe i need a revision lesson. I have a HEX printout in Wireshark 0C27 Am i right that this is reversed to interpret as 270C or have i got this wrong. I ask because when converting using HEX calculator my result is 3111 Yet i am expecting the result 9996
Thanks in Advance Sven
hexasked 29 Sep &#39;11, 22:47</description>
    </item>
    
    <item>
      <title>what is the work of trigcap?</title>
      <link>/questions/6656/what-is-the-work-of-trigcap/</link>
      <pubDate>Sat, 01 Oct 2011 00:12:00 +0000</pubDate>
      
      <guid>/questions/6656/what-is-the-work-of-trigcap/</guid>
      <description>what is the work of trigcap?  0 Can any one explain the main objective of trigcap.c and also its functioning briefly?
triggersThis question is marked &#34;community wiki&#34;.asked 01 Oct &#39;11, 00:12
Terrestrial ...
96●21●28●29
accept rate: 42%
 edited 01 Oct &#39;11, 02:54 
  
One Answer:
  
1It uses the BPF to find start and stop conditions. Between the two it saves captured packets to a file.</description>
    </item>
    
    <item>
      <title>what is the difference between capture filter and display filter?</title>
      <link>/questions/6660/what-is-the-difference-between-capture-filter-and-display-filter/</link>
      <pubDate>Sat, 01 Oct 2011 01:07:00 +0000</pubDate>
      
      <guid>/questions/6660/what-is-the-difference-between-capture-filter-and-display-filter/</guid>
      <description>what is the difference between capture filter and display filter?  2 what is the difference between capture filter and display filter?
filterasked 01 Oct &#39;11, 01:07
Terrestrial ...
96●21●28●29
accept rate: 42%
  
One Answer:
  
2 A capture filter is used to select which packets should be saved to disk while capturing. For capture filters wireshark uses the BPF syntax. BPF is module that runs in the kernel and can therefor maintain high rates of capturing because the packets do not have to move from kernel space to user space when filtering.</description>
    </item>
    
    <item>
      <title>How to specify start and stop conditions?</title>
      <link>/questions/6664/how-to-specify-start-and-stop-conditions/</link>
      <pubDate>Sat, 01 Oct 2011 02:15:00 +0000</pubDate>
      
      <guid>/questions/6664/how-to-specify-start-and-stop-conditions/</guid>
      <description>How to specify start and stop conditions?  0 How to specify start and stop conditions to wireshark?
triggerThis question is marked &#34;community wiki&#34;.asked 01 Oct &#39;11, 02:15
Terrestrial ...
96●21●28●29
accept rate: 42%
Do we have any updates with the triggers for wireshark? Is there any research being done? I need them badly. May i know the details like: what all the files that can be changed to bring triggers into effect?</description>
    </item>
    
    <item>
      <title>Hire Professional</title>
      <link>/questions/6672/hire-professional/</link>
      <pubDate>Sat, 01 Oct 2011 04:27:00 +0000</pubDate>
      
      <guid>/questions/6672/hire-professional/</guid>
      <description>Hire Professional  0 I am looking to hire someone who can view my Wireshark logs (or whatever it takes), so they can determine and/or convert the messages between my server and mobile devices, if possible. I would need the exact message and protocol, and any other information that is available.
consulting reverse-engineeringasked 01 Oct &#39;11, 04:27
davidp9470
1●1●1●1
accept rate: 0%
 edited 02 Oct &#39;11, 15:50 
helloworld</description>
    </item>
    
    <item>
      <title>How to mark an interface as wireless?</title>
      <link>/questions/6673/how-to-mark-an-interface-as-wireless/</link>
      <pubDate>Sat, 01 Oct 2011 06:10:00 +0000</pubDate>
      
      <guid>/questions/6673/how-to-mark-an-interface-as-wireless/</guid>
      <description>How to mark an interface as wireless?  0 Hello,
my Intel 3945ABG adapter running the 10.5.1.75-driver is not shown as wireless, so I can&#39;t set any channels or wireless settings. Promiscous mode works fine, I see a lot of packets from other computers in my WLAN. Is there any way to tell Wireshark that this is a wireless card?
Thx in advance!
interfaceasked 01 Oct &#39;11, 06:10
flash007
6●1●1●3</description>
    </item>
    
    <item>
      <title>permission to use &amp;quot;Wireshark&amp;quot;</title>
      <link>/questions/6674/permission-to-use-wireshark/</link>
      <pubDate>Sat, 01 Oct 2011 08:51:00 +0000</pubDate>
      
      <guid>/questions/6674/permission-to-use-wireshark/</guid>
      <description>permission to use &amp;ldquo;Wireshark&amp;rdquo;  0 Sir/Ma&#39;m, As per I directed by my Cisco study material, I request you to grant me permission for using the application for my knowledge and labs going on with cisco for the &#34;CCNA&#34;. This is the first time I came to know about such product. Hope i will gain required knowledge from the product and so about the &#34;WIRESHARE&#34; . I apologize, if I had it wrong since this is my first time when i came across such product only for my Cisco Labs to be a Cisco Certified Network Associate.</description>
    </item>
    
    <item>
      <title>detecting static route update contents in a wireshark trace</title>
      <link>/questions/6675/detecting-static-route-update-contents-in-a-wireshark-trace/</link>
      <pubDate>Sat, 01 Oct 2011 10:17:00 +0000</pubDate>
      
      <guid>/questions/6675/detecting-static-route-update-contents-in-a-wireshark-trace/</guid>
      <description>detecting static route update contents in a wireshark trace  0 after disabling cdp on router and all its interfaces how can i check in a wireshark trace that what are the ip addresses contained in a static route update?
investigating route static updateasked 01 Oct &#39;11, 10:17
manjeet
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>how to modify the warning level of vs2008</title>
      <link>/questions/6678/how-to-modify-the-warning-level-of-vs2008/</link>
      <pubDate>Sun, 02 Oct 2011 04:17:00 +0000</pubDate>
      
      <guid>/questions/6678/how-to-modify-the-warning-level-of-vs2008/</guid>
      <description>how to modify the warning level of vs2008  0 Hi guys,
Some warnings displayed when I compiled the Wireshark source code after modifying some code. Please see below:
packet-ethertype.c(211) : error C2220: warning treated as error - no &amp;#39;object&amp;#39; file generated packet-ethertype.c(211) : warning C4029: declared formal parameter list different from definition packet-eth.c(434) : error C2220: warning treated as error - no &amp;#39;object&amp;#39; file generated packet-eth.c(434) : warning C4020: &amp;#39;ethertype&amp;#39; : too many actual parameters NMAKE : fatal error U1077: &amp;#39;&amp;quot;C:\Program Files\Microsoft Visual Studio 9.</description>
    </item>
    
    <item>
      <title>wireshark-bin quit unexpectedly (Mac OS X Leopard)</title>
      <link>/questions/6682/wireshark-bin-quit-unexpectedly-mac-os-x-leopard/</link>
      <pubDate>Sun, 02 Oct 2011 14:50:00 +0000</pubDate>
      
      <guid>/questions/6682/wireshark-bin-quit-unexpectedly-mac-os-x-leopard/</guid>
      <description>wireshark-bin quit unexpectedly (Mac OS X Leopard)  0 Every time I try to open Wireshark, all I get is the error message:
wireshark-bin quit unexpectedlyHow do I fix this?
startup osx mac crashasked 02 Oct &#39;11, 14:50
danielle2013
1●1●1●1
accept rate: 0%
 edited 02 Oct &#39;11, 15:41 
helloworld
3.1k●4●20●41
There&#39;s usually an error message somewhere (e.g., in the syslog). See this post to find out what that is.</description>
    </item>
    
    <item>
      <title>retrieving tcp throughput using tshark</title>
      <link>/questions/6691/retrieving-tcp-throughput-using-tshark/</link>
      <pubDate>Tue, 04 Oct 2011 00:17:00 +0000</pubDate>
      
      <guid>/questions/6691/retrieving-tcp-throughput-using-tshark/</guid>
      <description>retrieving tcp throughput using tshark  0 In wireshark the throughput is displayed inside the stats -&amp;gt; conversations -&amp;gt; TCP tharks -q -z &#34;conv,tcp&#34; only prints number of frames.
Is there a way to retrive TCP throughput using tshark ?
tsharkasked 04 Oct &#39;11, 00:17
ddayan
41●15●17●20
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>troubleshoot the failure of a web page</title>
      <link>/questions/6692/troubleshoot-the-failure-of-a-web-page/</link>
      <pubDate>Tue, 04 Oct 2011 04:20:00 +0000</pubDate>
      
      <guid>/questions/6692/troubleshoot-the-failure-of-a-web-page/</guid>
      <description>troubleshoot the failure of a web page  0 How can i use a protocol analyser such as wireshark to troubleshoot the failure of a webpage to download successfully to a browser on a computer
troubleshootingasked 04 Oct &#39;11, 04:20
samy
1●2●2●2
accept rate: 0%
  
One Answer:
  
0You&#39;re not very specific, so you could have a look here, and maybe find a presentation here.</description>
    </item>
    
    <item>
      <title>Identify data traffic requested by users</title>
      <link>/questions/6694/identify-data-traffic-requested-by-users/</link>
      <pubDate>Tue, 04 Oct 2011 04:23:00 +0000</pubDate>
      
      <guid>/questions/6694/identify-data-traffic-requested-by-users/</guid>
      <description>Identify data traffic requested by users  0 Hi, how can i use wireshark to identify data traffic on a network that is requested by users
traffic dataasked 04 Oct &#39;11, 04:23
samy
1●2●2●2
accept rate: 0%
Hi Samy, you have to be a little more specific then that...is it some sort of client-server model, is it Windows, is it webtraffic...many questions..
(04 Oct &#39;11, 05:27) Marc   </description>
    </item>
    
    <item>
      <title>how to convert the user-defined item in hr_tree to a human-readable format</title>
      <link>/questions/6696/how-to-convert-the-user-defined-item-in-hr_tree-to-a-human-readable-format/</link>
      <pubDate>Tue, 04 Oct 2011 05:26:00 +0000</pubDate>
      
      <guid>/questions/6696/how-to-convert-the-user-defined-item-in-hr_tree-to-a-human-readable-format/</guid>
      <description>how to convert the user-defined item in hr_tree to a human-readable format  0 I created two items (stamp1 and stamp2 in hr_tree) to label special useful bytes with the following line of code in packet-eth.c:
proto_tree_add_item(fh_tree, vtime_id, trailer_tvb, (trailer_length - 8), 8, FALSE);Here&#39;s the decoding with the items added:
Frame 1: 69 bytes on wire (552 bits), 69 bytes captured (552 bits) Ethernet II, Src: JuniperN_17:d0:85 (00:05:85:17:d0:85), Dst: Cisco_ef:fd:00 (00:1b:0d:ef:fd:00) Destination: Cisco_ef:fd:00 (00:1b:0d:ef:fd:00) Source: JuniperN_17:d0:85 (00:05:85:17:d0:85) Type: IP (0x0800) stamp1: 4e64885133d37df8 stamp2: 04 Trailer: 000000000000 Internet Protocol Version 4, Src: 111.</description>
    </item>
    
    <item>
      <title>Unknown invokedata blob</title>
      <link>/questions/6698/unknown-invokedata-blob/</link>
      <pubDate>Tue, 04 Oct 2011 05:36:00 +0000</pubDate>
      
      <guid>/questions/6698/unknown-invokedata-blob/</guid>
      <description>Unknown invokedata blob  0 For packet Unknown INAP (64) invoke command:Unknown(64) is coming. Unknown invokedata blob error. Can a solution be suggested for this
ss7asked 04 Oct &#39;11, 05:36
rissac
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Hi,
If that&#39;s an operation code of 64, it&#39;s either a non standard INAP version or a later spec than IN-operationcodes (Q.1248.1:07/2001) which is waht Wireshark supports. If this Opcode exists in a later spec, raise an enhancment bug report.</description>
    </item>
    
    <item>
      <title>How to get long time statistics?</title>
      <link>/questions/6705/how-to-get-long-time-statistics/</link>
      <pubDate>Tue, 04 Oct 2011 08:11:00 +0000</pubDate>
      
      <guid>/questions/6705/how-to-get-long-time-statistics/</guid>
      <description>How to get long time statistics?  0 Hi,
I want to watch network traffic for a long time but I am not interested in every single package but only in statistics like displayed in the IO Graphs window. But I can&#39;t find how to do it. If I just let Wireshark run, it blows the memory of my computer and crashes and if I build a ring buffer the IO Graph is always started anew when a file is closed and a new one opened.</description>
    </item>
    
    <item>
      <title>basic question on tcp function</title>
      <link>/questions/6706/basic-question-on-tcp-function/</link>
      <pubDate>Tue, 04 Oct 2011 08:14:00 +0000</pubDate>
      
      <guid>/questions/6706/basic-question-on-tcp-function/</guid>
      <description>basic question on tcp function  0 Hi,
I would like to ask a beginners question, hope someone takes the time...
As much as I read a packet is said to be lost if there is no acknowledge packet returned to the sender before the corresponding RTT timer runs out. Now my question is, how it can be detected that a segment is lost and then retansmitted when being on the receiver side.</description>
    </item>
    
    <item>
      <title>UDP multicast, Windows 7 firewall, Labview</title>
      <link>/questions/6711/udp-multicast-windows-7-firewall-labview/</link>
      <pubDate>Tue, 04 Oct 2011 09:56:00 +0000</pubDate>
      
      <guid>/questions/6711/udp-multicast-windows-7-firewall-labview/</guid>
      <description>UDP multicast, Windows 7 firewall, Labview  0 I am sending UDP packets to a multicast address (224.1.1.1) on an unused port (60000) from an embedded board hooked into my network.
When I run a Wireshark capture on my PC, I can see the UDP packets. Everything appears correct (including checksums). I developed a Labview script to read the incoming UDP packets. However, it does not see the packets (i.e., times out when it tries to read the IP/port).</description>
    </item>
    
    <item>
      <title>Wireshark-users Digest, Vol 65, Issue 3</title>
      <link>/questions/6715/wireshark-users-digest-vol-65-issue-3/</link>
      <pubDate>Tue, 04 Oct 2011 12:06:00 +0000</pubDate>
      
      <guid>/questions/6715/wireshark-users-digest-vol-65-issue-3/</guid>
      <description>Wireshark-users Digest, Vol 65, Issue 3  0 I received a message with the subject: Wireshark-users Digest, Vol 65, Issue 3 from &#34;wireshark-users-request&#34;
It was 13.8 MB long. Not sure how it did it but it took my email client DOWN - twice - before I figured out that there was an issue with this email.
The only thing peculiar about the message is the length - I don&#39;t recall any of these messages being even one MB.</description>
    </item>
    
    <item>
      <title>Capturing on GigE Headend Network</title>
      <link>/questions/6717/capturing-on-gige-headend-network/</link>
      <pubDate>Tue, 04 Oct 2011 13:18:00 +0000</pubDate>
      
      <guid>/questions/6717/capturing-on-gige-headend-network/</guid>
      <description>Capturing on GigE Headend Network  0 I am trying to capture the video interface on an Arris ad server. Using Wireshark I CAN see pings and I CAN see FTP frames from it and i can capture that data on wireshark. When it sends a video file I can NOT see the UDP frames that are known to be coming from it because it is airing an ad to a splicer.</description>
    </item>
    
    <item>
      <title>Set maximum packet count.</title>
      <link>/questions/6729/set-maximum-packet-count/</link>
      <pubDate>Tue, 04 Oct 2011 22:48:00 +0000</pubDate>
      
      <guid>/questions/6729/set-maximum-packet-count/</guid>
      <description>Set maximum packet count.  1 For example, I hope to display the newest 65535 packets and drop the oldest ones, in order to save memory when I am waiting some event that happens randomly. I cannot find the option on this. Is it possible or no this feature currently?
Sorry for my poor English.
count maximumasked 04 Oct &#39;11, 22:48
OstCollector
16●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>wireshark mac filter ip addresses on same network</title>
      <link>/questions/6732/wireshark-mac-filter-ip-addresses-on-same-network/</link>
      <pubDate>Wed, 05 Oct 2011 02:05:00 +0000</pubDate>
      
      <guid>/questions/6732/wireshark-mac-filter-ip-addresses-on-same-network/</guid>
      <description>wireshark mac filter ip addresses on same network  0 Hi all,
Im having problems with setting up my wireshark correctly. It works on my machine and i can see all packets that are sent/received. But when i try to filter via ip.addr == xx.xx.xxx.xxx, for example, it doesn&#39;t work. All i am able to see on the wireshark is a few hits from dropbox and i know the machine that im trying to &#39;sniff&#39; is on the internet and surfing as its right next to me.</description>
    </item>
    
    <item>
      <title>Packet analyzer vs. Packet sniffer</title>
      <link>/questions/6737/packet-analyzer-vs-packet-sniffer/</link>
      <pubDate>Wed, 05 Oct 2011 10:43:00 +0000</pubDate>
      
      <guid>/questions/6737/packet-analyzer-vs-packet-sniffer/</guid>
      <description>Packet analyzer vs. Packet sniffer  1 Is there a difference between them?
sniffer analyzer packetasked 05 Oct &#39;11, 10:43
YKG
16●1●1●2
accept rate: 0%
  
One Answer:
  
5Mostly a semantic difference, but yes:
A packet sniffer records packets observed on a network interface.
A packet analyzer looks at packets and tries to make some inferences about what they contain.
answered 05 Oct &#39;11, 14:17</description>
    </item>
    
    <item>
      <title>How does dissector_add work?</title>
      <link>/questions/6738/how-does-dissector_add-work/</link>
      <pubDate>Wed, 05 Oct 2011 12:47:00 +0000</pubDate>
      
      <guid>/questions/6738/how-does-dissector_add-work/</guid>
      <description>How does dissector_add work?  0 Hi, I&#39;m a newbie trying to write a dissector for the first time. I&#39;ve noticed the function dissector_add() gets called to associate a particular identifier with a dissector handle.
If I call dissector_add() twice for the same handle does it &#34;and&#34; these two identifiers or &#34;or&#34; them?
What do I do if I want my dissector to match a combination of &#34;and&#34;s and &#34;or&#34;s, like an expression like this might indicate?</description>
    </item>
    
    <item>
      <title>Wireshark slow performance in Citrix</title>
      <link>/questions/6744/wireshark-slow-performance-in-citrix/</link>
      <pubDate>Wed, 05 Oct 2011 15:31:00 +0000</pubDate>
      
      <guid>/questions/6744/wireshark-slow-performance-in-citrix/</guid>
      <description>Wireshark slow performance in Citrix  0 Has anybody ever run wireshark in Unix via Citrix displayback? After we upgraded the wireshark from V0.99.8 to V1.2.6 Wireshark displayed really slow and became unusable in Citrix. Does anybody know which Citrix version is compatible with wireshark V1.2.6+ version (built upon GTK2)? Or any possible workaround for this?
performance gtk citrixasked 05 Oct &#39;11, 15:31
dxl
1●2●2●3
accept rate: 0%
 edited 05 Oct &#39;11, 22:30</description>
    </item>
    
    <item>
      <title>analysing a video stream</title>
      <link>/questions/6750/analysing-a-video-stream/</link>
      <pubDate>Thu, 06 Oct 2011 02:07:00 +0000</pubDate>
      
      <guid>/questions/6750/analysing-a-video-stream/</guid>
      <description>analysing a video stream  0 Hello, I connected a Set-Top-Box (IPTV-Box) with my Computer via ethernet. The IP-Box gets its signal from an antenna-cable. On my Computer I installed a software(including a videoplayer) of the box that allows me to watch the video stream. So when I am watching this stream i start a wireshark analysis. Now I want to know what kind of video stream is sent to my computer like mpeg1,2,3,4 or others.</description>
    </item>
    
    <item>
      <title>voice traffic sniffing</title>
      <link>/questions/6751/voice-traffic-sniffing/</link>
      <pubDate>Thu, 06 Oct 2011 04:11:00 +0000</pubDate>
      
      <guid>/questions/6751/voice-traffic-sniffing/</guid>
      <description>voice traffic sniffing  0 I am trying to sniffing the voice traffic (AVAYA VoIP) on my network (HP ProCurve) but there is no output except the network traffic like SNMP,VRRP, ARP....etc.
hp voice avayaasked 06 Oct &#39;11, 04:11
ashboull
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Problem with the command line &amp;quot;stop&amp;quot;</title>
      <link>/questions/6752/problem-with-the-command-line-stop/</link>
      <pubDate>Thu, 06 Oct 2011 06:24:00 +0000</pubDate>
      
      <guid>/questions/6752/problem-with-the-command-line-stop/</guid>
      <description>Problem with the command line &amp;ldquo;stop&amp;rdquo;  0 I have a problem, I can&#39;t stop wireshark with a command line. I used the command line to start wireshark : &#34;wireshark -i 3 -k&#34; and after I would like to stop wireshark with a new command line. But when I use the command &#34;wireshark -a duration:1&#34;, I have another instance of wireshark which opens. Is it possible to start and stop wireshark with 2 commands line ?</description>
    </item>
    
    <item>
      <title>Wireshark 1.6.2 doesn&amp;#x27;t catch http: login. Why not?</title>
      <link>/questions/6753/wireshark-162-doesnt-catch-http-login-why-not/</link>
      <pubDate>Thu, 06 Oct 2011 09:52:00 +0000</pubDate>
      
      <guid>/questions/6753/wireshark-162-doesnt-catch-http-login-why-not/</guid>
      <description>Wireshark 1.6.2 doesn&amp;rsquo;t catch http: login. Why not?  0 Hi, I&#39;m trying to catch the packet that contains the data for my home page login. I get the 401 not authorised page and Chrome/IE offer the login box. I put in my username and password but Wireshark doesn&#39;t seem to catch it. Can anyone explain please?
loginasked 06 Oct &#39;11, 09:52
turnbui
1●1●1●1
accept rate: 0%
How do you know that &#34;</description>
    </item>
    
    <item>
      <title>Linking Error with str_to_str</title>
      <link>/questions/6756/linking-error-with-str_to_str/</link>
      <pubDate>Thu, 06 Oct 2011 13:04:00 +0000</pubDate>
      
      <guid>/questions/6756/linking-error-with-str_to_str/</guid>
      <description>Linking Error with str_to_str  1 I&#39;ve made a custom dissector plugin for Wireshark and have a weird linking error. This is my first plugin and am using MSVC 2010 express as my compiler.
I get a linking error that it can&#39;t resolve the str_to_str function in value_string.h. It states &#34;unresolved external symbol _str_to_str referenced in function xyz&#34;. I&#39;m using value_string and string_string structs and have no problem compiling and linking other functions in the header (such as val_to_str).</description>
    </item>
    
    <item>
      <title>Just want to watch Server Internet Activity</title>
      <link>/questions/6760/just-want-to-watch-server-internet-activity/</link>
      <pubDate>Thu, 06 Oct 2011 13:50:00 +0000</pubDate>
      
      <guid>/questions/6760/just-want-to-watch-server-internet-activity/</guid>
      <description>Just want to watch Server Internet Activity  0 Can I easily use Wireshark installed on a Windows SBS 2003 server to capture traffic sent and received from the server (IP 192.168.1.10) to and from the internet. I want to eaily hide the traffic sent to other 192.168.1.x systems since they are internal.
Woudl also like to then hide traffic to and from known applications or services on my system, such as logmein, exchange SMTP port 25 packets, etc.</description>
    </item>
    
    <item>
      <title>Filtering: Bitwise-and is leading to linker error</title>
      <link>/questions/6768/filtering-bitwise-and-is-leading-to-linker-error/</link>
      <pubDate>Fri, 07 Oct 2011 00:18:00 +0000</pubDate>
      
      <guid>/questions/6768/filtering-bitwise-and-is-leading-to-linker-error/</guid>
      <description>Filtering: Bitwise-and is leading to linker error  0 Hello,
I have tried to put bitwise-and(&amp;amp;) into the display filter Dialog box&#39;s sources, made proper and necessary changes that are required (like calling the bitwise-and related function (ftype_can_bitwise_and) from ftypes/ftypes.c same as the other operator functions are called). There are no compile-time errors but at the end I&#39;m facing a linker error called :
Linking wireshark.exe link @C:\DOCUME~1\admin\LOCALS~1\Temp\nm1C1.tmp libui.lib(dfilter_expr_dlg.obj) : error LNK2019: unresolved external symbol _ftype_can_trig referenced in function _show_relations wireshark.</description>
    </item>
    
    <item>
      <title>Access to decrypted WPA/WPA2 data for lua dissector</title>
      <link>/questions/6769/access-to-decrypted-wpawpa2-data-for-lua-dissector/</link>
      <pubDate>Fri, 07 Oct 2011 00:48:00 +0000</pubDate>
      
      <guid>/questions/6769/access-to-decrypted-wpawpa2-data-for-lua-dissector/</guid>
      <description>Access to decrypted WPA/WPA2 data for lua dissector  0 I am using wireshark capturing WLAN traffic with AirPcap. All traffic in WLAN network is always encrypted with WPA/WPA2. So to be able to make analysis I use wireshark to decrypt traffic. Is there way for lua dissector to access this decrypted data ?
It seems that some dissector are able to access decrypted data since wireshark recognizes for example ARP messages from decrypted traffic.</description>
    </item>
    
    <item>
      <title>OS X Lion Install failure</title>
      <link>/questions/6780/os-x-lion-install-failure/</link>
      <pubDate>Fri, 07 Oct 2011 05:52:00 +0000</pubDate>
      
      <guid>/questions/6780/os-x-lion-install-failure/</guid>
      <description>OS X Lion Install failure  0 Hi,
I&#39;m having trouble running Wireshark on Mac OS X 10.7.1 Lion - The Install seems to proceed ok, but on running Wireshark I get a window warning me the app may take time to start the first time as the font caches are built, but then it quits.
I had a previous version installed, but I have cleaned out /Applications/Wireshark, /Library/StartupItems/ChmodBPF and /opt/local/bin/wireshark (remnant from a previous Macports install) - but there was no /Library/Wireshark.</description>
    </item>
    
    <item>
      <title>HTTP connect method</title>
      <link>/questions/6807/http-connect-method/</link>
      <pubDate>Sat, 08 Oct 2011 09:10:00 +0000</pubDate>
      
      <guid>/questions/6807/http-connect-method/</guid>
      <description>HTTP connect method  1 I am working to implement web proxy for HTTP tunnel. I am looking for sample HTTP connect method header sent by web proxy to the server. And the 200 OK that the web proxy will validate before allowing SSL hello client packet to the server.
Please let me know the above details and if possible provide me a sample wireshark capture to see HTTP connect and corresponding 200 ok of it.</description>
    </item>
    
    <item>
      <title>search in uncompressed packet bytes</title>
      <link>/questions/6809/search-in-uncompressed-packet-bytes/</link>
      <pubDate>Sat, 08 Oct 2011 11:56:00 +0000</pubDate>
      
      <guid>/questions/6809/search-in-uncompressed-packet-bytes/</guid>
      <description>search in uncompressed packet bytes  0 I&#39;ve captured some http packets and want to find out which ones contain some string. I use &#34;Edit-&amp;gt;Find Packet&#34; with &#34;Packet bytes&#34; option selected, but it doesn&#39;t find anything because the data is compressed (Content-Encoding: gzip). When I search in &#34;Packet details&#34;, it doesn&#39;t find everything because some lines are too long and get truncated.
Is there any way to search in uncompressed packet bytes?</description>
    </item>
    
    <item>
      <title>Special handling of an &amp;#x27;FT_ABSOLUTE_TIME&amp;#x27; field</title>
      <link>/questions/6811/special-handling-of-an-ft_absolute_time-field/</link>
      <pubDate>Sun, 09 Oct 2011 07:42:00 +0000</pubDate>
      
      <guid>/questions/6811/special-handling-of-an-ft_absolute_time-field/</guid>
      <description>Special handling of an &amp;lsquo;FT_ABSOLUTE_TIME&amp;rsquo; field  0 Hello guys,
There is a question about FT_ABSOLUTE_TIME you know, from the README.developer file, the FT_ABSOLUTE_TIME described as below:
An absolute time from some fixed point in time, displayed as the date, followed by the time, as hours, minutes, and seconds with 9 digits after the decimal point.
But I just want only the last 30 bits of the last four bytes used for the nsecs, the first 2 bits of the last four bytes used for other purposes.</description>
    </item>
    
    <item>
      <title>Wireshark setup with OSX Lion</title>
      <link>/questions/6812/wireshark-setup-with-osx-lion/</link>
      <pubDate>Sun, 09 Oct 2011 08:19:00 +0000</pubDate>
      
      <guid>/questions/6812/wireshark-setup-with-osx-lion/</guid>
      <description>Wireshark setup with OSX Lion  0 Can anyone give me step-by-step instructions on setting up Wireshark on OSX Lion?
osx lion installationasked 09 Oct &#39;11, 08:19
JAG
1●1●1●1
accept rate: 0%
 edited 09 Oct &#39;11, 09:18 
helloworld
3.1k●4●20●41
Do you know if your latest Snow Leopard compatible release is also compatible with OSX Lion, or do you have a projected release date for WS for Lion?
(09 Oct &#39;11, 08:20) JAG</description>
    </item>
    
    <item>
      <title>Block web sites on a lan platform</title>
      <link>/questions/6822/block-web-sites-on-a-lan-platform/</link>
      <pubDate>Mon, 10 Oct 2011 02:43:00 +0000</pubDate>
      
      <guid>/questions/6822/block-web-sites-on-a-lan-platform/</guid>
      <description>Block web sites on a lan platform  1 Hi
Can I use Wire Shark to block certain web sites?
I want to use it in an office environment and block certain sites that are not work related.
Jani
applicationasked 10 Oct &#39;11, 02:43
Jani Louw Fo...
16●1●1●3
accept rate: 0%
  
One Answer:
  
2No, you can&#39;t. Think of Wireshark as a passive diagnostic tool, just like a doctor uses a stethoscope to listen to a patients body.</description>
    </item>
    
    <item>
      <title>DHCP request packets</title>
      <link>/questions/6826/dhcp-request-packets/</link>
      <pubDate>Mon, 10 Oct 2011 05:16:00 +0000</pubDate>
      
      <guid>/questions/6826/dhcp-request-packets/</guid>
      <description>DHCP request packets  0 on my trace I have
DHCP Request DHCP ACK DHCP RequestI don&#39;t understand what triggers the second request. the difference between the two request packets is the packet subtype first request packet flags: .... ..01 = DS status: Frame from STA to DS via an AP (To DS: 1 From DS: 0) (0x01) second request packet flags: .... ..10 = DS status: Frame from DS to a STA via AP(To DS: 0 From DS: 1) (0x02)</description>
    </item>
    
    <item>
      <title>File size limit on TShark?</title>
      <link>/questions/6835/file-size-limit-on-tshark/</link>
      <pubDate>Mon, 10 Oct 2011 11:15:00 +0000</pubDate>
      
      <guid>/questions/6835/file-size-limit-on-tshark/</guid>
      <description>File size limit on TShark?  0 I have been attempting to capture a high volume of multicast traffic for a week now using TShark. The process always unexpectedly terminates. The captures start at various times of the day.
Trying to figure out what is going on, I noticed that the capture files almost always are just short of 40GB in size when TShark terminates. It appears to be the one constant I&#39;ve found in the problem.</description>
    </item>
    
    <item>
      <title>[closed] Feature Request - Output Format of Custom Columns</title>
      <link>/questions/6841/feature-request-output-format-of-custom-columns/</link>
      <pubDate>Tue, 11 Oct 2011 01:30:00 +0000</pubDate>
      
      <guid>/questions/6841/feature-request-output-format-of-custom-columns/</guid>
      <description>[closed] Feature Request - Output Format of Custom Columns  1 1Hi!
I would like to add a custom column for ptp.v2.ClockIdentity, but when I do this, the value of this field is represented in the column (packet list view) as a number while it shows as a hex-byte sequency in the packet details.
I guess this is because the data type of the field itself is 64bit unsigned int, so my question is: Is there a way to let custom columns use the same representation that is used in the packet details?</description>
    </item>
    
    <item>
      <title>how to decode TCAP messages using Wireshark</title>
      <link>/questions/6842/how-to-decode-tcap-messages-using-wireshark/</link>
      <pubDate>Tue, 11 Oct 2011 01:55:00 +0000</pubDate>
      
      <guid>/questions/6842/how-to-decode-tcap-messages-using-wireshark/</guid>
      <description>how to decode TCAP messages using Wireshark  0 Hi,
I am trying to decode TCAP messages(for CAP protocol) using WIreshark(v1.0.9),and I find that the data contents are not decoded at all while trying to open the SS7 IP traces recived.
Does it required to have special Dictionary files for TCAP while decoding such messages.
tcapasked 11 Oct &#39;11, 01:55
rouseparty
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>No more capturing packets from Wi-Fi</title>
      <link>/questions/6845/no-more-capturing-packets-from-wi-fi/</link>
      <pubDate>Tue, 11 Oct 2011 06:20:00 +0000</pubDate>
      
      <guid>/questions/6845/no-more-capturing-packets-from-wi-fi/</guid>
      <description>No more capturing packets from Wi-Fi  0 Look, I&#39;ve got a problem. My computer is MacBook Pro 13/2011. I used wireshark for a long time and everything was perfect. I was catching packets of Wi-Fi, analyzing them. But something changed and now, when I use HTTP protocol filter I can see only m-search which doesn&#39;t help me at all. I can see all packets but only of my own computer.</description>
    </item>
    
    <item>
      <title>SSL decode from Websphere</title>
      <link>/questions/6849/ssl-decode-from-websphere/</link>
      <pubDate>Tue, 11 Oct 2011 12:56:00 +0000</pubDate>
      
      <guid>/questions/6849/ssl-decode-from-websphere/</guid>
      <description>SSL decode from Websphere  0 Hi, I&#39;m trying to decode traffic from a (windows) browser to a (Linux) Websphere box. So far I have;
User OPENSSL to extract the default private key from Websphere key.p12. This is the websphere keystore used for SSL.Used OPENSSL to generate an RSA private key, with no password protect. (.pem)Setup Wireshark as &#34;10.x.x.x,9043,mykey.pem&#34; on the windows client.Generated some SSL traffic to the websphere box.Now, the debug file seems to read the private key fine, but I can&#39;t get any decoding to work.</description>
    </item>
    
    <item>
      <title>IP Addr. Generating the Most Traffic</title>
      <link>/questions/6850/ip-addr-generating-the-most-traffic/</link>
      <pubDate>Tue, 11 Oct 2011 13:11:00 +0000</pubDate>
      
      <guid>/questions/6850/ip-addr-generating-the-most-traffic/</guid>
      <description>IP Addr. Generating the Most Traffic  0 On our network, we noticed a spike in network utilization on a specific date at a specific time. Ever since then the network utilization is extemely high. I want to sniff the network and determine what IP addresses are generating all of the activity. How do I do that?
question network analysisasked 11 Oct &#39;11, 13:11
Netguru
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>radiotap.channel.freq wrong?</title>
      <link>/questions/6852/radiotapchannelfreq-wrong/</link>
      <pubDate>Tue, 11 Oct 2011 13:27:00 +0000</pubDate>
      
      <guid>/questions/6852/radiotapchannelfreq-wrong/</guid>
      <description>radiotap.channel.freq wrong?  0 This may actually be a radiotap question, forgive me if this is going to the wrong place...
I&#39;ve been seeing a lot of weird 2.4 GHz channels reported, using an Intel wireless card in a Dell, when the only channels in play should be 1, 6, and 11 (and 5, that&#39;s a different problem). On the other hand, the 802.11 header reports the &#34;correct&#34; channel. I went around with a Wi-Spy spectrum analyzer and the channels do appear to lie within the frequency ranges they belong in.</description>
    </item>
    
    <item>
      <title>Problems filtering by IP Address</title>
      <link>/questions/6861/problems-filtering-by-ip-address/</link>
      <pubDate>Wed, 12 Oct 2011 02:33:00 +0000</pubDate>
      
      <guid>/questions/6861/problems-filtering-by-ip-address/</guid>
      <description>Problems filtering by IP Address  0 I am using a mac running 10.6.8 and i am want to use wireshark to see the packet transmission between other devices on the network but i am having problems with this.
my current situation is that i am using ip.addr== &#39;then my ip address&#39;. If i put my own ip address in i can see all packets that are either sent or received by my ip address.</description>
    </item>
    
    <item>
      <title>strange relative sequence numbers</title>
      <link>/questions/6864/strange-relative-sequence-numbers/</link>
      <pubDate>Wed, 12 Oct 2011 02:59:00 +0000</pubDate>
      
      <guid>/questions/6864/strange-relative-sequence-numbers/</guid>
      <description>strange relative sequence numbers  0 The client sends 4 SYNs and receives RST,ACK for every one of them. Every time the relative sequence number of RST,ACK is different. Why is that so?
I - SYN seq=0; RST,ACK seq=1, ack=1
II - SYN seq=0; RST,ACK seq=1696235139, ack=1
III - SYN seq=0; RST,ACK seq=1544964366
IV- SYN seq=0; RST,ACK seq=937511781, ack=1
For the first SYN, RST,ACK has seq=1. What has changed for the following RSTs?</description>
    </item>
    
    <item>
      <title>win32 Installer doesn&amp;#x27;t include custom plugin dll</title>
      <link>/questions/6869/win32-installer-doesnt-include-custom-plugin-dll/</link>
      <pubDate>Wed, 12 Oct 2011 07:57:00 +0000</pubDate>
      
      <guid>/questions/6869/win32-installer-doesnt-include-custom-plugin-dll/</guid>
      <description>win32 Installer doesn&amp;rsquo;t include custom plugin dll  0 I created a dissector for my protocol and recompiled wireshark (1.6.2) using VS 2010. Everything works fine except when I try to create an installer. The dll for my custom plugin is not included. I&#39;ve changed everything in the ...packagingnsis directory to add the plugin (Custom.nmake, custom_plugins, Makefile.nmake, etc). Is there another file that needs modified?
Thanks, Brian
win32 installer dll pluginasked 12 Oct &#39;11, 07:57</description>
    </item>
    
    <item>
      <title>Server sends a strange ACK during three-way handshake</title>
      <link>/questions/6871/server-sends-a-strange-ack-during-three-way-handshake/</link>
      <pubDate>Wed, 12 Oct 2011 09:00:00 +0000</pubDate>
      
      <guid>/questions/6871/server-sends-a-strange-ack-during-three-way-handshake/</guid>
      <description>Server sends a strange ACK during three-way handshake  0 The service in question is FTP_DL with proxy between client and server. The problem is that proxy sends 2 SYNs with different sequence numbers over the same port and from same IP address. To the first SYN server responds with SYN,ACKs, but to the second it responds with ACK with unexpected seq/ack values. After receiving unexpected ACK, proxy RSTs the connection.</description>
    </item>
    
    <item>
      <title>Zero window and RST</title>
      <link>/questions/6872/zero-window-and-rst/</link>
      <pubDate>Wed, 12 Oct 2011 09:43:00 +0000</pubDate>
      
      <guid>/questions/6872/zero-window-and-rst/</guid>
      <description>Zero window and RST  0 1Hi Experts,
I am facing with the follwoving contradiction. In RFC 793 can be read the following sentences:
once: &#34;all reset (RST) segments are validated by checking their SEQ-fields. A reset is valid if its sequence number is in the window.&#34;
on other part of the doc: &#34;However, when the receive window is zero, a TCP must process the RST and URG fields of all incoming segments&#34;</description>
    </item>
    
    <item>
      <title>WPA 4-way handshake</title>
      <link>/questions/6873/wpa-4-way-handshake/</link>
      <pubDate>Wed, 12 Oct 2011 15:39:00 +0000</pubDate>
      
      <guid>/questions/6873/wpa-4-way-handshake/</guid>
      <description>WPA 4-way handshake  0 From this wiki page:
WPA and WPA2 use keys derived from an EAPOL handshake to encrypt traffic. Unless *all four* handshake packets are present for the session you&amp;#39;re trying to decrypt, Wireshark won&amp;#39;t be able to decrypt the traffic. You can use the display filter eapol to locate EAPOL packets in your capture.I&#39;ve noticed that it works with (1,2,4) too. Can someone please explain this?</description>
    </item>
    
    <item>
      <title>Do I need to enable an option in order to see the EIGRP payload encapsulated into an ESP with ESP-NULL encryption?</title>
      <link>/questions/6877/do-i-need-to-enable-an-option-in-order-to-see-the-eigrp-payload-encapsulated-into-an-esp-with-esp-null-encryption/</link>
      <pubDate>Thu, 13 Oct 2011 11:54:00 +0000</pubDate>
      
      <guid>/questions/6877/do-i-need-to-enable-an-option-in-order-to-see-the-eigrp-payload-encapsulated-into-an-esp-with-esp-null-encryption/</guid>
      <description>Do I need to enable an option in order to see the EIGRP payload encapsulated into an ESP with ESP-NULL encryption?  0 Good afternoon,
I&#39;m trying to look inside a EIGRP Update packet that is encapsulated over a DMVPN solutions (GRE and ESP with ESP-NULL set). For whatever reason the Data part of the EIGRP is garbage.
Any ideas how to fix this problem? Does Wireshark have a limitation on how far it can look inside an IP packet?</description>
    </item>
    
    <item>
      <title>Between CAT and PLC</title>
      <link>/questions/6878/between-cat-and-plc/</link>
      <pubDate>Thu, 13 Oct 2011 12:34:00 +0000</pubDate>
      
      <guid>/questions/6878/between-cat-and-plc/</guid>
      <description>Between CAT and PLC  0 Can I use Wireshark to capture data over Ethernet between a CAT engine and an Allen-Bradley PLC?
ethernet plc allen-bradley catasked 13 Oct &#39;11, 12:34
mgriffin2
6●1●1●3
accept rate: 0%
  
2 Answers:
  
1 I&#39;ve no idea what you mean by a &#39;CAT engine&#39;, but there&#39;s two forms of &#39;communication&#39; with a PLC.
On the data acquisition side where the PLC acquires the data from the I/O sensors Wireshark won&#39;t help as these are usually analog signals, and even where they are digital they are usually some form of serial protocol.</description>
    </item>
    
    <item>
      <title>Cannot Decrypt SSL Traffic - ssl_generate_keyring_material not enough data to generate key</title>
      <link>/questions/6881/cannot-decrypt-ssl-traffic-ssl_generate_keyring_material-not-enough-data-to-generate-key/</link>
      <pubDate>Thu, 13 Oct 2011 18:39:00 +0000</pubDate>
      
      <guid>/questions/6881/cannot-decrypt-ssl-traffic-ssl_generate_keyring_material-not-enough-data-to-generate-key/</guid>
      <description>Cannot Decrypt SSL Traffic - ssl_generate_keyring_material not enough data to generate key  1 I am no longer able to decrypt traffic. I noticed the new ssl certificate are 2048bits. Does wireshark support this? I have setup the private key, ip where the traffic is terminated and in the ssl log file i see that it successfully loaded the keys but I still cannot decrypt traffic. I am on server side so have public and private keys.</description>
    </item>
    
    <item>
      <title>possible virus infection</title>
      <link>/questions/6882/possible-virus-infection/</link>
      <pubDate>Thu, 13 Oct 2011 20:18:00 +0000</pubDate>
      
      <guid>/questions/6882/possible-virus-infection/</guid>
      <description>possible virus infection  0 I think my computer and Blackberry are being controlled by my competitor.
Why can I run a Wireshark live capture in any other house using their wireless connection, but in my house, it doesn’t capture anything?
My Blackberry &#34;black key work of my industry&#34; (???). When I send emails to my customers with the subject of key words from the industry, I get a red X near the email, which means blocked from sending.</description>
    </item>
    
    <item>
      <title>RTMPT just not showing up...</title>
      <link>/questions/6883/rtmpt-just-not-showing-up/</link>
      <pubDate>Thu, 13 Oct 2011 20:37:00 +0000</pubDate>
      
      <guid>/questions/6883/rtmpt-just-not-showing-up/</guid>
      <description>RTMPT just not showing up&amp;hellip;  0 I&#39;m trying to decode RTMP (real-time messaging protocol) in Wireshark. I just installed Wireshark v1.6.2 on Windows Vista 64 bit. The RTMP packets show up in the trace but are not decoded. The tcp port number if correctly displayed as macromedia-fcs, but the packets are displayed as TCP frames with undecoded data payloads. When I right click on a frame and select &#34;Decode As.</description>
    </item>
    
    <item>
      <title>How to use Wireshark to analyze QoS</title>
      <link>/questions/6884/how-to-use-wireshark-to-analyze-qos/</link>
      <pubDate>Thu, 13 Oct 2011 21:19:00 +0000</pubDate>
      
      <guid>/questions/6884/how-to-use-wireshark-to-analyze-qos/</guid>
      <description>How to use Wireshark to analyze QoS  0 How can I use Wireshark to analyze the data coming into the network and to determine where the network is not supporting the required QoS? Also, how can I use Wireshark to tell when the QoS I/O queue is full (and any other information about the queue)? How are packets assigned to that queue?
qos analysisasked 13 Oct &#39;11, 21:19
iti</description>
    </item>
    
    <item>
      <title>make rpm-package fails with 1.6.2</title>
      <link>/questions/6887/make-rpm-package-fails-with-162/</link>
      <pubDate>Fri, 14 Oct 2011 02:35:00 +0000</pubDate>
      
      <guid>/questions/6887/make-rpm-package-fails-with-162/</guid>
      <description>make rpm-package fails with 1.6.2  0 Hi.
I have just downloaded 1.6.2 Build is ok. (make works)
Now trying to make a rpm (make rpm-package). It failed. First I had an issue with krb5.h missing. I added package kerberos devel. Now I have error Kerberos not found
&#34;checking wether the Kerberos library is Hedimdal or MIT... no configure: error: Kerberos not found&#34;
If I am able to build with make, shouldn&#39;t I be able to make rpm-package ?</description>
    </item>
    
    <item>
      <title>glib directory not being created or updated in 1.4.9</title>
      <link>/questions/6892/glib-directory-not-being-created-or-updated-in-149/</link>
      <pubDate>Fri, 14 Oct 2011 08:52:00 +0000</pubDate>
      
      <guid>/questions/6892/glib-directory-not-being-created-or-updated-in-149/</guid>
      <description>glib directory not being created or updated in 1.4.9  0 I am trying to update a custom plugin from Ethereal 0.10.14 to Wireshark 1.4.9. I am following the README.plugins file to do the update. This is for a Win32 application, and I am using MSVC2008 as recommended.
I get the following error when compiling my plugin source:
c:\wireshark\wireshark-1.4.9\plugins\fatv\Rccu.h(12) : fatal error C1083: Cannot open include file: &amp;#39;glib.h&amp;#39;: No such file or directoryI had used the following command sequences:</description>
    </item>
    
    <item>
      <title>Laptop Hardware Recommendations for running Wireshark</title>
      <link>/questions/6894/laptop-hardware-recommendations-for-running-wireshark/</link>
      <pubDate>Fri, 14 Oct 2011 10:44:00 +0000</pubDate>
      
      <guid>/questions/6894/laptop-hardware-recommendations-for-running-wireshark/</guid>
      <description>Laptop Hardware Recommendations for running Wireshark  0 Forum
About a year ago, I purchased an HP gaming laptop based on its specs.. see below: Processor (Intel Core i7 - Q720 @ 1.6GHZ, 1600Mhz, 4 Core(s), 8 Logical Processors) Memory - 6 G with lots of HDD space.
I am not sure why, but I have been unsuccessful using WS for more than 10 minutes at a time before it shuts down/ locks up.</description>
    </item>
    
    <item>
      <title>Matshark function</title>
      <link>/questions/6898/matshark-function/</link>
      <pubDate>Fri, 14 Oct 2011 12:35:00 +0000</pubDate>
      
      <guid>/questions/6898/matshark-function/</guid>
      <description>Matshark function  0 Trying to extract traffic features in matlab.Can i use the matshark function....If yes,how,If not then how?
matsharkasked 14 Oct &#39;11, 12:35
deepanjan
0●3●3●3
accept rate: 0%
  
One Answer:
  
0You&#39;d need to build it, so it&#39;s not just something that you can download and drop in on an arbitrary operating system. See the mail message announcing it for details. Whether it&#39;ll support extracting the particular stuff you want to extract is another matter.</description>
    </item>
    
    <item>
      <title>How to filter multiple packets with same IP ID ?</title>
      <link>/questions/6903/how-to-filter-multiple-packets-with-same-ip-id/</link>
      <pubDate>Sat, 15 Oct 2011 04:44:00 +0000</pubDate>
      
      <guid>/questions/6903/how-to-filter-multiple-packets-with-same-ip-id/</guid>
      <description>How to filter multiple packets with same IP ID ?  0 Hello,
I have to filter and find if in the Trace we get 2 packets with same IP ID. (Ofcourse i dont know the IP ID in advance else its a simple filter).
So, an example: I have a 10,000 packets trace, i should show packets only which have same IP ID repeated.
How can i do it ?</description>
    </item>
    
    <item>
      <title>Sometimes I receive Assoc response packet before Assoc request was sent</title>
      <link>/questions/6909/sometimes-i-receive-assoc-response-packet-before-assoc-request-was-sent/</link>
      <pubDate>Sun, 16 Oct 2011 11:08:00 +0000</pubDate>
      
      <guid>/questions/6909/sometimes-i-receive-assoc-response-packet-before-assoc-request-was-sent/</guid>
      <description>Sometimes I receive Assoc response packet before Assoc request was sent  0 Image of the packet trace -&amp;gt; http://postimage.org/image/984jj38/
This is also happens with Auth packets the client -&amp;gt; AP packet has a timestamp which occurs after the AP -&amp;gt; client Auth packet
Does anyone know whats going on? is it a bug in the driver?
802.11 associationasked 16 Oct &#39;11, 11:08
ddayan
41●15●17●20
accept rate: 0%
 edited 16 Oct &#39;11, 13:21</description>
    </item>
    
    <item>
      <title>nmake -f Makefile.nmake setup Fails</title>
      <link>/questions/6910/nmake-f-makefilenmake-setup-fails/</link>
      <pubDate>Sun, 16 Oct 2011 16:36:00 +0000</pubDate>
      
      <guid>/questions/6910/nmake-f-makefilenmake-setup-fails/</guid>
      <description>nmake -f Makefile.nmake setup Fails  1 Anyone know what I&#39;m missing to cause the uzip err during the make setup?
&amp;gt;nmake -f Makefile.nmake setup Microsoft (R) Program Maintenance Utility Version 10.00.30319.01 Copyright (C) Microsoft Corporation. All rights reserved.
Checking for required applications: cl: /cygdrive/c/Program Files/Microsoft Visual Studio 10.0/VC/bin/cl link: /cygdrive/c/Program Files/Microsoft Visual Studio 10.0/VC/bin/link
 nmake: /cygdrive/c/Program Files/Microsoft Visual Studio 10.0/VC/bin/nmake mt: /cygdrive/c/Program Files/Microsoft SDKs/Windows/v7.0A/bin/mt bash: /usr/bin/bash bison: /cygdrive/c/Program Files/GnuWin32/bin/bison flex: /cygdrive/c/Program Files/GnuWin32/bin/flex env: /usr/bin/env grep: /usr/bin/grep /usr/bin/find: /usr/bin/find perl: /cygdrive/c/Perl/bin/perl C:\Python27\python.</description>
    </item>
    
    <item>
      <title>diagnose opening connection errors</title>
      <link>/questions/6916/diagnose-opening-connection-errors/</link>
      <pubDate>Mon, 17 Oct 2011 04:04:00 +0000</pubDate>
      
      <guid>/questions/6916/diagnose-opening-connection-errors/</guid>
      <description>diagnose opening connection errors  0 Newbie question.
I&#39;m trying to diagnose why a Java-based app runs for a while as a client making SOAP webservice calls, and then starts hitting an exception whereby it cannot open a socket. The OS is Windows 2003 server SP1.
I suspect that there&#39;s an error in the way that the client-side API is being used (Axis2 v1.4), such that it fails to recycle some internal resource.</description>
    </item>
    
    <item>
      <title>Wireshark errors and closes on save of capture filter?</title>
      <link>/questions/6919/wireshark-errors-and-closes-on-save-of-capture-filter/</link>
      <pubDate>Mon, 17 Oct 2011 06:12:00 +0000</pubDate>
      
      <guid>/questions/6919/wireshark-errors-and-closes-on-save-of-capture-filter/</guid>
      <description>Wireshark errors and closes on save of capture filter?  0 Running v1.6.2 - often when I &#34;save as&#34; a capture to my WindowsXP workstations, I get an error saying that Wireshark has encountered an error and has to close. The file appears to be saved intact but there is no &#34;recollection&#34; by Wireshark in the recent files list.
I have never encountered this with previous versions of Wireshark. Has anyone else had this problem, and if so is there a solution or work-around?</description>
    </item>
    
    <item>
      <title>dhcp failover analysis</title>
      <link>/questions/6920/dhcp-failover-analysis/</link>
      <pubDate>Mon, 17 Oct 2011 06:32:00 +0000</pubDate>
      
      <guid>/questions/6920/dhcp-failover-analysis/</guid>
      <description>dhcp failover analysis  0 Greetings,
I found this http://anonsvn.wireshark.org/wireshark/trunk/epan/dissectors/packet-dhcp-failover.c
But I don&#39;t know what to do with it. I&#39;m assuming that I might have to compile my own Wireshark with that included, could someone point me in the right direction?
failover dhcpdasked 17 Oct &#39;11, 06:32
dtdionne
1●1●1●1
accept rate: 0%
What is you want to do ?
The dhcp-failover dissector is included in Wireshark and has been for quite some time.</description>
    </item>
    
    <item>
      <title>Dissector uses C&#43;&#43;</title>
      <link>/questions/6936/dissector-uses-c/</link>
      <pubDate>Mon, 17 Oct 2011 16:49:00 +0000</pubDate>
      
      <guid>/questions/6936/dissector-uses-c/</guid>
      <description>Dissector uses C++  0 Hi, I&#39;m writing a dissector that I&#39;ve put in the plugins directory. Some of the code being called by my dissector is C++ code. The C++ code has been compiled into a library. Currently, I am calling &#34;make&#34; from my wireshark installation directory, which compiles foo.o with gcc and then attempts to link foo.o with my C++ library with gcc as well (to form foo.so). However, I believe I want to use g++ to link, right?</description>
    </item>
    
    <item>
      <title>custom hardware</title>
      <link>/questions/6937/custom-hardware/</link>
      <pubDate>Mon, 17 Oct 2011 16:56:00 +0000</pubDate>
      
      <guid>/questions/6937/custom-hardware/</guid>
      <description>custom hardware  0 Hi
I want to be able to &#34;on the fly&#34; remotely capture data.
I want to have 24 TAPS where they are connected to a custom PC that has 8*3 NIC PCI express cards. The Motherboard NIC would be the RDP connection.
When an issue happens I can RDP and start a capture on one or more of the 24 interfaces that I choose.
Will Wireshark handle 24 interfaces.</description>
    </item>
    
    <item>
      <title>How do I convert an &amp;quot;answer&amp;quot; to a comment</title>
      <link>/questions/6941/how-do-i-convert-an-answer-to-a-comment/</link>
      <pubDate>Mon, 17 Oct 2011 23:17:00 +0000</pubDate>
      
      <guid>/questions/6941/how-do-i-convert-an-answer-to-a-comment/</guid>
      <description>How do I convert an &amp;ldquo;answer&amp;rdquo; to a comment  1 Folks sometimes post &#34;answers&#34; to their own questions when they should really be comments to either the original question or an actual answer.
How can posters of the incorrect &#34;answer&#34; or editors turn the &#34;answer&#34; into a comment.
answer comment meta editor ask.wireshark.orgasked 17 Oct &#39;11, 23:17
grahamb ♦
19.8k●3●30●206
accept rate: 22%
 edited 20 Oct &#39;11, 07:27</description>
    </item>
    
    <item>
      <title>How to download a particular wireshark revision?</title>
      <link>/questions/6946/how-to-download-a-particular-wireshark-revision/</link>
      <pubDate>Tue, 18 Oct 2011 02:57:00 +0000</pubDate>
      
      <guid>/questions/6946/how-to-download-a-particular-wireshark-revision/</guid>
      <description>How to download a particular wireshark revision?  1 1I would like to download only the wireshark 1.6.1 version, 38101 revision. Today&#39;s Revision number of 1.6.1 is 39457. How can i Download 38101?
wiresharkThis question is marked &#34;community wiki&#34;.asked 18 Oct &#39;11, 02:57
Terrestrial ...
96●21●28●29
accept rate: 42%
  
One Answer:
  
2I don&#39;t think there are tar-balls of specific svn revisions (other than releases) available except for the trunk (1.</description>
    </item>
    
    <item>
      <title>Packet threshold</title>
      <link>/questions/6953/packet-threshold/</link>
      <pubDate>Tue, 18 Oct 2011 04:35:00 +0000</pubDate>
      
      <guid>/questions/6953/packet-threshold/</guid>
      <description>Packet threshold  0 Is there a way for Wireshark to give a notification when a certain number of packets/second (or other time interval) are transmitted from a given protocol? On a LAN recently, one computer was sending five thousand emails a second (not sure on the cause, obviously something malicious) and the staff did not realize it until the ISP handling the requests turned the service off.
threshold lanasked 18 Oct &#39;11, 04:35</description>
    </item>
    
    <item>
      <title>Adding to tree</title>
      <link>/questions/6957/adding-to-tree/</link>
      <pubDate>Tue, 18 Oct 2011 09:32:00 +0000</pubDate>
      
      <guid>/questions/6957/adding-to-tree/</guid>
      <description>Adding to tree  0 I am trying to build a dissector, and what I would like to do is extract pieces of data, perform some data manipulation (ie, logic, concatenating two separate sets of data together). After working on it some myself and looking at the documentation, it seems to me that the only way to add anything to a tree is the &#34;proto_tree_add_item(tree, id, tvb, start, length, encoding)&#34;. Is there a different function I can use for my purposes?</description>
    </item>
    
    <item>
      <title>Trying Vector CANcaseXL interface</title>
      <link>/questions/6962/trying-vector-cancasexl-interface/</link>
      <pubDate>Tue, 18 Oct 2011 11:19:00 +0000</pubDate>
      
      <guid>/questions/6962/trying-vector-cancasexl-interface/</guid>
      <description>Trying Vector CANcaseXL interface  0 Has anyone had success using the Vector CANcaseXL USB interface with Wireshark? The interface does not show up in the interface list.
Thanks in advance.
Norman
vector cancasexlasked 18 Oct &#39;11, 11:19
normanterry
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>SSL decryption issue using p12 (.pfx)</title>
      <link>/questions/6963/ssl-decryption-issue-using-p12-pfx/</link>
      <pubDate>Tue, 18 Oct 2011 11:29:00 +0000</pubDate>
      
      <guid>/questions/6963/ssl-decryption-issue-using-p12-pfx/</guid>
      <description>SSL decryption issue using p12 (.pfx)  0 I need to capture and decrypt https traffic from my exchange server.
I&#39;ve exported the exchange server&#39;s SSL certificate, and loaded it into wireshark under the ssl protocol, but my packets still are not being decrypted.
5.54.209.223,443,http,C:certname.pfx, (no password)
Picking an example packet, I&#39;ve grabbed a encrypted packet from my server responding to the client (#139) packet 139 in my capture remains encrypted I can go into &#34;</description>
    </item>
    
    <item>
      <title>FTP Problem</title>
      <link>/questions/6964/ftp-problem/</link>
      <pubDate>Tue, 18 Oct 2011 12:08:00 +0000</pubDate>
      
      <guid>/questions/6964/ftp-problem/</guid>
      <description>FTP Problem  0 Hi ,
I have a problem witch my FTP server. The problem are packet lost. I captured traffic and I saw strange problem with ftp-data length value.
Server and client have set MTU = 1460 but client sent data to server witch MTU 1590 bytes.
192.168.2.14 192.168.2.2 FTP-DATA 1078 FTP Data: 1024 bytes
192.168.2.14 192.168.2.2 FTP-DATA 1590 FTP Data: 1536 bytes
192.168.2.2 192.168.2.14 TCP 60 62305 &amp;gt; 62057 [ACK] Seq=1 Ack=105909 Win=28288 Len=0</description>
    </item>
    
    <item>
      <title>License Agreement</title>
      <link>/questions/6965/license-agreement/</link>
      <pubDate>Tue, 18 Oct 2011 12:09:00 +0000</pubDate>
      
      <guid>/questions/6965/license-agreement/</guid>
      <description>License Agreement  0 Hello,
I work in the marketing department at an IT training video company and I had a question about using the WireShark logo. We are building an free utilities for IT Professionals page for our site and have chose to have WireShark on our site. We wanted to use the WireShark Logo on that page. I wanted to know if this broke any of your license agreement&#39;s terms.</description>
    </item>
    
    <item>
      <title>Retrive tcp duration using tshark</title>
      <link>/questions/6977/retrive-tcp-duration-using-tshark/</link>
      <pubDate>Tue, 18 Oct 2011 17:20:00 +0000</pubDate>
      
      <guid>/questions/6977/retrive-tcp-duration-using-tshark/</guid>
      <description>Retrive tcp duration using tshark  0 I would like to know how long the TCP connection lasted using tshark, in wiresahrk this info is represented in the conversation statistics
tshark tcpasked 18 Oct &#39;11, 17:20
ddayan
41●15●17●20
accept rate: 0%
  
One Answer:
  
0If you know the TCP stream index for the connection, you can pull out the frame.time_epoch field for the first and last frames and subtract them.</description>
    </item>
    
    <item>
      <title>1.6.1 Display filter Expression Dialog Box Error and solution :-)</title>
      <link>/questions/6978/161-display-filter-expression-dialog-box-error-and-solution-/</link>
      <pubDate>Tue, 18 Oct 2011 22:09:00 +0000</pubDate>
      
      <guid>/questions/6978/161-display-filter-expression-dialog-box-error-and-solution-/</guid>
      <description>1.6.1 Display filter Expression Dialog Box Error and solution :-)  1 1Hello there,
I&#39;m glad to say that I &#39;ve come up with a small contribution to Wireshark. Display Filter dialog box is created each time whenever the Expression button in the filter tool bar is pressed. Likewise it can create n times for n clicks.
filter display-filterThis question is marked &#34;community wiki&#34;.asked 18 Oct &#39;11, 22:09
Terrestrial ...</description>
    </item>
    
    <item>
      <title>[closed] Binary packaging of wireshark in ubuntu failed</title>
      <link>/questions/6983/binary-packaging-of-wireshark-in-ubuntu-failed/</link>
      <pubDate>Wed, 19 Oct 2011 00:16:00 +0000</pubDate>
      
      <guid>/questions/6983/binary-packaging-of-wireshark-in-ubuntu-failed/</guid>
      <description>[closed] Binary packaging of wireshark in ubuntu failed  0 2make debian-package Results in errors ...
dpkg-checkbuilddeps: Unmet build dependencies: automake1.9 libc-ares-dev docbook-xsl (&amp;gt;= 1.64.1.0-0) libcap-dev bison libgnutls-dev portaudio19-dev libkrb5-dev liblua5.1-0-dev libsmi2-dev dpkg-buildpackage: warning: Build dependencies/conflicts unsatisfied; aborting. dpkg-buildpackage: warning: (Use -d flag to override.) make: *** [debian-package] Error 3
packagingasked 19 Oct &#39;11, 00:16
flashkicker
109●13●19●19
accept rate: 41%
 closed 20 Oct &#39;11, 02:17 
 The question has been closed for the following reason &amp;ldquo;inappropriate question&amp;rdquo; by flashkicker 20 Oct &amp;lsquo;11, 02:17</description>
    </item>
    
    <item>
      <title>How can I fix this Glib-ERROR?</title>
      <link>/questions/6987/how-can-i-fix-this-glib-error/</link>
      <pubDate>Wed, 19 Oct 2011 09:04:00 +0000</pubDate>
      
      <guid>/questions/6987/how-can-i-fix-this-glib-error/</guid>
      <description>How can I fix this Glib-ERROR?  0 Using an unmodified verion of wireshark 1.4.9 that I build from source I am getting the following error when I attempt to load a capture file with a proprietary protocol:
Glib-ERROR **:gmem.c:176: failed to allocate 2516584916 bytes aborting
After this I get a MSVC error and wireshark closes.
I get the same error when I run the same version of wireshark with a custom plug-in to decode the proprietary protocol.</description>
    </item>
    
    <item>
      <title>Can I rename a port?</title>
      <link>/questions/6988/can-i-rename-a-port/</link>
      <pubDate>Wed, 19 Oct 2011 09:08:00 +0000</pubDate>
      
      <guid>/questions/6988/can-i-rename-a-port/</guid>
      <description>Can I rename a port?  0 I am using Wireshark on a private netowrk. We are using port 4000 for some connections. Is there any way I can get Wireshark NOT to ID that port as terabase?
terabase naming portsasked 19 Oct &#39;11, 09:08
tnichols
1●1●1●1
accept rate: 0% 
  
One Answer:
  
2 Yes. You can edit the &#34;services&#34; file in your Wireshark installation directory, or you could disable service Name Resolution in the View Menu completely.</description>
    </item>
    
    <item>
      <title>Command priority  level in BACNET message</title>
      <link>/questions/6993/command-priority-level-in-bacnet-message/</link>
      <pubDate>Wed, 19 Oct 2011 14:01:00 +0000</pubDate>
      
      <guid>/questions/6993/command-priority-level-in-bacnet-message/</guid>
      <description>Command priority level in BACNET message  0 Hi anyone please let me know how to check the priority level in Wireshark?
I need to check the priority level send by two devices, please suggest me the filter and let me know where I can find the priority level in the message?
bacnetThis question is marked &#34;community wiki&#34;.asked 19 Oct &#39;11, 14:01
Ravi S
1●2●2●2
accept rate: 0%
 edited 20 Oct &#39;11, 07:30</description>
    </item>
    
    <item>
      <title>Find Source of Spam Email</title>
      <link>/questions/6994/find-source-of-spam-email/</link>
      <pubDate>Wed, 19 Oct 2011 14:16:00 +0000</pubDate>
      
      <guid>/questions/6994/find-source-of-spam-email/</guid>
      <description>Find Source of Spam Email  0 Our ISP informed us that there is a lot of spam coming from our IP address. I am trying to use WireShark to figure out which PC it is. I did quite a big of searching and the advice is to put set the Capture Filter to port 25. So I deleted all the default filters and added a new one with filter name = Email(Port 25) and Filter String port 25.</description>
    </item>
    
    <item>
      <title>Can we use No in the filter expression?</title>
      <link>/questions/7000/can-we-use-no-in-the-filter-expression/</link>
      <pubDate>Wed, 19 Oct 2011 22:08:00 +0000</pubDate>
      
      <guid>/questions/7000/can-we-use-no-in-the-filter-expression/</guid>
      <description>Can we use No in the filter expression?  0 Hi,
Can&#39;t we use No(default Number columnn in the capturing window) as a filter(for ex: No &amp;gt;25)? A Custom protocol has a Sequence Number field.This is also added as a column in the capturing window. My Requirement is: I should apply No==25(example) first and then take the Sequence Number from that row. If its not possible this way, please let me know all the other ways to obtain the Sequence Number value from a particular row.</description>
    </item>
    
    <item>
      <title>bandwidth usage</title>
      <link>/questions/7008/bandwidth-usage/</link>
      <pubDate>Thu, 20 Oct 2011 06:50:00 +0000</pubDate>
      
      <guid>/questions/7008/bandwidth-usage/</guid>
      <description>bandwidth usage  0 can wireshark be used to measure bandwidth usage?
bandwidthutilizationasked 20 Oct &#39;11, 06:50
dimmerrm
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Wireshark is intended for detailed packet dissection. Of course it can give statistics, but it&#39;s not really tailored for it. Better go with native solutions, like netflow statistics from your network equipment, Pilot, ntop. It depends a bit on the context in which you need to monitor.</description>
    </item>
    
    <item>
      <title>Help analyzing connection timeout</title>
      <link>/questions/7014/help-analyzing-connection-timeout/</link>
      <pubDate>Thu, 20 Oct 2011 16:31:00 +0000</pubDate>
      
      <guid>/questions/7014/help-analyzing-connection-timeout/</guid>
      <description>Help analyzing connection timeout  0 Hello,
I have been having issues with long-running ssh connections dropping. I want to blame our firewall, but I see no evidence of it timing out states (normally I&#39;d see packets associated with a session that timed out being blocked). To help figure this out, I started an session from one host to another after starting a tcpdump trace on both hosts.
Looking at the captures side-by-side in wireshark, I&#39;m a bit perplexed.</description>
    </item>
    
    <item>
      <title>wireshark not working on Mac OS snow leopard</title>
      <link>/questions/7015/wireshark-not-working-on-mac-os-snow-leopard/</link>
      <pubDate>Thu, 20 Oct 2011 17:52:00 +0000</pubDate>
      
      <guid>/questions/7015/wireshark-not-working-on-mac-os-snow-leopard/</guid>
      <description>wireshark not working on Mac OS snow leopard  0 Hi When I try to open wireshark, I am getting error as shown below.
[Start]
$ sudo wireshark Password: 2011-10-20 17:42:15.677 defaults[3179:903] The domain/default pair of (kCFPreferencesAnyApplication, AppleAquaColorVariant) does not exist 2011-10-20 17:42:15.707 defaults[3180:903] The domain/default pair of (kCFPreferencesAnyApplication, AppleHighlightColor) does not exist dyld: Library not loaded: /usr/X11/lib/libpixman-1.0.dylib Referenced from: /Applications/Wireshark.app/Contents/Resources/bin/wireshark-bin Reason: image not found Trace/BPT trap
[/End]
FYI.. I have XQuartz 2.</description>
    </item>
    
    <item>
      <title>My Laptop interface connected into Cisco 3550 switch is seeing lots of other Source IP&amp;#x27;s</title>
      <link>/questions/7019/my-laptop-interface-connected-into-cisco-3550-switch-is-seeing-lots-of-other-source-ips/</link>
      <pubDate>Fri, 21 Oct 2011 05:36:00 +0000</pubDate>
      
      <guid>/questions/7019/my-laptop-interface-connected-into-cisco-3550-switch-is-seeing-lots-of-other-source-ips/</guid>
      <description>My Laptop interface connected into Cisco 3550 switch is seeing lots of other Source IP&amp;rsquo;s  0 I ran a 2 minute capture and I see many other IP&#39;s TCP traffic (source &amp;amp; destination). My understanding is I should only see my own laptops IP traffic and maybe broadcast traffic. We have 12 switches all plugged into a Cisco 6506 backbone. When I plug directly into other switches I also see other IP&#39;s TCP traffic.</description>
    </item>
    
    <item>
      <title>DHCP offer, reject etc</title>
      <link>/questions/7021/dhcp-offer-reject-etc/</link>
      <pubDate>Fri, 21 Oct 2011 06:18:00 +0000</pubDate>
      
      <guid>/questions/7021/dhcp-offer-reject-etc/</guid>
      <description>DHCP offer, reject etc  0 Hi not sure for the life of me what I&#39;ve done as this was working, basically when entering &#34;bootp&#34; filter to capture DHCP data I get nothing, the data is shown as ARP as opposed to offer, ACK etc and I believe this is why it&#39;s not being shown with a bootp filter, if I run a trace from another PC this is shown correctly as offer, ACK etc.</description>
    </item>
    
    <item>
      <title>pdml files are very large ...</title>
      <link>/questions/7022/pdml-files-are-very-large/</link>
      <pubDate>Fri, 21 Oct 2011 06:26:00 +0000</pubDate>
      
      <guid>/questions/7022/pdml-files-are-very-large/</guid>
      <description>pdml files are very large &amp;hellip;  0 Could wireshark use the import facility of XML or some king of entity relationship so that pdml files do not become unordinately big? ~ I think tcpflow works that way. It only keeps active open connections and close the file with the particular data once the connection is closed. ~ Thank you lbrtchx
pdml file sizeasked 21 Oct &#39;11, 06:26
Albretch Mue...</description>
    </item>
    
    <item>
      <title>cdp packets don&amp;#x27;t show up on laptop</title>
      <link>/questions/7023/cdp-packets-dont-show-up-on-laptop/</link>
      <pubDate>Fri, 21 Oct 2011 06:55:00 +0000</pubDate>
      
      <guid>/questions/7023/cdp-packets-dont-show-up-on-laptop/</guid>
      <description>cdp packets don&amp;rsquo;t show up on laptop  0 Hi
I&#39;m trying to capture cdp and lldp packets from my cisco 2960 switch. This works just fine on a desktop computer but if i try to do the same thing on my laptop wireshark never gets the cdp packets at all.
and i know it is being transmitted by the switch since my desktop works fine in the same network port and is able to display the cdp packets.</description>
    </item>
    
    <item>
      <title>Point Code in decimal in display column</title>
      <link>/questions/7036/point-code-in-decimal-in-display-column/</link>
      <pubDate>Fri, 21 Oct 2011 14:55:00 +0000</pubDate>
      
      <guid>/questions/7036/point-code-in-decimal-in-display-column/</guid>
      <description>Point Code in decimal in display column  0 I cannot remember the settings change(s) that allows you to view Point Codes in the Source and Destinations columns as decimal point codes and not as hex. This setting also allows you to view the point codes embedded in SCCP as decimal and has the hex in parenthesis next to the decimal notation. Trying to pass this info on to a co-worker and I can&#39;t find the setting!</description>
    </item>
    
    <item>
      <title>How to measure packet loss, delay and throughput for VoIP, Video and Data packets over a LAN?</title>
      <link>/questions/7038/how-to-measure-packet-loss-delay-and-throughput-for-voip-video-and-data-packets-over-a-lan/</link>
      <pubDate>Sat, 22 Oct 2011 00:10:00 +0000</pubDate>
      
      <guid>/questions/7038/how-to-measure-packet-loss-delay-and-throughput-for-voip-video-and-data-packets-over-a-lan/</guid>
      <description>How to measure packet loss, delay and throughput for VoIP, Video and Data packets over a LAN?  0 hii can any1 help me with finding throughput, delay and packet loss in a LAN for voip, video and data packets transmitted over the network..its for my dissertation and i dont hv much time left..so damn tensed here! the LAN setup is this: 3 wired connections and 1 one wireless connection. one of the wired systems act as the server (just where the video files are hosted, and where the PBX server (3CX Phone system) for VoIP is installed).</description>
    </item>
    
    <item>
      <title>BER: Dissector for OID:1.2.826.0.1249.58.1.0 not implemented. Contact Wireshark developers if you want this supported</title>
      <link>/questions/7039/ber-dissector-for-oid12826012495810-not-implemented-contact-wireshark-developers-if-you-want-this-supported/</link>
      <pubDate>Sat, 22 Oct 2011 05:54:00 +0000</pubDate>
      
      <guid>/questions/7039/ber-dissector-for-oid12826012495810-not-implemented-contact-wireshark-developers-if-you-want-this-supported/</guid>
      <description>BER: Dissector for OID:1.2.826.0.1249.58.1.0 not implemented. Contact Wireshark developers if you want this supported  0 How Can i solve it?
not implementasked 22 Oct &#39;11, 05:54
JasonOliveira
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Contact the Wireshark developers, give them whatever information you have about that OID - the oid-info repository doesn&#39;t have information about it, and I&#39;m not sure why an Ericsson OID would be under &#34;</description>
    </item>
    
    <item>
      <title>How to monitor what websites are visited</title>
      <link>/questions/7040/how-to-monitor-what-websites-are-visited/</link>
      <pubDate>Sat, 22 Oct 2011 06:40:00 +0000</pubDate>
      
      <guid>/questions/7040/how-to-monitor-what-websites-are-visited/</guid>
      <description>How to monitor what websites are visited  1 Hi, I have a Laptop with wireless connection (windows), Im trying to simply monitor what websites the 2 other users (my kids) are accessing. One of the computers is connected via Ethernet Cable (windows), and the other is connected wireless (and is a Mac)
How do i get to the point where i see a list of websites (ex. http://www.google.com/) the users are accessing?</description>
    </item>
    
    <item>
      <title>Is there any way to find the tcp stream number based on packet number?</title>
      <link>/questions/7043/is-there-any-way-to-find-the-tcp-stream-number-based-on-packet-number/</link>
      <pubDate>Sat, 22 Oct 2011 19:33:00 +0000</pubDate>
      
      <guid>/questions/7043/is-there-any-way-to-find-the-tcp-stream-number-based-on-packet-number/</guid>
      <description>Is there any way to find the tcp stream number based on packet number?  0 Hi, I am wondering if i can follow the tcp stream when i have the packet number in tshark? For example, I　only know packet 10 is a HTTP packet, and I want to follow the tcp stream of packet 10. Is there any way to do that?
packet tcp tshark streamasked 22 Oct &#39;11, 19:33</description>
    </item>
    
    <item>
      <title>If a struct data is sent across the network how to dissect the contents as a protocol?</title>
      <link>/questions/7046/if-a-struct-data-is-sent-across-the-network-how-to-dissect-the-contents-as-a-protocol/</link>
      <pubDate>Sun, 23 Oct 2011 11:24:00 +0000</pubDate>
      
      <guid>/questions/7046/if-a-struct-data-is-sent-across-the-network-how-to-dissect-the-contents-as-a-protocol/</guid>
      <description>If a struct data is sent across the network how to dissect the contents as a protocol?  0 If I send a structure data across then network, then can you tell me the best method to dissect the individual data? Network byte ordering is a problem. And why is the tcpdump program skipping some packets sometimes? I&#39;ll be very thankful if you provide me a solution to the deadlock I&#39;m facing.</description>
    </item>
    
    <item>
      <title>Problem in decrypting SSL - Wireshark 1.6.2</title>
      <link>/questions/7049/problem-in-decrypting-ssl-wireshark-162/</link>
      <pubDate>Sun, 23 Oct 2011 21:35:00 +0000</pubDate>
      
      <guid>/questions/7049/problem-in-decrypting-ssl-wireshark-162/</guid>
      <description>Problem in decrypting SSL - Wireshark 1.6.2  0 I am using the current newest version of Wireshark, 1.6.2. I wanted to decrypt an SSL connection. I entered the IP address, port, protocol and .key file in Preferences -&amp;gt; SSL correctly, but the packets are still not decrypted. I am using an Apache webserver, so the keys are all in .pem format. I also tried converting the key and certificate to .</description>
    </item>
    
    <item>
      <title>Point Code Conversion</title>
      <link>/questions/7053/point-code-conversion/</link>
      <pubDate>Mon, 24 Oct 2011 11:37:00 +0000</pubDate>
      
      <guid>/questions/7053/point-code-conversion/</guid>
      <description>Point Code Conversion  0 14041651 decimal converted to hex is D64233, D64233 converted to 2 digits D6 42 33, D6 42 33 converted back to decimal 214-66-51, How can wireshark be set up to perform the conversion automatically?
sccpmg ss7 sctpasked 24 Oct &#39;11, 11:37
SoccerNumber6
1●1●1●1
accept rate: 0%
  
One Answer:
  
1 Edit-&amp;gt;preferences-&amp;gt;protocols-&amp;gt;MTP3-&amp;gt;ITU Pointcode structure And Address format
answered 25 Oct &#39;11, 11:56</description>
    </item>
    
    <item>
      <title>How does save as work in wireshark ??</title>
      <link>/questions/7057/how-does-save-as-work-in-wireshark/</link>
      <pubDate>Mon, 24 Oct 2011 22:53:00 +0000</pubDate>
      
      <guid>/questions/7057/how-does-save-as-work-in-wireshark/</guid>
      <description>How does save as work in wireshark ??  0 I would like to know how wireshark can save the capture in different formats
saveasked 24 Oct &#39;11, 22:53
flashkicker
109●13●19●19
accept rate: 41%
1How to set a different format as the default one? I mean where can i Hardcode this?
(28 Oct &#39;11, 03:19) Sriramula Ra...  
One Answer:
  
1 Do you want to know how it works internally, or how you use it at all?</description>
    </item>
    
    <item>
      <title>FTP_DL control port not opened properly</title>
      <link>/questions/7059/ftp_dl-control-port-not-opened-properly/</link>
      <pubDate>Tue, 25 Oct 2011 02:22:00 +0000</pubDate>
      
      <guid>/questions/7059/ftp_dl-control-port-not-opened-properly/</guid>
      <description>FTP_DL control port not opened properly  0 My FTP client sends Request:RETR and receives Response: 150 Opening BINARY mode ... but behaves as if it had not received it and retransmits Request RETR. Why is this so?
In successful FTP sessions, the packet that contains Response acknowledges the Request.
Greets,
fctpasked 25 Oct &#39;11, 02:22
brklp
1●4●4●4
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Using Dissectors and Subdissectors</title>
      <link>/questions/7060/using-dissectors-and-subdissectors/</link>
      <pubDate>Tue, 25 Oct 2011 07:57:00 +0000</pubDate>
      
      <guid>/questions/7060/using-dissectors-and-subdissectors/</guid>
      <description>Using Dissectors and Subdissectors  0 Hi all,
I have to write a Protcol-Analyzer, basing on TCP. The first Level is a company-specific Protocol which encapsulates several other company-specific protocols.
The first Level I have already implemented and it works. That means. The Data from TCP (lets call it Proto_One) I can analyze and make them viewable in the Tree. But next Step is to make the Data from (lets call it Proto_Two and Proto_Three) available for next dissector.</description>
    </item>
    
    <item>
      <title>RDP of a RDP</title>
      <link>/questions/7061/rdp-of-a-rdp/</link>
      <pubDate>Tue, 25 Oct 2011 08:34:00 +0000</pubDate>
      
      <guid>/questions/7061/rdp-of-a-rdp/</guid>
      <description>RDP of a RDP  0 Hi Folks.....
and thanks for reading my question. First some background:
I have a situation where I have a user in India using RDP to connect to a virtual desktop (VDI on VMWare View) in a data center in the U.S. This works OK. The user then starts a remote control session from the VDI to remote control (via RDP) a Sharepoint server in that same data center.</description>
    </item>
    
    <item>
      <title>capture filter: arp or port 5246, in Promiscuous mode</title>
      <link>/questions/7062/capture-filter-arp-or-port-5246-in-promiscuous-mode/</link>
      <pubDate>Tue, 25 Oct 2011 08:42:00 +0000</pubDate>
      
      <guid>/questions/7062/capture-filter-arp-or-port-5246-in-promiscuous-mode/</guid>
      <description>capture filter: arp or port 5246, in Promiscuous mode  0 I use wireshark 1.6.2 version. i switch Mirror port capature packet. I find capature fileter: arp . But no packet, in Promiscuoous mode.This is a error!
Wireshark: Summary Time First packet: 1970-01-01 08:00:00 Last packet: 1970-01-01 08:00:00 Elapse: 00:00:00
Capture capture filter: arp
Traffice packets: 0
arp capture filterasked 25 Oct &#39;11, 08:42
zhoutree
1●1●1●1
accept rate: 0%
 edited 25 Oct &#39;11, 09:44</description>
    </item>
    
    <item>
      <title>What are the causes of slow response between two host?</title>
      <link>/questions/7068/what-are-the-causes-of-slow-response-between-two-host/</link>
      <pubDate>Tue, 25 Oct 2011 11:01:00 +0000</pubDate>
      
      <guid>/questions/7068/what-are-the-causes-of-slow-response-between-two-host/</guid>
      <description>What are the causes of slow response between two host?  0 We are using the SAS progaram to run through a drive that is in the data center and the user are experiencing real slowness on a gig link running wireshark I saw a lots of [TCP segment of Reassembled PDU] between two host and the program runs so slow.
10.119.xx.yy 10.120.xx.yy TCP 1514 [TCP segment of a reassembled PDU] 10.</description>
    </item>
    
    <item>
      <title>wireshark 1.6.2 win64 sees only Ethernet NIC</title>
      <link>/questions/7070/wireshark-162-win64-sees-only-ethernet-nic/</link>
      <pubDate>Tue, 25 Oct 2011 12:48:00 +0000</pubDate>
      
      <guid>/questions/7070/wireshark-162-win64-sees-only-ethernet-nic/</guid>
      <description>wireshark 1.6.2 win64 sees only Ethernet NIC  0 I have D-Link DWA-120 USB WiFi card and PPTP VPN connection on my PC. They both look like NICs in Windows, but Wireshark sees only &#34;wired&#34; NIC as capture device. Why?
pptp vpn wifiasked 25 Oct &#39;11, 12:48
ZZWave
1●1●1●1
accept rate: 0%
where do you take the information that wireshark sees &#34;wired&#34; NICs from ? Did you check Capture Interface Details ?</description>
    </item>
    
    <item>
      <title>Column with arbitrary located byte in a packet</title>
      <link>/questions/7081/column-with-arbitrary-located-byte-in-a-packet/</link>
      <pubDate>Wed, 26 Oct 2011 07:18:00 +0000</pubDate>
      
      <guid>/questions/7081/column-with-arbitrary-located-byte-in-a-packet/</guid>
      <description>Column with arbitrary located byte in a packet  1 1How it is possible to create a &#34;Custom&#34; column which refers to an arbitrary offset in UDP payload. For example, in &#34;Filter definition&#34; it is possible to reffer to the 1st byte in UDP payload as udp[8]. Such simple approach seems to be blocked in Packet Display Plain. What am I missing?
column offsetasked 26 Oct &#39;11, 07:18
exbungee
16●2●3●4</description>
    </item>
    
    <item>
      <title>What does the 8 stand for in (tcp.stream eq 8)?</title>
      <link>/questions/7082/what-does-the-8-stand-for-in-tcpstream-eq-8/</link>
      <pubDate>Wed, 26 Oct 2011 07:42:00 +0000</pubDate>
      
      <guid>/questions/7082/what-does-the-8-stand-for-in-tcpstream-eq-8/</guid>
      <description>What does the 8 stand for in (tcp.stream eq 8)?  0 I just can&#39;t figure out what the 8 stands for in (tcp.stream eq 8)?
filter ip udp stream tcpasked 26 Oct &#39;11, 07:42
0xffff0
6●1●1●3
accept rate: 0%
  
One Answer:
  
2 It indicates that this is the 8th TCP or UDP stream found in the trace.
Before we had stream numbers a filter to identify the stream would specify a pair of IP addresses and port numbers, resulting in much longer display filters.</description>
    </item>
    
    <item>
      <title>Command line capture filter syntax</title>
      <link>/questions/7083/command-line-capture-filter-syntax/</link>
      <pubDate>Wed, 26 Oct 2011 08:33:00 +0000</pubDate>
      
      <guid>/questions/7083/command-line-capture-filter-syntax/</guid>
      <description>Command line capture filter syntax  0 I want to start wireshark from the command line using a capture filter so that when wireshark starts it begins capturing immediately and is only capturing packets that I am interested in. I thought the -f would be the ticket but I am not sure what is going on here? It seems to be thinking that -f is a capture file? Thanks
C:\Program Files\Wireshark&amp;gt;wireshark -i 2 -k -f tcp port==443 C:\Program Files\Wireshark&amp;gt;</description>
    </item>
    
    <item>
      <title>Any ETA on the Mac builds to use a newer GTK&#43;?</title>
      <link>/questions/7087/any-eta-on-the-mac-builds-to-use-a-newer-gtk/</link>
      <pubDate>Wed, 26 Oct 2011 12:29:00 +0000</pubDate>
      
      <guid>/questions/7087/any-eta-on-the-mac-builds-to-use-a-newer-gtk/</guid>
      <description>Any ETA on the Mac builds to use a newer GTK+?  0 For us spending a lot of time in Wireshark on Lion, the lines disappearing is a huge pain. Thanks!
osxasked 26 Oct &#39;11, 12:29
administraitor
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Fog Server slow to respond during peak office hours.</title>
      <link>/questions/7088/fog-server-slow-to-respond-during-peak-office-hours/</link>
      <pubDate>Wed, 26 Oct 2011 12:46:00 +0000</pubDate>
      
      <guid>/questions/7088/fog-server-slow-to-respond-during-peak-office-hours/</guid>
      <description>Fog Server slow to respond during peak office hours.  0 We are running an internal Fog server with address 10.X.X.X and when we try logging into it between the hours of 8am-4pm, we are seeing sluggish response times. Ran wireshark and saw lots of SYN/ACK packets and at one point I see an RST packet then a RETRANSMISSION. I don&#39;t even know where to start to look. The reset packet, as well as all the others say Header Checksum: 0x0000 incorrect, should be.</description>
    </item>
    
    <item>
      <title>[closed] Why gtk/gtk.h cannot be included into any header file?</title>
      <link>/questions/7089/why-gtkgtkh-cannot-be-included-into-any-header-file/</link>
      <pubDate>Thu, 27 Oct 2011 01:02:00 +0000</pubDate>
      
      <guid>/questions/7089/why-gtkgtkh-cannot-be-included-into-any-header-file/</guid>
      <description>[closed] Why gtk/gtk.h cannot be included into any header file?  0 Hello,
I have tried to include gtk/gtk.h into main_filter_toolbar.h but this is resulting in an error saying Cannot include file gtk/gtk.h. No such file or directory. How can i solve this problem?
gtkThis question is marked &#34;community wiki&#34;.asked 27 Oct &#39;11, 01:02
Terrestrial ...
96●21●28●29
accept rate: 42%
 closed 30 Oct &#39;11, 23:22 
Could you compile Wireshark source before you made any changes to it?</description>
    </item>
    
    <item>
      <title>How do i watch resolved and unresolved MAC simultaneously?</title>
      <link>/questions/7091/how-do-i-watch-resolved-and-unresolved-mac-simultaneously/</link>
      <pubDate>Thu, 27 Oct 2011 02:02:00 +0000</pubDate>
      
      <guid>/questions/7091/how-do-i-watch-resolved-and-unresolved-mac-simultaneously/</guid>
      <description>How do i watch resolved and unresolved MAC simultaneously?  0 how do i watch resolved and unresolved MAC simultaneously? all columns i add are either resolved or unresolved...
mac resolve ouiasked 27 Oct &#39;11, 02:02
Daniil Kharkov
1●1●1●1
accept rate: 0%
  
One Answer:
  
1If you mean &#34;how can I see both the resolved and unresolved MAC in the same column?&#34;, the answer is &#34;</description>
    </item>
    
    <item>
      <title>Mysterious DNS query to sites?</title>
      <link>/questions/7098/mysterious-dns-query-to-sites/</link>
      <pubDate>Thu, 27 Oct 2011 08:22:00 +0000</pubDate>
      
      <guid>/questions/7098/mysterious-dns-query-to-sites/</guid>
      <description>Mysterious DNS query to sites?  0 I&#39;m not sure whats going on, I was just using wireshark on my home network and I know everyones assigned local IP Address. I just wanted to see what sites everyone on my network was on, so I applied a DNS filter, and notice that My IP(192.168.1.100) was pulling in all this responses from sites I don&#39;t even get on. For an example: www.</description>
    </item>
    
    <item>
      <title>Response time testing with wireshark by using transaction&amp;#x27;s  --is it possible ?</title>
      <link>/questions/7107/response-time-testing-with-wireshark-by-using-transactions-is-it-possible/</link>
      <pubDate>Thu, 27 Oct 2011 09:14:00 +0000</pubDate>
      
      <guid>/questions/7107/response-time-testing-with-wireshark-by-using-transactions-is-it-possible/</guid>
      <description>Response time testing with wireshark by using transaction&amp;rsquo;s &amp;ndash;is it possible ?  0 Hi I am going to work on wireshark . I have some quiries here to ask .
I am working on migration project but client d&#39;nt want to use loadrunner before migrating and after migrating for response time i mean they want to know latency between pre migration and after migration . Can we know response time for 3 0r 4 existing trxn&#39;s with wireshark ?</description>
    </item>
    
    <item>
      <title>Wireshark on OS X Lion, not working</title>
      <link>/questions/7113/wireshark-on-os-x-lion-not-working/</link>
      <pubDate>Thu, 27 Oct 2011 16:39:00 +0000</pubDate>
      
      <guid>/questions/7113/wireshark-on-os-x-lion-not-working/</guid>
      <description>Wireshark on OS X Lion, not working  0 I have OS X Lion, up-to-date with patches, on a 32-bit Mac Pro. It installs fine, but does not launch.
Does anyone know what the problem is?
Thanks.
osx lion 32-bit installasked 27 Oct &#39;11, 16:39
forrie
0●1●1●1
accept rate: 0%
 edited 28 Feb &#39;12, 20:03 
cmaynard ♦♦
9.4k●10●38●142
ask.wireshark.org is not a traditional forum or chat. Please refrain from asking the same question multiple times (see http://ask.</description>
    </item>
    
    <item>
      <title>problem with network name resolution</title>
      <link>/questions/7114/problem-with-network-name-resolution/</link>
      <pubDate>Thu, 27 Oct 2011 16:40:00 +0000</pubDate>
      
      <guid>/questions/7114/problem-with-network-name-resolution/</guid>
      <description>problem with network name resolution  0 I&#39;m running wireshark 1.6.2. I have a main site with a network of 10.0.0.x and a sattelite office with a network of 192.168.17.x the machines on the 192.168.17.x network use a dns server on the 10.0.0.x network. from a machine on the 10.0.0.x network if I ping sat1 it correctly resolves and pings the machine at the remote office. If I look at the DNS server I see host records for the machines in the 192.</description>
    </item>
    
    <item>
      <title>Linker error</title>
      <link>/questions/7124/linker-error/</link>
      <pubDate>Thu, 27 Oct 2011 21:52:00 +0000</pubDate>
      
      <guid>/questions/7124/linker-error/</guid>
      <description>Linker error  0 Hello,
I have a function called catch_first_filtered_pkt() inside main_filter_toolbar.c. This should be called from inside wireshark/epan/dfilter/dfvm.c &#39;s any_test(dfilter_t *df, FvalueCmpFunc cmp, int reg1, int reg2) function block. I&#39;ve encountered a Linker error LINK2019:unresolved external symbol _catch_first_filtered_pkt inside dfilter.lib. How can i solve this error? Please Help.
gtk linker dfilter errorThis question is marked &#34;community wiki&#34;.asked 27 Oct &#39;11, 21:52
Terrestrial ...
96●21●28●29
accept rate: 42%
Creating library libwireshark.</description>
    </item>
    
    <item>
      <title>Capture from custom libpcap-based sniffer not honoring all display filters</title>
      <link>/questions/7139/capture-from-custom-libpcap-based-sniffer-not-honoring-all-display-filters/</link>
      <pubDate>Fri, 28 Oct 2011 11:36:00 +0000</pubDate>
      
      <guid>/questions/7139/capture-from-custom-libpcap-based-sniffer-not-honoring-all-display-filters/</guid>
      <description>Capture from custom libpcap-based sniffer not honoring all display filters  0 I &#34;inherited&#34; a custom sniffer program that is capturing traffic using libpcap.
When I try to use display filters such as &#34;http.request&#34; and &#34;http.response&#34;, no traffic is displayed in Wireshark. However, when I just use &#34;http&#34;, I see all of the packets I would expect.
Can anyone give me some hints as to what I should be looking at more closely at this custom code that would affect the ability to use these filters?</description>
    </item>
    
    <item>
      <title>error LNK2019</title>
      <link>/questions/7142/error-lnk2019/</link>
      <pubDate>Fri, 28 Oct 2011 17:53:00 +0000</pubDate>
      
      <guid>/questions/7142/error-lnk2019/</guid>
      <description>error LNK2019  0 hello guys,
I just add a sub-menu in menu &#39;statistics&#39;, and I created a new file named &#39;vss_dlg.c&#39; and then copy some code from &#39;summary_dlg.c&#39; and filled into the &#39;vss_dlg.c&#39;, some related code also modified, but still some ERROR founded as below:
libui.lib(vss_dlg.obj) : error LNK2019: unresolved external symbol _vss_fill_in_capture referenced in function _vss_open_cb
libui.lib(vss_dlg.obj) : error LNK2019: unresolved external symbol _vss_fill_in referenced in function _vss_open_cb</description>
    </item>
    
    <item>
      <title>rtsp...sdp, question concerning streaming radio</title>
      <link>/questions/7144/rtspsdp-question-concerning-streaming-radio/</link>
      <pubDate>Sat, 29 Oct 2011 08:57:00 +0000</pubDate>
      
      <guid>/questions/7144/rtspsdp-question-concerning-streaming-radio/</guid>
      <description>rtsp&amp;hellip;sdp, question concerning streaming radio  0 My phone (Samsung Solstice II) can only stream music from the internet that is in the following format rtsp://64.202.98.91:554/gs64.sdp (this is Soma Groove Salad). I have used Wireshark to track down the address of different internet radio stations, but I can&#39;t figure what to put in for the object (like the &#34;gs64&#34; for groove salad). Do all radio stations broadcast in this manner, and it&#39;s just up to me to figure it out?</description>
    </item>
    
    <item>
      <title>dif between captured and displayed seconds</title>
      <link>/questions/7150/dif-between-captured-and-displayed-seconds/</link>
      <pubDate>Sat, 29 Oct 2011 19:53:00 +0000</pubDate>
      
      <guid>/questions/7150/dif-between-captured-and-displayed-seconds/</guid>
      <description>dif between captured and displayed seconds  0 Hi, Does anyone know the difference between &#34;Seconds since previous captured packet&#34; &#34;Seconds since previous displayed packet&#34; for the time setting view
John
seconds timesasked 29 Oct &#39;11, 19:53
desert1940fox
1●2●2●2
accept rate: 0%
  
One Answer:
  
3 If you have a display filter, so that not all of the packets in the capture are displayed, &#34;seconds since previous captured packet&#34;</description>
    </item>
    
    <item>
      <title>Wireshark wifi http packages not showing</title>
      <link>/questions/7155/wireshark-wifi-http-packages-not-showing/</link>
      <pubDate>Sun, 30 Oct 2011 05:38:00 +0000</pubDate>
      
      <guid>/questions/7155/wireshark-wifi-http-packages-not-showing/</guid>
      <description>Wireshark wifi http packages not showing  0 Hey guys.
So I have for some time tried to get this working, and I feel like im close but just not there yet. I&#39;m using a broadcom wifi card... When I activate airmon-ng it creates a device called mon0.
If I listen on the traffic using the wan0 (normal wifi) I get only very few packages and only http when I use the machine that is listening to browse some site.</description>
    </item>
    
    <item>
      <title>Encrypted POST data not decrypted</title>
      <link>/questions/7159/encrypted-post-data-not-decrypted/</link>
      <pubDate>Sun, 30 Oct 2011 06:19:00 +0000</pubDate>
      
      <guid>/questions/7159/encrypted-post-data-not-decrypted/</guid>
      <description>Encrypted POST data not decrypted  0 To demonstrate SSL decryption, I created a dummy website running on a local webserver which prompts the user to login using HTTPS. I analyzed the traffic using WireShark and have successfully decrypted the SSL traffic. The cipher used is TLS_RSA_WITH_AES_256_CBC_SHA. However, the POST data (Line-based text data: application/x-www-form-urlencoded) containing the username and password remains encrypted. Any suggestions how to decrypt this data?
decryption post decrypt sslasked 30 Oct &#39;11, 06:19</description>
    </item>
    
    <item>
      <title>Cannot capture packet transfer between other PCs</title>
      <link>/questions/7165/cannot-capture-packet-transfer-between-other-pcs/</link>
      <pubDate>Sun, 30 Oct 2011 19:05:00 +0000</pubDate>
      
      <guid>/questions/7165/cannot-capture-packet-transfer-between-other-pcs/</guid>
      <description>Cannot capture packet transfer between other PCs  0 HI I have installed wireshark in a PC (lets say PC-A). PC-A, PC-B and PC-C are all connected through an ethernet switch. When i run wireshark, it shows capture of packets from/to PC-A only. it does not capture interactions between PC-B and PC-C. Is there any way i can capture this by wireshark? Please do help.
Bijoy
capture other interactions pcasked 30 Oct &#39;11, 19:05</description>
    </item>
    
    <item>
      <title>How to set a different capture file format as the default one?</title>
      <link>/questions/7166/how-to-set-a-different-capture-file-format-as-the-default-one/</link>
      <pubDate>Sun, 30 Oct 2011 21:59:00 +0000</pubDate>
      
      <guid>/questions/7166/how-to-set-a-different-capture-file-format-as-the-default-one/</guid>
      <description>How to set a different capture file format as the default one?  0 Hello All,
According to my group&#39;s requirements ,we need K12 txt file format for saving a file always. So may i know where i can hardcode this?
file-format saveThis question is marked &#34;community wiki&#34;.asked 30 Oct &#39;11, 21:59
Terrestrial ...
96●21●28●29
accept rate: 42%
  
One Answer:
  
0 goto wireshark\win32\file_dlg_win32.c make necessary modifications to build_file_type_list() or set appropriate filetype number to FILE_SAVE_DEFAULT macro.</description>
    </item>
    
    <item>
      <title>Can someone please have a look into my capture file?</title>
      <link>/questions/7169/can-someone-please-have-a-look-into-my-capture-file/</link>
      <pubDate>Sun, 30 Oct 2011 23:35:00 +0000</pubDate>
      
      <guid>/questions/7169/can-someone-please-have-a-look-into-my-capture-file/</guid>
      <description>Can someone please have a look into my capture file?  0 I captured some packets sent to/from two websites i&#39;m having problems with. However, unable to diagnose the problem myself so asking for help.
Can someone please diagnose the problem for me?
Thank you in advance
requested analysisasked 30 Oct &#39;11, 23:35
ulznsn
1●1●1●1
accept rate: 0%
Hi Ulznsn, you have not attached the capture file
(01 Nov &#39;11, 22:21) deepacket   </description>
    </item>
    
    <item>
      <title>Capture packet to SQL Database</title>
      <link>/questions/7174/capture-packet-to-sql-database/</link>
      <pubDate>Mon, 31 Oct 2011 09:09:00 +0000</pubDate>
      
      <guid>/questions/7174/capture-packet-to-sql-database/</guid>
      <description>Capture packet to SQL Database  0 I&#39;m using a serial to ethernet bridge (static IP) to connect a serial device to my network. I need a piece of software to grab the data from the ethernet bridge and store it in a SQL database (ideal) or a text file. The software needs to be able to run on a Win 2008 server when it is logged off. Can Wireshark do this?</description>
    </item>
    
    <item>
      <title>Where can I download Wireshark version with SSL decryption support?</title>
      <link>/questions/7175/where-can-i-download-wireshark-version-with-ssl-decryption-support/</link>
      <pubDate>Mon, 31 Oct 2011 09:34:00 +0000</pubDate>
      
      <guid>/questions/7175/where-can-i-download-wireshark-version-with-ssl-decryption-support/</guid>
      <description>Where can I download Wireshark version with SSL decryption support?  0 Hi,
Where can I download Wireshark version with SSL decryption support (gnuTLS and GCrypt) for Ubuntu or Win32?
Thanks, Andrey
wiresharkasked 31 Oct &#39;11, 09:34
vzs4xs
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Any build from the Wireshark website (Win32) or Ubuntu repository will do. Check the About Wireshark dialog for the libraries it&#39;s build with.</description>
    </item>
    
    <item>
      <title>Application RST</title>
      <link>/questions/7179/application-rst/</link>
      <pubDate>Tue, 01 Nov 2011 04:20:00 +0000</pubDate>
      
      <guid>/questions/7179/application-rst/</guid>
      <description>Application RST  0 I&#39;m a newbie to Wireshark and have a question on a Reset I&#39;m seeing in the trace with an application that&#39;s getting intermittent connection failure. There is a firewall in the path but no other applications are having issues. I did a Follow TCP stream for a known failure transaction and a good transaction. I&#39;m not sure but the failure transaction could be due to the Reset but want to confirm if it&#39;s the application that&#39;s the cause or the Firewall.</description>
    </item>
    
    <item>
      <title>Are there &amp;quot;tcp.srcport&amp;quot; or &amp;quot;tcp.dstport&amp;quot; dissector tables?</title>
      <link>/questions/7180/are-there-tcpsrcport-or-tcpdstport-dissector-tables/</link>
      <pubDate>Tue, 01 Nov 2011 07:14:00 +0000</pubDate>
      
      <guid>/questions/7180/are-there-tcpsrcport-or-tcpdstport-dissector-tables/</guid>
      <description>Are there &amp;ldquo;tcp.srcport&amp;rdquo; or &amp;ldquo;tcp.dstport&amp;rdquo; dissector tables?  1 Is it possible to get DissectorTable according to &#34;tcp.srcport&#34; or &#34;tcp.dstport&#34; in Lua? Now,I have two package, one&#39;s tcp source port is 7709, another&#39;s tcp destination port is 7709. That is ,a request and a response. The fields of request package and response package are different. So I need to register two different dissector to process the two different packaget. At the time, I do it like this: local tcp_req_table = DissectorTable.</description>
    </item>
    
    <item>
      <title>Wireshark stalls</title>
      <link>/questions/7182/wireshark-stalls/</link>
      <pubDate>Tue, 01 Nov 2011 12:29:00 +0000</pubDate>
      
      <guid>/questions/7182/wireshark-stalls/</guid>
      <description>Wireshark stalls  0 Wireshark will capture without stalling on my windows vista 32 bit OS, only once, if I install it, and directly after, when installation is finished, click the option to launch wireshark (as part of the GUI panel of the installer). Once I exit wireshark, and re enter the program, it will consistently stall, and crash, upon any attempt to capture. So if I want to use wireshark again after the first time it worked directly following installation, I am forced to uninstall, reinstall, and launch it directly from the installation panel after installation finishes, for it to only work once before I close it again.</description>
    </item>
    
    <item>
      <title>Decrypting capture with Abbreviated SSL handshake</title>
      <link>/questions/7189/decrypting-capture-with-abbreviated-ssl-handshake/</link>
      <pubDate>Tue, 01 Nov 2011 22:46:00 +0000</pubDate>
      
      <guid>/questions/7189/decrypting-capture-with-abbreviated-ssl-handshake/</guid>
      <description>Decrypting capture with Abbreviated SSL handshake  0 Hi, does anyone have any solution to decrypt captures with Abbreviated SSL handshake (RFC 2246).
What happens in a Abbreviated SSL handshake? From a previous SSL connection the client caches the session ID and resends it to the server to setup a new connection, so insted of the full SSL handshake where the keys are exchanged ,here only the session ID&#39;s are exchanged which makes it impossible to decrypt.</description>
    </item>
    
    <item>
      <title>Failed to change the width size of midde column in Graph Analysis.</title>
      <link>/questions/7191/failed-to-change-the-width-size-of-midde-column-in-graph-analysis/</link>
      <pubDate>Wed, 02 Nov 2011 00:01:00 +0000</pubDate>
      
      <guid>/questions/7191/failed-to-change-the-width-size-of-midde-column-in-graph-analysis/</guid>
      <description>Failed to change the width size of midde column in Graph Analysis.  0 Can someone tell me how I can fix it or which version will address this issue? I&#39;m now using v1.6.2.
graph analysisasked 02 Nov &#39;11, 00:01
ccie10953
1●1●1●1
accept rate: 0%
  
One Answer:
  
1By editing the code in graph_analysis.c to make it work in a nice manner :-)
answered 02 Nov &#39;11, 07:12</description>
    </item>
    
    <item>
      <title>Help to look at my reject file produced by installing wireshark under FreeBSD ports!</title>
      <link>/questions/7192/help-to-look-at-my-reject-file-produced-by-installing-wireshark-under-freebsd-ports/</link>
      <pubDate>Wed, 02 Nov 2011 00:39:00 +0000</pubDate>
      
      <guid>/questions/7192/help-to-look-at-my-reject-file-produced-by-installing-wireshark-under-freebsd-ports/</guid>
      <description>Help to look at my reject file produced by installing wireshark under FreeBSD ports!  0 I tried to install the wireshark under my FreeBSD ports, it failed and get the reject file, I want to know what the reject file mean, Does anyone of you can tell me that? Thank you!
[[email protected] /usr/ports/net/wireshark]# make install clean===&amp;gt; Found saved configuration for wireshark-0.99.7=&amp;gt; MD5 Checksum OK for wireshark-0.99.7.tar.bz2. =&amp;gt; SHA256 Checksum OK for wireshark-0.</description>
    </item>
    
    <item>
      <title>Facebook Login notifications</title>
      <link>/questions/7195/facebook-login-notifications/</link>
      <pubDate>Wed, 02 Nov 2011 05:00:00 +0000</pubDate>
      
      <guid>/questions/7195/facebook-login-notifications/</guid>
      <description>Facebook Login notifications  0 Login notifactions in ase you dont know says &#34;We can notify you when your account is accessed from a computer or mobile device that you haven&#39;t used before&#34;
I need to understand whether sniffing cookies will trigger this on a different laptop or whether i&#39;d have to do it on the sniffed laptop for it not to trigger the alert.
Thanks B
sniffing cookies facebookasked 02 Nov &#39;11, 05:00</description>
    </item>
    
    <item>
      <title>Wireshark crash with a two instance long time capture</title>
      <link>/questions/7197/wireshark-crash-with-a-two-instance-long-time-capture/</link>
      <pubDate>Wed, 02 Nov 2011 06:26:00 +0000</pubDate>
      
      <guid>/questions/7197/wireshark-crash-with-a-two-instance-long-time-capture/</guid>
      <description>Wireshark crash with a two instance long time capture  0 Hi, my wireshark crashed over night.
Short Version -&amp;gt; I had two instances of Wireshark running. For a long time capture over the weekend I configured multiple capture files (One file every 100MB). It seems like there was a memory overrun anyway. Any idea how to prevent my Shark from crashing?
Long Version -&amp;gt; I&#39;m testing a network device with different scenarios.</description>
    </item>
    
    <item>
      <title>How can I capture traffic with Wireshark?</title>
      <link>/questions/7201/how-can-i-capture-traffic-with-wireshark/</link>
      <pubDate>Wed, 02 Nov 2011 10:31:00 +0000</pubDate>
      
      <guid>/questions/7201/how-can-i-capture-traffic-with-wireshark/</guid>
      <description>How can I capture traffic with Wireshark?  0 Hi,
I am being driven round the bend by my isp as they want some results from wire shark, I know there is a problem with my line but they will not do anymore without these results. I am unable to get my network card in the drop down menu to enable me to start the capture. Any help will be much needed.</description>
    </item>
    
    <item>
      <title>wireshark capturing vlan tags on Microsoft 2008 Server Hyper-V</title>
      <link>/questions/7202/wireshark-capturing-vlan-tags-on-microsoft-2008-server-hyper-v/</link>
      <pubDate>Wed, 02 Nov 2011 10:39:00 +0000</pubDate>
      
      <guid>/questions/7202/wireshark-capturing-vlan-tags-on-microsoft-2008-server-hyper-v/</guid>
      <description>wireshark capturing vlan tags on Microsoft 2008 Server Hyper-V  0 Hello, is there any issue with wireshark working with Microsoft 2008 Server Hyper-V to capture vlan tagged frames on a VM? NIC is setup to not script vlan tags.
vlan tagsThis question is marked &#34;community wiki&#34;.asked 02 Nov &#39;11, 10:39
JeffStok1967
1●1●1●1
accept rate: 0%
Which version of Wireshark are you using?
(02 Nov &#39;11, 17:38) cmaynard ♦♦Does &#34;NIC&#34; refer to the physical NIC on the machine or to a virtual NIC?</description>
    </item>
    
    <item>
      <title>Upload &amp;amp; download</title>
      <link>/questions/7206/upload-download/</link>
      <pubDate>Wed, 02 Nov 2011 12:23:00 +0000</pubDate>
      
      <guid>/questions/7206/upload-download/</guid>
      <description>Upload &amp;amp; download  0 Hello I like to measure a download and upload in wireshark, but i&#39;m a beginner in this software. I need it to a project of the web. I&#39;l be grateful for help
and download uploadasked 02 Nov &#39;11, 12:23
Blazeyos
1●1●1●1
accept rate: 0%
1I went to the statistcs then IO Graphs, evry thing would be perfect if I it summary Graphs in the end of 8 hours</description>
    </item>
    
    <item>
      <title>Wireshark install</title>
      <link>/questions/7209/wireshark-install/</link>
      <pubDate>Wed, 02 Nov 2011 14:14:00 +0000</pubDate>
      
      <guid>/questions/7209/wireshark-install/</guid>
      <description>Wireshark install  0 Can I run wireshark without doing an install? We have some prod servers that we cannot install the program until the weekend and need to run it without an install?
Thank you, Dario
install wiresharkasked 02 Nov &#39;11, 14:14
lastcall1969
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0You can download the sources and compile Wireshark yourself, then you can run it from the build directory without doing an install.</description>
    </item>
    
    <item>
      <title>cant see 2 way for pptp</title>
      <link>/questions/7220/cant-see-2-way-for-pptp/</link>
      <pubDate>Thu, 03 Nov 2011 08:48:00 +0000</pubDate>
      
      <guid>/questions/7220/cant-see-2-way-for-pptp/</guid>
      <description>cant see 2 way for pptp  0 Hi, I am trying to measure pptp encrypted vpn traffic from my computer with wireshark. However, when I run it, I only see packets headed from one ip address to another ip address.
There is no 2 directional flows that I see. It seems to only flow from my computer to the server.
pptpasked 03 Nov &#39;11, 08:48
desert1940fox
1●2●2●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How can I examine the actual value of a proto_item?</title>
      <link>/questions/7225/how-can-i-examine-the-actual-value-of-a-proto_item/</link>
      <pubDate>Thu, 03 Nov 2011 15:57:00 +0000</pubDate>
      
      <guid>/questions/7225/how-can-i-examine-the-actual-value-of-a-proto_item/</guid>
      <description>How can I examine the actual value of a proto_item?  1 How can I examine the actual value of a proto_item in my dissector? I thought something like this would work:
... {&amp;amp;hf_pfield, {&amp;quot;ProtoField&amp;quot;, &amp;quot;proto.field&amp;quot;, FT_UINT32, BASE_HEX, VALS(ProtoFieldValueString), ProtoFieldBitmask, &amp;quot;Proto Field&amp;quot;, HFILL}} ... void dissect_proto(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree) { proto_item *p_item = NULL; guint32 guint32_value = 0; ... if(tree) { p_item = ptvcursor_add(cursor, hf_pfield, 4, endianness); guint32_value = fvalue_get_uinteger(&amp;amp;(item-&amp;gt;finfo-&amp;gt;value)); /*Crash*/ .</description>
    </item>
    
    <item>
      <title>wireless set up to view own traffic</title>
      <link>/questions/7226/wireless-set-up-to-view-own-traffic/</link>
      <pubDate>Thu, 03 Nov 2011 17:09:00 +0000</pubDate>
      
      <guid>/questions/7226/wireless-set-up-to-view-own-traffic/</guid>
      <description>wireless set up to view own traffic  0 have a airpcap on windows vista laptop, trying to set up veiwing my own traffic... on preferences, have tried to set up wpa key...my password is superbowl....my ssid id is lucky labidos...could someone give me the exact directions...as in spell that out how that should be written...i can see the ssid on channel 2...not the only one on there...but seems like its .</description>
    </item>
    
    <item>
      <title>Video File Information Command Line</title>
      <link>/questions/7233/video-file-information-command-line/</link>
      <pubDate>Fri, 04 Nov 2011 02:50:00 +0000</pubDate>
      
      <guid>/questions/7233/video-file-information-command-line/</guid>
      <description>Video File Information Command Line  0 I want to use Command Line Interface to pull out kind of Video File I am opening on my PC from Youtube.com or from dailymotion.com. Is there any way I can do with WireShark or tshark. But I want to use only command line Interface. No GUI please.
tshark command-lineasked 04 Nov &#39;11, 02:50
AnshumanG
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>TCP SYN/SYN ACK/PSH ACK/ACK</title>
      <link>/questions/7234/tcp-synsyn-ackpsh-ackack/</link>
      <pubDate>Fri, 04 Nov 2011 03:35:00 +0000</pubDate>
      
      <guid>/questions/7234/tcp-synsyn-ackpsh-ackack/</guid>
      <description>TCP SYN/SYN ACK/PSH ACK/ACK  0 Dear Wireshark,
After the TCP connection established, the client program sent Packet #7 to the server to check the settings. The server replied Packet #8 (included the setting data) and Packet #9 (ACK) to the client. Since the client received Packet #8, it sent Packet #10 (ACK) to the server.
The sequence number of Packet #8 is 1, and the data length is 6, so the sequence number of the next packet sent by the server should be 7 (1+6).</description>
    </item>
    
    <item>
      <title>what is &amp;#x27;WS&amp;#x27; &amp;#x27;TSval&amp;#x27; and &amp;#x27;SACK_PERM&amp;#x27; mean in  packet info columns???</title>
      <link>/questions/7235/what-is-ws-tsval-and-sack_perm-mean-in-packet-info-columns/</link>
      <pubDate>Fri, 04 Nov 2011 03:56:00 +0000</pubDate>
      
      <guid>/questions/7235/what-is-ws-tsval-and-sack_perm-mean-in-packet-info-columns/</guid>
      <description>what is &amp;lsquo;WS&amp;rsquo; &amp;lsquo;TSval&amp;rsquo; and &amp;lsquo;SACK_PERM&amp;rsquo; mean in packet info columns???  0 1Dear wireshark experts,
I got stuck in with some really tough questions, just as mentioned in subject. What is that???
Help!!!
8 1.253204 172.30.87.216 119.167.194.133 TCP 74 50785 &amp;gt; http [SYN] Seq=0 Win=5840 Len=0 MSS=1460 ***SACK_PERM=1 TSval=1575384402 TSecr=0 WS=128***So appreciated in advance!
info capture packetasked 04 Nov &#39;11, 03:56
wenchao_wang
1●1●2●1
accept rate: 0%
 edited 04 Nov &#39;11, 03:57</description>
    </item>
    
    <item>
      <title>Wireshark work on Citrix</title>
      <link>/questions/7239/wireshark-work-on-citrix/</link>
      <pubDate>Fri, 04 Nov 2011 09:10:00 +0000</pubDate>
      
      <guid>/questions/7239/wireshark-work-on-citrix/</guid>
      <description>Wireshark work on Citrix  0 Just wondering if wireshark works on Citrix? We are having some audio issues and were looking into this to be able to help us with dictation issues on a software our Dr.&#39;s use, which is called EPIC.
citrixasked 04 Nov &#39;11, 09:10
pb121970
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Is there a legend for the symbols used in RTP player?</title>
      <link>/questions/7240/is-there-a-legend-for-the-symbols-used-in-rtp-player/</link>
      <pubDate>Fri, 04 Nov 2011 09:56:00 +0000</pubDate>
      
      <guid>/questions/7240/is-there-a-legend-for-the-symbols-used-in-rtp-player/</guid>
      <description>Is there a legend for the symbols used in RTP player?  1 In version 1.6, the release notes say &#34;The RTP player now shows why media interruptions occur.&#34; I&#39;m now using 1.6.3, and I see the symbols where there are problems with the RTP stream but haven&#39;t been able to find a legend for what the symbols mean. Thanks.
player rtpasked 04 Nov &#39;11, 09:56
rdyaz
16●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>A question related to another question</title>
      <link>/questions/7248/a-question-related-to-another-question/</link>
      <pubDate>Sat, 05 Nov 2011 11:15:00 +0000</pubDate>
      
      <guid>/questions/7248/a-question-related-to-another-question/</guid>
      <description>A question related to another question  0 This is a question in relation to the following question and answer:
&#34;Q 7.3: Why am I only seeing ARP packets when I try to capture traffic?
A: You&#39;re probably on a switched network, and running Wireshark on a machine that&#39;s not sending traffic to the switch and not being sent any traffic from other machines on the switch. ARP packets are often broadcast packets, which are sent to all switch ports.</description>
    </item>
    
    <item>
      <title>How to read packets</title>
      <link>/questions/7249/how-to-read-packets/</link>
      <pubDate>Sat, 05 Nov 2011 11:30:00 +0000</pubDate>
      
      <guid>/questions/7249/how-to-read-packets/</guid>
      <description>How to read packets  0 Again, I&#39;m a total beginner in terms of computer technology..
So could someone give me some sort of a guideline or reference as to how to read packets and what they mean, in &#34;laymen&#34; terms?
Thanks again.
packets understandingasked 05 Nov &#39;11, 11:30
Iapologize
1●2●2●2
accept rate: 0%
  
One Answer:
  
0I would start here and start clicking the links in the Terminology section to dig deeper.</description>
    </item>
    
    <item>
      <title>TCP ACKed lost segment on OS X server</title>
      <link>/questions/7251/tcp-acked-lost-segment-on-os-x-server/</link>
      <pubDate>Sun, 06 Nov 2011 03:23:00 +0000</pubDate>
      
      <guid>/questions/7251/tcp-acked-lost-segment-on-os-x-server/</guid>
      <description>TCP ACKed lost segment on OS X server  0 I&#39;m running wireshark to capture packets on a mac os X system and I can see TCP ACKed lost segment packets on a TCP connection to a client. is there a reason why it happens? I thought if i&#39;m capturing on the server I will see all the packets that are sent to the client
tcpasked 06 Nov &#39;11, 03:23</description>
    </item>
    
    <item>
      <title>Best WS version for mid 2010 Mac Mini with 10.7.2</title>
      <link>/questions/7256/best-ws-version-for-mid-2010-mac-mini-with-1072/</link>
      <pubDate>Sun, 06 Nov 2011 11:43:00 +0000</pubDate>
      
      <guid>/questions/7256/best-ws-version-for-mid-2010-mac-mini-with-1072/</guid>
      <description>Best WS version for mid 2010 Mac Mini with 10.7.2  0 Having seen questions about, and experienced, several anomolies with installing 1.6.2 and 1.6.3, I&#39;m wondering what&#39;s seen as the best version to use on the 2.4mhz core 2 duo Mac mini Mid 2010 with 10.7.2 and 10.7 server? The 1.6.3 64bit for 10.6? My experience with 1.6.3/64 is that it requires x11 loaded by hand, first, to open. Then it still, as with 10.</description>
    </item>
    
    <item>
      <title>Controlling the subdissector of SSL</title>
      <link>/questions/7263/controlling-the-subdissector-of-ssl/</link>
      <pubDate>Mon, 07 Nov 2011 10:02:00 +0000</pubDate>
      
      <guid>/questions/7263/controlling-the-subdissector-of-ssl/</guid>
      <description>Controlling the subdissector of SSL  0 I&#39;m trying to decrypt data transmitted over SSL. I have set the RSA Keys section in Preferences / Protocol / SSL appropriately so that I can read the encrypted data.
The problem is that my data is not HTTP nor any other protocol (that I can find) for specifying which subdisector to use. If I put in &#34;http&#34;, I get a complaint about a Malformed GIF Image.</description>
    </item>
    
    <item>
      <title>HTTP Continuation vs. TCP segment</title>
      <link>/questions/7268/http-continuation-vs-tcp-segment/</link>
      <pubDate>Mon, 07 Nov 2011 18:31:00 +0000</pubDate>
      
      <guid>/questions/7268/http-continuation-vs-tcp-segment/</guid>
      <description>HTTP Continuation vs. TCP segment  1 1I&#39;m examining results from tcpdump using wireshark/tshark and I&#39;m seeing many packets with info &#34;Continuation or non-HTTP traffic&#34; and many other packets with info &#34;[TCP segment of a reassembled PDU]&#34;. I&#39;m curious as to what the difference between the two is.
The trace comes from a simulation of client-server interaction using HTTP streaming. Each client initiates an HTTP connection (using GET) and the server proceeds to send back chunked data indefinitely.</description>
    </item>
    
    <item>
      <title>Request for PDCP(LTE) pcap</title>
      <link>/questions/7276/request-for-pdcplte-pcap/</link>
      <pubDate>Tue, 08 Nov 2011 03:52:00 +0000</pubDate>
      
      <guid>/questions/7276/request-for-pdcplte-pcap/</guid>
      <description>Request for PDCP(LTE) pcap  0 Hi Sir/Madam,
I am looking for PDCP pcap (for using LTE protocol stack). Please help me in providing the same. PDCP should include ROHC and encryption (either AES or SNOW3G).
Regards, Sreekanth
pdcp lteThis question is marked &#34;community wiki&#34;.asked 08 Nov &#39;11, 03:52
v_sreekanth
0●1●1●1
accept rate: 0%
  
One Answer:
  
0If by &#34;pcap&#34; you mean &#34;link-layer header type value for pcap and pcap-ng file formats&#34;</description>
    </item>
    
    <item>
      <title>ARP Broadcast</title>
      <link>/questions/7277/arp-broadcast/</link>
      <pubDate>Tue, 08 Nov 2011 06:15:00 +0000</pubDate>
      
      <guid>/questions/7277/arp-broadcast/</guid>
      <description>ARP Broadcast  0 Hello everyone,
I ran analysis on a pretty complex network so that I could find the reason that all workstations run slowly when connected to the LAN but ran fine when not connected. I plugged directly in to a switch and monitored the network traffic.
Upon analysis I found that one device(server) is consistently sending out ARP Broadcast over the network. It does this at intervals no higher than five seconds and often twice per one second intervals.</description>
    </item>
    
    <item>
      <title>How to save the packets via AirPcap_Nx /w wpa-pwd description</title>
      <link>/questions/7278/how-to-save-the-packets-via-airpcap_nx-w-wpa-pwd-description/</link>
      <pubDate>Tue, 08 Nov 2011 06:29:00 +0000</pubDate>
      
      <guid>/questions/7278/how-to-save-the-packets-via-airpcap_nx-w-wpa-pwd-description/</guid>
      <description>How to save the packets via AirPcap_Nx /w wpa-pwd description  0 Hello, Thank you for everyone who is working for this site. :) I&#39;m a AirPcap reseller and one of my customer faced a strange symptom while saving wireless trace via Wireshark. They&#39;re using WPA-PWD and save the captured trace using Multiple_Capture_files.
Every file size is 50MB and they can decode the first file without any problem but they can&#39;t read the packets from the second files because all packets were encrypted.</description>
    </item>
    
    <item>
      <title>Fragmentation</title>
      <link>/questions/7281/fragmentation/</link>
      <pubDate>Tue, 08 Nov 2011 08:39:00 +0000</pubDate>
      
      <guid>/questions/7281/fragmentation/</guid>
      <description>Fragmentation  0 I&#39;m troubleshooting an application across the WAN and want to know how to look in the trace to see if IP fragmentation could be an issue. The client trace file is captured directly from the NIC and the server trace is from port span. The network team claimed there&#39;s fragmentation but it does do not show when filtered with the &#34;IP fragments&#34; flag for the trace. The trace show there&#39;s no delay with the response time for the request and response.</description>
    </item>
    
    <item>
      <title>UDP checksum error on IPv4 frame with loose source route.</title>
      <link>/questions/7284/udp-checksum-error-on-ipv4-frame-with-loose-source-route/</link>
      <pubDate>Tue, 08 Nov 2011 09:53:00 +0000</pubDate>
      
      <guid>/questions/7284/udp-checksum-error-on-ipv4-frame-with-loose-source-route/</guid>
      <description>UDP checksum error on IPv4 frame with loose source route.  0 I have a captured IPv4 frame with a few options in the header. One is a loose source route. The current pointer is not at the end. The frame has a UDP payload. Wireshark states the UDP checksum is incorrect. It appears it calculates the checksum based on the L3 IP destination address. Shouldn&#39;t it be calculated based on the last route in the loose source route table as long as the pointer hasn&#39;t gone past the table?</description>
    </item>
    
    <item>
      <title>IPv6 Routing Header with 0 left segments gives UDP checksum error</title>
      <link>/questions/7285/ipv6-routing-header-with-0-left-segments-gives-udp-checksum-error/</link>
      <pubDate>Tue, 08 Nov 2011 10:00:00 +0000</pubDate>
      
      <guid>/questions/7285/ipv6-routing-header-with-0-left-segments-gives-udp-checksum-error/</guid>
      <description>IPv6 Routing Header with 0 left segments gives UDP checksum error  0 A captured frame is stating the UDP checksum is in error. The frame is IPv6 and contains a type-2 routing header. The &#34;Left Segments&#34; is 0. Since there isn&#39;t a segment left, shouldn&#39;t the checksum be based on the L3 IP destination address and not the address in the routing header? I&#39;m using Wireshark version 1.6.3 on my MAC.</description>
    </item>
    
    <item>
      <title>facebook - send message</title>
      <link>/questions/7287/facebook-send-message/</link>
      <pubDate>Tue, 08 Nov 2011 12:30:00 +0000</pubDate>
      
      <guid>/questions/7287/facebook-send-message/</guid>
      <description>facebook - send message  0 Hi,
After some sniffing i can see profiles being viewed, photos being looked at etc - I&#39;m looking to see if i can see if a message is sent to a person. I searched for things containing &#34;message&#34; but no returns.
Does anyone know what to filter on to see when i message someone?
facebookasked 08 Nov &#39;11, 12:30
poopftw
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>file saves differently?</title>
      <link>/questions/7289/file-saves-differently/</link>
      <pubDate>Tue, 08 Nov 2011 12:54:00 +0000</pubDate>
      
      <guid>/questions/7289/file-saves-differently/</guid>
      <description>file saves differently?  0 I have a packet capture file and open it in wireshark and apply a filter. The resulting file is different when I save in 1.4.10 vs 1.6.3. Any idea why this is?
filesaveasked 08 Nov &#39;11, 12:54
Joe Garry
1●2●2●2
accept rate: 0%
What are the differences?
(08 Nov &#39;11, 19:04) Jim Aragon  
One Answer:
  
0may be few bugs were fixed.</description>
    </item>
    
    <item>
      <title>Checksum validation rejecting my security code</title>
      <link>/questions/7290/checksum-validation-rejecting-my-security-code/</link>
      <pubDate>Tue, 08 Nov 2011 13:32:00 +0000</pubDate>
      
      <guid>/questions/7290/checksum-validation-rejecting-my-security-code/</guid>
      <description>Checksum validation rejecting my security code  0 I am trying to log into an internet site in London and when I put in the code for the security, the checksum validation rejects it before I complete the code.
checksum security validation rejectasked 08 Nov &#39;11, 13:32
Tonya DeLozier
1●1●1●1
accept rate: 0%
 edited 26 Feb &#39;12, 21:33 
cmaynard ♦♦
9.4k●10●38●142
ok, it is not on my mac - it is on the dell.</description>
    </item>
    
    <item>
      <title>Missing data in PCAP.  What am I doing wrong?</title>
      <link>/questions/7292/missing-data-in-pcap-what-am-i-doing-wrong/</link>
      <pubDate>Tue, 08 Nov 2011 13:56:00 +0000</pubDate>
      
      <guid>/questions/7292/missing-data-in-pcap-what-am-i-doing-wrong/</guid>
      <description>Missing data in PCAP. What am I doing wrong?  0 I have a pcap file saved to my pc. If I provide this pcap to someone else, they can open it and filter for SIP and Q931 data and see the info. If I open it, I only see UDP data and my filter for SIP and Q931 filters zero results. I&#39;ve tried this on version .99, 1.2.2, 1.6.2 and 1.</description>
    </item>
    
    <item>
      <title>TCP previous segment lost...really?</title>
      <link>/questions/7295/tcp-previous-segment-lostreally/</link>
      <pubDate>Tue, 08 Nov 2011 14:15:00 +0000</pubDate>
      
      <guid>/questions/7295/tcp-previous-segment-lostreally/</guid>
      <description>TCP previous segment lost&amp;hellip;really?  0 I have users that RDP to servers from remote offices through a VPN. I do not get complaints from users running terminal server but when running a capure I&#39;m seeing a lot of (TCP previous segment lost) but not retransmitions or duplicate acknowledgements. Below is a small sample export:
 No. Time Delta Source Destination Protocol Info TCP Win Size 16594 35.668978 0.001375 10.11.4.151 10.</description>
    </item>
    
    <item>
      <title>Mistakenly exported to text file</title>
      <link>/questions/7297/mistakenly-exported-to-text-file/</link>
      <pubDate>Tue, 08 Nov 2011 15:25:00 +0000</pubDate>
      
      <guid>/questions/7297/mistakenly-exported-to-text-file/</guid>
      <description>Mistakenly exported to text file  0 Hi guys, I was running a capture and instead of saving the pcap, I exported it to text, now I can&#39;t open it in Wireshark. I tried using text2pcap and importing it back into Wireshark using various options (oct,dec,hex), but it doesn&#39;t show properly.
I am using windows.
text2pcap textasked 08 Nov &#39;11, 15:25
WatchFan
1●1●1●1
accept rate: 0%
Can you post one or two packets from your text file into your original question or as a new comment?</description>
    </item>
    
    <item>
      <title>lua how to set text to src dst column</title>
      <link>/questions/7328/lua-how-to-set-text-to-src-dst-column/</link>
      <pubDate>Wed, 09 Nov 2011 08:20:00 +0000</pubDate>
      
      <guid>/questions/7328/lua-how-to-set-text-to-src-dst-column/</guid>
      <description>lua how to set text to src dst column  0 Hi, All,
Does anyone know how to set text to src or dst column using LUA? I can set text to protocol and info column. I can only set IP addresses to src/dst column, but cannot find a way for string.
thanks! Bruce
luaasked 09 Nov &#39;11, 08:20
Bruce Z
1●1●1●3
accept rate: 0%
 edited 09 Nov &#39;11, 08:21</description>
    </item>
    
    <item>
      <title>Parse incoming DNS but do not query DNS server</title>
      <link>/questions/7339/parse-incoming-dns-but-do-not-query-dns-server/</link>
      <pubDate>Wed, 09 Nov 2011 15:06:00 +0000</pubDate>
      
      <guid>/questions/7339/parse-incoming-dns-but-do-not-query-dns-server/</guid>
      <description>Parse incoming DNS but do not query DNS server  0 Hello,
I have a packet capture from my LAN that contains a DNS query (wireless) and response (192.168.0.7).
When I copy it to another network and turn on name resolution it attempts to ask the DNS server for the host name of the IP (192.168.0.7) of the traffic... then gives up because the DNS server doesn&#39;t have it, but then notices that there is a DNS packet in the file already and uses the results of that.</description>
    </item>
    
    <item>
      <title>Why does Wireshark make multiple passes during dissection?</title>
      <link>/questions/7341/why-does-wireshark-make-multiple-passes-during-dissection/</link>
      <pubDate>Wed, 09 Nov 2011 15:21:00 +0000</pubDate>
      
      <guid>/questions/7341/why-does-wireshark-make-multiple-passes-during-dissection/</guid>
      <description>Why does Wireshark make multiple passes during dissection?  6 1Wireshark makes multiple passes over captured packets during dissection. I have read the various doc/README.*s, and I it my understanding that the first pass is made without constructing protocol trees (the tree argument to each dissect_PROTONAME function is NULL), and that the second pass is made to construct the protocol trees. Are these the only two passes made, or are there more?</description>
    </item>
    
    <item>
      <title>Wireshark does not detect my Sierra Aircard mobile broadband adapter</title>
      <link>/questions/7353/wireshark-does-not-detect-my-sierra-aircard-mobile-broadband-adapter/</link>
      <pubDate>Wed, 09 Nov 2011 21:29:00 +0000</pubDate>
      
      <guid>/questions/7353/wireshark-does-not-detect-my-sierra-aircard-mobile-broadband-adapter/</guid>
      <description>Wireshark does not detect my Sierra Aircard mobile broadband adapter  0 Wireshark does not detect my Sierra Aircard on Win 7 64 Bit
sierrawireless aircard windows7 64-bitasked 09 Nov &#39;11, 21:29
Rahaf
1●1●1●1
accept rate: 0%
 edited 27 Feb &#39;12, 14:07 
Guy Harris ♦♦
17.4k●3●35●196
sigh does it say &#34;Microsoft&#34; as Adapter somewhere?
(10 Nov &#39;11, 03:24) Landi  
2 Answers:
  
0Your Sierra Aircard is an adapter to connect your machine to the Internet through the mobile phone network; that means it probably looks like a PPP adapter to Windows, and WinPcap does not support capturing on PPP adapters on Windows 7.</description>
    </item>
    
    <item>
      <title>SIP 0 OK instead of 200 OK</title>
      <link>/questions/7363/sip-0-ok-instead-of-200-ok/</link>
      <pubDate>Thu, 10 Nov 2011 02:32:00 +0000</pubDate>
      
      <guid>/questions/7363/sip-0-ok-instead-of-200-ok/</guid>
      <description>SIP 0 OK instead of 200 OK  0 Wireshark version: &#34;Version 1.4.3 (SVN Rev 35482 from /trunk-1.4)&#34; When two SIP messages in one packet (sip request INFO for fast update picture AND sip response 200 OK) Graph Analysis will show &#34;0 OK&#34; status instead of &#34;200 OK&#34;, see screenshot: http://xmages.net/i/3200261
200 sip okasked 10 Nov &#39;11, 02:32
Костя Трушников
6●2●2●4
accept rate: 0%
 edited 10 Nov &#39;11, 02:33</description>
    </item>
    
    <item>
      <title>UDP traffic</title>
      <link>/questions/7364/udp-traffic/</link>
      <pubDate>Thu, 10 Nov 2011 03:14:00 +0000</pubDate>
      
      <guid>/questions/7364/udp-traffic/</guid>
      <description>UDP traffic  0 I see UDP traffic over port 20819 from various IP addresses. Does anyone know where does it come from?
unknown udpasked 10 Nov &#39;11, 03:14
brklp
1●4●4●4
accept rate: 0%
 edited 26 Feb &#39;12, 21:31 
cmaynard ♦♦
9.4k●10●38●142
Got Skype?
(10 Nov &#39;11, 03:24) LandiNo skype. This is equipment for testing purposes only. No such programmes should be installed.
(10 Nov &#39;11, 03:26) brklp</description>
    </item>
    
    <item>
      <title>HNBAP Procedures missing</title>
      <link>/questions/7373/hnbap-procedures-missing/</link>
      <pubDate>Thu, 10 Nov 2011 07:50:00 +0000</pubDate>
      
      <guid>/questions/7373/hnbap-procedures-missing/</guid>
      <description>HNBAP Procedures missing  0 Hi!
Does anyone know about which 3GPP standard version the HNBAP dissector is done (Display Filter Reference: UTRAN Iuh interface HNBAP signalling, Protocol field name: hnbap)?
Because 3GPP TNL Update and HNB Configuration Transfer Procedure are considered like Unknown Message and no field name aren&#39;t defined at http://www.wireshark.org/docs/dfref/h/hnbap.html
Thanks a lot.
3gpp dissector hnbapasked 10 Nov &#39;11, 07:50
sifu
31●3●3●7
accept rate: 0%
 edited 22 Nov &#39;11, 01:36</description>
    </item>
    
    <item>
      <title>TSHARK ADVANCED FILTER</title>
      <link>/questions/7375/tshark-advanced-filter/</link>
      <pubDate>Thu, 10 Nov 2011 11:04:00 +0000</pubDate>
      
      <guid>/questions/7375/tshark-advanced-filter/</guid>
      <description>TSHARK ADVANCED FILTER  0 Hi, I have a very huge trace file, how can I filter on TSHARK the next data.
expert.message == &#34;Duplicate ACK (#1)&#34; || expert.message == &#34;Duplicate ACK (#2)&#34; || expert.message == &#34;Duplicate ACK (#3)&#34; || expert.message == &#34;Duplicate ACK (#4)&#34;
I would like to do it with tshark because this trace file is so large to open it with wireshark and It will be paintfull to split the file and open one by one and apply the filter on Wireshark I can&#39;t find any reference about filter expert.</description>
    </item>
    
    <item>
      <title>Wireless Command Line Options</title>
      <link>/questions/7384/wireless-command-line-options/</link>
      <pubDate>Fri, 11 Nov 2011 12:58:00 +0000</pubDate>
      
      <guid>/questions/7384/wireless-command-line-options/</guid>
      <description>Wireless Command Line Options  0 I am needing to run Wireshark from a Windows Command Prompt but I don&#39;t see any options to specify the wireless settings such as the channel or decryption keys. Is this possible?
wirelessasked 11 Nov &#39;11, 12:58
eagle3089
1●2●2●2
accept rate: 0%
  
One Answer:
  
0create a configuration profile and use -C option
answered 13 Nov &#39;11, 03:38
ShomeaX</description>
    </item>
    
    <item>
      <title>TCP protocol without application layer protocols</title>
      <link>/questions/7385/tcp-protocol-without-application-layer-protocols/</link>
      <pubDate>Fri, 11 Nov 2011 15:51:00 +0000</pubDate>
      
      <guid>/questions/7385/tcp-protocol-without-application-layer-protocols/</guid>
      <description>TCP protocol without application layer protocols  0 Hi
I am new to networking and have a question about protocols.
I analyze wireshark capture files, some are http some are ftp but some are plain TCP.
For example; I started a video on youtube and all the stream data is shown as a plain TCP connection.
My questions are;
Can we say application layer protocols are not mandatory in computer networking?</description>
    </item>
    
    <item>
      <title>How to compile dissector to DLL or shared library?</title>
      <link>/questions/7386/how-to-compile-dissector-to-dll-or-shared-library/</link>
      <pubDate>Fri, 11 Nov 2011 16:56:00 +0000</pubDate>
      
      <guid>/questions/7386/how-to-compile-dissector-to-dll-or-shared-library/</guid>
      <description>How to compile dissector to DLL or shared library?  0 Hi, I had followed the steps mentioned in 9.2.1 section in the following link http://www.wireshark.org/docs/wsdg_html_chunked/ChDissectAdd.html and written &#34;myprotocol.c&#34; code to identify my own protocol. Next I want use it as plugin. Can anyone help me to compile &#34;myprotocol.c&#34; into &#34;.dll&#34; file for my Windows wireshark?
Thanks in Advance..
windows dissector pluginasked 11 Nov &#39;11, 16:56
JK7
31●11●12●14
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to write a dissector for a protocol that runs on top of TCP?</title>
      <link>/questions/7388/how-to-write-a-dissector-for-a-protocol-that-runs-on-top-of-tcp/</link>
      <pubDate>Fri, 11 Nov 2011 17:27:00 +0000</pubDate>
      
      <guid>/questions/7388/how-to-write-a-dissector-for-a-protocol-that-runs-on-top-of-tcp/</guid>
      <description>How to write a dissector for a protocol that runs on top of TCP?  0 void proto_reg_handoff_foo(void) { static dissector_handle_t foo_handle; foo_handle = create_dissector_handle(dissect_foo, proto_foo); dissector_add_uint(&amp;amp;quot;udp.port&amp;amp;quot;, FOO_PORT, foo_handle);  }Here, shall i change &amp;ldquo;udp.port&amp;rdquo; as &amp;ldquo;tcp.port&amp;rdquo; for my tcp based application layer protocol dissector?
development dissectorasked 11 Nov &amp;lsquo;11, 17:27
JK7
31●11●12●14
accept rate: 0%
 edited 12 Nov &amp;lsquo;11, 13:29 
Guy Harris ♦♦
17.4k●3●35●196</description>
    </item>
    
    <item>
      <title>Why my capture screen is nothing ???</title>
      <link>/questions/7399/why-my-capture-screen-is-nothing/</link>
      <pubDate>Sat, 12 Nov 2011 20:29:00 +0000</pubDate>
      
      <guid>/questions/7399/why-my-capture-screen-is-nothing/</guid>
      <description>Why my capture screen is nothing ???  0 I use 3g to connect internet and i try to capture but nothing happen?? nothingasked 12 Nov &#39;11, 20:29
Mong_Toi
1●1●1●2
accept rate: 0%
 edited 12 Nov &#39;11, 20:30 
  
One Answer:
  
0The screen shots look like you&#39;re running on Windows, but which version? 32 or 64 bit? Which version of WinPcap do you have installed?</description>
    </item>
    
    <item>
      <title>Lua tostring(tvb(offset,8):le_int64()) returns a Big Endian result</title>
      <link>/questions/7407/lua-tostringtvboffset8le_int64-returns-a-big-endian-result/</link>
      <pubDate>Sun, 13 Nov 2011 19:48:00 +0000</pubDate>
      
      <guid>/questions/7407/lua-tostringtvboffset8le_int64-returns-a-big-endian-result/</guid>
      <description>Lua tostring(tvb(offset,8):le_int64()) returns a Big Endian result  2 Hi,
I am trying to use lua tvb_range:le_uint64() but it does not return the correct value when converted from userdata to a lua integer? It seems to always return tvb_range:int64()
The captured buffer contains; &#34;aa c8 74 91 ba d2 4c 00&#34;
local f.my_proto.fields f.my_int64 = ProtoField.int64(&amp;quot;my_proto.my_int64&amp;quot;, &amp;quot;My Int 64&amp;quot;, base.Dec) tree:add_le(f.mt_int64, tvb(0,8))This code correctly dissects the bytes and displays
&#34;My Int 64: 216237969109738&#34;</description>
    </item>
    
    <item>
      <title>KeyTab - Kerberos</title>
      <link>/questions/7408/keytab-kerberos/</link>
      <pubDate>Mon, 14 Nov 2011 02:29:00 +0000</pubDate>
      
      <guid>/questions/7408/keytab-kerberos/</guid>
      <description>KeyTab - Kerberos  0 Hi there ,
i am trying to review some examples on: http://wiki.wireshark.org/Kerberos
but when i try to do either: a) add the keytab via the gui - the option no longer seems to be availble b) add using the -K from the command line - the command doesnt run sucessfully and just stops at the help section next to the -K (keytab).
I want to review some of the examples before i attempt to do this for myself.</description>
    </item>
    
    <item>
      <title>required hardware for capture filter</title>
      <link>/questions/7410/required-hardware-for-capture-filter/</link>
      <pubDate>Mon, 14 Nov 2011 03:44:00 +0000</pubDate>
      
      <guid>/questions/7410/required-hardware-for-capture-filter/</guid>
      <description>required hardware for capture filter  0 I&#39;ve been trying to setup Wireshark (V1.6.2) capture filter at different windows systems and failed. At one particular PC I used 3 different network adapters. One of them (Intel PRO/1000 PL) worked (example of capture filter: port 5060 or port 53), two others (Realthek RTL8139 and VIA Rhine III) using the same filter failed (Wireshark does not capture anything). Everything else works without problems using these adaptors.</description>
    </item>
    
    <item>
      <title>FP_Hint guidelines for FP/UDP dissection</title>
      <link>/questions/7411/fp_hint-guidelines-for-fpudp-dissection/</link>
      <pubDate>Mon, 14 Nov 2011 03:46:00 +0000</pubDate>
      
      <guid>/questions/7411/fp_hint-guidelines-for-fpudp-dissection/</guid>
      <description>FP_Hint guidelines for FP/UDP dissection  0 Can anyone share example of &#34;fp_hint&#34; modified pcap file? I&#39;m desperately trying to apply all available FP/MAC/RLC dissecting machinery, which seems to depend on info appended by fp_hint. A short example will hopefully put me on-track.
fp umts mac rlc heuristicsasked 14 Nov &#39;11, 03:46
exbungee
16●2●3●4
accept rate: 0%
 edited 18 Nov &#39;11, 23:03 
can someone provide an example of structure that needs to prepended to UDP packet carrying FP payload?</description>
    </item>
    
    <item>
      <title>Windows 7 64 Bit (npf.sys)</title>
      <link>/questions/7414/windows-7-64-bit-npfsys/</link>
      <pubDate>Mon, 14 Nov 2011 05:20:00 +0000</pubDate>
      
      <guid>/questions/7414/windows-7-64-bit-npfsys/</guid>
      <description>Windows 7 64 Bit (npf.sys)  0 Hi,
i try to capture the Win7 64 Bit Installation with the Repackaging Software Installshield.
Now i have a problem with the npf.sys driver. it does not install with my new created msi package. How can i manually install the driver ? or how can i solve my problem ?
Anyone an idea ?
Greetings Marc
not npf.sys installedThis question is marked &#34;community wiki&#34;</description>
    </item>
    
    <item>
      <title>Screen &amp;quot;freezing&amp;quot; on Mac os x 10.7.1</title>
      <link>/questions/7415/screen-freezing-on-mac-os-x-1071/</link>
      <pubDate>Mon, 14 Nov 2011 07:46:00 +0000</pubDate>
      
      <guid>/questions/7415/screen-freezing-on-mac-os-x-1071/</guid>
      <description>Screen &amp;ldquo;freezing&amp;rdquo; on Mac os x 10.7.1  0 HI there, I am using wireshark since several years now and this to my entire satisfaction on Windows. I am having troubles on Mac OS X, as when the capture is started, the program seems to freeze and you can hardly use menu options, without waiting endless time, or killing the program. In Windows, the display is behaving smoothly, without problem. I am running the latest stable version 1.</description>
    </item>
    
    <item>
      <title>GLib Thread not initialized</title>
      <link>/questions/7416/glib-thread-not-initialized/</link>
      <pubDate>Mon, 14 Nov 2011 08:54:00 +0000</pubDate>
      
      <guid>/questions/7416/glib-thread-not-initialized/</guid>
      <description>GLib Thread not initialized  0 Hi there,
I download the 1.6.3 source package, compile and install went OK, but on execution I&#39;ve got an error raising from GLib :
GLib-ERROR **: The thread system is not yet initialized. aborting...
Can anyone help... seems to be a GLib problem rather than Wiresharks... does glib require some intialization or so ? do I need glib-devel package ?
Thanks !
Tips: I&#39;ve got a 2.</description>
    </item>
    
    <item>
      <title>tcp acking every other segment?</title>
      <link>/questions/7418/tcp-acking-every-other-segment/</link>
      <pubDate>Mon, 14 Nov 2011 10:05:00 +0000</pubDate>
      
      <guid>/questions/7418/tcp-acking-every-other-segment/</guid>
      <description>tcp acking every other segment?  0 I am working on the tcp lab and am having trouble understading how the ack is and why it skips some segments? Can anyone shed a little light on this for me?
ackasked 14 Nov &#39;11, 10:05
hatcher44
1●1●1●1
accept rate: 0%
  
3 Answers:
  
2You are seeing a feature known as &#34;delayed ACK.&#34; Remember that ACKs are cumulative and the ACK number from the receiving system is the next expected sequence number from the sending system.</description>
    </item>
    
    <item>
      <title>Windows 8 Support</title>
      <link>/questions/7425/windows-8-support/</link>
      <pubDate>Mon, 14 Nov 2011 13:19:00 +0000</pubDate>
      
      <guid>/questions/7425/windows-8-support/</guid>
      <description>Windows 8 Support  1 I&#39;m using the Windows 8 Developer Preview and wireshark does not appear to function.
I get the error &#34;The NPF driver isn&#39;t running. You may have trouble capturing or listing interfaces.&#34; when attempting to run it.
Google appears to be full of useless links for this error, so I was hoping I might have some more luck here.
Thanks
winpcap windows8 wiresharkasked 14 Nov &#39;11, 13:19</description>
    </item>
    
    <item>
      <title>Archived portable versions</title>
      <link>/questions/7426/archived-portable-versions/</link>
      <pubDate>Mon, 14 Nov 2011 15:29:00 +0000</pubDate>
      
      <guid>/questions/7426/archived-portable-versions/</guid>
      <description>Archived portable versions  0 Is there a way to get archived portable versions of wireshark?
archived portableasked 14 Nov &#39;11, 15:29
Tnirps99
1●1●1●2
accept rate: 0%
 edited 14 Nov &#39;11, 20:17 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
2Yes. Visit the download page.
answered 14 Nov &#39;11, 20:16
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%
     </description>
    </item>
    
    <item>
      <title>Tcp Window Size and acknowledgment</title>
      <link>/questions/7428/tcp-window-size-and-acknowledgment/</link>
      <pubDate>Mon, 14 Nov 2011 15:34:00 +0000</pubDate>
      
      <guid>/questions/7428/tcp-window-size-and-acknowledgment/</guid>
      <description>Tcp Window Size and acknowledgment  0 I read a lot of things about these and I am very confused.
If you help me I will be very glad.
My questions are:
1-) Does TCP protocol send acknowledgment for every TCP segment or depends on window size?
Because in that link: http://www.firewall.cx/networking-topics/protocols/tcp/130-protocols-tcp-overview.html
It shows because of windows size, it sends one acknowledgment for 3 packets.
But in that animation: http://www.youtube.com/watch?v=9BuaeEjIeQI&amp;amp;feature=related</description>
    </item>
    
    <item>
      <title>if given an image size (in bytes), could you tell how many messages/packets the server would have to send</title>
      <link>/questions/7435/if-given-an-image-size-in-bytes-could-you-tell-how-many-messagespackets-the-server-would-have-to-send/</link>
      <pubDate>Mon, 14 Nov 2011 20:47:00 +0000</pubDate>
      
      <guid>/questions/7435/if-given-an-image-size-in-bytes-could-you-tell-how-many-messagespackets-the-server-would-have-to-send/</guid>
      <description>if given an image size (in bytes), could you tell how many messages/packets the server would have to send  0 Using wireshark, i was given an assignment to go to any webpage, right click on said image, goto properties and note the image size. Given this information, i used my browser to just request that one image. I was able to figure out how many packets it took for that image that was 6676 bytes.</description>
    </item>
    
    <item>
      <title>Broadcom NetLink (TM) Gigabit Eth card</title>
      <link>/questions/7438/broadcom-netlink-tm-gigabit-eth-card/</link>
      <pubDate>Tue, 15 Nov 2011 06:13:00 +0000</pubDate>
      
      <guid>/questions/7438/broadcom-netlink-tm-gigabit-eth-card/</guid>
      <description>Broadcom NetLink (TM) Gigabit Eth card  0 Hello The Broadcom NetLink (TM) Gigabit Eth card supports capturing vlan tag packet with wireshark?
Thanks !
broadcom netlink vlan tagasked 15 Nov &#39;11, 06:13
akalavri
1●2●2●3
accept rate: 0%
  
2 Answers:
  
0I think in the advanced settings of the broadcom NIC you have to turn on 802.1q tagging. I can&#39;t remember what the default is. Also, depending on what kind of switches you&#39;re using you have to enable them to pass on the 802.</description>
    </item>
    
    <item>
      <title>DNP3 Decode As setting in Wireshark 1.6.3</title>
      <link>/questions/7439/dnp3-decode-as-setting-in-wireshark-163/</link>
      <pubDate>Tue, 15 Nov 2011 06:34:00 +0000</pubDate>
      
      <guid>/questions/7439/dnp3-decode-as-setting-in-wireshark-163/</guid>
      <description>DNP3 Decode As setting in Wireshark 1.6.3  0 What should be setting in Wireshark 1.6.3 [Version 1.6.3 (SVN Rev 39702 from /trunk-1.6)] in Decode As, to properly analyze or capture DNP3 communication?
In specific, what selection should be under &#34;Decode As&#34; in right window for each of the tabs: -Link; -Network; -Protocol.
When I tried default selection, it is not decoding any DNP3 traffic
Any suggestion or help is greatly appreciated.</description>
    </item>
    
    <item>
      <title>SNMPV3 request not decrypted</title>
      <link>/questions/7443/snmpv3-request-not-decrypted/</link>
      <pubDate>Tue, 15 Nov 2011 07:23:00 +0000</pubDate>
      
      <guid>/questions/7443/snmpv3-request-not-decrypted/</guid>
      <description>SNMPV3 request not decrypted  0 SNMPV3 priv requests are not decrypted but responses and traps are decrypted in Wireshark 1.6.3.
Wireshark just skips the data in SNMP-requests after the authentication header or becomes [Malformed Packet]. The SNMP-response to this, is decrypted and decoded correctly.
snmpv3asked 15 Nov &#39;11, 07:23
olw
1●1●1●1
accept rate: 0%
Is this still a problem with Wireshark 1.6.4? If so, you might want to file a bug report, or at least post a small capture file that depicts the problem to the wireshark-dev mailing list (or somewhere else) so someone could take a look at it.</description>
    </item>
    
    <item>
      <title>libtool complains &amp;quot;version mismatch&amp;quot;</title>
      <link>/questions/7448/libtool-complains-version-mismatch/</link>
      <pubDate>Tue, 15 Nov 2011 08:57:00 +0000</pubDate>
      
      <guid>/questions/7448/libtool-complains-version-mismatch/</guid>
      <description>libtool complains &amp;ldquo;version mismatch&amp;rdquo;  0 Hello again,
1.6.3 build system fails under my distro. (related to libtool ?)
here is the output from make:
../libtool: line 466: CDPATH: command not found ../libtool: line 1144: func_opt_split: command not found libtool: Version mismatch error. This is libtool 2.2.6b Debian-2.2.6b-2ubuntu1, but the libtool: definition of this LT_INIT comes from an older release. libtool: You should recreate aclocal.m4 with macros from libtool 2.2.6b Debian-2.</description>
    </item>
    
    <item>
      <title>how do I see total traffic by IP</title>
      <link>/questions/7452/how-do-i-see-total-traffic-by-ip/</link>
      <pubDate>Tue, 15 Nov 2011 16:32:00 +0000</pubDate>
      
      <guid>/questions/7452/how-do-i-see-total-traffic-by-ip/</guid>
      <description>how do I see total traffic by IP  0 I want to know how to see the total traffic (byte/packet count) to/from each IP. After I determine that, I will probably want to drill in and see the traffic by protocol/port for an IP. Basically I want to know what IP addresses are accounting for the large traffic and then will want to see what protocol is the culpret.</description>
    </item>
    
    <item>
      <title>Capture Filters for 1.7</title>
      <link>/questions/7453/capture-filters-for-17/</link>
      <pubDate>Tue, 15 Nov 2011 16:41:00 +0000</pubDate>
      
      <guid>/questions/7453/capture-filters-for-17/</guid>
      <description>Capture Filters for 1.7  0 Is it me or is there no capture filter field in 1.7?
capture-filterasked 15 Nov &#39;11, 16:41
EricKnaus
46●19●20●26
accept rate: 0%
  
One Answer:
  
1 It&#39;s you. ;) Wireshark 1.7 supports capturing from multiple interfaces, so you can apply a different capture filter to each interface if you want. Because of this, the capture filter field was moved to the per-interface settings dialog.</description>
    </item>
    
    <item>
      <title>VOIP sniffing (Skype)</title>
      <link>/questions/7454/voip-sniffing-skype/</link>
      <pubDate>Tue, 15 Nov 2011 16:42:00 +0000</pubDate>
      
      <guid>/questions/7454/voip-sniffing-skype/</guid>
      <description>VOIP sniffing (Skype)  0 When i sniff for skype calls all i get is UDP packets. how can i get it so wireshark captures RTP packets so i can use wireshark player to hear the voice clips. Thanks. even if it means using a different voip client, i just need to get a example voip call recording. Thanks
sniffing voipasked 15 Nov &#39;11, 16:42
Stampy29
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>ASCII Translations</title>
      <link>/questions/7458/ascii-translations/</link>
      <pubDate>Tue, 15 Nov 2011 19:22:00 +0000</pubDate>
      
      <guid>/questions/7458/ascii-translations/</guid>
      <description>ASCII Translations  1 Pardon the (probably) stupid question, but I&#39;m completely new to Wireshark. I&#39;ve just captured some packets and am trying to read them. One of the lines from the capture looks like this:
0030 32 30 2d 32 32 30 32 53 05 f1 32 7d 05 f1 32 0b 2.-22.2. .12&amp;#39;.12.I thought that the right side was supposed to be the ASCII translation of the raw hex dump on the left.</description>
    </item>
    
    <item>
      <title>unknown inap</title>
      <link>/questions/7469/unknown-inap/</link>
      <pubDate>Wed, 16 Nov 2011 03:57:00 +0000</pubDate>
      
      <guid>/questions/7469/unknown-inap/</guid>
      <description>unknown inap  0 I&#39;m sending a INAP Initial DP message with an opCode or extension value of 59 but the wireshark trace shows &#39;Unknown INAP (59)&#39;. What is the reason
unknown inapasked 16 Nov &#39;11, 03:57
rks2k1
1●1●1●2
accept rate: 0%
 edited 18 Nov &#39;11, 05:56 
cmaynard ♦♦
9.4k●10●38●142
Not sure what you mean opcode-initialDP Code ::= local:0 There is no opcode 59 defined in IN-operationcodes.asn Regards Anders</description>
    </item>
    
    <item>
      <title>atheros ubuntu</title>
      <link>/questions/7475/atheros-ubuntu/</link>
      <pubDate>Wed, 16 Nov 2011 12:56:00 +0000</pubDate>
      
      <guid>/questions/7475/atheros-ubuntu/</guid>
      <description>atheros ubuntu  0 Hi!
I have a pci atheros card AR5212/AR5213 (rev 01) with madwifi driver and ubuntu 11.10. I installed wireshark 1.6.2. I created an interface in monitor mode but wireshark doesn&#39;t see it in monitor mode (the check box is grey).
Could you please help me?
Sboong
PS. This card works great with kismet.
atherosasked 16 Nov &#39;11, 12:56
_sbOOng_
1●1●1●1
accept rate: 0%
Did you happen to find a solution to your problem?</description>
    </item>
    
    <item>
      <title>Remote capture - Can&amp;#x27;t get list of interfaces: getaddrinfo() No such host is known.</title>
      <link>/questions/7476/remote-capture-cant-get-list-of-interfaces-getaddrinfo-no-such-host-is-known/</link>
      <pubDate>Wed, 16 Nov 2011 13:53:00 +0000</pubDate>
      
      <guid>/questions/7476/remote-capture-cant-get-list-of-interfaces-getaddrinfo-no-such-host-is-known/</guid>
      <description>Remote capture - Can&amp;rsquo;t get list of interfaces: getaddrinfo() No such host is known.  0 Trying to use Wireshark Version 1.4.0rc2 (SVN Rev 33665 from /trunk-1.4) on Win XP to capture from my linux box running Wireshark Version 1.4.9 on Fedora 15 (2.6.38.6-26.rc1.fc15i386 with libcap version 1.1.1) On Capture Options, I specify &#34;Remote&#34; interface, Host &#34;rpcapd://10.2.41.11&#34; Username &#34;pat&#34; and Password.
I get a error message:
&#34;Can&#39;t get list of interfaces: getaddrinfo() No such host is known.</description>
    </item>
    
    <item>
      <title>Wireshark not capturing packets where tpc.src==my.ip.addr</title>
      <link>/questions/7477/wireshark-not-capturing-packets-where-tpcsrcmyipaddr/</link>
      <pubDate>Wed, 16 Nov 2011 16:19:00 +0000</pubDate>
      
      <guid>/questions/7477/wireshark-not-capturing-packets-where-tpcsrcmyipaddr/</guid>
      <description>Wireshark not capturing packets where tpc.src==my.ip.addr  0 I have checked filters and options to resolve the problem. I do not see HTTP URI requests from my system nor do I see ACKs from my machine. When I filter tpc.src==10.72.xxx.xxx where 10.72.xxx.xxx is the IP addr of my system, no packets are listed. I have never experienced this problem before. Does anyone have any idea what is happening. I am using Windows7.</description>
    </item>
    
    <item>
      <title>GLib-ERROR **: gmem.c:239</title>
      <link>/questions/7480/glib-error-gmemc239/</link>
      <pubDate>Thu, 17 Nov 2011 03:43:00 +0000</pubDate>
      
      <guid>/questions/7480/glib-error-gmemc239/</guid>
      <description>GLib-ERROR **: gmem.c:239  0 At monitoring of interfaces (use multiple files) the size of a file 200МB. Through time there is an error: GLib-ERROR **: gmem.c:239: failed to allocate 8388608 bytes. Email: [email protected]
failed allocate toasked 17 Nov &#39;11, 03:43
Amrel
1●1●1●1
accept rate: 0%
 edited 17 Nov &#39;11, 09:44 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
0On 32-bit platforms, the address space size limits the amount of memory Wireshark can allocate; on all platforms, the amount of swap space (swap partition or partitions, pagefiles/swap files, etc.</description>
    </item>
    
    <item>
      <title>No interfaces in windows 7</title>
      <link>/questions/7485/no-interfaces-in-windows-7/</link>
      <pubDate>Thu, 17 Nov 2011 08:20:00 +0000</pubDate>
      
      <guid>/questions/7485/no-interfaces-in-windows-7/</guid>
      <description>No interfaces in windows 7  0 I have a %$£^ windows 7 64-bit, Wireshark and I can&#39;t see my interfaces just &#34;Microsoft&#34;. any idea how do I solve this.
nointerface windows7asked 17 Nov &#39;11, 08:20
sorino737
1●1●1●1
accept rate: 0%
hey, have you find the solution
(11 Oct &#39;13, 08:20) sekar  
One Answer:
  
0Run your wireshark in administrator mode,this time you will see network card in wireshark.</description>
    </item>
    
    <item>
      <title>capture file too large to parse</title>
      <link>/questions/7487/capture-file-too-large-to-parse/</link>
      <pubDate>Thu, 17 Nov 2011 08:48:00 +0000</pubDate>
      
      <guid>/questions/7487/capture-file-too-large-to-parse/</guid>
      <description>capture file too large to parse  0 Is there a way to take a already captured file (like 150mb) and turn it into several smaller files that are easier to manage?
parse filesizeasked 17 Nov &#39;11, 08:48
gtefft
1●1●1●2
accept rate: 0%
  
One Answer:
  
4Yes, you can slice it into smaller files using editcap -c 100000 &amp;lt;infile.pcap&amp;gt; &amp;lt;outfile.pcap&amp;gt;, which will slice the infile.pcap in multiple files with 100,000 frames each (or any other number you put in there).</description>
    </item>
    
    <item>
      <title>i got following error during compiling my dissector for windows [fatal error U1073: don&amp;#x27;t know how to make &amp;#x27;packet-tlv.obj&amp;#x27;]</title>
      <link>/questions/7497/i-got-following-error-during-compiling-my-dissector-for-windows-fatal-error-u1073-dont-know-how-to-make-packet-tlvobj/</link>
      <pubDate>Thu, 17 Nov 2011 18:18:00 +0000</pubDate>
      
      <guid>/questions/7497/i-got-following-error-during-compiling-my-dissector-for-windows-fatal-error-u1073-dont-know-how-to-make-packet-tlvobj/</guid>
      <description>i got following error during compiling my dissector for windows [fatal error U1073: don&amp;rsquo;t know how to make &amp;lsquo;packet-tlv.obj&amp;rsquo;]  0 Hi, I had written a dissector to identify my protocol. when compiling it for windows i got following error.please help me to resolve this one.
fatal error U1073: don&#39;t know how to make &#39;packet-tlv.obj&#39;
Output:
C: /wireshark /plugins /tlv&amp;gt;nmake -f Makefile.nmake distclean
Microsoft (R) Program Maintenance Utility Version 9.00.30729.01 Copyright (C) Microsoft Corporation.</description>
    </item>
    
    <item>
      <title>wireshark can capture traffice of switches configured in port mirroring?</title>
      <link>/questions/7499/wireshark-can-capture-traffice-of-switches-configured-in-port-mirroring/</link>
      <pubDate>Thu, 17 Nov 2011 23:41:00 +0000</pubDate>
      
      <guid>/questions/7499/wireshark-can-capture-traffice-of-switches-configured-in-port-mirroring/</guid>
      <description>wireshark can capture traffice of switches configured in port mirroring?  0 Below is the scenario: Linksys switches are configured in port-mirroring mode. there is lot of broadcast from the user machines.
Can we capture the logs of those machines who are broadcasting??
Pls reply asap.
thanks fro help.
on port mirroring wiresharkasked 17 Nov &#39;11, 23:41
Manmohan
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Postdissector executes more than one time per packet?</title>
      <link>/questions/7501/postdissector-executes-more-than-one-time-per-packet/</link>
      <pubDate>Fri, 18 Nov 2011 05:53:00 +0000</pubDate>
      
      <guid>/questions/7501/postdissector-executes-more-than-one-time-per-packet/</guid>
      <description>Postdissector executes more than one time per packet?  0 I&#39;m trying to use Postdissector, but I found that postdissector may be triggered several times per packet captured. I tried the following code and it proved the fact. I&#39;m a newbie to lua in wireshark and i&#39;m not sure if there&#39;s something else needs to be done. Glad if anyone can help~
do test_proto = Proto (&amp;quot;test&amp;quot;, &amp;quot;Test Protocol&amp;quot;) function test_proto.</description>
    </item>
    
    <item>
      <title>3GPP PCAP over SUA (SS7 SCCP-User Adaptation Layer)</title>
      <link>/questions/7504/3gpp-pcap-over-sua-ss7-sccp-user-adaptation-layer/</link>
      <pubDate>Fri, 18 Nov 2011 07:58:00 +0000</pubDate>
      
      <guid>/questions/7504/3gpp-pcap-over-sua-ss7-sccp-user-adaptation-layer/</guid>
      <description>3GPP PCAP over SUA (SS7 SCCP-User Adaptation Layer)  0 Hi!
I am using wire shark version 1.4.6 and i am trying to send encoded PCAP (Positioning Calculation Application Part) packet (POSITION INITIATION REQUEST message) over SUA (SS7 SCCP-User Adaptation Layer) between a Radio Network Controller (RNC) and the Stand-Alone SMLC (SAS) accordance with 3GPP standart. But when i send it wireshark is unable to recognize the PCAP protocol and it displays: Protocol is SUA (RFC 3868) and info is CORE.</description>
    </item>
    
    <item>
      <title>how to capture data from 2 servers that are in differentes VIPs</title>
      <link>/questions/7506/how-to-capture-data-from-2-servers-that-are-in-differentes-vips/</link>
      <pubDate>Fri, 18 Nov 2011 10:09:00 +0000</pubDate>
      
      <guid>/questions/7506/how-to-capture-data-from-2-servers-that-are-in-differentes-vips/</guid>
      <description>how to capture data from 2 servers that are in differentes VIPs  0 Hi, let me explain.. i have 2 sets of tornado servers that are in differents sites, with different VIP. So, im wondering how can i capture data from both and compare them, i mean, for example the Tornado A that is in Saint Louis, and the Tornado B that is in New York, we are experiencing TCP retransmissions, and so i want to compare where the data is being retransmitted.</description>
    </item>
    
    <item>
      <title>How do i find hidden URL&amp;#x27;s for radio streams?</title>
      <link>/questions/7511/how-do-i-find-hidden-urls-for-radio-streams/</link>
      <pubDate>Fri, 18 Nov 2011 18:15:00 +0000</pubDate>
      
      <guid>/questions/7511/how-do-i-find-hidden-urls-for-radio-streams/</guid>
      <description>How do i find hidden URL&amp;rsquo;s for radio streams?  0 I downloaded Wireshark for MAC and do not understand how it works. i watched the video but do not see how to get a URL?
i am looking for streams my customers request to play in the Beautiful Clock Radio app.
I have come across a site that i can not figure out the stream even though they have a iphone stream available.</description>
    </item>
    
    <item>
      <title>how to read TCP stream</title>
      <link>/questions/7513/how-to-read-tcp-stream/</link>
      <pubDate>Fri, 18 Nov 2011 23:06:00 +0000</pubDate>
      
      <guid>/questions/7513/how-to-read-tcp-stream/</guid>
      <description>how to read TCP stream  0 I am very new to this so forgive me if my question has a simply answer I am missing. I am trying to decipher a TCP Stream. I see some of the information is readable. However, there is a large section that needs to be decoded. Below is the beginning of what I would like to decode.
&amp;lt;detection&amp;gt; &amp;lt;keyId&amp;gt;1&amp;lt;/keyId&amp;gt; &amp;lt;data&amp;gt;!CDATA[T8PdjhIeYyFvWdI+lB5Gkh0A1uBtCNt6avFGFV3nzMiU1kZQgVOzF50dAfk8YZOHFEVbptTA/d8QWo7+wJ4vX934tZGjg+bz5wwfGyLMrS9Uq78PnH5EPgtUZwBulHWHL2StofzO94IpMe8A1r7/fMPQ94p3rgPvTvRCCkRifmMV03I1kwn8c7Can someone point me in the direction of what I need to do to successfully decode this section of the stream?</description>
    </item>
    
    <item>
      <title>DNS IPV6 query/reponse</title>
      <link>/questions/7514/dns-ipv6-queryreponse/</link>
      <pubDate>Fri, 18 Nov 2011 23:43:00 +0000</pubDate>
      
      <guid>/questions/7514/dns-ipv6-queryreponse/</guid>
      <description>DNS IPV6 query/reponse  0 In my traces I can see a DNS AAAA query and response but after the response is received I see DNS A (IPv4) query and response. Now if I have an IPv6 address why do I need to get the IPv4 ?
Maybe I can&#39;t use IPv6 addresses because my ISP might not support it?
Screenshot
Trace file: cloudshark
dns ipv6asked 18 Nov &#39;11, 23:43</description>
    </item>
    
    <item>
      <title>Ubuntu machine - no interfaces listed</title>
      <link>/questions/7523/ubuntu-machine-no-interfaces-listed/</link>
      <pubDate>Sun, 20 Nov 2011 18:13:00 +0000</pubDate>
      
      <guid>/questions/7523/ubuntu-machine-no-interfaces-listed/</guid>
      <description>Ubuntu machine - no interfaces listed  16 7I&#39;ve tried the procedures listed in the CaptureSetup/CapturePrivileges, and the Debian specific file, but still see no interfaces. I saw an earlier post referring to bpf* file permissions, but this appears to only be relevant to Mac OS X users. I&#39;m running Ubuntu 10.04 LTS. Any ideas?
interfaces ubuntuasked 20 Nov &#39;11, 18:13
mrcpuhead
246●3●3●5
accept rate: 0%
Hope i&#39;m not stating the obvious here.</description>
    </item>
    
    <item>
      <title>Find packets with the same h2h/e2e identifier in a trace file</title>
      <link>/questions/7525/find-packets-with-the-same-h2he2e-identifier-in-a-trace-file/</link>
      <pubDate>Mon, 21 Nov 2011 00:31:00 +0000</pubDate>
      
      <guid>/questions/7525/find-packets-with-the-same-h2he2e-identifier-in-a-trace-file/</guid>
      <description>Find packets with the same h2h/e2e identifier in a trace file  0 I have a trace file from the Diameter protocol. My goal is to find all packets (either Answers or Requests) with the same hop-by-hop/end-to-end identifier. This identifier is being given for several hours, and it is unique for each Request-Answer pair of packets during this period of time. I suspect that there are some Requests, which have the same identifier and are very close to each other in time.</description>
    </item>
    
    <item>
      <title>About the info column.</title>
      <link>/questions/7535/about-the-info-column/</link>
      <pubDate>Mon, 21 Nov 2011 09:33:00 +0000</pubDate>
      
      <guid>/questions/7535/about-the-info-column/</guid>
      <description>About the info column.  0 Can somebody tell me how to avoid, in the info column, the display of source port and destination port? I&#39;m checking megaco traces and it is not easy to follow the call due to this not necesary info in the info column: Source port: h248-binary Destination port: megaco-h248
or Source port: h248-binary Destination port: megaco-h248 I noticed this behaviour starting from release 1.6.0
info columnThis question is marked &#34;</description>
    </item>
    
    <item>
      <title>Windows 7 and old versions</title>
      <link>/questions/7539/windows-7-and-old-versions/</link>
      <pubDate>Mon, 21 Nov 2011 11:49:00 +0000</pubDate>
      
      <guid>/questions/7539/windows-7-and-old-versions/</guid>
      <description>Windows 7 and old versions  0 Hi,
The many coworkers at my company run various versions of Wireshark. We&#39;re upgrading to Windows 7 next year, so we need to know which is the first version which works under Windows 7. I see in old msgs that 1.2.3 (which came out when Win7 was released 2 years ago) works under Windows 7. But did earlier versions work? Did anyone try?</description>
    </item>
    
    <item>
      <title>Why does Wireshark save in temp file format?</title>
      <link>/questions/7543/why-does-wireshark-save-in-temp-file-format/</link>
      <pubDate>Mon, 21 Nov 2011 13:10:00 +0000</pubDate>
      
      <guid>/questions/7543/why-does-wireshark-save-in-temp-file-format/</guid>
      <description>Why does Wireshark save in temp file format?  0 I use Wireshark to take rolling captures on my machine overnight. I set it (in Capture Options) to take 200MB captures and stop after 30 captures. Everything works fine, but in the morning when I check the captures they are all stored in a temp format. I have to doubleclick on each one, load it up in Wireshark, and then save it back to the same folder in pcap format.</description>
    </item>
    
    <item>
      <title>If FCS is wrong, will Wireshark detect this fact? How can I see it?</title>
      <link>/questions/7549/if-fcs-is-wrong-will-wireshark-detect-this-fact-how-can-i-see-it/</link>
      <pubDate>Tue, 22 Nov 2011 00:01:00 +0000</pubDate>
      
      <guid>/questions/7549/if-fcs-is-wrong-will-wireshark-detect-this-fact-how-can-i-see-it/</guid>
      <description>If FCS is wrong, will Wireshark detect this fact? How can I see it?  0 I use Wireshark version 1.4.0; OS: Windows 7
details of problem: I capture UDP stream, and I definitely know, that FCS of all packets is wrong. But all packets are captured and look normally in caprure window (colored blue). Is this possible to differ packets with wrong FCS from packets with correct FCS?
Thank You!</description>
    </item>
    
    <item>
      <title>Unknown SCTP Payload Protocol Id (SABP)</title>
      <link>/questions/7552/unknown-sctp-payload-protocol-id-sabp/</link>
      <pubDate>Tue, 22 Nov 2011 01:32:00 +0000</pubDate>
      
      <guid>/questions/7552/unknown-sctp-payload-protocol-id-sabp/</guid>
      <description>Unknown SCTP Payload Protocol Id (SABP)  1 Hi!
I am using wire shark version 1.4.6 and when i send encoded SABP (Service Area Broadcast Protocol) packet (WRITE REPLACE message) over SCTP (Stream Control Transmission Protocol) the SCTP Payload protocol identifier is Unknown (31).
However i found two links where SABP is defined as PPI=31 and it&#39;s used over SCTP.
http://wiki.wireshark.org/SABPhttp://anonsvn.wireshark.org/wireshark/trunk/epan/dissectors/packet-sctp.cCould some one please help me on this or have a SCTP trace whith SABP message?</description>
    </item>
    
    <item>
      <title>capture filter does not filter</title>
      <link>/questions/7566/capture-filter-does-not-filter/</link>
      <pubDate>Tue, 22 Nov 2011 15:52:00 +0000</pubDate>
      
      <guid>/questions/7566/capture-filter-does-not-filter/</guid>
      <description>capture filter does not filter  0 version 1.6.4, Windows 7, 64 bit, connected to a router then a cable modem. Start WireShark then select Capture -&amp;gt; Captures Filters ... Enter Filter name: &#34;aaa&#34; Filter String: &#34;src port 64.4.231.55&#34; then Select New and restart the capture. The captured packets include data other than those with a source other than specified. How do I get the capture to work? Thanks for your time</description>
    </item>
    
    <item>
      <title>Compile error in windows</title>
      <link>/questions/7572/compile-error-in-windows/</link>
      <pubDate>Tue, 22 Nov 2011 21:53:00 +0000</pubDate>
      
      <guid>/questions/7572/compile-error-in-windows/</guid>
      <description>Compile error in windows  0 Hi There,
I tried to compile wireshark on a machine for the first time. I got the below given error.How to resolve this?
perl perlnoutf.pl make-authors-short.pl &amp;lt; ../AUTHORS &amp;gt; AUTHORS-SHORT perl perlnoutf.pl make-authors-format.pl &amp;lt; AUTHORS-SHORT &amp;gt; AUTHORS-SHORT -FORMAT copy /B wireshark.pod.template + AUTHORS-SHORT-FORMAT wireshark.pod wireshark.pod.template AUTHORS-SHORT-FORMAT 1 file(s) copied. copy ..\docbook\ws.css . 1 file(s) copied. bash -o igncr pod2html &amp;ndash;title=&amp;quot;The Wireshark Network Analyzer 1.6.1&amp;quot; &amp;ndash;css=ws.</description>
    </item>
    
    <item>
      <title>Matches operator doesn&amp;#x27;t work with some hex digits</title>
      <link>/questions/7582/matches-operator-doesnt-work-with-some-hex-digits/</link>
      <pubDate>Wed, 23 Nov 2011 07:53:00 +0000</pubDate>
      
      <guid>/questions/7582/matches-operator-doesnt-work-with-some-hex-digits/</guid>
      <description>Matches operator doesn&amp;rsquo;t work with some hex digits  1 I don&#39;t know why the matches operator doesn&#39;t find some hex digits. If I do something like: http matches &#34;\xff&#34;
I get no packets. This doesn&#39;t happen with hex digit which start by a number.
The funny is that If I use contains: http contains &#34;\xff&#34;
I get the packet I&#39;m looking for.
The problem is that I need to use matches operator to set some regex in perl like: &#34;</description>
    </item>
    
    <item>
      <title>How to split voip to saperate pcap files in easy way</title>
      <link>/questions/7585/how-to-split-voip-to-saperate-pcap-files-in-easy-way/</link>
      <pubDate>Wed, 23 Nov 2011 10:35:00 +0000</pubDate>
      
      <guid>/questions/7585/how-to-split-voip-to-saperate-pcap-files-in-easy-way/</guid>
      <description>How to split voip to saperate pcap files in easy way  0 Have to large pcap file. How can i get just the voip thereout. I already tried with time selection (-A -B)
pcap split voipasked 23 Nov &#39;11, 10:35
tkwire
1●2●2●3
accept rate: 0%
  
One Answer:
  
2In general splitting up files is easily done with editcap
editcap -c &amp;lt;packets per file&amp;gt; or editcap -i &amp;lt;seconds per file&amp;gt;</description>
    </item>
    
    <item>
      <title>Wireshark shows only PPI protocols</title>
      <link>/questions/7589/wireshark-shows-only-ppi-protocols/</link>
      <pubDate>Wed, 23 Nov 2011 13:46:00 +0000</pubDate>
      
      <guid>/questions/7589/wireshark-shows-only-ppi-protocols/</guid>
      <description>Wireshark shows only PPI protocols  0 When I connect to WiFi network and try to capture packets, I only see PPI protocols in Wireshark and nothing else. How do I get Wireshark to show me more than just PPI?
capture wifi troubleshootingasked 23 Nov &#39;11, 13:46
rajvirg
1●1●1●1
accept rate: 0%
 edited 23 Nov &#39;11, 14:53 
helloworld
3.1k●4●20●41
By &#34;I only see PPI protocols in Wireshark and nothing else&#34;</description>
    </item>
    
    <item>
      <title>Network Tap usage with wireshark</title>
      <link>/questions/7591/network-tap-usage-with-wireshark/</link>
      <pubDate>Wed, 23 Nov 2011 18:26:00 +0000</pubDate>
      
      <guid>/questions/7591/network-tap-usage-with-wireshark/</guid>
      <description>Network Tap usage with wireshark  0 Tap an 100Mbps ethernet with netoptics tap, the tap has two outputs transmit and receive, I have two network adapter but how can I combine intoa single realtime capture?
usage tapasked 23 Nov &#39;11, 18:26
cisoccoip
1●1●1●1
accept rate: 0%
  
3 Answers:
  
0Try the development version of Wireshark, which allows multiple capture interface selection.
answered 23 Nov &#39;11, 23:24</description>
    </item>
    
    <item>
      <title>Strange packets captured.</title>
      <link>/questions/7594/strange-packets-captured/</link>
      <pubDate>Wed, 23 Nov 2011 23:31:00 +0000</pubDate>
      
      <guid>/questions/7594/strange-packets-captured/</guid>
      <description>Strange packets captured.  0 Does anybody have any idea on why the client received so many ACK packets within such a short time?
 16562 16:03:24.960676 122.11.56.106 10.201.228.43 TCP [TCP segment of a reassembled PDU] 16563 16:03:24.961409 10.201.228.43 122.11.56.106 TCP 41945 &amp;gt; 80 [ACK] Seq=305 Ack=4912489 Win=224352 Len=0 TSV=24813 TSER=1978476727 16567 16:03:24.967421 122.11.56.106 10.201.228.43 TCP [TCP segment of a reassembled PDU] 16569 16:03:24.979078 122.11.56.106 10.201.228.43 TCP [TCP segment of a reassembled PDU] 16570 16:03:24.</description>
    </item>
    
    <item>
      <title>Connections to remote server just stall - Seq mismatch?</title>
      <link>/questions/7595/connections-to-remote-server-just-stall-seq-mismatch/</link>
      <pubDate>Thu, 24 Nov 2011 00:05:00 +0000</pubDate>
      
      <guid>/questions/7595/connections-to-remote-server-just-stall-seq-mismatch/</guid>
      <description>Connections to remote server just stall - Seq mismatch?  0 I have an issue I can’t quite figure out. Clients on my network connect to a terminal server on a remote network via a terminal emulator for Windows and perform the normal operations end-users do, but their sessions stall after seemingly random amounts of time (anywhere from 30 seconds to 4 hours). They are left staring at a blank terminal emulator screen and have to force-close the application instance.</description>
    </item>
    
    <item>
      <title>EOF while receiving data from socket.</title>
      <link>/questions/7596/eof-while-receiving-data-from-socket/</link>
      <pubDate>Thu, 24 Nov 2011 00:09:00 +0000</pubDate>
      
      <guid>/questions/7596/eof-while-receiving-data-from-socket/</guid>
      <description>EOF while receiving data from socket.  0 I found that in a TCP connection the java captured EOF exception(0 returned while reading or receiving) while receiving data from remote server and closed the connection, but from the tcpdump, the local side had been receiving data, I don&#39;t understand why the application would receive a EOF error.
This often happens when the peer was receiving data at extremely slow rate, but this doesn&#39;t look like the case.</description>
    </item>
    
    <item>
      <title>Is it possible to change location for data storage for a capture?</title>
      <link>/questions/7607/is-it-possible-to-change-location-for-data-storage-for-a-capture/</link>
      <pubDate>Thu, 24 Nov 2011 03:46:00 +0000</pubDate>
      
      <guid>/questions/7607/is-it-possible-to-change-location-for-data-storage-for-a-capture/</guid>
      <description>Is it possible to change location for data storage for a capture?  0 OS: Windows 7;
I have about 100 Mb of free space on disk C. When I launch capture in Wireshark, this space decreases fast (because of temporary data buffering on hard disk). Through several minutes space is exhausted and capture stops. Can I tell Wireshark to store data to other disk (say, disk D with much free space).</description>
    </item>
    
    <item>
      <title>is it possible to combine several filter names in the filter input text ?</title>
      <link>/questions/7610/is-it-possible-to-combine-several-filter-names-in-the-filter-input-text/</link>
      <pubDate>Thu, 24 Nov 2011 09:21:00 +0000</pubDate>
      
      <guid>/questions/7610/is-it-possible-to-combine-several-filter-names-in-the-filter-input-text/</guid>
      <description>is it possible to combine several filter names in the filter input text ?  0 I think It would be very useful if you could use the name of the filter to create another filters. I&#39;m not sure if you can do that. For instance you create the following filters: arp || smb &amp;lt;-- under the name of LAN rip || eigrp &amp;lt;--- under the name of WAN
so you could search for: LAN OR WAN</description>
    </item>
    
    <item>
      <title>Monitor mode checkbox not working on Debian Sid</title>
      <link>/questions/7618/monitor-mode-checkbox-not-working-on-debian-sid/</link>
      <pubDate>Thu, 24 Nov 2011 17:38:00 +0000</pubDate>
      
      <guid>/questions/7618/monitor-mode-checkbox-not-working-on-debian-sid/</guid>
      <description>Monitor mode checkbox not working on Debian Sid  0 Hello, I&#39;m using Debian, when I go to &#34;Capture Options&#34; and select the wlan0 interface, if I try to set it to monitor mode clicking on the checkbox &#34;Capture packets in monitor mode&#34;, the &#34;Link-layer header type&#34; menu blinks for a second and the checkbox remains blank. The &#34;Link-layer header type&#34; menu shows only two options: &#34;Ethernet&#34; and &#34;DOCSIS&#34;, with both options the monitor mode checkbox has the same behaviour.</description>
    </item>
    
    <item>
      <title>package fields is analysised by config file.field is defined in config file.</title>
      <link>/questions/7620/package-fields-is-analysised-by-config-filefield-is-defined-in-config-file/</link>
      <pubDate>Thu, 24 Nov 2011 19:38:00 +0000</pubDate>
      
      <guid>/questions/7620/package-fields-is-analysised-by-config-filefield-is-defined-in-config-file/</guid>
      <description>package fields is analysised by config file.field is defined in config file.  0 hi!I need wireshark dissect captured packages by a config file. When wireshark started,the config file will be loaded to wireshark,and the captured package will be dissected by the fields name defined in xml file. Every displayed field is defined in xml files,so every field is configurable .Could you help me? Give me an example.Thank you very much!</description>
    </item>
    
    <item>
      <title>identify packet</title>
      <link>/questions/7621/identify-packet/</link>
      <pubDate>Thu, 24 Nov 2011 20:24:00 +0000</pubDate>
      
      <guid>/questions/7621/identify-packet/</guid>
      <description>identify packet  0 I need some assistance getting started with WireShark and identifying the data it is capturing. The source computer is Windows XP and the destination is Windows Server 2008.
Below are a few lines from one packet of a capture. The send computer is IP address 192.10.11.227 (in hex c0 a0 0b e3) and the destination is 192.10.11.222 (in hex c0 a0 0b de) . I think that the sender has the server role while the receiver is client.</description>
    </item>
    
    <item>
      <title>Bytes in flight calculation/plotting</title>
      <link>/questions/7622/bytes-in-flight-calculationplotting/</link>
      <pubDate>Thu, 24 Nov 2011 22:47:00 +0000</pubDate>
      
      <guid>/questions/7622/bytes-in-flight-calculationplotting/</guid>
      <description>Bytes in flight calculation/plotting  0 I&#39;m trying to plot Bytes in flight using the I/O graph but i&#39;m not sure what i&#39;m getting is correct. How does wireshark calculates bytes in flight ? How come when I plot tcp.analysis.bytes_in_flight and ip.dst == &amp;lt; receiver ip&amp;gt;&amp;amp;&amp;amp;tcp.window_size_value I get the same graph?
graph tcpasked 24 Nov &#39;11, 22:47
ddayan
41●15●17●20
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>What are the IGMP Messages doing in my network?</title>
      <link>/questions/7629/what-are-the-igmp-messages-doing-in-my-network/</link>
      <pubDate>Fri, 25 Nov 2011 04:30:00 +0000</pubDate>
      
      <guid>/questions/7629/what-are-the-igmp-messages-doing-in-my-network/</guid>
      <description>What are the IGMP Messages doing in my network?  0 Hey guys,
I´m trying to analyze my networktraffic and I´m not a networking pro, so I got some questions regarding the traffic. If there are stupid I apologize in front.
The first thing I see are three IGMP Messages. 192.168.2.1 224.0.0.22 IGMP 62 V3 Membership Report /Join group 224.0.0.252 for any sources / Join group 239.255.255.254 for any sources</description>
    </item>
    
    <item>
      <title>Special MAC address</title>
      <link>/questions/7630/special-mac-address/</link>
      <pubDate>Fri, 25 Nov 2011 05:09:00 +0000</pubDate>
      
      <guid>/questions/7630/special-mac-address/</guid>
      <description>Special MAC address  0 Hey there,
i came across an interesting MAC address related to a troubleshooting issue.
There was a device using MAC address 19:02:16:08:vw:xy and i wonder where this address comes from. OUI has no info about 19:02:16 - so i googled for the string and found several forums etc. where people asked questions about systems having those MAC addresses. The vendors are widely spread like linksys, dlink, siemens and so on, but all those had this special MAC plus (!</description>
    </item>
    
    <item>
      <title>Wireshark can not capture any TCP packets (not even SYN/ACk )</title>
      <link>/questions/7631/wireshark-can-not-capture-any-tcp-packets-not-even-synack/</link>
      <pubDate>Fri, 25 Nov 2011 07:50:00 +0000</pubDate>
      
      <guid>/questions/7631/wireshark-can-not-capture-any-tcp-packets-not-even-synack/</guid>
      <description>Wireshark can not capture any TCP packets (not even SYN/ACk )  0 I was trying to capture traffci by port spanning on Cisco WS-C3750-48P. Cisco IOS Software, C3750 Software (C3750-IPBASEK9-M), Version 12.2(44)SE2, RELEASE SOFTWARE (fc2)
I can see UDP, ICMP, ARP, DHCP and microsoft stuff.However, I did not see any TCP packets captured, not even TCP SYN/ACK. Is it CIsco port SPAN problem?/IOS Version/ or Wireshark problem? Any ideas? BTW, I&#39;m using promiscurous mode.</description>
    </item>
    
    <item>
      <title>Is there a way to use listen to gsm and 3G frequencies ?</title>
      <link>/questions/7633/is-there-a-way-to-use-listen-to-gsm-and-3g-frequencies/</link>
      <pubDate>Fri, 25 Nov 2011 11:38:00 +0000</pubDate>
      
      <guid>/questions/7633/is-there-a-way-to-use-listen-to-gsm-and-3g-frequencies/</guid>
      <description>Is there a way to use listen to gsm and 3G frequencies ?  0 Is there any way to modify regular 3G cellphone to listen to CDMA and TDMA radio frequencies ?
I would like to know when a given cellphone is around, so I would only need to get 2 things:
A unique identifier doesn&#39;t need to be an IMSI or IMEI, something encrypted would be ok... I just need something that doesn&#39;t change.</description>
    </item>
    
    <item>
      <title>Speed Control</title>
      <link>/questions/7644/speed-control/</link>
      <pubDate>Fri, 25 Nov 2011 22:26:00 +0000</pubDate>
      
      <guid>/questions/7644/speed-control/</guid>
      <description>Speed Control  0 Can i control others wifi speed through my wireshark? I am a newbie to this..
control seedasked 25 Nov &#39;11, 22:26
akbarsha
5●4●4●6
accept rate: 0%
  
One Answer:
  
1 No you can&#39;t. Wireshark is a monitoring tool, which means it reads network frames and interprets them. It does not take an active role, neither injecting frames nor doing any kind of rate limiting.</description>
    </item>
    
    <item>
      <title>I got an error when compiling dissector.</title>
      <link>/questions/7648/i-got-an-error-when-compiling-dissector/</link>
      <pubDate>Sat, 26 Nov 2011 06:04:00 +0000</pubDate>
      
      <guid>/questions/7648/i-got-an-error-when-compiling-dissector/</guid>
      <description>I got an error when compiling dissector.  0 Hi, I had followed the examples (9.1,9.2 and 9.3) given in the following link &#34;http://www.wireshark.org/docs/wsdg_html_chunked/ChDissectAdd.html&#34; to dissect my protocol but i got error when i compiling it on my windows.My protocol name is &#34;TLV&#34;.
Please Help me to fix this error.
error:
packet-tlv.c(29) : error C2065: &#39;dissect_tlv&#39; : undeclared identifier
packet-tlv.c(29) : warning C4047: &#39;function&#39; : &#39;dissector_t&#39; differs in levels o f indirection from &#39;int&#39;</description>
    </item>
    
    <item>
      <title>Wire shark error messsage</title>
      <link>/questions/7651/wire-shark-error-messsage/</link>
      <pubDate>Sat, 26 Nov 2011 06:36:00 +0000</pubDate>
      
      <guid>/questions/7651/wire-shark-error-messsage/</guid>
      <description>Wire shark error messsage  0 When i am going to save my captured packets, it show the following error message, Microsoft Visual C++ runtime library (This application has requested the runtime to terminate it in an unusual way. Please contact the application&#39;s support team for more information) , This is the error message.. Pls help me to over come this..
message errorasked 26 Nov &#39;11, 06:36
akbarsha
5●4●4●6
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Deleting Packets</title>
      <link>/questions/7653/deleting-packets/</link>
      <pubDate>Sat, 26 Nov 2011 07:21:00 +0000</pubDate>
      
      <guid>/questions/7653/deleting-packets/</guid>
      <description>Deleting Packets  0 How to delete the captured packets?( from my computer).. pls help me..
deleting packetasked 26 Nov &#39;11, 07:21
akbarsha
5●4●4●6
accept rate: 0%
  
One Answer:
  
0&#34;Delete captured packets?&#34; Do you mean delete the file containing the captured packets? If you saved to a file, delete the file - otherwise, select Help | About Wireshark | Folders tab and locate your temporary directory.</description>
    </item>
    
    <item>
      <title>Problem creating zlib for Wireshark with VS C&#43;&#43; 2008 Express Edition</title>
      <link>/questions/7657/problem-creating-zlib-for-wireshark-with-vs-c-2008-express-edition/</link>
      <pubDate>Sat, 26 Nov 2011 21:20:00 +0000</pubDate>
      
      <guid>/questions/7657/problem-creating-zlib-for-wireshark-with-vs-c-2008-express-edition/</guid>
      <description>Problem creating zlib for Wireshark with VS C++ 2008 Express Edition  0 First of all, thanks to the contributors to this great tool. I was trying to create a dissector for our protocol. As the first step, I was trying to build the wireshark, so that I have all the tools set up correctly.
I was following instruction Developer&#39;s Guide
The OS is Windows 7. I was using Visual Studio C++ 2008 Express Edition.</description>
    </item>
    
    <item>
      <title>TCP packet size</title>
      <link>/questions/7659/tcp-packet-size/</link>
      <pubDate>Sun, 27 Nov 2011 02:36:00 +0000</pubDate>
      
      <guid>/questions/7659/tcp-packet-size/</guid>
      <description>TCP packet size  0 I captured a TCP stream from a linux server and a linux client (both running backtrack 5 (based on ubuntu 11.04) MSS on server and client = 1460 bytes must packets have a payload of 1448 bytes, yet some packets have larger payloads e.g 7240 = 5*1448
Does that mean the MTU set on the server OS is larger than 1500? if so how do I find the MTU value?</description>
    </item>
    
    <item>
      <title>Won&amp;#x27;t Capture Packets That I Know Are There</title>
      <link>/questions/7664/wont-capture-packets-that-i-know-are-there/</link>
      <pubDate>Sun, 27 Nov 2011 17:24:00 +0000</pubDate>
      
      <guid>/questions/7664/wont-capture-packets-that-i-know-are-there/</guid>
      <description>Won&amp;rsquo;t Capture Packets That I Know Are There  0 Experts,
Does Wireshark have hidden capture filters?
As far as I can tell, I have no capture filters (or display filters) enabled that would restrict the capture (or display) of any packets. Yet I cannot capture traffic between two devices that I know are communicating with each other. I am getting no notification that packets are being dropped.
Running ...</description>
    </item>
    
    <item>
      <title>Can anyone give me the functional syntax and its description to create a dissector?</title>
      <link>/questions/7673/can-anyone-give-me-the-functional-syntax-and-its-description-to-create-a-dissector/</link>
      <pubDate>Mon, 28 Nov 2011 06:19:00 +0000</pubDate>
      
      <guid>/questions/7673/can-anyone-give-me-the-functional-syntax-and-its-description-to-create-a-dissector/</guid>
      <description>Can anyone give me the functional syntax and its description to create a dissector?  0 HI, Currently I put myself to write a dissector, for that first I have to understand the various &#34;functional syntax and its descriptions&#34; involved in dissector creation. Can any one give me the functional syntax for writing a dissector?
I read through the &#34;http://www.wireshark.org/docs/wsdg_html_chunked/ChDissectAdd.html&#34; link, but I need the syntax and description.
Thanks
development dissector pluginasked 28 Nov &#39;11, 06:19</description>
    </item>
    
    <item>
      <title>Help with router information</title>
      <link>/questions/7675/help-with-router-information/</link>
      <pubDate>Mon, 28 Nov 2011 08:43:00 +0000</pubDate>
      
      <guid>/questions/7675/help-with-router-information/</guid>
      <description>Help with router information  0 I am constantly hacked and abused on the internet. I&#39;ve had to figure out a lot of things to get to what was going on and I recently used Wireshark to see if I can find the problem. I use an ethernet cable. There is a Linksys Cisco nat router on it. It is shared by three computers. I have used many different types of firewalls and when I block what appears to be the offender, I get no internet service.</description>
    </item>
    
    <item>
      <title>Capture using a monitor mode of the switch on a dual nic computer</title>
      <link>/questions/7676/capture-using-a-monitor-mode-of-the-switch-on-a-dual-nic-computer/</link>
      <pubDate>Mon, 28 Nov 2011 09:17:00 +0000</pubDate>
      
      <guid>/questions/7676/capture-using-a-monitor-mode-of-the-switch-on-a-dual-nic-computer/</guid>
      <description>Capture using a monitor mode of the switch on a dual nic computer  0 Hi, I&#39;ve been utilizing a Windows XP computer with a second NIC card as a &#34;sniffer&#34; box. I am having a problem where I am not seeing the traffic I expect to see on the capture. I suspect I am doing something wrong on the sniffer box because I have seen this issue on multiple model Cisco switches, running different IOS version.</description>
    </item>
    
    <item>
      <title>mb&amp;#x27;s vs gb&amp;#x27;s</title>
      <link>/questions/7688/mbs-vs-gbs/</link>
      <pubDate>Mon, 28 Nov 2011 11:54:00 +0000</pubDate>
      
      <guid>/questions/7688/mbs-vs-gbs/</guid>
      <description>mb&amp;rsquo;s vs gb&amp;rsquo;s  0 we r trying to run wireshark on our network and we have heard wireshark cannot run on a 1gb network line/switch, is that true and if it is, is there anyway around this? Basically we do not have a sniffer available and we r seeing spikes in network traffic and we need to determine where the increase in network traffic is coming from.
Thanks, Scott Kobel [email protected]</description>
    </item>
    
    <item>
      <title>What is the Importance of Import Text File?</title>
      <link>/questions/7693/what-is-the-importance-of-import-text-file/</link>
      <pubDate>Mon, 28 Nov 2011 23:19:00 +0000</pubDate>
      
      <guid>/questions/7693/what-is-the-importance-of-import-text-file/</guid>
      <description>What is the Importance of Import Text File?  0 If I Import any file either text or pcap, I cannot see any packets on the window but while closing Wireshark asks for saving the file. What is the Use of this Import option? Why cannot we see the packets?
importThis question is marked &#34;community wiki&#34;.asked 28 Nov &#39;11, 23:19
Terrestrial ...
96●21●28●29
accept rate: 42%
There&#39;s no option to &#34;</description>
    </item>
    
    <item>
      <title>INVITE seems as &amp;quot;Fragmented IP Protocol&amp;quot;</title>
      <link>/questions/7697/invite-seems-as-fragmented-ip-protocol/</link>
      <pubDate>Tue, 29 Nov 2011 03:45:00 +0000</pubDate>
      
      <guid>/questions/7697/invite-seems-as-fragmented-ip-protocol/</guid>
      <description>INVITE seems as &amp;ldquo;Fragmented IP Protocol&amp;rdquo;  0 Hi;
Whwn we create a SIP call INVITE do not appears in Wireshark trace. When we filter the trace as SIP the flow starts with &#34;100 Trying&#34;. When i search full trace the psition that belongs to INVITE is covered with &#34;Fragmented IP Protocol&#34;. It seems like wireshark can not produce the INVITE Message normally.
Is there ant option to have INVITE message with correct format with Wireshark?</description>
    </item>
    
    <item>
      <title>dual nic capture</title>
      <link>/questions/7700/dual-nic-capture/</link>
      <pubDate>Tue, 29 Nov 2011 11:28:00 +0000</pubDate>
      
      <guid>/questions/7700/dual-nic-capture/</guid>
      <description>dual nic capture  0 IS there a way to capture from 2 active 10 GB interfaces? I have set up a Linux server with to 10 GB interface to monitor 2 10 GB circuits between our 2 data centers. Interfaces are unnumbered ( layer 2), 1 interface to each switches the circuits terminate on
nic dual captureasked 29 Nov &#39;11, 11:28
sjweinstein
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Build was working on WindowsXP, but now it fails to build in Win7 x64</title>
      <link>/questions/7707/build-was-working-on-windowsxp-but-now-it-fails-to-build-in-win7-x64/</link>
      <pubDate>Tue, 29 Nov 2011 13:38:00 +0000</pubDate>
      
      <guid>/questions/7707/build-was-working-on-windowsxp-but-now-it-fails-to-build-in-win7-x64/</guid>
      <description>Build was working on WindowsXP, but now it fails to build in Win7 x64  0 I have a source tree of Wireshark 1.4.9 that builds grreat in WindowsXP. I am moving to a Windows 7 x64 box now and need it to build there. So I did all the normal stuff (install VS 2008ee, install the right cygwin packages) but I get an error from nmake (see below). There are lots of google hits on the U1045 error code, but they all lead no where.</description>
    </item>
    
    <item>
      <title>How to see set-cookie headers</title>
      <link>/questions/7713/how-to-see-set-cookie-headers/</link>
      <pubDate>Tue, 29 Nov 2011 15:10:00 +0000</pubDate>
      
      <guid>/questions/7713/how-to-see-set-cookie-headers/</guid>
      <description>How to see set-cookie headers  0 How can i see all the set-cookie headers sent to a browser, using wireshark? They at the moment, when doing somehting as simple as signing into yahoo mail, are not visible. I can see requests getting sent by the browser that mysteriously use cookie headers with names/values that are not visible in the preceding responses sent by the server.
cookie http responseasked 29 Nov &#39;11, 15:10</description>
    </item>
    
    <item>
      <title>Close File Dialog and v.1.6x</title>
      <link>/questions/7717/close-file-dialog-and-v16x/</link>
      <pubDate>Wed, 30 Nov 2011 08:17:00 +0000</pubDate>
      
      <guid>/questions/7717/close-file-dialog-and-v16x/</guid>
      <description>Close File Dialog and v.1.6x  0 On a Windows XP, SP2 machine I am getting this hung Close File issue. The only way around it is to define the filename beforehand and have it record multiple files of a specific size. Then when I am finished, I use TaskManager to kill Wireshark. Pretty tedious &amp;amp; not very pretty.
captureasked 30 Nov &#39;11, 08:17
VictorD
1●2●2●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Dsiplaying Optional metadata along with captured packet data in PCAP NG file format</title>
      <link>/questions/7722/dsiplaying-optional-metadata-along-with-captured-packet-data-in-pcap-ng-file-format/</link>
      <pubDate>Wed, 30 Nov 2011 23:18:00 +0000</pubDate>
      
      <guid>/questions/7722/dsiplaying-optional-metadata-along-with-captured-packet-data-in-pcap-ng-file-format/</guid>
      <description>Dsiplaying Optional metadata along with captured packet data in PCAP NG file format  0 Hi,
I am inserting some metadata in Optional field of Evolved Packet Block in PCAP NG file format. I want wireshark to decode and display those metadata info along with captured protocol data. Is there any provion in wireshark to do this. Or if any modification is required in wireshark, how to proceed ??
Please help.</description>
    </item>
    
    <item>
      <title>Problem while filtering frame[x] == ff (or fc)</title>
      <link>/questions/7724/problem-while-filtering-framex-ff-or-fc/</link>
      <pubDate>Thu, 01 Dec 2011 02:12:00 +0000</pubDate>
      
      <guid>/questions/7724/problem-while-filtering-framex-ff-or-fc/</guid>
      <description>Problem while filtering frame[x] == ff (or fc)  0 I can&#39;t filter displayed frames where specific byte is equal ff or fc (eq. frame[4] == ff), the filter sequence is not allowed, filter window turns red. Any solution, please?
filter frame displayasked 01 Dec &#39;11, 02:12
Jenda Nespor
1●1●1●2
accept rate: 0%
  
One Answer:
  
2The problem is because both fc and ff are filters on their own, for &#34;</description>
    </item>
    
    <item>
      <title>ssl decryption</title>
      <link>/questions/7728/ssl-decryption/</link>
      <pubDate>Thu, 01 Dec 2011 08:29:00 +0000</pubDate>
      
      <guid>/questions/7728/ssl-decryption/</guid>
      <description>ssl decryption  0 1Just upgraded to 1.7.0 from 1.6.4 In neither release was ssl decryption working (at least I couldn&#39;t get it to work) Have read the zillions of available googles on the topic. My question is simple - Has anyone actually got this to work with this version ?
Either way I&#39;ll likely give up - but I just wanted to know if someone had actually, with their very own fingers, gotten this to work with 1.</description>
    </item>
    
    <item>
      <title>Does TCP stream graph show some data points incorrectly?</title>
      <link>/questions/7731/does-tcp-stream-graph-show-some-data-points-incorrectly/</link>
      <pubDate>Thu, 01 Dec 2011 10:59:00 +0000</pubDate>
      
      <guid>/questions/7731/does-tcp-stream-graph-show-some-data-points-incorrectly/</guid>
      <description>Does TCP stream graph show some data points incorrectly?  0 Using version 1.6.4, I want to rely on TCP stream graph to chart and summarize RTT for ACKs. I capture data because I&#39;m suspecting some network delay is impacting a unicast HD Video on Demand application I&#39;m testing. This traffic is delivered via HTTP over TCP. Most data points plot in the graph around 30ms value which is okay for my application and normal for my network environment.</description>
    </item>
    
    <item>
      <title>Filtering Captures via Scripts</title>
      <link>/questions/7733/filtering-captures-via-scripts/</link>
      <pubDate>Thu, 01 Dec 2011 14:16:00 +0000</pubDate>
      
      <guid>/questions/7733/filtering-captures-via-scripts/</guid>
      <description>Filtering Captures via Scripts  0 I&#39;d like to write a script (I&#39;m on Windows) to open a WS capture, apply filters to it and write the output to a file.
I can get the correct information out of Wireshark by applying the filters there. How/what should I write a script in to run the file through WS, apply the filters, and then dump the output to a file?
Thanks!</description>
    </item>
    
    <item>
      <title>Why can&amp;#x27;t I see POST or GET HTTP statements?</title>
      <link>/questions/7738/why-cant-i-see-post-or-get-http-statements/</link>
      <pubDate>Fri, 02 Dec 2011 02:27:00 +0000</pubDate>
      
      <guid>/questions/7738/why-cant-i-see-post-or-get-http-statements/</guid>
      <description>Why can&amp;rsquo;t I see POST or GET HTTP statements?  0 Hi,
I have introduced a hub (from the Wireshark hub reference - thanks guys :) ) to my network and all traffic has to go through it.
Problem I have is that, although I am using web sites with online username/password forms, not SSL, I am not seeing any POST or GET statements. In fact, when I go to the email section of a website, one that does not have SSL activated, I am not seeing POST or GET there either.</description>
    </item>
    
    <item>
      <title>Solaris 10 tshark &amp;quot;bus error&amp;quot; when reading some pcap files</title>
      <link>/questions/7742/solaris-10-tshark-bus-error-when-reading-some-pcap-files/</link>
      <pubDate>Fri, 02 Dec 2011 10:12:00 +0000</pubDate>
      
      <guid>/questions/7742/solaris-10-tshark-bus-error-when-reading-some-pcap-files/</guid>
      <description>Solaris 10 tshark &amp;ldquo;bus error&amp;rdquo; when reading some pcap files  0 Can anyone provide me some insight what is the root cause of the following problem &amp;amp; how to fix it? (ie. Do it need to recompile tshark or just have the dependence updated?)
The version of tshark and its dependency are from the sunfreeware.com.
# uname -a SunOS daisy 5.10 Generic_127127-11 sun4u sparc SUNW,Sun-Blade-1500 Solaris # # tshark -r dhcp.</description>
    </item>
    
    <item>
      <title>Unable to decrypt SSL traffic</title>
      <link>/questions/7748/unable-to-decrypt-ssl-traffic/</link>
      <pubDate>Fri, 02 Dec 2011 12:32:00 +0000</pubDate>
      
      <guid>/questions/7748/unable-to-decrypt-ssl-traffic/</guid>
      <description>Unable to decrypt SSL traffic  0 I am attempting to decrypt ssl communication for troublshooting purposes but am unable to decode the traffic. It looks like there is a problem with not enough data to generate the key based on the debug log.
This part of the log file seems to be the same each time I try to decrypt something. The portion after this changes as I try different applications/protocols</description>
    </item>
    
    <item>
      <title>missing capture</title>
      <link>/questions/7756/missing-capture/</link>
      <pubDate>Sat, 03 Dec 2011 15:45:00 +0000</pubDate>
      
      <guid>/questions/7756/missing-capture/</guid>
      <description>missing capture  0 I just installed wireshark and have no capture, or display filters active.
Wireshark is missing a lot of messages that do show up on Microsoft Network Monitor. e.g. Some that are missing are marked as DNS and others as TCP in the Microsoft application.
I presume I&#39;ve got something set up wrong, any suggestions how to get the complete capture in wireshark too would be much appreciated :)</description>
    </item>
    
    <item>
      <title>[closed] network issue about fsk ack</title>
      <link>/questions/7763/network-issue-about-fsk-ack/</link>
      <pubDate>Sun, 04 Dec 2011 23:30:00 +0000</pubDate>
      
      <guid>/questions/7763/network-issue-about-fsk-ack/</guid>
      <description>[closed] network issue about fsk ack  0 No. ms Time Source Destination Protocol Length Frame is marked Info time delta 4872 0.298604 298.604 58.718061 10.211.135.98 172.19.98.20 TCP 216 FALSE sbl &amp;gt; 10820 [PSH, ACK] Seq=153133 Ack=173997 Win=64635 Len=162 4872 3751 0.253973 253.973 43.625935 10.211.135.98 172.19.98.20 TCP 188 FALSE sbl &amp;gt; 10820 [PSH, ACK] Seq=117741 Ack=133473 Win=65355 Len=134 3751 1619 0.253584 253.584 19.216507 10.211.135.98 172.19.98.20 TCP 216 FALSE sbl &amp;gt; 10820 [PSH, ACK] Seq=49367 Ack=56011 Win=64275 Len=162 1619 5012 0.</description>
    </item>
    
    <item>
      <title>Can I start a monitor and then log off/on as a new user?</title>
      <link>/questions/7768/can-i-start-a-monitor-and-then-log-offon-as-a-new-user/</link>
      <pubDate>Mon, 05 Dec 2011 07:18:00 +0000</pubDate>
      
      <guid>/questions/7768/can-i-start-a-monitor-and-then-log-offon-as-a-new-user/</guid>
      <description>Can I start a monitor and then log off/on as a new user?  0 OK, so here&#39;s my strange setup.
I have an XP machine that we need to monitor the traffic on. This machine runs a special program under a special User ID. When that ID is logged on, the whole machine is locked down and it loads up the program it runs. There is no way to get to the start bar or the desktop or anything.</description>
    </item>
    
    <item>
      <title>capture length with 60 bytes</title>
      <link>/questions/7769/capture-length-with-60-bytes/</link>
      <pubDate>Mon, 05 Dec 2011 07:26:00 +0000</pubDate>
      
      <guid>/questions/7769/capture-length-with-60-bytes/</guid>
      <description>capture length with 60 bytes  0 Hi,
I have, on my hp switch log with : &#34;A device on port 24 is transmitting packets shorter than 64 bytes or longer than 1518 bytes (longer than 1522 bytes if tagged), with valid CRCs&#34;
I capture the traffic with monitoring the port in default and a lot of packets have a length of 60 bytes, can i conclude that the equipement connected to my procurve send wrong packet ?</description>
    </item>
    
    <item>
      <title>period online</title>
      <link>/questions/7791/period-online/</link>
      <pubDate>Tue, 06 Dec 2011 01:33:00 +0000</pubDate>
      
      <guid>/questions/7791/period-online/</guid>
      <description>period online  0 I want to use Wireshark to check how much time my kids spend in front of the computer by seeing how long they were online. Is there a simple command or filter to see that?
timeasked 06 Dec &#39;11, 01:33
schwar42
1●1●1●1
accept rate: 0%
There are much easier ways to realize that e.g. buy a router with monitoring support and/or &#34;child safety&#34; features
(06 Dec &#39;11, 02:33) LandiI could say so much here.</description>
    </item>
    
    <item>
      <title>Getting the request URL for a reassembled PDU</title>
      <link>/questions/7794/getting-the-request-url-for-a-reassembled-pdu/</link>
      <pubDate>Tue, 06 Dec 2011 02:17:00 +0000</pubDate>
      
      <guid>/questions/7794/getting-the-request-url-for-a-reassembled-pdu/</guid>
      <description>Getting the request URL for a reassembled PDU  1 I am writing a lua script to process json responses. What I have so far follows below. My script runs for each json response returned from the server; it&#39;s based off one of the examples.
The problem I have is that some of the responses are identical to each other, but the interpretation of the data is context dependent. The context is the API URL that was used to make the request.</description>
    </item>
    
    <item>
      <title>TShark saving interface list into file doesn&amp;#x27;t work</title>
      <link>/questions/7799/tshark-saving-interface-list-into-file-doesnt-work/</link>
      <pubDate>Tue, 06 Dec 2011 05:02:00 +0000</pubDate>
      
      <guid>/questions/7799/tshark-saving-interface-list-into-file-doesnt-work/</guid>
      <description>TShark saving interface list into file doesn&amp;rsquo;t work  0 Hi,
I have problem with tshark when I&#39;m trying to save interface list into a file. I used comand: tshark.exe -D &amp;gt; file.txt and file was created but it is empty. In console I can see list of my interfaces. I&#39;m using wireshark 1.6.4 and have this problem. On wireshark 1.4.2 all works fine.
interface list tsharkasked 06 Dec &#39;11, 05:02</description>
    </item>
    
    <item>
      <title>How to decode CORBA over SSL?</title>
      <link>/questions/7800/how-to-decode-corba-over-ssl/</link>
      <pubDate>Tue, 06 Dec 2011 06:44:00 +0000</pubDate>
      
      <guid>/questions/7800/how-to-decode-corba-over-ssl/</guid>
      <description>How to decode CORBA over SSL?  0 Hello!
I&#39;m trying to analyse CORBA traffic encrypted with SSL. I&#39;ve clicked on the &#34;RSA keys list&#34; Edit button, opened the dialog to add a new entry, but when I try to set the protocol to GIOP, I get this error message:
error in column &#39;Protocol&#39;: Could not find dissector for: &#39;GIOP&#39;
What protocol shall I use for CORBA? I can see clear text CORBA communication, so Wireshark can definitely decode the GIOP protocol.</description>
    </item>
    
    <item>
      <title>Detect all conversation with a FIN packet</title>
      <link>/questions/7802/detect-all-conversation-with-a-fin-packet/</link>
      <pubDate>Tue, 06 Dec 2011 07:18:00 +0000</pubDate>
      
      <guid>/questions/7802/detect-all-conversation-with-a-fin-packet/</guid>
      <description>Detect all conversation with a FIN packet  0 How can I detect/print all conversation that (will) have a FIN packet within an existing capture file.
I&#39;m aiming at tshark usage.
finasked 06 Dec &#39;11, 07:18
Trevor
41●4●4●8
accept rate: 0% 
  
One Answer:
  
1 One way would be to actually filter for tcp.flags.fin==1 and then look for unique identifiers for that particular session. This could be tcp.</description>
    </item>
    
    <item>
      <title>Wireshark can&amp;#x27;t see Mac wireless interface</title>
      <link>/questions/7811/wireshark-cant-see-mac-wireless-interface/</link>
      <pubDate>Tue, 06 Dec 2011 20:34:00 +0000</pubDate>
      
      <guid>/questions/7811/wireshark-cant-see-mac-wireless-interface/</guid>
      <description>Wireshark can&amp;rsquo;t see Mac wireless interface  0 Hey,
I&#39;m trying to monitor my wireless network but I can&#39;t see the interface in the capture options.
Network Utility lists it as active, and it is active under the Preferences -&amp;gt; Network pane.
Am I missing something?
wireless interface macintoshasked 06 Dec &#39;11, 20:34
ASGR
20●4●4●8
accept rate: 0%
 edited 07 Dec &#39;11, 08:50 
multipleinte...
1.3k●15●23●40
Can you see any interfaces?</description>
    </item>
    
    <item>
      <title>Lua Listener - TCP flags</title>
      <link>/questions/7816/lua-listener-tcp-flags/</link>
      <pubDate>Wed, 07 Dec 2011 03:18:00 +0000</pubDate>
      
      <guid>/questions/7816/lua-listener-tcp-flags/</guid>
      <description>Lua Listener - TCP flags  0 I&#39;ve written a small Lua Listener.
I wish to visit every TCP packet received.
Here&#39;s how I declare the tap:
 local tap = Listener.new(&amp;quot;tcp&amp;quot;)And here&#39;s how I try to take the flags state.
 if (tcp.flags) thenWithin the tcp.packet method.
The code does not work as I expect it to work. I want to be able to grab to TCP flags state.</description>
    </item>
    
    <item>
      <title>Bandwidth usage</title>
      <link>/questions/7820/bandwidth-usage/</link>
      <pubDate>Wed, 07 Dec 2011 07:23:00 +0000</pubDate>
      
      <guid>/questions/7820/bandwidth-usage/</guid>
      <description>Bandwidth usage  0 Hi there,
I´m pretty new to Wireshark. So maybe you can answer me a question about sniffing my LAN.
Is there a possibility to see which IP address is using a high level of bandwidth? The best thing would be a new column in the capture pane, like MBit/s. I didn´t find anything in the wiki, so maybe you know even if it´s possible.
I was thinking of something like this:</description>
    </item>
    
    <item>
      <title>I can only see limited IP addresses</title>
      <link>/questions/7822/i-can-only-see-limited-ip-addresses/</link>
      <pubDate>Wed, 07 Dec 2011 07:32:00 +0000</pubDate>
      
      <guid>/questions/7822/i-can-only-see-limited-ip-addresses/</guid>
      <description>I can only see limited IP addresses  0 Ok, I am new to Wireshark so I am still learning...
The problem I am having is:
I start Wireshark and a gazillion lines appear - but it is only a few of the IP addresses on the network (maybe 10 IPs out of 1300!). I have tried changing the filter to TCP &amp;amp; HTTP and I still only see a few IPs, what am I doing wrong?</description>
    </item>
    
    <item>
      <title>Lua - passing arguments to a script</title>
      <link>/questions/7824/lua-passing-arguments-to-a-script/</link>
      <pubDate>Wed, 07 Dec 2011 07:51:00 +0000</pubDate>
      
      <guid>/questions/7824/lua-passing-arguments-to-a-script/</guid>
      <description>Lua - passing arguments to a script  2 How can I pass arguments (from the command line) to a tshark/Lua script?
Specifically, I&#39;m interested in having a DEBUG flag, that changes the script&#39;s logics.
lua tsharkasked 07 Dec &#39;11, 07:51
Trevor
41●4●4●8
accept rate: 0% 
 edited 07 Dec &#39;11, 07:52 
  
3 Answers:
  
3[This is a really old question, but I came upon it while searching through Lua-related questions and thought it should be updated]</description>
    </item>
    
    <item>
      <title>Lua - Efficient tables</title>
      <link>/questions/7826/lua-efficient-tables/</link>
      <pubDate>Wed, 07 Dec 2011 09:18:00 +0000</pubDate>
      
      <guid>/questions/7826/lua-efficient-tables/</guid>
      <description>Lua - Efficient tables  0 I&#39;ve written a small script, that logs some data about each connection.
Each connection is uniquely identified by IP1,port1,IP2,port2 - where direction doesn&#39;t matter.
For small dumps - the script works fine.
However,
as the dumps get bigger, and the number of unique connections follows - the table becomes very large - making the key look-up very long.
Can anyone suggest an efficient way/structure to handle/map unique connections.</description>
    </item>
    
    <item>
      <title>Better JSON access?</title>
      <link>/questions/7843/better-json-access/</link>
      <pubDate>Thu, 08 Dec 2011 00:51:00 +0000</pubDate>
      
      <guid>/questions/7843/better-json-access/</guid>
      <description>Better JSON access?  0 Surely there&#39;s got to be a better way to dump out the JSON text that this?
...Stu
do local json_fe = Field.new(&amp;quot;json&amp;quot;) local tap = Listener.new(&amp;quot;http&amp;quot;, &amp;quot;http.content_type contains \&amp;quot;json\&amp;quot;&amp;quot;) function decode(c) return string.char(tonumber(c, 16)) end
function tap.reset() end
function tap.packet(pinfo, tvb, ip) local json = json_fe()
-- The extra ()s in the next line is to discard the second returned value from gsub -- We only want to output the json object print((tostring(json.</description>
    </item>
    
    <item>
      <title>negative times in merged capture</title>
      <link>/questions/7847/negative-times-in-merged-capture/</link>
      <pubDate>Thu, 08 Dec 2011 07:39:00 +0000</pubDate>
      
      <guid>/questions/7847/negative-times-in-merged-capture/</guid>
      <description>negative times in merged capture  0 I have several voip captures which I merged using the Merge Packets Chronologically option, but when I open the merged file, and then go to telephony/voip calls I see negative start and stop times. What does this mean?
negativetimes mergepcapasked 08 Dec &#39;11, 07:39
Joe Garry
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Null / Loopback Link encapsulation conversion</title>
      <link>/questions/7849/null-loopback-link-encapsulation-conversion/</link>
      <pubDate>Thu, 08 Dec 2011 12:12:00 +0000</pubDate>
      
      <guid>/questions/7849/null-loopback-link-encapsulation-conversion/</guid>
      <description>Null / Loopback Link encapsulation conversion  0 Hello All...I&#39;m stuck.
I&#39;m on OSX 10.6 and I captured on the VPN tunnel interface (Juniper Network Connect jnc0). Wireshark is able to read the file just fine, but when I go to use &#34;advanced&#34; analysis system it tells me that the file is corrupt. I recapture, same problem. I can see that the file has an encapsulation of &#34;Null / Loopback&#34; so I use editcap to switch to ether - well, it&#39;s NOT ether and simply changing the encapsulation identifier isn&#39;t going to fix the problem.</description>
    </item>
    
    <item>
      <title>What installer should I use on Windows 7?</title>
      <link>/questions/7850/what-installer-should-i-use-on-windows-7/</link>
      <pubDate>Thu, 08 Dec 2011 12:33:00 +0000</pubDate>
      
      <guid>/questions/7850/what-installer-should-i-use-on-windows-7/</guid>
      <description>What installer should I use on Windows 7?  0 Currently, I am working with Windows7. What installer package should I use?
windows7 installationasked 08 Dec &#39;11, 12:33
gred
1●1●1●1
accept rate: 0%
 edited 08 Dec &#39;11, 13:03 
multipleinte...
1.3k●15●23●40
  
One Answer:
  
1 You should use either the 32-Bit or 64-Bit Windows installer from the Wireshark Downloads page as appropriate for your architecture.</description>
    </item>
    
    <item>
      <title>What is the vertical line with &amp;quot;W&amp;quot; on VOIP decoded RTP streams?</title>
      <link>/questions/7854/what-is-the-vertical-line-with-w-on-voip-decoded-rtp-streams/</link>
      <pubDate>Thu, 08 Dec 2011 15:37:00 +0000</pubDate>
      
      <guid>/questions/7854/what-is-the-vertical-line-with-w-on-voip-decoded-rtp-streams/</guid>
      <description>What is the vertical line with &amp;ldquo;W&amp;rdquo; on VOIP decoded RTP streams?  0 When I decode a VOIP call, I see vertical lines in the RTP player. Most of them are yellow with a &#34;W&#34; beside it. Some are red with a &#34;D&#34; (I believ) beside it. They are obviously located where the sound quality is bad. How do I learn more about those errors? Thanks Dan
decode player rtp voipasked 08 Dec &#39;11, 15:37</description>
    </item>
    
    <item>
      <title>how to synchronize voip RTP player with packet list view?</title>
      <link>/questions/7855/how-to-synchronize-voip-rtp-player-with-packet-list-view/</link>
      <pubDate>Thu, 08 Dec 2011 15:42:00 +0000</pubDate>
      
      <guid>/questions/7855/how-to-synchronize-voip-rtp-player-with-packet-list-view/</guid>
      <description>how to synchronize voip RTP player with packet list view?  0 I do have some obvious errors in VOIP calls. Those are visible and sometimes only recognizable by listening (either in the RTP player or an external audio recording. Is there a way to &#34;synchronize&#34; what I see/hear in the RTP player, with the actual packet list? Thanks Dan
player rtp voipasked 08 Dec &#39;11, 15:42
piuslor
1●3●3●5
accept rate: 100%</description>
    </item>
    
    <item>
      <title>[closed] How to capture GRE packets on MAC 10.7.x</title>
      <link>/questions/7859/how-to-capture-gre-packets-on-mac-107x/</link>
      <pubDate>Thu, 08 Dec 2011 18:37:00 +0000</pubDate>
      
      <guid>/questions/7859/how-to-capture-gre-packets-on-mac-107x/</guid>
      <description>[closed] How to capture GRE packets on MAC 10.7.x  0 Hi,
I intallled Wireshark(1.6.4) into my Mac book air and am using 3rd party USB Ethernet adapter(LUA3-U2-AGT). I would like to capture GRE packets in this environment, but I cannot see them.. Is this a problem of NIC? or my setting on Wireshark? Does anyone have a resolution for that?
Thanks in advance, Yutaka
greasked 08 Dec &#39;11, 18:37</description>
    </item>
    
    <item>
      <title>Macro with matches</title>
      <link>/questions/7865/macro-with-matches/</link>
      <pubDate>Fri, 09 Dec 2011 00:20:00 +0000</pubDate>
      
      <guid>/questions/7865/macro-with-matches/</guid>
      <description>Macro with matches  0 Hi, I was trying to define some macros using the matches operator but I get not result, just a error of the macro definition. After reading the wireshark doc I get no error with that example but what I want to set is something like:
tcp matches &#34;([x90])\1{$1,}&#34; --&amp;gt; this would find $1 times the x90 opcode. I&#39;ve called this macro BO and I&#39;ve tried the following without success.</description>
    </item>
    
    <item>
      <title>Closing file please wait</title>
      <link>/questions/7867/closing-file-please-wait/</link>
      <pubDate>Fri, 09 Dec 2011 06:11:00 +0000</pubDate>
      
      <guid>/questions/7867/closing-file-please-wait/</guid>
      <description>Closing file please wait  0 Hi WireShark
I set the capture to 100 mega-by-file to a SCSI disk. It&#39;s ok but the window &#34;Closing Wait&#34; is blocked. I am forced to kill the task. What should I do? Thank you for your response.
Marc
closing fileasked 09 Dec &#39;11, 06:11
mcado
1●1●1●1
accept rate: 0%
  
One Answer:
  
2This sounds like bug 3046.
I know on my Windows host I can click on the Closing Wait window and select Alt+F4 to kill that window and move forward.</description>
    </item>
    
    <item>
      <title>howto count total IP size of a capture</title>
      <link>/questions/7870/howto-count-total-ip-size-of-a-capture/</link>
      <pubDate>Fri, 09 Dec 2011 07:04:00 +0000</pubDate>
      
      <guid>/questions/7870/howto-count-total-ip-size-of-a-capture/</guid>
      <description>howto count total IP size of a capture  0 Hello,
I would like to get a total IP size of captured packets. I am asking IP size, not total size of the packets (with ethernet header included for example).
Thank you, G. Husson
count ip total sizeasked 09 Dec &#39;11, 07:04
thalos_ghusson
1●1●1●1
accept rate: 0%
  
2 Answers:
  
2Try TShark Statistics
$ tshark -r Clmt_04.</description>
    </item>
    
    <item>
      <title>How do I identify every IP address on my local network?</title>
      <link>/questions/7876/how-do-i-identify-every-ip-address-on-my-local-network/</link>
      <pubDate>Fri, 09 Dec 2011 08:55:00 +0000</pubDate>
      
      <guid>/questions/7876/how-do-i-identify-every-ip-address-on-my-local-network/</guid>
      <description>How do I identify every IP address on my local network?  0 Hello,
I live in a flat with 5 other people and I want to find out the IP address for each computer in my flat, in each room there is a telephone port to connect each computer to the internet via a Ethernet cable, pleas help.
many thanks Andy
ip lan dhcpasked 09 Dec &#39;11, 08:55
andypickleto...</description>
    </item>
    
    <item>
      <title>&amp;quot;wireshark cookie dump&amp;quot; appears in mail</title>
      <link>/questions/7880/wireshark-cookie-dump-appears-in-mail/</link>
      <pubDate>Fri, 09 Dec 2011 09:56:00 +0000</pubDate>
      
      <guid>/questions/7880/wireshark-cookie-dump-appears-in-mail/</guid>
      <description>&amp;ldquo;wireshark cookie dump&amp;rdquo; appears in mail  0 I&#39;ve recently installed Wireshark on my Macbook Pro. Since doing so, whenever I head over to http://jsfiddle.net, all of the input fields are pre-populated with
Wireshark Cookie Dump:
OKCancel
So I went ahead and did a Google search for &#34;Wireshark Cookie Dump&#34; and discovered thousands of results with the exact same problem at various sites across the internets.
Why on earth is this happening, and how can it be stopped?</description>
    </item>
    
    <item>
      <title>Understanding Wireshark</title>
      <link>/questions/7882/understanding-wireshark/</link>
      <pubDate>Fri, 09 Dec 2011 10:14:00 +0000</pubDate>
      
      <guid>/questions/7882/understanding-wireshark/</guid>
      <description>Understanding Wireshark  -3 What do the different colors mean?Why does my computer get packets that are addressed to another machine?How many packets does your computer send/receive in a single mouse click when you visit a Web site?Could you organize or filter the traffic to make it easier to understand?Why does my computer send so many packets? Why not send just on BIG packet?What do SYN, ACK, FIND, GET mean?Why do some packets have sequence numbers?</description>
    </item>
    
    <item>
      <title>SSL decrypting problem</title>
      <link>/questions/7886/ssl-decrypting-problem/</link>
      <pubDate>Fri, 09 Dec 2011 11:51:00 +0000</pubDate>
      
      <guid>/questions/7886/ssl-decrypting-problem/</guid>
      <description>SSL decrypting problem  0 1We set up a test environment to experiment with sniffing related attacks. Basically it is an Apache2 server using https authenticating against an LDAP Active Directory. We have several pcap captures using tcpdump, tshark and wireshark done while users were authenticating. As the authentication involves the external LDAP server Apache can&#39;t use other method than basic plain text, so it should be pretty straightforward for an attacker to capture the data, and use the private key (providing he somehow manage to get it) to obtain the login information and cause havoc.</description>
    </item>
    
    <item>
      <title>tshark batch file</title>
      <link>/questions/7894/tshark-batch-file/</link>
      <pubDate>Sat, 10 Dec 2011 13:17:00 +0000</pubDate>
      
      <guid>/questions/7894/tshark-batch-file/</guid>
      <description>tshark batch file  0 hey all, I am trying to make a windows batch script for tshark.
here is the tshark command I use
tshark -V -r file.pcap -T fields -E header=y -E separator=% -e wlan.sa -e ip.src -e wlan.da -e ip.dst &amp;gt; file.csv
I want to create a batch to ask where the folder is for the pcap, what the name of the pcap is and where to write the csv file.</description>
    </item>
    
    <item>
      <title>number of open ports</title>
      <link>/questions/7896/number-of-open-ports/</link>
      <pubDate>Sun, 11 Dec 2011 12:54:00 +0000</pubDate>
      
      <guid>/questions/7896/number-of-open-ports/</guid>
      <description>number of open ports  0 how can i tell how many tcp ports are open in a capture file and which ports are open
open ports tcpasked 11 Dec &#39;11, 12:54
rms
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Select Statistics | Endpoint List | TCP (IPv4 &amp;amp; IPv6) to see individual TCP ports in use (and the IP address in packets containing those ports).</description>
    </item>
    
    <item>
      <title>How do I fix error with contents of current_tag.txt during Wireshark build</title>
      <link>/questions/7902/how-do-i-fix-error-with-contents-of-current_tagtxt-during-wireshark-build/</link>
      <pubDate>Sun, 11 Dec 2011 17:54:00 +0000</pubDate>
      
      <guid>/questions/7902/how-do-i-fix-error-with-contents-of-current_tagtxt-during-wireshark-build/</guid>
      <description>How do I fix error with contents of current_tag.txt during Wireshark build  0 I&#39;ve run nmake -f Makefile.nmake setup with out any errors. When I run nmake -f Makefile.nmake check_libs I get:
ERROR: The contents of C:\wireshark-win32-libs\current_tag.txt is (unknown). It should be 2011-06-27.
Wireshark is ready to build.
Then when I run nmake -f Makefile.nmake all I get this error:
ERROR: The contents of C:\wireshark-win32-libs\current_tag.txt is (unknown). It should be 2011-06-27.</description>
    </item>
    
    <item>
      <title>Working of Dumpcap</title>
      <link>/questions/7909/working-of-dumpcap/</link>
      <pubDate>Mon, 12 Dec 2011 02:39:00 +0000</pubDate>
      
      <guid>/questions/7909/working-of-dumpcap/</guid>
      <description>Working of Dumpcap  0 How does Dumpcap work? Does it use pcap_open() or pcap_open_live() function? I got errors while running my custom Packet injector like:
`c:\pi&amp;gt; pi rpcap://my_device_name
ERROR: &#34;Unable to open my_device_name. my_device_name is not supported by Winpcap.&#34;`
I came to know that dumpcap use these Functions. May I know how you Resolved this?
winpcap pcapThis question is marked &#34;community wiki&#34;.asked 12 Dec &#39;11, 02:39
Terrestrial ...
96●21●28●29</description>
    </item>
    
    <item>
      <title>Find out email and password of an .exe data with Wireshark.</title>
      <link>/questions/7911/find-out-email-and-password-of-an-exe-data-with-wireshark/</link>
      <pubDate>Mon, 12 Dec 2011 05:47:00 +0000</pubDate>
      
      <guid>/questions/7911/find-out-email-and-password-of-an-exe-data-with-wireshark/</guid>
      <description>Find out email and password of an .exe data with Wireshark.  0 A few days ago, I downloaded a simple program. The program sends data you can enter in message fields to a certain email. Somehow the email sends it to itself so the password must be the same as programmed in the program. I tried to change the password of the email address and the program didn&#39;t work anymore.</description>
    </item>
    
    <item>
      <title>How to identify any rogue dns requests using wireshark?</title>
      <link>/questions/7914/how-to-identify-any-rogue-dns-requests-using-wireshark/</link>
      <pubDate>Mon, 12 Dec 2011 08:48:00 +0000</pubDate>
      
      <guid>/questions/7914/how-to-identify-any-rogue-dns-requests-using-wireshark/</guid>
      <description>How to identify any rogue dns requests using wireshark?  0 Hi, I am an administrator of a college and management is looking for a solution in order to identify if there are any rogue DNS requests to our DNS servers? I have set a packet capture for 24 hours to provide enough requests for analysis.
Thank you
rogue dnsasked 12 Dec &#39;11, 08:48
staramod
1●1●1●2
accept rate: 0%
 edited 12 Dec &#39;11, 08:56</description>
    </item>
    
    <item>
      <title>What should the sequence number of a TCP/RST packet be after a TCP/FIN</title>
      <link>/questions/7915/what-should-the-sequence-number-of-a-tcprst-packet-be-after-a-tcpfin/</link>
      <pubDate>Mon, 12 Dec 2011 09:41:00 +0000</pubDate>
      
      <guid>/questions/7915/what-should-the-sequence-number-of-a-tcprst-packet-be-after-a-tcpfin/</guid>
      <description>What should the sequence number of a TCP/RST packet be after a TCP/FIN  1 1I&#39;m troubleshooting an issue and it seems the receiver is not handling a RST packet. In this case the client sends a frame of data and then a frame with FIN set. The server responds with a couple of frames with data. This data trigger the client to send a RST. Should the sequence number of this RST be the same as the sequence number of the FIN?</description>
    </item>
    
    <item>
      <title>rtp.timestamp units</title>
      <link>/questions/7916/rtptimestamp-units/</link>
      <pubDate>Mon, 12 Dec 2011 11:10:00 +0000</pubDate>
      
      <guid>/questions/7916/rtptimestamp-units/</guid>
      <description>rtp.timestamp units  0 What are the units of rtp.timestamp? When I capture RTP traffic, I have a field under Real-Time Transport Protocol that shows TimeStamp = 2218552874.
What are the units of this number (sec, ms, usec, nsec)? And where does it come from? Mac Layer? Libpcap? System clock?
timestamp rtpasked 12 Dec &#39;11, 11:10
AminGho
51●4●4●8
accept rate: 0%
 edited 30 Dec &#39;11, 14:06 
helloworld
3.1k●4●20●41</description>
    </item>
    
    <item>
      <title>TShark CSV output problem</title>
      <link>/questions/7926/tshark-csv-output-problem/</link>
      <pubDate>Mon, 12 Dec 2011 14:02:00 +0000</pubDate>
      
      <guid>/questions/7926/tshark-csv-output-problem/</guid>
      <description>TShark CSV output problem  0 Hi all, I am trying to create a nice CSV file from a trace, but instead of a readable CSV file I get a file with all sorts of characters all over the place. Am I doing something wrong with encoding or so (windows)? the command I used is below:
tshark.exe -T fields -E separator=, -E quote=d -e frame.number -e ip.dst -e ip.src -e eth.</description>
    </item>
    
    <item>
      <title>TCP flags capture filter</title>
      <link>/questions/7947/tcp-flags-capture-filter/</link>
      <pubDate>Tue, 13 Dec 2011 09:18:00 +0000</pubDate>
      
      <guid>/questions/7947/tcp-flags-capture-filter/</guid>
      <description>TCP flags capture filter  1 With the &#34;Wireshark: Capture Options&#34; dialog, I&#39;m trying to use a custom &#34;Capture Filter&#34;
I want to capture reset packets only (display filter equivalent: tcp.flags.reset ==1)
filter capture flags tcp resetasked 13 Dec &#39;11, 09:18
Peter_Clark
16●1●2
accept rate: 0%
  
One Answer:
  
2On older versions of UN*X, the command man tcpdump will give, among other things, documentation about capture filters; on newer versions, man pcap-filter will give that documentation.</description>
    </item>
    
    <item>
      <title>Password promiscuous mode</title>
      <link>/questions/7950/password-promiscuous-mode/</link>
      <pubDate>Tue, 13 Dec 2011 13:04:00 +0000</pubDate>
      
      <guid>/questions/7950/password-promiscuous-mode/</guid>
      <description>Password promiscuous mode  0 HI everyone
So I am trying some experimentation: I have disabled wifi security and i go on http website. If I capture from my PC I can see my trafic and can get my password and login send without security. If I ask some one to go on this website from an other pc I can see everything where is going but I can&#39;t see his password.</description>
    </item>
    
    <item>
      <title>Want to see ALL individual 802.11 frames</title>
      <link>/questions/7952/want-to-see-all-individual-80211-frames/</link>
      <pubDate>Tue, 13 Dec 2011 17:46:00 +0000</pubDate>
      
      <guid>/questions/7952/want-to-see-all-individual-80211-frames/</guid>
      <description>Want to see ALL individual 802.11 frames  0 I am currently using AirPcap Nx and Wireshark, and I want to be sure that I am not missing any individual 802.11 frames. In particular, if I see a packet that Wireshark labels LLC, TCP, RTMP, HTTP, etc., is this still a single 802.11 packet communicated over the air interface OR is such a packet an aggregation of multiple 802.11 packets or fragments.</description>
    </item>
    
    <item>
      <title>wifi probe-request/response takes too long</title>
      <link>/questions/7954/wifi-probe-requestresponse-takes-too-long/</link>
      <pubDate>Wed, 14 Dec 2011 03:19:00 +0000</pubDate>
      
      <guid>/questions/7954/wifi-probe-requestresponse-takes-too-long/</guid>
      <description>wifi probe-request/response takes too long  0 In my trace I can see few of probe responses until authentication request is sent. I was wondering why probe Request /Response takes around 3 seconds when there&#39;s good signal between the client and the AP, while authentication Req/Resp and association Req/Resp packets take few mili seconds.
The client is using ubuntu and iwconfig with the Ap&#39;s MAC address specified
802.11asked 14 Dec &#39;11, 03:19</description>
    </item>
    
    <item>
      <title>Wireshark in Dos</title>
      <link>/questions/7955/wireshark-in-dos/</link>
      <pubDate>Wed, 14 Dec 2011 03:29:00 +0000</pubDate>
      
      <guid>/questions/7955/wireshark-in-dos/</guid>
      <description>Wireshark in Dos  0 Hi guys Does anyone know if you can use wireshark from DOS, basically, i m trying to read the wireshark output in labview. I would aim on sending to the DOS prompt the wireshark command to report back the traffic on a network and then read this in to labview for analysis. Any ideas would be greatly appreciated?? I am afraid i m a wireshark virgin really.</description>
    </item>
    
    <item>
      <title>ACKed lost segments - false positive?</title>
      <link>/questions/7972/acked-lost-segments-false-positive/</link>
      <pubDate>Wed, 14 Dec 2011 09:48:00 +0000</pubDate>
      
      <guid>/questions/7972/acked-lost-segments-false-positive/</guid>
      <description>ACKed lost segments - false positive?  0 Hi,
not sure if I am too dumb to get that right, but I am puzzled by that finding:
In a 30-sec trace I found quite a few packet pairs, each one for another socket/stream (and the only packets for those sockets(/streams during the captured period at all) like that one:
Time Source Destination Protocol Info 407 2011-12-14 17:17:30.182151 172.17.55.50 172.17.55.73 TCP 48730 &amp;gt; 33779 [ACK] Seq=1 Ack=1 Win=294 Len=0 TSV=3645344977 TSER=2526914065 408 2011-12-14 17:17:30.</description>
    </item>
    
    <item>
      <title>Wireshark setup Linux for nonroot user</title>
      <link>/questions/7976/wireshark-setup-linux-for-nonroot-user/</link>
      <pubDate>Wed, 14 Dec 2011 10:19:00 +0000</pubDate>
      
      <guid>/questions/7976/wireshark-setup-linux-for-nonroot-user/</guid>
      <description>Wireshark setup Linux for nonroot user  2 1Hello there
I&#39;ve setup Wireshark using &#39;apt-get install wireshark&#39; and followed the setup-configuration for non-root user (see Wireshark doesn&#39;t see my interface).
What I finally did, was following:
sudo groupadd wireshark sudo usermod -a -G wireshark dionysius sudo dpkg-reconfigure wireshark-common (and said there YES)But after that i still cannot see any interface. What am I missing?
edit: if it does matter i&#39;m using linux mint 12</description>
    </item>
    
    <item>
      <title>Uninstalling wireshark 1.6.4</title>
      <link>/questions/7978/uninstalling-wireshark-164/</link>
      <pubDate>Wed, 14 Dec 2011 11:21:00 +0000</pubDate>
      
      <guid>/questions/7978/uninstalling-wireshark-164/</guid>
      <description>Uninstalling wireshark 1.6.4  0 I am currently testing wireshark 1.6.4 within an Army environment and have discovered that I can not uninstall this version using the Programs and Features module. Any suggestions on why this is so?
windows error uninstallasked 14 Dec &#39;11, 11:21
dbhunee
1●1●1●1
accept rate: 0%
 edited 15 Dec &#39;11, 15:39 
helloworld
3.1k●4●20●41
I&#39;m assuming you get an error when you try to uninstall. What is the error message?</description>
    </item>
    
    <item>
      <title>Any way to run wireshark standalone (not installing it)</title>
      <link>/questions/7983/any-way-to-run-wireshark-standalone-not-installing-it/</link>
      <pubDate>Wed, 14 Dec 2011 14:38:00 +0000</pubDate>
      
      <guid>/questions/7983/any-way-to-run-wireshark-standalone-not-installing-it/</guid>
      <description>Any way to run wireshark standalone (not installing it)  0 We have some XP machines that have an app that periodically stop communicating with the network. Problem is we have 2500 machines and it&#39;s random that they stop. We can&#39;t put Wireshark on every machine so I&#39;m wondering if there&#39;s a way that when I see one with this app not talking, i can remote in and plop down an executable and run it that way without having to actually install the program.</description>
    </item>
    
    <item>
      <title>Order-of-operation</title>
      <link>/questions/7986/order-of-operation/</link>
      <pubDate>Thu, 15 Dec 2011 07:24:00 +0000</pubDate>
      
      <guid>/questions/7986/order-of-operation/</guid>
      <description>Order-of-operation  0 I am trying to solve a problem in an ESXi/XP environment. The VM is running XP and Wireshark, The host is running Solaris.
Wireshark shows a packet leaving the VM but the Solaris server never sees the packet, nor does the span port on the Cisco switch. The vendor of the VM installed an Intel driver and right now that is where our suspicions are focused. He will fix that today.</description>
    </item>
    
    <item>
      <title>Reassemble Problem atop UDP</title>
      <link>/questions/7987/reassemble-problem-atop-udp/</link>
      <pubDate>Thu, 15 Dec 2011 07:38:00 +0000</pubDate>
      
      <guid>/questions/7987/reassemble-problem-atop-udp/</guid>
      <description>Reassemble Problem atop UDP  0 hi,
so i am developing a dissector for decoding a specified protocol atop udp. so the whole data is in the pdu of udp.
so i cannot show you the code because of it is not allowed to me!
so i describe.
There was another reassemble problem here in the askings by chris: so i looked and tryed anything but it does not work.</description>
    </item>
    
    <item>
      <title>Cannot capture wireless traffic anymore?</title>
      <link>/questions/7990/cannot-capture-wireless-traffic-anymore/</link>
      <pubDate>Thu, 15 Dec 2011 09:17:00 +0000</pubDate>
      
      <guid>/questions/7990/cannot-capture-wireless-traffic-anymore/</guid>
      <description>Cannot capture wireless traffic anymore?  0 Hi all,
I have been using wireshark to analyze my wireless traffic for a while. The past couple of times I&#39;ve tried to use it, my wireless card (an Atheros AR9285) doesn&#39;t even show up on the interfaces list anymore. I re-installed WinPcap and wireshark (64-bit) but to no avail. Any ideas?
J.W. California
wireless windows windows7 wifi troubleshootingasked 15 Dec &#39;11, 09:17</description>
    </item>
    
    <item>
      <title>NMAKE : fatal error U1077: &amp;#x27;sed&amp;#x27; : return code &amp;#x27;0x1&amp;#x27;</title>
      <link>/questions/7991/nmake-fatal-error-u1077-sed-return-code-0x1/</link>
      <pubDate>Thu, 15 Dec 2011 09:25:00 +0000</pubDate>
      
      <guid>/questions/7991/nmake-fatal-error-u1077-sed-return-code-0x1/</guid>
      <description>NMAKE : fatal error U1077: &amp;lsquo;sed&amp;rsquo; : return code &amp;lsquo;0x1&amp;rsquo;  0 I am unable to build wireshark from the released source. I found a few references to this error but none were resolved. The source is version 1.4.4. Please help.
A verify tools command generates the following:
Checking for required applications:
cl: /cygdrive/c/Program Files/Microsoft Visual Studio 9.0/VC/BIN/cl
link: /cygdrive/c/Program Files/Microsoft Visual Studio 9.0/VC/BIN/link
nmake: /cygdrive/c/Program Files/Microsoft Visual Studio 9.0/VC/BIN/nmake</description>
    </item>
    
    <item>
      <title>SSL decryption only works in promiscuous mode?</title>
      <link>/questions/8004/ssl-decryption-only-works-in-promiscuous-mode/</link>
      <pubDate>Thu, 15 Dec 2011 20:26:00 +0000</pubDate>
      
      <guid>/questions/8004/ssl-decryption-only-works-in-promiscuous-mode/</guid>
      <description>SSL decryption only works in promiscuous mode?  0 With capture filter tcp port https I only seem to capture decrypted HTTP requests when promiscuous mode is enabled. Found the problem by accident and was wondering why this might be.
ssl promiscuous troubleshooting httpsThis question is marked &#34;community wiki&#34;.asked 15 Dec &#39;11, 20:26
kcd
6●1●1●3
accept rate: 0%
  
One Answer:
  
0 It might be that you do not receive all HTTPS packets when promiscuous mode is not enabled.</description>
    </item>
    
    <item>
      <title>TCAP Decode</title>
      <link>/questions/8005/tcap-decode/</link>
      <pubDate>Fri, 16 Dec 2011 04:52:00 +0000</pubDate>
      
      <guid>/questions/8005/tcap-decode/</guid>
      <description>TCAP Decode  0 Hi, I have a trace in which there is no SSN present. hence wireshark fails to decode the upper layers of the SCCP users (TCAP). Would it be possible to manually decode the TCAP portion?
thanks
wiresharkasked 16 Dec &#39;11, 04:52
chathura
1●1●1●2
accept rate: 0%
 edited 16 Dec &#39;11, 06:33 
  
One Answer:
  
0Modern (1.6.0 and later, IIRC) versions of Wireshark have a &#34;</description>
    </item>
    
    <item>
      <title>after disable the tcp offload network arp request coming</title>
      <link>/questions/8024/after-disable-the-tcp-offload-network-arp-request-coming/</link>
      <pubDate>Sat, 17 Dec 2011 02:35:00 +0000</pubDate>
      
      <guid>/questions/8024/after-disable-the-tcp-offload-network-arp-request-coming/</guid>
      <description>after disable the tcp offload network arp request coming  0 after disable the tcp offload on three server only, and run wireshark on my server arp request is coming, before disable tcp offload my network was normal. kindly help , is it issue or normal thing
0 0 Dell_e5:d8:59 Broadcast ARP 60 FALSE Gratuitous ARP for 192.168.0.120 (Reply) 1 21.278276 21.278276 Dell_e8:99:59 Broadcast ARP 60 FALSE Who has 192.168.2.100? Tell 192.</description>
    </item>
    
    <item>
      <title>Variable name in POST request</title>
      <link>/questions/8028/variable-name-in-post-request/</link>
      <pubDate>Sat, 17 Dec 2011 11:05:00 +0000</pubDate>
      
      <guid>/questions/8028/variable-name-in-post-request/</guid>
      <description>Variable name in POST request  0 Hello,
I have capture a emission packet, and this is a HTTP/XML protocol using POST request. I saw the source code, but normaly, when we send a post request, we have to send a variable with its value to an url/server right ? So, how can I know the variable name or the multiple variable name use for contact the serveur with a POST request ?</description>
    </item>
    
    <item>
      <title>Counting incoming TCP open &amp;amp; http GET requests to a web server</title>
      <link>/questions/8029/counting-incoming-tcp-open-http-get-requests-to-a-web-server/</link>
      <pubDate>Sat, 17 Dec 2011 13:52:00 +0000</pubDate>
      
      <guid>/questions/8029/counting-incoming-tcp-open-http-get-requests-to-a-web-server/</guid>
      <description>Counting incoming TCP open &amp;amp; http GET requests to a web server  1 I want to use wireshark (preferably tshark) as a sniffer for web server performance symbiotic simulation analysis. The countables of interest are:
Incoming TCP open connections i.e. &#34;tcp.flags.syn==1&#34; and &#34;tcp.flags.ack==0&#34;Incoming GET http requests.For those I don&#39;t need the details, only counters (quantities). These need to be stored in the same file, with some text readable format, because another application will be reading and producing output from them.</description>
    </item>
    
    <item>
      <title>How to capture all the traffic that passes from my router?</title>
      <link>/questions/8031/how-to-capture-all-the-traffic-that-passes-from-my-router/</link>
      <pubDate>Sun, 18 Dec 2011 11:39:00 +0000</pubDate>
      
      <guid>/questions/8031/how-to-capture-all-the-traffic-that-passes-from-my-router/</guid>
      <description>How to capture all the traffic that passes from my router?  0 Here is the problem. I have one router (Thomson TG585 v8) and two PCs connected to it with ethernet cables. What i want to do is to monitor the traffic of the second computer from the first. Is wireshark the tool i need and if yes how exactly am i going to do that ? Thank you in advance.</description>
    </item>
    
    <item>
      <title>Decode TP4(COTP) inside CLNP</title>
      <link>/questions/8037/decode-tp4cotp-inside-clnp/</link>
      <pubDate>Mon, 19 Dec 2011 04:10:00 +0000</pubDate>
      
      <guid>/questions/8037/decode-tp4cotp-inside-clnp/</guid>
      <description>Decode TP4(COTP) inside CLNP  0 Why there is no way to force wireshark to decode perfectly normal TP4 transport layer (it&#39;s called COTP in wireshark terms) packets inside CLNP network layer? All I see is &#34;Data&#34; and there is no way to &#34;Decode as&#34; or apply any other dissector. On wireshark wiki it states: &#34;CLNP: COTP uses CLNP as its underlying network protocol.&#34; And yes, this is the case.</description>
    </item>
    
    <item>
      <title>Wireshark GTK Compilation error</title>
      <link>/questions/8042/wireshark-gtk-compilation-error/</link>
      <pubDate>Mon, 19 Dec 2011 08:19:00 +0000</pubDate>
      
      <guid>/questions/8042/wireshark-gtk-compilation-error/</guid>
      <description>Wireshark GTK Compilation error  1 I am working to port wireshark(1.6.4) to iOS, and a am getting a GTK compilation error when running the configure script. It seems that the GTK version is undetermined as justified by these lines in the config.log file
configure:19423: gcc -o conftest -no-cpp-precomp -D_U_=&amp;quot;__attribute__((unused))&amp;quot; -g -O2 -Wall -W -Wextra -Wdeclaration-after-statement -Wendif-labels -Wpointer-arith -Wno-pointer-sign -Wcast-align -Wformat-security -I/usr/local/include -I/usr/local/include -Wl,-search_paths_first -L/usr/local/lib conftest.c &amp;gt;&amp;amp;5 Undefined symbols: &amp;quot;_gtk_micro_version&amp;quot;, referenced from: _gtk_micro_version$non_lazy_ptr in ccxkEWm4.</description>
    </item>
    
    <item>
      <title>errors permissions</title>
      <link>/questions/8044/errors-permissions/</link>
      <pubDate>Mon, 19 Dec 2011 11:39:00 +0000</pubDate>
      
      <guid>/questions/8044/errors-permissions/</guid>
      <description>errors permissions  0 failed to allow interface discovery using user wheel freebsd 8.2
errorsasked 19 Dec &#39;11, 11:39
pvh115
1●1●1●1
accept rate: 0%
Can you please provide some context here, and an actual question to answer?
(19 Dec &#39;11, 12:00) multipleinte...   </description>
    </item>
    
    <item>
      <title>Splitting a large file</title>
      <link>/questions/8048/splitting-a-large-file/</link>
      <pubDate>Mon, 19 Dec 2011 13:26:00 +0000</pubDate>
      
      <guid>/questions/8048/splitting-a-large-file/</guid>
      <description>Splitting a large file  1 An older capture now produces file sizes that are too large for WS to open. Is there a way to tell WS to open just a portion of the file, or to split the file into smaller pieces? It is not possible to change the capture at this time.
splitasked 19 Dec &#39;11, 13:26
truman220
31●1●1●3
accept rate: 0%
  
5 Answers:</description>
    </item>
    
    <item>
      <title>Verifying IP&amp;#x27;s</title>
      <link>/questions/8051/verifying-ips/</link>
      <pubDate>Mon, 19 Dec 2011 15:30:00 +0000</pubDate>
      
      <guid>/questions/8051/verifying-ips/</guid>
      <description>Verifying IP&amp;rsquo;s  0 Hi, I am not very familiar with Wireshark so I apologize if this is too basic of a question. I have searched the forums for hints on how to accomplish what I am about to ask but was unsuccessful in finding any clues.
I want to verify the IP&#39;s seen by Wireshark. Basically I want to turn wireshark on for a while and have it gather a listing of all the IP&#39;s seen.</description>
    </item>
    
    <item>
      <title>Is someone willing to walk me through setup of wireless monitoring?</title>
      <link>/questions/8054/is-someone-willing-to-walk-me-through-setup-of-wireless-monitoring/</link>
      <pubDate>Mon, 19 Dec 2011 20:30:00 +0000</pubDate>
      
      <guid>/questions/8054/is-someone-willing-to-walk-me-through-setup-of-wireless-monitoring/</guid>
      <description>Is someone willing to walk me through setup of wireless monitoring?  0 I bought a switch capable of port mirroring. Use a mac and need to monitor another mac on my wireless network. I need to know how to set up the system and use Wireshark. I don&#39;t have a PC or Mac close to the router/switch. I have multiple wireless routers if that matters, but don&#39;t have to use them.</description>
    </item>
    
    <item>
      <title>IPv6 RTSP packet capture</title>
      <link>/questions/8055/ipv6-rtsp-packet-capture/</link>
      <pubDate>Mon, 19 Dec 2011 22:18:00 +0000</pubDate>
      
      <guid>/questions/8055/ipv6-rtsp-packet-capture/</guid>
      <description>IPv6 RTSP packet capture  0 Hi, Can anyone give me realtime &#34;IPV6 RTSP&#34; packet capture for my testing or guide me how to get that capture. Thanks
rtsp ipv6asked 19 Dec &#39;11, 22:18
JK7
31●11●12●14
accept rate: 0%
  
One Answer:
  
2Take a look at pcapr.
Browse the list of protocols:
RTSP_IPv6.pcap
You have to register, if you want to view or download the sample files.</description>
    </item>
    
    <item>
      <title>dns qry class always nil?</title>
      <link>/questions/8059/dns-qry-class-always-nil/</link>
      <pubDate>Tue, 20 Dec 2011 11:27:00 +0000</pubDate>
      
      <guid>/questions/8059/dns-qry-class-always-nil/</guid>
      <description>dns qry class always nil?  1 hello,
I&#39;m attempting to write a Lua tap to grab DNS info from some pcap files using tshark. I have one problem: every approach I&#39;ve tried to get the dns.qry.class or dns.resp.class entities returns nil, even on packets that I know are dns packets (dns.qry.name, for example, isn&#39;t nil).
Example code:
local class = Field.new(&amp;#39;dns.qry.class&amp;#39;) function init_listener() local tap = Listener.new(&amp;quot;ip&amp;quot;) function tap.packet(pinfo,buffer, ip) if class() == nil then debug(&amp;#39;class is nil&amp;#39;) end end end init_listener()That bit of code always finds that the qry class is nil.</description>
    </item>
    
    <item>
      <title>Wireshark Build for windows 7 64-bit</title>
      <link>/questions/8065/wireshark-build-for-windows-7-64-bit/</link>
      <pubDate>Wed, 21 Dec 2011 00:26:00 +0000</pubDate>
      
      <guid>/questions/8065/wireshark-build-for-windows-7-64-bit/</guid>
      <description>Wireshark Build for windows 7 64-bit  0 I want to know what changes are required to build wireshark on windows 7 64-bit. Is there any step by step guide other than the one given in the developer&#39;s guide as it is for 32 bit system? Which visual C++ would be required, 2008 or 2010? A step by step guide would be much preferable. Thanks
development windows build 64-bitasked 21 Dec &#39;11, 00:26</description>
    </item>
    
    <item>
      <title>Missing Packets?</title>
      <link>/questions/8075/missing-packets/</link>
      <pubDate>Wed, 21 Dec 2011 18:35:00 +0000</pubDate>
      
      <guid>/questions/8075/missing-packets/</guid>
      <description>Missing Packets?  1 I am trying to observe downstream wireless data packets from an AP to a laptop. I see the downstream RTS and upstream CTS followed by an upstream Block ACK. The packet capture appears to be missing the downstream data packets. The streaming video to the laptop is working fine, so I know that a large amount of data should be flowing to it. Has anyone seen this before?</description>
    </item>
    
    <item>
      <title>Calling a chained dissector on a well-known port</title>
      <link>/questions/8081/calling-a-chained-dissector-on-a-well-known-port/</link>
      <pubDate>Thu, 22 Dec 2011 12:26:00 +0000</pubDate>
      
      <guid>/questions/8081/calling-a-chained-dissector-on-a-well-known-port/</guid>
      <description>Calling a chained dissector on a well-known port  1 I am currently trying to write a Lua chained dissector that would take place on a well-known port. I first wrote it as a post-dissector, and everything was working, but for some reason, the dissector function is never called for a chained dissector.
For test purposes, the code is as simple as this :
-- declare our protocol httpProto = Proto(&amp;quot;http&amp;quot;,&amp;quot;http&amp;quot;) print(&amp;quot;out of the dissector&amp;quot;) &amp;ndash;======================&amp;ndash; create a functions to dissect it &amp;ndash;======================&amp;ndash;</description>
    </item>
    
    <item>
      <title>802.11 Block ACK and the Radiotap Header</title>
      <link>/questions/8091/80211-block-ack-and-the-radiotap-header/</link>
      <pubDate>Thu, 22 Dec 2011 16:30:00 +0000</pubDate>
      
      <guid>/questions/8091/80211-block-ack-and-the-radiotap-header/</guid>
      <description>802.11 Block ACK and the Radiotap Header  0 While monitoring Block ACK operation, when I capture a block of QoS data packets, the Radiotap Header for the first data packet of the block includes a normal MAC timestamp and RSSI value of 0. The second data packet of the block indicates a MAC timestamp of 0 and an RSSI value of 0. The third and final data packet of the block indicates a MAC timestamp of 0 and a normal RSSI value.</description>
    </item>
    
    <item>
      <title>Is it possible to add Wireshark to the Windows path during installation?</title>
      <link>/questions/8092/is-it-possible-to-add-wireshark-to-the-windows-path-during-installation/</link>
      <pubDate>Thu, 22 Dec 2011 17:14:00 +0000</pubDate>
      
      <guid>/questions/8092/is-it-possible-to-add-wireshark-to-the-windows-path-during-installation/</guid>
      <description>Is it possible to add Wireshark to the Windows path during installation?  0 I&#39;d like to use Wireshark command line tools, such as tshark on Windows. In the command prompt, tshark can be only invoked if the Wireshark install directory is known or if it is added to the Windows path variables.
Is there a way that when Wireshark is installed with the standard Windows installer, the install directory is automatically added to the Path variable, so that the command line tools can be used from the command prompt?</description>
    </item>
    
    <item>
      <title>Looking for an 802.11 expert.  Missing 802.11 BlockAckReq</title>
      <link>/questions/8096/looking-for-an-80211-expert-missing-80211-blockackreq/</link>
      <pubDate>Thu, 22 Dec 2011 18:49:00 +0000</pubDate>
      
      <guid>/questions/8096/looking-for-an-80211-expert-missing-80211-blockackreq/</guid>
      <description>Looking for an 802.11 expert. Missing 802.11 BlockAckReq  0 I am analyzing 802.11 block ACK operation. I am seeing the initial RTS/CTS exchange, followed by a block of QoS data packets, followed by a Block ACK. The capture appears to be missing the BlockAckReq following the block of data packets. Is there some commonly used way to trigger transmission of a block ACK that I am missing? I read something about an &#34;</description>
    </item>
    
    <item>
      <title>How to decipher  the integrity protected NAS message?? Does anyone provides the solution</title>
      <link>/questions/8097/how-to-decipher-the-integrity-protected-nas-message-does-anyone-provides-the-solution/</link>
      <pubDate>Thu, 22 Dec 2011 20:49:00 +0000</pubDate>
      
      <guid>/questions/8097/how-to-decipher-the-integrity-protected-nas-message-does-anyone-provides-the-solution/</guid>
      <description>How to decipher the integrity protected NAS message?? Does anyone provides the solution  0 Hi All,
In LTE network, NAS messages are intigrity protected. How to decipher them? Does wireshark has the solution for this? If no is there any solution or application for this in the market?
Thanks in Advance
Prithvi
encrypted messages nasasked 22 Dec &#39;11, 20:49
prithvi
6●5●5●8
accept rate: 0%
 edited 22 Dec &#39;11, 20:49</description>
    </item>
    
    <item>
      <title>compile the wireshark sourcecode on win 7 64bit system meets link error</title>
      <link>/questions/8098/compile-the-wireshark-sourcecode-on-win-7-64bit-system-meets-link-error/</link>
      <pubDate>Thu, 22 Dec 2011 23:08:00 +0000</pubDate>
      
      <guid>/questions/8098/compile-the-wireshark-sourcecode-on-win-7-64bit-system-meets-link-error/</guid>
      <description>compile the wireshark sourcecode on win 7 64bit system meets link error  0 Here is the compile log ,can anybody help me?
 cl -DWIN32 -DNULL=0 -D_MT -D_DLL -WX -DHAVE_CONFIG_H /I. /I.. /If:\wireshark-win64-libs-1.2\gtk2\include\glib-2.0 /If:\wireshark-win64-libs-1.2\gtk2\lib\glib-2.0\include /If:\wireshark-win64-libs-1.2\WPdpack\include -D_U_=&amp;quot;&amp;quot; /Zi /W3 /MD /D_CRT_SECURE_NO_DEPRECATE/D_CRT_NONSTDC_NO_DEPRECATE /DWIN32_LEAN_AND_MEAN /DMSC_VER_REQUIRED=1500 -Fd.\ -c file_util.c unicode-utils.c mpeg-audio.c privileges.c str_util.c type_util.c Microsoft (R) C/C++ Optimizing Compiler Version 15.00.30729.01 for x64 Copyright (C) Microsoft Corporation. All rights reserved. file_util.c unicode-utils.c mpeg-audio.c privileges.</description>
    </item>
    
    <item>
      <title>win7 64bit wireshark 1.6.4 only can capture receive packets</title>
      <link>/questions/8100/win7-64bit-wireshark-164-only-can-capture-receive-packets/</link>
      <pubDate>Fri, 23 Dec 2011 00:00:00 +0000</pubDate>
      
      <guid>/questions/8100/win7-64bit-wireshark-164-only-can-capture-receive-packets/</guid>
      <description>win7 64bit wireshark 1.6.4 only can capture receive packets  0 win7 64bit wireshark 1.6.4 only can capture receive packets,can&#39;t capture the packets which the PC sent out,that&#39;s mean I can&#39;t see the packets which the src ip is my PC&#39;s.
64-bit 1.6.4asked 23 Dec &#39;11, 00:00
prince_23
1●1●1●1
accept rate: 0%
 edited 24 Dec &#39;11, 07:48 
grahamb ♦
19.8k●3●30●206
On what type of network interface is this happening?</description>
    </item>
    
    <item>
      <title>Wireshark 1.6.4 Windows 7 32-bit Crashes on Capture Save</title>
      <link>/questions/8113/wireshark-164-windows-7-32-bit-crashes-on-capture-save/</link>
      <pubDate>Fri, 23 Dec 2011 09:09:00 +0000</pubDate>
      
      <guid>/questions/8113/wireshark-164-windows-7-32-bit-crashes-on-capture-save/</guid>
      <description>Wireshark 1.6.4 Windows 7 32-bit Crashes on Capture Save  0 Am running 1.6.4 under 32-bit Windows and doing wireless captures using AirPcap cards across 1,6,11. Am using the aggregator virtual adapter that combines these. System captures properly, but when I go to save the capture the file (e.g. 71 MB) the file saves, and the a close dialog pops up on screen but never goes away. I have to kill the app and reboot to start a new capture.</description>
    </item>
    
    <item>
      <title>TCP initial congestion window (slow-start)</title>
      <link>/questions/8120/tcp-initial-congestion-window-slow-start/</link>
      <pubDate>Fri, 23 Dec 2011 16:09:00 +0000</pubDate>
      
      <guid>/questions/8120/tcp-initial-congestion-window-slow-start/</guid>
      <description>TCP initial congestion window (slow-start)  0 I have noticed that the initial congestion window in my traces is 8920bytes~=6*1448. rfc3390 states the initial cwand should be max 4000 bytes(around 3*1448).
At first i thought it might be because i&#39;m running my server on mac os x, so apple might have modified the tcp stack. Therefore I tried running the server on a Linux box (2.6.38) however i&#39;m getting similar results 13032bytes=9*1448.</description>
    </item>
    
    <item>
      <title>I want someone to help...</title>
      <link>/questions/8134/i-want-someone-to-help/</link>
      <pubDate>Sun, 25 Dec 2011 13:07:00 +0000</pubDate>
      
      <guid>/questions/8134/i-want-someone-to-help/</guid>
      <description>I want someone to help&amp;hellip;  0 I want someone to help interpret catches of several werishark, I&#39;m having arp snoofing and wanted to know more or less how to interpret them in detail, I give link to download direcion catch (Please privacy as these are the mac of my router need someone senior). I give private links)
captureasked 25 Dec &#39;11, 13:07
SAS
1●1●1●1
accept rate: 0%
better to send email to this direcion [email protected]</description>
    </item>
    
    <item>
      <title>How to interpret signal strength</title>
      <link>/questions/8136/how-to-interpret-signal-strength/</link>
      <pubDate>Mon, 26 Dec 2011 15:51:00 +0000</pubDate>
      
      <guid>/questions/8136/how-to-interpret-signal-strength/</guid>
      <description>How to interpret signal strength  0 Hi,
I use Google for hours but I do not find a satisfying answer how to interpret the captured signal strength, given by the radiotap header. For instance Wireshark shows me a SSI Signal of -52 dBm and I want to convert it to a linear representation/unit. For me, a sensible unit would be the signal power at the antenna in Watt oder mW.</description>
    </item>
    
    <item>
      <title>How are GTP packets decoded in Wireshark?</title>
      <link>/questions/8137/how-are-gtp-packets-decoded-in-wireshark/</link>
      <pubDate>Mon, 26 Dec 2011 23:21:00 +0000</pubDate>
      
      <guid>/questions/8137/how-are-gtp-packets-decoded-in-wireshark/</guid>
      <description>How are GTP packets decoded in Wireshark?  0 How does Wireshark decode GTP packets? Is any source code available?
decode gtpasked 26 Dec &#39;11, 23:21
Subhash
1●1●1●1
accept rate: 0%
 edited 27 Dec &#39;11, 06:06 
multipleinte...
1.3k●15●23●40
  
One Answer:
  
2epan/dissectors/packet-gtp.c
answered 27 Dec &#39;11, 00:41
Anders ♦
4.6k●9●52
accept rate: 17%
 edited 27 Dec &#39;11, 05:54 
cmaynard ♦♦
9.4k●10●38●142</description>
    </item>
    
    <item>
      <title>How can I retrieve video encoding information from a capture?</title>
      <link>/questions/8142/how-can-i-retrieve-video-encoding-information-from-a-capture/</link>
      <pubDate>Tue, 27 Dec 2011 09:42:00 +0000</pubDate>
      
      <guid>/questions/8142/how-can-i-retrieve-video-encoding-information-from-a-capture/</guid>
      <description>How can I retrieve video encoding information from a capture?  0 Hello, I am a Wireshark newbie. I am writing a project for computer networks. I used VLC to stream on other computer over LAN via HTTP protocol The profile used is h.264+acc (TS) to stream and capture it at destination with Wireshark and stream on vlc on that computer. It look like this Is there any way to obtain further information about video codec or the packetized elementary stream (pes) of mp4 file that was streamed from HTTP?</description>
    </item>
    
    <item>
      <title>Monitoring web sockets via wireshark?</title>
      <link>/questions/8144/monitoring-web-sockets-via-wireshark/</link>
      <pubDate>Tue, 27 Dec 2011 15:45:00 +0000</pubDate>
      
      <guid>/questions/8144/monitoring-web-sockets-via-wireshark/</guid>
      <description>Monitoring web sockets via wireshark?  0 Hi, I have built a simple html5/websocket application but I cannot seem to capture the packet data associated with any web socket connections with wireshark. Has anyone done this before? I am failing to find anything that looks like it was sent to or from the web socket server. My purpose here is to test how easy it is to monitor the contents of the packets (in the case that I want to send potentially sensitive data over the connection), and as a web developer this kind of thing is a little out of my normal scope so any help is appreciated.</description>
    </item>
    
    <item>
      <title>What do the TCP flags mean?</title>
      <link>/questions/8146/what-do-the-tcp-flags-mean/</link>
      <pubDate>Tue, 27 Dec 2011 23:17:00 +0000</pubDate>
      
      <guid>/questions/8146/what-do-the-tcp-flags-mean/</guid>
      <description>What do the TCP flags mean?  0  Source Destination Protocol Info 85.73.133.27 150.140.141.181 TCP hi3182&amp;gt;http [SYN] Seq=0 Len=0 MSS=1420,win=,..etcWhat is the meaning of the values of TCP flags in the Info column?
info tcpasked 27 Dec &#39;11, 23:17
george
1●1●1●1
accept rate: 0%
 edited 28 Dec &#39;11, 06:31 
multipleinte...
1.3k●15●23●40
  
One Answer:
  
2The TCP flags shows what the sending TCP entity wants the receiving TCP entity to do.</description>
    </item>
    
    <item>
      <title>how to get the x-cache field in tshark ?</title>
      <link>/questions/8149/how-to-get-the-x-cache-field-in-tshark/</link>
      <pubDate>Wed, 28 Dec 2011 00:32:00 +0000</pubDate>
      
      <guid>/questions/8149/how-to-get-the-x-cache-field-in-tshark/</guid>
      <description>how to get the x-cache field in tshark ?  0 hi I have a pcap file with some packets coming from squid cache. looking at wireshark, I can view the x-cache header under the HTTP section. however, I can not find an equivalent field for tshark . I have tried composing a lua listener to extract the info myself , but the tvb field is NIL for all packets .</description>
    </item>
    
    <item>
      <title>which version of wireshark to use on OS X Snow Leopard but 32-bit processor?</title>
      <link>/questions/8154/which-version-of-wireshark-to-use-on-os-x-snow-leopard-but-32-bit-processor/</link>
      <pubDate>Wed, 28 Dec 2011 11:56:00 +0000</pubDate>
      
      <guid>/questions/8154/which-version-of-wireshark-to-use-on-os-x-snow-leopard-but-32-bit-processor/</guid>
      <description>which version of wireshark to use on OS X Snow Leopard but 32-bit processor?  0 Have a MacBook Pro Intel Core Duo 32-bit, but run Snow Leopard... should I install Leopard 32-bit? any differences in the OS that will affect Wireshark?
Thanks
macbook versionsasked 28 Dec &#39;11, 11:56
canon273
1●2●2●2
accept rate: 0%
  
One Answer:
  
0The only 32-bit x86 binary version we have is the Leopard version; it should work, although the &#34;</description>
    </item>
    
    <item>
      <title>Cannot see capture points that i need</title>
      <link>/questions/8156/cannot-see-capture-points-that-i-need/</link>
      <pubDate>Wed, 28 Dec 2011 13:42:00 +0000</pubDate>
      
      <guid>/questions/8156/cannot-see-capture-points-that-i-need/</guid>
      <description>Cannot see capture points that i need  0 I am running Windows 7. Have a Napatech NT20E2 and NT4E cards installed on server. Drivers are up to date and shows device installed.
How do i get the device to show up in Wireshark?
captureasked 28 Dec &#39;11, 13:42
USMC_Contractor
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>cannot capture EAP-requset/response packet</title>
      <link>/questions/8162/cannot-capture-eap-requsetresponse-packet/</link>
      <pubDate>Thu, 29 Dec 2011 04:05:00 +0000</pubDate>
      
      <guid>/questions/8162/cannot-capture-eap-requsetresponse-packet/</guid>
      <description>cannot capture EAP-requset/response packet  0 I usd wireshark1.6.2 in Ubuntu 11.10 to capture wpa2 authentication packet, but in WPA2-PSK or EAP—TLS authentication methods I only capture EPAOL key switch packet and sequent DHCP、TCP packet ,can not capture eap-request/response packet. Why？How can i solve this problem?
eapolasked 29 Dec &#39;11, 04:05
zqm0209
1●1●1●2
accept rate: 0%
it is strange.when I first used EAP-TLS authenticate to the WLAN,I catch the eap-request/response packet,here is the packet: http://sharesend.</description>
    </item>
    
    <item>
      <title>Learning to understand the data captured by Wireshark?</title>
      <link>/questions/8164/learning-to-understand-the-data-captured-by-wireshark/</link>
      <pubDate>Thu, 29 Dec 2011 05:05:00 +0000</pubDate>
      
      <guid>/questions/8164/learning-to-understand-the-data-captured-by-wireshark/</guid>
      <description>Learning to understand the data captured by Wireshark?  0 I want to be able to use and understand the data captured by Wireshark.
To achieve this goal, can you please advise me if using the user manual and hands-on use will be enough? Or would you advise me to also purchase the Wireshark Network Analysis book written by Laura Chappell along with the Exam Prep Guide?
Additional to the books, are there any CBT videos that you may recommend not shown on the Wireshark websites?</description>
    </item>
    
    <item>
      <title>How to capture RPC communication using wireshark to remote computer</title>
      <link>/questions/8165/how-to-capture-rpc-communication-using-wireshark-to-remote-computer/</link>
      <pubDate>Thu, 29 Dec 2011 05:27:00 +0000</pubDate>
      
      <guid>/questions/8165/how-to-capture-rpc-communication-using-wireshark-to-remote-computer/</guid>
      <description>How to capture RPC communication using wireshark to remote computer  0 Hi,
I have wireshark Version 1.6.4 and am trying to connecting remote host which is failing.
First I wish to know how the wireshark works while capturing the packets from local or remote.
Secondly, I want to track the Outlook anywhere (RPC over HTTPs) communication with port 443 and need if wireshark helps us to track RPC endpoint and endpoint mapper communications between client and server.</description>
    </item>
    
    <item>
      <title>Truncated URI in the Wireshark UI</title>
      <link>/questions/8166/truncated-uri-in-the-wireshark-ui/</link>
      <pubDate>Thu, 29 Dec 2011 13:36:00 +0000</pubDate>
      
      <guid>/questions/8166/truncated-uri-in-the-wireshark-ui/</guid>
      <description>Truncated URI in the Wireshark UI  0 Long URIs are truncated in the Wireshark UI by default, even when the capture was run with tshark which does not limit the snaplen. I can view the full URI on the command-line using tshark and pulling out the http.request.uri. Is it possible to override whatever causes the truncation in the Wireshark UI? None of the options I came across in the UI seemed to lend itself to making this possible.</description>
    </item>
    
    <item>
      <title>Cannot capture EAPOL packets from client to AP</title>
      <link>/questions/8170/cannot-capture-eapol-packets-from-client-to-ap/</link>
      <pubDate>Sat, 31 Dec 2011 11:38:00 +0000</pubDate>
      
      <guid>/questions/8170/cannot-capture-eapol-packets-from-client-to-ap/</guid>
      <description>Cannot capture EAPOL packets from client to AP  1 Hi,
I&#39;m new to wireshark, and I&#39;ve spent many hours searching online and troubleshooting this peculiar behavior. I have a simple topology, just two computers wirelessly connected to a router, using WPA encryption. I&#39;ve set up my wireshark to decrypt packets, by going into the IEEE 802.11 protocol setting and enabling decryption with the key wpa-pwd:password:SSID, as explained in here</description>
    </item>
    
    <item>
      <title>Keylogger Need help to get the login info.</title>
      <link>/questions/8173/keylogger-need-help-to-get-the-login-info/</link>
      <pubDate>Sun, 01 Jan 2012 17:25:00 +0000</pubDate>
      
      <guid>/questions/8173/keylogger-need-help-to-get-the-login-info/</guid>
      <description>Keylogger Need help to get the login info.  0 Here is a picture of it. How does it connect to the server? I want to delete my logged files he have logged, please help me before I get hacked.
Thanks.
keylogger port tcpasked 01 Jan &#39;12, 17:25
Lelouch
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How to write filter expressions??</title>
      <link>/questions/8175/how-to-write-filter-expressions/</link>
      <pubDate>Sun, 01 Jan 2012 18:24:00 +0000</pubDate>
      
      <guid>/questions/8175/how-to-write-filter-expressions/</guid>
      <description>How to write filter expressions??  0 Hi
I&#39;m trying to figure out the generic logic of writing filter expression to be able to write them easily. I found a link that shows its syntax. The link is that : http://openmaniak.com/wireshark_filters.php
It shows that expressions always start with protocol name, then (.) dot and one of that protocol&#39;s substructure follows.
Is it always like this? Are there any more rules to write filter expression that must be followed?</description>
    </item>
    
    <item>
      <title>&amp;quot;Capture packets in monitor mode&amp;quot; option does not work/ unable to scan any http traffic other than my own</title>
      <link>/questions/8178/capture-packets-in-monitor-mode-option-does-not-work-unable-to-scan-any-http-traffic-other-than-my-own/</link>
      <pubDate>Mon, 02 Jan 2012 03:09:00 +0000</pubDate>
      
      <guid>/questions/8178/capture-packets-in-monitor-mode-option-does-not-work-unable-to-scan-any-http-traffic-other-than-my-own/</guid>
      <description>&amp;ldquo;Capture packets in monitor mode&amp;rdquo; option does not work/ unable to scan any http traffic other than my own  0 Hi! I&#39;m using linux mint which is an ubuntu dist., wireshark v1.4.6, installed it just a week ago. I have several computers connected to the same wireless network and I want to be able to see all the traffic. Using wlan0, I can only monitor my own traffic (i.e. of the computer running wireshark).</description>
    </item>
    
    <item>
      <title>How Differentiate the RBT Dial Tone (Rining) and Caller tone (any song)</title>
      <link>/questions/8190/how-differentiate-the-rbt-dial-tone-rining-and-caller-tone-any-song/</link>
      <pubDate>Mon, 02 Jan 2012 09:52:00 +0000</pubDate>
      
      <guid>/questions/8190/how-differentiate-the-rbt-dial-tone-rining-and-caller-tone-any-song/</guid>
      <description>How Differentiate the RBT Dial Tone (Rining) and Caller tone (any song)  0 Dear Sir/Madam,
Here i want to ask question regarding the Trace capture difference betweent the RBT of dial tone and caller tone(song), the scenario is basically Partey A call to Party B, during the begining of Part A call to party B call setup Party B set caller tone instead of Rining Bell hear by Party A as a Song Tone not getting ringing bell, so here i want to know, where we can found the difference between ringing RBT and Caller tone in Wireshark trace packets and also pls provide the details where we see difference with example so we can differencitae the route qulaity is this route better or not.</description>
    </item>
    
    <item>
      <title>CAP session</title>
      <link>/questions/8192/cap-session/</link>
      <pubDate>Mon, 02 Jan 2012 10:16:00 +0000</pubDate>
      
      <guid>/questions/8192/cap-session/</guid>
      <description>CAP session  0 Dear All,
how to delimite a complete CAP seesion in a given .pcap file ?
i wanna see all sequences since the beggining to the end for a given MSISDN.
thank you. mohamed
capture-filterasked 02 Jan &#39;12, 10:16
mzakour
1●1●1●1
accept rate: 0%
in other terms:
i wanna know how to identify packets related for a complete call flow.
(02 Jan &#39;12, 11:36) mzakour</description>
    </item>
    
    <item>
      <title>Windows 7 nic issue</title>
      <link>/questions/8193/windows-7-nic-issue/</link>
      <pubDate>Mon, 02 Jan 2012 10:20:00 +0000</pubDate>
      
      <guid>/questions/8193/windows-7-nic-issue/</guid>
      <description>Windows 7 nic issue  0 Has anyone figured out how to capture packets on a second nic in a Win 7 machine with the network location &#34;feature&#34;. Everytime I try to capture packets with a Win 7 machine it never works, it always shows &#34;limited connectivity&#34; on the sniffing nic.
windows7asked 02 Jan &#39;12, 10:20
Twidget
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>MAC Timestamp measurement Unit</title>
      <link>/questions/8203/mac-timestamp-measurement-unit/</link>
      <pubDate>Tue, 03 Jan 2012 02:08:00 +0000</pubDate>
      
      <guid>/questions/8203/mac-timestamp-measurement-unit/</guid>
      <description>MAC Timestamp measurement Unit  1 Hi guys, Hope you can help me with this one :
We have this 9-digits MAC Timestamp in the Radio Header Section, what is the measurement unit for that? Wireshark defines it as &#34;Value in microseconds of the MAC&#39;s Time Synchronizations Function timer when the first bit of the MPDU arrived at the MAC&#34; but I kind of not sure about that. Does it mean it took like about 974538712 usec for a Packet to reach my WLAN card?</description>
    </item>
    
    <item>
      <title>Temp file</title>
      <link>/questions/8205/temp-file/</link>
      <pubDate>Tue, 03 Jan 2012 11:22:00 +0000</pubDate>
      
      <guid>/questions/8205/temp-file/</guid>
      <description>Temp file  0 Hello -- I get the message when I start wireshark that it can&#39;t write its temp file -- Where does it write it
file tempasked 03 Jan &#39;12, 11:22
fpefpe
1●1●1●1
accept rate: 0%
What is the complete message from Wireshark? It should be reporting why it can&#39;t write its temporary file.
(03 Jan &#39;12, 18:18) Guy Harris ♦♦  
2 Answers:</description>
    </item>
    
    <item>
      <title>file can not be opened using version 1.6.4 (64 bit) on Windows 7</title>
      <link>/questions/8209/file-can-not-be-opened-using-version-164-64-bit-on-windows-7/</link>
      <pubDate>Tue, 03 Jan 2012 14:56:00 +0000</pubDate>
      
      <guid>/questions/8209/file-can-not-be-opened-using-version-164-64-bit-on-windows-7/</guid>
      <description>file can not be opened using version 1.6.4 (64 bit) on Windows 7  0 I am running Wireshark 1.6.4 (64 Bit) on Windows 7.
When I tried to open files, it failed with following errors.
&#34;The capture file appears to be damaged or corrupt. (pcap: File has 771751936 byte packet, bigger than maximum of 65535)&#34;.
The same file can be opened fine on wireshark on MacOS so I am assuming file is fine it is just some kind of bug is causing problem on Windows 7.</description>
    </item>
    
    <item>
      <title>How to create a filter to remove TCP sessions with no payload</title>
      <link>/questions/8224/how-to-create-a-filter-to-remove-tcp-sessions-with-no-payload/</link>
      <pubDate>Wed, 04 Jan 2012 13:04:00 +0000</pubDate>
      
      <guid>/questions/8224/how-to-create-a-filter-to-remove-tcp-sessions-with-no-payload/</guid>
      <description>How to create a filter to remove TCP sessions with no payload  0 Hi all,
I haven&#39;t found a good way to do this yet. Is there a way to filter out TCP sessions that have no payload? (Basically, sessions that have the 3-way handshake and then immediately close via FIN or RST that didn&#39;t actually transmit any meaningful data).
Thanks
-VK
filter tcp payload emptyasked 04 Jan &#39;12, 13:04</description>
    </item>
    
    <item>
      <title>pcap to text/csv conversion takes long time</title>
      <link>/questions/8226/pcap-to-textcsv-conversion-takes-long-time/</link>
      <pubDate>Wed, 04 Jan 2012 21:26:00 +0000</pubDate>
      
      <guid>/questions/8226/pcap-to-textcsv-conversion-takes-long-time/</guid>
      <description>pcap to text/csv conversion takes long time  0 I have captured traffic in pcap file and trying to convert the pcap file into txt/csv. I am using tshark -V -r infile.pcap &amp;gt; outputfile.txt/csv. I am observing that, the time taken to convert 100MB of pcap file takes more than average 10min on Xeon Dual core 2GB RAM system. This is the performance bottleneck for me as I want the time taken to convert the file at least linear with time taken to capture 100 MB of data on 100 MB NIC.</description>
    </item>
    
    <item>
      <title>Problems dissecting FT_ETHER</title>
      <link>/questions/8227/problems-dissecting-ft_ether/</link>
      <pubDate>Thu, 05 Jan 2012 01:19:00 +0000</pubDate>
      
      <guid>/questions/8227/problems-dissecting-ft_ether/</guid>
      <description>Problems dissecting FT_ETHER  0 Hello, I need to dissect a MAC address, but the format FT_ETHER gives me a hard time. I looked into packet_eth.c and used this code:
static int hf_mac = -1; static void dissect_xxx(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree) { if (tree) { const guint8 *address; address = tvb_get_ptr(tvb, 0, 6);  proto_tree_add_ether(tree, hf_mac, tvb, 0, 6, address); }  }
void proto_register_xxx(void) { static hf_register_info hf[] = { {&amp;amp;hf_mac, {&amp;quot;MAC&amp;quot;, &amp;quot;xxx.</description>
    </item>
    
    <item>
      <title>Absolute time and time resolution in tshark I/O statistics</title>
      <link>/questions/8233/absolute-time-and-time-resolution-in-tshark-io-statistics/</link>
      <pubDate>Thu, 05 Jan 2012 09:14:00 +0000</pubDate>
      
      <guid>/questions/8233/absolute-time-and-time-resolution-in-tshark-io-statistics/</guid>
      <description>Absolute time and time resolution in tshark I/O statistics  0 Hey there,
is there any way I can specify the
tshark -r file.pcap -qz &#34;io,stat,1,AVG(tcp.analysis.ack_rtt)tcp.analysis.ack_rtt&#34;
output, to 1. give me absolute time intervals and 2. give me more than milliseconds as a resolution for the AVG values?
thx as always in advance
statistics advanced tshark ioasked 05 Jan &#39;12, 09:14
Landi
2.3k●5●14●42
accept rate: 28%
 edited 05 Jan &#39;12, 19:22</description>
    </item>
    
    <item>
      <title>how to capture USB initiation</title>
      <link>/questions/8234/how-to-capture-usb-initiation/</link>
      <pubDate>Thu, 05 Jan 2012 09:42:00 +0000</pubDate>
      
      <guid>/questions/8234/how-to-capture-usb-initiation/</guid>
      <description>how to capture USB initiation  0 I&#39;m trying to debug a linux connection over usb to an embedded controller. The controller is part of a PV inverter and turns itself off when it gets dark. Powering up in the morning does not work properly with the device connected to a Linux box, leaving the embedded controller unable to communicate until it is reset (not a trivial task). All&#39;s well with Windows XP.</description>
    </item>
    
    <item>
      <title>optional comments field aren&amp;#x27;t displayed in wireshark In pcapng EnhancedPacketBlocks</title>
      <link>/questions/8246/optional-comments-field-arent-displayed-in-wireshark-in-pcapng-enhancedpacketblocks/</link>
      <pubDate>Thu, 05 Jan 2012 22:55:00 +0000</pubDate>
      
      <guid>/questions/8246/optional-comments-field-arent-displayed-in-wireshark-in-pcapng-enhancedpacketblocks/</guid>
      <description>optional comments field aren&amp;rsquo;t displayed in wireshark In pcapng EnhancedPacketBlocks  0 Hi,
I am trying to view optional comment field present in pcapng EnhancedPacketBlocks, but wireshark is not displaying that. I see a bug (https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6229) has been fixed related to this in wireshark 1.6.2 release and i am using 1.6.3.
Do i need to do something more. Plz help.
Thanks, Ambika
pcapng epbasked 05 Jan &#39;12, 22:55
ambika
1●2●2●3</description>
    </item>
    
    <item>
      <title>MMS decoding problem (asn1c Compiler)</title>
      <link>/questions/8255/mms-decoding-problem-asn1c-compiler/</link>
      <pubDate>Fri, 06 Jan 2012 07:28:00 +0000</pubDate>
      
      <guid>/questions/8255/mms-decoding-problem-asn1c-compiler/</guid>
      <description>MMS decoding problem (asn1c Compiler)  0 Hi all,
I know this is not directly related to wireshark but I expect that most of you will be able to help me on this one. I am using asn1c Compiler to decode MMS protocol (transported over TPKT, COTP,Session, Presentation, ACSE layers). The problem that I am having is the asn1c compiler complains of unexpected tag when I decode the MMS layer packets.</description>
    </item>
    
    <item>
      <title>Auto-update check</title>
      <link>/questions/8256/auto-update-check/</link>
      <pubDate>Fri, 06 Jan 2012 09:42:00 +0000</pubDate>
      
      <guid>/questions/8256/auto-update-check/</guid>
      <description>Auto-update check  0 Dear Wireshark team,
Would it be possible to have an automatic update check in Wireshark?
Beside making it easier for people to stay up-to-date, they can also be warned if the current version of Wireshark is really outdated or contain any security vulnerabilities. Especially on the Windows where no package managers (and maintainers) are present, most users don&#39;t check regularly if they use a non-vulnerable version of some software.</description>
    </item>
    
    <item>
      <title>Console warnings and &amp;quot;Running as root&amp;quot; dangerous</title>
      <link>/questions/8268/console-warnings-and-running-as-root-dangerous/</link>
      <pubDate>Sat, 07 Jan 2012 13:52:00 +0000</pubDate>
      
      <guid>/questions/8268/console-warnings-and-running-as-root-dangerous/</guid>
      <description>Console warnings and &amp;ldquo;Running as root&amp;rdquo; dangerous  0 When I run Wireshark as root in Backtrack Linux, I see these warnings from the console:
[email protected]: ~# wireshark (wireshark:4751): GLib-GOBject-WARNING **: invalid cast from `GtkMenuItem&amp;#39; to `GtkMenu&amp;#39; (wireshark:4751): Gtk-CRITICAL **: gtk_menu_get_attach_widget: assertion `GTK_IS_MENU (menu)&amp;#39; failed (wireshark:4751): Gtk-CRITICAL **: gtk_widget_set_sensitive: assertion `GTK_IS_WIDGET (widget)&amp;#39; failed
I also see a message box with this warning:
Running as user &amp;quot;root&amp;quot; and group &amp;quot;root&amp;quot;. This could be dangerous.</description>
    </item>
    
    <item>
      <title>Sniffing at the Coax</title>
      <link>/questions/8269/sniffing-at-the-coax/</link>
      <pubDate>Sat, 07 Jan 2012 15:33:00 +0000</pubDate>
      
      <guid>/questions/8269/sniffing-at-the-coax/</guid>
      <description>Sniffing at the Coax  0 I am wondering if it is even possible to sniff traffic at the coax level before it even reaches the ethernet router? If so, would special hardware be required?
Thanks much for any help, I have tried searching all over without luck to this question!
modem coax cableasked 07 Jan &#39;12, 15:33
kualla
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Can wireshark be used to log internet traffc?</title>
      <link>/questions/8270/can-wireshark-be-used-to-log-internet-traffc/</link>
      <pubDate>Sat, 07 Jan 2012 18:59:00 +0000</pubDate>
      
      <guid>/questions/8270/can-wireshark-be-used-to-log-internet-traffc/</guid>
      <description>Can wireshark be used to log internet traffc?  0 I have many computers in my house. I want to know where my bandwith is going, and what sites my kids are visiting. I am willing to dedicate a computer to log the data. I am developer and would be happy to write code to parase and report on the logged data.
traffic log internetasked 07 Jan &#39;12, 18:59
Kirkb</description>
    </item>
    
    <item>
      <title>Real Time measurement of RTMP and HTTP streams</title>
      <link>/questions/8271/real-time-measurement-of-rtmp-and-http-streams/</link>
      <pubDate>Sat, 07 Jan 2012 19:44:00 +0000</pubDate>
      
      <guid>/questions/8271/real-time-measurement-of-rtmp-and-http-streams/</guid>
      <description>Real Time measurement of RTMP and HTTP streams  0 Hello, I&#39;m now looking into WireShark with hope that it will have the capability to display an incoming stream&#39;s bit rate for RTMP and HTTP. In reading the User Guide I see that it has; Statistic infos: -y display average data rate (in bytes/sec) -i display average data rate (in bits/sec) -z display average packet size (in bytes) -x display average packet rate (in packets/sec) This seems to be what I am looking for.</description>
    </item>
    
    <item>
      <title>Difference between IMPLICIT and EXPLICIT tags (ASN.1)</title>
      <link>/questions/8277/difference-between-implicit-and-explicit-tags-asn1/</link>
      <pubDate>Sun, 08 Jan 2012 12:17:00 +0000</pubDate>
      
      <guid>/questions/8277/difference-between-implicit-and-explicit-tags-asn1/</guid>
      <description>Difference between IMPLICIT and EXPLICIT tags (ASN.1)  0 Can someone explain to me with an example how implicit tagging reduces overhead of number of bytes transfered in ASN.1 ?
Thanks.
asn1asked 08 Jan &#39;12, 12:17
mmalik10
1●2●2●2
accept rate: 0%
  
2 Answers:
  
1When using BER (BASIC ENCODING RULES) or DER (DISTINGUISHED ENCODING RULES), data for types are encoding using a Type-Length-Value format. Each primitive ASN.</description>
    </item>
    
    <item>
      <title>WinPcap/NPF not in the Device Manager</title>
      <link>/questions/8281/winpcapnpf-not-in-the-device-manager/</link>
      <pubDate>Sun, 08 Jan 2012 17:17:00 +0000</pubDate>
      
      <guid>/questions/8281/winpcapnpf-not-in-the-device-manager/</guid>
      <description>WinPcap/NPF not in the Device Manager  0 Hello When installing Wireshark in a Windows XP Virtual Macine, I saw that WinPcap was installed, yet it is not showing up in the Device Manager.
From the Device Manager you can select View-&amp;gt;Show hidden devices, then open Non-Plug and Play Drivers and right click on NetGroup Packet Filter Driver. In the driver properties you can set the startup type as well as start and stop the driver manually.</description>
    </item>
    
    <item>
      <title>Display a string coded in UTF-16</title>
      <link>/questions/8282/display-a-string-coded-in-utf-16/</link>
      <pubDate>Mon, 09 Jan 2012 01:34:00 +0000</pubDate>
      
      <guid>/questions/8282/display-a-string-coded-in-utf-16/</guid>
      <description>Display a string coded in UTF-16  0 Hi.
I am trying to patch a home made plugin. To summarize, a xml file describes message format and the plugin manages to decode the messages.
I have some messages containing some string coded in UTF-8. It works fine. I just have to write in my xml that I have to decode a FT_STRING .
Now, I have some new messages that are coded in UTF-16 If I use a FT_STRING, it just prints the first character (stop at the first 000 encountered)</description>
    </item>
    
    <item>
      <title>Sniffing cookies no secure bit set</title>
      <link>/questions/8293/sniffing-cookies-no-secure-bit-set/</link>
      <pubDate>Mon, 09 Jan 2012 22:11:00 +0000</pubDate>
      
      <guid>/questions/8293/sniffing-cookies-no-secure-bit-set/</guid>
      <description>Sniffing cookies no secure bit set  0 How do you see the cookies of a HTTPS site which does not set secure bit for cookies ?
cookies http httpsasked 09 Jan &#39;12, 22:11
novice87
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Crash when using a Plugin with xml</title>
      <link>/questions/8298/crash-when-using-a-plugin-with-xml/</link>
      <pubDate>Tue, 10 Jan 2012 05:46:00 +0000</pubDate>
      
      <guid>/questions/8298/crash-when-using-a-plugin-with-xml/</guid>
      <description>Crash when using a Plugin with xml  0 Hi,
I have written a Plugin for Wireshark wich includes the library mxml. The compile of the plugin is successfull. But when I start wireshark with my plugin wireshark crashes. Do you have any experiences with using an external dll (mxml) in your own plugin? The problem seems to be in &#39;mxmlloadfile&#39;...
Thanks
xml crash pluginasked 10 Jan &#39;12, 05:46
Nic</description>
    </item>
    
    <item>
      <title>Can TShark be used without WireShark</title>
      <link>/questions/8301/can-tshark-be-used-without-wireshark/</link>
      <pubDate>Tue, 10 Jan 2012 07:20:00 +0000</pubDate>
      
      <guid>/questions/8301/can-tshark-be-used-without-wireshark/</guid>
      <description>Can TShark be used without WireShark  0 I am interested in capturing traffic on our network from a range of devices as part of a device trial. The devices will not have wireshark installed on them. Is it possible to still capture data from these trial devices using TShark?
trial data tshark captureasked 10 Jan &#39;12, 07:20
Mike4G
1●1●1●1
accept rate: 0%
 edited 26 Feb &#39;12, 20:56</description>
    </item>
    
    <item>
      <title>Implementing a &amp;quot;next capture in directory&amp;quot; feature</title>
      <link>/questions/8304/implementing-a-next-capture-in-directory-feature/</link>
      <pubDate>Tue, 10 Jan 2012 09:21:00 +0000</pubDate>
      
      <guid>/questions/8304/implementing-a-next-capture-in-directory-feature/</guid>
      <description>Implementing a &amp;ldquo;next capture in directory&amp;rdquo; feature  0 I&#39;m not a coder, but I use Wireshark daily as I work at a networking company. I often have to go through hundreds of captures one-by-one, and right now I close each Wireshark instance and then open the next file (opening the next one in Wireshark itself is a pain because it jumps to the top of the directory each time). Perhaps it might be nice to be able to go forward and backward in a directory of capture files (like an &#34;</description>
    </item>
    
    <item>
      <title>Continuation or non-HTTP traffic</title>
      <link>/questions/8305/continuation-or-non-http-traffic/</link>
      <pubDate>Tue, 10 Jan 2012 11:36:00 +0000</pubDate>
      
      <guid>/questions/8305/continuation-or-non-http-traffic/</guid>
      <description>Continuation or non-HTTP traffic  0 I got a trace where appear several times the info &#34;[TCP Fast Retransmission] Continuation or non-HTTP traffic&#34;, &#34;[TCP Previous segment lost]Continuation or non-HTTP traffic&#34; or [TCP Retransmission]Continuation or non-HTTP traffic&#34;.
This traces is from a user is downloading software or videos that sometimes takes 20 or 1 hour but the download is not completed. This download is from a sft server.
Please could you tell me what is this length refer?</description>
    </item>
    
    <item>
      <title>USB Mobile Broadband Modem as Network Interface</title>
      <link>/questions/8309/usb-mobile-broadband-modem-as-network-interface/</link>
      <pubDate>Tue, 10 Jan 2012 13:23:00 +0000</pubDate>
      
      <guid>/questions/8309/usb-mobile-broadband-modem-as-network-interface/</guid>
      <description>USB Mobile Broadband Modem as Network Interface  0 In reading up on earlier posts, it does not seem like there is a way to recognize mobile broadband USB modems connected to Windows 7 as network interfaces in Wireshark. Is that still the case? I wanted get a more recent confirmation on this?
In my case, I am trying to monitor the Sierra Wireless ATT 4G LTE USB Modem. http://www.sierrawireless.com/productsandservices/AirCard/USBModems/AirCard_313U.aspx</description>
    </item>
    
    <item>
      <title>TCP Client ignores the acknowledge packet</title>
      <link>/questions/8313/tcp-client-ignores-the-acknowledge-packet/</link>
      <pubDate>Tue, 10 Jan 2012 20:02:00 +0000</pubDate>
      
      <guid>/questions/8313/tcp-client-ignores-the-acknowledge-packet/</guid>
      <description>TCP Client ignores the acknowledge packet  0 Can someone please help me with this. The TCP client just ignores the ACK packet, and kept resending packet 53741 until the connection is time out. Where could be the issue?
 67011 103.330429 192.168.232.6 192.168.233.6 TCP 590 [TCP Retransmission] tsp &amp;gt; icl-twobase1 [ACK] Seq=53741 Ack=3683 Win=262144 Len=536 //client send packet 53741 67048 103.358386 192.168.233.6 192.168.232.6 TCP 66 icl-twobase1 &amp;gt; tsp [ACK] Seq=3683 Ack=53741 Win=261072 Len=0 SLE=54049 SRE=58188 //server send ACK to packet 53741 67050 103.</description>
    </item>
    
    <item>
      <title>capture at multiple interface in Wireshark 1.7 development release</title>
      <link>/questions/8314/capture-at-multiple-interface-in-wireshark-17-development-release/</link>
      <pubDate>Tue, 10 Jan 2012 22:47:00 +0000</pubDate>
      
      <guid>/questions/8314/capture-at-multiple-interface-in-wireshark-17-development-release/</guid>
      <description>capture at multiple interface in Wireshark 1.7 development release  0 Could some pls tell me if it is possible to start wireshark 1.7 ( dev version ) from command line with multiple interfaces specified ? I could start a capture from a single interface from command line but not multiple interfaces.
I tried these but nothing worked
sudo wireshark -i eth1 -i /tmp/pipe sudo wireshark -k -i eth1 -i /tmp/pipeFor the above wireshark started but displayed some error information for dumpcap that &amp;ldquo;&amp;ndash;t option is invalid.</description>
    </item>
    
    <item>
      <title>Need a tool for analyzing / sniffing RTP packets over Wi-fi</title>
      <link>/questions/8320/need-a-tool-for-analyzing-sniffing-rtp-packets-over-wi-fi/</link>
      <pubDate>Wed, 11 Jan 2012 03:03:00 +0000</pubDate>
      
      <guid>/questions/8320/need-a-tool-for-analyzing-sniffing-rtp-packets-over-wi-fi/</guid>
      <description>Need a tool for analyzing / sniffing RTP packets over Wi-fi  0 Need a tool for analyzing / sniffing RTP packets over Wi-fi
wiresharkasked 11 Jan &#39;12, 03:03
rameshnairmp...
1●1●1●1
accept rate: 0%
  
One Answer:
  
2I think there&#39;s a program called &#34;Wireshark&#34; that can dissect RTP and do some statistical analysis of RTP and that can capture traffic on Wi-Fi networks.
answered 11 Jan &#39;12, 15:27</description>
    </item>
    
    <item>
      <title>Difference TShark / Wireshark when load a pcap</title>
      <link>/questions/8324/difference-tshark-wireshark-when-load-a-pcap/</link>
      <pubDate>Wed, 11 Jan 2012 05:38:00 +0000</pubDate>
      
      <guid>/questions/8324/difference-tshark-wireshark-when-load-a-pcap/</guid>
      <description>Difference TShark / Wireshark when load a pcap  0 Hi to all,
After merge 2 two pcap with the command &#34;mergepcap -a 1.pcap 2.pcap -w result.pcap&#34; the output from TShark and Wireshark is different.
In detail, if i open the result.pcap with TShark with this command, /usr/bin/tshark -r result.pcap -T fields -e tcp.stream -e frame.time -e tcp.checksum -R &#34;tcp&#34; | grep &#34;.02696400&#34; | more
The result is &#34;20 Dec 15, 2011 11:12:20.</description>
    </item>
    
    <item>
      <title>Wireshark not showing protocol field   as &amp;quot;RTSP&amp;quot;  for RTSP_IPv6 capture</title>
      <link>/questions/8325/wireshark-not-showing-protocol-field-as-rtsp-for-rtsp_ipv6-capture/</link>
      <pubDate>Wed, 11 Jan 2012 06:08:00 +0000</pubDate>
      
      <guid>/questions/8325/wireshark-not-showing-protocol-field-as-rtsp-for-rtsp_ipv6-capture/</guid>
      <description>Wireshark not showing protocol field as &amp;ldquo;RTSP&amp;rdquo; for RTSP_IPv6 capture  0 I had opened RTSP_IPv6 capture using wireshark and it shows protocol field as &#34;TCP&#34; instead of &#34;RTSP&#34;. Can anyone explain me why its happening and also Info field saying that &#34;TCP segment reassembeld PDU&#34;..
Uploaded Capture image.Refer below link.
http://www.flickr.com/photos/[email protected]/6678771333/in/photostream/
streaming rtsp ipv6asked 11 Jan &#39;12, 06:08
JK7
31●11●12●14
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>RTP Stream Analysis from command line</title>
      <link>/questions/8326/rtp-stream-analysis-from-command-line/</link>
      <pubDate>Wed, 11 Jan 2012 06:47:00 +0000</pubDate>
      
      <guid>/questions/8326/rtp-stream-analysis-from-command-line/</guid>
      <description>RTP Stream Analysis from command line  0 Hi all,
I need to save the RTP stream analisys in CSV format from command line and I don&#39;t know how. I tried typing &#34;tshark -r myrtpfile.cap -q -z rtp,streams&#34; but it just display the statistics. I need the information shown by in table (what it&#39;s obtained by pressing the &#34;save as CSV&#34;).
Thanks in advance.
Kind regards.
rtp analysisasked 11 Jan &#39;12, 06:47</description>
    </item>
    
    <item>
      <title>Order of entries in dissector tables at startup and lua</title>
      <link>/questions/8328/order-of-entries-in-dissector-tables-at-startup-and-lua/</link>
      <pubDate>Wed, 11 Jan 2012 09:07:00 +0000</pubDate>
      
      <guid>/questions/8328/order-of-entries-in-dissector-tables-at-startup-and-lua/</guid>
      <description>Order of entries in dissector tables at startup and lua  0 1Hello, I&#39;m trying to modify RTP dissector table with Lua. When I create a Lua script like below and run it either from plugins directory or the command line it doesn&#39;t work, and I can see via Internals -&amp;gt; Dissector Tables that my entry was overwritten by AMR protocol.
local ip_dissector = Dissector.get(&amp;quot;ip&amp;quot;) local rtp_table = DissectorTable.get(&amp;quot;rtp.pt&amp;quot;) rtp_table:add(96, ip_dissector)However, when I enter the same code via the evaluate window and reload the pcap file, it works as expected.</description>
    </item>
    
    <item>
      <title>how to execute winshark without installation on win2k3</title>
      <link>/questions/8333/how-to-execute-winshark-without-installation-on-win2k3/</link>
      <pubDate>Thu, 12 Jan 2012 06:04:00 +0000</pubDate>
      
      <guid>/questions/8333/how-to-execute-winshark-without-installation-on-win2k3/</guid>
      <description>how to execute winshark without installation on win2k3  0 can i execute winshark from the folder dump c:\programfiles\winshark\ installed on server 1 and copy the same folder to server 2 (not installing wireshark) and execute the same, would it work.
Prem
wiresharkThis question is marked &#34;community wiki&#34;.asked 12 Jan &#39;12, 06:04
prem055555
1●1●1●1
accept rate: 0%
 edited 12 Jan &#39;12, 06:40 
grahamb ♦
19.8k●3●30●206</description>
    </item>
    
    <item>
      <title>when is add_oid() funtion called?</title>
      <link>/questions/8335/when-is-add_oid-funtion-called/</link>
      <pubDate>Thu, 12 Jan 2012 07:13:00 +0000</pubDate>
      
      <guid>/questions/8335/when-is-add_oid-funtion-called/</guid>
      <description>when is add_oid() funtion called?  0 When is the add_oid() function that is present in epan\dissectors\oids.h called? Where particularly are the values for the funtion add_oid() passed?
developmentThis question is marked &#34;community wiki&#34;.asked 12 Jan &#39;12, 07:13
Premini Francis
1●2●2●2
accept rate: 0%
 edited 12 Jan &#39;12, 07:18 
bstn
375●1●4●15
  
One Answer:
  
0I presume you mean oid_add(). There is no add_oid() declared in oids.</description>
    </item>
    
    <item>
      <title>Limiting Packet Captures?</title>
      <link>/questions/8342/limiting-packet-captures/</link>
      <pubDate>Thu, 12 Jan 2012 08:43:00 +0000</pubDate>
      
      <guid>/questions/8342/limiting-packet-captures/</guid>
      <description>Limiting Packet Captures?  0 Watching tutorials and reading Guides has helped much but I&#39;ve noticed that the instructors on said tutorial/guide don&#39;t capture as many packets as I do when I run my chosen Capture Interface. When I start Wireshark and go to the Capture Interface list it displays 1 single Interface, Assuming this is the one for me I instantly notice a difference between Theirs and Mine. Mine is already Capturing packets: the Packets column will continue to rise (Up to 26,00 captures) while the Packets/s will grow to 10 or so then drop back to 0.</description>
    </item>
    
    <item>
      <title>How do I correct this problem with verify_tools?</title>
      <link>/questions/8344/how-do-i-correct-this-problem-with-verify_tools/</link>
      <pubDate>Thu, 12 Jan 2012 08:51:00 +0000</pubDate>
      
      <guid>/questions/8344/how-do-i-correct-this-problem-with-verify_tools/</guid>
      <description>How do I correct this problem with verify_tools?  0 I want build wireshark 1.7.0, but get the following output from the verify_tools step:
Z:\wireshark&amp;gt;nmake -f Makefile.nmake verify_tools  Microsoft (R) 程序维护实用工具 9.00.30729.01 版 版权所有(C) Microsoft Corporation。保留所有权利。  No such file or directory8: /cygdrive/z/wireshark/tools/win-setup.sh
  cannot execute: No such file or directoryve/z/wireshark/tools/win-setup.sh
  No such file or directory8: /cygdrive/z/wireshark/tools/win-setup.sh
  cannot execute: No such file or directoryve/z/wireshark/tools/win-setup.sh</description>
    </item>
    
    <item>
      <title>Calculate latency effect using number of &amp;quot;turns&amp;quot;</title>
      <link>/questions/8350/calculate-latency-effect-using-number-of-turns/</link>
      <pubDate>Thu, 12 Jan 2012 09:32:00 +0000</pubDate>
      
      <guid>/questions/8350/calculate-latency-effect-using-number-of-turns/</guid>
      <description>Calculate latency effect using number of &amp;ldquo;turns&amp;rdquo;  0 Hi all,
i&#39;d like to know if Wireshask could provide the number of change direction during a communication between 2 hosts. With this information i could estimate / calculate the latency effect for this communication.
I mean, if there are 26 (it&#39;s an example) change direction of IP traffic during a communication with 50ms of Latency. The total latency effect (loss time caused by latency) is : 26 * 0,050 = 1,3s</description>
    </item>
    
    <item>
      <title>Missing IP</title>
      <link>/questions/8353/missing-ip/</link>
      <pubDate>Thu, 12 Jan 2012 11:55:00 +0000</pubDate>
      
      <guid>/questions/8353/missing-ip/</guid>
      <description>Missing IP  0 Hi
I have a PC with Wireshark installed, the program starts and runs OK but only sees a few IP addresses on the network - there are 1000 public &amp;amp; private IP addresses. Am I missing something fundamental?
ipasked 12 Jan &#39;12, 11:55
stevewarden0
1●3●3●3
accept rate: 0%
  
2 Answers:
  
1Yep: :)
Undoubtedly, your PC is on a switch which will send to your PC only packets addressed to your PC (and also broadcasts).</description>
    </item>
    
    <item>
      <title>Protocol Hierarchy Meaning</title>
      <link>/questions/8357/protocol-hierarchy-meaning/</link>
      <pubDate>Thu, 12 Jan 2012 12:15:00 +0000</pubDate>
      
      <guid>/questions/8357/protocol-hierarchy-meaning/</guid>
      <description>Protocol Hierarchy Meaning  0 Hi,
I want to know what the &#34;DATA&#34; protocol under &#34;Statistics&amp;gt; Protocol Hierarchy&amp;gt; Frame&amp;gt; Ethernet&amp;gt; IPv4&amp;gt; TCP &amp;gt; DATA&#34; means.
I&#39;m analizing several captures but I don´t have any idea what this DATA means.
Best regards and thank for the help.
protocol statistics data ipv4 tcpasked 12 Jan &#39;12, 12:15
DavOz
1●1●1●3
accept rate: 0%
 edited 12 Jan &#39;12, 12:40</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t find: peflag in wireshark 1.6.5</title>
      <link>/questions/8366/cant-find-peflag-in-wireshark-165/</link>
      <pubDate>Fri, 13 Jan 2012 00:43:00 +0000</pubDate>
      
      <guid>/questions/8366/cant-find-peflag-in-wireshark-165/</guid>
      <description>Can&amp;rsquo;t find: peflag in wireshark 1.6.5  0 I tried to make build for 64-bit Windows 7 with wireshark 1.6.5. The following command: nmake -f Makefile.nmake verify_tools gave me an error: can&#39;t find: peflags The ERROR: These application(s) are either not installed or simply can&#39;t be found in the current PATH: How to resolve it?
1.6.5asked 13 Jan &#39;12, 00:43
vish
0●5●5●7
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Max data rates shown in wireshark wrong?</title>
      <link>/questions/8370/max-data-rates-shown-in-wireshark-wrong/</link>
      <pubDate>Fri, 13 Jan 2012 07:30:00 +0000</pubDate>
      
      <guid>/questions/8370/max-data-rates-shown-in-wireshark-wrong/</guid>
      <description>Max data rates shown in wireshark wrong?  0 I am sniffing packets(wireless) using AirPcap Nx and notice that the max data rates that Wireshark is showing is only 58.5. I know they are sending and receiving at higher rates than what is shown because we have another system that has a paid sniffer program on it that shows higher rates. Also, our devices say what they are transmitting at. Is this a limitation in Wireshark, or a setting I need to adjust?</description>
    </item>
    
    <item>
      <title>Why aren&amp;#x27;t my expert-infos filterable?</title>
      <link>/questions/8371/why-arent-my-expert-infos-filterable/</link>
      <pubDate>Fri, 13 Jan 2012 07:55:00 +0000</pubDate>
      
      <guid>/questions/8371/why-arent-my-expert-infos-filterable/</guid>
      <description>Why aren&amp;rsquo;t my expert-infos filterable?  0 I have a plugin dissector which may attach expert info to a packet as shown below:
if(EXPERT_CONDITION(p_item)) { expert_add_info_format(pinfo, p_item, PI_PROTOCOL, PI_WARN, &amp;quot;expert warning&amp;quot;); }Here, EXPERT_CONDITION is a macro that examines the data in p_item (equivalent to the code given in my answer here). I have captures where this expert info is visible in the tree, but no other expert info is present in the packet.</description>
    </item>
    
    <item>
      <title>DTLS decryption not working on Wireshark 1.6.5, even for sample capture</title>
      <link>/questions/8373/dtls-decryption-not-working-on-wireshark-165-even-for-sample-capture/</link>
      <pubDate>Fri, 13 Jan 2012 09:20:00 +0000</pubDate>
      
      <guid>/questions/8373/dtls-decryption-not-working-on-wireshark-165-even-for-sample-capture/</guid>
      <description>DTLS decryption not working on Wireshark 1.6.5, even for sample capture  0 Hi everyone,
Wireshark will not decrypt a DTLS capture, even when using the sample capture and private key provided in http://wiki.wireshark.org/DTLS (SampleCaptures/snakeoil.tgz).
My log file is shown below. Any help is greatly appreciated!
Private key imported: KeyID dd:29:74:15:7b:e6:76:47:f5:f0:68:3e:8a:55:61:62:... ssl_init IPv4 addr &amp;#39;127.0.0.1&amp;#39; (127.0.0.1) port &amp;#39;4433&amp;#39; filename &amp;#39;c:\snakeoil-rsa.key&amp;#39; password(only for p12 file) &amp;#39;&amp;#39; ssl_init private key file c:\snakeoil-rsa.key successfully loaded.</description>
    </item>
    
    <item>
      <title>porting from Linux to Windows - RC5 Decryption</title>
      <link>/questions/8377/porting-from-linux-to-windows-rc5-decryption/</link>
      <pubDate>Fri, 13 Jan 2012 10:59:00 +0000</pubDate>
      
      <guid>/questions/8377/porting-from-linux-to-windows-rc5-decryption/</guid>
      <description>porting from Linux to Windows - RC5 Decryption  0 Hi,
I am trying to port a dissector from Linux to Windows. The dissector requires rc5 encryption/decryption capability and the Linux code uses openssl rc5 header files. It seems wireshark doesnt use openssl instead uses GNUTLS. I am wondering if there is a way to use openssl for wireshark dissector development ? if yes, what changes are needed in the source code ?</description>
    </item>
    
    <item>
      <title>Wireshark TCAP BER error</title>
      <link>/questions/8378/wireshark-tcap-ber-error/</link>
      <pubDate>Fri, 13 Jan 2012 11:43:00 +0000</pubDate>
      
      <guid>/questions/8378/wireshark-tcap-ber-error/</guid>
      <description>Wireshark TCAP BER error  0 Hi Community,
I am trying to decode a GSM-MAP message and always see an error in the TCAP layer as &#39;BER Error: This error lies beyond the end of the known sequence definition.&#39;
This error is only in the first MAP-PUSSR and MAP-USSR message, rest all messages are fine. I am using Wireshark version 1.6.1 to capture data. Kindly note MAP is running on SCTP.</description>
    </item>
    
    <item>
      <title>Cant Resize Columns in Graph Analysis Window</title>
      <link>/questions/8382/cant-resize-columns-in-graph-analysis-window/</link>
      <pubDate>Fri, 13 Jan 2012 19:33:00 +0000</pubDate>
      
      <guid>/questions/8382/cant-resize-columns-in-graph-analysis-window/</guid>
      <description>Cant Resize Columns in Graph Analysis Window  0 Hi Folks,
I&#39;m new w/ WS. Learning how to use it to decode SIP session problems. I love the graph showing the dance that occurs between the endpoint and the Registrar/Proxy. I am not able to resize its columns even though the &#34;middle&#34; separator has those traction bumps on it and when the mouse hovers over it, I get a left/right arrow icon.</description>
    </item>
    
    <item>
      <title>what is all this chatter between my router and computer</title>
      <link>/questions/8383/what-is-all-this-chatter-between-my-router-and-computer/</link>
      <pubDate>Fri, 13 Jan 2012 20:00:00 +0000</pubDate>
      
      <guid>/questions/8383/what-is-all-this-chatter-between-my-router-and-computer/</guid>
      <description>what is all this chatter between my router and computer  0 what is all this chatter between my router and computer endless obscure names continuously exchanged between router and computer. no outside IPs just names like websphere, arkivio, spiral, ironmail, embrace, galileolog, odeumservlink, starquiz-port, raven-rmp, voispeed-port etc. etc. ad nauseum.
What is all this stuff? Is it necessary? Where is it coming from? Can/should I be concerned about it?</description>
    </item>
    
    <item>
      <title>How can I decode email message from Outlook 2010 to Exchange server 2003?</title>
      <link>/questions/8390/how-can-i-decode-email-message-from-outlook-2010-to-exchange-server-2003/</link>
      <pubDate>Sun, 15 Jan 2012 01:20:00 +0000</pubDate>
      
      <guid>/questions/8390/how-can-i-decode-email-message-from-outlook-2010-to-exchange-server-2003/</guid>
      <description>How can I decode email message from Outlook 2010 to Exchange server 2003?  0 I am trying to capture and decode email message body (client App is Outlook 2010 and server is Exchange server 2003), wireshark capture packets with &#34;DCERPC&#34; protocol and reassemble data packets, but can&#39;t decode App protocol, that is MAPI. How can i decode App data from DCERPC Stub-Data field?
outlook2010 exchangeserver2003 mapi dcerpcasked 15 Jan &#39;12, 01:20</description>
    </item>
    
    <item>
      <title>Just want to See MAC Addresses - what is the filter wording?</title>
      <link>/questions/8391/just-want-to-see-mac-addresses-what-is-the-filter-wording/</link>
      <pubDate>Sun, 15 Jan 2012 01:31:00 +0000</pubDate>
      
      <guid>/questions/8391/just-want-to-see-mac-addresses-what-is-the-filter-wording/</guid>
      <description>Just want to See MAC Addresses - what is the filter wording?  0 Hi Big Time NEWBIE, just want to know the simple filter term for finding MAC addresses. Can someone please quickly tell me the right filter command string to display MAC only.
Also if the command can be written in a way to not show my own MAC address.
Thanks
PEter
filter macasked 15 Jan &#39;12, 01:31</description>
    </item>
    
    <item>
      <title>Does packet capture work inside of VMWare?</title>
      <link>/questions/8394/does-packet-capture-work-inside-of-vmware/</link>
      <pubDate>Sun, 15 Jan 2012 09:09:00 +0000</pubDate>
      
      <guid>/questions/8394/does-packet-capture-work-inside-of-vmware/</guid>
      <description>Does packet capture work inside of VMWare?  0 Does anyone know if you can sniff network packets with Wireshark in a virtual machine? Networks settings with NAT doesn&#39;t show anything and Bridged only shows the traffic to and from the host. I&#39;m using BackTrack 3. Promiscuous mode is enabled.
vmware nat bridged backtrackasked 15 Jan &#39;12, 09:09
mpneele
1●1●1●1
accept rate: 0%
 edited 15 Jan &#39;12, 19:39</description>
    </item>
    
    <item>
      <title>Iu UP payload CRC - CRC10 poly</title>
      <link>/questions/8403/iu-up-payload-crc-crc10-poly/</link>
      <pubDate>Mon, 16 Jan 2012 03:36:00 +0000</pubDate>
      
      <guid>/questions/8403/iu-up-payload-crc-crc10-poly/</guid>
      <description>Iu UP payload CRC - CRC10 poly  0 Hi All,
CRC-10 poly = G(D) = D^10+D^9+D^5+D^4+D^1+1
I thought it is simple CRC-10 implementation. But Wireshark does this in different way. Why it so?
You can find the code here.
Wireshark code is different. Due to this I am getting CRC error in Iu UP layer.
If the way I implement is wrong then please explain how Wireshark is calculating CRC-10.</description>
    </item>
    
    <item>
      <title>CDP question</title>
      <link>/questions/8410/cdp-question/</link>
      <pubDate>Mon, 16 Jan 2012 09:24:00 +0000</pubDate>
      
      <guid>/questions/8410/cdp-question/</guid>
      <description>CDP question  0 The only thing that is not clear for me is the fact that for example I connect a cisco access point to a cisco swith with cdp enable both running same version and if then I SPAN the port connecting the access point I can clear see that the cdp packet reaching the port on the switch and then I should display at the other end with show cdp nei to say something.</description>
    </item>
    
    <item>
      <title>how to decrypt http over sslv3 (https) rsa NON diffie helman with a valid client auth cert</title>
      <link>/questions/8411/how-to-decrypt-http-over-sslv3-https-rsa-non-diffie-helman-with-a-valid-client-auth-cert/</link>
      <pubDate>Mon, 16 Jan 2012 10:06:00 +0000</pubDate>
      
      <guid>/questions/8411/how-to-decrypt-http-over-sslv3-https-rsa-non-diffie-helman-with-a-valid-client-auth-cert/</guid>
      <description>how to decrypt http over sslv3 (https) rsa NON diffie helman with a valid client auth cert  0 I have a valid sslv3 client authentication cert. that I use to access a company&#39;s web-site. The transaction works fine in a standard web browser. I would like to decrypt the ssl session (the server to client application data specifically). Maybe it is simply my ignorance, but shouldn&#39;t this be possible? I believe the client to server app data is encrypted with their public cert, so I am not sure if is this is accessible intra-wireshark, but I would minimally like to get the responses decrypted.</description>
    </item>
    
    <item>
      <title>TCP ZeroWindow loop</title>
      <link>/questions/8412/tcp-zerowindow-loop/</link>
      <pubDate>Mon, 16 Jan 2012 10:25:00 +0000</pubDate>
      
      <guid>/questions/8412/tcp-zerowindow-loop/</guid>
      <description>TCP ZeroWindow loop  0 My NFS client and NetApp filer got stuck in this loop of ACKs and ZeroWindows. This repeated over and over until i finally dropped the connection with tcpdrop. I&#39;m thinking this is a bug on the NetApp filer, can someone help me break down exactly what is happening? It seems like my client (10.231.96.85) is waiting for an acknowledgment of 55k of data, but the filer (10.</description>
    </item>
    
    <item>
      <title>Implementing a independent protocol in wireshark.</title>
      <link>/questions/8423/implementing-a-independent-protocol-in-wireshark/</link>
      <pubDate>Tue, 17 Jan 2012 00:37:00 +0000</pubDate>
      
      <guid>/questions/8423/implementing-a-independent-protocol-in-wireshark/</guid>
      <description>Implementing a independent protocol in wireshark.  0 Hi,
I want to implement a protocol in wireshark and decode its packets according to what is mentioned in the protocol specification. The protocol needs not to be a networking protocol. I will provide the data to decode in form of .csv file format.
I have read the developers guide on implementing custom dissector on top of some other protocol like tcp/udp etc.</description>
    </item>
    
    <item>
      <title>displaying object name</title>
      <link>/questions/8429/displaying-object-name/</link>
      <pubDate>Tue, 17 Jan 2012 03:29:00 +0000</pubDate>
      
      <guid>/questions/8429/displaying-object-name/</guid>
      <description>displaying object name  0 which function in which file displays the object name part in the wireshark?
object nameasked 17 Jan &#39;12, 03:29
Premini Francis
1●2●2●2
accept rate: 0%
Your question is very unclear; could you specify some more details? What object name? Where in Wirehshark is it displayed? What protocol are you talking about, and is it a protocol at all?
(17 Jan &#39;12, 03:32) Jasper ♦♦The object name that is displayed in packet details of the SNMP protocol.</description>
    </item>
    
    <item>
      <title>IP4 Endpoints are not shown in the MAP</title>
      <link>/questions/8435/ip4-endpoints-are-not-shown-in-the-map/</link>
      <pubDate>Tue, 17 Jan 2012 06:53:00 +0000</pubDate>
      
      <guid>/questions/8435/ip4-endpoints-are-not-shown-in-the-map/</guid>
      <description>IP4 Endpoints are not shown in the MAP  0 I use Wireshark 1.6.5 with Ubuntu 10.04. Opening existing pcap files and using Statistics - Endpoints - IPv4 the result by clicking the button - MAP - is the following. Ipmap.html from /tmp/.... will be opened by browser Google Chrome (failure: GoogleChrome cannot be started as root). After deinstalling Google Chrome the result by clicking the button -MAP - the browser OPERA starts, but shows not the mapdata, coming from ipmap.</description>
    </item>
    
    <item>
      <title>Error when opening a WireShark capture</title>
      <link>/questions/8437/error-when-opening-a-wireshark-capture/</link>
      <pubDate>Tue, 17 Jan 2012 08:25:00 +0000</pubDate>
      
      <guid>/questions/8437/error-when-opening-a-wireshark-capture/</guid>
      <description>Error when opening a WireShark capture  0 I was sent a wireshark capture from a customer but received the following error when I tried to open it:
The file &#34;{network shared drive}CAD.cap&#34; is a capture for a network type that Wireshark doesn&#39;t support. (Observer: unsupported file version ObserverPktBufferVersion=15.00)
I&#39;m trying to get information on this but not able to find anything yet. If there might be some suggestions, it would be helpful.</description>
    </item>
    
    <item>
      <title>Re: Capturing Incoming Email Addresses</title>
      <link>/questions/8452/re-capturing-incoming-email-addresses/</link>
      <pubDate>Wed, 18 Jan 2012 04:30:00 +0000</pubDate>
      
      <guid>/questions/8452/re-capturing-incoming-email-addresses/</guid>
      <description>Re: Capturing Incoming Email Addresses  0 I am working in the Marketing Communications position for a company, newly appointed. I was curious if Wireshark is able to capture incoming email addresses - visitors to sites, etc...anything that can help us with our business growth and base for email blasts, etc...
incomingemailThis question is marked &#34;community wiki&#34;.asked 18 Jan &#39;12, 04:30
ellyn83
1●1●1●1
accept rate: 0%
Sure, WireShark can do this.</description>
    </item>
    
    <item>
      <title>Wireshark &amp;amp; Lan-party</title>
      <link>/questions/8456/wireshark-lan-party/</link>
      <pubDate>Wed, 18 Jan 2012 10:54:00 +0000</pubDate>
      
      <guid>/questions/8456/wireshark-lan-party/</guid>
      <description>Wireshark &amp;amp; Lan-party  0 We&#39;re gonna have LAN-party with around 160 people and we thought using WireShark to monitor what is going on in our network, for example is there any BitTorrent-traffic or if someone using large amount of bandwith. Can WireShark handle that much data or will it run out of memory in 5 seconds? We dont have capacity to test this before the actual event.
Thank you for great program!</description>
    </item>
    
    <item>
      <title>Wireshark host file trouble with Windows 7</title>
      <link>/questions/8460/wireshark-host-file-trouble-with-windows-7/</link>
      <pubDate>Wed, 18 Jan 2012 19:12:00 +0000</pubDate>
      
      <guid>/questions/8460/wireshark-host-file-trouble-with-windows-7/</guid>
      <description>Wireshark host file trouble with Windows 7  0 I tried to create a simple host file in Wireshark using Windows 7 64-bit Ultimate edition and in captures, I see a lot of DNS request error packets stating no such name exists. I know with the virtual folders in Windows, i had to go to I assumed C:\%username%\AppData\roaming\wireshark to create the text document named &#34;hosts&#34; in notepad. Is this the correct path or anyone else experience similar results?</description>
    </item>
    
    <item>
      <title>Acknowledgment number: Broken TCP. The acknowledge field is nonzero while the ACK flag is not set</title>
      <link>/questions/8465/acknowledgment-number-broken-tcp-the-acknowledge-field-is-nonzero-while-the-ack-flag-is-not-set/</link>
      <pubDate>Thu, 19 Jan 2012 05:05:00 +0000</pubDate>
      
      <guid>/questions/8465/acknowledgment-number-broken-tcp-the-acknowledge-field-is-nonzero-while-the-ack-flag-is-not-set/</guid>
      <description>Acknowledgment number: Broken TCP. The acknowledge field is nonzero while the ACK flag is not set  1 Hi,
We are currently having a recurring (and intermittent) problem with an in-house application connecting to a server sitting on our local network. The process works fine for a certain amount of time (sometimes hours, sometimes days - never more than 48 Hours) then suddenly starts failing - the application hosted on the workstation throwing error messages.</description>
    </item>
    
    <item>
      <title>UAT issue in wireshark</title>
      <link>/questions/8466/uat-issue-in-wireshark/</link>
      <pubDate>Thu, 19 Jan 2012 05:31:00 +0000</pubDate>
      
      <guid>/questions/8466/uat-issue-in-wireshark/</guid>
      <description>UAT issue in wireshark  0 I m facing an issue using UAT in wireshark. Whatever value I m putting in the &#34;port&#34; box of UAT it takes the value used in UAT_FLD_RANGE(basename,field_name,title,max,desc). Suppose I enter a value of 123 in the box in UAT and then click &#34;OK&#34;, then it still stores &#34;max&#34; in the above mentioned function. I want to know when we click &#34;OK&#34; in the UAT how does it store the value we enter so that I can debug the issue.</description>
    </item>
    
    <item>
      <title>Merge error - Wireshark can&amp;#x27;t save this capture in that format.</title>
      <link>/questions/8469/merge-error-wireshark-cant-save-this-capture-in-that-format/</link>
      <pubDate>Thu, 19 Jan 2012 07:36:00 +0000</pubDate>
      
      <guid>/questions/8469/merge-error-wireshark-cant-save-this-capture-in-that-format/</guid>
      <description>Merge error - Wireshark can&amp;rsquo;t save this capture in that format.  0 I am trying to merge two capture files i downloaded from the sample captures from wireshark site. zigbee-join-authenticate.pcap Teredo.pcap
Every time i select a file to merge with currently opened cature file i get the following dialogue box
&#34;Wireshark can&#39;t save this capture in that format.&#34;
Could some one tell me what the issue is?
merge capture-file-mergeasked 19 Jan &#39;12, 07:36</description>
    </item>
    
    <item>
      <title>Using wireshark to spoof chat</title>
      <link>/questions/8474/using-wireshark-to-spoof-chat/</link>
      <pubDate>Thu, 19 Jan 2012 08:30:00 +0000</pubDate>
      
      <guid>/questions/8474/using-wireshark-to-spoof-chat/</guid>
      <description>Using wireshark to spoof chat  0 I know that wireshark can monitor plaintext chats for IRC, facebook, gmail, etc etc, but has anyone tried to inject data packets to fake a conversation with someone? Meaning, the victim thinks they are talking to someone else..thanks!
spoof irc inject chatasked 19 Jan &#39;12, 08:30
xenos
1●1●1●1
accept rate: 0%
  
One Answer:
  
0 Wireshark is a packet analyzer not a packet generator.</description>
    </item>
    
    <item>
      <title>Monitoring NORM message and decoding it</title>
      <link>/questions/8482/monitoring-norm-message-and-decoding-it/</link>
      <pubDate>Thu, 19 Jan 2012 11:15:00 +0000</pubDate>
      
      <guid>/questions/8482/monitoring-norm-message-and-decoding-it/</guid>
      <description>Monitoring NORM message and decoding it  0 Attempting to capture NORM message at the Ethernet port. Changed the filter selection only to NORM and TCP. Wireshark capture window displays UNKONWN on protocol column.
Please help where I am making mistake. I am using Wireshark 1.6.0 on Windows XP machine.
Also, do I need a Wireshark decoder plugin
normasked 19 Jan &#39;12, 11:15
sss
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Name resolution question when mirroring ports on a switch...</title>
      <link>/questions/8485/name-resolution-question-when-mirroring-ports-on-a-switch/</link>
      <pubDate>Thu, 19 Jan 2012 17:08:00 +0000</pubDate>
      
      <guid>/questions/8485/name-resolution-question-when-mirroring-ports-on-a-switch/</guid>
      <description>Name resolution question when mirroring ports on a switch&amp;hellip;  0 Folks,
I am relatively new to Wireshark. I am monitoring my home network traffic by mirroring a port on my GS116E sent to a second NIC on one of my PCs. I have my router (WRT54GL) set up to tee POSTROUTED traffic to this monitor NIC as well. This is working well and I see all the wired, wireless, and WAN traffic.</description>
    </item>
    
    <item>
      <title>Wireshark dissector for decoding GTP Prime (CDR)</title>
      <link>/questions/8486/wireshark-dissector-for-decoding-gtp-prime-cdr/</link>
      <pubDate>Thu, 19 Jan 2012 17:52:00 +0000</pubDate>
      
      <guid>/questions/8486/wireshark-dissector-for-decoding-gtp-prime-cdr/</guid>
      <description>Wireshark dissector for decoding GTP Prime (CDR)  0 I am using Wireshark Version 1.6.4 (SVN Rev 39941 from /trunk-1.6).
I would like to decode GTP Prime (CDR) messages as per the ASN.1 syntax specified in 3GPP Specification 32.298.
This feature is already available in Wireshark?. If yes, please suggest how to add/install the required plugin/dissector.
Thanks Raja
gtp prime 3gpp 32.298 cdrasked 19 Jan &#39;12, 17:52
Rajathi Raja
1●1●1●1</description>
    </item>
    
    <item>
      <title>How to configure router and port mirroring to minimize repeat packets?</title>
      <link>/questions/8489/how-to-configure-router-and-port-mirroring-to-minimize-repeat-packets/</link>
      <pubDate>Thu, 19 Jan 2012 19:38:00 +0000</pubDate>
      
      <guid>/questions/8489/how-to-configure-router-and-port-mirroring-to-minimize-repeat-packets/</guid>
      <description>How to configure router and port mirroring to minimize repeat packets?  0 Folks,
My home network is set up as MODEM &amp;lt;--&amp;gt; WAP (WRT54GL) &amp;lt;--&amp;gt; 16 port switch (GS116E). I have a 2nd NIC in my monitor computer connected to a port on the GS116E set up to mirror the computer ports. I do not mirror the NAS or uplink ports. Then I tee at the router which sends a copy of any traffic handled by the access point (iptables -A POSTROUTING -t mangle -j ROUTE --gw 10.</description>
    </item>
    
    <item>
      <title>TCP Retransmission is detected instead of a duplicate ip packet</title>
      <link>/questions/8490/tcp-retransmission-is-detected-instead-of-a-duplicate-ip-packet/</link>
      <pubDate>Thu, 19 Jan 2012 21:59:00 +0000</pubDate>
      
      <guid>/questions/8490/tcp-retransmission-is-detected-instead-of-a-duplicate-ip-packet/</guid>
      <description>TCP Retransmission is detected instead of a duplicate ip packet  0 1Hi,
I expect that there is a wrong TCP-retransmission detected where wireshark should detect a duplicate ip packet. We would like a possibility to filter out any duplicate ip packets (means same IP-Identification in a flow) caused by mirroring multiple interfaces on a switch at the same time (eg. before and after a firewall). The packets are different on L2 but are the same on Layer3 except TTL,.</description>
    </item>
    
    <item>
      <title>Cannot capture Local traffic</title>
      <link>/questions/8491/cannot-capture-local-traffic/</link>
      <pubDate>Thu, 19 Jan 2012 22:17:00 +0000</pubDate>
      
      <guid>/questions/8491/cannot-capture-local-traffic/</guid>
      <description>Cannot capture Local traffic  0 Dear friend, when I Open Interface select dialog I saw two interfaces 1)Marvell Yukon Ethernet controller fe80::8847.... 2)Microsoft 192.168.1.2 I want to capture local traffic 127.0.0.1:5000 to 127.0.0.1 simple terminal applications But I can&#39;t see any on above interfaces!!! I runned wireshark 1.6.4 on win7 64x professional I have same problem on many computers in my work. what should I do? Thanks Tarvirdi
traffic localasked 19 Jan &#39;12, 22:17</description>
    </item>
    
    <item>
      <title>Supported Adapters for Wireless packet capturing</title>
      <link>/questions/8504/supported-adapters-for-wireless-packet-capturing/</link>
      <pubDate>Fri, 20 Jan 2012 04:16:00 +0000</pubDate>
      
      <guid>/questions/8504/supported-adapters-for-wireless-packet-capturing/</guid>
      <description>Supported Adapters for Wireless packet capturing  0 Hello,
Please suggest us the Adapter to be used along with Wireshark for capturing Wireless packets.
If you have the list of supported adapters in your web page please direct us to the link.
Also we would like to know if the adapter model D-Link DWA-160 can be used with Wireshark for capturing Wireless packets?
Thank you.
wireless adapterasked 20 Jan &#39;12, 04:16</description>
    </item>
    
    <item>
      <title>capturing mms packet</title>
      <link>/questions/8510/capturing-mms-packet/</link>
      <pubDate>Fri, 20 Jan 2012 05:04:00 +0000</pubDate>
      
      <guid>/questions/8510/capturing-mms-packet/</guid>
      <description>capturing mms packet  0 What setting we have to do to capture mms(manufacturing message specification) on wire shark?
mmsasked 20 Jan &#39;12, 05:04
tod
1●1●1●1
accept rate: 0%
  
One Answer:
  
0The same settings you need to capture any other type of traffic; the only way the protocol would matter when capturing traffic would be if you were using a capture filter. The Wireshark dissector for MMS expects it to run atop the OSI Connection-Oriented Transport Protocol (COTP), and that&#39;s expected to run atop the OSI Connectionless Network Protocol, the TPKT protocol atop TCP, X.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t see other traffic but my own</title>
      <link>/questions/8513/cant-see-other-traffic-but-my-own/</link>
      <pubDate>Fri, 20 Jan 2012 10:12:00 +0000</pubDate>
      
      <guid>/questions/8513/cant-see-other-traffic-but-my-own/</guid>
      <description>Can&amp;rsquo;t see other traffic but my own  0 As a note, I have been using Wireshark with a hub for years and it has always worked. Now I’m experiencing the weirdest issue, I can’t see other traffic that I need, such as the Print Raster data from another computer to a networked copier. I’ve spent almost two days on this, got cables and hubs everywhere, I’ve been reading all the Help files from Wireshark online, trying everything possible.</description>
    </item>
    
    <item>
      <title>What are some ways Wireshark can be used in Network Troubleshooting?</title>
      <link>/questions/8516/what-are-some-ways-wireshark-can-be-used-in-network-troubleshooting/</link>
      <pubDate>Fri, 20 Jan 2012 12:58:00 +0000</pubDate>
      
      <guid>/questions/8516/what-are-some-ways-wireshark-can-be-used-in-network-troubleshooting/</guid>
      <description>What are some ways Wireshark can be used in Network Troubleshooting?  0 I am a noob at networking and i am currently writing a paper for my basic networking class, i was told by my teacher as a hint that Wire shark can be used for Network Troubleshooting and so i was curious how it is used in this manner?
I was hoping to use this a source for my Paper since i need between 3-5 Pages and 3-4 Sources.</description>
    </item>
    
    <item>
      <title>Collect expert.message from tshark</title>
      <link>/questions/8518/collect-expertmessage-from-tshark/</link>
      <pubDate>Fri, 20 Jan 2012 14:01:00 +0000</pubDate>
      
      <guid>/questions/8518/collect-expertmessage-from-tshark/</guid>
      <description>Collect expert.message from tshark  0 Is there some way to extract expert.message from a pcap using tshark?
I&#39;d like to do something like this in an automated script to get the number of packets with an expert message of severity Warn:
tshark -R &amp;quot;expert.severity eq Warn&amp;quot; -r eth1.pcap | wc -lThat just errs:
tshark: Neither &amp;quot;expert.severity&amp;quot; nor &amp;quot;Warn&amp;quot; are field or protocol names.Any suggestions would be very much appreciated!</description>
    </item>
    
    <item>
      <title>How does wireshark calculate jitter</title>
      <link>/questions/8520/how-does-wireshark-calculate-jitter/</link>
      <pubDate>Fri, 20 Jan 2012 14:58:00 +0000</pubDate>
      
      <guid>/questions/8520/how-does-wireshark-calculate-jitter/</guid>
      <description>How does wireshark calculate jitter  0 If I have a piece of test gear connected to a switch stack and it is sending simulated voice traffic and I sniff the up-link port leaving the stack how does wireshark calculate jitter? Seeing as how wireshark does not know what time the packet left my gear.
jitterasked 20 Jan &#39;12, 14:58
VoIP Ready
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Copy multiple URIs at once</title>
      <link>/questions/8533/copy-multiple-uris-at-once/</link>
      <pubDate>Sat, 21 Jan 2012 18:12:00 +0000</pubDate>
      
      <guid>/questions/8533/copy-multiple-uris-at-once/</guid>
      <description>Copy multiple URIs at once  0 Hi,
Is it possible to copy multiple URIs at once in Wireshark 1.6.5?
Right now, when Wireshark displays an http GET command of interest, I select the packet, then right click on the Full Request URI under &#34;Hypertext Transfer Protocol&#34;, &#34;Copy&#34;, then &#34;Value&#34;. When there are hundreds of URIs to copy, it becomes maddening.
Ideally, I would like to select the packets with ctrl+click, shift+click or ctrl+A, then right click and copy Full URIs.</description>
    </item>
    
    <item>
      <title>Read &amp;quot;WhatsApp&amp;quot; messages over wlan</title>
      <link>/questions/8539/read-whatsapp-messages-over-wlan/</link>
      <pubDate>Sun, 22 Jan 2012 01:39:00 +0000</pubDate>
      
      <guid>/questions/8539/read-whatsapp-messages-over-wlan/</guid>
      <description>Read &amp;ldquo;WhatsApp&amp;rdquo; messages over wlan  0 How can I follow messages sent over a mobile phone with WhatsApp Messenger in a local wlan?
filter whatsapp wlanasked 22 Jan &#39;12, 01:39
Anon
84●2●3●7
accept rate: 16%
 edited 22 Jan &#39;12, 07:55 
helloworld
3.1k●4●20●41
  
2 Answers:
  
0There is even an easier way to follow the conversations, if you use only the filter expression ssl contains F8:03:83:BD:AD you get the same result.</description>
    </item>
    
    <item>
      <title>How can i capture traffic with a fritz box?</title>
      <link>/questions/8541/how-can-i-capture-traffic-with-a-fritz-box/</link>
      <pubDate>Sun, 22 Jan 2012 01:46:00 +0000</pubDate>
      
      <guid>/questions/8541/how-can-i-capture-traffic-with-a-fritz-box/</guid>
      <description>How can i capture traffic with a fritz box?  1 How can i capture wlan traffic with a fritz box by avm?
avm fritz captureasked 22 Jan &#39;12, 01:46
Anon
84●2●3●7
accept rate: 16%
  
One Answer:
  
3 Most of the FRITZ!Boxes have a non-documentated page which enables a traffic capture in &#39;wireshark&#39; format for different ports. Open the page in a browser with following URL: fritz.</description>
    </item>
    
    <item>
      <title>Is it possible to capture 802.11 data packets without retaining the data?</title>
      <link>/questions/8544/is-it-possible-to-capture-80211-data-packets-without-retaining-the-data/</link>
      <pubDate>Sun, 22 Jan 2012 15:20:00 +0000</pubDate>
      
      <guid>/questions/8544/is-it-possible-to-capture-80211-data-packets-without-retaining-the-data/</guid>
      <description>Is it possible to capture 802.11 data packets without retaining the data?  0 I am presently using Wireshark and the AirPcapNx to capture 802.11 packets. My goal is to be able to analyze operation of the network without retaining the payload data in my capture files. I need header information, so cannot simply filter out entire data packets. I basically need to capture data packets, yet filter out the payload data.</description>
    </item>
    
    <item>
      <title>running capture corrects NIC failure</title>
      <link>/questions/8546/running-capture-corrects-nic-failure/</link>
      <pubDate>Sun, 22 Jan 2012 15:33:00 +0000</pubDate>
      
      <guid>/questions/8546/running-capture-corrects-nic-failure/</guid>
      <description>running capture corrects NIC failure  0 I am using a Realtek PCIe GBE NIC on a Sony Vaio running Windows 7.
Suddenly last week this NIC stopped commuicating beyone its gateway. The NIC can successfully ping its gateway but does not receive ping replies from any host beyond the gateway.
So I attempted to use Wireshark to diagnose this failure. Astoundingly, as soon as I started the Wireshark capture, the NIC is able to successfully communicate with the Internet.</description>
    </item>
    
    <item>
      <title>Suspicious ARP activity?</title>
      <link>/questions/8547/suspicious-arp-activity/</link>
      <pubDate>Sun, 22 Jan 2012 16:13:00 +0000</pubDate>
      
      <guid>/questions/8547/suspicious-arp-activity/</guid>
      <description>Suspicious ARP activity?  0 I&#39;m kind of new to the world of monitoring network activity and I&#39;m seeing something in my logs that concerns me a little.
One computer, and only one, seems to be sending ARP requests to every single possible IP address (&#34;Who has 192.168.1.1, Who has 192.168.1.2... etc.).
No other machine on this network is doing this. As I cannot fathom any legitimate reason any machine ought to be pinging every possible address, I&#39;m thinking this machine probably has a virus looking to do mischief.</description>
    </item>
    
    <item>
      <title>assert_not_reached:</title>
      <link>/questions/8557/assert_not_reached/</link>
      <pubDate>Mon, 23 Jan 2012 04:02:00 +0000</pubDate>
      
      <guid>/questions/8557/assert_not_reached/</guid>
      <description>assert_not_reached:  0 hello,
i&#39;m working on a project, that uses libwireshark.so while initializing the dissector &#34;init_dissection()&#34; it flashes an
error &#34; Dissector bug, protocol Ethernet, in packet 1: tvbuff.c:902: failed assertion &#34;DISSECTOR_ASSERT_NOT_REACHED&#34;
why i am getting this error: possible solutions.??
thanks!
dissector assertion wiresharkasked 23 Jan &#39;12, 04:02
Sanny_D
0●18●20●21
accept rate: 50%
1What version of Wireshark are you building from ??
In any case, you are basically on your own if you are trying to use libwireshark directly.</description>
    </item>
    
    <item>
      <title>Wireshark is sniffing only my pc&amp;#x27;s data</title>
      <link>/questions/8558/wireshark-is-sniffing-only-my-pcs-data/</link>
      <pubDate>Mon, 23 Jan 2012 04:15:00 +0000</pubDate>
      
      <guid>/questions/8558/wireshark-is-sniffing-only-my-pcs-data/</guid>
      <description>Wireshark is sniffing only my pc&amp;rsquo;s data  0 Hi,
managed to make wireshark work with my new macbook air 11&#34; with OS X 10.7.1 Lion. I can correctly see the network interface named en0 in the list of capture devices, however, when I start the packet sniffing on my own network to testing it, I only receive informations from my own computer&#39;s IP address.
How can i fix this? Is there any way?</description>
    </item>
    
    <item>
      <title>Fragmentation problems</title>
      <link>/questions/8562/fragmentation-problems/</link>
      <pubDate>Mon, 23 Jan 2012 07:15:00 +0000</pubDate>
      
      <guid>/questions/8562/fragmentation-problems/</guid>
      <description>Fragmentation problems  0 I&#39;m facing several problems on handling fragmented packets. Actually I have a packet with a 0x8F length, that comes in 2 parts, the first one with 0x72, the second with the rest of the packet with some extra bytes (The total size as well the fragment size can change , but I think my problem is not that).
What I&#39;m doing is:
save_fragmented = pinfo-&amp;gt;fragmented; fragment_data *frag_msg = fragment_add_seq_check ( tvb, 1, pinfo, nRXCounter, //Key of the packet iso7816_fragment_table, iso7816_reassembled_table, nFrameCounter, // guint32 fragment sequence number starting with value 1 tvb_length(tvb), FALSE); if (frag_msg) /* Reassembled */ { col_append_str(pinfo-&amp;gt;cinfo, COL_INFO,&amp;quot; R E A S S E M B L E D &amp;quot;); } else /* Not last packet of reassembled Message */ { col_append_fstr(pinfo-&amp;gt;cinfo, COL_INFO,&amp;quot; (Message fragment # %u)&amp;quot;, nFrameCounter++); }I thought that by passing the last argument as FALSE it would stop the fragmentation and set the frag_items with the tvb data for the two incoming packets, but it doesn&#39;t happen.</description>
    </item>
    
    <item>
      <title>Using AR5212/AR5213 with wireshark in monitor mode.</title>
      <link>/questions/8564/using-ar5212ar5213-with-wireshark-in-monitor-mode/</link>
      <pubDate>Mon, 23 Jan 2012 08:08:00 +0000</pubDate>
      
      <guid>/questions/8564/using-ar5212ar5213-with-wireshark-in-monitor-mode/</guid>
      <description>Using AR5212/AR5213 with wireshark in monitor mode.  0 I am working with ubuntu 11.10.
I am able to setup a monitor device using either iwconfig or airmon-ng, but i am unable to select the monitor mode box in the wireshark capture settings.
could anybody help?
ubuntu monitor ar5213 ar5212asked 23 Jan &#39;12, 08:08
red
0●1●1●1
accept rate: 0%
  
One Answer:
  
0Just try capturing on the monitor device without checking the monitor mode box.</description>
    </item>
    
    <item>
      <title>how to find out passwords in continuation or non- http traffic?</title>
      <link>/questions/8565/how-to-find-out-passwords-in-continuation-or-non-http-traffic/</link>
      <pubDate>Mon, 23 Jan 2012 10:12:00 +0000</pubDate>
      
      <guid>/questions/8565/how-to-find-out-passwords-in-continuation-or-non-http-traffic/</guid>
      <description>how to find out passwords in continuation or non- http traffic?  -1 in my college i can&#39;t find out any post(password finding method) for http protocols it shows &#34;continuation or non-http traffic&#34; for http protocols always. im so much confused.pls help me..if im filter out the tcp stream means all the datas are in encoded format(non human understandable(in raw)). any alternative ways to detect passwords? pls help me.
continuation post nonhttpasked 23 Jan &#39;12, 10:12</description>
    </item>
    
    <item>
      <title>Wireshark teardrop attack help</title>
      <link>/questions/8574/wireshark-teardrop-attack-help/</link>
      <pubDate>Mon, 23 Jan 2012 21:00:00 +0000</pubDate>
      
      <guid>/questions/8574/wireshark-teardrop-attack-help/</guid>
      <description>Wireshark teardrop attack help  0 How would I determine what packet is causing the direct attack of a teardrop attack. I&#39;m using the Wireshark capture from Wireshark wiki: teardrop.cap
How would I analyze this capture to determine the source IP address of the attack and the destination&#39;s IP address?
capture teardrop wireshark addressasked 23 Jan &#39;12, 21:00
ssams5
1●1●1●1
accept rate: 0%
 edited 25 Jan &#39;12, 02:24</description>
    </item>
    
    <item>
      <title>PNODE_FINFO returning NULL?</title>
      <link>/questions/8576/pnode_finfo-returning-null/</link>
      <pubDate>Mon, 23 Jan 2012 23:09:00 +0000</pubDate>
      
      <guid>/questions/8576/pnode_finfo-returning-null/</guid>
      <description>PNODE_FINFO returning NULL?  0 i am working on my current project using wireshark lib,
after calling dissector run on the data buffer, i get the &#39;edt&#39; tree but when i call PNODE_FINFO on the node where (&#39;node = edt.tree&#39;)
PNODE_FINFO returns NULL what is the problem? any help.
thanks!!
proto_node wiresharkasked 23 Jan &#39;12, 23:09
Sanny_D
0●18●20●21
accept rate: 50%
  
One Answer:
  
1 You are looking at the root of the tree, that has no field info (ref epan/epan.</description>
    </item>
    
    <item>
      <title>Find InDiscards frames in a pcap file</title>
      <link>/questions/8578/find-indiscards-frames-in-a-pcap-file/</link>
      <pubDate>Tue, 24 Jan 2012 04:27:00 +0000</pubDate>
      
      <guid>/questions/8578/find-indiscards-frames-in-a-pcap-file/</guid>
      <description>Find InDiscards frames in a pcap file  0 How to find InDiscards frames in a pcap file
indiscardsasked 24 Jan &#39;12, 04:27
Raghu
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>No Voip calls in Telephony VoIP calls</title>
      <link>/questions/8583/no-voip-calls-in-telephony-voip-calls/</link>
      <pubDate>Tue, 24 Jan 2012 07:13:00 +0000</pubDate>
      
      <guid>/questions/8583/no-voip-calls-in-telephony-voip-calls/</guid>
      <description>No Voip calls in Telephony VoIP calls  0 I just downloaded wireshark 1.6.1 and have a capture with RTP traffic. When I click on Telephony VoIP Calls there are no calls detected. But if I highlite a RTP stream and do Telephony RTP Stream Analysis the Player does decode the rtp to a VoIP call that can be listened to. Only the Telephony VoIP Calls does not detect the RTP to VoIP.</description>
    </item>
    
    <item>
      <title>Are there settings specific to outgoing packet capture?</title>
      <link>/questions/8585/are-there-settings-specific-to-outgoing-packet-capture/</link>
      <pubDate>Tue, 24 Jan 2012 12:36:00 +0000</pubDate>
      
      <guid>/questions/8585/are-there-settings-specific-to-outgoing-packet-capture/</guid>
      <description>Are there settings specific to outgoing packet capture?  0 New to the forum but I need assistance with changing the settings so that it displays the outgoing packets?
settings capture-setupThis question is marked &#34;community wiki&#34;.asked 24 Jan &#39;12, 12:36
fjg
0●2●2●2
accept rate: 0%
 edited 24 Jan &#39;12, 14:02 
multipleinte...
1.3k●15●23●40
  
One Answer:
  
0Wireshark will display your outbound packets by default, unless there are none to display.</description>
    </item>
    
    <item>
      <title>How to capture outbound packets</title>
      <link>/questions/8586/how-to-capture-outbound-packets/</link>
      <pubDate>Tue, 24 Jan 2012 12:40:00 +0000</pubDate>
      
      <guid>/questions/8586/how-to-capture-outbound-packets/</guid>
      <description>How to capture outbound packets  0 I have been attempting to change the settings to capture outbound packets. Can someone guide me on how to do so?
capture outboundasked 24 Jan &#39;12, 12:40
fjg
0●2●2●2
accept rate: 0%
 edited 26 Feb &#39;12, 20:50 
cmaynard ♦♦
9.4k●10●38●142
   </description>
    </item>
    
    <item>
      <title>Why can&amp;#x27;t I capture 802.11n data packets?</title>
      <link>/questions/8587/why-cant-i-capture-80211n-data-packets/</link>
      <pubDate>Tue, 24 Jan 2012 13:06:00 +0000</pubDate>
      
      <guid>/questions/8587/why-cant-i-capture-80211n-data-packets/</guid>
      <description>Why can&amp;rsquo;t I capture 802.11n data packets?  0 I have two ralink wireless cards (2860) with 802.11a/b/g/n support. I have put these (2 computers) in adhoc mode. I have an atheros (ath9k) wireless card which is in monitor mode listening in the same channel as adhoc network. I can see beacon and acknowledgements getting exchanged, but I am not able to see data packets which are being exchanged in Wireshark.</description>
    </item>
    
    <item>
      <title>Windows Server 2003 doesn&amp;#x27;t see IPv6 packets with Wireshark</title>
      <link>/questions/8588/windows-server-2003-doesnt-see-ipv6-packets-with-wireshark/</link>
      <pubDate>Tue, 24 Jan 2012 13:55:00 +0000</pubDate>
      
      <guid>/questions/8588/windows-server-2003-doesnt-see-ipv6-packets-with-wireshark/</guid>
      <description>Windows Server 2003 doesn&amp;rsquo;t see IPv6 packets with Wireshark  0 This is a VM on an HP G7 server. I know....it&#39;s an OLD OS, but it is necesary for my application. If I use Linux or XP or anything else, it picks up the V6 packets fine. Seems like it is getting discarded at a low level. Any ideas? -Chris
windows 2003 server w2k3 ipv6asked 24 Jan &#39;12, 13:55</description>
    </item>
    
    <item>
      <title>WS does not see my Hamachi adapter?</title>
      <link>/questions/8591/ws-does-not-see-my-hamachi-adapter/</link>
      <pubDate>Tue, 24 Jan 2012 14:57:00 +0000</pubDate>
      
      <guid>/questions/8591/ws-does-not-see-my-hamachi-adapter/</guid>
      <description>WS does not see my Hamachi adapter?  0 Hi, can anyone advise? WS sees all my NIs/adapters (including my Realtek gigabit NIC, my VMware virtual adapter, OpenVPN, Tunngle) but it does not see the Logmein Hamachi one?
The Hamachi network is connected and clearly visible in Windows Network Connections.
Any ideas?
capture issue hamachiasked 24 Jan &#39;12, 14:57
glon
1●1●1●2
accept rate: 0%
 edited 24 Jan &#39;12, 14:59</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t download or install WS</title>
      <link>/questions/8593/cant-download-or-install-ws/</link>
      <pubDate>Tue, 24 Jan 2012 16:21:00 +0000</pubDate>
      
      <guid>/questions/8593/cant-download-or-install-ws/</guid>
      <description>Can&amp;rsquo;t download or install WS  0 Hello, I&#39;m having some trouble downloading WS (tried two versions) on a Vista 64-bit laptop. I&#39;m getting an error Directory name is invalid. With this laptop, running with 7, I can&#39;t install and I get the error message error opening file for writing c:\Program Files\Wireshark\wiretap-1.6.0.dll. Any idea is welcome. Thanks in advance
download-install wsasked 24 Jan &#39;12, 16:21
kakougne
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Home network download analysis</title>
      <link>/questions/8594/home-network-download-analysis/</link>
      <pubDate>Tue, 24 Jan 2012 17:09:00 +0000</pubDate>
      
      <guid>/questions/8594/home-network-download-analysis/</guid>
      <description>Home network download analysis  0 Hi, I have cable/router at home and then about 7 computers (wired &amp;amp; Wireless) .. also a PS3 and smart TV. I want to track the usage of each of these units in terms of download and unload. Basically, sometimes, when looking at my daily usage from my provider, I see huge traffic and I want to know which computer/unit/IP is doing this. If I install WireShark on my computer which is wired to the cable/router.</description>
    </item>
    
    <item>
      <title>Convert the raw data inside Wireshark ?</title>
      <link>/questions/8597/convert-the-raw-data-inside-wireshark/</link>
      <pubDate>Wed, 25 Jan 2012 00:52:00 +0000</pubDate>
      
      <guid>/questions/8597/convert-the-raw-data-inside-wireshark/</guid>
      <description>Convert the raw data inside Wireshark ?  0 We are planning to make a solution on our Telecom system, that would monitor the signalling messages (e.g. RANAP/CC/MM/SMS, BICC, H..248, MAP, ISUP, INAP/CAP, etc.), which belongs to specific transactions and after post-processing those would be checked in Wireshark.
The raw monitoring data will be stored in the form as they captured from the system, which means
• all the type of signaling data that were involved in the transaction would be in the same monitoring file;</description>
    </item>
    
    <item>
      <title>one way audio with SIP</title>
      <link>/questions/8604/one-way-audio-with-sip/</link>
      <pubDate>Wed, 25 Jan 2012 08:07:00 +0000</pubDate>
      
      <guid>/questions/8604/one-way-audio-with-sip/</guid>
      <description>one way audio with SIP  0 For the past 3 years I have been using Linksys PAP2T phone adapter behind RV082 router with UDP port forwarding without any problems, until recently I started getting fast busy on all outgoing calls. Called the provider (ViaTalk) and was told they have to change the proxy setting on their end which fixed fast busy, but introduced ONE WAY audio on all incoming calls, however outgoing calls don’t seem to have this problem.</description>
    </item>
    
    <item>
      <title>Error: Unhandled Exception (group=1, code=6)?</title>
      <link>/questions/8606/error-unhandled-exception-group1-code6/</link>
      <pubDate>Wed, 25 Jan 2012 09:14:00 +0000</pubDate>
      
      <guid>/questions/8606/error-unhandled-exception-group1-code6/</guid>
      <description>Error: Unhandled Exception (group=1, code=6)?  0 I am trying to dissect the captured pcap header using libwireshark.so, but when i call
epan_dissect_init(&amp;amp;edt,true,true); epan_dissect_run();I see this error:
Error: Unhandled Exception (group=1, code=6)Why?
development exceptionasked 25 Jan &#39;12, 09:14
Sanny_D
0●18●20●21
accept rate: 50%
 edited 25 Jan &#39;12, 20:09 
helloworld
3.1k●4●20●41
  
3 Answers:
  
0 thanks guys!
there was some problem in initializing the epan</description>
    </item>
    
    <item>
      <title>Plotting (/measuring) packet latency (delay) in an 802.11 network.</title>
      <link>/questions/8607/plotting-measuring-packet-latency-delay-in-an-80211-network/</link>
      <pubDate>Wed, 25 Jan 2012 11:08:00 +0000</pubDate>
      
      <guid>/questions/8607/plotting-measuring-packet-latency-delay-in-an-80211-network/</guid>
      <description>Plotting (/measuring) packet latency (delay) in an 802.11 network.  0 Hi all,
I am trying to plot/measure packet latency (delay) in a 802.11 network using wireshark and I would like to know how people are doing this.
Up unitl now, my settings in the I/O Graph are: Units: Advanced Filter: empty, AVG(*): frame.time_delta_displayed
As I am relatively new to wireshark I am not sure whether this is correct, or not.</description>
    </item>
    
    <item>
      <title>SRTP over H323</title>
      <link>/questions/8612/srtp-over-h323/</link>
      <pubDate>Wed, 25 Jan 2012 15:03:00 +0000</pubDate>
      
      <guid>/questions/8612/srtp-over-h323/</guid>
      <description>SRTP over H323  0 Hi there.
My Automation Testing Environment runs SRTP calls over H323. In this case only payload part of RTP packet is encrypted. (Not whole RTP packet as in case of SIP/TLS).
So if I&#39;m Wiresharking the call, how do i actually know from its capture:
a) If payload is actually encrypted.
b) What encryption algorithm is used.
I read that DTMF can give an exact answer for those questions.</description>
    </item>
    
    <item>
      <title>Inbound and Outbound traffic</title>
      <link>/questions/8615/inbound-and-outbound-traffic/</link>
      <pubDate>Wed, 25 Jan 2012 22:39:00 +0000</pubDate>
      
      <guid>/questions/8615/inbound-and-outbound-traffic/</guid>
      <description>Inbound and Outbound traffic  0 Hi, I&#39;m writing a Lua program to process data that captured by tshark, and I&#39;m in need for a filter to separate inbound traffic from outbound traffic in our network to process each group alone. Can some one help me in this, because I&#39;m new in both: Lua and Wireshark. Thanks
lua tsharkasked 25 Jan &#39;12, 22:39
Leena
51●17●18●21
accept rate: 0%
 edited 26 Jan &#39;12, 00:46</description>
    </item>
    
    <item>
      <title>Starting problem</title>
      <link>/questions/8616/starting-problem/</link>
      <pubDate>Wed, 25 Jan 2012 23:48:00 +0000</pubDate>
      
      <guid>/questions/8616/starting-problem/</guid>
      <description>Starting problem  0 When I try to run the application a small window is shown on the screen for a very short time and then happens nothing. I can see only the icon on the bottom bar (see here http://aijaa.com/000509434345).
So what went wrong?
startingasked 25 Jan &#39;12, 23:48
scalpguy
1●1●1●1
accept rate: 0%
  
One Answer:
  
0For some reason the app was minimized and there was no maximize menu item available.</description>
    </item>
    
    <item>
      <title>[closed] TShark C5 Sigma not extracting all data types</title>
      <link>/questions/8617/tshark-c5-sigma-not-extracting-all-data-types/</link>
      <pubDate>Thu, 26 Jan 2012 00:23:00 +0000</pubDate>
      
      <guid>/questions/8617/tshark-c5-sigma-not-extracting-all-data-types/</guid>
      <description>[closed] TShark C5 Sigma not extracting all data types  0 Hi,
I am trying to extract the data out of a number of PCAP files in to a MySQL database using C5 SIGMA. I have managed to get it to create a range of tables such as frame/IP/TCP/UDP but it only creates some of the tables relating to the propriety datatypes that are decoded in wireshark using a plugin. C5 SIGMA uses TShark so it should decode anything that wireshark itself can decode and create the necessary tables in MySQL, a separate table for each layer in wireshark.</description>
    </item>
    
    <item>
      <title>Out Of Memory</title>
      <link>/questions/8618/out-of-memory/</link>
      <pubDate>Thu, 26 Jan 2012 00:57:00 +0000</pubDate>
      
      <guid>/questions/8618/out-of-memory/</guid>
      <description>Out Of Memory  0 I encountered the following message &#34;Out Of Memory!&#34; when opening a CAP file. The file size is 1,180,929 KB. The workstation I am using has an Intel Core i5 Processor, 4 GB Memory with Windows 7 32 Bit. I would like to find out if upgrading to a workstation with an Intel Core i7 Processor, 8 GB Memory with Windows 7 64 Bit will be able to overcome this issue.</description>
    </item>
    
    <item>
      <title>Extract data from frame</title>
      <link>/questions/8623/extract-data-from-frame/</link>
      <pubDate>Thu, 26 Jan 2012 08:09:00 +0000</pubDate>
      
      <guid>/questions/8623/extract-data-from-frame/</guid>
      <description>Extract data from frame  0 I would like to extract data from a frame. For example, a frame has SSL data (Non-ssl from malware). How would I extract that data using tshark.
Thx.
tsharkasked 26 Jan &#39;12, 08:09
wshk_newb
1●1●1●1
accept rate: 0%
I would try Splitcap. I have a video on how to use it at http://www.lovemytool.com/blog/2012/01/using-splitcap-to-help-analyze-your-wireshark-trace-files-by-tony-fortunato.html or http://tinyurl.com/6odr3m5
(26 Jan &#39;12, 08:30) thetechfirm   </description>
    </item>
    
    <item>
      <title>filter in WS for my unit</title>
      <link>/questions/8624/filter-in-ws-for-my-unit/</link>
      <pubDate>Thu, 26 Jan 2012 08:17:00 +0000</pubDate>
      
      <guid>/questions/8624/filter-in-ws-for-my-unit/</guid>
      <description>filter in WS for my unit  0 how can i scan without 3x ip numbers? (filter 3x ip ) i will only scan my unit of there is onother ip number whats going out.
thanks texi
scanasked 26 Jan &#39;12, 08:17
texi
1●1●1●1
accept rate: 0% 
   </description>
    </item>
    
    <item>
      <title>Can I pass arguments to a sub-dissector?</title>
      <link>/questions/8627/can-i-pass-arguments-to-a-sub-dissector/</link>
      <pubDate>Thu, 26 Jan 2012 11:26:00 +0000</pubDate>
      
      <guid>/questions/8627/can-i-pass-arguments-to-a-sub-dissector/</guid>
      <description>Can I pass arguments to a sub-dissector?  0 I&#39;ve written a dissector that takes various UDP ports and dissects their packets. Now I&#39;m writting a subdissector that my dissector calls based on an id value that it decodes. I have the subdissector registering for a range of ids (ex 600-700), however, I&#39;m not sure of the best way to pass that id value to the subdissector. Any suggestions?
Additional information: I parse about 4 different items in the dissector before I pass to the sub.</description>
    </item>
    
    <item>
      <title>RTP Header extension in Lua</title>
      <link>/questions/8629/rtp-header-extension-in-lua/</link>
      <pubDate>Thu, 26 Jan 2012 12:04:00 +0000</pubDate>
      
      <guid>/questions/8629/rtp-header-extension-in-lua/</guid>
      <description>RTP Header extension in Lua  1 I want to write a dissector to manage some header extensions for RTP protocol. Searching in code, I saw that we need to write a sub-dissector and that it would be called instead of the generic header extension, but how do I register my dissector to the list of sub-dissectors in Lua?
UpdateWhere is the payload type string locate?
In the packet I want to analyses, it said that payload type is DinamicRTP-Type-98 (98).</description>
    </item>
    
    <item>
      <title>Save and Save As are grayed out</title>
      <link>/questions/8633/save-and-save-as-are-grayed-out/</link>
      <pubDate>Thu, 26 Jan 2012 13:24:00 +0000</pubDate>
      
      <guid>/questions/8633/save-and-save-as-are-grayed-out/</guid>
      <description>Save and Save As are grayed out  0 Can someone tell me how to enable Save and Save As on Wireshark? When I start running Wireshark on my laptop it won&#39;t let me save the capture. I have uninstalled and reinstalled Wireshark several times with no luck. In the past I was able to save captures on my laptop with Wireshark but at some point in time this changed and now Save and Save As are grayed out.</description>
    </item>
    
    <item>
      <title>802.11 Capture Filter Question</title>
      <link>/questions/8637/80211-capture-filter-question/</link>
      <pubDate>Thu, 26 Jan 2012 14:15:00 +0000</pubDate>
      
      <guid>/questions/8637/80211-capture-filter-question/</guid>
      <description>802.11 Capture Filter Question  0 I am using Wireshark with the AirPcapNx adapter to capture 802.11 packets. Is there a Wireshark CAPTURE filter that can be utilized to filter out (NOT capture) particular packet types/subtypes? More specifically, I would like to capture no data frames (type 10) except for null data frames (subtype 0100).
capture-filterasked 26 Jan &#39;12, 14:15
S_P
21●6●6●9
accept rate: 0%
I tried using: &#34;not type data&#34;</description>
    </item>
    
    <item>
      <title>Are tshark statistics slow?</title>
      <link>/questions/8638/are-tshark-statistics-slow/</link>
      <pubDate>Thu, 26 Jan 2012 14:53:00 +0000</pubDate>
      
      <guid>/questions/8638/are-tshark-statistics-slow/</guid>
      <description>Are tshark statistics slow?  0 Previous post
I use one tshark instance to sniff for 30 sec a network interface before a web server:
tshark -a duration:30 -f &amp;quot;(tcp dst port 8080) &amp;amp;&amp;amp; (tcp[13]=0x02 or tcp[((tcp[12:1] &amp;amp; 0xf0) &amp;gt;&amp;gt; 2):4] = 0x47455420)&amp;quot; -w sniff.pcapto capture packets with TCP.SYN and/or HTTP.GET requests.
Following that, I call tshark to gather statistics from the capture file:
tshark -r sniff.pcap -qz &amp;quot;io,stat,0,COUNT(tcp.flags)tcp.flags==0x02&amp;quot; -z &amp;quot;io,stat,0,COUNT(http.</description>
    </item>
    
    <item>
      <title>Statistics over multiple captures</title>
      <link>/questions/8639/statistics-over-multiple-captures/</link>
      <pubDate>Thu, 26 Jan 2012 15:13:00 +0000</pubDate>
      
      <guid>/questions/8639/statistics-over-multiple-captures/</guid>
      <description>Statistics over multiple captures  0 Is there a simple way to grab statistics from multiple captures without having to merge them into a single capture file? In particular I want to generate statistics from Protocol Hierarchy and HTTP Packet Counter. I&#39;ve been able to do this with tshark using
tshark -q -z http,tree -z io,phs -r file.cap.gzbut it only works for a single file. I&#39;ve been merging them, but now my merged files are big enough to cause OutOfMemory errors.</description>
    </item>
    
    <item>
      <title>Cell-ID/ MNC /MCC for LTE</title>
      <link>/questions/8646/cell-id-mnc-mcc-for-lte/</link>
      <pubDate>Fri, 27 Jan 2012 01:43:00 +0000</pubDate>
      
      <guid>/questions/8646/cell-id-mnc-mcc-for-lte/</guid>
      <description>Cell-ID/ MNC /MCC for LTE  0 Hi there,
I am wondering about some discrepancies that I have noticed when using wireshark to read some LTE log files. Yesterday,some colleagues of mine and I were going through a log file. There were 3 different versions of wireshark being used we discovered later. Version 1.2 / v1.4 / v1.6. What we discovered while looking at the same S1-AP message in each version was that the cell identities were being presented as different values.</description>
    </item>
    
    <item>
      <title>Dissector bug, protocol MySQL, in packet 665: proto.c:2518: failed assertion &amp;quot;hfinfo-&amp;gt;type == FT_STRING || hfinfo-&amp;gt;type == FT_STRINGZ&amp;quot;</title>
      <link>/questions/8649/dissector-bug-protocol-mysql-in-packet-665-protoc2518-failed-assertion-hfinfo-type-ft_string-hfinfo-type-ft_stringz/</link>
      <pubDate>Fri, 27 Jan 2012 04:04:00 +0000</pubDate>
      
      <guid>/questions/8649/dissector-bug-protocol-mysql-in-packet-665-protoc2518-failed-assertion-hfinfo-type-ft_string-hfinfo-type-ft_stringz/</guid>
      <description>Dissector bug, protocol MySQL, in packet 665: proto.c:2518: failed assertion &amp;ldquo;hfinfo-&amp;gt;type == FT_STRING || hfinfo-&amp;gt;type == FT_STRINGZ&amp;rdquo;  0 I am getting this error:
WARNING **: Dissector bug, protocol MySQL, in packet 665: proto.c:2518: failed assertion &amp;quot;hfinfo-&amp;gt;type == FT_STRING || hfinfo-&amp;gt;type == FT_STRINGZ&amp;quot;What is the possible reason?
development exception dissector wiresharkasked 27 Jan &#39;12, 04:04
Sanny_D
0●18●20●21
accept rate: 50%
 edited 27 Jan &#39;12, 06:20 
multipleinte...
1.3k●15●23●40</description>
    </item>
    
    <item>
      <title>Capturing HTTP requests of a (flash) application</title>
      <link>/questions/8650/capturing-http-requests-of-a-flash-application/</link>
      <pubDate>Fri, 27 Jan 2012 04:08:00 +0000</pubDate>
      
      <guid>/questions/8650/capturing-http-requests-of-a-flash-application/</guid>
      <description>Capturing HTTP requests of a (flash) application  0 Hi there.
I&#39;m currently analysing a flash application. For that reason, I need to know what HTTP requests (such as POST and GET) are send by the application. For some reason only a very few HTTP requests are captured, even though I know for certain that there are many more requests. I have Wireshark set to the default settings.
Which settings should I change to view this traffic?</description>
    </item>
    
    <item>
      <title>Wireshark Building and debugging on visual c&#43;&#43; or Visual studio</title>
      <link>/questions/8660/wireshark-building-and-debugging-on-visual-c-or-visual-studio/</link>
      <pubDate>Sat, 28 Jan 2012 01:26:00 +0000</pubDate>
      
      <guid>/questions/8660/wireshark-building-and-debugging-on-visual-c-or-visual-studio/</guid>
      <description>Wireshark Building and debugging on visual c++ or Visual studio  0 Hi all,
I am having the free version of Visual c++ 2008 for running the build of wireshark. But debugging and development through command prompt seems to be difficult task. Is there anyway I can do the development in visual c++/Studio. Plz guide me through the steps.
development buildasked 28 Jan &#39;12, 01:26
ashish_goel
15●12●12●16
accept rate: 0%</description>
    </item>
    
    <item>
      <title>No packages shown</title>
      <link>/questions/8679/no-packages-shown/</link>
      <pubDate>Sun, 29 Jan 2012 06:07:00 +0000</pubDate>
      
      <guid>/questions/8679/no-packages-shown/</guid>
      <description>No packages shown  0 Hello. I&#39;ve tried to use wireshark to capture packages sending and recieving from google chrome. Still I can&#39;t see anything(I did set capture filter on TCP or UDP and HTTP - both for port 80).
What am I doing wrong? Can you help?
chrome 80 packagesasked 29 Jan &#39;12, 06:07
samuel_spring
1●1●1●1
accept rate: 0%
You&#39;re probably capturing on the wrong interface - can you try to capture without any filters, just to see if you get anything at all?</description>
    </item>
    
    <item>
      <title>Bytes in flight value</title>
      <link>/questions/8684/bytes-in-flight-value/</link>
      <pubDate>Mon, 30 Jan 2012 00:22:00 +0000</pubDate>
      
      <guid>/questions/8684/bytes-in-flight-value/</guid>
      <description>Bytes in flight value  1 Hello,
I&#39;ve got a question about the value of bytes in flight. I am using Wireshark 1.6.2 and have a trace where the bytes in flight have an incorrect value.
So my first question is: Is it true that bytes in flight are calculated with [NextSequenceNumber] - [ACK of the packet before] ?
Secondly i&#39;ve read that there was a bug concerning this bytes in flight has been fixed with version 1.</description>
    </item>
    
    <item>
      <title>Saving Capture Output Defaults</title>
      <link>/questions/8688/saving-capture-output-defaults/</link>
      <pubDate>Mon, 30 Jan 2012 03:16:00 +0000</pubDate>
      
      <guid>/questions/8688/saving-capture-output-defaults/</guid>
      <description>Saving Capture Output Defaults  0 I am using Wireshark to monitorall traffic on a switch for our VOIP supplier, and writing to multiple files, creating a new file every 10 minutes. Every time I restart Wireshark I have to add new settings - Is there any way I can save these settings so that it always restarts and makes the minute output files. Looking at help, I guess a batch file might do it - what is the syntax, or can I copy the syntax of my edited job to drop into a batch fle.</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t dissect the tcp payload!</title>
      <link>/questions/8690/cant-dissect-the-tcp-payload/</link>
      <pubDate>Mon, 30 Jan 2012 03:38:00 +0000</pubDate>
      
      <guid>/questions/8690/cant-dissect-the-tcp-payload/</guid>
      <description>can&amp;rsquo;t dissect the tcp payload!  0 i&#39;am working on a project, that is &#34;dissecting capture packets using libwireshark&#34;
my code successfully dissected till tcp header but it cant dissect further the payload..the underlying protocol.
how to do that.. any help!
thanks!
development dissector payload wiresharkasked 30 Jan &#39;12, 03:38
Sanny_D
0●18●20●21
accept rate: 50%
  
One Answer:
  
0Register you dissector with the TCP dissectors port table, like do:</description>
    </item>
    
    <item>
      <title>Wireshark latest security advisories</title>
      <link>/questions/8694/wireshark-latest-security-advisories/</link>
      <pubDate>Mon, 30 Jan 2012 03:57:00 +0000</pubDate>
      
      <guid>/questions/8694/wireshark-latest-security-advisories/</guid>
      <description>Wireshark latest security advisories  0 1Can I get the Wireshark latest security advisories link? From this http://www.wireshark.org/security/, I am able to get up to 2011 security advisories only. 2012 security advisories are not listed in the above link. Is there any any updated link for 2012 security advisories?
security advisories latest wiresharkasked 30 Jan &#39;12, 03:57
Prabhakar1621
6●1●2●3
accept rate: 0%
 edited 30 Jan &#39;12, 05:53 
cmaynard ♦♦</description>
    </item>
    
    <item>
      <title>where can i buy additional package for G.729</title>
      <link>/questions/8706/where-can-i-buy-additional-package-for-g729/</link>
      <pubDate>Mon, 30 Jan 2012 10:05:00 +0000</pubDate>
      
      <guid>/questions/8706/where-can-i-buy-additional-package-for-g729/</guid>
      <description>where can i buy additional package for G.729  0 Hello everyone. Could you please tell me where i can buy additional software package for G.729? It needed that i can play and save RTP stream from Wireshark immediately.
g.729asked 30 Jan &#39;12, 10:05
kamax
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Have you checked this wiki page?
answered 30 Jan &#39;12, 22:46
Jaap ♦</description>
    </item>
    
    <item>
      <title>Version of Wireshark to make .ts file</title>
      <link>/questions/8707/version-of-wireshark-to-make-ts-file/</link>
      <pubDate>Mon, 30 Jan 2012 10:11:00 +0000</pubDate>
      
      <guid>/questions/8707/version-of-wireshark-to-make-ts-file/</guid>
      <description>Version of Wireshark to make .ts file  0 I am looking for a version of Wireshark that will create a .ts MPEG video file from the UDP and PES packets for a multicast. The output from wireshark is a viewable video stream. Is that in the latest version or certain versions? I can&#39;t seem to find a version with it. Are there extensitons I am not getting?
.tsasked 30 Jan &#39;12, 10:11</description>
    </item>
    
    <item>
      <title>TLS public key decryption?</title>
      <link>/questions/8708/tls-public-key-decryption/</link>
      <pubDate>Mon, 30 Jan 2012 10:24:00 +0000</pubDate>
      
      <guid>/questions/8708/tls-public-key-decryption/</guid>
      <description>TLS public key decryption?  0 I have a trace including handshake for TLS between two servers using SIPS. I cannot decode because wireshark wants private keys? Why would wireshark want private keys? Why wouldn&#39;t the public keys work. I have both public keys from each server and cannot get it to work because wireshark will not accept the public key.
Listen most organizations are not going to give you their private key, in fact everything I have read says never give out your private key.</description>
    </item>
    
    <item>
      <title>global preference file</title>
      <link>/questions/8727/global-preference-file/</link>
      <pubDate>Tue, 31 Jan 2012 04:49:00 +0000</pubDate>
      
      <guid>/questions/8727/global-preference-file/</guid>
      <description>global preference file  0 wireshark is installed in the &#34;/usr/local/bin&#34; directory
but global preference file is not in &#34;/usr/local/share&#34;
do i need to create it.. if yes. please provide a sample file format.. it&#39;ll be great help
thanks!
development preferences wiresharkasked 31 Jan &#39;12, 04:49
Sanny_D
0●18●20●21
accept rate: 50%
  
One Answer:
  
0 Correct: the global preferences does not exist by default.
It takes the same format as the options in your ~/.</description>
    </item>
    
    <item>
      <title>missing SMTP traffic</title>
      <link>/questions/8729/missing-smtp-traffic/</link>
      <pubDate>Tue, 31 Jan 2012 06:37:00 +0000</pubDate>
      
      <guid>/questions/8729/missing-smtp-traffic/</guid>
      <description>missing SMTP traffic  0 I&#39;m trying to debug a connection issue with network printer that is refusing to connect to a specific smtp server. While capturing from the same switch that the printer is connected to I can see packets coming up and down but, even smtp communication with &#34;other smtp servers&#34; but NOT to this particular one. the smtp server is alive as I can ping it and telnet it to port 25, and I can even send mails from email clients and all this will be visible with wireshark, not the failed connection to the problematic smtp.</description>
    </item>
    
    <item>
      <title>wireshark application tracking</title>
      <link>/questions/8738/wireshark-application-tracking/</link>
      <pubDate>Tue, 31 Jan 2012 21:47:00 +0000</pubDate>
      
      <guid>/questions/8738/wireshark-application-tracking/</guid>
      <description>wireshark application tracking  0 hi, does wire-shark help track which application is connecting to the internet, just like geoip where we know which ip the os connects to, cause i think there is a rootkit installed in my laptop which connects to a &#34;gay&#34; network somewhere in Korea &#34;175.41.3.0 to 255&#34;, i don&#39;t want to format and re-install cause all my office work is on the laptop, i tried to use free version of ad-aware but no joy.</description>
    </item>
    
    <item>
      <title>How to use wireshark to analyze SS7 TUP package</title>
      <link>/questions/8742/how-to-use-wireshark-to-analyze-ss7-tup-package/</link>
      <pubDate>Wed, 01 Feb 2012 01:00:00 +0000</pubDate>
      
      <guid>/questions/8742/how-to-use-wireshark-to-analyze-ss7-tup-package/</guid>
      <description>How to use wireshark to analyze SS7 TUP package  0 I have a PCAP file for ss7 TUP protocol, BUT i can not decode correctly, it show &#34;data&#34; only, but the signal type show TUP and wireshark can decode the DTP/OPC. anyone knows how to decode correct TUP protocol using wireshark? many thanks. attachment is a sample for TUP signal
0000 84 00 00 00 09 09 09 61 00 11 18 00 30 11 04 .</description>
    </item>
    
    <item>
      <title>How can I capture RTP packets?</title>
      <link>/questions/8747/how-can-i-capture-rtp-packets/</link>
      <pubDate>Wed, 01 Feb 2012 09:19:00 +0000</pubDate>
      
      <guid>/questions/8747/how-can-i-capture-rtp-packets/</guid>
      <description>How can I capture RTP packets?  0 For a project that I have to submit, I have to stream between two computers (with RTP protocol) using VLC media player, and then capture the packets with Wireshark in order to evaluate eventual packet losses. I have got two questions:
As a first step, I tried to use the same computer both for sending and for receiving the stream; I opened the RTP network stream in another window of VLC media player and the video is effectively shown.</description>
    </item>
    
    <item>
      <title>packetizing the data</title>
      <link>/questions/8750/packetizing-the-data/</link>
      <pubDate>Wed, 01 Feb 2012 10:03:00 +0000</pubDate>
      
      <guid>/questions/8750/packetizing-the-data/</guid>
      <description>packetizing the data  0 Hi all,
I am working to implement a protocol dissector in wireshark. I have the sample data of this protocol in some format which has data in the form of continuous bits not packets. Now to import this sample data and dissector I am planning to convert this data file into .pcap format. But now the problem is that in .pcap format, there are packets of data.</description>
    </item>
    
    <item>
      <title>How can I extract email content from IMF packets using tshark?</title>
      <link>/questions/8754/how-can-i-extract-email-content-from-imf-packets-using-tshark/</link>
      <pubDate>Wed, 01 Feb 2012 11:38:00 +0000</pubDate>
      
      <guid>/questions/8754/how-can-i-extract-email-content-from-imf-packets-using-tshark/</guid>
      <description>How can I extract email content from IMF packets using tshark?  0 I&#39;m working on a bash script which can show email text. I can find what I want in an IMF packet:
-&amp;gt; IMF (Internet Message Format) ---&amp;gt; MIME Multipart Media Encapsulation, Type: multipart/alternative, Boundary: ------&amp;gt; Encapsulated multipart part: (text/plain) ---------&amp;gt; Line-based text data: text/plain --------------&amp;gt; **** Content to extract is here ****I only want the text/plain data, but I can&#39;t retrieve it.</description>
    </item>
    
    <item>
      <title>Wireshark won&amp;#x27;t start on Mac OSX</title>
      <link>/questions/8755/wireshark-wont-start-on-mac-osx/</link>
      <pubDate>Wed, 01 Feb 2012 12:22:00 +0000</pubDate>
      
      <guid>/questions/8755/wireshark-wont-start-on-mac-osx/</guid>
      <description>Wireshark won&amp;rsquo;t start on Mac OSX  0 I installed Wireshark 1.6.5 (Intel 64) on Mac OSX 10.6.8, but when I try to open it (by clicking the application icon), nothing appears to happen. How can I get Wireshark to run properly?
osx mac installationasked 01 Feb &#39;12, 12:22
saurabh
1●1●1●1
accept rate: 0%
 edited 02 Feb &#39;12, 15:27 
helloworld
3.1k●4●20●41
possible duplicate: wireshark does not run
(02 Feb &#39;12, 15:23) helloworld</description>
    </item>
    
    <item>
      <title>Capturing multiple Exegin boxes on one host</title>
      <link>/questions/8760/capturing-multiple-exegin-boxes-on-one-host/</link>
      <pubDate>Wed, 01 Feb 2012 16:50:00 +0000</pubDate>
      
      <guid>/questions/8760/capturing-multiple-exegin-boxes-on-one-host/</guid>
      <description>Capturing multiple Exegin boxes on one host  0 I think I have a unique problem. I would like to have multiple Exegin boxes sniffing RF traffic with static IPs (connected to 3G/4G modems) being captured simultaneously on multiple instances of Wireshark on a host Unix machine. I setup the host to have a VLAN for each instance of Wireshark to capture each Exegin&#39;s traffic. (If there&#39;s a more elegant way to do this, please tell me!</description>
    </item>
    
    <item>
      <title>Resolution name in already capture file</title>
      <link>/questions/8763/resolution-name-in-already-capture-file/</link>
      <pubDate>Wed, 01 Feb 2012 21:53:00 +0000</pubDate>
      
      <guid>/questions/8763/resolution-name-in-already-capture-file/</guid>
      <description>Resolution name in already capture file  0 hi all
I have a pcap file about 9000 file , not resolution name
I want convert to csv format and I want a filed of ip.dst like this &#39;www.google.com&#39;
who have any idea to convent file with resolution name
this my script tshark -r c:svr.pcap -T fields -e frame.number -e frame.time -e eth.src -e eth.dst -e ip.src -e ip.dst -e ip.proto -e frame.</description>
    </item>
    
    <item>
      <title>What is a tap, and how do I use one with the Lua interface?</title>
      <link>/questions/8776/what-is-a-tap-and-how-do-i-use-one-with-the-lua-interface/</link>
      <pubDate>Thu, 02 Feb 2012 04:26:00 +0000</pubDate>
      
      <guid>/questions/8776/what-is-a-tap-and-how-do-i-use-one-with-the-lua-interface/</guid>
      <description>What is a tap, and how do I use one with the Lua interface?  0 I want to understand what is meant by &#34;tap&#34; in Lua API. Specifically, I would like clarification on the following:
How I can use a tap and what are the benefits?
What is resetting a tap?What is removing a tap?
What information is lost when the tap is reset or removed?
When is the information lost when the reset and remove functions are called?</description>
    </item>
    
    <item>
      <title>Can I use Wireshark to troubleshoot being disconnected from World of Warcraft?</title>
      <link>/questions/8781/can-i-use-wireshark-to-troubleshoot-being-disconnected-from-world-of-warcraft/</link>
      <pubDate>Thu, 02 Feb 2012 10:05:00 +0000</pubDate>
      
      <guid>/questions/8781/can-i-use-wireshark-to-troubleshoot-being-disconnected-from-world-of-warcraft/</guid>
      <description>Can I use Wireshark to troubleshoot being disconnected from World of Warcraft?  0 My girlfriend and I (on same wired cable connection) are constantly getting disconnected simultaneously when we play World of Warcraft. Will Wireshark help us identify the issue and whether the disconnects are initiated on our side or the server end?
troubleshootingasked 02 Feb &#39;12, 10:05
paraella
1●1●1●1
accept rate: 0%
 edited 02 Feb &#39;12, 15:12</description>
    </item>
    
    <item>
      <title>Plug-in to view captures on the web</title>
      <link>/questions/8782/plug-in-to-view-captures-on-the-web/</link>
      <pubDate>Thu, 02 Feb 2012 10:55:00 +0000</pubDate>
      
      <guid>/questions/8782/plug-in-to-view-captures-on-the-web/</guid>
      <description>Plug-in to view captures on the web  0 We at Cloudshark.org just released a free plug-in for Wireshark that lets you upload captures directly to CloudShark. We&#39;ve made versions for each platform that Wireshark runs on. Written using the lua extensions for Wireshark, the plug-in appears in the Tools menu after installation.
If you are unfamiliar with CloudShark, it is a web based capture management and analysis application - free to use at Cloudshark.</description>
    </item>
    
    <item>
      <title>How can I determine the total time taken to load a Webpage?</title>
      <link>/questions/8786/how-can-i-determine-the-total-time-taken-to-load-a-webpage/</link>
      <pubDate>Thu, 02 Feb 2012 11:17:00 +0000</pubDate>
      
      <guid>/questions/8786/how-can-i-determine-the-total-time-taken-to-load-a-webpage/</guid>
      <description>How can I determine the total time taken to load a Webpage?  0 I would like to know the Total content size and Total time taken to load a particular Webpage in Wireshark. The time parameter in Wireshark shows either time elapsed from first frame or previous frame. How can I obtain the above parameters using Wireshark?
http timeasked 02 Feb &#39;12, 11:17
Rhiya
0●3●3●5
accept rate: 0%
 edited 02 Feb &#39;12, 11:28</description>
    </item>
    
    <item>
      <title>Commerical use of wireshark</title>
      <link>/questions/8798/commerical-use-of-wireshark/</link>
      <pubDate>Thu, 02 Feb 2012 22:56:00 +0000</pubDate>
      
      <guid>/questions/8798/commerical-use-of-wireshark/</guid>
      <description>Commerical use of wireshark  0 Hi folks,
I wanted to know if I make some changes in wireshark, suppose implementing support for extra protocol not already present in wireshark. Can I make the DLL of my changes and then sell it commercially ? Would it be legal?
usage protocolasked 02 Feb &#39;12, 22:56
ashish_goel
15●12●12●16
accept rate: 0%
  
One Answer:
  
5The rules of GPLv2 apply, which state that if you program against the API of the application (like you do using the functionality though dynamic linking) your code is covered by the GPL as well.</description>
    </item>
    
    <item>
      <title>Routers changing the packet window size?</title>
      <link>/questions/8799/routers-changing-the-packet-window-size/</link>
      <pubDate>Thu, 02 Feb 2012 23:46:00 +0000</pubDate>
      
      <guid>/questions/8799/routers-changing-the-packet-window-size/</guid>
      <description>Routers changing the packet window size?  0 I&#39;m having a problem in the company network, where server is receiving a high number of Zero Window-packets. Now, I understand that this would be quite normal if the client is too busy to handle the incoming flow.
But here&#39;s the thing, I captured the traffic from client&#39;s end simultaneously with server&#39;s end and there were none zero window-packets leaving from client. So somewhere on the path the packet window size had changed to zero which keeps stopping the flow.</description>
    </item>
    
    <item>
      <title>tshark pdml output embeds a  section within another  section</title>
      <link>/questions/8803/tshark-pdml-output-embeds-a-section-within-another-section/</link>
      <pubDate>Fri, 03 Feb 2012 02:45:00 +0000</pubDate>
      
      <guid>/questions/8803/tshark-pdml-output-embeds-a-section-within-another-section/</guid>
      <description>tshark pdml output embeds a section within another section  0 Hi Guys,
I have a pdml output file which is OK for all the IP, TCP, UDP etc but there is one protocol which does not get writen correctly. tshark puts a &amp;lt;proto&amp;gt;&amp;lt;/proto&amp;gt; section within another &amp;lt;proto&amp;gt;&amp;lt;/proto&amp;gt; section which makes it non XML compliant. Has anyone had this happen before? Any ideas how I can correct it?
regards,
Degsy</description>
    </item>
    
    <item>
      <title>Is there a capture filter for GTP protocol?</title>
      <link>/questions/8805/is-there-a-capture-filter-for-gtp-protocol/</link>
      <pubDate>Fri, 03 Feb 2012 04:43:00 +0000</pubDate>
      
      <guid>/questions/8805/is-there-a-capture-filter-for-gtp-protocol/</guid>
      <description>Is there a capture filter for GTP protocol?  0 Is there capture filter that is equivalent to the display filter gtp.user_ipv4 == 10.32.5.6?
gtp filter capture-filterasked 03 Feb &#39;12, 04:43
Majksner81
1●1●1●1
accept rate: 0%
 edited 03 Feb &#39;12, 07:41 
multipleinte...
1.3k●15●23●40
   </description>
    </item>
    
    <item>
      <title>which protocol to use for decoding a pcap</title>
      <link>/questions/8809/which-protocol-to-use-for-decoding-a-pcap/</link>
      <pubDate>Fri, 03 Feb 2012 10:12:00 +0000</pubDate>
      
      <guid>/questions/8809/which-protocol-to-use-for-decoding-a-pcap/</guid>
      <description>which protocol to use for decoding a pcap  0 Hi,
I have a .pcap file containing data of some protocol not already implemented in wireshark. While importing this pcap file into wireshark how will the wireshark know which protocol dissector to use for decoding the data?? I didn&#39;t find any field for such information in .pcap file format.
importasked 03 Feb &#39;12, 10:12
ashish_goel
15●12●12●16
accept rate: 0%</description>
    </item>
    
    <item>
      <title>POP auth method insecurely but impossible to found PASS in Wireshark!</title>
      <link>/questions/8815/pop-auth-method-insecurely-but-impossible-to-found-pass-in-wireshark/</link>
      <pubDate>Fri, 03 Feb 2012 13:56:00 +0000</pubDate>
      
      <guid>/questions/8815/pop-auth-method-insecurely-but-impossible-to-found-pass-in-wireshark/</guid>
      <description>POP auth method insecurely but impossible to found PASS in Wireshark!  0 Hello,
When I analyze POP packets with Wireshark, when I receive emails with Outlook, I can see USER and PASS commands with username and password transmitted unecrypted.
But if I try to get my emails with Thunderbird (without encryption), I CANNOT see in Wireshark USER and PASS commands, and for sure, no username and password !!
But there are new commands :</description>
    </item>
    
    <item>
      <title>Unable to get live streams URL</title>
      <link>/questions/8819/unable-to-get-live-streams-url/</link>
      <pubDate>Fri, 03 Feb 2012 21:01:00 +0000</pubDate>
      
      <guid>/questions/8819/unable-to-get-live-streams-url/</guid>
      <description>Unable to get live streams URL  0 i am trying to get the live streams URL from this site e.g http://watchindian.tv/index.php?option=com_wrapper&amp;amp;view=wrapper&amp;amp;Itemid=184 to play it in VLC. But I am not able to get any working URLs.
I&#39;ll appreciate if anyone can help me look up..
Thanks
live streamsasked 03 Feb &#39;12, 21:01
sitesmith
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>error in column &amp;#x27;Payload protocol&amp;#x27;: dissector not found</title>
      <link>/questions/8823/error-in-column-payload-protocol-dissector-not-found/</link>
      <pubDate>Sat, 04 Feb 2012 07:33:00 +0000</pubDate>
      
      <guid>/questions/8823/error-in-column-payload-protocol-dissector-not-found/</guid>
      <description>error in column &amp;lsquo;Payload protocol&amp;rsquo;: dissector not found  0 I have defined a foo protocol dissector in Wireshark and compiled it successfully, but when I try adding this dissector in Preferences-&amp;gt;Protocols-&amp;gt;DLT_USER-&amp;gt;Encapsulations Table, it shows this error:
error in column &amp;#39;Payload protocol&amp;#39;: dissector not foundPlease advise.
EDIT: SOURCE ADDED BELOW
void proto_register_foo(void) { static hf_register_info hf[] = { { &amp;amp;hf_foo_pdu_type, { &amp;quot;FOO PDU Type&amp;quot;, &amp;quot;foo.type&amp;quot;, FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL } } }; /* Setup protocol subtree array */ static gint *ett[] = { &amp;amp;amp;ett_foo }; proto_foo = proto_register_protocol ( &amp;amp;quot;FOO Protocol&amp;amp;quot;, /* name */ &amp;amp;quot;FOO&amp;amp;quot;, /* short name */ &amp;amp;quot;foo&amp;amp;quot; /* abbrev */ ); proto_register_field_array(proto_foo, hf, array_length(hf)); proto_register_subtree_array(ett, array_length(ett)); register_dissector(&amp;amp;quot;foo&amp;amp;quot;,dissect_foo,proto_foo);  }development errorasked 04 Feb &amp;lsquo;12, 07:33</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t sniff wifi</title>
      <link>/questions/8832/cant-sniff-wifi/</link>
      <pubDate>Sun, 05 Feb 2012 05:16:00 +0000</pubDate>
      
      <guid>/questions/8832/cant-sniff-wifi/</guid>
      <description>Can&amp;rsquo;t sniff wifi  0 I want to sniff wifi packets with wireshark but monitor mode seems to fail. I&#39;m using backtrack 5 and an alpha AWUS036H wifi usb card, i try to sniff my own box without encryption.
Here is what i&#39;m doing to activate monitor mode :
[email protected]:~# airmon-ng start wlan0
wich seems to be working :
[email protected]:~# iwconfig mon0
mon0 IEEE 802.11bg Mode:Monitor Tx-Power=20 dBm</description>
    </item>
    
    <item>
      <title>Bytes in flight - Problems with retransmissions?</title>
      <link>/questions/8843/bytes-in-flight-problems-with-retransmissions/</link>
      <pubDate>Mon, 06 Feb 2012 04:59:00 +0000</pubDate>
      
      <guid>/questions/8843/bytes-in-flight-problems-with-retransmissions/</guid>
      <description>Bytes in flight - Problems with retransmissions?  0 Hey
I&#39;ve read that wireshark had problems with the bytes in flight value, when retransmissions occur. This bug was fixed in version 1.4.1. Well, but I&#39;ve got a trace, where the values does not seem to bee correct. The link to this .pcap file is: http://uploading.com/files/ce18d69a/bytes_in_flight_problem.pcap/
In this trace the calculation of bytes in flight is correct until frame 17, where it is 1714.</description>
    </item>
    
    <item>
      <title>libxml2 in dessector - string encoding</title>
      <link>/questions/8845/libxml2-in-dessector-string-encoding/</link>
      <pubDate>Mon, 06 Feb 2012 05:28:00 +0000</pubDate>
      
      <guid>/questions/8845/libxml2-in-dessector-string-encoding/</guid>
      <description>libxml2 in dessector - string encoding  0 Hi, I&#39;m using libxml2 to read an xml-file (in utf-8) and set the tree-items in wireshark. My problem is that I only see unreadable text in wireshark. I used xmlNodeGetContent(node-&amp;gt;xmlChildrenNode); to get the content and than proto_item_append_text(ti,ts); to set text text to a tree-item and I get something like ð§Derungsanhang What should I call to get a readable string?
libxml2 dissector encodingasked 06 Feb &#39;12, 05:28</description>
    </item>
    
    <item>
      <title>Message Box from Dissector Plugin</title>
      <link>/questions/8848/message-box-from-dissector-plugin/</link>
      <pubDate>Mon, 06 Feb 2012 07:41:00 +0000</pubDate>
      
      <guid>/questions/8848/message-box-from-dissector-plugin/</guid>
      <description>Message Box from Dissector Plugin  0 Hi,
is there a possibility to create / open a message box from my own wireshark plugin?
box message dissector pluginasked 06 Feb &#39;12, 07:41
Nic
14●5●5●6
accept rate: 0%
  
One Answer:
  
0 There is a possibility to report an error that, IF your dissector is running in Wireshark, will appear as a message box. If it&#39;s running in TShark, it will appear as text on the standard output.</description>
    </item>
    
    <item>
      <title>Can dfilter_apply() over an edt tree be undone?</title>
      <link>/questions/8850/can-dfilter_apply-over-an-edt-tree-be-undone/</link>
      <pubDate>Mon, 06 Feb 2012 08:40:00 +0000</pubDate>
      
      <guid>/questions/8850/can-dfilter_apply-over-an-edt-tree-be-undone/</guid>
      <description>Can dfilter_apply() over an edt tree be undone?  0 I am writing a dissector, and I am applying a read filter using dfilter_apply() on edt tree on the packets during a live capture.
Is there any way to undo the effect of dfilter_apply(); on edt tree, since during live capture the tree gets modified after applying a read filter?
development dissector dfilter wiresharkasked 06 Feb &#39;12, 08:40
Sanny_D
0●18●20●21</description>
    </item>
    
    <item>
      <title>All Traffic Being Reported as Docsis</title>
      <link>/questions/8853/all-traffic-being-reported-as-docsis/</link>
      <pubDate>Mon, 06 Feb 2012 09:24:00 +0000</pubDate>
      
      <guid>/questions/8853/all-traffic-being-reported-as-docsis/</guid>
      <description>All Traffic Being Reported as Docsis  0 Hello - I received a trace from an outside source. When I opened it up I used the Decode As feature. As a result all the traffic was interpreted as Docsis which was fine since it was coming off a cable modem infrastructure. However, my problem now is that no matter what I capture is now always interpreted as Docsis which is nonsense.</description>
    </item>
    
    <item>
      <title>the filter ip.addr is not the sum of the two filters ip.src ip.dst</title>
      <link>/questions/8868/the-filter-ipaddr-is-not-the-sum-of-the-two-filters-ipsrc-ipdst/</link>
      <pubDate>Tue, 07 Feb 2012 00:13:00 +0000</pubDate>
      
      <guid>/questions/8868/the-filter-ipaddr-is-not-the-sum-of-the-two-filters-ipsrc-ipdst/</guid>
      <description>the filter ip.addr is not the sum of the two filters ip.src ip.dst  0 Well, I was trying to compare some capture and I did find a strange, to me, condition. If I sum the number of packets of the filter ip.src and the number of packets of the filter ip.dst I&#39;m not getting the same packet number of the filter ip.addr. After a deep analysis I&#39;ve found that the filter ip.</description>
    </item>
    
    <item>
      <title>How can I use idl2wrs with a dissector?</title>
      <link>/questions/8873/how-can-i-use-idl2wrs-with-a-dissector/</link>
      <pubDate>Tue, 07 Feb 2012 04:23:00 +0000</pubDate>
      
      <guid>/questions/8873/how-can-i-use-idl2wrs-with-a-dissector/</guid>
      <description>How can I use idl2wrs with a dissector?  1 I have installed wireshark, and I wanted to use idl2wrs. I have done everything a specified in the user guide:
idl2wrs echo.idl &amp;gt; packet-test-idl.c` cp packet-test-idl.c /dir/where/wireshark/lives/epan/dissectors/...changed Makefile.common, then ./configure and make wireshark again. Everything seemed okay. However, when I start Wireshark, I do not see it in the Edit-&amp;gt;preferences menu, in the protocol list. What can I do differently to fix this?</description>
    </item>
    
    <item>
      <title>dissector ip filter</title>
      <link>/questions/8878/dissector-ip-filter/</link>
      <pubDate>Tue, 07 Feb 2012 10:09:00 +0000</pubDate>
      
      <guid>/questions/8878/dissector-ip-filter/</guid>
      <description>dissector ip filter  0 Hi, I&#39;ve written a dissector plugin to filter my protocolls. I&#39;ve added dissector_add_uint(&#34;tcp.port&#34;, 5001, test_handle); to filter the port, but how can I add a filter of an ip adress? I tried something like dissector_add_string(&#34;ip.src&#34;, 127.0.0.1, test_handle); but this doesn&#39;t work. What is the correct way to add an ip to my dissector?
filter ip dissectorasked 07 Feb &#39;12, 10:09
Nic
14●5●5●6
accept rate: 0%</description>
    </item>
    
    <item>
      <title>wireshark in accespoint</title>
      <link>/questions/8882/wireshark-in-accespoint/</link>
      <pubDate>Tue, 07 Feb 2012 21:46:00 +0000</pubDate>
      
      <guid>/questions/8882/wireshark-in-accespoint/</guid>
      <description>wireshark in accespoint  0 can i install wireshark on my accesspoint???
access wireshark pointasked 07 Feb &#39;12, 21:46
Sona
1●1●1●1
accept rate: 0%
What is your accesspoint?
(07 Feb &#39;12, 23:19) Jaap ♦   </description>
    </item>
    
    <item>
      <title>Server does not send ACK</title>
      <link>/questions/8890/server-does-not-send-ack/</link>
      <pubDate>Wed, 08 Feb 2012 02:35:00 +0000</pubDate>
      
      <guid>/questions/8890/server-does-not-send-ack/</guid>
      <description>Server does not send ACK  0 hi
my server is connected to several clients. there is an expected packet I want to get from one of the clients to my application on the server, but I don&#39;t get it. when I use wireshark, I see that this packet came from the client but there no ACK on this packet from the server. then, the client retransmit this packet again and again, but there is no ACK.</description>
    </item>
    
    <item>
      <title>Wireshark causing network problems</title>
      <link>/questions/8892/wireshark-causing-network-problems/</link>
      <pubDate>Wed, 08 Feb 2012 02:44:00 +0000</pubDate>
      
      <guid>/questions/8892/wireshark-causing-network-problems/</guid>
      <description>Wireshark causing network problems  0 I am trying to use Wireshark to monitor our internet usage. We have been maxing out on our bandwidth and I want to work out who is using it and why. If it&#39;s valid we need to upgrade our internet pipe if not I need to stop the problem.
So I setup Wireshark on a spare Windows 7 machine that has two network cards. And setup Port mirroring (RA and TX) on my Switch (Netgear GS748T).</description>
    </item>
    
    <item>
      <title>PKTC 175 Unknown KMMID 0x4d</title>
      <link>/questions/8898/pktc-175-unknown-kmmid-0x4d/</link>
      <pubDate>Wed, 08 Feb 2012 05:17:00 +0000</pubDate>
      
      <guid>/questions/8898/pktc-175-unknown-kmmid-0x4d/</guid>
      <description>PKTC 175 Unknown KMMID 0x4d  0 Hello folks,
I&#39;m troubleshooting a network problem at a school and I&#39;m having difficulties finding the problematic node. It seems as if there&#39;s a node that&#39;s causing the spanning tree protocol to restart every ten minutes, leaving the entire network completely dead for half a minute in the process. At least this is my gathered info from talking to several network techs and HP support.</description>
    </item>
    
    <item>
      <title>FTP over explicit SSL</title>
      <link>/questions/8904/ftp-over-explicit-ssl/</link>
      <pubDate>Wed, 08 Feb 2012 09:24:00 +0000</pubDate>
      
      <guid>/questions/8904/ftp-over-explicit-ssl/</guid>
      <description>FTP over explicit SSL  0 Hello,
i need to decrypt the commands sent by FTP over explicit SSL. i had a couple of tries, but it never succeded.
I searched the internet up and down but it seems that nobody needed it before!
i already put the key file in Preferences/protocols/ssl but the stream never got decrypted!
ftps ftpes explicit secure ftpasked 08 Feb &#39;12, 09:24
PeaceTrain
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Exporting Data - How to Retain metadata/packet number to extracted data</title>
      <link>/questions/8908/exporting-data-how-to-retain-metadatapacket-number-to-extracted-data/</link>
      <pubDate>Wed, 08 Feb 2012 10:15:00 +0000</pubDate>
      
      <guid>/questions/8908/exporting-data-how-to-retain-metadatapacket-number-to-extracted-data/</guid>
      <description>Exporting Data - How to Retain metadata/packet number to extracted data  0 Hi all,
I am trying to extract and keep track of extracted TCP data. Wireshark exporting data give the option to SAVE ALL or SAVE AS.
I like to know is there a way for me to add the packet number to the file name? as a mean to identify the data to the original network packet.</description>
    </item>
    
    <item>
      <title>Monitor Ethernet though serial ports RS232 or USB</title>
      <link>/questions/8912/monitor-ethernet-though-serial-ports-rs232-or-usb/</link>
      <pubDate>Wed, 08 Feb 2012 16:49:00 +0000</pubDate>
      
      <guid>/questions/8912/monitor-ethernet-though-serial-ports-rs232-or-usb/</guid>
      <description>Monitor Ethernet though serial ports RS232 or USB  0 How I can monitor Ethernet&#39;s packets through a &#34;null modem of ethernet interface&#34; or connection direct (in a serial port RS232 or USB) with WireShark.
ethernet rs232 monitor usbasked 08 Feb &#39;12, 16:49
Walter
1●1●1●1
accept rate: 0%
 edited 28 Feb &#39;12, 19:49 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
0Well, to do it with an RS-232 device, the first step would be to get an RS-232 serial port that runs at the same speed as your Ethernet.</description>
    </item>
    
    <item>
      <title>How can I read K18 traces in Wireshark?</title>
      <link>/questions/8915/how-can-i-read-k18-traces-in-wireshark/</link>
      <pubDate>Wed, 08 Feb 2012 22:50:00 +0000</pubDate>
      
      <guid>/questions/8915/how-can-i-read-k18-traces-in-wireshark/</guid>
      <description>How can I read K18 traces in Wireshark?  0 How can I read K18 traces in Wireshark? If I open a K18 rf5 file, Wireshark crashes!
file-format k18 crash rf5asked 08 Feb &#39;12, 22:50
Debu
1●1●1●1
accept rate: 0%
 edited 09 Feb &#39;12, 07:44 
multipleinte...
1.3k●15●23●40
  
2 Answers:
  
0Use the latest Wireshark version 1.6.5. If that doesn&#39;t work file a full bug report at bugs.</description>
    </item>
    
    <item>
      <title>display filter for diameter protocol.</title>
      <link>/questions/8919/display-filter-for-diameter-protocol/</link>
      <pubDate>Thu, 09 Feb 2012 02:50:00 +0000</pubDate>
      
      <guid>/questions/8919/display-filter-for-diameter-protocol/</guid>
      <description>display filter for diameter protocol.  0 i want to use display filter for diameter protocol for some values..
when i set display filter for &#34;diameter.hopbyhopId=4545655567&#34; its a success..
but when i use display filter on session Id &#39;diameter.Session-Id == aaa://10.34.77.63:4876;1328783436;1&#34;
its shows segmentation fault.. but its the same value as shown by wireshark how to apply this..
help!
thanks
development diameter wireshark display-filterasked 09 Feb &#39;12, 02:50
Sanny_D
0●18●20●21</description>
    </item>
    
    <item>
      <title>Can I specify the magic number in pcap files?</title>
      <link>/questions/8929/can-i-specify-the-magic-number-in-pcap-files/</link>
      <pubDate>Thu, 09 Feb 2012 07:02:00 +0000</pubDate>
      
      <guid>/questions/8929/can-i-specify-the-magic-number-in-pcap-files/</guid>
      <description>Can I specify the magic number in pcap files?  0 Can I save a trace file from Wireshark with a specific magic_number in the pcap header? I want to choose whether it will be 0xa1b2c3d4 or 0xd4c3b2a1, which will reflect the endianness of the platforms on which it will be used. Can I do that from Wireshark?
file-format pcapasked 09 Feb &#39;12, 07:02
Kosta
1●1●1●1
accept rate: 0%
 edited 09 Feb &#39;12, 07:35</description>
    </item>
    
    <item>
      <title>capture file appears to be damaged or corrupt</title>
      <link>/questions/8931/capture-file-appears-to-be-damaged-or-corrupt/</link>
      <pubDate>Thu, 09 Feb 2012 07:16:00 +0000</pubDate>
      
      <guid>/questions/8931/capture-file-appears-to-be-damaged-or-corrupt/</guid>
      <description>capture file appears to be damaged or corrupt  0 The capture file appears to be damaged or corrupt. (pcap: File has 65706-byte packet, bigger than the maximum of 65535)
Hello, I am having an issue when trying to debug some voip calls. I capture the errors but the wireshark file is always corrupt with the error at the top of my post. I have tried using the wireshark GUI and also dumpcap using the following string</description>
    </item>
    
    <item>
      <title>monitor HTTP between CBS and local device Logitech Revue</title>
      <link>/questions/8939/monitor-http-between-cbs-and-local-device-logitech-revue/</link>
      <pubDate>Thu, 09 Feb 2012 10:47:00 +0000</pubDate>
      
      <guid>/questions/8939/monitor-http-between-cbs-and-local-device-logitech-revue/</guid>
      <description>monitor HTTP between CBS and local device Logitech Revue  0 Hi,
Trying to find out what gets sent to CBS.com from my Google TV device(Logitech Revue) that is different then when I use my PC to watch a TV show using Chrome browser.
I am pretty sure that the User Agent is different but I think that&#39;s NOT everything.
Looking to find out what else is different as ABC,CBS &amp;amp; NBC tells the Revue that it not a supported device.</description>
    </item>
    
    <item>
      <title>What is normal network traffic?</title>
      <link>/questions/8941/what-is-normal-network-traffic/</link>
      <pubDate>Thu, 09 Feb 2012 19:25:00 +0000</pubDate>
      
      <guid>/questions/8941/what-is-normal-network-traffic/</guid>
      <description>What is normal network traffic?  0 What is the normal network traffic to open a webpage?
webpage http traffic analysisasked 09 Feb &#39;12, 19:25
susan
1●1●1●1
accept rate: 0%
 edited 10 Feb &#39;12, 13:39 
multipleinte...
1.3k●15●23●40
  
3 Answers:
  
1As the other answers have noted, there is no one simple definition of &#34;normal&#34; when it comes to web traffic. There are a few things that will be common to each attempt, but the number of things that not only can, but very likely will, be different make it difficult to describe exactly what will constitute normal web traffic.</description>
    </item>
    
    <item>
      <title>Wireshark capture question</title>
      <link>/questions/8942/wireshark-capture-question/</link>
      <pubDate>Thu, 09 Feb 2012 22:07:00 +0000</pubDate>
      
      <guid>/questions/8942/wireshark-capture-question/</guid>
      <description>Wireshark capture question  0 Hello, Can someone help to figure out what methods to use to find ip address of the person implementing the teardrop attack and the ip address of the one who is being attacked? Also, how would I figure out the byte numbers that are being replaced by the teardrop attack.
The capture that I am using is the sample teardrop that is found from wiki wireshark; http://wiki.</description>
    </item>
    
    <item>
      <title>use tshark to write output to .log file for realtime review</title>
      <link>/questions/8945/use-tshark-to-write-output-to-log-file-for-realtime-review/</link>
      <pubDate>Fri, 10 Feb 2012 07:31:00 +0000</pubDate>
      
      <guid>/questions/8945/use-tshark-to-write-output-to-log-file-for-realtime-review/</guid>
      <description>use tshark to write output to .log file for realtime review  0 Folks, I am trying to leverage tshark to write output in plain text to a log file (.log), so I can review with a log viewer from another machine. My wireshark machine does not have a GUI, which is no big deal since I can use tshark.
I have already learned how to limit pcap output by time and filesize, but I need something that will write until stopped.</description>
    </item>
    
    <item>
      <title>packet sniffer to discover the root of a trojan spammer</title>
      <link>/questions/8947/packet-sniffer-to-discover-the-root-of-a-trojan-spammer/</link>
      <pubDate>Fri, 10 Feb 2012 09:30:00 +0000</pubDate>
      
      <guid>/questions/8947/packet-sniffer-to-discover-the-root-of-a-trojan-spammer/</guid>
      <description>packet sniffer to discover the root of a trojan spammer  0 --- disregard...I placed between our switch and gateway and was able to sniff it all ;) ---
it was suggested we use a packet sniffer to discover the root of a trojan spammer behind our firewall, and we have Wireshark Version 0.99.6a (SVN Rev 22276) installed.
Does Wireshark have the ability to analyze the network as a whole, or is it specific to a single device?</description>
    </item>
    
    <item>
      <title>GeoIP no longitude or latitude found</title>
      <link>/questions/8959/geoip-no-longitude-or-latitude-found/</link>
      <pubDate>Fri, 10 Feb 2012 16:31:00 +0000</pubDate>
      
      <guid>/questions/8959/geoip-no-longitude-or-latitude-found/</guid>
      <description>GeoIP no longitude or latitude found  0 Hi,
I&#39;m having trouble getting GeoIP resolution to work. I&#39;ve downloaded the databases from Maxmind, set the correct path ( double checked ), checked permissions and file names and they&#39;re accurate.
I&#39;ve also selected &#34;Enable GeoIP resolution&#34; under Protocols | IPV4.
When I view Endpoints, no Latitude or Longitude information is displayed in any of the tabs, and if I try to use the map, I get the error &#34;</description>
    </item>
    
    <item>
      <title>GeoIP Nothing Shows on Map</title>
      <link>/questions/8961/geoip-nothing-shows-on-map/</link>
      <pubDate>Fri, 10 Feb 2012 19:57:00 +0000</pubDate>
      
      <guid>/questions/8961/geoip-nothing-shows-on-map/</guid>
      <description>GeoIP Nothing Shows on Map  0 I have GeoIP configured in Wireshark, and when I go to Statistics &amp;gt; Endpoints and click on the IPv4 tab, I see location information, including latitude and longitude. However, when I click on the Map button, I always get a blank map; no locations are shown.
I&#39;m using IE 8. When I click the Map button, I get a bar across the top that says &#34;</description>
    </item>
    
    <item>
      <title>TCP segment of a reassembled PDU length too small</title>
      <link>/questions/8966/tcp-segment-of-a-reassembled-pdu-length-too-small/</link>
      <pubDate>Sat, 11 Feb 2012 19:03:00 +0000</pubDate>
      
      <guid>/questions/8966/tcp-segment-of-a-reassembled-pdu-length-too-small/</guid>
      <description>TCP segment of a reassembled PDU length too small  0 Hello Everyone,
I am having a sporadic issue when I attempt to download files from a certain web site. One of the things I noticed is that when the download succeeds the TCP segment of a reassembled PDU packet length is 1514. When the download fails the TCP segment of a reassembled PDU is 1314. I am not quite sure what to make of this.</description>
    </item>
    
    <item>
      <title>HTTP Post not being captured</title>
      <link>/questions/8967/http-post-not-being-captured/</link>
      <pubDate>Sat, 11 Feb 2012 19:14:00 +0000</pubDate>
      
      <guid>/questions/8967/http-post-not-being-captured/</guid>
      <description>HTTP Post not being captured  0 I&#39;m not capturing all HTTP packets I think, specifically posts when I log into an email or my facebook. I can&#39;t sniff out the specific log in info. Why don&#39;t I see all packets?
capture httpasked 11 Feb &#39;12, 19:14
BR BR
1●1●1●1
accept rate: 0%
 edited 13 Feb &#39;12, 20:18 
helloworld
3.1k●4●20●41
  
One Answer:</description>
    </item>
    
    <item>
      <title>View Gzipped message</title>
      <link>/questions/8970/view-gzipped-message/</link>
      <pubDate>Sun, 12 Feb 2012 16:30:00 +0000</pubDate>
      
      <guid>/questions/8970/view-gzipped-message/</guid>
      <description>View Gzipped message  0 Given that Wireshark can do everthyng but eat, it seems odd it is not obvious how to ask it to unzip Gzipped responses so I can read the messages. Is the feature actually missing, or did I just overlook it.
gzipasked 12 Feb &#39;12, 16:30
RoedyGreen
1●2●2●2
accept rate: 0%
Gzipped responses in what protocol ?
ISTR that Gzipped HTTP Content Encoding will be unzipped (and shown in a separate tab).</description>
    </item>
    
    <item>
      <title>process traffic with Lua</title>
      <link>/questions/8971/process-traffic-with-lua/</link>
      <pubDate>Sun, 12 Feb 2012 23:05:00 +0000</pubDate>
      
      <guid>/questions/8971/process-traffic-with-lua/</guid>
      <description>process traffic with Lua  0 Hi, I&#39;m writing a program with Lua processing the captured data in real time. I need to process data collected at the end of each minute (I collect the data for a minute or any other suitable period and at the end of the period I will process the data collected withen this peroid only and start collecting the data for the next period) I&#39;m afraid of losing data in the time between processing data and starting collecting data again in the new period,is it possible to happen?</description>
    </item>
    
    <item>
      <title>Need help with a tftp trace</title>
      <link>/questions/8972/need-help-with-a-tftp-trace/</link>
      <pubDate>Sun, 12 Feb 2012 23:45:00 +0000</pubDate>
      
      <guid>/questions/8972/need-help-with-a-tftp-trace/</guid>
      <description>Need help with a tftp trace  0 I am stuck at a problem where i am trying to telnet into a network device, copy file using telnet from this device to a window server. The file is copied till 2k data and then terminated. I took trace on the windows machine and need help with it. This is what I see in the trace with tftp traffic:
569 18.778842 171.</description>
    </item>
    
    <item>
      <title>Seeing traffic from other machines on a switched network</title>
      <link>/questions/8975/seeing-traffic-from-other-machines-on-a-switched-network/</link>
      <pubDate>Mon, 13 Feb 2012 06:10:00 +0000</pubDate>
      
      <guid>/questions/8975/seeing-traffic-from-other-machines-on-a-switched-network/</guid>
      <description>Seeing traffic from other machines on a switched network  0 Greetings to all, I&#39;ve captured traffic on a machine, which is connected to a switch. I should see only my traffic, multicasts and broadcasts. I will occasionally see traffic conversation from two machines, neither of which is mine. I check MAC addresses and IP addresses to make sure the traffic is legit,and it is. Has anyone else seen this, and do you know why?</description>
    </item>
    
    <item>
      <title>How can I dissect fields less than 1-byte wide?</title>
      <link>/questions/8978/how-can-i-dissect-fields-less-than-1-byte-wide/</link>
      <pubDate>Mon, 13 Feb 2012 09:52:00 +0000</pubDate>
      
      <guid>/questions/8978/how-can-i-dissect-fields-less-than-1-byte-wide/</guid>
      <description>How can I dissect fields less than 1-byte wide?  0 I am working on a protocol dissector where some fields are comprised of fewer than 8 bits. For example, the first 4 bits identify the packet type, and the next 16 bits the length of following data. Can I dissect fields with length less than one byte, and how can I display them?
development fields dissectorasked 13 Feb &#39;12, 09:52</description>
    </item>
    
    <item>
      <title>Packet data in wireshark not highlighted on click using my custom dissector</title>
      <link>/questions/8982/packet-data-in-wireshark-not-highlighted-on-click-using-my-custom-dissector/</link>
      <pubDate>Mon, 13 Feb 2012 13:02:00 +0000</pubDate>
      
      <guid>/questions/8982/packet-data-in-wireshark-not-highlighted-on-click-using-my-custom-dissector/</guid>
      <description>Packet data in wireshark not highlighted on click using my custom dissector  1 I am writing a dissector in Lua for a custom binary protocol. I have defined three field types:
f.field1 = ProtoField.bytes(&amp;quot;myproto.field1&amp;quot;,&amp;quot;Field 1&amp;quot;,base.HEX) f.field2 = ProtoField.uint16(&amp;quot;myproto.field2&amp;quot;,&amp;quot;Field 2&amp;quot;,base.HEX) f.field3 = ProtoField.bytes(&amp;quot;myproto.field3&amp;quot;,&amp;quot;Field 3&amp;quot;,base.HEX)These fields are added to the tree like this:
subtree:add(f.field1,buf(offset,4)) offset = offset + 4 val2 = buf(offset,2):uint() &amp;ndash; some logic around populating f2_description omitted offset = offset + 2 subtree:add(f.</description>
    </item>
    
    <item>
      <title>ip.dsfield.dscp &amp;quot;text&amp;quot; value instead of decimal/hexadecimal</title>
      <link>/questions/8984/ipdsfielddscp-text-value-instead-of-decimalhexadecimal/</link>
      <pubDate>Mon, 13 Feb 2012 14:47:00 +0000</pubDate>
      
      <guid>/questions/8984/ipdsfielddscp-text-value-instead-of-decimalhexadecimal/</guid>
      <description>ip.dsfield.dscp &amp;ldquo;text&amp;rdquo; value instead of decimal/hexadecimal  0 In Wireshark 1.6.0, ip.dsfield.dscp was displayed once applied as a column either in hexa or in text &#34;Expedited Forwarding&#34; e.g. In Wireshark 1.6.5, the same field only offers decimal or hexadecimal, based on the &#34;show resolved&#34; checked/unchecked. Is there an option to change decimal to text-based?
Thanks!
ip.dsfield.dscp dscpasked 13 Feb &#39;12, 14:47
yul_analyzer
6●5●5●8
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How to cross compile Wireshark x64 on an x86 Windows machine</title>
      <link>/questions/8986/how-to-cross-compile-wireshark-x64-on-an-x86-windows-machine/</link>
      <pubDate>Mon, 13 Feb 2012 18:47:00 +0000</pubDate>
      
      <guid>/questions/8986/how-to-cross-compile-wireshark-x64-on-an-x86-windows-machine/</guid>
      <description>How to cross compile Wireshark x64 on an x86 Windows machine  0 I am using rev 37663 of Wireshark (1.7.0) and VS 2008 on Windows XP x86 and I would like to compile a 64-bit version of Wireshark. I have followed all the instructions detailed in http://wiki.wireshark.org/Development/Win64
Here&#39;s what I&#39;ve done:
prepared cmd.exe by running:
&#34;C:\Program Files\Microsoft Visual Studio 9.0\VC\vcvarsall.bat&#34; x86_amd64I&#39;ve also tried running this command as well, with the same result:</description>
    </item>
    
    <item>
      <title>how to read a specific octet from the dest IP in Lua</title>
      <link>/questions/8990/how-to-read-a-specific-octet-from-the-dest-ip-in-lua/</link>
      <pubDate>Tue, 14 Feb 2012 01:32:00 +0000</pubDate>
      
      <guid>/questions/8990/how-to-read-a-specific-octet-from-the-dest-ip-in-lua/</guid>
      <description>how to read a specific octet from the dest IP in Lua  0 What&#39;s the Lua to get a specific octet out of the destination IP address of a packet?
luaasked 14 Feb &#39;12, 01:32
Leena
51●17●18●21
accept rate: 0%
 edited 15 Feb &#39;12, 06:06 
helloworld
3.1k●4●20●41
By &#34;check&#34;, do you mean &#34;get the value of&#34;?
Where is this IP from? The source IP address of a packet?</description>
    </item>
    
    <item>
      <title>Decoding of WebSocket protocol (RFC 6455)</title>
      <link>/questions/8992/decoding-of-websocket-protocol-rfc-6455/</link>
      <pubDate>Tue, 14 Feb 2012 03:00:00 +0000</pubDate>
      
      <guid>/questions/8992/decoding-of-websocket-protocol-rfc-6455/</guid>
      <description>Decoding of WebSocket protocol (RFC 6455)  0 Is there any plan for WireShark to provide decoding of the new WebSocket protocol (RFC 6455)? This would be most useful for debugging code that uses websockets. At present it appears that websocket traffic gets decoded as malformed packets.
rfc6455 websocketsasked 14 Feb &#39;12, 03:00
theRat
1●1●1●1
accept rate: 0%
  
One Answer:
  
0There doesn&#39;t appear to be anything in current trunk or bugzilla.</description>
    </item>
    
    <item>
      <title>SMB	Write AndX Request, FID: Process question</title>
      <link>/questions/8994/smb-write-andx-request-fid-process-question/</link>
      <pubDate>Tue, 14 Feb 2012 06:07:00 +0000</pubDate>
      
      <guid>/questions/8994/smb-write-andx-request-fid-process-question/</guid>
      <description>SMB Write AndX Request, FID: Process question  0 Hello All,
I need to understand the SMB Write AndX Request order Please correct me if i am wrong with process as follows: Thanks
1.Client &amp;gt; Storage SMB Write AndX Request,FID: 0x0009 next 2.TCP [TCP segment of a reassembled PDU] . . . . TCP [TCP segment of a reassembled PDU] . . 3.Storage &amp;gt; Client SMB Write AndX Response, FID: 0x0009smbasked 14 Feb &#39;12, 06:07</description>
    </item>
    
    <item>
      <title>How can I tell which HTTP GET a particular response belongs to?</title>
      <link>/questions/8997/how-can-i-tell-which-http-get-a-particular-response-belongs-to/</link>
      <pubDate>Tue, 14 Feb 2012 10:21:00 +0000</pubDate>
      
      <guid>/questions/8997/how-can-i-tell-which-http-get-a-particular-response-belongs-to/</guid>
      <description>How can I tell which HTTP GET a particular response belongs to?  0 I would like to know which HTTP GET relates to which response. Is there somewhere in the TCP packet that references the GET and is included in the response? For example, if there are five GET requests and only one response, is there a way to determine what GET it corresponds to?
httpasked 14 Feb &#39;12, 10:21</description>
    </item>
    
    <item>
      <title>30 seconds delays in server response</title>
      <link>/questions/9000/30-seconds-delays-in-server-response/</link>
      <pubDate>Tue, 14 Feb 2012 11:26:00 +0000</pubDate>
      
      <guid>/questions/9000/30-seconds-delays-in-server-response/</guid>
      <description>30 seconds delays in server response  0 After examining the Wireshark flow graph. The clients connects to the the server then after the PSH, ACK it takes the server 30 seconds to respond. This happens 6 times in the total conversation, making data transfer take forever. Win7 PC connecting to a VM CentOS 5.7. VMWare are tools installed. Does any one have any ideas what might cause this 30 second delay in server response?</description>
    </item>
    
    <item>
      <title>How can I identify the instant at which a webage is refreshed?</title>
      <link>/questions/9001/how-can-i-identify-the-instant-at-which-a-webage-is-refreshed/</link>
      <pubDate>Tue, 14 Feb 2012 11:51:00 +0000</pubDate>
      
      <guid>/questions/9001/how-can-i-identify-the-instant-at-which-a-webage-is-refreshed/</guid>
      <description>How can I identify the instant at which a webage is refreshed?  0 Is way to know when a webpage is refreshed based on the information in a packet? I ran Wireshark for different websites, and refreshed them when the capturing was in progress. I couldn&#39;t find a concrete pattern as to which packet in particular indicates that the page has been refreshed.
webpage http analysis packetasked 14 Feb &#39;12, 11:51</description>
    </item>
    
    <item>
      <title>SSL Session ReUse</title>
      <link>/questions/9007/ssl-session-reuse/</link>
      <pubDate>Tue, 14 Feb 2012 14:45:00 +0000</pubDate>
      
      <guid>/questions/9007/ssl-session-reuse/</guid>
      <description>SSL Session ReUse  0 Does anyone know how SSL Servers maintains its SSL Session ID Table so it know that a SSL Session ID that is being reused is still valid? What I&#39;m trying to determine is if it keeps track of the session id and the client ip or is it something else that the server uses to keep track of the sessions.
Thanks!
sslasked 14 Feb &#39;12, 14:45</description>
    </item>
    
    <item>
      <title>Need of sample pcap file for STUN  and  STUN2  protocols</title>
      <link>/questions/9009/need-of-sample-pcap-file-for-stun-and-stun2-protocols/</link>
      <pubDate>Tue, 14 Feb 2012 22:41:00 +0000</pubDate>
      
      <guid>/questions/9009/need-of-sample-pcap-file-for-stun-and-stun2-protocols/</guid>
      <description>Need of sample pcap file for STUN and STUN2 protocols  0 Hi,
As i am new for using STUN protocol and i need to implement this in our code base. Please provide me a sample captured pcap file and wireshark open source code for the STUN and STUN2 protocols.
I hope wireshark community definitely will help me for my project.
Thanks &amp;amp; Regards, Suman
and stun protocols stun2This question is marked &#34;</description>
    </item>
    
    <item>
      <title>Anlyzing SMB write issue</title>
      <link>/questions/9011/anlyzing-smb-write-issue/</link>
      <pubDate>Wed, 15 Feb 2012 02:23:00 +0000</pubDate>
      
      <guid>/questions/9011/anlyzing-smb-write-issue/</guid>
      <description>Anlyzing SMB write issue  0 Hello,
I have a situation with station that have video feed that writing the video directly into Netapp storage as follows.
The client that write the feed write it in dv25 format (approx. 4MB/s) the issue is that every few min 2~3 we have error in write application took more than 400~800ms to write the frame causing frame lost , i have done a trace from station feed and started to analyze it i can see that SMB Service response time Write andX MAX have 826ms which correspond to issue we have but looking on TCP [TCP segment of a reassembled PDU] related i can see many notification during pdu transmit [TCP Window Full] [TCP segment of a reassembled PDU] My question would be ,can that be the reason for the high Write andX MAX response meaning pure storage system latency or the fact that client writing have no buffer multiplier causing the delay for late response.</description>
    </item>
    
    <item>
      <title>Confusing Lua reassembly documentation, how is this done in current 1.6.x/1.7.0 ?</title>
      <link>/questions/9018/confusing-lua-reassembly-documentation-how-is-this-done-in-current-16x170/</link>
      <pubDate>Wed, 15 Feb 2012 04:54:00 +0000</pubDate>
      
      <guid>/questions/9018/confusing-lua-reassembly-documentation-how-is-this-done-in-current-16x170/</guid>
      <description>Confusing Lua reassembly documentation, how is this done in current 1.6.x/1.7.0 ?  4 1Hi,
As I am using a Lua dissector to debug the implementation of a proprietary protocol, I am having trouble getting TCP reassembly to work. End user stuff such as allowing reassembly seems OK, but currently my dissector still sees each TCP segment/packet as a new stream, giving wrong results for data crossing segment bounds.
The documentation I have been able to find is confusing and seems self-contradictory:</description>
    </item>
    
    <item>
      <title>Troubleshoot Outlook Anywhere Outlook 2010 Connectivity Problems</title>
      <link>/questions/9019/troubleshoot-outlook-anywhere-outlook-2010-connectivity-problems/</link>
      <pubDate>Wed, 15 Feb 2012 05:27:00 +0000</pubDate>
      
      <guid>/questions/9019/troubleshoot-outlook-anywhere-outlook-2010-connectivity-problems/</guid>
      <description>Troubleshoot Outlook Anywhere Outlook 2010 Connectivity Problems  0 Client is stating they are receiving intermittent connectivity with our Exchange Outlook Anywhere server, this is an isolated incident. I had the client provide a .pcap trace over a 15 minute period where their Outlook client was connecting/disconnecting every 10 seconds or so. Can someone assist me in what I should look for in this trace to try and determine why their network connectivity is sporadic?</description>
    </item>
    
    <item>
      <title>Can Wireshark monitor wifi?</title>
      <link>/questions/9022/can-wireshark-monitor-wifi/</link>
      <pubDate>Wed, 15 Feb 2012 07:45:00 +0000</pubDate>
      
      <guid>/questions/9022/can-wireshark-monitor-wifi/</guid>
      <description>Can Wireshark monitor wifi?  0 Can Wireshark monitor traffic on a wireless interface (e.g. I&#39;m in an Internet cafe, and I would like to monitor cookies from another PC)?
wireless capture wifi cookieasked 15 Feb &#39;12, 07:45
devilsk13
1●2●2●4
accept rate: 0%
 edited 15 Feb &#39;12, 08:25 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
2 Yes; Wireshark can be used to sniff wireless traffic (see the WLAN Capture Setup article on the Wireshark wiki).</description>
    </item>
    
    <item>
      <title>HTTP GET &amp;amp; 200 in 1 filter</title>
      <link>/questions/9024/http-get-200-in-1-filter/</link>
      <pubDate>Wed, 15 Feb 2012 08:12:00 +0000</pubDate>
      
      <guid>/questions/9024/http-get-200-in-1-filter/</guid>
      <description>HTTP GET &amp;amp; 200 in 1 filter  1 Trying this filter but getting error msg, any idea how can I put GET and 200 in 1 filter. http.request.method == &#34;GET&#34; and http.response.code == 200
Thank you
httpasked 15 Feb &#39;12, 08:12
Ezat
21●2●2●5
accept rate: 0%
Sorry guys I found it in Sake respond to 1 of the questions in HTTP tad as follows. http and (http.request.method == &#34;GET&#34; || http.</description>
    </item>
    
    <item>
      <title>Bandwidth calculation formula</title>
      <link>/questions/9026/bandwidth-calculation-formula/</link>
      <pubDate>Wed, 15 Feb 2012 08:25:00 +0000</pubDate>
      
      <guid>/questions/9026/bandwidth-calculation-formula/</guid>
      <description>Bandwidth calculation formula  0 Help I need to calculate bandwidth requirement for site with 200 workstations running 15 different applications, got all the applications bandwidth per workstation. How do I calculate the bandwidth to get the right size line?
calculation formula bandwidthasked 15 Feb &#39;12, 08:25
Hennie
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>[closed] How to use firesheep</title>
      <link>/questions/9029/how-to-use-firesheep/</link>
      <pubDate>Wed, 15 Feb 2012 08:51:00 +0000</pubDate>
      
      <guid>/questions/9029/how-to-use-firesheep/</guid>
      <description>[closed] How to use firesheep  -3 Hello,
I would like to know how to use firesheep because i´m having problems using it. I&#39;m running Mozilla Firefox 10.0.1, I have a 64-bit operating system, Windows 7. When I try to install it, it says that the firesheep isn&#39;t compatible. What should I do?
Thanks
firesheepasked 15 Feb &#39;12, 08:51
devilsk13
1●2●2●4
accept rate: 0%
 closed 15 Feb &#39;12, 09:48</description>
    </item>
    
    <item>
      <title>Filter repeat destination IPs showing</title>
      <link>/questions/9032/filter-repeat-destination-ips-showing/</link>
      <pubDate>Wed, 15 Feb 2012 09:05:00 +0000</pubDate>
      
      <guid>/questions/9032/filter-repeat-destination-ips-showing/</guid>
      <description>Filter repeat destination IPs showing  0 Hi,
i dont think this is possible but i thought id check.
i want to audit which ips are being accessed by one source host over a certain link. this bit easy as i can see all ips in the dump...
how ever i want to only see one hit to the destination ips in the output...not all traffic so that i can make a list of servers remote side for my audit.</description>
    </item>
    
    <item>
      <title>Unable to parse RTPS2 attributes through MATE or through display filter</title>
      <link>/questions/9045/unable-to-parse-rtps2-attributes-through-mate-or-through-display-filter/</link>
      <pubDate>Wed, 15 Feb 2012 14:36:00 +0000</pubDate>
      
      <guid>/questions/9045/unable-to-parse-rtps2-attributes-through-mate-or-through-display-filter/</guid>
      <description>Unable to parse RTPS2 attributes through MATE or through display filter  0 I have a network of machines all participating in a publish/subscribe environment using NDDS. My goal is to generate a list of all Topics and associated Messages. In addition, that list will include the publishers and subscribers of said messages.
NDDS, according to Wireshark parsing, equates to RTPS2 packets, and Wireshark has no problem parsing out the packets into awe-inspiring hierarchies.</description>
    </item>
    
    <item>
      <title>hairpinning static NAT</title>
      <link>/questions/9047/hairpinning-static-nat/</link>
      <pubDate>Wed, 15 Feb 2012 18:56:00 +0000</pubDate>
      
      <guid>/questions/9047/hairpinning-static-nat/</guid>
      <description>hairpinning static NAT  0 Hi network experts,
My question is not directly related to wireshark. But when I start wireshark, the network behaviour is changed and I don&#39;t know why.
I have the following setup: Linux machine (OpenSuse 12.1) with one physical network interface. Interface has many IP&#39;s like 192.168.10.10, 192.168.10.11 ... 192.168.10.15
KVM is running on this box using libvirt and virt-manage.
Second interface is a virtual bridge virbr0 with IP 10.</description>
    </item>
    
    <item>
      <title>Capturing only IEEE 802.11 Beacon Frames??</title>
      <link>/questions/9048/capturing-only-ieee-80211-beacon-frames/</link>
      <pubDate>Wed, 15 Feb 2012 19:19:00 +0000</pubDate>
      
      <guid>/questions/9048/capturing-only-ieee-80211-beacon-frames/</guid>
      <description>Capturing only IEEE 802.11 Beacon Frames??  0 Hey, so When i start to capture my own traffic i get only IEEE 802.11 protocol. So i tryed googling but strangley no answer soooo any tips would be very appreciated!!!
802.11 ieeeasked 15 Feb &#39;12, 19:19
John Why U Care
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>can i run/recompile a zip app that i capture?</title>
      <link>/questions/9050/can-i-runrecompile-a-zip-app-that-i-capture/</link>
      <pubDate>Wed, 15 Feb 2012 20:56:00 +0000</pubDate>
      
      <guid>/questions/9050/can-i-runrecompile-a-zip-app-that-i-capture/</guid>
      <description>can i run/recompile a zip app that i capture?  0 hello i have caputed a zip/app and i was wondering if i could use the hex code to recompile said app. thanks for any help.
app zipasked 15 Feb &#39;12, 20:56
Wolf Demon
1●1●1●2
accept rate: 0%
  
One Answer:
  
1if the protocol used is HTTP or SMB, you can try File-&amp;gt;Export-&amp;gt;Objects.
Otherwise, as far I as know there isn&#39;t an &#39;easy way&#39; to do this.</description>
    </item>
    
    <item>
      <title>Within the scope of a Wireshark dissector, Is it possible to detect out order sequence ids (based on arrival time) in PTP V2?</title>
      <link>/questions/9051/within-the-scope-of-a-wireshark-dissector-is-it-possible-to-detect-out-order-sequence-ids-based-on-arrival-time-in-ptp-v2/</link>
      <pubDate>Wed, 15 Feb 2012 22:00:00 +0000</pubDate>
      
      <guid>/questions/9051/within-the-scope-of-a-wireshark-dissector-is-it-possible-to-detect-out-order-sequence-ids-based-on-arrival-time-in-ptp-v2/</guid>
      <description>Within the scope of a Wireshark dissector, Is it possible to detect out order sequence ids (based on arrival time) in PTP V2?  0 Is it possible to detect out order sequence ids (based on arrival time) in PTP V2?
This would be for both file open and streaming pcaps, and the ordering would also be based on packets that share a &#34;flow&#34; direction (based on the &#34;class&#34; of message_id they belong too as well.</description>
    </item>
    
    <item>
      <title>K12 protocols</title>
      <link>/questions/9054/k12-protocols/</link>
      <pubDate>Thu, 16 Feb 2012 02:48:00 +0000</pubDate>
      
      <guid>/questions/9054/k12-protocols/</guid>
      <description>K12 protocols  0 Hello.
I wonder what protocol should be used in case of ISDN PRI in tectronix files .rf5 ?
k12 protocolasked 16 Feb &#39;12, 02:48
Pnk
6●2●2●5
accept rate: 0%
  
2 Answers:
  
1 I would guess at q931 or LAPD. browsing the .r5 file might give a hint.
answered 17 Feb &#39;12, 11:28
Anders ♦
4.6k●9●52
accept rate: 17%
 edited 27 Feb &#39;12, 13:39</description>
    </item>
    
    <item>
      <title>Is there a way to tell if a packet is from a pcap file, or is from a live capture from within a dissector?</title>
      <link>/questions/9060/is-there-a-way-to-tell-if-a-packet-is-from-a-pcap-file-or-is-from-a-live-capture-from-within-a-dissector/</link>
      <pubDate>Thu, 16 Feb 2012 06:42:00 +0000</pubDate>
      
      <guid>/questions/9060/is-there-a-way-to-tell-if-a-packet-is-from-a-pcap-file-or-is-from-a-live-capture-from-within-a-dissector/</guid>
      <description>Is there a way to tell if a packet is from a pcap file, or is from a live capture from within a dissector?  0 Within a dissector, is it possible to know if the tvbuff_t is populated from a file or from a live capture?
tvbuff_t capture dissector developmentasked 16 Feb &#39;12, 06:42
wintermut3
6●2●2●5
accept rate: 0%
 edited 16 Feb &#39;12, 07:09 
multipleinte...
1.3k●15●23●40
1Why do you need to know?</description>
    </item>
    
    <item>
      <title>Unable to view HTTPS stream using SSL decryption (&amp;quot;Follow SSL Stream&amp;quot; is greyed out.)</title>
      <link>/questions/9071/unable-to-view-https-stream-using-ssl-decryption-follow-ssl-stream-is-greyed-out/</link>
      <pubDate>Thu, 16 Feb 2012 10:04:00 +0000</pubDate>
      
      <guid>/questions/9071/unable-to-view-https-stream-using-ssl-decryption-follow-ssl-stream-is-greyed-out/</guid>
      <description>Unable to view HTTPS stream using SSL decryption (&amp;ldquo;Follow SSL Stream&amp;rdquo; is greyed out.)  1 I&#39;m trying to use wireshark to debug a REST application running over HTTP with SSL.
I&#39;m using Version 1.6.5 (SVN Rev 40429 from /trunk-1.6)running on Windows 7.
I&#39;ve installed the RSA key in Wireshark using Edit/Prefernces/Protocols/SSL and installing my server&#39;s unencrypted private key inthe &#34;RSA keys list&#34;. It&#39;s installed with the IP address of the server (in this case I&#39;m running both server and client on the local machine, so it&#39;s the same as the address of the client), the port (which happens to be 8181), protocol=http (get an error if I try to put in https, so I assume http is the correct value here), and the location of my key file.</description>
    </item>
    
    <item>
      <title>Does Wireshark capture/support RSC packets</title>
      <link>/questions/9074/does-wireshark-capturesupport-rsc-packets/</link>
      <pubDate>Thu, 16 Feb 2012 11:01:00 +0000</pubDate>
      
      <guid>/questions/9074/does-wireshark-capturesupport-rsc-packets/</guid>
      <description>Does Wireshark capture/support RSC packets  0 Hi, Windows 8 Server and certain network adapters will be supporting Receive Side Coalescing (or Receive Segment Coalescing if you&#39;re Intel). Does Wireshark support the capturing of Coalesced packets? Will Wireshark have any restrictions on the packet size?
Thank you!
windows8 coalescing rscasked 16 Feb &#39;12, 11:01
eastilleros
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1Does Wireshark support the capturing of Coalesced packets?</description>
    </item>
    
    <item>
      <title>HTTP &amp;quot;Get&amp;quot; messages are not visible in Wireshark</title>
      <link>/questions/9076/http-get-messages-are-not-visible-in-wireshark/</link>
      <pubDate>Thu, 16 Feb 2012 14:12:00 +0000</pubDate>
      
      <guid>/questions/9076/http-get-messages-are-not-visible-in-wireshark/</guid>
      <description>HTTP &amp;ldquo;Get&amp;rdquo; messages are not visible in Wireshark  0 Hi,
I am working on Windows 7 Labtop connecting to my home WIFI network.
I am new to Wireshark, i have read all the basic tutorials and i understand the tool pretty well though.
After choosing my network interface and hitting the start button, i opened the browser and went to many websites and clicked on many links, i am getting packets related to HTTP (most of them are 200 OK), but not a single packet with &#34;</description>
    </item>
    
    <item>
      <title>implementing autostop condition on packet capture!</title>
      <link>/questions/9080/implementing-autostop-condition-on-packet-capture/</link>
      <pubDate>Thu, 16 Feb 2012 23:11:00 +0000</pubDate>
      
      <guid>/questions/9080/implementing-autostop-condition-on-packet-capture/</guid>
      <description>implementing autostop condition on packet capture!  0 Im doing a live capture using pcap librery..
pcap_t pcap_open_live(const char device, int snaplen,int promisc, int to_ms, char *errbuf)
then i dump it into a file...
pcap_dumper_t pcap_dump_open(pcap_t p, const char *fname)
void pcap_dump(u_char user, struct pcap_pkthdr h,u_char *sp)
and then dissecting it using libwireshark..
now i want to put a tiimer based autostop condition on packet capturing and dumping.. coudnt find a way how to do it.</description>
    </item>
    
    <item>
      <title>Edit PCAP file</title>
      <link>/questions/9088/edit-pcap-file/</link>
      <pubDate>Fri, 17 Feb 2012 05:25:00 +0000</pubDate>
      
      <guid>/questions/9088/edit-pcap-file/</guid>
      <description>Edit PCAP file  0 Hello, I need to modify a pcap file. For example, I need to edit the IP address, timestamp, URL, ... fields. How can I do it? Do I have to write a new software application, or is one available in the network?
Thanks Paolino
edit pcapasked 17 Feb &#39;12, 05:25
Paolino
1●1●1●1
accept rate: 0%
 edited 26 Feb &#39;12, 20:37 
cmaynard ♦♦
9.4k●10●38●142</description>
    </item>
    
    <item>
      <title>Capturing packets from Nokia E5 connected through USB</title>
      <link>/questions/9089/capturing-packets-from-nokia-e5-connected-through-usb/</link>
      <pubDate>Fri, 17 Feb 2012 05:26:00 +0000</pubDate>
      
      <guid>/questions/9089/capturing-packets-from-nokia-e5-connected-through-usb/</guid>
      <description>Capturing packets from Nokia E5 connected through USB  1 IS there a way to capture 3G packets when connecting to the internet using Nokia E5. I was able to connect using HTC as the interface appeared normally, but for E5 the interface isn&#39;t seen.
Could it be related to HTC being android which is based on a linux kernal? while Nokia E5 isn&#39;t?
capture data phoneasked 17 Feb &#39;12, 05:26</description>
    </item>
    
    <item>
      <title>wireless card not detected, and cannot capture low-level traffic</title>
      <link>/questions/9093/wireless-card-not-detected-and-cannot-capture-low-level-traffic/</link>
      <pubDate>Fri, 17 Feb 2012 07:02:00 +0000</pubDate>
      
      <guid>/questions/9093/wireless-card-not-detected-and-cannot-capture-low-level-traffic/</guid>
      <description>wireless card not detected, and cannot capture low-level traffic  0 I&#39;m running Wireshark 1.2.4 on Windows 7 and I have WinPcap 4.1.1 installed. In Wireshark only the following three interfaces are listed: &#34;Microsoft&#34; &#34;NDIS-WDM Driver for HighSpeed USB-Ethernet Adapter&#34; &#34;Realtek RTL8102/8103 Family PCI-E FE NIC&#34;
It doesn&#39;t list the wireless card inside my Dell laptop, the wireless card which is listed in Control Panel as &#34;Dell Wireless 1520 Wireless-N WLAN Mini-Card&#34;</description>
    </item>
    
    <item>
      <title>tshark auto shutdown</title>
      <link>/questions/9095/tshark-auto-shutdown/</link>
      <pubDate>Fri, 17 Feb 2012 08:23:00 +0000</pubDate>
      
      <guid>/questions/9095/tshark-auto-shutdown/</guid>
      <description>tshark auto shutdown  0 Hi folks;
I am automating some tests that use wireshark. I will switching to tshark so the tests can be batched.
Each test will perform a capture, perhaps with a unique capture filter. How do I &#34;terminate&#34; the tshark process once I&#39;ve captured 1000 packets (just an example), so that I can create a new tshark process for my next test ?? If a set a capture filter to &#34;</description>
    </item>
    
    <item>
      <title>Unable to capture packets promiscuously on Wi-Fi on Windows</title>
      <link>/questions/9102/unable-to-capture-packets-promiscuously-on-wi-fi-on-windows/</link>
      <pubDate>Fri, 17 Feb 2012 11:39:00 +0000</pubDate>
      
      <guid>/questions/9102/unable-to-capture-packets-promiscuously-on-wi-fi-on-windows/</guid>
      <description>Unable to capture packets promiscuously on Wi-Fi on Windows  0 I am trying to configure Wireshark to capture all packets on my WiFi network, however I am only packets to and from my computers, in addition to broadcast packets.
I am relatively new to Wireshark but I seem to remember when I used it on my old laptop, Wireshark had this functionality &#34;out of the box&#34;.
The interface I am using is a Intel Centrino Wireless-N 1030.</description>
    </item>
    
    <item>
      <title>Tshark equivalent to endpoints Gui window</title>
      <link>/questions/9104/tshark-equivalent-to-endpoints-gui-window/</link>
      <pubDate>Fri, 17 Feb 2012 11:46:00 +0000</pubDate>
      
      <guid>/questions/9104/tshark-equivalent-to-endpoints-gui-window/</guid>
      <description>Tshark equivalent to endpoints Gui window  0 I&#39;m interested in finding out how to produce an endpoints graph via Tshark that is essentially equivalent to the IPv4 endpoints window with no filter?
Joke, I&#39;m specifically looking for something that isn&#39;t conversation specific, but host specific like the Wireshark IPv4 endpoints window... I&#39;ve already been down the conversations road and it is too finely grained; I just need summarizations for each IPv4 endpoint only.</description>
    </item>
    
    <item>
      <title>How to capture LTE data card packet in Wireshark?</title>
      <link>/questions/9106/how-to-capture-lte-data-card-packet-in-wireshark/</link>
      <pubDate>Fri, 17 Feb 2012 11:51:00 +0000</pubDate>
      
      <guid>/questions/9106/how-to-capture-lte-data-card-packet-in-wireshark/</guid>
      <description>How to capture LTE data card packet in Wireshark?  0 Hi, I would like to know if anyone has tried to use Wireshark with an LTE data card to dissect the RRC messages? If so how should it be done?
Thanks, Ganesh
datacard rrc lteasked 17 Feb &#39;12, 11:51
VGM
1●1●1●2
accept rate: 0%
 edited 17 Feb &#39;12, 12:04 
  
3 Answers:</description>
    </item>
    
    <item>
      <title>[closed] how to access data in such table?</title>
      <link>/questions/9111/how-to-access-data-in-such-table/</link>
      <pubDate>Fri, 17 Feb 2012 19:24:00 +0000</pubDate>
      
      <guid>/questions/9111/how-to-access-data-in-such-table/</guid>
      <description>[closed] how to access data in such table?  0 Hi, I&#39;m writing a program with lua. I have data that organized in the following way: t= {i1{p1{,,,},p2{,,,},...pm{,,,}},i2{p1{,,,},p2{,,,},...pm{,,,}},...,in{p1{,,,},p2{,,,},...pm{,,,}}} (inner tables) In another way each group of data is indexed by two variables i&amp;amp;p,I am sure that the data is kept correctly but I want a way to print the data from their tables because I won&#39;t know the values of i and p to iterate over them or even the numbers n &amp;amp; m any body know how to do this with lua?</description>
    </item>
    
    <item>
      <title>[closed] use a timer in lua</title>
      <link>/questions/9112/use-a-timer-in-lua/</link>
      <pubDate>Fri, 17 Feb 2012 20:37:00 +0000</pubDate>
      
      <guid>/questions/9112/use-a-timer-in-lua/</guid>
      <description>[closed] use a timer in lua  0 hi i need to process data withen 1 minute using lua, data processing starts at t=0s and stops at t=60s,how can i figure it out using lua?if possible explain with an example.
luaasked 17 Feb &#39;12, 20:37
Leena
51●17●18●21
accept rate: 0%
 closed 25 Feb &#39;12, 17:04 
helloworld
3.1k●4●20●41
http://stackoverflow.com/questions/9393693/how-to-use-a-timer-in-lua
(25 Feb &#39;12, 17:06) helloworld The question has been closed for the following reason &amp;ldquo;http://stackoverflow.</description>
    </item>
    
    <item>
      <title>Capture filter does not work</title>
      <link>/questions/9118/capture-filter-does-not-work/</link>
      <pubDate>Sat, 18 Feb 2012 01:36:00 +0000</pubDate>
      
      <guid>/questions/9118/capture-filter-does-not-work/</guid>
      <description>Capture filter does not work  0 Hi all
No packets are captured when i try to find out http traffic (tcp port 80). Althuogh I can find them when I capture all packets (e.g. without any capture filter), applying display filter.
I ran Wireshark as administrator but the problem remained.
Windows 7 Wireshark 1.6.5
Thanks in advance
filter capture does not workasked 18 Feb &#39;12, 01:36
clipsya
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>nothing to capture</title>
      <link>/questions/9129/nothing-to-capture/</link>
      <pubDate>Sat, 18 Feb 2012 09:02:00 +0000</pubDate>
      
      <guid>/questions/9129/nothing-to-capture/</guid>
      <description>nothing to capture  0 why does it say nothing to capture? how do I turn on a driver?
driverasked 18 Feb &#39;12, 09:02
Justme
1●1●1●1
accept rate: 0%
It might help if you add some information. What kind of OS are you using, which version of wireshark? Which steps have you taken when the error message occurred? And what is the exact error message?
(20 Feb &#39;12, 13:16) SYN-bit ♦♦   </description>
    </item>
    
    <item>
      <title>How do I list all of the packet types within a capture?</title>
      <link>/questions/9130/how-do-i-list-all-of-the-packet-types-within-a-capture/</link>
      <pubDate>Sun, 19 Feb 2012 12:39:00 +0000</pubDate>
      
      <guid>/questions/9130/how-do-i-list-all-of-the-packet-types-within-a-capture/</guid>
      <description>How do I list all of the packet types within a capture?  0 I am running Wireshark, and I can view statistics, but what part of the output shows a &#34;packet type&#34;?
packetlist statisticsasked 19 Feb &#39;12, 12:39
sssddd
1●3●3●3
accept rate: 0%
 edited 20 Feb &#39;12, 09:29 
multipleinte...
1.3k●15●23●40
  
2 Answers:
  
1I&#39;m assuming by &#34;packet type&#34; you mean the protocol.</description>
    </item>
    
    <item>
      <title>How do I determine if a packet is a broadcast packet?</title>
      <link>/questions/9131/how-do-i-determine-if-a-packet-is-a-broadcast-packet/</link>
      <pubDate>Sun, 19 Feb 2012 12:58:00 +0000</pubDate>
      
      <guid>/questions/9131/how-do-i-determine-if-a-packet-is-a-broadcast-packet/</guid>
      <description>How do I determine if a packet is a broadcast packet?  0 I know nothing about networking. I was asked to find a percentage of all packets that are broadcast packets from a capture I did. Can someone tell me how to do that please?
broadcast packets analysisasked 19 Feb &#39;12, 12:58
sssddd
1●3●3●3
accept rate: 0%
 edited 20 Feb &#39;12, 09:27 
multipleinte...
1.3k●15●23●40</description>
    </item>
    
    <item>
      <title>How do I get TCP problem list?</title>
      <link>/questions/9132/how-do-i-get-tcp-problem-list/</link>
      <pubDate>Sun, 19 Feb 2012 13:27:00 +0000</pubDate>
      
      <guid>/questions/9132/how-do-i-get-tcp-problem-list/</guid>
      <description>How do I get TCP problem list?  0 I need to use wireshark for a couple hours and list all the TCP problems like &#34;zero window&#34; and &#34;window update&#34;. Where do I find that information after a capture? thanks
tcpasked 19 Feb &#39;12, 13:27
sssddd
1●3●3●3
accept rate: 0%
  
2 Answers:
  
0Just put in the display filter &#34;tcp.analysis.flags&#34;. Please keep in mind that not all those messages are in fact &#34;</description>
    </item>
    
    <item>
      <title>Wireshark crash after 2 days</title>
      <link>/questions/9137/wireshark-crash-after-2-days/</link>
      <pubDate>Mon, 20 Feb 2012 01:05:00 +0000</pubDate>
      
      <guid>/questions/9137/wireshark-crash-after-2-days/</guid>
      <description>Wireshark crash after 2 days  0 Hey,
I&#39;ve got an effect with a Wireshark crash. After two days Wireshark crashes with the error: &#34;This application has requested the Runtim to terminate it in an unusual way. Please contacs the application&#39;s support team&#34;. The problem signature looks like this: Problem signature: Problem Event Name: APPCRASH Application Name: wireshark.exe Application Version: 1.6.5.40429 Application Timestamp: 4f0c8ce1 Fault Module Name: libglib-2.0-0.dll Fault Module Version: 2.</description>
    </item>
    
    <item>
      <title>How do you get wireshark to scan all subnets in windows?</title>
      <link>/questions/9144/how-do-you-get-wireshark-to-scan-all-subnets-in-windows/</link>
      <pubDate>Mon, 20 Feb 2012 11:10:00 +0000</pubDate>
      
      <guid>/questions/9144/how-do-you-get-wireshark-to-scan-all-subnets-in-windows/</guid>
      <description>How do you get wireshark to scan all subnets in windows?  0 I&#39;m a bit of a layman with this, so I apologize if I&#39;m using the wrong terms. Say I have a device that has an IP in it and has no method to reset. I have no idea what the IP/subnet/gateway might be. I have seen wireshark on a Linux machine find the IP of a device like this but in Windows I have only been able to find it if I know the IP range it is in 10.</description>
    </item>
    
    <item>
      <title>Cannot extract complete Http Header with Intel Interface</title>
      <link>/questions/9145/cannot-extract-complete-http-header-with-intel-interface/</link>
      <pubDate>Mon, 20 Feb 2012 12:03:00 +0000</pubDate>
      
      <guid>/questions/9145/cannot-extract-complete-http-header-with-intel-interface/</guid>
      <description>Cannot extract complete Http Header with Intel Interface  0 I am using jNetPcap library to extract packet information from an offline Pcap file.When I capture packets on Wi-fi network with Microsoft Interface I am able to extract the Http header with all fields. However with Intel Interface(i.e when I am on Proxy Connection), I am unable to get the complete http header, certain fields such as RequestURl,Request Version,RequestMethod are missing, Although they are visible in my Pcap file.</description>
    </item>
    
    <item>
      <title>utility to convert usbmon capture to libpcap format</title>
      <link>/questions/9151/utility-to-convert-usbmon-capture-to-libpcap-format/</link>
      <pubDate>Mon, 20 Feb 2012 14:30:00 +0000</pubDate>
      
      <guid>/questions/9151/utility-to-convert-usbmon-capture-to-libpcap-format/</guid>
      <description>utility to convert usbmon capture to libpcap format  0 I am working on an embedded system. no GUI. Would like to analyze usbmon file offline to see output like wireshark produces. I gather there is no way to do this at the moment since wireshark uses libpcap format.
a) Has someone written a utility to convert usbmon file to correct format. b) if not --&amp;gt; can you point me in the right direction to see if I can do this.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t get Lua dissector to add to tree with Protofields</title>
      <link>/questions/9155/cant-get-lua-dissector-to-add-to-tree-with-protofields/</link>
      <pubDate>Mon, 20 Feb 2012 16:04:00 +0000</pubDate>
      
      <guid>/questions/9155/cant-get-lua-dissector-to-add-to-tree-with-protofields/</guid>
      <description>Can&amp;rsquo;t get Lua dissector to add to tree with Protofields  2 1I&#39;ve a simple Lua dissector, which uses what I think is the &#39;old&#39; format for adding to the tree.
subtree:add(buffer(3,1),&amp;quot;The 4th byte: &amp;quot; .. buffer(3,1):uint())I&#39;ve tried using protofields instead, but nothing gets added to the tree.
foo_proto.fields.u16 = ProtoField.uint16(&amp;quot;foo.u16&amp;quot;, &amp;quot;Unsigned short&amp;quot;, base.HEX) local t = tree:add(foo_proto,buf()) t:add(foo_proto.fields.u16, buf(0,2))Does anyone have any pointers to how to do this, or a working simple dummy TCP dissector?</description>
    </item>
    
    <item>
      <title>Are 3GPP TS 32.298 Charging Data Records from the Ga Reference Point dissected?</title>
      <link>/questions/9156/are-3gpp-ts-32298-charging-data-records-from-the-ga-reference-point-dissected/</link>
      <pubDate>Mon, 20 Feb 2012 16:20:00 +0000</pubDate>
      
      <guid>/questions/9156/are-3gpp-ts-32298-charging-data-records-from-the-ga-reference-point-dissected/</guid>
      <description>Are 3GPP TS 32.298 Charging Data Records from the Ga Reference Point dissected?  0 Hello, does Ga interface is supported by any release of WireShark? If it does please, could you please give me the hint what version to use to have Charging Data Records decoded?
records data charging gaasked 20 Feb &#39;12, 16:20
emarina
1●2●2●2
accept rate: 0%
 edited 05 Apr &#39;12, 13:18 
Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>SSL decoding not working 1.6.5 on Windows 7 64-bit</title>
      <link>/questions/9158/ssl-decoding-not-working-165-on-windows-7-64-bit/</link>
      <pubDate>Tue, 21 Feb 2012 02:08:00 +0000</pubDate>
      
      <guid>/questions/9158/ssl-decoding-not-working-165-on-windows-7-64-bit/</guid>
      <description>SSL decoding not working 1.6.5 on Windows 7 64-bit  0 The routine seems straight forward:
remote server has address 75.147.41.121 with port 8443I have created its private key and placed its pem encoded form on the client for wireshark-in the preferences/protocol/ssl I have added the required information such that the ssl_keys file contains the following:-&#34;75.147.121.41&#34;,&#34;8443&#34;,&#34;http&#34;,&#34;C:\users\brian\projects\cJoxPlz\demo\BaseManagerWan_SecureRawHttpSend\res\tomcat75.pem&#34;,&#34;&#34;Everything looks correct according to the documentation, this forum, googling etc. The ssl debug log indicates that the pem-encoded private key is properly loaded:</description>
    </item>
    
    <item>
      <title>Wireshark not capturing packets</title>
      <link>/questions/9160/wireshark-not-capturing-packets/</link>
      <pubDate>Tue, 21 Feb 2012 04:38:00 +0000</pubDate>
      
      <guid>/questions/9160/wireshark-not-capturing-packets/</guid>
      <description>Wireshark not capturing packets  0 Hi to All. I have just installed WinPCap 4.1.2 &amp;amp; also Wireshark 1.6.5 but both my Wireshark &amp;amp; Windump are not capturing any packets. Is it bcoz I use broadband VPN wifi connection, or Windows 7 doesn’t support these? Help pls. Many thanks.
wiresharkasked 21 Feb &#39;12, 04:38
Warren
1●1●1●2
accept rate: 0%
  
2 Answers:
  
1The actual capturing mechanism on Windows, WinPCap, has issues with captures on WiFi interfaces.</description>
    </item>
    
    <item>
      <title>Why does my heuristic dissector leave &amp;quot;Data&amp;quot; on the tree?</title>
      <link>/questions/9168/why-does-my-heuristic-dissector-leave-data-on-the-tree/</link>
      <pubDate>Tue, 21 Feb 2012 11:56:00 +0000</pubDate>
      
      <guid>/questions/9168/why-does-my-heuristic-dissector-leave-data-on-the-tree/</guid>
      <description>Why does my heuristic dissector leave &amp;ldquo;Data&amp;rdquo; on the tree?  0 I have a heuristic dissector which works perfectly, but the tree still contains a &#34;data&#34; field which contains the same number of bytes as the dissector decoded. The tree appears as:
IP
TCP
&amp;lt;my protocol&amp;gt;
Data &amp;lt;x bytes&amp;gt;
Is there a way to remove or block that Data leaf from binding to the tree?
development heuristic dissector data treeasked 21 Feb &#39;12, 11:56</description>
    </item>
    
    <item>
      <title>[closed] Heuristic Dissector leaves &amp;quot;data&amp;quot; on protocol tree</title>
      <link>/questions/9171/heuristic-dissector-leaves-data-on-protocol-tree/</link>
      <pubDate>Wed, 22 Feb 2012 04:56:00 +0000</pubDate>
      
      <guid>/questions/9171/heuristic-dissector-leaves-data-on-protocol-tree/</guid>
      <description>[closed] Heuristic Dissector leaves &amp;ldquo;data&amp;rdquo; on protocol tree  0 I have a dissector which seems to work perfectly. If I register to the TCP ports specifically, it is clean, but if I instead use it as heuristic TCP, it will run, but then below the dissector&#39;s tree entry there is a &#34;data&#34; entry with the TCP payload, even though the dissector should have consumed the entire payload. Is there a way to block this behavior so that the dissector&#39;s tree data will not be followed by the extra entry?</description>
    </item>
    
    <item>
      <title>Can I save manual address resolutions?</title>
      <link>/questions/9173/can-i-save-manual-address-resolutions/</link>
      <pubDate>Wed, 22 Feb 2012 09:21:00 +0000</pubDate>
      
      <guid>/questions/9173/can-i-save-manual-address-resolutions/</guid>
      <description>Can I save manual address resolutions?  0 Is there any way to SAVE manually resolved addresses to LOAD them next time Wireshark runs?
ip resolve addressasked 22 Feb &#39;12, 09:21
contradictor_
1●2●2●4
accept rate: 0%
 edited 23 Feb &#39;12, 17:18 
multipleinte...
1.3k●15●23●40
  
2 Answers:
  
2You can create a hosts file and put it in the Wireshark configuration directory. This file follows the same format as the standard Windows or UNIX hosts file.</description>
    </item>
    
    <item>
      <title>How do I add a custom column to the display via the API?</title>
      <link>/questions/9176/how-do-i-add-a-custom-column-to-the-display-via-the-api/</link>
      <pubDate>Wed, 22 Feb 2012 20:49:00 +0000</pubDate>
      
      <guid>/questions/9176/how-do-i-add-a-custom-column-to-the-display-via-the-api/</guid>
      <description>How do I add a custom column to the display via the API?  0 I know how to add user defined columns from the Wireshark GUI, but I want to know if there is any way to do this through code.
EDITED: I tried adding user defined field to column_info.h but no help. It is not getting reflected in the GUI. I added the corresponding entry in slist[] and dlist[].</description>
    </item>
    
    <item>
      <title>Why cant I capture packets even after I turn off promiscuous mode?</title>
      <link>/questions/9177/why-cant-i-capture-packets-even-after-i-turn-off-promiscuous-mode/</link>
      <pubDate>Wed, 22 Feb 2012 21:25:00 +0000</pubDate>
      
      <guid>/questions/9177/why-cant-i-capture-packets-even-after-i-turn-off-promiscuous-mode/</guid>
      <description>Why cant I capture packets even after I turn off promiscuous mode?  0 When capturing packets without promiscuous mode I get nothing. How do I set WireShark to work on my Wireless N router?
wirelessasked 22 Feb &#39;12, 21:25
bburke89
1●1●1●1
accept rate: 0%
  
One Answer:
  
0If this is on Windows, the answer may be &#34;by installing Linux or *BSD on your machine&#34;. The support for Wi-Fi on Windows with WinPcap is limited, due to a combination of driver problems and WinPcap not supporting NDIS 6 (so that even with drivers that support Native Wi-Fi, WinPcap can&#39;t use it).</description>
    </item>
    
    <item>
      <title>response time - single src ip, multiple dst ip addresses</title>
      <link>/questions/9178/response-time-single-src-ip-multiple-dst-ip-addresses/</link>
      <pubDate>Wed, 22 Feb 2012 22:11:00 +0000</pubDate>
      
      <guid>/questions/9178/response-time-single-src-ip-multiple-dst-ip-addresses/</guid>
      <description>response time - single src ip, multiple dst ip addresses  0 I have a trace with a single source ip address talking to several destination ip addresses. I need a report or graph that shows the http response times for the source going to each dest ip. I need to know who the fastest and slowest servers are when communicating with this ip address. How can I do this? Thank you.</description>
    </item>
    
    <item>
      <title>Strip off GTP Headers</title>
      <link>/questions/9180/strip-off-gtp-headers/</link>
      <pubDate>Thu, 23 Feb 2012 00:44:00 +0000</pubDate>
      
      <guid>/questions/9180/strip-off-gtp-headers/</guid>
      <description>Strip off GTP Headers  1 Hello, I&#39;m trying to strip off the GTP headers of a Gn trace and be left with the TCP/IP stream, which I can then feed into tcptrace for analysis. Any idea how this can be done? What layer 2 protocol is then used for the IP packets, which won&#39;t have the GTP headers anymore? Thanks, Dan
gtp header tcptrace stripasked 23 Feb &#39;12, 00:44</description>
    </item>
    
    <item>
      <title>Can I use subnets or hosts file for manual subnet member resolution?</title>
      <link>/questions/9189/can-i-use-subnets-or-hosts-file-for-manual-subnet-member-resolution/</link>
      <pubDate>Thu, 23 Feb 2012 22:10:00 +0000</pubDate>
      
      <guid>/questions/9189/can-i-use-subnets-or-hosts-file-for-manual-subnet-member-resolution/</guid>
      <description>Can I use subnets or hosts file for manual subnet member resolution?  0 Situation: we have a host with a dynamic ip, e.g today 8.8.1.2, tomorrow 8.8.3.200. The subnet is the same 8.8.0.0/16. During the live capture we need to spot (notice) that we have one of the hosts belonging to 8.8.0.0/16 subnet.
Can we specify the subnet in HOSTS or SUBNETS file (in wireshark directory) for manual resolution of it ?</description>
    </item>
    
    <item>
      <title>Can I recover a discarded capture?</title>
      <link>/questions/9194/can-i-recover-a-discarded-capture/</link>
      <pubDate>Fri, 24 Feb 2012 08:48:00 +0000</pubDate>
      
      <guid>/questions/9194/can-i-recover-a-discarded-capture/</guid>
      <description>Can I recover a discarded capture?  0 I was using Wireshark a few hours ago, and started a capture. A couple of hours later, it closed unexpectedly. I was not able to save the capture that I started, but I really need the VOIP call that I recorded earlier. Will I be able to recover it?
capture crash recoveryasked 24 Feb &#39;12, 08:48
ishella
1●1●1●1
accept rate: 0%
 edited 24 Feb &#39;12, 09:29</description>
    </item>
    
    <item>
      <title>Lua: Comparing a boolean value</title>
      <link>/questions/9203/lua-comparing-a-boolean-value/</link>
      <pubDate>Fri, 24 Feb 2012 23:14:00 +0000</pubDate>
      
      <guid>/questions/9203/lua-comparing-a-boolean-value/</guid>
      <description>Lua: Comparing a boolean value  0 I&#39;ve been trying to get a comparison going on my code, but can&#39;t seem to manage the way to do it:
I have this field:
f.bitmap1_b1_10000000 = ProtoField.bool(&amp;quot;f.bitmap1_b1_10000000&amp;quot;,&amp;quot;condition present?&amp;quot;,8,{&amp;quot;Present&amp;quot;,&amp;quot;Not Present&amp;quot;},0x80)I then eventually set it&#39;s value:
local bitmap1_b1_10000000 = data(offset,1) subtree:add(f.bitmap1_b1_10000000,bitmap1_b1_10000000)And the value shows up correctly on the dissector window (I&#39;ve checked, and it works for every one of the 128 fields.. &amp;gt;_&amp;lt;)
Now, onto parsing the rest of the data, I&#39;m trying to conditionally execute my code based upon the boolean fields, but cannot seem to:</description>
    </item>
    
    <item>
      <title>memory leak problem with libwireshark!</title>
      <link>/questions/9204/memory-leak-problem-with-libwireshark/</link>
      <pubDate>Sat, 25 Feb 2012 03:03:00 +0000</pubDate>
      
      <guid>/questions/9204/memory-leak-problem-with-libwireshark/</guid>
      <description>memory leak problem with libwireshark!  0 i am working on a project: capture and dissect the network packets using libwireshark when i execute my code with valgrind.. i found this report
7,024 bytes in 143 blocks are definitely lost in loss record 25 of 41
==21679== at 0x4A05809: malloc (vg_replace_malloc.c:149)
==21679== by 0x32D2E33BFA: g_malloc (in /lib64/libglib-2.0.so.0.1200.3)
==21679== by 0x32D2E45A7E: g_strdup (in /lib64/libglib-2.0.so.0.1200.3)
==21679== by 0x5BD2A2E: add_oid (oids.c:145)
==21679== by 0x5BD2BAA: oid_add_from_string (oids.</description>
    </item>
    
    <item>
      <title>Sequence number are all the same(125) throughout the capture why?</title>
      <link>/questions/9209/sequence-number-are-all-the-same125-throughout-the-capture-why/</link>
      <pubDate>Sat, 25 Feb 2012 16:08:00 +0000</pubDate>
      
      <guid>/questions/9209/sequence-number-are-all-the-same125-throughout-the-capture-why/</guid>
      <description>Sequence number are all the same(125) throughout the capture why?  0 Hi every body For my project (the TCP performance) I dowloaded a file and capture it on the wireshark and now when I look at the captured wireshark all the sequence number are the same throughout the file, they all are seq=125,this is when I have the Acks number all different.I am sure it shouldn&#39;t be like this can you help me and tell me what is wrong?</description>
    </item>
    
    <item>
      <title>why wireshark  don&amp;#x27;t support  Gvsp protocol ???????</title>
      <link>/questions/9224/why-wireshark-dont-support-gvsp-protocol/</link>
      <pubDate>Sun, 26 Feb 2012 12:02:00 +0000</pubDate>
      
      <guid>/questions/9224/why-wireshark-dont-support-gvsp-protocol/</guid>
      <description>why wireshark don&amp;rsquo;t support Gvsp protocol ???????  0 why wireshark can&#39;t catch packets with Gvsp protocol (standard of GigE vision camera)?????
i can only catch packets with GVCP protocol
thank you
gvsp wiresharkasked 26 Feb &#39;12, 12:02
jelladtarek
1●1●1●2
accept rate: 0%
  
One Answer:
  
2Wireshark can &#34;catch&#34; all packets it sees, but Wireshark can only dissect packets for which someone has written a protocol dissector for.</description>
    </item>
    
    <item>
      <title>where can i see the decoding log</title>
      <link>/questions/9226/where-can-i-see-the-decoding-log/</link>
      <pubDate>Sun, 26 Feb 2012 18:21:00 +0000</pubDate>
      
      <guid>/questions/9226/where-can-i-see-the-decoding-log/</guid>
      <description>where can i see the decoding log  0 I download the wireshark source-code and install it on ubuntu. Now i&#39;d like to see the log when decoding such as: RTMPT_DEBUG(&#34;Segment: cdir=%d seq=%d-%d\n&#34;, cdir, seq, seq+remain-1). where can i find the log file? (i&#39;ve enable the macro of DEBUG_RTMPT and compile/re-install). Thanks
logasked 26 Feb &#39;12, 18:21
mumulinp
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>tshark...can I  do the following</title>
      <link>/questions/9227/tsharkcan-i-do-the-following/</link>
      <pubDate>Sun, 26 Feb 2012 18:58:00 +0000</pubDate>
      
      <guid>/questions/9227/tsharkcan-i-do-the-following/</guid>
      <description>tshark&amp;hellip;can I do the following  0 I use tshark to capture a group of packets. I&#39;d like to use tshark a second time to:
1) look at a specific packet number
2) return the bytes in the data field (the actual textual response to an http query) to a file as text.
Can I issue a single tshark command that does both things ??
thanks, wk
link data tshark retrievalasked 26 Feb &#39;12, 18:58</description>
    </item>
    
    <item>
      <title>Winpcap Will Not Install</title>
      <link>/questions/9229/winpcap-will-not-install/</link>
      <pubDate>Sun, 26 Feb 2012 20:56:00 +0000</pubDate>
      
      <guid>/questions/9229/winpcap-will-not-install/</guid>
      <description>Winpcap Will Not Install  0 I downloaded Wireshark and am having trouble getting Winpcap to install with it. The Wireshark installer does not detect any version of Winpcap on my system and I cannot find it in my system, but every time I run the Winpcap installer I get a message that it detects another version of Winpcap an application is running. No applications besides the installer are running. I am using Windows 7.</description>
    </item>
    
    <item>
      <title>How to capture packets when connected via data Card</title>
      <link>/questions/9230/how-to-capture-packets-when-connected-via-data-card/</link>
      <pubDate>Sun, 26 Feb 2012 22:01:00 +0000</pubDate>
      
      <guid>/questions/9230/how-to-capture-packets-when-connected-via-data-card/</guid>
      <description>How to capture packets when connected via data Card  0 Hi All,
I am New to wireshark, and i have window 7 OS and connected to internet via Reliance DATA CARD. But wireshark is not able to capture any packet. Kindly help me how to capture packets when connected via DATA CARD.
Regards, manish
capture packetasked 26 Feb &#39;12, 22:01
manish4990
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>adding new menu item</title>
      <link>/questions/9237/adding-new-menu-item/</link>
      <pubDate>Mon, 27 Feb 2012 02:22:00 +0000</pubDate>
      
      <guid>/questions/9237/adding-new-menu-item/</guid>
      <description>adding new menu item  0 i&#39;m trying to edit the GUI of wireshark to add new menu items to existing menu bar...but the code is huge and i dont know what files it is dependent on ..please kndly help me with which files to be edited
[email protected]gmail.com
menuasked 27 Feb &#39;12, 02:22
sangmeshp
36●7●8●11
accept rate: 0%
  
One Answer:
  
1It very much depends on which branch you&#39;re working with.</description>
    </item>
    
    <item>
      <title>Intrusion attempts when using WireShark</title>
      <link>/questions/9238/intrusion-attempts-when-using-wireshark/</link>
      <pubDate>Mon, 27 Feb 2012 02:37:00 +0000</pubDate>
      
      <guid>/questions/9238/intrusion-attempts-when-using-wireshark/</guid>
      <description>Intrusion attempts when using WireShark  0 I recently tried WireShark for some days. Later, my antivirus suite (Symantec) reported three blocked intrusion attempts into my system (Windows 7) on exactly those three consecutive days I used the software. They were categorized as &#34;Web Attack: Exploit Kit Variant 2&#34; and all came from some St. Petersburg IP (31.184.192.8). I didn&#39;t install any other new software during those days (apart wrom the WinPCap installed during WireShark setup).</description>
    </item>
    
    <item>
      <title>Data which has been sent over TCP&amp;#92;IP has been recognized by wireshark as &amp;quot;IPA&amp;quot; Protocol</title>
      <link>/questions/9240/data-which-has-been-sent-over-tcpip-has-been-recognized-by-wireshark-as-ipa-protocol/</link>
      <pubDate>Mon, 27 Feb 2012 03:25:00 +0000</pubDate>
      
      <guid>/questions/9240/data-which-has-been-sent-over-tcpip-has-been-recognized-by-wireshark-as-ipa-protocol/</guid>
      <description>Data which has been sent over TCP\IP has been recognized by wireshark as &amp;ldquo;IPA&amp;rdquo; Protocol  0 Hey
I was trying to send some data in TCP\IP protocol, and Wireshark has defined it as IPA protocol. The data was in there, but also some kind of unknown info at the start of the monitored data, data which I don&#39;t know and didn&#39;t try to send...
did anybody heard about this phenomenon ?</description>
    </item>
    
    <item>
      <title>megaco H.248 decoding only partially (1.6.5)</title>
      <link>/questions/9263/megaco-h248-decoding-only-partially-165/</link>
      <pubDate>Mon, 27 Feb 2012 14:13:00 +0000</pubDate>
      
      <guid>/questions/9263/megaco-h248-decoding-only-partially-165/</guid>
      <description>megaco H.248 decoding only partially (1.6.5)  0 Trying to decode h.248 megaco packets, only getting a partial decode of the packet. majority of the packet is shown as additional text and can only be viewed in binary. is there a fix for this?
h.248 megaco mediaasked 27 Feb &#39;12, 14:13
ddd
1●1●1●1
accept rate: 0%
Could you please add an example packet file to see what you are referring to?</description>
    </item>
    
    <item>
      <title>decrypting ssl using tshark while only seeing one side of the conversation</title>
      <link>/questions/9264/decrypting-ssl-using-tshark-while-only-seeing-one-side-of-the-conversation/</link>
      <pubDate>Mon, 27 Feb 2012 23:49:00 +0000</pubDate>
      
      <guid>/questions/9264/decrypting-ssl-using-tshark-while-only-seeing-one-side-of-the-conversation/</guid>
      <description>decrypting ssl using tshark while only seeing one side of the conversation  0 Hello, Been bashing my brain trying to find a solution to decrypting ssl traffic using tshark when I only have access to one side of the conversation. The traffic I see is asymmetric so I will never see the response from the ssl handshake leaving my network as it leaves out of another network pipe. Would it be possible to sniff the traffic having the private/pub keys or would I require full visibility into the TCP session?</description>
    </item>
    
    <item>
      <title>Using Network Tap between router and modem; All ARP packets?</title>
      <link>/questions/9265/using-network-tap-between-router-and-modem-all-arp-packets/</link>
      <pubDate>Tue, 28 Feb 2012 01:08:00 +0000</pubDate>
      
      <guid>/questions/9265/using-network-tap-between-router-and-modem-all-arp-packets/</guid>
      <description>Using Network Tap between router and modem; All ARP packets?  0 Hi,
I installed a TAP between my router and modem so I can get answers when the internet gets slow. My idea was to get all the outgoing traffic from the router mirrored and then capture it with Wireshark. I&#39;ve turned promiscuous mode on but all I&#39;m getting is ARP packets (see screenshot). I&#39;m a novice at networking; any help would be greatly appreciated.</description>
    </item>
    
    <item>
      <title>What can cause a crash when opening a pcap file on Windows 7?</title>
      <link>/questions/9266/what-can-cause-a-crash-when-opening-a-pcap-file-on-windows-7/</link>
      <pubDate>Tue, 28 Feb 2012 01:26:00 +0000</pubDate>
      
      <guid>/questions/9266/what-can-cause-a-crash-when-opening-a-pcap-file-on-windows-7/</guid>
      <description>What can cause a crash when opening a pcap file on Windows 7?  0 I run Wireshark on Windows 7 and try to open a pcap file (captured on Windows XP), but Wireshark crashes when I try to open the file. What could be the problem?
crash windows7 pcapasked 28 Feb &#39;12, 01:26
Nic
14●5●5●6
accept rate: 0%
 edited 28 Feb &#39;12, 09:09 
multipleinte...
1.3k●15●23●40</description>
    </item>
    
    <item>
      <title>tshark capturing packets over interface aliases</title>
      <link>/questions/9272/tshark-capturing-packets-over-interface-aliases/</link>
      <pubDate>Tue, 28 Feb 2012 11:24:00 +0000</pubDate>
      
      <guid>/questions/9272/tshark-capturing-packets-over-interface-aliases/</guid>
      <description>tshark capturing packets over interface aliases  0 Hello,
I am running tshark version 1.4.3 &amp;amp; I am running linux 2.6-18 kernel. I have two ethernet ports eth0 &amp;amp; eth1 on the box. Assuming I create three IP aliases based on the interface &#34;eth0&#34; namely &#34;eth0:0&#34;, &#34;eth0:1&#34;, &#34;eth0:2&#34;. The IP address for the interfaces &amp;amp; aliases are as below:
eth0 192.168.10.10/255.255.0.0 eth0:0 172.27.0.10/255.255.255.0 eth0:1 172.27.0.11/255.255.255.0
I am running a ping to eth0 from another host on the same subnet as eth0 &amp;amp; when I run tshark as below:</description>
    </item>
    
    <item>
      <title>TMPDIR ignored by Wireshark when running as unpriviledged user</title>
      <link>/questions/9276/tmpdir-ignored-by-wireshark-when-running-as-unpriviledged-user/</link>
      <pubDate>Wed, 29 Feb 2012 03:37:00 +0000</pubDate>
      
      <guid>/questions/9276/tmpdir-ignored-by-wireshark-when-running-as-unpriviledged-user/</guid>
      <description>TMPDIR ignored by Wireshark when running as unpriviledged user  0 Hi,
wireshark-1.0.15-1.el5_5.3
RHEL5.6
I have set the dumpcap with below so that all users in the group &#34;testgroup&#34; can run the wireshark and capture (without sudoers)
chgrp testgroup /usr/sbin/dumpcap
chmod 4750 /usr/sbin/dumpcap

Meaning that when I run the dumpcap command manually
as root:
[[email protected] etc]# env |grep TMPDIR
TMPDIR=/data
[[email protected] etc]# /usr/sbin/dumpcap
File: /data/etherXXXXGhhoEl
Packets: 25 Packets dropped: 0</description>
    </item>
    
    <item>
      <title>Using Wireshark In A High Speed Environment</title>
      <link>/questions/9277/using-wireshark-in-a-high-speed-environment/</link>
      <pubDate>Wed, 29 Feb 2012 06:58:00 +0000</pubDate>
      
      <guid>/questions/9277/using-wireshark-in-a-high-speed-environment/</guid>
      <description>Using Wireshark In A High Speed Environment  0 I am trying to measure a high speed telemetry system. It is capable of producing &amp;gt; 1000 frames per second or 1000Hz. I am using wireshark to capture the UDP port where these frames are produced. I have had much trouble getting a reliable measurement. I was wondering if your team has tested wireshark at these rates before? If so, can you tell me what rate wireshark can reliably measure?</description>
    </item>
    
    <item>
      <title>tshark filter from a file</title>
      <link>/questions/9278/tshark-filter-from-a-file/</link>
      <pubDate>Wed, 29 Feb 2012 07:01:00 +0000</pubDate>
      
      <guid>/questions/9278/tshark-filter-from-a-file/</guid>
      <description>tshark filter from a file  1 Hi, I&#39;m using tshark to capture hostnames (http.host), source (ip.src) and destination (ip.dst) IP&#39;s, and the frame time (frame.time). I am capturing only tcp ports 80 and 443 (web traffic). The command I&#39;m using is: tshark tcp port 80 or tcp port 443 -V -R &#34;http.request&#34; -Tfields -e http.host -e ip.src -e ip.dst -e frame.time
Is there a way for me to pass a list of hostnames that I want to capture from a file?</description>
    </item>
    
    <item>
      <title>Lua dissector failing: occasionally returns nil values instead of TCP endpoints for valid packets</title>
      <link>/questions/9281/lua-dissector-failing-occasionally-returns-nil-values-instead-of-tcp-endpoints-for-valid-packets/</link>
      <pubDate>Wed, 29 Feb 2012 08:04:00 +0000</pubDate>
      
      <guid>/questions/9281/lua-dissector-failing-occasionally-returns-nil-values-instead-of-tcp-endpoints-for-valid-packets/</guid>
      <description>Lua dissector failing: occasionally returns nil values instead of TCP endpoints for valid packets  0 Hi all. I have a small dissector, which keeps returning nil values for a normal TCP packets from time to time.
For some reason, even if pinfo.net_src is set, ip_src_f() may return nil. Also, I can&#39;t get how to decode ip_len_f() return, which is userdata, to number.
 do local testdissector = Proto(&amp;quot;Test&amp;quot;, &amp;quot;Test&amp;quot;);  ip_src_f = Field.</description>
    </item>
    
    <item>
      <title>Getting user input for dissection</title>
      <link>/questions/9284/getting-user-input-for-dissection/</link>
      <pubDate>Wed, 29 Feb 2012 19:04:00 +0000</pubDate>
      
      <guid>/questions/9284/getting-user-input-for-dissection/</guid>
      <description>Getting user input for dissection  0 Hi,
In wireshark is there any way I can get input from user at run time and use that information to dissect packet information. The user information will be basically used to assign names to dissected fields.
developmentasked 29 Feb &#39;12, 19:04
ashish_goel
15●12●12●16
accept rate: 0%
  
One Answer:
  
1You may want to look into UAT&#39;s, see epan/uat.</description>
    </item>
    
    <item>
      <title>Can I print colored text in the Lua TextWindow?</title>
      <link>/questions/9289/can-i-print-colored-text-in-the-lua-textwindow/</link>
      <pubDate>Thu, 01 Mar 2012 02:29:00 +0000</pubDate>
      
      <guid>/questions/9289/can-i-print-colored-text-in-the-lua-textwindow/</guid>
      <description>Can I print colored text in the Lua TextWindow?  0 Is it possible to print colored text in the Wireshark Lua TextWindow?
luaasked 01 Mar &#39;12, 02:29
Rijith
1●4●4●6
accept rate: 0%
 edited 01 Mar &#39;12, 10:37 
multipleinte...
1.3k●15●23●40
  
2 Answers:
  
1No.
The TextWindow does not expose any functionality to perform text formatting, nor does it simulate a terminal that would accept escape sequences.</description>
    </item>
    
    <item>
      <title>10gbe huge frames seen in captures</title>
      <link>/questions/9294/10gbe-huge-frames-seen-in-captures/</link>
      <pubDate>Thu, 01 Mar 2012 11:09:00 +0000</pubDate>
      
      <guid>/questions/9294/10gbe-huge-frames-seen-in-captures/</guid>
      <description>10gbe huge frames seen in captures  0 I&#39;m capturing on a linux server using tcpdump
tcpdump -i eth2 -s 1600 -w file.out
When reviewing the file.out in Wireshark I see many frames that are huge (larger than 9K bytes). These ethernet frames aren&#39;t valid on the network. I&#39;m not using jumbo frames either and they are larger than 9K.
Our theory is the huge ethernet frames are not &#34;real&#34; but are the OS transferring to the 10Gbe nic driver.</description>
    </item>
    
    <item>
      <title>I can not see ipv4 and http, I can just see ipv6 and SSDP WHY ?</title>
      <link>/questions/9296/i-can-not-see-ipv4-and-http-i-can-just-see-ipv6-and-ssdp-why/</link>
      <pubDate>Thu, 01 Mar 2012 12:45:00 +0000</pubDate>
      
      <guid>/questions/9296/i-can-not-see-ipv4-and-http-i-can-just-see-ipv6-and-ssdp-why/</guid>
      <description>I can not see ipv4 and http, I can just see ipv6 and SSDP WHY ?  0 Hi ! I have a real huge problem, when I am connected through the wireless of my university, I can just see adresses like this :
1823731 14856.287768 fe80::74b6:2d79:4343:41e1 ff02::c SSDP 208 M-SEARCH * HTTP/1.1
Here is a picture to understand more :
How Can I solve this problem ? Because I want to see the IP ADDRESS connected in the same wireless.</description>
    </item>
    
    <item>
      <title>Where in the source code is the IP Addresses GUI code</title>
      <link>/questions/9299/where-in-the-source-code-is-the-ip-addresses-gui-code/</link>
      <pubDate>Thu, 01 Mar 2012 19:46:00 +0000</pubDate>
      
      <guid>/questions/9299/where-in-the-source-code-is-the-ip-addresses-gui-code/</guid>
      <description>Where in the source code is the IP Addresses GUI code  0 I am looking for the GUI code for the Statistics -&amp;gt; IP Addresses window. Is there a naming convention for windows to GTK source code that I can use to find that window or other files?
ip gui gtk addressesasked 01 Mar &#39;12, 19:46
zewrestler
1●1●1●1
accept rate: 0%
Well, at first it would be good to tell us which branch you&#39;re working with, either one of the 1.</description>
    </item>
    
    <item>
      <title>How to display strings instead of values for custom columns defined</title>
      <link>/questions/9301/how-to-display-strings-instead-of-values-for-custom-columns-defined/</link>
      <pubDate>Thu, 01 Mar 2012 20:37:00 +0000</pubDate>
      
      <guid>/questions/9301/how-to-display-strings-instead-of-values-for-custom-columns-defined/</guid>
      <description>How to display strings instead of values for custom columns defined  0 Hi,
I have defined some custom columns through prefs.c. The columns which I have defined take values from fields registered through my custom dissector. But the problem is that in packet details the value of these fields are displayed as strings(As I have used vals() function in dissector code) but while the same field is used in column the raw value is displayed.</description>
    </item>
    
    <item>
      <title>how to retrieve packet information using wireshark commands</title>
      <link>/questions/9303/how-to-retrieve-packet-information-using-wireshark-commands/</link>
      <pubDate>Thu, 01 Mar 2012 22:41:00 +0000</pubDate>
      
      <guid>/questions/9303/how-to-retrieve-packet-information-using-wireshark-commands/</guid>
      <description>how to retrieve packet information using wireshark commands  0 I have pcap file containing all the packets captured for certain duration.Given a packet type and tag number i have to get all the information of that tagged parameter from the command line.how to do this?
display-filter capture-filter tshark analysis wiresharkasked 01 Mar &#39;12, 22:41
automation
1●2●2●3
accept rate: 0%
 edited 02 Mar &#39;12, 02:08</description>
    </item>
    
    <item>
      <title>wireshark installation commands</title>
      <link>/questions/9304/wireshark-installation-commands/</link>
      <pubDate>Thu, 01 Mar 2012 23:46:00 +0000</pubDate>
      
      <guid>/questions/9304/wireshark-installation-commands/</guid>
      <description>wireshark installation commands  0 I downloaded wireshark-1.6.0.tar.bz2 for LINUX amd 64. Let me know the wireshark installation commands after extracting tar.
commands installationasked 01 Mar &#39;12, 23:46
redranger
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Check out the Developers Guide.
answered 02 Mar &#39;12, 04:08
Jaap ♦
11.7k●16●101
accept rate: 14%
     </description>
    </item>
    
    <item>
      <title>registering hf_register_info array in dissect_XXX function</title>
      <link>/questions/9313/registering-hf_register_info-array-in-dissect_xxx-function/</link>
      <pubDate>Fri, 02 Mar 2012 10:24:00 +0000</pubDate>
      
      <guid>/questions/9313/registering-hf_register_info-array-in-dissect_xxx-function/</guid>
      <description>registering hf_register_info array in dissect_XXX function  0 Hi,
Is it a good practice to register some entries of hf_register_info array from dissect_XXX function instead of proto_register_XXX() function.
Reason being : the value_string structure assigned to some fields(through vals() function) changes based on the data fetched from packet in dissector code. Basically I have a requirement where the same field and with the same value will be assigned different names based on some data part of packet.</description>
    </item>
    
    <item>
      <title>What am I looking at?</title>
      <link>/questions/9316/what-am-i-looking-at/</link>
      <pubDate>Fri, 02 Mar 2012 13:46:00 +0000</pubDate>
      
      <guid>/questions/9316/what-am-i-looking-at/</guid>
      <description>What am I looking at?  0 Trying to learn what I am looking at in wireshark. Clicked statistics and the endpoints after a capture. Under the Ethernet 10, the first node is listed as Dell_70:4b:cf. This confused me as I own nothing I am aware of that was manufactured by Dell. Does this represent equipment? Or something else?
ethernet statistics endpointsasked 02 Mar &#39;12, 13:46
mooneierah
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>4-Bytes Extra between LLC and 802.11 header</title>
      <link>/questions/9317/4-bytes-extra-between-llc-and-80211-header/</link>
      <pubDate>Fri, 02 Mar 2012 14:09:00 +0000</pubDate>
      
      <guid>/questions/9317/4-bytes-extra-between-llc-and-80211-header/</guid>
      <description>4-Bytes Extra between LLC and 802.11 header  0 Hi,
I am analyzing a 802.11n network with various tools using AirPcap Nx cards. In all cases i am seeing 4 extra bytes between LLC-Snap and IEEE-802.11 headers. Most of the tools are failing to recognize traffic properly. wireshark and com-view recognize these 4 extra bytes as LLC header but you can see the Snap header in raw view. Is there any proper header that can be expected in that place.</description>
    </item>
    
    <item>
      <title>Browser User-Agent</title>
      <link>/questions/9321/browser-user-agent/</link>
      <pubDate>Fri, 02 Mar 2012 19:48:00 +0000</pubDate>
      
      <guid>/questions/9321/browser-user-agent/</guid>
      <description>Browser User-Agent  0 Capturing traffic with tcpdump on Linux CentOS 5.7 machine running Apache httpd and analyzing in Wireshark.
IE browser user-agent is somethimes captured fine in both the http log and network traffic captured http get request. And sometimes only in the http log.
However the BlackBerry 7 (9810 Torch) browser &#39;user-agent&#39; string is captured in http log, but is never in the network traffic captured http get request.</description>
    </item>
    
    <item>
      <title>FTP over non-standard TCP ports</title>
      <link>/questions/9323/ftp-over-non-standard-tcp-ports/</link>
      <pubDate>Fri, 02 Mar 2012 23:26:00 +0000</pubDate>
      
      <guid>/questions/9323/ftp-over-non-standard-tcp-ports/</guid>
      <description>FTP over non-standard TCP ports  0 is it possible to build a capture filter to capture FTP traffic using non-standard TCP port 20 or 21?
ftpasked 02 Mar &#39;12, 23:26
wsitu
1●1●1●1
accept rate: 0%
  
One Answer:
  
0If you are using Active FTP, you can use the alternative TCP ports for the command and the data channel to build a capture filter. If you use 10021 for the command channel and 10020 for the data channel, you can use the capture filter &#34;</description>
    </item>
    
    <item>
      <title>How do I use Wireshark to uncover a Citrix problem?</title>
      <link>/questions/9330/how-do-i-use-wireshark-to-uncover-a-citrix-problem/</link>
      <pubDate>Sat, 03 Mar 2012 08:59:00 +0000</pubDate>
      
      <guid>/questions/9330/how-do-i-use-wireshark-to-uncover-a-citrix-problem/</guid>
      <description>How do I use Wireshark to uncover a Citrix problem?  0 We have this small application that goes out to a web server and it pulls down a report (about 57K on average) which works fine on a standalone workstation. The whole process is a couple of seconds long.
Put that application on a Citrix server and you&#39;re waiting just over 2 minutes. And you don&#39;t even need to do it through citrix.</description>
    </item>
    
    <item>
      <title>Wireshark Capture Interfaces not showing up properly</title>
      <link>/questions/9331/wireshark-capture-interfaces-not-showing-up-properly/</link>
      <pubDate>Sat, 03 Mar 2012 10:13:00 +0000</pubDate>
      
      <guid>/questions/9331/wireshark-capture-interfaces-not-showing-up-properly/</guid>
      <description>Wireshark Capture Interfaces not showing up properly  0 I installed Wireshark 1.6.5 to do packet captures on my home network for my LAN Security class and under the capture interface window my adapters are not listed properly. I see my Ethernet adapter show up but not the wireless. It shows up as &#34;Microsoft&#34; instead of &#34;Atheros AR9285&#34;. I need to be able to see the wireless packets flowing through the network to do my assignment.</description>
    </item>
    
    <item>
      <title>Segmentation Fault while using Wireshark 1.6.5 with PIPE</title>
      <link>/questions/9333/segmentation-fault-while-using-wireshark-165-with-pipe/</link>
      <pubDate>Sat, 03 Mar 2012 12:30:00 +0000</pubDate>
      
      <guid>/questions/9333/segmentation-fault-while-using-wireshark-165-with-pipe/</guid>
      <description>Segmentation Fault while using Wireshark 1.6.5 with PIPE  0 I am using Wireshark 1.6.5 in Ubuntu and here is my capture setting:
I start Wireshark from the command line as: ./wireshark -k -i /tmp/pipe
After starting Wireshark I dump the contents of a capture file (in libpcap format) into the pipe on which Wireshark listens.
Wireshark displays the packets here but at the end it throws segmentation fault? I have used older version of Wireshark in similar fashion and it worked perfectly fine.</description>
    </item>
    
    <item>
      <title>Decoding ANSI standard protocols</title>
      <link>/questions/9336/decoding-ansi-standard-protocols/</link>
      <pubDate>Sat, 03 Mar 2012 20:30:00 +0000</pubDate>
      
      <guid>/questions/9336/decoding-ansi-standard-protocols/</guid>
      <description>Decoding ANSI standard protocols  0 I am using Wireshark version 1.6.5 to decode captured RANAP and SCCP packets over M3UA with ANSI configuration point codes. I could observe that only 2 bytes are being considered for point code decoding. Moreover the order of subsystem number and point code seems to be the other way when compared with the ANSI SCCP standard (T1.112.3). This problem is observed only for connectionless SCCP messages like UDT and XUDT.</description>
    </item>
    
    <item>
      <title>WLAN capturing</title>
      <link>/questions/9337/wlan-capturing/</link>
      <pubDate>Sat, 03 Mar 2012 21:43:00 +0000</pubDate>
      
      <guid>/questions/9337/wlan-capturing/</guid>
      <description>WLAN capturing  0 Hello
I&#39;m not a computer nor a network specialist, but I can fly Airbuses :). We are running a small privat house LAN with two WLAN access points, one of them is them modem. I have system administrator rights. Even after changing the password, after a few days somebody is again in our WLAN, we suspect with a iPhone. We would like to see what traffic is going trough our Access Point.</description>
    </item>
    
    <item>
      <title>Track dropped packetes</title>
      <link>/questions/9338/track-dropped-packetes/</link>
      <pubDate>Sat, 03 Mar 2012 22:31:00 +0000</pubDate>
      
      <guid>/questions/9338/track-dropped-packetes/</guid>
      <description>Track dropped packetes  0 I have two pcaps taken one at the ingress of the device and the other at the egress. The device seems to be dropping the udp packets. The packets have an identification of all 0s Is there a way I can track what packets are missing in the packets at the output.
identification packetasked 03 Mar &#39;12, 22:31
Packet
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Command line to retrieve packet info</title>
      <link>/questions/9346/command-line-to-retrieve-packet-info/</link>
      <pubDate>Sun, 04 Mar 2012 21:00:00 +0000</pubDate>
      
      <guid>/questions/9346/command-line-to-retrieve-packet-info/</guid>
      <description>Command line to retrieve packet info  0 Hi, thanks for the reply, tried several commands from the manual but could not get what i wanted. Supose I am given a MAC address, a packet type of 8(a beacon frame) and an element ID of 0, then I want to display the SSID parameter set(a tagged parameter) information of a beacon frame from that MAC address. Can someone give any relevant examples.</description>
    </item>
    
    <item>
      <title>Intel Pro Wireless 3945ABG</title>
      <link>/questions/9349/intel-pro-wireless-3945abg/</link>
      <pubDate>Mon, 05 Mar 2012 01:22:00 +0000</pubDate>
      
      <guid>/questions/9349/intel-pro-wireless-3945abg/</guid>
      <description>Intel Pro Wireless 3945ABG  0 After installing Wireshark on Windows Vista (unfortunatelly) :) I have a big problem. I use Intel Wireless Card. But it does not show in a list of interfaces for capturing data. I thought it is a problem of putting card into promiscous mode. Tried to change drivers etc. Googled a lot and some people have problems with putting it in the mode some do not.</description>
    </item>
    
    <item>
      <title>[closed] Wireshark Lua - Rich text formatting without third-party packages</title>
      <link>/questions/9352/wireshark-lua-rich-text-formatting-without-third-party-packages/</link>
      <pubDate>Mon, 05 Mar 2012 01:31:00 +0000</pubDate>
      
      <guid>/questions/9352/wireshark-lua-rich-text-formatting-without-third-party-packages/</guid>
      <description>[closed] Wireshark Lua - Rich text formatting without third-party packages  0 HI,
Currently I have a Wireshark Lua Text Window with data similar to Follow Tcp Stream Window. I need to show request in one color and response in another color. I understood that it is not possible to show in Wireshark Lua Text window since it doesn&#39;t support. So I want to know whether it can be achieved by saving to a file without the use of any THIRD PARTY PACKAGES.</description>
    </item>
    
    <item>
      <title>Wireshark Lua - Wireshark Version problem</title>
      <link>/questions/9353/wireshark-lua-wireshark-version-problem/</link>
      <pubDate>Mon, 05 Mar 2012 01:36:00 +0000</pubDate>
      
      <guid>/questions/9353/wireshark-lua-wireshark-version-problem/</guid>
      <description>Wireshark Lua - Wireshark Version problem  0 Hi, I have developed a post dissector using Wireshark Lua. Its is running without any problem on Development release 1.7.0 or higher, but it doesn&#39;t run properly on versions less than 1.7.0. Why is it so ?
Is there any dependencies on the versions for wireshark lua support?
luaasked 05 Mar &#39;12, 01:36
Rijith
1●4●4●6
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How can follow the tcp stream in batch?</title>
      <link>/questions/9354/how-can-follow-the-tcp-stream-in-batch/</link>
      <pubDate>Mon, 05 Mar 2012 02:16:00 +0000</pubDate>
      
      <guid>/questions/9354/how-can-follow-the-tcp-stream-in-batch/</guid>
      <description>How can follow the tcp stream in batch?  0 Hello,
Wireshark is an excellent network tool, and I like the follow tcp/udp etc stream way that convert the raw data into a readable format, but how can I use it in a batch mode? You can image that if I want to watch thousands of data, had I click the items with mouse one by one?
Any tips?
regards.</description>
    </item>
    
    <item>
      <title>Ts3 record/analysis</title>
      <link>/questions/9361/ts3-recordanalysis/</link>
      <pubDate>Mon, 05 Mar 2012 09:07:00 +0000</pubDate>
      
      <guid>/questions/9361/ts3-recordanalysis/</guid>
      <description>Ts3 record/analysis  0 1Is it possible To record TS3 conversations like other VoIP services?
telephonyasked 05 Mar &#39;12, 09:07
Rune
1●1●2●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>monitoring the WAN port of a router</title>
      <link>/questions/9364/monitoring-the-wan-port-of-a-router/</link>
      <pubDate>Mon, 05 Mar 2012 10:21:00 +0000</pubDate>
      
      <guid>/questions/9364/monitoring-the-wan-port-of-a-router/</guid>
      <description>monitoring the WAN port of a router  0 I have the following setup: a router connected to a few wireless and wired computer a hub:
connected to the modem on port1connected to the WAN port of the router on port2connected to a PC running wireshark on port3.I was expecting to see the traffic of my internet connection on the PC running wireshark, but instead all I see is a bunch of DHCP protocol packets.</description>
    </item>
    
    <item>
      <title>count simultaneous RTP sessions from live capture/saved pcap with Lua</title>
      <link>/questions/9368/count-simultaneous-rtp-sessions-from-live-capturesaved-pcap-with-lua/</link>
      <pubDate>Mon, 05 Mar 2012 12:46:00 +0000</pubDate>
      
      <guid>/questions/9368/count-simultaneous-rtp-sessions-from-live-capturesaved-pcap-with-lua/</guid>
      <description>count simultaneous RTP sessions from live capture/saved pcap with Lua  0 Currently, I&#39;m looking for a Lua script that would count active RTP sessions on a live tshark capture or on saved pcap files.
Right now, the only way I found is to count RTP packets per second with tshark -qz io,stat and divide by 50 to get actual number of VOIP conversations. However, this requires way too many steps to be realistic on a regular basis other than to troubleshoot specific time ranges.</description>
    </item>
    
    <item>
      <title>HELP - Laptop stolen and I want to &amp;quot;search for it&amp;quot; using Wireshark and wireless signal</title>
      <link>/questions/9369/help-laptop-stolen-and-i-want-to-search-for-it-using-wireshark-and-wireless-signal/</link>
      <pubDate>Mon, 05 Mar 2012 14:21:00 +0000</pubDate>
      
      <guid>/questions/9369/help-laptop-stolen-and-i-want-to-search-for-it-using-wireshark-and-wireless-signal/</guid>
      <description>HELP - Laptop stolen and I want to &amp;ldquo;search for it&amp;rdquo; using Wireshark and wireless signal  0 I had the misfortune of having my wife&#39;s laptop stolen from my home.
The laptop was set to always use a particular SSID (&#34;c1&#34;) and also a particular Channel (I need to check but beleive it was set to &#34;11&#34;)
I also know the laptop name is &#34;TOSHIBA-PC&#34;.
Using Wireshark and my PCAP usb device, is it possible to search for a signal coming from the laptop?</description>
    </item>
    
    <item>
      <title>Is there a way to get Wireshark to provide SNMP dissection on non-standard ports (e.g. 163, 165, etc.) rather than the standard ports of 161 and 162</title>
      <link>/questions/9371/is-there-a-way-to-get-wireshark-to-provide-snmp-dissection-on-non-standard-ports-eg-163-165-etc-rather-than-the-standard-ports-of-161-and-162/</link>
      <pubDate>Mon, 05 Mar 2012 16:25:00 +0000</pubDate>
      
      <guid>/questions/9371/is-there-a-way-to-get-wireshark-to-provide-snmp-dissection-on-non-standard-ports-eg-163-165-etc-rather-than-the-standard-ports-of-161-and-162/</guid>
      <description>Is there a way to get Wireshark to provide SNMP dissection on non-standard ports (e.g. 163, 165, etc.) rather than the standard ports of 161 and 162  0 I have Wireshark performing SNMP dissection of custom MIB. This works great on the standards SNMP ports of 161 and 162. However, when I setup an SNMP agent to use non-standard ports like 163 and 164, multiple agents on a single IP, Wireshark no longer provides SNMP decode.</description>
    </item>
    
    <item>
      <title>dumpcap doesn&amp;#x27;t work</title>
      <link>/questions/9373/dumpcap-doesnt-work/</link>
      <pubDate>Mon, 05 Mar 2012 17:15:00 +0000</pubDate>
      
      <guid>/questions/9373/dumpcap-doesnt-work/</guid>
      <description>dumpcap doesn&amp;rsquo;t work  0 hi! i&#39;m korean. i wonder you can understand what i&#39;m saying.. i&#39;m installing the wireshark program based on window 7. when i&#39;m staring this program, windows error message is showed by dumpcap error. i don&#39;t know this problem. please answer my question to resolve it.. thank you
dumpcap errorasked 05 Mar &#39;12, 17:15
Young
1●1●1●1
accept rate: 0%
What does the error message say? It might indicate why dumpcap failed; we&#39;d have to know exactly what happened in order to help.</description>
    </item>
    
    <item>
      <title>SIP Notify Message Body is gzip&amp;#x27;ed</title>
      <link>/questions/9374/sip-notify-message-body-is-gziped/</link>
      <pubDate>Mon, 05 Mar 2012 17:37:00 +0000</pubDate>
      
      <guid>/questions/9374/sip-notify-message-body-is-gziped/</guid>
      <description>SIP Notify Message Body is gzip&amp;rsquo;ed  0 Hi,
I am looking to find out if Wireshark can decode the Body of a SIP Notify when the body is gzipped by the sender. I can see the SIP header, but just not the body.
Thanks.
body gzip sipasked 05 Mar &#39;12, 17:37
decodeme
1●1●1●1
accept rate: 0%
  
One Answer:
  
0The HTTP dissector includes code to handle gzipped content encodings of the body, but not gzipped transfer encodings.</description>
    </item>
    
    <item>
      <title>Unable to capture SOAP response</title>
      <link>/questions/9375/unable-to-capture-soap-response/</link>
      <pubDate>Mon, 05 Mar 2012 18:25:00 +0000</pubDate>
      
      <guid>/questions/9375/unable-to-capture-soap-response/</guid>
      <description>Unable to capture SOAP response  0 Hi everyone, I am having an issue trying to capture the incoming message from my webservice.
The situation is as follows:
1) We have a portable device used for sending and receiving SOAP messages from our webservice. We are trying to capture the messages sent back and forth.
2) We set up a test configuration where the device will connect via wifi to a laptop (set to Access Point mode using Connectify) that is connected to the Internet using an Ethernet cable.</description>
    </item>
    
    <item>
      <title>wireshark customisation</title>
      <link>/questions/9385/wireshark-customisation/</link>
      <pubDate>Mon, 05 Mar 2012 22:19:00 +0000</pubDate>
      
      <guid>/questions/9385/wireshark-customisation/</guid>
      <description>wireshark customisation  0 hello guys,
I&#39;m trying to customize wireshark for my team needs ,i have created a new menu-item in main menu-bar. the menu contains options to add pcap files and filter.then on click it will generate an output file for specific values in packets. so please kindly guide me how to proceed for filter integration ,and what files are to be made changes to have filter connected to this menu item</description>
    </item>
    
    <item>
      <title>Data is not getting flushed</title>
      <link>/questions/9388/data-is-not-getting-flushed/</link>
      <pubDate>Tue, 06 Mar 2012 01:11:00 +0000</pubDate>
      
      <guid>/questions/9388/data-is-not-getting-flushed/</guid>
      <description>Data is not getting flushed  0 Hello I have added a .CSV parser and a dissector. It is observed that if my .CSV file is opened as the first file in wireshark, then packet dump is proper as expected.
But if an other file is opened first and then my .CSV file is opened then packet dump is of the previous data. This is not the behaviour with other sample files.</description>
    </item>
    
    <item>
      <title>statistics summary generator</title>
      <link>/questions/9391/statistics-summary-generator/</link>
      <pubDate>Tue, 06 Mar 2012 04:21:00 +0000</pubDate>
      
      <guid>/questions/9391/statistics-summary-generator/</guid>
      <description>statistics summary generator  0 hello experts,
i&#39;m trying to generate an option in wireshark for creating statistics summary as a text file.please kindly help what should i do to parse this data.where can i find this code in source ..
regards, [email protected]gmail.com
menu statistics summaryasked 06 Mar &#39;12, 04:21
sangmeshp
36●7●8●11
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>mac behind a router</title>
      <link>/questions/9393/mac-behind-a-router/</link>
      <pubDate>Tue, 06 Mar 2012 06:37:00 +0000</pubDate>
      
      <guid>/questions/9393/mac-behind-a-router/</guid>
      <description>mac behind a router  0 I have data captured from the WAN port of my router. is it possible to filter the data based on the MAC addresses of the computers using the router? is that information present in the packet? obviously, all the packets now have the MAC of the router itself.
router monitoring mac-addressasked 06 Mar &#39;12, 06:37
gamba
6●3●3●5
accept rate: 0%
  
3 Answers:</description>
    </item>
    
    <item>
      <title>Can Replay be disabled in Wireshark?</title>
      <link>/questions/9401/can-replay-be-disabled-in-wireshark/</link>
      <pubDate>Tue, 06 Mar 2012 10:41:00 +0000</pubDate>
      
      <guid>/questions/9401/can-replay-be-disabled-in-wireshark/</guid>
      <description>Can Replay be disabled in Wireshark?  0 Can Replay be disabled in Wireshark? I need a version of Wireshark or I need to modify Wireshark so that packets can not be replayed. Is this possible? If so, how?
replayasked 06 Mar &#39;12, 10:41
Balthazar2007
1●1●1●1
accept rate: 0%
  
3 Answers:
  
1Assuming you mean you want Wireshark to make a capture file non-replayable by a third party, I don&#39;t think there&#39;s a feature for that.</description>
    </item>
    
    <item>
      <title>Identify Bandwidth Hog</title>
      <link>/questions/9405/identify-bandwidth-hog/</link>
      <pubDate>Tue, 06 Mar 2012 12:07:00 +0000</pubDate>
      
      <guid>/questions/9405/identify-bandwidth-hog/</guid>
      <description>Identify Bandwidth Hog  0 Can I use Wireshark to idenitify a bandwidth hog, i.e. a user/pc that is perhaps watching videos or on peer to peer file sharing networks and thus using high bandwidth?
Thank you
high bandwidth bandwidthutilizationasked 06 Mar &#39;12, 12:07
IT Tropolis
6●2●2●4
accept rate: 0%
  
One Answer:
  
2 Yes you can...
... by using &#34;Statistics -&amp;gt; Endpoints&#34;. Click on the IP tab and then sort on the column you find most interesting.</description>
    </item>
    
    <item>
      <title>old cable drops</title>
      <link>/questions/9409/old-cable-drops/</link>
      <pubDate>Tue, 06 Mar 2012 14:28:00 +0000</pubDate>
      
      <guid>/questions/9409/old-cable-drops/</guid>
      <description>old cable drops  0 I am a desktop support analyst with no formal training. part of the area I support has several computers that are EXTREEMLY slow. I have brought this to the attention of the approprate staff a few times, they continue to blame it on the desktops... I knew it isn&#39;t the issue because they were dual processor machines with at least 2 g ram... but i went along.</description>
    </item>
    
    <item>
      <title>dissector frame buffer is not getting refreshed</title>
      <link>/questions/9413/dissector-frame-buffer-is-not-getting-refreshed/</link>
      <pubDate>Tue, 06 Mar 2012 22:02:00 +0000</pubDate>
      
      <guid>/questions/9413/dissector-frame-buffer-is-not-getting-refreshed/</guid>
      <description>dissector frame buffer is not getting refreshed  0 Hello I have added a .CSV parser and a dissector. It is observed that if my .CSV file is opened as the first file in wireshark, tvb buffer contents is proper.
But if an other file is opened first and then my .CSV file is opened then packet dump is of the previous data. This is not the behaviour with other sample files.</description>
    </item>
    
    <item>
      <title>address of pcap file</title>
      <link>/questions/9414/address-of-pcap-file/</link>
      <pubDate>Tue, 06 Mar 2012 23:21:00 +0000</pubDate>
      
      <guid>/questions/9414/address-of-pcap-file/</guid>
      <description>address of pcap file  0 hello experts,
i wanted to know what part of source code contains the file pointer which contains path to pcap file when u try to open a pcap file in wireshark . like for example: when i click file/open file_dlg_open_cb is called then you browse the menu for pcap file now i wanted to know what part of code stores this address or path to pcap file.</description>
    </item>
    
    <item>
      <title>How to troubleshoot wireshark when it doesn&amp;#x27;t want to capture?</title>
      <link>/questions/9415/how-to-troubleshoot-wireshark-when-it-doesnt-want-to-capture/</link>
      <pubDate>Wed, 07 Mar 2012 00:15:00 +0000</pubDate>
      
      <guid>/questions/9415/how-to-troubleshoot-wireshark-when-it-doesnt-want-to-capture/</guid>
      <description>How to troubleshoot wireshark when it doesn&amp;rsquo;t want to capture?  0 I&#39;m trying to capture RTP traffic from one of my IP phones. When I run wireshark on the server connected to a span port I can easily see the RTP traffic. Unfortunately when I use capture filter like this:
host 192.168.9.4
where the given IP is the address of my IP phone it doesn&#39;t display RTP traffic at all (just some ARP traffic).</description>
    </item>
    
    <item>
      <title>Cannot monitor other users uni-cast traffic  on WLAN</title>
      <link>/questions/9420/cannot-monitor-other-users-uni-cast-traffic-on-wlan/</link>
      <pubDate>Wed, 07 Mar 2012 13:38:00 +0000</pubDate>
      
      <guid>/questions/9420/cannot-monitor-other-users-uni-cast-traffic-on-wlan/</guid>
      <description>Cannot monitor other users uni-cast traffic on WLAN  0 I am able to monitor all of my own traffic, but I cannot monitor other users&#39; DNS queries and unicast packets. I can only see multicast and ICMP traffic of other users. I have also tried to switch promiscuous mode off, but to no avail.
wireless wlan capture-setupThis question is marked &#34;community wiki&#34;.asked 07 Mar &#39;12, 13:38
Mian82
-1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>need info on Wireshark data</title>
      <link>/questions/9422/need-info-on-wireshark-data/</link>
      <pubDate>Wed, 07 Mar 2012 14:01:00 +0000</pubDate>
      
      <guid>/questions/9422/need-info-on-wireshark-data/</guid>
      <description>need info on Wireshark data  0 I have created a monitor interface on an atheros card (AR922X) which is part of a separate laptop with ath9k driver. I am using wireshark to monitor the traffic in the channel through this monitor interface. I have another laptop connected to an AP in the same channel and the laptop is downloading a huge file(say a linux ISO). I get QoS data packets of size greater than 1500.</description>
    </item>
    
    <item>
      <title>libpcap format - packet header - incl_len / orig_len</title>
      <link>/questions/9424/libpcap-format-packet-header-incl_len-orig_len/</link>
      <pubDate>Wed, 07 Mar 2012 21:17:00 +0000</pubDate>
      
      <guid>/questions/9424/libpcap-format-packet-header-incl_len-orig_len/</guid>
      <description>libpcap format - packet header - incl_len / orig_len  0 The libpcap packet header structure has 2 length fields:
typedef struct pcaprec_hdr_s { guint32 ts_sec; /* timestamp seconds */ guint32 ts_usec; /* timestamp microseconds */ guint32 incl_len; /* number of octets of packet saved in file */ guint32 orig_len; /* actual length of packet */ } pcaprec_hdr_t;incl_len: the number of bytes of packet data actually captured and saved in the file.</description>
    </item>
    
    <item>
      <title>making pcap-ng hadoop friendly</title>
      <link>/questions/9428/making-pcap-ng-hadoop-friendly/</link>
      <pubDate>Thu, 08 Mar 2012 04:47:00 +0000</pubDate>
      
      <guid>/questions/9428/making-pcap-ng-hadoop-friendly/</guid>
      <description>making pcap-ng hadoop friendly  0 Are there any plans to make the pcap-ng format more friendly to hadoop and mapreduce. Meaning being able to &#34;split&#34; a single file and stay on cut. I believe this can be accomplished with pcap-ng and just wondering if was in the plans.
pcapng hadoopasked 08 Mar &#39;12, 04:47
jdbethge
1●1●1●2
accept rate: 0%
 edited 08 Mar &#39;12, 14:32 
Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>How to print a list of tshark interfaces to a txt file?</title>
      <link>/questions/9429/how-to-print-a-list-of-tshark-interfaces-to-a-txt-file/</link>
      <pubDate>Thu, 08 Mar 2012 05:26:00 +0000</pubDate>
      
      <guid>/questions/9429/how-to-print-a-list-of-tshark-interfaces-to-a-txt-file/</guid>
      <description>How to print a list of tshark interfaces to a txt file?  0 Looks simple but is annoying...
dumpcap.exe -D &amp;gt;&amp;gt; interfaces.txtor:
tshark.exe -D &amp;gt;&amp;gt; interfaces.txtBecause interface numbers can be different among different machines, i want to use this command to sort out the Local Ethernet Cable connection and use it as a variable in my tshark script after sorting this out first... but i can&#39;t seem to print a list to a txt file?</description>
    </item>
    
    <item>
      <title>Link own libpcap.a</title>
      <link>/questions/9439/link-own-libpcapa/</link>
      <pubDate>Thu, 08 Mar 2012 12:08:00 +0000</pubDate>
      
      <guid>/questions/9439/link-own-libpcapa/</guid>
      <description>Link own libpcap.a  0 Hey, I downloaded the wireshark source code and I was wondering if it&#39;s possible to link my own libpcap.a?
link library libpcapasked 08 Mar &#39;12, 12:08
Freaky
1●1●1●1
accept rate: 0%
  
One Answer:
  
1You&#39;d have to install your own libpcap.a (or libpcap shared library) and:
if you&#39;re building Wireshark with autotools, so that you&#39;re running the ./configure script before you run make, you need to run the configure script with the --with-pcap=directory command-line option, where directory is the install directory for your libpcap (&#34;</description>
    </item>
    
    <item>
      <title>How to use tshark to print certain number of bytes in a packet at a specific offset</title>
      <link>/questions/9441/how-to-use-tshark-to-print-certain-number-of-bytes-in-a-packet-at-a-specific-offset/</link>
      <pubDate>Thu, 08 Mar 2012 12:13:00 +0000</pubDate>
      
      <guid>/questions/9441/how-to-use-tshark-to-print-certain-number-of-bytes-in-a-packet-at-a-specific-offset/</guid>
      <description>How to use tshark to print certain number of bytes in a packet at a specific offset  0 I have a pcap file and want to print x number of bytes starting at offset i in the packet. I can specify a filter which will match the frames based on the content of those bytes, for instance, frame[i:x] == b2f5... , but I cannot figure out how to actually print those bytes.</description>
    </item>
    
    <item>
      <title>Which Interface to Monitor?</title>
      <link>/questions/9447/which-interface-to-monitor/</link>
      <pubDate>Thu, 08 Mar 2012 18:32:00 +0000</pubDate>
      
      <guid>/questions/9447/which-interface-to-monitor/</guid>
      <description>Which Interface to Monitor?  0 Sorry, I&#39;m a newbie to WireShark. After install on a workstation on my LAN, I see WireShark selects the local interface to monitor by default, but provides option to monitor a remote interface. This LAN has only one /24 subnet with an internet router (AdTran). Two wireless devices are also connected on LAN side of router in bridge mode.
To accurately capture all traffic in/out from LAN/WAN, I think I need to monitor the LAN interface of my AdTran router, ya, i.</description>
    </item>
    
    <item>
      <title>about the capacity of wireshark, so many packets drop</title>
      <link>/questions/9448/about-the-capacity-of-wireshark-so-many-packets-drop/</link>
      <pubDate>Thu, 08 Mar 2012 19:16:00 +0000</pubDate>
      
      <guid>/questions/9448/about-the-capacity-of-wireshark-so-many-packets-drop/</guid>
      <description>about the capacity of wireshark, so many packets drop  0 I have met some problem with wireshark. my situation is i have a good IBM server,the server&#39;s configuration is below：
CPU: 4 core, xeon 7500, 2.0GHz disk: 10000RPM 600GBytes RAM: 32GBytes Ethernet ports: 1 Gigabit the version of wireshark: 1.6 64bits the OS : Windows 2008 R2the flow of my data is 250Mbps more or less, but when i collect the date for one hour, the size of the date collected is just only 95GBytes.</description>
    </item>
    
    <item>
      <title>How can WinPcap be installed unatttended and silently on Windows</title>
      <link>/questions/9452/how-can-winpcap-be-installed-unatttended-and-silently-on-windows/</link>
      <pubDate>Thu, 08 Mar 2012 23:56:00 +0000</pubDate>
      
      <guid>/questions/9452/how-can-winpcap-be-installed-unatttended-and-silently-on-windows/</guid>
      <description>How can WinPcap be installed unatttended and silently on Windows  0 We want to pre-stage WireShark on our servers. Doing this we have it all prepared when we need to do some tracing. Also we can delegate the right to trace/troubleshoot without having people being permanently administrators on the Window servers.
We would like to be able to distribute WinPcap and WireShark independently and maintain/upgrade them indecently.
Out of the box WinPcap has no option to install unattended and silently – is this deliberately or?</description>
    </item>
    
    <item>
      <title>How to identify traffic blocked by ACLs</title>
      <link>/questions/9453/how-to-identify-traffic-blocked-by-acls/</link>
      <pubDate>Fri, 09 Mar 2012 04:17:00 +0000</pubDate>
      
      <guid>/questions/9453/how-to-identify-traffic-blocked-by-acls/</guid>
      <description>How to identify traffic blocked by ACLs  0 Is there a method for determining if a particular entry(s) in a network trace are being blocked by ACLs? If so, can you help me identify where in the trace it would show the packet being rejected/blocked?
For example, we&#39;ve written ACLs to prevent traffic on certain ports directed toward a particular host. In the network trace I see the client and host entries on the defined ports.</description>
    </item>
    
    <item>
      <title>radiotap header format data rate alignment</title>
      <link>/questions/9461/radiotap-header-format-data-rate-alignment/</link>
      <pubDate>Fri, 09 Mar 2012 13:14:00 +0000</pubDate>
      
      <guid>/questions/9461/radiotap-header-format-data-rate-alignment/</guid>
      <description>radiotap header format data rate alignment  0 hi, I have attached a trace from wireshark. Can someone tell me from where the wireshark is decoding the rate to be 26 MBps. Clicking on the rate points to an invalid location. I am unable to find the reason behind why this is happening. Why is Also, Shouldnt data rate be a 2-byte value? The reason why I am asking is wireshark generally shows rate as (2*rate because unit is in 500KBps) in the bit representation(as seen in the second image).</description>
    </item>
    
    <item>
      <title>802.11r, 802.11k, 802.11u Supported fully? or Partially?</title>
      <link>/questions/9462/80211r-80211k-80211u-supported-fully-or-partially/</link>
      <pubDate>Fri, 09 Mar 2012 13:18:00 +0000</pubDate>
      
      <guid>/questions/9462/80211r-80211k-80211u-supported-fully-or-partially/</guid>
      <description>802.11r, 802.11k, 802.11u Supported fully? or Partially?  0 Hi all,
I have searched through the forums and the help sections and seen reference to these three 802.11 amendments but I haven&#39;t found definitive statements of support.
Does wireshark + AriPcap decode:
802.11u, 802.11r, 802.11k headers/fields ?
Thanks Joey
decode 802.11u 802.11k 802.11r 802.11asked 09 Mar &#39;12, 13:18
jpaddencl
1●1●1●2
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>I cant remember the password for my wireshark</title>
      <link>/questions/9463/i-cant-remember-the-password-for-my-wireshark/</link>
      <pubDate>Fri, 09 Mar 2012 17:34:00 +0000</pubDate>
      
      <guid>/questions/9463/i-cant-remember-the-password-for-my-wireshark/</guid>
      <description>I cant remember the password for my wireshark  0 My customer do not remember the password for wireshark access, does any one knows how to reset it?
passwordasked 09 Mar &#39;12, 17:34
fmoralesgt
1●1●1●2
accept rate: 0%
  
One Answer:
  
4Wireshark, as shipped by the Wireshark developers, does not require a password to access it.
Either somebody provided your customer with a version of Wireshark modified to require a password, somebody configured their system to require a password to run Wireshark, or the password is actually a password to get sufficient privileges to do traffic capture with Wireshark.</description>
    </item>
    
    <item>
      <title>No Username Password Record</title>
      <link>/questions/9465/no-username-password-record/</link>
      <pubDate>Sat, 10 Mar 2012 11:43:00 +0000</pubDate>
      
      <guid>/questions/9465/no-username-password-record/</guid>
      <description>No Username Password Record  0 I recently downloaded Wireshark to monitor my son&#39;s internet activity, which has been suspicious lately. He has his Facebook Password saved to the computer, but not his e-mail&#39;s (I have a feeling they might be the same). Wireshark is recording packets, but when I log into his Facebook, all the Packet information is in Wireshark except for Username and Password when I go to &#34;</description>
    </item>
    
    <item>
      <title>How can I view encapsulation type?</title>
      <link>/questions/9468/how-can-i-view-encapsulation-type/</link>
      <pubDate>Sun, 11 Mar 2012 05:17:00 +0000</pubDate>
      
      <guid>/questions/9468/how-can-i-view-encapsulation-type/</guid>
      <description>How can I view encapsulation type?  0 I have a Wireshark capture file, and I&#39;d like to see what encapsulations it has in one of its packages. How can I do this?
encapsulationasked 11 Mar &#39;12, 05:17
Skorzeny8814
1●1●1●1
accept rate: 0%
 edited 11 Mar &#39;12, 12:29 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
1I&#39;m not sure what you mean by &#34;encapsulations it has in one of its packages&#34;</description>
    </item>
    
    <item>
      <title>Packet length shown in Wireshark</title>
      <link>/questions/9469/packet-length-shown-in-wireshark/</link>
      <pubDate>Sun, 11 Mar 2012 06:15:00 +0000</pubDate>
      
      <guid>/questions/9469/packet-length-shown-in-wireshark/</guid>
      <description>Packet length shown in Wireshark  0 Does the packet length shown in Wireshark in the main column under Length include the header length?
I am working out bottleneck bandwidth and need to know.
Thank you.
Steve.
header length wiresharkasked 11 Mar &#39;12, 06:15
sjb89
6●1●1●3
accept rate: 0%
  
One Answer:
  
1 The packet length (aka the field named frame.len) is the size of the frame as seen &#34;</description>
    </item>
    
    <item>
      <title>Driver for wireshark</title>
      <link>/questions/9475/driver-for-wireshark/</link>
      <pubDate>Sun, 11 Mar 2012 15:29:00 +0000</pubDate>
      
      <guid>/questions/9475/driver-for-wireshark/</guid>
      <description>Driver for wireshark  0 I can&#39;t wireshark because I need driver for it. Where I an find it to download. Thank you
wiresharkasked 11 Mar &#39;12, 15:29
polman
1●1●1●1
accept rate: 0%
Please provide more info (with your question).
What OS are you using ?
(11 Mar &#39;12, 15:31) Bill Meier ♦♦   </description>
    </item>
    
    <item>
      <title>cisco erspan id as a filter method?</title>
      <link>/questions/9478/cisco-erspan-id-as-a-filter-method/</link>
      <pubDate>Sun, 11 Mar 2012 19:11:00 +0000</pubDate>
      
      <guid>/questions/9478/cisco-erspan-id-as-a-filter-method/</guid>
      <description>cisco erspan id as a filter method?  0 Hi, I have a single cisco 6500 running two erspan sessions with different erspan id&#39;s. I have a server running wireshark as the destination of the erspans. I would like to split the capture into two separate captures based on the erspan id. Is this possible? I cannot seem to find a way to display an erspan id in the gui.</description>
    </item>
    
    <item>
      <title>Wireshark 1.6.5 fails to install on Mac OS X 10.7.3</title>
      <link>/questions/9479/wireshark-165-fails-to-install-on-mac-os-x-1073/</link>
      <pubDate>Sun, 11 Mar 2012 19:22:00 +0000</pubDate>
      
      <guid>/questions/9479/wireshark-165-fails-to-install-on-mac-os-x-1073/</guid>
      <description>Wireshark 1.6.5 fails to install on Mac OS X 10.7.3  0 I&#39;m having trouble installing the 1.6.5 Wireshark on a MacBook Pro running OS X 10.7.3. The installer runs but very little is really done. No /Applications/Wireshark created, no /Library/Wireshark created. It did create the /Library/StartupItems/ChmodBPF and did create the BPF devices in /dev. The following are all the messages (note the errors) that appeared in the console during the install process (by double-clicking on the &#34;</description>
    </item>
    
    <item>
      <title>Batch export to csv of .pcap files</title>
      <link>/questions/9484/batch-export-to-csv-of-pcap-files/</link>
      <pubDate>Mon, 12 Mar 2012 02:05:00 +0000</pubDate>
      
      <guid>/questions/9484/batch-export-to-csv-of-pcap-files/</guid>
      <description>Batch export to csv of .pcap files  0 Hi all,
I have been attempting to use TShark in a batch method to process a significant number of pcap files to .csv files.
I am aware that this can be done using the &#34;-T fields&#34; approach, or just as &#34;-T text&#34;. However, the output I want is just as it would be presented in wireshark, i.e. an overall source, not just an IP or Ethernet address, etc.</description>
    </item>
    
    <item>
      <title>How can I get the Tcp Request part and response part from a TCP Stream Index?</title>
      <link>/questions/9485/how-can-i-get-the-tcp-request-part-and-response-part-from-a-tcp-stream-index/</link>
      <pubDate>Mon, 12 Mar 2012 03:38:00 +0000</pubDate>
      
      <guid>/questions/9485/how-can-i-get-the-tcp-request-part-and-response-part-from-a-tcp-stream-index/</guid>
      <description>How can I get the Tcp Request part and response part from a TCP Stream Index?  0 HI , I have an entire payload of a particular tcp stream say tcp.stream eq 2 using Wireshark lua script. But in this , the request and response are not differentiated. I want to differentiate the request part and response part. How can i do it.
Thanks in advance for you rhelp</description>
    </item>
    
    <item>
      <title>Command line option</title>
      <link>/questions/9486/command-line-option/</link>
      <pubDate>Mon, 12 Mar 2012 04:15:00 +0000</pubDate>
      
      <guid>/questions/9486/command-line-option/</guid>
      <description>Command line option  0 I am running the following command line to capture large files but I would like the logs to be created in my log folder under the Wireshark folder
dumpcap -b files:10000 -b filesize:10000 -w logs.pcap
I have tried all sorts of option to make it create the file in that folder but nothing seems to work
command-lineThis question is marked &#34;community wiki&#34;.asked 12 Mar &#39;12, 04:15</description>
    </item>
    
    <item>
      <title>Wireshark build on Visual studio 2010</title>
      <link>/questions/9493/wireshark-build-on-visual-studio-2010/</link>
      <pubDate>Mon, 12 Mar 2012 10:01:00 +0000</pubDate>
      
      <guid>/questions/9493/wireshark-build-on-visual-studio-2010/</guid>
      <description>Wireshark build on Visual studio 2010  0 I am getting compile time error when I am trying to compile the Windows source build in the Visual studio 2010.
Error 1 error U1065: invalid option &#39;-&#39; C:\Wireshark\NMAKE wireshark Error 2 error MSB3073: The command &#34;nmake -f Makefile.nmake distclean&#34; exited with code 2. C:\Program Files\MSBuild\Microsoft.Cpp\v4.0\Microsoft.MakeFile.Targets 33 6 wireshark
2010 visual-studioasked 12 Mar &#39;12, 10:01
Krishna
1●1●1●1
accept rate: 0%
This type of question is better asked on the [email protected]wireshark.</description>
    </item>
    
    <item>
      <title>Dissector extra info</title>
      <link>/questions/9501/dissector-extra-info/</link>
      <pubDate>Mon, 12 Mar 2012 16:46:00 +0000</pubDate>
      
      <guid>/questions/9501/dissector-extra-info/</guid>
      <description>Dissector extra info  0 Hello,
I&#39;m trying to build a protocol dissector.
The dissector works just fine, however the problem is the body is encrypted. I already reversed everything and i can retrieve the session key from within the dissector (its hackish but w/e).
However as the key changes, and we can not store extra info somewhere to link a key to a pcap file.
So my question is, is there a way to: A) Store the key somewhere related to pcap file to load the key in the dissector for each pcap file B) Save modified packets to pcap file (its a hell, already tried, but perhaps i looked wrong)</description>
    </item>
    
    <item>
      <title>802.11n slow file transfer speeds</title>
      <link>/questions/9504/80211n-slow-file-transfer-speeds/</link>
      <pubDate>Mon, 12 Mar 2012 22:30:00 +0000</pubDate>
      
      <guid>/questions/9504/80211n-slow-file-transfer-speeds/</guid>
      <description>802.11n slow file transfer speeds  0 So hoping to get some input on this, a solution even. I&#39;m experiencing slow file transfer speeds (56Mb/s) from my wireless laptop to a wired (Gigabit) server. I&#39;ve tried on another computer and it&#39;s faster (80Mb/s) but still not where I&#39;d expect with 802.11N.
Setup: - WNDR3700 Netgear router, dualband, 2.4GHz is b/g (using WEP), 5GHz is n (using WPA AES). Different SSIDs for the two bands.</description>
    </item>
    
    <item>
      <title>multiple ip addresses</title>
      <link>/questions/9505/multiple-ip-addresses/</link>
      <pubDate>Tue, 13 Mar 2012 00:18:00 +0000</pubDate>
      
      <guid>/questions/9505/multiple-ip-addresses/</guid>
      <description>multiple ip addresses  0 I tried to capture traffic to a site with multiple ip addresses, and got very few results. Obviously, if I state a pcap filter like &#34;host facebook.com&#34;, this creates a filter with one ip address returned from dns at the time I start the capture. How should I capture that traffic correctly?
multiple-ipasked 13 Mar &#39;12, 00:18
Wurzelsepp
1●2●2●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Is it possible to set the coloring of a packet from a dissector?</title>
      <link>/questions/9511/is-it-possible-to-set-the-coloring-of-a-packet-from-a-dissector/</link>
      <pubDate>Tue, 13 Mar 2012 09:32:00 +0000</pubDate>
      
      <guid>/questions/9511/is-it-possible-to-set-the-coloring-of-a-packet-from-a-dissector/</guid>
      <description>Is it possible to set the coloring of a packet from a dissector?  1 Is there any way to set the packet colors through dissector (or any other file), but through code only?
coloring dissector packet-displayasked 13 Mar &#39;12, 09:32
ashish_goel
15●12●12●16
accept rate: 0%
 edited 13 Mar &#39;12, 09:57 
multipleinte...
1.3k●15●23●40
  
One Answer:
  
2Packet coloring rules are defined by the user via the View -&amp;gt; Coloring Rules dialog.</description>
    </item>
    
    <item>
      <title>RadioTap header in wireless packet capture</title>
      <link>/questions/9518/radiotap-header-in-wireless-packet-capture/</link>
      <pubDate>Tue, 13 Mar 2012 11:44:00 +0000</pubDate>
      
      <guid>/questions/9518/radiotap-header-in-wireless-packet-capture/</guid>
      <description>RadioTap header in wireless packet capture  0 Hi folks;
I bought the AirPcap device and am sniffing away. I am curious about some of the fields in the Radiotap header. Can someone explain the SSI Signal/Noise values in the packet capture. Are those fields/values inserted by AirPcap when upon packet capture ?? or are they already in the received packet ??
I have found surprising little online documentation providing an explanation of the fields.</description>
    </item>
    
    <item>
      <title>Extracting SOAP XML Payload</title>
      <link>/questions/9521/extracting-soap-xml-payload/</link>
      <pubDate>Tue, 13 Mar 2012 12:49:00 +0000</pubDate>
      
      <guid>/questions/9521/extracting-soap-xml-payload/</guid>
      <description>Extracting SOAP XML Payload  0 I am referring to a thread already answered last summer - http://ask.wireshark.org/questions/4639/extracting-soap-xml-payload?sort=votes&amp;amp;page=1
I got this script working reading off of a pcap with:
tshark -r &amp;quot;/tmp/test.pcap&amp;quot; &amp;quot;tcp and data&amp;quot; -X lua_script:/tmp/luaListener.luaNow, I am having a problem running the Lua script on a live capture (here&#39;s a sample pcap). In the Lua file, I have tap set to xml and field set to xml. Here is my command prompt:</description>
    </item>
    
    <item>
      <title>Http response</title>
      <link>/questions/9523/http-response/</link>
      <pubDate>Tue, 13 Mar 2012 12:52:00 +0000</pubDate>
      
      <guid>/questions/9523/http-response/</guid>
      <description>Http response  0 I see some HTTP response that are occasionally being decoded by wireshark as TCP segments, as opposed to HTTP Response OK&#39;s. The total response spans approx 300 packets (450KBytes). Would such a large response hinder Wiresharks ability to decode/reassemble properly ?? If so, what is the limit ?
If not, what is the likely reason for such behavior ??
thanks, wk
decode httpasked 13 Mar &#39;12, 12:52</description>
    </item>
    
    <item>
      <title>How can Wireshark decrypt SSL on same client PC with browser?</title>
      <link>/questions/9535/how-can-wireshark-decrypt-ssl-on-same-client-pc-with-browser/</link>
      <pubDate>Wed, 14 Mar 2012 07:11:00 +0000</pubDate>
      
      <guid>/questions/9535/how-can-wireshark-decrypt-ssl-on-same-client-pc-with-browser/</guid>
      <description>How can Wireshark decrypt SSL on same client PC with browser?  0 Is there a way to pair up my instance of Wireshark with the Browser running on my PC so that I can decrypt my own SSL sessions? I&#39;m not trying to feed other captures to my instance of Wireshark. It just seems that on the same PC that is able to conduct the SSL session there should be a way for Wireshark to be able to have access to the decrypted payloads.</description>
    </item>
    
    <item>
      <title>how to calculate ACK</title>
      <link>/questions/9537/how-to-calculate-ack/</link>
      <pubDate>Wed, 14 Mar 2012 07:42:00 +0000</pubDate>
      
      <guid>/questions/9537/how-to-calculate-ack/</guid>
      <description>how to calculate ACK  0 Given the 3 frames how is the acknowledgment receipt of 2700 calculated?
Transmission Control Protocol, Src Port: http (80), Dst Port: 52545 (52545), Seq: 1, Ack: 973, Len: 1460
Transmission Control Protocol, Src Port: http (80), Dst Port: 52545 (52545), Seq: 1461, Ack: 973, Len: 1239
Transmission Control Protocol, Src Port: 52545 (52545 ), Dst Port: http(80), Seq: 973, Ack: 2700, Len: 0
ack calculationasked 14 Mar &#39;12, 07:42</description>
    </item>
    
    <item>
      <title>WireShark and Jumbograms</title>
      <link>/questions/9542/wireshark-and-jumbograms/</link>
      <pubDate>Wed, 14 Mar 2012 10:56:00 +0000</pubDate>
      
      <guid>/questions/9542/wireshark-and-jumbograms/</guid>
      <description>WireShark and Jumbograms  1 Dear *,
I&#39;m currently investigating the effects of IPv6 Jumbograms on a network (IP packets of up to 4GiB). However, Wireshark does not seem to support packet sizes over IPv4&#39;s maximum, 64k.
I&#39;ve already edited and recompiled libpcap and wireshark from source to allow a higher snaplen, but it seems that whenever I send a packet being &amp;gt; 64k, the received data loops and restarts at 0.</description>
    </item>
    
    <item>
      <title>how to disable dissectors in tshark?</title>
      <link>/questions/9544/how-to-disable-dissectors-in-tshark/</link>
      <pubDate>Wed, 14 Mar 2012 13:12:00 +0000</pubDate>
      
      <guid>/questions/9544/how-to-disable-dissectors-in-tshark/</guid>
      <description>how to disable dissectors in tshark?  0 This works:
tshark -r $pcap -R &#39;tcp.seq==1 and tcp.flags.push==1&#39; -T fields -e ip.src -e tcp.srcport -e ip.dst -e tcp.dstport -e data ...but when the payload is recognized as SSL or HTTP, the data does not get output. I want to turn off ALL decoding.
This is the parameter that I wish exists:
-d tcp.port==any,nodecode ...or something like that.
Any ideas?
disable tshark dissectorsasked 14 Mar &#39;12, 13:12</description>
    </item>
    
    <item>
      <title>Does Wireshark support Modbus/TCP?</title>
      <link>/questions/9547/does-wireshark-support-modbustcp/</link>
      <pubDate>Wed, 14 Mar 2012 19:54:00 +0000</pubDate>
      
      <guid>/questions/9547/does-wireshark-support-modbustcp/</guid>
      <description>Does Wireshark support Modbus/TCP?  0 Can I use Wireshark as a sniffer on Modbus/TCP traffic? Can I use it for simulating either a Modbus/TCP client or a server?
modbusasked 14 Mar &#39;12, 19:54
mshani
1●1●1●1
accept rate: 0%
 edited 14 Mar &#39;12, 22:23 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
2Can I use WireShark as a sniffer on Modbus/TCP traffic?
Wireshark includes, at least in the top of the SVN trunk, a Modbus/TCP dissector:</description>
    </item>
    
    <item>
      <title>how to analyse different http request and response messages</title>
      <link>/questions/9551/how-to-analyse-different-http-request-and-response-messages/</link>
      <pubDate>Thu, 15 Mar 2012 02:23:00 +0000</pubDate>
      
      <guid>/questions/9551/how-to-analyse-different-http-request-and-response-messages/</guid>
      <description>how to analyse different http request and response messages  0 I am analyzing different http request and response messages. I have got three different http request messages and i wana see at which time each of these messages are generated and how much bytes they consume? I can see number of bytes against each http request on clicking at any packet but i need some sort of automatic mechanism through which i am able to know number of bytes against different http request messages and same the case with the http response messages.</description>
    </item>
    
    <item>
      <title>how to recognize skinny message when decrypt ssl vpn</title>
      <link>/questions/9555/how-to-recognize-skinny-message-when-decrypt-ssl-vpn/</link>
      <pubDate>Thu, 15 Mar 2012 06:49:00 +0000</pubDate>
      
      <guid>/questions/9555/how-to-recognize-skinny-message-when-decrypt-ssl-vpn/</guid>
      <description>how to recognize skinny message when decrypt ssl vpn  0 The scenario is that I use openconnect to connect cisco phone to cisco IOS&#39;s sslvpn server.
phone will be registered to the call manager and the call manager communicate with phone using skinny msg.
I already have the private key of the sslvpn server and use it in wireshark.
My wireshark&#39;s version is 1.6.5 My setting is that:
Preferences-&amp;gt;Protocols-&amp;gt;SSL</description>
    </item>
    
    <item>
      <title>Why are packets incorrectly identified as PCLI?</title>
      <link>/questions/9557/why-are-packets-incorrectly-identified-as-pcli/</link>
      <pubDate>Thu, 15 Mar 2012 07:56:00 +0000</pubDate>
      
      <guid>/questions/9557/why-are-packets-incorrectly-identified-as-pcli/</guid>
      <description>Why are packets incorrectly identified as PCLI?  0 While capturing a multicast video feed on port 9000, I noticed Wireshark was identifying the content of the UDP packets as PCLI (Packet Cable Lawful Intercept) containing another IP datagram.
Has anyone seen this issue before?
Disabling the PCLI dissector fixes this.
pcli multicast udpasked 15 Mar &#39;12, 07:56
Manu
4●1●1●3
accept rate: 0%
 edited 15 Mar &#39;12, 08:46</description>
    </item>
    
    <item>
      <title>SSL decrypting</title>
      <link>/questions/9560/ssl-decrypting/</link>
      <pubDate>Thu, 15 Mar 2012 11:16:00 +0000</pubDate>
      
      <guid>/questions/9560/ssl-decrypting/</guid>
      <description>SSL decrypting  0 I am trying to decode/decrypt ssl transactions between my laptop and an EC2 on the Amazon Cloud. We have an ssl cert from Verisign (cert, chain, root). How do I take this info and create a key that Wireshark will use to decrypt the data ?? I look at the SSL log file and it tells me that it can&#39;t load the pem file. Specifically, the ssl log file says:</description>
    </item>
    
    <item>
      <title>Windows 7 ignores TCP MSS</title>
      <link>/questions/9573/windows-7-ignores-tcp-mss/</link>
      <pubDate>Thu, 15 Mar 2012 23:16:00 +0000</pubDate>
      
      <guid>/questions/9573/windows-7-ignores-tcp-mss/</guid>
      <description>Windows 7 ignores TCP MSS  0 Is it possible that Windows 7 ignores TCP MSS? Even if another side announces MSS 256 bytes TCP/IP stack on Windows 7 sends TCP segments with payload &amp;gt; 256 bytes. Please find pcap files and a simple server program for testing this issue by following the link below:
Wireshark logs.
The issue can be reproduced on Windows 7 PC only (32/64 bits), i.e. not on Windows XP/Linux machines.</description>
    </item>
    
    <item>
      <title>Multiport Adapter is not detecting</title>
      <link>/questions/9581/multiport-adapter-is-not-detecting/</link>
      <pubDate>Fri, 16 Mar 2012 05:34:00 +0000</pubDate>
      
      <guid>/questions/9581/multiport-adapter-is-not-detecting/</guid>
      <description>Multiport Adapter is not detecting  0 Multiport Adapter is not detecting
I have intel pro/1000 PT Dual Port network card but its is not detecting by wireshark. I am using winpcap4.1.1.is winpcap4.1.1 support Dual Port network card(like 2 ports in one adapter). I also have created java application using winpcap4.1.1 amd jpcap0.7 to capture network trafic. that application also not detected that lan card
.What should I need to do?</description>
    </item>
    
    <item>
      <title>Ethernet address display filter on 802.11 frames</title>
      <link>/questions/9585/ethernet-address-display-filter-on-80211-frames/</link>
      <pubDate>Fri, 16 Mar 2012 07:17:00 +0000</pubDate>
      
      <guid>/questions/9585/ethernet-address-display-filter-on-80211-frames/</guid>
      <description>Ethernet address display filter on 802.11 frames  0 For example, I want to capture traffic between an AP (00:00:00:11:11:11) and a terminal (00:00:00:22:22:22.) by the AirPCap
I have been able to capture all 802.11 frames by defining capture filter:
(ether src host 00:00:00:11:11:11 and ether dst host 00:00:00:22:22:22) or (ether dst host 00:00:00:11:11:11 and ether src host 00:00:00:22:22:22)
However, when I try to capture all frames without this capture filter and later on apply &#34;</description>
    </item>
    
    <item>
      <title>windows 8 problem</title>
      <link>/questions/9589/windows-8-problem/</link>
      <pubDate>Fri, 16 Mar 2012 18:13:00 +0000</pubDate>
      
      <guid>/questions/9589/windows-8-problem/</guid>
      <description>windows 8 problem  0 hey.
i have win 8 developer ver on my computer.
i tried to install wireshrk but the winpcap driver isnt supported by win 8...
dose anyone running win 8 ver of wireshark or atleaset some fitting drivers??
thanks.
windows8asked 16 Mar &#39;12, 18:13
Helldad
1●1●1●1
accept rate: 0%
  
One Answer:
  
1This has been asked before. Please take a look at this thread.</description>
    </item>
    
    <item>
      <title>copy/paste?</title>
      <link>/questions/9592/copypaste/</link>
      <pubDate>Fri, 16 Mar 2012 22:49:00 +0000</pubDate>
      
      <guid>/questions/9592/copypaste/</guid>
      <description>copy/paste?  0 Hi,
once I have spotted the relevant data in a capture (actually Referer lines in http GET requests), how could I get them into a file? When I click http, and then the line, it gets highlighted in the hexdump. Idid not find a way how I could copy that line and paste it into a text document
copy-pasteasked 16 Mar &#39;12, 22:49
Wurzelsepp
1●2●2●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Decryption of Zigbee packets, works in Win32 version, not in Linux version</title>
      <link>/questions/9597/decryption-of-zigbee-packets-works-in-win32-version-not-in-linux-version/</link>
      <pubDate>Fri, 16 Mar 2012 23:56:00 +0000</pubDate>
      
      <guid>/questions/9597/decryption-of-zigbee-packets-works-in-win32-version-not-in-linux-version/</guid>
      <description>Decryption of Zigbee packets, works in Win32 version, not in Linux version  0 I am having difficulty decrypting Zigbee packets on my 1.6.5 installation on Gentoo Linux, installed from an ebuild. However, the same version installed on a win32 (WinXP) system auto decrypts and finds the key correctly (same .pcap file). I have tried manally entering the key into the Linux release and it still does not decrypt the encrypted packets.</description>
    </item>
    
    <item>
      <title>follow UDP stream with time stamp?</title>
      <link>/questions/9605/follow-udp-stream-with-time-stamp/</link>
      <pubDate>Sat, 17 Mar 2012 12:56:00 +0000</pubDate>
      
      <guid>/questions/9605/follow-udp-stream-with-time-stamp/</guid>
      <description>follow UDP stream with time stamp?  0 Hello How can I get a timestamp at the beginning of the sentences if I have carried out the “follow UDP stream” command.”
$RZHTD,A,16.5,R,R,T,,,,1.7,,,,,,,,,71 $RZFPI,000,00,8,2,071 $RZRSA,15.9,A,,V4C $RZROT,0.1,A,900A
This data is from one IP address, I would like to mix it again with data from another IP address, therefore I need a timestamp. Is this possible? And How?? Thanks in advance, Regards, P Hoornstrijk.</description>
    </item>
    
    <item>
      <title>Wireshark on Solaris 10 live capture suspends after some time</title>
      <link>/questions/9608/wireshark-on-solaris-10-live-capture-suspends-after-some-time/</link>
      <pubDate>Sat, 17 Mar 2012 19:34:00 +0000</pubDate>
      
      <guid>/questions/9608/wireshark-on-solaris-10-live-capture-suspends-after-some-time/</guid>
      <description>Wireshark on Solaris 10 live capture suspends after some time  0 I&#39;m finding that when running a live capture on my rge0 interface, after some time (eg 30 minutes) the display of new packets stops updating. The UI does not hang, I can interact with it and select packets etc. It&#39;s just that no new packets are displayed and the total packet capture count remains fixed.
On each live capture session, this behavior occurs at different times &amp;amp; total packet counts.</description>
    </item>
    
    <item>
      <title>Wireshark won&amp;#x27;t start on OSX Lion</title>
      <link>/questions/9617/wireshark-wont-start-on-osx-lion/</link>
      <pubDate>Mon, 19 Mar 2012 13:24:00 +0000</pubDate>
      
      <guid>/questions/9617/wireshark-wont-start-on-osx-lion/</guid>
      <description>Wireshark won&amp;rsquo;t start on OSX Lion  0 I am running OSX Lion and both Wireshark 1.6.5 and Wireshark 1.7 and neither of them will open.
The install looks like it works, and when I launch wireshark from the /Applications folder, the icon appears and a window pops up saying that it may take a few minutes for the window to appear. I click the button to continue, the immediately wireshark closes.</description>
    </item>
    
    <item>
      <title>reconstruct/create a stream file from pcap</title>
      <link>/questions/9618/reconstructcreate-a-stream-file-from-pcap/</link>
      <pubDate>Mon, 19 Mar 2012 15:38:00 +0000</pubDate>
      
      <guid>/questions/9618/reconstructcreate-a-stream-file-from-pcap/</guid>
      <description>reconstruct/create a stream file from pcap  0 i have a pcap and filter it to a TCP stream index and source ip. i want to build a file from the packets (reconstruct) streamed data.
is there away to do this with Wireshark? or do i need to create my own method for this?
data streamasked 19 Mar &#39;12, 15:38
auldh
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Response In/To in a icmp packets</title>
      <link>/questions/9624/response-into-in-a-icmp-packets/</link>
      <pubDate>Tue, 20 Mar 2012 01:42:00 +0000</pubDate>
      
      <guid>/questions/9624/response-into-in-a-icmp-packets/</guid>
      <description>Response In/To in a icmp packets  0 Hello,
I used wireshark to resolv a problem! pings goes lost sometimes on my network...
I&#39;ve see following packets on wireshark and I need to known is this normal or not! For one ping the are four packet, two with request and two with reply ( I means so because the four packets are same sequence number ):  393 53.000650 192.168.141.100 10.</description>
    </item>
    
    <item>
      <title>Record message with wireshark</title>
      <link>/questions/9626/record-message-with-wireshark/</link>
      <pubDate>Tue, 20 Mar 2012 03:11:00 +0000</pubDate>
      
      <guid>/questions/9626/record-message-with-wireshark/</guid>
      <description>Record message with wireshark  0 I want to use wireshark to record the messages. But i don&#39;t need all of them. I want to add some rules, for example:
interface: eth1 Network ip: 127.0.0.1 CBTC Base port: 61500 filename: my_record.pcap
Is this possible?
recording wiresharkasked 20 Mar &#39;12, 03:11
Alice
1●3●3●3
accept rate: 0%
  
One Answer:
  
1Sure. You&#39;re talking about capturing network packets while using a capture filter.</description>
    </item>
    
    <item>
      <title>can tcpdump work in windows?</title>
      <link>/questions/9627/can-tcpdump-work-in-windows/</link>
      <pubDate>Tue, 20 Mar 2012 03:34:00 +0000</pubDate>
      
      <guid>/questions/9627/can-tcpdump-work-in-windows/</guid>
      <description>can tcpdump work in windows?  0 Does TCPDUMP work in windows?
windows tcpdumpasked 20 Mar &#39;12, 03:34
Alice
1●3●3●3
accept rate: 0%
  
2 Answers:
  
3Tcpdump on Windows is called WinDump.
And apparently there is also at least one commercially available version of tcpdump for Windows. See the MicroOLAP TCPDUMP for Windows 3.9.8 page for more details.
Wireshark also provides other command-line packet capture tools that you might find useful as well, such as dumpcap, as Jasper already mentioned, and tshark.</description>
    </item>
    
    <item>
      <title>Want to monitor https traffic.</title>
      <link>/questions/9633/want-to-monitor-https-traffic/</link>
      <pubDate>Tue, 20 Mar 2012 04:42:00 +0000</pubDate>
      
      <guid>/questions/9633/want-to-monitor-https-traffic/</guid>
      <description>Want to monitor https traffic.  0 hi,
i would like to monitor the traffic on my client , to whome i have asked to open the fireall for port 55443 .
the client is saying that it has opened the firewall port 55443, but my application is still failing . how can i check from the client side that my requests are comming to its server from my location from a forworded port 55443.</description>
    </item>
    
    <item>
      <title>Can SMB v1 vs. SMB v2 be detected in the header?</title>
      <link>/questions/9647/can-smb-v1-vs-smb-v2-be-detected-in-the-header/</link>
      <pubDate>Tue, 20 Mar 2012 10:13:00 +0000</pubDate>
      
      <guid>/questions/9647/can-smb-v1-vs-smb-v2-be-detected-in-the-header/</guid>
      <description>Can SMB v1 vs. SMB v2 be detected in the header?  0 Can one determine which version of SMB is being used by looking at the SMB header?
smbasked 20 Mar &#39;12, 10:13
Janis Bishop
1●2●2●2
accept rate: 0%
  
One Answer:
  
3Yes.
According to Microsoft&#39;s [MS-CIFS] specification, the first 4 bytes of the header for an SMB message &#34;MUST contain the 4-byte literal string &#39;\xFF&#39;, &#39;S&#39;, &#39;M&#39;, &#39;B&#39;, with the letters represented by their respective ASCII values in the order shown.</description>
    </item>
    
    <item>
      <title>RST&#43;ACK That is NOT Response to SYN on Closed Port</title>
      <link>/questions/9659/rstack-that-is-not-response-to-syn-on-closed-port/</link>
      <pubDate>Tue, 20 Mar 2012 13:31:00 +0000</pubDate>
      
      <guid>/questions/9659/rstack-that-is-not-response-to-syn-on-closed-port/</guid>
      <description>RST+ACK That is NOT Response to SYN on Closed Port  0 I&#39;m seeing RST+ACK received at a PC, often, and it is not a response to a SYN sent to a closed port.
In one case, the PC opened a TCP session, sent HTTP 1.1 traffic in a TLS session, got a response, ACKed the response. The connection sat idle for 130 seconds and then the host sent RST+ACK.</description>
    </item>
    
    <item>
      <title>How to exclude LAN Subnets from capturing in WireShark</title>
      <link>/questions/9677/how-to-exclude-lan-subnets-from-capturing-in-wireshark/</link>
      <pubDate>Wed, 21 Mar 2012 07:48:00 +0000</pubDate>
      
      <guid>/questions/9677/how-to-exclude-lan-subnets-from-capturing-in-wireshark/</guid>
      <description>How to exclude LAN Subnets from capturing in WireShark  0 How to exclude LAN Subnets from capturing in WireShark
exclude lan subnetsasked 21 Mar &#39;12, 07:48
fbaig
1●3●3●4
accept rate: 0%
  
One Answer:
  
1You just have to apply a capture filter: e.g. if you don&#39;t want to capture 192.168.1.0/24 --&amp;gt; not host 192.168.1
just leave out the last octet(s)
or you can directly do not net 192.</description>
    </item>
    
    <item>
      <title>Trigger an executable file once wireshark finds a &amp;quot;keyword&amp;quot; on live capture</title>
      <link>/questions/9682/trigger-an-executable-file-once-wireshark-finds-a-keyword-on-live-capture/</link>
      <pubDate>Wed, 21 Mar 2012 09:11:00 +0000</pubDate>
      
      <guid>/questions/9682/trigger-an-executable-file-once-wireshark-finds-a-keyword-on-live-capture/</guid>
      <description>Trigger an executable file once wireshark finds a &amp;ldquo;keyword&amp;rdquo; on live capture  0 Hi,
I&#39;m setting up a trap for hackers on my server, by putting an attractive file named: &#34;source-code.zip&#34; (as an example) so only hackers can see. (If the hacker is using a PHP shell trap or something)
Once the hacker trys to open or access the &#34;source-code.zip&#34; file, I need wireshark to trigger an executable file that will shut down the network card on my server to prevent any other theft, just in case.</description>
    </item>
    
    <item>
      <title>Can not decrypt packets sent to/from my iPad</title>
      <link>/questions/9684/can-not-decrypt-packets-sent-tofrom-my-ipad/</link>
      <pubDate>Wed, 21 Mar 2012 11:56:00 +0000</pubDate>
      
      <guid>/questions/9684/can-not-decrypt-packets-sent-tofrom-my-ipad/</guid>
      <description>Can not decrypt packets sent to/from my iPad  0 I have noticed a strange thing, I cannot decrypt packets that are sent to/from my iPad. But I can decrypt packets that are sent from/to my other laptop. Both are (of course) connected to the same WPA2 (AES) encrypted network.
I have captured the four-way handshake with both my iPad and laptop, but I can only decrypt the packets going to my laptop when setting the wpa-psk pre-shared key in Edit-&amp;gt;Preferences-&amp;gt;Protocols-&amp;gt;IEEE 802.</description>
    </item>
    
    <item>
      <title>about capturing of Fibre Channel packets</title>
      <link>/questions/9687/about-capturing-of-fibre-channel-packets/</link>
      <pubDate>Thu, 22 Mar 2012 00:32:00 +0000</pubDate>
      
      <guid>/questions/9687/about-capturing-of-fibre-channel-packets/</guid>
      <description>about capturing of Fibre Channel packets  0 As I know about wireshark,It can capture the Ethernet packets by Winpcap。 But now，I want to capture the FC packets, how can I do?
And I have find the source code file : &#34;packet-fc.c&#34;, what about it?
ps: sorry, My english is poor ,thank you all the time.
capture fcasked 22 Mar &#39;12, 00:32
taiyangluoyu
0●2●2●4
accept rate: 0%
 edited 22 Mar &#39;12, 01:08</description>
    </item>
    
    <item>
      <title>NMAKE : fatal error U1077: &amp;#x27;sed&amp;#x27; : return code &amp;#x27;0x1&amp;#x27;</title>
      <link>/questions/9692/nmake-fatal-error-u1077-sed-return-code-0x1/</link>
      <pubDate>Thu, 22 Mar 2012 03:39:00 +0000</pubDate>
      
      <guid>/questions/9692/nmake-fatal-error-u1077-sed-return-code-0x1/</guid>
      <description>NMAKE : fatal error U1077: &amp;lsquo;sed&amp;rsquo; : return code &amp;lsquo;0x1&amp;rsquo;  0 When trying to build Wireshark I get NMAKE : fatal error U1077: &#39;sed&#39; : return code &#39;0x1&#39;
Or to be more precise I get :
c:\wireshark&amp;gt;nmake -f Makefile.nmake all
Microsoft (R) Program Maintenance Utility Version 9.00.30729.01 Copyright (C) Microsoft Corporation. All rights reserved.
sed -e s/@[email protected]/1.7.1-Hg on the test patrol-/ -e &amp;quot;s/@[email protected]/#define HAVE_C_ARES 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_MIT_KERBEROS 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBZ 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBPCAP 1/&amp;quot; -e s/@[email protected]/#define HAVE_PCAP_FINDALLDEVS 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_DATALINK_NAME_TO_VAL 1/&amp;quot; -e s/@[email protected]/#define HAVE_PCAP_DATALINK_VAL_TO_NAME 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_DATALINK_VAL_TO_DESCRIPTION 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_REMOTE 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_REMOTE 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_OPEN 1/&amp;quot;-e &amp;quot;s/@[email protected]/#define HAVE_PCAP_OPEN_DEAD 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_LIST_DATALINKS 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_FREE_DATALINKS 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_SET_DATALINK 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_SETSAMPLING 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_BPF_IMAGE 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBWIRESHARKDLL 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBGNUTLS 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBGCRYPT 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LUA 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LUA_5_1 1/&amp;quot; -e&amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_AIRPCAP 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBPORTAUDIO 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBSMI 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_GEOIP 1/&amp;quot; -e s/@[email protected]/#define HAVE_GEOIP_V6 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define INET6 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_NTDDNDIS_H 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define PCAP_NG_DEFAULT 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; &amp;lt; config.</description>
    </item>
    
    <item>
      <title>How to exclude traffic between LAN subnets from capturing in Wireshark</title>
      <link>/questions/9693/how-to-exclude-traffic-between-lan-subnets-from-capturing-in-wireshark/</link>
      <pubDate>Thu, 22 Mar 2012 04:14:00 +0000</pubDate>
      
      <guid>/questions/9693/how-to-exclude-traffic-between-lan-subnets-from-capturing-in-wireshark/</guid>
      <description>How to exclude traffic between LAN subnets from capturing in Wireshark  0 How to exclude traffic between LAN subnets from capturing in Wireshark. We want to capture traffic only between LAN Subnets and subnets residing off the WAN external link and exclude any communication between LAN Subnets
subnets lanasked 22 Mar &#39;12, 04:14
fbaig
1●3●3●4
accept rate: 0%
  
One Answer:
  
1You do a filter which includes your internal networks as source and excludes them as destination and vice versa.</description>
    </item>
    
    <item>
      <title>How can I capture from a BTS</title>
      <link>/questions/9697/how-can-i-capture-from-a-bts/</link>
      <pubDate>Thu, 22 Mar 2012 05:16:00 +0000</pubDate>
      
      <guid>/questions/9697/how-can-i-capture-from-a-bts/</guid>
      <description>How can I capture from a BTS  0 hi all, i am a newbie for this tool, my question is i have BTS physically with me i want to capture the packets where exactly it is routed ? so i don&#39;t know how to start! if anyone can help with this it will be great! thanking you in advance!
capture gsmasked 22 Mar &#39;12, 05:16
anil
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Should an Interface on Laptop running WireShark have an IP Address</title>
      <link>/questions/9699/should-an-interface-on-laptop-running-wireshark-have-an-ip-address/</link>
      <pubDate>Thu, 22 Mar 2012 07:34:00 +0000</pubDate>
      
      <guid>/questions/9699/should-an-interface-on-laptop-running-wireshark-have-an-ip-address/</guid>
      <description>Should an Interface on Laptop running WireShark have an IP Address  0 Just curious to know if I should assign an IP Address to my laptop (running wireshark) interface connected to the SPAN destination port on my cisco swich?
i have noticed that when i don&#39;t assign an address to my laptop&#39;s interface (Wireshark capturing interface) connected to SPAN destination port on my cisco switch, wireshark captures only DNS, DHCP &amp;amp; NBNS packets.</description>
    </item>
    
    <item>
      <title>Voip calls graph for sip protocol (Q931 over SIP)</title>
      <link>/questions/9702/voip-calls-graph-for-sip-protocol-q931-over-sip/</link>
      <pubDate>Thu, 22 Mar 2012 10:13:00 +0000</pubDate>
      
      <guid>/questions/9702/voip-calls-graph-for-sip-protocol-q931-over-sip/</guid>
      <description>Voip calls graph for sip protocol (Q931 over SIP)  0 Hello team. In the newest Cisco application device can carry QSIG (Q931) protocol over SIP. If I use the latest wireshark version to capture this kind of traffic I&#39;m realizing that I cannot see the voip call graph flow. I remember that in the past it was possible but it seems that in this scenario this feature doesn&#39;t work. Have you any clue about this ?</description>
    </item>
    
    <item>
      <title>Counting IP occurrences in PCAP file using tshark</title>
      <link>/questions/9704/counting-ip-occurrences-in-pcap-file-using-tshark/</link>
      <pubDate>Thu, 22 Mar 2012 12:31:00 +0000</pubDate>
      
      <guid>/questions/9704/counting-ip-occurrences-in-pcap-file-using-tshark/</guid>
      <description>Counting IP occurrences in PCAP file using tshark  1 2Hi
I&#39;m looking for TSHARK syntax to count:
how many times IP address is present in the PCAP file as source ip.how many times IP address is present in the PCAP file as destination ip.how many times TCP Port is present in the PCAP file as destination port.This needs to be OS-independent, so pipes and OS-specific commands can&#39;t be used...</description>
    </item>
    
    <item>
      <title>(OSX) libcairo.2.dylib claims libfreetype.6.dylib provides an older package than it does</title>
      <link>/questions/9711/osx-libcairo2dylib-claims-libfreetype6dylib-provides-an-older-package-than-it-does/</link>
      <pubDate>Thu, 22 Mar 2012 13:58:00 +0000</pubDate>
      
      <guid>/questions/9711/osx-libcairo2dylib-claims-libfreetype6dylib-provides-an-older-package-than-it-does/</guid>
      <description>(OSX) libcairo.2.dylib claims libfreetype.6.dylib provides an older package than it does  0 1Just updated from 1.5 to 1.6.5 on my Macbook Pro and now Wireshark will not launch. Checking the crash file, I see this:
Dyld Error Message: Library not loaded: /usr/X11/lib/libfreetype.6.dylib Referenced from: /usr/X11/lib/libcairo.2.dylib Reason: Incompatible library version: libcairo.2.dylib requires version 14.0.0 or later, but libfreetype.6.dylib provides version 13.0.0But if I check with otool, my libfreetype.6.dylib says it provides version 14.</description>
    </item>
    
    <item>
      <title>Diagnosing intermittent slowness with HTTPS connections</title>
      <link>/questions/9714/diagnosing-intermittent-slowness-with-https-connections/</link>
      <pubDate>Thu, 22 Mar 2012 17:08:00 +0000</pubDate>
      
      <guid>/questions/9714/diagnosing-intermittent-slowness-with-https-connections/</guid>
      <description>Diagnosing intermittent slowness with HTTPS connections  0 I have a Java-based client that uses HTTPS to talk -- over the Internet -- with an Apache web server. When this client is run behind my firewall, some HTTP requests (about 5% of them) take far too long to complete (e.g. 15 seconds instead of the normal 20 milliseconds). Some requests, like ~750 KB file uploads, seemingly never complete.
When the firewall is bypassed, everything works fine.</description>
    </item>
    
    <item>
      <title>Wireshark not displaying captured packets</title>
      <link>/questions/9717/wireshark-not-displaying-captured-packets/</link>
      <pubDate>Fri, 23 Mar 2012 02:40:00 +0000</pubDate>
      
      <guid>/questions/9717/wireshark-not-displaying-captured-packets/</guid>
      <description>Wireshark not displaying captured packets  0 Hi All,
I am unable to view the packets on my wireshark installed on Win Xp machine. It only shows one frame, however I can see that packets are being captured just fine and below I see the number of packets captured and displayed. If I open the pcap on another machine, it works just fine. I cant remember having changed any setting on wireshark, it was working for me two days ago.</description>
    </item>
    
    <item>
      <title>pause frame</title>
      <link>/questions/9718/pause-frame/</link>
      <pubDate>Fri, 23 Mar 2012 05:17:00 +0000</pubDate>
      
      <guid>/questions/9718/pause-frame/</guid>
      <description>pause frame  0 To filter pause frame in captured pcap file, How do I type filter expression ?
mac-pauseasked 23 Mar &#39;12, 05:17
mom
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Display Filters:
macc will filter for all the mac-control frames
macc.opcode == pause will filter for all the mac-control pause frames
Note: Selecting Expression ! macc in the Wireshark filter bar will show all the possible mac-control filters.</description>
    </item>
    
    <item>
      <title>microsoft terminal server thin client</title>
      <link>/questions/9720/microsoft-terminal-server-thin-client/</link>
      <pubDate>Fri, 23 Mar 2012 06:52:00 +0000</pubDate>
      
      <guid>/questions/9720/microsoft-terminal-server-thin-client/</guid>
      <description>microsoft terminal server thin client  0 Is there any way to decript the packets from this type of connection
decodeasked 23 Mar &#39;12, 06:52
lewi99
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How do I extract the x509 commonName from a capture of the SSL handshake?</title>
      <link>/questions/9721/how-do-i-extract-the-x509-commonname-from-a-capture-of-the-ssl-handshake/</link>
      <pubDate>Fri, 23 Mar 2012 14:18:00 +0000</pubDate>
      
      <guid>/questions/9721/how-do-i-extract-the-x509-commonname-from-a-capture-of-the-ssl-handshake/</guid>
      <description>How do I extract the x509 commonName from a capture of the SSL handshake?  0 How do I extract the x509 commonName from a capture of the SSL handshake?
I want all of the subject fields and all of the issuer fields from the signedCertificate(s). This works but only gets the last printableString from the signing authority.
tshark -r ssl.pcap -E header=y -T fields -e x509sat.printableStringI want the first certificate and all fields from the subject and issuer.</description>
    </item>
    
    <item>
      <title>Capture an IP inside a GRE packet</title>
      <link>/questions/9723/capture-an-ip-inside-a-gre-packet/</link>
      <pubDate>Fri, 23 Mar 2012 17:06:00 +0000</pubDate>
      
      <guid>/questions/9723/capture-an-ip-inside-a-gre-packet/</guid>
      <description>Capture an IP inside a GRE packet  0 I&#39;m having a problem with a capture filter. When I capture a host IP (host a.b.c.d) on a vlan with NO GRE tunnel the capture works perfect (I&#39;ve done it hundres of times). When I move the capture vlan (change the VLAN that it is connected to on the Cisco switch - no physicl cable move just change the monitor port from vlan 500 to vlan 700) the capture stops capturing on a GRE tunnel VLAN.</description>
    </item>
    
    <item>
      <title>Understanding wireshark ISA/OSI stack (in RTP/HTTP)</title>
      <link>/questions/9733/understanding-wireshark-isaosi-stack-in-rtphttp/</link>
      <pubDate>Sat, 24 Mar 2012 05:50:00 +0000</pubDate>
      
      <guid>/questions/9733/understanding-wireshark-isaosi-stack-in-rtphttp/</guid>
      <description>Understanding wireshark ISA/OSI stack (in RTP/HTTP)  0 Hello, I am trying to understand how wirehark generates the 7 levels of ISA/OSI stack in the trace. Because after stack level 4 (trasport), how could I know if the &#34;data&#34; shown is level 5,6 or 7? For example, theoretically HTTP works on level 7, but in trace are only displayed: 1.Frame -&amp;gt; 2. Eth II -&amp;gt; 3.IPv4 -&amp;gt; 4. TCP -&amp;gt; 5.</description>
    </item>
    
    <item>
      <title>Using two instances of a field as different custom columns</title>
      <link>/questions/9742/using-two-instances-of-a-field-as-different-custom-columns/</link>
      <pubDate>Sun, 25 Mar 2012 05:10:00 +0000</pubDate>
      
      <guid>/questions/9742/using-two-instances-of-a-field-as-different-custom-columns/</guid>
      <description>Using two instances of a field as different custom columns  1 Hi folks!
What I want to do, is to add 2 custom columns to the WireShark view. The columns must contain a custom value which I add there by performing the following steps:
Choose the relevant packetOpen the relevant layer (GSM Mobile Application in my case)Click right mouse button on the desired field and choose &#34;Apply as filter&#34;Then I check what appear in the filter edit field and copy this value (in this case: gsm_map.</description>
    </item>
    
    <item>
      <title>Gateway Settings</title>
      <link>/questions/9747/gateway-settings/</link>
      <pubDate>Sun, 25 Mar 2012 10:22:00 +0000</pubDate>
      
      <guid>/questions/9747/gateway-settings/</guid>
      <description>Gateway Settings  0 1Hello! If a network has newly reconfigured routers, how can you use Wireshark to check if the default gateway settings for the hosts are correct? Thanks!
correct hosts gateway settingsasked 25 Mar &#39;12, 10:22
Cveti
1●1●2●3
accept rate: 0%
  
2 Answers:
  
1You could hook up Wireshark at the mirror port and look for ARP requests for the old routers.
answered 26 Mar &#39;12, 03:53</description>
    </item>
    
    <item>
      <title>Only Capturing SYN packets, no SYN-ACKs or ACKs</title>
      <link>/questions/9752/only-capturing-syn-packets-no-syn-acks-or-acks/</link>
      <pubDate>Sun, 25 Mar 2012 19:15:00 +0000</pubDate>
      
      <guid>/questions/9752/only-capturing-syn-packets-no-syn-acks-or-acks/</guid>
      <description>Only Capturing SYN packets, no SYN-ACKs or ACKs  0 Been having an issue on my network for a few days and can&#39;t quite seem to figure out the issue here. In a nutshell, from my cable modem I have an outer router, switch and an inner router. All hosts connect to the inner router and all traffic flows out through the outer router. The 5-port switch is technically a hardwired TAP, (everything ingressing/degressing) on port 1 (plugged to the outer router) is mirrored on port 5 (where I have an IDS).</description>
    </item>
    
    <item>
      <title>How to monitor DNS server using Wireshark</title>
      <link>/questions/9753/how-to-monitor-dns-server-using-wireshark/</link>
      <pubDate>Sun, 25 Mar 2012 23:23:00 +0000</pubDate>
      
      <guid>/questions/9753/how-to-monitor-dns-server-using-wireshark/</guid>
      <description>How to monitor DNS server using Wireshark  0 Dear Gurus, How can i monitor DNS ot some other system packets which are consuming BW of my network
packetflowasked 25 Mar &#39;12, 23:23
ARsa
1●1●1●1
accept rate: 0%
  
One Answer:
  
0You could start a capture and filter on DNS?
answered 26 Mar &#39;12, 04:08
Jaap ♦
11.7k●16●101
accept rate: 14%
     </description>
    </item>
    
    <item>
      <title>Dissector for PORT 80</title>
      <link>/questions/9754/dissector-for-port-80/</link>
      <pubDate>Sun, 25 Mar 2012 23:33:00 +0000</pubDate>
      
      <guid>/questions/9754/dissector-for-port-80/</guid>
      <description>Dissector for PORT 80  0 I need a dissector for tcp Port 80 and the first Data Byte like Hex 03. Only then. If is not is Hex03 the normaly dissector run.
I use Wireshark Version 1.6.5
Thanks Ralf
development dissectorasked 25 Mar &#39;12, 23:33
Ralf Kruppa
1●1●1●1
accept rate: 0%
 retagged 26 Mar &#39;12, 05:37 
bstn
375●1●4●15
  
One Answer:
  
1Create your dissector as an heuristic dissector and check the TCP preference &#34;</description>
    </item>
    
    <item>
      <title>Wireshark beginners(m3ua and sctp)</title>
      <link>/questions/9756/wireshark-beginnersm3ua-and-sctp/</link>
      <pubDate>Mon, 26 Mar 2012 01:23:00 +0000</pubDate>
      
      <guid>/questions/9756/wireshark-beginnersm3ua-and-sctp/</guid>
      <description>Wireshark beginners(m3ua and sctp)  0 Hello, I want to start capturing m3ua and sctp files but i dont know how to start can anybody out there help me? Thanks, Legrand
sctp m3uaasked 26 Mar &#39;12, 01:23
legrand83
1●2●2●2
accept rate: 0%
  
One Answer:
  
0You can filter by gsm_map. This will include both layers, sctp and m3ua.
answered 26 Mar &#39;12, 01:47
Eugene S</description>
    </item>
    
    <item>
      <title>tshark: Read filters were specified both with &amp;quot;-R&amp;quot; and with additional command-line arguments</title>
      <link>/questions/9758/tshark-read-filters-were-specified-both-with-r-and-with-additional-command-line-arguments/</link>
      <pubDate>Mon, 26 Mar 2012 03:35:00 +0000</pubDate>
      
      <guid>/questions/9758/tshark-read-filters-were-specified-both-with-r-and-with-additional-command-line-arguments/</guid>
      <description>tshark: Read filters were specified both with &amp;ldquo;-R&amp;rdquo; and with additional command-line arguments  0 1I&#39;m facing this problem whenever I run tshark:
tshark: Read filters were specified both with &amp;quot;-R&amp;quot; and with additional command-line argumentsMy command (run in a script) looks something like this:
./tshark -r $1 -w $2 -R &amp;quot;(frame.time &amp;gt;= &amp;#39;Mar 21, 2012 14:45:13.000&amp;#39; &amp;amp;&amp;amp; \ frame.time &amp;lt; &amp;#39;Mar 21, 2012 15:00:13.000&amp;#39;) &amp;amp;&amp;amp; \ (eth.dst==18:80:f5:10:85:08 || eth.dst==ff:ff:ff:ff:ff:ff) &amp;amp;&amp;amp; \ !</description>
    </item>
    
    <item>
      <title>exporting reassembled TCP segments with tshark</title>
      <link>/questions/9761/exporting-reassembled-tcp-segments-with-tshark/</link>
      <pubDate>Mon, 26 Mar 2012 04:00:00 +0000</pubDate>
      
      <guid>/questions/9761/exporting-reassembled-tcp-segments-with-tshark/</guid>
      <description>exporting reassembled TCP segments with tshark  0 when wireshark exports to a file, there is a line that says if the packet is a reassembled one, and which other packet it consists of: like this:
10 Reassembled TCP Segments (13611 bytes): #4411(1420), #4412(1420), #4414(1420), #4415(1420), #4416(1420), #4417(1420), #4418(1420), #4419(1420), #4420(1420), #4421(831)
I&#39;m trying to get the same information exported using the command line. currently I&#39;m trying tshark. which fields should be included?</description>
    </item>
    
    <item>
      <title>how to know the maximum number of TCP retransmission?</title>
      <link>/questions/9765/how-to-know-the-maximum-number-of-tcp-retransmission/</link>
      <pubDate>Mon, 26 Mar 2012 04:42:00 +0000</pubDate>
      
      <guid>/questions/9765/how-to-know-the-maximum-number-of-tcp-retransmission/</guid>
      <description>how to know the maximum number of TCP retransmission?  0 hi, the network quality in my lab is not good,a lot of packets are lost, so many TCP retransmission appears, i want to know the maximum number of the retransmission for each TCP packets, how should i know? thanks!
retransmission tcpasked 26 Mar &#39;12, 04:42
sherry
1●1●1●1
accept rate: 0%
 edited 26 Mar &#39;12, 05:57 
cmaynard ♦♦</description>
    </item>
    
    <item>
      <title>could someone tell me what a microsoft interface is.  I have had all kinds of problems with network.  Is this normal?  This is home computer that may have been hijacked.</title>
      <link>/questions/9777/could-someone-tell-me-what-a-microsoft-interface-is-i-have-had-all-kinds-of-problems-with-network-is-this-normal-this-is-home-computer-that-may-have-been-hijacked/</link>
      <pubDate>Mon, 26 Mar 2012 19:09:00 +0000</pubDate>
      
      <guid>/questions/9777/could-someone-tell-me-what-a-microsoft-interface-is-i-have-had-all-kinds-of-problems-with-network-is-this-normal-this-is-home-computer-that-may-have-been-hijacked/</guid>
      <description>could someone tell me what a microsoft interface is. I have had all kinds of problems with network. Is this normal? This is home computer that may have been hijacked.  -2 No. Time Source Destination Protocol Info 1 0.000000 74.125.227.116 192.168.1.3 TLSv1 Application Data Frame 1: 115 bytes on wire (920 bits), 115 bytes captured (920 bits) Ethernet II, Src: Netgear_6b:01:1c (e0:46:9a:6b:01:1c), Dst: Arcadyan_05:ae:6e (7c:4f:b5:05:ae:6e) Internet Protocol, Src: 74.125.227.116 (74.</description>
    </item>
    
    <item>
      <title>OUT-OF-ORDER</title>
      <link>/questions/9783/out-of-order/</link>
      <pubDate>Tue, 27 Mar 2012 01:58:00 +0000</pubDate>
      
      <guid>/questions/9783/out-of-order/</guid>
      <description>OUT-OF-ORDER  0 13 0.000000 10.151.19.21 10.151.17.21 TCP 1518 [TCP Out-Of-Order] 59988 &amp;gt; vnetd [ACK] Seq=1 Ack=1 Win=65535 Len=1460 我怎么样才能解决这个问题？ how to solve this problem?
out-of-orderasked 27 Mar &#39;12, 01:58
wtycc
1●1●1●2
accept rate: 0%
  
2 Answers:
  
1Your screenshot is showing a strange trace. First of all, you only seem to have captured one direction of the communication, from IP 10.151.19.21 to 10.151.17.21. So we don&#39;t know what the IP 10.</description>
    </item>
    
    <item>
      <title>Trouble decoding LDAP over SSL</title>
      <link>/questions/9784/trouble-decoding-ldap-over-ssl/</link>
      <pubDate>Tue, 27 Mar 2012 06:55:00 +0000</pubDate>
      
      <guid>/questions/9784/trouble-decoding-ldap-over-ssl/</guid>
      <description>Trouble decoding LDAP over SSL  0 I&#39;m trying to decode LDAP traffic over SSL to troubleshoot an issue we&#39;re having. I&#39;ve setup the SSL protocol properties with the PFX file that has the private key in it and I&#39;ve decoded both source 636 and dest 636 as LDAP, but it never wants to actually decode anything and just leaves everything as TCP. I&#39;m running Wireshark 1.6.5. I know that I&#39;ve done this in the past with an earlier version of Wireshark.</description>
    </item>
    
    <item>
      <title>How can I find out what Data my computer is sending over internet</title>
      <link>/questions/9799/how-can-i-find-out-what-data-my-computer-is-sending-over-internet/</link>
      <pubDate>Tue, 27 Mar 2012 16:21:00 +0000</pubDate>
      
      <guid>/questions/9799/how-can-i-find-out-what-data-my-computer-is-sending-over-internet/</guid>
      <description>How can I find out what Data my computer is sending over internet  0 Hi ! I am new to wireshark and i need to ask a question. My question is: How can I find out what Data my computer is sending over internet with wireshark ? I have an .exe file in my pc and it asks for some info. It sends that info somewhere. Iwould like to know how can i find out were this info goes, if that is possible, with wireshark.</description>
    </item>
    
    <item>
      <title>Wireshark can&amp;#x27;t see the WLAN interface??? why?? please help</title>
      <link>/questions/9800/wireshark-cant-see-the-wlan-interface-why-please-help/</link>
      <pubDate>Tue, 27 Mar 2012 16:29:00 +0000</pubDate>
      
      <guid>/questions/9800/wireshark-cant-see-the-wlan-interface-why-please-help/</guid>
      <description>Wireshark can&amp;rsquo;t see the WLAN interface??? why?? please help  0 Hi guys.
I wanted to capture wireless packets but when I run wireshark I can&#39;t see the my wireless interface card listed under the interface list?
please help me
thank you
wireless interfaceasked 27 Mar &#39;12, 16:29
NAOUFL
1●1●1●1
accept rate: 0%
 edited 27 Mar &#39;12, 17:45 
cmaynard ♦♦
9.4k●10●38●142
  
2 Answers:</description>
    </item>
    
    <item>
      <title>analysis wireshark</title>
      <link>/questions/9804/analysis-wireshark/</link>
      <pubDate>Tue, 27 Mar 2012 18:57:00 +0000</pubDate>
      
      <guid>/questions/9804/analysis-wireshark/</guid>
      <description>analysis wireshark  0 What is the mean of search &amp;gt; agent &amp;gt; 33689 [ACK} seq=4 ...................... ?
messagesasked 27 Mar &#39;12, 18:57
djedje
1●1●1●1
accept rate: 0%
  
One Answer:
  
1I guess you wonder about &#34;search-agent&#34; being shown in the packet list. It is the service name that was officially registered for port 1234, and Wireshark will replace that port number by default with the name.</description>
    </item>
    
    <item>
      <title>measure the total transmitted byte in a time interval</title>
      <link>/questions/9805/measure-the-total-transmitted-byte-in-a-time-interval/</link>
      <pubDate>Wed, 28 Mar 2012 03:07:00 +0000</pubDate>
      
      <guid>/questions/9805/measure-the-total-transmitted-byte-in-a-time-interval/</guid>
      <description>measure the total transmitted byte in a time interval  1 I want to measure the total transmitted byte in a time interval from my captured traffic. e.g from time 46.3901 to time 46.4329 how many byte was transmitted.
Or if i see the IO Graphic. I want to measure the burst in byte from 187,3s to 188,7s.
How can i measure this?
Thank you for your help.
total burst bytes measureasked 28 Mar &#39;12, 03:07</description>
    </item>
    
    <item>
      <title>generation of summary statistics window in tshark</title>
      <link>/questions/9809/generation-of-summary-statistics-window-in-tshark/</link>
      <pubDate>Wed, 28 Mar 2012 03:18:00 +0000</pubDate>
      
      <guid>/questions/9809/generation-of-summary-statistics-window-in-tshark/</guid>
      <description>generation of summary statistics window in tshark  0 hello experts,
i was trying to generate the whole statistics summary window(present in wireshark) using tshark and then re direct to it a unix file.however i am not able to find the correct options for -Z .please kindly help me with the options...
statistics summaryasked 28 Mar &#39;12, 03:18
sangmeshp
36●7●8●11
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Porting to Blackberry</title>
      <link>/questions/9811/porting-to-blackberry/</link>
      <pubDate>Wed, 28 Mar 2012 04:11:00 +0000</pubDate>
      
      <guid>/questions/9811/porting-to-blackberry/</guid>
      <description>Porting to Blackberry  0 Any plans to port wireshark to blackberry?
blackberryasked 28 Mar &#39;12, 04:11
palindrome
1●1●1●1
accept rate: 0%
  
One Answer:
  
1None that I know of. I think the traditional Blackberry OS supports only Java applications, in which case it&#39;s not going to happen any time soon; I don&#39;t know what the Shiny New QNX-Based OS supports, but even if RIM are supporting C apps on it, that&#39;s probably not likely to happen soon either.</description>
    </item>
    
    <item>
      <title>Calculate Client / server processing time</title>
      <link>/questions/9821/calculate-client-server-processing-time/</link>
      <pubDate>Wed, 28 Mar 2012 08:13:00 +0000</pubDate>
      
      <guid>/questions/9821/calculate-client-server-processing-time/</guid>
      <description>Calculate Client / server processing time  0 Hi Everybody,
i use Wireshark since some years to help me to troubleshoot performance issue.
As Wireshark can see the between packets, it should provide the total time spend (by processing). I never find in Wireshark where i can have this kind of information.
I can&#39;t imagine Wireshark doesn&#39;t provide this information.
Could you help me?
Best regards
calculate timeasked 28 Mar &#39;12, 08:13</description>
    </item>
    
    <item>
      <title>tshark reporting packet loss</title>
      <link>/questions/9827/tshark-reporting-packet-loss/</link>
      <pubDate>Wed, 28 Mar 2012 13:32:00 +0000</pubDate>
      
      <guid>/questions/9827/tshark-reporting-packet-loss/</guid>
      <description>tshark reporting packet loss  0 Greetings All;
I run tshark to capture date for 45 seconds. At the end of 45 seconds tshark stops and reports:
6504 79 packets dropped
I assume that 6504 is the number of packets captured.
I am confused as to the 79 packets dropped. Are these packets that are somehow dropped by wireshark (maybe for memory reasons ?), or are these packets it believes are somehow dropped in the network.</description>
    </item>
    
    <item>
      <title>abnormal packet loss in wireshark</title>
      <link>/questions/9829/abnormal-packet-loss-in-wireshark/</link>
      <pubDate>Wed, 28 Mar 2012 17:28:00 +0000</pubDate>
      
      <guid>/questions/9829/abnormal-packet-loss-in-wireshark/</guid>
      <description>abnormal packet loss in wireshark  0 I am testing the packETH 1.7 packet genrator and used wireshark 1.2.7 for same. I use two ubuntu 10.04 machine with 100Mb NIC and later added 1Gb NIC.Both machine are connected PtoP with CAT6 straight cable. Now i transmit 200000 udp packet at rate from 125packet/sec to 1000000packet/sec.I used wireshark on both machine to capture packet and measure performance of packet generator. The observation is that in some readings source machine wireshark capture less packets than destination machine wireshark.</description>
    </item>
    
    <item>
      <title>Diagnosing SSL timeout</title>
      <link>/questions/9830/diagnosing-ssl-timeout/</link>
      <pubDate>Wed, 28 Mar 2012 20:36:00 +0000</pubDate>
      
      <guid>/questions/9830/diagnosing-ssl-timeout/</guid>
      <description>Diagnosing SSL timeout  0 I&#39;m attempting to use a PayPal listener plugin in WordPress and am hung up on an SSL timeout. Searches to date have yielded nothing on topic and the plugin developer is effectively offline. I thought perhaps I&#39;d learn something by performing a packet trace. Unfortunately I don&#39;t quite know what to look for. Any suggestions on how best to proceed are welcome. Thanks.
George
ssl paypal ipn timeoutasked 28 Mar &#39;12, 20:36</description>
    </item>
    
    <item>
      <title>both 32 and 64 bit installs use the 32 bit registry</title>
      <link>/questions/9832/both-32-and-64-bit-installs-use-the-32-bit-registry/</link>
      <pubDate>Thu, 29 Mar 2012 02:03:00 +0000</pubDate>
      
      <guid>/questions/9832/both-32-and-64-bit-installs-use-the-32-bit-registry/</guid>
      <description>both 32 and 64 bit installs use the 32 bit registry  0 I&#39;ve noticed that both 32 and 64 bit installs use the 32 bit registry which makes it impossible to distinguish them in the registry. Any workaround on it please?
registryasked 29 Mar &#39;12, 02:03
Eugenia
1●1●1●2
accept rate: 0%
  
One Answer:
  
2I&#39;m not sure it would make sense for us to explicitly write to the 64-bit view of the registry, at least for our current set of keys.</description>
    </item>
    
    <item>
      <title>3GPP Message Decoder by Vincent Helfre not working</title>
      <link>/questions/9833/3gpp-message-decoder-by-vincent-helfre-not-working/</link>
      <pubDate>Thu, 29 Mar 2012 03:06:00 +0000</pubDate>
      
      <guid>/questions/9833/3gpp-message-decoder-by-vincent-helfre-not-working/</guid>
      <description>3GPP Message Decoder by Vincent Helfre not working  0 Hi,
I&#39;ve installed the latest SW release (Decoder-0.7-Setup.exe) to read out user capabilities, but Wireshark path seems always wrong:
Could not find d:\prog\Wireshark\ wireshark.exe - Install it from www.wireshark.org if not installed - if already installed, set the correct wireshark installation path and restart 3GPP message decoder. Config file located in: d:\prog\Decoder\Preferences\ws_installation_dir.txt
For sure the problem concerns installation paths or admin rights (although I&#39;m currently useing D drive).</description>
    </item>
    
    <item>
      <title>How can you specify the next dissector</title>
      <link>/questions/9839/how-can-you-specify-the-next-dissector/</link>
      <pubDate>Thu, 29 Mar 2012 08:39:00 +0000</pubDate>
      
      <guid>/questions/9839/how-can-you-specify-the-next-dissector/</guid>
      <description>How can you specify the next dissector  0 Hi!
I created a dissector that dissects EtherNet/IP data payload. I also want to create a dissector that will be used as a &#34;link layer&#34; dissector that will read packets created by a vendor specific protocol.
In some cases, I want wireshark to dissect from self created pcap files. In those, I have a different protocol that has the same payload type that otherwise goes through EtherNet/IP.</description>
    </item>
    
    <item>
      <title>How can i see vlan id and pcp on wireshark?</title>
      <link>/questions/9852/how-can-i-see-vlan-id-and-pcp-on-wireshark/</link>
      <pubDate>Thu, 29 Mar 2012 16:15:00 +0000</pubDate>
      
      <guid>/questions/9852/how-can-i-see-vlan-id-and-pcp-on-wireshark/</guid>
      <description>How can i see vlan id and pcp on wireshark?  0 On filter when i enter vlan, the message that appears is:
&#34;vlan&#34; is neither a field nor a protocol name.
The following display filter isn&#39;t a valid display filter: vlan See the help for a description of the display filter syntax.
How can i see vlan id and pcp on wireshark?
I am using Ubuntu 11.10 amd64.
Thanks,</description>
    </item>
    
    <item>
      <title>wi-fi direct measurement</title>
      <link>/questions/9858/wi-fi-direct-measurement/</link>
      <pubDate>Fri, 30 Mar 2012 03:15:00 +0000</pubDate>
      
      <guid>/questions/9858/wi-fi-direct-measurement/</guid>
      <description>wi-fi direct measurement  0 Is it possible to measure wi-fi direct packet using the wireshark. If so, how to measure and analyze ??
wi-fi directasked 30 Mar &#39;12, 03:15
novice10
1●2●2●2
accept rate: 0%
  
One Answer:
  
0See the Wiki page on capturing 802.11 traffic HERE. Note that you&#39;ll likely have difficulties doing this on Windows.
answered 30 Mar &#39;12, 03:28
grahamb ♦
19.8k●3●30●206</description>
    </item>
    
    <item>
      <title>Tshark does not display all ssl.records</title>
      <link>/questions/9862/tshark-does-not-display-all-sslrecords/</link>
      <pubDate>Fri, 30 Mar 2012 06:36:00 +0000</pubDate>
      
      <guid>/questions/9862/tshark-does-not-display-all-sslrecords/</guid>
      <description>Tshark does not display all ssl.records  0 Hi,
According to the post here:
http://www.wireshark.org/lists/wireshark-users/200909/msg00254.html
there was a feature request for printing all occurances of a field when there are multiple occurances in a single packet (in my case it&#39;s ssl.record and all other fields related to ssl). Is it already implemented?
Best Regards
ssl occurances multiple bug fieldasked 30 Mar &#39;12, 06:36
korczyn
6●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Tshark problem</title>
      <link>/questions/9866/tshark-problem/</link>
      <pubDate>Fri, 30 Mar 2012 08:40:00 +0000</pubDate>
      
      <guid>/questions/9866/tshark-problem/</guid>
      <description>Tshark problem  0 Dear friends, I am trying to export output to a csv file with tshark and I would like to export Beacon Timestamp not in a Hex format but in Decimal format. When I am using this method : -e wlan_mgt.fixed.timestamp I see hexadecimal value in my CSV file. But when I open wireshark and look at the Timestamp custome column the value is in Decimal. Please help me to find out what am I doing wrong?</description>
    </item>
    
    <item>
      <title>Wireshark on MAC OSX VPN</title>
      <link>/questions/9867/wireshark-on-mac-osx-vpn/</link>
      <pubDate>Fri, 30 Mar 2012 09:10:00 +0000</pubDate>
      
      <guid>/questions/9867/wireshark-on-mac-osx-vpn/</guid>
      <description>Wireshark on MAC OSX VPN  0 I am troubleshooting dns issues with apple products on our corporate network. We are seeing a problem where windows users can resolve short-name dns just fine but users on apple products can not (Iphone, Ipad, Mac). To start I am troubleshooting with a mac, but I am not seeing any packets go across the VPN when I try to start a wireshark from it.</description>
    </item>
    
    <item>
      <title>InstallLocation not updated in Registry Uninstall</title>
      <link>/questions/9868/installlocation-not-updated-in-registry-uninstall/</link>
      <pubDate>Fri, 30 Mar 2012 09:47:00 +0000</pubDate>
      
      <guid>/questions/9868/installlocation-not-updated-in-registry-uninstall/</guid>
      <description>InstallLocation not updated in Registry Uninstall  -1 Hi,
I&#39;ve see that Registry is not updated correctly during program install : HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wireshark the field &#39;InstallLocation&#39; is not present.
++ Vincent
installation registry wiresharkasked 30 Mar &#39;12, 09:47
Vincent Duve...
0●1●1●1
accept rate: 0%
  
One Answer:
  
0This isn&#39;t really a question for Ask Wireshark. Please report your issue on the developers mailing list, details HERE.</description>
    </item>
    
    <item>
      <title>WireShark newbie. Help with filter expressions.</title>
      <link>/questions/9875/wireshark-newbie-help-with-filter-expressions/</link>
      <pubDate>Sat, 31 Mar 2012 08:51:00 +0000</pubDate>
      
      <guid>/questions/9875/wireshark-newbie-help-with-filter-expressions/</guid>
      <description>WireShark newbie. Help with filter expressions.  0 I am very new to WS. Have a general grasp of things but building expressions to use in a filter is giving me a lot of heartburn. Could someone please help me. Please remember I am not tech savvy.
I need an expression for a capture filter that will do the following: 1) Capture TCP protocol and 2) Filter for ports 9501 to 9505 and 3) Filter unique source IP addresses</description>
    </item>
    
    <item>
      <title>Server sends PSH, ACK during 3-way handshake</title>
      <link>/questions/9879/server-sends-psh-ack-during-3-way-handshake/</link>
      <pubDate>Sat, 31 Mar 2012 16:29:00 +0000</pubDate>
      
      <guid>/questions/9879/server-sends-psh-ack-during-3-way-handshake/</guid>
      <description>Server sends PSH, ACK during 3-way handshake  0 2This is the sequence:
Client sends SYN – sequence number 0
Server returns PSH, ACK – Sequence number 1, Acknowledgement number 31267
I was expecting SYN, ACK from the server. What is going on here?
So, client sends RST and connection never gets established.
Normally everything works fine but once in a while this issue occurs
Thanks,
tcpasked 31 Mar &#39;12, 16:29</description>
    </item>
    
    <item>
      <title>802.11 FCS calculation</title>
      <link>/questions/9883/80211-fcs-calculation/</link>
      <pubDate>Sun, 01 Apr 2012 04:44:00 +0000</pubDate>
      
      <guid>/questions/9883/80211-fcs-calculation/</guid>
      <description>802.11 FCS calculation  0 Hi, Im trying to understand how 802.11 calculates the FCS. Im using scapy to build and dissect packets quickly and easily however the FCS field of 802.11 packet is not calculated automatically when building an 802.11 packet. The Dot11Wep packet calculates the IC -WEP specific IC- however there is a second redundancy check that is supposed to check the entire 802.11 packet including the wep data.</description>
    </item>
    
    <item>
      <title>data visualization options in Wireshark</title>
      <link>/questions/9884/data-visualization-options-in-wireshark/</link>
      <pubDate>Sun, 01 Apr 2012 04:54:00 +0000</pubDate>
      
      <guid>/questions/9884/data-visualization-options-in-wireshark/</guid>
      <description>data visualization options in Wireshark  0 Hi, I am wondering what types of data visualization options Wireshark offers beyond IO and Flow graphs. It would be nice to have a &#34;birds-eye view&#34; option in the Statistics menu that let you see network traffic as a true network in link diagram form. And perhaps be able to dynamically change the network diagram in response to arbitrary BPF. It is much easier to catch odd / interesting network behavior when looking at the data this way.</description>
    </item>
    
    <item>
      <title>Help me  &amp;quot;wifi direct&amp;quot; packets measurement</title>
      <link>/questions/9891/help-me-wifi-direct-packets-measurement/</link>
      <pubDate>Sun, 01 Apr 2012 20:00:00 +0000</pubDate>
      
      <guid>/questions/9891/help-me-wifi-direct-packets-measurement/</guid>
      <description>Help me &amp;ldquo;wifi direct&amp;rdquo; packets measurement  0 Now I am try to measure &#34;wifi direct&#34; packets between two cellphones using Wireshark &amp;amp; Airpcap on window
Is there anyone who measure these packets successfully please share know-how to me
[email protected]naver.com
wifi directasked 01 Apr &#39;12, 20:00
novice10
1●2●2●2
accept rate: 0%
  
One Answer:
  
0hi did u find the solution for this question? Can we capture using AirPcap nx tool?</description>
    </item>
    
    <item>
      <title>60 who has 169.254.25.31</title>
      <link>/questions/9892/60-who-has-1692542531/</link>
      <pubDate>Sun, 01 Apr 2012 21:24:00 +0000</pubDate>
      
      <guid>/questions/9892/60-who-has-1692542531/</guid>
      <description>60 who has 169.254.25.31  0 I am seeing many of this type of listing &#34;60 who has 169.254.25.31? tell 10.248.252.50&#34; Can you please tell me what it means?
Thanks
arpasked 01 Apr &#39;12, 21:24
dbruce
1●1●1●1
accept rate: 0%
 edited 21 Sep &#39;12, 08:34 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
2That&#39;s an Address Resolution Protocol (ARP) packet. The machine with an IP address of 10.</description>
    </item>
    
    <item>
      <title>help me with this tools</title>
      <link>/questions/9896/help-me-with-this-tools/</link>
      <pubDate>Mon, 02 Apr 2012 05:46:00 +0000</pubDate>
      
      <guid>/questions/9896/help-me-with-this-tools/</guid>
      <description>help me with this tools  0 Hi friends.please help me to solve these questions about wireshark: 1.how can i get communication rate with the other devices,2.a brief explanation about round trip time,throughput and time sequence in their vertical axis,3.a brief explanation of tcp,udp,http packet rate in io graph , 4. analysis of the network while connecting with a ssl connection and comparing it with the one without ssl,5.analysis of using tcp and udp port addresses.</description>
    </item>
    
    <item>
      <title>any one please help me to learn wire shark</title>
      <link>/questions/9898/any-one-please-help-me-to-learn-wire-shark/</link>
      <pubDate>Mon, 02 Apr 2012 07:53:00 +0000</pubDate>
      
      <guid>/questions/9898/any-one-please-help-me-to-learn-wire-shark/</guid>
      <description>any one please help me to learn wire shark  0 1)i want to lean abt wire shak itryed many ways but i cont get the clear idea please some one help me to learn this 2)what is meant by malformed packet is it virus or some thing else
windows7asked 02 Apr &#39;12, 07:53
arasu
1●3●3●3
accept rate: 0%
  
One Answer:
  
2Clear idea = &#34;</description>
    </item>
    
    <item>
      <title>Need to find which IP address is taking  most bandwith usage in my network</title>
      <link>/questions/9900/need-to-find-which-ip-address-is-taking-most-bandwith-usage-in-my-network/</link>
      <pubDate>Mon, 02 Apr 2012 08:13:00 +0000</pubDate>
      
      <guid>/questions/9900/need-to-find-which-ip-address-is-taking-most-bandwith-usage-in-my-network/</guid>
      <description>Need to find which IP address is taking most bandwith usage in my network  0 Using Wireshark, is there any possibility to check which IP address is using more bandwidth in my network?
bandwidthasked 02 Apr &#39;12, 08:13
arasu
1●3●3●3
accept rate: 0%
 edited 02 Apr &#39;12, 11:00 
multipleinte...
1.3k●15●23●40
  
2 Answers:
  
2Try looking at Statistics -&amp;gt; Endpoints, then choose the IPv4 (or IPv6) tab.</description>
    </item>
    
    <item>
      <title>sniffer setup help needed</title>
      <link>/questions/9903/sniffer-setup-help-needed/</link>
      <pubDate>Mon, 02 Apr 2012 12:51:00 +0000</pubDate>
      
      <guid>/questions/9903/sniffer-setup-help-needed/</guid>
      <description>sniffer setup help needed  0 I&#39;m trying to put together a sniff environment where wireless client hit a WAP, the waps wired ethernet port brings the traffic back to a port mirror switch for me to look at. Does anyone know how to get a WAP to stop &#34;local switching&#34; (the wap seems to switch the local traffic and only allows traffic destined to a different network to come over the wired port.</description>
    </item>
    
    <item>
      <title>About epan_dissect_run function</title>
      <link>/questions/9906/about-epan_dissect_run-function/</link>
      <pubDate>Mon, 02 Apr 2012 20:45:00 +0000</pubDate>
      
      <guid>/questions/9906/about-epan_dissect_run-function/</guid>
      <description>About epan_dissect_run function  0 I am now reading source code of wireshark and have leaned much from it. Thank you for all developers.
But I am confused about &#34;epan_dissect_run&#34; function.
When we get a packet from the capture file, we used &#34;read_packet&#34; function to read and dissect the packet; In the &#34;read_packet&#34; we call the function named &#34;epan_dissect_run&#34; to dissect the packet;But I also find the &#34;epan_dissect_run&#34; function called in the callback fuction &#34;</description>
    </item>
    
    <item>
      <title>Bind not acknowledged</title>
      <link>/questions/9907/bind-not-acknowledged/</link>
      <pubDate>Mon, 02 Apr 2012 23:31:00 +0000</pubDate>
      
      <guid>/questions/9907/bind-not-acknowledged/</guid>
      <description>Bind not acknowledged  0 I was doing a capture from client&#39;s end and there were 43 packets in warnings marked with &#34;Bind not acknowledged&#34;. Could somebody explain me what this is? Google didn&#39;t give me any help. Thanks.
-Rakki
not bind acknowledged tcpasked 02 Apr &#39;12, 23:31
rakki
0●5●5●8
accept rate: 0%
  
One Answer:
  
0It means that (whether correctly or incorrectly) Wireshark thinks those packets are DCE RPC packets (at this point, Windows is probably the largest user of DCE RPC), and those are &#34;</description>
    </item>
    
    <item>
      <title>Wireshark is capturing the probe request frame but no probe response for this request</title>
      <link>/questions/9910/wireshark-is-capturing-the-probe-request-frame-but-no-probe-response-for-this-request/</link>
      <pubDate>Tue, 03 Apr 2012 04:55:00 +0000</pubDate>
      
      <guid>/questions/9910/wireshark-is-capturing-the-probe-request-frame-but-no-probe-response-for-this-request/</guid>
      <description>Wireshark is capturing the probe request frame but no probe response for this request  0 I could send the probe request which is visible on the wireshark but not getting any probe response for this request
proberesponseasked 03 Apr &#39;12, 04:55
hel
1●1●1●1
accept rate: 0%
So what is your question?
(31 May &#39;12, 21:23) cmaynard ♦♦   </description>
    </item>
    
    <item>
      <title>missing player button</title>
      <link>/questions/9912/missing-player-button/</link>
      <pubDate>Tue, 03 Apr 2012 06:51:00 +0000</pubDate>
      
      <guid>/questions/9912/missing-player-button/</guid>
      <description>missing player button  0 Is there anyone who has problem with missing button player in wireshark? I have version 1.2.15 instaled on centos 6.2, instaled portaudio and portaudio-devel but still no success.
Best Regards
playerasked 03 Apr &#39;12, 06:51
2cv6club
1●1●1●2
accept rate: 0%
 edited 03 Apr &#39;12, 06:52 
  
2 Answers:
  
1That&#39;s a really old and unsupported version of Wireshark. You should look to upgrade to a supported version.</description>
    </item>
    
    <item>
      <title>Capturing traffic to any host within a specific domain</title>
      <link>/questions/9916/capturing-traffic-to-any-host-within-a-specific-domain/</link>
      <pubDate>Tue, 03 Apr 2012 10:13:00 +0000</pubDate>
      
      <guid>/questions/9916/capturing-traffic-to-any-host-within-a-specific-domain/</guid>
      <description>Capturing traffic to any host within a specific domain  2 I need to capture HTTP GET and POST requests to (responses from aren&#39;t of interest) any host that is within .example.com. This will be a long running capture and the machine is fairly heavily used, so I&#39;m keenly interested in controlling what is captured rather than just what is displayed. There are probably hundreds of hosts within .example.com, some I won&#39;t even know about.</description>
    </item>
    
    <item>
      <title>How can I capture VPN/encrypted packets?</title>
      <link>/questions/9918/how-can-i-capture-vpnencrypted-packets/</link>
      <pubDate>Tue, 03 Apr 2012 11:06:00 +0000</pubDate>
      
      <guid>/questions/9918/how-can-i-capture-vpnencrypted-packets/</guid>
      <description>How can I capture VPN/encrypted packets?  1 Symantec antivirus on a VPN connected Windoze machine is detecting an intrusion from a host on our VPN. Symantec can do this because the VPN client on the destination machine decrypts the messages before Symantec see it. (Right?)
I am monitoring using a Mac with Wireshark on a hub which also supports the Windoze machine that&#39;s detecting the intrusion.
Because the Winders machine is on the VPN, but my monitoring Wireshark machine is not VPN connected, is there some capture filter that can decode the encrypted messages?</description>
    </item>
    
    <item>
      <title>Internet Usage</title>
      <link>/questions/9919/internet-usage/</link>
      <pubDate>Tue, 03 Apr 2012 11:19:00 +0000</pubDate>
      
      <guid>/questions/9919/internet-usage/</guid>
      <description>Internet Usage  0 We are almost maxing out our isp bandwidth at certain times of the day. Using wireshark and Cascade, how can I determine which IP or MAC address is utilizing the most bandwidth?
bandwidth internetasked 03 Apr &#39;12, 11:19
jmillsapps
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How to decode MAC-LTE message?</title>
      <link>/questions/9925/how-to-decode-mac-lte-message/</link>
      <pubDate>Wed, 04 Apr 2012 03:01:00 +0000</pubDate>
      
      <guid>/questions/9925/how-to-decode-mac-lte-message/</guid>
      <description>How to decode MAC-LTE message?  0 I want to decode MAC-LTE message but when I try to decode using tshark it gives the following error. Can&#39;t dissect LTE MAC frame because no per-frame info was attached!
mac tshark lteasked 04 Apr &#39;12, 03:01
ender
6●1●1●4
accept rate: 0%
How are the LTE frames stored in the file? Is this a Catapult DCT2000 file (text file), or is it a capture with LTE MAC-over-UDP, or is it something else?</description>
    </item>
    
    <item>
      <title>How can I get ISIS Neighbors if no Display Filter Reference exists?</title>
      <link>/questions/9926/how-can-i-get-isis-neighbors-if-no-display-filter-reference-exists/</link>
      <pubDate>Wed, 04 Apr 2012 07:23:00 +0000</pubDate>
      
      <guid>/questions/9926/how-can-i-get-isis-neighbors-if-no-display-filter-reference-exists/</guid>
      <description>How can I get ISIS Neighbors if no Display Filter Reference exists?  0 I need to get IS and ES Neighbors as well as Area Address for ISIS packets, but I do not see any Display Reference Filter for such. Can someone advise on how this may be done without parsing an ASCII text dump from tshark.
neighbors area_address isisasked 04 Apr &#39;12, 07:23
clayton2710
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Disable port number popular name allocation</title>
      <link>/questions/9928/disable-port-number-popular-name-allocation/</link>
      <pubDate>Wed, 04 Apr 2012 08:02:00 +0000</pubDate>
      
      <guid>/questions/9928/disable-port-number-popular-name-allocation/</guid>
      <description>Disable port number popular name allocation  2 Hello all,
Can anyone tell me how to stop wireshark giving the port numbers for TCP packets popular names like &#34;ddi-tcp&#34; and &#34;blackjack&#34; etc, I just want to see the port number.
Regards
Baz
popular allocation disable port nameasked 04 Apr &#39;12, 08:02
Baz
31●2●2●4
accept rate: 0%
  
One Answer:
  
5Sure, just disable &#34;Name Resolution&#34; for the &#34;</description>
    </item>
    
    <item>
      <title>Drag/drop preference columns not working in 1.6.6</title>
      <link>/questions/9937/dragdrop-preference-columns-not-working-in-166/</link>
      <pubDate>Wed, 04 Apr 2012 10:47:00 +0000</pubDate>
      
      <guid>/questions/9937/dragdrop-preference-columns-not-working-in-166/</guid>
      <description>Drag/drop preference columns not working in 1.6.6  0 Neither 1.6.5 nor 1.6.6 allows one to drag and drop columns in Preferences. This is running on Windows 7 64-bit. I create a new column which ends up at the end of the list . I click and drag it toward the top, but when I release the mouse button the new column floats back to the bottom of the list.</description>
    </item>
    
    <item>
      <title>Seeing Traffic I shouldn&amp;#x27;t</title>
      <link>/questions/9945/seeing-traffic-i-shouldnt/</link>
      <pubDate>Wed, 04 Apr 2012 16:07:00 +0000</pubDate>
      
      <guid>/questions/9945/seeing-traffic-i-shouldnt/</guid>
      <description>Seeing Traffic I shouldn&amp;rsquo;t  0 Please excuse my ignorance, I am a nitwit (Nerd In Training With Information Technology). I am running wireshark on my PC and seeing ton&#39;s of traffic I think I should not be seeing. For example a Server has a mapi connection to another server. I thought the idea of a switch is that that traffic is only between those two hosts? The environment I setup has 4 Brocade FCX48&#39;s in a stack in the server farm and a seperate stack of 8 fcx48&#39;s for the user&#39;s.</description>
    </item>
    
    <item>
      <title>NASDAQ MOLD UDP 64 Dissector?</title>
      <link>/questions/9946/nasdaq-mold-udp-64-dissector/</link>
      <pubDate>Wed, 04 Apr 2012 16:44:00 +0000</pubDate>
      
      <guid>/questions/9946/nasdaq-mold-udp-64-dissector/</guid>
      <description>NASDAQ MOLD UDP 64 Dissector?  0 Anyone know of a dissector for NASDAQ&#39;s mold UDP 64 protocol ? I regularly have to identify sequence gaps in MOLD data feeds and this came in very handy. (Link is to Chris Bidwells MOLD UDP dissector)
http://www.chrisbidwell.com/moldudp/
Anyway NASDAQ are phasing this out in favor of MOLD UDP 64 and i was hoping someone might have written a similar plugin.
Any help would be greatly appreciated.</description>
    </item>
    
    <item>
      <title>Packet seen in wireshark but not in application.</title>
      <link>/questions/9949/packet-seen-in-wireshark-but-not-in-application/</link>
      <pubDate>Wed, 04 Apr 2012 21:01:00 +0000</pubDate>
      
      <guid>/questions/9949/packet-seen-in-wireshark-but-not-in-application/</guid>
      <description>Packet seen in wireshark but not in application.  0 Hi all, I am sending a UDP request using my application and response is also sent by the destination. In the host where I run the application, I am running wireshark and in that I found that the response is received. But this data is not received in my application. Can you suggest me what all could have led to this issue</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t get tcp.port of packet in lua</title>
      <link>/questions/9952/cant-get-tcpport-of-packet-in-lua/</link>
      <pubDate>Thu, 05 Apr 2012 01:22:00 +0000</pubDate>
      
      <guid>/questions/9952/cant-get-tcpport-of-packet-in-lua/</guid>
      <description>Can&amp;rsquo;t get tcp.port of packet in lua  0 Hello how can i get a tcp.port of packet in lua?
lua dissectorasked 05 Apr &#39;12, 01:22
Zvika
6●2●2●4
accept rate: 0%
  
One Answer:
  
1 Use pinfo.src_port or pinfo.dst_port.
From a dissector:function proto_foo.dissector(buf, pinfo, tree) print(&amp;#39;src_port&amp;#39;, pinfo.src_port) print(&amp;#39;dst_port&amp;#39;, pinfo.dst_port) endFrom a tap:function tap.packet(pinfo, buf) print(&amp;#39;src_port&amp;#39;, pinfo.src_port) print(&amp;#39;dst_port&amp;#39;, pinfo.dst_port) endanswered 05 Apr &#39;12, 09:48
bstn
375●1●4●15</description>
    </item>
    
    <item>
      <title>adding following support to wireshark</title>
      <link>/questions/9954/adding-following-support-to-wireshark/</link>
      <pubDate>Thu, 05 Apr 2012 02:23:00 +0000</pubDate>
      
      <guid>/questions/9954/adding-following-support-to-wireshark/</guid>
      <description>adding following support to wireshark  0 I&#39;m looking for following features 1. g729 support for VOIP calls(playback) 2. exporting call quality record to SQL
These features are not available in wireshark. If i want to develop them, what specific things i should i know before attempting it. wireshark codebase is big, so any specific information will be very helpful.
g729 sqlasked 05 Apr &#39;12, 02:23
arif
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Upgraded from 1.6.4 to 1.6.6, now I get &amp;quot;runtime error&amp;quot;</title>
      <link>/questions/9967/upgraded-from-164-to-166-now-i-get-runtime-error/</link>
      <pubDate>Thu, 05 Apr 2012 10:08:00 +0000</pubDate>
      
      <guid>/questions/9967/upgraded-from-164-to-166-now-i-get-runtime-error/</guid>
      <description>Upgraded from 1.6.4 to 1.6.6, now I get &amp;ldquo;runtime error&amp;rdquo;  0 I use named pipes to access serial port data.
After I upgraded from Wireshark 1.6.4 to Wireshark 1.6.6, I get a runtime error when I try to enter my named pipe address in the capture dialog box.
runtime errorasked 05 Apr &#39;12, 10:08
korwinula
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Hmm, a problem having to do with named pipes was supposed to have been fixed with 1.</description>
    </item>
    
    <item>
      <title>Ga Reference Point</title>
      <link>/questions/9968/ga-reference-point/</link>
      <pubDate>Thu, 05 Apr 2012 11:15:00 +0000</pubDate>
      
      <guid>/questions/9968/ga-reference-point/</guid>
      <description>Ga Reference Point  0 Is Ga reference point (3GPP 32.298) decoding supported by Wireshark?
cdrs gaasked 05 Apr &#39;12, 11:15
emarina
1●2●2●2
accept rate: 0%
  
One Answer:
  
0The last time you asked this question, somebody answered it. Please refer back to that answer and, if you have further questions, ask them in comments on that answer.
answered 05 Apr &#39;12, 13:09
Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>Network outage during capture</title>
      <link>/questions/9975/network-outage-during-capture/</link>
      <pubDate>Thu, 05 Apr 2012 22:44:00 +0000</pubDate>
      
      <guid>/questions/9975/network-outage-during-capture/</guid>
      <description>Network outage during capture  0 I have been trying to diagnose a SQL timeout issue, and started a capture on one web server tonight. 10 minutes after starting we started receiving monitoring pages and customer calls that we were offline. This issue was affecting all subnets; crossing VLANs, Cisco ASA firewalls between subnets, and Cisco ACE load balancers fronting a dozen web services. Various applications were unable to connect to the backend web services (through the load balancers and firewalls, with services both in the same subnet/VLAN and crossing through routers/firewalls/load balancers).</description>
    </item>
    
    <item>
      <title>No fonts found</title>
      <link>/questions/9977/no-fonts-found/</link>
      <pubDate>Thu, 05 Apr 2012 23:38:00 +0000</pubDate>
      
      <guid>/questions/9977/no-fonts-found/</guid>
      <description>No fonts found  0 Hi,
I&#39;m getting the following error..when i try to run wireshark-2.4.2 on solaris-10.
No fonts found; this probably means that the fontconfig library is not correctly configured. You may need to edit the fonts.conf configuration file. More information about fontconfig can be found in the fontconfig(3) manual page and on http://fontconfig.org http://fontconfig.org/
I have installed fontconfig-2.4.2.
please help...i&#39;m stuck with this issue.
Thank&#39;s in advance</description>
    </item>
    
    <item>
      <title>Unable to see decrypted client SSL requests</title>
      <link>/questions/9980/unable-to-see-decrypted-client-ssl-requests/</link>
      <pubDate>Fri, 06 Apr 2012 05:26:00 +0000</pubDate>
      
      <guid>/questions/9980/unable-to-see-decrypted-client-ssl-requests/</guid>
      <description>Unable to see decrypted client SSL requests  0 Hi folks;
I am using IE and|or Firefox to do some browsing to pages protected with SSL. I have the server private key, and have configured Wireshark to use it to decrypt the server responses. This works great. My problem is that the browser requests are still encrypted within wireshark so I am not seeing the entire ssl transaction in the clear.</description>
    </item>
    
    <item>
      <title>MTU size and Path MTU Discovery</title>
      <link>/questions/9982/mtu-size-and-path-mtu-discovery/</link>
      <pubDate>Fri, 06 Apr 2012 08:17:00 +0000</pubDate>
      
      <guid>/questions/9982/mtu-size-and-path-mtu-discovery/</guid>
      <description>MTU size and Path MTU Discovery  0 I am a bit confused by the MTU limit on different devices. My understanding the default for Ethernet II frames is a max MTU size of 1500. So in other words, MTU is based on the size of the entire frame! Math is not my strong point! So I understand a default frame size of 1500 would mean I could send a 1458 payload size using Path MTU Discovery method(8 bytes for ICMP header + 20 IP Header + 14 for Ethernet II = total frame size 1500.</description>
    </item>
    
    <item>
      <title>Windows 7 Compatibility</title>
      <link>/questions/9984/windows-7-compatibility/</link>
      <pubDate>Fri, 06 Apr 2012 08:43:00 +0000</pubDate>
      
      <guid>/questions/9984/windows-7-compatibility/</guid>
      <description>Windows 7 Compatibility  0 At what version did Wireshark become Windows 7 compatible? Not the latest but the very first.
windows7 compatibility versionsasked 06 Apr &#39;12, 08:43
cre8tivspirit
1●1●1●1
accept rate: 0%
  
One Answer:
  
3The first version released!
I just downloaded and installed 0.99.2, and that was able to run and capture traffic on Win 7 SP1 64 bit.
There were some graphical glitches, but nothing to make it unusable, and I did the capture using the installed WinPCap 4.</description>
    </item>
    
    <item>
      <title>how to detect nmap connections?</title>
      <link>/questions/9986/how-to-detect-nmap-connections/</link>
      <pubDate>Fri, 06 Apr 2012 08:50:00 +0000</pubDate>
      
      <guid>/questions/9986/how-to-detect-nmap-connections/</guid>
      <description>how to detect nmap connections?  0 HI can anyone help with an issue I am having using wireshark to detect nmap scans I have managed to filter the amount of SYN/ACK packets for the 3 way with ip.proto == 6 and tcp.flags == 18. I have also filtered for a SYN scan only with ip.proto == 6 and tcp.flags == 2 and have identified areas with large amounts of these in a small space of time which prob proves a SYN scan happening.</description>
    </item>
    
    <item>
      <title>as a full call filter h323</title>
      <link>/questions/9997/as-a-full-call-filter-h323/</link>
      <pubDate>Fri, 06 Apr 2012 13:38:00 +0000</pubDate>
      
      <guid>/questions/9997/as-a-full-call-filter-h323/</guid>
      <description>as a full call filter h323  0 Hello, I could filter a multi protocol h323 calls these sentence q931.calling_party_number.digits contains &#34;223288923&#34; / h225.guid == c0fef93e-cd9e-d611-9ab2-000476222017, but I can only filter the H225, I would like to see the accompanying h245 in that call, anyone have any idea
regards
h323asked 06 Apr &#39;12, 13:38
sabayon
1●1●1●1
accept rate: 0%
You could add a filter for the q931 call Id(s)of the filtered packets to get the H.</description>
    </item>
    
    <item>
      <title>conversation duration with command line tools</title>
      <link>/questions/9998/conversation-duration-with-command-line-tools/</link>
      <pubDate>Fri, 06 Apr 2012 13:39:00 +0000</pubDate>
      
      <guid>/questions/9998/conversation-duration-with-command-line-tools/</guid>
      <description>conversation duration with command line tools  1 I need the values Rel Start and duration that is displayed in Wireshark conversation list window. However tshark does not provide these columns. So how can i get this information from the command line or is there any way to forward this output info into a text file from the command line.
Thanks
conversationlistasked 06 Apr &#39;12, 13:39
esmayildirim
16●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to get the .txt file back to wireshark?</title>
      <link>/questions/10000/how-to-get-the-txt-file-back-to-wireshark/</link>
      <pubDate>Fri, 06 Apr 2012 16:29:00 +0000</pubDate>
      
      <guid>/questions/10000/how-to-get-the-txt-file-back-to-wireshark/</guid>
      <description>How to get the .txt file back to wireshark?  0 An engineer from our group went to customer site and capture their system using Wireshark. Unfortunately he exported the files each time he capture rather than use the save button on the Wireshark... all these exported files are .txt, and we cannot get them back to wireshark... Can anyone help how we can get these .txt files back to wireshark?</description>
    </item>
    
    <item>
      <title>Ralink usb wireless</title>
      <link>/questions/10004/ralink-usb-wireless/</link>
      <pubDate>Fri, 06 Apr 2012 23:29:00 +0000</pubDate>
      
      <guid>/questions/10004/ralink-usb-wireless/</guid>
      <description>Ralink usb wireless  0 I have a USB Dongle WIFI Device. - DEVICE INSTANCE = USB\VID_148F&amp;amp;PID_3070\1.0
(which translates to)
RAILINK RT3070
Which integrates a CMOS RF, MAC, Baseband and USB interface into a single-chip.
They fully comply with IEEE 802.11a/b/g/n and IEEE 802.11b/g/n
Drivers are Ralink - UTILITY = 4.1.3.0
DRIVER = 3.2.4.0
SDK = 1.1.2.0
Shows up as &#34;Wireless Network Connection 8&#34; at Windoze level.
Wireshark see&#39;s it as &#34;</description>
    </item>
    
    <item>
      <title>No Interfaces - Windows</title>
      <link>/questions/10008/no-interfaces-windows/</link>
      <pubDate>Sat, 07 Apr 2012 01:58:00 +0000</pubDate>
      
      <guid>/questions/10008/no-interfaces-windows/</guid>
      <description>No Interfaces - Windows  0 I have recently installed WireShark and WinPCap. During the install, everything seemed to be fine. During my first launch, I got an error somewhere along the lines of &#34;Child dumpcap closed sync pipe prematurely.&#34; I read and read and read to finding no solution. I unistalled everything, re-downloaded the 1.7.1 Developer version of WireShark and downloaded WinPCap version 4.1.2 directly from winpcap.org.
After installing both, I now get no errors, but also have no interfaces like before.</description>
    </item>
    
    <item>
      <title>can wireshark be installed on an iPad or iPhone?</title>
      <link>/questions/10010/can-wireshark-be-installed-on-an-ipad-or-iphone/</link>
      <pubDate>Sat, 07 Apr 2012 16:22:00 +0000</pubDate>
      
      <guid>/questions/10010/can-wireshark-be-installed-on-an-ipad-or-iphone/</guid>
      <description>can wireshark be installed on an iPad or iPhone?  0 I would like to know if wireshark or any other packet catcher can be installed on the Ipad2. 64gig,safari browser. newest version
ipad download safari wiresharkasked 07 Apr &#39;12, 16:22
redbud702
1●1●1●1
accept rate: 0%
 edited 07 Apr &#39;12, 22:42 
Guy Harris ♦♦
17.4k●3●35●196
Since this is the top google result for &#34;ios wireshark&#34;: https://ask.wireshark.org/questions/17559/packet-capturing-application-for-the-iphone/36881
(09 Mar &#39;15, 19:17) bennettp123</description>
    </item>
    
    <item>
      <title>Copying displayed fields</title>
      <link>/questions/10015/copying-displayed-fields/</link>
      <pubDate>Sun, 08 Apr 2012 10:12:00 +0000</pubDate>
      
      <guid>/questions/10015/copying-displayed-fields/</guid>
      <description>Copying displayed fields  0 Hello Sir, I want to copy displayed fields e.g. time and packet length only. I want to use only these fields for further processing of my dataset. How can I do that?
copyingasked 08 Apr &#39;12, 10:12
chandu85420
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Have you looked at tshark, the command line version of Wireshark? Using the options -T fields -e frame.</description>
    </item>
    
    <item>
      <title>Capturing handshake packets</title>
      <link>/questions/10016/capturing-handshake-packets/</link>
      <pubDate>Sun, 08 Apr 2012 13:31:00 +0000</pubDate>
      
      <guid>/questions/10016/capturing-handshake-packets/</guid>
      <description>Capturing handshake packets  0 Hi to all! I&#39;m using Wireshark in BackTrack, with an Alfa AWUS036H as wireless interface, put in monitor mode. I&#39;m trying to analyze the traffic in my wireless network: if there&#39;s no protection, I can capture the packets and analyze them; if the network is protected with WPA, following this guide: http://wiki.wireshark.org/HowToDecrypt802.11
I added the wpa-psk in the preferences. So, I can capture the packets, but I can&#39;t decrypt them.</description>
    </item>
    
    <item>
      <title>Making a dissector that filters packets</title>
      <link>/questions/10022/making-a-dissector-that-filters-packets/</link>
      <pubDate>Mon, 09 Apr 2012 01:09:00 +0000</pubDate>
      
      <guid>/questions/10022/making-a-dissector-that-filters-packets/</guid>
      <description>Making a dissector that filters packets  0 Hi! What I wonder is, how can you make so that your dissector compares the next packet to the previous one? I want to make so that if the next packet has the same data as the previous one, it wont be displayed. I dont want to show a large amount of packtes in a row that are identical, I only want to show packets where some change has been made to the data.</description>
    </item>
    
    <item>
      <title>command line option for &amp;quot;Follow tcp stream&amp;quot;</title>
      <link>/questions/10023/command-line-option-for-follow-tcp-stream/</link>
      <pubDate>Mon, 09 Apr 2012 01:48:00 +0000</pubDate>
      
      <guid>/questions/10023/command-line-option-for-follow-tcp-stream/</guid>
      <description>command line option for &amp;ldquo;Follow tcp stream&amp;rdquo;  2 2Hi , Is there any command line option to generate &#34;Follow tcp stream&#34;(which is availabe in GUI) ,so that we can look at the messages which are exchanged between the apllications as a whole with out having the message broken in multiple parts. Basically i wanted to track all the payload which are getting exchanged between th applications..and write it to some file.</description>
    </item>
    
    <item>
      <title>[closed] How to clear the possibly delay SACK in SCTP associations of type M2PA?</title>
      <link>/questions/10024/how-to-clear-the-possibly-delay-sack-in-sctp-associations-of-type-m2pa/</link>
      <pubDate>Mon, 09 Apr 2012 01:50:00 +0000</pubDate>
      
      <guid>/questions/10024/how-to-clear-the-possibly-delay-sack-in-sctp-associations-of-type-m2pa/</guid>
      <description>[closed] How to clear the possibly delay SACK in SCTP associations of type M2PA?  0 Hello
1)what are the Causes for delay SACK in SCTP associations ? 2)How to clear the possibly delay SACK in SCTP associations of type M2PA? 3)Whether CRC32 Checksum off loading is related to delay SACK in SCTP associations?
Request to reply my queries at the earliest.
Regards Pradeep Doddawad
delay associations sctp sack inasked 09 Apr &#39;12, 01:50</description>
    </item>
    
    <item>
      <title>tcp.length 1460 for downloads</title>
      <link>/questions/10034/tcplength-1460-for-downloads/</link>
      <pubDate>Mon, 09 Apr 2012 12:35:00 +0000</pubDate>
      
      <guid>/questions/10034/tcplength-1460-for-downloads/</guid>
      <description>tcp.length 1460 for downloads  0 If the TCP length is always set to 1460 for a file tranfer download, but it&#39;s up to 10 times that amount for the same file uploaded, what could be a contributing factor?
length 1460 tcpasked 09 Apr &#39;12, 12:35
dij
5●1●1●3
accept rate: 0%
  
One Answer:
  
3 It&#39;s probably because you&#39;re capturing on the uploading PC, and that PC uses LSO (Large Send Offloading) to have the network interface card handle the segmentation into 1460 byte segments.</description>
    </item>
    
    <item>
      <title>Calling MAC-LTE dissector from my own dissector</title>
      <link>/questions/10038/calling-mac-lte-dissector-from-my-own-dissector/</link>
      <pubDate>Tue, 10 Apr 2012 00:27:00 +0000</pubDate>
      
      <guid>/questions/10038/calling-mac-lte-dissector-from-my-own-dissector/</guid>
      <description>Calling MAC-LTE dissector from my own dissector  0 Hi All
I am building a dissector that is my own.
After dissecting my past of the packet (which is successfully done) i would now also like to dissect the payload that it carries
It carries LTE MAC payload.
How should i start this. Is there any tutorial to do these kind of nested packet dissection.
Please suggest
dissection packet nestedasked 10 Apr &#39;12, 00:27</description>
    </item>
    
    <item>
      <title>[closed] How can I compare two Gtkwidget pointers?</title>
      <link>/questions/10040/how-can-i-compare-two-gtkwidget-pointers/</link>
      <pubDate>Tue, 10 Apr 2012 03:03:00 +0000</pubDate>
      
      <guid>/questions/10040/how-can-i-compare-two-gtkwidget-pointers/</guid>
      <description>[closed] How can I compare two Gtkwidget pointers?  0 I want to compare values two Gtkwidget pointers for equality..... how can I do this?
I am trying to typecast it to int, but it isn&#39;t working...
Gtkwidget *a; Gtkwidget *b; if((int)a==(int)b) { //do something }development gtkasked 10 Apr &amp;lsquo;12, 03:03
prashanth cm
-1●2●2●3
accept rate: 0%
 closed 10 Apr &amp;lsquo;12, 07:30 
multipleinte&amp;hellip;
1.3k●15●23●40

The question has been closed for the following reason &amp;ldquo;Question is off-topic or not relevant.</description>
    </item>
    
    <item>
      <title>SSL decrypting when Browser in play ??</title>
      <link>/questions/10045/ssl-decrypting-when-browser-in-play/</link>
      <pubDate>Tue, 10 Apr 2012 12:37:00 +0000</pubDate>
      
      <guid>/questions/10045/ssl-decrypting-when-browser-in-play/</guid>
      <description>SSL decrypting when Browser in play ??  0 I am trying to decrypt a complete SSL session using wireshark (and then will use tshark). I have the server private key and can see wireshark decrypting return traffic from server to client. However, the client sourced traffic is not decrypted (I can&#39;t see the decrypted GET). I am using the Internet Explorer browser on a Win7 system. Wireshark is running on the Win7 system.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t decode TCAP ANSI over MTP-2 frame.</title>
      <link>/questions/10046/cant-decode-tcap-ansi-over-mtp-2-frame/</link>
      <pubDate>Tue, 10 Apr 2012 12:48:00 +0000</pubDate>
      
      <guid>/questions/10046/cant-decode-tcap-ansi-over-mtp-2-frame/</guid>
      <description>Can&amp;rsquo;t decode TCAP ANSI over MTP-2 frame.  0 Hi Guys,
I&#39;m trying to open a TCAP ANSI trace that is over MTP-2, but Wireshark decodes the lower layers (MTP-2 and MTP-3) as Ethernet. I tried to force the decode to MTP-2 using &#34;Decode As...&#34; but couldn&#39;t find such option.
Below you can an example:
c0 af 28 83 22 73 02 02 e6 e1 0b 09 80 03 05 0a</description>
    </item>
    
    <item>
      <title>Not capturing RoIP multicast traffic</title>
      <link>/questions/10049/not-capturing-roip-multicast-traffic/</link>
      <pubDate>Tue, 10 Apr 2012 16:42:00 +0000</pubDate>
      
      <guid>/questions/10049/not-capturing-roip-multicast-traffic/</guid>
      <description>Not capturing RoIP multicast traffic  0 I have a Telex Radio over IP multicast network and have had trouble getting it to pass over a carrier&#39;s ethernet link. I am trying to make sure the traffic is getting out to the carrier network. I have simplified the network to a minimum configuration for troubleshooting, so I have a radio console connected to a Linksys SF300-24 switch, connected to the Telex IP-223 (radio controller), then connected to the radio.</description>
    </item>
    
    <item>
      <title>Log File that detects DoS</title>
      <link>/questions/10051/log-file-that-detects-dos/</link>
      <pubDate>Wed, 11 Apr 2012 01:42:00 +0000</pubDate>
      
      <guid>/questions/10051/log-file-that-detects-dos/</guid>
      <description>Log File that detects DoS  0 I would like to get a log file that contains Denial of Service (Dos) attack events from WireShark. May i know how i do i get it using Wireshark?
dos logasked 11 Apr &#39;12, 01:42
misteryuku
20●24●26●30
accept rate: 0%
You need the tshark option --DOS. Unfortunately that hasn&#39;t been implemented yet.
If you explain a bit more about your requirements, e.g. what you think a DOS attack event looks like, then we can tell you how to use Wireshark to show the information.</description>
    </item>
    
    <item>
      <title>GSM traffic analysis</title>
      <link>/questions/10057/gsm-traffic-analysis/</link>
      <pubDate>Wed, 11 Apr 2012 08:00:00 +0000</pubDate>
      
      <guid>/questions/10057/gsm-traffic-analysis/</guid>
      <description>GSM traffic analysis  0 Is it possible to use Wireshark to capture GSM traffic using a GSM dongle
gsm capture-setupasked 11 Apr &#39;12, 08:00
PhilD
1●1●1●1
accept rate: 0%
  
One Answer:
  
1No, the dongle makes it possible to connect to internet it will not forward the comunication with the GSM network.
answered 11 Apr &#39;12, 12:43
Anders ♦
4.6k●9●52
accept rate: 17%
     </description>
    </item>
    
    <item>
      <title>Will this switch work with wireshark?</title>
      <link>/questions/10059/will-this-switch-work-with-wireshark/</link>
      <pubDate>Wed, 11 Apr 2012 10:24:00 +0000</pubDate>
      
      <guid>/questions/10059/will-this-switch-work-with-wireshark/</guid>
      <description>Will this switch work with wireshark?  0 I need to monitorate a VOIP call that have some errors, I found this switch:
http://www.ebay.com/itm/8-Port-Nway-Network-TAP-10-100-Fast-Ethernet-LAN-Switch-/300691168886?pt=COMP_EN_Hubs&amp;amp;hash=item4602971e76#ht_4342wt_1344
Will it work?
switchasked 11 Apr &#39;12, 10:24
Julian
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Doesn&#39;t look like it has a span/monitor port feature, at least it doesn&#39;t say anything about being configurable or packing a hard wired monitor port. I wouldn&#39;t buy it - it&#39;s cheap, but it probably won&#39;t do what you need.</description>
    </item>
    
    <item>
      <title>VLAN Tagging with different versions of Wireshark</title>
      <link>/questions/10060/vlan-tagging-with-different-versions-of-wireshark/</link>
      <pubDate>Wed, 11 Apr 2012 11:44:00 +0000</pubDate>
      
      <guid>/questions/10060/vlan-tagging-with-different-versions-of-wireshark/</guid>
      <description>VLAN Tagging with different versions of Wireshark  0 Wireshark version 1.2.11 grabs the VLAN tag in FC_ELS frame but 1.4.6 doesn’t. Running on an ESXi5 or ESXi4, VM1 has Wireshark 1.2.11 and VM2 has Wireshark 1.4.6; both VMs are in the same VM Network in Networking using the same 10GigE adapter to access the network.
VM1 platform is Ubuntu version 10.10 with Wireshark 1.2.11 VM2 platform is Ubuntu version 11.</description>
    </item>
    
    <item>
      <title>[Window size scaling factor: -1 (unknown)]</title>
      <link>/questions/10071/window-size-scaling-factor-1-unknown/</link>
      <pubDate>Wed, 11 Apr 2012 18:04:00 +0000</pubDate>
      
      <guid>/questions/10071/window-size-scaling-factor-1-unknown/</guid>
      <description>[Window size scaling factor: -1 (unknown)]  0 What does this mean in a summary of the trace file? [Window size scaling factor: -1 (unknown)]
I captured it on a linux server with tcpdump and am reading the file on a Windows PC with Wireshark.
scaling window factor sizeasked 11 Apr &#39;12, 18:04
godfreydanials
1●1●1●1
accept rate: 0%
  
One Answer:
  
4It means that the trace file does not contain the TCP three-way handshake, so Wireshark does not know whether window scaling is in use, and if it is, what the window scaling factor is.</description>
    </item>
    
    <item>
      <title>How to use tshark option for Wireshark 1.6.7</title>
      <link>/questions/10075/how-to-use-tshark-option-for-wireshark-167/</link>
      <pubDate>Wed, 11 Apr 2012 19:24:00 +0000</pubDate>
      
      <guid>/questions/10075/how-to-use-tshark-option-for-wireshark-167/</guid>
      <description>How to use tshark option for Wireshark 1.6.7  0 Hello professionals, I am very new to Wireshark. May i know how do i start using the tshark option?
tsharkasked 11 Apr &#39;12, 19:24
misteryuku
20●24●26●30
accept rate: 0%
  
2 Answers:
  
1The best place to start is with the man page! Either type &#34;man tshark&#34; on your linux/unix command line, or check it out on line: http://www.</description>
    </item>
    
    <item>
      <title>How do I check the synchronization of audo/video RTP streams?</title>
      <link>/questions/10080/how-do-i-check-the-synchronization-of-audovideo-rtp-streams/</link>
      <pubDate>Wed, 11 Apr 2012 22:06:00 +0000</pubDate>
      
      <guid>/questions/10080/how-do-i-check-the-synchronization-of-audovideo-rtp-streams/</guid>
      <description>How do I check the synchronization of audo/video RTP streams?  0 1I am currently analyzing the RTP packets captured in a video call. I see that there are two RTP streams: one for audio and one for video. Is there a way to check how the synchronization is happening between audio and video?
I have looked at the timestamp field in the RTP packet, but it was of no use.</description>
    </item>
    
    <item>
      <title>How do I run TShark on Windows?</title>
      <link>/questions/10087/how-do-i-run-tshark-on-windows/</link>
      <pubDate>Wed, 11 Apr 2012 23:51:00 +0000</pubDate>
      
      <guid>/questions/10087/how-do-i-run-tshark-on-windows/</guid>
      <description>How do I run TShark on Windows?  0 how do i do tshark on windows 7?
windows tsharkasked 11 Apr &#39;12, 23:51
misteryuku
20●24●26●30
accept rate: 0%
 converted 12 Apr &#39;12, 10:19 
Guy Harris ♦♦
17.4k●3●35●196
  
2 Answers:
  
1Two other methods, both require you to open a command prompt:
Provide the path to tshark as part of the command, e.g. &#34;C:\Program Files\Wireshark\tshark.</description>
    </item>
    
    <item>
      <title>Capture Options on wireshark</title>
      <link>/questions/10089/capture-options-on-wireshark/</link>
      <pubDate>Thu, 12 Apr 2012 02:48:00 +0000</pubDate>
      
      <guid>/questions/10089/capture-options-on-wireshark/</guid>
      <description>Capture Options on wireshark  0 Based on what i read from a forum : http://ask.wireshark.org/questions/1709/automatically-start-capturing-packets-when-bandwidth-is-high
Ninjadude101 wants to capture log events that contains DoS attack from WireShark.
hansangb told him to open the capture options (CTRL-K)
I don&#39;t understand and how to go to the capture options on wireshark??
captureasked 12 Apr &#39;12, 02:48
misteryuku
20●24●26●30
accept rate: 0%
  
One Answer:
  
0You need to start reading the very fine manual, as seen here.</description>
    </item>
    
    <item>
      <title>How to clear the gui.window_title option from the command-line?</title>
      <link>/questions/10095/how-to-clear-the-guiwindow_title-option-from-the-command-line/</link>
      <pubDate>Thu, 12 Apr 2012 14:01:00 +0000</pubDate>
      
      <guid>/questions/10095/how-to-clear-the-guiwindow_title-option-from-the-command-line/</guid>
      <description>How to clear the gui.window_title option from the command-line?  0 I am running Wireshark 1.6.6 on Windows XP SP3 (32-bit). Previously, a custom window title had been added through the Edit -&amp;gt; Preferences -&amp;gt; Layout -&amp;gt; Custom window title preference. Now I want to be able to start Wireshark from the command-line (or a Windows shortcut) and have that window title cleared out, but I have been unsuccessful at doing so.</description>
    </item>
    
    <item>
      <title>This is a test for a bug in OSQA&amp;#x27;s backslash handling - don&amp;#x27;t delete it, just ignore it</title>
      <link>/questions/10096/this-is-a-test-for-a-bug-in-osqas-backslash-handling-dont-delete-it-just-ignore-it/</link>
      <pubDate>Thu, 12 Apr 2012 15:48:00 +0000</pubDate>
      
      <guid>/questions/10096/this-is-a-test-for-a-bug-in-osqas-backslash-handling-dont-delete-it-just-ignore-it/</guid>
      <description>This is a test for a bug in OSQA&amp;rsquo;s backslash handling - don&amp;rsquo;t delete it, just ignore it  0 If, in a question:
I type &#34;UN&#34; {backslash} {asterisk} &#34;X&#34;, it comes out as UN\*X, with a backslash before the asterisk.
I type {backquote} &#34;C&#34; &#34;:&#34; {backslash} &#34;Program Files&#34; {backslash} &#34;Wireshark&#34; {backquote}, it comes out as C:\\Program Files\\Wireshark, with both backslashes doubled.
osqaasked 12 Apr &#39;12, 15:48
Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>[closed] Getting MORE sample wireshark crack traces (.pcap files) with DoS (Anyone else? any more suggestions??)</title>
      <link>/questions/10101/getting-more-sample-wireshark-crack-traces-pcap-files-with-dos-anyone-else-any-more-suggestions/</link>
      <pubDate>Thu, 12 Apr 2012 17:59:00 +0000</pubDate>
      
      <guid>/questions/10101/getting-more-sample-wireshark-crack-traces-pcap-files-with-dos-anyone-else-any-more-suggestions/</guid>
      <description>[closed] Getting MORE sample wireshark crack traces (.pcap files) with DoS (Anyone else? any more suggestions??)  0 Dear Sir/Madam,
I would like to get MORE sample wireshark traces (.cap or .pcap files) that contains Denial of Service events that comes from Wireshark. I have gotten one sample trace for SYN-Flood and one sample trace for Teardrop attack (already have them). Can anyone provide MORE sample traces that contain the following DoS attacks?</description>
    </item>
    
    <item>
      <title>Capturing packets to a file using Wireshark&amp;#x27;s Capture options.</title>
      <link>/questions/10105/capturing-packets-to-a-file-using-wiresharks-capture-options/</link>
      <pubDate>Fri, 13 Apr 2012 00:56:00 +0000</pubDate>
      
      <guid>/questions/10105/capturing-packets-to-a-file-using-wiresharks-capture-options/</guid>
      <description>Capturing packets to a file using Wireshark&amp;rsquo;s Capture options.  0 I went to the Wireshark&#39;s caputure options and created file name, check use multiple files, determine the rotation of files, check ring buffer with x files, how many files to create...? The files are generated and when i opened up the files, i saw many unreadable characters on the windows 7 notepad file. Why is this so? I want to get the events in the windows 7 notepad file as readable logs.</description>
    </item>
    
    <item>
      <title>How can I use a global variable from a dissector in gtk code?</title>
      <link>/questions/10113/how-can-i-use-a-global-variable-from-a-dissector-in-gtk-code/</link>
      <pubDate>Fri, 13 Apr 2012 01:47:00 +0000</pubDate>
      
      <guid>/questions/10113/how-can-i-use-a-global-variable-from-a-dissector-in-gtk-code/</guid>
      <description>How can I use a global variable from a dissector in gtk code?  0 I have a global variable in a .c file in the dissectors/ folder. How do I use it in another .c file in the gtk/ folder? Every time I try using extern, I get an &#34;undefined reference&#34; error. I am able to use the same variable in another .c file in the epan/ folder. Is there anything I am missing?</description>
    </item>
    
    <item>
      <title>Give a name to an ip in lua wireshark</title>
      <link>/questions/10120/give-a-name-to-an-ip-in-lua-wireshark/</link>
      <pubDate>Fri, 13 Apr 2012 02:34:00 +0000</pubDate>
      
      <guid>/questions/10120/give-a-name-to-an-ip-in-lua-wireshark/</guid>
      <description>Give a name to an ip in lua wireshark  0 Hi,
how can i give a name to an ip address of a tcp packet in lua?
(I want to see in wireshark a name instead of the ip address).
Thanks.
lua dissector wiresharkasked 13 Apr &#39;12, 02:34
Zvika
6●2●2●4
accept rate: 0%
  
One Answer:
  
0Name resolution and Lua are independent of each other; and Wireshark Lua has no built-in API to control name resolution, but you can do it with the following instructions (untested).</description>
    </item>
    
    <item>
      <title>New to WireShark &amp;amp; Networks</title>
      <link>/questions/10122/new-to-wireshark-networks/</link>
      <pubDate>Fri, 13 Apr 2012 04:26:00 +0000</pubDate>
      
      <guid>/questions/10122/new-to-wireshark-networks/</guid>
      <description>New to WireShark &amp;amp; Networks  0 I run a small business and have network problems from time to time. I am very interested in broadening my knowledge and also get to grips with WireShark.
As this is a new field and I have limited knowledge about Networks, please can someone direct me in where to start, maybe literature, videos and/or websites that will help me. I&#39;ve read through the WireShark Manual and looked at some of the linked videos, but I think I need to get a grip on Networks first.</description>
    </item>
    
    <item>
      <title>what version to install on Snow Leopard but 32-bit processor?</title>
      <link>/questions/10132/what-version-to-install-on-snow-leopard-but-32-bit-processor/</link>
      <pubDate>Fri, 13 Apr 2012 10:17:00 +0000</pubDate>
      
      <guid>/questions/10132/what-version-to-install-on-snow-leopard-but-32-bit-processor/</guid>
      <description>what version to install on Snow Leopard but 32-bit processor?  0 I have a MacBookPro with these specs: Model Name: MacBook Pro Model Identifier: MacBookPro1,2 Processor Name: Intel Core Duo Processor Speed: 2.16 GHz Number Of Processors: 1 Total Number Of Cores: 2 L2 Cache: 2 MB Memory: 2 GB Bus Speed: 667 MHz
What version of Wireshark do I need to install? The download page says OS X 10.</description>
    </item>
    
    <item>
      <title>Change selected packet colors.</title>
      <link>/questions/10134/change-selected-packet-colors/</link>
      <pubDate>Fri, 13 Apr 2012 10:38:00 +0000</pubDate>
      
      <guid>/questions/10134/change-selected-packet-colors/</guid>
      <description>Change selected packet colors.  0 I see how to change the colors of foreground (characters) &amp;amp; background in a captured trace, but when I select a packet it&#39;s white on light green and barely readable. It doesn&#39;t matter which pre-selected packet coloring is applied. (I.E. Bad TCP is Red on Black but when selected it&#39;s white on light green.)
How do I change the colors of a selected packet to something easier to see?</description>
    </item>
    
    <item>
      <title>Wireshark core dump while dissecting http traffic capture</title>
      <link>/questions/10135/wireshark-core-dump-while-dissecting-http-traffic-capture/</link>
      <pubDate>Fri, 13 Apr 2012 11:00:00 +0000</pubDate>
      
      <guid>/questions/10135/wireshark-core-dump-while-dissecting-http-traffic-capture/</guid>
      <description>Wireshark core dump while dissecting http traffic capture  0 Hi all,
I&#39;m using wireshark to decode traffic captures in order to login requests/answers from a web service.
My current version is:
bash-3.00$ /usr/local/bin/tshark -v TShark 1.6.4 (SVN Rev Unknown from unknown)
Copyright 1998-2011 Gerald Combs [email protected] and contributors. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t Capture HTTP from other computers</title>
      <link>/questions/10142/cant-capture-http-from-other-computers/</link>
      <pubDate>Fri, 13 Apr 2012 18:19:00 +0000</pubDate>
      
      <guid>/questions/10142/cant-capture-http-from-other-computers/</guid>
      <description>Can&amp;rsquo;t Capture HTTP from other computers  0 I have my PC with wireshark on it, and my laptop (the target) connected via ethernet to a dumb hub, which in turn is connected to my XFINITY router.
The hub is a true dumb hub, and I also used a small network tap and got the same results, so the hub is not the problem.
I can surf the internet from my PC and from my laptop.</description>
    </item>
    
    <item>
      <title>Packet loss of any medium.</title>
      <link>/questions/10148/packet-loss-of-any-medium/</link>
      <pubDate>Sat, 14 Apr 2012 14:10:00 +0000</pubDate>
      
      <guid>/questions/10148/packet-loss-of-any-medium/</guid>
      <description>Packet loss of any medium.  0 Hai,
Can any one tell me about how to calculate the BER or Packet loss using the Wireshark or any idea using its tools?.
Since every protocol has a checksum mechanism, so is it possible to know the packets lost or the number of re-transmissions done by using the filters?.
Thank you in Advance.
packetlossasked 14 Apr &#39;12, 14:10
reddy
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Not capturing anything</title>
      <link>/questions/10151/not-capturing-anything/</link>
      <pubDate>Sat, 14 Apr 2012 22:47:00 +0000</pubDate>
      
      <guid>/questions/10151/not-capturing-anything/</guid>
      <description>Not capturing anything  0 Hi
I&#39;ve installed wireshark on my PC but when I am connected to the Internet and have Wireshark running a capture, it is not capturing anything.
I have no idea what I&#39;m doing wrong - any suggestions?
Thanks in advance
captureasked 14 Apr &#39;12, 22:47
jasial
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Did you make sure you are capturing on the right interface, you may be capturing on the PPP interface instead of the Ethernet interface.</description>
    </item>
    
    <item>
      <title>How can I find my 3G network card in the &amp;#x27;interface&amp;#x27;?</title>
      <link>/questions/10154/how-can-i-find-my-3g-network-card-in-the-interface/</link>
      <pubDate>Sat, 14 Apr 2012 23:28:00 +0000</pubDate>
      
      <guid>/questions/10154/how-can-i-find-my-3g-network-card-in-the-interface/</guid>
      <description>How can I find my 3G network card in the &amp;lsquo;interface&amp;rsquo;?  0 Test system1: Windows7 home edition Software ver.: wireshark-win64-1.6.7.exe Question: Afer the installation of wireshark, I run it, I can see my 3G network card(Huawei E367) on the dailog: capture-- interface. Second day, I run wireshark again, but I can&#39;t find my 3G network card. I check the NPF driver, it is normal running. Why? Test system2: Windows xp professional Software ver.</description>
    </item>
    
    <item>
      <title>How to open wireshark in unprivileged mode from command line?</title>
      <link>/questions/10161/how-to-open-wireshark-in-unprivileged-mode-from-command-line/</link>
      <pubDate>Sun, 15 Apr 2012 10:01:00 +0000</pubDate>
      
      <guid>/questions/10161/how-to-open-wireshark-in-unprivileged-mode-from-command-line/</guid>
      <description>How to open wireshark in unprivileged mode from command line?  0 I am working on a machine without root access. When I open wireshark on it I get the following pop up: http://tinypic.com/r/2v9x6qg/5
Now when I remotely login to the machine using SSH, it asks me for the root password and does not allow me to run wireshark in unpriviliged mode. Is there a command line option which can help me do so?</description>
    </item>
    
    <item>
      <title>Using the wireshark pcap file capture data as Splunk Log Data</title>
      <link>/questions/10165/using-the-wireshark-pcap-file-capture-data-as-splunk-log-data/</link>
      <pubDate>Sun, 15 Apr 2012 18:51:00 +0000</pubDate>
      
      <guid>/questions/10165/using-the-wireshark-pcap-file-capture-data-as-splunk-log-data/</guid>
      <description>Using the wireshark pcap file capture data as Splunk Log Data  0 Can i use the wireshark pcap file capture data and store the data into Splunk for indexing?
capture pcap splunkasked 15 Apr &#39;12, 18:51
misteryuku
20●24●26●30
accept rate: 0%
 edited 15 Apr &#39;12, 18:51 
  
2 Answers:
  
0Probably. Using either Wireshark, or more likely tshark and setting options to output only the fields required and using a csv format the data could be fed into Splunk.</description>
    </item>
    
    <item>
      <title>Online Tutorial for reading packet capture files</title>
      <link>/questions/10166/online-tutorial-for-reading-packet-capture-files/</link>
      <pubDate>Sun, 15 Apr 2012 22:03:00 +0000</pubDate>
      
      <guid>/questions/10166/online-tutorial-for-reading-packet-capture-files/</guid>
      <description>Online Tutorial for reading packet capture files  0 Hi professionals, is there any online tutorial that teaches beginners on how to read packet captures of a pcap file?
tutorials pcapasked 15 Apr &#39;12, 22:03
misteryuku
20●24●26●30
accept rate: 0%
  
One Answer:
  
2Have a look at the presentations from previous SharkFest events. In particular see I&#39;ve downloaded Wireshark ... Now What? by Betty Dubois.</description>
    </item>
    
    <item>
      <title>How do I decode my mobile capture?</title>
      <link>/questions/10167/how-do-i-decode-my-mobile-capture/</link>
      <pubDate>Sun, 15 Apr 2012 22:42:00 +0000</pubDate>
      
      <guid>/questions/10167/how-do-i-decode-my-mobile-capture/</guid>
      <description>How do I decode my mobile capture?  0 Hi,
I have this problem. To try and figure out what the problem is I have created two dumps, one over Wifi and one over 3G / HSDPA by running tcpdump on the Android device.
The Wifi dump is decoded by Wireshark no problem.
But the 3G dump isn&#39;t very helpful.
Does anyone know how I can get Wireshark to decode this data so I can figure out what the problem might be?</description>
    </item>
    
    <item>
      <title>Start making commands for tshark</title>
      <link>/questions/10172/start-making-commands-for-tshark/</link>
      <pubDate>Mon, 16 Apr 2012 01:05:00 +0000</pubDate>
      
      <guid>/questions/10172/start-making-commands-for-tshark/</guid>
      <description>Start making commands for tshark  0 My PC is running windows 7 and I opened the tshark.exe from the wireshark installation file in my computer folder. The program kept recurring messages. I am a beginner in using tshark and i would like to start making commands. How do i start making commands on tshark?
commands tsharkasked 16 Apr &#39;12, 01:05
misteryuku
20●24●26●30
accept rate: 0%
1MisterYuku, do me a favor and STOP creating new questions that are in the same topic as one you have already started.</description>
    </item>
    
    <item>
      <title>Covert the .pcap file to a .csv file using tshark</title>
      <link>/questions/10173/covert-the-pcap-file-to-a-csv-file-using-tshark/</link>
      <pubDate>Mon, 16 Apr 2012 01:10:00 +0000</pubDate>
      
      <guid>/questions/10173/covert-the-pcap-file-to-a-csv-file-using-tshark/</guid>
      <description>Covert the .pcap file to a .csv file using tshark  0 1What is the &#34;tshark&#34; command for to converting the .pcap file to a .csv file? The packet capture data will be monitored using Splunk.
conversion csv pcap tsharkasked 16 Apr &#39;12, 01:10
misteryuku
20●24●26●30
accept rate: 0%
  
One Answer:
  
1That depends on which particular fields you want to use in the CSV file.</description>
    </item>
    
    <item>
      <title>SCCP Protocol version?</title>
      <link>/questions/10182/sccp-protocol-version/</link>
      <pubDate>Mon, 16 Apr 2012 03:13:00 +0000</pubDate>
      
      <guid>/questions/10182/sccp-protocol-version/</guid>
      <description>SCCP Protocol version?  0 i use wireshark-win32-1.6.5. what sccp protocol version is supported for wireshark-win32-1.6.5 ?? i can&#39;t have some information in sccp packet.
sccpThis question is marked &#34;community wiki&#34;.asked 16 Apr &#39;12, 03:13
kernel7k
1●1●1●1
accept rate: 0%
What fields are missing? Keep in mind that if your MTP3 variant (ANSI or ITU or ???) is wrong, then the decoding of SCCP will be a train wreck because Wireshark will then not know where SCCP starts.</description>
    </item>
    
    <item>
      <title>SSL Descrypt _without_ specifying a protocol?</title>
      <link>/questions/10184/ssl-descrypt-_without_-specifying-a-protocol/</link>
      <pubDate>Mon, 16 Apr 2012 04:18:00 +0000</pubDate>
      
      <guid>/questions/10184/ssl-descrypt-_without_-specifying-a-protocol/</guid>
      <description>SSL Descrypt _without_ specifying a protocol?  0 Hi there,
Is there any way of NOT specifying a protocol when configuring Wireshark to automatically SSL decrypt (i.e. when adding the key to the RSA key list).
I have a custom app that uses SSL to protect its connections, and I&#39;d just like to decrypt the textual data that is passed. Instead, for now, I just put http, wireshark lists it as &#34;</description>
    </item>
    
    <item>
      <title>SSL Decryption Anomolies</title>
      <link>/questions/10189/ssl-decryption-anomolies/</link>
      <pubDate>Mon, 16 Apr 2012 07:42:00 +0000</pubDate>
      
      <guid>/questions/10189/ssl-decryption-anomolies/</guid>
      <description>SSL Decryption Anomolies  0 Still trying to use wiresharks SSL decryption service. I took Syn-Bits advise and used Data as the protocol decode for the SSL key. There are a few things I don&#39;t understand.
Why would the SSL dissector (or perhaps HTTP header decoder) document 2 data fields. The first data field is 1 byte long and contains the ASCII letter G. The second data field starts off with ASCII letters ET followed by the remainder of HTTP header.</description>
    </item>
    
    <item>
      <title>Absolute time in statistics from &amp;quot;tshark -z io,stat&amp;quot;</title>
      <link>/questions/10190/absolute-time-in-statistics-from-tshark-z-iostat/</link>
      <pubDate>Mon, 16 Apr 2012 09:50:00 +0000</pubDate>
      
      <guid>/questions/10190/absolute-time-in-statistics-from-tshark-z-iostat/</guid>
      <description>Absolute time in statistics from &amp;ldquo;tshark -z io,stat&amp;rdquo;  0 Hi,
To get some traffic statistics on multiple capture files in a folder, I am using a batch file running a simple tshark command e.g. &#34;tshark -z io,stat,1,ip.addr==1.2.3.4&#34; on each file one after the other, resulting in a large csv file containing the results.
Unluckily, the statistics generated by this command use Relative Time i.e. timestamps start at zero for each new file.</description>
    </item>
    
    <item>
      <title>Dissector for org specific TLVs in the 802.3 OAM protocol</title>
      <link>/questions/10195/dissector-for-org-specific-tlvs-in-the-8023-oam-protocol/</link>
      <pubDate>Mon, 16 Apr 2012 11:29:00 +0000</pubDate>
      
      <guid>/questions/10195/dissector-for-org-specific-tlvs-in-the-8023-oam-protocol/</guid>
      <description>Dissector for org specific TLVs in the 802.3 OAM protocol  0 I hope I am asking the right question. I have just started looking into making my own dissector for this.
I&#39;m trying to write a dissector in LUA that will parse a couple of org specific TLVs in the OAM protocol. I can&#39;t seem to wrap my head around the steps I&#39;d need to take to allow the built in dissector to do all the work it can, and only run my code when the frame contains the TLVs I care about.</description>
    </item>
    
    <item>
      <title>How to compile/build Wireshark 1.65 on RHEL?</title>
      <link>/questions/10197/how-to-compilebuild-wireshark-165-on-rhel/</link>
      <pubDate>Mon, 16 Apr 2012 12:28:00 +0000</pubDate>
      
      <guid>/questions/10197/how-to-compilebuild-wireshark-165-on-rhel/</guid>
      <description>How to compile/build Wireshark 1.65 on RHEL?  0 The Quick Setup only provided for UNIX and Windows. For UNIX, it did not give enough information on how to compile/build the wireshark exact what it gives the instruction for Windows.
The reason why I ask for the instruction on how to compile/build wireshark is because I need to run Fortify against wireshark on RHEL (Red Hat Enterprise Linux).
fortify rhel redhatasked 16 Apr &#39;12, 12:28</description>
    </item>
    
    <item>
      <title>Parser Error?</title>
      <link>/questions/10199/parser-error/</link>
      <pubDate>Mon, 16 Apr 2012 13:40:00 +0000</pubDate>
      
      <guid>/questions/10199/parser-error/</guid>
      <description>Parser Error?  0 I&#39;m running a packet capture on a x64 Windows Server 2008 R2 system running the latest version of x64 wireshark (1.6.7). Everytime I see the following packet, all traffic that is to follow is [Malformed Packet].
This particular packet is categorized as SMB2 and is connecting to this server on port 445. There are only two things that jump out at me as they are different from the other captured packets.</description>
    </item>
    
    <item>
      <title>a lot of retransmits, but no drops or significant delays</title>
      <link>/questions/10200/a-lot-of-retransmits-but-no-drops-or-significant-delays/</link>
      <pubDate>Mon, 16 Apr 2012 14:19:00 +0000</pubDate>
      
      <guid>/questions/10200/a-lot-of-retransmits-but-no-drops-or-significant-delays/</guid>
      <description>a lot of retransmits, but no drops or significant delays  0 We are troubleshooting connectivity issues across a layer two connection between sites across a provider. Users experience application hangs and timeouts when passing across this specific link.
Packet captures do NOT show packet DROPS, but show RE-TRANSMITS. It is the strangest thing.
Complete details here, I would have put the pcaps here, but i couldn&#39;t figure out how to attach.</description>
    </item>
    
    <item>
      <title>Transforming a .pcap file to a text file on windows 7 using tshark</title>
      <link>/questions/10205/transforming-a-pcap-file-to-a-text-file-on-windows-7-using-tshark/</link>
      <pubDate>Mon, 16 Apr 2012 18:16:00 +0000</pubDate>
      
      <guid>/questions/10205/transforming-a-pcap-file-to-a-text-file-on-windows-7-using-tshark/</guid>
      <description>Transforming a .pcap file to a text file on windows 7 using tshark  0 I want to transform a captured sample .pcap file stored in the windows 7 desktop into a text file on windows 7 command line cmd using tshark. I tried : C:&amp;gt;Program Files&amp;gt;Wireshark&amp;gt; tshark -V -r C:\Users\myName\Desktop\WiresharkLog\SynFlood Sample.pcap &amp;gt; C:\Users\myName\Desktop\logcapture.txt When i hit enter after entering this command, the message on the command line says &#34;access is denied.</description>
    </item>
    
    <item>
      <title>Wireshark doesnt reconize my wireless adapter Realtek</title>
      <link>/questions/10206/wireshark-doesnt-reconize-my-wireless-adapter-realtek/</link>
      <pubDate>Mon, 16 Apr 2012 20:26:00 +0000</pubDate>
      
      <guid>/questions/10206/wireshark-doesnt-reconize-my-wireless-adapter-realtek/</guid>
      <description>Wireshark doesnt reconize my wireless adapter Realtek  0 Hello, I dont know what happens, but Wireshark doesnt reconize my wireless adapter Realtek RTL8188CE Wireless LAN 802.11n . My adapter is OK, I can access my access point and I can run others applications. Please, any hint? I installed WS version 1.6.7 and Winpcap 1.4.2.
thanks!
Claudia
realtekasked 16 Apr &#39;12, 20:26
claudia1974
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>LPPa PDU can decode by wireshark ?</title>
      <link>/questions/10213/lppa-pdu-can-decode-by-wireshark/</link>
      <pubDate>Tue, 17 Apr 2012 00:21:00 +0000</pubDate>
      
      <guid>/questions/10213/lppa-pdu-can-decode-by-wireshark/</guid>
      <description>LPPa PDU can decode by wireshark ?  0 Dear All: Is the Wireshark can decode the LPPa-PDU in LPPa Transport Messages of S1AP protocol ? Anyone known it or give an example packet?
lppaasked 17 Apr &#39;12, 00:21
kwind
1●1●1●3
accept rate: 0%
 edited 17 Apr &#39;12, 00:22 
  
One Answer:
  
1It should be possible with the development version 1.7.1 or a recent buildbot build.</description>
    </item>
    
    <item>
      <title>Getting detailed 5-tuple flow information</title>
      <link>/questions/10214/getting-detailed-5-tuple-flow-information/</link>
      <pubDate>Tue, 17 Apr 2012 01:52:00 +0000</pubDate>
      
      <guid>/questions/10214/getting-detailed-5-tuple-flow-information/</guid>
      <description>Getting detailed 5-tuple flow information  0 I am trying to analyse a file containing packets captured using tcpdump. I first want to categorize the packets into flows using 5-tuple. Then I need to get the size and inter-arrival time of each packet in each flow. I tried Conversation list in wireshark but it gives only the number of packets in the flow not information about each packet in the flow.</description>
    </item>
    
    <item>
      <title>Listen on other channels</title>
      <link>/questions/10222/listen-on-other-channels/</link>
      <pubDate>Tue, 17 Apr 2012 11:13:00 +0000</pubDate>
      
      <guid>/questions/10222/listen-on-other-channels/</guid>
      <description>Listen on other channels  0 Got it to work using tcpdump on backtrack and am curious now if it works as well for Wireshark. While using tcpdump, my iPad shows traffic in both directions (src and dst) on channel 44 (5.2 GHz). Channel 6 (2.437 GHz) for example just reports the response (SYN-ACK, ACK, FIN) but not the request (SYN). Is there an option to change channels in Wireshark? Looks like that one is just listening on channel 6 since I get the same response as on backtrack for that specific channel.</description>
    </item>
    
    <item>
      <title>Enquiry on Wireshark pcap file</title>
      <link>/questions/10227/enquiry-on-wireshark-pcap-file/</link>
      <pubDate>Tue, 17 Apr 2012 19:55:00 +0000</pubDate>
      
      <guid>/questions/10227/enquiry-on-wireshark-pcap-file/</guid>
      <description>Enquiry on Wireshark pcap file  0 I would like to know if a wireshark pcap file when converted to a windows 7 .txt file using the tshark command tshark -V -r {file} is considered a log file?
txt pcap logasked 17 Apr &#39;12, 19:55
misteryuku
20●24●26●30
accept rate: 0%
 edited 17 Apr &#39;12, 19:56 
  
2 Answers:
  
0No. It&#39;s a text file containing the dissection of the network data in the pcap file.</description>
    </item>
    
    <item>
      <title>Decoding a wireshark pcap file</title>
      <link>/questions/10228/decoding-a-wireshark-pcap-file/</link>
      <pubDate>Tue, 17 Apr 2012 22:21:00 +0000</pubDate>
      
      <guid>/questions/10228/decoding-a-wireshark-pcap-file/</guid>
      <description>Decoding a wireshark pcap file  0 Is there such thing as decoding a wireshark pcap file. Is decoding a pcap file the same as transforming a wireshark pcap file to a windows txt file?
txt pcap decodingasked 17 Apr &#39;12, 22:21
misteryuku
20●24●26●30
accept rate: 0%
  
3 Answers:
  
0No. See my answer to your other very similar question here
answered 17 Apr &#39;12, 23:54</description>
    </item>
    
    <item>
      <title>Getting logs out from the Wireshark&amp;#x27;s Capture pcap File</title>
      <link>/questions/10234/getting-logs-out-from-the-wiresharks-capture-pcap-file/</link>
      <pubDate>Wed, 18 Apr 2012 01:42:00 +0000</pubDate>
      
      <guid>/questions/10234/getting-logs-out-from-the-wiresharks-capture-pcap-file/</guid>
      <description>Getting logs out from the Wireshark&amp;rsquo;s Capture pcap File  0 I would like to get logs out of pcap files (the pcap file is converted to windows .txt file using tshark command tshark -V -r {file}) so that i can display these packet capture logs in Splunk. What is the most common,standard, correct way of getting logs out from the pcap files that are converted to windows 7 .txt file especially when i am going to show the logs in the Splunk?</description>
    </item>
    
    <item>
      <title>Capturing packet captures live</title>
      <link>/questions/10238/capturing-packet-captures-live/</link>
      <pubDate>Wed, 18 Apr 2012 02:50:00 +0000</pubDate>
      
      <guid>/questions/10238/capturing-packet-captures-live/</guid>
      <description>Capturing packet captures live  0 Is it possible to capture packets live and store it into a pcap file then converting pcap to a windows txt file using tshark or windows shell scripting?
shell pcap tsharkasked 18 Apr &#39;12, 02:50
misteryuku
20●24●26●30
accept rate: 0%
  
2 Answers:
  
0tshark -i your_interface -V &amp;gt; your_path_to_text_file will write the text output directly to a file.
answered 18 Apr &#39;12, 03:06</description>
    </item>
    
    <item>
      <title>Wireshark crashes</title>
      <link>/questions/10240/wireshark-crashes/</link>
      <pubDate>Wed, 18 Apr 2012 05:24:00 +0000</pubDate>
      
      <guid>/questions/10240/wireshark-crashes/</guid>
      <description>Wireshark crashes  0 Hi, Wireshark crashes when i try to configure ssl preference .When i provide the location of .pem private key file in windows 7 and click on apply,wireshark crashes
sslasked 18 Apr &#39;12, 05:24
vikram
41●7●8●13
accept rate: 0%
  
One Answer:
  
0 Which version of Wireshark are you running? Are you running 64-bit or 32-bit Windows? Note that there&#39;s a known bug with SSL preferences in Wireshark 1.</description>
    </item>
    
    <item>
      <title>How can I get the payload using the command line</title>
      <link>/questions/10242/how-can-i-get-the-payload-using-the-command-line/</link>
      <pubDate>Wed, 18 Apr 2012 06:26:00 +0000</pubDate>
      
      <guid>/questions/10242/how-can-i-get-the-payload-using-the-command-line/</guid>
      <description>How can I get the payload using the command line  0 Hi , Is there any way to capture only the actual payload(say xml message) using command line. I am aware of using wireshark GUI and select Follow tcp stream which will show me the actaul payload(xml) message,can we achive the same thing using command line option Any help will be greatly appriciated
payload command-line tsharkasked 18 Apr &#39;12, 06:26</description>
    </item>
    
    <item>
      <title>See Data before encripted with HTTPS</title>
      <link>/questions/10246/see-data-before-encripted-with-https/</link>
      <pubDate>Wed, 18 Apr 2012 09:49:00 +0000</pubDate>
      
      <guid>/questions/10246/see-data-before-encripted-with-https/</guid>
      <description>See Data before encripted with HTTPS  0 Can I, with WireShark, see what data is being sent via HTTPS before it has been encripted?
encripted httpsasked 18 Apr &#39;12, 09:49
IraH
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1You can, in some cases, if you have enough information, decrypt the data after it has been encrypted and transmitted; see the Wireshark Wiki page about SSL.</description>
    </item>
    
    <item>
      <title>Field Columns on the Wireshark User Interface</title>
      <link>/questions/10254/field-columns-on-the-wireshark-user-interface/</link>
      <pubDate>Wed, 18 Apr 2012 17:49:00 +0000</pubDate>
      
      <guid>/questions/10254/field-columns-on-the-wireshark-user-interface/</guid>
      <description>Field Columns on the Wireshark User Interface  0 Dear Professionals,
I&#39;m a newbie in wireshark and i would like if there are other field columns on the wireshark UI interface other than No, time, source, destination, Protocol, length, info...................
columns wiresharkasked 18 Apr &#39;12, 17:49
misteryuku
20●24●26●30
accept rate: 0%
  
One Answer:
  
1Go to Edit -&amp;gt; Preferences -&amp;gt; User Interface/Columns and add whatever you like.</description>
    </item>
    
    <item>
      <title>Converting a wireshark pcap file to a windows txt file that contains field=value data.</title>
      <link>/questions/10256/converting-a-wireshark-pcap-file-to-a-windows-txt-file-that-contains-fieldvalue-data/</link>
      <pubDate>Wed, 18 Apr 2012 18:13:00 +0000</pubDate>
      
      <guid>/questions/10256/converting-a-wireshark-pcap-file-to-a-windows-txt-file-that-contains-fieldvalue-data/</guid>
      <description>Converting a wireshark pcap file to a windows txt file that contains field=value data.  0 What is the tshark command for converting a wireshark pcap file to a windows .txt file that will result in the output in the windows .txt file shown below? (The x&#39;s represents a numeric value of the ip address.)
Sample output : No=1,Time=0.000000,source=xxx.xxx.xxx.xxx,Destination=xxx.xxx.xxx.xxx,Protocol=TCP,Length=54,Info=35165 &amp;gt; http [SYN] Seq=0 Win=16384 Len=0 No=2,Time=0.000001,source=xxx.xxx.xxx.xxx,Destination=xxx.xxx.xxx.xxx,Protocol=TCP,Length=54,Info=14378 &amp;gt; http [SYN] Seq=0 Win=16384 Len=0 No=3,Time=0.</description>
    </item>
    
    <item>
      <title>can Wireshark software work for 10base-T hubs that conforms to IEEE 802.3</title>
      <link>/questions/10268/can-wireshark-software-work-for-10base-t-hubs-that-conforms-to-ieee-8023/</link>
      <pubDate>Thu, 19 Apr 2012 01:49:00 +0000</pubDate>
      
      <guid>/questions/10268/can-wireshark-software-work-for-10base-t-hubs-that-conforms-to-ieee-8023/</guid>
      <description>can Wireshark software work for 10base-T hubs that conforms to IEEE 802.3  0 kindly reply for the following queries :
1) Wireshark software work for 10base-T hubs that conforms to IEEE 802.3 , ethernet. 2) can we get the report of the network load, bandwidth utilization, 3) can we get screen shots for reference.
mb300asked 19 Apr &#39;12, 01:49
tech
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Exporting pcap to csv using tshark</title>
      <link>/questions/10270/exporting-pcap-to-csv-using-tshark/</link>
      <pubDate>Thu, 19 Apr 2012 02:15:00 +0000</pubDate>
      
      <guid>/questions/10270/exporting-pcap-to-csv-using-tshark/</guid>
      <description>Exporting pcap to csv using tshark  0 I have a sample pcap file and i opened it as a wireshark GUI. On the wireshark GUI,i click file -&amp;gt; Export. I export it as a CSV file.
I would like the output csv file output using tshark AS IF i export the pcap data to the csv file using Wireshark GUI. what is the TSHARK command for EXPORTING pcap sample file to a csv file?</description>
    </item>
    
    <item>
      <title>Want to get IEs of wlan frames</title>
      <link>/questions/10272/want-to-get-ies-of-wlan-frames/</link>
      <pubDate>Thu, 19 Apr 2012 02:25:00 +0000</pubDate>
      
      <guid>/questions/10272/want-to-get-ies-of-wlan-frames/</guid>
      <description>Want to get IEs of wlan frames  0 I have a complete capture. Is it possible shall i get complete IE&#39;s each frame and store it in some file?
Ex. For example, let us take beacon frame, i want to extract TIM IE (hex values) of each frame and store it in text file. I need to check it for analysis using perl script.
analysisasked 19 Apr &#39;12, 02:25</description>
    </item>
    
    <item>
      <title>Reproducing the HTTP Post Call to a webservice based on a Wireshark log</title>
      <link>/questions/10281/reproducing-the-http-post-call-to-a-webservice-based-on-a-wireshark-log/</link>
      <pubDate>Thu, 19 Apr 2012 07:29:00 +0000</pubDate>
      
      <guid>/questions/10281/reproducing-the-http-post-call-to-a-webservice-based-on-a-wireshark-log/</guid>
      <description>Reproducing the HTTP Post Call to a webservice based on a Wireshark log  0 Hi,
Im trying to use Wireshark to dissect the communication between two an application and a webservice, with the goal to implement the same call to the webservice in my own application.
When I filter out the request it looks like this in TCP Stream :
POST Call HTTP/1.1 Content-Type: application/x-tpnet-package Content-Length: 254 x-tpnet-msgid: 382</description>
    </item>
    
    <item>
      <title>How do I Extract the cookie path?</title>
      <link>/questions/10282/how-do-i-extract-the-cookie-path/</link>
      <pubDate>Thu, 19 Apr 2012 07:30:00 +0000</pubDate>
      
      <guid>/questions/10282/how-do-i-extract-the-cookie-path/</guid>
      <description>How do I Extract the cookie path?  0 I am using wireshark to extract the cookie details. But wireshark only gives details like name of the cookie and value.
How do I read the path tof the cookie for which it is set?
cookies http wiresharkasked 19 Apr &#39;12, 07:30
Ashwin
31●3●3●7
accept rate: 0% 
  
3 Answers:
  
0 If you mean the URL for which the cookie was set (&#34;</description>
    </item>
    
    <item>
      <title>Packets appear twice</title>
      <link>/questions/10283/packets-appear-twice/</link>
      <pubDate>Thu, 19 Apr 2012 07:47:00 +0000</pubDate>
      
      <guid>/questions/10283/packets-appear-twice/</guid>
      <description>Packets appear twice  0 Hi folks!
I have a strange issue. It seems that the GSM packets which I filter out by gsm_map are shown twice, as appears in the below screenshot: I use the following command from command line to capture the traffic:
tcpdump -i any -s0 -w test.capAny clue why such behavior could occur?
Thanks!
capture gui gsm duplicateasked 19 Apr &#39;12, 07:47
Eugene S
21●2●2●5
accept rate: 0%</description>
    </item>
    
    <item>
      <title>unable to decode SSL</title>
      <link>/questions/10286/unable-to-decode-ssl/</link>
      <pubDate>Thu, 19 Apr 2012 08:48:00 +0000</pubDate>
      
      <guid>/questions/10286/unable-to-decode-ssl/</guid>
      <description>unable to decode SSL  0 Hi, I have configured preference -&amp;gt;ssl with the private key.But still wireshark is unable to decode ssl.Below is the output from the log file.
ssl_association_remove removing TCP 443 - http handle 0000000003D911A0 Private key imported: KeyID 52:53:3d:d3:ce:ce:cd:2e:29:ab:0b:c8:0b:ca:78:ba:... ssl_init IPv4 addr &amp;#39;IPaddressofmyserver&amp;#39; (IPaddressofmyserver) port &amp;#39;443&amp;#39; filename &amp;#39;c:\\BckUP\\server.pem&amp;#39; password(only for p12 file) &amp;#39;&amp;#39; ssl_init private key file c:\\BckUP\\server.pem successfully loaded. association_add TCP port 443 protocol http handle 0000000003D911A0 dissect_ssl enter frame #3 (first time) ssl_session_init: initializing ptr 0000000005871BC0 size 680 conversation = 0000000005871880, ssl_session = 0000000005871BC0 record: offset = 0, reported_length_remaining = 141 packet_from_server: is from server - FALSE ssl_find_private_key server IPaddressofmyserver:443 client random len: 16 padded to 32 dissect_ssl2_hnd_client_hello found CLIENT RANDOM -&amp;gt; state 0x01</description>
    </item>
    
    <item>
      <title>Why doesn&amp;#x27;t the Wireshark Team fix the MacOsx version of wireshark install</title>
      <link>/questions/10289/why-doesnt-the-wireshark-team-fix-the-macosx-version-of-wireshark-install/</link>
      <pubDate>Thu, 19 Apr 2012 09:54:00 +0000</pubDate>
      
      <guid>/questions/10289/why-doesnt-the-wireshark-team-fix-the-macosx-version-of-wireshark-install/</guid>
      <description>Why doesn&amp;rsquo;t the Wireshark Team fix the MacOsx version of wireshark install  1 I ran the Wireshark installation and it fails to start. When run from the command line I get the following error: Incompatible library version: wireshark-bin requires version 14.0.0 or later, but libfreetype.6.dylib provides version 13.0.0
I googled around and saw suggestions such as update freetype and macports. I did this and am currently running latest macports and $ sudo port installed | grep freetype shows freetype @2.</description>
    </item>
    
    <item>
      <title>Editing the packet live?</title>
      <link>/questions/10292/editing-the-packet-live/</link>
      <pubDate>Thu, 19 Apr 2012 10:56:00 +0000</pubDate>
      
      <guid>/questions/10292/editing-the-packet-live/</guid>
      <description>Editing the packet live?  0 Hi!
I wonder if it is possible for Wireshark (or any compatible extension for Win7) to modify the packets being sent to the server based on some conditions (like checking the POST field value and taking action upon that)?
For example, when sending an application/x-www-form-urlencoded with a field like &#34;login=user&#34;, is there a way to script it to change that to something like &#34;login=otheruser&#34;?</description>
    </item>
    
    <item>
      <title>Install fails on 64 bit OSX 10.6.8</title>
      <link>/questions/10299/install-fails-on-64-bit-osx-1068/</link>
      <pubDate>Thu, 19 Apr 2012 12:08:00 +0000</pubDate>
      
      <guid>/questions/10299/install-fails-on-64-bit-osx-1068/</guid>
      <description>Install fails on 64 bit OSX 10.6.8  0 I just downloaded the latest stable OS X 10.6 and later Intel 64-bit .dmg from wireshark.org, and installed it on a MacBook Pro running OS X 10.6.8. The same error occurs when attempting to start wireshark. Seems as though the wireshark installation is broken not this user&#39;s mac.
Would someone on the wireshark team please look in to fixing this? Why do you need to link to such new libraries anyhow?</description>
    </item>
    
    <item>
      <title>Wireshark crashes</title>
      <link>/questions/10320/wireshark-crashes/</link>
      <pubDate>Thu, 19 Apr 2012 21:57:00 +0000</pubDate>
      
      <guid>/questions/10320/wireshark-crashes/</guid>
      <description>Wireshark crashes  0 After V1.62 if I install the software, All OK but when I go to capture options and delete the NIC card manually to enter &#34;rpcap://IP address/eth2&#34; the program crashes (I cannot enter the rpcap it crashes straight after I try and delete the NIC card). If I reinstall V1.62 all works OK but as I said after that version they all crash if I try and delete the NIC card manually (to enter my own settings).</description>
    </item>
    
    <item>
      <title>Searching for set cookies  does not show all the cookies that are set in the browser</title>
      <link>/questions/10321/searching-for-set-cookies-does-not-show-all-the-cookies-that-are-set-in-the-browser/</link>
      <pubDate>Thu, 19 Apr 2012 22:02:00 +0000</pubDate>
      
      <guid>/questions/10321/searching-for-set-cookies-does-not-show-all-the-cookies-that-are-set-in-the-browser/</guid>
      <description>Searching for set cookies does not show all the cookies that are set in the browser  0 I first cleared all the cookies in my browser. Then I went to www.yahoo.com. Mean while wireshark was capturing. In the search field of the wireshark, I entered http.set_cookie. But the filtered packets do not show all the cookies that are set in the browser. For example, the cookies shown(in wireshark) in the domain in.</description>
    </item>
    
    <item>
      <title>How to view the encrypted key during ssl key exchange?</title>
      <link>/questions/10324/how-to-view-the-encrypted-key-during-ssl-key-exchange/</link>
      <pubDate>Thu, 19 Apr 2012 23:45:00 +0000</pubDate>
      
      <guid>/questions/10324/how-to-view-the-encrypted-key-during-ssl-key-exchange/</guid>
      <description>How to view the encrypted key during ssl key exchange?  1 I am trying to view the excrypted key during ssl key exchange process. But I am not able to view the encrypted keys. Surely it must be possible to view the keys ni their encrypted form, but how?
ssl key wiresharkasked 19 Apr &#39;12, 23:45
Ashwin
31●3●3●7
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Tshark filterable fields</title>
      <link>/questions/10326/tshark-filterable-fields/</link>
      <pubDate>Fri, 20 Apr 2012 00:11:00 +0000</pubDate>
      
      <guid>/questions/10326/tshark-filterable-fields/</guid>
      <description>Tshark filterable fields  1 Does any one know of documentation that lists all the tshark filterable fields???
filter tsharkasked 20 Apr &#39;12, 00:11
misteryuku
20●24●26●30
accept rate: 0%
  
One Answer:
  
2The Display Filter Reference shows the fields in the 1.6.5 release.
There are, as of a somewhat recent top-of-trunk, 113,606 filterable (and displayable with -e) fields. A list isn&#39;t going to be very easy to browse, but if you run tshark -G fields, it will print them all.</description>
    </item>
    
    <item>
      <title>Adding function to libwireshark.def</title>
      <link>/questions/10333/adding-function-to-libwiresharkdef/</link>
      <pubDate>Fri, 20 Apr 2012 01:54:00 +0000</pubDate>
      
      <guid>/questions/10333/adding-function-to-libwiresharkdef/</guid>
      <description>Adding function to libwireshark.def  0 Hi, Is it possible to add to file &#39;libwireshark.def&#39; function &#39;de_ms_cm_3 &#39; as there are &#39;de_ms_cm_1 &#39; and &#39;de_ms_cm_2 &#39;? Symbol &#39;_de_ms_cm_3 &#39; isn&#39;t appears in &#39;wireshark.lib&#39; and since I was linking with this library I&#39;ve got error below.
packet-rrc.obj : error LNK2019: unresolved external symbol _de_ms_cm_3 referenced in function _dissect_rrc_GSM_Classmark3
Regards
radekasked 20 Apr &#39;12, 01:54
ringo
1●1●1●2
accept rate: 0%
 edited 20 Apr &#39;12, 01:55</description>
    </item>
    
    <item>
      <title>RTP player gives portaudio error</title>
      <link>/questions/10349/rtp-player-gives-portaudio-error/</link>
      <pubDate>Fri, 20 Apr 2012 07:26:00 +0000</pubDate>
      
      <guid>/questions/10349/rtp-player-gives-portaudio-error/</guid>
      <description>RTP player gives portaudio error  0 Hi,
I&#39;m sorry if I missed something. I just installed wireshark on my laptop to practice with. I&#39;m running Opensuse 12.1 and have to admit I&#39;m also rather new to Linux!
I have a problem when trying to play a RTP stream. I&#39;m trying to do the following:
Load captureGo to telephony -&amp;gt; rtp -&amp;gt; show all streamsI select the stream I want to listen to and click analyze -&amp;gt; player -&amp;gt; decode and play.</description>
    </item>
    
    <item>
      <title>Does Wireshark support this adapter?</title>
      <link>/questions/10353/does-wireshark-support-this-adapter/</link>
      <pubDate>Fri, 20 Apr 2012 10:08:00 +0000</pubDate>
      
      <guid>/questions/10353/does-wireshark-support-this-adapter/</guid>
      <description>Does Wireshark support this adapter?  0 My house has a wireless network, with a Netgear router that is password protected. I am on my desktop, which initially to get internet I had to bridge the connection between it and a laptop. The other week, I bought a Netgear N300 Wireless USB adapter. Anyways, I was using Wireshark the other week while the desktop was tethered to my laptop. Now, however, I have the USB adapter.</description>
    </item>
    
    <item>
      <title>Why do my captures NEVER show my client as the Source IP address?  (only response/destination)</title>
      <link>/questions/10355/why-do-my-captures-never-show-my-client-as-the-source-ip-address-only-responsedestination/</link>
      <pubDate>Fri, 20 Apr 2012 11:46:00 +0000</pubDate>
      
      <guid>/questions/10355/why-do-my-captures-never-show-my-client-as-the-source-ip-address-only-responsedestination/</guid>
      <description>Why do my captures NEVER show my client as the Source IP address? (only response/destination)  0 Whether it be wired or wireless, any captures I perform only show my client&#39;s IP in the destination, and the return traffic. This is true for the exception of ICMP. If I capture a web browsing session to &#34;google.com&#34;, the very first package I see in my trace is the SYN ACK from the web server.</description>
    </item>
    
    <item>
      <title>Multiple packet import from text</title>
      <link>/questions/10362/multiple-packet-import-from-text/</link>
      <pubDate>Fri, 20 Apr 2012 16:04:00 +0000</pubDate>
      
      <guid>/questions/10362/multiple-packet-import-from-text/</guid>
      <description>Multiple packet import from text  0 Hi, i have a TCP stream with multiple request/response in a text file. When importing the text file, it seems that all the file is put into one packet. how do i distinguish between the different HTTP request/response while importing?
import multiple packetsasked 20 Apr &#39;12, 16:04
yuvalshu
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Save what i have downloaded</title>
      <link>/questions/10367/save-what-i-have-downloaded/</link>
      <pubDate>Fri, 20 Apr 2012 22:20:00 +0000</pubDate>
      
      <guid>/questions/10367/save-what-i-have-downloaded/</guid>
      <description>Save what i have downloaded  0 The title is a little vague(sorry for that)- I have two computers which are plugged into the same router. Now i have arp poisoned my router so whatever goes through it is captured in my wireshark terminal. What i need to to is the following- If a user on the 2nd computer a downloads a 1mb file(program), I want to be able to see the exact file that he downloaded-That is i want to have a copy of the file that he downloaded.</description>
    </item>
    
    <item>
      <title>Convert a hexdump to the corresponding file.</title>
      <link>/questions/10368/convert-a-hexdump-to-the-corresponding-file/</link>
      <pubDate>Fri, 20 Apr 2012 22:44:00 +0000</pubDate>
      
      <guid>/questions/10368/convert-a-hexdump-to-the-corresponding-file/</guid>
      <description>Convert a hexdump to the corresponding file.  0 I downloaded a zip file and have the hexdump,c Arrays output in wireshark. How would i convert this back to the zip file.
wireshark1.2.5asked 20 Apr &#39;12, 22:44
Developer
1●2●2●3
accept rate: 0%
 edited 20 Apr &#39;12, 22:45 
   </description>
    </item>
    
    <item>
      <title>Too many lost segments, Dup Acks and retransmission</title>
      <link>/questions/10369/too-many-lost-segments-dup-acks-and-retransmission/</link>
      <pubDate>Fri, 20 Apr 2012 22:58:00 +0000</pubDate>
      
      <guid>/questions/10369/too-many-lost-segments-dup-acks-and-retransmission/</guid>
      <description>Too many lost segments, Dup Acks and retransmission  0 Hi all,
I am building a new network and I started monitoring the network using Wireshark. All the switches are Cisco SG300 52 ports switch with FW 1.0.0.27. I configured port mirroring on one of the switches so as to view communications between servers on that switch. I found that there are too many lost segments that are causing Dup Acks and fast retransmit.</description>
    </item>
    
    <item>
      <title>Basic 802.11 Decryption</title>
      <link>/questions/10370/basic-80211-decryption/</link>
      <pubDate>Sat, 21 Apr 2012 00:24:00 +0000</pubDate>
      
      <guid>/questions/10370/basic-80211-decryption/</guid>
      <description>Basic 802.11 Decryption  1 Greetings friends.
I&#39;ve been trying to perform the basic task of decrypting the 802.11 packets from my own WPA-PSK network for the last 10 hours or so now and I&#39;m about to lose my mind out of frustration :)
The instructions I find all say the same thing: &#34;Once you&#39;ve begun monitoring the network, select from the menu Edit &amp;gt; Preferences &amp;gt; Protocols &amp;gt; IEEE 802.</description>
    </item>
    
    <item>
      <title>When I capture ping test in Wireshark, I only see the Reply  and no Request, why?</title>
      <link>/questions/10377/when-i-capture-ping-test-in-wireshark-i-only-see-the-reply-and-no-request-why/</link>
      <pubDate>Sat, 21 Apr 2012 08:29:00 +0000</pubDate>
      
      <guid>/questions/10377/when-i-capture-ping-test-in-wireshark-i-only-see-the-reply-and-no-request-why/</guid>
      <description>When I capture ping test in Wireshark, I only see the Reply and no Request, why?  2 I was doing a connectivity test by sending ping from a host to a destination [email protected] I was only seeing the Reply to the ping but not the Request in Wireshark. Is this normal? I was expecting to see a line for the ping Request and another line for the ping Reply</description>
    </item>
    
    <item>
      <title>capture sybase sql anywhere traffic on a local machine</title>
      <link>/questions/10378/capture-sybase-sql-anywhere-traffic-on-a-local-machine/</link>
      <pubDate>Sat, 21 Apr 2012 09:56:00 +0000</pubDate>
      
      <guid>/questions/10378/capture-sybase-sql-anywhere-traffic-on-a-local-machine/</guid>
      <description>capture sybase sql anywhere traffic on a local machine  0 Hi. I just installed WireShark. I would like to capture all traffic between a sybase sql anywhere client and server, both operating on the same machine. The database communicates on port 2638. How do I setup WireShark to capture only sybase client/server traffic? Thanks.
localasked 21 Apr &#39;12, 09:56
snowtracks
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>What is commplex-main</title>
      <link>/questions/10380/what-is-commplex-main/</link>
      <pubDate>Sat, 21 Apr 2012 18:33:00 +0000</pubDate>
      
      <guid>/questions/10380/what-is-commplex-main/</guid>
      <description>What is commplex-main  0 I am learning computer networking. When I started using Wireshark to capture packets on my wireless card, I noticed the following entries:
39 15.453128 169.254.1.127 169.254.1.255 UDP Source port: 43292 Destination port: commplex-main 40 16.989062 169.254.1.107 169.254.1.255 UDP Source port: intecom-ps1 Destination port: commplex-main 41 20.070231 169.254.1.107 255.255.255.255 UDP Source port: 21302 Destination port: 21302What do the above entries resemble?
commplex-mainasked 21 Apr &#39;12, 18:33</description>
    </item>
    
    <item>
      <title>Monitor Mode Filter HTTP</title>
      <link>/questions/10383/monitor-mode-filter-http/</link>
      <pubDate>Sun, 22 Apr 2012 09:14:00 +0000</pubDate>
      
      <guid>/questions/10383/monitor-mode-filter-http/</guid>
      <description>Monitor Mode Filter HTTP  0 Folowing up http://ask.wireshark.org/questions/8178/capture-packets-in-monitor-mode-option-does-not-work-unable-to-scan-any-http-traffic-other-than-my-own
I added an interface to monitor all the traffic on the wireless WPA network and I&#39;m able to see lots of 802.11 packets.
I inserted wy wpa key in preferences, enabled the option to decrypt traffic, started sniffing, disconnected a computer from the network and reconnected and lastly acessed a page on youtube with http.
My problem is that I can&#39;t decrypt the http traffic.</description>
    </item>
    
    <item>
      <title>running tshark command in windows batch file</title>
      <link>/questions/10385/running-tshark-command-in-windows-batch-file/</link>
      <pubDate>Sun, 22 Apr 2012 20:25:00 +0000</pubDate>
      
      <guid>/questions/10385/running-tshark-command-in-windows-batch-file/</guid>
      <description>running tshark command in windows batch file  0 I have written a batch file that runs a tshark command to filter fields from a wireshark pcap file and write them to a csv file. When i ran on the windows cmd CLI, i had to change the current working directory to the wireshark folder directory in the My Computer&amp;gt; Program Files, so i changed the current working directory in the batch file so that it would run the same way as i ran in the windows cmd CLI.</description>
    </item>
    
    <item>
      <title>please please please  some help</title>
      <link>/questions/10386/please-please-please-some-help/</link>
      <pubDate>Sun, 22 Apr 2012 21:05:00 +0000</pubDate>
      
      <guid>/questions/10386/please-please-please-some-help/</guid>
      <description>please please please some help  -1 please any one can help me to do the following filters in wireshark
number of connections to the same host as current connection in the past two seconds.number of connections to the same services as current connection% connection that have syn error to the same host% connection that have syn error to the same service% connection that have reg error to the same host% connection that have syn error to the same service% connection to the same service in same host% connection to the different services in same host% connection to different hostfilter homeworkasked 22 Apr &#39;12, 21:05</description>
    </item>
    
    <item>
      <title>Installation attempts GTK&#43; error by configure step</title>
      <link>/questions/10388/installation-attempts-gtk-error-by-configure-step/</link>
      <pubDate>Mon, 23 Apr 2012 00:22:00 +0000</pubDate>
      
      <guid>/questions/10388/installation-attempts-gtk-error-by-configure-step/</guid>
      <description>Installation attempts GTK+ error by configure step  0 I know, the solution should be &#34;upgrade my Solaris 10 to latest version&#34;, but I still want to solve this issue but not just upgrade.
wireshark source: wireshark-1.6.4.tar.gz
os:
bash-3.00# cat /etc/release  Solaris 10 11/06 s10x_u3wos_10 X86 Copyright 2006 Sun Microsystems, Inc. All Rights Reserved. Use is subject to license terms. Assembled 14 November 2006  bash-3.00# uname -a SunOS solx86lab2 5.</description>
    </item>
    
    <item>
      <title>Generating own expected output form live pcap capture live to a windows txt file</title>
      <link>/questions/10389/generating-own-expected-output-form-live-pcap-capture-live-to-a-windows-txt-file/</link>
      <pubDate>Mon, 23 Apr 2012 00:30:00 +0000</pubDate>
      
      <guid>/questions/10389/generating-own-expected-output-form-live-pcap-capture-live-to-a-windows-txt-file/</guid>
      <description>Generating own expected output form live pcap capture live to a windows txt file  0 This is a tshark command to output packet capture live to a windows txt file.
tshark -i your_interface -V &amp;gt; your _path _to _text _file
This is a tshark command to output the wireshark GUI column data of the pcap to the txt file
tshark -n -r path _ of _ pcap_file &amp;gt; path _ of _ txt _ file</description>
    </item>
    
    <item>
      <title>Source code cannot be compiled successfully</title>
      <link>/questions/10396/source-code-cannot-be-compiled-successfully/</link>
      <pubDate>Mon, 23 Apr 2012 02:50:00 +0000</pubDate>
      
      <guid>/questions/10396/source-code-cannot-be-compiled-successfully/</guid>
      <description>Source code cannot be compiled successfully  0 Source code can no be compiled successful in linux,the error is in the following, who can help me to deal with it,and ido not know what the reason is.thanks!
mate_runtime.c: In function &amp;#39;destroy_mate_pdus&amp;#39;: mate_runtime.c:64: warning: implicit declaration of function &amp;#39;g_slice_free&amp;#39; mate_runtime.c:64: error: expected expression before &amp;#39;mate_max_size&amp;#39; mate_runtime.c: In function &amp;#39;destroy_mate_gops&amp;#39;: mate_runtime.c:81: error: expected expression before &amp;#39;mate_max_size&amp;#39; mate_runtime.c: In function &amp;#39;destroy_mate_gogs&amp;#39;: mate_runtime.c:99: error: expected expression before &amp;#39;mate_max_size&amp;#39; mate_runtime.</description>
    </item>
    
    <item>
      <title>Read filters aren&amp;#x27;t supported when capturing and saving the captured packets.</title>
      <link>/questions/10397/read-filters-arent-supported-when-capturing-and-saving-the-captured-packets/</link>
      <pubDate>Mon, 23 Apr 2012 03:22:00 +0000</pubDate>
      
      <guid>/questions/10397/read-filters-arent-supported-when-capturing-and-saving-the-captured-packets/</guid>
      <description>Read filters aren&amp;rsquo;t supported when capturing and saving the captured packets.  0 Latest stable version 1.6.7 of TShark gives the following error message when trying to capture and save packets at the same time with read filter specified:
C:&amp;gt;&#34;c:Program FilesWireshark_1.6.7tshark.exe&#34; -R sip -w file
tshark: Read filters aren&#39;t supported when capturing and saving the captured packets.
This limitation was introduced in version 1.4.0. Earlier versions supported this combination:
C:&amp;gt;&#34;c:Program FilesWireshark_1.</description>
    </item>
    
    <item>
      <title>wireshark hangs up by VPN sniffing</title>
      <link>/questions/10400/wireshark-hangs-up-by-vpn-sniffing/</link>
      <pubDate>Mon, 23 Apr 2012 08:02:00 +0000</pubDate>
      
      <guid>/questions/10400/wireshark-hangs-up-by-vpn-sniffing/</guid>
      <description>wireshark hangs up by VPN sniffing  0 hello
i will observ my VPN connection. first i start my VPN and then Wireshark to sniff on tun device. after my work in VPN and stops my VPN client wireshark is &#34;dead&#34; i can only &#34;kill&#34; them. i can not save or close wireshark - only the kill helps
can i save the &#34;temp-file&#34; they wireshark make at sniffing?
thx for help</description>
    </item>
    
    <item>
      <title>Which Wireshark Version to Use</title>
      <link>/questions/10401/which-wireshark-version-to-use/</link>
      <pubDate>Mon, 23 Apr 2012 08:57:00 +0000</pubDate>
      
      <guid>/questions/10401/which-wireshark-version-to-use/</guid>
      <description>Which Wireshark Version to Use  0 I have Windows 2008 Server, 64bit, running on my box. Which is the most stable version of Wireshark to run?
version wiresharkasked 23 Apr &#39;12, 08:57
BaselineTech
1●1●1●1
accept rate: 0%
  
2 Answers:
  
032bit or 64bit stable versions are pretty much the same when it comes to stability - at least that&#39;s my observation. The 64bit version seems to be able to handle larger traces, but still has some functionality missing (usually found in the known bugs list in the release notes).</description>
    </item>
    
    <item>
      <title>Next sequence number calculation in wireshark</title>
      <link>/questions/10405/next-sequence-number-calculation-in-wireshark/</link>
      <pubDate>Mon, 23 Apr 2012 11:10:00 +0000</pubDate>
      
      <guid>/questions/10405/next-sequence-number-calculation-in-wireshark/</guid>
      <description>Next sequence number calculation in wireshark  0 1Hello,
I am trying to analyse packets in an ssl stream. Some packets have an additional field in the TCP header [Next Sequence Number : XXXX] which is calculated by wireshark. Would be great if someone could tell me how this calculation is done.
Thanks!
wiresharkasked 23 Apr &#39;12, 11:10
flyhigh
1●1●2●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How can I find the total data bytes sent over TCP connection excluding headers?</title>
      <link>/questions/10412/how-can-i-find-the-total-data-bytes-sent-over-tcp-connection-excluding-headers/</link>
      <pubDate>Mon, 23 Apr 2012 15:01:00 +0000</pubDate>
      
      <guid>/questions/10412/how-can-i-find-the-total-data-bytes-sent-over-tcp-connection-excluding-headers/</guid>
      <description>How can I find the total data bytes sent over TCP connection excluding headers?  0 Is there anyway in wireshark to do this easily? I hope it&#39;s not something simple that I keep missing. I just need to be able to find the total number of data bytes sent of a TCP connection excluding the headers.
databytes data tcpasked 23 Apr &#39;12, 15:01
PandaSlanda
1●1●1●2
accept rate: 0%
 edited 23 Apr &#39;12, 15:02</description>
    </item>
    
    <item>
      <title>capinfos file size and summary statistics file size not matching</title>
      <link>/questions/10415/capinfos-file-size-and-summary-statistics-file-size-not-matching/</link>
      <pubDate>Tue, 24 Apr 2012 02:37:00 +0000</pubDate>
      
      <guid>/questions/10415/capinfos-file-size-and-summary-statistics-file-size-not-matching/</guid>
      <description>capinfos file size and summary statistics file size not matching  0 hey experts,
i used tshark and applied a filter to the pcap file .and then used capinfos utility capinfos -c -s pcapfiledirectory and found the output(no of packets and file size) .but the file size in not matching with that of the value i found using the same pcap in wireshark GUI ,applying same filter.then summary&amp;gt;statistics .but ,the values are not matching.</description>
    </item>
    
    <item>
      <title>packet data size with padding using capinfos</title>
      <link>/questions/10417/packet-data-size-with-padding-using-capinfos/</link>
      <pubDate>Tue, 24 Apr 2012 03:16:00 +0000</pubDate>
      
      <guid>/questions/10417/packet-data-size-with-padding-using-capinfos/</guid>
      <description>packet data size with padding using capinfos  0 hello,
I want to display the data size of the captured file along with the padding. which option of the capinfos has to be used?
thank u
data filesize capinfosasked 24 Apr &#39;12, 03:16
prashanth cm
-1●2●2●3
accept rate: 0%
can you elaborate a little? What do you mean by &#34;with the padding&#34;? Do you want to know how much padding was added in total for the file?</description>
    </item>
    
    <item>
      <title>Rolling packet data capture using tshark live.</title>
      <link>/questions/10423/rolling-packet-data-capture-using-tshark-live/</link>
      <pubDate>Tue, 24 Apr 2012 18:38:00 +0000</pubDate>
      
      <guid>/questions/10423/rolling-packet-data-capture-using-tshark-live/</guid>
      <description>Rolling packet data capture using tshark live.  0 Lets say if i want to capture the wireshark capture GUI column data live to a windows txt file using tshark. The tshark command will be like this : tshark -i your_interface -n &amp;gt; your _path _to _text _file I would like to ROLL the windows txt file that conatins the wireshark capture GUI column data that is captured live. The windows batch file will then run the java files that process the txt file data that has just rolled (The packet data info had stopped appending to the same file) while more the packet data is captured to another txt file live.</description>
    </item>
    
    <item>
      <title>Showing resolved and unresolved column at the same time</title>
      <link>/questions/10425/showing-resolved-and-unresolved-column-at-the-same-time/</link>
      <pubDate>Tue, 24 Apr 2012 21:40:00 +0000</pubDate>
      
      <guid>/questions/10425/showing-resolved-and-unresolved-column-at-the-same-time/</guid>
      <description>Showing resolved and unresolved column at the same time  0 Hi
I have a problem with the name resolution in wireshark 1.6.2 on ubuntu. I want to display both the IP and , when possible, the resolved ip in two separate columns. I added both the Src addr (resolved) and Src adr (unresolved). The problem is that both column always show the same value. Either the resolved value or the IP depending on name resolution settings.</description>
    </item>
    
    <item>
      <title>Query over the Protocal name</title>
      <link>/questions/10427/query-over-the-protocal-name/</link>
      <pubDate>Wed, 25 Apr 2012 00:00:00 +0000</pubDate>
      
      <guid>/questions/10427/query-over-the-protocal-name/</guid>
      <description>Query over the Protocal name  0 hello all
i am fresher to the networking field. i am working on switch working.
i connected 3 PCs to a switch by ethernet cables. i am able to ping all the 3 machines, one from the other. wireshark is running on all the three. suppose, when i run a simple server and client on 2 machines..i.e sending a message from one to other; in what form i.</description>
    </item>
    
    <item>
      <title>Which NIC do I capture on?</title>
      <link>/questions/10433/which-nic-do-i-capture-on/</link>
      <pubDate>Wed, 25 Apr 2012 06:22:00 +0000</pubDate>
      
      <guid>/questions/10433/which-nic-do-i-capture-on/</guid>
      <description>Which NIC do I capture on?  0 Hello, I would like to analyze my network using Wireshark. The problem I have one internet connection, but two networks which run from the one connection. This means that on my admin computer, I have two NICs. One for each network.
My question is, say I wanted to monitor internet protocols, how could I work out which NIC my computer is using to get a route outside to the internet.</description>
    </item>
    
    <item>
      <title>wireshark based 3g protocol analyzer</title>
      <link>/questions/10437/wireshark-based-3g-protocol-analyzer/</link>
      <pubDate>Wed, 25 Apr 2012 07:23:00 +0000</pubDate>
      
      <guid>/questions/10437/wireshark-based-3g-protocol-analyzer/</guid>
      <description>wireshark based 3g protocol analyzer  0 how do i get wireshark based 3g protocol analyzer? I am a learner of 3G protocol and i need an software where I can study wcdma utms protocol stack from sample packets of wcdma , rlc, rrc, etc....
protocol based 3g analyzer wiresharkasked 25 Apr &#39;12, 07:23
souhal67
1●2●2●3
accept rate: 0%
 edited 25 Apr &#39;12, 18:47 
  
One Answer:</description>
    </item>
    
    <item>
      <title>RLC &amp;amp; RRC packet sample</title>
      <link>/questions/10438/rlc-rrc-packet-sample/</link>
      <pubDate>Wed, 25 Apr 2012 07:28:00 +0000</pubDate>
      
      <guid>/questions/10438/rlc-rrc-packet-sample/</guid>
      <description>RLC &amp;amp; RRC packet sample  0 how do i get sample capture of RLC and RRC packet in 3g (UTMS) technology? is any body upload it?
rrc sample_packet utms 3g rlcasked 25 Apr &#39;12, 07:28
souhal67
1●2●2●3
accept rate: 0%
 edited 30 Apr &#39;12, 08:20 
   </description>
    </item>
    
    <item>
      <title>How to decode the UDP to RTP in command line?</title>
      <link>/questions/10440/how-to-decode-the-udp-to-rtp-in-command-line/</link>
      <pubDate>Wed, 25 Apr 2012 08:33:00 +0000</pubDate>
      
      <guid>/questions/10440/how-to-decode-the-udp-to-rtp-in-command-line/</guid>
      <description>How to decode the UDP to RTP in command line?  0 Hi all,
Under the Wireshark GUI, I am able to decode the UDP to RTP by using the
&#34;Analyze &amp;gt; decode as...&#34;
. However, for the command line, I am not able to do it
tshark -r c:\input.cap -d udp.port==20390,rtp -w c:\output.capit runs without error but after I open the output.cap in Wireshark GUI, the problem is all the frames are still UDP.</description>
    </item>
    
    <item>
      <title>Couldn&amp;#x27;t see sflow traffic sent from windows server 8(beta) box.</title>
      <link>/questions/10443/couldnt-see-sflow-traffic-sent-from-windows-server-8beta-box/</link>
      <pubDate>Wed, 25 Apr 2012 11:11:00 +0000</pubDate>
      
      <guid>/questions/10443/couldnt-see-sflow-traffic-sent-from-windows-server-8beta-box/</guid>
      <description>Couldn&amp;rsquo;t see sflow traffic sent from windows server 8(beta) box.  0 Hi, I was using wireshark 1.6.7&amp;amp;previous stable release trying to catch sflow data sent from my windows server 8(beta) to my windows 2008 R2 box. Using other 2 tools(netmon and sflowTrend) I could see sflow data sent to my monitoring box, but I couldn&#39;t see it in wireshark. Actually I could see it once but couldn&#39;t no longer and I didn&#39;t seem to make any change to the tool.</description>
    </item>
    
    <item>
      <title>How to capture PGP overhead using wireshark</title>
      <link>/questions/10444/how-to-capture-pgp-overhead-using-wireshark/</link>
      <pubDate>Wed, 25 Apr 2012 12:15:00 +0000</pubDate>
      
      <guid>/questions/10444/how-to-capture-pgp-overhead-using-wireshark/</guid>
      <description>How to capture PGP overhead using wireshark  0 Hello
Can anyone help me as I&#39;m trying to find monitor PGP protocol and capture its overhead, but I&#39;m unable to do it
Please Help me
Thanks Vi
capture overhead pgpasked 25 Apr &#39;12, 12:15
Viv
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Hi,
may I ask what you mean by PGP &#39;protocol&#39;? PGP is mainly a framework (and format) for e-mail encryption.</description>
    </item>
    
    <item>
      <title>Why doesn&amp;#x27;t Wireshark open on my Mac OS X machine?</title>
      <link>/questions/10447/why-doesnt-wireshark-open-on-my-mac-os-x-machine/</link>
      <pubDate>Wed, 25 Apr 2012 15:17:00 +0000</pubDate>
      
      <guid>/questions/10447/why-doesnt-wireshark-open-on-my-mac-os-x-machine/</guid>
      <description>Why doesn&amp;rsquo;t Wireshark open on my Mac OS X machine?  0 Hi, I&#39;ve been running Wireshark for a while in this computer, but I reinstalled Mac OS X and Wireshark won&#39;t open. I&#39;ve deleted it and reinstalled it but the answer is the same; it just doesn&#39;t open. How do I fix it?
mac open problemasked 25 Apr &#39;12, 15:17
JoseMtz
6●1●1●3
accept rate: 0%
 edited 21 Sep &#39;12, 08:40</description>
    </item>
    
    <item>
      <title>ASN.1 Tag Encoding Problem</title>
      <link>/questions/10457/asn1-tag-encoding-problem/</link>
      <pubDate>Thu, 26 Apr 2012 02:38:00 +0000</pubDate>
      
      <guid>/questions/10457/asn1-tag-encoding-problem/</guid>
      <description>ASN.1 Tag Encoding Problem  1 Hello,
I have an application that uses ASN.1 ber to encode its data to transmit. One particular field encodes an OCTET STRING, and uses an implicit application tag. The hex bytes are these:
5F 01 04 .. .. .. ..
Where 0x5F01 is the tag and 0x04 the length. This encodes the APPLICATION type, with a tag number of 1. However, an APPLICATION type with tag number of 1 should (AFAIK) encodes as 0x41.</description>
    </item>
    
    <item>
      <title>Export RTP from command line</title>
      <link>/questions/10461/export-rtp-from-command-line/</link>
      <pubDate>Thu, 26 Apr 2012 08:08:00 +0000</pubDate>
      
      <guid>/questions/10461/export-rtp-from-command-line/</guid>
      <description>Export RTP from command line  0 In Wireshark GUI, I can export a .raw / .au file by using
Telephony &amp;gt; RTP &amp;gt; Stream Analysis ...&amp;gt; Save Payload
But how can I export the .raw / .au by using command line ?
Thanks a lot!
rtp command-lineasked 26 Apr &#39;12, 08:08
manfree
1●2●2●4
accept rate: 0%
 converted to question 27 Apr &#39;12, 04:12 
Jaap ♦
11.7k●16●101</description>
    </item>
    
    <item>
      <title>How can I resolve this link error LNK1112 when building on 64-bit Windows?</title>
      <link>/questions/10463/how-can-i-resolve-this-link-error-lnk1112-when-building-on-64-bit-windows/</link>
      <pubDate>Thu, 26 Apr 2012 09:09:00 +0000</pubDate>
      
      <guid>/questions/10463/how-can-i-resolve-this-link-error-lnk1112-when-building-on-64-bit-windows/</guid>
      <description>How can I resolve this link error LNK1112 when building on 64-bit Windows?  0 I followed the steps mentioned in the wiki article for win64 compilation, but I am getting the below error:
ERROR fatal error LNK1112: module machine type &amp;#39;x64&amp;#39; conflicts with target machine type &amp;#39;X86&amp;#39;Below is the compilation log:
D:\wireshark-1.6.7&amp;gt;nmake -f Makefile.nmake all Microsoft (R) Program Maintenance Utility Version 9.00.21022.08 Copyright (C) Microsoft Corporation. All rights reserved.</description>
    </item>
    
    <item>
      <title>Window size scaling factor unknown?</title>
      <link>/questions/10466/window-size-scaling-factor-unknown/</link>
      <pubDate>Thu, 26 Apr 2012 11:30:00 +0000</pubDate>
      
      <guid>/questions/10466/window-size-scaling-factor-unknown/</guid>
      <description>Window size scaling factor unknown?  0 I have noticed some strange packets with the &#34;Window size scaling factor: -1 (unknown)&#34;. Is this a buffer full problem? I am seeing this on both the source and destination intermittently.
Thanks for your help in advance,
scaling factorasked 26 Apr &#39;12, 11:30
arpsalot
1●1●1●1
accept rate: 0%
 edited 26 Apr &#39;12, 14:48 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:</description>
    </item>
    
    <item>
      <title>Need to decode the captured data</title>
      <link>/questions/10468/need-to-decode-the-captured-data/</link>
      <pubDate>Thu, 26 Apr 2012 11:52:00 +0000</pubDate>
      
      <guid>/questions/10468/need-to-decode-the-captured-data/</guid>
      <description>Need to decode the captured data  0 how to decode the captured packets how to view the original message or picture some thing like that
decodeingasked 26 Apr &#39;12, 11:52
arasu
1●3●3●3
accept rate: 0% 
 edited 26 Apr &#39;12, 13:39 
Jim Aragon
7.2k●7●33●118
Ok... what exactly is your problem?!
(28 Apr &#39;12, 05:17) Landiif it&#39;s a &#34;text based&#34; protcol, use: Analyze -&amp;gt; Follow TCP/UDP Stream. You will see the transmitted data in text form.</description>
    </item>
    
    <item>
      <title>scsi transfer limited due to allocation length too small</title>
      <link>/questions/10469/scsi-transfer-limited-due-to-allocation-length-too-small/</link>
      <pubDate>Thu, 26 Apr 2012 15:03:00 +0000</pubDate>
      
      <guid>/questions/10469/scsi-transfer-limited-due-to-allocation-length-too-small/</guid>
      <description>scsi transfer limited due to allocation length too small  0 Im having slow read/write performance on my iscsi san. The packet traces show this message frequently &#34;scsi transfer limited due to allocation length too small&#34;. Any one have an idea of why these messages show up in the traces? Tushar.
allocation transfer scsi length smallasked 26 Apr &#39;12, 15:03
tushar
11●2●2●4
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How to capture on all interfaces with a single Tshark command?</title>
      <link>/questions/10472/how-to-capture-on-all-interfaces-with-a-single-tshark-command/</link>
      <pubDate>Fri, 27 Apr 2012 02:06:00 +0000</pubDate>
      
      <guid>/questions/10472/how-to-capture-on-all-interfaces-with-a-single-tshark-command/</guid>
      <description>How to capture on all interfaces with a single Tshark command?  0 Current wireshark version support capturing on multiple adapters at the same time, can we do this from the command line as well? At the moment i&#39;m stuck with:
C:\Progra~1\Wireshark\tshark.exe -i 2 -a duration:600 -n -w &amp;quot;%subor%&amp;quot;i would very much like something like this:
C:\Progra~1\Wireshark\tshark.exe -i any -a duration:600 -n -w &amp;quot;%subor%&amp;quot;is this possible? Thanks!
tsharkasked 27 Apr &#39;12, 02:06</description>
    </item>
    
    <item>
      <title>Dumpcap Parameter -Z</title>
      <link>/questions/10473/dumpcap-parameter-z/</link>
      <pubDate>Fri, 27 Apr 2012 03:43:00 +0000</pubDate>
      
      <guid>/questions/10473/dumpcap-parameter-z/</guid>
      <description>Dumpcap Parameter -Z  0 Can someone tell me what the parameter &#34;-Z&#34; does for dumpcap? I&#39;ve seen Wireshark calling dumpcap with that parameter, but the integrated help doesn&#39;t tell what it means. The complete command line was:
&amp;quot;C:\Program Files\Wireshark\dumpcap&amp;quot; -t -n -i \Device\NPF_{F7CB705F-7A3D-4CBF-B881-1D0074D695D7} -y EN10MB -u -r -i \Device\NPF_{E98CD01D-49F2-412E-A1AD-EE1B89EF3E61} -y EN10MB -u -r -Z 6264dumpcap parametersasked 27 Apr &#39;12, 03:43
Jasper ♦♦
23.8k●5●51●284
accept rate: 18%</description>
    </item>
    
    <item>
      <title>ACKed lost segment (common at capture start)</title>
      <link>/questions/10489/acked-lost-segment-common-at-capture-start/</link>
      <pubDate>Fri, 27 Apr 2012 10:47:00 +0000</pubDate>
      
      <guid>/questions/10489/acked-lost-segment-common-at-capture-start/</guid>
      <description>ACKed lost segment (common at capture start)  0 Hi,
When I&#39;m looking at the expert info in a capture&amp;lt;I see these messages: ACKed lost segment (common at capture start) previous segment lost (common at capture start)
I&#39;m running WS 1.4.9 on a VM server. The through put on the interface is avg. 45.8 Mbits/sec for a 5 minute period. Am I running into and issue with the interface because wireshark is not talking directly to it?</description>
    </item>
    
    <item>
      <title>capturing clients talking to my dns server</title>
      <link>/questions/10490/capturing-clients-talking-to-my-dns-server/</link>
      <pubDate>Fri, 27 Apr 2012 11:10:00 +0000</pubDate>
      
      <guid>/questions/10490/capturing-clients-talking-to-my-dns-server/</guid>
      <description>capturing clients talking to my dns server  0 Can you show me a filter i can use to see who is looking at my server for DNS resolution. I have used tcp.port == 53 but need a more refined filter showing clients talking to the DNS server only.
dnsasked 27 Apr &#39;12, 11:10
bilweiser
1●1●1●1
accept rate: 0% 
  
3 Answers:
  
0How about &#34;</description>
    </item>
    
    <item>
      <title>Can TShark extract voice data from an RTP stream?</title>
      <link>/questions/10493/can-tshark-extract-voice-data-from-an-rtp-stream/</link>
      <pubDate>Fri, 27 Apr 2012 18:58:00 +0000</pubDate>
      
      <guid>/questions/10493/can-tshark-extract-voice-data-from-an-rtp-stream/</guid>
      <description>Can TShark extract voice data from an RTP stream?  0 In Wireshark, I can go to Telephony/RTP/Stream Analysis and then click &#34;Save Payload As...&#34; to dump the voice data into a file. Can I do this using TShark, too?
voice rtp tsharkasked 27 Apr &#39;12, 18:58
Homayoon
6●1●1●3
accept rate: 0%
  
One Answer:
  
1 afaik that&#39;s not possible with tshark (please correct, if I&#39;m wrong).</description>
    </item>
    
    <item>
      <title>Wireless capture</title>
      <link>/questions/10494/wireless-capture/</link>
      <pubDate>Fri, 27 Apr 2012 23:13:00 +0000</pubDate>
      
      <guid>/questions/10494/wireless-capture/</guid>
      <description>Wireless capture  0 OK, I don&#39;t know if I&#39;m doing this wrong or if what I&#39;m trying to do is even supported. What I&#39;m trying to do is monitor packets on my WEP network. I am connected via wireless and I can pass traffic with no issues via wlan0. I start Wireshark in promiscuous mode on wlan0 and all I can see is broadcast, multicast and my (to/from) traffic. It&#39;s just like I&#39;m on a switched network.</description>
    </item>
    
    <item>
      <title>Use plaintext file for a capturing filter</title>
      <link>/questions/10499/use-plaintext-file-for-a-capturing-filter/</link>
      <pubDate>Sat, 28 Apr 2012 07:49:00 +0000</pubDate>
      
      <guid>/questions/10499/use-plaintext-file-for-a-capturing-filter/</guid>
      <description>Use plaintext file for a capturing filter  0 Hi,
Is it possible to use a plaintext file with ip-ranges (CIDR-Notation) in it to exclude specific ip-ranges from the capturing process? If so, how can i do that?
Thanks in advance
Steve
cidr ip-ranges exclusion fileasked 28 Apr &#39;12, 07:49
LA_FORGE
6●1●1●3
accept rate: 0%
  
2 Answers:
  
1at least on unix you can do it this way:</description>
    </item>
    
    <item>
      <title>Kerberos sample cap</title>
      <link>/questions/10501/kerberos-sample-cap/</link>
      <pubDate>Sat, 28 Apr 2012 13:37:00 +0000</pubDate>
      
      <guid>/questions/10501/kerberos-sample-cap/</guid>
      <description>Kerberos sample cap  0 Hi, I read this info http://wiki.wireshark.org/Kerberos Do you know if the capture files samples are working ? Because I downloaded the files and open them with -K but I cannot see the content inside the ticket Thanks
kerberosasked 28 Apr &#39;12, 13:37
KerbTest
1●1●1●1
accept rate: 0%
BTW, why I cannot find this option in the new wireshark version ? Preferences -&amp;gt; Protocols -&amp;gt; KRB5 -&amp;gt; keytab path</description>
    </item>
    
    <item>
      <title>WireShark on LAN</title>
      <link>/questions/10504/wireshark-on-lan/</link>
      <pubDate>Sun, 29 Apr 2012 06:47:00 +0000</pubDate>
      
      <guid>/questions/10504/wireshark-on-lan/</guid>
      <description>WireShark on LAN  0 Hello. I have problems with a PC/PCS from my LAN network. One PC made spam on 25 port but i don&#39;t know who. My Network is like ex: ROUTER (with wan IP -xxx.xxx.xxx.xxx snd lan IP 192.168.1.1) and many PC&#39;s linked to router . I want to install whireshark on a pc from network (192.168.1.2) to monitoring the router to find what PC from LAN made spam on internet.</description>
    </item>
    
    <item>
      <title>Connecting to an HP 2510g-28 Switch</title>
      <link>/questions/10511/connecting-to-an-hp-2510g-28-switch/</link>
      <pubDate>Mon, 30 Apr 2012 01:59:00 +0000</pubDate>
      
      <guid>/questions/10511/connecting-to-an-hp-2510g-28-switch/</guid>
      <description>Connecting to an HP 2510g-28 Switch  0 Hi there, I would like to connect my Wireshark to my HP 2510g-48 network switch so I can analyze the network traffic. I know the switch is capable of mirroring on specific ports. I have promiscous mode set on my NIC. Can anyone advise me on which steps I need to take next in order to recieve all network traffic on Wireshark?</description>
    </item>
    
    <item>
      <title>Filter on HW Level</title>
      <link>/questions/10519/filter-on-hw-level/</link>
      <pubDate>Mon, 30 Apr 2012 07:39:00 +0000</pubDate>
      
      <guid>/questions/10519/filter-on-hw-level/</guid>
      <description>Filter on HW Level  0 I&#39;m using Wireshark for my project and i need support to filter packets from HW level. Basically, i&#39;m getting lot of packets and i would like to filter some useless packets captured on my interface. Could you please give me a hand?
Thanks/ Alexis
capture-filterasked 30 Apr &#39;12, 07:39
Alexis
6●1●1●4
accept rate: 0%
 edited 30 Apr &#39;12, 07:42</description>
    </item>
    
    <item>
      <title>Wireshark 1.6.7 crashing in Windows 2008</title>
      <link>/questions/10528/wireshark-167-crashing-in-windows-2008/</link>
      <pubDate>Mon, 30 Apr 2012 09:54:00 +0000</pubDate>
      
      <guid>/questions/10528/wireshark-167-crashing-in-windows-2008/</guid>
      <description>Wireshark 1.6.7 crashing in Windows 2008  0 Hi:
I downloaded wireshark 1.6.7 for windows (32 bits). I am running it in a Windows 2008(32 bits) virtual machine (The hypervisor is Hyper-V)
After a period of running wireshark making a capture, it crashes with the following error:
Faulting application wireshark.exe, version 1.6.7.41973, time stamp 0x4f7f4286, faulting module libglib-2.0-0.dll, version 2.28.8.0, time stamp 0x4e253544, exception code 0x40000015, fault offset 0x0004c2d8, process id 0xb74, application start time 0x01cd26dd6a840d67.</description>
    </item>
    
    <item>
      <title>TCP ZeroWindow Probe.</title>
      <link>/questions/10531/tcp-zerowindow-probe/</link>
      <pubDate>Mon, 30 Apr 2012 12:00:00 +0000</pubDate>
      
      <guid>/questions/10531/tcp-zerowindow-probe/</guid>
      <description>TCP ZeroWindow Probe.  0 1After doing a capture from the source to the destination address. I keep seeing an TCP {Ack} being sent and an a{PSH}, but no {ACK}. After a minute or so I get the {TCP ZEROWINDOW PROBE}, which is causing the backup server to hang since theres no data actually being sent correctly. Not sure what would cause the {TCP ZEROWINDOW PROBE}. I have read up on it and I believe it has something to do with the destination IP Address Buffer being filled up to quickly.</description>
    </item>
    
    <item>
      <title>SIP-I Decode:- National Specific ISUP parameter decode</title>
      <link>/questions/10544/sip-i-decode-national-specific-isup-parameter-decode/</link>
      <pubDate>Tue, 01 May 2012 01:14:00 +0000</pubDate>
      
      <guid>/questions/10544/sip-i-decode-national-specific-isup-parameter-decode/</guid>
      <description>SIP-I Decode:- National Specific ISUP parameter decode  0 How can I add National Specific ISUP parameter&#39;s into the Wireshark decode for SIP-I ?
Once I&#39;ve done that can I save the SIP-I variant as a specific version of SIP-I decode, eg SIP-I (UK ISUP) etc.
wiresharkasked 01 May &#39;12, 01:14
IAMoramnot
1●1●1●1
accept rate: 0%
  
One Answer:
  
0The ISUP content of SIP-I is dissected by packet-isup.</description>
    </item>
    
    <item>
      <title>SASL GSS-API Privacy</title>
      <link>/questions/10545/sasl-gss-api-privacy/</link>
      <pubDate>Tue, 01 May 2012 04:24:00 +0000</pubDate>
      
      <guid>/questions/10545/sasl-gss-api-privacy/</guid>
      <description>SASL GSS-API Privacy  0 Hi,
Just wonder if it is possible to decrypt the signed LDAP packets to and from a Windows server. I have disabled LDAP signing on the client and server, plus implemented various registry settings that are also meant to disable this however after binding the next packets are all listed as SASL GSS-API Privacy. The changes have allowed me to see the bind request and response however the next packets are a mystery.</description>
    </item>
    
    <item>
      <title>sniffing another PC&amp;#x27;s ?!</title>
      <link>/questions/10546/sniffing-another-pcs/</link>
      <pubDate>Tue, 01 May 2012 05:17:00 +0000</pubDate>
      
      <guid>/questions/10546/sniffing-another-pcs/</guid>
      <description>sniffing another PC&amp;rsquo;s ?!  0 can i start sniffing another pc&#39;s packets without a LAN connection , maybe through remote network programs such as &#34;hamachi&#34; ?
P.S. how can i see information which are encrypted (like accounts info , mmpor games actually ) ?
sniffing encryption packetsasked 01 May &#39;12, 05:17
kimocool
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1No, you can&#39;t, unless you&#39;re able to use some tricks like ARP cache poisoning which might or might not work on a connection like hamachi.</description>
    </item>
    
    <item>
      <title>Piping output from tshark to Java program</title>
      <link>/questions/10558/piping-output-from-tshark-to-java-program/</link>
      <pubDate>Tue, 01 May 2012 18:13:00 +0000</pubDate>
      
      <guid>/questions/10558/piping-output-from-tshark-to-java-program/</guid>
      <description>Piping output from tshark to Java program  0 Lets say that the tshark command for piping the output from tshark is :
tshark -i your_interface -n | your_program
I would like to pipe the output from tshark to the java program.
I compiled the java file and i piped the tshark output to the java program like this :
tshark -i 1 -n | java &#34;C:\Users\L33604\Desktop\Eclipse Indigo x64-Bit\eclipse\project workspace\Splunk Project\src\Program.</description>
    </item>
    
    <item>
      <title>Outputting a tshark command result to a window</title>
      <link>/questions/10566/outputting-a-tshark-command-result-to-a-window/</link>
      <pubDate>Tue, 01 May 2012 22:49:00 +0000</pubDate>
      
      <guid>/questions/10566/outputting-a-tshark-command-result-to-a-window/</guid>
      <description>Outputting a tshark command result to a window  0 Let&#39;s say the tshark command for converting a pcap file to a Windows .txt file is:
tshark -n -r &amp;quot;C:\Users\L33604\Desktop\SplunkWireshark\WiresharkPacketLogMonitor\SynFlood Sample.pcap&amp;quot; &amp;gt; &amp;quot;C:\Users\L33604\Desktop\SplunkWireshark\WiresharkPacketLogMonitor\capfile.txt&amp;quot;The output is shown in the .txt file but not on the Windows cmd console.
How do I change the above tshark command such that it shows the same output from the .txt file on the console?
tsharkasked 01 May &#39;12, 22:49</description>
    </item>
    
    <item>
      <title>Creating my own filter</title>
      <link>/questions/10569/creating-my-own-filter/</link>
      <pubDate>Tue, 01 May 2012 23:52:00 +0000</pubDate>
      
      <guid>/questions/10569/creating-my-own-filter/</guid>
      <description>Creating my own filter  0 I want to create my own filter in wireshark. I mean I want to have a function which will apply the filter automatically. How can I do it?
filterasked 01 May &#39;12, 23:52
vish
0●5●5●7
accept rate: 0%
 edited 01 May &#39;12, 23:56 
  
One Answer:
  
1Your best approach would be to use a display filter macro. It&#39;s fairly straightforward, and you can create fairly complex filters in this fashion.</description>
    </item>
    
    <item>
      <title>Unable to Decode DAP(X.519 Directory Access Protocol) messages using wireshark</title>
      <link>/questions/10579/unable-to-decode-dapx519-directory-access-protocol-messages-using-wireshark/</link>
      <pubDate>Wed, 02 May 2012 03:19:00 +0000</pubDate>
      
      <guid>/questions/10579/unable-to-decode-dapx519-directory-access-protocol-messages-using-wireshark/</guid>
      <description>Unable to Decode DAP(X.519 Directory Access Protocol) messages using wireshark  0 Hi,
I have captured the DAP protocol messages in a file Dumpfile.pcap. I opened the file with Wireshark &amp;amp; used the following filter to filter DAP protocol messages:
tcp.srcport == 16602 || tcp.srcport == 16614 || tcp.dstport == 16602 || tcp.dstport == 16614
Where 16602 &amp;amp; 16614 are the TCP ports used for DAP protocol.
Then I went to wiresharks &#34;</description>
    </item>
    
    <item>
      <title>Capturing packets between two laptops sending text files between each other</title>
      <link>/questions/10583/capturing-packets-between-two-laptops-sending-text-files-between-each-other/</link>
      <pubDate>Wed, 02 May 2012 03:59:00 +0000</pubDate>
      
      <guid>/questions/10583/capturing-packets-between-two-laptops-sending-text-files-between-each-other/</guid>
      <description>Capturing packets between two laptops sending text files between each other  0 Hi there,
I am currently doing a university project. I am trying to send a text file from one laptop to another over wi-fi, with both laptops connected to the same network. I am then using a third laptop to try and capture the packets of this file transfer but I cannot seem to capture anything coming or going from these two laptops.</description>
    </item>
    
    <item>
      <title>absolute_time field in Lua dissector</title>
      <link>/questions/10584/absolute_time-field-in-lua-dissector/</link>
      <pubDate>Wed, 02 May 2012 04:11:00 +0000</pubDate>
      
      <guid>/questions/10584/absolute_time-field-in-lua-dissector/</guid>
      <description>absolute_time field in Lua dissector  0 The function ProtoField.absolute_time is documented (11.10.6.14), but may be broken in some way. At least, when I try to call it, I get an error dialogue containing the message &#34;attempt to call field &#39;?&#39; (a nil value)&#34;, and pointing to the line with the absolute_time call, when starting wireshark.
I am using version 1.6.7.
Is this deliberate, or a bug?
absolute_time luaasked 02 May &#39;12, 04:11</description>
    </item>
    
    <item>
      <title>tshark commands -e and -T</title>
      <link>/questions/10605/tshark-commands-e-and-t/</link>
      <pubDate>Wed, 02 May 2012 08:32:00 +0000</pubDate>
      
      <guid>/questions/10605/tshark-commands-e-and-t/</guid>
      <description>tshark commands -e and -T  0 I want to print the information that I need of a PCAP file. I know that I can use the command &#34;tshark -e&#34;:
tshark -r rdpcap.pcap -e ip.src -e ip.dst -e data -e frame.number -T fieldsMy question is: How can I display the &#34;id source port&#34;, &#34;id destination port&#34;?
And for &#34;-e data&#34;, is it possible to display just the first 8 bytes?</description>
    </item>
    
    <item>
      <title>Who is using &amp;quot;tsclient&amp;quot; on my network?</title>
      <link>/questions/10609/who-is-using-tsclient-on-my-network/</link>
      <pubDate>Wed, 02 May 2012 10:31:00 +0000</pubDate>
      
      <guid>/questions/10609/who-is-using-tsclient-on-my-network/</guid>
      <description>Who is using &amp;ldquo;tsclient&amp;rdquo; on my network?  0 Hello, I respectfully ask if someone can assist me in sniffing out who is &#34;tsclient&#34; on my network.
tsclientasked 02 May &#39;12, 10:31
crobinso777
1●1●1●1
accept rate: 0%
where did you find that string. Please provide as much information as possible.
BTW: if you are talking about the linux &#34;Terminal Server Client [tsclient]&#34;, there is no chance to detect that with wireshark, as tsclient is just a GUI wrapper for rdesktop and other remote access tools.</description>
    </item>
    
    <item>
      <title>How to capture LLDP packets using Atheros AR8151 PCI-E gigabit Ethernet card</title>
      <link>/questions/10619/how-to-capture-lldp-packets-using-atheros-ar8151-pci-e-gigabit-ethernet-card/</link>
      <pubDate>Wed, 02 May 2012 20:54:00 +0000</pubDate>
      
      <guid>/questions/10619/how-to-capture-lldp-packets-using-atheros-ar8151-pci-e-gigabit-ethernet-card/</guid>
      <description>How to capture LLDP packets using Atheros AR8151 PCI-E gigabit Ethernet card  0 I can not capture LLDP packets when using Atheros AR8151 PCI-E gigabit Ethernet card while using other Ethernet cards work fine. And I have update driver to 1.0.0.45 for Windows XP.
lldpasked 02 May &#39;12, 20:54
Jasmine
1●2●2●3
accept rate: 0%
 edited 02 May &#39;12, 21:00 
   </description>
    </item>
    
    <item>
      <title>Cant Connect to Remote FileShare using Wireless Connection while it works fine with Wired</title>
      <link>/questions/10631/cant-connect-to-remote-fileshare-using-wireless-connection-while-it-works-fine-with-wired/</link>
      <pubDate>Thu, 03 May 2012 04:53:00 +0000</pubDate>
      
      <guid>/questions/10631/cant-connect-to-remote-fileshare-using-wireless-connection-while-it-works-fine-with-wired/</guid>
      <description>Cant Connect to Remote FileShare using Wireless Connection while it works fine with Wired  0 Dear all,
I am working in a sales office, where wired and wireless connection works. Strangely I have encountered the issue with the wireless connection only where I cant connect to multiple remote file share systems. Have anyone experienced that kind of behavior in their environment?
Thanks, Faiz
cifsasked 03 May &#39;12, 04:53
Farhan_J</description>
    </item>
    
    <item>
      <title>How to find syn not followed by a syn&#43;ack</title>
      <link>/questions/10640/how-to-find-syn-not-followed-by-a-synack/</link>
      <pubDate>Thu, 03 May 2012 08:26:00 +0000</pubDate>
      
      <guid>/questions/10640/how-to-find-syn-not-followed-by-a-synack/</guid>
      <description>How to find syn not followed by a syn+ack  0 I am having trouble with occasional connect timeouts. Is there anyway in wireshark to find where the three way handshake fails?
Thanks in advance
Chip
handshake three-wayasked 03 May &#39;12, 08:26
blueridge55
1●1●1●1
accept rate: 0%
 edited 04 May &#39;12, 12:41 
grahamb ♦
19.8k●3●30●206
  
3 Answers:
  
2Use the display filter &#39;tcp.flags eq 0x02&#39; (only SYN flag set)</description>
    </item>
    
    <item>
      <title>Cannot stop the capture</title>
      <link>/questions/10644/cannot-stop-the-capture/</link>
      <pubDate>Thu, 03 May 2012 09:56:00 +0000</pubDate>
      
      <guid>/questions/10644/cannot-stop-the-capture/</guid>
      <description>Cannot stop the capture  0 I am unable to stop captures. Neither the key shortcut, the stop button in the main window, nor the stop button in the interfaces window work. Neither does setting an automatic stop time using the interface options window.
OS: Win 2k3 x86 Wireshark v. 1.6.7
captureasked 03 May &#39;12, 09:56
wreckanize
1●1●1●1
accept rate: 0%
Bug https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5892 ?
(03 May &#39;12, 21:48) Anders ♦   </description>
    </item>
    
    <item>
      <title>Q&amp;amp;A Site search</title>
      <link>/questions/10650/qa-site-search/</link>
      <pubDate>Thu, 03 May 2012 14:38:00 +0000</pubDate>
      
      <guid>/questions/10650/qa-site-search/</guid>
      <description>Q&amp;amp;A Site search  2 Hi,
I wonder, why I do see 0 (zero) results when searching the forum questions.
Example: Try to search for the string &#39;capture&#39; and the radio-box &#39;questions&#39; is selected.
Result: 0 questions matching &#39;capture&#39;
However, there are clearly questions with that string in the question title and the content.
Is it me, or is it the forum software?
Secondly, I suggest to change the background color of the search field.</description>
    </item>
    
    <item>
      <title>how to use Lua to write multi protocol dissector plugin</title>
      <link>/questions/10658/how-to-use-lua-to-write-multi-protocol-dissector-plugin/</link>
      <pubDate>Thu, 03 May 2012 19:40:00 +0000</pubDate>
      
      <guid>/questions/10658/how-to-use-lua-to-write-multi-protocol-dissector-plugin/</guid>
      <description>how to use Lua to write multi protocol dissector plugin  0 I am writing an XLES protocol dissector, but this protocol is in the payload of LAPV5, so I have to write the LAPV5 dissector first. How do I connect the two protocols?
I wrote something like this:
udp_encap_table = DissectorTable.get(&amp;quot;udp.port&amp;quot;) udp_encap_table:add(49152,lapV5Proto) lapV5DessectorTable = DissectorTable.new(&amp;quot;lapv5.data&amp;quot;, &amp;quot;lapv5 dissector table&amp;quot;,ftypes.STRING,base.none) lapv5_encap_table = DissectorTable.get(&amp;quot;lapv5.data&amp;quot;) lapv5_encap_table:add(&amp;quot;.&amp;quot;,xlesProto)But it doesn&amp;rsquo;t work. XLES only exists when LAPV5 has a payload.</description>
    </item>
    
    <item>
      <title>Using Tshark to get all Avaya telephones sorted..</title>
      <link>/questions/10664/using-tshark-to-get-all-avaya-telephones-sorted/</link>
      <pubDate>Fri, 04 May 2012 01:49:00 +0000</pubDate>
      
      <guid>/questions/10664/using-tshark-to-get-all-avaya-telephones-sorted/</guid>
      <description>Using Tshark to get all Avaya telephones sorted..  0 Hi all, i&#39;m having trouble with the following script, what it&#39;s supposed to do is:
read all files in the folder one by onefilter on all Avaya OUI Mac addresses (is there a better way for this as well?)print only eth src, dst and ip src and dst addressesprint all uniq entries sorted in a file called MAC-$file.csv
$ for file in dir -d * ; do</description>
    </item>
    
    <item>
      <title>ICMP reply packets missing in winXP capture</title>
      <link>/questions/10667/icmp-reply-packets-missing-in-winxp-capture/</link>
      <pubDate>Fri, 04 May 2012 01:58:00 +0000</pubDate>
      
      <guid>/questions/10667/icmp-reply-packets-missing-in-winxp-capture/</guid>
      <description>ICMP reply packets missing in winXP capture  0 I did a capture on a hub with a winXP WS1.6.2 machine (not the source or destination) of PING&#39;s from several machines/IP&#39;s to a machine with [email protected] 10.22.249.47 (this machne being on the hub as well, with the same speed). In the capture I see the ICMP Echo Requests, but the replies are missing although the replies do come back to the source.</description>
    </item>
    
    <item>
      <title>missing base.HEX definition in Lua</title>
      <link>/questions/10681/missing-basehex-definition-in-lua/</link>
      <pubDate>Fri, 04 May 2012 05:03:00 +0000</pubDate>
      
      <guid>/questions/10681/missing-basehex-definition-in-lua/</guid>
      <description>missing base.HEX definition in Lua  0 I&#39;m trying to write a dissector in Lua, and I ran this code:
local asc = Proto(&amp;quot;asc&amp;quot;, &amp;quot;ASC Protocol&amp;quot;) local f = asc.fields f.version = ProtoField.uint8(&amp;quot;asc.version&amp;quot;, &amp;quot;version&amp;quot;, base.HEX, nil, 0xC)but I receive the following error:
attempt to index global &amp;#39;base&amp;#39; (a nil value)How do I fix this?
lua dissectorasked 04 May &#39;12, 05:03
Olga
1●2●2●4
accept rate: 0%
 edited 23 May &#39;12, 07:01</description>
    </item>
    
    <item>
      <title>How can I fix the NPF Driver not running error?</title>
      <link>/questions/10683/how-can-i-fix-the-npf-driver-not-running-error/</link>
      <pubDate>Fri, 04 May 2012 06:47:00 +0000</pubDate>
      
      <guid>/questions/10683/how-can-i-fix-the-npf-driver-not-running-error/</guid>
      <description>How can I fix the NPF Driver not running error?  0 I keep getting a message when I start Wireshark that the NPF driver is not running. Nothing that I have done has been able to get this to run. The latest version of WinPcap is installed on my laptop. What can I do?
windows npfasked 04 May &#39;12, 06:47
emjohnson1125
1●1●1●1
accept rate: 0%
 edited 04 May &#39;12, 13:14</description>
    </item>
    
    <item>
      <title>Viewing SSL packets</title>
      <link>/questions/10689/viewing-ssl-packets/</link>
      <pubDate>Fri, 04 May 2012 14:01:00 +0000</pubDate>
      
      <guid>/questions/10689/viewing-ssl-packets/</guid>
      <description>Viewing SSL packets  0 If I just want to see encrypted SSL packets, do I need to capture the handshake (even if I am not decrypting the packets?) I am trying to find out this information to help a friend who started capturing after the handshake and is getting far fewer packets than expected.
Thanks
sslasked 04 May &#39;12, 14:01
dcushing
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireless Interface not listed</title>
      <link>/questions/10691/wireless-interface-not-listed/</link>
      <pubDate>Fri, 04 May 2012 20:46:00 +0000</pubDate>
      
      <guid>/questions/10691/wireless-interface-not-listed/</guid>
      <description>Wireless Interface not listed  0 Hello,
I&#39;m using the 64-bit version of Wireshark on a Windows 7 laptop and in the program when I go to Capture-&amp;gt;Interfaces, it does not show the wireless adapter of the laptop. It shows the Ethernet card of the laptop but not the wireless.
Is there a way to add the wireless card to the interface list?
I primarily use the laptop with a wireless network and so was under the impression that monitoring the wireless network should be possible.</description>
    </item>
    
    <item>
      <title>wireshark doesnt see my USB interface</title>
      <link>/questions/10696/wireshark-doesnt-see-my-usb-interface/</link>
      <pubDate>Sat, 05 May 2012 06:09:00 +0000</pubDate>
      
      <guid>/questions/10696/wireshark-doesnt-see-my-usb-interface/</guid>
      <description>wireshark doesnt see my USB interface  0 hi, what should i do to make wireshark see my interface its nat Ethernet its USB connection ..thank you for your help
networkinterfacesasked 05 May &#39;12, 06:09
shilan
1●1●1●1
accept rate: 0%
what do you mean by: &#34;my interface its nat Ethernet its USB connection&#34;? Is this a USB network adapter? If so, what&#39;s the output of &#34;tshark -D&#34;?
(06 May &#39;12, 08:29) Kurt Knochner ♦   </description>
    </item>
    
    <item>
      <title>use wireshark to restore VOIP streams</title>
      <link>/questions/10709/use-wireshark-to-restore-voip-streams/</link>
      <pubDate>Sun, 06 May 2012 19:09:00 +0000</pubDate>
      
      <guid>/questions/10709/use-wireshark-to-restore-voip-streams/</guid>
      <description>use wireshark to restore VOIP streams  0 hello, I use wireshatk to capture RTP streams and restore them. But the waveform is in yellow background and there is no waveform curve.After I click play button, there is no voice. My wireshark version is 1.6.4. Thank you.
restoreasked 06 May &#39;12, 19:09
qingbaibai
1●1●1●2
accept rate: 0%
  
One Answer:
  
1Then the codec used is probably not supported.</description>
    </item>
    
    <item>
      <title>how to find the maximum segment size</title>
      <link>/questions/10713/how-to-find-the-maximum-segment-size/</link>
      <pubDate>Sun, 06 May 2012 23:29:00 +0000</pubDate>
      
      <guid>/questions/10713/how-to-find-the-maximum-segment-size/</guid>
      <description>how to find the maximum segment size  0 I have this wireshark file with a list of traffics. I want to find the maximum segment size of a TCP segment but I can&#39;t find it. I saw online that this is normally found when you expand the TCP line and under the &#34;Options&#34; line, but I can&#39;t seem to find the Options line, all it has under TCP is &#34;</description>
    </item>
    
    <item>
      <title>How do I get the acknowledgement number for a packet in Wireshark using Lua?</title>
      <link>/questions/10723/how-do-i-get-the-acknowledgement-number-for-a-packet-in-wireshark-using-lua/</link>
      <pubDate>Mon, 07 May 2012 03:20:00 +0000</pubDate>
      
      <guid>/questions/10723/how-do-i-get-the-acknowledgement-number-for-a-packet-in-wireshark-using-lua/</guid>
      <description>How do I get the acknowledgement number for a packet in Wireshark using Lua?  0 I am writing a Lua dissector for a protocol on top of the TCP protocol. It needs to store the acknowledgment number of request packets, in order to determine which is the corresponding response packet.
For example I can get the packet number with pinfo.number, is there any similar way I can access the acknowledgement number?</description>
    </item>
    
    <item>
      <title>tshark option -M (together with -D)</title>
      <link>/questions/10726/tshark-option-m-together-with-d/</link>
      <pubDate>Mon, 07 May 2012 05:50:00 +0000</pubDate>
      
      <guid>/questions/10726/tshark-option-m-together-with-d/</guid>
      <description>tshark option -M (together with -D)  0 Hi,
is there a reason why tshark does not offer the option -M (together with -D), comparable to dumpcap? dumpcap -D -M dumps the IP address of the interface, which is quite usefull to identify the right NIC, if there are several similar (or identical) ones in a machine. BTW: tshark does not complain about any unknown option (e.g. -M), if used after -D.</description>
    </item>
    
    <item>
      <title>tcp segment of a reassembled PDU</title>
      <link>/questions/10727/tcp-segment-of-a-reassembled-pdu/</link>
      <pubDate>Mon, 07 May 2012 06:09:00 +0000</pubDate>
      
      <guid>/questions/10727/tcp-segment-of-a-reassembled-pdu/</guid>
      <description>tcp segment of a reassembled PDU  0 In the captured packets(by wireshark),there are a lot of tcp segment of a reassembled PDU.the packet have data,but if i want export the packet out in a text file, in the text file i can not see the data?
tcp-segmentasked 07 May &#39;12, 06:09
yizhibi
1●2●2●3
accept rate: 0%
  
One Answer:
  
1You can disable &#34;Allow subdissector to reassemble TCP streams&#34;</description>
    </item>
    
    <item>
      <title>BER Error: This field lies beyond the end of the known sequence definition.</title>
      <link>/questions/10729/ber-error-this-field-lies-beyond-the-end-of-the-known-sequence-definition/</link>
      <pubDate>Mon, 07 May 2012 06:47:00 +0000</pubDate>
      
      <guid>/questions/10729/ber-error-this-field-lies-beyond-the-end-of-the-known-sequence-definition/</guid>
      <description>BER Error: This field lies beyond the end of the known sequence definition.  0 Dear Team, I am trying to decode IDP query trace from GSM world, i am getting the above error after the field iPSSPCapabilities: 00 in Expert Info: BER ERROR UNKNOWN FIELD IN SEQUENCE is the message, kindly let me know how to get this error cleared.
gsmasked 07 May &#39;12, 06:47
praveen_kr
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>how to config Master-key and Session-ID in wireshark</title>
      <link>/questions/10730/how-to-config-master-key-and-session-id-in-wireshark/</link>
      <pubDate>Mon, 07 May 2012 06:55:00 +0000</pubDate>
      
      <guid>/questions/10730/how-to-config-master-key-and-session-id-in-wireshark/</guid>
      <description>how to config Master-key and Session-ID in wireshark  0 i read the &#34;Follow SSL stream using Master-key and Session-ID&#34;(http://ask.wireshark.org/questions/4229/follow-ssl-stream-using-master-key-and-session-id) but i don&#39;t knew how to config in wireshark, Edit-&amp;gt; preference-&amp;gt;protocols-&amp;gt;ssl, but where to set RSA Session-ID:xxxx Master-Key:xxxx,????
session-id ssl master-keyasked 07 May &#39;12, 06:55
endofkok3
1●1●1●2
accept rate: 0%
  
One Answer:
  
1Within the SSL preferences, there should be a text box called
(Pre)-Master-Secret log filename</description>
    </item>
    
    <item>
      <title>Using Wireshark to monitor specific locations on a map that have IP&amp;#x27;s within the area searched</title>
      <link>/questions/10738/using-wireshark-to-monitor-specific-locations-on-a-map-that-have-ips-within-the-area-searched/</link>
      <pubDate>Mon, 07 May 2012 08:59:00 +0000</pubDate>
      
      <guid>/questions/10738/using-wireshark-to-monitor-specific-locations-on-a-map-that-have-ips-within-the-area-searched/</guid>
      <description>Using Wireshark to monitor specific locations on a map that have IP&amp;rsquo;s within the area searched  -2 I hate hackers and voyeurs who think that they have the right for whatever reason their twisted little minds tell them the reason is for their hacking and watching a persons online activity so that that the information can be used for political or religious reasons.
I like my privacy and am entitled to my privacy.</description>
    </item>
    
    <item>
      <title>Erro Message When Starting a Capture Using a WiFi (WLAN) connection</title>
      <link>/questions/10740/erro-message-when-starting-a-capture-using-a-wifi-wlan-connection/</link>
      <pubDate>Mon, 07 May 2012 09:17:00 +0000</pubDate>
      
      <guid>/questions/10740/erro-message-when-starting-a-capture-using-a-wifi-wlan-connection/</guid>
      <description>Erro Message When Starting a Capture Using a WiFi (WLAN) connection  0 Message received when trying to monitor a network.
The capture session could not be initiated (failed to set hardware filter to promiscuous mode).
Please check that &#34;\Device\NPF_{37AEC650-717D-42BF-AB23-4DFA1B1B9748}&#34; is the proper interface.
message wifi for errorasked 07 May &#39;12, 09:17
screenburner
-1●2●2●2
accept rate: 0%
  
One Answer:
  
0Please check this question, with the same problem:</description>
    </item>
    
    <item>
      <title>help with V.150.1 capture</title>
      <link>/questions/10745/help-with-v1501-capture/</link>
      <pubDate>Mon, 07 May 2012 13:02:00 +0000</pubDate>
      
      <guid>/questions/10745/help-with-v1501-capture/</guid>
      <description>help with V.150.1 capture  0 What wireshark version contains the ability to capture V.150.1 information like the SSE and SPRT protocols?
v.150asked 07 May &#39;12, 13:02
dgibson
1●1●1●1
accept rate: 0%
  
One Answer:
  
0by looking at the code of wireshark 1.7.1, I conclude that there is no support vo V.150.1 (V.MOIP). However, you can allways write your own dissector for that protocol.
http://wiki.wireshark.org/Lua/Dissectors</description>
    </item>
    
    <item>
      <title>Any way to use frame.time_delta_displayed in a filter?</title>
      <link>/questions/10747/any-way-to-use-frametime_delta_displayed-in-a-filter/</link>
      <pubDate>Mon, 07 May 2012 13:36:00 +0000</pubDate>
      
      <guid>/questions/10747/any-way-to-use-frametime_delta_displayed-in-a-filter/</guid>
      <description>Any way to use frame.time_delta_displayed in a filter?  0 I&#39;m working with a capture file in which a particular conversation suffers from a periodic interruption. I&#39;d like to be able to use that delay in a display filter, but it just doesn&#39;t seem to work when I&#39;m dealing with one conversation among many. I&#39;ve tried:
tcp.stream eq 12 &amp;amp;&amp;amp; frame.time_delta_displayed &amp;gt; 5.0
and
tcp.stream eq 12 &amp;amp;&amp;amp; frame.time_delta_displayed == 6.</description>
    </item>
    
    <item>
      <title>Error compiling on Solaris 10 - Makefile unexpected end of line</title>
      <link>/questions/10749/error-compiling-on-solaris-10-makefile-unexpected-end-of-line/</link>
      <pubDate>Mon, 07 May 2012 13:53:00 +0000</pubDate>
      
      <guid>/questions/10749/error-compiling-on-solaris-10-makefile-unexpected-end-of-line/</guid>
      <description>Error compiling on Solaris 10 - Makefile unexpected end of line  0 My first attempt at installing Wireshark on a Solaris 10 x86 system was to download the packages from Sunfreeware.com (including all dependencies) and install them. There are some library errors with libwireshark.so.1 where a dependent library (libgnutls.so.26 (&#39;GNU_1_4&#39;)) isn&#39;t found. I&#39;m not finding much on that issue so I decided to try and compile Wireshark myself.
Here is the configure output.</description>
    </item>
    
    <item>
      <title>How would I write a filter to capture specific request operations and their replies?</title>
      <link>/questions/10751/how-would-i-write-a-filter-to-capture-specific-request-operations-and-their-replies/</link>
      <pubDate>Mon, 07 May 2012 15:10:00 +0000</pubDate>
      
      <guid>/questions/10751/how-would-i-write-a-filter-to-capture-specific-request-operations-and-their-replies/</guid>
      <description>How would I write a filter to capture specific request operations and their replies?  0 Hi all - I&#39;m trying to write a display filter that will filter certain specific operations and only their responses - is this possible?
for example the current filter is:
((giop.request_op == &amp;quot;reportStatus&amp;quot;) || (giop.request_op == &amp;quot;getStatus&amp;quot;)|| (giop.request_op == &amp;quot;newChanges&amp;quot;)) || giop.exceptionidIs there any way to include only the responses to these requests? In the case of the exception, I&#39;d love it to throw the request that caused the exception, but I realise this would be potentially difficult.</description>
    </item>
    
    <item>
      <title>Syntax for Multiple Ports In Filter</title>
      <link>/questions/10759/syntax-for-multiple-ports-in-filter/</link>
      <pubDate>Mon, 07 May 2012 17:56:00 +0000</pubDate>
      
      <guid>/questions/10759/syntax-for-multiple-ports-in-filter/</guid>
      <description>Syntax for Multiple Ports In Filter  0 I am trying look for all the ports used by Fifa 12. I am using https://help.ea.com/article/fifa-12-online-ports for the information. Is this the best way look for the information for a PC communications as follows?
(udp.port==9565)||(udp.port==9570)||(udp.port==6000)||(tcp.port==9946)||(tcp.port==9988)||(tcp.port==42124)||(tcp.port&amp;gt;=10000)||(tcp.port&amp;lt;=20000)
fifa12asked 07 May &#39;12, 17:56
Perceptus
10●2●2●6
accept rate: 0%
  
2 Answers:
  
1 If one uses tcp.port, then both source and destination port will match, which makes it impossible to define a valid range, as the source port will be random and might match as well (and possibly more often than the intended destination port)</description>
    </item>
    
    <item>
      <title>the data field in the packet detail pane</title>
      <link>/questions/10761/the-data-field-in-the-packet-detail-pane/</link>
      <pubDate>Mon, 07 May 2012 19:10:00 +0000</pubDate>
      
      <guid>/questions/10761/the-data-field-in-the-packet-detail-pane/</guid>
      <description>the data field in the packet detail pane  0 When I export the packet out to a text file,there are hexadecimal data in the file If there is a data field in the packet detail pane.But if there is not this field,I can not get the data when export the packet out to the text file in spite of it contains many bytes data. The data field Such as the following: field dataasked 07 May &#39;12, 19:10</description>
    </item>
    
    <item>
      <title>End to End message tracking -is it possible with wireshark</title>
      <link>/questions/10763/end-to-end-message-tracking-is-it-possible-with-wireshark/</link>
      <pubDate>Mon, 07 May 2012 22:03:00 +0000</pubDate>
      
      <guid>/questions/10763/end-to-end-message-tracking-is-it-possible-with-wireshark/</guid>
      <description>End to End message tracking -is it possible with wireshark  0 We are planning to implement end-to-end message tracking functionality.We have various products/appliations running on Linux servers and they exchange messges(XML,HTTP,HTTPS,LDAP) in our architecure.We thought of using tshark(for https-SSL) and tcpflow(for other protocols) and we are able to track each and every messge which is flowing from one linux server to the other.I wanted to know how we can implement the messge correlation?</description>
    </item>
    
    <item>
      <title>Window appears off-screen!</title>
      <link>/questions/10765/window-appears-off-screen/</link>
      <pubDate>Tue, 08 May 2012 00:53:00 +0000</pubDate>
      
      <guid>/questions/10765/window-appears-off-screen/</guid>
      <description>Window appears off-screen!  1 1Running on Windows 7, with three monitors attached, the main window appears off the top of the leftmost screen, so it is impossible to drag the title bar. I use keyboard commands to move it. Next time I run Wireshark it does not reappear where I left it, but once again is off-screen.
It appears to be positioned as high up as the main screen would allow, but the left screen doesn&#39;t go that high up.</description>
    </item>
    
    <item>
      <title>Can Download Wireshark for Ubuntu Linux?</title>
      <link>/questions/10784/can-download-wireshark-for-ubuntu-linux/</link>
      <pubDate>Tue, 08 May 2012 10:34:00 +0000</pubDate>
      
      <guid>/questions/10784/can-download-wireshark-for-ubuntu-linux/</guid>
      <description>Can Download Wireshark for Ubuntu Linux?  1 1Hi everyone! I use Ubuntu Linux and would like to download Wireshark. But in the list of Third-Party Packages, the link to download it for Ubuntu takes me to a page that says that Wireshark software does not exist for Ubuntu. (Here&#39;s the link: http://packages.ubuntu.com/search?suite=all&amp;amp;searchon=names&amp;amp;keywords=wireshark)
So does that mean it&#39;s not possible for me to download it for my computer? Or is there some other way?</description>
    </item>
    
    <item>
      <title>bus error core dump when running capture on bge1 on sol10.</title>
      <link>/questions/10788/bus-error-core-dump-when-running-capture-on-bge1-on-sol10/</link>
      <pubDate>Tue, 08 May 2012 12:14:00 +0000</pubDate>
      
      <guid>/questions/10788/bus-error-core-dump-when-running-capture-on-bge1-on-sol10/</guid>
      <description>bus error core dump when running capture on bge1 on sol10.  0 why does wireshark 1.6.4 get a bus error core dump when running capture on bge1? it does not core dump on bge0. I am running solaris 10.
coreasked 08 May &#39;12, 12:14
empressdawn2
1●1●1●2
accept rate: 0%
 edited 08 May &#39;12, 12:15 
  
One Answer:
  
0Chances are the problem isn&#39;t with the interface it&#39;s with what&#39;s being captured (e.</description>
    </item>
    
    <item>
      <title>Wireshark hijacked?</title>
      <link>/questions/10792/wireshark-hijacked/</link>
      <pubDate>Tue, 08 May 2012 14:43:00 +0000</pubDate>
      
      <guid>/questions/10792/wireshark-hijacked/</guid>
      <description>Wireshark hijacked?  0 I&#39;ve been running Wireshark for relatively short (1-4 hrs) periods since downloading it several days ago to try to isolate some unauthorized activity on my Dell (in promiscuous mode). About an hour ago my firewall (Vipre) &#39;active connections&#39; showed for the first time that Wireshark has established two outgoing connections through local ports 51201 and 51020, to 75.185.112.192 which appears to be the IP of Road Runner HoldCo LLC.</description>
    </item>
    
    <item>
      <title>Wireshark Capture Analysis</title>
      <link>/questions/10795/wireshark-capture-analysis/</link>
      <pubDate>Tue, 08 May 2012 17:16:00 +0000</pubDate>
      
      <guid>/questions/10795/wireshark-capture-analysis/</guid>
      <description>Wireshark Capture Analysis  0 There is an application which runs smoothly but, during random intervals the application fails. There nothing int the servers or appllication and the problem is directed towrds network with a wireshark capture. I give below some of the captured packets and hoping that some clues would be posted through this forum as I am unfamiliar with interpreting the output.
737783, &amp;quot;13237.043511&amp;quot; ,&amp;quot;Vmware_57:a4 :2a&amp;quot;,&amp;quot;Broadcas t&amp;quot;,&amp;quot;0x8 922&amp;quot;, &amp;quot;77&amp;quot;,&amp;quot;Ethernet II&amp;quot; 737784, &amp;quot;13237.</description>
    </item>
    
    <item>
      <title>MAC address and IP on a LAN</title>
      <link>/questions/10796/mac-address-and-ip-on-a-lan/</link>
      <pubDate>Tue, 08 May 2012 18:11:00 +0000</pubDate>
      
      <guid>/questions/10796/mac-address-and-ip-on-a-lan/</guid>
      <description>MAC address and IP on a LAN  0 I&#39;ve made a capture of a FTP session between my computer and a server. The result of a single packet is as follow:
Ethernet II, Src: 00:80:5f:31:d9:7c, Dst: 00:01:f4:96:50:7f Internet Protocol, Src Addr: 164.0.0.130 (164.0.0.130), Dst Addr: 10.0.0.20 (10.0.0.20) Transmission Control Protocol, Src Port: ftp (21), Dst Port: 32769 (32769), Seq: 81, Ack: 35, Len: 19My questions:
1) Is There a router/switcher between these 2 hosts because they are on different networks?</description>
    </item>
    
    <item>
      <title>Capture packet on wifi adapter</title>
      <link>/questions/10797/capture-packet-on-wifi-adapter/</link>
      <pubDate>Tue, 08 May 2012 21:46:00 +0000</pubDate>
      
      <guid>/questions/10797/capture-packet-on-wifi-adapter/</guid>
      <description>Capture packet on wifi adapter  0 Hello everybody I need some help how i can capture packet form the wifi adapter (TP-Link). Its interface is not displayed in the list where to start capturing in wireshark.
Thanks in advance.
adapter wifi wiresharkasked 08 May &#39;12, 21:46
aamir screen
1●1●1●1
accept rate: 0%
 edited 09 May &#39;12, 02:10 
grahamb ♦
19.8k●3●30●206
  
One Answer:</description>
    </item>
    
    <item>
      <title>Changing Display Filter to Capture Filter</title>
      <link>/questions/10798/changing-display-filter-to-capture-filter/</link>
      <pubDate>Tue, 08 May 2012 21:54:00 +0000</pubDate>
      
      <guid>/questions/10798/changing-display-filter-to-capture-filter/</guid>
      <description>Changing Display Filter to Capture Filter  0 In a previous question, I received some excellent explanation for a display filter. Now, I would like to use that filter with tshark. When I use the current one with tshark, I get a message that says it&#39;s a valid display filter but not a valid capture filter. What are the differences?
The display filter suggested was
udp.port==9565 or udp.port==9570 or udp.port==6000 or tcp.</description>
    </item>
    
    <item>
      <title>SSL decode</title>
      <link>/questions/10805/ssl-decode/</link>
      <pubDate>Tue, 08 May 2012 23:15:00 +0000</pubDate>
      
      <guid>/questions/10805/ssl-decode/</guid>
      <description>SSL decode  0 Hi,
I just downloaded the 1.7.1 source and build it by,
./configure; makeWhen I run this wireshark and try to setup SSL decode (RSA Key list), I don&#39;t find out any such option in preference/protocols/SSL. All I find is the check-boxes and nothing else.
Do I need to build with some extra flags or something?
BTW, I am on Ubuntu 12.04 and want to write a decoder for some custom messages which are sent over SSL.</description>
    </item>
    
    <item>
      <title>could the wireshark analyzer be used in the textbook cd</title>
      <link>/questions/10806/could-the-wireshark-analyzer-be-used-in-the-textbook-cd/</link>
      <pubDate>Tue, 08 May 2012 23:51:00 +0000</pubDate>
      
      <guid>/questions/10806/could-the-wireshark-analyzer-be-used-in-the-textbook-cd/</guid>
      <description>could the wireshark analyzer be used in the textbook cd  0 hello，my tutor wrote a textbook about network protocol analysis, and the book had network packet capture experiments. The wireshark is free of charge and open-source, so we planned to include the software in the textbook CD, and the CD is a gift with the book. Is this legitimate?
legitimateasked 08 May &#39;12, 23:51
wei167
6●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Capture filter bug? - SIP &amp;quot;udp port 5060&amp;quot; is not working with IP-IP-Encapsulation RFC2003</title>
      <link>/questions/10815/capture-filter-bug-sip-udp-port-5060-is-not-working-with-ip-ip-encapsulation-rfc2003/</link>
      <pubDate>Wed, 09 May 2012 01:54:00 +0000</pubDate>
      
      <guid>/questions/10815/capture-filter-bug-sip-udp-port-5060-is-not-working-with-ip-ip-encapsulation-rfc2003/</guid>
      <description>Capture filter bug? - SIP &amp;ldquo;udp port 5060&amp;rdquo; is not working with IP-IP-Encapsulation RFC2003  0 I have an Session Border Controller which can use IP-in-IP encapsulation (RFC 2003) to send all sip data for example to a capture machine.
On that machine I have a wireshark to make SIP traces. It seems capture filter &#34;udp port 5060&#34; is not working. Could it cause by IP-IP encapsulation?
These packets contians the following headers: -Ethernet -IP -IP -UDP -SIP</description>
    </item>
    
    <item>
      <title>how to read K18 rf5 traces in Wireshark?</title>
      <link>/questions/10820/how-to-read-k18-rf5-traces-in-wireshark/</link>
      <pubDate>Wed, 09 May 2012 03:53:00 +0000</pubDate>
      
      <guid>/questions/10820/how-to-read-k18-rf5-traces-in-wireshark/</guid>
      <description>how to read K18 rf5 traces in Wireshark?  0 Hi
I am unable to open rf5 files(K18) using Wireshark. An error reading &#34;rf5 file may be corrupt or damaged&#34; appears. I am using Wireshark 1.6.7. kindly help.
Abhinav
k18asked 09 May &#39;12, 03:53
Abhinav
1●1●1●2
accept rate: 0%
  
2 Answers:
  
1According to the Wiki page, Wireshark supports reading rf5 files from K12 and K15 analyzers, but K18 is not mentioned.</description>
    </item>
    
    <item>
      <title>program running on some machine and some not wireshark report</title>
      <link>/questions/10823/program-running-on-some-machine-and-some-not-wireshark-report/</link>
      <pubDate>Wed, 09 May 2012 05:02:00 +0000</pubDate>
      
      <guid>/questions/10823/program-running-on-some-machine-and-some-not-wireshark-report/</guid>
      <description>program running on some machine and some not wireshark report  0 i made an application that stream an video from a live source to a particular ip address,but when i open the network stream through vlc it says unidentified format.My wireshark shows the following report:-
446 3.534718 192.168.0.1 192.168.0.2 IPv4 1314 Fragmented IP protocol (proto=UDP 0x11, off=0, ID=164f) [Reassembled in #447] 447 3.534773 192.168.0.1 192.168.0.2 UDP 90 Source port: 18886 Destination port: 18886 448 3.</description>
    </item>
    
    <item>
      <title>filters for Torpig / Sinowal etc</title>
      <link>/questions/10839/filters-for-torpig-sinowal-etc/</link>
      <pubDate>Wed, 09 May 2012 07:32:00 +0000</pubDate>
      
      <guid>/questions/10839/filters-for-torpig-sinowal-etc/</guid>
      <description>filters for Torpig / Sinowal etc  0 Could someone tell me where to set the filters on to see on what machine is a rootkit ?
For example. Customer has 100+ pc&#39;s all have antivirus. Now 1 machine has a torpig virus. running wireshark on the server to check packages for 24 hours.
Now i would like to filter it to quickly see it. Did tcp.dstport == 80 as filter and http.</description>
    </item>
    
    <item>
      <title>Wireshark capture stops showing packets…even though my server is definitely receiving client traffic</title>
      <link>/questions/10840/wireshark-capture-stops-showing-packetseven-though-my-server-is-definitely-receiving-client-traffic/</link>
      <pubDate>Wed, 09 May 2012 08:07:00 +0000</pubDate>
      
      <guid>/questions/10840/wireshark-capture-stops-showing-packetseven-though-my-server-is-definitely-receiving-client-traffic/</guid>
      <description>Wireshark capture stops showing packets…even though my server is definitely receiving client traffic  0 0 down vote favorite share [g+] share [fb] share [tw]
I&#39;m looking into a potential network issue. On a dev box I&#39;ve been noticing mysteriously FIN/ACK and RST/ACKs that are breaking comm between my client and server. However, before I can start to tackle that I need to know why a capture session just seems to go dead.</description>
    </item>
    
    <item>
      <title>Where is pcapng development happening and what is the roadmap?</title>
      <link>/questions/10845/where-is-pcapng-development-happening-and-what-is-the-roadmap/</link>
      <pubDate>Wed, 09 May 2012 10:29:00 +0000</pubDate>
      
      <guid>/questions/10845/where-is-pcapng-development-happening-and-what-is-the-roadmap/</guid>
      <description>Where is pcapng development happening and what is the roadmap?  0 Could someone clarify the development process going on for pcapng? It looks interesting, and if the recent blog post on Wireshark.org is an indication, something we need to keep track of.
But where is it happening? Libpcap seems to be incorporating more functionality for reading it, but does not seem to support writing it. Winpcap development seems to have stopped, which bothers me a lot.</description>
    </item>
    
    <item>
      <title>H.264 CBP level 1.3</title>
      <link>/questions/10859/h264-cbp-level-13/</link>
      <pubDate>Wed, 09 May 2012 17:04:00 +0000</pubDate>
      
      <guid>/questions/10859/h264-cbp-level-13/</guid>
      <description>H.264 CBP level 1.3  0 Wireshark seems to show a max bit rate of 2Mbps with CBP profile level 1.3, whereas it should be 768kbps as per standard. Did anyone else find the same?
h.264 sdp rtpasked 09 May &#39;12, 17:04
Bob3280
6●2●2●4
accept rate: 0%
  
One Answer:
  
0 That&#39;s a bug, a fix committed revision 42559.
answered 10 May &#39;12, 22:22
Anders ♦</description>
    </item>
    
    <item>
      <title>Monitor traffic of connected iphone to my wireless network</title>
      <link>/questions/10861/monitor-traffic-of-connected-iphone-to-my-wireless-network/</link>
      <pubDate>Wed, 09 May 2012 20:12:00 +0000</pubDate>
      
      <guid>/questions/10861/monitor-traffic-of-connected-iphone-to-my-wireless-network/</guid>
      <description>Monitor traffic of connected iphone to my wireless network  0 Hi, I want to monitor traffic coming from iphone connected to my wireless network. My Modem+wireless router is Motorola SBG901 and I am on windows laptop. When I run wireshark, It just shows interfaces for my laptop, does not show iphone interface. Is my router capable of this type of sniffing? Can someone please tell me how to do this, without requiring any configuration on iphone?</description>
    </item>
    
    <item>
      <title>Working on jumbo frames with Wireshark</title>
      <link>/questions/10862/working-on-jumbo-frames-with-wireshark/</link>
      <pubDate>Wed, 09 May 2012 20:30:00 +0000</pubDate>
      
      <guid>/questions/10862/working-on-jumbo-frames-with-wireshark/</guid>
      <description>Working on jumbo frames with Wireshark  0 I was asked to do a pcap for an applicaiton that is using jumbo frames over a fiber connection. Are there any special settings - or trap doors - that I need to be aware of? All my captures up to date have been with MTU 1500 and down.
Thanks
jumboframesasked 09 May &#39;12, 20:30
EricKnaus
46●19●20●26
accept rate: 0%
 edited 10 May &#39;12, 12:07</description>
    </item>
    
    <item>
      <title>Adding VLAN Tag on Wireshark capture</title>
      <link>/questions/10868/adding-vlan-tag-on-wireshark-capture/</link>
      <pubDate>Thu, 10 May 2012 00:06:00 +0000</pubDate>
      
      <guid>/questions/10868/adding-vlan-tag-on-wireshark-capture/</guid>
      <description>Adding VLAN Tag on Wireshark capture  0 Hi all, I have basic Wireshark capture (HTTP, CAP format) I would like to put VLAN Tag label on this capture, I mean I want to have the original capture with encapsulate of VLAN ID. For this purpose I having Cisco SW Layer 2 and Layer 3 if needed and two PCs , I am using “bittwist” software to inject the XXX.CAP capture to the SW.</description>
    </item>
    
    <item>
      <title>IPX traffic question</title>
      <link>/questions/10900/ipx-traffic-question/</link>
      <pubDate>Thu, 10 May 2012 08:57:00 +0000</pubDate>
      
      <guid>/questions/10900/ipx-traffic-question/</guid>
      <description>IPX traffic question  0 I have been using Tshark on an Ubuntu server for some time now. I just noticed the other day that if I do a capture using -i any, I have a pile of IPX traffic that is seen. I have looked at the source and dest addresses and they do not seem to be listed in my database of machines on my network. However under the Linux Cooked Capture, there are mac address there that correspond with machines on my network.</description>
    </item>
    
    <item>
      <title>Capture Filter for Arp poisoning</title>
      <link>/questions/10901/capture-filter-for-arp-poisoning/</link>
      <pubDate>Thu, 10 May 2012 10:03:00 +0000</pubDate>
      
      <guid>/questions/10901/capture-filter-for-arp-poisoning/</guid>
      <description>Capture Filter for Arp poisoning  0 Can you create a capture filter where you specify the packet offset and value of the gateway&#39;s ip address and then have a not value for the packet offset and value of the gateway&#39;s mac address. In this way the only packet&#39;s captured would be the poisoner&#39;s mac address.
I can certainly create one as a post filter:
arp.src.proto_ipv4 == xxx.xxx.xxx.xxx &amp;amp;&amp;amp; !arp.src.hw_mac == xx:xx:xx:xx:xx:xx</description>
    </item>
    
    <item>
      <title>How do I remove access_bpf group?</title>
      <link>/questions/10914/how-do-i-remove-access_bpf-group/</link>
      <pubDate>Thu, 10 May 2012 21:02:00 +0000</pubDate>
      
      <guid>/questions/10914/how-do-i-remove-access_bpf-group/</guid>
      <description>How do I remove access_bpf group?  0 1Greetings,
I installed Wireshark 1.6.7 on a 32-bit Intel processor MacBook running OSX 10.6.8.
I now understand I need Wireshark for Snow Leopard and performed the uninstall process up to &#34;remove access_bpf group&#34;.
How do I perform this step?
Thank you for your help.
Regards.
osxasked 10 May &#39;12, 21:02
BeachsideJim
6●1●2●3
accept rate: 0%
 edited 11 May &#39;12, 01:24</description>
    </item>
    
    <item>
      <title>How to enable FP-Hint, MAC-es dissector</title>
      <link>/questions/10917/how-to-enable-fp-hint-mac-es-dissector/</link>
      <pubDate>Thu, 10 May 2012 22:51:00 +0000</pubDate>
      
      <guid>/questions/10917/how-to-enable-fp-hint-mac-es-dissector/</guid>
      <description>How to enable FP-Hint, MAC-es dissector  0 My traffic is built with protocols like below: IP UDP MAC-es RLC TCP
but wireshark can only decode frame up to UDP layer. Aside from writing my own dissector, anything else?
Thanks!
umts rlcasked 10 May &#39;12, 22:51
leonizeme
1●1●1●1
accept rate: 0%
If you are not writing out a header in the FP-hint format, I don&#39;t think it will help you.</description>
    </item>
    
    <item>
      <title>Using Wireshark libraries in C#</title>
      <link>/questions/10923/using-wireshark-libraries-in-c/</link>
      <pubDate>Fri, 11 May 2012 02:49:00 +0000</pubDate>
      
      <guid>/questions/10923/using-wireshark-libraries-in-c/</guid>
      <description>Using Wireshark libraries in C#  0 I want to make my own application using Wireshark libs. I did it already with NetworkMonitor API, but Wireshark offers some protocolls (i.e. S7comm).
The only one possibility I&#39;ve found is to use Wireshark indirectly, using Lua. (Set a reference on LuaInterface.dll then &#34;using LuaInterface&#34; etc.) http://www.dreamincode.net/forums/topic/240886-integrating-lua-with-c%23-using-luainterface/
Is it posiible without Lua? I want to make a reference to Wireshark in my project and to use all benefits of C#.</description>
    </item>
    
    <item>
      <title>How do you launch Wireshark from a remote shell?</title>
      <link>/questions/10941/how-do-you-launch-wireshark-from-a-remote-shell/</link>
      <pubDate>Fri, 11 May 2012 07:03:00 +0000</pubDate>
      
      <guid>/questions/10941/how-do-you-launch-wireshark-from-a-remote-shell/</guid>
      <description>How do you launch Wireshark from a remote shell?  0 Hi, I installed the wireshark-1.0.15-1.el5_6.4.x86_64.rpm packet on my server, and I expected to be able to use the &#34;export DISPLAY&#34; command then &#34;wireshark&#34; command in order to have a real time display of the packets traffic by Wireshark. Instead, the &#34;wireshark&#34; commad gives back &#34;command not found&#34;
wireshark-bash: wireshark: command not found.
The rpm installation was successful. So, what&#39;s wrong?</description>
    </item>
    
    <item>
      <title>analysing packets in a cap file</title>
      <link>/questions/10945/analysing-packets-in-a-cap-file/</link>
      <pubDate>Fri, 11 May 2012 09:59:00 +0000</pubDate>
      
      <guid>/questions/10945/analysing-packets-in-a-cap-file/</guid>
      <description>analysing packets in a cap file  0 Im quite new to wireshark, in fact ive hardly used it.
Basically, we have been set the task to analyse sniffer data in a cap file we have been given. We are also expected to turn all the network packets back into files, web pages emails etc
Does anyone have any idea how i can do this? as im completely confused. I would really appreciate the help</description>
    </item>
    
    <item>
      <title>Switched Network</title>
      <link>/questions/10946/switched-network/</link>
      <pubDate>Fri, 11 May 2012 10:09:00 +0000</pubDate>
      
      <guid>/questions/10946/switched-network/</guid>
      <description>Switched Network  0 Is it possible to use wireshark over a switched network! I&#39;m trying to capture data packets being sent to and from a computer other than mine! I tried setting the capture filter like so &#39;host 10.x.x.x&#39; (where x is a number) but after using the internet on said machine no packets are captured???
switchednetwork wiresharkasked 11 May &#39;12, 10:09
scorpio
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Regarding analysing 11n packets on wireshark</title>
      <link>/questions/10949/regarding-analysing-11n-packets-on-wireshark/</link>
      <pubDate>Fri, 11 May 2012 13:41:00 +0000</pubDate>
      
      <guid>/questions/10949/regarding-analysing-11n-packets-on-wireshark/</guid>
      <description>Regarding analysing 11n packets on wireshark  0 hi, I see a list of over around 10-12 consecutive packets(without any mac in the middle) with the same exact mac timestamp and a block ack after all these packets. Does this mean all these packets were sent as a single block after aggregation? It will be really useful if anyone can throw some light over it. Would MIMO have anything to do with this?</description>
    </item>
    
    <item>
      <title>[closed] computer network</title>
      <link>/questions/10954/computer-network/</link>
      <pubDate>Sat, 12 May 2012 00:33:00 +0000</pubDate>
      
      <guid>/questions/10954/computer-network/</guid>
      <description>[closed] computer network  0 how to calculate rtt time to get the object from server?
cnasked 12 May &#39;12, 00:33
sanjit
1●2●2●2
accept rate: 0%
 closed 12 May &#39;12, 02:57 
grahamb ♦
19.8k●3●30●206
 The question has been closed for the following reason &amp;ldquo;Duplicate Question&amp;rdquo; by grahamb 12 May &amp;lsquo;12, 02:57    </description>
    </item>
    
    <item>
      <title>Computer Network</title>
      <link>/questions/10955/computer-network/</link>
      <pubDate>Sat, 12 May 2012 00:42:00 +0000</pubDate>
      
      <guid>/questions/10955/computer-network/</guid>
      <description>Computer Network  -1 Suppose you visit a website using the browser. The IP address for the associated URL is not cached in your local host, so a DNS lookup is necessary to obtain the IP address. Suppose that your local DNS server is ip-srv1.vanderbilt.edu and the round-trip time (RTT) from your local DNS server is denoted as RTT_dns_local. The local DNS server performs iterative queries to a Root DNS server, a TLD DNS server and an Authorative DNS server.</description>
    </item>
    
    <item>
      <title>no packets visible, Verizon VZAccess wireless broadband</title>
      <link>/questions/10965/no-packets-visible-verizon-vzaccess-wireless-broadband/</link>
      <pubDate>Sun, 13 May 2012 16:11:00 +0000</pubDate>
      
      <guid>/questions/10965/no-packets-visible-verizon-vzaccess-wireless-broadband/</guid>
      <description>no packets visible, Verizon VZAccess wireless broadband  0 I&#39;m new, probably asking a dumb question, and expecting an obvious answer.
I run on an HP laptop, Windows Vista, with a Verizon broadband internet connection and I can see no packet traffic.
My WireShark interface list:
Microsoft .... MS Tunnel Interface Driver ,,, Realtek RTL8102 PCI-E Fast Ethernet NIC ...None of these show any packet traffic. I&#39;ve tried with promiscuous mode on and off.</description>
    </item>
    
    <item>
      <title>Unable Getting SSI noise value in NEC WL300NC(ath9k)</title>
      <link>/questions/10971/unable-getting-ssi-noise-value-in-nec-wl300ncath9k/</link>
      <pubDate>Mon, 14 May 2012 14:04:00 +0000</pubDate>
      
      <guid>/questions/10971/unable-getting-ssi-noise-value-in-nec-wl300ncath9k/</guid>
      <description>Unable Getting SSI noise value in NEC WL300NC(ath9k)  0 now. I want get SSI noise value in Radiotap header by wireshark(on ubuntu 10.04 LTS). but I couldn&#39;t, so it became useless during the weekend..... Then, there are some questions.
1.how to Get SSI noise value in NEC WL300NC(running with ubuntu 10.04 default ath9k)?
2.The conditions which acquire the value? (Device,DriverModule,Config..?)
I already succeeded getting other radiotap values(this card can set to monitor mode).</description>
    </item>
    
    <item>
      <title>Run Time Error</title>
      <link>/questions/10972/run-time-error/</link>
      <pubDate>Mon, 14 May 2012 15:52:00 +0000</pubDate>
      
      <guid>/questions/10972/run-time-error/</guid>
      <description>Run Time Error  0 I am getting &#34;Run Time Error, The application has requested the Run Time to terminate the application in a unusaull way. Please contact the application administrator&#34; while it is capturing the pacjets approxmiately after two minutes.
I am running WireShark on VMware Windows Server 2003 SP2. Any idea?
runtime error wiresharkasked 14 May &#39;12, 15:52
Younisg
1●1●1●1
accept rate: 0%
I have been getting this a lot too in a VM environment with Server 2008 R2.</description>
    </item>
    
    <item>
      <title>How to open two PCAP Files in Wireshark</title>
      <link>/questions/10974/how-to-open-two-pcap-files-in-wireshark/</link>
      <pubDate>Tue, 15 May 2012 00:45:00 +0000</pubDate>
      
      <guid>/questions/10974/how-to-open-two-pcap-files-in-wireshark/</guid>
      <description>How to open two PCAP Files in Wireshark  0 Is it possible to open and to view two (or more) different PCAP files in Wireshark? In other words, is a &#34;multi document interface&#34; possible in Wireshark?
mdiasked 15 May &#39;12, 00:45
ZvDj
1●3●3●3
accept rate: 0%
  
One Answer:
  
0If you use File -&amp;gt; Open, Wireshark will replace the currently viewed pcap file with the new one.</description>
    </item>
    
    <item>
      <title>NPF Driver fails to start</title>
      <link>/questions/10975/npf-driver-fails-to-start/</link>
      <pubDate>Tue, 15 May 2012 00:46:00 +0000</pubDate>
      
      <guid>/questions/10975/npf-driver-fails-to-start/</guid>
      <description>NPF Driver fails to start  0 Microsoft Windows [Version 6.1.7601] Copyright (c) 2009 Microsoft Corporation. All rights reserved. C:\Users\JOURIS SIMBOLON&amp;gt;sc qc npf [SC] QueryServiceConfig SUCCESS
SERVICE_NAME: npf TYPE : 1 KERNEL_DRIVER START_TYPE : 3 DEMAND_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : system32\drivers\NPF.sys LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : WinPcap Packet Driver (NPF) DEPENDENCIES : SERVICE_START_NAME :
C:\Users\JOURIS SIMBOLON&amp;gt;sc start npf [SC] StartService: OpenService FAILED 5:
Access is denied.</description>
    </item>
    
    <item>
      <title>Insert an empty line in Wireshark</title>
      <link>/questions/10980/insert-an-empty-line-in-wireshark/</link>
      <pubDate>Tue, 15 May 2012 02:01:00 +0000</pubDate>
      
      <guid>/questions/10980/insert-an-empty-line-in-wireshark/</guid>
      <description>Insert an empty line in Wireshark  0 Is there a possibility to insert an empty line in the &#34;packet list pane&#34; of Wireshark on some particular spot?
It should be as in the picture below - lines 8 and 10 look like &#34;inserted&#34;. Wenn an empty line is marked, the packet details pane and the packet bytes pane shouls be empty too.
I think about two possibilities:
The PCAP File should not be changed, only the view of the file, orinsert an &#34;</description>
    </item>
    
    <item>
      <title>Wireshark to analyze 802.15.4 packet</title>
      <link>/questions/10993/wireshark-to-analyze-802154-packet/</link>
      <pubDate>Tue, 15 May 2012 07:02:00 +0000</pubDate>
      
      <guid>/questions/10993/wireshark-to-analyze-802154-packet/</guid>
      <description>Wireshark to analyze 802.15.4 packet  0 Hi,
I want to analyze 802.15.4 packet using wireshark. I am encapsulating 802.15.4 packet into udp and sending it to my pc. But anyhow I am unable to decode packet as a 802.15.4.
Does any know in what format I should send this packet so that wireshark can decode it easily. Is there any significance of ether type(809a) while sending in udp? This is my setup: Wireshark&amp;lt;-ethernet-&amp;gt;My 802.</description>
    </item>
    
    <item>
      <title>lua tap and multiple instances of a protocol in one frame</title>
      <link>/questions/11000/lua-tap-and-multiple-instances-of-a-protocol-in-one-frame/</link>
      <pubDate>Tue, 15 May 2012 12:18:00 +0000</pubDate>
      
      <guid>/questions/11000/lua-tap-and-multiple-instances-of-a-protocol-in-one-frame/</guid>
      <description>lua tap and multiple instances of a protocol in one frame  0 I&#39;ve got following situation in one frame in my capture file
Frame ethernet IP SCTP -&amp;gt; MTP3 -&amp;gt; *SCCP* -&amp;gt; TCAP -&amp;gt; INAP SCTP -&amp;gt; MTP3 -&amp;gt; SCCP -&amp;gt; TCAP -&amp;gt; INAP SCTP -&amp;gt; MTP3 -&amp;gt; _SCCP_ -&amp;gt; TCAP -&amp;gt; _CAP_I want to extract information from _CAP_ and _SCCP_ (both marked with underscore above) I used following extractors</description>
    </item>
    
    <item>
      <title>Time sequence stevens graph question</title>
      <link>/questions/11001/time-sequence-stevens-graph-question/</link>
      <pubDate>Tue, 15 May 2012 13:49:00 +0000</pubDate>
      
      <guid>/questions/11001/time-sequence-stevens-graph-question/</guid>
      <description>Time sequence stevens graph question  0 I&#39;m using Wireshark 1.6.7 and 1.5.0, and I noticed an anomaly. After loading a capture file that consists of 300K+ packets, I use the Expert Info feature to check the file for retransmits, duplicate ACK&#39;s and other warnings or errors within a TCP stream. It shows no errors or warnings. Then, I use the TCP Stream Time sequence (Stevens♔) feature to generate a time sequence diagram.</description>
    </item>
    
    <item>
      <title>how to make it so wire-shark auto updates</title>
      <link>/questions/11009/how-to-make-it-so-wire-shark-auto-updates/</link>
      <pubDate>Tue, 15 May 2012 18:21:00 +0000</pubDate>
      
      <guid>/questions/11009/how-to-make-it-so-wire-shark-auto-updates/</guid>
      <description>how to make it so wire-shark auto updates  0 how to make it so wire-shark auto updates
wiresharkasked 15 May &#39;12, 18:21
wiresharkhel...
30●9●9●13
accept rate: 0%
  
2 Answers:
  
0 If by &#34;make it so Wireshark auto-updates&#34; you mean &#34;make it so that when new versions of Wireshark are released, they get installed automatically&#34;, you do it by installing Wireshark as supplied by a Linux distribution or *BSD that provides an update mechanism.</description>
    </item>
    
    <item>
      <title>where is a concise version or summaries of http://www.wireshark.org/docs/wsug_html_chunked/index.html</title>
      <link>/questions/11010/where-is-a-concise-version-or-summaries-of-httpwwwwiresharkorgdocswsug_html_chunkedindexhtml/</link>
      <pubDate>Tue, 15 May 2012 18:28:00 +0000</pubDate>
      
      <guid>/questions/11010/where-is-a-concise-version-or-summaries-of-httpwwwwiresharkorgdocswsug_html_chunkedindexhtml/</guid>
      <description>where is a concise version or summaries of http://www.wireshark.org/docs/wsug_html_chunked/index.html  -1 too wordy, can&#39;t find what&#39;s needed -- excessive
wiresharkasked 15 May &#39;12, 18:28
wiresharkhel...
30●9●9●13
accept rate: 0%
  
One Answer:
  
1 If you mean &#34;where&#39;s the Wireshark help file?&#34; the answer is &#34;nowhere&#34; - for better or worse, there isn&#39;t one. The only user documentation offered by wireshark.org is the User&#39;s Manual and the man pages.</description>
    </item>
    
    <item>
      <title>what is the 1-step method to test if you have &amp;quot;sufficient CapturePrivileges&amp;quot;?</title>
      <link>/questions/11011/what-is-the-1-step-method-to-test-if-you-have-sufficient-captureprivileges/</link>
      <pubDate>Tue, 15 May 2012 18:35:00 +0000</pubDate>
      
      <guid>/questions/11011/what-is-the-1-step-method-to-test-if-you-have-sufficient-captureprivileges/</guid>
      <description>what is the 1-step method to test if you have &amp;ldquo;sufficient CapturePrivileges&amp;rdquo;?  0 http://wiki.wireshark.org/CaptureSetup/CapturePrivileges http://wiki.wireshark.org/CaptureSetup
none of these tell us how to test if we do or not
on win xp system
wiresharkasked 15 May &#39;12, 18:35
wiresharkhel...
30●9●9●13
accept rate: 0%
  
One Answer:
  
2 I think that it&#39;s somewhat difficult on XP to not have capture privs. A simple test is to run tshark -D, if any interfaces are listed then you have capture privs.</description>
    </item>
    
    <item>
      <title>Can I selectively name IPs and MACs?</title>
      <link>/questions/11012/can-i-selectively-name-ips-and-macs/</link>
      <pubDate>Tue, 15 May 2012 18:44:00 +0000</pubDate>
      
      <guid>/questions/11012/can-i-selectively-name-ips-and-macs/</guid>
      <description>Can I selectively name IPs and MACs?  1 1For troubleshooting on a regular basis I would LOVE to right-click on a src or dst addr in EITHER the packet list or packet details pane and name the item and ONLY the item (like an alias). AFAIK this is only currently (1.6.7) available if I edit the hosts file. I do not want to resolve every IP and I don&#39;t want to match MACs to IPs.</description>
    </item>
    
    <item>
      <title>what&amp;#x27;s the primary reason for wireshark not being hosted on github</title>
      <link>/questions/11019/whats-the-primary-reason-for-wireshark-not-being-hosted-on-github/</link>
      <pubDate>Tue, 15 May 2012 23:12:00 +0000</pubDate>
      
      <guid>/questions/11019/whats-the-primary-reason-for-wireshark-not-being-hosted-on-github/</guid>
      <description>what&amp;rsquo;s the primary reason for wireshark not being hosted on github  0 when it&#39;s free -- https://github.com/plans
and the UI is far superior -- http://marmoush.com/2011/10/04/sourceforge-vs-github-2011/
and when it&#39;s leading -- http://sourceforge.net/blog/github-collaboration-and-haters/
wiresharkasked 15 May &#39;12, 23:12
wiresharkhel...
30●9●9●13
accept rate: 0% 
 edited 15 May &#39;12, 23:19 
  
2 Answers:
  
1 Because Wireshark has used svn since the projects start, and has a lot of infrastructure built around that.</description>
    </item>
    
    <item>
      <title>what&amp;#x27;s the primary reason windows can&amp;#x27;t capture usb packets yet linux can</title>
      <link>/questions/11025/whats-the-primary-reason-windows-cant-capture-usb-packets-yet-linux-can/</link>
      <pubDate>Wed, 16 May 2012 01:15:00 +0000</pubDate>
      
      <guid>/questions/11025/whats-the-primary-reason-windows-cant-capture-usb-packets-yet-linux-can/</guid>
      <description>what&amp;rsquo;s the primary reason windows can&amp;rsquo;t capture usb packets yet linux can  0 http://wiki.wireshark.org/CaptureSetup/USB
is it because windows just doesn&#39;t have the software to do so?
wiresharkasked 16 May &#39;12, 01:15
wiresharkhel...
30●9●9●13
accept rate: 0% 
  
2 Answers:
  
1 Microsoft :-)
Just kidding.... Linux offers a subsystem (usbmon) that enables libpcap to sniff USB traffic. There is nothing comparable under windows, as nobody has implemented it yet.</description>
    </item>
    
    <item>
      <title>how to counterscan a system capturing your packets</title>
      <link>/questions/11030/how-to-counterscan-a-system-capturing-your-packets/</link>
      <pubDate>Wed, 16 May 2012 01:38:00 +0000</pubDate>
      
      <guid>/questions/11030/how-to-counterscan-a-system-capturing-your-packets/</guid>
      <description>how to counterscan a system capturing your packets  0 if wireshark cannot, what software can?
wiresharkasked 16 May &#39;12, 01:38
wiresharkhel...
30●9●9●13
accept rate: 0%
 edited 16 May &#39;12, 01:39 
  
One Answer:
  
1 You can&#39;t detect a sniffer if it is listening to traffic passively (on a switch mirror/span/monitor port or a TAP), as it will not interact with the network.</description>
    </item>
    
    <item>
      <title>Wireshark and WinPcap on Win 7</title>
      <link>/questions/11050/wireshark-and-winpcap-on-win-7/</link>
      <pubDate>Wed, 16 May 2012 09:05:00 +0000</pubDate>
      
      <guid>/questions/11050/wireshark-and-winpcap-on-win-7/</guid>
      <description>Wireshark and WinPcap on Win 7  0 Hi,
I have worked with WinPcap site with no luck when I try and install WinPcap native or through Wireshark I get a message it is already installed when this is a new win 7 install.
I can see that others have had this problem but I see no solutions?
I have a network down and need help
Thanks!
winpcap installationasked 16 May &#39;12, 09:05</description>
    </item>
    
    <item>
      <title>Can I save RTP packets without the media data?</title>
      <link>/questions/11052/can-i-save-rtp-packets-without-the-media-data/</link>
      <pubDate>Wed, 16 May 2012 09:12:00 +0000</pubDate>
      
      <guid>/questions/11052/can-i-save-rtp-packets-without-the-media-data/</guid>
      <description>Can I save RTP packets without the media data?  0 I have a trace where I don&#39;t need the media inside the RTP Packets. I need the RTP headers, but not the real payload.
Is it possible to discard/drop the media/payload while saving a trace?
rtp payloadasked 16 May &#39;12, 09:12
Ramsundar Ka...
6●1●1●2
accept rate: 0%
 edited 16 May &#39;12, 09:54 
multipleinte...
1.3k●15●23●40</description>
    </item>
    
    <item>
      <title>Analysing USB traffic</title>
      <link>/questions/11054/analysing-usb-traffic/</link>
      <pubDate>Wed, 16 May 2012 09:15:00 +0000</pubDate>
      
      <guid>/questions/11054/analysing-usb-traffic/</guid>
      <description>Analysing USB traffic  1 2I&#39;ve captured USB traffic using Wireshark, but I&#39;m finding it difficult to analyse. Most of my useful data lies in hundreds of URB_BULK in/out packets (too many to browse through one by one). I&#39;m specifically interested in the actual data sent over USB, not the headers.
For TCP/IP data, I&#39;ve found the &#34;Follow TCP stream&#34; function very useful to view the entire &#34;coversation&#34; between the host and the client, but there doesn&#39;t seem to be anything similar for USB.</description>
    </item>
    
    <item>
      <title>ICMP Checksum.</title>
      <link>/questions/11061/icmp-checksum/</link>
      <pubDate>Wed, 16 May 2012 12:18:00 +0000</pubDate>
      
      <guid>/questions/11061/icmp-checksum/</guid>
      <description>ICMP Checksum.  0 Hi all,
I need your help, I&#39;m trying to calculate checksum on icmp packet type 8 ( Ping ) but I can&#39;t obtain checksum value, how i can do it? what is the value of data field?
I have this values, you can check the print, I hope you can help me.
type 8--8_bits; codigo 0--8_bits; id_be 1 --- 16 bits; id_le 256 --16bits; Se_be 4104---16 bits; Se_le 2064 16 bits data ?</description>
    </item>
    
    <item>
      <title>SRT statistics for TDS?</title>
      <link>/questions/11062/srt-statistics-for-tds/</link>
      <pubDate>Wed, 16 May 2012 12:59:00 +0000</pubDate>
      
      <guid>/questions/11062/srt-statistics-for-tds/</guid>
      <description>SRT statistics for TDS?  0 Is there a way to perform SRT statistics for TDS protocol using the Service Response Time statistics tool like can be done for NFS, SMB, etc? Or maybe is there some other way anyone may know to get request/reply statistics other than going through and doing it manually?
Thank-you
tds statistics srtasked 16 May &#39;12, 12:59
seyerekim
36●3●4●7
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Vendor claims Wireshark incorrectly reporting Out of Order Packets</title>
      <link>/questions/11066/vendor-claims-wireshark-incorrectly-reporting-out-of-order-packets/</link>
      <pubDate>Wed, 16 May 2012 14:37:00 +0000</pubDate>
      
      <guid>/questions/11066/vendor-claims-wireshark-incorrectly-reporting-out-of-order-packets/</guid>
      <description>Vendor claims Wireshark incorrectly reporting Out of Order Packets  0 I am getting traces from TCP Dump from interface of EMC NAS device sending from one network over MPLS WAN to another NAS device. TCP Dump taken from both sending and receiving end. Since we saw out of order reported in trace file of sending device, we assumed it was happening at device. However, the vendor (EMC) says that this is a known problem with the Wireshark dissector.</description>
    </item>
    
    <item>
      <title>Duplicate ICMP echo replies mystery</title>
      <link>/questions/11076/duplicate-icmp-echo-replies-mystery/</link>
      <pubDate>Wed, 16 May 2012 20:01:00 +0000</pubDate>
      
      <guid>/questions/11076/duplicate-icmp-echo-replies-mystery/</guid>
      <description>Duplicate ICMP echo replies mystery  0 When running a ping -t to one of our Cisco routers, we noticed on occasion a (DUP!) after a few of the replies. When looking at the pcap, I can see the sequence number of the request with 2 replies from the same target. The only difference I could see was that in the first reply, WS showed that it was a response to the requesting packet and in the second reply, there was no such reference.</description>
    </item>
    
    <item>
      <title>Error: Unhandled Exception (group=1, code=6)</title>
      <link>/questions/11088/error-unhandled-exception-group1-code6/</link>
      <pubDate>Thu, 17 May 2012 01:00:00 +0000</pubDate>
      
      <guid>/questions/11088/error-unhandled-exception-group1-code6/</guid>
      <description>Error: Unhandled Exception (group=1, code=6)  0 hi, when i use tshark to sniffer, it always appear error:Unhandled Exception (group=1, code=6)
My cmd is &#34;tshark -nn -i eth1 -t ad -R &#39;(tcp.flags.syn == 1 and tcp.flags.ack == 0 and ip.dst&amp;lt;192.168.0.0 or ip.dst&amp;gt;192.168.255.255)&#39;&#34;
Firstly, i thought maybe the memory isn`t enough, but after i freed memory,i found it still error and now the free memory have 4G,
Can you tell me how to solve?</description>
    </item>
    
    <item>
      <title>using command line option to save major udp/tcp flows</title>
      <link>/questions/11098/using-command-line-option-to-save-major-udptcp-flows/</link>
      <pubDate>Thu, 17 May 2012 05:08:00 +0000</pubDate>
      
      <guid>/questions/11098/using-command-line-option-to-save-major-udptcp-flows/</guid>
      <description>using command line option to save major udp/tcp flows  0 Can anyone please tell me what is the difference between wireshark, ethereal and tshark ? And which one should be used for my below problem ?
i want to save the major udp/tcp flows (by major i mean having maximum number of bytes) using command line ethereal (or tshark/wireshark if not possible with ethereal) , to a separate pcap. Then sometimes, i would like to even save the 2nd major udp &amp;amp; tcp flows (want to save udp and tcp flows separately) in a separate pcap.</description>
    </item>
    
    <item>
      <title>No [SYN, ACK] from some web sites</title>
      <link>/questions/11099/no-syn-ack-from-some-web-sites/</link>
      <pubDate>Thu, 17 May 2012 05:11:00 +0000</pubDate>
      
      <guid>/questions/11099/no-syn-ack-from-some-web-sites/</guid>
      <description>No [SYN, ACK] from some web sites  0 I’ve set up a lone server connected via LAN to a router. It used to work fine, but something happened and messed up my Network settings.
Now after re-setting up the lan connection to the gateway I can only open some sites from the server. The sites I can’t open - I get using the Wireshark software this message: 4679 6697.004581 10.</description>
    </item>
    
    <item>
      <title>Wireshark 1.7.1 Solaris Sparc installation failed</title>
      <link>/questions/11100/wireshark-171-solaris-sparc-installation-failed/</link>
      <pubDate>Thu, 17 May 2012 05:39:00 +0000</pubDate>
      
      <guid>/questions/11100/wireshark-171-solaris-sparc-installation-failed/</guid>
      <description>Wireshark 1.7.1 Solaris Sparc installation failed  0 In file included from packet-coap.c:32: ../../config.h:391:1: &amp;quot;_FILE_OFFSET_BITS&amp;quot; redefined In file included from /usr/include/stdio.h:21, from packet-coap.c:1: /usr/include/sys/feature_tests.h:187:1: this is the location of the previous definition make[5]: *** [libdissectors_la-packet-coap.lo] Error 1 make[5]: Leaving directory `/Software/wireshark-1.7.1/epan/dissectors&amp;#39; make[4]: *** [all-recursive] Error 1 make[4]: Leaving directory `/Software/wireshark-1.7.1/epan/dissectors&amp;#39; make[3]: *** [all] Error 2 make[3]: Leaving directory `/Software/wireshark-1.7.1/epan/dissectors&amp;#39; make[2]: *** [all-recursive] Error 1 make[2]: Leaving directory `/Software/wireshark-1.7.1/epan&amp;#39; make[1]: *** [all-recursive] Error 1 make[1]: Leaving directory `/Software/wireshark-1.</description>
    </item>
    
    <item>
      <title>Insensitive network tap or wireshark 1.6.7 dropping packets?</title>
      <link>/questions/11105/insensitive-network-tap-or-wireshark-167-dropping-packets/</link>
      <pubDate>Thu, 17 May 2012 08:21:00 +0000</pubDate>
      
      <guid>/questions/11105/insensitive-network-tap-or-wireshark-167-dropping-packets/</guid>
      <description>Insensitive network tap or wireshark 1.6.7 dropping packets?  0 I have a Datacom Systems Singlestream 10/100 Link Aggregation tap (http://www.datacomsystems.com/datasheets/SS-100.pdf) between my LAN and my WAN router. I should be seeing all traffic to/from this site&#39;s network on a laptop connected to one of the monitor ports on the tap. I have Wireshark 1.6.7 running on the laptop.
I am unable to see full traffic between a couple of devices on the LAN going to remote destinations across the WAN.</description>
    </item>
    
    <item>
      <title>Why can I not see all addresses on network?</title>
      <link>/questions/11110/why-can-i-not-see-all-addresses-on-network/</link>
      <pubDate>Thu, 17 May 2012 11:17:00 +0000</pubDate>
      
      <guid>/questions/11110/why-can-i-not-see-all-addresses-on-network/</guid>
      <description>Why can I not see all addresses on network?  0 Hi, I need some help. I have installed Wireshark on a PC that is connected to a switch, this inturn is connected to a Motorola CMM and then to multiple Motorola Canopy backhauls which then feed to CMM and then onto the AP/SM. all these are on 10.x.x.x
I can see some of the 10.x.x.x IP addresses, I can also see some of the customers IP addresses (i.</description>
    </item>
    
    <item>
      <title>Internet header &#43; 64 bits o datagram</title>
      <link>/questions/11114/internet-header-64-bits-o-datagram/</link>
      <pubDate>Thu, 17 May 2012 12:29:00 +0000</pubDate>
      
      <guid>/questions/11114/internet-header-64-bits-o-datagram/</guid>
      <description>Internet header + 64 bits o datagram  0 Hello,
I have a little question about the field &#34;Internet Header + 64 bits of Data Datagram&#34; when I trying to calculate checksum icmp type 11. How can i check it on wireshark?
Thanks checksumasked 17 May &#39;12, 12:29
blackfredy
0●2●2●5
accept rate: 0%
 edited 17 May &#39;12, 12:31 
  
One Answer:
  
1 The checksum calculation works exactly the same as for ICMP ECHO/ECHO-REPLY packets.</description>
    </item>
    
    <item>
      <title>support for g8032v2</title>
      <link>/questions/11124/support-for-g8032v2/</link>
      <pubDate>Thu, 17 May 2012 21:20:00 +0000</pubDate>
      
      <guid>/questions/11124/support-for-g8032v2/</guid>
      <description>support for g8032v2  0 when will wirehark support itu-g8032v2 packet capture and decode?
dissector itu-g8032v2asked 17 May &#39;12, 21:20
dtiernan
1●1●1●2
accept rate: 0%
 edited 18 May &#39;12, 12:40 
grahamb ♦
19.8k●3●30●206
  
2 Answers:
  
1When some has enough time and interest to write a dissector for it. Please check Bugzilla, and if there isn&#39;t already an open item for it, then create one and make it as an enhancement.</description>
    </item>
    
    <item>
      <title>TCP PREVIOUS SEGMENT LOST #REALLY RARE CASE#</title>
      <link>/questions/11146/tcp-previous-segment-lost-really-rare-case/</link>
      <pubDate>Sat, 19 May 2012 15:40:00 +0000</pubDate>
      
      <guid>/questions/11146/tcp-previous-segment-lost-really-rare-case/</guid>
      <description>TCP PREVIOUS SEGMENT LOST #REALLY RARE CASE#  0 Hi everybody!
Currently I&#39;m in troubleshooting a web communication problem and I say web because a user tries to web browser unsuccessfully an HP multifuntional administration page that it is located in a remote branch that is connected to the main office using an ISP MPLS where the user is. Here comes the rare part, trying to web brower the HP multifuntional administration page locally it works!</description>
    </item>
    
    <item>
      <title>why wireshark can not decode this packet as mms</title>
      <link>/questions/11148/why-wireshark-can-not-decode-this-packet-as-mms/</link>
      <pubDate>Sat, 19 May 2012 18:49:00 +0000</pubDate>
      
      <guid>/questions/11148/why-wireshark-can-not-decode-this-packet-as-mms/</guid>
      <description>why wireshark can not decode this packet as mms  0 Hi,all. I captured mms packets from traffic, save it as file name &#34;mmscc7&#34;, there is no problem when use wireshark to decode it. but when I use &#34;editcap.exe -r mmscc7 mmscc7300-400&#34; to get packets 300-400 as another file name &#34;mmscc7300-400&#34;,and use wirshark to decode it. I find that packet 37 can not decode as mms, but cotp,the other mms packets are all ok!</description>
    </item>
    
    <item>
      <title>Why Does wireshark not capture any traffic from Source Machine with Outbound Firewall Rules?</title>
      <link>/questions/11149/why-does-wireshark-not-capture-any-traffic-from-source-machine-with-outbound-firewall-rules/</link>
      <pubDate>Sat, 19 May 2012 22:00:00 +0000</pubDate>
      
      <guid>/questions/11149/why-does-wireshark-not-capture-any-traffic-from-source-machine-with-outbound-firewall-rules/</guid>
      <description>Why Does wireshark not capture any traffic from Source Machine with Outbound Firewall Rules?  0 Hi,
I was testing on Windows 2008 Standard Edition (Local Machine IP :- 192.168.2.160) with normal windows firewall (no 3rd party) and created an outbound firewall rule to deny for TCP Ports 80/443 of Remote IP (i.e. 192.168.10.104) (and Local Port All as it could be random). The firewall worked fine and I could block all outbound traffic to Ports 80/443 of that remote IP.</description>
    </item>
    
    <item>
      <title>Remote RTP monitor of second Tomato router using dual nics</title>
      <link>/questions/11151/remote-rtp-monitor-of-second-tomato-router-using-dual-nics/</link>
      <pubDate>Sun, 20 May 2012 02:35:00 +0000</pubDate>
      
      <guid>/questions/11151/remote-rtp-monitor-of-second-tomato-router-using-dual-nics/</guid>
      <description>Remote RTP monitor of second Tomato router using dual nics  0 My setup:
One cable modem (assigned two IP Addresses) to an HP Procurve 1410-8G switch. IP Address 1 to E4200 Tomato router and home network computers. IP Address 2 to E3000 Tomato and IP Phones; Panasonic KX-TGP550T04 base unit plus 3 TPA50 remotes (no computers permanently attached). QoS and bandwidth caps keep things in order.
I have successfully used Wireshark to run a remote capture of RTP and SIP streams from the Panasonic phones on the VOIP network by attaching a netbook running Wireshark to the E3000, and I have also monitored the streams from the home network softphone using Wireshark on one of the home network computers.</description>
    </item>
    
    <item>
      <title>Does Wireshark have an API?</title>
      <link>/questions/11153/does-wireshark-have-an-api/</link>
      <pubDate>Sun, 20 May 2012 06:27:00 +0000</pubDate>
      
      <guid>/questions/11153/does-wireshark-have-an-api/</guid>
      <description>Does Wireshark have an API?  0 Hi everyone,
I am a MSc. student, and I want to use Wireshark to analyze packets and import this result to Java. Anyone know whether Wireshark has an API?
Sarwar
[email protected]unimail.hud.ac.uk
javaasked 20 May &#39;12, 06:27
sarwar
1●1●1●1
accept rate: 0% 
 edited 20 May &#39;12, 14:44 
helloworld
3.1k●4●20●41
Dear All,
Have anyone information about library to analysis packets in Java.</description>
    </item>
    
    <item>
      <title>Wireshark on USB port and Wireless Broadband Modem</title>
      <link>/questions/11158/wireshark-on-usb-port-and-wireless-broadband-modem/</link>
      <pubDate>Sun, 20 May 2012 10:13:00 +0000</pubDate>
      
      <guid>/questions/11158/wireshark-on-usb-port-and-wireless-broadband-modem/</guid>
      <description>Wireshark on USB port and Wireless Broadband Modem  0 Two issues:
Wireshark doesn&#39;t seem to recognize a wireless broadband modem (WBM) connected via the USB port.Using netstat, this particular WBM -- apparetly was being routed through a DOD network, out of Maryland as I recall. Isn&#39;t that interesting.. So, thinking it was a one-time/temporary thing, I acquired another separate unit (though similar/identical manufacturer and model) and -- same thing. Routing through a DOD network.</description>
    </item>
    
    <item>
      <title>capturing of line based text data</title>
      <link>/questions/11168/capturing-of-line-based-text-data/</link>
      <pubDate>Mon, 21 May 2012 01:38:00 +0000</pubDate>
      
      <guid>/questions/11168/capturing-of-line-based-text-data/</guid>
      <description>capturing of line based text data  0 i am trying to filter the line-based text data out of the captured packets using tshark.
tshark -i 3 -R data-text-lines -VUsing the command above would get me a whole data packet, but I would like to extract the line-based text only. Is it possible to obtain only the line based text? Or else any advice for doing that?
tsharkasked 21 May &#39;12, 01:38</description>
    </item>
    
    <item>
      <title>Wireshark in VMWare Machines</title>
      <link>/questions/11170/wireshark-in-vmware-machines/</link>
      <pubDate>Mon, 21 May 2012 04:13:00 +0000</pubDate>
      
      <guid>/questions/11170/wireshark-in-vmware-machines/</guid>
      <description>Wireshark in VMWare Machines  0 I am new to Wireshark and would like to learn a lot. Since I&#39;m a student I have only one Machine(laptop). But, in my laptop, I have installed VMWare Workstation 7. Now my question is...since Wireshark is a network packet analysis tool... Is it possible for me to practice Wireshark in a virtual machine. I mean, I would like to install a Server OS (basically Windows Server 2003) and 5 Win XP OS as a guest and connect them via NAT in the VMWare itself with the server.</description>
    </item>
    
    <item>
      <title>tshark filters using &amp;quot;and&amp;quot; vs &amp;quot;&amp;amp;&amp;amp;&amp;quot;</title>
      <link>/questions/11175/tshark-filters-using-and-vs/</link>
      <pubDate>Mon, 21 May 2012 06:59:00 +0000</pubDate>
      
      <guid>/questions/11175/tshark-filters-using-and-vs/</guid>
      <description>tshark filters using &amp;ldquo;and&amp;rdquo; vs &amp;ldquo;&amp;amp;&amp;amp;&amp;quot;  0 Hi,
I am trying to build a capture filter on some traffic which contains VLAN tags. The frames happen to contain two VLAN tags. I don&#39;t really care what VLANs they are, as I am mainly interested in the destination IP and port number.
If I use this capture filter below, I dont see any traffic:
tshark -i eth1 vlan and host 192.</description>
    </item>
    
    <item>
      <title>[closed] Outlook connection lost frequently</title>
      <link>/questions/11181/outlook-connection-lost-frequently/</link>
      <pubDate>Mon, 21 May 2012 08:12:00 +0000</pubDate>
      
      <guid>/questions/11181/outlook-connection-lost-frequently/</guid>
      <description>[closed] Outlook connection lost frequently  -1 I am using Outlook 2007. I get Outlook connection lost msg very frequently @ home. I connect via wireless from home. Never at office. I switched to a new internet provider recently and experiencing issue since then. Any idea if I need to configure anything?
connection outlook 2007 lostasked 21 May &#39;12, 08:12
psomayaj
0●1●1●1
accept rate: 0%
 closed 21 May &#39;12, 08:33</description>
    </item>
    
    <item>
      <title>TCP eth or IP protocols are not in frame</title>
      <link>/questions/11186/tcp-eth-or-ip-protocols-are-not-in-frame/</link>
      <pubDate>Mon, 21 May 2012 12:54:00 +0000</pubDate>
      
      <guid>/questions/11186/tcp-eth-or-ip-protocols-are-not-in-frame/</guid>
      <description>TCP eth or IP protocols are not in frame  0 Hi, I&#39;m trying to capture some http traffic from a machine&#39;s local interface. So I run a command as such
tshark -i 1 -R data -V -l
The frames I get are like this
Frame 18: 531 bytes on wire (4248 bits), 531 bytes captured (4248 bits) Arrival Time: May 21, 2012 15:15:13.311786000 Eastern Daylight Time Epoch Time: 1337627713.311786000 seconds [Time delta from previous captured frame: 0.</description>
    </item>
    
    <item>
      <title>not recieving http traffic from other computers</title>
      <link>/questions/11187/not-recieving-http-traffic-from-other-computers/</link>
      <pubDate>Mon, 21 May 2012 13:02:00 +0000</pubDate>
      
      <guid>/questions/11187/not-recieving-http-traffic-from-other-computers/</guid>
      <description>not recieving http traffic from other computers  0 Hi I am trying to run Wireshark on my home network to see traffic from several of my computers. I am running Wireshark on my laptop which is running Ubuntu 10.10, has a broadcom 43224 wireless adapter with b43 driver installed.
My home network has WPA+WPA2 security mode.
When I start capture in promiscuous mode I only get http traffic from my own laptop and not the other computers (that are also connected over wireless).</description>
    </item>
    
    <item>
      <title>why program can&amp;#x27;t capture  data from HUB but wireshark can?</title>
      <link>/questions/11200/why-program-cant-capture-data-from-hub-but-wireshark-can/</link>
      <pubDate>Tue, 22 May 2012 01:03:00 +0000</pubDate>
      
      <guid>/questions/11200/why-program-cant-capture-data-from-hub-but-wireshark-can/</guid>
      <description>why program can&amp;rsquo;t capture data from HUB but wireshark can?  0 Recently, my job involved capturing data, which STB communicates with BOSS. I connected my computer with STB using a 10M HUB in sharing mode (not switching mode), then, using wireshark, I do capture the desired data, but using my program, I can not capture any more. My program is linked with libpcap library. What&#39;s more, I download several network analyzing tools, and none of them can work as I desired and capture the desired data.</description>
    </item>
    
    <item>
      <title>MTU Size value</title>
      <link>/questions/11204/mtu-size-value/</link>
      <pubDate>Tue, 22 May 2012 02:02:00 +0000</pubDate>
      
      <guid>/questions/11204/mtu-size-value/</guid>
      <description>MTU Size value  0 Hi, sorry for the &#34;beginners&#34; question :)
I´ve a appliance that works as a transparent bridge. I wanted to know, if i can use wireshark in order to know which is the MTU value that is received by the bridge (i´ve been having issues in regards http latency, and i want to know if this could be network related.
I´m using this filter: tcp.flags.syn== 1 and tcp.</description>
    </item>
    
    <item>
      <title>Lua open_capture_file in tshark</title>
      <link>/questions/11209/lua-open_capture_file-in-tshark/</link>
      <pubDate>Tue, 22 May 2012 05:31:00 +0000</pubDate>
      
      <guid>/questions/11209/lua-open_capture_file-in-tshark/</guid>
      <description>Lua open_capture_file in tshark  0 I want to parse all files in a directory using a Lua tap. The tap is already working, but the problem now is opening snoop files from Lua in tshark. When I try this:
for filename in Dir.open(&amp;quot;D:/snoop/&amp;quot;,&amp;quot;snoop&amp;quot;) do local logfile = filename..&amp;quot;.csv&amp;quot; open_capture_file(filename) endI see:
tshark: Lua: Error during loading: [string &amp;quot;lua_tap_1.lua&amp;quot;]:88: open_capture_file: GUI not available Capturing on Microsoft 0 packets capturedIs there anything like open_capture_file() for tshark (not GUI)?</description>
    </item>
    
    <item>
      <title>Getting field values from ProtoField</title>
      <link>/questions/11211/getting-field-values-from-protofield/</link>
      <pubDate>Tue, 22 May 2012 06:26:00 +0000</pubDate>
      
      <guid>/questions/11211/getting-field-values-from-protofield/</guid>
      <description>Getting field values from ProtoField  0 I have a ProtoField defined as:
proto.led = ProtoField.uint8(&amp;quot;led&amp;quot;, &amp;quot;LED&amp;quot;, base.HEX, LED_FLAGS, 0x1)That bit changes a few fields in the message. Ideally, I&#39;d be able to do something like:
if (proto.led) then -- do a else -- do bIs there any shortcut to grabbing the value of a field (or bit) from the ProtoField definitions? The bit field is displayed correctly in the GUI, so I know I am parsing this part right.</description>
    </item>
    
    <item>
      <title>How to sniff information leaving a piece of software.</title>
      <link>/questions/11212/how-to-sniff-information-leaving-a-piece-of-software/</link>
      <pubDate>Tue, 22 May 2012 06:26:00 +0000</pubDate>
      
      <guid>/questions/11212/how-to-sniff-information-leaving-a-piece-of-software/</guid>
      <description>How to sniff information leaving a piece of software.  0 I need to streamline a process for a client. Currently he has a bit of software which extracts products from a supplier website which he then manually imports into his website to sell. Once the sale of the product is done on the client&#39;s site though, he needs to update the software which then updates the supplier website. Very clunky.</description>
    </item>
    
    <item>
      <title>Realtime Analysis with WireShark GUI</title>
      <link>/questions/11217/realtime-analysis-with-wireshark-gui/</link>
      <pubDate>Tue, 22 May 2012 09:26:00 +0000</pubDate>
      
      <guid>/questions/11217/realtime-analysis-with-wireshark-gui/</guid>
      <description>Realtime Analysis with WireShark GUI  0 Has anyone tried real-time packet analysis using wiresharks GUI with high volumes of traffic(&amp;gt;1Gbps)? Is this even possible with Wireshark?
analysis packet real-timeasked 22 May &#39;12, 09:26
kfryklund
1●3●3●4
accept rate: 0%
 edited 22 May &#39;12, 17:38 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
1if you say &amp;gt; 1 GBit/s. Do you mean 10 GBit/s? If so, there have been talks about this at several sharkfest events:</description>
    </item>
    
    <item>
      <title>How can I capture packets between a wireless laptop and a router? (linux)</title>
      <link>/questions/11225/how-can-i-capture-packets-between-a-wireless-laptop-and-a-router-linux/</link>
      <pubDate>Tue, 22 May 2012 12:59:00 +0000</pubDate>
      
      <guid>/questions/11225/how-can-i-capture-packets-between-a-wireless-laptop-and-a-router-linux/</guid>
      <description>How can I capture packets between a wireless laptop and a router? (linux)  0 I tried sniffing packets with monitor mode, and I&#39;m not getting the packets between the laptop and the router. I also tried turning off promiscuous mode, but with no success. All of what i&#39;m picking up is just &#34;broadcasts&#34;.
Is there something i&#39;m missing? It should be really easy to read packets that are wirelessly transmitted right?</description>
    </item>
    
    <item>
      <title>How to decode 3GPP LTE messages using Wireshark</title>
      <link>/questions/11231/how-to-decode-3gpp-lte-messages-using-wireshark/</link>
      <pubDate>Tue, 22 May 2012 20:41:00 +0000</pubDate>
      
      <guid>/questions/11231/how-to-decode-3gpp-lte-messages-using-wireshark/</guid>
      <description>How to decode 3GPP LTE messages using Wireshark  0 Hi all,
I am trying to capture the MAC, RLC, PDCP and RRC messages from a LTE usb dongle.
I&#39;m new to wireshark but have been reading about the dissectors but I find it a bit confusing.
Could someone explain to me how to go about seeing the LTE messages using wireshark?
Regards,
J
pdcp-lte rrc rlc lte wiresharkasked 22 May &#39;12, 20:41</description>
    </item>
    
    <item>
      <title>does mtu size on capture NIC limit the size of packets you can capture?</title>
      <link>/questions/11232/does-mtu-size-on-capture-nic-limit-the-size-of-packets-you-can-capture/</link>
      <pubDate>Tue, 22 May 2012 20:49:00 +0000</pubDate>
      
      <guid>/questions/11232/does-mtu-size-on-capture-nic-limit-the-size-of-packets-you-can-capture/</guid>
      <description>does mtu size on capture NIC limit the size of packets you can capture?  0 I&#39;m wondering, because I captured traffic on a network link that handles &#34;jumbo&#34; frames, but the capture NIC I used had the MTU set at the default 1500 value. I looked at the resulting .pcap file, and I do have frames with byte sizes exceeding 1500. So can anyone confirm that the promisc function of the NIC is not subject to the MTU set on the NIC?</description>
    </item>
    
    <item>
      <title>SIP - Bindings</title>
      <link>/questions/11241/sip-bindings/</link>
      <pubDate>Tue, 22 May 2012 23:02:00 +0000</pubDate>
      
      <guid>/questions/11241/sip-bindings/</guid>
      <description>SIP - Bindings  0 What does bindings means in SIP. And what does 1 bindings and 0 bindings refers?
sip_bindingsasked 22 May &#39;12, 23:02
devrajk
1●1●1●1
accept rate: 0%
  
One Answer:
  
0from RFC 3261
The REGISTER messages associate Bob&#39;s SIP or SIPS URI (sip:[email protected]biloxi.com) with the machine into which he is currently logged (conveyed as a SIP or SIPS URI in the Contact header field).</description>
    </item>
    
    <item>
      <title>how to add IP address to TreeItem in Lua?</title>
      <link>/questions/11249/how-to-add-ip-address-to-treeitem-in-lua/</link>
      <pubDate>Wed, 23 May 2012 05:19:00 +0000</pubDate>
      
      <guid>/questions/11249/how-to-add-ip-address-to-treeitem-in-lua/</guid>
      <description>how to add IP address to TreeItem in Lua?  0 How can I add an IP address to a TreeItem?
I&#39;m using the following Lua:
sourceIpAddr = ProtoField.uint32(&amp;quot;asc_sccp.sourceIpAddr&amp;quot;, &amp;quot;sourceIpAddr&amp;quot;, base.HEX) subtree:add (sourceIpAddr, buffer(72,4))As a result, I see:
sourceIpAddr: 0But I would like to see:
sourceIpAddr: 0.0.0.0How can I get this result?
lua dissectorasked 23 May &#39;12, 05:19
Olga
1●2●2●4
accept rate: 0%
 edited 23 May &#39;12, 06:37</description>
    </item>
    
    <item>
      <title>What are the CVEs for the 1.4.13 and 1.6.8 releases?</title>
      <link>/questions/11252/what-are-the-cves-for-the-1413-and-168-releases/</link>
      <pubDate>Wed, 23 May 2012 05:30:00 +0000</pubDate>
      
      <guid>/questions/11252/what-are-the-cves-for-the-1413-and-168-releases/</guid>
      <description>What are the CVEs for the 1.4.13 and 1.6.8 releases?  0 What are the CVEs for the 1.4.13 and 1.6.8 releases? In particular for the wnpa-sec-2012-08, wnpa-sec-2012-09 and wnpa-sec-2012-10 advisories for security fixes?
security cveasked 23 May &#39;12, 05:30
andreasstieger
2●1●1●2
accept rate: 0%
  
2 Answers:
  
0 Be patient, young padawan.
answered 23 May &#39;12, 08:57
Jaap ♦
11.7k●16●101
accept rate: 14%
Thanks, just need the info, hold the rest.</description>
    </item>
    
    <item>
      <title>tshark -E occurrence=a</title>
      <link>/questions/11265/tshark-e-occurrencea/</link>
      <pubDate>Wed, 23 May 2012 09:11:00 +0000</pubDate>
      
      <guid>/questions/11265/tshark-e-occurrencea/</guid>
      <description>tshark -E occurrence=a  0 For my purposes, I record packets sent from radios stations that tell me their GPS position. The provider sometimes packages up 4 radio station reports into 1 packet. Basically, all the reports are exactly the same in terms of data, except for one or two fields where its ID# and position are different. All 4 reports are assembled and sent in one packet. I can easily decode and see the 4 distinct reports in that one packet while in the Wireshark GUI.</description>
    </item>
    
    <item>
      <title>802.11 decryption</title>
      <link>/questions/11293/80211-decryption/</link>
      <pubDate>Wed, 23 May 2012 13:09:00 +0000</pubDate>
      
      <guid>/questions/11293/80211-decryption/</guid>
      <description>802.11 decryption  0 Like a few other posters, I&#39;m not able to decrypt data captured from my wifi network.
I have:
Entered the key into the IEEE 802.11 preferences, in the wpa-pwd:KEY:SSID format.Turned on Enable Decryption in the IEEE 802.11 preferences.Tried all combinations of FCS/protection bit.Ensured that I have captured the handshake by:Disconnecting and reconnecting a client.Confirmed EAPOL packets in the capture: I see 1/4, 2/4, 3/4 and 4/4 on the expected addresses.</description>
    </item>
    
    <item>
      <title>RANAP INFORMATION ELEMENTS</title>
      <link>/questions/11299/ranap-information-elements/</link>
      <pubDate>Wed, 23 May 2012 18:52:00 +0000</pubDate>
      
      <guid>/questions/11299/ranap-information-elements/</guid>
      <description>RANAP INFORMATION ELEMENTS  0 Hello,can somebody out there give me an exemple of ranap captured packets and tell me how to find exactly the information elements?i m really new to this Thank you
ranapasked 23 May &#39;12, 18:52
legrand83
1●2●2●2
accept rate: 0%
  
One Answer:
  
0Sample Capture: http://wiki.wireshark.org/SampleCaptures?action=AttachFile&amp;amp;do=view&amp;amp;target=3gpp_mc.cap
Load that file into Wireshark. Then select frame #3 and open the detailed information MTP 3, GSM or whatever you need.</description>
    </item>
    
    <item>
      <title>[closed] assignment of timestamps in sharp-pcap to the captured packets</title>
      <link>/questions/11301/assignment-of-timestamps-in-sharp-pcap-to-the-captured-packets/</link>
      <pubDate>Thu, 24 May 2012 00:20:00 +0000</pubDate>
      
      <guid>/questions/11301/assignment-of-timestamps-in-sharp-pcap-to-the-captured-packets/</guid>
      <description>[closed] assignment of timestamps in sharp-pcap to the captured packets  0 hi i need a code for assigning timestamps(readble format) to the incoming packets.plz hep me in this regard i am using the library that is sharp-pcap in c#.
timestampsasked 24 May &#39;12, 00:20
rocky_1025
1●1●1●1
accept rate: 0%
 closed 24 May &#39;12, 00:48 
grahamb ♦
19.8k●3●30●206
 The question has been closed for the following reason &amp;ldquo;I&amp;rsquo;ve closed this as this is the Ask Wireshark Q&amp;amp;A site.</description>
    </item>
    
    <item>
      <title>Automate / Schedule Capture WireShark sessions? (5 minutes top/bottom of each hour)</title>
      <link>/questions/11304/automate-schedule-capture-wireshark-sessions-5-minutes-topbottom-of-each-hour/</link>
      <pubDate>Thu, 24 May 2012 02:34:00 +0000</pubDate>
      
      <guid>/questions/11304/automate-schedule-capture-wireshark-sessions-5-minutes-topbottom-of-each-hour/</guid>
      <description>Automate / Schedule Capture WireShark sessions? (5 minutes top/bottom of each hour)  0 Hello, I&#39;ve been asked to capture data for my Ceton InfiniTV PCI CableCard tuner card. The error I&#39;m trying to capture happens at the start of TV Recordings. The problem is, the error is very intermittent. I can&#39;t leave WireShark in capture mode for more then 5 or 10 minutes, or they data captured will be WAY too big!</description>
    </item>
    
    <item>
      <title>Why is message Time To Live only 1?</title>
      <link>/questions/11309/why-is-message-time-to-live-only-1/</link>
      <pubDate>Thu, 24 May 2012 06:15:00 +0000</pubDate>
      
      <guid>/questions/11309/why-is-message-time-to-live-only-1/</guid>
      <description>Why is message Time To Live only 1?  0 About half of my packets are window size 32768 and TTL = 64, which is what I would expect. I&#39;m on a dedicated VLAN for iSCSI. The other half of my packets are window size 524 and TTL = 1. All these packets come from one host. Like I said, this is a dedicated non-routed VLAN. The customer is experiencing latency issues across the board from several hosts.</description>
    </item>
    
    <item>
      <title>Low WAN Throughput TCP Window scaling</title>
      <link>/questions/11318/low-wan-throughput-tcp-window-scaling/</link>
      <pubDate>Thu, 24 May 2012 16:45:00 +0000</pubDate>
      
      <guid>/questions/11318/low-wan-throughput-tcp-window-scaling/</guid>
      <description>Low WAN Throughput TCP Window scaling  0 I&#39;m troubleshooting a low throughput replication transfer on a OC12 circuit with 36 msec RTT between two sites. The TCP handshake in the trace shows the advertised scaling for the recipient side of the data to be 1MB WS-5. Based on the calculation, the throughput should be around 220Mbps but it&#39;s only 14.6Mbps over an OC12 that&#39;s barely being utilized. Based on the 14Mbps throughput, I estimated the Window size is more 64KB even though the recipient is advertising 1MB.</description>
    </item>
    
    <item>
      <title>[closed] capture logs from router</title>
      <link>/questions/11319/capture-logs-from-router/</link>
      <pubDate>Thu, 24 May 2012 19:45:00 +0000</pubDate>
      
      <guid>/questions/11319/capture-logs-from-router/</guid>
      <description>[closed] capture logs from router  0 How do I collect the logs that the Netgear FVS318v3 sends to the PC?
I point the logs to PC, but I can not see a way to capture them.
capture logsasked 24 May &#39;12, 19:45
AAB
1●1●1●2
accept rate: 0%
 closed 25 May &#39;12, 06:12 
JeffMorriss ♦
6.2k●5●72
 The question has been closed for the following reason &amp;ldquo;Question is off-topic or not relevant&amp;rdquo; by JeffMorriss 25 May &amp;lsquo;12, 06:12</description>
    </item>
    
    <item>
      <title>wireshark in rpm</title>
      <link>/questions/11323/wireshark-in-rpm/</link>
      <pubDate>Fri, 25 May 2012 02:25:00 +0000</pubDate>
      
      <guid>/questions/11323/wireshark-in-rpm/</guid>
      <description>wireshark in rpm  0 dear expert,
please help our issue on installing and running wireshark.rpm
i&#39;ve install wireshark with : rpm -ivh wireshark
then it had installed, but how to running this application ?
i&#39;ve type wireshark on root#wireshark ,
but it cannot running
please advice :(
rpm wiresharkasked 25 May &#39;12, 02:25
chipset83
1●1●1●1
accept rate: 0%
 edited 25 May &#39;12, 03:21 
Kurt Knochner ♦
24.8k●10●39●237</description>
    </item>
    
    <item>
      <title>Make Error.</title>
      <link>/questions/11326/make-error/</link>
      <pubDate>Fri, 25 May 2012 03:54:00 +0000</pubDate>
      
      <guid>/questions/11326/make-error/</guid>
      <description>Make Error.  0 Hello All ,
I am new to Wireshark and also linux env . I am trying to install on ubuntu 12.04 LTS . I checked out from the version repository trying to install . ./autogen.sh ./configure
Both work fine . However , in the next step. when I try to make .
It gives me below error .
[email protected]:~/wireshark$ sudo make /usr/bin/perl ./make-version.pl . Version configuration file version.</description>
    </item>
    
    <item>
      <title>Lua binding / integration - documentation</title>
      <link>/questions/11330/lua-binding-integration-documentation/</link>
      <pubDate>Fri, 25 May 2012 04:20:00 +0000</pubDate>
      
      <guid>/questions/11330/lua-binding-integration-documentation/</guid>
      <description>Lua binding / integration - documentation  2 Hi,
I&#39;m fascinated about Lua, after I had some time to learn a bit of Lua, on a longer travel by train yesterday (also inspired by this question and the code provided by @helloworld). The language is pretty simple but powerful and apparently (sometimes) faster than other scripting languages (I use Perl a lot).
Now my question: Is there a detailed description available about the Lua integration into wireshark?</description>
    </item>
    
    <item>
      <title>tshark -T fields question</title>
      <link>/questions/11331/tshark-t-fields-question/</link>
      <pubDate>Fri, 25 May 2012 07:05:00 +0000</pubDate>
      
      <guid>/questions/11331/tshark-t-fields-question/</guid>
      <description>tshark -T fields question  0 Hi, We have some web services that we&#39;d like to capture packets for using tshark. Some of the service traffic is dissected using -R xml argument and some are dissected using -R data argument. We like to see the payload using the -T fields argument. So with -R data we run the following command. tshark -i 1 -R data -T fields -e frame - frame.</description>
    </item>
    
    <item>
      <title>Qt4 GUI build fails</title>
      <link>/questions/11347/qt4-gui-build-fails/</link>
      <pubDate>Fri, 25 May 2012 11:27:00 +0000</pubDate>
      
      <guid>/questions/11347/qt4-gui-build-fails/</guid>
      <description>Qt4 GUI build fails  1 Hi,
I&#39;m trying to compile the Qt4 version of Wireshark on Ubuntu 12.04 (--with-qt). Unfortunately the build process fails at several places (latest SVN trunk). And: yes, I did install libqt4-dev ;-)
Is it my system, or is the Qt4 build not yet finished?
Regards
Kurt
qt4asked 25 May &#39;12, 11:27
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15% 
 edited 25 May &#39;12, 11:32</description>
    </item>
    
    <item>
      <title>Calculating Enterprise NetFlow Volume</title>
      <link>/questions/11349/calculating-enterprise-netflow-volume/</link>
      <pubDate>Fri, 25 May 2012 13:04:00 +0000</pubDate>
      
      <guid>/questions/11349/calculating-enterprise-netflow-volume/</guid>
      <description>Calculating Enterprise NetFlow Volume  0 how can I use wireshark (or Pilot/Cascade) analysis to determine my enterprise netflows per sec?
volume netflow enterpriseasked 25 May &#39;12, 13:04
Philster
1●1●1●1
accept rate: 0%
determine my enterprise netflows per sec?
what does that mean?
(25 May &#39;12, 13:07) Kurt Knochner ♦a) netflow records per second received, which would mean some sort of investigation of the volume of netflow records coming in b) statistical drilldown of flows reported, which would mean &#34;</description>
    </item>
    
    <item>
      <title>Wrong TimeStamp Determination</title>
      <link>/questions/11353/wrong-timestamp-determination/</link>
      <pubDate>Fri, 25 May 2012 13:35:00 +0000</pubDate>
      
      <guid>/questions/11353/wrong-timestamp-determination/</guid>
      <description>Wrong TimeStamp Determination  0 what criteria is WS using to determine a &#34;wrong timestamp&#34; in an rtp playback? We see &#34;W&#34; &#39;s all over the place in the beginning of the capture but nothing within the packets to tell us which packet it is flagging.
Thanks
Eric
rtp voip wrongtimestampasked 25 May &#39;12, 13:35
EricKnaus
46●19●20●26
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Memory Leak in 1.6.8?</title>
      <link>/questions/11359/memory-leak-in-168/</link>
      <pubDate>Fri, 25 May 2012 15:21:00 +0000</pubDate>
      
      <guid>/questions/11359/memory-leak-in-168/</guid>
      <description>Memory Leak in 1.6.8?  0 I am performing an SNA trace (capture filter is &#34;not ip &amp;amp;&amp;amp; not arp &amp;amp;&amp;amp; not ether proto 0x8805 &amp;amp;&amp;amp; not ether proto 0x8806 &amp;amp;&amp;amp; not ether proto 0x0800&#34;). I am collecting about 10 packets per minute; the last trace file was ~32KB -- small capture data!
Running on Win XP SP3 with latest patches. 1GB RAM, P4 2.66 CPU.
I am seeing the wireshark.</description>
    </item>
    
    <item>
      <title>Wireshark or TShark Working Binary for Fedora 11 (FC11)?</title>
      <link>/questions/11362/wireshark-or-tshark-working-binary-for-fedora-11-fc11/</link>
      <pubDate>Fri, 25 May 2012 15:49:00 +0000</pubDate>
      
      <guid>/questions/11362/wireshark-or-tshark-working-binary-for-fedora-11-fc11/</guid>
      <description>Wireshark or TShark Working Binary for Fedora 11 (FC11)?  0 Is there a working binary for Fedora 11 (FC11)? We are struggling to get it to work. Any suggestions?
linux-support fedoraasked 25 May &#39;12, 15:49
duquet
1●1●1●1
accept rate: 0%
  
One Answer:
  
0what happens if you run this command:
yum install wireshark wireshark-gui
BTW: What are your problems with the binary?
Regards
Kurt</description>
    </item>
    
    <item>
      <title>A good way to learn how to use wireshark</title>
      <link>/questions/11370/a-good-way-to-learn-how-to-use-wireshark/</link>
      <pubDate>Sat, 26 May 2012 01:01:00 +0000</pubDate>
      
      <guid>/questions/11370/a-good-way-to-learn-how-to-use-wireshark/</guid>
      <description>A good way to learn how to use wireshark  0 1I&#39;m new to wireshark, and I&#39;d like to learn how to use it properly.
I&#39;m going to use wireshark to reverse-engineer communication protocols of applications, and I&#39;d like to see an applied sample on how to do this.
I&#39;ve tried to use Wireshark to reverse engeneer communication between zynga pocker client, and the server, and I run into a problem: how can I know, which packets belong to which applications?</description>
    </item>
    
    <item>
      <title>Building a Display filter on a portion of a SIP packet</title>
      <link>/questions/11399/building-a-display-filter-on-a-portion-of-a-sip-packet/</link>
      <pubDate>Sun, 27 May 2012 06:51:00 +0000</pubDate>
      
      <guid>/questions/11399/building-a-display-filter-on-a-portion-of-a-sip-packet/</guid>
      <description>Building a Display filter on a portion of a SIP packet  0 I have a capture of a VoIP call showing lots of dropped packets do to jitter and wrong time stamps that occur only at the very beginning of the call - according to the WS Player - and have figured out the cause (too many packets hitting at once for the router to handle). The packets in question are the SIP &#34;</description>
    </item>
    
    <item>
      <title>how to capture analog lines packets?</title>
      <link>/questions/11408/how-to-capture-analog-lines-packets/</link>
      <pubDate>Sun, 27 May 2012 12:50:00 +0000</pubDate>
      
      <guid>/questions/11408/how-to-capture-analog-lines-packets/</guid>
      <description>how to capture analog lines packets?  0 Can I use wireshark to capture analog lines&#39; voice traffic? And if yes, how?
wireshark analog markasked 27 May &#39;12, 12:50
markkarp
1●2●2●3
accept rate: 0%
 edited 27 May &#39;12, 13:02 
  
One Answer:
  
0Wireshark is a network sniffer. To sniff analog phone lines, you would need a device that &#34;captures&#34; data on those lines and converts it to something wireshark can read.</description>
    </item>
    
    <item>
      <title>Why Do I Have Video Stutter Through Netgear MCAB1001 MoCA Adapters--Possibly Related to TCP Window</title>
      <link>/questions/11413/why-do-i-have-video-stutter-through-netgear-mcab1001-moca-adapters-possibly-related-to-tcp-window/</link>
      <pubDate>Sun, 27 May 2012 16:30:00 +0000</pubDate>
      
      <guid>/questions/11413/why-do-i-have-video-stutter-through-netgear-mcab1001-moca-adapters-possibly-related-to-tcp-window/</guid>
      <description>Why Do I Have Video Stutter Through Netgear MCAB1001 MoCA Adapters&amp;ndash;Possibly Related to TCP Window  0 I use a pair of Netgear MCAB1001 MoCA (multimedia over coax cable) adapters for my home theater setup. The connections are: PC--&amp;gt;Cat6--&amp;gt;WNDR3700 router--&amp;gt;Cat6--&amp;gt;MoCA--&amp;gt;coax cable--&amp;gt;MoCA--&amp;gt;Cat6--&amp;gt;bluray player. LAN Speed Test (www.totusoft.com) indicates I have a sustained read/write of 84Mbps over the adapters on large files. Ping latency from my computer to the bluray player is less than 1ms.</description>
    </item>
    
    <item>
      <title>How to verify signature on the text file containing hashes (of Wireshark binaries)</title>
      <link>/questions/11417/how-to-verify-signature-on-the-text-file-containing-hashes-of-wireshark-binaries/</link>
      <pubDate>Mon, 28 May 2012 00:51:00 +0000</pubDate>
      
      <guid>/questions/11417/how-to-verify-signature-on-the-text-file-containing-hashes-of-wireshark-binaries/</guid>
      <description>How to verify signature on the text file containing hashes (of Wireshark binaries)  0 How to verify signature on the text file containing hashes (of Wireshark binaries) using gpg4win 2.1.0?
Tried several times, says signature invalid
gpg verification pgp signatureasked 28 May &#39;12, 00:51
Hans
1●1●1●2
accept rate: 0%
  
One Answer:
  
2this works on my system:
Download the wireshark PGP Key: http://www.wireshark.org/download/gerald_at_wireshark_dot_org.gpgDownload the signature file: http://www.</description>
    </item>
    
    <item>
      <title>tshark command to write payload to a file</title>
      <link>/questions/11421/tshark-command-to-write-payload-to-a-file/</link>
      <pubDate>Mon, 28 May 2012 02:19:00 +0000</pubDate>
      
      <guid>/questions/11421/tshark-command-to-write-payload-to-a-file/</guid>
      <description>tshark command to write payload to a file  0 Hi, Can some tell me what are the arguments that we need to pass to tshark command to capture all the request and response(http xml) messages and write them to a file in txt format? I am aware of -W option, but the issue is that the file data is not readable; it can only be readable by a tool like wireshark.</description>
    </item>
    
    <item>
      <title>Stop sniffing after a period of network inactivity</title>
      <link>/questions/11429/stop-sniffing-after-a-period-of-network-inactivity/</link>
      <pubDate>Mon, 28 May 2012 11:02:00 +0000</pubDate>
      
      <guid>/questions/11429/stop-sniffing-after-a-period-of-network-inactivity/</guid>
      <description>Stop sniffing after a period of network inactivity  0 I&#39;m triggering tshark to capture packets when certain events occur. The actions I&#39;m interested in capturing might last minutes, hours, or even days before ceasing, are on multiple interfaces, arbitrary hosts/IP addresses (public and private) and are captured in unique filenames.
Unfortunately there is no magic packet that would signal the end of the event, so I have to figure out a way to stop capturing the stuff (obviously there is not much harm done if I continue to capture traffic, but eventually I&#39;ll have to kill off the process!</description>
    </item>
    
    <item>
      <title>error LNK2005 and LNK1169</title>
      <link>/questions/11433/error-lnk2005-and-lnk1169/</link>
      <pubDate>Tue, 29 May 2012 01:42:00 +0000</pubDate>
      
      <guid>/questions/11433/error-lnk2005-and-lnk1169/</guid>
      <description>error LNK2005 and LNK1169  1 Hello guys,
I&#39;ve developped a dissector for a &#34;homemade&#34; protocol. So far, everything went well, it did its job, told all the information I wanted on wireshark. Then, I tried to implement some statistics operation... And it doesn&#39;t compile anymore ! I followed the developer&#39;s guide, implemented the tap functions, the statistics functions. But it doesn&#39;t work.
Here are my error messages :
plugin.obj : error LNK2005: _version already defined in packet-subnet.</description>
    </item>
    
    <item>
      <title>How to use  dissector_add function ?</title>
      <link>/questions/11435/how-to-use-dissector_add-function/</link>
      <pubDate>Tue, 29 May 2012 04:58:00 +0000</pubDate>
      
      <guid>/questions/11435/how-to-use-dissector_add-function/</guid>
      <description>How to use dissector_add function ?  0 I am a newbie trying to make a plugin , and in my case criteria for wireshark to call my dissector has to be that either source or destination mac will be in this format - &#34;02 00 6f 0x 0y 01&#34; where only x and y are positive integers and can vary. Do we have option to use regex sort of thing here ?</description>
    </item>
    
    <item>
      <title>&amp;quot;Delta Time Displayed&amp;quot; not showing &amp;#x27;correct&amp;#x27; values after re-sorting frames by clicking on any column</title>
      <link>/questions/11440/delta-time-displayed-not-showing-correct-values-after-re-sorting-frames-by-clicking-on-any-column/</link>
      <pubDate>Tue, 29 May 2012 06:22:00 +0000</pubDate>
      
      <guid>/questions/11440/delta-time-displayed-not-showing-correct-values-after-re-sorting-frames-by-clicking-on-any-column/</guid>
      <description>&amp;ldquo;Delta Time Displayed&amp;rdquo; not showing &amp;lsquo;correct&amp;rsquo; values after re-sorting frames by clicking on any column  0 I understand that the default order Wireshark is sorting frames is the frame number. Displaying either &#34;Delta Time Displayed&#34; or frame.delta_time_displayed will show the time difference between two frames based on the sorting by frame number.
Unfortunately the &#34;Delta Time Displayed&#34; (∂t) is not being calculated again after one changes the order by sorting by column.</description>
    </item>
    
    <item>
      <title>Wireshark join a multicast</title>
      <link>/questions/11445/wireshark-join-a-multicast/</link>
      <pubDate>Tue, 29 May 2012 08:31:00 +0000</pubDate>
      
      <guid>/questions/11445/wireshark-join-a-multicast/</guid>
      <description>Wireshark join a multicast  0 I have a server playing out 24 multi-cast streams on three GbE ports (8 per port), which are connected to a switch. When I connect directly to one of the GbE ports I am able to capture all the multicast streams.
When I connect to the switch I have to set-up TSReader (or StreamXpert) to join to a multicast before Wireshark will display the packets</description>
    </item>
    
    <item>
      <title>how to capture vlan tag on osx 10.6 (lion)?</title>
      <link>/questions/11446/how-to-capture-vlan-tag-on-osx-106-lion/</link>
      <pubDate>Tue, 29 May 2012 08:34:00 +0000</pubDate>
      
      <guid>/questions/11446/how-to-capture-vlan-tag-on-osx-106-lion/</guid>
      <description>how to capture vlan tag on osx 10.6 (lion)?  0 i installed wireshark (64bits) on my macbook pro(2011 edition). but i found i couldn&#39;t see vlan tag information. every packets were UNtagged. :(
any idea?
osx lion vlanasked 29 May &#39;12, 08:34
itsmecho
1●1●1●2
accept rate: 0%
  
2 Answers:
  
0Are you capturing by connecting the Macbook to the span port of a switch? Or are you trying to monitor the traffic originating and terminating on the Mac?</description>
    </item>
    
    <item>
      <title>How to install CSG2 plugin</title>
      <link>/questions/11456/how-to-install-csg2-plugin/</link>
      <pubDate>Tue, 29 May 2012 18:34:00 +0000</pubDate>
      
      <guid>/questions/11456/how-to-install-csg2-plugin/</guid>
      <description>How to install CSG2 plugin  0 Hi,
I would like to know how to add or install plugin for CSG2 in my wireshark. Below are my wireshark version. Thanks.
Version 1.6.4 (SVN Rev 39941 from /trunk-1.6)
Copyright 1998-2011 Gerald Combs [email protected] and contributors. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
Compiled (64-bit) with GTK+ 2.</description>
    </item>
    
    <item>
      <title>CDR dissector in development version 1.7.1, available?</title>
      <link>/questions/11461/cdr-dissector-in-development-version-171-available/</link>
      <pubDate>Tue, 29 May 2012 22:47:00 +0000</pubDate>
      
      <guid>/questions/11461/cdr-dissector-in-development-version-171-available/</guid>
      <description>CDR dissector in development version 1.7.1, available?  0 Could anyone please let me know how to decode a CDR in ASN.1 BER format using wireshark?
gtp-primeasked 29 May &#39;12, 22:47
nanzone
1●1●1●1
accept rate: 0%
CDR being what?
(30 May &#39;12, 00:36) Jaap ♦call data record used in GTP prime protocol message DRT
(30 May &#39;12, 00:38) nanzone  
One Answer:
  
0Wireshark&#39;s GTP dissector handles CDRs in BER format since 1.</description>
    </item>
    
    <item>
      <title>Bandwidth measurement and display for each tcp connection in wireshark.</title>
      <link>/questions/11469/bandwidth-measurement-and-display-for-each-tcp-connection-in-wireshark/</link>
      <pubDate>Wed, 30 May 2012 04:18:00 +0000</pubDate>
      
      <guid>/questions/11469/bandwidth-measurement-and-display-for-each-tcp-connection-in-wireshark/</guid>
      <description>Bandwidth measurement and display for each tcp connection in wireshark.  0 Hi All,
I am new to wireshark , recently started . I am trying to measure the bandwidth between two hosts which uses tcp connection. I want it to be displayed graphically and it should be dynamic( display contiously throught the connection).
Is there any option for this to get it done ? .
Best Regards, yash
bandwidthutilizationasked 30 May &#39;12, 04:18</description>
    </item>
    
    <item>
      <title>How can I dissect 1- and 3-bit fields from a byte?</title>
      <link>/questions/11476/how-can-i-dissect-1-and-3-bit-fields-from-a-byte/</link>
      <pubDate>Wed, 30 May 2012 11:36:00 +0000</pubDate>
      
      <guid>/questions/11476/how-can-i-dissect-1-and-3-bit-fields-from-a-byte/</guid>
      <description>How can I dissect 1- and 3-bit fields from a byte?  0 Hi, I am trying to dissect a byte field for protocol with following byte structure.
============= |T|S|TSG|RES| ============= |1|1| 3 | 3 | =============T bit 1 bit
S bit 1 bit
TSG 3 bit
RES 3 bit
I was trying to get 1 byte unsigned int, AND with the MASKs for the bits and right shift operation.</description>
    </item>
    
    <item>
      <title>Why don&amp;#x27;t I see all of the information I want?</title>
      <link>/questions/11477/why-dont-i-see-all-of-the-information-i-want/</link>
      <pubDate>Wed, 30 May 2012 11:53:00 +0000</pubDate>
      
      <guid>/questions/11477/why-dont-i-see-all-of-the-information-i-want/</guid>
      <description>Why don&amp;rsquo;t I see all of the information I want?  0 I am testing wireshark for learning purposes. I wanted to try out a tutorial that hacks a facebook account stealing cookie information. I couldn&#39;t manage to hack my facebook account because wireshark is sending me truncated packets that I can&#39;t get cookie info out of.
This is the topography of the network: my desktop PC is connected to the Internet to a hub (D-LINK router) via LAN (ethernet cable).</description>
    </item>
    
    <item>
      <title>Customer seeing lots of latency. Are these tcp.retransmits accurate?</title>
      <link>/questions/11481/customer-seeing-lots-of-latency-are-these-tcpretransmits-accurate/</link>
      <pubDate>Wed, 30 May 2012 14:11:00 +0000</pubDate>
      
      <guid>/questions/11481/customer-seeing-lots-of-latency-are-these-tcpretransmits-accurate/</guid>
      <description>Customer seeing lots of latency. Are these tcp.retransmits accurate?  0 I&#39;m seeing about 6% retransmits when I divide the number of packets displayed with display filter tcp.analysis.retransmission/ total number of captured packets. Am I doing this correctly? I also looked under expert and got the same number of retransmissions. I also was reading that for iSCSI traffic it is recommended to turn off Unicast Storm control. They mention this feature discarding packets when traffic reaches a threshold.</description>
    </item>
    
    <item>
      <title>how to read XML from SSL debug file (generated by tshark during SSL decryption)</title>
      <link>/questions/11487/how-to-read-xml-from-ssl-debug-file-generated-by-tshark-during-ssl-decryption/</link>
      <pubDate>Thu, 31 May 2012 05:26:00 +0000</pubDate>
      
      <guid>/questions/11487/how-to-read-xml-from-ssl-debug-file-generated-by-tshark-during-ssl-decryption/</guid>
      <description>how to read XML from SSL debug file (generated by tshark during SSL decryption)  0 I am successful in decrypting the SSL trafic using the tshark command below.
tshark -o &amp;quot;ssl.desegment_ssl_records: TRUE&amp;quot; -o &amp;quot;ssl.desegment_ssl_application_data: TRUE&amp;quot; -o &amp;quot;ssl.keys_list: (Servers&amp;#39;s ip),443,http,cert.pkf&amp;quot; -o &amp;quot;ssl.debug_file: ssldebug.log&amp;quot; -i eth1 -R &amp;quot;tcp.port == 443&amp;quot; -V -w Wireshark.pcapThe SSL debug file has the payload XML messge, which is being exchanged between the applications. Now, I&#39;m struggling on how to retrieve the XML message from SSL debug file.</description>
    </item>
    
    <item>
      <title>Searching for a Packet Sequence</title>
      <link>/questions/11490/searching-for-a-packet-sequence/</link>
      <pubDate>Thu, 31 May 2012 08:57:00 +0000</pubDate>
      
      <guid>/questions/11490/searching-for-a-packet-sequence/</guid>
      <description>Searching for a Packet Sequence  0 Is there an efficient way in Wireshark to search for a particular packet sequence in a capture file? For example, I want to search for a sequence of three consecutive packets, where: packet 1 is a first particular type of packet, packet 2 is a second particular type of packet, and packet 3 is a third particular type of packet.
packetsearch packetsequenceasked 31 May &#39;12, 08:57</description>
    </item>
    
    <item>
      <title>Seeing non-broadcast traffic on my switchport</title>
      <link>/questions/11510/seeing-non-broadcast-traffic-on-my-switchport/</link>
      <pubDate>Thu, 31 May 2012 15:57:00 +0000</pubDate>
      
      <guid>/questions/11510/seeing-non-broadcast-traffic-on-my-switchport/</guid>
      <description>Seeing non-broadcast traffic on my switchport  0 Some of this info has been posted as a reply in an earlier question. My main concern is during a capture I am seeing packets not destined for my IP. I have no SPAN sessions configured and some packets are from other networks even.
(Kurt) I am using a Cisco IronPort web security appliance that utilizes WCCP as well as a Catalyst 6500 which uses CEF.</description>
    </item>
    
    <item>
      <title>tcp.time_delta and tcp.time_relative not showing any values</title>
      <link>/questions/11519/tcptime_delta-and-tcptime_relative-not-showing-any-values/</link>
      <pubDate>Fri, 01 Jun 2012 00:29:00 +0000</pubDate>
      
      <guid>/questions/11519/tcptime_delta-and-tcptime_relative-not-showing-any-values/</guid>
      <description>tcp.time_delta and tcp.time_relative not showing any values  3 1Is it just me or do the display-filter for tcp.time_delta and tcp.time_relative don&#39;t show any values ...?
tested with:
Version 1.6.8 (SVN Rev 42761 from /trunk-1.6)
Copyright 1998-2012 Gerald Combs [email protected] and contributors. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
Compiled (64-bit) with GTK+ 2.</description>
    </item>
    
    <item>
      <title>./autogen giving these errors, what wrong am i doing ?</title>
      <link>/questions/11525/autogen-giving-these-errors-what-wrong-am-i-doing/</link>
      <pubDate>Fri, 01 Jun 2012 04:36:00 +0000</pubDate>
      
      <guid>/questions/11525/autogen-giving-these-errors-what-wrong-am-i-doing/</guid>
      <description>./autogen giving these errors, what wrong am i doing ?  0 [[email protected] wireshark-1.7.1]# ./autogen.sh
./autogen.sh: line 101: ./aclocal-flags: Permission denied
configure.in:208: warning: macro `AM_PATH_LIBGCRYPT&#39; not found in library
configure.in:833: warning: macro `AM_PATH_GTK_3_0&#39; not found in library
configure.in:39: warning: AC_CACHE_VAL(lt_prog_compiler_pic_works, ...): suspicious cache-id, must contain cv to be cached ../../lib/autoconf/general.m4:1974: AC_CACHE_VAL is expanded from... ../../lib/autoconf/general.m4:1994: AC_CACHE_CHECK is expanded from...
.
. . . .
aclocal.m4:4534: _LT_AC_LANG_GCJ_CONFIG is expanded from...</description>
    </item>
    
    <item>
      <title>Editing Filters on wireshark.</title>
      <link>/questions/11531/editing-filters-on-wireshark/</link>
      <pubDate>Fri, 01 Jun 2012 06:48:00 +0000</pubDate>
      
      <guid>/questions/11531/editing-filters-on-wireshark/</guid>
      <description>Editing Filters on wireshark.  0 1hello guys, I&#39;m new in Wireshark world and I would help to capture only the packets with RST or SYN or FIN and that between two hosts A and B. I tride this:
host A.A.A.A and host B.B.B.B and tcp[tcpflags] &amp;amp; (tcp-rst) !=0 or tcp[tcpflags] &amp;amp; (tcp-syn) !=0 or tcp[tcpflags] &amp;amp; (tcp-fin) != 0
but i only capture [SYN, ACK] packets.
thank you for your response.</description>
    </item>
    
    <item>
      <title>duplicate IP address display filter</title>
      <link>/questions/11534/duplicate-ip-address-display-filter/</link>
      <pubDate>Fri, 01 Jun 2012 08:30:00 +0000</pubDate>
      
      <guid>/questions/11534/duplicate-ip-address-display-filter/</guid>
      <description>duplicate IP address display filter  0 In expert info, I have found two warnings about duplicate IP addresses. Ofcourse, the customer thinks I&#39;m crazy (&#34;Not on my network!&#34;) so I took some screenshots showing his this. The only way I was able to show him both in the same screen was to build the filter using the &#34;or&#34; for both IP address warns. expert.message == &#34;Duplicate IP address configured (192.</description>
    </item>
    
    <item>
      <title>H.248 partially decoded</title>
      <link>/questions/11537/h248-partially-decoded/</link>
      <pubDate>Fri, 01 Jun 2012 10:13:00 +0000</pubDate>
      
      <guid>/questions/11537/h248-partially-decoded/</guid>
      <description>H.248 partially decoded  0 In H.248 all values items inside descriptors are not decoded (e.g. parameter: BNC Characteristics, value item: 0a0102 or parameter: interface, value item: 0a0101 and so on).
h.248asked 01 Jun &#39;12, 10:13
cle
1●1●1●2
accept rate: 0%
 edited 01 Jun &#39;12, 10:20 
  
2 Answers:
  
0Hi, You should state which version of Wireshark you are usina and if it&#39;s 1.</description>
    </item>
    
    <item>
      <title>Why do I see different data using the same capture file in two places?</title>
      <link>/questions/11545/why-do-i-see-different-data-using-the-same-capture-file-in-two-places/</link>
      <pubDate>Fri, 01 Jun 2012 11:50:00 +0000</pubDate>
      
      <guid>/questions/11545/why-do-i-see-different-data-using-the-same-capture-file-in-two-places/</guid>
      <description>Why do I see different data using the same capture file in two places?  0 My partner and I are opening the same capture file without filtering, but we both have different information displayed on the screen. What is happening?
dissection resultsasked 01 Jun &#39;12, 11:50
TecnoSaenz
1●1●1●1
accept rate: 0%
 edited 01 Jun &#39;12, 12:26 
multipleinte...
1.3k●15●23●40
Are you both using the same version of Wireshark? Are your preferences set the same?</description>
    </item>
    
    <item>
      <title>Capture IP filter</title>
      <link>/questions/11547/capture-ip-filter/</link>
      <pubDate>Fri, 01 Jun 2012 12:24:00 +0000</pubDate>
      
      <guid>/questions/11547/capture-ip-filter/</guid>
      <description>Capture IP filter  0 Hello all,
Setting the capture filter in wireshark and restarting the capture still shows other IP network traffic....what went south? Here is what I did: started WS went into capture -&amp;gt; Capture Filters -&amp;gt; Cliked New -&amp;gt; filtername = 192.168.2.12 filter string = host 192.168.2.12. then restarted capture but I still see all the other traffic being displayed; Does this mean that the capture only collects data in the log file for x.</description>
    </item>
    
    <item>
      <title>Company usage confirmation</title>
      <link>/questions/11553/company-usage-confirmation/</link>
      <pubDate>Fri, 01 Jun 2012 14:43:00 +0000</pubDate>
      
      <guid>/questions/11553/company-usage-confirmation/</guid>
      <description>Company usage confirmation  0 Dear Wireshark colleagues, I had to ask for your confirmation allowing Comcel S.A. company to use Wireshark software due to some local regulations. Please confirm us if we can use your software.
Thanks in advance!
Comcel S.A.
approval licenseasked 01 Jun &#39;12, 14:43
Telco Eng
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Short answer: Yes, you can use it. Wireshark is free software.</description>
    </item>
    
    <item>
      <title>Unable to capture (or display) incoming TCP/IP packets with port 8100</title>
      <link>/questions/11560/unable-to-capture-or-display-incoming-tcpip-packets-with-port-8100/</link>
      <pubDate>Fri, 01 Jun 2012 17:25:00 +0000</pubDate>
      
      <guid>/questions/11560/unable-to-capture-or-display-incoming-tcpip-packets-with-port-8100/</guid>
      <description>Unable to capture (or display) incoming TCP/IP packets with port 8100  0 I&#39;m trying to capture a SSLv3 encrypted connection between a target device I&#39;m developing using a PIC32 micro and the Microchip TCP/IP stack (v5.41) + Encryption(v2.6) using Wireshark(v1.6.8). I&#39;m connecting to an openSSL loopback server setup for development testing.
When I capture the trace, Wireshark displays only the outgoing packets from my device to the server and does not display the packets from the server to my device.</description>
    </item>
    
    <item>
      <title>Possible malware on network</title>
      <link>/questions/11566/possible-malware-on-network/</link>
      <pubDate>Sat, 02 Jun 2012 09:59:00 +0000</pubDate>
      
      <guid>/questions/11566/possible-malware-on-network/</guid>
      <description>Possible malware on network  1 1Some windows machine on our network is constantly broadcasting UDP packets to the port numbers 10019 and 10007. It also constantly changes its source port number. Seems suspicious to me, although I can&#39;t find any information of malware having this behavior.
The content of the packages is always the same:
0000 f0 ff 00 00 12 00 00 00 00 00 00 00 00 00 00 00 .</description>
    </item>
    
    <item>
      <title>Stop wireshark from decoding wbxml?</title>
      <link>/questions/11573/stop-wireshark-from-decoding-wbxml/</link>
      <pubDate>Sat, 02 Jun 2012 16:02:00 +0000</pubDate>
      
      <guid>/questions/11573/stop-wireshark-from-decoding-wbxml/</guid>
      <description>Stop wireshark from decoding wbxml?  0 How do I stop wireshark from attempt to decode wbxml? I want also to be able to see the actual binary data! Also wireshark cannot decode wbxml properly!
decode wbxmlasked 02 Jun &#39;12, 16:02
dakke
6●1●1●4
accept rate: 0%
 edited 02 Jun &#39;12, 21:17 
cmaynard ♦♦
9.4k●10●38●142
  
2 Answers:
  
2 Disable wbxml in the GUI:</description>
    </item>
    
    <item>
      <title>Installed Wireshark but CAN&amp;#x27;T FIND IT (total rookie question)</title>
      <link>/questions/11576/installed-wireshark-but-cant-find-it-total-rookie-question/</link>
      <pubDate>Sat, 02 Jun 2012 18:51:00 +0000</pubDate>
      
      <guid>/questions/11576/installed-wireshark-but-cant-find-it-total-rookie-question/</guid>
      <description>Installed Wireshark but CAN&amp;rsquo;T FIND IT (total rookie question)  0 Hello! Quick question: I use Ubuntu/Linux and I recently installed Wireshark using Ubuntu Software Center. It says that I successfully installed it, but now I don&#39;t know where to find the Wireshark folder or program! Which folder is it in and how do I access it?
Thanks to anyone who helps me! And thank you for not judging my embarrassingly low level of computer literacy.</description>
    </item>
    
    <item>
      <title>How do i save logs with selected attributes only?</title>
      <link>/questions/11580/how-do-i-save-logs-with-selected-attributes-only/</link>
      <pubDate>Sun, 03 Jun 2012 07:28:00 +0000</pubDate>
      
      <guid>/questions/11580/how-do-i-save-logs-with-selected-attributes-only/</guid>
      <description>How do i save logs with selected attributes only?  0 I need to get only the time, size and the number of the packets from the generated logs in the text file and then I can then upload the text file into my software. Can anyone please help me with that?
filteringasked 03 Jun &#39;12, 07:28
manish
1●1●1●1
accept rate: 0%
 edited 04 Jun &#39;12, 06:54 
multipleinte...</description>
    </item>
    
    <item>
      <title>Internal NB workgroup query gets result from outside IP address&amp;gt;</title>
      <link>/questions/11585/internal-nb-workgroup-query-gets-result-from-outside-ip-address/</link>
      <pubDate>Sun, 03 Jun 2012 12:54:00 +0000</pubDate>
      
      <guid>/questions/11585/internal-nb-workgroup-query-gets-result-from-outside-ip-address/</guid>
      <description>Internal NB workgroup query gets result from outside IP address&amp;gt;  0 Please have a look at this screenshot.
http://i.imgur.com/0rqCt.png?1
I am wondering why a local netbios query would result in a outside Colorado based IP being returned.
Thanks,
Pluribus
security ubuntu netbiosasked 03 Jun &#39;12, 12:54
pluribus
1●4●4●6
accept rate: 0%
  
One Answer:
  
0That&#39;s down to the name resolution done by IP 192.168.1.1, possibly your router.</description>
    </item>
    
    <item>
      <title>Strange Netbios queries , possible malware?</title>
      <link>/questions/11586/strange-netbios-queries-possible-malware/</link>
      <pubDate>Sun, 03 Jun 2012 13:07:00 +0000</pubDate>
      
      <guid>/questions/11586/strange-netbios-queries-possible-malware/</guid>
      <description>Strange Netbios queries , possible malware?  0 I have been looking at packets on my network a lot lately and I found out some crazy things. One is that most of the laptops sold today come with a windows/osx BIOS loading trojan called computrace, lojack. It has the purported intention of tracking stolen laptops but is easily exploited into very persistent trojan that can load into windows/osx and now linux too.</description>
    </item>
    
    <item>
      <title>Use of call_dissector ?</title>
      <link>/questions/11608/use-of-call_dissector/</link>
      <pubDate>Mon, 04 Jun 2012 02:57:00 +0000</pubDate>
      
      <guid>/questions/11608/use-of-call_dissector/</guid>
      <description>Use of call_dissector ?  0 I am total newbie in wireshark plugin development and i was curious about precise use case of this function , some &#34;packet-xx.c&#34; don&#39;t use it and some use it but still i am not able to make out difference. I am under impression that even if we don&#39;t use it , dissectors get called by default from epan/dissectors for all basic protocols.Please point some source file for more understanding of this function.</description>
    </item>
    
    <item>
      <title>what determines the position of pointer of tree in main dissection function</title>
      <link>/questions/11610/what-determines-the-position-of-pointer-of-tree-in-main-dissection-function/</link>
      <pubDate>Mon, 04 Jun 2012 03:04:00 +0000</pubDate>
      
      <guid>/questions/11610/what-determines-the-position-of-pointer-of-tree-in-main-dissection-function/</guid>
      <description>what determines the position of pointer of tree in main dissection function  0 I have a very basic question.From what i understand , dissector_add determines criteria of wireshark calling my dissector. Now suppose if i have udp.port==7011 kind of filter , then i guess the pointer of &#34;tree&#34;(in dissect_proto) starts from udp packet ? Am i correct ? What will happen if i am using heuristic dissector of &#34;eth&#34; ?</description>
    </item>
    
    <item>
      <title>add own dictionary of VSA</title>
      <link>/questions/11614/add-own-dictionary-of-vsa/</link>
      <pubDate>Mon, 04 Jun 2012 06:09:00 +0000</pubDate>
      
      <guid>/questions/11614/add-own-dictionary-of-vsa/</guid>
      <description>add own dictionary of VSA  0 Hello,
I want to add dictionary of RADIUS protocol VSA, so that whenever RADIUS packet contains our AVP it shows properly. I have added in my local wireshark but i want it to available it as an in bult functionality. So, whoever install wireshark our dictionary is available to them.vsa avp attribute-value-pair dictionaryThis question is marked &#34;community wiki&#34;.asked 04 Jun &#39;12, 06:09
kartik jajal</description>
    </item>
    
    <item>
      <title>How to save reports of Telephony-&amp;gt;VoIP Calls</title>
      <link>/questions/11618/how-to-save-reports-of-telephony-voip-calls/</link>
      <pubDate>Mon, 04 Jun 2012 07:30:00 +0000</pubDate>
      
      <guid>/questions/11618/how-to-save-reports-of-telephony-voip-calls/</guid>
      <description>How to save reports of Telephony-&amp;gt;VoIP Calls  0 I found a similar question on this topics, but I am asking again if anybody can provide me other solution. When I select Telephony and then VoIP calls, a report of all VoIP calls (CDR) are found in an window, but I cannot save this report for future processing. How can I save this report? Is there any other alternatives? Thanks in advance.</description>
    </item>
    
    <item>
      <title>Do I have looping packets?</title>
      <link>/questions/11620/do-i-have-looping-packets/</link>
      <pubDate>Mon, 04 Jun 2012 07:32:00 +0000</pubDate>
      
      <guid>/questions/11620/do-i-have-looping-packets/</guid>
      <description>Do I have looping packets?  0 I have an iSCSI performance problem. So I&#39;m just going thru my checklist. One thing mentioned on page 336 is using IP ID to identify looping packets. So i did a tshark dump of the ip.id and created a Perl script to check for duplicates. Once I identified these I looked at the packets to see if Don&#39;t Fragment is set. I found a case where I have duplicate IDs and the DF is set.</description>
    </item>
    
    <item>
      <title>Snifferclient?</title>
      <link>/questions/11631/snifferclient/</link>
      <pubDate>Mon, 04 Jun 2012 08:54:00 +0000</pubDate>
      
      <guid>/questions/11631/snifferclient/</guid>
      <description>Snifferclient?  0 Watching some traffic on a host via logmein I see traffic that starts with this
https &amp;gt; snifferclient
what does that mean? google did not help much.
generalasked 04 Jun &#39;12, 08:54
pluribus
1●4●4●6
accept rate: 0%
  
One Answer:
  
1That&#39;s (most certainly) just the source port of your connection, resolved to &#39;snifferclient&#39; (TCP/2452).
Disable name resolution and you will see the numbers instead of the names.</description>
    </item>
    
    <item>
      <title>PPP captured but MPPC decompres?</title>
      <link>/questions/11648/ppp-captured-but-mppc-decompres/</link>
      <pubDate>Mon, 04 Jun 2012 17:52:00 +0000</pubDate>
      
      <guid>/questions/11648/ppp-captured-but-mppc-decompres/</guid>
      <description>PPP captured but MPPC decompres?  0 I want to go deep to GRE/PPP packets. The PPP Compressed data by MPPC (Microsoft Point-to-Point Compression) which is one of three compress methods under CiscoIOS. The problem is Wireshark just stop at decoding the PPP packets not go any further to decompress the payload of them. Any one who know some kind of plug-in for Wireshark to do such thing??? Pls, help.</description>
    </item>
    
    <item>
      <title>cdp packets missing</title>
      <link>/questions/11651/cdp-packets-missing/</link>
      <pubDate>Mon, 04 Jun 2012 21:47:00 +0000</pubDate>
      
      <guid>/questions/11651/cdp-packets-missing/</guid>
      <description>cdp packets missing  0 Hello;
I am using Dell Latitude E6400, and my Wireshark version is version 1.6.7. When I try to capture through my interface, CDP packets are missing. It shows other multicast packets like HSRP, OSPF. What may be the reason and how to solve it?
I am using Symantec End Point.
cdp packets missingasked 04 Jun &#39;12, 21:47
afsal
1●1●1●1
accept rate: 0%
 edited 16 Jun &#39;12, 19:55</description>
    </item>
    
    <item>
      <title>add valuestring value to column</title>
      <link>/questions/11653/add-valuestring-value-to-column/</link>
      <pubDate>Tue, 05 Jun 2012 02:00:00 +0000</pubDate>
      
      <guid>/questions/11653/add-valuestring-value-to-column/</guid>
      <description>add valuestring value to column  0 I&#39;m having a problem with getting the value of a protofield to the Info column. I&#39;ve defined the following ProtoField:
f.payload = ProtoField.uint8(&amp;quot;observation.payload&amp;quot;,&amp;quot;payload&amp;quot;,base.HEX,{ [0] = &amp;quot;Off&amp;quot;, [1] = &amp;quot;On&amp;quot;},0x10)I want add this field value (On or Off) to pinfo.col.info. How can I do it?
lua dissectorasked 05 Jun &#39;12, 02:00
ekrako
6●1●1●3
accept rate: 0%
 edited 05 Jun &#39;12, 16:00 
helloworld</description>
    </item>
    
    <item>
      <title>How to convert le_nstime() to string in Lua</title>
      <link>/questions/11654/how-to-convert-le_nstime-to-string-in-lua/</link>
      <pubDate>Tue, 05 Jun 2012 03:24:00 +0000</pubDate>
      
      <guid>/questions/11654/how-to-convert-le_nstime-to-string-in-lua/</guid>
      <description>How to convert le_nstime() to string in Lua  0 How do I convert TvbRange.le_nstime() to a string? I tried the following Lua:
local field_time = ProtoField.absolute_time(&amp;quot;TIME&amp;quot;,&amp;quot;TIME&amp;quot;,base.LOCAL); ... function SCP_proto.dissector (buf, pkt, root){ local value={ [0] =0, [1] =0, [2] =0 } ... for i=0,2,1 do ... local example_subtree = subtree:add(field_time,buf(offset,8):le_nstime()); value[i] = tostring(buf(offset,8):le_nstime()); ... end }...but value[i] = tostring(buf(offset,8):le\_nstime()) does not work the way I expected. The time format of value[i] is in seconds (&#34;</description>
    </item>
    
    <item>
      <title>TShark not finding http traffic</title>
      <link>/questions/11655/tshark-not-finding-http-traffic/</link>
      <pubDate>Tue, 05 Jun 2012 03:35:00 +0000</pubDate>
      
      <guid>/questions/11655/tshark-not-finding-http-traffic/</guid>
      <description>TShark not finding http traffic  0 Hi.
I&#39;m new to Wireshark, so be warned that this is a newbie question.
I&#39;m using Wireshark on an Ubuntu server, and have enabled dumpcap to collect raw data and store to files:
/usr/bin/dumpcap -i eth1 -w /var/tracefiles/eth1.pcap -b duration:3600
When trying to analyze the files produced, I would for instance like to see http requests and the resulting status code. I think I have found an example on how to do this on 1:</description>
    </item>
    
    <item>
      <title>help for writing heuristic dissector plugin</title>
      <link>/questions/11671/help-for-writing-heuristic-dissector-plugin/</link>
      <pubDate>Tue, 05 Jun 2012 09:36:00 +0000</pubDate>
      
      <guid>/questions/11671/help-for-writing-heuristic-dissector-plugin/</guid>
      <description>help for writing heuristic dissector plugin  0 I intend to write a plugin using heuristic dissector.I am using eth heuristic dissector and my protocol relevant data will be part of ethernet payload and located at the end of ethernet payload.Now in dissect_myproto , the tree pointer will directly/autonomously point to my protocol relevant data when my dissector gets called or i will have to manipulate it to point to my protocol relevant data ?</description>
    </item>
    
    <item>
      <title>Error on &amp;#x27;make&amp;#x27; for 1.7.1 on Archlinux 64 bit</title>
      <link>/questions/11673/error-on-make-for-171-on-archlinux-64-bit/</link>
      <pubDate>Tue, 05 Jun 2012 10:39:00 +0000</pubDate>
      
      <guid>/questions/11673/error-on-make-for-171-on-archlinux-64-bit/</guid>
      <description>Error on &amp;lsquo;make&amp;rsquo; for 1.7.1 on Archlinux 64 bit  0 I&#39;m trying to install the 1.7.1 version on ArchLinux (3.3.7-1-ARCH #1 SMP PREEMPT Tue May 22 00:26:26 CEST 2012 x86_64 GNU/Linux)
In the past, I was able to get it installed but haven&#39;t been able to for the last few months. I keep getting the following errors. My configure options are:
$ ./configure --prefix=/opt --with-dumpcap-group=wireshark --disable-warnings-as-errorsI&#39;ve googled and looked all over the place for a solution with no luck.</description>
    </item>
    
    <item>
      <title>Cannot see Wi-Fi packets like RTS/CTS, or PS-Pole</title>
      <link>/questions/11674/cannot-see-wi-fi-packets-like-rtscts-or-ps-pole/</link>
      <pubDate>Tue, 05 Jun 2012 11:13:00 +0000</pubDate>
      
      <guid>/questions/11674/cannot-see-wi-fi-packets-like-rtscts-or-ps-pole/</guid>
      <description>Cannot see Wi-Fi packets like RTS/CTS, or PS-Pole  0 Hello, using a Windows computer with Wireshark 1.6.7 and a AirPcap Nx. I am filtering by wlan.addr. I cannot see things like RTS/CTS or PS-Poll packets in my trace. Do I have to change a setting somewhere to let me see those type of packets?
management packets rts wi-fi ctsasked 05 Jun &#39;12, 11:13
Joseph Conley
1●3●3●5
accept rate: 0%</description>
    </item>
    
    <item>
      <title>checksum errors when browsing the internet</title>
      <link>/questions/11682/checksum-errors-when-browsing-the-internet/</link>
      <pubDate>Tue, 05 Jun 2012 13:08:00 +0000</pubDate>
      
      <guid>/questions/11682/checksum-errors-when-browsing-the-internet/</guid>
      <description>checksum errors when browsing the internet  0 Any ideas on what is causing all these header checksum errors... A few times a day users intermittently lose network connections to the exchange server or the internet. Upon opening IE I start to see checksum errors like the following and they stop when closing IE...
Header checksum: 0x0000 [incorrect, should be 0x54ad (maybe caused by &#34;IP checksum offload&#34;?)]
This is a sample of the packet traffic that get the checksum error:</description>
    </item>
    
    <item>
      <title>pls point example source file of dual heuristic/normal dissector</title>
      <link>/questions/11698/pls-point-example-source-file-of-dual-heuristicnormal-dissector/</link>
      <pubDate>Tue, 05 Jun 2012 17:47:00 +0000</pubDate>
      
      <guid>/questions/11698/pls-point-example-source-file-of-dual-heuristicnormal-dissector/</guid>
      <description>pls point example source file of dual heuristic/normal dissector  0 I want an example where dual heuristic/normal dissector is used in /epan/dissectors/
plugin wiresharkasked 05 Jun &#39;12, 17:47
yogeshg
41●22●23●26
accept rate: 0%
  
One Answer:
  
0Here are a couple of examples:
packet-ppp.cpacket-wol.canswered 05 Jun &#39;12, 18:25
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%
I want my dissector to get called if my src mac or dest mac is of some specific pattern , for that i am using heuristic dissector for eth but then tvb will point to eth payload i suppose and instead i want dissection of http payload , so for this i need to use these dual dissectors right ?</description>
    </item>
    
    <item>
      <title>Malware on Network</title>
      <link>/questions/11701/malware-on-network/</link>
      <pubDate>Tue, 05 Jun 2012 18:45:00 +0000</pubDate>
      
      <guid>/questions/11701/malware-on-network/</guid>
      <description>Malware on Network  0 I have tried to use wireshark before just to get aquainted but now its needed. I seem to have a computer sending out massive amounts of e-mail. I have found a few traces of the culprit from my firewall logs but their seems to be more computers. My question is there any way of tracking whats getting sent through port 25. ANy help would be appreciated.</description>
    </item>
    
    <item>
      <title>Can we call_dissector function prior to my protocol relevant dissection ?</title>
      <link>/questions/11702/can-we-call_dissector-function-prior-to-my-protocol-relevant-dissection/</link>
      <pubDate>Tue, 05 Jun 2012 19:59:00 +0000</pubDate>
      
      <guid>/questions/11702/can-we-call_dissector-function-prior-to-my-protocol-relevant-dissection/</guid>
      <description>Can we call_dissector function prior to my protocol relevant dissection ?  0 I am using eth heuristic dissector and my protocol relevant data will be part of ethernet payload and located at the end of ethernet payload. Now in dissect_myproto , the tvb pointer will directly/autonomously point to my protocol relevant data when my dissector gets called or i will have to manipulate it to point to my protocol relevant data and if yes then how ?</description>
    </item>
    
    <item>
      <title>Increase maximun packet size (more than 64 Kbyte)</title>
      <link>/questions/11708/increase-maximun-packet-size-more-than-64-kbyte/</link>
      <pubDate>Wed, 06 Jun 2012 00:13:00 +0000</pubDate>
      
      <guid>/questions/11708/increase-maximun-packet-size-more-than-64-kbyte/</guid>
      <description>Increase maximun packet size (more than 64 Kbyte)  0 Hello to all
I try to increase the maximun packet size that Wireshark can read in order to support packets up to 16 Mbyte (or even more up to 256 Mbyte). I already changed the WTAP_MAX_PACKET_SIZE to 32 * 1024 * 1024 in wireshark/wiretap/wiretap.h and recompiled succesfully the Wireshark. I also succesfully read a PCAP file where each packet is 16 Mbyte each in command line with tshark -r file.</description>
    </item>
    
    <item>
      <title>Only inbound traffic</title>
      <link>/questions/11714/only-inbound-traffic/</link>
      <pubDate>Wed, 06 Jun 2012 05:30:00 +0000</pubDate>
      
      <guid>/questions/11714/only-inbound-traffic/</guid>
      <description>Only inbound traffic  0 Hi.
I&#39;m using Wireshark on the Windows 2008 Server PC with to interfaces and Firefront TMG installed on it. And when I start capturing packets with wireshark, it shows only inbound traffic. I tried it on both interfaces.
Is this normal?
wiresharkasked 06 Jun &#39;12, 05:30
SKamil
1●1●1●1
accept rate: 0%
  
3 Answers:
  
0sounds like a similar problem as in this question</description>
    </item>
    
    <item>
      <title>Request-to-send flood from access point</title>
      <link>/questions/11717/request-to-send-flood-from-access-point/</link>
      <pubDate>Wed, 06 Jun 2012 08:15:00 +0000</pubDate>
      
      <guid>/questions/11717/request-to-send-flood-from-access-point/</guid>
      <description>Request-to-send flood from access point  0 I&#39;m experiencing constant intermittent lag spikes from my wireless network and decided the investigate using wireshark.
I found out that during one of the spikes, the transmitting address (Station A), which happens to be my wireless router (Engenius ESR9850), is sending out 25 of these RTS packets.
540 0.201225 Station A (TA) Station B (RA) 802.11 52 Request-to-send, Flags=........C
I&#39;ve exhausted all my options trying to eliminate the lag spike.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t decrypt TLS</title>
      <link>/questions/11720/cant-decrypt-tls/</link>
      <pubDate>Wed, 06 Jun 2012 10:40:00 +0000</pubDate>
      
      <guid>/questions/11720/cant-decrypt-tls/</guid>
      <description>Can&amp;rsquo;t decrypt TLS  0 I&#39;ve added the server&#39;s private key to the RSA keys list, confirmed the connection is over TLSv1.0 with a DES-CBC3-SHA cipher, and made sure to capture the entire handshake including ClientHello, but Wireshark still can&#39;t decrypt the connection. What am I doing wrong?
I&#39;ve got the debug console open, but it remains blank the whole time - would that have useful info? Since the server is just for testing, I can provide the private key and URL if it would help.</description>
    </item>
    
    <item>
      <title>Using BPF on a .pcap file</title>
      <link>/questions/11723/using-bpf-on-a-pcap-file/</link>
      <pubDate>Wed, 06 Jun 2012 12:45:00 +0000</pubDate>
      
      <guid>/questions/11723/using-bpf-on-a-pcap-file/</guid>
      <description>Using BPF on a .pcap file  0 So I have a whatever.pcap file and load it into Wireshark. I do not want to use the native Wireshark display filters, but use BPF to filter through my traffic.
I know I can use BPF to filter traffic during the capture, but I want to be able to use it after the capture as well.
Is there a way to do this?</description>
    </item>
    
    <item>
      <title>Will this approach work ?</title>
      <link>/questions/11729/will-this-approach-work/</link>
      <pubDate>Wed, 06 Jun 2012 22:33:00 +0000</pubDate>
      
      <guid>/questions/11729/will-this-approach-work/</guid>
      <description>Will this approach work ?  0 Hi, I want my dissector to get called when there is some specific pattern of dest mac , for that i am using eth heuristic dissector and my data which i want to dissect is last 12 bytes of IP payload.For this i am calling eth_dissector and then i am calculating exact location of my data and hence dissecting it. I need to know if this is right approach ?</description>
    </item>
    
    <item>
      <title>Is there a way to save packet comment when saving file.</title>
      <link>/questions/11730/is-there-a-way-to-save-packet-comment-when-saving-file/</link>
      <pubDate>Thu, 07 Jun 2012 00:17:00 +0000</pubDate>
      
      <guid>/questions/11730/is-there-a-way-to-save-packet-comment-when-saving-file/</guid>
      <description>Is there a way to save packet comment when saving file.  0 Hi,
I&#39;ve installed rc8.0. I&#39;m highly interested in packet comment feature. When I add a comment to a packet and then save the file, packet comment is not saved in the file. This lack makes packet comment feature much less interesting to me.
Is it planned to implement saving packet comment within file?
comment pkt_comment save rc8 fileasked 07 Jun &#39;12, 00:17</description>
    </item>
    
    <item>
      <title>Why can&amp;#x27;t Wireshark see the network interfaces on Solaris?</title>
      <link>/questions/11731/why-cant-wireshark-see-the-network-interfaces-on-solaris/</link>
      <pubDate>Thu, 07 Jun 2012 00:27:00 +0000</pubDate>
      
      <guid>/questions/11731/why-cant-wireshark-see-the-network-interfaces-on-solaris/</guid>
      <description>Why can&amp;rsquo;t Wireshark see the network interfaces on Solaris?  0 When I click the Wireshark toolbar button labeled as &#34;List the available capture interfaces&#34;, I see the following error message in a popup:
There are no interfaces on which a capture can be done
and I&#39;m running Wireshark as root, so I don&#39;t think there&#39;s a privilege problem in play here. How can I get Wireshark to list my capture interfaces?</description>
    </item>
    
    <item>
      <title>Wireshark install seems to improve performance</title>
      <link>/questions/11733/wireshark-install-seems-to-improve-performance/</link>
      <pubDate>Thu, 07 Jun 2012 02:03:00 +0000</pubDate>
      
      <guid>/questions/11733/wireshark-install-seems-to-improve-performance/</guid>
      <description>Wireshark install seems to improve performance  0 We have a web based system (HTTP) which seems to be having performance issues. In our UAT environment performance is fine, in production, there is a significant reduction. These are typically request / response type messages for data lookups (i.e. search a data cache for filtered data).
UAT and Prod reside on the exactly the same infrastructure, only differecne is the hardware. I installed wireshark to moinitor network traffic and performance.</description>
    </item>
    
    <item>
      <title>Illegal Message fragment</title>
      <link>/questions/11740/illegal-message-fragment/</link>
      <pubDate>Thu, 07 Jun 2012 08:10:00 +0000</pubDate>
      
      <guid>/questions/11740/illegal-message-fragment/</guid>
      <description>Illegal Message fragment  0 Hello to all,
I write a dissector for my protocol that reassebles multiple fragmet packets of 60 Kbytes each. For each fragment, a message (Message Reassembled) appears in the info column of Wireshark. For the last fragment (the reassebled packet) in info column the text [Illegal Message fragment] (Message Reassembled) appears. Here I have to note that the message is correctly reassebled. Obviously the reassebly routine runs before if (tree).</description>
    </item>
    
    <item>
      <title>How to find the symmetric key generated by the browser</title>
      <link>/questions/11744/how-to-find-the-symmetric-key-generated-by-the-browser/</link>
      <pubDate>Thu, 07 Jun 2012 22:19:00 +0000</pubDate>
      
      <guid>/questions/11744/how-to-find-the-symmetric-key-generated-by-the-browser/</guid>
      <description>How to find the symmetric key generated by the browser  0 Hi folks,
During an Https connection,our browser will encrypt the randomly generated number with the public key of a website to have an encrypted communication.I just want to know is there any method to find out the randomy generated number of our browser using wireshark. I would also like to know can we sniff https connection to see the payload?</description>
    </item>
    
    <item>
      <title>Is there a Lua bug that prevents byte highlighting upon field selection?</title>
      <link>/questions/11750/is-there-a-lua-bug-that-prevents-byte-highlighting-upon-field-selection/</link>
      <pubDate>Fri, 08 Jun 2012 01:54:00 +0000</pubDate>
      
      <guid>/questions/11750/is-there-a-lua-bug-that-prevents-byte-highlighting-upon-field-selection/</guid>
      <description>Is there a Lua bug that prevents byte highlighting upon field selection?  1 The following Lua does not highlight the corresponding bytes upon field selection (for f_length):
version = &amp;quot;0.1&amp;quot;; workPort = 3003; full_name = &amp;quot;Service Control Point protocol&amp;quot;; short_name = &amp;quot;SCP&amp;quot;; perent_port = &amp;quot;tcp.port&amp;quot;; SCP_proto = Proto(short_name,full_name); local f_length = ProtoField.uint32(&amp;quot;length&amp;quot;, &amp;quot;length&amp;quot;); SCP_proto.fields = { f_length } function SCP_proto.dissector (buf, pkt, root) pkt.cols.protocol = SCP_proto.name subtree = root:add(SCP_proto, buf(0)); subtree:append_text(&amp;quot;(using BER),version &amp;quot;.</description>
    </item>
    
    <item>
      <title>How to filter browsers?</title>
      <link>/questions/11754/how-to-filter-browsers/</link>
      <pubDate>Fri, 08 Jun 2012 03:51:00 +0000</pubDate>
      
      <guid>/questions/11754/how-to-filter-browsers/</guid>
      <description>How to filter browsers?  0 How can i filter browsers for GET / HTTP/1.1? I want to get list of browsers that have been used in capture file. Thanks.
filter list browserasked 08 Jun &#39;12, 03:51
besomuk
1●1●1●2
accept rate: 0%
  
One Answer:
  
1Please try this:
tshark -r input.cap -R http.request -T fields -e http.user_agent
and with a filter on HTTP/1.1
tshark.exe -r http_sample.</description>
    </item>
    
    <item>
      <title>Decode UDP as RTMP</title>
      <link>/questions/11759/decode-udp-as-rtmp/</link>
      <pubDate>Fri, 08 Jun 2012 04:20:00 +0000</pubDate>
      
      <guid>/questions/11759/decode-udp-as-rtmp/</guid>
      <description>Decode UDP as RTMP  0 Hi,
I have a network dump with a RTMP stream but it&#39;s transported over UDP rather then TCP, so Wireshark seems not to be able to decode the RTMP stream. I&#39;ve tried also to decode the packages manual, but there is no option for RTMP when selecting a UDP packet.
I&#39;m using the current stable version 1.6.8 and I tried the 1.8.0rc1 as well.</description>
    </item>
    
    <item>
      <title>new to filters</title>
      <link>/questions/11768/new-to-filters/</link>
      <pubDate>Fri, 08 Jun 2012 07:33:00 +0000</pubDate>
      
      <guid>/questions/11768/new-to-filters/</guid>
      <description>new to filters  0 I&#39;m new to filters in wireshark. Any filter I try like tcp or http or ip clears all packets. I&#39;m specifically trying to see only broadcasts with the filter eth.addr == ff:ff:ff:ff:ff:ff . Applying this filter clears all packets. When I remove the filter, I see all kinds of broadcast packets. I&#39;m running wireshark 1.6.7 as root, capturing on wlan0.mon
filtersasked 08 Jun &#39;12, 07:33</description>
    </item>
    
    <item>
      <title>Why am I getting duplicate tcp acks?</title>
      <link>/questions/11773/why-am-i-getting-duplicate-tcp-acks/</link>
      <pubDate>Fri, 08 Jun 2012 11:15:00 +0000</pubDate>
      
      <guid>/questions/11773/why-am-i-getting-duplicate-tcp-acks/</guid>
      <description>Why am I getting duplicate tcp acks?  0 I have an application I&#39;ve written on Windows 7 that is connecting TCP to a custom device. The device is sending status packets approx. every 25ms to the host. The device is also running code I&#39;ve written. They are connected ethernet via a DSL router. The application is also sending data over a second TCP port to the device.
All works well until I get a duplicate ACK from the host.</description>
    </item>
    
    <item>
      <title>Is this normal ARP for cable service?</title>
      <link>/questions/11775/is-this-normal-arp-for-cable-service/</link>
      <pubDate>Fri, 08 Jun 2012 15:52:00 +0000</pubDate>
      
      <guid>/questions/11775/is-this-normal-arp-for-cable-service/</guid>
      <description>Is this normal ARP for cable service?  0 http://www.cloudshark.org/captures/79e79275d8ce
I sniffed this from a laptop plugged directly into my cable modem.
I get HAMMERED with arp on my cable service. My ISP IT support is not very knowledgeable (did not know what ARP was) and my activity lights are on constant flicker mode. It really makes the lights useless and all the traffic cannot be good for anything.
I read in a few places this could be considered normal or might be due to virus infected machines on my subnet?</description>
    </item>
    
    <item>
      <title>Problem viewing unencrypting SSL packet</title>
      <link>/questions/11778/problem-viewing-unencrypting-ssl-packet/</link>
      <pubDate>Fri, 08 Jun 2012 16:15:00 +0000</pubDate>
      
      <guid>/questions/11778/problem-viewing-unencrypting-ssl-packet/</guid>
      <description>Problem viewing unencrypting SSL packet  0 I&#39;ve followed the guides etc, but no luck.
Here is the log:
ssl_association_remove removing TCP 8443 - http handle 0000000003DC0F70 Private key imported: KeyID ea:a4:54:89:95:d5:9e:3b:41:fa:21:22:0c:e3:12:14:... ssl_init IPv4 addr &amp;#39;10.10.1.58&amp;#39; (10.10.1.58) port &amp;#39;8443&amp;#39; filename &amp;#39;C:\applications\keys\foo2.pkf&amp;#39; password(only for p12 file) &amp;#39;&amp;#39; ssl_init private key file C:\applications\keys\foo2.pkf successfully loaded. association_add TCP port 8443 protocol http handle 0000000003DC0F70 dissect_ssl enter frame #4 (first time) ssl_session_init: initializing ptr 0000000005891D30 size 680 conversation = 0000000005891880, ssl_session = 0000000005891D30 record: offset = 0, reported_length_remaining = 165 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 160, ssl state 0x00 association_find: TCP port 52160 found 0000000000000000 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 1 offset 5 length 156 bytes, remaining 165 packet_from_server: is from server - FALSE ssl_find_private_key server 10.</description>
    </item>
    
    <item>
      <title>Intercept communication to certain websites</title>
      <link>/questions/11791/intercept-communication-to-certain-websites/</link>
      <pubDate>Sat, 09 Jun 2012 23:11:00 +0000</pubDate>
      
      <guid>/questions/11791/intercept-communication-to-certain-websites/</guid>
      <description>Intercept communication to certain websites  0 Hi, there! I am quite curious about WireShark, and as an experiment, I have programmed a simple application which contacts a specific website, and outputs the contents of that website.
My goal is to see if it is possible to use wireshark to:
Detect that my app (or any app at all, no need for specificity, only my app will visit this page) is contacting the specific webpageStop the connectionSend back false data, making my app think that the website returned something that it didn&#39;tIs this possible at all, and if so, how might I do it?</description>
    </item>
    
    <item>
      <title>How can start the wireshark with command line</title>
      <link>/questions/11795/how-can-start-the-wireshark-with-command-line/</link>
      <pubDate>Sun, 10 Jun 2012 01:52:00 +0000</pubDate>
      
      <guid>/questions/11795/how-can-start-the-wireshark-with-command-line/</guid>
      <description>How can start the wireshark with command line  0 i have XP i go to cmd &#34;C:\Program Files\Wireshark\wireshark.exe&#34;
thanks
qaasked 10 Jun &#39;12, 01:52
artur1979
1●1●1●1
accept rate: 0%
This is not a question. What is it do you want to know?
(10 Jun &#39;12, 03:40) Jasper ♦♦   </description>
    </item>
    
    <item>
      <title>error: implicit declaration of function &amp;#x27;tvb_get_guint16&amp;#x27;</title>
      <link>/questions/11797/error-implicit-declaration-of-function-tvb_get_guint16/</link>
      <pubDate>Sun, 10 Jun 2012 09:10:00 +0000</pubDate>
      
      <guid>/questions/11797/error-implicit-declaration-of-function-tvb_get_guint16/</guid>
      <description>error: implicit declaration of function &amp;lsquo;tvb_get_guint16&amp;rsquo;  0 Getting following error while make :
error: implicit declaration of function &#39;tvb_get_guint16&#39;
error: implicit declaration of function &#39;tvb_get_guint24&#39;
What library i will have to include to fix this ?
dissector wiresharkasked 10 Jun &#39;12, 09:10
yogeshg
41●22●23●26
accept rate: 0%
  
One Answer:
  
0You are calling a function that does not exist, hence the error message. In tvbuff.</description>
    </item>
    
    <item>
      <title>Is UDP-Lite checksum correct (IPv6) ?</title>
      <link>/questions/11798/is-udp-lite-checksum-correct-ipv6/</link>
      <pubDate>Sun, 10 Jun 2012 09:26:00 +0000</pubDate>
      
      <guid>/questions/11798/is-udp-lite-checksum-correct-ipv6/</guid>
      <description>Is UDP-Lite checksum correct (IPv6) ?  0 the packet
00 50 56 c0 00 01 //dst mac
00 0c 29 fb 59 a8 //src mac
86 dd
60 00 00 00 //ipv6
00 28 //payload length
88 //next header UDP-Lite
80 //hop limit
20 01 00 00 00 00 00 00 00 00 00 00 00 00 00 01 //src ip
20 01 00 00 00 00 00 00 00 00 00 00 00 00 00 02 //dst ip</description>
    </item>
    
    <item>
      <title>line based text data</title>
      <link>/questions/11803/line-based-text-data/</link>
      <pubDate>Sun, 10 Jun 2012 16:09:00 +0000</pubDate>
      
      <guid>/questions/11803/line-based-text-data/</guid>
      <description>line based text data  0 Im new to wireshark, but from my understanding line based texta data of POST methods is where usernames and passwords are displayed, however sometimes this field appears to be encrypted, is there anyway to see the text form of it? Thanks for the help!
helpasked 10 Jun &#39;12, 16:09
gumby67
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Using Rawshark or tshark for wireless traffic</title>
      <link>/questions/11804/using-rawshark-or-tshark-for-wireless-traffic/</link>
      <pubDate>Sun, 10 Jun 2012 23:30:00 +0000</pubDate>
      
      <guid>/questions/11804/using-rawshark-or-tshark-for-wireless-traffic/</guid>
      <description>Using Rawshark or tshark for wireless traffic  0 Hi ,
I am trying to use AirPcap to sniff wireless packets using t-shark but I cannot save the capture and use a filter together
C:\Program Files\Wireshark&amp;gt;tshark.exe -a &amp;quot;duration:5&amp;quot; -R &amp;quot;wlan.fc.type_subtype = = 0x08&amp;quot; -i 1 -w D:tshark.cap tshark: Read filters aren&#39;t supported when capturing and saving the captured packets.So I use t-shark only to capture packets and later try to filter it using rawshark</description>
    </item>
    
    <item>
      <title>WNSRP support?</title>
      <link>/questions/11805/wnsrp-support/</link>
      <pubDate>Mon, 11 Jun 2012 01:03:00 +0000</pubDate>
      
      <guid>/questions/11805/wnsrp-support/</guid>
      <description>WNSRP support?  0 Hello, I have captured a mobile link using wireshark application. The file is a Sip conversation for a video call using WNSRP instead of h245 for its control channel. When I see the capture file analysis and use the filter h245, four h245 messages have been found; in their Information field it says terminalCapabilitySet, MasterSlaveDetermination, and vendorIdentification messages is detected. No more h245 messages are found, so openLogicalChannel and multiplexEntrySend messages is not available.</description>
    </item>
    
    <item>
      <title>How to capture TCP without its payload?</title>
      <link>/questions/11807/how-to-capture-tcp-without-its-payload/</link>
      <pubDate>Mon, 11 Jun 2012 05:30:00 +0000</pubDate>
      
      <guid>/questions/11807/how-to-capture-tcp-without-its-payload/</guid>
      <description>How to capture TCP without its payload?  0 During sending a large amount of data (~1 TB) there are some kind of connection errors which I want to track out. If I capture the whole tcp traffic, than the final pcap file will be more likely about ~1TB.
How to capture my tcp traffic to a file not writing its payload. I am not interested in contents I send, I am much interested in tcp conversation instead.</description>
    </item>
    
    <item>
      <title>How to filter From field in HTTP header?</title>
      <link>/questions/11809/how-to-filter-from-field-in-http-header/</link>
      <pubDate>Mon, 11 Jun 2012 08:40:00 +0000</pubDate>
      
      <guid>/questions/11809/how-to-filter-from-field-in-http-header/</guid>
      <description>How to filter From field in HTTP header?  0 Hi, I want to filter &#34;From: &#34; field in HTTP header of a packet but it seems wireshark doesn&#39;t understands that field. I am using wireshark verison 1.6.8.
What should be done to resolve this issue? Is there any newer version which supports this field?
Thanks, Ravi
httpasked 11 Jun &#39;12, 08:40
RAVI_TANDON
10●4●4●7
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark Plugin Help</title>
      <link>/questions/11816/wireshark-plugin-help/</link>
      <pubDate>Mon, 11 Jun 2012 10:47:00 +0000</pubDate>
      
      <guid>/questions/11816/wireshark-plugin-help/</guid>
      <description>Wireshark Plugin Help  0 Hi All,
Recently I began to work with Wireshark, so I have little experience with the &#34;plugin&#34; environment or setup. When I attempted to install the plugin by building Wireshark, I got the following errors. Could someone tell me what I&#39;m doing wrong and/or what I can do to fix it?
Thanks!
Ian
packet-ipa.c c:\Program Files (x86)\wireshark\epan/reassemble.h(69) : error C2061: syntax error : identifier &amp;#39;guint32&amp;#39; c:\Program Files (x86)\wireshark\epan/reassemble.</description>
    </item>
    
    <item>
      <title>Struggling, want to get started...</title>
      <link>/questions/11823/struggling-want-to-get-started/</link>
      <pubDate>Mon, 11 Jun 2012 12:23:00 +0000</pubDate>
      
      <guid>/questions/11823/struggling-want-to-get-started/</guid>
      <description>Struggling, want to get started&amp;hellip;  0 I have Windows 7 64 bit with Linksys WUSB54GC and as I understands it it is not possible to make to work in promiscous mode?
I&#39;ve tried some netsh to enable it but still no luck. I would like to be able to capture packets not ment for me :-)
any magic and i can perform to make it happen?
windows7 wiresharkasked 11 Jun &#39;12, 12:23</description>
    </item>
    
    <item>
      <title>Sharktools: Build Matshark...Please help!!!</title>
      <link>/questions/11839/sharktools-build-matsharkplease-help/</link>
      <pubDate>Mon, 11 Jun 2012 14:17:00 +0000</pubDate>
      
      <guid>/questions/11839/sharktools-build-matsharkplease-help/</guid>
      <description>Sharktools: Build Matshark&amp;hellip;Please help!!!  0 Hello All,
In order to build Matshark, I followed the instructions on http://cpansearch.perl.org/src/NANIS/Net-Sharktools-0.009/README.sharktools-0.1.5.txt
I am using a 32 bit, ubuntu 10.04 machine with gcc-4.3.4
I configured as follows: ./configure --disable-pyshark --with-mex=/[path/to/mex] --with-wireshark-src=[/path/to/wireshark]
The process completes successfully and makefile is generated. When I issue the &#34;make&#34; command, I get:
sharktools_cfile.c: In function &#39;cap_file_init&#39;:
sharktools_cfile.c:47: error:&#39;capture_file&#39; has no member named &#39;plist_start&#39;
sharktools_cfile.c:51: error:&#39;capture_file&#39; has no member named &#39;plist_end&#39;</description>
    </item>
    
    <item>
      <title>how can i capture tcp traffic without ip layer and frame layer?</title>
      <link>/questions/11848/how-can-i-capture-tcp-traffic-without-ip-layer-and-frame-layer/</link>
      <pubDate>Tue, 12 Jun 2012 04:31:00 +0000</pubDate>
      
      <guid>/questions/11848/how-can-i-capture-tcp-traffic-without-ip-layer-and-frame-layer/</guid>
      <description>how can i capture tcp traffic without ip layer and frame layer?  1 Hi all how can i capture tcp traffic without capturing ip layer and frame layer?
i want to see only tcp layer information execpt L2 and L3 layer information. in this case, can i make it shows just tcp layer only. i think, if it is possible, it seems so easy to analysis captured wireshark. also it will make exported txt file very short.</description>
    </item>
    
    <item>
      <title>filter string does not shown at first time?</title>
      <link>/questions/11853/filter-string-does-not-shown-at-first-time/</link>
      <pubDate>Tue, 12 Jun 2012 06:50:00 +0000</pubDate>
      
      <guid>/questions/11853/filter-string-does-not-shown-at-first-time/</guid>
      <description>filter string does not shown at first time?  0 Hi all after upgrading wireshark into ver1.6.8 can&#39;t input filter string on Filter as the below cursor is pointing Filter: but can&#39;t insert any character or something else. also after opening a wireshark files, when i click any frame, it&#39;s color is shown as gray color but not blue. as i know, on normal operation, frame i clicked is shown as blue background color.</description>
    </item>
    
    <item>
      <title>How to use multiple lines for one header field?</title>
      <link>/questions/11857/how-to-use-multiple-lines-for-one-header-field/</link>
      <pubDate>Tue, 12 Jun 2012 09:05:00 +0000</pubDate>
      
      <guid>/questions/11857/how-to-use-multiple-lines-for-one-header-field/</guid>
      <description>How to use multiple lines for one header field?  0 The dissector that I&#39;m working on includes a header that encodes a DAG. The easiest way to read a DAG in human-readable format is in a way where each node (maximum of 9 nodes) is converted to a string and placed on a different line. I am looking to implement in Wireshark something like:
Destination DAG: 0x1-1234567890123456789012345678901234567890-1: 0x2-123456789a123456789a123456789a123456789a-1; 0x3-123456789b123456789b123456789b123456789b-0;Where the indentation denotes that the three nodes above are in the subtree of &#34;</description>
    </item>
    
    <item>
      <title>packet bytes field is not shown</title>
      <link>/questions/11862/packet-bytes-field-is-not-shown/</link>
      <pubDate>Tue, 12 Jun 2012 19:23:00 +0000</pubDate>
      
      <guid>/questions/11862/packet-bytes-field-is-not-shown/</guid>
      <description>packet bytes field is not shown  0 Hi all in my wireshark, packet bytes field is not shown such as attached image. some frames are good but few frames doesn&#39;t show packet bytes filed. (packet list and packet details field are shown always)
how can i fix it?
bytes packetasked 12 Jun &#39;12, 19:23
Ray_Han
56●6●6●11
accept rate: 0%
 edited 12 Jun &#39;12, 19:23 
after downgrading into ver1.</description>
    </item>
    
    <item>
      <title>Why do TCP clients send packets with no data?</title>
      <link>/questions/11863/why-do-tcp-clients-send-packets-with-no-data/</link>
      <pubDate>Tue, 12 Jun 2012 20:12:00 +0000</pubDate>
      
      <guid>/questions/11863/why-do-tcp-clients-send-packets-with-no-data/</guid>
      <description>Why do TCP clients send packets with no data?  1 After the TCP connection between server and client establishes, I&#39;m seeing a lot of TCP packets with no length like the one below, where 172.16.80.65 is the client and 172.16.178.77 is the server:
70 1.064245 172.16.80.65 172.16.178.77 TCP cvspserver &amp;gt; 60000 [ACK] Seq=1112 Ack=33028 Win=65535 Len=0 detail:Frame 74 (60 bytes on wire, 60 bytes captured)I determined the 60 bytes are from:</description>
    </item>
    
    <item>
      <title>vs2008 open the wireshark, convenient debug research?</title>
      <link>/questions/11867/vs2008-open-the-wireshark-convenient-debug-research/</link>
      <pubDate>Wed, 13 Jun 2012 03:47:00 +0000</pubDate>
      
      <guid>/questions/11867/vs2008-open-the-wireshark-convenient-debug-research/</guid>
      <description>vs2008 open the wireshark, convenient debug research?  0 On Windows, Wireshark compiled engineering, exe also created.
Because the compiler is in the console, it is not convenient to debug learning, I hope can vs2008 open the engineering, convenient debug research. But, the original project is nmake file organization with the compiler, no vs2008. SLN files, do not know to have method conversion. Nmake to. SLN, or through the other way for vs2008 open project?</description>
    </item>
    
    <item>
      <title>Debug console - nothing displayed</title>
      <link>/questions/11874/debug-console-nothing-displayed/</link>
      <pubDate>Wed, 13 Jun 2012 09:01:00 +0000</pubDate>
      
      <guid>/questions/11874/debug-console-nothing-displayed/</guid>
      <description>Debug console - nothing displayed  1 I want to do some printf debugging and have used g_print() as described in http://wiki.wireshark.org/Development/Tips .
I am setting the &#34;Open a console window&#34; dropdown to show &#34;Always (debugging)&#34;.
I am building from SVN source using MSVC Express 2010. When I run Wireshark by double-clicking on the &#34;Wireshark&#34; icon in &#34;wireshark-gtk2&#34; directory, the console appears but there is no output at all apart from when I close Wireshark and it says &#34;</description>
    </item>
    
    <item>
      <title>Why is Wireshark using Dell Latitude E6400 not capturing all data ?</title>
      <link>/questions/11877/why-is-wireshark-using-dell-latitude-e6400-not-capturing-all-data/</link>
      <pubDate>Wed, 13 Jun 2012 10:56:00 +0000</pubDate>
      
      <guid>/questions/11877/why-is-wireshark-using-dell-latitude-e6400-not-capturing-all-data/</guid>
      <description>Why is Wireshark using Dell Latitude E6400 not capturing all data ?  0 Running various versions of Wireshark on a Dell Latitude E6400 only displays some TCPIP data in one direction and IP traffic etc. from laptop in the other when monitoring the link in the other direction. We are using a Copper Tap A &amp;amp; B outputs.
All other models of Dell laptop e.g E4300, D630 etc. work ok.</description>
    </item>
    
    <item>
      <title>protocol text file to pcap</title>
      <link>/questions/11878/protocol-text-file-to-pcap/</link>
      <pubDate>Wed, 13 Jun 2012 13:29:00 +0000</pubDate>
      
      <guid>/questions/11878/protocol-text-file-to-pcap/</guid>
      <description>protocol text file to pcap  0 Hi friends! I need to convert text to pcap, this is an example. Can you help me? Thanks! Julian
================================================================================ [No. ] 1 [TimeStamp ] 2012-06-13 11:49:03 [Msg Name ] &amp;lt;BYE [Module No ] 1407 [Remote Address] 172.26.2.65:9163 [Ticks ] 1561178745 [Hex Msg ] 42 59 45 20 73 69 70 3A 31 37 32 2E 32 36 2E 32 2E 36 35 3A &amp;hellip;</description>
    </item>
    
    <item>
      <title>TCP problem</title>
      <link>/questions/11880/tcp-problem/</link>
      <pubDate>Wed, 13 Jun 2012 16:38:00 +0000</pubDate>
      
      <guid>/questions/11880/tcp-problem/</guid>
      <description>TCP problem  0 ![alt text][1]
[1]: imgur.com&#34; /&amp;gt;
This one capture at site B. I try to understand this. After [SYN], the server at site A just keep pushing the data to server at site B, but I did not see any [ACK] back at site B. I only see the Window size 92 but with unknown scaling. They communicate over satellite link. Any body can point out what going on?</description>
    </item>
    
    <item>
      <title>Multiple Header Files</title>
      <link>/questions/11881/multiple-header-files/</link>
      <pubDate>Wed, 13 Jun 2012 18:04:00 +0000</pubDate>
      
      <guid>/questions/11881/multiple-header-files/</guid>
      <description>Multiple Header Files  0 I am working on a network-layer dissector for a prototypical protocol (that&#39;s a mouthful) that is an alternative to IP; an eXpressive Internet Architecture. The addressing scheme for this protocol includes the use of DAGs, which require a few header files and a .c source file that defines various functions for operating on the DAGs.
I would like to keep the header files intact and separate, rather than incorporating them all into packet-xip.</description>
    </item>
    
    <item>
      <title>Point me example using  eth.trailer subdissector list of Ethernet dissector</title>
      <link>/questions/11888/point-me-example-using-ethtrailer-subdissector-list-of-ethernet-dissector/</link>
      <pubDate>Wed, 13 Jun 2012 23:13:00 +0000</pubDate>
      
      <guid>/questions/11888/point-me-example-using-ethtrailer-subdissector-list-of-ethernet-dissector/</guid>
      <description>Point me example using eth.trailer subdissector list of Ethernet dissector  0 The Ethernet dissector has an eth.trailer subdissector list , i want an example using this
plugin wiresharkasked 13 Jun &#39;12, 23:13
yogeshg
41●22●23●26
accept rate: 0%
  
One Answer:
  
1Have a look at the VSS monitoring dissector:
epan/dissectors/packet-vssmonitoring.canswered 13 Jun &#39;12, 23:36
SYN-bit ♦♦
17.1k●9●57●245
accept rate: 20%
Thanks for instant reply. How will wireshark decide on what part of packet is a trailer ?</description>
    </item>
    
    <item>
      <title>Can we get total length of IP packet from pinfo pointer ?</title>
      <link>/questions/11892/can-we-get-total-length-of-ip-packet-from-pinfo-pointer/</link>
      <pubDate>Thu, 14 Jun 2012 00:51:00 +0000</pubDate>
      
      <guid>/questions/11892/can-we-get-total-length-of-ip-packet-from-pinfo-pointer/</guid>
      <description>Can we get total length of IP packet from pinfo pointer ?  0 I intend to dissect last 12 bytes of my protocol packet and for that i am using eth.trailer subdissector list of standard ethernet dissector. And we know that in IP header we have a field of 2 bytes which denotes total length of IP packet.Also i assume IP dissector must have done its dissection before my dissector will get called.</description>
    </item>
    
    <item>
      <title>[closed] how to use heur_dissector_add() function to dissect.</title>
      <link>/questions/11893/how-to-use-heur_dissector_add-function-to-dissect/</link>
      <pubDate>Thu, 14 Jun 2012 00:55:00 +0000</pubDate>
      
      <guid>/questions/11893/how-to-use-heur_dissector_add-function-to-dissect/</guid>
      <description>[closed] how to use heur_dissector_add() function to dissect.  0 I have put the dissector upon &#34;udp&#34;.But in the wireshark UI,open a packet,select a item, use the &#34;disscetor as&#34; option. the question is :there is no fp(my protocol) to select.why? thank U very much! follow is the code.
void proto_reg_handoff_fp(void) { mac_fdd_rach_handle = find_dissector(&#34;mac.fdd.rach&#34;); mac_fdd_fach_handle = find_dissector(&#34;mac.fdd.fach&#34;); mac_fdd_pch_handle = find_dissector(&#34;mac.fdd.pch&#34;); mac_fdd_dch_handle = find_dissector(&#34;mac.fdd.dch&#34;); mac_fdd_edch_handle = find_dissector(&#34;mac.fdd.edch&#34;); mac_fdd_hsdsch_handle = find_dissector(&#34;mac.fdd.hsdsch&#34;); heur_dissector_add(&#34;udp&#34;, heur_dissect_fp, proto_fp); }</description>
    </item>
    
    <item>
      <title>how to use the two function: heur_dissect_XX() and heur_dissector_add()？</title>
      <link>/questions/11894/how-to-use-the-two-function-heur_dissect_xx-and-heur_dissector_add/</link>
      <pubDate>Thu, 14 Jun 2012 01:06:00 +0000</pubDate>
      
      <guid>/questions/11894/how-to-use-the-two-function-heur_dissect_xx-and-heur_dissector_add/</guid>
      <description>how to use the two function: heur_dissect_XX() and heur_dissector_add()？  0 The two function just in the packet-umts-fp.c. The protocol is &#34;fp&#34;.but i don&#39;t know how to use it. When I select a packet,then dissect as,there is no &#34;fp&#34; to select.why?
Hope the master give advice or comments please!
fp heur-dissect umts-fpasked 14 Jun &#39;12, 01:06
smilezuzu
20●32●32●37
accept rate: 0%
  
One Answer:
  
0Hi, Look in doc/README.</description>
    </item>
    
    <item>
      <title>Why can&amp;#x27;t Wireshark catch packets?</title>
      <link>/questions/11895/why-cant-wireshark-catch-packets/</link>
      <pubDate>Thu, 14 Jun 2012 01:11:00 +0000</pubDate>
      
      <guid>/questions/11895/why-cant-wireshark-catch-packets/</guid>
      <description>Why can&amp;rsquo;t Wireshark catch packets?  0 Hi guys:
My OS is windowsxp.When I use Wireshark to catch the packets between server and client who are both running on my comuputer,I can&#39;t catch any packets between them. But on the other hand,I use command &#39;netstat&#39; to show connection between them and still find the establishment between them.
Maybe I can figure out the reason why Wireshark catch no data.(Because of their correspondence relys on LoopBack and datas aren&#39;t sent by interface.</description>
    </item>
    
    <item>
      <title>&#43;&#43;CC Runtime Errors after upgrade to Wireshark 1.68</title>
      <link>/questions/11901/cc-runtime-errors-after-upgrade-to-wireshark-168/</link>
      <pubDate>Thu, 14 Jun 2012 10:12:00 +0000</pubDate>
      
      <guid>/questions/11901/cc-runtime-errors-after-upgrade-to-wireshark-168/</guid>
      <description>++CC Runtime Errors after upgrade to Wireshark 1.68  0 Run time errors coming up randomly while doing a Capture or looking at statistics?? We recently upgraded from Version 1.6.2 due to multiple performance of tool not responding, loosing graphic display and also abends due to low memory errors. This was corrected the performance of the software improved. I can navigate without a probem the different pannels of the tool, but I am unable to stop now the CC ++ Runtime errors please advice on how I can correct this problem?</description>
    </item>
    
    <item>
      <title>Only Able to Capture One Side of RTP</title>
      <link>/questions/11910/only-able-to-capture-one-side-of-rtp/</link>
      <pubDate>Thu, 14 Jun 2012 17:18:00 +0000</pubDate>
      
      <guid>/questions/11910/only-able-to-capture-one-side-of-rtp/</guid>
      <description>Only Able to Capture One Side of RTP  0 When I capture RTP Packets from my IP phone I only seem to get one side of the conversation. The source and destination stay the same all the way through the conversation. I never see the switch during the call. So when I go to play back the call I only get one side. The source always seems to be the person who initiated the call.</description>
    </item>
    
    <item>
      <title>Criteria for dissector calling</title>
      <link>/questions/11911/criteria-for-dissector-calling/</link>
      <pubDate>Thu, 14 Jun 2012 17:50:00 +0000</pubDate>
      
      <guid>/questions/11911/criteria-for-dissector-calling/</guid>
      <description>Criteria for dissector calling  0 Hi, allI am a newbie on dissector development. I have a question about the &#34;dissector_add( )&#34; function.
I went through a few examples, most of them are using &#34;tcp.port&#34; or &#34;udp.port&#34; or something like that.My dissector not uses any port number to instruct wireshark to pass packets to my dissector, instead i want it to be called only when eth.dst is of certain pattern and i don&#39;t want to use heuristic dissector coz that&#39;s getting complicated.</description>
    </item>
    
    <item>
      <title>How to use umts-fp dissector?</title>
      <link>/questions/11913/how-to-use-umts-fp-dissector/</link>
      <pubDate>Thu, 14 Jun 2012 20:59:00 +0000</pubDate>
      
      <guid>/questions/11913/how-to-use-umts-fp-dissector/</guid>
      <description>How to use umts-fp dissector?  0 I have a fp packet ,but I don&#39;t know how to use the umts-fp dissector to disset it . Becouse if I use &#34;fp&#34; filter to filter my packet,then is nothing.
Hope the master give advice or comments please! or give me the packet that can be filter by the &#34;fp&#34;.My email is &#34;[email protected]163.com&#34;.
Thanks!
fp umts-fpasked 14 Jun &#39;12, 20:59
smilezuzu</description>
    </item>
    
    <item>
      <title>[closed] How to decode FP over UDP?</title>
      <link>/questions/11918/how-to-decode-fp-over-udp/</link>
      <pubDate>Thu, 14 Jun 2012 23:17:00 +0000</pubDate>
      
      <guid>/questions/11918/how-to-decode-fp-over-udp/</guid>
      <description>[closed] How to decode FP over UDP?  0 I am using Wireshark version 1.6.4. I have some FP packets in pcap format. However I do not see FP protocol option in &#34;decode as&#34; list. However Enabled protocols， shows FP protocolsenabled which indicates Wireshark supports fp. I fill &#34;fp&#34; in filters,I can not get no Packets filtered.Howerver,I see some packets over UDP transported from RNC.
Please tell me how can I decode packets as FP.</description>
    </item>
    
    <item>
      <title>filter to capture entire sessions</title>
      <link>/questions/11922/filter-to-capture-entire-sessions/</link>
      <pubDate>Fri, 15 Jun 2012 01:51:00 +0000</pubDate>
      
      <guid>/questions/11922/filter-to-capture-entire-sessions/</guid>
      <description>filter to capture entire sessions  0 I have a application talking to a database using persistent sessions. From time to time new sessions are initiated and I want to capture only those ones. I could wait hours before seeing a new session, so I&#39;m looking for a capture filter that will allow only interesting traffic to be saved on disk. Please point me to any linux command line tool and filter syntax I could use.</description>
    </item>
    
    <item>
      <title>looking for a computer sending out spam how do I find it using wireshark?</title>
      <link>/questions/11941/looking-for-a-computer-sending-out-spam-how-do-i-find-it-using-wireshark/</link>
      <pubDate>Fri, 15 Jun 2012 07:56:00 +0000</pubDate>
      
      <guid>/questions/11941/looking-for-a-computer-sending-out-spam-how-do-i-find-it-using-wireshark/</guid>
      <description>looking for a computer sending out spam how do I find it using wireshark?  0 I am looking for a computer sending email, I have an IP of the source, I am trying to locate the machine. It is internal on our domain, we are using NAT. The emails are getting blocked, I am just trying to the computer, any ideas. All the posts I read, is to use wireshark.</description>
    </item>
    
    <item>
      <title>How do I compile Wireshark with Lua and libsmi in Redhat?</title>
      <link>/questions/11948/how-do-i-compile-wireshark-with-lua-and-libsmi-in-redhat/</link>
      <pubDate>Fri, 15 Jun 2012 08:26:00 +0000</pubDate>
      
      <guid>/questions/11948/how-do-i-compile-wireshark-with-lua-and-libsmi-in-redhat/</guid>
      <description>How do I compile Wireshark with Lua and libsmi in Redhat?  0 I tried to compile Wireshark 1.6.8 with Lua and libsmi in RHEL with the below commands, but I&#39;m seeing errors:
$ ./configure --prefix=&amp;quot;/home/OPENSOURCE/WIRESHARK/1.6.8/Linux/RHEL4_2.6&amp;quot; \ --with-lua=&amp;quot;/home/OPENSOURCE/LUA/5.1/Linux/RHEL4_2.6&amp;quot; \ --with-libsmi=&amp;quot;/home/OPENSOURCE/LIBSMI/0.4.8/Linux/RHEL4_2.6&amp;quot; $ make &amp;ndash;&amp;gt; After running &amp;quot;make&amp;quot; command, it&#39;s hung up with below error &amp;quot;/home/OPENSOURCE/LUA/5.1/Linux/RHEL4_2.6/lib/liblua.a: could not read symbols: Bad value&amp;quot;I also recompiled Lua and tried again, but no luck&amp;hellip;same error.</description>
    </item>
    
    <item>
      <title>Measuring bandwidth without capture all data</title>
      <link>/questions/11971/measuring-bandwidth-without-capture-all-data/</link>
      <pubDate>Fri, 15 Jun 2012 12:31:00 +0000</pubDate>
      
      <guid>/questions/11971/measuring-bandwidth-without-capture-all-data/</guid>
      <description>Measuring bandwidth without capture all data  0 Hi,
I&#39;m new to Wireshark and I want to be able to take the measure of our File Server bandwidth utilisation for a possible move into a remote location. So I want to capture (by port miroring) on a week my file server.
For testing purpose I start a capture excluding broadcast and multicast packets, in files with a 5 minutes rotation for a couples of hour.</description>
    </item>
    
    <item>
      <title>Can ACKs happen outside the RWIN?</title>
      <link>/questions/11972/can-acks-happen-outside-the-rwin/</link>
      <pubDate>Fri, 15 Jun 2012 13:14:00 +0000</pubDate>
      
      <guid>/questions/11972/can-acks-happen-outside-the-rwin/</guid>
      <description>Can ACKs happen outside the RWIN?  0 I hope this is a straightforward question. Can the receiving side send ACKs at significantly less than the RWIN size? Example:
Note the bytes in flight
Receiving side 1.1.1.1
Sending side 2.2.2.2
48 0.000 1.1.1.1 2.2.2.2 TCP printer &amp;gt; netviewdm1 [ACK] Seq=3 Ack=32798 Win=64296 Len=0 TSV=26412037 TSER=3842799487 49 0.029 2.2.2.2 1.1.1.1 LPD LPD continuation [Number of bytes in flight: 1368] 50 0.000 2.</description>
    </item>
    
    <item>
      <title>GSM A-Interface over IP setting ?</title>
      <link>/questions/11981/gsm-a-interface-over-ip-setting/</link>
      <pubDate>Fri, 15 Jun 2012 15:36:00 +0000</pubDate>
      
      <guid>/questions/11981/gsm-a-interface-over-ip-setting/</guid>
      <description>GSM A-Interface over IP setting ?  0 Hi, Could someone help/show me the setting so I can see the GSM A-interface over IP message? Basically, I do have pcap trace captured BUT I could not tell what is the message because.... -Info Column shows &#34;SACK Unassigned: treated as an unknown Message Type&#34; -Protocol Colunm shows &#34;BSSAP+&#34; Therefore, wireshark does not decode whatever after/under BSAP/BSSAP.
aoipasked 15 Jun &#39;12, 15:36</description>
    </item>
    
    <item>
      <title>Find an IP address</title>
      <link>/questions/11984/find-an-ip-address/</link>
      <pubDate>Fri, 15 Jun 2012 21:12:00 +0000</pubDate>
      
      <guid>/questions/11984/find-an-ip-address/</guid>
      <description>Find an IP address  0 I have just downloaded wireshark, I have an access point from a manufacturer that is no longer in business and the I don&#39;t know the default ip address. I am a novice. How do I determine the AP&#39;s address. (simple... with steps... please.... thanks)
ip addressasked 15 Jun &#39;12, 21:12
vsimon
1●1●1●1
accept rate: 0%
  
One Answer:
  
0power off the APconnect the AP and your sniffer PC with a switch (don&#39;t use a crossover cable!</description>
    </item>
    
    <item>
      <title>Only recieve win=65535 info packets</title>
      <link>/questions/11987/only-recieve-win65535-info-packets/</link>
      <pubDate>Sat, 16 Jun 2012 03:57:00 +0000</pubDate>
      
      <guid>/questions/11987/only-recieve-win65535-info-packets/</guid>
      <description>Only recieve win=65535 info packets  0 I only want to display packets which have win=65535 in the info, how to do this as filter?
info win65535asked 16 Jun &#39;12, 03:57
solvapolva
1●1●1●1
accept rate: 0%
  
One Answer:
  
1You can use the filter:
tcp.window_size == 65535You can always look in the packet details for a field with it&#39;s value and then use (rightclick) Apply as filter to achieve this in an easy way :-)</description>
    </item>
    
    <item>
      <title>Sniffer port down while Wireshark shows packets receive</title>
      <link>/questions/11988/sniffer-port-down-while-wireshark-shows-packets-receive/</link>
      <pubDate>Sat, 16 Jun 2012 04:09:00 +0000</pubDate>
      
      <guid>/questions/11988/sniffer-port-down-while-wireshark-shows-packets-receive/</guid>
      <description>Sniffer port down while Wireshark shows packets receive  0 Currently we are involved in Nice VoIP Infrastructure. We had a case where sniffer port was unable to receive data but wireshark shows packets receive.
Is it a current status of sniffer port?
Is it that wireshark is only capturing what switch port is throwing not what sniffer captures?
Your quick response will be highly appreciated.
Thanks.
Umar.
switch sniffer systems niceasked 16 Jun &#39;12, 04:09</description>
    </item>
    
    <item>
      <title>Can wireshark capture traffic between a browser and jboss (both running on localhost)?</title>
      <link>/questions/11992/can-wireshark-capture-traffic-between-a-browser-and-jboss-both-running-on-localhost/</link>
      <pubDate>Sat, 16 Jun 2012 06:25:00 +0000</pubDate>
      
      <guid>/questions/11992/can-wireshark-capture-traffic-between-a-browser-and-jboss-both-running-on-localhost/</guid>
      <description>Can wireshark capture traffic between a browser and jboss (both running on localhost)?  0 I&#39;m trying to capture traffic between a web browser running on my windows 7 machine and a jboss server also running on my machine but wireshark doesn&#39;t seem to capture it.
For what it&#39;s worth, I&#39;ve successfully captured the traffic if the web browser is on another machine.
Is this even possible? If so, what am I missing?</description>
    </item>
    
    <item>
      <title>How to rebuilt when I add a new dissector in Plugin mode.</title>
      <link>/questions/12000/how-to-rebuilt-when-i-add-a-new-dissector-in-plugin-mode/</link>
      <pubDate>Sun, 17 Jun 2012 23:45:00 +0000</pubDate>
      
      <guid>/questions/12000/how-to-rebuilt-when-i-add-a-new-dissector-in-plugin-mode/</guid>
      <description>How to rebuilt when I add a new dissector in Plugin mode.  0 I have add a new protocol&#34;scoreboard&#34; dissector in plugin,files is located in wireshark1.6.4\plugins\scoreboard. when i rebuilt the dissector in \plugin. as: nmake -f Makefile.nmake all. and then I run the main program, there is nothing changed. but when i rebuilt all of the project .(need much more time) .the change had been write in code has appeared .</description>
    </item>
    
    <item>
      <title>I Can&amp;#x27;t see any FTP traffic in WireShark log</title>
      <link>/questions/12001/i-cant-see-any-ftp-traffic-in-wireshark-log/</link>
      <pubDate>Sun, 17 Jun 2012 23:56:00 +0000</pubDate>
      
      <guid>/questions/12001/i-cant-see-any-ftp-traffic-in-wireshark-log/</guid>
      <description>I Can&amp;rsquo;t see any FTP traffic in WireShark log  0 FTP server 10.10.1.4 | | | HUB | |
| | FTP client Monitor PC 10.10.1.150 10.10.1.136
FTP client logon FTP server success , and download file from FTP server , i can&#39;t see any traffic about FTP and
IP based 10.10.1.150 , i have no ideal why no traffic captured by wireshark , pls help me
ftpasked 17 Jun &#39;12, 23:56</description>
    </item>
    
    <item>
      <title>wireshark not in executable format: File format not recognized</title>
      <link>/questions/12007/wireshark-not-in-executable-format-file-format-not-recognized/</link>
      <pubDate>Mon, 18 Jun 2012 02:45:00 +0000</pubDate>
      
      <guid>/questions/12007/wireshark-not-in-executable-format-file-format-not-recognized/</guid>
      <description>wireshark not in executable format: File format not recognized  0 I followed standard procedure , autogen.sh , configure then make .. And somehow executable was not produced instead a shell script was made up , that&#39;s why getting this error below in gdb :-
I want to make executable , in order to debug via gdb .. what i am missing?
[[email protected] wireshark-1.7.1]# gdb ./wireshark GNU gdb Fedora (6.</description>
    </item>
    
    <item>
      <title>How monitor disconnection of a program.</title>
      <link>/questions/12014/how-monitor-disconnection-of-a-program/</link>
      <pubDate>Mon, 18 Jun 2012 04:08:00 +0000</pubDate>
      
      <guid>/questions/12014/how-monitor-disconnection-of-a-program/</guid>
      <description>How monitor disconnection of a program.  0 Hi everyone,
We have a program like telnet, the wireshark installation is on the host machine. ¿How I can monitor the client and how I can filter this connections (client to host) to know then a network or program disconnect from the host server?
I ready tryed with tcp.flags.reset==1 or tcp.flags.fin==1 but this is not usefull to me, i&#39;m looking a way to get more deep info like what port the client app opens to the host server, etc.</description>
    </item>
    
    <item>
      <title>TCP analysis / interpertation - ACKs and lost segments</title>
      <link>/questions/12016/tcp-analysis-interpertation-acks-and-lost-segments/</link>
      <pubDate>Mon, 18 Jun 2012 04:36:00 +0000</pubDate>
      
      <guid>/questions/12016/tcp-analysis-interpertation-acks-and-lost-segments/</guid>
      <description>TCP analysis / interpertation - ACKs and lost segments  0 Hi,
I&#39;m trying to perform TCP analysis, or at least learn how to do it, and I would really appreciate some information about the following filter fields.
tcp.analysis.ack_lost_segment tcp.analysis.lost_segment tcp.analysis.duplicate_ack tcp.analysis.retransmission
I&#39;m not really sure about the first two, since I&#39;ve read in some places that they might be due to drops in Wireshark while capturing, and might not be a real issue of the TCP stream.</description>
    </item>
    
    <item>
      <title>How can I decrypt IKEv1 and/or ESP packets ?</title>
      <link>/questions/12019/how-can-i-decrypt-ikev1-andor-esp-packets/</link>
      <pubDate>Mon, 18 Jun 2012 06:27:00 +0000</pubDate>
      
      <guid>/questions/12019/how-can-i-decrypt-ikev1-andor-esp-packets/</guid>
      <description>How can I decrypt IKEv1 and/or ESP packets ?  1 1I am using the latest development release. When I try to create a new SA for ISAKMP, it asks for Initiator Cookie and Encryption Cookie. I know the initiator cookie but I am not sure where I can I get this encryption. I know all the configuration of my VPN (encryption algorithm, authentication algorithm, pre-shared key) let me know if it is required here.</description>
    </item>
    
    <item>
      <title>Wireshark logs</title>
      <link>/questions/12026/wireshark-logs/</link>
      <pubDate>Mon, 18 Jun 2012 07:59:00 +0000</pubDate>
      
      <guid>/questions/12026/wireshark-logs/</guid>
      <description>Wireshark logs  0 Hello,
I made a successfull test call and the call was connected fine. But i can&#39;t see the signals from the called party and the only signals are from calling party. Its seems to be quite strange. What could be the reason? ======================
This is a SIP call and the SONUS SBC and the media is voice. The Wireshark is not showing the signals from the called party.</description>
    </item>
    
    <item>
      <title>Built in Dissector compiles but doesn&amp;#x27;t load.</title>
      <link>/questions/12028/built-in-dissector-compiles-but-doesnt-load/</link>
      <pubDate>Mon, 18 Jun 2012 11:11:00 +0000</pubDate>
      
      <guid>/questions/12028/built-in-dissector-compiles-but-doesnt-load/</guid>
      <description>Built in Dissector compiles but doesn&amp;rsquo;t load.  0 I wrote the foo dissector example, put it in epan/dissectors, changed the Makefile.common, and ran the whole autogen, configure, make, make install. My code compiles just fine now and i don&#39;t run into any errors or warnings. However when i run wireshark my protocol is not there. It is red when i type it in the filter and it does not appear on the list of supported protocols.</description>
    </item>
    
    <item>
      <title>Malformed radiotap header in wireshark and background noise parameter missing</title>
      <link>/questions/12031/malformed-radiotap-header-in-wireshark-and-background-noise-parameter-missing/</link>
      <pubDate>Mon, 18 Jun 2012 15:47:00 +0000</pubDate>
      
      <guid>/questions/12031/malformed-radiotap-header-in-wireshark-and-background-noise-parameter-missing/</guid>
      <description>Malformed radiotap header in wireshark and background noise parameter missing  0 0 down vote favorite share [g+] share [fb] share [tw]
I have set up an experiment to measure Wireless communication parameters using two laptops. I am injecting custom packets into the network on a monitor interface using one laptop programmed as a transmitter(Macbook Pro using Broadcom BCM 4331 interface card) and another laptop ( Dell Latitude E6410 using the Intel Corporation Centrino Ultimate-N 6300 interface card) programmed as a receiver sniffs the network for the custom injected packets and reports parameters such as Received signal strength, propagation delay etc.</description>
    </item>
    
    <item>
      <title>Wireshark reporting different parameters in different machines</title>
      <link>/questions/12032/wireshark-reporting-different-parameters-in-different-machines/</link>
      <pubDate>Mon, 18 Jun 2012 15:58:00 +0000</pubDate>
      
      <guid>/questions/12032/wireshark-reporting-different-parameters-in-different-machines/</guid>
      <description>Wireshark reporting different parameters in different machines  0 I have Wireshark installed in two laptops, one injecting custom packets into the network and another sniffing these injected packets. When I transmit the packets using the fist machine (Macbook Pro using Broadcom BCM 4331 interface card), I am able to see these packets in Wireshark with all the various fields such as SSI, Noise etc.
But the Wireshark installed on the other machine (Dell Latitude E6410 using the Intel Corporation Centrino Ultimate-N 6300 interface card) shows the radio-tap header to be of length 18 only, and is missing parameters like Noise and timestamp.</description>
    </item>
    
    <item>
      <title>Display Filters - Importing Kismet pcapdump - Can I get unique MAC addresses?</title>
      <link>/questions/12036/display-filters-importing-kismet-pcapdump-can-i-get-unique-mac-addresses/</link>
      <pubDate>Mon, 18 Jun 2012 17:54:00 +0000</pubDate>
      
      <guid>/questions/12036/display-filters-importing-kismet-pcapdump-can-i-get-unique-mac-addresses/</guid>
      <description>Display Filters - Importing Kismet pcapdump - Can I get unique MAC addresses?  0 I have scanned wireless networks (access points) with Kismet. Kismet gives me different files, including pcapdump, which I can open in Wireshark. I am very new to Wireshark, but I am reading and trying to grasp the concepts.
My main goal is to find the percentage of population using different encryption types, like WEP, WPA, WPA2 etc.</description>
    </item>
    
    <item>
      <title>[closed] How to get imformation used in dissector FP over udp/ip?</title>
      <link>/questions/12051/how-to-get-imformation-used-in-dissector-fp-over-udpip/</link>
      <pubDate>Tue, 19 Jun 2012 02:14:00 +0000</pubDate>
      
      <guid>/questions/12051/how-to-get-imformation-used-in-dissector-fp-over-udpip/</guid>
      <description>[closed] How to get imformation used in dissector FP over udp/ip?  0 I am using Wireshark version 1.6.4. I have some FP packets in pcap format. Please tell me how can I decode packets as FP. Those sample fp packets are transported over UDP. In the function &#34;dissector_fp()&#34;,it have some preference come from ATM/DCT2000,but in UDP/IP,there is no such information pass to fp level. how can I get this information(used to decode the fp and above level,exmple:channel_type,is_uplink)?</description>
    </item>
    
    <item>
      <title>[closed] get the outhdr_string  to dissect FP.</title>
      <link>/questions/12052/get-the-outhdr_string-to-dissect-fp/</link>
      <pubDate>Tue, 19 Jun 2012 02:23:00 +0000</pubDate>
      
      <guid>/questions/12052/get-the-outhdr_string-to-dissect-fp/</guid>
      <description>[closed] get the outhdr_string to dissect FP.  0 In FP/AAL2/ATM/DCT2000 mode,the outhdr_string imformation(use to dissect in higher level) is dissector in dct2000 level.but in FP/UDP/IP/ mode,the outhdr_string imformation can&#39;t dissector from lower level. And with out the outhdr_string imformation ,I can&#39;t dissector the fp packet. Hope the master tell me how to resolve the problem. Best regards!
fp dissect_fp outhdr_stringasked 19 Jun &#39;12, 02:23
smilezuzu
20●32●32●37
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Malformed 32 byte TLS/SSL packet</title>
      <link>/questions/12062/malformed-32-byte-tlsssl-packet/</link>
      <pubDate>Tue, 19 Jun 2012 09:34:00 +0000</pubDate>
      
      <guid>/questions/12062/malformed-32-byte-tlsssl-packet/</guid>
      <description>Malformed 32 byte TLS/SSL packet  0 I have the following packet when trying to examine an SSL session. This is a local capture but I have a capture from the target network as well. I see the same packet on both ends.
Frame 16: 540 bytes on wire (4320 bits), 540 bytes captured (4320 bits) Internet Protocol Version 4, Src: 172.20.2.164 (172.20.2.164), Dst: 169.20.69.250 (169.20.69.250) Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport)) Total Length: 526 Flags: 0x02 (Don&amp;#39;t Fragment) Header checksum: 0x790d [correct] Transmission Control Protocol, Src Port: 57599 (57599), Dst Port: https (443), Seq: 2331060189, Ack: 18913651, Len: 474 Checksum: 0x56c7 [validation disabled] Secure Sockets Layer TLSv1 Record Layer: Application Data Protocol: tcp Content Type: Application Data (23) Version: TLS 1.</description>
    </item>
    
    <item>
      <title>How to know GSM MAP protocol version and release supported by wireshark(Version 1.0.3 (SVN Rev 26134))</title>
      <link>/questions/12066/how-to-know-gsm-map-protocol-version-and-release-supported-by-wiresharkversion-103-svn-rev-26134/</link>
      <pubDate>Wed, 20 Jun 2012 02:03:00 +0000</pubDate>
      
      <guid>/questions/12066/how-to-know-gsm-map-protocol-version-and-release-supported-by-wiresharkversion-103-svn-rev-26134/</guid>
      <description>How to know GSM MAP protocol version and release supported by wireshark(Version 1.0.3 (SVN Rev 26134))  0 How to know GSM MAP protocol version and latest release supported by wire shark. Is there any way So, that user can find out which protocol version and Release supported by wireshark release Version 1.0.3 (SVN Rev 26134)
gsm wiresharkasked 20 Jun &#39;12, 02:03
amankalra13
1●1●1●3
accept rate: 0%
 edited 20 Jun &#39;12, 02:26</description>
    </item>
    
    <item>
      <title>How do I get the interface name for use with the -i flag in Windows</title>
      <link>/questions/12075/how-do-i-get-the-interface-name-for-use-with-the-i-flag-in-windows/</link>
      <pubDate>Wed, 20 Jun 2012 08:49:00 +0000</pubDate>
      
      <guid>/questions/12075/how-do-i-get-the-interface-name-for-use-with-the-i-flag-in-windows/</guid>
      <description>How do I get the interface name for use with the -i flag in Windows  0 How do I know the name of the interface for the -i flag in windows? I tried the reported name (Intel(r) 82579LM Gigabit Network Connection) both with and without quotes around it.. as well as the interface listed when you go to Capture Interfaces -&amp;gt; Details.. which shows
\Devices\NPF_{362508C4-F6CC-4A4A-AB17-9DA1017E4C41} (I tried using just the NPF and the rest to the right with the -i flag)</description>
    </item>
    
    <item>
      <title>Multiple [RST] pacquets on ms-sql-s sessions.</title>
      <link>/questions/12077/multiple-rst-pacquets-on-ms-sql-s-sessions/</link>
      <pubDate>Wed, 20 Jun 2012 08:51:00 +0000</pubDate>
      
      <guid>/questions/12077/multiple-rst-pacquets-on-ms-sql-s-sessions/</guid>
      <description>Multiple [RST] pacquets on ms-sql-s sessions.  0 Dear all,
Is there someone who can explain to me why in my Wireshark captures I have sessions that ends with several RST packets following normal TCP end Session and the other not.
I want to specifie that hosts concerned are always the same hosts but in different processes numbers
here attaching the captures.   
Thank you for your help.</description>
    </item>
    
    <item>
      <title>tshark doesn&amp;#x27;t seem to like radius</title>
      <link>/questions/12078/tshark-doesnt-seem-to-like-radius/</link>
      <pubDate>Wed, 20 Jun 2012 09:43:00 +0000</pubDate>
      
      <guid>/questions/12078/tshark-doesnt-seem-to-like-radius/</guid>
      <description>tshark doesn&amp;rsquo;t seem to like radius  0 I have a capture file that i&#39;d like to post process a bit and needing to focus on the sub name and framed ip addr in the radius files, but each time i try to filter off specific radius fields i get:
RADIUS$ tshark -r radius.cap2 -R &#39;radius.Framed-Ip-Address&#39;
tshark: &#34;radius.Framed-Ip-Address&#34; is neither a field nor a protocol name.
radius tshark framed-ip-addressasked 20 Jun &#39;12, 09:43</description>
    </item>
    
    <item>
      <title>Will wireshark detect source of ping floods on Syswan SW-24?</title>
      <link>/questions/12098/will-wireshark-detect-source-of-ping-floods-on-syswan-sw-24/</link>
      <pubDate>Wed, 20 Jun 2012 22:00:00 +0000</pubDate>
      
      <guid>/questions/12098/will-wireshark-detect-source-of-ping-floods-on-syswan-sw-24/</guid>
      <description>Will wireshark detect source of ping floods on Syswan SW-24?  0 howdee all... first time on. below is one of hundreds emails i&#39;ve been getting over the last two weeks from my SW-24. the floods last 10-20 minutes, then seem to stop for a while...some days there are multiple floods, others only one. They occur at random times.
...DL&#39;d WS, BUT...not sure how to set up filters for the SW-24.</description>
    </item>
    
    <item>
      <title>Logging CAN bus data to WS in Windows</title>
      <link>/questions/12102/logging-can-bus-data-to-ws-in-windows/</link>
      <pubDate>Thu, 21 Jun 2012 02:17:00 +0000</pubDate>
      
      <guid>/questions/12102/logging-can-bus-data-to-ws-in-windows/</guid>
      <description>Logging CAN bus data to WS in Windows  1 I&#39;d like to add CAN bus support to Wireshark under Windows (unfortunately), and I&#39;m hoping someone can give me an idea where to start.
WS currently has a dissector for CAN (Controller Area Network) data - but I&#39;m assuming that the source of the data is from the socketcan library (is that correct?) which is a patch to the Linux sockets stack.</description>
    </item>
    
    <item>
      <title>Is Encrypted Alert the cause of this delay?</title>
      <link>/questions/12106/is-encrypted-alert-the-cause-of-this-delay/</link>
      <pubDate>Thu, 21 Jun 2012 08:19:00 +0000</pubDate>
      
      <guid>/questions/12106/is-encrypted-alert-the-cause-of-this-delay/</guid>
      <description>Is Encrypted Alert the cause of this delay?  0 I am helping a volunteer community run a local library. We are working with the local authority and have to use their book loan/reservation system. Currently this is driving the volunteers crazy with unexplained and undiagnosed IT problems. The problem is not unique to our site - other volunteer libraries also experience it with the same frequency (up to 10 or more times per day).</description>
    </item>
    
    <item>
      <title>Save the SMB object list?</title>
      <link>/questions/12113/save-the-smb-object-list/</link>
      <pubDate>Thu, 21 Jun 2012 11:49:00 +0000</pubDate>
      
      <guid>/questions/12113/save-the-smb-object-list/</guid>
      <description>Save the SMB object list?  0 If I invoke &#34;File-&amp;gt;Export-&amp;gt;Objects-&amp;gt;SMB&#34;, it brings up a pop-up window with a list of SMB objects. Is there a way to save this list? There are &#34;Save...&#34; buttons on the pop-up window, but these save the SMB objects themselves, not the list. I&#39;d like to generate a report for SMB objects similar to the Statistics-&amp;gt;HTTP-&amp;gt;Requests... menu item.
save export smbasked 21 Jun &#39;12, 11:49</description>
    </item>
    
    <item>
      <title>How to use Wireshark as a FTP proxy checker tool</title>
      <link>/questions/12118/how-to-use-wireshark-as-a-ftp-proxy-checker-tool/</link>
      <pubDate>Thu, 21 Jun 2012 17:13:00 +0000</pubDate>
      
      <guid>/questions/12118/how-to-use-wireshark-as-a-ftp-proxy-checker-tool/</guid>
      <description>How to use Wireshark as a FTP proxy checker tool  0 How to use Wireshark as a FTP proxy checker tool when using various FTP clients uploading to a proxy server with a proxifying program for the FTP client. How can Wireshark confirm files are being transmitted through the port tunneling to the proxy server? Browser proxy can be checked with www.whatismyipadress.com. Where are the instructions on how can FTP uploading by proxy be checked with Wireshark?</description>
    </item>
    
    <item>
      <title>unable to decrypt ssl traffic in wireshark logs</title>
      <link>/questions/12121/unable-to-decrypt-ssl-traffic-in-wireshark-logs/</link>
      <pubDate>Thu, 21 Jun 2012 19:47:00 +0000</pubDate>
      
      <guid>/questions/12121/unable-to-decrypt-ssl-traffic-in-wireshark-logs/</guid>
      <description>unable to decrypt ssl traffic in wireshark logs  0 I have applied the correct ips as well as the server key for this log but am still unable to decypt it . this waqs taken from the client system connected to my server. there were no proxies involved.
ssl_association_remove removing TCP 443 - http handle 00000000049BDF30 1821 bytes read PKCS#12 imported Bag 0/0: Encrypted Bag 0/0 decrypted: Certificate Certificate imported: *.</description>
    </item>
    
    <item>
      <title>capture filter for ipv6 network prefix</title>
      <link>/questions/12128/capture-filter-for-ipv6-network-prefix/</link>
      <pubDate>Fri, 22 Jun 2012 01:17:00 +0000</pubDate>
      
      <guid>/questions/12128/capture-filter-for-ipv6-network-prefix/</guid>
      <description>capture filter for ipv6 network prefix  0 hello.
I want to write a filter to capture all IPv6 packets that match the net prefix with a subnet id. With ipv4 is simple: net 192.168.5 but with ipv6 this not works for me: net fec0:abcd:1234::
How can i capture the packets that match with network prefix?
Thanks and sorry for my poor english
filter capture ipv6asked 22 Jun &#39;12, 01:17</description>
    </item>
    
    <item>
      <title>How to capture RTSP flow?</title>
      <link>/questions/12134/how-to-capture-rtsp-flow/</link>
      <pubDate>Fri, 22 Jun 2012 14:57:00 +0000</pubDate>
      
      <guid>/questions/12134/how-to-capture-rtsp-flow/</guid>
      <description>How to capture RTSP flow?  0 Hi!
I&#39;m using Unreal Media Server and would like to capture the network traffic related to RTSP protocol. I&#39;m able to get some data but it is not in the format I was expecting. I can&#39;t see OPTIONS in the info column and can&#39;t follow the RTSP negotiation.
Is there any specific setting in wireshark so it can show RSTP packets in the full form?</description>
    </item>
    
    <item>
      <title>Can anyone decode this Encrypted Alert please?</title>
      <link>/questions/12137/can-anyone-decode-this-encrypted-alert-please/</link>
      <pubDate>Sun, 24 Jun 2012 11:17:00 +0000</pubDate>
      
      <guid>/questions/12137/can-anyone-decode-this-encrypted-alert-please/</guid>
      <description>Can anyone decode this Encrypted Alert please?  0 The hex data shown below is a TLSv1 packet taken from a Wireshark trace. It shows an Encrypted Alert message according to Wireshark. The only problem is I cannot work out just what the alert really is - according to my research on the web the alert code level and description bytes contain the values 53 and AD - however these do not correspond to any values I can find.</description>
    </item>
    
    <item>
      <title>Can Wireshark detect a rogue program silently sending an email?</title>
      <link>/questions/12139/can-wireshark-detect-a-rogue-program-silently-sending-an-email/</link>
      <pubDate>Sun, 24 Jun 2012 18:45:00 +0000</pubDate>
      
      <guid>/questions/12139/can-wireshark-detect-a-rogue-program-silently-sending-an-email/</guid>
      <description>Can Wireshark detect a rogue program silently sending an email?  0 How can I use Wireshark to determine that a rogue program (malware) silently sent an email from my computer?
malwareasked 24 Jun &#39;12, 18:45
Dee
1●1●1●1
accept rate: 0%
 edited 25 Jun &#39;12, 19:34 
helloworld
3.1k●4●20●41
  
One Answer:
  
0You can sniff on your computer, but Wireshark will only show that there is something sending an e-mail, however it will not show the process name.</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t run Wireshark in Mac OS X - Mountain Lion</title>
      <link>/questions/12140/cant-run-wireshark-in-mac-os-x-mountain-lion/</link>
      <pubDate>Sun, 24 Jun 2012 19:57:00 +0000</pubDate>
      
      <guid>/questions/12140/cant-run-wireshark-in-mac-os-x-mountain-lion/</guid>
      <description>can&amp;rsquo;t run Wireshark in Mac OS X - Mountain Lion  4 1Why doesn&#39;t Wireshark start in Mac OS X Mountain Lion?
osx mac startupasked 24 Jun &#39;12, 19:57
teulong
61●1●3●3
accept rate: 0%
 edited 26 Jul &#39;12, 16:53 
helloworld
3.1k●4●20●41
  
6 Answers:
  
9I&#39;m having problems as well... Double-clicking on the Wireshark icon, or launching via Alfred doesn&#39;t do anything. I did install XQuartz since upgrading to ML.</description>
    </item>
    
    <item>
      <title>Win2008 fails with .dll error</title>
      <link>/questions/12142/win2008-fails-with-dll-error/</link>
      <pubDate>Mon, 25 Jun 2012 00:12:00 +0000</pubDate>
      
      <guid>/questions/12142/win2008-fails-with-dll-error/</guid>
      <description>Win2008 fails with .dll error  0 I have recently installed Wireshark on a Windows 2008 SP2 server. The NICs are Broadcom NetExtreme II with the latest drivers. The error in the Windows application error log is:
Faulting application wireshark.exe, version 1.8.0.43431, time stamp 0x4fe369bd, faulting module libglib-2.0-0.dll, version 2.32.2.0, time stamp 0x4faa7bfc, exception code 0x40000015, fault offset 0x000000000004fd12, process id 0x1110, application start time 0x01cd52939171d90c.
Any help would be appreciated</description>
    </item>
    
    <item>
      <title>TCP Retransmission sending wrong sequence</title>
      <link>/questions/12145/tcp-retransmission-sending-wrong-sequence/</link>
      <pubDate>Mon, 25 Jun 2012 04:46:00 +0000</pubDate>
      
      <guid>/questions/12145/tcp-retransmission-sending-wrong-sequence/</guid>
      <description>TCP Retransmission sending wrong sequence  0 Hi,
I hope someone here can help. I have seen a strange problem where our server seems to be retransmitting the segment prior to the one being requested by the Duplicate ACKs sent by the client.
The Duplicate ACK is requesting re-transmission: Acknowledgement number: 422281 (relative ack number)
Sometimes I see an ICMP packet being sent by the server after receipt of the Duplicate ACK, usually in response to the first five of these Duplicate ACKs, but can be later as well, in this particular case the last five received too :</description>
    </item>
    
    <item>
      <title>Couldn&amp;#x27;t load module....specified module cannot be found.</title>
      <link>/questions/12153/couldnt-load-modulespecified-module-cannot-be-found/</link>
      <pubDate>Mon, 25 Jun 2012 11:29:00 +0000</pubDate>
      
      <guid>/questions/12153/couldnt-load-modulespecified-module-cannot-be-found/</guid>
      <description>Couldn&amp;rsquo;t load module&amp;hellip;.specified module cannot be found.  0 I downloaded and installed Wireshark 1.8.0 executable (win32). Its runs without a problem.
I have a custom dissector that I have been using since at least Wireshark 1.4.x. I downloaded the 1.8.0 source and compiled it and my dissector. I ran Wireshark out of the gtk2 subdirectory; and it ran great, and my dissector had no issues.
I copied my dissector (adsb.</description>
    </item>
    
    <item>
      <title>Can I write a filter to locate sequence number inconsistencies?</title>
      <link>/questions/12154/can-i-write-a-filter-to-locate-sequence-number-inconsistencies/</link>
      <pubDate>Mon, 25 Jun 2012 14:49:00 +0000</pubDate>
      
      <guid>/questions/12154/can-i-write-a-filter-to-locate-sequence-number-inconsistencies/</guid>
      <description>Can I write a filter to locate sequence number inconsistencies?  0 Consider the following. I believe that one of my rouers is failing to pass an ICMP response back very intermittently (maybe 1:10,000). While I do not care about the ICMP packets themselves this issue is causing intermittent transmission failure.
What I have been doing is runnning a capture for a period of time and checking the sequence number for skips.</description>
    </item>
    
    <item>
      <title>Capture Review</title>
      <link>/questions/12175/capture-review/</link>
      <pubDate>Tue, 26 Jun 2012 06:54:00 +0000</pubDate>
      
      <guid>/questions/12175/capture-review/</guid>
      <description>Capture Review  0 I am new to WireShark and was wondering if there is a fee based service to have a capture file reviewed by a professional. I am learning as I go but don&#39;t think I will be able to properly evaluate the data anytime soon.
professional reviewasked 26 Jun &#39;12, 06:54
idtfla
0●1●1
accept rate: 0%
 edited 26 Jun &#39;12, 07:14 
Bill Meier ♦♦
3.2k●1●8●50</description>
    </item>
    
    <item>
      <title>Capture filter, tcp port and tcp portrange</title>
      <link>/questions/12176/capture-filter-tcp-port-and-tcp-portrange/</link>
      <pubDate>Tue, 26 Jun 2012 06:59:00 +0000</pubDate>
      
      <guid>/questions/12176/capture-filter-tcp-port-and-tcp-portrange/</guid>
      <description>Capture filter, tcp port and tcp portrange  0 Hello guys :)
I&#39;m looking for a help. I have a problem with capture filter configuration.
I want to capture just a traffic from specific tcp ports. (TCP port 23 (telnet) and tcp portrange 2066-2100)
So my syntax in &#34;Capture options&#34; &#34;Capture filter&#34; field looks like this:
tcp dst port 23 and tcp dst portrange 2066-2100
and there is no capture with this command!</description>
    </item>
    
    <item>
      <title>Capture filter. TCP stream as txt file</title>
      <link>/questions/12179/capture-filter-tcp-stream-as-txt-file/</link>
      <pubDate>Tue, 26 Jun 2012 07:24:00 +0000</pubDate>
      
      <guid>/questions/12179/capture-filter-tcp-stream-as-txt-file/</guid>
      <description>Capture filter. TCP stream as txt file  0 Hi guys.
Maybe there is a method, to save or convert wireshark capture file directly to txt?
For example, to get the same output into txt file, as we can see, when we press the button &#34;Follow tcp stream&#34; ?
capture stream tcpasked 26 Jun &#39;12, 07:24
jomajo
1●3●3●5
accept rate: 100%
  
One Answer:
  
1You can use tshark (Version &amp;gt;= 1.</description>
    </item>
    
    <item>
      <title>No Server Hello, Certificate, but works</title>
      <link>/questions/12187/no-server-hello-certificate-but-works/</link>
      <pubDate>Tue, 26 Jun 2012 09:08:00 +0000</pubDate>
      
      <guid>/questions/12187/no-server-hello-certificate-but-works/</guid>
      <description>No Server Hello, Certificate, but works  0 Running version 1.8.0. I have a trace of my client connecting to its server successfully. The WireShark trace does not have a Server Hello, Certificate, Server Hello Done. There is a Client Hello, followed by 1494 bytes [TCP segment of a reassembled PDU] followed by 967 bytes of &#34;Ignored unknown Record&#34; followed by Client Key Exchange. I can see the certificate info in the data preceding the Client Key Exchange but Wireshark doesn&#39;t recognize it.</description>
    </item>
    
    <item>
      <title>Cisco Spectrum Expert (cognio) to Wireshark</title>
      <link>/questions/12189/cisco-spectrum-expert-cognio-to-wireshark/</link>
      <pubDate>Tue, 26 Jun 2012 10:30:00 +0000</pubDate>
      
      <guid>/questions/12189/cisco-spectrum-expert-cognio-to-wireshark/</guid>
      <description>Cisco Spectrum Expert (cognio) to Wireshark  0 Is there a way to migrate/convert Cisco (formerly Cognio) Spectrum Expert ccf file format into a file that wireshark can see (ie pcap)...Didn&#39;t see anything in Cisco&#39;s guide:
http://www.cisco.com/en/US/docs/wireless/spectrum/expert/users/guide/spectrumexpert.pdf
ccf cognioasked 26 Jun &#39;12, 10:30
aamercado
1●1●1●1
accept rate: 0% 
  
One Answer:
  
0From the manual:
Cisco Spectrum Expert monitors the RF spectrum used by a variety of wireless network and communications technologies, such as Wi-Fi (802.</description>
    </item>
    
    <item>
      <title>Remote Interface setup</title>
      <link>/questions/12191/remote-interface-setup/</link>
      <pubDate>Tue, 26 Jun 2012 11:28:00 +0000</pubDate>
      
      <guid>/questions/12191/remote-interface-setup/</guid>
      <description>Remote Interface setup  0 Under Capture Options Interface remote - after completing the dialog I get the following error:
Microsoft Visual C++ runtime library. This application has requested the runtime to terminate it in an unusual way. Please contact the application&#39;s support team for more information. I can repeat this over and over again.
Running Wireshark 1.6.6 (SVN Rev 41803 from /trunk-1.6) on Windows 7 64 bit workstation. WinPcap 4.</description>
    </item>
    
    <item>
      <title>USB to Ethernet Adapter doesn&amp;#x27;t show under interfaces</title>
      <link>/questions/12192/usb-to-ethernet-adapter-doesnt-show-under-interfaces/</link>
      <pubDate>Tue, 26 Jun 2012 12:02:00 +0000</pubDate>
      
      <guid>/questions/12192/usb-to-ethernet-adapter-doesnt-show-under-interfaces/</guid>
      <description>USB to Ethernet Adapter doesn&amp;rsquo;t show under interfaces  1 I have a regular NIC and an USB to Ethernet Adapter. The NIC shows but the USB doesn&#39;t. How can I get this to work.
to adapter usb ethernetasked 26 Jun &#39;12, 12:02
gvbingel
16●1●1●2
accept rate: 0%
  
One Answer:
  
3What is your OS?
Windows
Might be a problem with WinPcap. See here: http://www.winpcap.org/pipermail/winpcap-bugs/2010-March/001183.html</description>
    </item>
    
    <item>
      <title>Q.931 - Does anyone know what might generate this traffic?</title>
      <link>/questions/12197/q931-does-anyone-know-what-might-generate-this-traffic/</link>
      <pubDate>Tue, 26 Jun 2012 12:44:00 +0000</pubDate>
      
      <guid>/questions/12197/q931-does-anyone-know-what-might-generate-this-traffic/</guid>
      <description>Q.931 - Does anyone know what might generate this traffic?  0 lapd q.931asked 26 Jun &#39;12, 12:44
someitguy2012
1●1●1●1
accept rate: 0%
  
4 Answers:
  
1Maybe it&#39;s just the Cisco RLM dissector getting a &#34;false positive&#34;; almost all the packets appear not to be LAPD-over-UDP, even if the dissector is treating them as such, given all the errors in the dissection. To quote a comment in that dissector:</description>
    </item>
    
    <item>
      <title>Checksum: 0xcdbe [validation disabled]</title>
      <link>/questions/12205/checksum-0xcdbe-validation-disabled/</link>
      <pubDate>Tue, 26 Jun 2012 13:03:00 +0000</pubDate>
      
      <guid>/questions/12205/checksum-0xcdbe-validation-disabled/</guid>
      <description>Checksum: 0xcdbe [validation disabled]  0 Does anyone know what this string is using port 1434 for?
User Datagram Protocol, Src Port: 54781 (54781), Dst Port: ms-sql-m (1434) Source port: 54781 (54781) Destination port: ms-sql-m (1434) Length: 20
Checksum: 0xcdbe [validation disabled] Good Checksum: False Bad Checksum: False
checksum udpasked 26 Jun &#39;12, 13:03
Wshark6
1●2●2●3
accept rate: 0%
  
One Answer:
  
0See SQL Server Browser Service.</description>
    </item>
    
    <item>
      <title>Differentiated Services Field?</title>
      <link>/questions/12206/differentiated-services-field/</link>
      <pubDate>Tue, 26 Jun 2012 13:06:00 +0000</pubDate>
      
      <guid>/questions/12206/differentiated-services-field/</guid>
      <description>Differentiated Services Field?  0 Does anyone know what this is using port 1433 for?
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport)) Total Length: 732 Identification: 0x0599 (1433)
services field differentiated identificationasked 26 Jun &#39;12, 13:06
Wshark6
1●2●2●3
accept rate: 0%
  
One Answer:
  
2The Identification field is simply a unique ID applied to each packet a host sends on a particular connection.</description>
    </item>
    
    <item>
      <title>Cannot capture crafted raw packet on Intel X540 T2 10G NIC</title>
      <link>/questions/12214/cannot-capture-crafted-raw-packet-on-intel-x540-t2-10g-nic/</link>
      <pubDate>Tue, 26 Jun 2012 15:36:00 +0000</pubDate>
      
      <guid>/questions/12214/cannot-capture-crafted-raw-packet-on-intel-x540-t2-10g-nic/</guid>
      <description>Cannot capture crafted raw packet on Intel X540 T2 10G NIC  0 I create and send Ethernet packet by SharpPcap, then I catch those packets by wireshark. When I send those packets to my Intel 82579LM gigabit NIC, I can catch those packets. But I cannot catch any single packet when I send those packets to my Intel X540 T2 10 GE NIC. I can catch packets such as ICMP, TCP but not my own packets.</description>
    </item>
    
    <item>
      <title>Question regarding Wireshark and port mirroring</title>
      <link>/questions/12220/question-regarding-wireshark-and-port-mirroring/</link>
      <pubDate>Tue, 26 Jun 2012 20:25:00 +0000</pubDate>
      
      <guid>/questions/12220/question-regarding-wireshark-and-port-mirroring/</guid>
      <description>Question regarding Wireshark and port mirroring  0 I am trying to use Wireshark to analyze traffic from my Netgear Stora media server to my Xbox 360. I know (after researching here) that if the PC I have Wireshark installed on is connected to a switch, that switch must allow port mirroring.
My setup:
* Comcast Modem --&amp;gt; Linksys Router (e4200) --&amp;gt; Switch 1 (GS105) &amp;amp; Switch 2 (GS108) &amp;amp; Netgear Stora media server</description>
    </item>
    
    <item>
      <title>How to chose a capture-filter in version 1.8.0 as previous in the capture-options menu of version 1.6</title>
      <link>/questions/12221/how-to-chose-a-capture-filter-in-version-180-as-previous-in-the-capture-options-menu-of-version-16/</link>
      <pubDate>Tue, 26 Jun 2012 21:11:00 +0000</pubDate>
      
      <guid>/questions/12221/how-to-chose-a-capture-filter-in-version-180-as-previous-in-the-capture-options-menu-of-version-16/</guid>
      <description>How to chose a capture-filter in version 1.8.0 as previous in the capture-options menu of version 1.6  2 1Hello wireshark community
With version 1.6 I can choose/select a capture-filter in the capture-options dialog menue. In version 1.8 this option has disappeared in the capture-options dialog menue. How to select a capture-filter in version 1.8 by GUI? Perhaps only now with the -f parameter when I start wireshark?
I am not a very expirienced user of wireshark yet, but very impressed.</description>
    </item>
    
    <item>
      <title>Prepopulate Filters in IO Graphs?</title>
      <link>/questions/12226/prepopulate-filters-in-io-graphs/</link>
      <pubDate>Tue, 26 Jun 2012 23:35:00 +0000</pubDate>
      
      <guid>/questions/12226/prepopulate-filters-in-io-graphs/</guid>
      <description>Prepopulate Filters in IO Graphs?  0 I use the same IO Graphs filters every time when I begin my analysis of WLAN traces. Is there a way to pre-populate the filters and save them so I don&#39;t have to fill them in every time?
graphasked 26 Jun &#39;12, 23:35
robin5u
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Go to:
Analyze -&amp;gt; Dsiplay Filters -&amp;gt; New</description>
    </item>
    
    <item>
      <title>WirelessChipset</title>
      <link>/questions/12227/wirelesschipset/</link>
      <pubDate>Wed, 27 Jun 2012 01:18:00 +0000</pubDate>
      
      <guid>/questions/12227/wirelesschipset/</guid>
      <description>WirelessChipset  0 Hi all. I just installed WireShark today. And in the interfaces menu, I couldnot find my wirelesscard. It could not recognise. I have &#34;Atheros AR5B97&#34; wirelesschipset. I need your help.
Ps. I don&#39;t have a card called MICROSOFT but it shows me. I was seekin&#39; in this forum. Saw someone was talkin&#39; about this.
ar5b97 atherosasked 27 Jun &#39;12, 01:18
mebeyce
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>WireShark AirPCAP</title>
      <link>/questions/12229/wireshark-airpcap/</link>
      <pubDate>Wed, 27 Jun 2012 02:17:00 +0000</pubDate>
      
      <guid>/questions/12229/wireshark-airpcap/</guid>
      <description>WireShark AirPCAP  0 I’m a Software Reseller in Korea.
Reason of sending mail to you, I have a question. My customer want using pre-version of WireShark AirPCAP.
If they purchase current version license, they have a use of right for pre-version for WireShark AirPCAP? According to answer about it, my customer decide to purchase order.
I am looking forward to your ASAP Reply.
Best Regards S.E-Park
wirelessasked 27 Jun &#39;12, 02:17</description>
    </item>
    
    <item>
      <title>Why am I seeing all this NTP activity?</title>
      <link>/questions/12247/why-am-i-seeing-all-this-ntp-activity/</link>
      <pubDate>Wed, 27 Jun 2012 15:40:00 +0000</pubDate>
      
      <guid>/questions/12247/why-am-i-seeing-all-this-ntp-activity/</guid>
      <description>Why am I seeing all this NTP activity?  0 I&#39;ve been doing some traces to try to determine why my users are seeing &#34;xxx.gov.uk not responding&#34; messages at irregular intervals for a business application. I see the pattern (in terms of trace records) below in virtually every case where my users see a 2 minute delay. Can anyone shed any light on why the PC (Win7) appears to suddenly start contacting lots of time servers?</description>
    </item>
    
    <item>
      <title>Bad Certificate</title>
      <link>/questions/12248/bad-certificate/</link>
      <pubDate>Wed, 27 Jun 2012 15:56:00 +0000</pubDate>
      
      <guid>/questions/12248/bad-certificate/</guid>
      <description>Bad Certificate  0 I have a Wireshark trace of a client machine I have that when it tries to connect to the server, gets &#34;Bad Certificate&#34;. If I use any browser, it works fine and never gets the error. I&#39;m by no means an expert on certificates. Can anyone take a look and see why the certificate is being rejected?
The location of the trace is: http://cloudshark.org/captures/9af27d06ecb3?filter=tcp.port%20%3D%3D%20443
bad certificateasked 27 Jun &#39;12, 15:56</description>
    </item>
    
    <item>
      <title>connection error between two laptop&amp;#x27;s</title>
      <link>/questions/12269/connection-error-between-two-laptops/</link>
      <pubDate>Thu, 28 Jun 2012 05:18:00 +0000</pubDate>
      
      <guid>/questions/12269/connection-error-between-two-laptops/</guid>
      <description>connection error between two laptop&amp;rsquo;s  0 Hi everybody,
I am using Wireshark ver.1.6.5 and tried to get a remote connection on other PC on my local network but i could&#39;nt able to do that and got a error &#34; Can&#39;t get list of interfaces: Is the server properly installed on X.X.X.X ?&#34; i need to explain that i created a user on my remote pc and added to Remote Packet Capture Protocol v.</description>
    </item>
    
    <item>
      <title>ftp connections found... how do I delete them?</title>
      <link>/questions/12270/ftp-connections-found-how-do-i-delete-them/</link>
      <pubDate>Thu, 28 Jun 2012 05:47:00 +0000</pubDate>
      
      <guid>/questions/12270/ftp-connections-found-how-do-i-delete-them/</guid>
      <description>ftp connections found&amp;hellip; how do I delete them?  0 So, recently i&#39;ve been downloading several high-risk and malicious programs/files/etc... At first, wireshark didnt find any ftp connections, meaning I haven&#39;t been keylogged then. But when i started wireshark today, i found several ftp connection, meaning i am the victim of keyloggers... Can anybody please help me on how to get rid of these connections?
Here are some of the ftp&#39;s found by wireshark.</description>
    </item>
    
    <item>
      <title>easy way to extract websites visited from a capture</title>
      <link>/questions/12271/easy-way-to-extract-websites-visited-from-a-capture/</link>
      <pubDate>Thu, 28 Jun 2012 06:08:00 +0000</pubDate>
      
      <guid>/questions/12271/easy-way-to-extract-websites-visited-from-a-capture/</guid>
      <description>easy way to extract websites visited from a capture  0 Hi all,
I have always wondered is there an easy way to extract the web pages that have been visited from a capture.
For example let&#39;s say I have a 30 min capture of all traffic from a user and I want a simple list of the websites he/she has visited i.e. facebook bbc etc. Is there an easy way to do this in wireshark or with another tool (by feeding in the pcap)?</description>
    </item>
    
    <item>
      <title>how can i read file continuously??</title>
      <link>/questions/12273/how-can-i-read-file-continuously/</link>
      <pubDate>Thu, 28 Jun 2012 06:56:00 +0000</pubDate>
      
      <guid>/questions/12273/how-can-i-read-file-continuously/</guid>
      <description>how can i read file continuously??  0 hi
I made packet-capture file and this is updated continuously by program. And I opened this file in wireshark and I reloaded file continuously because wireshark readed file once. I annoyed this act, so how can I do automaticuly this act?
I &#39;m bad at English. But please understand me.
open fileasked 28 Jun &#39;12, 06:56
netwguy
1●1●1●2
accept rate: 0%
 edited 28 Jun &#39;12, 06:58</description>
    </item>
    
    <item>
      <title>Capture all network traffic to single ip address</title>
      <link>/questions/12274/capture-all-network-traffic-to-single-ip-address/</link>
      <pubDate>Thu, 28 Jun 2012 07:47:00 +0000</pubDate>
      
      <guid>/questions/12274/capture-all-network-traffic-to-single-ip-address/</guid>
      <description>Capture all network traffic to single ip address  0 Hi I&#39;ve just started using wireshark and don&#39;t know what i&#39;m doing!! I need to capture all traffic on our LAN going to a single ip address so that I can find individual pc&#39;s. As soon as I have the ip addresses I can do a lookup in DNS. Is this possible and if so how using the Wireshark GUI?</description>
    </item>
    
    <item>
      <title>Port a linux plugin to windows</title>
      <link>/questions/12277/port-a-linux-plugin-to-windows/</link>
      <pubDate>Thu, 28 Jun 2012 09:23:00 +0000</pubDate>
      
      <guid>/questions/12277/port-a-linux-plugin-to-windows/</guid>
      <description>Port a linux plugin to windows  1 Is there any easy way for me to make the .dll file from what i already have in linux? From what I read, I&#39;d have to build wireshark in windows but it&#39;d take me a while to get all the necessary tools and set up the environment. Is there an easier method to get a plugin working on a windows platform? And yes my plugin works fine and I was able to use the .</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t call AirPDcapPacketProcess from a plugin dissector</title>
      <link>/questions/12285/cant-call-airpdcappacketprocess-from-a-plugin-dissector/</link>
      <pubDate>Thu, 28 Jun 2012 11:52:00 +0000</pubDate>
      
      <guid>/questions/12285/cant-call-airpdcappacketprocess-from-a-plugin-dissector/</guid>
      <description>Can&amp;rsquo;t call AirPDcapPacketProcess from a plugin dissector  0 packet-foo.obj : error LNK2019: unresolved external symbol _AirPDcapPacket Process referenced in function _try_decrypt foo.dll : fatal error LNK1120: 1 unresolved externalsCurrently, for some reason, even with all the includes added, there doesn&#39;t seem to be any linking occuring to airpdcap.c, where the definition and declaration for AirPDcapPacketProcess are.
#include &amp;lt;stdio.h&amp;gt; #include &amp;lt;stdlib.h&amp;gt; #include &amp;lt;string.h&amp;gt; #include &amp;lt;glib.h&amp;gt; #include &amp;lt;epan/emem.h&amp;gt; #include &amp;lt;epan/packet.h&amp;gt; #include &amp;lt;epan/dissectors/packet-tcp.</description>
    </item>
    
    <item>
      <title>reassembled tcp bytes cannot be displayed</title>
      <link>/questions/12298/reassembled-tcp-bytes-cannot-be-displayed/</link>
      <pubDate>Thu, 28 Jun 2012 20:41:00 +0000</pubDate>
      
      <guid>/questions/12298/reassembled-tcp-bytes-cannot-be-displayed/</guid>
      <description>reassembled tcp bytes cannot be displayed  0 Running version 1.8.0. When Wireshark opens a captured file, the reassembled tcp bytes cannot be displayed in the Packet Bytes Pane, and the corresponding packet bytes cannot be displayed either.
How can I fix it?
UPDATE:
reassembly tcpasked 28 Jun &#39;12, 20:41
mildblues
21●2●3●6
accept rate: 0%
 edited 30 Jun &#39;12, 03:48 
helloworld
3.1k●4●20●41
please post a screenshot.
(29 Jun &#39;12, 02:14) Kurt Knochner ♦did you try to re-install and delete the &#34;</description>
    </item>
    
    <item>
      <title>text2pcap issue</title>
      <link>/questions/12302/text2pcap-issue/</link>
      <pubDate>Fri, 29 Jun 2012 01:58:00 +0000</pubDate>
      
      <guid>/questions/12302/text2pcap-issue/</guid>
      <description>text2pcap issue  1 How to convert below hexdump into readable pcap format
c364f21d7e098003101b0d120600710419895812049733070b1207001204198915 9309024462424804e95404eb6b1e281c060700118605010101a011600f80020780 a109060704000001000e036c1aa1180201000201383010800804142341703973f8 020104830100&amp;#39;Htext2pcapasked 29 Jun &#39;12, 01:58
rks2k122
16●1●1●2
accept rate: 0%
 edited 29 Jun &#39;12, 02:09 
Kurt Knochner ♦
24.8k●10●39●237
  
One Answer:
  
1that format is not supported by text2pcap.
http://www.wireshark.org/docs/wsug_html_chunked/AppToolstext2pcap.html
Text2pcap understands a hexdump of the form generated by od -Ax -tx1 -v. In other words, each byte is individually displayed and surrounded with a space.</description>
    </item>
    
    <item>
      <title>How to add New vendor definition in wireshark?</title>
      <link>/questions/12306/how-to-add-new-vendor-definition-in-wireshark/</link>
      <pubDate>Fri, 29 Jun 2012 03:04:00 +0000</pubDate>
      
      <guid>/questions/12306/how-to-add-new-vendor-definition-in-wireshark/</guid>
      <description>How to add New vendor definition in wireshark?  0 hi, can anyone tell me how to add new vendor-id &amp;amp; its attributes definition in wireshark?
I have wireshark Version 1.6.5 (SVN Rev 40429 from /trunk-1.6) installed on my laptop with windows7 (64-bit edition).
I tried to add the vendor Id for Starent in dictionary.xml and also copied the starent.xml under the diameter folder in Program Files&amp;gt;&amp;gt;wireshark; but it seems either I have missed out somewhere or added wrong definition.</description>
    </item>
    
    <item>
      <title>No packets seen under Windows 7 64 bit</title>
      <link>/questions/12309/no-packets-seen-under-windows-7-64-bit/</link>
      <pubDate>Fri, 29 Jun 2012 06:01:00 +0000</pubDate>
      
      <guid>/questions/12309/no-packets-seen-under-windows-7-64-bit/</guid>
      <description>No packets seen under Windows 7 64 bit  0 I use Windows 7 64 bit and Wireshark Version 1.8.0 (SVN Rev 43431 from /trunk-1.8). WinPcap : Version 4.1.2 I work with Internet dsl network connection. When I open the Capture Interface window that lets me see all the interface I see tens of packets on a specific interface. When I capture the proper interface by the &#34;Start&#34; botton I get (no filter) just one frame.</description>
    </item>
    
    <item>
      <title>RTP player not able to play</title>
      <link>/questions/12325/rtp-player-not-able-to-play/</link>
      <pubDate>Fri, 29 Jun 2012 09:18:00 +0000</pubDate>
      
      <guid>/questions/12325/rtp-player-not-able-to-play/</guid>
      <description>RTP player not able to play  0 How can i play rtp packet with payload type dynamic 96? I googled the feature but first time only i can play the packet. After second time there were some bug console window and it shows &#34;WARN Dissector bug, Protoclo H264 in packet 226: packet-h264.c:521: failed assertion &#34;DISECTOR_ASSERT_NOT_REACHED&#34;&#34;
rtpasked 29 Jun &#39;12, 09:18
Mamun
1●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>pcsync-https rst</title>
      <link>/questions/12335/pcsync-https-rst/</link>
      <pubDate>Fri, 29 Jun 2012 13:34:00 +0000</pubDate>
      
      <guid>/questions/12335/pcsync-https-rst/</guid>
      <description>pcsync-https rst  0 Hi Team, I am getting a pcsync-https RST from server to server TCP connections. Do anybody know why this happens?
rst pcsync-httpsasked 29 Jun &#39;12, 13:34
Sajan
1●1●1●1
accept rate: 0%
without a full capture file, it&#39;s impossible to give a meaningfull answer. Please post a sample capture at cloudshark.org.
HINT: You cannot delete an anonymous upload at cloudshark.org!
(03 Jul &#39;12, 13:41) Kurt Knochner ♦   </description>
    </item>
    
    <item>
      <title>tshark VoIP call listing</title>
      <link>/questions/12344/tshark-voip-call-listing/</link>
      <pubDate>Sat, 30 Jun 2012 02:04:00 +0000</pubDate>
      
      <guid>/questions/12344/tshark-voip-call-listing/</guid>
      <description>tshark VoIP call listing  0 Dears,
On wireshark you can display the voIP calls with the start time the stop time the number the ip addresses. How can we manage to do that ???? I use Tshak to filer sip I just got phone numbers and ip addresses. How can I get the start time an the stop time. Thank you for your help
Best Regards
Mouhamet
duration start tshark voip timeasked 30 Jun &#39;12, 02:04</description>
    </item>
    
    <item>
      <title>How to calculate the total network traffic pass though a Gigabit NIC with high precision?</title>
      <link>/questions/12348/how-to-calculate-the-total-network-traffic-pass-though-a-gigabit-nic-with-high-precision/</link>
      <pubDate>Sat, 30 Jun 2012 09:25:00 +0000</pubDate>
      
      <guid>/questions/12348/how-to-calculate-the-total-network-traffic-pass-though-a-gigabit-nic-with-high-precision/</guid>
      <description>How to calculate the total network traffic pass though a Gigabit NIC with high precision?  0 Hi,
I am using a Windows PC. I would like to calculate the total network traffic pass though a Gigabit NIC between time t1 and t2. In my case, accuracy is very important. I don&#39;t want to miss any packet. And the network speed during t1-t2 is &amp;gt;900Mbps.
Is it possible to use tshark/tcpdump/dumpcap/Winpcap to calculate the total network traffic for a Gigabit NIC with high accuracy?</description>
    </item>
    
    <item>
      <title>capture from other device</title>
      <link>/questions/12351/capture-from-other-device/</link>
      <pubDate>Sat, 30 Jun 2012 23:34:00 +0000</pubDate>
      
      <guid>/questions/12351/capture-from-other-device/</guid>
      <description>capture from other device  0 Hi I have Siemens HiPath PBX connected to my LAN. I want to capture all the traffic going in and out from that PBX on my computer.
Can I use wireshark to capture the packets?
SNMP is enables on Siemens HiPath system, is that useful for capture full traffic? I cannot install anything on Siemens HiPath as its not computer but IP-PBX hardware. please let me know what are the ways to capture the packets from it.</description>
    </item>
    
    <item>
      <title>[Lua] bytes consumed during dissection</title>
      <link>/questions/12358/lua-bytes-consumed-during-dissection/</link>
      <pubDate>Sun, 01 Jul 2012 12:22:00 +0000</pubDate>
      
      <guid>/questions/12358/lua-bytes-consumed-during-dissection/</guid>
      <description>[Lua] bytes consumed during dissection  0 Hi,
I&#39;m new to Lua dissector and experimenting with Lua. I need some help understand how can a sub-protocol dissector return bytes consumed during its decoding to its caller dissector.
Example:
MYPROTO = Proto (&amp;quot;myproto&amp;quot;, &amp;quot;My Simple Protocol&amp;quot;) local myproto_dt = DissectorTable.new (&amp;quot;myproto.msgid&amp;quot;, &amp;quot;MYPROTO&amp;quot;) local f = MYPROTO.fields f.var1 = ProtoField.uint16 (&amp;quot;myproto.var1&amp;quot;, &amp;quot;var1&amp;quot;)
f.msgid = ProtoField.uint16 (&amp;quot;myproto.msgid&amp;quot;, &amp;quot;Message Id&amp;quot;) f.var2 = ProtoField.uint16 (&amp;quot;myproto.var1&amp;quot;, &amp;quot;var1&amp;quot;)</description>
    </item>
    
    <item>
      <title>Mapping a well known protocol to a custom port</title>
      <link>/questions/12360/mapping-a-well-known-protocol-to-a-custom-port/</link>
      <pubDate>Sun, 01 Jul 2012 14:52:00 +0000</pubDate>
      
      <guid>/questions/12360/mapping-a-well-known-protocol-to-a-custom-port/</guid>
      <description>Mapping a well known protocol to a custom port  1 I have an http server that listens on port XXXX where XXXX is not 80 or 8080. Wireshark does not recognize the traffic to the server as http. What can I do to map port XXXX to http.
http mapping portasked 01 Jul &#39;12, 14:52
dheerajrs
16●1●1●2
accept rate: 0%
Maybe a patch is required to automatically do this?</description>
    </item>
    
    <item>
      <title>ARP Detection Period</title>
      <link>/questions/12364/arp-detection-period/</link>
      <pubDate>Mon, 02 Jul 2012 03:28:00 +0000</pubDate>
      
      <guid>/questions/12364/arp-detection-period/</guid>
      <description>ARP Detection Period  0 Can anyone tell me what the &#34;Detection period (in ms):&#34; setting means for the ARP protocol in the capture preferences? I&#39;m a little confused by it. We&#39;re seeing some funny things with ARP going on and I wonder if the default settings mean we might be missing something.
Thanks for any help.
arpasked 02 Jul &#39;12, 03:28
jmccabe
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>SSL decryption help?</title>
      <link>/questions/12365/ssl-decryption-help/</link>
      <pubDate>Mon, 02 Jul 2012 03:41:00 +0000</pubDate>
      
      <guid>/questions/12365/ssl-decryption-help/</guid>
      <description>SSL decryption help?  0 I&#39;m having problems making SSL decryption work.
I&#39;m running wireshark 1.6.2
Compiled (64-bit) with GTK+ 2.24.6, with GLib 2.29.92, with libpcap 1.1.1, with libz 1.2.3.4, with POSIX capabilities (Linux), without libpcre, with SMI 0.4.8, with c-ares 1.7.4, with Lua 5.1, without Python, with GnuTLS 2.10.5, with Gcrypt 1.5.0, with MIT Kerberos, with GeoIP, with PortAudio V19-devel (built Jul 27 2011 11:52:20), without AirPcap. Running on Linux 3.</description>
    </item>
    
    <item>
      <title>filter on tshark</title>
      <link>/questions/12370/filter-on-tshark/</link>
      <pubDate>Mon, 02 Jul 2012 06:39:00 +0000</pubDate>
      
      <guid>/questions/12370/filter-on-tshark/</guid>
      <description>filter on tshark  0 hi i have a folder full of pcap files i want that each pcapfile extract information with filter Tcp.flags.syn==1 &amp;amp;&amp;amp; tcp.flags.ack==1 tcp.flags.reset==1 icmp udp and !icmp and then find no of packets average per second and store in a file like that eg:
 file Rst syn-ack icmp udp! icmp totalpcap file 1 1309.08 107.683 19.7167 .14444 1436.62plshelpasked 02 Jul &#39;12, 06:39
honey
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark plugin and GPL license</title>
      <link>/questions/12371/wireshark-plugin-and-gpl-license/</link>
      <pubDate>Mon, 02 Jul 2012 07:16:00 +0000</pubDate>
      
      <guid>/questions/12371/wireshark-plugin-and-gpl-license/</guid>
      <description>Wireshark plugin and GPL license  0 Hi, I&#39;m expecting to work with Wireshark software in a commercial projet environment. Wireshark is licensed under the GNU General Public License. But what about the plugin source code I develop for a well-known protocol but specific for our application ? The source code of Wireshark software is not modified and development of the plug-in is not, in my mind, a &#34;derivative work&#34; according to GPL definition.</description>
    </item>
    
    <item>
      <title>What is the difference in LIBGDK between Wireshark 1.6.8 and 1.8.0?</title>
      <link>/questions/12381/what-is-the-difference-in-libgdk-between-wireshark-168-and-180/</link>
      <pubDate>Mon, 02 Jul 2012 19:31:00 +0000</pubDate>
      
      <guid>/questions/12381/what-is-the-difference-in-libgdk-between-wireshark-168-and-180/</guid>
      <description>What is the difference in LIBGDK between Wireshark 1.6.8 and 1.8.0?  0 What is the difference in libgdk-win32-2.0-0.dll between Wireshark 1.6.8 and 1.8.0? Both libraries have the same version 2.24.10.0, but they have different sizes from each other.
Wireshark 1.8.0: 680,068 bytesWireshark 1.6.8: 932,373 bytesIn my environment, 1.8.0 has a little problem, but It works fine when I replace the dll which is included in Wireshark 1.6.8.
I&#39;ll try to compile GTK+ myself to see if I can determine the difference.</description>
    </item>
    
    <item>
      <title>PCAPNG: timestamps get changed when tshark reads and saves a pcang file</title>
      <link>/questions/12382/pcapng-timestamps-get-changed-when-tshark-reads-and-saves-a-pcang-file/</link>
      <pubDate>Mon, 02 Jul 2012 20:54:00 +0000</pubDate>
      
      <guid>/questions/12382/pcapng-timestamps-get-changed-when-tshark-reads-and-saves-a-pcang-file/</guid>
      <description>PCAPNG: timestamps get changed when tshark reads and saves a pcang file  0 When you try to read a pcapng file and save it to a new pcapng file, the timestamp was trimmed down! The decimal place is moved to the front and the last digit is rounded off. The timestamp is no longer correct. Could anyone please help how to correct it? Thanks a lot!
-------------------------------------------------- $ tshark -r capture.</description>
    </item>
    
    <item>
      <title>Can I build a sub-dissector for a close source dissector?</title>
      <link>/questions/12384/can-i-build-a-sub-dissector-for-a-close-source-dissector/</link>
      <pubDate>Mon, 02 Jul 2012 22:40:00 +0000</pubDate>
      
      <guid>/questions/12384/can-i-build-a-sub-dissector-for-a-close-source-dissector/</guid>
      <description>Can I build a sub-dissector for a close source dissector?  0 I have a plugin for a protocol which encapsulates another protocol (i.e. ASN.1 based LTE-RRC). Unfortunately I don&#39;t have the source code for this plugin. Do I still have the chance to develop a plugin to decode the encapsulated protocol? And I also noticed LTE-RRC is already supported by wireshark, how to request wireshark to decode a filed of a protocol as LTE-RRC?</description>
    </item>
    
    <item>
      <title>get the payload data in ascii only not in hex using tshark</title>
      <link>/questions/12385/get-the-payload-data-in-ascii-only-not-in-hex-using-tshark/</link>
      <pubDate>Tue, 03 Jul 2012 00:29:00 +0000</pubDate>
      
      <guid>/questions/12385/get-the-payload-data-in-ascii-only-not-in-hex-using-tshark/</guid>
      <description>get the payload data in ascii only not in hex using tshark  0 Hi, I captured some traffic on my linux, and l want to be able using tshark to get the data in the ascii format with out the hex format. is there some flag i can use for that? (i only found -x which gives both ascii and hex)
thanks
ascii tsharkasked 03 Jul &#39;12, 00:29
silvik</description>
    </item>
    
    <item>
      <title>Could you give me a *.pcap that have protocols(dct2000:atm:fp:MAC:RLC:RRC.)？</title>
      <link>/questions/12387/could-you-give-me-a-pcap-that-have-protocolsdct2000atmfpmacrlcrrc/</link>
      <pubDate>Tue, 03 Jul 2012 01:08:00 +0000</pubDate>
      
      <guid>/questions/12387/could-you-give-me-a-pcap-that-have-protocolsdct2000atmfpmacrlcrrc/</guid>
      <description>Could you give me a *.pcap that have protocols(dct2000:atm:fp:MAC:RLC:RRC.)？  0 Could you give me a *.pcap that have these protocols(dct2000:atm:fp:MAC:RLC:RRC) in？ Protocols in frame: dct2000:atm:fp:MAC:RLC:RRC.
fp dct2000 rlcasked 03 Jul &#39;12, 01:08
smilezuzu
20●32●32●37
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>could you tell me how to dissect fp over udp？</title>
      <link>/questions/12388/could-you-tell-me-how-to-dissect-fp-over-udp/</link>
      <pubDate>Tue, 03 Jul 2012 01:11:00 +0000</pubDate>
      
      <guid>/questions/12388/could-you-tell-me-how-to-dissect-fp-over-udp/</guid>
      <description>could you tell me how to dissect fp over udp？  1 could you tell me how to dissect fp over udp？ Gr.
fp over udpasked 03 Jul &#39;12, 01:11
smilezuzu
20●32●32●37
accept rate: 0%
  
One Answer:
  
1You can&#39;t dissect FP over UDP and the higer layers without prior knowledge of the content/Configuration hence the FP dissector requires a &#34;per-packet&#34; structure to be filed in in order to do the dissection.</description>
    </item>
    
    <item>
      <title>Time delayfrom ACK to HTTP GET</title>
      <link>/questions/12395/time-delayfrom-ack-to-http-get/</link>
      <pubDate>Tue, 03 Jul 2012 07:02:00 +0000</pubDate>
      
      <guid>/questions/12395/time-delayfrom-ack-to-http-get/</guid>
      <description>Time delayfrom ACK to HTTP GET  0 Hi, We&#39;re trying to trouble shoot a recent change in our load test results. A full second of time has been added to each request. Using Wireshark to look at a packet capture from the web server, we saw the delay coming from the server/requester side.
What appears to be happening if the SYN, SYN/ACK, ACK conversation finishes in basically 0 seconds. The load server&#39;s GET request waits almost a full second before it&#39;s sent.</description>
    </item>
    
    <item>
      <title>What options do I use to never lose data?</title>
      <link>/questions/12402/what-options-do-i-use-to-never-lose-data/</link>
      <pubDate>Tue, 03 Jul 2012 09:02:00 +0000</pubDate>
      
      <guid>/questions/12402/what-options-do-i-use-to-never-lose-data/</guid>
      <description>What options do I use to never lose data?  0 What options do I use to never lose data?
I do not want capture files to ever be overwritten or discarded.
I do not want capturing to ever stop.
great ghestsurasked 03 Jul &#39;12, 09:02
tompdiaz
1●1●1●1
accept rate: 0%
  
One Answer:
  
0You can use dumpcap with a very large number of ring buffer files.</description>
    </item>
    
    <item>
      <title>HTTP/1.1 401 Unauthorized&amp;#92;r&amp;#92;n</title>
      <link>/questions/12405/http11-401-unauthorizedrn/</link>
      <pubDate>Tue, 03 Jul 2012 09:36:00 +0000</pubDate>
      
      <guid>/questions/12405/http11-401-unauthorizedrn/</guid>
      <description>HTTP/1.1 401 Unauthorized\r\n  0 How do I correct these errors?
httpasked 03 Jul &#39;12, 09:36
donnagAFFCU
1●1●1●1
accept rate: 0%
  
One Answer:
  
0How exactly is wireshark in error?
answered 03 Jul &#39;12, 09:41
SYN-bit ♦♦
17.1k●9●57●245
accept rate: 20%
Wireshark is not in error. I am getting this error from the PC I am running a capture on and was wondering how to correct it.</description>
    </item>
    
    <item>
      <title>Raw packets analysis</title>
      <link>/questions/12420/raw-packets-analysis/</link>
      <pubDate>Tue, 03 Jul 2012 12:13:00 +0000</pubDate>
      
      <guid>/questions/12420/raw-packets-analysis/</guid>
      <description>Raw packets analysis  0 I am sending packets using the UDP protocol and raw sockets. i want to manually build the ip header which I want to transmit over wlan0 and capture these packets using wireshark so that I can analyse the contents that I have received. But for some reason, I am not able to capture these packets using wireshark. Do you need to write an explicit receiver code on the client side to capture these packets or can can wireshark capture them automatically?</description>
    </item>
    
    <item>
      <title>SSID Displayed in Column</title>
      <link>/questions/12423/ssid-displayed-in-column/</link>
      <pubDate>Tue, 03 Jul 2012 14:18:00 +0000</pubDate>
      
      <guid>/questions/12423/ssid-displayed-in-column/</guid>
      <description>SSID Displayed in Column  0 Hi. I&#39;m capturing packet data using a AirPcap NX and cannot get the SSID to be displayed in the column. I go to the preferences, select columns, select add and try to locate the SSID field type. I cannot find this field type in the pull down menu. Are there other options to get the SSID field type?
Thanks
Martin
column ssidasked 03 Jul &#39;12, 14:18</description>
    </item>
    
    <item>
      <title>Capturing and decoding http data from 802.11 packets</title>
      <link>/questions/12427/capturing-and-decoding-http-data-from-80211-packets/</link>
      <pubDate>Tue, 03 Jul 2012 18:32:00 +0000</pubDate>
      
      <guid>/questions/12427/capturing-and-decoding-http-data-from-80211-packets/</guid>
      <description>Capturing and decoding http data from 802.11 packets  0 I&#39;m trying to capture http packets through Wireshark in monitor mode started by airmon-ng, bonded to the specific channel the desired SSID is broadcasting. It&#39;s an open wireless network (no encryption), so I thought it would be easy to get complete HTTP packets after decoding. The problem is all the 802.11 packets captured by Wireshark contain no data at all. They are described as Beacon Frames and contain nothing more than information about the adapter.</description>
    </item>
    
    <item>
      <title>how to add data length column in wireshark display or plot payload length vs packet no</title>
      <link>/questions/12431/how-to-add-data-length-column-in-wireshark-display-or-plot-payload-length-vs-packet-no/</link>
      <pubDate>Tue, 03 Jul 2012 23:32:00 +0000</pubDate>
      
      <guid>/questions/12431/how-to-add-data-length-column-in-wireshark-display-or-plot-payload-length-vs-packet-no/</guid>
      <description>how to add data length column in wireshark display or plot payload length vs packet no  0 if i open any pcap in wireshark, it will have several columns to display the information like src/dest ip &amp;amp; port no&#39;s, prot, info etc for each packet. i want one more column to be added which displays the data length field. i searched for this field but rather i could only find &#34;</description>
    </item>
    
    <item>
      <title>Wireshark AMQP Plugin</title>
      <link>/questions/12438/wireshark-amqp-plugin/</link>
      <pubDate>Wed, 04 Jul 2012 05:34:00 +0000</pubDate>
      
      <guid>/questions/12438/wireshark-amqp-plugin/</guid>
      <description>Wireshark AMQP Plugin  0 Hi How do you install and make use of the AMQP plugin (or dissector) for Linux? I am running a Redhat 5.5 system, have Wireshark v1.0.8 installed but do not know how to get the AMQP plugin online?
Can you help please? I have searched for hours for online docs etc. but have come up with nothing :(
Many thanks, any help is appreciated.
Brgds, David</description>
    </item>
    
    <item>
      <title>delay in TCP</title>
      <link>/questions/12442/delay-in-tcp/</link>
      <pubDate>Wed, 04 Jul 2012 08:37:00 +0000</pubDate>
      
      <guid>/questions/12442/delay-in-tcp/</guid>
      <description>delay in TCP  0 Hi!!
I am new to wireshark and I am trying to plot and measure the delay of an end to end tcp packet, that is, I would like to find out how long it takes a tcp packet transmitted from a node to be received from the another node.
Thanks!!!
rocioasked 04 Jul &#39;12, 08:37
Rocio
1●2●2●3
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>There are no interfaces on which a capture can be done</title>
      <link>/questions/12448/there-are-no-interfaces-on-which-a-capture-can-be-done/</link>
      <pubDate>Wed, 04 Jul 2012 18:52:00 +0000</pubDate>
      
      <guid>/questions/12448/there-are-no-interfaces-on-which-a-capture-can-be-done/</guid>
      <description>There are no interfaces on which a capture can be done  0 Hi,
I am using Wireshark. In one Proxy Server, the Live list of the capture interfaces are not showing in Wireshark. On selecting the Interface List there is an error message shows &#34;There are no interfaces on which a capture can be done.&#34;
In order to fix this, i tried:- 1. Restarted the NPF service. It didn&#39;t help me.</description>
    </item>
    
    <item>
      <title>How do I read an *.xml file in wireshark?</title>
      <link>/questions/12451/how-do-i-read-an-xml-file-in-wireshark/</link>
      <pubDate>Wed, 04 Jul 2012 23:40:00 +0000</pubDate>
      
      <guid>/questions/12451/how-do-i-read-an-xml-file-in-wireshark/</guid>
      <description>How do I read an *.xml file in wireshark?  0 I&#39;m trying to dissect FP over UDP, but this process needs some extra information. So, I added an *.xml to save the information, but I don&#39;t know how to read an *.xml file in Wireshark. How can I accomplish this?
xmlasked 04 Jul &#39;12, 23:40
smilezuzu
20●32●32●37
accept rate: 0%
 edited 07 Jul &#39;12, 22:29 
helloworld
3.1k●4●20●41</description>
    </item>
    
    <item>
      <title>Where are the capture-filter options in Wireshark 1.8.0?</title>
      <link>/questions/12452/where-are-the-capture-filter-options-in-wireshark-180/</link>
      <pubDate>Thu, 05 Jul 2012 03:17:00 +0000</pubDate>
      
      <guid>/questions/12452/where-are-the-capture-filter-options-in-wireshark-180/</guid>
      <description>Where are the capture-filter options in Wireshark 1.8.0?  2 1I just installed 1.8.0, and the capture filter is missing. I checked this on a Windows 7 and a Windows XP PC. Is this a bug?
gui capture-filter capture-setupasked 05 Jul &#39;12, 03:17
meneerB
31●1●2●5
accept rate: 0%
 edited 07 Jul &#39;12, 22:30 
helloworld
3.1k●4●20●41
  
2 Answers:
  
7In the interface list: scroll to the right and you will see a column called &#34;</description>
    </item>
    
    <item>
      <title>wireshark says this packet is malformed but our engineers agree it is ok</title>
      <link>/questions/12454/wireshark-says-this-packet-is-malformed-but-our-engineers-agree-it-is-ok/</link>
      <pubDate>Thu, 05 Jul 2012 03:47:00 +0000</pubDate>
      
      <guid>/questions/12454/wireshark-says-this-packet-is-malformed-but-our-engineers-agree-it-is-ok/</guid>
      <description>wireshark says this packet is malformed but our engineers agree it is ok  0 wireshark says this packet is malformed but our engineers agree it is ok so what do I do ? Should I raise a bug ?
Packet 1833 - look at ptp section, I&#39;ve highlighted the lengthField (you can see this in the bytes at the end as well). Apparently it is malformed after there - however when we look at the 1588 ptp spec it all seems to be ok.</description>
    </item>
    
    <item>
      <title>What is normal ARP percentage in the Protocol Hierarchy Statistics?</title>
      <link>/questions/12472/what-is-normal-arp-percentage-in-the-protocol-hierarchy-statistics/</link>
      <pubDate>Thu, 05 Jul 2012 14:59:00 +0000</pubDate>
      
      <guid>/questions/12472/what-is-normal-arp-percentage-in-the-protocol-hierarchy-statistics/</guid>
      <description>What is normal ARP percentage in the Protocol Hierarchy Statistics?  0 I have captured around 30,000 packets and am looking at the ARP statistics and noticed that the ARP traffic seems a little high. What percentage should it be?
Thanks.
arp statisticsasked 05 Jul &#39;12, 14:59
Gump3rs
1●1●1●1
accept rate: 0%
what exactly is &#34;a little high&#34; and how many devices are there on the network?
(06 Jul &#39;12, 01:01) Kurt Knochner ♦</description>
    </item>
    
    <item>
      <title>Why am I seeing &amp;quot;TCP Window Full&amp;quot; on upload?</title>
      <link>/questions/12474/why-am-i-seeing-tcp-window-full-on-upload/</link>
      <pubDate>Thu, 05 Jul 2012 16:57:00 +0000</pubDate>
      
      <guid>/questions/12474/why-am-i-seeing-tcp-window-full-on-upload/</guid>
      <description>Why am I seeing &amp;ldquo;TCP Window Full&amp;rdquo; on upload?  0 What would be some of the reasons that I am seeing TCP Window Full flag in Wireshark? I am performing an upload to my server, and the flag is seen on the packets that the user is sending to the server.
tcpasked 05 Jul &#39;12, 16:57
shpakster
1●1●1●1
accept rate: 0%
 edited 07 Jul &#39;12, 22:20 
helloworld</description>
    </item>
    
    <item>
      <title>Damaged capture file</title>
      <link>/questions/12478/damaged-capture-file/</link>
      <pubDate>Fri, 06 Jul 2012 01:48:00 +0000</pubDate>
      
      <guid>/questions/12478/damaged-capture-file/</guid>
      <description>Damaged capture file  0 I was trying to capture the GNS3 serial traffic with Wireshark (ver 1.6.5). But every time the same error message is showing up when i tried to open the cap file. The error message is &#34;The capture file appears to be damaged or corrupt (pcap: File has 67109120-bye packet, bigger than maximum of 65535.). Just wondering how is this possible? cap file is only 10 KB size?</description>
    </item>
    
    <item>
      <title>Why are FTP codes 150 and 226 in the same packet?</title>
      <link>/questions/12483/why-are-ftp-codes-150-and-226-in-the-same-packet/</link>
      <pubDate>Fri, 06 Jul 2012 05:03:00 +0000</pubDate>
      
      <guid>/questions/12483/why-are-ftp-codes-150-and-226-in-the-same-packet/</guid>
      <description>Why are FTP codes 150 and 226 in the same packet?  0 In Wireshark traces, I can find a packet which has both 150 and 226 FTP codes. The server is programmed to handle 150 and 226 codes in different packets: the former followed by latter. If both codes are found in a single packet, the server gets confused and skips the data transfer.
The packet flow is:
Request: RETR[TCP Retransmission] Request: RETR[TCP previous segment lost][TCP Retransmission] Response: 150 .</description>
    </item>
    
    <item>
      <title>Why is Wireshark not detecting my wireless cards?</title>
      <link>/questions/12489/why-is-wireshark-not-detecting-my-wireless-cards/</link>
      <pubDate>Fri, 06 Jul 2012 13:11:00 +0000</pubDate>
      
      <guid>/questions/12489/why-is-wireshark-not-detecting-my-wireless-cards/</guid>
      <description>Why is Wireshark not detecting my wireless cards?  0 I&#39;ve downloaded Wireshark on Ubuntu from the Ubuntu Software Centre. There are no interfaces found at all even after I restart the wireless interfaces. What would the problem be? How do I fix it?
interfaces ubuntuasked 06 Jul &#39;12, 13:11
carla123
1●1●1●1
accept rate: 0%
 edited 06 Jul &#39;12, 13:25 
helloworld
3.1k●4●20●41
duplicate: http://ask.wireshark.org/questions/7523/ubuntu-machine-no-interfaces-listed
(06 Jul &#39;12, 13:24) helloworld</description>
    </item>
    
    <item>
      <title>can the wifi service provider access or read my gmail chats using wireshark?</title>
      <link>/questions/12494/can-the-wifi-service-provider-access-or-read-my-gmail-chats-using-wireshark/</link>
      <pubDate>Fri, 06 Jul 2012 21:02:00 +0000</pubDate>
      
      <guid>/questions/12494/can-the-wifi-service-provider-access-or-read-my-gmail-chats-using-wireshark/</guid>
      <description>can the wifi service provider access or read my gmail chats using wireshark?  1 i am connected to the internet in my laptop via wifi connection provided by my company.can the company authorities access and read my gmail chats and mails using wireshark?
wifi wireshark gmailasked 06 Jul &#39;12, 21:02
ammu
16●1●1●4
accept rate: 0%
 edited 06 Jul &#39;12, 22:33 
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark not recognizing port 8888 HTTP traffic as HTTP</title>
      <link>/questions/12497/wireshark-not-recognizing-port-8888-http-traffic-as-http/</link>
      <pubDate>Sat, 07 Jul 2012 05:35:00 +0000</pubDate>
      
      <guid>/questions/12497/wireshark-not-recognizing-port-8888-http-traffic-as-http/</guid>
      <description>Wireshark not recognizing port 8888 HTTP traffic as HTTP  0 Hello,
I can&#39;t capture http localhost traffic under Ubuntu: it does not display anything.
It works with wlan0 but not with loopback 127.0.0.1. I probably missed something but can&#39;t figure out what.
Could someone helps? Thanks
PS: I can see the localhost http traffic under Chromium developer&#39;s tool network tab.
loopback http ubuntuasked 07 Jul &#39;12, 05:35
Grangousier
6●1●1●3</description>
    </item>
    
    <item>
      <title>How do I stop Wireshark 1.8.0rc2 from crashing on file save?</title>
      <link>/questions/12502/how-do-i-stop-wireshark-180rc2-from-crashing-on-file-save/</link>
      <pubDate>Sat, 07 Jul 2012 18:54:00 +0000</pubDate>
      
      <guid>/questions/12502/how-do-i-stop-wireshark-180rc2-from-crashing-on-file-save/</guid>
      <description>How do I stop Wireshark 1.8.0rc2 from crashing on file save?  0 Whenever I try to save a packet to disk or even export a packet, Wireshark crashes immediately. Here&#39;s the log: http://pastebin.com/Cxz0PBBL
What&#39;s the workaround for this problem?
crashasked 07 Jul &#39;12, 18:54
ostar2
1●1●1●1
accept rate: 0%
 edited 08 Jul &#39;12, 13:38 
Guy Harris ♦♦
17.4k●3●35●196
  
2 Answers:
  
0Is any interfering software installed on that machine?</description>
    </item>
    
    <item>
      <title>Cannot decrypt WPA2 despite EAPOL capture</title>
      <link>/questions/12504/cannot-decrypt-wpa2-despite-eapol-capture/</link>
      <pubDate>Sun, 08 Jul 2012 01:50:00 +0000</pubDate>
      
      <guid>/questions/12504/cannot-decrypt-wpa2-despite-eapol-capture/</guid>
      <description>Cannot decrypt WPA2 despite EAPOL capture  0 Hello everyone,
I have spent several hours trying to get this to work without any success, so I would really appreciate your help. So here is the scenario, I have a Macbook pro running Mac OS X Lion connected to my home wireless network secured with WPA2. I have Wireshark running on this computer and want to capture and decrypt the traffic. I have specified the passphrase and the network SSID in IEEE 802.</description>
    </item>
    
    <item>
      <title>Questions about &amp;quot;TCP Stream Graph&amp;quot;</title>
      <link>/questions/12520/questions-about-tcp-stream-graph/</link>
      <pubDate>Mon, 09 Jul 2012 02:08:00 +0000</pubDate>
      
      <guid>/questions/12520/questions-about-tcp-stream-graph/</guid>
      <description>Questions about &amp;ldquo;TCP Stream Graph&amp;rdquo;  0 Hi all!!
Please, see attached graphs. 1. How to zoom on the graphs? I haven&#39;t got middle mouse button, then I used the &#39;+&#39; and &#39;-&#39; keys to zoom in and out, but I get nothing. 2. How to change the values of X and Y axes on the graphs to values more appropriate for me? Please, see Time/Sequence Graph. 3. Why do I get horizontal lines on the RTT graph?</description>
    </item>
    
    <item>
      <title>rpcap support in Wireshark 1.8</title>
      <link>/questions/12526/rpcap-support-in-wireshark-18/</link>
      <pubDate>Mon, 09 Jul 2012 06:26:00 +0000</pubDate>
      
      <guid>/questions/12526/rpcap-support-in-wireshark-18/</guid>
      <description>rpcap support in Wireshark 1.8  1 In Wireshark 1.6.8 in the capture options I was able to replace the selection of a local interface into: rpcap://[ip-address]/[interface]
In version 1.8 this isn&#39;t possible anymore. Please could you explain how I need to make a pcap of a remote machine in version 1.8.
Best regards, Theo
rpcap 1.8asked 09 Jul &#39;12, 06:26
Theo
16●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>how many remote destination available?</title>
      <link>/questions/12527/how-many-remote-destination-available/</link>
      <pubDate>Mon, 09 Jul 2012 06:46:00 +0000</pubDate>
      
      <guid>/questions/12527/how-many-remote-destination-available/</guid>
      <description>how many remote destination available?  0 Hi Everybody
How many remote destination will be available if I want to get reports from a PC ?
Regards
remote-monitoringasked 09 Jul &#39;12, 06:46
mm23
1●2●2●2
accept rate: 0%
I&#39;m not sure what you are looking for. Is the question about the max. number of remote capture devices that can feed captured packets to Wireshark in parallel?
(09 Jul &#39;12, 11:58) Kurt Knochner ♦Dear Kurt,</description>
    </item>
    
    <item>
      <title>Is there a way to export the full payload information along with the full summary details to a csv file?</title>
      <link>/questions/12529/is-there-a-way-to-export-the-full-payload-information-along-with-the-full-summary-details-to-a-csv-file/</link>
      <pubDate>Mon, 09 Jul 2012 08:14:00 +0000</pubDate>
      
      <guid>/questions/12529/is-there-a-way-to-export-the-full-payload-information-along-with-the-full-summary-details-to-a-csv-file/</guid>
      <description>Is there a way to export the full payload information along with the full summary details to a csv file?  1 Hi,
I am trying to export the tshark pcapng file to a csv file,I am only able to export the summary details to the CSV.Is there a way to export the full packet payload information with the summary.I am able to get the full packet details when i am exporting it as C array.</description>
    </item>
    
    <item>
      <title>Wireshark does not detect any network interfaces on OS X 10.7 Lion?</title>
      <link>/questions/12531/wireshark-does-not-detect-any-network-interfaces-on-os-x-107-lion/</link>
      <pubDate>Mon, 09 Jul 2012 09:26:00 +0000</pubDate>
      
      <guid>/questions/12531/wireshark-does-not-detect-any-network-interfaces-on-os-x-107-lion/</guid>
      <description>Wireshark does not detect any network interfaces on OS X 10.7 Lion?  0 How do I make Wireshark to work on OS X 10.7 running on a 2011 MBP?
The application started but it complains that it cannot detect any network interfaces and I do want to monitor WiFi in promiscuous mode.
osx lion macasked 09 Jul &#39;12, 09:26
sorin
6●3●3●5
accept rate: 0%
Recommend you try the &#34;lion-native wireshark&#34;</description>
    </item>
    
    <item>
      <title>Understanding wireshark</title>
      <link>/questions/12534/understanding-wireshark/</link>
      <pubDate>Mon, 09 Jul 2012 12:42:00 +0000</pubDate>
      
      <guid>/questions/12534/understanding-wireshark/</guid>
      <description>Understanding wireshark  0 I am new to Wireshark and I am needing help with navigating through it. How do I lfind the IP and MAC address of the suspect system, the DNS server, the default gateway, and the DHCP server. How do I find the vendor of the suspect network card. How do I extract a web page and a graphic file from wire shark. How do I find the computer name of the suspect system.</description>
    </item>
    
    <item>
      <title>10Gbps&#43; stream to disk capture appliance</title>
      <link>/questions/12535/10gbps-stream-to-disk-capture-appliance/</link>
      <pubDate>Mon, 09 Jul 2012 13:41:00 +0000</pubDate>
      
      <guid>/questions/12535/10gbps-stream-to-disk-capture-appliance/</guid>
      <description>10Gbps+ stream to disk capture appliance  0 Is it possible to build a 10Gbps+ stream to disk capture appliance using WireShare software?
I already have the necessary hardware, but I haven&#39;t found any packet analysis software (free) capable of a capture with such a large amount of traffic. Does Wireshark include a stream to disk feature for this amount of traffic?
Any help or advice would be appreciated.
capture disk 10g stream analysisasked 09 Jul &#39;12, 13:41</description>
    </item>
    
    <item>
      <title>What is &amp;quot;Use External Network Name Resolver&amp;quot; setting?</title>
      <link>/questions/12542/what-is-use-external-network-name-resolver-setting/</link>
      <pubDate>Mon, 09 Jul 2012 19:53:00 +0000</pubDate>
      
      <guid>/questions/12542/what-is-use-external-network-name-resolver-setting/</guid>
      <description>What is &amp;ldquo;Use External Network Name Resolver&amp;rdquo; setting?  0 I noticed a new setting on the Name Resolution menu of Wireshark 1.9.0 development versions called &#34;Use External Network Name Resolver.&#34; It was enabled by default. What is the purpose of this setting? On my system, enabling this setting seems to result in Wireshark making DNS PTR queries even when View &amp;gt; Name Resolution &amp;gt; Enable for Network Layer is unchecked.</description>
    </item>
    
    <item>
      <title>Wireshark 1.8.0 with ethernet lan tap</title>
      <link>/questions/12548/wireshark-180-with-ethernet-lan-tap/</link>
      <pubDate>Mon, 09 Jul 2012 23:11:00 +0000</pubDate>
      
      <guid>/questions/12548/wireshark-180-with-ethernet-lan-tap/</guid>
      <description>Wireshark 1.8.0 with ethernet lan tap  0 I am using Wireshark 1.8.0 in ubuntu 12.04, and I made my own passive lan tap from enigma curry website I just checked to make sure the connections are good. all of the connections are intact and not loose. The way my setup is I use ethernet port on my laptop, and I use usb 2.0 ethernet adapter. It seem to work on Windows with my lan tap but I am wanting to get it working in ubuntu.</description>
    </item>
    
    <item>
      <title>How to use UAT?</title>
      <link>/questions/12552/how-to-use-uat/</link>
      <pubDate>Tue, 10 Jul 2012 03:26:00 +0000</pubDate>
      
      <guid>/questions/12552/how-to-use-uat/</guid>
      <description>How to use UAT?  0 how to use UAT to put parameter in wireshark? thanks!
fp uatasked 10 Jul &#39;12, 03:26
smilezuzu
20●32●32●37
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How do I exclude own traffic from wireshark when in promiscuous mode?</title>
      <link>/questions/12553/how-do-i-exclude-own-traffic-from-wireshark-when-in-promiscuous-mode/</link>
      <pubDate>Tue, 10 Jul 2012 04:58:00 +0000</pubDate>
      
      <guid>/questions/12553/how-do-i-exclude-own-traffic-from-wireshark-when-in-promiscuous-mode/</guid>
      <description>How do I exclude own traffic from wireshark when in promiscuous mode?  0 How do I exclude own traffic from wireshark when in promiscuous mode?
excludeasked 10 Jul &#39;12, 04:58
sorin
6●3●3●5
accept rate: 0%
  
One Answer:
  
1 Two options:
You could use a filter to exclude anything with ether destination same as your MAC address. Determine the MAC address of your capture card, and set a capture filter: &#34;</description>
    </item>
    
    <item>
      <title>How to I add a wireshark filter to record only HTTP requests and not responses?</title>
      <link>/questions/12554/how-to-i-add-a-wireshark-filter-to-record-only-http-requests-and-not-responses/</link>
      <pubDate>Tue, 10 Jul 2012 05:01:00 +0000</pubDate>
      
      <guid>/questions/12554/how-to-i-add-a-wireshark-filter-to-record-only-http-requests-and-not-responses/</guid>
      <description>How to I add a wireshark filter to record only HTTP requests and not responses?  0 How to I add a filter to record only HTTP requests and not responses?
includeasked 10 Jul &#39;12, 05:01
sorin
6●3●3●5
accept rate: 0%
  
One Answer:
  
0filter to RECORD only HTTP requests
well, that&#39;s not easy. One option would be to use tshark
tshark -i eth0 (or 1,2,3,4.</description>
    </item>
    
    <item>
      <title>Prevent Patch file from getting outdated</title>
      <link>/questions/12559/prevent-patch-file-from-getting-outdated/</link>
      <pubDate>Tue, 10 Jul 2012 07:45:00 +0000</pubDate>
      
      <guid>/questions/12559/prevent-patch-file-from-getting-outdated/</guid>
      <description>Prevent Patch file from getting outdated  0 Hi guys,
I have finished developing(on Ubuntu 12.4) my second dissector for Wireshark as a plugin and made a patch file(.diff). However, when I went to patch the Wireshark source, obtained by &#39;svn co http://anonsvn.wireshark.org/wireshark/trunk/&#39;, the patch failed because the source had been updated to not include one of the plugins it used to and that I have on my main computer(&#34;giop&#34; is the name).</description>
    </item>
    
    <item>
      <title>network card</title>
      <link>/questions/12567/network-card/</link>
      <pubDate>Tue, 10 Jul 2012 11:41:00 +0000</pubDate>
      
      <guid>/questions/12567/network-card/</guid>
      <description>network card  0 Where can I find the vendor of a network card. I can&#39;t seem to find the way to locate it on Wireshark. This is for an intro to Wireshark for a college course.
vendorasked 10 Jul &#39;12, 11:41
jennifer26m
1●3●3●3
accept rate: 0%
 edited 10 Jul &#39;12, 12:41 
Jim Aragon
7.2k●7●33●118
  
One Answer:
  
0Read about MAC addresses here. Pay particular attention to the OUI.</description>
    </item>
    
    <item>
      <title>extract web page</title>
      <link>/questions/12568/extract-web-page/</link>
      <pubDate>Tue, 10 Jul 2012 12:15:00 +0000</pubDate>
      
      <guid>/questions/12568/extract-web-page/</guid>
      <description>extract web page  0 How do you extract a web page and a graphc file from wire shark?
extracttopasked 10 Jul &#39;12, 12:15
jennifer26m
1●3●3●3
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Trace only relevant traffic</title>
      <link>/questions/12576/trace-only-relevant-traffic/</link>
      <pubDate>Tue, 10 Jul 2012 16:30:00 +0000</pubDate>
      
      <guid>/questions/12576/trace-only-relevant-traffic/</guid>
      <description>Trace only relevant traffic  0 Hi,
I am absolutely new to Wireshark but I am asked to trace the complete traffic between to machines (IP addresses are known, but nothing else). How can I do this?
thx a lot
filter traceasked 10 Jul &#39;12, 16:30
palustris
0●1●1●1
accept rate: 0%
 edited 10 Jul &#39;12, 19:53 
Jim Aragon
7.2k●7●33●118
  
One Answer:
  
1First you have to position Wireshark where it can capture the traffic between the two machines.</description>
    </item>
    
    <item>
      <title>Open tshark capture text output in Wireshark 1.8.0</title>
      <link>/questions/12595/open-tshark-capture-text-output-in-wireshark-180/</link>
      <pubDate>Wed, 11 Jul 2012 02:19:00 +0000</pubDate>
      
      <guid>/questions/12595/open-tshark-capture-text-output-in-wireshark-180/</guid>
      <description>Open tshark capture text output in Wireshark 1.8.0  0 I have a tshark capture file capture using the following command:
tshark -i bond0 -t ad &amp;gt; cap.txtHow to open the cap.txt in Wireshark 1.8.0 ?
tsharkasked 11 Jul &#39;12, 02:19
Raptor
1●1●1●2
accept rate: 0%
 edited 11 Jul &#39;12, 02:44 
Kurt Knochner ♦
24.8k●10●39●237
  
One Answer:
  
0That&#39;s just text output. You cannot read that with Wireshark.</description>
    </item>
    
    <item>
      <title>Decrypting F5 Server side SSL Traffic</title>
      <link>/questions/12599/decrypting-f5-server-side-ssl-traffic/</link>
      <pubDate>Wed, 11 Jul 2012 03:15:00 +0000</pubDate>
      
      <guid>/questions/12599/decrypting-f5-server-side-ssl-traffic/</guid>
      <description>Decrypting F5 Server side SSL Traffic  0 Im a beginner in decrypting SSL traffic but im able to decrypt normal client to server SSL traffic. The problem im encountering is when I try to decrypt SSL traffic bridged from an F5 to the Server. I was expecting the F5 to just re-established the connection in the same method as a client to the F5.
All I see are:
TLSv1 Client Hello TLSv1 Server Hello TLSv1 Change Cipher Spec TLSv1 Encrypted Handshake MessageWhat I normally see is:</description>
    </item>
    
    <item>
      <title>File Sets Hotkey</title>
      <link>/questions/12600/file-sets-hotkey/</link>
      <pubDate>Wed, 11 Jul 2012 03:29:00 +0000</pubDate>
      
      <guid>/questions/12600/file-sets-hotkey/</guid>
      <description>File Sets Hotkey  0 Hi,
Is there a hotkey for scrolling trough filesets avoiding to got to File-Filesets evertytime?
Thanks
hotkeyasked 11 Jul &#39;12, 03:29
Ivan
31●2●2●4
accept rate: 0%
  
One Answer:
  
0There is no such hotkey. Please file an enhancement request at bugs.wireshark.org.
Regards
Kurt
answered 11 Jul &#39;12, 06:17
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15% 
     </description>
    </item>
    
    <item>
      <title>Play Xbox 360 and a person takes me out of it. Help!</title>
      <link>/questions/12608/play-xbox-360-and-a-person-takes-me-out-of-it-help/</link>
      <pubDate>Wed, 11 Jul 2012 04:16:00 +0000</pubDate>
      
      <guid>/questions/12608/play-xbox-360-and-a-person-takes-me-out-of-it-help/</guid>
      <description>Play Xbox 360 and a person takes me out of it. Help!  0 I downloaded wireshark because this is a program that analyzes packets and tracks their destination or source. So i play Xbox 360 and 1 guy that hates me got my IP Address and he has a booter system and eveytime he will be booting me out of xbox and will have trouble connecting back. So 1 day i was using the Wireshark program and was live capturing the packets and suddenly was booted from xbox and in the analyzer a red line appeared and after 5 minutes another red line appeared and after that i was back online, so im guessing he booted me off my connection for 5 minutes.</description>
    </item>
    
    <item>
      <title>asn2wrs: how to handle import definitions with the same definition name? Use tags?</title>
      <link>/questions/12619/asn2wrs-how-to-handle-import-definitions-with-the-same-definition-name-use-tags/</link>
      <pubDate>Wed, 11 Jul 2012 05:13:00 +0000</pubDate>
      
      <guid>/questions/12619/asn2wrs-how-to-handle-import-definitions-with-the-same-definition-name-use-tags/</guid>
      <description>asn2wrs: how to handle import definitions with the same definition name? Use tags?  0 Hi, I am trying to create a ASN.1 dissector using asn2wrs. To do so, I need a asn file. The asn protocol requires IMPORTS of definitions from several other asn files. Unfortunately the naming of some definitions is identical. Resulting in a &#39;Duplicate type&#39; error
This problem could be circumvented using tags. eg. filename1.parameters filename2.parameters</description>
    </item>
    
    <item>
      <title>I just installed Wireshark on Win7 on a Thinkpad.  Why is the wireless interface not listed?</title>
      <link>/questions/12635/i-just-installed-wireshark-on-win7-on-a-thinkpad-why-is-the-wireless-interface-not-listed/</link>
      <pubDate>Wed, 11 Jul 2012 08:51:00 +0000</pubDate>
      
      <guid>/questions/12635/i-just-installed-wireshark-on-win7-on-a-thinkpad-why-is-the-wireless-interface-not-listed/</guid>
      <description>I just installed Wireshark on Win7 on a Thinkpad. Why is the wireless interface not listed?  0 I just installed Wireshark on Win7 on a Thinkpad. Why is the wireless interface not listed?
wireless interfaceasked 11 Jul &#39;12, 08:51
daveap
1●1●1●1
accept rate: 0%
  
One Answer:
  
0On Windows, Wireless adaptes show up as &#34;Microsoft&#34;. Please check the IP address of the adapter to identify it.</description>
    </item>
    
    <item>
      <title>Is it possible to Analyze Jitter from the captured pcap file?</title>
      <link>/questions/12637/is-it-possible-to-analyze-jitter-from-the-captured-pcap-file/</link>
      <pubDate>Wed, 11 Jul 2012 12:16:00 +0000</pubDate>
      
      <guid>/questions/12637/is-it-possible-to-analyze-jitter-from-the-captured-pcap-file/</guid>
      <description>Is it possible to Analyze Jitter from the captured pcap file?  0 1Hi All,
I have captured the logs at both ends for a end-to-end Wi-Fi call using two phones. They have mainly SIP and RTP packets. I am getting jitter between 5-15 ms for reverse and forward directions. I have a local router which isn&#39;t connected to LAN.
My question is: Is it possible to analyze jitter and find the possible root cause of why it is occurring?</description>
    </item>
    
    <item>
      <title>Save As Missing Packet Range Option in 1.8.0 version</title>
      <link>/questions/12641/save-as-missing-packet-range-option-in-180-version/</link>
      <pubDate>Wed, 11 Jul 2012 16:59:00 +0000</pubDate>
      
      <guid>/questions/12641/save-as-missing-packet-range-option-in-180-version/</guid>
      <description>Save As Missing Packet Range Option in 1.8.0 version  0 I downloaded the current stable release today and went to save a capture with only the filtered / displayed packets, and this option does not appear in the Save As dialog box.
I downloaded the 64 Bit Windows version (Version 1.8.0 (SVN Rev 43431 from /trunk-1.8)) and while the User&#39;s Guide still shows these options the dialog I am getting only shows options to change folders, file name, or save as type.</description>
    </item>
    
    <item>
      <title>wireshark 1.8 installed on mac os x 10.7 don&amp;#x27;t find &amp;quot;add remote interface&amp;quot;</title>
      <link>/questions/12644/wireshark-18-installed-on-mac-os-x-107-dont-find-add-remote-interface/</link>
      <pubDate>Wed, 11 Jul 2012 23:23:00 +0000</pubDate>
      
      <guid>/questions/12644/wireshark-18-installed-on-mac-os-x-107-dont-find-add-remote-interface/</guid>
      <description>wireshark 1.8 installed on mac os x 10.7 don&amp;rsquo;t find &amp;ldquo;add remote interface&amp;rdquo;  0 lionasked 11 Jul &#39;12, 23:23
bigkun
6●1●1●4
accept rate: 0%
 edited 12 Jul &#39;12, 06:36 
  
One Answer:
  
0 I believe some libpcap functions, needed for remote capturing, are not available on Mac OS X.
See here http://anonsvn.wireshark.org/wireshark/trunk/acinclude.m4
 if test $ac_cv_func_pcap_open = &amp;quot;yes&amp;quot; -a \ $ac_cv_func_pcap_findalldevs_ex = &amp;quot;yes&amp;quot; -a \ $ac_cv_func_pcap_createsrcstr = &amp;quot;yes&amp;quot; ; then AC_DEFINE(HAVE_PCAP_REMOTE, 1, [Define to 1 if you have WinPcap remote capturing support and prefer to use these new API features.</description>
    </item>
    
    <item>
      <title>GIOP filter - tshark</title>
      <link>/questions/12645/giop-filter-tshark/</link>
      <pubDate>Thu, 12 Jul 2012 00:02:00 +0000</pubDate>
      
      <guid>/questions/12645/giop-filter-tshark/</guid>
      <description>GIOP filter - tshark  0 Hi,
im trying to filter all GIOP packets with a filter parameter. I know it works in wireshark by just typing &#34;giop&#34; in the filter - but it wont work when i use it as a parameter?
tshark -i eth0 -f &#34;´ip --.--.--.-- proto giop´&#34; -w /---/---/---/file.log - wont work...
I cant figure out the right syntax for this filter. Can anyone help here?</description>
    </item>
    
    <item>
      <title>Why causes ARP request  a &amp;quot;TCP previous segment lost&amp;quot;?</title>
      <link>/questions/12655/why-causes-arp-request-a-tcp-previous-segment-lost/</link>
      <pubDate>Thu, 12 Jul 2012 05:18:00 +0000</pubDate>
      
      <guid>/questions/12655/why-causes-arp-request-a-tcp-previous-segment-lost/</guid>
      <description>Why causes ARP request a &amp;ldquo;TCP previous segment lost&amp;rdquo;?  1 We have two windows XP pc&#39;s 10.10.10.1 and 10.10.10.2 with a direct connection to each other (So not via a router). These both have a user application running, which continuously exchange information via TCP/IP. When the communication between the 2 pc&#39;s is logged with wireshark, it shows every 10 minutes a ARP request is broadcast to refresh the arp cache.</description>
    </item>
    
    <item>
      <title>How to filter SNMP packets by oid?</title>
      <link>/questions/12657/how-to-filter-snmp-packets-by-oid/</link>
      <pubDate>Thu, 12 Jul 2012 05:28:00 +0000</pubDate>
      
      <guid>/questions/12657/how-to-filter-snmp-packets-by-oid/</guid>
      <description>How to filter SNMP packets by oid?  0 Has this possibility been removed? I think in previous versions it was possible to do the following filter: &#34;snmp.ObjectName == ...&#34; However, this is not supported. Also snmp.value.oid does not support the == operator. What is wrong here?
snmpasked 12 Jul &#39;12, 05:28
gubbanoa
6●1●1●3
accept rate: 0%
  
One Answer:
  
1 snmp.ObjectName may have changed. I can find snmp.</description>
    </item>
    
    <item>
      <title>Where to find documentation of writing an encapsulated file reader</title>
      <link>/questions/12660/where-to-find-documentation-of-writing-an-encapsulated-file-reader/</link>
      <pubDate>Thu, 12 Jul 2012 07:50:00 +0000</pubDate>
      
      <guid>/questions/12660/where-to-find-documentation-of-writing-an-encapsulated-file-reader/</guid>
      <description>Where to find documentation of writing an encapsulated file reader  0 Hi I am working on a file reader that can read dump files containing ETSI (Ber encoded) data and .... struggling. Especially when trying to dissect the data. I already implemented a dissector, a simple ber-based reader and a packet-encap file, but the dissection mechanism, and how to call the dissector is still a bit of a mystery to me.</description>
    </item>
    
    <item>
      <title>Cant see packets from SQL Server</title>
      <link>/questions/12668/cant-see-packets-from-sql-server/</link>
      <pubDate>Thu, 12 Jul 2012 13:20:00 +0000</pubDate>
      
      <guid>/questions/12668/cant-see-packets-from-sql-server/</guid>
      <description>Cant see packets from SQL Server  0 Hello all,
i have problem what i would like to do is to se packets between application and sql server. I use filter for Wireshark set to port 1433 and i cant see any of packets beetwen app and db even i do some queries etc. Could you tell me why it can be that situation please of help...
sql server wiresharkasked 12 Jul &#39;12, 13:20</description>
    </item>
    
    <item>
      <title>Will WOL work on non-broadcast packets?</title>
      <link>/questions/12677/will-wol-work-on-non-broadcast-packets/</link>
      <pubDate>Thu, 12 Jul 2012 19:49:00 +0000</pubDate>
      
      <guid>/questions/12677/will-wol-work-on-non-broadcast-packets/</guid>
      <description>Will WOL work on non-broadcast packets?  0 Hi
I have been trying to use the Wake on LAN feature but I have been struggling very much with it. Limitation with my router.
My config is
router -&amp;gt; hub -&amp;gt; PC1 | v PC2 (always awake).The workaround: When I intend to do is send the magic packets to PC2 (always awake). The understanding I got is that the hub will broadcast to both PC1 and PC2.</description>
    </item>
    
    <item>
      <title>LTE RRC dissector</title>
      <link>/questions/12687/lte-rrc-dissector/</link>
      <pubDate>Thu, 12 Jul 2012 22:01:00 +0000</pubDate>
      
      <guid>/questions/12687/lte-rrc-dissector/</guid>
      <description>LTE RRC dissector  0 Hi,
Is it possible to send LTE RRC frames over UDP somehow and for wireshark to decode them. Like in case of MAC PDUs there is a UDP format defined (http://wiki.wireshark.org/MAC-LTE), is there a similar format for RRC frames as well. I couldn&#39;t find anything regarding this on the internet.
Any help regarding this would be highly appreciated.
Thanks, Saurabh
rrc lteasked 12 Jul &#39;12, 22:01</description>
    </item>
    
    <item>
      <title>playback speex codec in VOIP rtp player?</title>
      <link>/questions/12688/playback-speex-codec-in-voip-rtp-player/</link>
      <pubDate>Thu, 12 Jul 2012 22:11:00 +0000</pubDate>
      
      <guid>/questions/12688/playback-speex-codec-in-voip-rtp-player/</guid>
      <description>playback speex codec in VOIP rtp player?  0 I have captured a very important VOIP conversation on my magicjack line but the codec that was used was speex. Is there anyway to get the wireshark voip rtp player to play this call properly instead of just silence? I am open to using another program if that is the only option but I really have no clue where to start if that is even an option.</description>
    </item>
    
    <item>
      <title>Why is the advertised MSS smaller than expected</title>
      <link>/questions/12704/why-is-the-advertised-mss-smaller-than-expected/</link>
      <pubDate>Fri, 13 Jul 2012 02:52:00 +0000</pubDate>
      
      <guid>/questions/12704/why-is-the-advertised-mss-smaller-than-expected/</guid>
      <description>Why is the advertised MSS smaller than expected  0 The client NIC is set to MTU of 4000 and supposedly the switches along the paths. The SYN is showing a 1380 MSS instead of 3960. What is the cause?
mss mtuasked 13 Jul &#39;12, 02:52
ws2006
1●12●12●14
accept rate: 0%
 converted 13 Jul &#39;12, 05:01 
grahamb ♦
19.8k●3●30●206
  
2 Answers:
  
0There are several possibilities why the MSS is different than the MTU.</description>
    </item>
    
    <item>
      <title>Custom Dissector Portability</title>
      <link>/questions/12706/custom-dissector-portability/</link>
      <pubDate>Fri, 13 Jul 2012 08:37:00 +0000</pubDate>
      
      <guid>/questions/12706/custom-dissector-portability/</guid>
      <description>Custom Dissector Portability  0 Hi,
I have a custom plug-in that I want to distribute across many different versions of Windows.
My question is, if I compile the plugin with VS2008, will I be able to simply distribute the resulting DLL file and have any recipients place it in their Personal Plugins folder? I&#39;ve tried a couple of different versions so far and it seems to work fine but it&#39;s important that I be sure of this.</description>
    </item>
    
    <item>
      <title>Decrypt Lync TLS SIP</title>
      <link>/questions/12707/decrypt-lync-tls-sip/</link>
      <pubDate>Fri, 13 Jul 2012 14:10:00 +0000</pubDate>
      
      <guid>/questions/12707/decrypt-lync-tls-sip/</guid>
      <description>Decrypt Lync TLS SIP  0 Hi, I&#39;m running Wireshark 1.8 and I try to decrypt a SIP communication on a Lync server (Microsft voip server). Lync use TLS v1 to crypt sip flows but I can&#39;t decrypt with wireshark. Somebody can maybe help me, this is the logs, thank&#39;s :
ssl_load_key: can&amp;#39;t import pem data dissect_ssl enter frame #39 (first time) ssl_session_init: initializing ptr 0528416C size 588 conversation = 05283BD8, ssl_session = 0528416C record: offset = 0, reported_length_remaining = 70 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 65, ssl state 0x00 association_find: TCP port 1264 found 00000000 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 1 offset 5 length 61 bytes, remaining 70 packet_from_server: is from server - FALSE ssl_find_private_key server 192.</description>
    </item>
    
    <item>
      <title>Decrypting L2TP/IPsec, ESP</title>
      <link>/questions/12708/decrypting-l2tpipsec-esp/</link>
      <pubDate>Fri, 13 Jul 2012 15:04:00 +0000</pubDate>
      
      <guid>/questions/12708/decrypting-l2tpipsec-esp/</guid>
      <description>Decrypting L2TP/IPsec, ESP  1 Hello,
I need to diagnose L2TP/Ipsec VPN Connection which has encrypted packets exchanged between the server and client. Is there any way to test the connection by decrypting the packets using wireshark, like we do it for SSL/TLS connection using the private key/pem file. If there is some other way out there I would be very thankful for the same. Also, when I am trying to capture packets in wireshark while initiating L2TP connection I cannot see l2tp packets in the capture.</description>
    </item>
    
    <item>
      <title>GeoIP...no longitude/latitude</title>
      <link>/questions/12723/geoipno-longitudelatitude/</link>
      <pubDate>Sat, 14 Jul 2012 22:38:00 +0000</pubDate>
      
      <guid>/questions/12723/geoipno-longitudelatitude/</guid>
      <description>GeoIP&amp;hellip;no longitude/latitude  0 Hello All,
I have installed the GeoIP database. I&#39;ve pointed my wireshark to the correct database. But when I take a capture and go to statistics-endpoints, I do not see the Latitude/Longitude even for Public IP addresses. Does anyone know why its not working ?
geoipasked 14 Jul &#39;12, 22:38
parvikram
1●2●2●2
accept rate: 0%
  
2 Answers:
  
2It works with Wireshark 1.</description>
    </item>
    
    <item>
      <title>Wireshark based 3G Protocol Analyser</title>
      <link>/questions/12727/wireshark-based-3g-protocol-analyser/</link>
      <pubDate>Sun, 15 Jul 2012 08:21:00 +0000</pubDate>
      
      <guid>/questions/12727/wireshark-based-3g-protocol-analyser/</guid>
      <description>Wireshark based 3G Protocol Analyser  0 Can anyone please post the link to download Wireshark based 3G Protocol Analyser referred to by this email message?
3g analyser protocolasked 15 Jul &#39;12, 08:21
vin_66_sag
1●1●1●1
accept rate: 0%
 edited 16 Jul &#39;12, 12:24 
Guy Harris ♦♦
17.4k●3●35●196
the link to the screenshot is no longer available. Please update!
(16 Jul &#39;12, 00:30) Kurt Knochner ♦  
One Answer:</description>
    </item>
    
    <item>
      <title>Remote Capture from Linux to Windows</title>
      <link>/questions/12728/remote-capture-from-linux-to-windows/</link>
      <pubDate>Sun, 15 Jul 2012 13:06:00 +0000</pubDate>
      
      <guid>/questions/12728/remote-capture-from-linux-to-windows/</guid>
      <description>Remote Capture from Linux to Windows  0 Am trying to set up remote capture from Linux (on a Amazon EC2 VM) to my Windows 7 laptop. I have found a couple of commands that claim to work using the plink SSH client that comes with Putty.
Number 1: plink PersonEC2 &#39; sudo tshark -i eth0 &amp;gt; /tmp/pipe &#39; | wireshark -k –i where PersonEC2 is my Putty Saved Session Name</description>
    </item>
    
    <item>
      <title>ICMP data field corruption</title>
      <link>/questions/12729/icmp-data-field-corruption/</link>
      <pubDate>Sun, 15 Jul 2012 14:52:00 +0000</pubDate>
      
      <guid>/questions/12729/icmp-data-field-corruption/</guid>
      <description>ICMP data field corruption  0 Hello,
my (old) laptop is unable to establish a wireless link over a cardbus WLAN card. After disabling WLAN encryption, I am able to send an echo request and there is an echo response from the server. Using WireShark, I can see that the ICMP checksum is wrong because the ICMP data is corrupted. Typically, 4 bytes &#34;62 63 64 65&#34; are blanked to &#34;</description>
    </item>
    
    <item>
      <title>RTP Analysis: Wrong sequence nr.</title>
      <link>/questions/12737/rtp-analysis-wrong-sequence-nr/</link>
      <pubDate>Mon, 16 Jul 2012 01:20:00 +0000</pubDate>
      
      <guid>/questions/12737/rtp-analysis-wrong-sequence-nr/</guid>
      <description>RTP Analysis: Wrong sequence nr.  0 Doing an RTP analysis to a file. After the RTP sequence number loops from 65534 to 18 (some packets missing in between), the rest of the packets are reported with status of &#34;Wrong sequence nr.&#34;.
It seems like a bug???
nr rtp analysis sequenceasked 16 Jul &#39;12, 01:20
jussivee
1●1●1●2
accept rate: 0%
 edited 16 Jul &#39;12, 01:21</description>
    </item>
    
    <item>
      <title>HTTP requests/responses out of sequence</title>
      <link>/questions/12738/http-requestsresponses-out-of-sequence/</link>
      <pubDate>Mon, 16 Jul 2012 01:32:00 +0000</pubDate>
      
      <guid>/questions/12738/http-requestsresponses-out-of-sequence/</guid>
      <description>HTTP requests/responses out of sequence  0 Hi,
I was recently looking at HTTP requests/responses made by the default web browser on an HTC Android smartphone and noticed some strange behaviour. When using Follow TCP Stream for HTTP traffic you normally see an HTTP request (e.g. GET) followed by the response repeated many times over. However in this case I&#39;m seeing 2 or 3 GETs together followed later by responses. I thought that HTTP communication on a given connection had to be sequential - a request followed by a response.</description>
    </item>
    
    <item>
      <title>Wireshark packet loss</title>
      <link>/questions/12741/wireshark-packet-loss/</link>
      <pubDate>Mon, 16 Jul 2012 02:59:00 +0000</pubDate>
      
      <guid>/questions/12741/wireshark-packet-loss/</guid>
      <description>Wireshark packet loss  0 Hi,
My VoIP application is running on a windows PC at 1 end and on a android device at the other over a wifi network. My usecase needs the windows side to only send data and android side to only receive. I am running wireshark on windows PC and tcpdump on android device to capture all the voip data. I am getting to see some packet drops in the android side dump.</description>
    </item>
    
    <item>
      <title>Wireshark 1.8.0 crash when plotting IO graph</title>
      <link>/questions/12742/wireshark-180-crash-when-plotting-io-graph/</link>
      <pubDate>Mon, 16 Jul 2012 03:14:00 +0000</pubDate>
      
      <guid>/questions/12742/wireshark-180-crash-when-plotting-io-graph/</guid>
      <description>Wireshark 1.8.0 crash when plotting IO graph  0 Hi all,
My wireshark crashes since I&#39;ve upgraded to the latest version 1.8.0 when i am trying to plot the retransmission count over time in the IO graph. I got the same error message when trying to plot duplicate ack count over time in the IO graph as well. When i use the earlier stable version (1.6.8), I have no problem. Here is my setup:</description>
    </item>
    
    <item>
      <title>Copy to notepad</title>
      <link>/questions/12746/copy-to-notepad/</link>
      <pubDate>Mon, 16 Jul 2012 04:43:00 +0000</pubDate>
      
      <guid>/questions/12746/copy-to-notepad/</guid>
      <description>Copy to notepad  2 Hi,
If i want to copy multiple rows to textfile ctrl or shift pressed in doesn&#39;t work. what is the easiest way to copy specific rows to a textfile?
notepadasked 16 Jul &#39;12, 04:43
Ivan
31●2●2●4
accept rate: 0%
  
One Answer:
  
1Mark the packtes (CRTL-M) you need, then print them to a text file:
File -&amp;gt; Print -&amp;gt; Plain Text</description>
    </item>
    
    <item>
      <title>Adding a new protocol to Wireshark</title>
      <link>/questions/12749/adding-a-new-protocol-to-wireshark/</link>
      <pubDate>Mon, 16 Jul 2012 05:10:00 +0000</pubDate>
      
      <guid>/questions/12749/adding-a-new-protocol-to-wireshark/</guid>
      <description>Adding a new protocol to Wireshark  0 1I&#39;m currently working with the Wireshark source on Linux to develop a few dissectors for different protocols (MAVLINK being the one in question). The only way I know of at the moment to get MAVLINK packets to display in Wireshark is to capture raw data with a serial port logger, then import that into Wireshark as Raw USB packets. It would be very useful to be able to do a live capture (specifically on a serial port), but I can&#39;t seem to find any useful information on adding a new protocol Wireshark.</description>
    </item>
    
    <item>
      <title>Is MSRPC::DCOM:RemoteCreateInstance Request/Response decoder planned?</title>
      <link>/questions/12750/is-msrpcdcomremotecreateinstance-requestresponse-decoder-planned/</link>
      <pubDate>Mon, 16 Jul 2012 05:24:00 +0000</pubDate>
      
      <guid>/questions/12750/is-msrpcdcomremotecreateinstance-requestresponse-decoder-planned/</guid>
      <description>Is MSRPC::DCOM:RemoteCreateInstance Request/Response decoder planned?  0 Hi guys,
Is MSRPC::DCOM:RemoteCreateInstance Request/Response decoder planned? And is this feature on demand?
msrpc remotecreateinstance dcomasked 16 Jul &#39;12, 05:24
ltgao
1●1●1●2
accept rate: 0%
  
One Answer:
  
0As Wireshark is Open Source software primarily developed by people in their spare time, there isn&#39;t much of a plan.
Anyway, looking through Wireshark&#39;s source code I can see that packet-dcom-sysact.</description>
    </item>
    
    <item>
      <title>VMWare ESXi 5.0 and Wireshark</title>
      <link>/questions/12760/vmware-esxi-50-and-wireshark/</link>
      <pubDate>Mon, 16 Jul 2012 07:10:00 +0000</pubDate>
      
      <guid>/questions/12760/vmware-esxi-50-and-wireshark/</guid>
      <description>VMWare ESXi 5.0 and Wireshark  0 What I&#39;m trying to do: Use vmnic1 in a Windows 2008 R2 in EXSi 5.0 as a dedicated wireshark port. I need to be able to set a port mirror on my Avaya ERS5650 and have vmnic1 capture this data.
Physical Server = ESXi 5.0 Server with 2 Physical NICs.
Physical Data Switch = Avaya ERS5650
ESXi vmnic0 = vSwitch0, standard network traffic for all VM&#39;s</description>
    </item>
    
    <item>
      <title>Editing info column of dissector</title>
      <link>/questions/12764/editing-info-column-of-dissector/</link>
      <pubDate>Mon, 16 Jul 2012 07:55:00 +0000</pubDate>
      
      <guid>/questions/12764/editing-info-column-of-dissector/</guid>
      <description>Editing info column of dissector  0 I am trying to edit an existing dissector to make it display some values in the info column. Currently, I am able to do this to a certain extent and display values that come from a value_string array, using the val_to_str function. However, now I want to be able to display other values that are contained within an array of the type hf_register_info.</description>
    </item>
    
    <item>
      <title>Apache server shows multiple POST requests, Wireshark shows none. Why?</title>
      <link>/questions/12776/apache-server-shows-multiple-post-requests-wireshark-shows-none-why/</link>
      <pubDate>Mon, 16 Jul 2012 11:55:00 +0000</pubDate>
      
      <guid>/questions/12776/apache-server-shows-multiple-post-requests-wireshark-shows-none-why/</guid>
      <description>Apache server shows multiple POST requests, Wireshark shows none. Why?  0 I have an Apache access log showing that multiple POST requests were sent to it and they all succeeded with a return code of 200. When I look at the Wireshark trace, I don&#39;t see anything except the certificate authentications. What am I missing here? Why don&#39;t I see the POST activity?
The Wireshark trace is at: http://cloudshark.org/captures/b97dc3a7b311?filter=ip.addr%20%3D%3D%20192.168.5.103</description>
    </item>
    
    <item>
      <title>Problem - wireless capture on windows in promiscuous mode</title>
      <link>/questions/12786/problem-wireless-capture-on-windows-in-promiscuous-mode/</link>
      <pubDate>Mon, 16 Jul 2012 14:06:00 +0000</pubDate>
      
      <guid>/questions/12786/problem-wireless-capture-on-windows-in-promiscuous-mode/</guid>
      <description>Problem - wireless capture on windows in promiscuous mode  0 hey i have Tp-Link Wireless Usb And I Try To Start caputre with wireshark i have this problem
The capture session could not be initiated (failed to set hardware filter to promiscuous mode). Please check that &amp;quot;\Device\NPF_{1BD779A8-8634-4EB8-96FA-4A5F9AB8701F}&amp;quot; is the proper interface.
Help can be found at:
http://wiki.wireshark.org/WinPcap http://wiki.wireshark.org/CaptureSetupand i have windows xp can anyone help me pleas?
windows promiscuous wlanasked 16 Jul &amp;lsquo;12, 14:06</description>
    </item>
    
    <item>
      <title>Wireshark Doesn&amp;#x27;t detect USB datacards.</title>
      <link>/questions/12791/wireshark-doesnt-detect-usb-datacards/</link>
      <pubDate>Mon, 16 Jul 2012 21:03:00 +0000</pubDate>
      
      <guid>/questions/12791/wireshark-doesnt-detect-usb-datacards/</guid>
      <description>Wireshark Doesn&amp;rsquo;t detect USB datacards.  0 Hi, Wireshark Doesn&#39;t detect USB datacards. Is there anyway to get this detected and run captures ?
usbasked 16 Jul &#39;12, 21:03
Raghu_capture
1●1●1●1
accept rate: 0%
  
3 Answers:
  
0If by &#34;USB datacard&#34; you mean a USB adapter that connects to a mobile phone network for data access, then:
if this is on Windows, you may be seeing this problem with WinPcap;if this is on some flavor of UN*X, such as Linux, there should be a PPP interface available on which to capture if you&#39;re connected to the network.</description>
    </item>
    
    <item>
      <title>Calculate RTT using TSecr field</title>
      <link>/questions/12793/calculate-rtt-using-tsecr-field/</link>
      <pubDate>Tue, 17 Jul 2012 00:39:00 +0000</pubDate>
      
      <guid>/questions/12793/calculate-rtt-using-tsecr-field/</guid>
      <description>Calculate RTT using TSecr field  0 Hey guys,
I have a basic question which I&#39;m stucked....
Im trying to use the TSecr (tcp.options.timestamp.tsecr) in order to help me calculate RTT since its stores time info from the sending server...
I just dont have any clue how to transform the values of Tsecr into time information in order to calculate the RTT. As far as I understood RTT would be RTT = Actual Time (for ACK) - TSecr but since it seems that TSecr is a field of 32 bits I have no clue how to transform it into time reference in order to help into RTT calculations.</description>
    </item>
    
    <item>
      <title>wireshark as IDS for event logging?</title>
      <link>/questions/12798/wireshark-as-ids-for-event-logging/</link>
      <pubDate>Tue, 17 Jul 2012 06:13:00 +0000</pubDate>
      
      <guid>/questions/12798/wireshark-as-ids-for-event-logging/</guid>
      <description>wireshark as IDS for event logging?  0 Dear Developer&#39;s and User&#39;s of Wireshark,
Wireshark is a great application for network monitoring and sniffing. It can decode almost all protocols available from Ethernet,IP even to the WSN&#39;s protocols such as 802.15.4,6LOWPAN .. etc.
In order to find an attack, we need to monitor the network ( src, dest address and the invalid packets nature ). So is it possible for an application or plugin developed for wireshark, to use it for detecting attack event&#39;s?</description>
    </item>
    
    <item>
      <title>How to convert multiple .pcap files to .csv</title>
      <link>/questions/12799/how-to-convert-multiple-pcap-files-to-csv/</link>
      <pubDate>Tue, 17 Jul 2012 06:53:00 +0000</pubDate>
      
      <guid>/questions/12799/how-to-convert-multiple-pcap-files-to-csv/</guid>
      <description>How to convert multiple .pcap files to .csv  0 Hi,
I would like to know if it is possible to convert multiple wireshark capture files to csv files. For example there are 3 files in a folder, is there any way to convert all three with a command or does anyone know a way to do this? Any help is appreciated.
I am using a tshark command to convert one file at a time,instead of test.</description>
    </item>
    
    <item>
      <title>Wireshark 1.8.0 causes screen freeze on Win7 64</title>
      <link>/questions/12801/wireshark-180-causes-screen-freeze-on-win7-64/</link>
      <pubDate>Tue, 17 Jul 2012 10:00:00 +0000</pubDate>
      
      <guid>/questions/12801/wireshark-180-causes-screen-freeze-on-win7-64/</guid>
      <description>Wireshark 1.8.0 causes screen freeze on Win7 64  0 Since installing 1.8.0 I find that almost every time I move or resize a Wireshark window, my screen freezes: the mouse cursor moves but clicking does nothing. I can recover by using control-alt-del, then clicking Cancel, after which the screen repaints and normal mouse operations resume, until I next move a window. Reverting to 1.6.8 has restored sanity.
mouse freezeasked 17 Jul &#39;12, 10:00</description>
    </item>
    
    <item>
      <title>Decryption of ISKAMP Packets in wireshark version 1.8.0</title>
      <link>/questions/12803/decryption-of-iskamp-packets-in-wireshark-version-180/</link>
      <pubDate>Tue, 17 Jul 2012 11:00:00 +0000</pubDate>
      
      <guid>/questions/12803/decryption-of-iskamp-packets-in-wireshark-version-180/</guid>
      <description>Decryption of ISKAMP Packets in wireshark version 1.8.0  0 Hi,
Decrypting of the ISKAMP packet results in expert info/malformed Packet. When we are decrypting the ISKAMP Packet in wireshark it results in a MALFORMED Packet. Can anyone please help me with this.
Regards, Sharad
isakmp ike decryptionThis question is marked &#34;community wiki&#34;.asked 17 Jul &#39;12, 11:00
Sharad Kodkani
1●1●1●1
accept rate: 0%
 edited 23 Jul &#39;12, 12:49</description>
    </item>
    
    <item>
      <title>Include OpenFlow dissector in Wireshark</title>
      <link>/questions/12804/include-openflow-dissector-in-wireshark/</link>
      <pubDate>Tue, 17 Jul 2012 11:48:00 +0000</pubDate>
      
      <guid>/questions/12804/include-openflow-dissector-in-wireshark/</guid>
      <description>Include OpenFlow dissector in Wireshark  0 There is an OpenFlow dissector developed for Wireshark. It does not look like it was ever added to trunk. Is there any history here about why this has not been submitted as a patch?
http://www.openflow.org/wk/index.php/OpenFlow_Wireshark_Dissector
openflowasked 17 Jul &#39;12, 11:48
joemc
21●2●2●5
accept rate: 0%
  
One Answer:
  
1That question can be best asked at the people who developed the dissector.</description>
    </item>
    
    <item>
      <title>Lost Captured Files</title>
      <link>/questions/12812/lost-captured-files/</link>
      <pubDate>Tue, 17 Jul 2012 14:28:00 +0000</pubDate>
      
      <guid>/questions/12812/lost-captured-files/</guid>
      <description>Lost Captured Files  0 I recently used Wriehsrak to look through cookies on my computer . I had already chosen which interface I wanted , but later in the capturing decided I wanted to inclued another interface . I was prompted to save my captured packets , I declined . I continued on to select multipule interface , and noticed that I had lost a lot of what I had .</description>
    </item>
    
    <item>
      <title>Filter string length</title>
      <link>/questions/12819/filter-string-length/</link>
      <pubDate>Wed, 18 Jul 2012 01:41:00 +0000</pubDate>
      
      <guid>/questions/12819/filter-string-length/</guid>
      <description>Filter string length  0 Hello,
anyone knows if there&#39;s a maximum length for a display filter string?
Thanks Lucio
filteringasked 18 Jul &#39;12, 01:41
luxxx
1●2●2●3
accept rate: 0%
  
One Answer:
  
1Without looking at the code, I just tried to fill the filter field and was able to enter a maximum of 65535 characters.
answered 18 Jul &#39;12, 01:51
SYN-bit ♦♦
17.1k●9●57●245
accept rate: 20%</description>
    </item>
    
    <item>
      <title>How to  get all of the http sessions related to one web page?</title>
      <link>/questions/12824/how-to-get-all-of-the-http-sessions-related-to-one-web-page/</link>
      <pubDate>Wed, 18 Jul 2012 05:32:00 +0000</pubDate>
      
      <guid>/questions/12824/how-to-get-all-of-the-http-sessions-related-to-one-web-page/</guid>
      <description>How to get all of the http sessions related to one web page?  0 how to get all of the http session related to one web page? Dear , When I load one web-page, it generates many http sessions (like get/response..), and it&#39;s difficult to get all of the http packets related to one web page. Do you have some ideas?
session http web-pageasked 18 Jul &#39;12, 05:32
chinasan</description>
    </item>
    
    <item>
      <title>Unable to update wireshark in Fedora13</title>
      <link>/questions/12826/unable-to-update-wireshark-in-fedora13/</link>
      <pubDate>Wed, 18 Jul 2012 06:32:00 +0000</pubDate>
      
      <guid>/questions/12826/unable-to-update-wireshark-in-fedora13/</guid>
      <description>Unable to update wireshark in Fedora13  0 Hello Team
I need your help in upgrading the wireshark in my machine which has Fedora 13 installed on it. I tried the following ways and was not able to proceed further.
[[email protected] sbin]# yum update wireshark Loaded plugins: presto, refresh-packagekit Setting up Update Process No Packages marked for Update [[email protected] sbin]#
I am a new user to Fedora. Could you please help/suggest me how to proceed further, as the 1.</description>
    </item>
    
    <item>
      <title>Why is the Zigbee decryption using Version 1.8.0 win32 not correct?</title>
      <link>/questions/12830/why-is-the-zigbee-decryption-using-version-180-win32-not-correct/</link>
      <pubDate>Wed, 18 Jul 2012 07:25:00 +0000</pubDate>
      
      <guid>/questions/12830/why-is-the-zigbee-decryption-using-version-180-win32-not-correct/</guid>
      <description>Why is the Zigbee decryption using Version 1.8.0 win32 not correct?  0 I just installed version 1.8.0 and set the preconfigured key for the Zigbee Protocol to (39:30:65:63:6E:61:69:6C:6C:41:65:65:42:67:69:5A) and Byte order (normal). It is not decrypting my Zigbee packet properly. Can anyone help me?
zigbeeasked 18 Jul &#39;12, 07:25
April
1●1●1●1
accept rate: 0%
 edited 18 Jul &#39;12, 12:05 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:</description>
    </item>
    
    <item>
      <title>How to use dissector not in &amp;quot;decode as&amp;quot;</title>
      <link>/questions/12831/how-to-use-dissector-not-in-decode-as/</link>
      <pubDate>Wed, 18 Jul 2012 08:48:00 +0000</pubDate>
      
      <guid>/questions/12831/how-to-use-dissector-not-in-decode-as/</guid>
      <description>How to use dissector not in &amp;ldquo;decode as&amp;rdquo;  0 1I have made a custom dissector but do not know how to use it in wireshark.
It appears that it should work, as I am able to type it into the filter bar and it turns green. However, it is not listed in the &#34;decode as&#34; menu, therefore I do not know of anyway to use it.
Is there a way to add this custom dissector to the decode as menu or simply use it some other way?</description>
    </item>
    
    <item>
      <title>Unknown frame [Malformed Packet]</title>
      <link>/questions/12833/unknown-frame-malformed-packet/</link>
      <pubDate>Wed, 18 Jul 2012 10:42:00 +0000</pubDate>
      
      <guid>/questions/12833/unknown-frame-malformed-packet/</guid>
      <description>Unknown frame [Malformed Packet]  0 I am new at this, but my company has something serious going on. We are getting flooded with &#34;Unknown frame[Malformed Packet]&#34; that are 60 bits and lots of them. This is causing major issues with my VOIP system (ShoreTel) to the point that we are almost unable to use the phones.
IP range: 10.0.x.x Subnet: 255.255.0.0 HP switching equipment
We have a flat network, but plan to change that soon.</description>
    </item>
    
    <item>
      <title>how to use dumpcap to monitor winpcap on a remote machine</title>
      <link>/questions/12835/how-to-use-dumpcap-to-monitor-winpcap-on-a-remote-machine/</link>
      <pubDate>Wed, 18 Jul 2012 11:57:00 +0000</pubDate>
      
      <guid>/questions/12835/how-to-use-dumpcap-to-monitor-winpcap-on-a-remote-machine/</guid>
      <description>how to use dumpcap to monitor winpcap on a remote machine  0 I&#39;ve been using wireshark to monitor a remote interface on a pc that is having an intermittent problem that we believe to be network related. The problem is, wireshark crashes on my win7 machine every 15 minutes or so after consuming more than a gig of RAM.
I read that wireshark actually uses dumpcap to retrieve the packet info from winpcap.</description>
    </item>
    
    <item>
      <title>UDP packets&amp;#x27; jitter and delay</title>
      <link>/questions/12837/udp-packets-jitter-and-delay/</link>
      <pubDate>Wed, 18 Jul 2012 13:48:00 +0000</pubDate>
      
      <guid>/questions/12837/udp-packets-jitter-and-delay/</guid>
      <description>UDP packets&#39; jitter and delay  0 Dear all, I&#39;m new in Wireshark and I would like to know if it&#39;s possible to get the delay and jitter of UDP packets directly in WireShark. I saw many examples on Internet but they are all about RTP protocol. Thank you in advance for your help. Best regards.
delay udp jitterasked 18 Jul &#39;12, 13:48
nezha
6●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Weird NBNS queries</title>
      <link>/questions/12840/weird-nbns-queries/</link>
      <pubDate>Wed, 18 Jul 2012 21:51:00 +0000</pubDate>
      
      <guid>/questions/12840/weird-nbns-queries/</guid>
      <description>Weird NBNS queries  0 1I see plenty of &#34;normal&#34; NBMS queries, in that the host names are ones I recognize. These ones...notsomuch.
Any ideas?
Thx
====
613 352.118450000 xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx NBNS 92 Name query NB AAPFPTPQUG&amp;lt;00&amp;gt;
614 352.118462000 xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx NBNS 92 Name query NB JSHNNMKQEJ&amp;lt;00&amp;gt;
615 352.118741000 xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx NBNS 92 Name query NB SIXXNSTOSD&amp;lt;00&amp;gt;
618 352.882326000 xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx NBNS 92 Name query NB SIXXNSTOSD&amp;lt;00&amp;gt;
619 352.882515000 xxx.xxx.xxx.xxx xxx.</description>
    </item>
    
    <item>
      <title>where is the cipher/decipher function used in umts(3G) in wireshark code?</title>
      <link>/questions/12843/where-is-the-cipherdecipher-function-used-in-umts3g-in-wireshark-code/</link>
      <pubDate>Thu, 19 Jul 2012 01:38:00 +0000</pubDate>
      
      <guid>/questions/12843/where-is-the-cipherdecipher-function-used-in-umts3g-in-wireshark-code/</guid>
      <description>where is the cipher/decipher function used in umts(3G) in wireshark code?  0 I can&#39;t find the cipher/decipher function used in umts(3G). I have to make sure the (RLC)UM, (RLC)AM ,MAC -d, have cipher/decipher function.
decipher um cipher amasked 19 Jul &#39;12, 01:38
smilezuzu
20●32●32●37
accept rate: 0%
  
One Answer:
  
0Nowhere as no one has implemented it, unless it uses functions available trough OPENssl or TLS.</description>
    </item>
    
    <item>
      <title>SCTP unbundle</title>
      <link>/questions/12845/sctp-unbundle/</link>
      <pubDate>Thu, 19 Jul 2012 02:03:00 +0000</pubDate>
      
      <guid>/questions/12845/sctp-unbundle/</guid>
      <description>SCTP unbundle  0 hello,
i`m looking for some method capable of separating bundled SCTP chunks into separate frames. i think this guy is modifying editcap for sctp-unbundle, but i do not know how to get it . . .
https://gitorious.org/~vasilvelichkov
thanks
bundling sctp editcap unbundleasked 19 Jul &#39;12, 02:03
knuf
1●1●1●1
accept rate: 0%
  
One Answer:
  
0besides the tool you mentioned, you can try this perl script:</description>
    </item>
    
    <item>
      <title>ISDN LAPD X.25 packet data</title>
      <link>/questions/12848/isdn-lapd-x25-packet-data/</link>
      <pubDate>Thu, 19 Jul 2012 02:33:00 +0000</pubDate>
      
      <guid>/questions/12848/isdn-lapd-x25-packet-data/</guid>
      <description>ISDN LAPD X.25 packet data  0 I try to analyze ISDN data which contain SAPI 16 packet data, which is X.31. X.31 data is X.25 packet data (layer 3). So far I know, wireshark can decode X.25, but if I select the data field, I cannot decode it since Decode as is not available (grayed out). The layer 2 LAPD data is displayed correctly, the address field SAPI is also correctly displayed as &#34;</description>
    </item>
    
    <item>
      <title>First time compile: stdint.h not found in crc7.c</title>
      <link>/questions/12858/first-time-compile-stdinth-not-found-in-crc7c/</link>
      <pubDate>Thu, 19 Jul 2012 06:23:00 +0000</pubDate>
      
      <guid>/questions/12858/first-time-compile-stdinth-not-found-in-crc7c/</guid>
      <description>First time compile: stdint.h not found in crc7.c  0 Hello i&#39;m compiling for the 1st time wireshark. I&#39;ve followed the Win32 related part on the developers guide.
Check with the verify_tools : OK distclean: OK nmake .... setup OK
nmake .... all : fails because in the crc7.c the compiler find a reference to stdint.h file not found.
I&#39;m using VS2008EE
Thanks,
Paolo
crc7.c stdint.hasked 19 Jul &#39;12, 06:23</description>
    </item>
    
    <item>
      <title>analyzing 802.11 capture</title>
      <link>/questions/12869/analyzing-80211-capture/</link>
      <pubDate>Thu, 19 Jul 2012 16:33:00 +0000</pubDate>
      
      <guid>/questions/12869/analyzing-80211-capture/</guid>
      <description>analyzing 802.11 capture  0 I have captured a ping request/response via AirPcap interface. The ICMP messages are displayed as QoS Data versus ICMP. How do I display these frames as ICMP protocol ?
semperfiasked 19 Jul &#39;12, 16:33
Jeff
1●1●1●1
accept rate: 0%
  
One Answer:
  
0That means wireshark is not able to decrypt the packets. Have you entered your wireless key/password correctly?
answered 20 Jul &#39;12, 00:12</description>
    </item>
    
    <item>
      <title>what is  the mean of this funtion: rlc_decode_li?</title>
      <link>/questions/12870/what-is-the-mean-of-this-funtion-rlc_decode_li/</link>
      <pubDate>Thu, 19 Jul 2012 19:31:00 +0000</pubDate>
      
      <guid>/questions/12870/what-is-the-mean-of-this-funtion-rlc_decode_li/</guid>
      <description>what is the mean of this funtion: rlc_decode_li?  0 In UMTS, lub_decoder,MAC to RLC,there is a cipher/decipher process. I have to find this process.But I can&#39;t find code in wireshark,just a function:rlc_decode_li,maybe this a cipher?? follow is the code in wireshark.
pos = fpinf-&amp;gt;cur_tb; if (rlcinf-&amp;gt;ciphered[pos] == TRUE &amp;amp;&amp;amp; rlcinf-&amp;gt;deciphered[pos] == FALSE) { proto_tree_add_text(tree, tvb, 0, -1, &amp;quot;Cannot dissect RLC frame because it is ciphered&amp;quot;); return; } num_li = rlc_decode_li(RLC_AM, tvb, pinfo, tree, li, MAX_LI); if (num_li == -1) return; /* something went wrong */ offs += num_li;decipher cipher rlc_decode_liasked 19 Jul &#39;12, 19:31</description>
    </item>
    
    <item>
      <title>weird windows copy behaviour</title>
      <link>/questions/12880/weird-windows-copy-behaviour/</link>
      <pubDate>Fri, 20 Jul 2012 03:22:00 +0000</pubDate>
      
      <guid>/questions/12880/weird-windows-copy-behaviour/</guid>
      <description>weird windows copy behaviour  0 I have a problem with a very slow copy action from a window 2003 server to an XP workstation.
In the trace of the workstation large delays of 1 second are seen for retransmissions. What happens is that 2 lost segments are encountered. The XP workstation sends one duplicate ack (so 2 ack all together) but not any more. After this it takes 1 second for the server to do a retransmission.</description>
    </item>
    
    <item>
      <title>Memory Consumption</title>
      <link>/questions/12882/memory-consumption/</link>
      <pubDate>Fri, 20 Jul 2012 11:38:00 +0000</pubDate>
      
      <guid>/questions/12882/memory-consumption/</guid>
      <description>Memory Consumption  0 The new version of wireshark 1.6.8 + are consuming excessive amounts of RAM memory, and has used up all the memory on the machine I am using.
Are you planning to go back to how 1.2.7 works, not using local RAM or at least minimize it so it doesn&#39;t grow more than 5 mb of memory.
with this memory usage on 1.6.8 and up, we cannot upgrade because this causes our servers problems when we are doing long term packet captures.</description>
    </item>
    
    <item>
      <title>FIltering out my mobile packets</title>
      <link>/questions/12883/filtering-out-my-mobile-packets/</link>
      <pubDate>Fri, 20 Jul 2012 12:13:00 +0000</pubDate>
      
      <guid>/questions/12883/filtering-out-my-mobile-packets/</guid>
      <description>FIltering out my mobile packets  0 How to filter out traffic that I do with my mobile phone while being on computer? I can filter out other computers but I can&#39;t do that for phones that are connecting to Internet wirelessly through my router. IPs and MAC are like these:
192.168.1.101 64:A7:69:47:5C:50
192.168.1.119 00:24:1D:91:8D:73
192.168.1.103 E4:B0:21:B5:1E:58 - phone
192.168.1.114 00:18:8B:71:16:7E
Thanks in advance
mobile filtering packetsasked 20 Jul &#39;12, 12:13</description>
    </item>
    
    <item>
      <title>capture error on Windows (failed to set hardware filter to promiscuous mode)</title>
      <link>/questions/12889/capture-error-on-windows-failed-to-set-hardware-filter-to-promiscuous-mode/</link>
      <pubDate>Fri, 20 Jul 2012 14:27:00 +0000</pubDate>
      
      <guid>/questions/12889/capture-error-on-windows-failed-to-set-hardware-filter-to-promiscuous-mode/</guid>
      <description>capture error on Windows (failed to set hardware filter to promiscuous mode)  0 i got this error:
The capture session could not be initiated (failed to set hardware filter to promiscuous mode).
Please check that &#34;\Device\NPF_{9E2076EE-E241-43AB-AC4B-8698D1A876F8}&#34; is the proper interface.
captureerrorasked 20 Jul &#39;12, 14:27
kayvan
1●1●1●1
accept rate: 0%
 edited 20 Jul &#39;12, 15:16 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:</description>
    </item>
    
    <item>
      <title>Http request</title>
      <link>/questions/12891/http-request/</link>
      <pubDate>Fri, 20 Jul 2012 23:47:00 +0000</pubDate>
      
      <guid>/questions/12891/http-request/</guid>
      <description>Http request  0 After username and password for our intranet website I see communication from Client Seq -1 next relative sequence no - 918 Ack =1 to server Get /webpage .aspx?q=sdfcklasdkcklejklwfjkacklasjcklasjdkcfsjckljsakl Ack from Server wit seq = 1 and ack = 918 after this i don&#39;t see any communication in the wire , we have restarted the server and checked no hope and finally i have unpluged n replug the server interface cable in the switch it stared working .</description>
    </item>
    
    <item>
      <title>Perl Net::Pcap Can not parse wireshark saved pcap file</title>
      <link>/questions/12896/perl-netpcap-can-not-parse-wireshark-saved-pcap-file/</link>
      <pubDate>Sun, 22 Jul 2012 02:17:00 +0000</pubDate>
      
      <guid>/questions/12896/perl-netpcap-can-not-parse-wireshark-saved-pcap-file/</guid>
      <description>Perl Net::Pcap Can not parse wireshark saved pcap file  0 hello,
I am writing a perl script to parse pcap file from wireshark with Net::Pcap module, here are the simple code:
use strict; use warnings; use utf8; use NetPacket::Ethernet qw(:types); use NetPacket::IP qw(:protos); use NetPacket::TCP; use Net::Pcap qw(:functions); my $pcap_file = &amp;quot;test.cap&amp;quot;; my $err = undef; # read data from pcap file. my $pcap = pcap_open_offline($pcap_file, \$err) or die &amp;quot;Can&amp;#39;t read $pcap_file : $err\n&amp;quot;; # loop over next 10 packets pcap_loop($pcap, -1, \&amp;amp;process_packet, &amp;quot;just for the demo&amp;quot;); # close the device pcap_close($pcap); sub process_packet { my ($user_data, $header, $packet) = @_; my $ether_data = NetPacket::Ethernet-&amp;gt;decode($packet); # Decode contents of TCP/IP packet contained within # captured ethernet packet # Print all out where its coming from and where its # going to!</description>
    </item>
    
    <item>
      <title>pre-emption decoding on S11 interface</title>
      <link>/questions/12907/pre-emption-decoding-on-s11-interface/</link>
      <pubDate>Mon, 23 Jul 2012 01:18:00 +0000</pubDate>
      
      <guid>/questions/12907/pre-emption-decoding-on-s11-interface/</guid>
      <description>pre-emption decoding on S11 interface  0 Hello,
within the Create Session request message on the S11 inteface the wireshark within Bearer Context IE decodes Bearer Level Quality of Service (Bearer QoS) in ARP field the wireshark decoded preemption values
 .... ...1 = PVI (Pre-emption Vulnerability): Enabled ..00 01.. = PL (Priority Level): 1 .1.. .... = PCI (Pre-emption Capability): Enabledfrom within the 3GPP a different value seems to be given:</description>
    </item>
    
    <item>
      <title>Does WireShark Support Dissector of 1xEVDO and CDMA2000 Air Interface protocols?</title>
      <link>/questions/12908/does-wireshark-support-dissector-of-1xevdo-and-cdma2000-air-interface-protocols/</link>
      <pubDate>Mon, 23 Jul 2012 01:21:00 +0000</pubDate>
      
      <guid>/questions/12908/does-wireshark-support-dissector-of-1xevdo-and-cdma2000-air-interface-protocols/</guid>
      <description>Does WireShark Support Dissector of 1xEVDO and CDMA2000 Air Interface protocols?  0 Does any expert knows that if WireShark support Dissector of 1xEVDO and CDMA2000 Over the Air (OTA) Interface protocols?
c2k cdma2000 ota 1xevdoasked 23 Jul &#39;12, 01:21
tools_hpp
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How to get source IP address?</title>
      <link>/questions/12921/how-to-get-source-ip-address/</link>
      <pubDate>Mon, 23 Jul 2012 08:23:00 +0000</pubDate>
      
      <guid>/questions/12921/how-to-get-source-ip-address/</guid>
      <description>How to get source IP address?  1 I am making a custom dissector that needs to be able to find the source ip address of a packet and compare it with the IP address of the host computer.
How would I be able to find the source IP address?
Thanks in advance for any help.
ip dissector addressasked 23 Jul &#39;12, 08:23
bball2601
16●5●6●7
accept rate: 50%</description>
    </item>
    
    <item>
      <title>Debug console not working</title>
      <link>/questions/12928/debug-console-not-working/</link>
      <pubDate>Mon, 23 Jul 2012 11:57:00 +0000</pubDate>
      
      <guid>/questions/12928/debug-console-not-working/</guid>
      <description>Debug console not working  0 I&#39;m working on a plugin and want to display debug data. I&#39;ve done this before with another plugin I built a couple of years ago, but now I can&#39;t even get the debug console to display! I&#39;ve got the preference set correctly (&#34;always&#34;), but the only time a debug console is displayed is the first time after I install Wireshark. When I close WS and open it again there&#39;s no debug console.</description>
    </item>
    
    <item>
      <title>Colorize Conversation keyboard shortcut removed from 1.8?</title>
      <link>/questions/12935/colorize-conversation-keyboard-shortcut-removed-from-18/</link>
      <pubDate>Mon, 23 Jul 2012 16:37:00 +0000</pubDate>
      
      <guid>/questions/12935/colorize-conversation-keyboard-shortcut-removed-from-18/</guid>
      <description>Colorize Conversation keyboard shortcut removed from 1.8?  0 Hello,
In WireShark 1.6 and 1.4 (maybe earlier I haven&#39;t checked), CTRL+1 through CTRL+0 would do the action of View &amp;gt; Colorize Conversation &amp;gt; Color 1 (or more specifically, it would colorize the TCP stream).
I am unable to do this same keyboard shortcut in 1.8. I did not see this listed in the release notes, and am not sure why such a feature would be removed but not replaced with anything else (CTRL+1 doesn&#39;t seem to do anything).</description>
    </item>
    
    <item>
      <title>pppoe architecture tracing</title>
      <link>/questions/12938/pppoe-architecture-tracing/</link>
      <pubDate>Mon, 23 Jul 2012 22:37:00 +0000</pubDate>
      
      <guid>/questions/12938/pppoe-architecture-tracing/</guid>
      <description>pppoe architecture tracing  0 I have a dsl modem connected directly to my PC. I want to trace few details of the packets passing through my PC with the help of Wireshark. Using Capture--&amp;gt;Interfaces I can see the only card with the IP = 10.0.0.1(probably because its a pppoe connection). Can someone direct me where exactly this address should be found in the packet(I guise somewher in the lower levels of the protocol stack)?</description>
    </item>
    
    <item>
      <title>wireshark decode  element in classmark3 information</title>
      <link>/questions/12940/wireshark-decode-element-in-classmark3-information/</link>
      <pubDate>Tue, 24 Jul 2012 00:04:00 +0000</pubDate>
      
      <guid>/questions/12940/wireshark-decode-element-in-classmark3-information/</guid>
      <description>wireshark decode element in classmark3 information  0 wireshark decode &amp;lt; 8-PSK Struct&amp;gt;element in classmark3 information as fixed 5bits. but, is it right ?from 3GPP24.008 the structure of this element is
 &amp;lt; 8-PSK Struct&amp;gt; : := &amp;lt; Modulation Capability : bit &amp;gt; { 0 | 1 &amp;lt; 8-PSK RF Power Capability 1: bit(2) &amp;gt; } { 0 | 1 &amp;lt; 8-PSK RF Power Capability 2: bit(2) &amp;gt; }that means if &amp;lt;8-PSK Struct&amp;gt;=1，the following data length will be from 3 to 7 bis？</description>
    </item>
    
    <item>
      <title>Wireshark release.</title>
      <link>/questions/12942/wireshark-release/</link>
      <pubDate>Tue, 24 Jul 2012 01:56:00 +0000</pubDate>
      
      <guid>/questions/12942/wireshark-release/</guid>
      <description>Wireshark release.  0 Hi,
When will 1.4.14 be released.
wiresharkasked 24 Jul &#39;12, 01:56
harjoti
1●1●1●1
accept rate: 0%
  
One Answer:
  
2See http://wiki.wireshark.org/Development/Roadmap looks like it&#39;s planned for today Pacific Standard Time ( PST ). 1.8.1 is a better choice though.
answered 24 Jul &#39;12, 02:55
Anders ♦
4.6k●9●52
accept rate: 17%
     </description>
    </item>
    
    <item>
      <title>TCP previous segment not captured, why?</title>
      <link>/questions/12943/tcp-previous-segment-not-captured-why/</link>
      <pubDate>Tue, 24 Jul 2012 02:24:00 +0000</pubDate>
      
      <guid>/questions/12943/tcp-previous-segment-not-captured-why/</guid>
      <description>TCP previous segment not captured, why?  0 Hi, I have a software who dumps data from a remote controller. The dump is made though a tcp connection that is not stable; my software is telling me &#34;communication stopped&#34; after 5-6 seconds
I run Wireshark to understand what was going on, but I&#39;m not able to spot the reason behind this. All I see in the pcap trace is that when the connection ends, I have a general error &#34;</description>
    </item>
    
    <item>
      <title>Searching for Text in a Pcap from a Blog DTD XHTML 1.0</title>
      <link>/questions/12954/searching-for-text-in-a-pcap-from-a-blog-dtd-xhtml-10/</link>
      <pubDate>Tue, 24 Jul 2012 05:26:00 +0000</pubDate>
      
      <guid>/questions/12954/searching-for-text-in-a-pcap-from-a-blog-dtd-xhtml-10/</guid>
      <description>Searching for Text in a Pcap from a Blog DTD XHTML 1.0  0 I have been noticing that when I sniff traffic from blogs, that I cannot seem to be able to read the text on the main blog page as it shows up as all garbled when you follow the tcp stream in Wireshark. For instance, you would see something like.
14949
...............W.%.&amp;gt;.}[email protected])\M...w..-....0%2]#Y.=.-#sy....._./......Qs...dd0:Y.A....=.}.}....{......x...u.......&#39;..d..........&#39;..g.....N...uZ6y.WeZ..?.jo...Vm.y...qq1..9.......
Instead of text on the blog.</description>
    </item>
    
    <item>
      <title>Install on Windows 8 (WinPCap issue)</title>
      <link>/questions/12956/install-on-windows-8-winpcap-issue/</link>
      <pubDate>Tue, 24 Jul 2012 07:04:00 +0000</pubDate>
      
      <guid>/questions/12956/install-on-windows-8-winpcap-issue/</guid>
      <description>Install on Windows 8 (WinPCap issue)  1 I know that to get Wireshark working on Windows 8, you set the installer to Windows 7 Compatibility mode (see this Question). My questions is this: Is this workaround going to be the only way to install Wireshark or is there going to be a native version of Wireshark for Windows 8?
winpcap windows8 installasked 24 Jul &#39;12, 07:04
Andrew
16●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Still getting header checksum errors after disabling</title>
      <link>/questions/12958/still-getting-header-checksum-errors-after-disabling/</link>
      <pubDate>Tue, 24 Jul 2012 08:45:00 +0000</pubDate>
      
      <guid>/questions/12958/still-getting-header-checksum-errors-after-disabling/</guid>
      <description>Still getting header checksum errors after disabling  0 I understand why I was getting so many header checksum errors so I went to Edit &amp;gt; Preferences &amp;gt; Protocols and chose IPv4 as well as TCP and deselected &#39;Validate the IPv4 checksum if possible&#39;
I&#39;m still getting lots of header checksum errors, however. I would think they would be taken care of by making those setting changes.
Anyone have any ideas?</description>
    </item>
    
    <item>
      <title>Dump list of unique IP&amp;#x27;s</title>
      <link>/questions/12963/dump-list-of-unique-ips/</link>
      <pubDate>Tue, 24 Jul 2012 11:45:00 +0000</pubDate>
      
      <guid>/questions/12963/dump-list-of-unique-ips/</guid>
      <description>Dump list of unique IP&amp;rsquo;s  0 1Im getting ddos&#39;d by a large group of servers, large enough that sorting IP&#39;s human wise is too large but small enough that I&#39;d like to block all of them. My one second capture has each one hitting ~50-100 times and its consistently from these IP&#39;s (It&#39;s not from the same IP range)
Any way i could dump these into text?
ip dump textasked 24 Jul &#39;12, 11:45</description>
    </item>
    
    <item>
      <title>Why are packets from one TCP stream not being captured on Lenovo, but working on an HP?</title>
      <link>/questions/12984/why-are-packets-from-one-tcp-stream-not-being-captured-on-lenovo-but-working-on-an-hp/</link>
      <pubDate>Wed, 25 Jul 2012 05:00:00 +0000</pubDate>
      
      <guid>/questions/12984/why-are-packets-from-one-tcp-stream-not-being-captured-on-lenovo-but-working-on-an-hp/</guid>
      <description>Why are packets from one TCP stream not being captured on Lenovo, but working on an HP?  0 Hi, When using the same SPAN session OR when installing a hub between a local server and switch, Wireshark does not display packets from one remote server on a Lenovo T400 or an HP Elitebook 8460P, but it does display on a different model HP laptop. The missing packets are only from one remote server.</description>
    </item>
    
    <item>
      <title>IP filter from command line</title>
      <link>/questions/12988/ip-filter-from-command-line/</link>
      <pubDate>Wed, 25 Jul 2012 08:22:00 +0000</pubDate>
      
      <guid>/questions/12988/ip-filter-from-command-line/</guid>
      <description>IP filter from command line  0 Hi all , I am looking for a command that i can use to filter a particular IP . For example I just want to get info about 10.82.23.343 and store in file hello.cap , how will I go about doing that from command line [linux] ? FYI I have used the commands tshark -i 2 -p -w hello.cap to capture and it works but I want to know how do i filter on a particular IP address</description>
    </item>
    
    <item>
      <title>PCI NIC interferes with traffic, WireShark setup.</title>
      <link>/questions/12996/pci-nic-interferes-with-traffic-wireshark-setup/</link>
      <pubDate>Wed, 25 Jul 2012 11:37:00 +0000</pubDate>
      
      <guid>/questions/12996/pci-nic-interferes-with-traffic-wireshark-setup/</guid>
      <description>PCI NIC interferes with traffic, WireShark setup.  0 Hi,
We&#39;re currently having an issue with our WireShark set up any help would be appreciated . Details are below:
I currently have a x32bit Windows XP computer with the WireShark version 1.8.0 installed. We&#39;ve got port forwarding set up on the built in NIC and it does not have an IP address assigned. We also require the computer to be on the network so I added a PCI NIC which is connected to the network on a separate switch.</description>
    </item>
    
    <item>
      <title>Decoding ssl traffic</title>
      <link>/questions/13004/decoding-ssl-traffic/</link>
      <pubDate>Wed, 25 Jul 2012 14:54:00 +0000</pubDate>
      
      <guid>/questions/13004/decoding-ssl-traffic/</guid>
      <description>Decoding ssl traffic  0 I am new to wireshare. I am using wireshark 1.4.10. I am trying to capture traffic from a Smalltalk app to a mainframe. I have captured the traffic several times using a http port. Do to security risks the company has shut down the http port and I am trying to use the https port. I have capture the traffic on the https port several times, but I cannot get the decryption of the data to work.</description>
    </item>
    
    <item>
      <title>Windows 7 how to calculate window size in tcp</title>
      <link>/questions/13006/windows-7-how-to-calculate-window-size-in-tcp/</link>
      <pubDate>Wed, 25 Jul 2012 21:58:00 +0000</pubDate>
      
      <guid>/questions/13006/windows-7-how-to-calculate-window-size-in-tcp/</guid>
      <description>Windows 7 how to calculate window size in tcp  0 can some one plese explain how to calculate TCP window size in windows 7 .is it depend on the initial link quality or does it calculate dyamicaly depend on the link quality .what are the parameters used ?
syswan windows7 tcpThis question is marked &#34;community wiki&#34;.asked 25 Jul &#39;12, 21:58
gayandis
1●1●1●2
accept rate: 0%
 edited 25 Jul &#39;12, 22:16</description>
    </item>
    
    <item>
      <title>Can plugins be written to analyse an existing protocol&amp;#x27;s header more deeply?</title>
      <link>/questions/13007/can-plugins-be-written-to-analyse-an-existing-protocols-header-more-deeply/</link>
      <pubDate>Wed, 25 Jul 2012 22:06:00 +0000</pubDate>
      
      <guid>/questions/13007/can-plugins-be-written-to-analyse-an-existing-protocols-header-more-deeply/</guid>
      <description>Can plugins be written to analyse an existing protocol&amp;rsquo;s header more deeply?  0 Hi! I want to add a module to the wireshark source to extract more details from the Options field of the tcp header and display them. I found out elsewhere that I need to edit ip_tcp_opt structure of the ip_opts header file in the epan folder. However, I would prefer a plugin that does the the same.</description>
    </item>
    
    <item>
      <title>Remote Packet Capturing from command prompt</title>
      <link>/questions/13012/remote-packet-capturing-from-command-prompt/</link>
      <pubDate>Thu, 26 Jul 2012 03:09:00 +0000</pubDate>
      
      <guid>/questions/13012/remote-packet-capturing-from-command-prompt/</guid>
      <description>Remote Packet Capturing from command prompt  0 Hi everyone, I am a new user of wireshark. I want to know that how can i capture packets from a remote computer using commands from my command prompt. I am using windows xp 32-bit and the latest version of wireshark. Please mention the solution for both of windows and linux environment running on the remote computer.
Thanks.
wiresharkasked 26 Jul &#39;12, 03:09</description>
    </item>
    
    <item>
      <title>How to do repetive tasks.</title>
      <link>/questions/13013/how-to-do-repetive-tasks/</link>
      <pubDate>Thu, 26 Jul 2012 03:16:00 +0000</pubDate>
      
      <guid>/questions/13013/how-to-do-repetive-tasks/</guid>
      <description>How to do repetive tasks.  0 I have sample SS7 traces...and my aim is to find tcap abort send in response of alertSC to achieve same following is the procedure i follow.
1.Apply filter gsm_old.localValue == 64 this will filter out all alertSC packet. 2.Get tcap id from TCAP layer. 3.Apply filter tcap.tid == &amp;lt;id&amp;gt; 4.Check if this is abort packet or not.
Now my problem is there are n huge number of alertSC packets and i cant keep on doing this for every packet, is there any way to sort out the problem</description>
    </item>
    
    <item>
      <title>Decrypting ESP packets, verifying IPSec settings</title>
      <link>/questions/13022/decrypting-esp-packets-verifying-ipsec-settings/</link>
      <pubDate>Thu, 26 Jul 2012 09:01:00 +0000</pubDate>
      
      <guid>/questions/13022/decrypting-esp-packets-verifying-ipsec-settings/</guid>
      <description>Decrypting ESP packets, verifying IPSec settings  0 I&#39;m trying to decrypt ESP packets that I captured. I have a VPN setup using L2TP. I&#39;ve read the http://wiki.wireshark.org/ESP_Preferences page. However, I don&#39;t know how to verify all the fields required for a windows 7 Machine. For example the Encryption Algorithm, Authentication Algorithm, Encryption key ect. Any guidance would be greatly appreciated.
ipsec vpn algorithm l2tp espasked 26 Jul &#39;12, 09:01</description>
    </item>
    
    <item>
      <title>Filter multiple IPs</title>
      <link>/questions/13023/filter-multiple-ips/</link>
      <pubDate>Thu, 26 Jul 2012 09:04:00 +0000</pubDate>
      
      <guid>/questions/13023/filter-multiple-ips/</guid>
      <description>Filter multiple IPs  0 I want to filter IPs on a .cap file , I use the command ip.addr == 123.456.789 but this only filters out one IP , I was wondering if there was a way to filter out multiple IPs ? thanks
filter ip pcap tshark wiresharkasked 26 Jul &#39;12, 09:04
helloworld0722
10●7●7●9
accept rate: 0%
  
2 Answers:
  
3 ip.addr==x.x.x.x || ip.</description>
    </item>
    
    <item>
      <title>Does Wireshark Inform You of Malicious Packets While Scanning?</title>
      <link>/questions/13035/does-wireshark-inform-you-of-malicious-packets-while-scanning/</link>
      <pubDate>Thu, 26 Jul 2012 14:21:00 +0000</pubDate>
      
      <guid>/questions/13035/does-wireshark-inform-you-of-malicious-packets-while-scanning/</guid>
      <description>Does Wireshark Inform You of Malicious Packets While Scanning?  0 When you have malware infect your network, does Wireshark have any ways of detecting or telling you there are packets transmitting it?
I am still learning how WireShark works and all it&#39;s features. :)
Thanks, Eric
malwareasked 26 Jul &#39;12, 14:21
TechnoLion
6●1●1●3
accept rate: 0%
  
One Answer:
  
2 Wireshark is a packet analysis tool and as such will display all captured packets, but does nothing to specifically highlight malware packets.</description>
    </item>
    
    <item>
      <title>Unable to see Voip calls with Polycom phones</title>
      <link>/questions/13041/unable-to-see-voip-calls-with-polycom-phones/</link>
      <pubDate>Thu, 26 Jul 2012 16:42:00 +0000</pubDate>
      
      <guid>/questions/13041/unable-to-see-voip-calls-with-polycom-phones/</guid>
      <description>Unable to see Voip calls with Polycom phones  0 When I plug my PC into Polycom phones and try to analyze the data from the phones I&#39;m not able to see any data. No RTP stream, no Voip calls, nothing. When I plug my computer into a Cisco phone and analyze the data everything shows up perfectly, just not with the Soundpoint IP 430 and 330 Polycom phones we use.</description>
    </item>
    
    <item>
      <title>Plugin not loading</title>
      <link>/questions/13043/plugin-not-loading/</link>
      <pubDate>Thu, 26 Jul 2012 17:41:00 +0000</pubDate>
      
      <guid>/questions/13043/plugin-not-loading/</guid>
      <description>Plugin not loading  0 I&#39;m getting WAY more fun than just locating X11 on ML...
Couldn&amp;#39;t load module /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so: dlopen(/Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so, 10): Symbol not found: dissector_get_port_handle Referenced from: /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so Expected in: flat namespace in /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so&amp;lt;/p&amp;gt;pluginasked 26 Jul &#39;12, 17:41
IanJ
1●1●1●1
accept rate: 0%
 edited 26 Jul &#39;12, 19:20 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
1That problem is due to a plugin having been built against an older version of Wireshark that called that routine dissector_get_port_handle being run against a newer version of Wireshark that calls it dissector_get_uint_handle.</description>
    </item>
    
    <item>
      <title>vlan tag can&amp;#x27;t display in the detail panel</title>
      <link>/questions/13046/vlan-tag-cant-display-in-the-detail-panel/</link>
      <pubDate>Thu, 26 Jul 2012 20:38:00 +0000</pubDate>
      
      <guid>/questions/13046/vlan-tag-cant-display-in-the-detail-panel/</guid>
      <description>vlan tag can&amp;rsquo;t display in the detail panel  0 vlan tag can&#39;t display in the detail panel in this path,there is not have vlan :edit---preference---protocol so the vlan tag is contained in ethernet II i want the vlan tag can dispaly singlely in the detail panel like the old version. thanks!!
vlan tagasked 26 Jul &#39;12, 20:38
tufei
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark fails to start on Mountain Lion</title>
      <link>/questions/13047/wireshark-fails-to-start-on-mountain-lion/</link>
      <pubDate>Thu, 26 Jul 2012 21:07:00 +0000</pubDate>
      
      <guid>/questions/13047/wireshark-fails-to-start-on-mountain-lion/</guid>
      <description>Wireshark fails to start on Mountain Lion  0 I get the following when I try and run wireshark after running xquartz:
bash-3.2$ /Applications/Wireshark.app/Contents/MacOS/Wireshark dyld: Symbol not found: _iconv Referenced from: /usr/lib/libcups.2.dylib Expected in: /Applications/Wireshark.app/Contents/Resources/lib/libiconv.2.dylib in /usr/lib/libcups.2.dylib bash-3.2$
Any takers??
mountainlionasked 26 Jul &#39;12, 21:07
thebruge
1●1●1●1
accept rate: 0%
 converted 13 Sep &#39;12, 11:47 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
0What version of Wireshark is that?</description>
    </item>
    
    <item>
      <title>How can I set interesting_hfid and get the protocol ID list.</title>
      <link>/questions/13053/how-can-i-set-interesting_hfid-and-get-the-protocol-id-list/</link>
      <pubDate>Thu, 26 Jul 2012 23:08:00 +0000</pubDate>
      
      <guid>/questions/13053/how-can-i-set-interesting_hfid-and-get-the-protocol-id-list/</guid>
      <description>How can I set interesting_hfid and get the protocol ID list.  0 Hi everyone:
now I am reading the source code of wireshark 1.81 to develop a communication analysis tool and there are some questions
I am using libwireshark.dll to dissect and print the packet and I want to print those fields that I am interested in instead of the whole packet. In my plan, I want to keep a database linked the hfinfo and the pointer to field-info by its ID, where can I find those information?</description>
    </item>
    
    <item>
      <title>Capturing from multiple pipes</title>
      <link>/questions/13059/capturing-from-multiple-pipes/</link>
      <pubDate>Fri, 27 Jul 2012 00:52:00 +0000</pubDate>
      
      <guid>/questions/13059/capturing-from-multiple-pipes/</guid>
      <description>Capturing from multiple pipes  1 In our environment we do a lot of live traces on specific interface on a Linux server, and pipes the result back to our Windows PC where it is presented in wireshark. We use PLINK to open a SSH connection to the server and have the stream piped back:
plink.exe -ssh -pw somepassword [email protected] tcpdump -i eth4 -s 0 -w - | &#34;C:\Program Files\Wireshark\Wireshark.</description>
    </item>
    
    <item>
      <title>Tshark 1.0.3 Download</title>
      <link>/questions/13069/tshark-103-download/</link>
      <pubDate>Fri, 27 Jul 2012 02:41:00 +0000</pubDate>
      
      <guid>/questions/13069/tshark-103-download/</guid>
      <description>Tshark 1.0.3 Download  0 Hello all,
I am looking for tshark 1.0.3 Version for linux OS in wireshark.org download page.
I am not able to find it .
Please let me know where to find it and download.
It will be of utmost help.
Regards,
Shobana
tsharkasked 27 Jul &#39;12, 02:41
shobana
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Go to the Wireshark download area on SourceForge, choose the src directory and then look under the &#34;</description>
    </item>
    
    <item>
      <title>help please!!</title>
      <link>/questions/13072/help-please/</link>
      <pubDate>Fri, 27 Jul 2012 05:31:00 +0000</pubDate>
      
      <guid>/questions/13072/help-please/</guid>
      <description>help please!!  0 I used wireshark.... with no other programs running, in the capture window when i start.. my system is peppered with files... some of them say malformed packet.. On top of this, there is no way i can target a specific http ip to investigate with all of this other interference. Please help
problems helpasked 27 Jul &#39;12, 05:31
abert
1●1●1●1
accept rate: 0%
This is a Q&amp;amp;A site (see FAQ: http://ask.</description>
    </item>
    
    <item>
      <title>Customizing tick interval in IO Graph</title>
      <link>/questions/13084/customizing-tick-interval-in-io-graph/</link>
      <pubDate>Fri, 27 Jul 2012 17:02:00 +0000</pubDate>
      
      <guid>/questions/13084/customizing-tick-interval-in-io-graph/</guid>
      <description>Customizing tick interval in IO Graph  0 In IO Graph I would like to use tick interval value other than 0.001/0/0.01/0.1/1/10 second like 0.025 second. Is there an add-on somewhere that allows us to specify our own value or do I need to perhaps request that?
graph tick io intervalasked 27 Jul &#39;12, 17:02
ntwkeng
21●1●1●4
accept rate: 0%
  
One Answer:
  
2 Those values are hard-coded in io_stat.</description>
    </item>
    
    <item>
      <title>How do you decrypt The Encrypted Handshakes and Application Data.</title>
      <link>/questions/13090/how-do-you-decrypt-the-encrypted-handshakes-and-application-data/</link>
      <pubDate>Sat, 28 Jul 2012 04:56:00 +0000</pubDate>
      
      <guid>/questions/13090/how-do-you-decrypt-the-encrypted-handshakes-and-application-data/</guid>
      <description>How do you decrypt The Encrypted Handshakes and Application Data.  0 Hi folks,
I am trying to use wire shark to evaluate the security of my server. Specifically the SSL section. I have seen some documentation witch show wire shark decrypting The Encrypted Handshakes and Application Data from a 2 conversations between client and server. I Need to learn how to configure wire shark to be able to do this.</description>
    </item>
    
    <item>
      <title>How to get Statistics-&amp;gt;Conversation List--&amp;gt;TCP information in a text file?</title>
      <link>/questions/13096/how-to-get-statistics-conversation-list-tcp-information-in-a-text-file/</link>
      <pubDate>Sat, 28 Jul 2012 16:14:00 +0000</pubDate>
      
      <guid>/questions/13096/how-to-get-statistics-conversation-list-tcp-information-in-a-text-file/</guid>
      <description>How to get Statistics-&amp;gt;Conversation List&amp;ndash;&amp;gt;TCP information in a text file?  1 I want to feed the nice table that Statistics-&amp;gt;Conversation List--&amp;gt;TCP makes to a script. How to dump that table in a file?
statistics conversationlist tcpasked 28 Jul &#39;12, 16:14
oscarmeyer
16●1●1●2
accept rate: 0%
  
2 Answers:
  
1There is &#34;Copy&#34; button next at the bottom left in the same window. Click on Copy and paste it to a text file, then save it as CSV file.</description>
    </item>
    
    <item>
      <title>iPhone traffic visible but no Android traffic</title>
      <link>/questions/13107/iphone-traffic-visible-but-no-android-traffic/</link>
      <pubDate>Sun, 29 Jul 2012 19:02:00 +0000</pubDate>
      
      <guid>/questions/13107/iphone-traffic-visible-but-no-android-traffic/</guid>
      <description>iPhone traffic visible but no Android traffic  0 Hello!
I let Wireshark run on my Windows 7 computer. My computer is connected to the router and two mobile devices are also connected to the router by WLAN. I have no problems to see the network traffic from the iPhone but nothing is visible from the Android. Why?
Best regards Marc
android iphoneasked 29 Jul &#39;12, 19:02
Marcophono
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>how to export marked packets to pcap</title>
      <link>/questions/13108/how-to-export-marked-packets-to-pcap/</link>
      <pubDate>Mon, 30 Jul 2012 01:00:00 +0000</pubDate>
      
      <guid>/questions/13108/how-to-export-marked-packets-to-pcap/</guid>
      <description>how to export marked packets to pcap  0 If I have a large pcap file that was created with tcpdump and then I open it in Wireshark and using filters I find the frames I am interested in, then I want to export these frames to a new pcap file, but the Export File function doesn&#39;t allow to save as type &#39;pcap&#39;. Is this possible somehow?
exportasked 30 Jul &#39;12, 01:00</description>
    </item>
    
    <item>
      <title>How do I retrieve an http request payload as xml?</title>
      <link>/questions/13111/how-do-i-retrieve-an-http-request-payload-as-xml/</link>
      <pubDate>Mon, 30 Jul 2012 03:57:00 +0000</pubDate>
      
      <guid>/questions/13111/how-do-i-retrieve-an-http-request-payload-as-xml/</guid>
      <description>How do I retrieve an http request payload as xml?  0 I am unable to get the http request in xml format. The response it giving in both hexadecimal and xml format. I&#39;m firing the request from one linux server to another.
0090 74 3a 20 74 65 78 74 2f 68 74 6d 6c 2c 20 69 6d t: text/html, im 00a0 61 67 65 2f 67 69 66 2c 20 69 6d 61 67 65 2f 6a age/gif, image/j 00b0 70 65 67 2c 20 2a 2f 2a 3b 20 71 3d 2e 32 0d 0a peg, */*; q=.</description>
    </item>
    
    <item>
      <title>GUI of dumpcap</title>
      <link>/questions/13113/gui-of-dumpcap/</link>
      <pubDate>Mon, 30 Jul 2012 05:29:00 +0000</pubDate>
      
      <guid>/questions/13113/gui-of-dumpcap/</guid>
      <description>GUI of dumpcap  0 Hello everyone, dumpcap works for the remote capturing. Does it provides any GUI? If so,how?
I want to know that if i run dumpcap and store the packets in a file,it only shows the number of captured packets. Can we get the any output like running wireshark from command prompt?
Thanks.
gui rpcap dumpcapasked 30 Jul &#39;12, 05:29
baila
21●10●11●15
accept rate: 0%
 edited 01 Aug &#39;12, 03:54</description>
    </item>
    
    <item>
      <title>Insight Desktop (ISD) File Support</title>
      <link>/questions/13118/insight-desktop-isd-file-support/</link>
      <pubDate>Mon, 30 Jul 2012 09:31:00 +0000</pubDate>
      
      <guid>/questions/13118/insight-desktop-isd-file-support/</guid>
      <description>Insight Desktop (ISD) File Support  0 Wondering when support for the Insight Desktop (.isd) file type might be included in a formal release? While Insight provides its own interface, I would prefer to conduct some analysis with Wireshark.
Thank you, Jacob
insight desktopasked 30 Jul &#39;12, 09:31
qcjacobo
1●1●1●1
accept rate: 0%
May I ask:
What is &#34;Insight Desktop&#34;?Can you post the file format specs?(30 Jul &#39;12, 12:51) Kurt Knochner ♦</description>
    </item>
    
    <item>
      <title>mac crash with &amp;quot;Duplicate protocol name&amp;quot;</title>
      <link>/questions/13120/mac-crash-with-duplicate-protocol-name/</link>
      <pubDate>Mon, 30 Jul 2012 11:01:00 +0000</pubDate>
      
      <guid>/questions/13120/mac-crash-with-duplicate-protocol-name/</guid>
      <description>mac crash with &amp;ldquo;Duplicate protocol name&amp;rdquo;  1 On Mac OS X 10.6.8, WireShark 1.8.1 will crash with &#34;Duplicate protocol name&#34;:
$ wireshark 2012-07-30 11:54:01.134 defaults[766:903] The domain/default pair of (kCFPreferencesAnyApplication, AppleAquaColorVariant) does not exist 2012-07-30 11:54:01.143 defaults[767:903] The domain/default pair of (kCFPreferencesAnyApplication, AppleHighlightColor) does not exist (process:756): Gtk-WARNING **: Locale not supported by C library. Using the fallback &#39;C&#39; locale. Xlib: extension &amp;quot;RANDR&amp;quot; missing on display &amp;quot;/tmp/launch-LsbeDg/org.x:0&amp;quot;.
(wireshark-bin:756): Gtk-WARNING **: Unable to locate theme engine in module_path: &amp;quot;clearlooks&amp;quot;, 11:54:01 Err Duplicate protocol name &amp;quot;Coseventcomm Dissector Using GIOP API&amp;quot;!</description>
    </item>
    
    <item>
      <title>Filtering Initial Capture File</title>
      <link>/questions/13121/filtering-initial-capture-file/</link>
      <pubDate>Mon, 30 Jul 2012 11:04:00 +0000</pubDate>
      
      <guid>/questions/13121/filtering-initial-capture-file/</guid>
      <description>Filtering Initial Capture File  0 Hi, I&#39;m wanting to filter the initial capture file using the following expression &#34;(expert.message contains &#34;GET /Pages/Home.aspx&#34;) &amp;amp;&amp;amp; (ip.dst == x.x.x.x)&#34;. Unfortunately when I come to setup the capture file and apply the filter it won&#39;t accept the expression.
It would be much appreicated if you could point me in the right direction.
Thanks!!
capture-filterasked 30 Jul &#39;12, 11:04
Testsubjec
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark does not capture packets w/ payloads?</title>
      <link>/questions/13131/wireshark-does-not-capture-packets-w-payloads/</link>
      <pubDate>Mon, 30 Jul 2012 13:32:00 +0000</pubDate>
      
      <guid>/questions/13131/wireshark-does-not-capture-packets-w-payloads/</guid>
      <description>Wireshark does not capture packets w/ payloads?  0 I have a very strange issue with wireshark that I&#39;ve never seen before, and have been using Wireshark/Ethereal for some time now.
This issue only occurs on one particular server. I am able to run Wireshark without an issue and I can see the proper interface listed and capture from it. The window fills with both broadcast and unicast messages, both sourced from and destined for the interface from which I&#39;m capturing.</description>
    </item>
    
    <item>
      <title>TCP Retransmission Behavior</title>
      <link>/questions/13146/tcp-retransmission-behavior/</link>
      <pubDate>Mon, 30 Jul 2012 17:49:00 +0000</pubDate>
      
      <guid>/questions/13146/tcp-retransmission-behavior/</guid>
      <description>TCP Retransmission Behavior  0 I have uploaded a sample trace to: http://www.cloudshark.org/captures/b6c6ccb4d513
In this trace, which was just an FTP GET between two hosts and I pulled the cable on the client in the middle of the transfer, I have some questions as to TCP Retransmission behavior that hopefully someone can help me better understand.
Since cable was pulled in this example there was multiple successive packets dropped from server to client that ulitmatley did not get any ACK, so RTO fired.</description>
    </item>
    
    <item>
      <title>changing dictionary file location for wireshark!</title>
      <link>/questions/13148/changing-dictionary-file-location-for-wireshark/</link>
      <pubDate>Mon, 30 Jul 2012 22:43:00 +0000</pubDate>
      
      <guid>/questions/13148/changing-dictionary-file-location-for-wireshark/</guid>
      <description>changing dictionary file location for wireshark!  0 hello all,
i&#39;m using wireshark library for dissection of the network packets, so the question is how to change the default location of the all the dictionary files and preference files for the wireshark.(that it uses for the specific protocol, i.e. diameter, radius)
as i dont want to install wireshark, just using the library and dictionary , preference file,
thanks!
libwireshark dissection dictionary wiresharkasked 30 Jul &#39;12, 22:43</description>
    </item>
    
    <item>
      <title>Retrieving TIPC values in an encapsulated dissector</title>
      <link>/questions/13170/retrieving-tipc-values-in-an-encapsulated-dissector/</link>
      <pubDate>Tue, 31 Jul 2012 00:51:00 +0000</pubDate>
      
      <guid>/questions/13170/retrieving-tipc-values-in-an-encapsulated-dissector/</guid>
      <description>Retrieving TIPC values in an encapsulated dissector  0 I am trying to create a dissector for packets which use the TIPC encoding. The dissector will convert the destination port into a meaningful value by comparing against a table as well as doing some analysis on the data. This information would be presented as well as all the TIPC information. I currently have it so &#34;dissect_mydissect(tvbuff_t tvb, packet_info pinfo, proto_tree *tree)&#34;</description>
    </item>
    
    <item>
      <title>Wireshark on pppoe</title>
      <link>/questions/13175/wireshark-on-pppoe/</link>
      <pubDate>Tue, 31 Jul 2012 01:43:00 +0000</pubDate>
      
      <guid>/questions/13175/wireshark-on-pppoe/</guid>
      <description>Wireshark on pppoe  0 Hi everyone, I have just one network card in my PC (windows 7)and Wireshark displays the address 10.0.0.1 as its only address. I was asked to run the following(thanks Kurt for that) dumpcap -D -M ipconfig /all Following are the results... Can someone explain why don&#39;t I get a routable address in Wireshark display(though it captures the packets and displys them fine). Regards I. Lesher</description>
    </item>
    
    <item>
      <title>Delayed ack requirements for server</title>
      <link>/questions/13191/delayed-ack-requirements-for-server/</link>
      <pubDate>Tue, 31 Jul 2012 09:08:00 +0000</pubDate>
      
      <guid>/questions/13191/delayed-ack-requirements-for-server/</guid>
      <description>Delayed ack requirements for server  0 I have a NIC vendor that claims the server is not sending frames soon enough and the delayed ack from the client is timing out causing large latency.
I&#39;ve uploaded part of a conversation which shows the delayed acks. See trace:
http://www.cloudshark.org/captures/2d1653abbaeb
Frame 21 is an example where the delayed ack waits 200 ms before acking. Note this ack is to frame 19 which had the push bit set.</description>
    </item>
    
    <item>
      <title>winr openkey response, error unknown dos error</title>
      <link>/questions/13194/winr-openkey-response-error-unknown-dos-error/</link>
      <pubDate>Tue, 31 Jul 2012 12:55:00 +0000</pubDate>
      
      <guid>/questions/13194/winr-openkey-response-error-unknown-dos-error/</guid>
      <description>winr openkey response, error unknown dos error  0 I am getting tons of malformed packet errors with &#34; winr openkey response, error unknown dos error&#34; in the information before and below.
errorsasked 31 Jul &#39;12, 12:55
cyberseeds
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Perhaps they&#39;re not actually &#34;Windows Registry access&#34; protocol packets, and Wireshark is misidentifying them as such, trying to dissect them as such, and reporting errors (which would be errors if they were those packets, but wouldn&#39;t be if they&#39;re not).</description>
    </item>
    
    <item>
      <title>Not getting any data on WLAN</title>
      <link>/questions/13195/not-getting-any-data-on-wlan/</link>
      <pubDate>Tue, 31 Jul 2012 13:11:00 +0000</pubDate>
      
      <guid>/questions/13195/not-getting-any-data-on-wlan/</guid>
      <description>Not getting any data on WLAN  0 UPDATE: I&#39;m getting my Q51 ZigBee sniffer to show up, but not getting any packets. Need to know what I need to do to get the packets....
I am in need of desperate help. Trying to sniff out zigbee signals on the WLAN and can&#39;t pull it up on the interface. Also, nothing is showing up in 802.11. Please help!
zigbeeasked 31 Jul &#39;12, 13:11</description>
    </item>
    
    <item>
      <title>How to decode and display as ASCII?</title>
      <link>/questions/13198/how-to-decode-and-display-as-ascii/</link>
      <pubDate>Tue, 31 Jul 2012 14:13:00 +0000</pubDate>
      
      <guid>/questions/13198/how-to-decode-and-display-as-ascii/</guid>
      <description>How to decode and display as ASCII?  0 How would I edit my custom dissector to make it decode bytes and display them as ASCII rather than hex or dec or any of the standard formats?
decode dissector asciiasked 31 Jul &#39;12, 14:13
bball2601
16●5●6●7
accept rate: 50%
  
One Answer:
  
0ASCII is a standard format - use a field of type FT_STRING or FT_UINT_STRING or FT_STRINGZ, with an encoding of ENC_ASCII.</description>
    </item>
    
    <item>
      <title>Hi, I am new in analysing the network captures. Can any one help me guiding how to work on Wire shark</title>
      <link>/questions/13208/hi-i-am-new-in-analysing-the-network-captures-can-any-one-help-me-guiding-how-to-work-on-wire-shark/</link>
      <pubDate>Tue, 31 Jul 2012 23:14:00 +0000</pubDate>
      
      <guid>/questions/13208/hi-i-am-new-in-analysing-the-network-captures-can-any-one-help-me-guiding-how-to-work-on-wire-shark/</guid>
      <description>Hi, I am new in analysing the network captures. Can any one help me guiding how to work on Wire shark  0 Hi,
Can any one help me guiding how to work on Wire shark
helpasked 31 Jul &#39;12, 23:14
pavan1621
1●1●1●1
accept rate: 0%
  
One Answer:
  
0There are plenty of resources listed on the Wireshark website. I suggest you study them or enrole in a Wireshark University course.</description>
    </item>
    
    <item>
      <title>Writing a dissector for a non ethernet protocol - Which type of &amp;quot;dissector_add&amp;quot; should I use?</title>
      <link>/questions/13211/writing-a-dissector-for-a-non-ethernet-protocol-which-type-of-dissector_add-should-i-use/</link>
      <pubDate>Wed, 01 Aug 2012 00:41:00 +0000</pubDate>
      
      <guid>/questions/13211/writing-a-dissector-for-a-non-ethernet-protocol-which-type-of-dissector_add-should-i-use/</guid>
      <description>Writing a dissector for a non ethernet protocol - Which type of &amp;ldquo;dissector_add&amp;rdquo; should I use?  0 Hi all,
we have a complex protocol, which is not ethernet based (it has nothing to do with ethernet) and which consists of frames with timestamps.
In order to analyze and display the individual protocol parts, I would like to use Wireshark. What I have done so far:
I have written a converter, so that our frames are now inside a pcapng file.</description>
    </item>
    
    <item>
      <title>How do I use filter on the command line</title>
      <link>/questions/13212/how-do-i-use-filter-on-the-command-line/</link>
      <pubDate>Wed, 01 Aug 2012 01:52:00 +0000</pubDate>
      
      <guid>/questions/13212/how-do-i-use-filter-on-the-command-line/</guid>
      <description>How do I use filter on the command line  0 I am trying use filter like this. But it return error on -R options? It looks like it doesn&#39;t like brackets any clues how the syntax should be?
&#34;C:\Program files\Wireshark\wireshark&#34; -r &#34;2012-07-27_154856_10.36.1.210_4.pcap&#34; -R &#34;(ip.addr==x.x.x.x and gtp) || ( ranap.gTP_TEI == 0x000059ca or sctp.port==xxxxxx and (frame.time &amp;gt; &#34;Jul 27, 2012 16:36:00&#34; and frame.time &amp;lt; &#34;July 27, 2012 16:38:00&#34;))&#34;
line command filtersasked 01 Aug &#39;12, 01:52</description>
    </item>
    
    <item>
      <title>Remote packet capture on Remote Linux machine</title>
      <link>/questions/13217/remote-packet-capture-on-remote-linux-machine/</link>
      <pubDate>Wed, 01 Aug 2012 02:24:00 +0000</pubDate>
      
      <guid>/questions/13217/remote-packet-capture-on-remote-linux-machine/</guid>
      <description>Remote packet capture on Remote Linux machine  0 Hello all, I am trying to capture packets on a Remote Linux machine ( CentOS 6). I have already tried the instructions mentioned in the URL : http://www.winpcap.org/docs/docs_40_2/html/group__remote.html
I have run the command to start daemon on that Remote machine. But from my Local machine ( Windows XP), it shows the following error while trying to start the Remote Capture!
Can&#39;t get list of interfaces: Is the server properly installed on 192.</description>
    </item>
    
    <item>
      <title>Wireshark not capturing traffic on 64 bit linux (not capturing RLS and OHMPI Requets)</title>
      <link>/questions/13229/wireshark-not-capturing-traffic-on-64-bit-linux-not-capturing-rls-and-ohmpi-requets/</link>
      <pubDate>Wed, 01 Aug 2012 04:06:00 +0000</pubDate>
      
      <guid>/questions/13229/wireshark-not-capturing-traffic-on-64-bit-linux-not-capturing-rls-and-ohmpi-requets/</guid>
      <description>Wireshark not capturing traffic on 64 bit linux (not capturing RLS and OHMPI Requets)  0 Wireshark is capturing the traffic well on a 32 bit linux machine. Oracle service bus is installed on 32 bit linux machine and its capturing all the traffic well. But not in 64 bit.
12345asked 01 Aug &#39;12, 04:06
prasobh
1●2●2●2
accept rate: 0%
what is your
OS / OS version of the system running WiresharkWireshark version (wireshark -v)Are there</description>
    </item>
    
    <item>
      <title>How to apply display filter for a cap file and save it as seperate cap file with filtered data only by using Tshark..?</title>
      <link>/questions/13233/how-to-apply-display-filter-for-a-cap-file-and-save-it-as-seperate-cap-file-with-filtered-data-only-by-using-tshark/</link>
      <pubDate>Wed, 01 Aug 2012 04:42:00 +0000</pubDate>
      
      <guid>/questions/13233/how-to-apply-display-filter-for-a-cap-file-and-save-it-as-seperate-cap-file-with-filtered-data-only-by-using-tshark/</guid>
      <description>How to apply display filter for a cap file and save it as seperate cap file with filtered data only by using Tshark..?  0 Is there way to apply display filter for a cap file and save it as seperate cap file with filtered data only..? eg, 1.I have a cap file with full packets 2.Apply display filter to the first cap and save the filtered packets in to another cap file.</description>
    </item>
    
    <item>
      <title>wireshark command not found</title>
      <link>/questions/13243/wireshark-command-not-found/</link>
      <pubDate>Wed, 01 Aug 2012 07:02:00 +0000</pubDate>
      
      <guid>/questions/13243/wireshark-command-not-found/</guid>
      <description>wireshark command not found  0 Hi ,I am trying to install wireshark on CentOS 6 and get the following error - bash:wireshark command not found , i tried to uninstall rpm , run as sudo , but have had no luck . any suggestions ?
rpm wiresharkasked 01 Aug &#39;12, 07:02
helloworld0722
10●7●7●9
accept rate: 0%
  
One Answer:
  
2 I guess you installed just the package &#39;wireshark&#39;.</description>
    </item>
    
    <item>
      <title>Using Packets to Differentiate Between Protocols</title>
      <link>/questions/13265/using-packets-to-differentiate-between-protocols/</link>
      <pubDate>Wed, 01 Aug 2012 09:27:00 +0000</pubDate>
      
      <guid>/questions/13265/using-packets-to-differentiate-between-protocols/</guid>
      <description>Using Packets to Differentiate Between Protocols  0 Hi, I am new to Wireshark. I am hoping to identify and obtain information about the different protocols on the basis of the packet transfers.
To clarify further, I am hoping to differentiate between HTTP, FTP, IMAP and POP3 by analyzing the packets.
I am thinking of using Capture Filters to simplify my task. But I am not sure on to approach the problem.</description>
    </item>
    
    <item>
      <title>I am seeing lots of retransmission between two nodes in same subnet.</title>
      <link>/questions/13275/i-am-seeing-lots-of-retransmission-between-two-nodes-in-same-subnet/</link>
      <pubDate>Wed, 01 Aug 2012 09:58:00 +0000</pubDate>
      
      <guid>/questions/13275/i-am-seeing-lots-of-retransmission-between-two-nodes-in-same-subnet/</guid>
      <description>I am seeing lots of retransmission between two nodes in same subnet.  0 Dear Team,
I am new to TCP analysis, i am seeing lots of retransmission , i am unable to understand how come there are so many retransmission if they are in same sub nett.Other node is Application side and i suspect while submitting packet on SMPP (using TCP as transport layer ) there window size is giving 46, is the same reason we are seeing retransmission ?</description>
    </item>
    
    <item>
      <title>how do you resolve Wireshark 1.6.9 libxml2-2.dll error?</title>
      <link>/questions/13297/how-do-you-resolve-wireshark-169-libxml2-2dll-error/</link>
      <pubDate>Wed, 01 Aug 2012 12:23:00 +0000</pubDate>
      
      <guid>/questions/13297/how-do-you-resolve-wireshark-169-libxml2-2dll-error/</guid>
      <description>how do you resolve Wireshark 1.6.9 libxml2-2.dll error?  0 After installing Wireshark 1.6.9 and trying to launch, I get &#34;This application has failed to start because libxml2-2.dll was not found. Re-installing the application may fix this problem.&#34; A re-install does not resolve the issue. Re-installation of Wireshark 1.6.8 works fine.
libxml2-2.dllasked 01 Aug &#39;12, 12:23
Macktheknife
1●1●1●1
accept rate: 0%
  
One Answer:
  
1This is an issue in the 1.</description>
    </item>
    
    <item>
      <title>No packets are being detected on outgoing traffic</title>
      <link>/questions/13303/no-packets-are-being-detected-on-outgoing-traffic/</link>
      <pubDate>Wed, 01 Aug 2012 17:18:00 +0000</pubDate>
      
      <guid>/questions/13303/no-packets-are-being-detected-on-outgoing-traffic/</guid>
      <description>No packets are being detected on outgoing traffic  0 I have a device which is set to automatically report to an external site. This device also had a web interface that I can log into by navigating to its ip address. When I navigate to the device&#39;s IP address, it is lighting up wireshark, and there is lots of activity.
However, I detect no other packets. So if I don&#39;t go to the web interface and let wireshark sit there for a few hours, there are literally no packets detected with that ip address as the source.</description>
    </item>
    
    <item>
      <title>Mac OS X 10.6 Installation problem</title>
      <link>/questions/13305/mac-os-x-106-installation-problem/</link>
      <pubDate>Wed, 01 Aug 2012 19:22:00 +0000</pubDate>
      
      <guid>/questions/13305/mac-os-x-106-installation-problem/</guid>
      <description>Mac OS X 10.6 Installation problem  0 I previously had Wireshark 1.4.6 Intel 64 installed on Mac OS X 10.6. I installed Wireshark 1.8.1 Intel 64 over it by executing the installer package. The installation claimed to be successful. When I tried to launch it, I got the error message
Couldn&#39;t load module /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so: dlopen(/Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so, 10): Symbol not found: _dissector_get_port_handle Referenced from: /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so Expected in: flat namespace in /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so</description>
    </item>
    
    <item>
      <title>How to enable the tshark name resolution while exporting to csv from an already captured pcapng file</title>
      <link>/questions/13310/how-to-enable-the-tshark-name-resolution-while-exporting-to-csv-from-an-already-captured-pcapng-file/</link>
      <pubDate>Thu, 02 Aug 2012 02:56:00 +0000</pubDate>
      
      <guid>/questions/13310/how-to-enable-the-tshark-name-resolution-while-exporting-to-csv-from-an-already-captured-pcapng-file/</guid>
      <description>How to enable the tshark name resolution while exporting to csv from an already captured pcapng file  0 Hi, How to enable the tshark name resolution while exporting to a csv from an already captured pcapng file.. When export from wireshark UI i get the resolved src/dest ip...but when i try to do from tshark the name resolution is not working...is there anything i need to do to get the resolved names in the csv ?</description>
    </item>
    
    <item>
      <title>Operating System TCP &amp;amp; TCP protocol implementation</title>
      <link>/questions/13311/operating-system-tcp-tcp-protocol-implementation/</link>
      <pubDate>Thu, 02 Aug 2012 03:34:00 +0000</pubDate>
      
      <guid>/questions/13311/operating-system-tcp-tcp-protocol-implementation/</guid>
      <description>Operating System TCP &amp;amp; TCP protocol implementation  0 Hi All,
I have implemented TCP protocol (RFC 793). For testing it I am using Windows Sockets. From my TCP I am sending SYN packet(Connect). I can capture the syn packet in wireshark.. It seems that the server written using Win Socket does not receives any message. Does anyone knows why this is happening??
Wireshark displays checksum error. Even i could not fix this checksum error also.</description>
    </item>
    
    <item>
      <title>Error after adding Plugin: No protocol registrations found</title>
      <link>/questions/13315/error-after-adding-plugin-no-protocol-registrations-found/</link>
      <pubDate>Thu, 02 Aug 2012 06:27:00 +0000</pubDate>
      
      <guid>/questions/13315/error-after-adding-plugin-no-protocol-registrations-found/</guid>
      <description>Error after adding Plugin: No protocol registrations found  0 Hello. I&#39;m writing a postdissector plugin in C to look into the options field found in the tcp header. Unfortunately, the following error turns up when I try to build:
Making plugin.c (using python)
No protocol registrations found
NMAKE : fatal error U1077: &#39;C:\Python27\python.exe&#39; : return code &#39;0x1&#39;
Stop.
NMAKE : fatal error U1077: &#39;&#34;c:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\BIN\nmake.exe&#34;&#39; : return code &#39;0x2&#39;</description>
    </item>
    
    <item>
      <title>Wireshark 1.8.1 Intel 64.dmg on Lion completes but no app installed</title>
      <link>/questions/13316/wireshark-181-intel-64dmg-on-lion-completes-but-no-app-installed/</link>
      <pubDate>Thu, 02 Aug 2012 07:50:00 +0000</pubDate>
      
      <guid>/questions/13316/wireshark-181-intel-64dmg-on-lion-completes-but-no-app-installed/</guid>
      <description>Wireshark 1.8.1 Intel 64.dmg on Lion completes but no app installed  0 OS X Lion: I have an older version of Wireshark 1.2.1 which I installed in ~/Applicaitons/ and it still launches correctly. Today I decided to upgrade to the latest Wireshark 1.8.1 and although the installer says it is successful, I noticed (a) it does not let me choose to install in my own ~/Applications folder and (b) there is no app installed to /Applications/Wireshark nor /Library/Wireshark.</description>
    </item>
    
    <item>
      <title>WhatsApp is now encrypted?</title>
      <link>/questions/13317/whatsapp-is-now-encrypted/</link>
      <pubDate>Thu, 02 Aug 2012 07:53:00 +0000</pubDate>
      
      <guid>/questions/13317/whatsapp-is-now-encrypted/</guid>
      <description>WhatsApp is now encrypted?  0 Hello,
just noticed that since the release of WhatsApp version 2.8.2-5222 (iPhone) I&#39;m no longer able to read my sniffed messages. Probably they added some kind of encryption or at least compression to the raw data. Does anyone have further informations?
encryption whatsapp compression wiresharkasked 02 Aug &#39;12, 07:53
tvfreak666
1●1●1●1
accept rate: 0%
if you post a capture file, we can check.
(02 Aug &#39;12, 12:02) Kurt Knochner ♦</description>
    </item>
    
    <item>
      <title>MMS packet&amp;#x27;s binary stream can not display correctly</title>
      <link>/questions/13320/mms-packets-binary-stream-can-not-display-correctly/</link>
      <pubDate>Thu, 02 Aug 2012 08:41:00 +0000</pubDate>
      
      <guid>/questions/13320/mms-packets-binary-stream-can-not-display-correctly/</guid>
      <description>MMS packet&amp;rsquo;s binary stream can not display correctly  0 On my PC，I found the reassembled MMS packet can not display in 1.8.0 and 1.8.1,please pay attention to this promble,thanks wish Wireshark become more and more powerful and useful
if any question,please emailto:[email protected]126.com
wrong 1.8.0asked 02 Aug &#39;12, 08:41
zxr
1●1●1●1
accept rate: 0%
 edited 02 Aug &#39;12, 16:43 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:</description>
    </item>
    
    <item>
      <title>Networking Issue or Wireshark</title>
      <link>/questions/13321/networking-issue-or-wireshark/</link>
      <pubDate>Thu, 02 Aug 2012 09:30:00 +0000</pubDate>
      
      <guid>/questions/13321/networking-issue-or-wireshark/</guid>
      <description>Networking Issue or Wireshark  0 All,
I recently inherited a large airport network and I&#39;m performing Wireshark analysis to get a feel of what is being transmitted. I&#39;m seeing a lot of Dup Acks, TCP Retransmits and Reassembling. The trace that I will post was between two computers performing a simple file transfer. The two computers are attached to the same Cisco switch, member of the same VLAN and in the same building.</description>
    </item>
    
    <item>
      <title>Cannot capture packets between two vmware virtual machines on the same host</title>
      <link>/questions/13332/cannot-capture-packets-between-two-vmware-virtual-machines-on-the-same-host/</link>
      <pubDate>Thu, 02 Aug 2012 19:45:00 +0000</pubDate>
      
      <guid>/questions/13332/cannot-capture-packets-between-two-vmware-virtual-machines-on-the-same-host/</guid>
      <description>Cannot capture packets between two vmware virtual machines on the same host  0 I set them both at bridged model. I tried NAT as well, still cannot get the packets between them. The capture interface I chose was the physical interface of the host.
Any ideas, thank u!
vmwareasked 02 Aug &#39;12, 19:45
Siyang
6●1●1●4
accept rate: 0%
 edited 04 Aug &#39;12, 04:27 
Kurt Knochner ♦
24.8k●10●39●237</description>
    </item>
    
    <item>
      <title>Windows 7 64 bit MSS issue with Wireshark Ver 1.8.1</title>
      <link>/questions/13341/windows-7-64-bit-mss-issue-with-wireshark-ver-181/</link>
      <pubDate>Fri, 03 Aug 2012 01:57:00 +0000</pubDate>
      
      <guid>/questions/13341/windows-7-64-bit-mss-issue-with-wireshark-ver-181/</guid>
      <description>Windows 7 64 bit MSS issue with Wireshark Ver 1.8.1  0 I have a MSS question with Wireshark Ver 1.8.1. When I check TCP syn packet,I can&#39;t see MSS value but Malformed Packet. When I install it back to Wiresahrk Ver 1.6.2,I can see the MSS value without problem... The MSS value in my test environment is 1460 bytes. I have enabled and disable large offload send but both not work.</description>
    </item>
    
    <item>
      <title>Extract VoIP audio AFTER started call</title>
      <link>/questions/13346/extract-voip-audio-after-started-call/</link>
      <pubDate>Fri, 03 Aug 2012 05:03:00 +0000</pubDate>
      
      <guid>/questions/13346/extract-voip-audio-after-started-call/</guid>
      <description>Extract VoIP audio AFTER started call  0 Excuse me for my not perfect english. I have recorded some Calls becouse my ISP and I have problems (tech).
But I cant extract any audio from VoIP calls. I have asked google, and I found the problem.
I must start Wireshark recording, then do any Call via VoIP. And I started a Call, then started Wireshark recording.
Have I any chance to get Audio from the Wireshark recordings with my fault?</description>
    </item>
    
    <item>
      <title>Catch information about an incoming call</title>
      <link>/questions/13351/catch-information-about-an-incoming-call/</link>
      <pubDate>Fri, 03 Aug 2012 07:42:00 +0000</pubDate>
      
      <guid>/questions/13351/catch-information-about-an-incoming-call/</guid>
      <description>Catch information about an incoming call  0 Hi guys, i&#39;m develoing a software for my business and one of the features is to identify the incoming call, search in data base and show client&#39;s information.
Well, we&#39;re using a NEC Aspire central with 4 RDSI lines. Yesterday I shutted down all pc&#39;s and capture all traffic with Wireshark while I called myself (mobile phone to NEC Aspire), but apparently no information was captured when I pick up, hang or call.</description>
    </item>
    
    <item>
      <title>[closed] Remote Packet Capture : Linux to Linux</title>
      <link>/questions/13352/remote-packet-capture-linux-to-linux/</link>
      <pubDate>Fri, 03 Aug 2012 07:44:00 +0000</pubDate>
      
      <guid>/questions/13352/remote-packet-capture-linux-to-linux/</guid>
      <description>[closed] Remote Packet Capture : Linux to Linux  0 Hello guys, I have a question. I have tried the Remote Packet Capture from Local Windows to a Remote Linux machine. But i can&#39;t do the same from a Local Linux machine. I have found the facts, like
In the help page of dumpcap ( i.e. the output of ./dumpcap -h) there is no option for Remote Capture ( like -A for authentication ).</description>
    </item>
    
    <item>
      <title>Interface crashed</title>
      <link>/questions/13356/interface-crashed/</link>
      <pubDate>Fri, 03 Aug 2012 09:18:00 +0000</pubDate>
      
      <guid>/questions/13356/interface-crashed/</guid>
      <description>Interface crashed  0 while trying to capture packets that I was sending from another machine, I got a message saying that wireshark has crashed. Now I am not able to capture the packets that I am sending from the other machine. Does anyone have any idea why?
wireshark_crashedasked 03 Aug &#39;12, 09:18
Noob
1●2●2●2
accept rate: 0%
  
One Answer:
  
0It probably crashed because you were capturing too much data for Wireshark to handle.</description>
    </item>
    
    <item>
      <title>MPEG2 I, P, B frames</title>
      <link>/questions/13370/mpeg2-i-p-b-frames/</link>
      <pubDate>Sun, 05 Aug 2012 09:36:00 +0000</pubDate>
      
      <guid>/questions/13370/mpeg2-i-p-b-frames/</guid>
      <description>MPEG2 I, P, B frames  0 Hello,
I use VLC to stream MPEG2 video files in MPEG TS container through UDP over LAN. I have captured packets with Wireshark and I want to ask if there is any way to identify which frames are I, P, B?
Pcap files link: http://www.sendspace.com/filegroup/cuJsOSzuqIrxbGJOQolg1g
mpeg2 frameasked 05 Aug &#39;12, 09:36
MiniComa
1●1●1●2
accept rate: 0%
 edited 06 Aug &#39;12, 10:41</description>
    </item>
    
    <item>
      <title>Can Wireshark sniff a network interface in a Solaris Zone?</title>
      <link>/questions/13371/can-wireshark-sniff-a-network-interface-in-a-solaris-zone/</link>
      <pubDate>Sun, 05 Aug 2012 12:16:00 +0000</pubDate>
      
      <guid>/questions/13371/can-wireshark-sniff-a-network-interface-in-a-solaris-zone/</guid>
      <description>Can Wireshark sniff a network interface in a Solaris Zone?  0 Need to sniff packets in a Solaris Zone.
Thanks in advance.
solaris zoneasked 05 Aug &#39;12, 12:16
Joe98765432s1
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0I haven&#39;t tried it (and I don&#39;t have a zone&#39;d system to try it on), but I don&#39;t see why it would not work. I&#39;d suggest giving it a try.</description>
    </item>
    
    <item>
      <title>What is wrong with the following tcp postdissector registration?</title>
      <link>/questions/13379/what-is-wrong-with-the-following-tcp-postdissector-registration/</link>
      <pubDate>Sun, 05 Aug 2012 23:54:00 +0000</pubDate>
      
      <guid>/questions/13379/what-is-wrong-with-the-following-tcp-postdissector-registration/</guid>
      <description>What is wrong with the following tcp postdissector registration?  0 My module is a postdissector for tcp packets that needs to be called sometime after the tcp dissector has done its bit. My proto_register_foo() and proto_reg_handoff_foo() functions are as given below:
void
proto_register_foo(void)
{
static hf_register_info hf[] = {
...
};
static gint *ett[] = { ...
};
proto_foo = proto_register_protocol(&amp;quot;Foo Protocol&amp;quot;, &amp;quot;FOO&amp;quot;, &amp;quot;foo&amp;quot;); register_dissector(&amp;quot;foo&amp;quot;, dissect_foo, proto_foo); proto_register_field_array(proto_foo, hf, array_length(hf)); proto_register_subtree_array(ett, array_length(ett));}</description>
    </item>
    
    <item>
      <title>Using dumpcap without installing Wireshark</title>
      <link>/questions/13381/using-dumpcap-without-installing-wireshark/</link>
      <pubDate>Mon, 06 Aug 2012 01:04:00 +0000</pubDate>
      
      <guid>/questions/13381/using-dumpcap-without-installing-wireshark/</guid>
      <description>Using dumpcap without installing Wireshark  0 I learned here about the utility DumpCap to get the right ip on which Wireshark is actually captures(the syntax is DumpCap -D -M, thanks Kurt). I want to deploy it inside my open source application but if there is a better alternative I&#39;d be very happy, since it demands to deploy all the dll&#39;s that come with Wireshark(Wireshark itself is not deployed but WinPcap does) Can someone direct me regarding and alternative?</description>
    </item>
    
    <item>
      <title>Spam port 25</title>
      <link>/questions/13383/spam-port-25/</link>
      <pubDate>Mon, 06 Aug 2012 02:02:00 +0000</pubDate>
      
      <guid>/questions/13383/spam-port-25/</guid>
      <description>Spam port 25  0 Can someone explain me in detailed how can i setup wireshark to locate which ip address of our network is causing problem to port 25
port25 virus spamasked 06 Aug &#39;12, 02:02
kosman
1●1●1●1
accept rate: 0%
  
One Answer:
  
0By &#34;problem&#34;, you mean spam, right?
O.K. you need to capture the traffic &#34;in front&#34; of your internet access router. Please take a look at the Capture Setup to learn how to do that.</description>
    </item>
    
    <item>
      <title>Display HTTP Header</title>
      <link>/questions/13384/display-http-header/</link>
      <pubDate>Mon, 06 Aug 2012 02:28:00 +0000</pubDate>
      
      <guid>/questions/13384/display-http-header/</guid>
      <description>Display HTTP Header  0 Hello.
I am using WireShark on the Windows 7 platform.
I was wondering if someone could tell me the settings I should use in my WireShark to log the full HTTP header for any traces I run in the program?
Many thanks in advance. DC.
header http log address. ipasked 06 Aug &#39;12, 02:28
DustinCook
21●2●2●5
accept rate: 0%
Can I also setup WireShark to detect if a web-based proxy site is being used?</description>
    </item>
    
    <item>
      <title>Can we call a dissector plugin from another dissector plugin?</title>
      <link>/questions/13387/can-we-call-a-dissector-plugin-from-another-dissector-plugin/</link>
      <pubDate>Mon, 06 Aug 2012 05:09:00 +0000</pubDate>
      
      <guid>/questions/13387/can-we-call-a-dissector-plugin-from-another-dissector-plugin/</guid>
      <description>Can we call a dissector plugin from another dissector plugin?  0 Folks,
As per my requirements i will have to dissect eth header for all packets of my relevant protocol. So i was wondering if we have such functionality , i may write another plugin for eth and call it from my protocol plugin.
dissector wiresharkasked 06 Aug &#39;12, 05:09
yogeshg
41●22●23●26
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How should I set up a new PC for Wireshark?</title>
      <link>/questions/13395/how-should-i-set-up-a-new-pc-for-wireshark/</link>
      <pubDate>Mon, 06 Aug 2012 06:25:00 +0000</pubDate>
      
      <guid>/questions/13395/how-should-i-set-up-a-new-pc-for-wireshark/</guid>
      <description>How should I set up a new PC for Wireshark?  0 We are replacing Distributed Sniffers with PC&#39;s running Wireshark. I&#39;m used to a 2 NIC scenerio- one to do the monitoring and one for communications. As we will be running these boxes remotely, are 2 NIC&#39;s needed/reccomended/not needed?
Thanks.
remote-monitoring sniffer configasked 06 Aug &#39;12, 06:25
SteveBrady
6●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>What is the meaning of this error?</title>
      <link>/questions/13401/what-is-the-meaning-of-this-error/</link>
      <pubDate>Mon, 06 Aug 2012 13:19:00 +0000</pubDate>
      
      <guid>/questions/13401/what-is-the-meaning-of-this-error/</guid>
      <description>What is the meaning of this error?  0 &amp;quot;\Device\NPF_{12D8C25E-1599-4276-A1DD-C37CE0539DE8}&amp;quot; is the proper interface.What does this mean?
npf errorThis question is marked &#34;community wiki&#34;.asked 06 Aug &#39;12, 13:19
RadioRebel
1●1●1●1
accept rate: 0%
 edited 06 Aug &#39;12, 13:55 
multipleinte...
1.3k●15●23●40
  
One Answer:
  
0That information is displayed by dumpcap, if you specify the wrong interface for option -i. The full error message is this:</description>
    </item>
    
    <item>
      <title>Alternate display for Packet List Pane</title>
      <link>/questions/13402/alternate-display-for-packet-list-pane/</link>
      <pubDate>Mon, 06 Aug 2012 14:09:00 +0000</pubDate>
      
      <guid>/questions/13402/alternate-display-for-packet-list-pane/</guid>
      <description>Alternate display for Packet List Pane  1 For the situation whereby multiple payload messages are in a single TCP/UDP packet, it would be nice to be able to display the Info for each payload on adjacent rows of the Packet List Pane.
What would be the appropriate API calls to display the Info in any of the following formats within a custom dissector plug-in code?
e.g. – Currently, my dissector performs the correction dissection on both messages, but I’m having to display the information for both messages on the same row within the “Info” column</description>
    </item>
    
    <item>
      <title>TShark: Capture and Display Filters for HTTP/HTTPS</title>
      <link>/questions/13408/tshark-capture-and-display-filters-for-httphttps/</link>
      <pubDate>Mon, 06 Aug 2012 17:27:00 +0000</pubDate>
      
      <guid>/questions/13408/tshark-capture-and-display-filters-for-httphttps/</guid>
      <description>TShark: Capture and Display Filters for HTTP/HTTPS  0 I am running CentOS v5.8 64bit. What are the correct capture and display filters to use in TShark to monitor and trace HTTP/HTTPS traffic similar to what is provided by HTTPWatch?
Also, what is the safest value to use for snaplen if I only want the following information below:
NumberTimeAbsolute Date and TimeSource IP AddressSource FQDNSource PortDestination IP AddressDestination FQDNDestination PortProtocolURLThank you in advance.</description>
    </item>
    
    <item>
      <title>Is it possible to prepare a filter for TCPDUMP command in Linux Servers</title>
      <link>/questions/13414/is-it-possible-to-prepare-a-filter-for-tcpdump-command-in-linux-servers/</link>
      <pubDate>Mon, 06 Aug 2012 23:14:00 +0000</pubDate>
      
      <guid>/questions/13414/is-it-possible-to-prepare-a-filter-for-tcpdump-command-in-linux-servers/</guid>
      <description>Is it possible to prepare a filter for TCPDUMP command in Linux Servers  0 Dear Team,
We have Linux OS installed on one of our nodes (which has SS7 stack) now if we want to filter packets which are submit towards network we use below command to do.
tcpdump -ni any sctp s0 -w filename.pcap
Now above command captures the all packets of ss7 layer, is it possible to prepare a filter on command line itself like ((gsm_sms.</description>
    </item>
    
    <item>
      <title>wireshark gui freezes upon loading logfile</title>
      <link>/questions/13416/wireshark-gui-freezes-upon-loading-logfile/</link>
      <pubDate>Mon, 06 Aug 2012 23:33:00 +0000</pubDate>
      
      <guid>/questions/13416/wireshark-gui-freezes-upon-loading-logfile/</guid>
      <description>wireshark gui freezes upon loading logfile  0 I am having difficulty opening a series of files created by tshark.exe. It is rather large, but I have opened large files before without a problem. The loading is even done in a separate thread so I can see the progress of it in the GUI.
This is the info from capsinfos.exe about the file in question:
File type: Wireshark - pcapng File encapsulation: Ethernet Packet size limit: file hdr: (not set) Number of packets: 907544 File size: 146040212 bytes Data size: 115427911 bytes Capture duration: 86397 seconds Start time: Sat Aug 04 22:07:38 2012 End time: Sun Aug 05 22:07:35 2012 Data byte rate: 1336.</description>
    </item>
    
    <item>
      <title>Capture filter</title>
      <link>/questions/13417/capture-filter/</link>
      <pubDate>Tue, 07 Aug 2012 00:41:00 +0000</pubDate>
      
      <guid>/questions/13417/capture-filter/</guid>
      <description>Capture filter  0 Hello.
How can i make capture filter for single protocol like Jabber fo example? I dont have certain ip or port, just protocol.
capture-filterasked 07 Aug &#39;12, 00:41
Pnk
6●2●2●5
accept rate: 0%
  
One Answer:
  
0You can&#39;t really. The capture filter engine is powerful at the lower level protocols (datalink up to transport layer) but not above. The application protocols you refer to are beyond its reach.</description>
    </item>
    
    <item>
      <title>Decoding the last bytes of a stream?</title>
      <link>/questions/13424/decoding-the-last-bytes-of-a-stream/</link>
      <pubDate>Tue, 07 Aug 2012 07:41:00 +0000</pubDate>
      
      <guid>/questions/13424/decoding-the-last-bytes-of-a-stream/</guid>
      <description>Decoding the last bytes of a stream?  0 I am making a dissector that calculates the remaining length of a stream, and decodes it in as many groups of 11 bytes as possible. However, whenever it decodes the last couple of bytes I get an error saying malformed packets.
This does not happen when the last possible 11 byte group ends and there are 6 or so bytes left over.</description>
    </item>
    
    <item>
      <title>streaming url</title>
      <link>/questions/13425/streaming-url/</link>
      <pubDate>Tue, 07 Aug 2012 07:51:00 +0000</pubDate>
      
      <guid>/questions/13425/streaming-url/</guid>
      <description>streaming url  0 Can one use wireshark to find the correct streaming url of a webradio, like http://www.chanson.ru/on-line.html? I would like to record their songs with audial one.
If one can find the url, how does one do it specifically (in detail please, I&#39;m a newbie here)?
Thanks in advance gfheiche
url streamingasked 07 Aug &#39;12, 07:51
gfheiche
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>View Capture with Color Rules</title>
      <link>/questions/13427/view-capture-with-color-rules/</link>
      <pubDate>Tue, 07 Aug 2012 08:12:00 +0000</pubDate>
      
      <guid>/questions/13427/view-capture-with-color-rules/</guid>
      <description>View Capture with Color Rules  0 I saved a capture and sent it on the colleagues, they are able to view it with the color rules. When I view the same capture file it does not show with color rules. What setting am I missing?
color-rules capture viewasked 07 Aug &#39;12, 08:12
mgwolf13
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Either you do not have color rules defined (you might have deleted them all) or your Wireshark is set to not colorize packets.</description>
    </item>
    
    <item>
      <title>how to packet capture for server with load balancing</title>
      <link>/questions/13432/how-to-packet-capture-for-server-with-load-balancing/</link>
      <pubDate>Tue, 07 Aug 2012 09:35:00 +0000</pubDate>
      
      <guid>/questions/13432/how-to-packet-capture-for-server-with-load-balancing/</guid>
      <description>how to packet capture for server with load balancing  0 I apologize if this question is too basic and obvious.
I want to do a packet capture on servers (OS type - Windows 2003, 2003R2, 2008, and 2008R2) with multiple NICs teamed together. The NICs might be teamed in a load balanced manner.
Would the only way to do an accurate capture require port spanning (or port mirroring) to capture all the packets to and from the server or can running wireshark on the server itself be able to get a complete capture from more than one interface?</description>
    </item>
    
    <item>
      <title>Why can&amp;#x27;t I open a large file?</title>
      <link>/questions/13433/why-cant-i-open-a-large-file/</link>
      <pubDate>Tue, 07 Aug 2012 10:37:00 +0000</pubDate>
      
      <guid>/questions/13433/why-cant-i-open-a-large-file/</guid>
      <description>Why can&amp;rsquo;t I open a large file?  0 I am using Wireshark version 1.8, newly installed. Wireshark is crashing when trying to open a 400MB file. It gets to roughly 47%, then dies.
I get a Microsoft Visual C++ Runtime library error.
crash errorasked 07 Aug &#39;12, 10:37
drumhrd
1●1●1●1
accept rate: 0%
 edited 07 Aug &#39;12, 14:02 
multipleinte...
1.3k●15●23●40
  
One Answer:</description>
    </item>
    
    <item>
      <title>Plot arrival time of UDP packets</title>
      <link>/questions/13441/plot-arrival-time-of-udp-packets/</link>
      <pubDate>Tue, 07 Aug 2012 13:18:00 +0000</pubDate>
      
      <guid>/questions/13441/plot-arrival-time-of-udp-packets/</guid>
      <description>Plot arrival time of UDP packets  0 My application should send a UDP packet every 16.7mS. I would like to see how much the arrival time varies. I want what &#34;Statistics-&amp;gt;TCP StreamGraph-&amp;gt;Stephens&#34; does for TCP except for UDP. I tried &#34;Statistics-&amp;gt;IO Graph&#34; but couldn&#39;t get it to do what I wanted.
Any hints? Thanks, Todd
arrival plot udp graph timeasked 07 Aug &#39;12, 13:18
sampsont
1●2●2●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Delay in client&amp;#x27;s response to 302 redirect</title>
      <link>/questions/13442/delay-in-clients-response-to-302-redirect/</link>
      <pubDate>Tue, 07 Aug 2012 15:21:00 +0000</pubDate>
      
      <guid>/questions/13442/delay-in-clients-response-to-302-redirect/</guid>
      <description>Delay in client&amp;rsquo;s response to 302 redirect  0 Hi All i am trying to figure out as to why the client after receiving 302 is delaying to close the connection and initiate new one for the url in Location header.
Basically the traffic to the Web App (via load balancer is as follows):
1) the client posts with a HTTP POST containing their login details
2) the server accepts that message, commits it, and responds to the client by sending a HTTP 302 redirect to a page called .</description>
    </item>
    
    <item>
      <title>issue with add_new_data_source() in trunk 1.8.0</title>
      <link>/questions/13446/issue-with-add_new_data_source-in-trunk-180/</link>
      <pubDate>Tue, 07 Aug 2012 18:38:00 +0000</pubDate>
      
      <guid>/questions/13446/issue-with-add_new_data_source-in-trunk-180/</guid>
      <description>issue with add_new_data_source() in trunk 1.8.0  0 When I try to add dissectors that is not octet-aligned, I found as long as add the following highlighted code the contents of &#34;Hex&#34; view is disappeared. Does anyone know if this is an existing known issue for trunk 1.8.0?
 ... next_tvb = tvb_new_octet_aligned(tvb, offset, tbs[i]); add_new_data_source(pinfo, next_tvb, &amp;quot;MyProt PDU&amp;quot;); // add this line of code the HEX view is disappeared call_dissector(my_handle, next_tvb, pinfo, tree);1.</description>
    </item>
    
    <item>
      <title>Server unable to access websites (HTTP or HTTPS) from a windows server</title>
      <link>/questions/13461/server-unable-to-access-websites-http-or-https-from-a-windows-server/</link>
      <pubDate>Wed, 08 Aug 2012 03:44:00 +0000</pubDate>
      
      <guid>/questions/13461/server-unable-to-access-websites-http-or-https-from-a-windows-server/</guid>
      <description>Server unable to access websites (HTTP or HTTPS) from a windows server  0 Scenario. The customer has a number of server and workstations all of which go out through the same gateway firewall. One of the server is unable to access the internet via HTTP or HTTPS. I&#39;ve tested different browsers and via telnet and I get the same results.
SSH, DNS and everything else I&#39;ve tried works fine, just HTTP and HTTPS which fail.</description>
    </item>
    
    <item>
      <title>IS it possible to create equations on wireshark filters</title>
      <link>/questions/13466/is-it-possible-to-create-equations-on-wireshark-filters/</link>
      <pubDate>Wed, 08 Aug 2012 05:41:00 +0000</pubDate>
      
      <guid>/questions/13466/is-it-possible-to-create-equations-on-wireshark-filters/</guid>
      <description>IS it possible to create equations on wireshark filters  0 I&#39;d like if it is possible to use wireshark filter to do equations. For example. If I have two fields with timestamps on a frame. Can I gete the difference between then, or add on to another? something like that? thanks in advance.
filter equation wiresharkasked 08 Aug &#39;12, 05:41
higorsilvacomh
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Hacking wifi router</title>
      <link>/questions/13467/hacking-wifi-router/</link>
      <pubDate>Wed, 08 Aug 2012 05:54:00 +0000</pubDate>
      
      <guid>/questions/13467/hacking-wifi-router/</guid>
      <description>Hacking wifi router  0 Im just a tech guy wondering whether is it possible to get the wifi router password which is secured with wpa2-psk with wireshark or any such other software after capturing pcap file on windows?
router hacking password wpa2asked 08 Aug &#39;12, 05:54
rulerofthehell
1●1●1●1
accept rate: 0%
  
One Answer:
  
0If you have the WPA2 key of the router AP you might be able to decode the password, if someone is accessing the router via telnet (or any other plain text protocol) over WIFI while you are capturing.</description>
    </item>
    
    <item>
      <title>Why Does 1.6.8 No Longer Populate RPCAP shortcuts?</title>
      <link>/questions/13475/why-does-168-no-longer-populate-rpcap-shortcuts/</link>
      <pubDate>Wed, 08 Aug 2012 10:10:00 +0000</pubDate>
      
      <guid>/questions/13475/why-does-168-no-longer-populate-rpcap-shortcuts/</guid>
      <description>Why Does 1.6.8 No Longer Populate RPCAP shortcuts?  0 We are running the latest version of wireshark on workstations at our office, version 1.6.8. We have remote captures that allow users to use rpcap to capture from an interface on another server. With previous versions, this would automatically populate the interface with the proper server and interface to allow ease of use. Since upgrading, the interface no longer gets automatically populated.</description>
    </item>
    
    <item>
      <title>Verifying Split Tunnel VPN</title>
      <link>/questions/13480/verifying-split-tunnel-vpn/</link>
      <pubDate>Wed, 08 Aug 2012 15:44:00 +0000</pubDate>
      
      <guid>/questions/13480/verifying-split-tunnel-vpn/</guid>
      <description>Verifying Split Tunnel VPN  0 I have a site-to-site VPN tunnel with a Cisco ASA connected to an Adtran Netvanta. We think split tunneling is configured properly, but it would be nice to know for sure. Looking for guidance on how to confirm this using Wireshark...if possible. Any assistance would be greatly appreciated!
vpnasked 08 Aug &#39;12, 15:44
sotelbrad
0●1●1●3
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>DLL not working with Wireshark 1.8.1</title>
      <link>/questions/13484/dll-not-working-with-wireshark-181/</link>
      <pubDate>Wed, 08 Aug 2012 23:00:00 +0000</pubDate>
      
      <guid>/questions/13484/dll-not-working-with-wireshark-181/</guid>
      <description>DLL not working with Wireshark 1.8.1  0 Hi,
I wrote a Wireshark Plugin on Wireshark 1.7.1 and compiled WS to generate a DLL. Now when I take this DLL and put this in Wireshark 1.8.1 I get an error saying msvcr90.dll is missing. In my Wireshark 1.8.1 installation, I checked and found that I have msvcr100.dll instead of msvcr90.dll.
Please help me fix this..!!
dll pluginsasked 08 Aug &#39;12, 23:00</description>
    </item>
    
    <item>
      <title>How do I prove that a downstream entity is the cause of TCP connection instability?</title>
      <link>/questions/13486/how-do-i-prove-that-a-downstream-entity-is-the-cause-of-tcp-connection-instability/</link>
      <pubDate>Thu, 09 Aug 2012 00:52:00 +0000</pubDate>
      
      <guid>/questions/13486/how-do-i-prove-that-a-downstream-entity-is-the-cause-of-tcp-connection-instability/</guid>
      <description>How do I prove that a downstream entity is the cause of TCP connection instability?  1 Hi Everyone
I am a wirshark n00b and in desperate need of help. We have a SMPP client on some our server and it is connecting to an SMSC. They chat backwards and forwards using SMPP which is just a protocol over TCP. Everything was working great until 1 August 2012 (very strange date for things to suddenly go pear shape).</description>
    </item>
    
    <item>
      <title>How and which version libprotobuf to install ?</title>
      <link>/questions/13490/how-and-which-version-libprotobuf-to-install/</link>
      <pubDate>Thu, 09 Aug 2012 02:14:00 +0000</pubDate>
      
      <guid>/questions/13490/how-and-which-version-libprotobuf-to-install/</guid>
      <description>How and which version libprotobuf to install ?  0 I intend to write protobuf dissector , for that i read in http://protobuf-wireshark.googlecode.com/files/README-runtime-v0.1.txt , that we have to install libprotobuf?
Step 2: Prepare Protocol BuffersWe assume that libprotobuf is installed in a well-known location.
How to go about it ? Please help
google protobuf wiresharkasked 09 Aug &#39;12, 02:14
yogeshg
41●22●23●26
accept rate: 0%
 edited 09 Aug &#39;12, 02:16</description>
    </item>
    
    <item>
      <title>bandwidth overload - lost packets</title>
      <link>/questions/13512/bandwidth-overload-lost-packets/</link>
      <pubDate>Thu, 09 Aug 2012 04:59:00 +0000</pubDate>
      
      <guid>/questions/13512/bandwidth-overload-lost-packets/</guid>
      <description>bandwidth overload - lost packets  0 Hello, Recently we had problem with one of our branch office - due to bandwidth overload we had 35% of lost packets to that site. We contacted our ISP and they told us that on our 2mbit leased line we were using 2.7 mbit of bandwidth. This only happens at 3pm when most of application contact it&#39;s servers over WAN.
I have used wireshark at exact time of WAN bandwidth overload and have captured a lot of packets.</description>
    </item>
    
    <item>
      <title>[closed] v1.8.1 capture options filter field</title>
      <link>/questions/13516/v181-capture-options-filter-field/</link>
      <pubDate>Thu, 09 Aug 2012 07:54:00 +0000</pubDate>
      
      <guid>/questions/13516/v181-capture-options-filter-field/</guid>
      <description>[closed] v1.8.1 capture options filter field  0 where has the capture options filter field gone? it isn&#39;t showing in my capture options dialog.
capture-options capture-filterasked 09 Aug &#39;12, 07:54
Mehuge
1●1●1●1
accept rate: 0%
 closed 09 Aug &#39;12, 08:14 
grahamb ♦
19.8k●3●30●206
 The question has been closed for the following reason &amp;ldquo;Duplicate Question&amp;rdquo; by grahamb 09 Aug &amp;lsquo;12, 08:14   
One Answer:</description>
    </item>
    
    <item>
      <title>How to read IOA-Adresses from IEC 60870-5-104?</title>
      <link>/questions/13520/how-to-read-ioa-adresses-from-iec-60870-5-104/</link>
      <pubDate>Thu, 09 Aug 2012 11:28:00 +0000</pubDate>
      
      <guid>/questions/13520/how-to-read-ioa-adresses-from-iec-60870-5-104/</guid>
      <description>How to read IOA-Adresses from IEC 60870-5-104?  0 Hi,
today i tried to log some IEC 60870-5-104 traffic and to read those log and to find some special data traffic, at all i was able to find ASDU1 and ASDU2 but wasnt able to make out IOA1, IOA2, IOA3? Sure i found IOA=123485 (for example) but since IOA value change from 1 to 12 (so it can be 12 - 34 or 12 -3-4), how can i read those values exactly?</description>
    </item>
    
    <item>
      <title>Data Source tab without hex?</title>
      <link>/questions/13531/data-source-tab-without-hex/</link>
      <pubDate>Fri, 10 Aug 2012 03:22:00 +0000</pubDate>
      
      <guid>/questions/13531/data-source-tab-without-hex/</guid>
      <description>Data Source tab without hex?  0 I can use the add_data_source function to add a tab with some data. However it always shows a hex view followed by an ascii view. Is it possible to open a tab that only shows the ascii without the hex being added?
data hex sourceasked 10 Aug &#39;12, 03:22
thesquiff
1●1●1●1
accept rate: 0%
  
One Answer:
  
0No. That&#39;s the way the packet bytes display works.</description>
    </item>
    
    <item>
      <title>How can I follow one conversation/session in a wireshark trace?</title>
      <link>/questions/13536/how-can-i-follow-one-conversationsession-in-a-wireshark-trace/</link>
      <pubDate>Fri, 10 Aug 2012 03:56:00 +0000</pubDate>
      
      <guid>/questions/13536/how-can-i-follow-one-conversationsession-in-a-wireshark-trace/</guid>
      <description>How can I follow one conversation/session in a wireshark trace?  0 Hi guys
I have trace that I am trying to analyze. It is a bit difficult because we open two connections to the same IP and Port within the same application. So there are two different sockets opening connections on two different threads. We have application logs but they are huge and to try and match up what was sent from the app logs with wireshark trace is quite difficult from each thread is quite difficult.</description>
    </item>
    
    <item>
      <title>EVRC payload type</title>
      <link>/questions/13545/evrc-payload-type/</link>
      <pubDate>Fri, 10 Aug 2012 08:29:00 +0000</pubDate>
      
      <guid>/questions/13545/evrc-payload-type/</guid>
      <description>EVRC payload type  0 Hi,
I would like to parse my EVRC-A / EVRC-B RTP packets (as per RFC3558 and RFC4788) into Windows Wireshark. Which RTP payload does it need to be parsed as EVRC? I went into preferences/EVRC but only found a check box to &#34;Add sissector for Legacy EVRC...&#34;. Is there a way to specify my EVRC payload type?
Thanks,
Mark
evrcasked 10 Aug &#39;12, 08:29
maboisv</description>
    </item>
    
    <item>
      <title>How can I convert pcapng to wav?</title>
      <link>/questions/13549/how-can-i-convert-pcapng-to-wav/</link>
      <pubDate>Fri, 10 Aug 2012 14:01:00 +0000</pubDate>
      
      <guid>/questions/13549/how-can-i-convert-pcapng-to-wav/</guid>
      <description>How can I convert pcapng to wav?  0 I have a pcapng file, and I want to convert it to .wav file. How can I do that?
Thank you!
pcapngasked 10 Aug &#39;12, 14:01
roubao
6●1●1●3
accept rate: 0%
  
One Answer:
  
2 You can&#39;t. A pcapng file is a container file for network packets, with packet headers and their payload. If you captured a wave file being transported inside the packets you could try to extract the payload to get the reassembled file.</description>
    </item>
    
    <item>
      <title>decoding scsi over usb</title>
      <link>/questions/13564/decoding-scsi-over-usb/</link>
      <pubDate>Sun, 12 Aug 2012 03:46:00 +0000</pubDate>
      
      <guid>/questions/13564/decoding-scsi-over-usb/</guid>
      <description>decoding scsi over usb  0 I am trying to analyse a conventional SCSI over USB stream (from a USB DVD drive, using Ubuntu 12.04). I have captured the trace using tcpdump, and Wireshark correctly displays the traffic at the USB command level, however in every case the SCSI payload is shown simply as &#39;leftover capture data&#39;. On inspection this data is clearly the wanted SCSI payload.
I have tried both the latest 1.</description>
    </item>
    
    <item>
      <title>Can we define multiple criteria for our dissector plugin to be called ?</title>
      <link>/questions/13566/can-we-define-multiple-criteria-for-our-dissector-plugin-to-be-called/</link>
      <pubDate>Sun, 12 Aug 2012 09:40:00 +0000</pubDate>
      
      <guid>/questions/13566/can-we-define-multiple-criteria-for-our-dissector-plugin-to-be-called/</guid>
      <description>Can we define multiple criteria for our dissector plugin to be called ?  0 I know that we have to give some criteria in proto_reg_handoff_PROTOABBREV function such as --
dissector_add(&#34;tcp.port&#34;, 3011, ns_nnm_msg_handle);
So here i want my dissector to be called also when tcp.port == 3008, so can i add just another line here such as --
dissector_add(&#34;tcp.port&#34;, 3008, ns_nnm_msg_handle);
Am i doing correct ? Any help is sincerely appreciated.</description>
    </item>
    
    <item>
      <title>wireshark shows desktop packets but not laptop packets</title>
      <link>/questions/13570/wireshark-shows-desktop-packets-but-not-laptop-packets/</link>
      <pubDate>Sun, 12 Aug 2012 22:44:00 +0000</pubDate>
      
      <guid>/questions/13570/wireshark-shows-desktop-packets-but-not-laptop-packets/</guid>
      <description>wireshark shows desktop packets but not laptop packets  0 Ok. I installed wireshark on my desktop unit. All good. I enter the WEP key into wireshark for decryption. I click on start. It shows packets - cool. Using internet explorer, I go to yahoo.com. Wireshark shows I went to yahoo.com. Pretty neat. Ok, I get on my laptop which connects to the wireless router (which, of course, is connected to the desktop).</description>
    </item>
    
    <item>
      <title>capture bridge SSL packet</title>
      <link>/questions/13573/capture-bridge-ssl-packet/</link>
      <pubDate>Mon, 13 Aug 2012 02:54:00 +0000</pubDate>
      
      <guid>/questions/13573/capture-bridge-ssl-packet/</guid>
      <description>capture bridge SSL packet  0 I use linux SSL server with non priviledged port in virtualbox. Virtualbox use bridge network. SSL client use a hub to connect to SSL server. I use wireshark to capture packet. But I didn&#39;t find any packet from linux or SSL client. Why? setting problem?
ssl openssl bridgeasked 13 Aug &#39;12, 02:54
eugene
1●1●1●2
accept rate: 0%
On which machine and on which interface where you making the capture?</description>
    </item>
    
    <item>
      <title>Header Checksum error (incorrect, should be ....)</title>
      <link>/questions/13577/header-checksum-error-incorrect-should-be/</link>
      <pubDate>Mon, 13 Aug 2012 04:09:00 +0000</pubDate>
      
      <guid>/questions/13577/header-checksum-error-incorrect-should-be/</guid>
      <description>Header Checksum error (incorrect, should be &amp;hellip;.)  0 Hi there,
It has been a while that I&#39;m experiencing some problems on my network, as I&#39;m not the network admin and I&#39;ve got from them the info that everything is OK on the network side I&#39;ll need your help to investigate what&#39;s going on.
I&#39;ve started the capture and most of the packets had the Checksum error, I&#39;ve deactivated this filter as per some other post recommendation to see what is left and I can see a couple of packets, when i go to detail window expand the Internet Protocal and the Header, it shows a red highlight on the Header and then on Bad:True, also says Header checksum: 0x0000 [incorrect, should be 0x822f], this 0x822f is replaced by many other numbers for the other packets.</description>
    </item>
    
    <item>
      <title>Can tvb_get_ntoh24 , tvb_get_guint8 take negative offset ?</title>
      <link>/questions/13578/can-tvb_get_ntoh24-tvb_get_guint8-take-negative-offset/</link>
      <pubDate>Mon, 13 Aug 2012 04:13:00 +0000</pubDate>
      
      <guid>/questions/13578/can-tvb_get_ntoh24-tvb_get_guint8-take-negative-offset/</guid>
      <description>Can tvb_get_ntoh24 , tvb_get_guint8 take negative offset ?  0 I may sound pretty novice but i just want to avoid any silly mistakes. Do these two functions work properly with negative offset ?
tvb_get_ntoh24 , tvb_get_guint8
Thanks in advance!!
plugin wiresharkasked 13 Aug &#39;12, 04:13
yogeshg
41●22●23●26
accept rate: 0%
  
One Answer:
  
0I believe so, both those functions, and most of the other tvb accessors, take a gint for offset where a negative value indicates bytes from the end of the buffer to start at.</description>
    </item>
    
    <item>
      <title>how to decode mef8 88d8 protocol</title>
      <link>/questions/13583/how-to-decode-mef8-88d8-protocol/</link>
      <pubDate>Mon, 13 Aug 2012 05:18:00 +0000</pubDate>
      
      <guid>/questions/13583/how-to-decode-mef8-88d8-protocol/</guid>
      <description>how to decode mef8 88d8 protocol  0 Hi I will appreciate help . I am using Version 1.8.1 (SVN Rev 43946 from /trunk-1.8). My packet stack is eth 88a8 8100 88d8. The application recognizes 88d8 as MEF 8 but the protocol is not decoded. I tried in several protocols enable: 1. All 2. Ethernet , Vlan, IEEE8021.D with several combination of the following a. Ethernet PW (CW heuristic) b. Ethernet PW (no CW) c.</description>
    </item>
    
    <item>
      <title>TOR Detection</title>
      <link>/questions/13590/tor-detection/</link>
      <pubDate>Mon, 13 Aug 2012 09:30:00 +0000</pubDate>
      
      <guid>/questions/13590/tor-detection/</guid>
      <description>TOR Detection  1 Hello.
Is there any way to determine from a basic Wireshaark trace if a TOR browser is being used?
There&#39;s the tell-tale signs of TCP and TLSv1 use, along with port 9001 and 9030.
But having completed some tests - I&#39;ve discovered this only worked once over 10 tests!!
Any help would be appreciated.
tor detectionasked 13 Aug &#39;12, 09:30
DustinCook
21●2●2●5
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Save as -&amp;gt; don&amp;#x27;t have &amp;quot;Packet Range frame&amp;quot;</title>
      <link>/questions/13591/save-as-dont-have-packet-range-frame/</link>
      <pubDate>Mon, 13 Aug 2012 10:26:00 +0000</pubDate>
      
      <guid>/questions/13591/save-as-dont-have-packet-range-frame/</guid>
      <description>Save as -&amp;gt; don&amp;rsquo;t have &amp;ldquo;Packet Range frame&amp;rdquo;  0 Hello, I downloaded last version - 1.8.1. And there are no &#34;Packet Range&#34; frame in window &#34;save as&#34;. It&#39;s some configuration option or some other reason for it?
save displayedasked 13 Aug &#39;12, 10:26
Viktor
1●1●1●2
accept rate: 0%
  
One Answer:
  
2This feature has been moved to the File-&amp;gt;Export Specified Packets menu item.
answered 13 Aug &#39;12, 10:47</description>
    </item>
    
    <item>
      <title>Is it possible to capture TCPDUMP logging and import into Wireshark?</title>
      <link>/questions/13593/is-it-possible-to-capture-tcpdump-logging-and-import-into-wireshark/</link>
      <pubDate>Mon, 13 Aug 2012 13:51:00 +0000</pubDate>
      
      <guid>/questions/13593/is-it-possible-to-capture-tcpdump-logging-and-import-into-wireshark/</guid>
      <description>Is it possible to capture TCPDUMP logging and import into Wireshark?  0 Hello,
Is it possible to capture tcpdump data from the screen (not a file) and then import into Wireshark? For example, I want to run the following tcpdump command:
./tcpdump -vvvvv -i eth0
Then I want to be able to import this into Wireshark (Window GuI version) for analysis.
Thanks in advance
tcpdumpasked 13 Aug &#39;12, 13:51</description>
    </item>
    
    <item>
      <title>Is there an easy way to update my own plugin?</title>
      <link>/questions/13594/is-there-an-easy-way-to-update-my-own-plugin/</link>
      <pubDate>Mon, 13 Aug 2012 14:51:00 +0000</pubDate>
      
      <guid>/questions/13594/is-there-an-easy-way-to-update-my-own-plugin/</guid>
      <description>Is there an easy way to update my own plugin?  0 I have previously developed a plugin. It works quite well, but now after installing the new version of Wireshark (1.8.1), it doesn&#39;t work anymore.
I think it is because it was built with version 1.7.0.
Is there an easy way to get it working on 1.8.1? Do I have to download the sources again, compile it, and than recompile my plugin?</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t view and write at the same time now?</title>
      <link>/questions/13595/cant-view-and-write-at-the-same-time-now/</link>
      <pubDate>Mon, 13 Aug 2012 14:57:00 +0000</pubDate>
      
      <guid>/questions/13595/cant-view-and-write-at-the-same-time-now/</guid>
      <description>Can&amp;rsquo;t view and write at the same time now?  0 Hello. I used to be able to to the following:
tshark -t ad -n -S -w bleh.pcap ip and host whatever
is there a way I can do this with the new version of tshark? Thank you.
James
and capture viewasked 13 Aug &#39;12, 14:57
DigiAngel
1●3●3●4
accept rate: 0%
  
One Answer:
  
1The -S option is now used for something else, you can use the -P option, see &#34;</description>
    </item>
    
    <item>
      <title>Unexpected TCP retransmissions</title>
      <link>/questions/13600/unexpected-tcp-retransmissions/</link>
      <pubDate>Mon, 13 Aug 2012 17:13:00 +0000</pubDate>
      
      <guid>/questions/13600/unexpected-tcp-retransmissions/</guid>
      <description>Unexpected TCP retransmissions  1 1I am trying to debug a network using wireshark. I have a few VMs running on virtualbox. One of the VM is connected to the host using a &#34;host only&#34; interface. The host runs OVS through which all the VMs communicate. I ran wireshark on one of the VMs and the corresponding port on OVS and I see a number of TCP retransmissions. What can cause this?</description>
    </item>
    
    <item>
      <title>Problem using proto_tree_free()</title>
      <link>/questions/13602/problem-using-proto_tree_free/</link>
      <pubDate>Tue, 14 Aug 2012 02:40:00 +0000</pubDate>
      
      <guid>/questions/13602/problem-using-proto_tree_free/</guid>
      <description>Problem using proto_tree_free()  0 I get a linker error when I try to free a subtree using the proto_tree_free() function in my dissector plugin:
error LNK2019: unresolved external symbol _proto_tree_free referenced in function _func
However I&#39;m able to call other functions declared in epan/proto.h such as proto_item_add_subtree(). Why the linker error?
lnk2019 errorasked 14 Aug &#39;12, 02:40
SidR
245●12●17●22
accept rate: 30%
 edited 14 Aug &#39;12, 02:41</description>
    </item>
    
    <item>
      <title>LLC/CDP flood</title>
      <link>/questions/13608/llccdp-flood/</link>
      <pubDate>Tue, 14 Aug 2012 04:23:00 +0000</pubDate>
      
      <guid>/questions/13608/llccdp-flood/</guid>
      <description>LLC/CDP flood  0 Hi,
I am seeing on my network a flood of LLC packets all seeming to come from the same MAC address (which is a mitel phone about 4 switches away from the capturing PC).
Even stranger it is now unpluged and I am still seeing the traffic!!
So I need some help in picking apart the wireshark log and tracking down where this data is coming from.</description>
    </item>
    
    <item>
      <title>problem decoding SIP TLS - only one side decoded</title>
      <link>/questions/13610/problem-decoding-sip-tls-only-one-side-decoded/</link>
      <pubDate>Tue, 14 Aug 2012 07:02:00 +0000</pubDate>
      
      <guid>/questions/13610/problem-decoding-sip-tls-only-one-side-decoded/</guid>
      <description>problem decoding SIP TLS - only one side decoded  0 Hi, I&#39;m having problem with decoding captured SIP TLS connection. I have the server private key. However, after configuring wireshark to decode packets I can see only one side of the connection (for example I can see REGISTER packet) but I can not see the response - it&#39;s ciphered. Can any one help me?
Here is a debug of such connection</description>
    </item>
    
    <item>
      <title>How can Wireshark indicate SSL Application Data as HTTP?</title>
      <link>/questions/13612/how-can-wireshark-indicate-ssl-application-data-as-http/</link>
      <pubDate>Tue, 14 Aug 2012 07:08:00 +0000</pubDate>
      
      <guid>/questions/13612/how-can-wireshark-indicate-ssl-application-data-as-http/</guid>
      <description>How can Wireshark indicate SSL Application Data as HTTP?  0 Hi all
I am analyzing a captured TLS/SSL session with Wireshark. Although I know that its a HTTPS session I wonder how Wireshark can indicate the Application Data as HTTP too. Every since the record structure for Application Data provides Content Type (23) and Application Data Length only!
Example: SSLv3 Record Layer: Application Data Protocol: http
Any help on this is very much appreciated!</description>
    </item>
    
    <item>
      <title>SOAP HTTP Calls are not recognized</title>
      <link>/questions/13614/soap-http-calls-are-not-recognized/</link>
      <pubDate>Tue, 14 Aug 2012 07:52:00 +0000</pubDate>
      
      <guid>/questions/13614/soap-http-calls-are-not-recognized/</guid>
      <description>SOAP HTTP Calls are not recognized  0 I&#39;m a newbe, so my question might be pretty trivial.
I have developed a SOAP client &amp;amp; am testing it by calling a remote server. When tracing with wire shark while issuing a call via SOAP-UI, all packages are only recognized by wireshark as &#39;TCP&#39;, not as HTTP or XML.
The result is that debugging is a nightmare, since I have to leave through all traffic to that destination and source IP address.</description>
    </item>
    
    <item>
      <title>Use tshark to search http gzip encoded</title>
      <link>/questions/13618/use-tshark-to-search-http-gzip-encoded/</link>
      <pubDate>Tue, 14 Aug 2012 10:22:00 +0000</pubDate>
      
      <guid>/questions/13618/use-tshark-to-search-http-gzip-encoded/</guid>
      <description>Use tshark to search http gzip encoded  0 So...topic says it. I&#39;m attempting to do something like ngrep (which for some reason isn&#39;t working on my pcaps). I&#39;m trying to search for an item in a gzip encoded pcap, but I&#39;m having a rough go of it. Here&#39;s what I&#39;ve tried:
tshark -o http.decompress_body:TRUE -r _test.pcap -R &#39;data-text-lines contains Commentary&#39;
But it&#39;s not seeming to fly. Any hints on how to look into an http body that&#39;s gzip&#39;ed with tshark?</description>
    </item>
    
    <item>
      <title>Capture Filter for DSCP 46</title>
      <link>/questions/13619/capture-filter-for-dscp-46/</link>
      <pubDate>Tue, 14 Aug 2012 10:26:00 +0000</pubDate>
      
      <guid>/questions/13619/capture-filter-for-dscp-46/</guid>
      <description>Capture Filter for DSCP 46  0 How do I apply a capture filter using version 1.8.0 And what capture filter would I use to capture packets marked with DSCP 46 (EF)
Thanks
filter capture efasked 14 Aug &#39;12, 10:26
VoIP Ready
1●2●2●2
accept rate: 0%
  
One Answer:
  
0You can use the following capture filter:
(ip[1] &amp;amp; 0xfc)&amp;gt;&amp;gt;2 = 46or if your traffic is vlan tagged:</description>
    </item>
    
    <item>
      <title>How decode a gzip url</title>
      <link>/questions/13622/how-decode-a-gzip-url/</link>
      <pubDate>Tue, 14 Aug 2012 11:03:00 +0000</pubDate>
      
      <guid>/questions/13622/how-decode-a-gzip-url/</guid>
      <description>How decode a gzip url  0 Hi,
I used wireshark to capture some traffic between a closed-program and a server.
The program request some URL with this format:
GET /m_back/page.php?a5bXBpYyBHYW1lcy0mYXBwdmVyc2lvxNzImcm5kdmFsPTEzNDQ4NTM2ODE= HTTP/1.1
Host: xxx.xxx.xxx.xxx
Connection: Keep-Alive
User-Agent: My User Agent
Accept-Encoding: gzip
Looks like the parameter is gzipped, but wireshark can not decoded it.
The answer from the server is coded with GZIP and wireshark can decoded it easily, I can see it under tab &#34;</description>
    </item>
    
    <item>
      <title>Duplicate IP addres from Sonicwall TZ-215</title>
      <link>/questions/13628/duplicate-ip-addres-from-sonicwall-tz-215/</link>
      <pubDate>Tue, 14 Aug 2012 11:57:00 +0000</pubDate>
      
      <guid>/questions/13628/duplicate-ip-addres-from-sonicwall-tz-215/</guid>
      <description>Duplicate IP addres from Sonicwall TZ-215  0 I have an Copper pipe which includes 60 usable Public IP Addresses.
Maybe 20 of them are actually in use; lets say 10.0.0.2 - 10.0.0.22 ( using local IPs for security )
I am currently getting intermittent connectivity on my network.
I assigned my laptop 10.0.0.2 and all other routers are assigned 10.0.0.x if x &amp;gt; 2 &amp;amp;&amp;amp; x &amp;lt;=22
I am pinging the HP1810 switch, 10.</description>
    </item>
    
    <item>
      <title>Raw Hex format of an http packet.</title>
      <link>/questions/13635/raw-hex-format-of-an-http-packet/</link>
      <pubDate>Tue, 14 Aug 2012 13:41:00 +0000</pubDate>
      
      <guid>/questions/13635/raw-hex-format-of-an-http-packet/</guid>
      <description>Raw Hex format of an http packet.  0 Can someone tell me how to look at a packet in raw form. I want to see the preamble and every octet after in binary or hex form. I want to look at the packet and find the destination ip adress,the payload length, the payload, etc.
For example I will go to google.com in my browser and then look at the raw response.</description>
    </item>
    
    <item>
      <title>Wireshark 1.8.x doesn&amp;#x27;t save decryption keys for wireless</title>
      <link>/questions/13647/wireshark-18x-doesnt-save-decryption-keys-for-wireless/</link>
      <pubDate>Wed, 15 Aug 2012 02:01:00 +0000</pubDate>
      
      <guid>/questions/13647/wireshark-18x-doesnt-save-decryption-keys-for-wireless/</guid>
      <description>Wireshark 1.8.x doesn&amp;rsquo;t save decryption keys for wireless  0 On several Windows 7 64-bit systems I&#39;m not able to save decryption keys for decrypting wireless packets. Normally I use the Decryption Keys button on the Wireless toolbar. Also the key management under Preferences -&amp;gt; Protocols -&amp;gt; IEEE 802.11 and the Decryption Keys Settings on the toolbar are not consistent. Does anyone else can confirm this problem?
Best Regards
decryption windows7asked 15 Aug &#39;12, 02:01</description>
    </item>
    
    <item>
      <title>There are no interfaces on which a capture can be done.</title>
      <link>/questions/13649/there-are-no-interfaces-on-which-a-capture-can-be-done/</link>
      <pubDate>Wed, 15 Aug 2012 03:11:00 +0000</pubDate>
      
      <guid>/questions/13649/there-are-no-interfaces-on-which-a-capture-can-be-done/</guid>
      <description>There are no interfaces on which a capture can be done.  1 I&#39;ve made all steps described in wiki.wireshark.org/CaptureSetup/CapturePrivileges, but I still get next error message
There are no interfaces on which a capture can be done.
Where I&#39;ve made a mistake?
$ groups dima lp wheel games video audio optical storage power wireshark users $ ls -l /usr/bin/dumpcap -rwxr-xr-- 1 root wireshark 77000 Jul 29 12:07 /usr/bin/dumpcap $ getcap /usr/bin/dumpcap /usr/bin/dumpcap = cap_net_admin,cap_net_raw+eipcaptureerror errorasked 15 Aug &#39;12, 03:11</description>
    </item>
    
    <item>
      <title>Proxy and Window scaling factor of 0</title>
      <link>/questions/13660/proxy-and-window-scaling-factor-of-0/</link>
      <pubDate>Wed, 15 Aug 2012 13:17:00 +0000</pubDate>
      
      <guid>/questions/13660/proxy-and-window-scaling-factor-of-0/</guid>
      <description>Proxy and Window scaling factor of 0  0 I was wondering if anyone had any advice for what i&#39;m seeing in our network.
I was looking at some captures and noticed that the window scale factor for anything coming back through the blue coat was a scale factor of 0. Which means I support it..but I wont scale.. That was just odd me to and I started to do some digging.</description>
    </item>
    
    <item>
      <title>Is there a capture filter for a MAC address range?</title>
      <link>/questions/13663/is-there-a-capture-filter-for-a-mac-address-range/</link>
      <pubDate>Wed, 15 Aug 2012 15:47:00 +0000</pubDate>
      
      <guid>/questions/13663/is-there-a-capture-filter-for-a-mac-address-range/</guid>
      <description>Is there a capture filter for a MAC address range?  0 I am using Wireshark 1.6.9 currently, but have no particular requirement to use that version and plan to upgrade at some point anyway. I know that I can filter on a specific Ethernet MAC address using the capture filter ether host 00:04:a3:00:00:00. Furthermore, I know I can filter on a particular IP subnet with ip net 10.0.0.0/24. Is there a similar capture filter syntax for Ethernet MAC addresses?</description>
    </item>
    
    <item>
      <title>Why does Wireshark 1.8.2 not work on OS X if I install it atop a pre-1.8 release?</title>
      <link>/questions/13664/why-does-wireshark-182-not-work-on-os-x-if-i-install-it-atop-a-pre-18-release/</link>
      <pubDate>Wed, 15 Aug 2012 16:35:00 +0000</pubDate>
      
      <guid>/questions/13664/why-does-wireshark-182-not-work-on-os-x-if-i-install-it-atop-a-pre-18-release/</guid>
      <description>Why does Wireshark 1.8.2 not work on OS X if I install it atop a pre-1.8 release?  0 I have installed 1.8.2 over a previous installation that worked before I upgraded to ML. I installed XQuartz. I rebooted. I browsed to XQuartz when OSX wanted to know what to use for X11. I ran by clicking Wireshark. This results in XQ being launched, but no WS. I tried launching WS in a terminal and got this set of messages.</description>
    </item>
    
    <item>
      <title>can otr be detected using wireshark?</title>
      <link>/questions/13671/can-otr-be-detected-using-wireshark/</link>
      <pubDate>Wed, 15 Aug 2012 23:21:00 +0000</pubDate>
      
      <guid>/questions/13671/can-otr-be-detected-using-wireshark/</guid>
      <description>can otr be detected using wireshark?  0 I&#39;m running spark on openfire server and communicating to another client using otr. Is it possible to detect this using wireshark?
otrasked 15 Aug &#39;12, 23:21
mv93
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Spark tries to use TLS by default and Openfire has TLS enabled by default, as optional parameter for the client connection (Admin Console -&amp;gt; Server -&amp;gt; Server Settings -&amp;gt; Security Settings -&amp;gt; Client Connection Security -&amp;gt; Custom -&amp;gt; TLS method).</description>
    </item>
    
    <item>
      <title>Packet Size</title>
      <link>/questions/13679/packet-size/</link>
      <pubDate>Thu, 16 Aug 2012 04:53:00 +0000</pubDate>
      
      <guid>/questions/13679/packet-size/</guid>
      <description>Packet Size  0 Hi Team
I want to Know what is the packet size of the packets captured in the wireshark trace. can you please also confirm is there any way to see the statical way to see how the packets on the Packet size basis.
Regards Ankit Jain
ankitasked 16 Aug &#39;12, 04:53
Ank1t Ja1n
1●1●1●1
accept rate: 0%
  
3 Answers:
  
0Sure, just go to Statistics -&amp;gt; Packet Length for a statistics on packet length in the current trace.</description>
    </item>
    
    <item>
      <title>error updating record: invalid key format</title>
      <link>/questions/13688/error-updating-record-invalid-key-format/</link>
      <pubDate>Thu, 16 Aug 2012 10:29:00 +0000</pubDate>
      
      <guid>/questions/13688/error-updating-record-invalid-key-format/</guid>
      <description>error updating record: invalid key format  0 I&#39;m trying to decrypt IEEE 802.11 wireless traffic and am using a NetGear router set to &#34;WPA-PSK [TKIP]&#34; with SSID: rasa and Pass:rasadesign. I&#39;m using Wireshark 1.8.1 (with X11) for Mac and I&#39;ve tried to enter the string created by Wireshark&#39;s PSK generator: 1e3d2784c2693c013d5e20f58371b5b25b92ae00389eaf7c525427dd28b2c3ef but all I get is an error: &#34;error updating record: invalid key format&#34;
I&#39;ve also tried wpa-pwd with the format &#34;</description>
    </item>
    
    <item>
      <title>error building wireshark rpm for cent os 6.2</title>
      <link>/questions/13693/error-building-wireshark-rpm-for-cent-os-62/</link>
      <pubDate>Thu, 16 Aug 2012 14:56:00 +0000</pubDate>
      
      <guid>/questions/13693/error-building-wireshark-rpm-for-cent-os-62/</guid>
      <description>error building wireshark rpm for cent os 6.2  0 Hi,
I am trying to build a rpm for my modified wireshark source code version 1.8.0rc2. is there any steps on website where I can loop up inorder to generate rpm package?
Regards, Kerol
rpm-package wiresharkasked 16 Aug &#39;12, 14:56
kerolkarper
1●2●2●4
accept rate: 0%
  
2 Answers:
  
0Currently I&#39;m aware of The Developers Guide as the only source of information on it.</description>
    </item>
    
    <item>
      <title>Capture packets sent to a specific IP</title>
      <link>/questions/13696/capture-packets-sent-to-a-specific-ip/</link>
      <pubDate>Thu, 16 Aug 2012 21:09:00 +0000</pubDate>
      
      <guid>/questions/13696/capture-packets-sent-to-a-specific-ip/</guid>
      <description>Capture packets sent to a specific IP  0 I am playing around with the wireshark for a while now, but I&#39;m still not sure if this is possible.
Is it possible to capture packets sent to a specific IP, not from my computer? Obviously outside of a local network, let&#39;s say www.google.com as a brutal example.
wiresharkasked 16 Aug &#39;12, 21:09
Trfvbg
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How can I show a string for a decoded value?</title>
      <link>/questions/13700/how-can-i-show-a-string-for-a-decoded-value/</link>
      <pubDate>Fri, 17 Aug 2012 05:37:00 +0000</pubDate>
      
      <guid>/questions/13700/how-can-i-show-a-string-for-a-decoded-value/</guid>
      <description>How can I show a string for a decoded value?  0 I am trying to have a dissector for my proprietary protocol. I have to decode Flags byte in my protocol as bit-string and I have done it with below code:
f.msg_flags = ProtoField.uint8(&amp;quot;MyProto.Flags&amp;quot;, &amp;quot;Flags&amp;quot;, base.HEX) f.msgver = ProtoField.uint8(&amp;quot;MyProto.msgver&amp;quot;, &amp;quot;Version&amp;quot;, base_DEC, nil, 0xE0) f.prototype = ProtoField.uint8(&amp;quot;MyProto.prototype&amp;quot;, &amp;quot;Protocol Type&amp;quot;, base.DEC, nil, 0x10) f.reserver = ProtoField.uint8(&amp;quot;MyProto.reserved&amp;quot;, &amp;quot;Reserved&amp;quot;, base.DEC, nil, 0x0E) local msg_flags = buffer (offset,1):bytes() subtree:add(f.</description>
    </item>
    
    <item>
      <title>Duplicate RTP packets</title>
      <link>/questions/13705/duplicate-rtp-packets/</link>
      <pubDate>Fri, 17 Aug 2012 07:32:00 +0000</pubDate>
      
      <guid>/questions/13705/duplicate-rtp-packets/</guid>
      <description>Duplicate RTP packets  0 I have a customer trace that is showing duplicate RTP packets (lost RTP packets shows a negative number). My span session on a Cisco 2940 is only spanning the interface, not the VLAN and is correct:-
monitor session 1 source interface fa0/1
monitor session 1 destination interface fa0/8 encaps dot1q
However, after taking the trace I found that both data &amp;amp; voice all use the same VLAN (OK poor network design).</description>
    </item>
    
    <item>
      <title>wireshark placement</title>
      <link>/questions/13706/wireshark-placement/</link>
      <pubDate>Fri, 17 Aug 2012 08:57:00 +0000</pubDate>
      
      <guid>/questions/13706/wireshark-placement/</guid>
      <description>wireshark placement  0 Ok, I am a newbie to wireshark and a little confused on what traffic wireshark captures depending on where it is. Okay, for example I am using wireshark on my desktop PC. I have the usual home network setup. &#34;modem connect to wireless router&#34; &amp;amp; &#34;desktop connected to wireless router&#34;. What traffic am I suppose to see? just the traffic coming in on my ethernet port through the switch?</description>
    </item>
    
    <item>
      <title>Writing a tshark filter through tcl</title>
      <link>/questions/13710/writing-a-tshark-filter-through-tcl/</link>
      <pubDate>Fri, 17 Aug 2012 13:07:00 +0000</pubDate>
      
      <guid>/questions/13710/writing-a-tshark-filter-through-tcl/</guid>
      <description>Writing a tshark filter through tcl  0 Hi,
I&#39;m facing an issue while writing a tshark filter expression through tcl -- where we write the expression using &#39;contains&#39;
For Eg. &#34;tshark -r $captureFile -qz io,stat,0, eth.src==$sourceMac&amp;amp;&amp;amp;isis.lsp.lspid contains &#39;ff&#39; &#34;
I am able to write expressions which do not contain any spaces and use the == operator but I&#39;m getting an error when trying to get the above expression working .</description>
    </item>
    
    <item>
      <title>Remote Packet capture in version 1.82</title>
      <link>/questions/13711/remote-packet-capture-in-version-182/</link>
      <pubDate>Fri, 17 Aug 2012 21:43:00 +0000</pubDate>
      
      <guid>/questions/13711/remote-packet-capture-in-version-182/</guid>
      <description>Remote Packet capture in version 1.82  0 Hi I used to use the remote packet capture. How do i set this up in the latest version of wireshark 1.82 ?
Best regards Lenny
remote-monitoringasked 17 Aug &#39;12, 21:43
Lenny_dk
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Hi I solved it.
answered 17 Aug &#39;12, 22:02
Lenny_dk
1●1●1●1
accept rate: 0%
Thanks for your insightful answer.</description>
    </item>
    
    <item>
      <title>Capture WLAN-traffic using Wireshark</title>
      <link>/questions/13713/capture-wlan-traffic-using-wireshark/</link>
      <pubDate>Sat, 18 Aug 2012 03:10:00 +0000</pubDate>
      
      <guid>/questions/13713/capture-wlan-traffic-using-wireshark/</guid>
      <description>Capture WLAN-traffic using Wireshark  0 I&#39;m trying to understand how to capture traffic on my WLAN(WPA2) using Wireshark. I can see the traffic going to and from my Backtrack-PC and Wireshark is able to decrypt it (using the WPA-password and the four EAPOL Key msg), but I can&#39;t see any traffic going from other clients on the network. If I deauth a client from my BT-PC I only get two EAPOL Key msg, 1/4 and 3/4, it&#39;s missing key 2/4 and 4/4.</description>
    </item>
    
    <item>
      <title>Wireshark packet analysis  resources</title>
      <link>/questions/13718/wireshark-packet-analysis-resources/</link>
      <pubDate>Sat, 18 Aug 2012 11:20:00 +0000</pubDate>
      
      <guid>/questions/13718/wireshark-packet-analysis-resources/</guid>
      <description>Wireshark packet analysis resources  0 Okay, I am just now learning how to use wireshark as an application, however when looking at the &#34;info&#34; section of the packet captures I don&#39;t fully understand what some of the information means. Is there a book or website I can reference to help me understand the packet/s analysis better? I understand the coloring rules and that they can help you determine the problem with most packets, but I was wondering if there is a good book or website out there to help you fully understand the packet/s info data?</description>
    </item>
    
    <item>
      <title>Decrypt SSL traffic problem because of DHE Cipher</title>
      <link>/questions/13721/decrypt-ssl-traffic-problem-because-of-dhe-cipher/</link>
      <pubDate>Sat, 18 Aug 2012 15:27:00 +0000</pubDate>
      
      <guid>/questions/13721/decrypt-ssl-traffic-problem-because-of-dhe-cipher/</guid>
      <description>Decrypt SSL traffic problem because of DHE Cipher  0 Decrypt SSL traffic problem because of DHE Cipher
Hi,
I read a lot about Wireshark and decrypting SSL using the private key. I read most of the post SYN-bit wrote, and saw his presentations he did @Sharkfest.
I just want to know, how can I create a SSL certificate without the DHE cipher in it? I went through lots of doc.</description>
    </item>
    
    <item>
      <title>How do we start analyzing TCP Traffic.</title>
      <link>/questions/13741/how-do-we-start-analyzing-tcp-traffic/</link>
      <pubDate>Sun, 19 Aug 2012 08:53:00 +0000</pubDate>
      
      <guid>/questions/13741/how-do-we-start-analyzing-tcp-traffic/</guid>
      <description>How do we start analyzing TCP Traffic.  0 Hi ,
I am often confused how do we start to analyze the TCP traffic, I have trace file attached.Can any one guide how do we start.I usually do .Analyze &amp;gt; Export Info Composite.
Here i See
TCP Out of OrderPrevious Segment LostFast Re transmission suspectedSo i do start.....Now IP : 10.45.56.8 is at our end....
I am very thankfull in advance for the Guidance given.</description>
    </item>
    
    <item>
      <title>1500 bytes over wan link of 1492 MTU. Is that possible?</title>
      <link>/questions/13751/1500-bytes-over-wan-link-of-1492-mtu-is-that-possible/</link>
      <pubDate>Mon, 20 Aug 2012 06:45:00 +0000</pubDate>
      
      <guid>/questions/13751/1500-bytes-over-wan-link-of-1492-mtu-is-that-possible/</guid>
      <description>1500 bytes over wan link of 1492 MTU. Is that possible?  0 Hi i have ppoe which allows 1492 bytes to pass through. This makes the mss go to 1452. I examined the packet and the IP header is 20 bytes the TCP header is 32 bytes and the data is 1448 which makes it in total 1500 bytes. Ive noticed that the tcp header is 32 beacause of a additonal 12 byte option value.</description>
    </item>
    
    <item>
      <title>Getting R6034 runtime error while opening any trace file</title>
      <link>/questions/13755/getting-r6034-runtime-error-while-opening-any-trace-file/</link>
      <pubDate>Mon, 20 Aug 2012 08:11:00 +0000</pubDate>
      
      <guid>/questions/13755/getting-r6034-runtime-error-while-opening-any-trace-file/</guid>
      <description>Getting R6034 runtime error while opening any trace file  0 Hi Folks,
I had made a dissector plugin some time back with VS 2008 and Wireshark 1.7.1.
It used to run fine with version-1.7.1 but same plugin gives me &#34;R6034 runtime error&#34; with Wireshark 1.8.2 ,which happens to be latest stable release.
Now i found this thread below , wherein it is mentioned that VS version should be same for plugin and executable.</description>
    </item>
    
    <item>
      <title>Capture Filters in Wireshark Version 1.8.2</title>
      <link>/questions/13756/capture-filters-in-wireshark-version-182/</link>
      <pubDate>Mon, 20 Aug 2012 08:22:00 +0000</pubDate>
      
      <guid>/questions/13756/capture-filters-in-wireshark-version-182/</guid>
      <description>Capture Filters in Wireshark Version 1.8.2  0 I downloaded version 1.8.2 last week to assist at a client site where we needed to look at some activity on the network. One issue i noticed was when I went to try to build a capture filter, and then apply it, under Capture&amp;gt;Options, there is no longer a place to pick the Capture Filter. In other words, the Capture Filter field seems to be gone.</description>
    </item>
    
    <item>
      <title>Number of open (active) connections</title>
      <link>/questions/13769/number-of-open-active-connections/</link>
      <pubDate>Mon, 20 Aug 2012 11:01:00 +0000</pubDate>
      
      <guid>/questions/13769/number-of-open-active-connections/</guid>
      <description>Number of open (active) connections  0 Hi all, Don&#39;t eat me alive please, I&#39;m a total noob to this area of computing. My ISP has informed me that his firewall resets a customer&#39;s broadband if the customer opens more than 30 connections. This is to prevent file-sharing causing contention issues apparently. My problem is that I have no idea how many connections the two PCs here at home have open (or active?</description>
    </item>
    
    <item>
      <title>name of boinc in gui</title>
      <link>/questions/13782/name-of-boinc-in-gui/</link>
      <pubDate>Mon, 20 Aug 2012 16:12:00 +0000</pubDate>
      
      <guid>/questions/13782/name-of-boinc-in-gui/</guid>
      <description>name of boinc in gui  0 I need to manage &#34;boinc&#34; under EDIT &amp;gt; PREFERENCE &amp;gt; PROTOCOLS and ANALYZE &amp;gt; ENABLED PROTOCOLS.
I can find nothing related to &#34;boinc&#34;, &#34;berkley open ...&#34;, etc.
Under what name does &#34;boinc&#34; appear in these two GUI functions?
Thanks,
David
boincasked 20 Aug &#39;12, 16:12
david8322
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Wireshark does not have a dissector for &#34;</description>
    </item>
    
    <item>
      <title>DG gryphon protocol</title>
      <link>/questions/13786/dg-gryphon-protocol/</link>
      <pubDate>Mon, 20 Aug 2012 19:35:00 +0000</pubDate>
      
      <guid>/questions/13786/dg-gryphon-protocol/</guid>
      <description>DG gryphon protocol  0 Hi. I&#39;m not an expert with Wireshark by any means.. but have come across DG Gryphon Protocol whilst capturing information. I can&#39;t find any information on Wireshark about this so I would very much appreciate it if anyone can give me some information on this. I have tried the FAQs etc and tried the user guide.. but nothing. Google gives a certain amount of information, but I&#39;d really like to hear from someone from Wireshark as to what this is.</description>
    </item>
    
    <item>
      <title>how can i sniff other IPs on the same network using WireSHARK on mac</title>
      <link>/questions/13787/how-can-i-sniff-other-ips-on-the-same-network-using-wireshark-on-mac/</link>
      <pubDate>Mon, 20 Aug 2012 20:23:00 +0000</pubDate>
      
      <guid>/questions/13787/how-can-i-sniff-other-ips-on-the-same-network-using-wireshark-on-mac/</guid>
      <description>how can i sniff other IPs on the same network using WireSHARK on mac  0 how can i sniff other IPs on the same network using WireSHARK on mac... i can see for example my mobile IP address in the interfaces but i can&#39;t start capturing the packets
macbookasked 20 Aug &#39;12, 20:23
Mazen
1●1●1●1
accept rate: 0%
  
3 Answers:
  
2Refer to the Wireshark Capture Setup wiki page.</description>
    </item>
    
    <item>
      <title>Incredibar problems</title>
      <link>/questions/13789/incredibar-problems/</link>
      <pubDate>Mon, 20 Aug 2012 22:06:00 +0000</pubDate>
      
      <guid>/questions/13789/incredibar-problems/</guid>
      <description>Incredibar problems  0 I&#39;ve been having a strange malware problem with something called the Incredibar. I&#39;ve been working with someone from Malwarebytes. We are still working on it but we haven&#39;t been able to solve it yet. Meanwhile, I heard about Wire Shark through a friend and wanted to see if it could be applied to this situation. I am running XP Home Edition on my computer for my OS.</description>
    </item>
    
    <item>
      <title>wireshark mountain lion</title>
      <link>/questions/13793/wireshark-mountain-lion/</link>
      <pubDate>Tue, 21 Aug 2012 09:59:00 +0000</pubDate>
      
      <guid>/questions/13793/wireshark-mountain-lion/</guid>
      <description>wireshark mountain lion  0 I just went through installing wireshark and xquartz on a new mountain lion install, and after pointing wireshark to the X11 directory, have been getting some weird gdk errors that prevent it from loading altogether.
I&#39;ll paste part of the log here in hopes that someone else has run through the same issue.
(wireshark-bin:1838): Gdk-CRITICAL **: gdk_window_set_icon_list: assertion `GDK_IS_PIXBUF (pixbuf)&#39; failed
(wireshark-bin:1838): GdkPixbuf-CRITICAL **: gdk_pixbuf_get_width: assertion `GDK_IS_PIXBUF (pixbuf)&#39; failed</description>
    </item>
    
    <item>
      <title>Where do you set capture filters in 1.8.2 ?</title>
      <link>/questions/13795/where-do-you-set-capture-filters-in-182/</link>
      <pubDate>Tue, 21 Aug 2012 11:39:00 +0000</pubDate>
      
      <guid>/questions/13795/where-do-you-set-capture-filters-in-182/</guid>
      <description>Where do you set capture filters in 1.8.2 ?  0 The Capture / Options dialog has changed. Now it shows the list of adapters ... but the place where you select a capture filter (or type in an new one) has disappeared. The Help file still shows the old dialog, so it&#39;s no help.
Where do you set a capture filter before starting a capture in 1.8.2 ?
filter capture optionsasked 21 Aug &#39;12, 11:39</description>
    </item>
    
    <item>
      <title>wireshark capture only my pc packets</title>
      <link>/questions/13799/wireshark-capture-only-my-pc-packets/</link>
      <pubDate>Tue, 21 Aug 2012 12:51:00 +0000</pubDate>
      
      <guid>/questions/13799/wireshark-capture-only-my-pc-packets/</guid>
      <description>wireshark capture only my pc packets  0 Hi, I have broadcom 4313 wirless adapter, I used wireshark but I can only see my packets how I can see pacekts of other pc&#39;s on my lan, I have windows 7 64bit.
wiresharkasked 21 Aug &#39;12, 12:51
mkarmi
6●1●1●3
accept rate: 0%
  
2 Answers:
  
1 By either running something other than Windows, by running something other than Wireshark, or by buying an AirPcap USB adapter.</description>
    </item>
    
    <item>
      <title>HOW TO capture linksys wrt320n to arris tm722 home network HTTP and other traffic</title>
      <link>/questions/13804/how-to-capture-linksys-wrt320n-to-arris-tm722-home-network-http-and-other-traffic/</link>
      <pubDate>Tue, 21 Aug 2012 17:54:00 +0000</pubDate>
      
      <guid>/questions/13804/how-to-capture-linksys-wrt320n-to-arris-tm722-home-network-http-and-other-traffic/</guid>
      <description>HOW TO capture linksys wrt320n to arris tm722 home network HTTP and other traffic  0 Hi WireShark community,
I am new to wireshark and network monitoring in general, but not new to software and computer technology. I&#39;m a software engineer with over 20 years experience, but have never dropped down this low in the weeds before.
My goal is to use WireShark to capture all outbound web traffic going between my linksys/cisco wrt320n router and the comcast arris tm722 cable modem.</description>
    </item>
    
    <item>
      <title>How do you make tshark read a ring buffer created by dumpcap?</title>
      <link>/questions/13808/how-do-you-make-tshark-read-a-ring-buffer-created-by-dumpcap/</link>
      <pubDate>Tue, 21 Aug 2012 22:57:00 +0000</pubDate>
      
      <guid>/questions/13808/how-do-you-make-tshark-read-a-ring-buffer-created-by-dumpcap/</guid>
      <description>How do you make tshark read a ring buffer created by dumpcap?  0 Greetings. I wish to use tshark to monitor an network interface. I understand that in do so, tshark executes dumpcap and dumpcap creates a pcap file that tshark then reads. The only problem is that I have restricted file capacity. I also understand that both tshark and dumpcap can be instructed to use files in a ring buffer manner with the -b option.</description>
    </item>
    
    <item>
      <title>Windows Server 2012</title>
      <link>/questions/13812/windows-server-2012/</link>
      <pubDate>Wed, 22 Aug 2012 03:06:00 +0000</pubDate>
      
      <guid>/questions/13812/windows-server-2012/</guid>
      <description>Windows Server 2012  0 When a new OS comes out like Release Candidate Windows Server 2012, do you actively test with it?
2012asked 22 Aug &#39;12, 03:06
GaryChaulklin
1●2●2●2
accept rate: 0%
  
One Answer:
  
0Someone might on their own behalf, but there is no buildbot for Windows 8 or Server 2012 yet, so no &#34;official&#34; tests. I would suggest that you check on the dev mailing list for info as I&#39;m sure it will come up there at some point.</description>
    </item>
    
    <item>
      <title>Where can I find a good tap?</title>
      <link>/questions/13814/where-can-i-find-a-good-tap/</link>
      <pubDate>Wed, 22 Aug 2012 05:01:00 +0000</pubDate>
      
      <guid>/questions/13814/where-can-i-find-a-good-tap/</guid>
      <description>Where can I find a good tap?  0 Can anyone tell me where I can find an inexpensive tap. I have tried amazon and google and they both give me bogus results? Does anybody know of a particular website that I can go to?
inexpensive tap wiresharkasked 22 Aug &#39;12, 05:01
I_GEEK_IT
1●5●5●6
accept rate: 0%
  
4 Answers:
  
0Tough question, because there are tons of different taps.</description>
    </item>
    
    <item>
      <title>Wireshark dissector support for BER OID for &amp;quot;{itu-t(0) identified-organization(4) etsi(0) securityDomain(2)...}&amp;quot;</title>
      <link>/questions/13816/wireshark-dissector-support-for-ber-oid-for-itu-t0-identified-organization4-etsi0-securitydomain2/</link>
      <pubDate>Wed, 22 Aug 2012 06:36:00 +0000</pubDate>
      
      <guid>/questions/13816/wireshark-dissector-support-for-ber-oid-for-itu-t0-identified-organization4-etsi0-securitydomain2/</guid>
      <description>Wireshark dissector support for BER OID for &amp;ldquo;{itu-t(0) identified-organization(4) etsi(0) securityDomain(2)&amp;hellip;}&amp;quot;  0 Hi,
I am trying to decode ASN.1 encoded packets for BER OID for &#34;{itu-t(0) identified-organization(4) etsi(0) securityDomain(2)...}&#34; using the latest 1.8.2 but I am not able to decode it. Could someone please point if Wireshark supports this. The Dissector table list DOES NOT show up BER OID 0.4.0.2.x.x.x
lawfulinterceptThis question is marked &#34;community wiki&#34;.asked 22 Aug &#39;12, 06:36</description>
    </item>
    
    <item>
      <title>cannot filter when i open wireshark</title>
      <link>/questions/13818/cannot-filter-when-i-open-wireshark/</link>
      <pubDate>Wed, 22 Aug 2012 09:16:00 +0000</pubDate>
      
      <guid>/questions/13818/cannot-filter-when-i-open-wireshark/</guid>
      <description>cannot filter when i open wireshark  0 when i open a cap with the wireshark(ver after 1.413) i cannot key-in any words in filter i must wait 1-3 min to key-in any words in filter my pc win7 32bit Language ch
filterasked 22 Aug &#39;12, 09:16
jin_lost
1●1●1●2
accept rate: 0%
 edited 22 Aug &#39;12, 20:13 
to clarify it:
you open a capture filewireshark loads the whole file and displays packets in the packet listyou cannot enter a display filter for up to 1-3 minutes, as the display filter field does not react on key strokes?</description>
    </item>
    
    <item>
      <title>capture ring buffer problem</title>
      <link>/questions/13822/capture-ring-buffer-problem/</link>
      <pubDate>Wed, 22 Aug 2012 11:13:00 +0000</pubDate>
      
      <guid>/questions/13822/capture-ring-buffer-problem/</guid>
      <description>capture ring buffer problem  0 Hi , i am using dumpcap to caputre but the way i have setup my script a new file should be made everytime it reaches maximum filesize and its not doing it . can you please help i am using the following command ...
/usr/bin/dumpcap -i eth0 -g -s 65536 -w /data/int0/int0 -b files:10000 -b filesize:24000 -b duration:600 -q &amp;amp;
capture ring buffer option not working</description>
    </item>
    
    <item>
      <title>NPF Driver not working; says service name is invalid when I try to start in cmd!</title>
      <link>/questions/13823/npf-driver-not-working-says-service-name-is-invalid-when-i-try-to-start-in-cmd/</link>
      <pubDate>Wed, 22 Aug 2012 11:28:00 +0000</pubDate>
      
      <guid>/questions/13823/npf-driver-not-working-says-service-name-is-invalid-when-i-try-to-start-in-cmd/</guid>
      <description>NPF Driver not working; says service name is invalid when I try to start in cmd!  0 &#34;NPF Driver not working&#34; is what I get every time I start up wireshark and I went to the forums and found what worked for most people; typing in commands to start it up, but when I do it says &#34;service name is invalid&#34; and I&#39;m thinking something didn&#39;t install right or something.</description>
    </item>
    
    <item>
      <title>How to turn off RPCAP traffic in 1.8.2</title>
      <link>/questions/13825/how-to-turn-off-rpcap-traffic-in-182/</link>
      <pubDate>Wed, 22 Aug 2012 12:11:00 +0000</pubDate>
      
      <guid>/questions/13825/how-to-turn-off-rpcap-traffic-in-182/</guid>
      <description>How to turn off RPCAP traffic in 1.8.2  0 I am trying to capture remote traffic with v1.8.2. I have done this in previous versions and there is a setting in previous versions that states &#34;Do not capture own RPCAP traffic&#34;. I cannot find this same setting in v1.8.2 (maybe it is default?). Anyhow, I can get the remote capture started but all I see is the connection packets between my machine and the remote machine.</description>
    </item>
    
    <item>
      <title>RST, ACK after sending huge portion of data</title>
      <link>/questions/13826/rst-ack-after-sending-huge-portion-of-data/</link>
      <pubDate>Wed, 22 Aug 2012 12:53:00 +0000</pubDate>
      
      <guid>/questions/13826/rst-ack-after-sending-huge-portion-of-data/</guid>
      <description>RST, ACK after sending huge portion of data  0 I have IMAP server (e.g. Dovecot). I try to create 1200 mailboxes (for test performance). Servers successfully performs it. After this operation I want to list all created folders. Server gives some portion of data but after some time (near 1 second) CLIENT sends RST, ACK to server while server responds with IMAP protocol&#39;s command about the list of created folders.</description>
    </item>
    
    <item>
      <title>Uninstall &amp;quot;ghost&amp;quot; files from OSX 10.6</title>
      <link>/questions/13834/uninstall-ghost-files-from-osx-106/</link>
      <pubDate>Wed, 22 Aug 2012 23:39:00 +0000</pubDate>
      
      <guid>/questions/13834/uninstall-ghost-files-from-osx-106/</guid>
      <description>Uninstall &amp;ldquo;ghost&amp;rdquo; files from OSX 10.6  0 Hi,
I&#39;m trying to do the same thing. I have a macbook pro 10.6. The problem is I installed it and followed the directions. After installing it and restarting my computer a bunch of (I think they are called) &#34;ghost files&#34; appeared on my desktop and on my main harddrive and maybe other places. So want to uninstall Wireshark and everything that came with it, including the X11 app that came with it and ALL those &#34;</description>
    </item>
    
    <item>
      <title>Anyone know what Cspuni is?</title>
      <link>/questions/13837/anyone-know-what-cspuni-is/</link>
      <pubDate>Thu, 23 Aug 2012 01:36:00 +0000</pubDate>
      
      <guid>/questions/13837/anyone-know-what-cspuni-is/</guid>
      <description>Anyone know what Cspuni is?  0 Hi
I am trying to send files with FTPS (SSL/TLS) but it&#39;s not working that well. When I do a wireshark trace I see that source port are 2806 (cspuni) 1.1.1.2 3.3.3.4 TCP cspuni &amp;gt; ftps [SYN] Seq=0 Win=65535 Len=0 MSS=1460 Source port: cspuni (2806) Destination port: ftps (990)
I havent heard of cspuni before, anyone have an idea what that is. Or do this appear when something is wrong, for example the certificate doesn&#39;t match?</description>
    </item>
    
    <item>
      <title>RTP stream repetitively shown in SIP call flow with Wireshark 1.8.2</title>
      <link>/questions/13838/rtp-stream-repetitively-shown-in-sip-call-flow-with-wireshark-182/</link>
      <pubDate>Thu, 23 Aug 2012 01:46:00 +0000</pubDate>
      
      <guid>/questions/13838/rtp-stream-repetitively-shown-in-sip-call-flow-with-wireshark-182/</guid>
      <description>RTP stream repetitively shown in SIP call flow with Wireshark 1.8.2  0 Hi, I&#39;ve been using call flow window of wireshark since quite a long time. It used to show the RTP stream as one item. It worked perfect and the only thing I was missing was the time stamp. Now I&#39;ve updated to version 1.8.2 of Wireshark and since then it shows the RTP stream repetitevly, even though it&#39;s clearly the same stream, which can be seen at the time stamp.</description>
    </item>
    
    <item>
      <title>Wireshark windows build not working due to ZLIB</title>
      <link>/questions/13841/wireshark-windows-build-not-working-due-to-zlib/</link>
      <pubDate>Thu, 23 Aug 2012 03:58:00 +0000</pubDate>
      
      <guid>/questions/13841/wireshark-windows-build-not-working-due-to-zlib/</guid>
      <description>Wireshark windows build not working due to ZLIB  0 Hi,
&#34;The windows builds might be working at buildbot (buildbot Windows-XP-x8).&#34;
New developers are stopped at first point (compilation ) we are not able to download the zlib-1.2.5.zip file required for compilation. (&#34;same case for 64 Bit zlib125ws.zip&#34; ).
The wget works but while unzipping it fails, Its not a problem with Zip utility (tried all util&#39;s on the planet 7zip,winrar,winzip.</description>
    </item>
    
    <item>
      <title>Checkpoint R75 prevents Wireshark from capturing ALL packets</title>
      <link>/questions/13845/checkpoint-r75-prevents-wireshark-from-capturing-all-packets/</link>
      <pubDate>Thu, 23 Aug 2012 06:13:00 +0000</pubDate>
      
      <guid>/questions/13845/checkpoint-r75-prevents-wireshark-from-capturing-all-packets/</guid>
      <description>Checkpoint R75 prevents Wireshark from capturing ALL packets  0 Hi,
This isn&#39;t a question, its an answer to my own question. I had problem capturing packets onsite with Windows 7 64bit, however other PCs from colleagues (XP 32 bit, 7 32bit and 7 64bit) worked fine. I tried everything: - Reinstalling Wireshark (with the NPF set to start on boot) - Trying MS Network Monitor instead - Checking McAffe didn&#39;t have any firewall functions - Installing latest Intel network drivers - Checking intel supports promisbious mode - Checking Windows 7 supports promiscious mode</description>
    </item>
    
    <item>
      <title>[closed] how to capture using dumpcap</title>
      <link>/questions/13850/how-to-capture-using-dumpcap/</link>
      <pubDate>Thu, 23 Aug 2012 12:25:00 +0000</pubDate>
      
      <guid>/questions/13850/how-to-capture-using-dumpcap/</guid>
      <description>[closed] how to capture using dumpcap  0 Hello , can someone please tell me how to capture traffic using syntax and limit file size to 2.4GB and create new files once capture reaches 2.4GB . Any suggestions ????
capture dumpcap ringbuffer wiresharkasked 23 Aug &#39;12, 12:25
helloworld0722
10●7●7●9
accept rate: 0%
 edited 24 Aug &#39;12, 19:38 
Guy Harris ♦♦
17.4k●3●35●196
This is almost identical to your previous question so I&#39;m closing this one.</description>
    </item>
    
    <item>
      <title>Display Filter not working for newly added fields</title>
      <link>/questions/13854/display-filter-not-working-for-newly-added-fields/</link>
      <pubDate>Thu, 23 Aug 2012 21:46:00 +0000</pubDate>
      
      <guid>/questions/13854/display-filter-not-working-for-newly-added-fields/</guid>
      <description>Display Filter not working for newly added fields  0 My plugin postdissector dissects, and displays, newly added suboptions in the tcp options field. But I just noticed that I&#39;m unable to filter these fields when I type tcp.options.foo in the filter bar(but tcp.options,foo still appears in the drop down box). When I type tcp.options.foo, it shows absolutely no packets. However, the filter seems to work just fine when I try to filter something like, say, tcp.</description>
    </item>
    
    <item>
      <title>tool for saving files (html, php etc.) from capture</title>
      <link>/questions/13855/tool-for-saving-files-html-php-etc-from-capture/</link>
      <pubDate>Fri, 24 Aug 2012 00:03:00 +0000</pubDate>
      
      <guid>/questions/13855/tool-for-saving-files-html-php-etc-from-capture/</guid>
      <description>tool for saving files (html, php etc.) from capture  1 1Hi. I am heavily using tcpdump and wireshark. Right now I need to dump traffic between some hosts and track why some webservices behave oddly. Looking in big dumps in wireshark or tcpdump is a bit problematical.
Is there a way to batch dump files from tcp captures? Some sort of multiripper known from old days.
I have tried to look for such tools but with not much success.</description>
    </item>
    
    <item>
      <title>TCP ACKed lost segment problem</title>
      <link>/questions/13856/tcp-acked-lost-segment-problem/</link>
      <pubDate>Fri, 24 Aug 2012 00:10:00 +0000</pubDate>
      
      <guid>/questions/13856/tcp-acked-lost-segment-problem/</guid>
      <description>TCP ACKed lost segment problem  0 Hi Guys,
i am using wireshark check an issue we have with slow connectivity to our server and sometimes server have to restart. I am see a lot of the following lines in the capture and i wondered if anyone could explain what they are:
39 TCP src &amp;gt; 38378 [PSH, ACK] Seq=1786 Ack=1726 Win=32768 Len=119
40 TCP 38378 &amp;gt; src [ACK] Seq=1726 Ack=1905 Win=54 Len=0</description>
    </item>
    
    <item>
      <title>Wireshark : Ping using Jpcap</title>
      <link>/questions/13864/wireshark-ping-using-jpcap/</link>
      <pubDate>Fri, 24 Aug 2012 02:58:00 +0000</pubDate>
      
      <guid>/questions/13864/wireshark-ping-using-jpcap/</guid>
      <description>Wireshark : Ping using Jpcap  0 Hello All,
I made a basic program in java using Jpcap to ping a machine. However the problem is whenever I ping using Win 7 command prompt, it returns a ping reply. However using Jpcap, it doesn&#39;t send a reply to my ping request. However I came across a strange situation. On the other machine, which I am pinging, If I open a Wireshark console and monitor the packets, it shows a ICMP request and sends a reply then.</description>
    </item>
    
    <item>
      <title>SSL Decrypt works depending on the used browser</title>
      <link>/questions/13874/ssl-decrypt-works-depending-on-the-used-browser/</link>
      <pubDate>Fri, 24 Aug 2012 06:17:00 +0000</pubDate>
      
      <guid>/questions/13874/ssl-decrypt-works-depending-on-the-used-browser/</guid>
      <description>SSL Decrypt works depending on the used browser  0 Hello all,
I have a &#34;strange&#34; problem with SSL decoding and I don&#39;t know how to explain it. I have a test server (apache+ssl) and I access that server with IE 8. Wireshark configured with the corect server SSL key, everything is working fine and I can see the SSL stream decoded.
Same scenario, but I use Firefox 14. In this case I cannot see anything being decoded.</description>
    </item>
    
    <item>
      <title>how to build DIS PDUType dissector</title>
      <link>/questions/13880/how-to-build-dis-pdutype-dissector/</link>
      <pubDate>Fri, 24 Aug 2012 12:39:00 +0000</pubDate>
      
      <guid>/questions/13880/how-to-build-dis-pdutype-dissector/</guid>
      <description>how to build DIS PDUType dissector  0 I&#39;m working on wireshark v1.8.0 and was trying to understand the DIS dissectors already installed in wireshark in order to modify them however it has been a trying process. Does anyone here have some experience directly editting the packet-dis.c, packet-dis-pdus.c and .h files in order to add in further dissectors for different PDU types? Thanks in advance.
dissectors wiresharkasked 24 Aug &#39;12, 12:39</description>
    </item>
    
    <item>
      <title>how to decode dynamic PT in RTP, e.g. RFC 2429 in RTP carring H.263&#43; video</title>
      <link>/questions/13891/how-to-decode-dynamic-pt-in-rtp-eg-rfc-2429-in-rtp-carring-h263-video/</link>
      <pubDate>Sat, 25 Aug 2012 12:20:00 +0000</pubDate>
      
      <guid>/questions/13891/how-to-decode-dynamic-pt-in-rtp-eg-rfc-2429-in-rtp-carring-h263-video/</guid>
      <description>how to decode dynamic PT in RTP, e.g. RFC 2429 in RTP carring H.263+ video  0 I am using Wireshark to decode a UDP/RTP stream. I can set the &#34;Decode as&#34; to decode RTP based on the dest port. This is working fine. However, by default, Wireshark is decoding the RTP payload using RFC 2198 (Redundant Audio Data). So it is deciding to decode the RTP payload using RFC 2198 specs.</description>
    </item>
    
    <item>
      <title>Port mirror switch</title>
      <link>/questions/13892/port-mirror-switch/</link>
      <pubDate>Sat, 25 Aug 2012 23:19:00 +0000</pubDate>
      
      <guid>/questions/13892/port-mirror-switch/</guid>
      <description>Port mirror switch  0 Does anybody know where I can find a cheap switch with port mirroring/monitoring ability. I have search google and other common sites but want to know if there is any specific one anybody would recommend. I was going to just get a tap, but they are kind of expensive.
Thanks!
switch inexpensive port mirroringasked 25 Aug &#39;12, 23:19
I_GEEK_IT
1●5●5●6
accept rate: 0%
 edited 25 Aug &#39;12, 23:21</description>
    </item>
    
    <item>
      <title>TShark: Display Filter and Statistics</title>
      <link>/questions/13898/tshark-display-filter-and-statistics/</link>
      <pubDate>Sun, 26 Aug 2012 19:37:00 +0000</pubDate>
      
      <guid>/questions/13898/tshark-display-filter-and-statistics/</guid>
      <description>TShark: Display Filter and Statistics  0 Hello all,
I am running CentOS v5.8 64bit. What is the correct display filter options to use in TShark if I want to redirect the output as CSV from reading a PCAP file? The columns will have the following output separated by commas:
timestamp,ip.src,source-port,ip.dst,destination-port,transport-layer-protocol,upload-bandwidth,download-bandwidth
Where:
timestamp = the actual time of a packetip.src = the source IP addresssource-port = the source portip.dst = the destination IP addressdestination-port = the destination porttransport-layer-protocol = be it in TCP, UDP, SCTP, etc.</description>
    </item>
    
    <item>
      <title>Capturing Over a Long Period of Time</title>
      <link>/questions/13900/capturing-over-a-long-period-of-time/</link>
      <pubDate>Sun, 26 Aug 2012 21:10:00 +0000</pubDate>
      
      <guid>/questions/13900/capturing-over-a-long-period-of-time/</guid>
      <description>Capturing Over a Long Period of Time  0 Hi Folks
I am investigating an issue of intermittent connectivity between two applications on seperate server, and want to set up Wireshark to capture packets between the two. The period of time I am looking to capture for is about 3 days - As the problem is intermittent and seems totally random, we have to leave the capture running the whole time to ensure that we are capturing when connectivity is interrupted.</description>
    </item>
    
    <item>
      <title>Interface names</title>
      <link>/questions/13901/interface-names/</link>
      <pubDate>Sun, 26 Aug 2012 22:07:00 +0000</pubDate>
      
      <guid>/questions/13901/interface-names/</guid>
      <description>Interface names  0 I am using Wireshark on both Windows XP Pro and Windows 7 Pro. In both cases I have multiple interfaces so I&#39;ve given them friendly names like: - Internet Switch Mirror - LAN Switch Mirror - LAN
In the XP system, these assigned names show up in Wireshark. In the Win 7 system, the manufacturer and model of the NIC shows up.
How can I fix the Windows 7 system NIC names in Wireshark?</description>
    </item>
    
    <item>
      <title>Passive Capture</title>
      <link>/questions/13912/passive-capture/</link>
      <pubDate>Mon, 27 Aug 2012 05:39:00 +0000</pubDate>
      
      <guid>/questions/13912/passive-capture/</guid>
      <description>Passive Capture  0 I was wondering if anyone has tried using a multiport gigabit switch adapter NIC such as the HP NC150T whilst capturing traffic, and if so does it affect results when capturing, such as jitter and delay at all? I am trying to model the affects of any virtualisation overhead on QoS for RTSP traffic.
How have you used them, as packets pass-through or tap off from the source/destination?</description>
    </item>
    
    <item>
      <title>save as in v 1.8.2</title>
      <link>/questions/13913/save-as-in-v-182/</link>
      <pubDate>Mon, 27 Aug 2012 06:23:00 +0000</pubDate>
      
      <guid>/questions/13913/save-as-in-v-182/</guid>
      <description>save as in v 1.8.2  0 I am using wireshark v 1.8.2, and with do &#34;save as&#34;, in the windows I have not option: Packet Range. So, I can not select that packet I can save.
But I installed v 1.6.10, and I can use PAcket Range with &#34;save as&#34;.
Thank you
saveasasked 27 Aug &#39;12, 06:23
Juan Carlos
6●1●1●3
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Network Loop Finding Process</title>
      <link>/questions/13919/network-loop-finding-process/</link>
      <pubDate>Tue, 28 Aug 2012 00:25:00 +0000</pubDate>
      
      <guid>/questions/13919/network-loop-finding-process/</guid>
      <description>Network Loop Finding Process  0 Hi,
In My Company Setup I am facing some Firewall related issues;when this firewall connected in Network switch My plant to plant communication Goes down;This problem occurs in the evening only... !
Network Setup is like below; We Have 3 Plants and those all are connected Through Wireless as Point to Point; Every Plant has 2 Devices. Plant A, Plant B, Plant C Plant A Wireless Device1 has a same SSID like Plant B Device1(its connected Plant A &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Plant B) Plant B Device2 is Connected to Plant C Device1 (with same SSID) For Redundancy we configured Extra Devices Of Plant A and Plant C its is in the Switch But SSID are different than Exist.</description>
    </item>
    
    <item>
      <title>How to only view streams, merging corresponding packets together</title>
      <link>/questions/13924/how-to-only-view-streams-merging-corresponding-packets-together/</link>
      <pubDate>Tue, 28 Aug 2012 02:18:00 +0000</pubDate>
      
      <guid>/questions/13924/how-to-only-view-streams-merging-corresponding-packets-together/</guid>
      <description>How to only view streams, merging corresponding packets together  0 Is there a way to see only a list of streams, without every single packet separately, like in HttpFox, e.g.
HTTP localip:12345 -&amp;gt; www.example.org:80 GET /index.html HTTP localip:12346 -&amp;gt; www.example.org:80 POST /example-form a=b&amp;amp;x=y SMTP localip:12347 -&amp;gt; mail.example.org:25 LOGIN user:password, MAIL: [email protected]example.org -&amp;gt; [email protected]example.org SSH localip:12348 -&amp;gt; ssh.example.org:22And clicking on a stream should show the corresponding packets or the stream content.</description>
    </item>
    
    <item>
      <title>Cannot see other LAN traffic</title>
      <link>/questions/13925/cannot-see-other-lan-traffic/</link>
      <pubDate>Tue, 28 Aug 2012 02:23:00 +0000</pubDate>
      
      <guid>/questions/13925/cannot-see-other-lan-traffic/</guid>
      <description>Cannot see other LAN traffic  0 I have three machines on my VLAN- A, B and C, all running Ubuntu. If I run Wireshark in promiscuous mode on, say, machine B, I am unable to see the traffic between machine A/C and the internet. The LAN traffic between them is detected fine. Where am I going wrong?
vlan trafficasked 28 Aug &#39;12, 02:23
pnp
6●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>A-GPS Trace Needed</title>
      <link>/questions/13930/a-gps-trace-needed/</link>
      <pubDate>Tue, 28 Aug 2012 05:00:00 +0000</pubDate>
      
      <guid>/questions/13930/a-gps-trace-needed/</guid>
      <description>A-GPS Trace Needed  0 Hi all,
Does someone have A-GPS (MS-Based and MS-Assisted GPS) trace for Lb (BSC-SMLC) interface? Also if possible please send me RRLP and RRC traces.
Thanks a lot. Mert
ms-assisted ms-based gpsasked 28 Aug &#39;12, 05:00
antialias
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>how do I rename wireshark files in second folder to same name as files in old folder</title>
      <link>/questions/13932/how-do-i-rename-wireshark-files-in-second-folder-to-same-name-as-files-in-old-folder/</link>
      <pubDate>Tue, 28 Aug 2012 06:06:00 +0000</pubDate>
      
      <guid>/questions/13932/how-do-i-rename-wireshark-files-in-second-folder-to-same-name-as-files-in-old-folder/</guid>
      <description>how do I rename wireshark files in second folder to same name as files in old folder  0 Hi,
I currently have two folders, one with WireShark .pcapng files(folder A) and one with .csv files(folder B) that correspond with the .pcapng files. I would like to know if there is any way I can rename the files in folder B to have the same name as the files in folder A?</description>
    </item>
    
    <item>
      <title>SCCP decode problem</title>
      <link>/questions/13933/sccp-decode-problem/</link>
      <pubDate>Tue, 28 Aug 2012 06:21:00 +0000</pubDate>
      
      <guid>/questions/13933/sccp-decode-problem/</guid>
      <description>SCCP decode problem  0 Hi!
I am using last version of Wireshrk. So, i have a hex dump of one packet (SCCP):
09 81 03 10 1B 0D 12 06 00 72 04 73 21 85 25 03 00 79 24 0B 12 07 00 11 04 53 97 79 10 00 00 46 62 44 48 04 0E 00 03 77 6B 1E 28 1C 06 07 00 11 86 05 01 01 01 A0 11 60 0F 80 02 07 80 A1 09 06 07 04 00 00 01 00 0E 03 6C 80 A1 18 02 01 01 02 01 38 30 10 80 08 42 06 22 03 00 79 24 F5 02 01 01 83 01 00 00 00 00 00 03 65 8B 80 02 73 81 70 00 6E F9 A0 01 7B 2A F8 01 12 FA 18 02 73 81 80 01 13 07 88 04 73 21 85 25 03 00 79 02 73 82 38 00 11 04 53 97 79 10 00 00 46 62 44 48 04 0E 00 03 77 6B 1E 01 1B BE F8 00 00 00 00 01 01 01 A0 11 60 0F 80 02 73 82 20 09 06 07 04 00 00 01 00 0E 03 6C 80 A1 18 02 01 01 02 01 38 30 10 80 08 01 7A D8 80 00 79 24 F5 02 01 01 83 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 5E 76 0C 00 00 00 02 02 73 82 30 00 A4 32 5C 02 73 82 30 00 A4 2E 64 03 65 8B 80 00 81 F7 58 00 00 00 00 00 00 00 00 03 65 8B 80 00 A4 2D DC 02 73 82 38 00 A4 2E 08 02 73 82 48 00 81 F7 6C 00 00 00 00 00 00 00 02 02 73 82 58 00 81 F6 C4 00 00 90 32 00 00 00 00 02 73 82 60 00 80 5A E8 02 73 82 70 01 12 F6 C0 00 00</description>
    </item>
    
    <item>
      <title>preserve the original packet number after applying a filter on a pcap file</title>
      <link>/questions/13934/preserve-the-original-packet-number-after-applying-a-filter-on-a-pcap-file/</link>
      <pubDate>Tue, 28 Aug 2012 07:51:00 +0000</pubDate>
      
      <guid>/questions/13934/preserve-the-original-packet-number-after-applying-a-filter-on-a-pcap-file/</guid>
      <description>preserve the original packet number after applying a filter on a pcap file  0 hi there i want to apply a filter on pcap file to filter the RTP packets, but when i do that the packet number changes and starts from 1 . i know this should be like this, but i need to know the previous packet number, so i can modify the corresponding packet in the original pcap file .</description>
    </item>
    
    <item>
      <title>Capture from a single IP</title>
      <link>/questions/13942/capture-from-a-single-ip/</link>
      <pubDate>Tue, 28 Aug 2012 11:12:00 +0000</pubDate>
      
      <guid>/questions/13942/capture-from-a-single-ip/</guid>
      <description>Capture from a single IP  0 Hi, I&#39;m new on the Wireshark and, even I have read some manuals, the capture filter doesn&#39;t seems to work for me. I only want to capture packets to/from a single IP. So, I open Capture -&amp;gt; Capture Filters.. and create a new rule:
name: MyRule
string: host 192.168.1.100
But it doesn&#39;t work, I see (and Wireshark captures) packets from every host on the LAN.</description>
    </item>
    
    <item>
      <title>When will 11ac sniffer be available?</title>
      <link>/questions/13947/when-will-11ac-sniffer-be-available/</link>
      <pubDate>Tue, 28 Aug 2012 16:36:00 +0000</pubDate>
      
      <guid>/questions/13947/when-will-11ac-sniffer-be-available/</guid>
      <description>When will 11ac sniffer be available?  0 When will 11ac sniffer be available?
11acasked 28 Aug &#39;12, 16:36
AAM
1●1●1●1
accept rate: 0%
 edited 21 Sep &#39;12, 08:31 
cmaynard ♦♦
9.4k●10●38●142
   </description>
    </item>
    
    <item>
      <title>invalid key format wireshark 1.8.2</title>
      <link>/questions/13951/invalid-key-format-wireshark-182/</link>
      <pubDate>Tue, 28 Aug 2012 22:18:00 +0000</pubDate>
      
      <guid>/questions/13951/invalid-key-format-wireshark-182/</guid>
      <description>invalid key format wireshark 1.8.2  0 I can&#39;t input my WPA2 key, It keeps saying &#34;invalid key format&#34; , is this a bug and how can I solve the problem?
Thanks
bugs wiresharkasked 28 Aug &#39;12, 22:18
mierdix
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Yes, this was a bug. I checked in a fix in r44694, which will be scheduled to be backported to the 1.</description>
    </item>
    
    <item>
      <title>Manual address resolve</title>
      <link>/questions/13961/manual-address-resolve/</link>
      <pubDate>Thu, 30 Aug 2012 02:42:00 +0000</pubDate>
      
      <guid>/questions/13961/manual-address-resolve/</guid>
      <description>Manual address resolve  0 Hi
I don&#39;t seem to be able to manually resolve addresses in wireshark (ver 1.8.1) anymore. When I bring up the manual resolve dialouge the OK button is greyed out. I &#39;ve tried various combinations in the Name resolution in preferences but nothing seems to make any difference. Any suggestions?
resolve manual addressasked 30 Aug &#39;12, 02:42
Mr_P
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Can TCP checksum be ZERO(0)??</title>
      <link>/questions/13962/can-tcp-checksum-be-zero0/</link>
      <pubDate>Thu, 30 Aug 2012 05:38:00 +0000</pubDate>
      
      <guid>/questions/13962/can-tcp-checksum-be-zero0/</guid>
      <description>Can TCP checksum be ZERO(0)??  0 Hi All,
I have implemented TCP protocol. For calculation of TCP Checksum I have used code from &#34;http://www.netfor2.com/tcpsum.htm&#34;. Some times it calculates checksum as zero.
My question is can TCP checksum be zero??I have captured this in Wireshark and it displays as correct checksum.Neither the OS nor the network card is calculating the checksum. Both client and server application are written using my tcp.</description>
    </item>
    
    <item>
      <title>how to decode a CITRIX capture</title>
      <link>/questions/13965/how-to-decode-a-citrix-capture/</link>
      <pubDate>Thu, 30 Aug 2012 09:29:00 +0000</pubDate>
      
      <guid>/questions/13965/how-to-decode-a-citrix-capture/</guid>
      <description>how to decode a CITRIX capture  0 I have a pcap of a citrix capture within a citrix network. I am trying to replay this in a not citrix environment to simulate the traffic for test purposes. When i look at the pcap, &#34;citrix&#34; or ICA is not seen in the decode. When I try to decode as, Citrix and ICA are not seen.
What am i missing? Or is a Citrix capture decode not supported?</description>
    </item>
    
    <item>
      <title>dissector onDoubleClick</title>
      <link>/questions/13966/dissector-ondoubleclick/</link>
      <pubDate>Thu, 30 Aug 2012 13:15:00 +0000</pubDate>
      
      <guid>/questions/13966/dissector-ondoubleclick/</guid>
      <description>dissector onDoubleClick  0 Hi, is it possible to know about, why the dissector was called ? Here is the description of my problem : - The complete decoding of the packet takes to long while capturing so i wish do decode the tcp packet only if the details window will open ( double click on the packet).
development dissectorasked 30 Aug &#39;12, 13:15
derinicehand
1●1●1●2
accept rate: 0%
 edited 30 Aug &#39;12, 13:23</description>
    </item>
    
    <item>
      <title>How to know the total bytes in the message ?</title>
      <link>/questions/13970/how-to-know-the-total-bytes-in-the-message/</link>
      <pubDate>Thu, 30 Aug 2012 19:46:00 +0000</pubDate>
      
      <guid>/questions/13970/how-to-know-the-total-bytes-in-the-message/</guid>
      <description>How to know the total bytes in the message ?  0 Hey guys,
I&#39;m using the Wireshark for the first time :) I&#39;d like to ask you guys what&#39;s the difference between the total bytes in the message and the total number of bytes in the whole frame? Also, how can I get them from the [app after captured]?
Looking forward to hearing from you soon!
Thanks.
message farmeasked 30 Aug &#39;12, 19:46</description>
    </item>
    
    <item>
      <title>1496 continuation</title>
      <link>/questions/13973/1496-continuation/</link>
      <pubDate>Fri, 31 Aug 2012 04:00:00 +0000</pubDate>
      
      <guid>/questions/13973/1496-continuation/</guid>
      <description>1496 continuation  0 during capturing of packets through wireshark i&#39;m only getting packets having details 1496 continuation and non http taffic but not the required ones even wen i&#39;m not downloading anything..plzzz help
continuation 1496asked 31 Aug &#39;12, 04:00
sky_walker
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Diameter - Command code: 506 Unknown</title>
      <link>/questions/13974/diameter-command-code-506-unknown/</link>
      <pubDate>Fri, 31 Aug 2012 12:48:00 +0000</pubDate>
      
      <guid>/questions/13974/diameter-command-code-506-unknown/</guid>
      <description>Diameter - Command code: 506 Unknown  0 I&#39;am investigating some issue about Diameter and HSS (AAA). In wireshark I keep having: Command Code: 506 Unknown
The AVP 506 seem to be related to Mobile-Node-Identifier source http://www.rfc-editor.org/rfc/rfc5779.txt (section 5.6) I tried to add this in the wireshark file dictionnary.xml but it seem it doesn&#39;t work :( &amp;lt;avp name=&#34;Mobile-Node-Identifier&#34; code=&#34;506&#34; mandatory=&#34;must&#34; may-encrypt=&#34;no&#34; protected=&#34;mustnot&#34; vendor-bit=&#34;mustnot&#34; vendor-id=&#34;TGPP&#34;&amp;gt; &amp;lt;type type-name=&#34;UTF8String&#34;/&amp;gt; &amp;lt;/avp&amp;gt;
diameter avp aaa hssThis question is marked &#34;</description>
    </item>
    
    <item>
      <title>Capture filters not working and/or disappeared in 1.8.2?</title>
      <link>/questions/13978/capture-filters-not-working-andor-disappeared-in-182/</link>
      <pubDate>Fri, 31 Aug 2012 15:14:00 +0000</pubDate>
      
      <guid>/questions/13978/capture-filters-not-working-andor-disappeared-in-182/</guid>
      <description>Capture filters not working and/or disappeared in 1.8.2?  0 Hi,
I installed 1.8.2 of WireShark and I noticed that the UI has changed a bit. The one feature that I appear to be missing is the ability to set a capture filter in the &#34;Captures Option&#34; dialog; which I was able to do previously.
I then tried to use the &#34;Capture Filters&#34; dialog but that doesn&#39;t seem to do anything at all when I enter my filter and then press &#34;</description>
    </item>
    
    <item>
      <title>802.11 decryption not working properly</title>
      <link>/questions/13982/80211-decryption-not-working-properly/</link>
      <pubDate>Sat, 01 Sep 2012 02:25:00 +0000</pubDate>
      
      <guid>/questions/13982/80211-decryption-not-working-properly/</guid>
      <description>802.11 decryption not working properly  0 Hi all, I am working on some pentests in my home network using WPA2 and I am trying to sniff the traffic between the clients and the AP. Capturing data works like a charm with Wireshark, but WPA2 decryption seems not to work at all. Here is what I&#39;ve done so far:
First of all, I sniffed some traffic I generated. To be more specific, Wireshark was running on one computer with wireless card in monitor mode (A), while I used another computer (B) to authenticate into the home network and after it received config from DHCP, I accessed the router&#39;s web UI.</description>
    </item>
    
    <item>
      <title>[1.8.2] no difference between unresolved and resolved source address...</title>
      <link>/questions/13984/182-no-difference-between-unresolved-and-resolved-source-address/</link>
      <pubDate>Sat, 01 Sep 2012 12:23:00 +0000</pubDate>
      
      <guid>/questions/13984/182-no-difference-between-unresolved-and-resolved-source-address/</guid>
      <description>[1.8.2] no difference between unresolved and resolved source address&amp;hellip;  0 I&#39;ve set up my columns to display both unresolved and resolved &#39;Src/Dest addr&#39; but Wireshark reflects the changes to the options onto both of the columns i.e. both columns display unresolved or resolved, not one or the other. Before you ask... I&#39;ve specifically selected the unresolved and resolved field types for both address and port.
Under the options, if I &#39;Enable MAC and Transport Name Resolution, the Src/Dest addr (Resolved) columns don&#39;t resolve but both &#39;Src/Dest Port (Resolved)&#39; do resolve and Src/Dest Port (unresolved) stays as unresolved.</description>
    </item>
    
    <item>
      <title>Remote Capture with fifo -- Windows?</title>
      <link>/questions/13985/remote-capture-with-fifo-windows/</link>
      <pubDate>Sat, 01 Sep 2012 20:02:00 +0000</pubDate>
      
      <guid>/questions/13985/remote-capture-with-fifo-windows/</guid>
      <description>Remote Capture with fifo &amp;ndash; Windows?  0 Is it possible to do this:
$ mkfifo /tmp/sharkfin
$ wireshark -k -i /tmp/sharkfin &amp;amp;
$ ssh [email protected] &#34;dumpcap -w - not port 22&#34; &amp;gt; /tmp/sharkfin
On a linux box, connecting via SSH to a Windows box? ie, the Windows box is the one performing the actual capture and passing the traffic back to the Linux box.
Any reason why it wouldn&#39;t work?</description>
    </item>
    
    <item>
      <title>Why TCP Reset sent after receive [FIN,ACK] Packet?</title>
      <link>/questions/13986/why-tcp-reset-sent-after-receive-finack-packet/</link>
      <pubDate>Sat, 01 Sep 2012 21:09:00 +0000</pubDate>
      
      <guid>/questions/13986/why-tcp-reset-sent-after-receive-finack-packet/</guid>
      <description>Why TCP Reset sent after receive [FIN,ACK] Packet?  0 I found my connection got packet TCP Reset after I receive packet [FIN,ACK] in every time. I don&#39;t understand, why it send TCP Reset packet? This case is the normal or not? Cause my application didn&#39;t got error message when I found these packets.
P.S. Trace file is in this link.http://cloudshark.org/captures/fa18617b777d and http://cloudshark.org/captures/ee9c044e161d
rstasked 01 Sep &#39;12, 21:09
horboyz
1●1●1●2</description>
    </item>
    
    <item>
      <title>How to configure Wireshark to decode/disect JMS</title>
      <link>/questions/13989/how-to-configure-wireshark-to-decodedisect-jms/</link>
      <pubDate>Sun, 02 Sep 2012 06:18:00 +0000</pubDate>
      
      <guid>/questions/13989/how-to-configure-wireshark-to-decodedisect-jms/</guid>
      <description>How to configure Wireshark to decode/disect JMS  0 Does wireshark decode/disect JMS Protols?
I do not see &#34;JMS&#34; in the &#34;Enabled Protocols&#34; list of valid protocols.
Is the a plugin or disector for Wireshatk and JMS?
Please provide link and product info if it does exist.
Thanks Ralph Leyrer [email protected] Cell#: 252-204-6760 Work#: 404-269-5706
jms disector wireshark pluginasked 02 Sep &#39;12, 06:18
rleyrer
1●1●1●1
accept rate: 0%
 edited 06 Jun &#39;13, 05:35</description>
    </item>
    
    <item>
      <title>How to decode Timeticks (Hundreds seconds) to readable date time</title>
      <link>/questions/14002/how-to-decode-timeticks-hundreds-seconds-to-readable-date-time/</link>
      <pubDate>Mon, 03 Sep 2012 01:54:00 +0000</pubDate>
      
      <guid>/questions/14002/how-to-decode-timeticks-hundreds-seconds-to-readable-date-time/</guid>
      <description>How to decode Timeticks (Hundreds seconds) to readable date time  0 Hi All,
sorry if I&#39;m disturbing for probably stupid question .
I&#39;m looking for a way to decode directly from wireshark (I&#39;m actually using release 1.8.2) the timeticks from the hundred seconds view, like:
(Wireshark running on top of Windows XD Professional):
Object Name: 1.3.6.1.2.1.1.3.0 (iso.3.6.1.2.1.1.3.0) Value (TimeTicks): 129528167
to a readable values (Solaris 10 Example):
bash-3.00$ /usr/sfw/bin/snmpget -v2c -c public 10.</description>
    </item>
    
    <item>
      <title>Will wireshark analyze the entire network traffic</title>
      <link>/questions/14009/will-wireshark-analyze-the-entire-network-traffic/</link>
      <pubDate>Mon, 03 Sep 2012 22:28:00 +0000</pubDate>
      
      <guid>/questions/14009/will-wireshark-analyze-the-entire-network-traffic/</guid>
      <description>Will wireshark analyze the entire network traffic  0 I am using a machine which is connected through LAN. If i will install Wireshark on my machine, will it capture the Network traffic of the entire network connected to the LAN? or it is only specific to the machine where it is installed.
Thanks, Smruti
captureasked 03 Sep &#39;12, 22:28
Smruti Ranja...
1●1●1●2
accept rate: 0%
 edited 04 Sep &#39;12, 04:09</description>
    </item>
    
    <item>
      <title>CustomColumn &amp;quot;data.text&amp;quot;</title>
      <link>/questions/14011/customcolumn-datatext/</link>
      <pubDate>Mon, 03 Sep 2012 23:48:00 +0000</pubDate>
      
      <guid>/questions/14011/customcolumn-datatext/</guid>
      <description>CustomColumn &amp;ldquo;data.text&amp;rdquo;  0 In Wireshark 1.6.4 I have a &#34;costum column&#34; - &#34;data.text&#34; to see my Telegramm-stream
What about this information in Wireshark 1.8 --&amp;gt; data.text show&#39;s me an empty column?
text dataasked 03 Sep &#39;12, 23:48
sniffer
1●1●1●2
accept rate: 0%
  
One Answer:
  
0Very hard to find.. but:
Edit &amp;gt; Preferences &amp;gt; Protocols &amp;gt; Data &amp;gt; check &#34;Show data as text&#34;
Then the custom column using data.</description>
    </item>
    
    <item>
      <title>Can wireshark be used to identify AFDX(Avionics Full Duplex Switched Ethernet) frame?</title>
      <link>/questions/14012/can-wireshark-be-used-to-identify-afdxavionics-full-duplex-switched-ethernet-frame/</link>
      <pubDate>Tue, 04 Sep 2012 01:29:00 +0000</pubDate>
      
      <guid>/questions/14012/can-wireshark-be-used-to-identify-afdxavionics-full-duplex-switched-ethernet-frame/</guid>
      <description>Can wireshark be used to identify AFDX(Avionics Full Duplex Switched Ethernet) frame?  0 I want to know, can wireshark identify AFDX protocol? Or has anybody used wireshark to analyze AFDX frame? Many thanks.
wireshark_afdxasked 04 Sep &#39;12, 01:29
gmyun
1●1●1●1
accept rate: 0%
 edited 04 Sep &#39;12, 22:39 
cmaynard ♦♦
9.4k●10●38●142
  
2 Answers:
  
0there is no AFDX dissector in the official code of Wireshark.</description>
    </item>
    
    <item>
      <title>the function init_listener</title>
      <link>/questions/14013/the-function-init_listener/</link>
      <pubDate>Tue, 04 Sep 2012 01:36:00 +0000</pubDate>
      
      <guid>/questions/14013/the-function-init_listener/</guid>
      <description>the function init_listener  0 Hi, I&#39;m new to Lua and I want to know the statement ( init_Listener() ) that written at the end of the function init_Listener, what is the benefit from it??
luaasked 04 Sep &#39;12, 01:36
Leena
51●17●18●21
accept rate: 0%
  
One Answer:
  
0init_listener() is probably what you have seen in the following example:
http://wiki.wireshark.org/Lua/Examples
In that example it&#39;s just a self declared function in the code that will called as soon as the Lua file gets loaded.</description>
    </item>
    
    <item>
      <title>run more than one Lua file simultaneously with tshark</title>
      <link>/questions/14017/run-more-than-one-lua-file-simultaneously-with-tshark/</link>
      <pubDate>Tue, 04 Sep 2012 02:12:00 +0000</pubDate>
      
      <guid>/questions/14017/run-more-than-one-lua-file-simultaneously-with-tshark/</guid>
      <description>run more than one Lua file simultaneously with tshark  0 Is it possible to run more than one Lua file at the same time with tshark? Can you provide an example?
luaasked 04 Sep &#39;12, 02:12
Leena
51●17●18●21
accept rate: 0%
 edited 04 Sep &#39;12, 21:46 
helloworld
3.1k●4●20●41
1I assume you mistakenly tagged this question with luainterface (i.e., LuaInterface), which is a Lua bridge to .NET, allowing one to instantiate CLR objects and use them in Lua.</description>
    </item>
    
    <item>
      <title>intercept packet send by a DSP to an host inside a VPN network</title>
      <link>/questions/14027/intercept-packet-send-by-a-dsp-to-an-host-inside-a-vpn-network/</link>
      <pubDate>Tue, 04 Sep 2012 03:24:00 +0000</pubDate>
      
      <guid>/questions/14027/intercept-packet-send-by-a-dsp-to-an-host-inside-a-vpn-network/</guid>
      <description>intercept packet send by a DSP to an host inside a VPN network  0 Hi all, i&#39;m new... i&#39;m facing this problem for a while and i&#39;m a bit out of ideas. Basically i&#39;d like to intercept the packet send by a remote DSP/DSPs to a host directly connected to them via ssh. I can connect to a third host via VPN that communicate with those two parts. Please somebody help me :).</description>
    </item>
    
    <item>
      <title>Extracting ip addresses from dns answer section with tshark</title>
      <link>/questions/14033/extracting-ip-addresses-from-dns-answer-section-with-tshark/</link>
      <pubDate>Tue, 04 Sep 2012 07:00:00 +0000</pubDate>
      
      <guid>/questions/14033/extracting-ip-addresses-from-dns-answer-section-with-tshark/</guid>
      <description>Extracting ip addresses from dns answer section with tshark  0 1I am trying to extract the ip addresses from a standard dns query response using &#34;-e dns.resp.addr&#34;. Unfortunately, I also get the ip addresses from &#34;additional records&#34; section because the fieldname is the same: &#34;dns.resp.addr&#34;
When I query www.bfh.ch I would expect to get the A record.
tshark -i eth0 port 53 -R &amp;quot;dns.flags.response == 1&amp;quot; -T fields -E separator=\; -E quote=s -e frame.</description>
    </item>
    
    <item>
      <title>Tshark and bash scripting</title>
      <link>/questions/14037/tshark-and-bash-scripting/</link>
      <pubDate>Tue, 04 Sep 2012 12:42:00 +0000</pubDate>
      
      <guid>/questions/14037/tshark-and-bash-scripting/</guid>
      <description>Tshark and bash scripting  0 I capture everything on port 25 into a pcap file using dumpcap. Sometimes, I see a malicious email campaign come through, so now, I want to find all the times it occurs. So far, I have this bash script:
sudo tshark -n -t ad -r $2 -R &amp;quot;smtp.command___line contains $1 || data-text-lines contains $1 || imf contains $1&amp;quot; -T fields -e frame.time -e ip.src -e ip.</description>
    </item>
    
    <item>
      <title>Decrypting traffic using pre-shared key</title>
      <link>/questions/14047/decrypting-traffic-using-pre-shared-key/</link>
      <pubDate>Tue, 04 Sep 2012 15:51:00 +0000</pubDate>
      
      <guid>/questions/14047/decrypting-traffic-using-pre-shared-key/</guid>
      <description>Decrypting traffic using pre-shared key  0 Hi,
Due to security restrictions I can only get a private key on a certain pc. I saved the trace and pre-shared key so I could look at it on my laptop however, when I configure the SSL preferences to use this key I can see in the SSL debug file that the traffic is being decrypted but in wireshark itself it is still showing the encrypted traffic.</description>
    </item>
    
    <item>
      <title>read multiple files using tcpdump</title>
      <link>/questions/14064/read-multiple-files-using-tcpdump/</link>
      <pubDate>Wed, 05 Sep 2012 13:19:00 +0000</pubDate>
      
      <guid>/questions/14064/read-multiple-files-using-tcpdump/</guid>
      <description>read multiple files using tcpdump  0 Hi I wanted to know if I can read multiple files using tcpdump .
filter ip wireshark tcpdump multiple-filesasked 05 Sep &#39;12, 13:19
helloworld0722
10●7●7●9
accept rate: 0%
  
One Answer:
  
0only one after the other. If that does not work for you, I suggest to use Wiresharks mergecap to merge the files and then either open it with tcpdump or wireshark.</description>
    </item>
    
    <item>
      <title>Malformed smrse packet</title>
      <link>/questions/14065/malformed-smrse-packet/</link>
      <pubDate>Wed, 05 Sep 2012 15:02:00 +0000</pubDate>
      
      <guid>/questions/14065/malformed-smrse-packet/</guid>
      <description>Malformed smrse packet  0 Hi everyone,
Getting &#34;malformed smrse packet (exception occured)&#34; errors on our Win2003 server. Anything I should be concerned about?
smrse malformedasked 05 Sep &#39;12, 15:02
quickpath
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Please refer to the malformed wiki page.
answered 05 Sep &#39;12, 18:51
cmaynard ♦♦
9.4k●10●38●142
accept rate: 20%
In particular, note the list on that page:
There are three main causes:</description>
    </item>
    
    <item>
      <title>Why does Wireshark not open after upgrading from Snow Leopard to Mountain Lion?</title>
      <link>/questions/14066/why-does-wireshark-not-open-after-upgrading-from-snow-leopard-to-mountain-lion/</link>
      <pubDate>Wed, 05 Sep 2012 16:00:00 +0000</pubDate>
      
      <guid>/questions/14066/why-does-wireshark-not-open-after-upgrading-from-snow-leopard-to-mountain-lion/</guid>
      <description>Why does Wireshark not open after upgrading from Snow Leopard to Mountain Lion?  0 I recently installed Mountain Lion and then Wireshark stopped working. Before, with Snow Leopard, Wireshark worked well. I upgraded X11 to the latest version, but if I launch Wireshark (even with X11 already running), nothing seems to happen. Any ideas? Thanks and greeting from Italy.
x11 osx mountain-lionasked 05 Sep &#39;12, 16:00
carlogiga
0●2●2●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Limit Interface</title>
      <link>/questions/14067/limit-interface/</link>
      <pubDate>Wed, 05 Sep 2012 16:26:00 +0000</pubDate>
      
      <guid>/questions/14067/limit-interface/</guid>
      <description>Limit Interface  0 Is it possible to limit which interface can me monitored on a Windows system? Seems easy to do in Linux but we want only one Ethernet adapter to run wireshark/winpcap and the other nics in the system are not allowed.
windows administrator limitasked 05 Sep &#39;12, 16:26
raypitt
1●1●1●1
accept rate: 0%
  
One Answer:
  
0That&#39;s only possible if you build your own version of Wireshark and filter the list of interfaces that is delivered by WinPcap.</description>
    </item>
    
    <item>
      <title>Can not see packets from local machine</title>
      <link>/questions/14075/can-not-see-packets-from-local-machine/</link>
      <pubDate>Wed, 05 Sep 2012 22:15:00 +0000</pubDate>
      
      <guid>/questions/14075/can-not-see-packets-from-local-machine/</guid>
      <description>Can not see packets from local machine  0 Hello
Can&#39;t see the packets from my local Win7 machine in wireshark trace. I&#39;m using wireshark 1.8.1 (x86) with winpcap (x86) 4.1.2 (4.1.0.2001) but my win7 x64. The machine itself is a DELL laptop with Intel(R) 82579LM Gigabit Network adapter (driver e1c62x64.sys (11.13.51.0) and DW1530 Wireless-N WLAN Half-Mini Card - I have the same problem on both.
missing local packet wiresharkasked 05 Sep &#39;12, 22:15</description>
    </item>
    
    <item>
      <title>Display packet transitions before capturing</title>
      <link>/questions/14077/display-packet-transitions-before-capturing/</link>
      <pubDate>Wed, 05 Sep 2012 23:42:00 +0000</pubDate>
      
      <guid>/questions/14077/display-packet-transitions-before-capturing/</guid>
      <description>Display packet transitions before capturing  0 Running Wireshark, before selecting the right interface, I can see packet transitions on all interfaces, by means of flashing numbers. Since I use WinPcap library I&#39;d like to mimic that in my C++ program. Can someone direct me how to do that? Regards I. Lesher
winpcapasked 05 Sep &#39;12, 23:42
triplebit
1●7●7●7
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Decapsulation of data</title>
      <link>/questions/14078/decapsulation-of-data/</link>
      <pubDate>Thu, 06 Sep 2012 02:02:00 +0000</pubDate>
      
      <guid>/questions/14078/decapsulation-of-data/</guid>
      <description>Decapsulation of data  0 Hi
Can anybody help to decapsulate only the data or payload from all other network related data, so I on a easy way, can find data transmitted from one ip address.
I have a system transmitting data, and need to extract data for display on another system
I have recorded a wireshark-file, but I need help to get Tshark or Wireshark to insulate or extract &#39;data only&#39;.</description>
    </item>
    
    <item>
      <title>WS version 1.02 patched make: *** [all] Error 2</title>
      <link>/questions/14081/ws-version-102-patched-make-all-error-2/</link>
      <pubDate>Thu, 06 Sep 2012 04:15:00 +0000</pubDate>
      
      <guid>/questions/14081/ws-version-102-patched-make-all-error-2/</guid>
      <description>WS version 1.02 patched make: *** [all] Error 2  0 Hey im trying to install a version of ws with a patched applied already, but when i get to the MAKE command i get the error below. I am running Ubuntu 11.10 and i believe all have all the dependencies installed. Is there a way to check for the dependencies that are needed? Any help would be great. And the patch is for P25 radio from the op25-dev yahoo group.</description>
    </item>
    
    <item>
      <title>Weird behavior when connecting to google.com (TCP previous segment not captured)</title>
      <link>/questions/14082/weird-behavior-when-connecting-to-googlecom-tcp-previous-segment-not-captured/</link>
      <pubDate>Thu, 06 Sep 2012 04:24:00 +0000</pubDate>
      
      <guid>/questions/14082/weird-behavior-when-connecting-to-googlecom-tcp-previous-segment-not-captured/</guid>
      <description>Weird behavior when connecting to google.com (TCP previous segment not captured)  0 I had Ubuntu 11.10 and in the last few weeks I experienced an obscure problem: after I had the computer running for a few days I could no longer connect to google.com or anything related to google. All sites worked with all browsers (Firefox, chrome, opera) except google. It remained in the connecting phase for a few minutes and either timed out or finally connected with this huge delay.</description>
    </item>
    
    <item>
      <title>Where is Decode as RTP option in 1.8.2?</title>
      <link>/questions/14092/where-is-decode-as-rtp-option-in-182/</link>
      <pubDate>Thu, 06 Sep 2012 07:53:00 +0000</pubDate>
      
      <guid>/questions/14092/where-is-decode-as-rtp-option-in-182/</guid>
      <description>Where is Decode as RTP option in 1.8.2?  0 I normally work with Wireshark for tracing and troubleshooting VoIP calls, and whenever Wireshark shows me UDP packets instead of RTP, I am used to &#39;Decode as...&#39; RTP the UDP packets and then I see my RTP streams correctly. I just downloaded 1.8.2, and I can&#39;t find RTP in the list of protocols inside &#39;Decode as...&#39; window any more. How can I tell now to Wireshark to decode some RTP streams as RTP if it is not doing so correctly from the beginning?</description>
    </item>
    
    <item>
      <title>Unaltering filter after following a stream</title>
      <link>/questions/14104/unaltering-filter-after-following-a-stream/</link>
      <pubDate>Fri, 07 Sep 2012 00:02:00 +0000</pubDate>
      
      <guid>/questions/14104/unaltering-filter-after-following-a-stream/</guid>
      <description>Unaltering filter after following a stream  0 When you try to follow tcp/udp stream on a packet, it pops up a new window with the stream content but it also changes the display filter on the main window (tc.stream eq 100 for instance). Is there a way to make wireshark not change the filter?
filter streamasked 07 Sep &#39;12, 00:02
l46kok
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>String syntax error</title>
      <link>/questions/14106/string-syntax-error/</link>
      <pubDate>Fri, 07 Sep 2012 01:47:00 +0000</pubDate>
      
      <guid>/questions/14106/string-syntax-error/</guid>
      <description>String syntax error  0 Hi! I have one little problem:
C:\Program Files\Wireshark\tshark -x lua_script:hello.lua Capturing on Microsoft tshark: Invalid capture filter &#34;lua_script:hello.lua&#34; for interface Microsoft!
That string isn&#39;t a valid capture filter &amp;lt;syntax error=&#34;&#34;&amp;gt;. See the User&#39;s Guide for a description of the capture filter syntax. 0 packets captured
hello.lua contains only this: print(&#34;Hello World&#34;)
What&#39;s the problem?
executable tshark syntaxasked 07 Sep &#39;12, 01:47
speede05
6●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Ping reply time occasionally very high in in one direction only</title>
      <link>/questions/14120/ping-reply-time-occasionally-very-high-in-in-one-direction-only/</link>
      <pubDate>Fri, 07 Sep 2012 07:49:00 +0000</pubDate>
      
      <guid>/questions/14120/ping-reply-time-occasionally-very-high-in-in-one-direction-only/</guid>
      <description>Ping reply time occasionally very high in in one direction only  0 I have a customer with a WAN link 280 miles apart. Us (the Vendor) have an IP address on each side both on the same subnet on an isolated VLAN. Pings from site A to site B are around 8ms consistently with no drops. Pings from site B to site A vary from 8ms to 750ms. When I run a 64 byte 1 packet ping every 5 seconds I see the 10 latest ping reply times of : 9ms, 9ms, 32ms, 14ms, 264ms, 13ms, 36ms, 19ms, 17ms, 254ms.</description>
    </item>
    
    <item>
      <title>subdissector window tree not appearing</title>
      <link>/questions/14122/subdissector-window-tree-not-appearing/</link>
      <pubDate>Fri, 07 Sep 2012 08:12:00 +0000</pubDate>
      
      <guid>/questions/14122/subdissector-window-tree-not-appearing/</guid>
      <description>subdissector window tree not appearing  0 Greetings,
I have two protocols that are encapsulated like so: TCP or UDP -&amp;gt; proto1 -&amp;gt; proto2.
I have created a heuristic dissector for proto1 that is registered to TCP or UDP (my protocols can run over either). This works fine, and in the Wireshark GUI I see proto1 being dissected, with its tree information being populated appropriately. I then created a subdissector proto2, that is registered to proto1.</description>
    </item>
    
    <item>
      <title>Resolving Torrent to MAC</title>
      <link>/questions/14125/resolving-torrent-to-mac/</link>
      <pubDate>Fri, 07 Sep 2012 11:49:00 +0000</pubDate>
      
      <guid>/questions/14125/resolving-torrent-to-mac/</guid>
      <description>Resolving Torrent to MAC  0 Having a bit of trouble finding a string I can use for tshark to get it to capture bittorrent traffic only, and include a mac address.
Preferably it would be something like:
[time] [MAC] [torrent hash]
I got as far as: tshark tcp portrange 6881-6889 -i 3 -w cap -b filesize:4096 -b filenum:100 -T fields -e eth.src
But there&#39;s several problems there, mainly the lack of the torrent hash and that tcp portrange 6881-6889 doesn&#39;t seem to reliably capture torrent traffic at all.</description>
    </item>
    
    <item>
      <title>Tshark not resolving names and not showing protocol as text when exporting to CSV file</title>
      <link>/questions/14126/tshark-not-resolving-names-and-not-showing-protocol-as-text-when-exporting-to-csv-file/</link>
      <pubDate>Fri, 07 Sep 2012 12:37:00 +0000</pubDate>
      
      <guid>/questions/14126/tshark-not-resolving-names-and-not-showing-protocol-as-text-when-exporting-to-csv-file/</guid>
      <description>Tshark not resolving names and not showing protocol as text when exporting to CSV file  1 Hello, I have captured a Wireshark file and would like to extract some information using Tshark. The below command is what I have been using:
tshark -r c:\temp\test.pcap &amp;gt;c:\temp\test1.csv -T fields -e ip.src_host -e ip.dst_host -e ip.proto
Issue 1 = Not resolving IP addresses to network names. When I captured the PCAP file, I had &#34;</description>
    </item>
    
    <item>
      <title>&amp;quot;tcp previous segment not captured&amp;quot;</title>
      <link>/questions/14134/tcp-previous-segment-not-captured/</link>
      <pubDate>Fri, 07 Sep 2012 20:05:00 +0000</pubDate>
      
      <guid>/questions/14134/tcp-previous-segment-not-captured/</guid>
      <description>&amp;ldquo;tcp previous segment not captured&amp;rdquo;  0 greetings, what does &#34;tcp previous segment not captured&#34; indicate? I am running wireshark when trying to connect to a wireless windows 7 vnc server from a wireless ubuntu laptop.
windows7 vnc capturedasked 07 Sep &#39;12, 20:05
bishop2001
1●1●1●1
accept rate: 0%
  
One Answer:
  
0It means that Wireshark (or whatever program you used to capture the traffic) either wasn&#39;t fast enough to cope with the amount of data the NIC received (dropped frames due to performance problems or WiFi &#34;</description>
    </item>
    
    <item>
      <title>[Protocol Comparisons] TCP, UDP, SCTP (DCCP)</title>
      <link>/questions/14139/protocol-comparisons-tcp-udp-sctp-dccp/</link>
      <pubDate>Sat, 08 Sep 2012 06:45:00 +0000</pubDate>
      
      <guid>/questions/14139/protocol-comparisons-tcp-udp-sctp-dccp/</guid>
      <description>[Protocol Comparisons] TCP, UDP, SCTP (DCCP)  0 Hi. I want to know how to measure [1] Throughput [2] Loss [3] Delay and Jitter on my application. I am running a video streaming server in my office on both LAN and WIFI. It runs TCP,UDP and SCTP, all over RTP.
As I understand it, I get the throughput from the IO graphs? in WS. (PLEASE CORRECT ME IF IM WRONG)I want to measure delay, but I only know the time when I receive each packet on my client computers.</description>
    </item>
    
    <item>
      <title>Cannot successfully supply Master Secret and Session ID for SSL Decryption?</title>
      <link>/questions/14142/cannot-successfully-supply-master-secret-and-session-id-for-ssl-decryption/</link>
      <pubDate>Sat, 08 Sep 2012 14:33:00 +0000</pubDate>
      
      <guid>/questions/14142/cannot-successfully-supply-master-secret-and-session-id-for-ssl-decryption/</guid>
      <description>Cannot successfully supply Master Secret and Session ID for SSL Decryption?  0 After capturing some SSL traffic (using tcpdump on an embedded linux system), I&#39;m attempting to decrypt the traffic from the dumpfile using Wireshark (I&#39;ve tried both v1.8.1 on linux and v1.8.2 on Win32).
The Session-ID was taken from the packet capture and the master secret was obtained from the memory of an application executing on the embedded system.</description>
    </item>
    
    <item>
      <title>Is it Arp Cache Attack ?</title>
      <link>/questions/14143/is-it-arp-cache-attack/</link>
      <pubDate>Sun, 09 Sep 2012 03:38:00 +0000</pubDate>
      
      <guid>/questions/14143/is-it-arp-cache-attack/</guid>
      <description>Is it Arp Cache Attack ?  0 Don&#39;t know that Am I really under this attack or not, eSet (ESS 5.0) several times is reporting this to me.
What I should mention are :
Here are using a Wireless point-to-point to get Internet to our tower, Then with a DSLAM the internet is provided to our room.
Some times I&#39;m using a VPN.
The reported IPs are similar to 192.</description>
    </item>
    
    <item>
      <title>Cannot scan with my Alfa AWUS036H</title>
      <link>/questions/14148/cannot-scan-with-my-alfa-awus036h/</link>
      <pubDate>Sun, 09 Sep 2012 16:26:00 +0000</pubDate>
      
      <guid>/questions/14148/cannot-scan-with-my-alfa-awus036h/</guid>
      <description>Cannot scan with my Alfa AWUS036H  0 Hi,
I have been working on this problem for weeks. I can only get broadcast traffic over my alfa AWUS036H. I started on windows and tried everything. And then I went to backtrack 5r2 -- which supposed has the right driver already installed. I have followed the instructions on countless forums with no luck: I only see broadcast traffic.
Is it possible that I have a bad alfa?</description>
    </item>
    
    <item>
      <title>Can I get the exact peak/maximum rate value from IO Graphs</title>
      <link>/questions/14151/can-i-get-the-exact-peakmaximum-rate-value-from-io-graphs/</link>
      <pubDate>Sun, 09 Sep 2012 18:42:00 +0000</pubDate>
      
      <guid>/questions/14151/can-i-get-the-exact-peakmaximum-rate-value-from-io-graphs/</guid>
      <description>Can I get the exact peak/maximum rate value from IO Graphs  0 I set Tick interval as 1 sec at X Axis and Unit as Bits/Tick at Y axis.
Can I get the exact peak/maximum rate value from IO Graphs?
Thank you!
io graphs rate peak valueasked 09 Sep &#39;12, 18:42
mobilefone
0●1●1●1
accept rate: 0%
  
One Answer:
  
0I don&#39;t know how exact it has to be for you, but if you need the absolute number of bits/second down to the last digit you probably can&#39;t get that from the I/O graph.</description>
    </item>
    
    <item>
      <title>DT1 ranap message not decoding</title>
      <link>/questions/14152/dt1-ranap-message-not-decoding/</link>
      <pubDate>Sun, 09 Sep 2012 22:11:00 +0000</pubDate>
      
      <guid>/questions/14152/dt1-ranap-message-not-decoding/</guid>
      <description>DT1 ranap message not decoding  0 I have found lot of ranap messages are not decoded by wireshark. These messages are decoded up to sccp.
-------------------------------------------- No. Time Source Destination Protocol Length Info 21781 18.879876 201 7 SCCP (Int. ITU) 122 DT1 Frame 21781: 122 bytes on wire (976 bits), 122 bytes captured (976 bits) Ethernet II, Src: AlcatelL_14:c5:44 (0c:a4:02:14:c5:44), Dst: AlcatelD_cd:c1:0c (00:11:3f:cd:c1:0c) 802.1Q Virtual LAN, PRI: 0, CFI: 0, ID: 1490 Internet Protocol Version 4, Src: 10.</description>
    </item>
    
    <item>
      <title>About the conversations table</title>
      <link>/questions/14165/about-the-conversations-table/</link>
      <pubDate>Mon, 10 Sep 2012 07:52:00 +0000</pubDate>
      
      <guid>/questions/14165/about-the-conversations-table/</guid>
      <description>About the conversations table  0 Hello everyone, I am writing you about the source code for the conversation table in WireShark. More specifically, I am interested into the function that is in the menu Statistics -&amp;gt; Conversations. I found some source code file under the name conversations_table.c. Unfortunately, there is a serious lack of comments, thus making the code impossible to read.
I would like to ask you, if it is possible, to tell me if this is the source code file for the conversations table?</description>
    </item>
    
    <item>
      <title>tshark, dns.addr.resp and IPv6</title>
      <link>/questions/14169/tshark-dnsaddrresp-and-ipv6/</link>
      <pubDate>Mon, 10 Sep 2012 10:17:00 +0000</pubDate>
      
      <guid>/questions/14169/tshark-dnsaddrresp-and-ipv6/</guid>
      <description>tshark, dns.addr.resp and IPv6  0 Hello,
I am attempting to use tshark to collect DNS answers. Below is the command I am using:
tshark -e frame.time -e dns.resp.name -e dns.resp.addr -e dns.resp.ttl -e dns.resp.type -e dns.resp.rpimaryname -E separator=/t -T fields -nl -e eth1 -f &#34;port 53&#34; -R &#34;dns &amp;amp;&amp;amp; dns.count.answers != 0 &amp;amp;&amp;amp; dns.flags.response == 1&#34;
This works fine for DNS responses that contain ipv4 addresses, but fails to return ipv6 addresses.</description>
    </item>
    
    <item>
      <title>NBSS traffic... Large amounts = Network flood</title>
      <link>/questions/14171/nbss-traffic-large-amounts-network-flood/</link>
      <pubDate>Mon, 10 Sep 2012 10:50:00 +0000</pubDate>
      
      <guid>/questions/14171/nbss-traffic-large-amounts-network-flood/</guid>
      <description>NBSS traffic&amp;hellip; Large amounts = Network flood  0 I have a Database server sitting in one vlan and a backup server sitting in another at our co-lo. Occasionally, we will lose connectivity to the co-lo. When I run wireshark on a span port, I see massive amounts of:
137 0.012353000 10.10.1.253 17.16.1.151 NBSS 1434 [TCP ACKed unseen segment] [TCP Out-Of-Order] NBSS Continuation Message
or similar. If I can connect to the ilo on my backup server, I hit reboot and the problem goes away and users go back to normal.</description>
    </item>
    
    <item>
      <title>New user: Network flow analysis help...</title>
      <link>/questions/14174/new-user-network-flow-analysis-help/</link>
      <pubDate>Mon, 10 Sep 2012 13:15:00 +0000</pubDate>
      
      <guid>/questions/14174/new-user-network-flow-analysis-help/</guid>
      <description>New user: Network flow analysis help&amp;hellip;  0 Have one site that is dropping packets because they are getting a lot of traffic. Have Fortinet products and know that most of the traffic is between a webserver and two mail servers at two other sites.
How can I filter my capture to show me specifically what traffic my webserver is receiving from the other two mail servers?
newbie network analysisasked 10 Sep &#39;12, 13:15</description>
    </item>
    
    <item>
      <title>SNDCP reassemble failure</title>
      <link>/questions/14182/sndcp-reassemble-failure/</link>
      <pubDate>Mon, 10 Sep 2012 21:18:00 +0000</pubDate>
      
      <guid>/questions/14182/sndcp-reassemble-failure/</guid>
      <description>SNDCP reassemble failure  0 Hi,
When I did trace of Gb over IP interface for a user who downloaded frob a website, The packet sent from the website cannot be decoded by wireshark Only the ACK message can be read by wireshark
Is there any ways to decode/reassemble these SNDCP fragment ?
BR//Joko
sndcpasked 10 Sep &#39;12, 21:18
jokow
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>how to decode multiplexed protocols</title>
      <link>/questions/14183/how-to-decode-multiplexed-protocols/</link>
      <pubDate>Mon, 10 Sep 2012 23:59:00 +0000</pubDate>
      
      <guid>/questions/14183/how-to-decode-multiplexed-protocols/</guid>
      <description>how to decode multiplexed protocols  0 protocols like stun uses the same port as rtp and rtcp. if rtp is multiplexed with rtcp then three protocols uses the same udp port. how can all protocols be decoded correctly?
rtcp rtp muxasked 10 Sep &#39;12, 23:59
Munich
1●1●1●2
accept rate: 0%
 edited 11 Sep &#39;12, 00:02 
   </description>
    </item>
    
    <item>
      <title>dumpcap:print_statistics_loop</title>
      <link>/questions/14186/dumpcapprint_statistics_loop/</link>
      <pubDate>Tue, 11 Sep 2012 05:43:00 +0000</pubDate>
      
      <guid>/questions/14186/dumpcapprint_statistics_loop/</guid>
      <description>dumpcap:print_statistics_loop  0 I was referred to dumpcap:print_statistics_loop by some of the experts here(forgive me if I don&#39;t remember his name). Trying to import the function into my code I see no linkage to the function get_interface_list (my be some others also). So far I use WinPcap library. What should I do more? Regards I. Lesher
winpcapasked 11 Sep &#39;12, 05:43
triplebit
1●7●7●7
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>new user need help with layers</title>
      <link>/questions/14189/new-user-need-help-with-layers/</link>
      <pubDate>Tue, 11 Sep 2012 12:24:00 +0000</pubDate>
      
      <guid>/questions/14189/new-user-need-help-with-layers/</guid>
      <description>new user need help with layers  0 Can you show me a diagarm that has each layer labeled? 2 data layer 3 Network layer 4 trasnport layer 5 application layer
layersasked 11 Sep &#39;12, 12:24
Marcia
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Is this what you&#39;re looking for?
http://www.telecommunications-tutorials.com/tutorial-OSI-7-layer-model.htm
answered 11 Sep &#39;12, 13:27
sreiner
1●1●1●1
accept rate: 0%
  
0This may be a more applicable diagram, it shows the strict OSI model side-by-side to the somewhat loosely defined TCP/IP model.</description>
    </item>
    
    <item>
      <title>Possible to setup Wireshark to use alternate port for Modbus TCP?</title>
      <link>/questions/14190/possible-to-setup-wireshark-to-use-alternate-port-for-modbus-tcp/</link>
      <pubDate>Tue, 11 Sep 2012 13:11:00 +0000</pubDate>
      
      <guid>/questions/14190/possible-to-setup-wireshark-to-use-alternate-port-for-modbus-tcp/</guid>
      <description>Possible to setup Wireshark to use alternate port for Modbus TCP?  0 Hello -- We have a server setup to act as three separate Modbus &#34;slave servers&#34;. One uses the standard Modbus TCP port 502. The others use ports 503 and 504, respectively. When we use Wireshark to look at network traffic, it has no problem recognizing all port 502 traffic as Modbus TCP protocol. However, it does not recognize the other port traffic as Modbus TCP.</description>
    </item>
    
    <item>
      <title>microsoft visual C&#43;&#43; Runtime library</title>
      <link>/questions/14193/microsoft-visual-c-runtime-library/</link>
      <pubDate>Tue, 11 Sep 2012 14:29:00 +0000</pubDate>
      
      <guid>/questions/14193/microsoft-visual-c-runtime-library/</guid>
      <description>microsoft visual C++ Runtime library  0 Please be advised as we are getting microsoft visual C++ Runtime library error after installing the newer version i.e 1.8.2 , we also tried to reinstall the whole package but it didn&#39;t help either. The system never had the older version basically its the first time we started using it.
wireshark_crashed wiresharkasked 11 Sep &#39;12, 14:29
crazii007
1●1●1●1
accept rate: 0%
O.K. some questions:</description>
    </item>
    
    <item>
      <title>Automate wireshark capture</title>
      <link>/questions/14195/automate-wireshark-capture/</link>
      <pubDate>Tue, 11 Sep 2012 19:59:00 +0000</pubDate>
      
      <guid>/questions/14195/automate-wireshark-capture/</guid>
      <description>Automate wireshark capture  1 Hi Experts,
I am new to Wireshark. I want to capture all the network traffic on one of our Windows servers. I wrote the following command in terminal
c:\Program Files\Wireshark&amp;gt;tshark -i 1 -a duration:3600 -w c:\WiresharkCapture\test
It works perfectly fine, except I have 2 questions:
I want to capture all the traffic between 6am-7am. Is there a way I can schedule the task to automatically execute this command between 6am-7am?</description>
    </item>
    
    <item>
      <title>Meaning of differences between responses in WireShark - 2 web servers</title>
      <link>/questions/14198/meaning-of-differences-between-responses-in-wireshark-2-web-servers/</link>
      <pubDate>Wed, 12 Sep 2012 01:26:00 +0000</pubDate>
      
      <guid>/questions/14198/meaning-of-differences-between-responses-in-wireshark-2-web-servers/</guid>
      <description>Meaning of differences between responses in WireShark - 2 web servers  0 This question relates more to HTTP and web server responses than to WireShark, yet I am hoping that someone with intimate knowledge of comms and HTTP in particular, could take a look at the following and possibly offer insights.
I have a device which issues GET and POST requests to a web endpoint.
When the device issues these requests to an Apache web server, it responds properly to the Apache web server HTTP/1.</description>
    </item>
    
    <item>
      <title>Verify an option sent by DHCP / option 78</title>
      <link>/questions/14207/verify-an-option-sent-by-dhcp-option-78/</link>
      <pubDate>Wed, 12 Sep 2012 06:13:00 +0000</pubDate>
      
      <guid>/questions/14207/verify-an-option-sent-by-dhcp-option-78/</guid>
      <description>Verify an option sent by DHCP / option 78  0 Hi guys,
Some AP needs the option 78 of DHCP to discover the Controller. How I can check it out if DHCP is sending this? There is no option 78 at &#34;Parameter request List Item&#34;
Regards, Ronaldo.
dhcpasked 12 Sep &#39;12, 06:13
Ronaldo
1●1●1●1
accept rate: 0%
 edited 13 Sep &#39;12, 04:45 
Jaap ♦
11.7k●16●101</description>
    </item>
    
    <item>
      <title>Wireshark Program quits</title>
      <link>/questions/14209/wireshark-program-quits/</link>
      <pubDate>Wed, 12 Sep 2012 08:53:00 +0000</pubDate>
      
      <guid>/questions/14209/wireshark-program-quits/</guid>
      <description>Wireshark Program quits  0 Hello all, I am running into the issue of Wireshark quitting after about 12 minutes. I am trying to run it on Widows server standard. It will run for a few then display the message: Microsoft Visual C++ Runtime Library &#34;This application has requested the Runtime to terminate it in an unusual way. Please contact the applications support team for more information.&#34; The installations (WinPcap, and wireshark) are both the right bit.</description>
    </item>
    
    <item>
      <title>Definitions of the structures used in the code</title>
      <link>/questions/14210/definitions-of-the-structures-used-in-the-code/</link>
      <pubDate>Wed, 12 Sep 2012 08:58:00 +0000</pubDate>
      
      <guid>/questions/14210/definitions-of-the-structures-used-in-the-code/</guid>
      <description>Definitions of the structures used in the code  0 Hello everyone,
Is there some list of all data types (structures) definitions that are defined by the developers? For example, the definition of the structure conversations___table I found in the file conversations_table.h.
For now, I need the definitions for the structures:
-conv___id_t
-nstime_t
-SAT_E
-address
-ptype
Thank you in advance.
Best regards,
Kiril
source-code definitions structures definitionasked 12 Sep &#39;12, 08:58</description>
    </item>
    
    <item>
      <title>Router replies with [RST] after [FIN, ACK]</title>
      <link>/questions/14212/router-replies-with-rst-after-fin-ack/</link>
      <pubDate>Wed, 12 Sep 2012 09:56:00 +0000</pubDate>
      
      <guid>/questions/14212/router-replies-with-rst-after-fin-ack/</guid>
      <description>Router replies with [RST] after [FIN, ACK]  0 I&#39;m testing an application which downloads info from photovoltaic equipment, so I have to connect to a remote power plant via Internet, using a TCP connection, I download info with my application and then I disconnect... Sometimes when I try to reconnect with remote power plant after few minutes, I can&#39;t do it, so, looking for a clue I have started capturing packets with wireshark and I can see that sometimes I send [FIN, ACK] and I get [ACK], then I get [FIN,ACK] and I send [ACK] and everything is OK for next connection, but sometimes I send [FIN,ACK] and I get [RST] and then I have to wait about 5 minutes before I can reconnect with remote router.</description>
    </item>
    
    <item>
      <title>Protocol port change or port adding in wireshark</title>
      <link>/questions/14213/protocol-port-change-or-port-adding-in-wireshark/</link>
      <pubDate>Wed, 12 Sep 2012 10:15:00 +0000</pubDate>
      
      <guid>/questions/14213/protocol-port-change-or-port-adding-in-wireshark/</guid>
      <description>Protocol port change or port adding in wireshark  0 In our product for LDAP we use 16110 as port along with default 389. SO everytime I need to &#34;decode as&#34; option. Is there any way to automatically decode the packets in this port?
I see one option in Edit --&amp;gt; Preferences --&amp;gt; Protocol --&amp;gt; LDAP, here I think I can change the port number, but anywhere I can add the port like - 389,16110 ?</description>
    </item>
    
    <item>
      <title>Count packets/bytes without capturing them?</title>
      <link>/questions/14215/count-packetsbytes-without-capturing-them/</link>
      <pubDate>Wed, 12 Sep 2012 11:46:00 +0000</pubDate>
      
      <guid>/questions/14215/count-packetsbytes-without-capturing-them/</guid>
      <description>Count packets/bytes without capturing them?  0 Hi, all. I hope this isn&#39;t repeating a question that&#39;s been asked; I did a search and couldn&#39;t find it:
I need to count throughput on my network without actually capturing packets -- it&#39;s a lot to store, and all I want is to add up the count of packets and bytes, by source and destination.
Can Wireshark do this without a hack or complicated workaround?</description>
    </item>
    
    <item>
      <title>Wireshark 1.8.2 won&amp;#x27;t start on Mac OS 10.6.8</title>
      <link>/questions/14224/wireshark-182-wont-start-on-mac-os-1068/</link>
      <pubDate>Wed, 12 Sep 2012 20:33:00 +0000</pubDate>
      
      <guid>/questions/14224/wireshark-182-wont-start-on-mac-os-1068/</guid>
      <description>Wireshark 1.8.2 won&amp;rsquo;t start on Mac OS 10.6.8  0 I just downloaded Wireshark 1.8.2. When I try to run it, it quits right after starting. The following is in the crash log:
Dyld Error Message: Library not loaded: /usr/X11/lib/libpng12.0.dylib Referenced from: /Applications/Wireshark.app/Contents/Resources/bin/wireshark-bin Reason: Incompatible library version: wireshark-bin requires version 47.0.0 or later, but libpng12.0.dylib provides version 45.0.0
I appear to have the latest X11 (2.7.3, also just downloaded), so I&#39;m not sure what the best thing to do about this is.</description>
    </item>
    
    <item>
      <title>How do I add a pdml tool that could benefit others</title>
      <link>/questions/14228/how-do-i-add-a-pdml-tool-that-could-benefit-others/</link>
      <pubDate>Thu, 13 Sep 2012 02:25:00 +0000</pubDate>
      
      <guid>/questions/14228/how-do-i-add-a-pdml-tool-that-could-benefit-others/</guid>
      <description>How do I add a pdml tool that could benefit others  0 I have written an app in VB.Net that can carry out two functions:
1) Create a raw binary of all the payload data contained in a .pdml file 2) Create a text file with the specific field data from all packets in a .pdml file by specifying the search string.
The application has been added to sourceforge at the following address:</description>
    </item>
    
    <item>
      <title>infiniband packet decode</title>
      <link>/questions/14233/infiniband-packet-decode/</link>
      <pubDate>Thu, 13 Sep 2012 06:35:00 +0000</pubDate>
      
      <guid>/questions/14233/infiniband-packet-decode/</guid>
      <description>infiniband packet decode  0 where do I find the sources for the infiniband packet decode ?
infinibandasked 13 Sep &#39;12, 06:35
Hal
1●1●1●1
accept rate: 0%
Got it. Thanks.
(13 Sep &#39;12, 06:52) Hal  
2 Answers:
  
0In the source tree:
epan\dissectors\packet-infiniband.c
epan\dissectors\packet-infiniband_sdp.c
Regards
Kurt
answered 13 Sep &#39;12, 06:42
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15% 
 edited 13 Sep &#39;12, 06:43</description>
    </item>
    
    <item>
      <title>How to detect a broken pipe using wireshark packet traces?</title>
      <link>/questions/14248/how-to-detect-a-broken-pipe-using-wireshark-packet-traces/</link>
      <pubDate>Thu, 13 Sep 2012 11:44:00 +0000</pubDate>
      
      <guid>/questions/14248/how-to-detect-a-broken-pipe-using-wireshark-packet-traces/</guid>
      <description>How to detect a broken pipe using wireshark packet traces?  0 I am getting a broken pipe socket error, most probably the other end is not closing the connection because the other end timeout later when it does not receive any packets. How can I find this by looking at packet trace. In case if the other end(destination) is closing the connection, should I see rst message at point of failure.</description>
    </item>
    
    <item>
      <title>Netscreen firewall Snoop detail captured for tunnel interface</title>
      <link>/questions/14255/netscreen-firewall-snoop-detail-captured-for-tunnel-interface/</link>
      <pubDate>Thu, 13 Sep 2012 22:45:00 +0000</pubDate>
      
      <guid>/questions/14255/netscreen-firewall-snoop-detail-captured-for-tunnel-interface/</guid>
      <description>Netscreen firewall Snoop detail captured for tunnel interface  0 Hi team,
I am a Netscreen Firewall user, I tried doing a snoop detail on tunnel interface, however couldn&#39;t open it in wireshark.
2530000.0: tunnel.50(it) vpn=AU-4350-vpn type=ipsec proto=0x0800 10.10.10.1 -&amp;gt; 224.0.0.5/89 vhl=45, tos=c0, id=520, frag=0000, ttl=1 tlen=228 ospf:ver=2, type=1, len=208 45 c0 00 e4 da 0c 00 00 01 59 77 c8 0a a6 7b 81 E........Yw...{. e0 00 00 05 02 01 00 d0 0a a6 91 c1 00 00 00 00 .</description>
    </item>
    
    <item>
      <title>reading (decoding?) IPFIX in wireshark</title>
      <link>/questions/14256/reading-decoding-ipfix-in-wireshark/</link>
      <pubDate>Thu, 13 Sep 2012 23:08:00 +0000</pubDate>
      
      <guid>/questions/14256/reading-decoding-ipfix-in-wireshark/</guid>
      <description>reading (decoding?) IPFIX in wireshark  0 Hey,
I can detect CFLOW messages in wireshark and they have the information I need,like the src address, dest address etc but when I do Follow UDP Stream the output in ASCII are characters like these &#34;.J.B......2........&#34; for example. So does anyone know if there is a way to decode these characters to get something useful out of them.
Thank you!
netflowasked 13 Sep &#39;12, 23:08</description>
    </item>
    
    <item>
      <title>why the client resend whole message to server?</title>
      <link>/questions/14257/why-the-client-resend-whole-message-to-server/</link>
      <pubDate>Thu, 13 Sep 2012 23:48:00 +0000</pubDate>
      
      <guid>/questions/14257/why-the-client-resend-whole-message-to-server/</guid>
      <description>why the client resend whole message to server?  0 client:any browser,PC(windows os) server:firewall-&amp;gt;F5-&amp;gt;IHS-&amp;gt;WAS In my case,a http request will be hanged by WAS for 10 min.Somtimes,When WAS hang the request for about 5 min,client(PC) will resend the whole message to server.I&#39;ve used httpwatch and fiddler to see the resent message,but can&#39;t catch any resent info.And wireshark can catch the resent info. The resent time decided by the F5&#39;s idle-time settings.</description>
    </item>
    
    <item>
      <title>win7 64bit wireshark 1.8.2 only can capture receive packets</title>
      <link>/questions/14259/win7-64bit-wireshark-182-only-can-capture-receive-packets/</link>
      <pubDate>Fri, 14 Sep 2012 00:44:00 +0000</pubDate>
      
      <guid>/questions/14259/win7-64bit-wireshark-182-only-can-capture-receive-packets/</guid>
      <description>win7 64bit wireshark 1.8.2 only can capture receive packets  0 I can get no http.request.method == GET packets at all~ I can&#39;t see my sent packets
64bit windows7 1.8.2asked 14 Sep &#39;12, 00:44
qsLampard
1●1●1●1
accept rate: 0%
 edited 21 Sep &#39;12, 08:36 
cmaynard ♦♦
9.4k●10●38●142
Interesting enough, or not, I am experiencing the same issue as you. I am running an IDS via a tap between two routers and I only see outbound traffic, nothing inbound even though the host is able to connect with no issues.</description>
    </item>
    
    <item>
      <title>Problem turning on monitor mode in Ubuntu</title>
      <link>/questions/14262/problem-turning-on-monitor-mode-in-ubuntu/</link>
      <pubDate>Fri, 14 Sep 2012 03:03:00 +0000</pubDate>
      
      <guid>/questions/14262/problem-turning-on-monitor-mode-in-ubuntu/</guid>
      <description>Problem turning on monitor mode in Ubuntu  2 1Hi all, I am trying to turn on monitor mode in Ubuntu 12.04 and wireshark 1.6.7 I have 2 wireless adapters 1. Ralink 2870/3070 instaled and working 2: Intel 5100 internal ok both have white field turn on monitor mode but both gives me error ---The capabilities of the capture device &#34;ra0&#34; could not be obtained (pcap_activate() failed: ra0: SIOCGIWPRIV: Argument list too long).</description>
    </item>
    
    <item>
      <title>Where can I go for (paid) network/protocol analysis services and consultancy?</title>
      <link>/questions/14264/where-can-i-go-for-paid-networkprotocol-analysis-services-and-consultancy/</link>
      <pubDate>Fri, 14 Sep 2012 03:28:00 +0000</pubDate>
      
      <guid>/questions/14264/where-can-i-go-for-paid-networkprotocol-analysis-services-and-consultancy/</guid>
      <description>Where can I go for (paid) network/protocol analysis services and consultancy?  7 1Sometimes people on this site look for support in analyzing trace files that go (a little) beyond what people offer here for free. There are quite a few people here that also do network/protocol analysis for a living. Would it be a good idea for those people to answer this question with the services they offer and how they can be contacted?</description>
    </item>
    
    <item>
      <title>RTP definition of forward (fwd) and reverse (rev)?</title>
      <link>/questions/14265/rtp-definition-of-forward-fwd-and-reverse-rev/</link>
      <pubDate>Fri, 14 Sep 2012 03:32:00 +0000</pubDate>
      
      <guid>/questions/14265/rtp-definition-of-forward-fwd-and-reverse-rev/</guid>
      <description>RTP definition of forward (fwd) and reverse (rev)?  0 Hi, Please can you tell me what is the definition of forward and reverse with regards to RTP analysis? Cheers Femto.
rtpasked 14 Sep &#39;12, 03:32
Femto
6●1●1●3
accept rate: 0%
  
One Answer:
  
2 RTP in itself has no forward and reverse direction, the sessions are totally independent. What binds them is the context in which they are used.</description>
    </item>
    
    <item>
      <title>Free Windows based tool - SPAN port configurator</title>
      <link>/questions/14266/free-windows-based-tool-span-port-configurator/</link>
      <pubDate>Fri, 14 Sep 2012 05:21:00 +0000</pubDate>
      
      <guid>/questions/14266/free-windows-based-tool-span-port-configurator/</guid>
      <description>Free Windows based tool - SPAN port configurator  0 Hi All, We here at www.netfort.com are about to release a new free tool which allows you to configure SPAN ports on Cisco switches. Even though its not a complicated task in the first place, the SPAN port configurator makes it really easy to setup SPAN ports with multiple vlan or port sources.
It will be a week or two before its available for download on our site but if any of you want a copy please email me at darragh.</description>
    </item>
    
    <item>
      <title>Block sniffing on ports - UBUNTU</title>
      <link>/questions/14267/block-sniffing-on-ports-ubuntu/</link>
      <pubDate>Fri, 14 Sep 2012 08:15:00 +0000</pubDate>
      
      <guid>/questions/14267/block-sniffing-on-ports-ubuntu/</guid>
      <description>Block sniffing on ports - UBUNTU  0 The server where Wireshark is running has two network interfaces with two networks. The «sniffed» network, and the «office» one, from where people connect to the server. I don´t want wireshark to be able to sniff the office network. How do I do that?
ports block ubuntuasked 14 Sep &#39;12, 08:15
ASantos
1●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Merging Different media type PCAP files</title>
      <link>/questions/14268/merging-different-media-type-pcap-files/</link>
      <pubDate>Fri, 14 Sep 2012 09:15:00 +0000</pubDate>
      
      <guid>/questions/14268/merging-different-media-type-pcap-files/</guid>
      <description>Merging Different media type PCAP files  0 Can I merge or concatanate a wireless PCAP capture file with a wired PCAP capture file?
mergeasked 14 Sep &#39;12, 09:15
MSshark
1●1●1●1
accept rate: 0%
  
One Answer:
  
0No that&#39;s not possible as mergecap will print this error message:
mergecap -w out.cap http.cap wlan.pcap
mergecap: Can&#39;t open or create out.cap: Files from that network type can&#39;t be saved in that format</description>
    </item>
    
    <item>
      <title>wireshark opens and closes immediately after startup (ubuntu)</title>
      <link>/questions/14269/wireshark-opens-and-closes-immediately-after-startup-ubuntu/</link>
      <pubDate>Fri, 14 Sep 2012 10:20:00 +0000</pubDate>
      
      <guid>/questions/14269/wireshark-opens-and-closes-immediately-after-startup-ubuntu/</guid>
      <description>wireshark opens and closes immediately after startup (ubuntu)  0 wireshark opens and closes immediately after startup when started as sudo. When started as a root user in ubuntu, additionally a segmentation fault appears. This happens when building from source code as well as installing using synaptic package manager. Any comments appreciated
startupasked 14 Sep &#39;12, 10:20
mna
1●1●1●1
accept rate: 0%
can you please post the seg fault message?</description>
    </item>
    
    <item>
      <title>On windows xp, error of temporary file</title>
      <link>/questions/14271/on-windows-xp-error-of-temporary-file/</link>
      <pubDate>Fri, 14 Sep 2012 12:52:00 +0000</pubDate>
      
      <guid>/questions/14271/on-windows-xp-error-of-temporary-file/</guid>
      <description>On windows xp, error of temporary file  0 I have windows xp;
I have this error;
The temporary file to which the capture would be saved (&#34;&#34;) could not be opened: No such file or directory.
how to solve?
windows temp errorasked 14 Sep &#39;12, 12:52
albs
1●2●2●3
accept rate: 0%
 edited 14 Sep &#39;12, 12:53 
  
One Answer:
  
0Wireshark writes a temp file while capturing (to be able to recover from crashes).</description>
    </item>
    
    <item>
      <title>Wireshark can track activity of a localhost php application (email, url .. activity)</title>
      <link>/questions/14273/wireshark-can-track-activity-of-a-localhost-php-application-email-url-activity/</link>
      <pubDate>Fri, 14 Sep 2012 13:05:00 +0000</pubDate>
      
      <guid>/questions/14273/wireshark-can-track-activity-of-a-localhost-php-application-email-url-activity/</guid>
      <description>Wireshark can track activity of a localhost php application (email, url .. activity)  0 I have in localhost on windows xp an php&#39;s application that run with easyphp (apache, php, mysql) Is possible with Wireshark to see all connections that php application does ? 1) the connection or datas that are send/required and at which url; 2) the email sended at which address and generally all the activity with the external</description>
    </item>
    
    <item>
      <title>Wireless disconnecting - need help diagnosing</title>
      <link>/questions/14278/wireless-disconnecting-need-help-diagnosing/</link>
      <pubDate>Fri, 14 Sep 2012 14:36:00 +0000</pubDate>
      
      <guid>/questions/14278/wireless-disconnecting-need-help-diagnosing/</guid>
      <description>Wireless disconnecting - need help diagnosing  0 We have an application that runs over wireless. One component of the application which is web based randomly disconnects. The other parts of the application do not and no other applications experience issues. I sent a Wireshark capture to the vendor but they only say it is on our network. The funny thing is that this is happening at three hospitals that I work at, all with the same application but different types of wireless access points, laptops, switches, etc.</description>
    </item>
    
    <item>
      <title>How does Wireshark reassemble TCP Segments</title>
      <link>/questions/14280/how-does-wireshark-reassemble-tcp-segments/</link>
      <pubDate>Fri, 14 Sep 2012 15:06:00 +0000</pubDate>
      
      <guid>/questions/14280/how-does-wireshark-reassemble-tcp-segments/</guid>
      <description>How does Wireshark reassemble TCP Segments  0 1I am dealing with a packet capture that has two TCP packets that are re-assembled TCP. How can wireshark associate the two packets together? I am talking about TCP re-assembly, not IP header fragment offset usage to identify reassembly. In fact the IP header ID&#39;s are not even in sequence. I am curious how Wireshark can associate the two packets correctly when there are no identifiable correlation between the two packets?</description>
    </item>
    
    <item>
      <title>What protocol should I use to trace raw hex SSL traffic?</title>
      <link>/questions/14284/what-protocol-should-i-use-to-trace-raw-hex-ssl-traffic/</link>
      <pubDate>Fri, 14 Sep 2012 16:28:00 +0000</pubDate>
      
      <guid>/questions/14284/what-protocol-should-i-use-to-trace-raw-hex-ssl-traffic/</guid>
      <description>What protocol should I use to trace raw hex SSL traffic?  0 I&#39;m tracing three IP addresses. Address A and Address B communicate with each other using HTTPS. Address C and B communicate with each other using raw packets that are encrypted using the same certificate as the other two. Address A and C are servers. My question is, when I configure Wireshark for SSL packets using the &#34;SSL Decrypt Edit&#34;</description>
    </item>
    
    <item>
      <title>Why isn&amp;#x27;t Application Data being decoded in SSL transactions?</title>
      <link>/questions/14286/why-isnt-application-data-being-decoded-in-ssl-transactions/</link>
      <pubDate>Fri, 14 Sep 2012 20:09:00 +0000</pubDate>
      
      <guid>/questions/14286/why-isnt-application-data-being-decoded-in-ssl-transactions/</guid>
      <description>Why isn&amp;rsquo;t Application Data being decoded in SSL transactions?  0 I have an SSL trace on CloudShark below my question. My question is why isn&#39;t the &#34;Application Data&#34; being decrypted in the trace? How can I get it decoded or can I? I keep seeing this in the debug
dissect_ssl enter frame #86 (first time) conversation = 04C66A1C, ssl_session = 04C675D0 record: offset = 0, reported_length_remaining = 2480 dissect_ssl3_record found version 0x0301(TLS 1.</description>
    </item>
    
    <item>
      <title>Newb question; viewing capture results</title>
      <link>/questions/14298/newb-question-viewing-capture-results/</link>
      <pubDate>Sat, 15 Sep 2012 19:36:00 +0000</pubDate>
      
      <guid>/questions/14298/newb-question-viewing-capture-results/</guid>
      <description>Newb question; viewing capture results  0 Hello I&#39;m taking a networking class and have been searching all weekend for my answer and I can&#39;t figure out how to do it.
I was told to do a 1 minute capture. I did that. I had like 604 packets captured. How do I find out which source address was used the most? How do I find that break down?
Also is asks: b.</description>
    </item>
    
    <item>
      <title>WS V1.8.2 on win server 2003, msvcr100.dll issue!</title>
      <link>/questions/14303/ws-v182-on-win-server-2003-msvcr100dll-issue/</link>
      <pubDate>Sun, 16 Sep 2012 06:15:00 +0000</pubDate>
      
      <guid>/questions/14303/ws-v182-on-win-server-2003-msvcr100dll-issue/</guid>
      <description>WS V1.8.2 on win server 2003, msvcr100.dll issue!  0 Hi
I have installed Wireshark version 1.8.2 (SVN Rev 44520 from /trunk-1.8) on a new win server 2003.
I can open a large (previously captured) packet capture file ~ 600MB, without any trouble.
When I select &#34;Telephony&#34; - &#34;VoIP Calls&#34;, I get a progress screen. This stalls at about 60%, and 30 sec later wireshark ends.
Event log shows: Faulting application wireshark.</description>
    </item>
    
    <item>
      <title>Wireshark QuickStart Guide</title>
      <link>/questions/14308/wireshark-quickstart-guide/</link>
      <pubDate>Sun, 16 Sep 2012 19:21:00 +0000</pubDate>
      
      <guid>/questions/14308/wireshark-quickstart-guide/</guid>
      <description>Wireshark QuickStart Guide  0 Are there answers available to the exercises in the Wireshark QuickStart Guide?
quickstart answersasked 16 Sep &#39;12, 19:21
dude101
1●1●1●1
accept rate: 0%
And by &#34;Wireshark Quickstart Guide&#34; you are referring to which guide exactly (please provide the URL)?
(17 Sep &#39;12, 00:47) SYN-bit ♦♦   </description>
    </item>
    
    <item>
      <title>Query about combining capture filter</title>
      <link>/questions/14310/query-about-combining-capture-filter/</link>
      <pubDate>Sun, 16 Sep 2012 21:13:00 +0000</pubDate>
      
      <guid>/questions/14310/query-about-combining-capture-filter/</guid>
      <description>Query about combining capture filter  0 Hello all,
I am new to wireshark and wireshark community. I am preparing for wcna exam and have the below query. I am right now studying packet capture filters and I am successfully able to write this filter
tcp[1] == 80 , while i want to also to do the filter tcp[1]== 80 &amp;amp; tcp[2] == 443, wireshark is not accepting the filter, while wireshark is accepting tcp[1]==80 &amp;amp; tcp[2]</description>
    </item>
    
    <item>
      <title>Wireshark 1.8.2 is only displaying 2 filters from the drop-down menu</title>
      <link>/questions/14319/wireshark-182-is-only-displaying-2-filters-from-the-drop-down-menu/</link>
      <pubDate>Mon, 17 Sep 2012 07:21:00 +0000</pubDate>
      
      <guid>/questions/14319/wireshark-182-is-only-displaying-2-filters-from-the-drop-down-menu/</guid>
      <description>Wireshark 1.8.2 is only displaying 2 filters from the drop-down menu  0 I have recently upgraded to Wireshark 1.8.2 on Windows 7 (64-bit). On the top menu bar, the filter area is only displaying the latest 2 created filters. In previous Wireshark versions, I was able to view at least the latest 10 or more filters. I have made changes to the following areas in Wireshark: 1) Edit -&amp;gt; Preferences -&amp;gt; User Interface -&amp;gt; Filter display max.</description>
    </item>
    
    <item>
      <title>Need to decode ssl locally</title>
      <link>/questions/14321/need-to-decode-ssl-locally/</link>
      <pubDate>Mon, 17 Sep 2012 08:35:00 +0000</pubDate>
      
      <guid>/questions/14321/need-to-decode-ssl-locally/</guid>
      <description>Need to decode ssl locally  0 I want to decode the traffic between a desktop application (on my desktop) and a server out over the Internet. This is HTTPS traffic, but not from a web browser.
There is no pre-shared key or such, but it is traffic on my machine so I don&#39;t think it&#39;s unreasonable to be able to decode this stream to see what information is being sent.</description>
    </item>
    
    <item>
      <title>No Data indication is it possible ?</title>
      <link>/questions/14322/no-data-indication-is-it-possible/</link>
      <pubDate>Mon, 17 Sep 2012 08:52:00 +0000</pubDate>
      
      <guid>/questions/14322/no-data-indication-is-it-possible/</guid>
      <description>No Data indication is it possible ?  0 I am running some tests and need a quick visual indication.
I have set up a display filter for the correct ip, i have also set a display colour for packets arriving over the specified time frame.
What I want to do is display a colour or other alert if data stops completely.
Example: Data is coming in on filtered ip. (done this) A red line is shown when a packet arrives late (my time specified) (done this)</description>
    </item>
    
    <item>
      <title>How to monitor internet usage over a network?</title>
      <link>/questions/14328/how-to-monitor-internet-usage-over-a-network/</link>
      <pubDate>Mon, 17 Sep 2012 11:22:00 +0000</pubDate>
      
      <guid>/questions/14328/how-to-monitor-internet-usage-over-a-network/</guid>
      <description>How to monitor internet usage over a network?  0 Hi,
I&#39;m a newbie of using WireShark, just told by our network provider to use it in order to check internal usage of bandwidth as they are saying, it&#39;s perfectly fine but we are experiencing very slow internet connection as we have many tenants who are using same internet. It was working perfectly fine about 2 weeks ago but there&#39;s something ambiguous activities going on, so, I would like to check which IP or who is using infact abusing the internet.</description>
    </item>
    
    <item>
      <title>Setting Development Project Under Visual Studio 2012</title>
      <link>/questions/14343/setting-development-project-under-visual-studio-2012/</link>
      <pubDate>Tue, 18 Sep 2012 02:23:00 +0000</pubDate>
      
      <guid>/questions/14343/setting-development-project-under-visual-studio-2012/</guid>
      <description>Setting Development Project Under Visual Studio 2012  1 although i believe that not all new must be better. trying to create my development project for Wire Shark in the first time, and although the developers guide is pretty great, it seems it not yet updated for development under visual studio 2012.
after going through steps of the Win32: Step-by-Step Guide in sub section 2.2, and all went quite well and easy, i came to a problem while trying to verify all installed tool as described in sub section &#34;</description>
    </item>
    
    <item>
      <title>Custom Dissector help!</title>
      <link>/questions/14345/custom-dissector-help/</link>
      <pubDate>Tue, 18 Sep 2012 04:21:00 +0000</pubDate>
      
      <guid>/questions/14345/custom-dissector-help/</guid>
      <description>Custom Dissector help!  0 I&#39;ve got an interesting problem.
I need to create a dissector for a custom protocol, The protocol is very simple and is designed to work on a point to point link as follows.
1 DWORD (32 bits) of Header, the lowest 16 bits of which are a sequence number. Multiples of 8DWORDS which represent Data samples.
I&#39;ve got the header dissection working, but I can&#39;t work out a neat way of chunking up the Data into samples (32 byte chunks following the header).</description>
    </item>
    
    <item>
      <title>detect/prevent wireshark?</title>
      <link>/questions/14351/detectprevent-wireshark/</link>
      <pubDate>Tue, 18 Sep 2012 09:30:00 +0000</pubDate>
      
      <guid>/questions/14351/detectprevent-wireshark/</guid>
      <description>detect/prevent wireshark?  0 Someone on my network have wireshark. Can someone tell me how i can detect if he capturing my pc-internet packets? I mean detect or prevent wireshark of doing it.
detection preventasked 18 Sep &#39;12, 09:30
Johnny
1●1●1●2
accept rate: 0%
  
3 Answers:
  
2Basically you can detect if a system on the same subnet is running a sniffer, if some conditions are fulfilled (see below).</description>
    </item>
    
    <item>
      <title>what IS wireshark</title>
      <link>/questions/14354/what-is-wireshark/</link>
      <pubDate>Tue, 18 Sep 2012 11:47:00 +0000</pubDate>
      
      <guid>/questions/14354/what-is-wireshark/</guid>
      <description>what IS wireshark  0 All,
Just passing through, but there are so many things about this site which, on first glance, seem to be so very cool, that I thought I&#39;d make a comment. I got here by Googling &#39;wireshark&#39;--I read a reference to it in a context that made me want to know more--but, getting here, I can&#39;t find a single thing that explains what wireshark is. The FAQs explain the rules of the forum very well, but there seems to be no FAQ about the software itself.</description>
    </item>
    
    <item>
      <title>Tshark io,stat, filtering broken in 1.8.x?</title>
      <link>/questions/14367/tshark-iostat-filtering-broken-in-18x/</link>
      <pubDate>Tue, 18 Sep 2012 23:53:00 +0000</pubDate>
      
      <guid>/questions/14367/tshark-iostat-filtering-broken-in-18x/</guid>
      <description>Tshark io,stat, filtering broken in 1.8.x?  0 Hi all,
i was just trying to use filters in tshark -r file.pcap -qz io,stat,0,filter1,filter2,filter3... which works perfectly up to 1.6.x but in my 1.8.2 tshark always just throws me the all packet statistics without any filter and without displaying multiple coloumns like one per filter which it should do and always did with pre-1.8 versions.
Any suggestions or did I overlook something in the release notes like syntax change or anything?</description>
    </item>
    
    <item>
      <title>capture filter MAC</title>
      <link>/questions/14368/capture-filter-mac/</link>
      <pubDate>Wed, 19 Sep 2012 00:20:00 +0000</pubDate>
      
      <guid>/questions/14368/capture-filter-mac/</guid>
      <description>capture filter MAC  0 when i write in the filter i get an error, this is what i write: &#34;ether host &#39;macaddress&#39;&#34;. I want to filter it so it only displays packets from the host Mac-address. And when i starts to write &#39;ether&#39; it doesn&#39;t come up white anything i can use. How can a make it capture the MAC address.
capture mac mac-addressasked 19 Sep &#39;12, 00:20
Munken</description>
    </item>
    
    <item>
      <title>ping duplicate request and replies ?</title>
      <link>/questions/14370/ping-duplicate-request-and-replies/</link>
      <pubDate>Wed, 19 Sep 2012 01:18:00 +0000</pubDate>
      
      <guid>/questions/14370/ping-duplicate-request-and-replies/</guid>
      <description>ping duplicate request and replies ?  0 Hello, I am sending a PING between one two computers. I am finding that Wireshark is detecting duplicate frames of each ping request and reply. I notice each of the duplicates has a different source value e.g. one is: Source: Cisco4f:b1:05 (00:21:a0:4f:b1:05) the other is: Source: DigitalD99:0a:3d (00:11:6b:99:0a:3d)
Is this because of multiple interfaces on my routers, or is it some other reason ?</description>
    </item>
    
    <item>
      <title>Bad packets - UDP port incrementing - Network Canon printer</title>
      <link>/questions/14373/bad-packets-udp-port-incrementing-network-canon-printer/</link>
      <pubDate>Wed, 19 Sep 2012 04:40:00 +0000</pubDate>
      
      <guid>/questions/14373/bad-packets-udp-port-incrementing-network-canon-printer/</guid>
      <description>Bad packets - UDP port incrementing - Network Canon printer  0 Hello and thank you for reading my post.
Here is my problem:
My PC IP address is x.y.z.w1.On the same LAN, I have a Canon printer which IP address is x.y.z.w2.When I observe the traffic on my PC network interface using Wireshark, I observe lots of packets like these:No. Time Source Destination Protocol Length Info --------------------------------------------------------------------------------------------------------- 1 0.000000000 x.</description>
    </item>
    
    <item>
      <title>Save TFTP transferred file from capture</title>
      <link>/questions/14375/save-tftp-transferred-file-from-capture/</link>
      <pubDate>Wed, 19 Sep 2012 05:05:00 +0000</pubDate>
      
      <guid>/questions/14375/save-tftp-transferred-file-from-capture/</guid>
      <description>Save TFTP transferred file from capture  0 I have monitored a TFTP session of a file being transfered. Is there any way to extract the file from the capture?
capture tftp save fileasked 19 Sep &#39;12, 05:05
Vlad
1●1●1●1
accept rate: 0%
 edited 20 Sep &#39;12, 10:07 
cmaynard ♦♦
9.4k●10●38●142
1The current development version of Wireshark (post 1.12) now does let you export files transferred over TFTP. See &#39;File | Export Objects | TFTP&#39;.</description>
    </item>
    
    <item>
      <title>Generating TSHARK decoded output from TCPDUMP PCAP file ? without tshark</title>
      <link>/questions/14376/generating-tshark-decoded-output-from-tcpdump-pcap-file-without-tshark/</link>
      <pubDate>Wed, 19 Sep 2012 05:36:00 +0000</pubDate>
      
      <guid>/questions/14376/generating-tshark-decoded-output-from-tcpdump-pcap-file-without-tshark/</guid>
      <description>Generating TSHARK decoded output from TCPDUMP PCAP file ? without tshark  0 Hello,
I would like to convert tcpdump output into tshark standard decoded output. As you know tcpdump don&#39;t summarize gathered data just like tshark does it. That&#39;s too bad, because there are so many doubled values in the pcap file: for example:
ipsrc,port,ipdest,port,data_sent
10.38.39.245,1267,10.238.125.83,9999,0
10.38.39.245,1267,10.238.125.83,9999,116
10.227.40.61,2491,10.238.125.83,9999,0
I would like to have decoded output, similiar to this from t-shark</description>
    </item>
    
    <item>
      <title>capture filter,  syntax error in filter string, wireshark 1.8.2</title>
      <link>/questions/14380/capture-filter-syntax-error-in-filter-string-wireshark-182/</link>
      <pubDate>Wed, 19 Sep 2012 09:16:00 +0000</pubDate>
      
      <guid>/questions/14380/capture-filter-syntax-error-in-filter-string-wireshark-182/</guid>
      <description>capture filter, syntax error in filter string, wireshark 1.8.2  0 i upgraded to wirshark 1.8.0 , could not get a filter to work , syntex error in filter string . i upgraded to wireshark 1.8.2 , still the same problem . tried two filters filter name = IP address 192.168.0.1 filter string = host 192.168.0.1
filter name = test ip address filter string = ! ( ip.addr == 10.43.54.65 )</description>
    </item>
    
    <item>
      <title>&amp;quot;Piping&amp;quot; to wireshark airodump-ng or airoserv-ng</title>
      <link>/questions/14383/piping-to-wireshark-airodump-ng-or-airoserv-ng/</link>
      <pubDate>Wed, 19 Sep 2012 11:15:00 +0000</pubDate>
      
      <guid>/questions/14383/piping-to-wireshark-airodump-ng-or-airoserv-ng/</guid>
      <description>&amp;ldquo;Piping&amp;rdquo; to wireshark airodump-ng or airoserv-ng  0 Hi, I would like to pipe the output of airodump or airoserv to wireshark in a remote way and thus I will be able to use wireshark tools. However, I&#39;m not able to do, I have tried to do it in two ways.
-First one: create a connection to airserver-ng and the retrieved output is pipped as input to wireshark,but doing this I get an error on wireshark saying that &#34;</description>
    </item>
    
    <item>
      <title>How does TCP track sequence numbers?</title>
      <link>/questions/14393/how-does-tcp-track-sequence-numbers/</link>
      <pubDate>Thu, 20 Sep 2012 06:34:00 +0000</pubDate>
      
      <guid>/questions/14393/how-does-tcp-track-sequence-numbers/</guid>
      <description>How does TCP track sequence numbers?  0 1Hey Guys,
So, I&#39;m developing a dissector for a custom protocol (let&#39;s call it foo for now), part of that protocol is an incrementing sequence number, which we call a heartbeat, it&#39;s synonymous with &#34;Packet Number&#34; (this hbt = last_hbt++, very simple to check to see if we missed a packet).
I&#39;ve been trying to get this working with the conversation interface, but I&#39;ve run into an issue.</description>
    </item>
    
    <item>
      <title>Saved RTP Payload Bigger than expected</title>
      <link>/questions/14397/saved-rtp-payload-bigger-than-expected/</link>
      <pubDate>Thu, 20 Sep 2012 07:43:00 +0000</pubDate>
      
      <guid>/questions/14397/saved-rtp-payload-bigger-than-expected/</guid>
      <description>Saved RTP Payload Bigger than expected  0 Hi, I have an RTP packet capture 273 seconds long. There are 13654 packets in the forward direction and 13646 in the reverse. There are no lost packets and virtually no jitter. The codec is G.729. When I use the &#34;Save payload&#34; feature I get files of 285260 and 272920 bytes respectively for forward and reverse. When I then convert these into PCM the audio file in the forward direction is ~15 seconds too long!</description>
    </item>
    
    <item>
      <title>CIP Motion capture</title>
      <link>/questions/14399/cip-motion-capture/</link>
      <pubDate>Thu, 20 Sep 2012 08:14:00 +0000</pubDate>
      
      <guid>/questions/14399/cip-motion-capture/</guid>
      <description>CIP Motion capture  0 Hello
I&#39;m using WS 1.7.0. With that revision I can trace CIP Motion traffic I have downloaded the 1.8.0 I can&#39;t read the CIP traffic ! do you know if I have to a special setup in WS 1.8.8 ?
Thanks a lot
motion cipasked 20 Sep &#39;12, 08:14
vincentb
1●1●1●1
accept rate: 0%
  
One Answer:
  
0In general there are two options:</description>
    </item>
    
    <item>
      <title>How do I track packet loss when I have the UDP protocol ?</title>
      <link>/questions/14406/how-do-i-track-packet-loss-when-i-have-the-udp-protocol/</link>
      <pubDate>Thu, 20 Sep 2012 11:02:00 +0000</pubDate>
      
      <guid>/questions/14406/how-do-i-track-packet-loss-when-i-have-the-udp-protocol/</guid>
      <description>How do I track packet loss when I have the UDP protocol ?  0 How do I track packet loss when I have the UDP protocol?
loss udp packetasked 20 Sep &#39;12, 11:02
souss
6●2●2●4
accept rate: 0%
 edited 20 Sep &#39;12, 13:54 
Jim Aragon
7.2k●7●33●118
Hello Jim, When you said : then you could display that number in a custom column and manually look for missing numbers.</description>
    </item>
    
    <item>
      <title>Capturing packets on wifi devices</title>
      <link>/questions/14409/capturing-packets-on-wifi-devices/</link>
      <pubDate>Thu, 20 Sep 2012 14:42:00 +0000</pubDate>
      
      <guid>/questions/14409/capturing-packets-on-wifi-devices/</guid>
      <description>Capturing packets on wifi devices  0 I have a cisco router with a port mirroring function. I set it up so my wifi traffic is being mirrored to a port in which my computer is connected to with wireshark running. This used to work for me back in the day, but I dont know why its not working anymore. Are their some sort of IP Address conflict that I may be running in to?</description>
    </item>
    
    <item>
      <title>Feature Request: Being able to add a Column which is a calculated field</title>
      <link>/questions/14418/feature-request-being-able-to-add-a-column-which-is-a-calculated-field/</link>
      <pubDate>Fri, 21 Sep 2012 02:31:00 +0000</pubDate>
      
      <guid>/questions/14418/feature-request-being-able-to-add-a-column-which-is-a-calculated-field/</guid>
      <description>Feature Request: Being able to add a Column which is a calculated field  0 I often need to analyze FIX messages and doing this I could really need a way to be able to create a &#34;calculated field&#34;.
e.g. - I have a trace containing FIX stream - I have the OS timestamp when we received the message - I have the FIX time stamp inside the message in SendingTime (Tag52)</description>
    </item>
    
    <item>
      <title>SSL Record Layer vs SSLv3 Record Layer</title>
      <link>/questions/14419/ssl-record-layer-vs-sslv3-record-layer/</link>
      <pubDate>Fri, 21 Sep 2012 02:39:00 +0000</pubDate>
      
      <guid>/questions/14419/ssl-record-layer-vs-sslv3-record-layer/</guid>
      <description>SSL Record Layer vs SSLv3 Record Layer  0 Hi,
I have two captures, one of an successful SSL handshake, and one of an unsuccessful SSL handshake (server never responded with server hello but instead sent a FIN,ACK).
The successful one displays in wireshark protocol column as SSLv3, and in the decoding window shows like so:
Secure Socket Layer SSLv3 Record Layer: Handshake Protocol: Client Hello Content Type: Handshake (22) Version: SSL 3.</description>
    </item>
    
    <item>
      <title>unable run wireshark after install</title>
      <link>/questions/14420/unable-run-wireshark-after-install/</link>
      <pubDate>Fri, 21 Sep 2012 03:13:00 +0000</pubDate>
      
      <guid>/questions/14420/unable-run-wireshark-after-install/</guid>
      <description>unable run wireshark after install  0 I have built wireshark 1.7.0, lua ver lua5.1.dll from win7 OS, 32 bit installer using VS 2008. have set target to win32. After installation when run on a m/c without VS 2008 , it throws an error &#34;unable to start application &#34; with error code 0xc150002 and terminates. It runs properly on a m/c with VS 2008
Please answer 1) can we build an installer on win7 , a 32 bit installer?</description>
    </item>
    
    <item>
      <title>Source/Destination for UDP packets reversed in 1.8.2 windows 32</title>
      <link>/questions/14432/sourcedestination-for-udp-packets-reversed-in-182-windows-32/</link>
      <pubDate>Fri, 21 Sep 2012 08:03:00 +0000</pubDate>
      
      <guid>/questions/14432/sourcedestination-for-udp-packets-reversed-in-182-windows-32/</guid>
      <description>Source/Destination for UDP packets reversed in 1.8.2 windows 32  0 I&#39;ve been using Ethereal/Wireshark for many years. Today I&#39;ve been using Wireshark 1.8.2 to look at UDP packets between an embedded device I am developing and a PC. Everything works OK, except the Source and Destination IP addresses seem to be swapped on the display. Actually the TCP source/destination seem swapped as well. When looking at the Ethernet II header display, the source and Destination are swapped there as well.</description>
    </item>
    
    <item>
      <title>Help with Skinny of Cisco Please.</title>
      <link>/questions/14433/help-with-skinny-of-cisco-please/</link>
      <pubDate>Fri, 21 Sep 2012 08:42:00 +0000</pubDate>
      
      <guid>/questions/14433/help-with-skinny-of-cisco-please/</guid>
      <description>Help with Skinny of Cisco Please.  0 Hello! very good day. I dared to write in your forum to ask because I have a problem and I have spent a long time looking for the solution but I can not solve the problem. I commented: I need to record calls that are generated in a Cisco Call Manager using Wireshark.
So I did the following:
Enable a mirror port on my Cisco switch so I could IM traffic esuchar Call Manager Operating.</description>
    </item>
    
    <item>
      <title>Which layer packets are captured?</title>
      <link>/questions/14437/which-layer-packets-are-captured/</link>
      <pubDate>Fri, 21 Sep 2012 09:58:00 +0000</pubDate>
      
      <guid>/questions/14437/which-layer-packets-are-captured/</guid>
      <description>Which layer packets are captured?  0 Hello, Can you please let me know at which layer snoop captures packets? Is it after physical layer or?
Thanks, Siva
layerasked 21 Sep &#39;12, 09:58
vnkt4u
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Is that &#34;snoop&#34; as in &#34;the Solaris (and IRIX?) packet analyzer named &#34;snoop&#34;&#34; or &#34;snoop&#34; as in &#34;packet analyzers in general, including Wireshark&#34;?
In either case, if you use the OSI model, the capturing is usually done at the data link layer, above the physical layer, at least for LAN traffic.</description>
    </item>
    
    <item>
      <title>iSCSI Latency</title>
      <link>/questions/14446/iscsi-latency/</link>
      <pubDate>Sat, 22 Sep 2012 03:35:00 +0000</pubDate>
      
      <guid>/questions/14446/iscsi-latency/</guid>
      <description>iSCSI Latency  0 Hello,
I have been working on a major issue in our enviroment since monday morning. We have a couple of iscsi san&#39;s (equallogic) those are connected to a stack of 4 dell switches and then i have a couple of dell server running vmware esx. (i ever have it from windows btw..) Now i generate with IOmeter 64KB read&#39;s and i get a latency of +/-270MS.</description>
    </item>
    
    <item>
      <title>Multiple RST packets in HTTPS and then Connection Termination</title>
      <link>/questions/14447/multiple-rst-packets-in-https-and-then-connection-termination/</link>
      <pubDate>Sat, 22 Sep 2012 04:02:00 +0000</pubDate>
      
      <guid>/questions/14447/multiple-rst-packets-in-https-and-then-connection-termination/</guid>
      <description>Multiple RST packets in HTTPS and then Connection Termination  0 Hi All,
I have been analyzing the wire shark logs of an HTTPS communication between two Applications. One applications works always, and the second one causes intermittent failures. I will post the logs of the one sample dialogue between the two and highlight the differences. But being new to Wire shark, I am not able to interpret what behavior change is being caused by the difference, and need your expert opinion on the same:</description>
    </item>
    
    <item>
      <title>Trace outgoing system account</title>
      <link>/questions/14449/trace-outgoing-system-account/</link>
      <pubDate>Sat, 22 Sep 2012 14:37:00 +0000</pubDate>
      
      <guid>/questions/14449/trace-outgoing-system-account/</guid>
      <description>Trace outgoing system account  0 Hi We have an application (IBM Notes) which communicates with several other systems (servers), but we don&#39;t know which, although we do know that it uses its system account to communicate.
Is it possible in Wireshark to trace which servers the account communicates with? I&#39;ve tried to look in Conversations and Endpoint but with no luck.
Thanks
//hp
user traceasked 22 Sep &#39;12, 14:37</description>
    </item>
    
    <item>
      <title>Instructor help</title>
      <link>/questions/14455/instructor-help/</link>
      <pubDate>Sat, 22 Sep 2012 20:22:00 +0000</pubDate>
      
      <guid>/questions/14455/instructor-help/</guid>
      <description>Instructor help  0 I am teaching Intrusion Detection and Protection course. We will be using Wireshark as the tool. Do you have any resources available for instructor or postprocessors which student could use.
instructor resourcesThis question is marked &#34;community wiki&#34;.asked 22 Sep &#39;12, 20:22
divaker
1●1●1●1
accept rate: 0%
  
One Answer:
  
0How about http://wiki.wireshark.org? Or if you prefer a book you should check out Laura&#39;s Wireshark study guide at http://wiresharkbook.</description>
    </item>
    
    <item>
      <title>All packet information outwrite</title>
      <link>/questions/14458/all-packet-information-outwrite/</link>
      <pubDate>Sun, 23 Sep 2012 02:19:00 +0000</pubDate>
      
      <guid>/questions/14458/all-packet-information-outwrite/</guid>
      <description>All packet information outwrite  0 Hi!
I would like all packet information outwrite. But i can write out only IP header and media_attr, sdp data, sip data...etc... How can i all information outwrite with LUA?
information packet outwriteasked 23 Sep &#39;12, 02:19
speede05
6●2●2●4
accept rate: 0%
 edited 23 Sep &#39;12, 02:56 
   </description>
    </item>
    
    <item>
      <title>Broken TCP ACK in the SYN Packet</title>
      <link>/questions/14462/broken-tcp-ack-in-the-syn-packet/</link>
      <pubDate>Sun, 23 Sep 2012 07:59:00 +0000</pubDate>
      
      <guid>/questions/14462/broken-tcp-ack-in-the-syn-packet/</guid>
      <description>Broken TCP ACK in the SYN Packet  0 The SYN packet is reporting a broken TCP. Why does this being reported in the SYN and if there&#39;s any possible issue for the rest of the connections?
brokentcpasked 23 Sep &#39;12, 07:59
ws2006
1●12●12●14
accept rate: 0%
You may be referring to the fact that ACK field is not set, and yet the ACK field is non-zero. Is that the error message you&#39;re getting?</description>
    </item>
    
    <item>
      <title>Failed to Build Wireshark due to Microsoft Resource File To COFF Object Conversion Utility has stopped working</title>
      <link>/questions/14463/failed-to-build-wireshark-due-to-microsoft-resource-file-to-coff-object-conversion-utility-has-stopped-working/</link>
      <pubDate>Sun, 23 Sep 2012 12:05:00 +0000</pubDate>
      
      <guid>/questions/14463/failed-to-build-wireshark-due-to-microsoft-resource-file-to-coff-object-conversion-utility-has-stopped-working/</guid>
      <description>Failed to Build Wireshark due to Microsoft Resource File To COFF Object Conversion Utility has stopped working  0 When I run &#34;nmake -f Makefile.nmake all&#34; to build Wireshark for the very first time I got a pop-up from Windows saying &#34;Microsoft Resource File To COFF Object Conversion Utility ha stopped working&#34;, and so build fails. In the command prompt where I was doing the build I see the following.</description>
    </item>
    
    <item>
      <title>in ue aggregatemaximum bitrate ie of ranap  not able to display the values</title>
      <link>/questions/14478/in-ue-aggregatemaximum-bitrate-ie-of-ranap-not-able-to-display-the-values/</link>
      <pubDate>Mon, 24 Sep 2012 05:53:00 +0000</pubDate>
      
      <guid>/questions/14478/in-ue-aggregatemaximum-bitrate-ie-of-ranap-not-able-to-display-the-values/</guid>
      <description>in ue aggregatemaximum bitrate ie of ranap not able to display the values  0 in ue aggregatemaximum bitrate ie of ranap iam able to display the present bit map of ue aggregate-maximum bit rate down link and ue aggregate-maximum bit-rate down-link also the constrained integer length for the both on wire-shark .but iam not able to display both the vales on wire-shark . iam getting dissector bug , protocol RANAP: proto.</description>
    </item>
    
    <item>
      <title>Wireshark caps taken in Linux are unavailable in windows</title>
      <link>/questions/14480/wireshark-caps-taken-in-linux-are-unavailable-in-windows/</link>
      <pubDate>Mon, 24 Sep 2012 08:06:00 +0000</pubDate>
      
      <guid>/questions/14480/wireshark-caps-taken-in-linux-are-unavailable-in-windows/</guid>
      <description>Wireshark caps taken in Linux are unavailable in windows  0 Hi,
I have captures taken in a Linux (ubunto) virtual machine. I transferred them using ftp to a windows 7 virtual machine and I&#39;m getting the following message: &#34;The capture file appears to be damaged or corrupt. (pcap: File has 3186583733-byte packet, bigger then maximum of 65535)&#34; I tried saving the captures in other formats but getting the same resault.</description>
    </item>
    
    <item>
      <title>Who&amp;#x27;s got the wrong password?</title>
      <link>/questions/14482/whos-got-the-wrong-password/</link>
      <pubDate>Mon, 24 Sep 2012 08:19:00 +0000</pubDate>
      
      <guid>/questions/14482/whos-got-the-wrong-password/</guid>
      <description>Who&amp;rsquo;s got the wrong password?  0 Hi (wireshark newbee here), I work in a school where we occasionally have to update client software from an external local education authority source. This means we have to use a mapped drive to a server on a different subnet thus requiring a different domain\username and password. As this update applies to more than 30 members of staff the mapped drive is connected via batch script with one username and password.</description>
    </item>
    
    <item>
      <title>SIP Sequence Number Question</title>
      <link>/questions/14486/sip-sequence-number-question/</link>
      <pubDate>Mon, 24 Sep 2012 14:21:00 +0000</pubDate>
      
      <guid>/questions/14486/sip-sequence-number-question/</guid>
      <description>SIP Sequence Number Question  0 I have a PCAP for a SIP session that has the relative sequence number start at 1509 and then after 6 packets it restarts at zero and then subsequently thinking that everything afterwards is out of sequence. What is value &#34;SET&#34; mean in the Marker column? I see it as set to True in the Packet detail screen in the Marker parameter field. Normally this occurs at the very beginning of the session.</description>
    </item>
    
    <item>
      <title>SIP Synchronization Source Identifier (SSRC) Determination Method</title>
      <link>/questions/14487/sip-synchronization-source-identifier-ssrc-determination-method/</link>
      <pubDate>Mon, 24 Sep 2012 14:31:00 +0000</pubDate>
      
      <guid>/questions/14487/sip-synchronization-source-identifier-ssrc-determination-method/</guid>
      <description>SIP Synchronization Source Identifier (SSRC) Determination Method  0 How does Wireshark determine the which RTP streams are part of a call. In a multiple stream PCAP, how does it determine who belongs to who?
thanks
Eric
sip rtp voipasked 24 Sep &#39;12, 14:31
EricKnaus
46●19●20●26
accept rate: 0%
  
One Answer:
  
1First of all SSRC stands for Synchronization Source Identifier in the context of RTP.</description>
    </item>
    
    <item>
      <title>Wireshark Debug Console buffer size</title>
      <link>/questions/14493/wireshark-debug-console-buffer-size/</link>
      <pubDate>Mon, 24 Sep 2012 22:07:00 +0000</pubDate>
      
      <guid>/questions/14493/wireshark-debug-console-buffer-size/</guid>
      <description>Wireshark Debug Console buffer size  0 I&#39;m printing certain messages to the debug console to decode a small section of my code. I print specific messages everytime certain dissectors are called (most are called for each packet), however some of the earlier messages get cut off because the debug console doesn&#39;t scroll up to the place where they&#39;ve been printed. And I don&#39;t want to write to file because it slows down my work.</description>
    </item>
    
    <item>
      <title>wireshark 1.4.3</title>
      <link>/questions/14499/wireshark-143/</link>
      <pubDate>Tue, 25 Sep 2012 02:47:00 +0000</pubDate>
      
      <guid>/questions/14499/wireshark-143/</guid>
      <description>wireshark 1.4.3  0 We require wireshark 1.4.3 for PMU test lab. whether wireshark 1.4.3 is available for free?
wireshark1.2.5asked 25 Sep &#39;12, 02:47
sci
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Have a look at the download area, e.g. for win32 see here.
answered 25 Sep &#39;12, 02:58
grahamb ♦
19.8k●3●30●206
accept rate: 22%
  
0... and several others here. As well as your favorite Linux distribution may have it on file in their repositories.</description>
    </item>
    
    <item>
      <title>&amp;quot;save as&amp;quot; functionality</title>
      <link>/questions/14502/save-as-functionality/</link>
      <pubDate>Tue, 25 Sep 2012 03:49:00 +0000</pubDate>
      
      <guid>/questions/14502/save-as-functionality/</guid>
      <description>&amp;ldquo;save as&amp;rdquo; functionality  0 I installed Wireshark 1.8.2 on Windows 7, when I try to save a file using &#34;Save as&#34; function, following fields are showed: &#34;File name&#34; and &#34;save as type&#34; but the field &#34;Packet range&#34; is not displayed (so I can&#39;t select packets to be saved).
range save packetasked 25 Sep &#39;12, 03:49
pmoz
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1The option to only &#34;</description>
    </item>
    
    <item>
      <title>SNMP router port monitoring</title>
      <link>/questions/14503/snmp-router-port-monitoring/</link>
      <pubDate>Tue, 25 Sep 2012 03:50:00 +0000</pubDate>
      
      <guid>/questions/14503/snmp-router-port-monitoring/</guid>
      <description>SNMP router port monitoring  0 I have a network setup with about 15 Mac workstations connecting to a router with SNMP. Can wireshark monitor all web traiffic (souce and destination IP) going over router? I want to install Wireshark on a mac workstation with OS 10.4.11 .
snmpasked 25 Sep &#39;12, 03:50
quinny
1●1●1●1
accept rate: 0%
  
One Answer:
  
0I don&#39;t know what SNMP has to do with this, but have a look at capture setup here.</description>
    </item>
    
    <item>
      <title>RRC filters</title>
      <link>/questions/14506/rrc-filters/</link>
      <pubDate>Tue, 25 Sep 2012 05:47:00 +0000</pubDate>
      
      <guid>/questions/14506/rrc-filters/</guid>
      <description>RRC filters  0 Hello to everybody, I&#39;ve found something strange in rrc filters expression, in several cases the same filter abbreviation have different type, this can be a problem and/or can cause a crash?
for example:
{ &amp;amp;hf_rrc_criticalExtensions_117, { &#34;criticalExtensions&#34;, &#34;rrc.criticalExtensions&#34;, FT_UINT32, BASE_DEC, VALS(rrc_T_criticalExtensions_117_vals), 0, &#34;T_criticalExtensions_117&#34;, HFILL }},
and
{ &amp;amp;hf_rrc_criticalExtensions_118, { &#34;criticalExtensions&#34;, &#34;rrc.criticalExtensions&#34;, FT_NONE, BASE_NONE, NULL, 0, &#34;T_criticalExtensions_118&#34;, HFILL }},
Lucio
filter duplicate rrcasked 25 Sep &#39;12, 05:47</description>
    </item>
    
    <item>
      <title>how can i filter on a serial port ?</title>
      <link>/questions/14514/how-can-i-filter-on-a-serial-port/</link>
      <pubDate>Tue, 25 Sep 2012 11:34:00 +0000</pubDate>
      
      <guid>/questions/14514/how-can-i-filter-on-a-serial-port/</guid>
      <description>how can i filter on a serial port ?  0 I have an encoder that I attached to it on a serial port an analogue camera and a ptz motor. The camera is controlled via a keyboard specific to this task. In addition, the cable used between the ptz motor and the encoder is coaxial and uses a converter from coax to serial.
I’m having pb with the PTZ when I move the joystick on the keboard to control the PTZ, the camera starts spinning.</description>
    </item>
    
    <item>
      <title>How to change the default capture options for Linux based wireshark GUI</title>
      <link>/questions/14516/how-to-change-the-default-capture-options-for-linux-based-wireshark-gui/</link>
      <pubDate>Tue, 25 Sep 2012 12:35:00 +0000</pubDate>
      
      <guid>/questions/14516/how-to-change-the-default-capture-options-for-linux-based-wireshark-gui/</guid>
      <description>How to change the default capture options for Linux based wireshark GUI  0 I am trying to find a way to set the default capture options. I would like to have my capture by default stop capturing after 5MB. The default is curranly set to 1000KB. Is there a config file or enviroment variable that could be set to change the default capture options? This is for a Linux base box and i&#39;m needing these changes for the GUI.</description>
    </item>
    
    <item>
      <title>http content length calculation</title>
      <link>/questions/14524/http-content-length-calculation/</link>
      <pubDate>Tue, 25 Sep 2012 20:28:00 +0000</pubDate>
      
      <guid>/questions/14524/http-content-length-calculation/</guid>
      <description>http content length calculation  0 Can anyone explain how do I calculate the content length in a http response? I do see the content length header with some value in the server response but would like to validate it. Is there any manual way?
I tried adding the tcp lengths of all previous packets including the http response with the status code but guess I need to subtract http header from the last packet.</description>
    </item>
    
    <item>
      <title>Rpcapd for Fedora 13-64 bit</title>
      <link>/questions/14525/rpcapd-for-fedora-13-64-bit/</link>
      <pubDate>Tue, 25 Sep 2012 21:28:00 +0000</pubDate>
      
      <guid>/questions/14525/rpcapd-for-fedora-13-64-bit/</guid>
      <description>Rpcapd for Fedora 13-64 bit  0 Hello Everyone,
I want to know that, is there any package of rpcapd ( for Remote capturing ) for Fedora 13-64 bit? Or any rpcapd package for 64-bit Linux will work on that?
Please reply!!
rpcapd fedora13asked 25 Sep &#39;12, 21:28
baila
21●10●11●15
accept rate: 0%
  
One Answer:
  
0To the best of my knowledge rpcapd.exe is part of WinPACP and doesn&#39;t exist for linux, so you won&#39;t find it in any repositories.</description>
    </item>
    
    <item>
      <title>what is the decoding mechanism for User Data in case of IS-637-A message protocol</title>
      <link>/questions/14531/what-is-the-decoding-mechanism-for-user-data-in-case-of-is-637-a-message-protocol/</link>
      <pubDate>Tue, 25 Sep 2012 22:57:00 +0000</pubDate>
      
      <guid>/questions/14531/what-is-the-decoding-mechanism-for-user-data-in-case-of-is-637-a-message-protocol/</guid>
      <description>what is the decoding mechanism for User Data in case of IS-637-A message protocol  0 Hi,
My UE is sending message in form of IS-637-A protocol. Its a SIP request:Message. Wireshark is able to decode the user data. I want to know the decoding machanism so that I will be able to decode that mesasge without help of wireshark. I am devloping an application which will decode the message and come out with user data.</description>
    </item>
    
    <item>
      <title>wireshark extensions for VANETs messages</title>
      <link>/questions/14541/wireshark-extensions-for-vanets-messages/</link>
      <pubDate>Wed, 26 Sep 2012 05:27:00 +0000</pubDate>
      
      <guid>/questions/14541/wireshark-extensions-for-vanets-messages/</guid>
      <description>wireshark extensions for VANETs messages  0 Hi everybody !
Is there any patch or extension able to read also the field of VANETs messages such as CAM or DENM ?
vanetsasked 26 Sep &#39;12, 05:27
Aleb
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Wireshark not displaying response path</title>
      <link>/questions/14544/wireshark-not-displaying-response-path/</link>
      <pubDate>Wed, 26 Sep 2012 07:28:00 +0000</pubDate>
      
      <guid>/questions/14544/wireshark-not-displaying-response-path/</guid>
      <description>Wireshark not displaying response path  0 Hi Guyz,
I am a new bie in this world of wireshark.
I have a set up where I need to sniff the communication between two devices.. Say A and B I have my laptop connected to a HUB with A and B and UPlink to this Hub is from a router. A , B and my laptop has got ips. So far so good.</description>
    </item>
    
    <item>
      <title>Capturing network traffic (rtmp) between VMs or using loopback in the same VM using wireshark</title>
      <link>/questions/14548/capturing-network-traffic-rtmp-between-vms-or-using-loopback-in-the-same-vm-using-wireshark/</link>
      <pubDate>Wed, 26 Sep 2012 11:48:00 +0000</pubDate>
      
      <guid>/questions/14548/capturing-network-traffic-rtmp-between-vms-or-using-loopback-in-the-same-vm-using-wireshark/</guid>
      <description>Capturing network traffic (rtmp) between VMs or using loopback in the same VM using wireshark  0 I need to to capture RTMP traffic between two virtual machines (server and client) or atleast have the server and client on the same machine and capture the traffic. I am able to capture the traffic if I run wireshark on the host rather than on the VMs. But I need to capture it on the VM to be able to manipulate it.</description>
    </item>
    
    <item>
      <title>How to filter OPTIONS messages</title>
      <link>/questions/14552/how-to-filter-options-messages/</link>
      <pubDate>Wed, 26 Sep 2012 13:13:00 +0000</pubDate>
      
      <guid>/questions/14552/how-to-filter-options-messages/</guid>
      <description>How to filter OPTIONS messages  0 Hi All,
To filter out OPTIONS message in wireshark traces, I could not find a way. Whatever I tried, broke another thing and since there are too many OPTIONS heartbeat message and 200 OK response to these message, I need to filter them out for sure.
I tried these 2 things too add in addition to &#34;camel || inap || tcap || sip&#34; filter</description>
    </item>
    
    <item>
      <title>Need advice with trace file</title>
      <link>/questions/14561/need-advice-with-trace-file/</link>
      <pubDate>Wed, 26 Sep 2012 15:19:00 +0000</pubDate>
      
      <guid>/questions/14561/need-advice-with-trace-file/</guid>
      <description>Need advice with trace file  0 This issue is with the client timing out when accessing a particular web site going through a proxy appliance. The client can access all other Internet web sites with no issue with exception of this url that had previously worked fine. A capture was done on the bluecoat proxy and it shows the http 200 ok response being sent to the client. For the client side, the firewall capture does not show the reply reaching the firewall.</description>
    </item>
    
    <item>
      <title>listener needs to look at only displayed packets</title>
      <link>/questions/14566/listener-needs-to-look-at-only-displayed-packets/</link>
      <pubDate>Wed, 26 Sep 2012 16:43:00 +0000</pubDate>
      
      <guid>/questions/14566/listener-needs-to-look-at-only-displayed-packets/</guid>
      <description>listener needs to look at only displayed packets  0 I wrote a listener in Lua that looks for certain fields and displays a summary. When I change the display filter my listener still gets all packets. I would like it to only get, or only look at, those packets that pass the current display filter. Can I do that?
listener filterasked 26 Sep &#39;12, 16:43
Wingman
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Dual Stack V4 and V6 interpretation</title>
      <link>/questions/14570/dual-stack-v4-and-v6-interpretation/</link>
      <pubDate>Thu, 27 Sep 2012 07:06:00 +0000</pubDate>
      
      <guid>/questions/14570/dual-stack-v4-and-v6-interpretation/</guid>
      <description>Dual Stack V4 and V6 interpretation  0 I&#39;m doing a few packet captures for testing purposes with dual stack enabled (Both v4 and v6 addresses) but I&#39;m unsure how to analyze the packets. Lets say I went to facebook (which has v6 enabled). Is there a way to use wireshark to determine what protocol (v4 or v6) that my browser ends up using for facebook. I see that it sends both A and AAAA queries and gets them back as well but I don&#39;t think it&#39;s possible for them to be using both.</description>
    </item>
    
    <item>
      <title>&amp;quot;Capture Interfaces&amp;quot; dialog box missing select boxes</title>
      <link>/questions/14572/capture-interfaces-dialog-box-missing-select-boxes/</link>
      <pubDate>Thu, 27 Sep 2012 07:48:00 +0000</pubDate>
      
      <guid>/questions/14572/capture-interfaces-dialog-box-missing-select-boxes/</guid>
      <description>&amp;ldquo;Capture Interfaces&amp;rdquo; dialog box missing select boxes  0 Version 1.6.2 on Linux the &#34;Capture Interfaces&#34; dialog box (Menu Capture::Interfaces...) does not include selection boxes to select more than one interface. This is different than Figure 4.2 in the documentation, which shows a checkbox to the left of the interface icon and device identifier.
How can I select more than one but less than all of the interfaces for a capture?</description>
    </item>
    
    <item>
      <title>Remote server not responding</title>
      <link>/questions/14576/remote-server-not-responding/</link>
      <pubDate>Thu, 27 Sep 2012 14:19:00 +0000</pubDate>
      
      <guid>/questions/14576/remote-server-not-responding/</guid>
      <description>Remote server not responding  0 Hi
I have a Windows 2008 server running a bespoke app that needs to speak to a vendor server named vendor.domain.com on the Internet on port 443.
Unfortunately, the application is not working - the vendor says that it&#39;s because our server can&#39;t speak with vendor.domain.com
If I ping vendor.domain.com from the server, then I get &#34;request timed out&#34;, although it does resolve to 66.</description>
    </item>
    
    <item>
      <title>How to use tshark to output a tcpdump  into text-formatted file</title>
      <link>/questions/14581/how-to-use-tshark-to-output-a-tcpdump-into-text-formatted-file/</link>
      <pubDate>Thu, 27 Sep 2012 20:19:00 +0000</pubDate>
      
      <guid>/questions/14581/how-to-use-tshark-to-output-a-tcpdump-into-text-formatted-file/</guid>
      <description>How to use tshark to output a tcpdump into text-formatted file  0 Hello All,
The following command will export a view of the packet details rather than a one-line summary of the packet into a text file: tshark -V -r input &amp;gt; output.txt
My question is how can I export a view of the packet details AND a one-line summary of the packet into a text file?
Thanks.
tsharkasked 27 Sep &#39;12, 20:19</description>
    </item>
    
    <item>
      <title>How to identify the cause of network flooding using wireshark?</title>
      <link>/questions/14582/how-to-identify-the-cause-of-network-flooding-using-wireshark/</link>
      <pubDate>Thu, 27 Sep 2012 20:25:00 +0000</pubDate>
      
      <guid>/questions/14582/how-to-identify-the-cause-of-network-flooding-using-wireshark/</guid>
      <description>How to identify the cause of network flooding using wireshark?  0 Hi wireshark experts, I am a new wireshark user. I find intermittent link down from 3:00am ~ 3:02am sometimes. I use Windows perfmon and I found the network flooding. Could you tell me how to identify the root cause using wireshark?
As you can see bytes total/sec on four 10GbE(screenshot 1) below, it went from 10MB/s to 140MB/s on four links at 3:00am and caused no buffers errors.</description>
    </item>
    
    <item>
      <title>How to locate one packet and the icmp packets using wireshark?</title>
      <link>/questions/14584/how-to-locate-one-packet-and-the-icmp-packets-using-wireshark/</link>
      <pubDate>Fri, 28 Sep 2012 01:20:00 +0000</pubDate>
      
      <guid>/questions/14584/how-to-locate-one-packet-and-the-icmp-packets-using-wireshark/</guid>
      <description>How to locate one packet and the icmp packets using wireshark?  0 When I found a icmp(example: icmp need to fragmented..) packet using wireshark,how can I easily locate the unique packet generating the icmp ?
locate icmpasked 28 Sep &#39;12, 01:20
chinasan
0●6●6●8
accept rate: 0%
  
One Answer:
  
2That&#39;s the nice thing about ICMP, it includes part of the packet that generated the ICMP message.</description>
    </item>
    
    <item>
      <title>Total length of packets</title>
      <link>/questions/14587/total-length-of-packets/</link>
      <pubDate>Fri, 28 Sep 2012 01:59:00 +0000</pubDate>
      
      <guid>/questions/14587/total-length-of-packets/</guid>
      <description>Total length of packets  0 1I am capturing packets using libpcap. I am calculating the payload size as given here
size_payload = ntohs(ip-&amp;gt;ip_len) - (size_ip + size_tcp);
Now when I print ntohs(ip-&amp;gt;ip_len), I see that the value is 1280. For the same packets, wireshark shows a value of 1500 for the total length field in the IP header. Why do they differ?
ethernet libpcap wiresharkasked 28 Sep &#39;12, 01:59</description>
    </item>
    
    <item>
      <title>How to open large pcap files faster?</title>
      <link>/questions/14592/how-to-open-large-pcap-files-faster/</link>
      <pubDate>Fri, 28 Sep 2012 07:44:00 +0000</pubDate>
      
      <guid>/questions/14592/how-to-open-large-pcap-files-faster/</guid>
      <description>How to open large pcap files faster?  0 I&#39;m trying to open fairly large pcap files (about 500MB) and they&#39;re loading extremely slow. I imagine the reason for this is due to the sheer number of packets. While loading, I noticed that only a single core on my processor is being used (maxed out to 99% utilization). I believe this is my bottleneck since I have plenty of memory.</description>
    </item>
    
    <item>
      <title>GeoIP opening blank browser</title>
      <link>/questions/14593/geoip-opening-blank-browser/</link>
      <pubDate>Fri, 28 Sep 2012 07:46:00 +0000</pubDate>
      
      <guid>/questions/14593/geoip-opening-blank-browser/</guid>
      <description>GeoIP opening blank browser  0 I have tried in IE, Chrome and IE but the web browser is always blank.
geoipasked 28 Sep &#39;12, 07:46
rob123
1●3●3●5
accept rate: 0%
  
One Answer:
  
3This is a known bug, bug 5016, which will be fixed in the next release, version 1.8.3, currently scheduled to be released around October 1, 2012.
answered 28 Sep &#39;12, 07:54</description>
    </item>
    
    <item>
      <title>Question about fix.sendingTime for FIX Protocol</title>
      <link>/questions/14594/question-about-fixsendingtime-for-fix-protocol/</link>
      <pubDate>Fri, 28 Sep 2012 07:49:00 +0000</pubDate>
      
      <guid>/questions/14594/question-about-fixsendingtime-for-fix-protocol/</guid>
      <description>Question about fix.sendingTime for FIX Protocol  0 Hi All,
I am using FIX Dissector to decode FIX Protocol, and I got following message.
SendingTime (52): 20120927-19:28:04.909
I am sure there should be 6 digits for milliseconds and microseconds, for instance, 19:28:04.909XXX. Can I show the all 6 digits by changing some settings?
Thanks.
fixasked 28 Sep &#39;12, 07:49
ylin
1●2●2●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark 1.6 ,1.8. 1.8 RC2 generating a runtime library error (Terminal in a unusual way...)</title>
      <link>/questions/14599/wireshark-16-18-18-rc2-generating-a-runtime-library-error-terminal-in-a-unusual-way/</link>
      <pubDate>Fri, 28 Sep 2012 08:28:00 +0000</pubDate>
      
      <guid>/questions/14599/wireshark-16-18-18-rc2-generating-a-runtime-library-error-terminal-in-a-unusual-way/</guid>
      <description>Wireshark 1.6 ,1.8. 1.8 RC2 generating a runtime library error (Terminal in a unusual way&amp;hellip;)  0 Hi there,
Could anyone let me know if you encountered this issue where Wireshark is capturing packets fine for few minutes and then crash with the following Microsoft Virtual C++ runtime library error:
This application has requested the runtime to terminate it in an unusual way. ...
I am running windows 2008 R2 x64 SP1 + all the latest patches and tried it over 3 different servers and with Wireshark V1.</description>
    </item>
    
    <item>
      <title>Differences Between I/O Graph and TCPStream Throughput Graph</title>
      <link>/questions/14605/differences-between-io-graph-and-tcpstream-throughput-graph/</link>
      <pubDate>Fri, 28 Sep 2012 09:51:00 +0000</pubDate>
      
      <guid>/questions/14605/differences-between-io-graph-and-tcpstream-throughput-graph/</guid>
      <description>Differences Between I/O Graph and TCPStream Throughput Graph  0 The I/O graph appears to let you visually graph throughput, yet there&#39;s the TCPStream Throughput graph. The throughput measured between the two graphs seem to be way off just comparing Bytes/sec. I&#39;m not sure how either is derived, so I need some input on this.
Which is the more accurate representation of actual data throughput?
graph throughputasked 28 Sep &#39;12, 09:51</description>
    </item>
    
    <item>
      <title>where can I find the source code for editcap</title>
      <link>/questions/14606/where-can-i-find-the-source-code-for-editcap/</link>
      <pubDate>Fri, 28 Sep 2012 10:13:00 +0000</pubDate>
      
      <guid>/questions/14606/where-can-i-find-the-source-code-for-editcap/</guid>
      <description>where can I find the source code for editcap  0 I would like to know where I can find the source files for editcap. What libpcap API&#39;s are being called to convert .pcapng to .pcap with the following cmd?
editcap -F libpcap -T ether file.pcapng file.pcap
development libpcapasked 28 Sep &#39;12, 10:13
phileo99
1●1●1●1
accept rate: 0%
  
One Answer:
  
2The current stable Wireshark sources, which includes the source code for editcap, can be downloaded from the Wireshark download page.</description>
    </item>
    
    <item>
      <title>how to decode an user custom exception from GIOP stream?</title>
      <link>/questions/14610/how-to-decode-an-user-custom-exception-from-giop-stream/</link>
      <pubDate>Fri, 28 Sep 2012 19:15:00 +0000</pubDate>
      
      <guid>/questions/14610/how-to-decode-an-user-custom-exception-from-giop-stream/</guid>
      <description>how to decode an user custom exception from GIOP stream?  0 Hey all,
I have caught a GIOP stream by wireshark, which should contain my user custom exception propagation data between :
my server(jboss iiop/jacorb) and my client(simple test to get threw exception from deploy jar on server)
In my threw exception, I defined a variable &#34;i&#34;, and want to check that variable value in my GIOP stream(because when I read back that value from client side, it&#39;s wrong).</description>
    </item>
    
    <item>
      <title>sequence counter</title>
      <link>/questions/14621/sequence-counter/</link>
      <pubDate>Mon, 01 Oct 2012 02:30:00 +0000</pubDate>
      
      <guid>/questions/14621/sequence-counter/</guid>
      <description>sequence counter  0 I would like, not only to see the packets that have a specified pattern (filter like &#34;udp contains XX:YY:ZZ&#34;), but also to know : How many times i have the pattern in the whole whire shark capture? Becouse, one pattern could be found more than one time in one packet.
Any idea? Thanks a lot E.
pattern counterasked 01 Oct &#39;12, 02:30
ebsws
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Decode mDNS</title>
      <link>/questions/14622/decode-mdns/</link>
      <pubDate>Mon, 01 Oct 2012 02:40:00 +0000</pubDate>
      
      <guid>/questions/14622/decode-mdns/</guid>
      <description>Decode mDNS  0 Hello,
I have two questions. I&#39;m trying to write mDNS queries, to make a service discovery. That why i want to know if it is possible to decode mDNS packets that I took with wireshark? That would be very useful for me! And how do I do with DNS queries?
Thanks
query mdns request dnsasked 01 Oct &#39;12, 02:40
matthieu526
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>MAP user abort</title>
      <link>/questions/14625/map-user-abort/</link>
      <pubDate>Mon, 01 Oct 2012 05:40:00 +0000</pubDate>
      
      <guid>/questions/14625/map-user-abort/</guid>
      <description>MAP user abort  0 hi... i need your expertise...
below is an SS7 trace captured where the MSC is sending an abort message... what is causing this abort?
Transaction Capabilities Application Part abort Destination Transaction ID Transaction Id: 0817184d reason: u-abortCause (11) oid: 0.0.17.773.1.1.1 (id-as-dialogue) dialogueAbort abort-source: dialogue-service-user (0) user-information: 1 item user-information item direct-reference: 0.4.0.0.1.1.1.1 (map-DialogueAS) encoding: single-ASN1-type (0) MAP-DialoguePDU: map-userAbort (4) map-userAbort map-UserAbortChoice: userSpecificReason (0) userSpecificReason .map ss7 gsmasked 01 Oct &#39;12, 05:40</description>
    </item>
    
    <item>
      <title>Drive shows as interface?</title>
      <link>/questions/14627/drive-shows-as-interface/</link>
      <pubDate>Mon, 01 Oct 2012 06:34:00 +0000</pubDate>
      
      <guid>/questions/14627/drive-shows-as-interface/</guid>
      <description>Drive shows as interface?  0 I&#39;ve installed wireshark on a server running Windows Server 2008 R2 Sp 2 to diagnose some multicast issues with an application and in the list of interfaces that wireshark shows it includes a mapped network drive. The list of interfaces to select for capturing includes the following:
Physical NIC 1M:\Physical NIC 2Any idea why? It&#39;s a real problem because the multicast transmissions from my application are going through this interface.</description>
    </item>
    
    <item>
      <title>Remote capturing</title>
      <link>/questions/14636/remote-capturing/</link>
      <pubDate>Tue, 02 Oct 2012 05:56:00 +0000</pubDate>
      
      <guid>/questions/14636/remote-capturing/</guid>
      <description>Remote capturing  0 Hi, I am trying to use remote capturing between two machines running win7 32b. When I try to add a remote interface in Wireshark, I see the error &#34;can&#39;t get the list of interfaces: getaddrinfo() the requested name is valid but no data of the requested type was found&#34; How can I solve the problem?
getaddrinfo rpcap remoteasked 02 Oct &#39;12, 05:56
mah
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark 1.8.3 release date</title>
      <link>/questions/14640/wireshark-183-release-date/</link>
      <pubDate>Tue, 02 Oct 2012 09:27:00 +0000</pubDate>
      
      <guid>/questions/14640/wireshark-183-release-date/</guid>
      <description>Wireshark 1.8.3 release date  0 The expected release date is today does anyone know what time today?
1.8.3asked 02 Oct &#39;12, 09:27
rob123
1●3●3●5
accept rate: 0%
  
3 Answers:
  
1After the build finishes the release is usually announced within two to three hours. If you&#39;re especially impatient you can poke around in the all-versions directories on the server. Releases will show up there before the announcement.</description>
    </item>
    
    <item>
      <title>tshark: write packets matching a filter</title>
      <link>/questions/14645/tshark-write-packets-matching-a-filter/</link>
      <pubDate>Tue, 02 Oct 2012 12:47:00 +0000</pubDate>
      
      <guid>/questions/14645/tshark-write-packets-matching-a-filter/</guid>
      <description>tshark: write packets matching a filter  0 Greetings.
On a production system, I&#39;m using &#34;dumpcap -i any -b ...&#34; to capture all network traffic on the machine and write it to a rotating set of files, so I have a set of files containing all of the network traffic for the previous few hours.
I need to know how to read one or more of these files, filter out specific types of traffic (based on client IP address), and write the matching packets to a new pcap file which contains only the matching packets.</description>
    </item>
    
    <item>
      <title>Mac VirtualBox capture HTTP traffic to/from Linux VM</title>
      <link>/questions/14646/mac-virtualbox-capture-http-traffic-tofrom-linux-vm/</link>
      <pubDate>Tue, 02 Oct 2012 13:30:00 +0000</pubDate>
      
      <guid>/questions/14646/mac-virtualbox-capture-http-traffic-tofrom-linux-vm/</guid>
      <description>Mac VirtualBox capture HTTP traffic to/from Linux VM  1 1I&#39;ve got VirtualBox installed on a Mac running an Ubuntu VM. The VM is setup to use a Host-only Adapter on vboxnet0. The VM is running a web server on non-standard port 5000.
I&#39;ve got a vanilla installation of Wireshark running on the Mac and I start a capture on the vboxnet0 interface. My understanding is that wireshark should capture everything on all ports on an interface out of the box.</description>
    </item>
    
    <item>
      <title>TCP options</title>
      <link>/questions/14647/tcp-options/</link>
      <pubDate>Tue, 02 Oct 2012 15:00:00 +0000</pubDate>
      
      <guid>/questions/14647/tcp-options/</guid>
      <description>TCP options  0 What will cause the TCP options such as scaling and SACK not to show during the handshake? Would a router or firewall do this? A message of NOP 4 NOP row a router may have removed is reported by Wireshark.
tcp-optionsasked 02 Oct &#39;12, 15:00
ws2006
1●12●12●14
accept rate: 0%
  
One Answer:
  
5If you don&#39;t see a TCP option in the handshake packet(s), then the option wasn&#39;t there when Wireshark saw the packet.</description>
    </item>
    
    <item>
      <title>Regarding wireshark</title>
      <link>/questions/14653/regarding-wireshark/</link>
      <pubDate>Tue, 02 Oct 2012 21:57:00 +0000</pubDate>
      
      <guid>/questions/14653/regarding-wireshark/</guid>
      <description>Regarding wireshark  -1 DESCRIBE THE STEPS TO DISPLAY A SINGLE CONVERSATION /TRACE FROM A NETWORK CAPTURE FILE using wireshark
conversation singleasked 02 Oct &#39;12, 21:57
bhuma
0●1●1●1
accept rate: 0%
  
One Answer:
  
2Yay, homework...
Take a look at Statistics -&amp;gt; Conversations, play around with the tabs and sorting columns and using the popup menu. Figure out the rest by yourself, you should learn something ;-)</description>
    </item>
    
    <item>
      <title>libwireshark is not dissecting diameter messages.</title>
      <link>/questions/14654/libwireshark-is-not-dissecting-diameter-messages/</link>
      <pubDate>Tue, 02 Oct 2012 22:38:00 +0000</pubDate>
      
      <guid>/questions/14654/libwireshark-is-not-dissecting-diameter-messages/</guid>
      <description>libwireshark is not dissecting diameter messages.  0 Hi,
I have written an application to dissect diameter packets ,i&#39;m using wireshark dissection engine to do it.. problem is-
I have build the application on wireshark version 1.6.5 , and the application is working fine on that system, it dissects the packets, shows the AVPs.
now when i copy the application on another system(wireshark 1.0.8) , and i also copied the libraries from that system to another one.</description>
    </item>
    
    <item>
      <title>How to make dataset such as KDDCup99 via wireshark?</title>
      <link>/questions/14655/how-to-make-dataset-such-as-kddcup99-via-wireshark/</link>
      <pubDate>Tue, 02 Oct 2012 23:49:00 +0000</pubDate>
      
      <guid>/questions/14655/how-to-make-dataset-such-as-kddcup99-via-wireshark/</guid>
      <description>How to make dataset such as KDDCup99 via wireshark?  1 I am going to make a dataset such as KDDCup99 for machine learning purposes, but I don&#39;t know how can i extract intrinsic and time-based attributes from wireshark analyzer!! KDDCup99 introduces 43 attributes (intrinsic, time-based and host-based attributes), and I am going to extract this attributes from wireshark analyzer. How can i do it?
traffic networking wiresharkasked 02 Oct &#39;12, 23:49</description>
    </item>
    
    <item>
      <title>Decoding CDRs</title>
      <link>/questions/14656/decoding-cdrs/</link>
      <pubDate>Tue, 02 Oct 2012 23:54:00 +0000</pubDate>
      
      <guid>/questions/14656/decoding-cdrs/</guid>
      <description>Decoding CDRs  0 Hello all,
I&#39;d like to know how I can decode GGSN CDRs in wireshark. I have the version 1.8 installed. I see that the packets are recognized as GTP Data record transfer request and response but when I checked the contents, it says that it&#39;s malformed.
Do I need to add something to wireshark to decode it and how? I did not see much options for GTP in preferences</description>
    </item>
    
    <item>
      <title>VirtualBox interface not shown in list of interfaces.</title>
      <link>/questions/14657/virtualbox-interface-not-shown-in-list-of-interfaces/</link>
      <pubDate>Wed, 03 Oct 2012 00:01:00 +0000</pubDate>
      
      <guid>/questions/14657/virtualbox-interface-not-shown-in-list-of-interfaces/</guid>
      <description>VirtualBox interface not shown in list of interfaces.  0 I installed the VirtualBox and it installed VirtualBox Host-Only Network adapter as well. However after reinstalling newer version of VirtualBox the adapter disappeared from list of Wireshark&#39;s captured interfaces. How can I restore it?
interfacelist virtualboxasked 03 Oct &#39;12, 00:01
T_12
1●1●1●2
accept rate: 0%
 edited 03 Oct &#39;12, 00:57 
  
One Answer:</description>
    </item>
    
    <item>
      <title>Diameter command code 318,316,317,321,319,320 not getting captured</title>
      <link>/questions/14658/diameter-command-code-318316317321319320-not-getting-captured/</link>
      <pubDate>Wed, 03 Oct 2012 00:57:00 +0000</pubDate>
      
      <guid>/questions/14658/diameter-command-code-318316317321319320-not-getting-captured/</guid>
      <description>Diameter command code 318,316,317,321,319,320 not getting captured  0 Hello Experts,
I am using wireshark 1.8.3. I would like to capture the traces on the s6a interface(between MME and HLR). I am getting traces related to Disconnect Peer Request/Answer(282) and Capabilities Exchange Request/Answer (257). But I am not able to see the rest of the things like ULR/ULA(316),AIR/AIA(318). What could be the reason for this. Do I have to change any settings related to this in the wireshark?</description>
    </item>
    
    <item>
      <title>only see inbound traffic</title>
      <link>/questions/14669/only-see-inbound-traffic/</link>
      <pubDate>Wed, 03 Oct 2012 07:31:00 +0000</pubDate>
      
      <guid>/questions/14669/only-see-inbound-traffic/</guid>
      <description>only see inbound traffic  0 Hi,
On two Dell PC, with Intel 82567LM-3 network Card on a switched wired network. I only see incoming trafic, I can&#39;t see the outgoing trafic from my interface. As exemple, I only get the ICPM reply when a do a ping from my computer
Any idea?
capture outgoing outbound seeingasked 03 Oct &#39;12, 07:31
yokan
1●1●1●1
accept rate: 0%
 edited 15 Jan &#39;14, 07:12</description>
    </item>
    
    <item>
      <title>Port Mirroring and Wireshark</title>
      <link>/questions/14672/port-mirroring-and-wireshark/</link>
      <pubDate>Wed, 03 Oct 2012 08:31:00 +0000</pubDate>
      
      <guid>/questions/14672/port-mirroring-and-wireshark/</guid>
      <description>Port Mirroring and Wireshark  0 Hello. I&#39;m trying to capture the traffic one one port and mirror that traffic to the other. I&#39;m using an HP ProCurve 2810-24G switch, I&#39;ve set up the Port Monitoring option through the web configuration. Now for the WireShark, it looks as though it&#39;s only showing the traffic on the PC running wireshark, as opposed to showing me the mirrored traffic on the PC being monitored.</description>
    </item>
    
    <item>
      <title>No data packets when turning on monitor mode</title>
      <link>/questions/14684/no-data-packets-when-turning-on-monitor-mode/</link>
      <pubDate>Wed, 03 Oct 2012 11:30:00 +0000</pubDate>
      
      <guid>/questions/14684/no-data-packets-when-turning-on-monitor-mode/</guid>
      <description>No data packets when turning on monitor mode  0 Hi all, I&#39;m a novice in Wireshark. I apologize if this question is silly. The problem is that when I turn on the wifi monitor mode and choose an appropriate channel, Wireshark can catch 802.11 management packets such as beacon, probe_request, but it can&#39;t catch any user data packets such as the tcp packets. After I turn the wifi back to managed mode and connect to an AP, I can catch user data packets again.</description>
    </item>
    
    <item>
      <title>Wireshark to recover video / live stream.</title>
      <link>/questions/14691/wireshark-to-recover-video-live-stream/</link>
      <pubDate>Wed, 03 Oct 2012 14:23:00 +0000</pubDate>
      
      <guid>/questions/14691/wireshark-to-recover-video-live-stream/</guid>
      <description>Wireshark to recover video / live stream.  0 Hey everybody, I am taking baby steps with using Wireshark and I have encountered an issue. To cut a long story short, here&#39;s my problem: I have a sample capture of a video stream (this one is from youtube, but I am extending the discussion towards any capture from any video streaming / live streaming site) that I have uploaded to Cloudshark, here: Youtube capture file; When looking at the conversations, the 4.</description>
    </item>
    
    <item>
      <title>How to hide ICMP packets?</title>
      <link>/questions/14697/how-to-hide-icmp-packets/</link>
      <pubDate>Wed, 03 Oct 2012 22:42:00 +0000</pubDate>
      
      <guid>/questions/14697/how-to-hide-icmp-packets/</guid>
      <description>How to hide ICMP packets?  0 Hi,
This is the first time I am using wireshark and facing below issue:-
I have created my own dissector named IPTWP(UDP). While trying to filter IPTWP packets, the ICMP packets also get displayed. How to find out whats common between my dissector and ICMP dissector? Also, when looking at the ICMP tree, IPTWP is shown as a part of tree along with UDP and IPv4.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t display RSSI values in Wireshark</title>
      <link>/questions/14699/cant-display-rssi-values-in-wireshark/</link>
      <pubDate>Thu, 04 Oct 2012 01:46:00 +0000</pubDate>
      
      <guid>/questions/14699/cant-display-rssi-values-in-wireshark/</guid>
      <description>Can&amp;rsquo;t display RSSI values in Wireshark  0 Hello everybody,
I am trying to analyze the up-link Wireless traffic generated by my Sony Ericsson phone and captured by my D-Link router, on which I installed the DD-WRT firmware. To do this, first I log in the router and enable the prism0 interface by typing the command:
wl -i eth1 monitor 1
and then I start to capture the packets by typing:</description>
    </item>
    
    <item>
      <title>L2P and DSCP tags</title>
      <link>/questions/14707/l2p-and-dscp-tags/</link>
      <pubDate>Thu, 04 Oct 2012 05:57:00 +0000</pubDate>
      
      <guid>/questions/14707/l2p-and-dscp-tags/</guid>
      <description>L2P and DSCP tags  0 How to check L2P and DSCP tags in the packet. Which NIC supports the tagged packets? If driver is stripping off the tags then how to check the same?
1.0.4 versionasked 04 Oct &#39;12, 05:57
Maldini
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>how to change the fake ip addresses in text2pcap output?</title>
      <link>/questions/14708/how-to-change-the-fake-ip-addresses-in-text2pcap-output/</link>
      <pubDate>Thu, 04 Oct 2012 06:55:00 +0000</pubDate>
      
      <guid>/questions/14708/how-to-change-the-fake-ip-addresses-in-text2pcap-output/</guid>
      <description>how to change the fake ip addresses in text2pcap output?  0 Hi! I have an aplication level hex dump that I imported into wireshark successfully with text2pcap. I have what is sent and what is received, and I want to reflect that conversation in wireshark. So I created two hex dumps, one for reads and one for writes, and converted them to two pcap files, reversing the fake TCP port numbers.</description>
    </item>
    
    <item>
      <title>Wireless Toolbar Available with 1.8.0 but NOT with 1.8.2, 1.8.3</title>
      <link>/questions/14709/wireless-toolbar-available-with-180-but-not-with-182-183/</link>
      <pubDate>Thu, 04 Oct 2012 08:54:00 +0000</pubDate>
      
      <guid>/questions/14709/wireless-toolbar-available-with-180-but-not-with-182-183/</guid>
      <description>Wireless Toolbar Available with 1.8.0 but NOT with 1.8.2, 1.8.3  0 AirPcap is installed, Wireshark 1.8.0 displays wireless toolbar, 1.8.2, 1.8.3 DO NOT. Is there a remedy? Has that not been tested?
Jasper&#39;s answer was not the solution. The wireless toolbar is more specifically grayed-out and unavailable, not completely absent. If the View option is used to disabled it, the display of the wireless toolbar disappears. Re-enabling it in the view only restores the grayed-out, inaccessible display.</description>
    </item>
    
    <item>
      <title>It sees my wireless interfaces as &amp;quot;Microsoft&amp;quot;</title>
      <link>/questions/14715/it-sees-my-wireless-interfaces-as-microsoft/</link>
      <pubDate>Thu, 04 Oct 2012 13:05:00 +0000</pubDate>
      
      <guid>/questions/14715/it-sees-my-wireless-interfaces-as-microsoft/</guid>
      <description>It sees my wireless interfaces as &amp;ldquo;Microsoft&amp;rdquo;  0 It sees my Ethernet interface, but my wireless interfaces are displayed as &#34;Microsoft&#34; and of coarse don&#39;t have a properties of a wireless interfaces! I used to capture packets with my Belkin USB wireless adaptor on CommView, because my built-in wi-fi card doesn&#39;t support monitor mode, so I know it works. At that moment I had WinPcap 4.1.1. I tryed to roll back WinPcap, but it didn&#39;t help!</description>
    </item>
    
    <item>
      <title>SSL decryption fails</title>
      <link>/questions/14717/ssl-decryption-fails/</link>
      <pubDate>Thu, 04 Oct 2012 13:23:00 +0000</pubDate>
      
      <guid>/questions/14717/ssl-decryption-fails/</guid>
      <description>SSL decryption fails  0 I&#39;m trying to decrypt SSL traffic, which I&#39;ve done several times before without problems. Now I&#39;m using wireshark 1.8.3. on linux 64 bit and something gone wrong - decryption doesn&#39;t work.
I checked just everything (with great help of Sake Blok&#39;s Sharkfest&#39;09 presentation) - private key and certificate match, I have entire session in capture file, I do not use Server Key Exchange etc.
After several hours trying I desperately created own certificate and SSL server (openssl server) - which I would expect to work, but nope, no luck.</description>
    </item>
    
    <item>
      <title>AMR codec payload missing</title>
      <link>/questions/14722/amr-codec-payload-missing/</link>
      <pubDate>Thu, 04 Oct 2012 13:58:00 +0000</pubDate>
      
      <guid>/questions/14722/amr-codec-payload-missing/</guid>
      <description>AMR codec payload missing  0 Hi,
I am trying to capture an AMR codec generated using Navtel. When I decode it to RTP, the trace shows &#34;RTP EVENT&#34; instead of &#34;RTP&#34; and the payload is missing in all of those packets.
I have used the same setup for various other codecs like PCMU, PCMA, AMR-WB, etc which are captured fine. What could be the cause and a possible solution?</description>
    </item>
    
    <item>
      <title>No [SYN, ACK] back from my IP address</title>
      <link>/questions/14727/no-syn-ack-back-from-my-ip-address/</link>
      <pubDate>Thu, 04 Oct 2012 22:53:00 +0000</pubDate>
      
      <guid>/questions/14727/no-syn-ack-back-from-my-ip-address/</guid>
      <description>No [SYN, ACK] back from my IP address  0 I am using FileZilla on my PC. I never had a problem having people connecting to it. I had to move to another PC because of hardware problems. Now on the new machine I nor anyone can connect to FileZilla using my IP address. My ISP is Comcast and their second level people could not see any problems on their side of the SMC router/modem.</description>
    </item>
    
    <item>
      <title>Is this a correct connection buildup?</title>
      <link>/questions/14730/is-this-a-correct-connection-buildup/</link>
      <pubDate>Fri, 05 Oct 2012 05:04:00 +0000</pubDate>
      
      <guid>/questions/14730/is-this-a-correct-connection-buildup/</guid>
      <description>Is this a correct connection buildup?  0 Hi all,
I setup the LwIP Stack on a microcontroller, buildup a connection to a PC, transmit some data and close the connection. Please see the screenshot below. The first connection seems to be correct (Frame 6 has the PSH and ACK flag) but when I reset the controller and try to buildup a connection in the same way as the first one I receive previous segment not captured.</description>
    </item>
    
    <item>
      <title>Not seeing any interfaces on my Ubuntu machine</title>
      <link>/questions/14733/not-seeing-any-interfaces-on-my-ubuntu-machine/</link>
      <pubDate>Fri, 05 Oct 2012 06:58:00 +0000</pubDate>
      
      <guid>/questions/14733/not-seeing-any-interfaces-on-my-ubuntu-machine/</guid>
      <description>Not seeing any interfaces on my Ubuntu machine  0 Hello,
I am using wireshark on a laptop do I need to install anything extra to get it to capture packets going through my wireless network card?
When I go to intrefaces it says there is no interfaces.
I am running wiresahrk 1.8.2 on Ubuntu.
Thanks,
wireless networkasked 05 Oct &#39;12, 06:58
rob123
1●3●3●5
accept rate: 0%
 edited 05 Oct &#39;12, 11:31</description>
    </item>
    
    <item>
      <title>Approved/Recommended Dual NICs</title>
      <link>/questions/14738/approvedrecommended-dual-nics/</link>
      <pubDate>Fri, 05 Oct 2012 11:48:00 +0000</pubDate>
      
      <guid>/questions/14738/approvedrecommended-dual-nics/</guid>
      <description>Approved/Recommended Dual NICs  0 We have captured using an old Netgear GA511 for many years. Using Netoptics taps, we capture to both the laptop onboard NIC and the GA511. We occasionally experience minor timestamp differences between them, but nothing we can&#39;t deal with. We were never sure if it was due to the NICs or the two instances of Wireshark that were running. With the advantages of 1.8, we are re-visiting our configuration, and are interested in the possibility of a dual-NIC PC card.</description>
    </item>
    
    <item>
      <title>Long term capture</title>
      <link>/questions/14745/long-term-capture/</link>
      <pubDate>Sat, 06 Oct 2012 14:30:00 +0000</pubDate>
      
      <guid>/questions/14745/long-term-capture/</guid>
      <description>Long term capture  0 I have a site with an intermittent issue that appears to be a client (probably a laptop) using all the bandwidth. It will be a while before I can be onsite and my remote options are limited.
There is a monitor port configured for the internet connection and they have offered to put a laptop on it with any tool that they can install. It would need to be a Windows tool and easy for them to configure.</description>
    </item>
    
    <item>
      <title>Really need help</title>
      <link>/questions/14752/really-need-help/</link>
      <pubDate>Sun, 07 Oct 2012 06:39:00 +0000</pubDate>
      
      <guid>/questions/14752/really-need-help/</guid>
      <description>Really need help  0 I am just trying to learn wireshark and have an assignment that I hope someone can point me in the right direction. I am suppose to analyze network traffic from google.ca. Q#1 is the query and response to determine th ip address of google.ca---done Q2 is three stages of three way handshake.---done Q3 is the first http packet sent to google.ca after handshake. Don&#39;t know what to look for here?</description>
    </item>
    
    <item>
      <title>HTTP 100 Continue not received triggering a FIN</title>
      <link>/questions/14757/http-100-continue-not-received-triggering-a-fin/</link>
      <pubDate>Sun, 07 Oct 2012 10:58:00 +0000</pubDate>
      
      <guid>/questions/14757/http-100-continue-not-received-triggering-a-fin/</guid>
      <description>HTTP 100 Continue not received triggering a FIN  0 HI, I am facing a very strange issue. After a successful TCP Handshake, client sends an HTTP Request. Server received it, and responded with a HTTP 100 Continue and right after with a HTPP 200 OK.
But on the client, the Continue doesn&#39;t arrive. Instead, only a TCP packet arrives acknowledging the fist HTTP request with the right SEQ,ACK. (The normal flow would be receiving the HTTP 100 with the right SEQ,ACK).</description>
    </item>
    
    <item>
      <title>Need advice on using Wireshark &#43; aircrack-ng</title>
      <link>/questions/14758/need-advice-on-using-wireshark-aircrack-ng/</link>
      <pubDate>Sun, 07 Oct 2012 11:14:00 +0000</pubDate>
      
      <guid>/questions/14758/need-advice-on-using-wireshark-aircrack-ng/</guid>
      <description>Need advice on using Wireshark + aircrack-ng  0 Hi! I am making acquiantance with wireless security and attacks and was told to run some tests with aircrack-ng and wireshark.
So I installed both of them and ran airmon to switch wi-fi adapter to monitor mode: sudo airmon-ng start ra0 (this is my dwa-140 usb wi-fi)
The wi-fi adapter seems to have restarted after that. Guess that&#39;s ok.
After that I ran wireshark as a superuser, chose the ra0 adapter and tried to sniff the test open network.</description>
    </item>
    
    <item>
      <title>how to build a release verson of wireshark?</title>
      <link>/questions/14768/how-to-build-a-release-verson-of-wireshark/</link>
      <pubDate>Mon, 08 Oct 2012 01:08:00 +0000</pubDate>
      
      <guid>/questions/14768/how-to-build-a-release-verson-of-wireshark/</guid>
      <description>how to build a release verson of wireshark?  0 1Hi all, I have downloaded the 1.6.4 source code for 32 bit machines. Now, i want to build a release version of wireshark, but I do not know how to change the file &#34;config.nmake&#34;, Any ideas?
buildasked 08 Oct &#39;12, 01:08
ekgh
1●1●2●2
accept rate: 0%
 edited 08 Oct &#39;12, 01:10 
  
One Answer:</description>
    </item>
    
    <item>
      <title>End of file on pipe magic during open</title>
      <link>/questions/14773/end-of-file-on-pipe-magic-during-open/</link>
      <pubDate>Mon, 08 Oct 2012 02:49:00 +0000</pubDate>
      
      <guid>/questions/14773/end-of-file-on-pipe-magic-during-open/</guid>
      <description>End of file on pipe magic during open  0 I&#39;m trying to pipe my android device&#39;s network traffic on wireshark, which is installed on my desktop.
Terminal 1sudo ./adb shell &#34;./data/local/tcpdump-armn -s 0 -v -w - | ./data/local/netcat -l -p 12345&#34;
This would allow me to route the data to port number 12345 on the android device.
Terminal 2sudo ./adb forward tcp:12345 tcp:54321 &amp;amp;&amp;amp; netcat 127.0.0.1 54321 | wireshark -k -S -i -</description>
    </item>
    
    <item>
      <title>How can I capture and summarize a whole day of traffic for a host?</title>
      <link>/questions/14775/how-can-i-capture-and-summarize-a-whole-day-of-traffic-for-a-host/</link>
      <pubDate>Mon, 08 Oct 2012 08:59:00 +0000</pubDate>
      
      <guid>/questions/14775/how-can-i-capture-and-summarize-a-whole-day-of-traffic-for-a-host/</guid>
      <description>How can I capture and summarize a whole day of traffic for a host?  0 I&#39;m trying to help our server gang check if it&#39;s safe to retire a particular server. They ask me (since I&#39;m network support) who&#39;s talking with this host over the course of a full day?
I know I can have them run TSHARK, and use its conversation summary:
tshark -i 1 -c ####### -z conv,&amp;quot;ip&amp;quot;,ip.</description>
    </item>
    
    <item>
      <title>Mac colorizing filter</title>
      <link>/questions/14776/mac-colorizing-filter/</link>
      <pubDate>Mon, 08 Oct 2012 09:43:00 +0000</pubDate>
      
      <guid>/questions/14776/mac-colorizing-filter/</guid>
      <description>Mac colorizing filter  0 I am using the latest Wireshark version 1.8.3 on my mac along with X11 which makes it work. The issue that I am facing is that whenever i try to create a new colorizing rule, it crashes Wireshark and closes it. It doesn&#39;t even ask for saving the capture and just shuts it down. If you know the solution to this problem, let me know.</description>
    </item>
    
    <item>
      <title>how to confirm encrypted data using WIRESHARK ?</title>
      <link>/questions/14802/how-to-confirm-encrypted-data-using-wireshark/</link>
      <pubDate>Mon, 08 Oct 2012 17:23:00 +0000</pubDate>
      
      <guid>/questions/14802/how-to-confirm-encrypted-data-using-wireshark/</guid>
      <description>how to confirm encrypted data using WIRESHARK ?  0 I am new to WIRESHARK have installed it.
WIRESHARK provide many useful features but in start I want to just capture my required data. Can you please guide me how I can capture data relevant to a particular web site ? I want to confirm my user id and password are encrypted.
I highly appreciate your guidance on it.
Thanks</description>
    </item>
    
    <item>
      <title>SSL Decryption Error</title>
      <link>/questions/14805/ssl-decryption-error/</link>
      <pubDate>Tue, 09 Oct 2012 00:57:00 +0000</pubDate>
      
      <guid>/questions/14805/ssl-decryption-error/</guid>
      <description>SSL Decryption Error  0 I keep getting a [Can&#39;t load private key from filename.pem.
Any idea what the problem is and how to resolve it?
Walter
ssl error decryptionasked 09 Oct &#39;12, 00:57
Walter Benton
16●1●1●2
accept rate: 0%
My current Wireshark version info is a follows:
Version 1.8.2 (SVN Rev 44520 from /trunk-1.8)
Copyright 1998-2012 Gerald Combs [email protected] and contributors. This is free software; see the source for copying conditions.</description>
    </item>
    
    <item>
      <title>Tshark HTTP multiple files</title>
      <link>/questions/14810/tshark-http-multiple-files/</link>
      <pubDate>Tue, 09 Oct 2012 02:27:00 +0000</pubDate>
      
      <guid>/questions/14810/tshark-http-multiple-files/</guid>
      <description>Tshark HTTP multiple files  0 Hi,
How can i get all the http.requests and http.response packets from 10 pcap files. I know how to do it from a single file. But i was wondering how to do it on 10 files, cause I&#39;m thinking that http packets may be truncated between one file and the other. Am i right ?
There is capture options to not split http packets between pcap files ?</description>
    </item>
    
    <item>
      <title>Follow tcp stream with tshark still can not in batch mode?</title>
      <link>/questions/14811/follow-tcp-stream-with-tshark-still-can-not-in-batch-mode/</link>
      <pubDate>Tue, 09 Oct 2012 02:54:00 +0000</pubDate>
      
      <guid>/questions/14811/follow-tcp-stream-with-tshark-still-can-not-in-batch-mode/</guid>
      <description>Follow tcp stream with tshark still can not in batch mode?  0 I tried to use the latest wireshark &amp;amp; tshark of version 1.90, I tried to follow tcp stream with tshark in following options:
[email protected]:~/Work/NetWork/packets$ tshark -r follow_tcp.pcapng -z follow,tcp,ascii,127.0.0.1:12345,127.0.0.1:5678
But I just can get one session between the client and server, and I want get all of the sessions, so any tips?
It&#39;s easy to build the test environment with nc, we can use</description>
    </item>
    
    <item>
      <title>Hiding/Replacing Packet Payload Data</title>
      <link>/questions/14813/hidingreplacing-packet-payload-data/</link>
      <pubDate>Tue, 09 Oct 2012 04:45:00 +0000</pubDate>
      
      <guid>/questions/14813/hidingreplacing-packet-payload-data/</guid>
      <description>Hiding/Replacing Packet Payload Data  0 We will be performing analysis on a network in an environment governed by strict security laws and client policies. The user data cannot be removed from the facility.
We would like to be able to take our captures back to the office and review them there, rather than analyzing under the watchful gaze of our client. We can obfuscate the address info, but do not know a way to selectively remove (or replace) the packet payloads based on the highest level protocol in the packet, and still leave the protocol info, packet sizes, and other info needed to perform our analysis.</description>
    </item>
    
    <item>
      <title>Monitoring 2 interfaces on the same machine</title>
      <link>/questions/14817/monitoring-2-interfaces-on-the-same-machine/</link>
      <pubDate>Tue, 09 Oct 2012 06:55:00 +0000</pubDate>
      
      <guid>/questions/14817/monitoring-2-interfaces-on-the-same-machine/</guid>
      <description>Monitoring 2 interfaces on the same machine  0 Hi
I wish to use a machine with 2 interfaces, and transmit frames on one interface, to be received on the other interface via a switch.
I wish to capture the frames leaving and coming back on the 2 interfaces at the same time. The intention is to compare the two captures to test for jitter and latency across the switch.</description>
    </item>
    
    <item>
      <title>Destination IP address when proxy server is configured</title>
      <link>/questions/14823/destination-ip-address-when-proxy-server-is-configured/</link>
      <pubDate>Tue, 09 Oct 2012 10:34:00 +0000</pubDate>
      
      <guid>/questions/14823/destination-ip-address-when-proxy-server-is-configured/</guid>
      <description>Destination IP address when proxy server is configured  0 I m new to Wireshark and have very limited knowledge on how proxy servers function.
I ran Wireshark on a campus LAN where the PCs are configured with a proxy server (e.g. proxy.example.com and port 8000), and I am not sure about the type of proxy server used. All the packets captured show the destination IP address as that of the proxy server, not of the real destination (e.</description>
    </item>
    
    <item>
      <title>how to filter out tcap location update messages</title>
      <link>/questions/14824/how-to-filter-out-tcap-location-update-messages/</link>
      <pubDate>Tue, 09 Oct 2012 10:35:00 +0000</pubDate>
      
      <guid>/questions/14824/how-to-filter-out-tcap-location-update-messages/</guid>
      <description>how to filter out tcap location update messages  0 Hi All,
I want to filter out these wireshark messages. They are always coming, does anyone know how to filter below messages out?
*GSM MAP invoke subscriberLocationReport
GSM MAP returnResultLast subscriberLocationReport
GSM MAP invoke provideSubscriberLocation*
tcap map gsm filter outasked 09 Oct &#39;12, 10:35
omer
6●1●1●4
accept rate: 0% 
 edited 09 Oct &#39;12, 10:35</description>
    </item>
    
    <item>
      <title>How to capture packets only to/from specific ip.</title>
      <link>/questions/14828/how-to-capture-packets-only-tofrom-specific-ip/</link>
      <pubDate>Tue, 09 Oct 2012 12:11:00 +0000</pubDate>
      
      <guid>/questions/14828/how-to-capture-packets-only-tofrom-specific-ip/</guid>
      <description>How to capture packets only to/from specific ip.  0 Hello,
I&#39;m a naive user of Wireshark tool. Normally when we start capturing packets over specific interface, Wireshark will captures all packets over the interface and then we have to apply ip filters to view the data to/from specific ip.
Is there any way where we can capture packets to/from only specific ip and save it to file rather than capturing all the packets and applying filters.</description>
    </item>
    
    <item>
      <title>WireShark sending data to HTTP destinations</title>
      <link>/questions/14832/wireshark-sending-data-to-http-destinations/</link>
      <pubDate>Tue, 09 Oct 2012 13:01:00 +0000</pubDate>
      
      <guid>/questions/14832/wireshark-sending-data-to-http-destinations/</guid>
      <description>WireShark sending data to HTTP destinations  0 Hello. Does anyone happen to know if WireShark is capable of sending data it finds to HTTP destinations?
httpasked 09 Oct &#39;12, 13:01
InfusionDev20
6●2●2●4
accept rate: 0%
what do you mean exactly by &#34;sending data to HTTP destinations&#34; (by using a HTTP POST request)?
What kind of data? Packets in pcap format? Payload bytes (which encoding)?
(09 Oct &#39;12, 14:30) Kurt Knochner ♦It&#39;s more is it possible as WireShark is capturing the data to send the results to an HTTP server as it&#39;s being captured in real time.</description>
    </item>
    
    <item>
      <title>How to find response times for an HTTP call to specific ip.</title>
      <link>/questions/14843/how-to-find-response-times-for-an-http-call-to-specific-ip/</link>
      <pubDate>Tue, 09 Oct 2012 15:16:00 +0000</pubDate>
      
      <guid>/questions/14843/how-to-find-response-times-for-an-http-call-to-specific-ip/</guid>
      <description>How to find response times for an HTTP call to specific ip.  0 Hi,
Do we have any specific filter to use to find response times for an HTTP call to/from specific ip.
Thanks,
wiresharkasked 09 Oct &#39;12, 15:16
dvsrk
1●2●2●4
accept rate: 0%
 edited 09 Oct &#39;12, 22:40 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
0&#34;call&#34; in what sense? Voice over IP phone call?</description>
    </item>
    
    <item>
      <title>Please Help! Why Window Size of one receiver (company B) retain same?</title>
      <link>/questions/14848/please-help-why-window-size-of-one-receiver-company-b-retain-same/</link>
      <pubDate>Tue, 09 Oct 2012 20:41:00 +0000</pubDate>
      
      <guid>/questions/14848/please-help-why-window-size-of-one-receiver-company-b-retain-same/</guid>
      <description>Please Help! Why Window Size of one receiver (company B) retain same?  0 Hi Guru,
We are experiencing email delay issue to company B only and we are fine with sending to other companies. After invesigation, we realized when we do SMTP transission, window size of company always has same number and never increased. And then we got TCP Window is Full message and their window size increase after 5-6 time re-try.</description>
    </item>
    
    <item>
      <title>Wireshark keeps giving a 0 for length.</title>
      <link>/questions/14850/wireshark-keeps-giving-a-0-for-length/</link>
      <pubDate>Tue, 09 Oct 2012 22:29:00 +0000</pubDate>
      
      <guid>/questions/14850/wireshark-keeps-giving-a-0-for-length/</guid>
      <description>Wireshark keeps giving a 0 for length.  0 Hello. I am analyzing virus through Virtualbox, and am using Wireshark in my real computer (mac) to monitor all of the network connections it makes. I have gotten a lot of network activity from the virus, showing me the IP that it is communicating to, the network protocol that it is using, etc. I always get data inside of my little hex viewer at the bottom of Wireshark, but whenever I click &#34;</description>
    </item>
    
    <item>
      <title>Slow throughput over USB tethering</title>
      <link>/questions/14852/slow-throughput-over-usb-tethering/</link>
      <pubDate>Tue, 09 Oct 2012 22:57:00 +0000</pubDate>
      
      <guid>/questions/14852/slow-throughput-over-usb-tethering/</guid>
      <description>Slow throughput over USB tethering  0 Dear Experts,
I am actually testing USB tethering throughput over LTE network. I have found that the throughput is quite low - the DownLink speed is about ~ 3MBps. When tested without USB tethering (i.e. Embedded mode of Smart phone), I can reach the throughput more than 13Mbps. But as soon as I turn to the USB Tethering, the throughput significantly drops.
I have gathered the PCAP logs and has found lots of Duplicate ACKs and Retransmissions.</description>
    </item>
    
    <item>
      <title>kindly help me to confirm to get confirmation of packet loss</title>
      <link>/questions/14864/kindly-help-me-to-confirm-to-get-confirmation-of-packet-loss/</link>
      <pubDate>Wed, 10 Oct 2012 02:10:00 +0000</pubDate>
      
      <guid>/questions/14864/kindly-help-me-to-confirm-to-get-confirmation-of-packet-loss/</guid>
      <description>kindly help me to confirm to get confirmation of packet loss  0 Hi ,
Somebody can help there is file missing from client to server&amp;amp; observed below massage in the snoop logs.kindly help me to confirm is there packet drop during the data transmission.
&#34;21618&#34;,&#34;5135.427497&#34;,&#34;172.29.0.52&#34;,&#34;10.31.96.9&#34;,&#34;TCP&#34;,&#34;[TCP segment of a reassembled PDU]&#34; &#34;21619&#34;,&#34;5135.427510&#34;,&#34;172.29.0.52&#34;,&#34;10.31.96.9&#34;,&#34;TCP&#34;,&#34;[TCP Dup ACK 21618#1] 34560 &amp;gt; ssh [ACK] Seq=302100 Ack=953008 Win=49640 Len=0 SLE=954468 SRE=955928&#34; &#34;21620&#34;,&#34;5135.517490&#34;,&#34;10.31.96.9&#34;,&#34;172.29.0.52&#34;,&#34;SSHv2&#34;,&#34;[TCP Previous segment lost] Encrypted response packet len=1460&#34;</description>
    </item>
    
    <item>
      <title>Filtering Window Update-packet</title>
      <link>/questions/14865/filtering-window-update-packet/</link>
      <pubDate>Wed, 10 Oct 2012 02:12:00 +0000</pubDate>
      
      <guid>/questions/14865/filtering-window-update-packet/</guid>
      <description>Filtering Window Update-packet  0 Is it possible to filter Window Update-packets with tcpdump? I know that in wireshark the filter is &#34;tcp.analysis.window_update&#34; but I&#39;m capturing traffic from a server and I can&#39;t use wireshark.
For example the Zero Window packet (tcp.analysis.zero_window) can be filtered with &#34;tcp[14] = 0 &amp;amp;&amp;amp; tcp[15] = 0&#34; in tcpdump. Is there something similar for Window Update?
-Rakki
filter window tcpdump updateasked 10 Oct &#39;12, 02:12</description>
    </item>
    
    <item>
      <title>Not seeing Jumbo Packets in Wireshark</title>
      <link>/questions/14867/not-seeing-jumbo-packets-in-wireshark/</link>
      <pubDate>Wed, 10 Oct 2012 02:39:00 +0000</pubDate>
      
      <guid>/questions/14867/not-seeing-jumbo-packets-in-wireshark/</guid>
      <description>Not seeing Jumbo Packets in Wireshark  0 Hi All, I have a hardware board which sends Jumbo packets of around 8192 byte sized packet.My laptop is of following configuration Windows-7 64-Bit Operating System. Wireshark version Version 1.8.0 (SVN Rev 43431 from /trunk-1.8)
I followed below steps to change the MTU Size to 9216 bytes.
Open a command line window as an Administrator (ie. right click on All Programs &amp;gt; Accessories &amp;gt; Command Prompt and select Run as administrator) .</description>
    </item>
    
    <item>
      <title>[closed] TCP Previous segment lost</title>
      <link>/questions/14868/tcp-previous-segment-lost/</link>
      <pubDate>Wed, 10 Oct 2012 02:43:00 +0000</pubDate>
      
      <guid>/questions/14868/tcp-previous-segment-lost/</guid>
      <description>[closed] TCP Previous segment lost  0 Hi Guys,
I&#39;m quite new to wireshark but i am using it to try and diagnose an issue with have with data loss from client to server. I am see a lot of the following lines in the capture and wondered if anyone could help explain what they are:
&#34;21618&#34;,&#34;5135.427497&#34;,&#34;172.29.0.52&#34;,&#34;10.31.96.9&#34;,&#34;TCP&#34;,&#34;[TCP segment of a reassembled PDU]&#34; &#34;21619&#34;,&#34;5135.427510&#34;,&#34;172.29.0.52&#34;,&#34;10.31.96.9&#34;,&#34;TCP&#34;,&#34;[TCP Dup ACK 21618#1] 34560 &amp;gt; ssh [ACK] Seq=302100 Ack=953008 Win=49640 Len=0 SLE=954468 SRE=955928&#34;</description>
    </item>
    
    <item>
      <title>Active Directory does not allow changing of interface card</title>
      <link>/questions/14879/active-directory-does-not-allow-changing-of-interface-card/</link>
      <pubDate>Wed, 10 Oct 2012 04:51:00 +0000</pubDate>
      
      <guid>/questions/14879/active-directory-does-not-allow-changing-of-interface-card/</guid>
      <description>Active Directory does not allow changing of interface card  0 Hello all, I&#39;m running the latest version of Wireshark as part of the Cisco curriculum. All of our machines are on Windows 7 Enterprise with all the latest updates and service packs and Windows Server 2008 R2. When the students try to change the interface card, there is nothing listed in the box. I logged in with my ID to the domain figuring it was a rights issue, but I can&#39;t see it either and I have administrator rights to the machine if not the domain,but my account gets the same error.</description>
    </item>
    
    <item>
      <title>Filter(show)a  URL Webserver using a wireshark</title>
      <link>/questions/14885/filtershowa-url-webserver-using-a-wireshark/</link>
      <pubDate>Wed, 10 Oct 2012 06:18:00 +0000</pubDate>
      
      <guid>/questions/14885/filtershowa-url-webserver-using-a-wireshark/</guid>
      <description>Filter(show)a URL Webserver using a wireshark  0 How can I see which particular web server has been used on particular URL(Web Site)? Which filter and command do I have to use?
web serverasked 10 Oct &#39;12, 06:18
marsal
1●3●3●5
accept rate: 0%
 edited 10 Oct &#39;12, 06:23 
  
One Answer:
  
1which particular web server has been used on particular URL(Web Site)?
Maybe I&#39;m getting your question wrong, but the HTTP Host header (the accessed server) is usually the same as the host part in the URL (what you type in the browser - http://host/xxxx).</description>
    </item>
    
    <item>
      <title>Language used from Browser to Web Server</title>
      <link>/questions/14890/language-used-from-browser-to-web-server/</link>
      <pubDate>Wed, 10 Oct 2012 06:41:00 +0000</pubDate>
      
      <guid>/questions/14890/language-used-from-browser-to-web-server/</guid>
      <description>Language used from Browser to Web Server  0 How can I find in http header which language is being used from Browser to Webserver? How can I filter, which command I have to use?
languagesasked 10 Oct &#39;12, 06:41
marsal
1●3●3●5
accept rate: 0%
  
One Answer:
  
1That&#39;s the HTTP request header Accept-Language.
Display Filter: http.accept_language contains &#34;en-en&#34; (or any other language, like &#34;de-de&#34;, &#34;</description>
    </item>
    
    <item>
      <title>segment capture into smaller files of 1/2 hour increments on windows 2008 server</title>
      <link>/questions/14898/segment-capture-into-smaller-files-of-12-hour-increments-on-windows-2008-server/</link>
      <pubDate>Wed, 10 Oct 2012 08:47:00 +0000</pubDate>
      
      <guid>/questions/14898/segment-capture-into-smaller-files-of-12-hour-increments-on-windows-2008-server/</guid>
      <description>segment capture into smaller files of 1/2 hour increments on windows 2008 server  0 how can this be done? when i attempt to editcap -i, an error is returned stating &#39;editcap&#39; is not recognized as an internal or external command,operable program or batch file
editcapasked 10 Oct &#39;12, 08:47
allstreamtech
1●1●1●1
accept rate: 0%
 edited 10 Oct &#39;12, 08:58 
grahamb ♦
19.8k●3●30●206
  
One Answer:</description>
    </item>
    
    <item>
      <title>Monitoring WhatsApp</title>
      <link>/questions/14906/monitoring-whatsapp/</link>
      <pubDate>Wed, 10 Oct 2012 15:30:00 +0000</pubDate>
      
      <guid>/questions/14906/monitoring-whatsapp/</guid>
      <description>Monitoring WhatsApp  0 hi, how can i monitore whatsapp on my network?? thank you
whatsappasked 10 Oct &#39;12, 15:30
lebtrack
1●1●1●1
accept rate: 0%
 edited 06 Mar &#39;16, 23:30 
Jasper ♦♦
23.8k●5●51●284
You mean WhatsApp Messenger? The mobile messaging app?
(12 Oct &#39;12, 01:06) rakkiyou can capture the whatsapp packets traffic travelling through gateway or modem through wireshark,After that you can dissect and monitor.
(06 Mar &#39;16, 23:13) rathnaTech</description>
    </item>
    
    <item>
      <title>Freenet6 Wireshark Trace</title>
      <link>/questions/14908/freenet6-wireshark-trace/</link>
      <pubDate>Wed, 10 Oct 2012 20:58:00 +0000</pubDate>
      
      <guid>/questions/14908/freenet6-wireshark-trace/</guid>
      <description>Freenet6 Wireshark Trace  0 I connected to IPv6 via Freenet6, logged into ipv6.google.com and captured the Wireshark trace.
In the trace it does not show any IPv4 address. Connection mode is IPv6-in-UDP-IPv4 Tunnel (NAT Traversal). My question is,
shouldn&#39;t the tunnel be going through my IPv4 network?If it is not so how is the connection established with remote server?If anyone knows please help me.
Thank You
Shreehari M
tunnel ipv6 freenet6asked 10 Oct &#39;12, 20:58</description>
    </item>
    
    <item>
      <title>[closed] View traffic in and out similtaniously</title>
      <link>/questions/14912/view-traffic-in-and-out-similtaniously/</link>
      <pubDate>Wed, 10 Oct 2012 23:58:00 +0000</pubDate>
      
      <guid>/questions/14912/view-traffic-in-and-out-similtaniously/</guid>
      <description>[closed] View traffic in and out similtaniously  0 If a machine has 2 network adapters and an ethernet frame leaves on one, addressed for the other. Is it possible to captur both instances of the frame in one instance of wireshark? the default behaviour of the psudo interface capturing both interfaces seems only to be to record one instance of the frome?
multiple_interfacesasked 10 Oct &#39;12, 23:58
Urumiko
1●3●3●4</description>
    </item>
    
    <item>
      <title>Linux access to interfaces</title>
      <link>/questions/14913/linux-access-to-interfaces/</link>
      <pubDate>Thu, 11 Oct 2012 00:00:00 +0000</pubDate>
      
      <guid>/questions/14913/linux-access-to-interfaces/</guid>
      <description>Linux access to interfaces  0 As I understand it only one process can access a network interface at any given time. Does this mean running wireshark and a packet generator on the same interface will half productivity?
linuxasked 11 Oct &#39;12, 00:00
Urumiko
1●3●3●4
accept rate: 0%
  
One Answer:
  
0As I understand it only one process can access a network interface at any given time.</description>
    </item>
    
    <item>
      <title>Wireshark crashing</title>
      <link>/questions/14914/wireshark-crashing/</link>
      <pubDate>Thu, 11 Oct 2012 00:13:00 +0000</pubDate>
      
      <guid>/questions/14914/wireshark-crashing/</guid>
      <description>Wireshark crashing  0 Hi all, thanks for being here. I&#39;m running Wireshark 1.6.7 on Ubuntu 12.04.Total newbie.Left side of screen &#34;capture&#34; box says &#34;no interface can be used for capturing in this system with the current configuration&#34;. Striking 1st top left icon for &#34;listing available capture interfaces&#34; gives me a pop-up box with a red circle w/ white bar inside stating &#34;There are no interfaces on which a capture can be done.</description>
    </item>
    
    <item>
      <title>Detect p2p (torrent) traffic in console with tshark</title>
      <link>/questions/14918/detect-p2p-torrent-traffic-in-console-with-tshark/</link>
      <pubDate>Thu, 11 Oct 2012 04:34:00 +0000</pubDate>
      
      <guid>/questions/14918/detect-p2p-torrent-traffic-in-console-with-tshark/</guid>
      <description>Detect p2p (torrent) traffic in console with tshark  0 Hello,
What are the methods of determining the torrent traffic in console, using a utility tshark? At the moment I use the following command:
tshark tcp portrange 6881-6889
Are there other ways?
p2p torrentasked 11 Oct &#39;12, 04:34
dkorzhevin
1●2●2●3
accept rate: 0%
  
One Answer:
  
0You can try this: bittorrent is a valid display filter and you can use it with tshark.</description>
    </item>
    
    <item>
      <title>Sample V5UA pcap file</title>
      <link>/questions/14925/sample-v5ua-pcap-file/</link>
      <pubDate>Thu, 11 Oct 2012 05:54:00 +0000</pubDate>
      
      <guid>/questions/14925/sample-v5ua-pcap-file/</guid>
      <description>Sample V5UA pcap file  0 Hello everyone,
Does anyone have a sample V5UA pcap file. I have a text file that has a E1 HDLC capture of a V52 message. I want to convert it to V5UA pcap file so wireshark can decode it. Does anyone have a sample V5UA pcap file so I can copy the SCTP and V5UA specific hex before the HDLC dump and use text2pcap to convert it to pcap file.</description>
    </item>
    
    <item>
      <title>filter GSM MAP requests and responses with single filter</title>
      <link>/questions/14927/filter-gsm-map-requests-and-responses-with-single-filter/</link>
      <pubDate>Thu, 11 Oct 2012 06:47:00 +0000</pubDate>
      
      <guid>/questions/14927/filter-gsm-map-requests-and-responses-with-single-filter/</guid>
      <description>filter GSM MAP requests and responses with single filter  0 I&#39;m trying to find a proper way to filter requests and responses for GSM MAP operations. So, usualy capture looks like this:
TCAP - Transaction ID - Components GSM MAP - opCode - MSISDN - etc&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;p&amp;gt;I.e., GSM MAP is payload of TCAP. I filter requests based on MAP values (opCode and msisdn), such as&amp;lt;/p&amp;gt;&amp;lt;pre&amp;gt;&amp;lt;code&amp;gt;(gsm_map.address.digits == &amp;amp;quot;123456789&amp;amp;quot;) &amp;amp;amp;&amp;amp;amp; (gsm_old.localValue == 45)&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;p&amp;gt;Response comes with the same TCAP Transaction ID, so I manualy extract it from request and filter again:&amp;lt;/p&amp;gt;&amp;lt;pre&amp;gt;&amp;lt;code&amp;gt;tcap.</description>
    </item>
    
    <item>
      <title>Filter on HTTP Content (Line-based text data)</title>
      <link>/questions/14931/filter-on-http-content-line-based-text-data/</link>
      <pubDate>Thu, 11 Oct 2012 08:32:00 +0000</pubDate>
      
      <guid>/questions/14931/filter-on-http-content-line-based-text-data/</guid>
      <description>Filter on HTTP Content (Line-based text data)  0 Hi,
I have about a months worth of Wireshark captures that I&#39;d like to now view only http content that contains the word &#34;EXITAU&#34;. That data appears in the &#34;Line-based text data&#34;.
I don&#39;t know how to create a display filter on that. Can it even be done?
Thanks,
Dana
filter content httpasked 11 Oct &#39;12, 08:32
Dana
11●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Lua postdissector executed every time I click on a packet</title>
      <link>/questions/14936/lua-postdissector-executed-every-time-i-click-on-a-packet/</link>
      <pubDate>Thu, 11 Oct 2012 09:28:00 +0000</pubDate>
      
      <guid>/questions/14936/lua-postdissector-executed-every-time-i-click-on-a-packet/</guid>
      <description>Lua postdissector executed every time I click on a packet  0 Hi, I wrote a simple postdissector in lua but it seems to be executed twice when wireshark is opened and then every time for a packet I click on, or move to another packet with arrow keys.
I&#39;ve also noticed that if I restrict the execution by tracking how many times it was run for a given packet the new tree item will be removed.</description>
    </item>
    
    <item>
      <title>Excessive LLMNR packets from one workstation</title>
      <link>/questions/14940/excessive-llmnr-packets-from-one-workstation/</link>
      <pubDate>Thu, 11 Oct 2012 11:36:00 +0000</pubDate>
      
      <guid>/questions/14940/excessive-llmnr-packets-from-one-workstation/</guid>
      <description>Excessive LLMNR packets from one workstation  0 We have one workstation which sends out 40 LLMNR packets every 30 seconds (marked &#34;Standard query A&#34;) It&#39;s been checked every way possible for malware and rootkits, I feel pretty confident that it&#39;s clean. But what gives? None of the other machines on our network broadcast anywhere near this much. Or am I obsessing over nothing?
-Roger
llmnr excessiveasked 11 Oct &#39;12, 11:36</description>
    </item>
    
    <item>
      <title>Looking for a little help</title>
      <link>/questions/14941/looking-for-a-little-help/</link>
      <pubDate>Thu, 11 Oct 2012 12:37:00 +0000</pubDate>
      
      <guid>/questions/14941/looking-for-a-little-help/</guid>
      <description>Looking for a little help  0 I&#39;m using a couple of Color Rules that were given to me during a WireShark class with Laura Chappell. The color rule that this network is hitting is as follows: (tcp.window_size &amp;lt; 1460) &amp;amp;&amp;amp; (tcp.flags.reset == 0)
I know that this is a color rule to find Windows Zero Errors and Window Size under 1460. The question: Is this rule correct or is there a better rule?</description>
    </item>
    
    <item>
      <title>all packets</title>
      <link>/questions/14943/all-packets/</link>
      <pubDate>Thu, 11 Oct 2012 17:55:00 +0000</pubDate>
      
      <guid>/questions/14943/all-packets/</guid>
      <description>all packets  0 are there packets wireshark will not capture? I am trying to watch a link between my router and a destination server but I do not see the traffic. I seem to see quite a bit of traffic but not to the server the router is supposed to be sending to.
packetsasked 11 Oct &#39;12, 17:55
wrcooke
1●2●2●2
accept rate: 0%
You&#39;ve got to be a little more specific than this.</description>
    </item>
    
    <item>
      <title>how to begin with wireshark plugin coding</title>
      <link>/questions/14948/how-to-begin-with-wireshark-plugin-coding/</link>
      <pubDate>Thu, 11 Oct 2012 23:14:00 +0000</pubDate>
      
      <guid>/questions/14948/how-to-begin-with-wireshark-plugin-coding/</guid>
      <description>how to begin with wireshark plugin coding  0 I a new to wireshark plugin development. How can I start with wireshark plugin development.
developmentasked 11 Oct &#39;12, 23:14
Akhil
53●27●28●31
accept rate: 0%
  
One Answer:
  
1Invaluable sources are
Wireshark Developer Guidethe doc/ directory in the sourcesThe sourcesYou could opt to start in Lua, or use the Wireshark Generic Dissector
answered 12 Oct &#39;12, 05:47</description>
    </item>
    
    <item>
      <title>[closed] tcp_dissect_pdus. get reassemble TCP</title>
      <link>/questions/14950/tcp_dissect_pdus-get-reassemble-tcp/</link>
      <pubDate>Thu, 11 Oct 2012 23:56:00 +0000</pubDate>
      
      <guid>/questions/14950/tcp_dissect_pdus-get-reassemble-tcp/</guid>
      <description>[closed] tcp_dissect_pdus. get reassemble TCP  0 Hi, I&#39;m using
tcp_dissect_pdus(tvb, pinfo, tree, TRUE, FRAME_HEADER_LEN, get_foo_message_len, dissect_foo_message)
to reassemble split TCP Packets in my own dissector. However, I cannot get the full TCP packet. In the dissect_foo_message, I do nothing first, just get the full TCP context by using:
data_len = tvb_length(tvb); sprintf(str, &amp;quot;%s\n&amp;quot;, tvb_get_string(tvb, 122, data_len));the context in str is truncated.
I&#39;m confused, according to the tutorial, I should get the full TCP packet in the dissect_foo_message, right?</description>
    </item>
    
    <item>
      <title>How to get the field &amp;quot;DID unknown 4041&amp;quot; into the column</title>
      <link>/questions/14963/how-to-get-the-field-did-unknown-4041-into-the-column/</link>
      <pubDate>Fri, 12 Oct 2012 06:21:00 +0000</pubDate>
      
      <guid>/questions/14963/how-to-get-the-field-did-unknown-4041-into-the-column/</guid>
      <description>How to get the field &amp;ldquo;DID unknown 4041&amp;rdquo; into the column  0 Hello everybody,
I am trying to analyze the up-link Wireless traffic generated by my Sony Ericsson phone and captured by my D-Link router, on which I installed the DD-WRT firmware. To do this, first I log in the router and enable the prism0 interface by typing the command:
wl -i eth1 monitor 1
and then I start to capture the packets by typing:</description>
    </item>
    
    <item>
      <title>out of order packets</title>
      <link>/questions/14965/out-of-order-packets/</link>
      <pubDate>Fri, 12 Oct 2012 10:39:00 +0000</pubDate>
      
      <guid>/questions/14965/out-of-order-packets/</guid>
      <description>out of order packets  0 I seem to get an awful lot of out of order frames from a server to a specific station. There is nothing really complicated about the system. The server is in the states and the w/s is in holland. There is not a bandwidth issue at all. any thoughts
of order outasked 12 Oct &#39;12, 10:39
Raymond
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Zero window error</title>
      <link>/questions/14967/zero-window-error/</link>
      <pubDate>Fri, 12 Oct 2012 11:58:00 +0000</pubDate>
      
      <guid>/questions/14967/zero-window-error/</guid>
      <description>Zero window error  0 I am getting a zero window error from a copier, I&#39;m sorry 2 copiers and 1 printer, this did not occur before changes were made to the customers network. They replaced the nic in the printer to resolve the problem. my question is what could have caused the failure of the 3 nics if they are infact the cause of the zero window error
copier zero-window nicasked 12 Oct &#39;12, 11:58</description>
    </item>
    
    <item>
      <title>UDP Retransmissions</title>
      <link>/questions/14968/udp-retransmissions/</link>
      <pubDate>Fri, 12 Oct 2012 12:05:00 +0000</pubDate>
      
      <guid>/questions/14968/udp-retransmissions/</guid>
      <description>UDP Retransmissions  0 Is there a mechanism or script that derives the MAC layer (not TCP) retransmission statistics for a UDP connection using Block Acks? I assume that such a script would analyze repeating 802.11 sequence numbers and possibly Block Ack bitmaps.
ack retransmission blockasked 12 Oct &#39;12, 12:05
ReidW
1●2●2●3
accept rate: 0%
  
One Answer:
  
0There is no bulit-in (in the protocol) ethernet and/or UDP retransmission mechanism.</description>
    </item>
    
    <item>
      <title>How to capture LACP packets with wireshark</title>
      <link>/questions/14977/how-to-capture-lacp-packets-with-wireshark/</link>
      <pubDate>Fri, 12 Oct 2012 21:46:00 +0000</pubDate>
      
      <guid>/questions/14977/how-to-capture-lacp-packets-with-wireshark/</guid>
      <description>How to capture LACP packets with wireshark  0 1I am using Wireshark ver 1.8.3 but unable to capture LACP packets. Can you please tell me step by step procedure to capture LACP using Wireshark
lacpasked 12 Oct &#39;12, 21:46
chirantan
1●1●2●1
accept rate: 0%
  
2 Answers:
  
0What is your system and your NIC driver? LACP is done at the driver level. So maybe, you don&#39;t see those packets, because the driver strips those packets before they arrive at wireshark.</description>
    </item>
    
    <item>
      <title>interface problem</title>
      <link>/questions/14987/interface-problem/</link>
      <pubDate>Sat, 13 Oct 2012 08:57:00 +0000</pubDate>
      
      <guid>/questions/14987/interface-problem/</guid>
      <description>interface problem  0 I am using wireshark in windows 7. While opening wireshark it is not showing the interfaces for capturing the packets. I did troubleshoot, for the first time it had shown the interfaces and I was able to capture packet, but when reopened again no interface and showing Error = 0;this &#34;can&#39;t happen&#34;. or showing that- No interface can be used for capturing in this system with the current configuration.</description>
    </item>
    
    <item>
      <title>get packet from wireshark from CET time 16::00 to 17::00</title>
      <link>/questions/14995/get-packet-from-wireshark-from-cet-time-1600-to-1700/</link>
      <pubDate>Sat, 13 Oct 2012 20:41:00 +0000</pubDate>
      
      <guid>/questions/14995/get-packet-from-wireshark-from-cet-time-1600-to-1700/</guid>
      <description>get packet from wireshark from CET time 16::00 to 17::00  0 i want to write the filter to get packets in a time slice; and it seems wireshark use GMT time. and so how to write the filer?
timeasked 13 Oct &#39;12, 20:41
boyxiaolong
1●1●1●1
accept rate: 0%
The UI is localized to your timezone by default. Unless you change it to display absolute time. But I don&#39;t quite understand your question.</description>
    </item>
    
    <item>
      <title>Windows 8 App?</title>
      <link>/questions/15002/windows-8-app/</link>
      <pubDate>Sun, 14 Oct 2012 20:40:00 +0000</pubDate>
      
      <guid>/questions/15002/windows-8-app/</guid>
      <description>Windows 8 App?  0 is there an App for Windows 8 for Wire Shark? or any plans to make one
windows8asked 14 Oct &#39;12, 20:40
equilibrium24
1●1●1●1
accept rate: 0%
 edited 15 Oct &#39;12, 01:33 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
0Wireshark can already be installed on Windows 8, see the question Install on windows 8 (WinPcap issue). There are currently no plans for a MetroModern UI version.</description>
    </item>
    
    <item>
      <title>How to filter out all packets to/from a specific process?</title>
      <link>/questions/15006/how-to-filter-out-all-packets-tofrom-a-specific-process/</link>
      <pubDate>Mon, 15 Oct 2012 01:49:00 +0000</pubDate>
      
      <guid>/questions/15006/how-to-filter-out-all-packets-tofrom-a-specific-process/</guid>
      <description>How to filter out all packets to/from a specific process?  0 Hi all,
May I know how to filter out all packets to/from a specific process through display filter?
thanks!
display-filterasked 15 Oct &#39;12, 01:49
SteveZhou
191●27●30●34
accept rate: 0%
  
2 Answers:
  
0 It&#39;s not possible with current Wireshark as it has no knowledge of processes. If you know which port(s) a process is using then you can construct a filter with those ports.</description>
    </item>
    
    <item>
      <title>duplicate ack within 0,000001 seconds of original ack</title>
      <link>/questions/15012/duplicate-ack-within-0000001-seconds-of-original-ack/</link>
      <pubDate>Mon, 15 Oct 2012 03:48:00 +0000</pubDate>
      
      <guid>/questions/15012/duplicate-ack-within-0000001-seconds-of-original-ack/</guid>
      <description>duplicate ack within 0,000001 seconds of original ack  0 I am seeing an ack real quick after the same ack thus wireshark marks it as duplicate. It is the first packet after the original ack.
My question is is it normal to have ack this close together. What scenario&#39;s would have this kind of traffic.
Thank you for your time
ack duplicateasked 15 Oct &#39;12, 03:48
dtor
1●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>how to write a wireshark  dissector to write a amf packet to a file</title>
      <link>/questions/15025/how-to-write-a-wireshark-dissector-to-write-a-amf-packet-to-a-file/</link>
      <pubDate>Mon, 15 Oct 2012 22:59:00 +0000</pubDate>
      
      <guid>/questions/15025/how-to-write-a-wireshark-dissector-to-write-a-amf-packet-to-a-file/</guid>
      <description>how to write a wireshark dissector to write a amf packet to a file  0 I want to write a wireshark dissector in ubuntu to write an amf packet to a file.
dissectorasked 15 Oct &#39;12, 22:59
Akhil
53●27●28●31
accept rate: 0%
 edited 15 Oct &#39;12, 23:00 
There already is a dissector: RTMPT
(15 Oct &#39;12, 23:28) Jaap ♦Dissectors don&#39;t write stuff to files, they just dissect packets and construct a tree of fields and subfields.</description>
    </item>
    
    <item>
      <title>UnInistall problems</title>
      <link>/questions/15027/uninistall-problems/</link>
      <pubDate>Mon, 15 Oct 2012 23:24:00 +0000</pubDate>
      
      <guid>/questions/15027/uninistall-problems/</guid>
      <description>UnInistall problems  0 Hi Lately, it seems that every day wireshark uninstalls itself running windows 7 pro. Add / Remove programs shows it is no longer installed. I&#39;ve tried versions 1.6.x and 1.8.x and both do the same thing. It had been working for a while but now everdayit goes away. I run GFI vipre antimalware and it has never detected a virus. The program is great and it helped me pass CompTIA&#39;s Network+ Exam.</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t capture</title>
      <link>/questions/15037/cant-capture/</link>
      <pubDate>Tue, 16 Oct 2012 12:47:00 +0000</pubDate>
      
      <guid>/questions/15037/cant-capture/</guid>
      <description>can&amp;rsquo;t capture  0 Why i cant capture any packages after i start my interface &#34;Atheros L1C&#34;?
captureasked 16 Oct &#39;12, 12:47
rbnaraujo
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Wireshark build in Ubuntu failed</title>
      <link>/questions/15039/wireshark-build-in-ubuntu-failed/</link>
      <pubDate>Tue, 16 Oct 2012 22:05:00 +0000</pubDate>
      
      <guid>/questions/15039/wireshark-build-in-ubuntu-failed/</guid>
      <description>Wireshark build in Ubuntu failed  0 I get the following error when I &#34;make&#34; Wireshark in Ubuntu 12.04:
/usr/bin/perl ./make-version.pl . Version configuration file version.conf not found. Using defaults. svn: The path &amp;#39;.&amp;#39; appears to be part of a Subversion 1.7 or greater working copy. Please upgrade your Subversion client to use this working copy. svnversion.h unchanged. make all-recursive make[1]: Entering directory `/home/sss/wireshark&amp;#39; Making all in tools make[2]: Entering directory `/home/sss/wireshark/tools&amp;#39; Making all in lemon make[3]: Entering directory `/home/sss/wireshark/tools/lemon&amp;#39; make[3]: Nothing to be done for `all&amp;#39;.</description>
    </item>
    
    <item>
      <title>hello everyone ,who can give me a cap file which has RAI type of ULI(USER LOCATION INFORMATION),thanks very much</title>
      <link>/questions/15042/hello-everyone-who-can-give-me-a-cap-file-which-has-rai-type-of-uliuser-location-informationthanks-very-much/</link>
      <pubDate>Wed, 17 Oct 2012 00:21:00 +0000</pubDate>
      
      <guid>/questions/15042/hello-everyone-who-can-give-me-a-cap-file-which-has-rai-type-of-uliuser-location-informationthanks-very-much/</guid>
      <description>hello everyone ,who can give me a cap file which has RAI type of ULI(USER LOCATION INFORMATION),thanks very much  0 1,hello everyone ,who can give me a cap file which has RAI type of ULI(USER LOCATION INFORMATION) 2,i compose a rai type UTL,but the wireshark can not decode the rac ,who can tell me what&#39;s wrong with it. the cap file as follow: compose raiasked 17 Oct &#39;12, 00:21</description>
    </item>
    
    <item>
      <title>dumpcap.exe stops remote capture after 6-7 minutes</title>
      <link>/questions/15045/dumpcapexe-stops-remote-capture-after-6-7-minutes/</link>
      <pubDate>Wed, 17 Oct 2012 01:23:00 +0000</pubDate>
      
      <guid>/questions/15045/dumpcapexe-stops-remote-capture-after-6-7-minutes/</guid>
      <description>dumpcap.exe stops remote capture after 6-7 minutes  0 Hi,
I have problem with remote capturing. After 6-7 minutes from tshark remote start, pcap file stops growing. Nothing happens, no errors shows up. Dumpcap.exe is still running in Task Manager, and the lock to pcap file is still holding by dumpcap. I use command: C:\Program Files (x86)\Wireshark\tshark.exe -i rpcap://[10.154.5.33]:2002/\Device\NPF_{E5C7CD1D-35A9-4C3C-8E5F-C0BC37904D10} -w D:/tshark_dump.pcap
BR, Paul
dumpcap hangsasked 17 Oct &#39;12, 01:23
Paul_PL</description>
    </item>
    
    <item>
      <title>MODBUS TCP  traffic is not captured</title>
      <link>/questions/15046/modbus-tcp-traffic-is-not-captured/</link>
      <pubDate>Wed, 17 Oct 2012 01:53:00 +0000</pubDate>
      
      <guid>/questions/15046/modbus-tcp-traffic-is-not-captured/</guid>
      <description>MODBUS TCP traffic is not captured  0 Running Modbus Slave and Modbus Master on one machine with Modbus TCP protocl enabled,Wireshark(Ver.1.8.1) captured any Modbus TCP traffic. Are there any checkups for this case?
modbus tcpasked 17 Oct &#39;12, 01:53
choejs
0●1●1●2
accept rate: 0%
  
One Answer:
  
1Are you running on Windows? If so it&#39;s not easy to capture &#34;loopback&#34; traffic on the same machine.</description>
    </item>
    
    <item>
      <title>How to capture tcp 3 way handshake</title>
      <link>/questions/15057/how-to-capture-tcp-3-way-handshake/</link>
      <pubDate>Wed, 17 Oct 2012 07:08:00 +0000</pubDate>
      
      <guid>/questions/15057/how-to-capture-tcp-3-way-handshake/</guid>
      <description>How to capture tcp 3 way handshake  0 I&#39;m looking to capture the conversation between 2 hosts that contains the 3 way handshake. I&#39;m not sure if this would be doable with a capture filter. Or maybe it&#39;s a display filter. I&#39;m thinking something like: tcp.flags == 0x02 | tcp.flags == 0x10 But I don&#39;t know if this is just a display capture. It doesn&#39;t seem to be recognized in capture filter box.</description>
    </item>
    
    <item>
      <title>554 message is not RFC compliant;missing &amp;quot;date&amp;quot; header</title>
      <link>/questions/15071/554-message-is-not-rfc-compliantmissing-date-header/</link>
      <pubDate>Thu, 18 Oct 2012 00:30:00 +0000</pubDate>
      
      <guid>/questions/15071/554-message-is-not-rfc-compliantmissing-date-header/</guid>
      <description>554 message is not RFC compliant;missing &amp;ldquo;date&amp;rdquo; header  0 Hi everybody. i have a serious problem with SMTP. when i want to test pop3 and smtp status in outlook it respond to me that pop3 is ok but smtp hast a problem and its error is &#34;554 message is not RFC compliant;missing &#34;date&#34; header&#34;. The connection with destination is fine (i checked it by telnet command on both ports 25 and 110 ) .</description>
    </item>
    
    <item>
      <title>how to write a wireshark dissector for amf packet sent over tcp</title>
      <link>/questions/15072/how-to-write-a-wireshark-dissector-for-amf-packet-sent-over-tcp/</link>
      <pubDate>Thu, 18 Oct 2012 01:28:00 +0000</pubDate>
      
      <guid>/questions/15072/how-to-write-a-wireshark-dissector-for-amf-packet-sent-over-tcp/</guid>
      <description>how to write a wireshark dissector for amf packet sent over tcp  0 I want to write a wireshark dissector for amf packet sent over tcp. In wireshark capture window amf packet which is inside a tcp is dissected as tcp . I want to dissect the amf packet that is encapsulated inside tcp.
dissectorasked 18 Oct &#39;12, 01:28
Akhil
53●27●28●31
accept rate: 0%
 edited 18 Oct &#39;12, 02:04</description>
    </item>
    
    <item>
      <title>Reassemble file problem</title>
      <link>/questions/15077/reassemble-file-problem/</link>
      <pubDate>Thu, 18 Oct 2012 03:08:00 +0000</pubDate>
      
      <guid>/questions/15077/reassemble-file-problem/</guid>
      <description>Reassemble file problem  0 Hi Forum readers,
I obtained a pcap file and wanted to find a pdf file and reassemble it i think i have found the tcp stream for it but when I try to save it the pdf is unreadable. i get refered to chapter 7 of the user manual but that isnt helpful for pdfs. Can anyone help me? If you require any more info just let me know</description>
    </item>
    
    <item>
      <title>how to decrypt https packet in wireshark</title>
      <link>/questions/15078/how-to-decrypt-https-packet-in-wireshark/</link>
      <pubDate>Thu, 18 Oct 2012 03:43:00 +0000</pubDate>
      
      <guid>/questions/15078/how-to-decrypt-https-packet-in-wireshark/</guid>
      <description>how to decrypt https packet in wireshark  0 I am writing a dissector for amf packets.These packets are enccrypted inside https packet. To make my amf dissector work i need to decrypt https packets.
Debug File:::::::::::::::::;
ssl_association_remove removing TCP 9443 - http handle 0x2704950 ssl_association_remove removing TCP 443 - http handle 0x2704950 Private key imported: KeyID 03:37:de:f1:a6:0c:a6:a7:52:f2:77:d5:7e:06:bf:7a:... ssl_init IPv4 addr &amp;#39;10.43.100.50&amp;#39; (10.43.100.50) port &amp;#39;9443&amp;#39; filename &amp;#39;/home/akhil/Desktop/Fwd vmware certs/rui.pem&amp;#39; password(only for p12 file) &amp;#39;&amp;#39; ssl_init private key file /home/akhil/Desktop/Fwd vmware certs/rui.</description>
    </item>
    
    <item>
      <title>make visual studio project from wireshark sources</title>
      <link>/questions/15087/make-visual-studio-project-from-wireshark-sources/</link>
      <pubDate>Thu, 18 Oct 2012 09:53:00 +0000</pubDate>
      
      <guid>/questions/15087/make-visual-studio-project-from-wireshark-sources/</guid>
      <description>make visual studio project from wireshark sources  0 Is it possible to create a visual studio project (or may be solution) from wireshark sources and use all advantages of VS to debug and edit sources.
visual-studioasked 18 Oct &#39;12, 09:53
vensan vega
1●2●2●2
accept rate: 0%
  
One Answer:
  
0You can use VS to debug and edit the sources as it is. What we don&#39;t have is a Visual Studio project that ties it all together so that you can just click on the solution.</description>
    </item>
    
    <item>
      <title>Wireshark won&amp;#x27;t start on MacOS - missing libraries?</title>
      <link>/questions/15091/wireshark-wont-start-on-macos-missing-libraries/</link>
      <pubDate>Thu, 18 Oct 2012 13:20:00 +0000</pubDate>
      
      <guid>/questions/15091/wireshark-wont-start-on-macos-missing-libraries/</guid>
      <description>Wireshark won&amp;rsquo;t start on MacOS - missing libraries?  0 Wireshark fails on 10.7.5 with the following errors:
Couldn&#39;t load module /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so: dlopen(/Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so, 10): Symbol not found: _dissector_get_port_handle Referenced from: /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so Expected in: flat namespace in /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/interlink.so
Couldn&#39;t load module /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/sercosiii.so: dlopen(/Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/sercosiii.so, 10): Symbol not found: _dissector_add Referenced from: /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/sercosiii.so Expected in: flat namespace in /Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins/sercosiii.so
Am I missing something that should be in there?
osx macosxasked 18 Oct &#39;12, 13:20</description>
    </item>
    
    <item>
      <title>using &amp;quot;follow tcp stream&amp;quot; code in my project</title>
      <link>/questions/15093/using-follow-tcp-stream-code-in-my-project/</link>
      <pubDate>Thu, 18 Oct 2012 14:24:00 +0000</pubDate>
      
      <guid>/questions/15093/using-follow-tcp-stream-code-in-my-project/</guid>
      <description>using &amp;ldquo;follow tcp stream&amp;rdquo; code in my project  0 I want to assemble all tcp sessions from pcap file and save payload to file. I know about 2 decisions: 1)libnids 2) tcpflow, but all of them can be used only for linux. Could you advise me any such decision for windows.
assemble all tcp sessionsasked 18 Oct &#39;12, 14:24
vensan vega
1●2●2●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Many RST from the Client Machine</title>
      <link>/questions/15095/many-rst-from-the-client-machine/</link>
      <pubDate>Thu, 18 Oct 2012 17:16:00 +0000</pubDate>
      
      <guid>/questions/15095/many-rst-from-the-client-machine/</guid>
      <description>Many RST from the Client Machine  0 Hello, Maybe you can help me figure this out.We&#39;re having time out issues with a web application. The client machine is IP Address: 192.168.108.142 and the Host Web Server IP Address is 193.246.224.116. I ran wireshark from the client machine. Can someone help me understand what is going on here? Thanks. link text
rst tcpasked 18 Oct &#39;12, 17:16
TechQueen
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Why Does Wireshark show my pc&amp;#x27;s searching for their default gateway address repeatedly?</title>
      <link>/questions/15103/why-does-wireshark-show-my-pcs-searching-for-their-default-gateway-address-repeatedly/</link>
      <pubDate>Fri, 19 Oct 2012 05:37:00 +0000</pubDate>
      
      <guid>/questions/15103/why-does-wireshark-show-my-pcs-searching-for-their-default-gateway-address-repeatedly/</guid>
      <description>Why Does Wireshark show my pc&amp;rsquo;s searching for their default gateway address repeatedly?  0 Why Does Wireshark show my pc&#39;s searching for their default gateway address repeatedly? It seems that when I do a Traceroute the first hop is going to the vlan address not the default gateway being passed out by the DHCP server. Every PC in the network is ARP broadcasting for it&#39;s default gateway address. The VLAN address is on the same physical device as the default gateway.</description>
    </item>
    
    <item>
      <title>How do I see traffic to and from a machine?</title>
      <link>/questions/15106/how-do-i-see-traffic-to-and-from-a-machine/</link>
      <pubDate>Fri, 19 Oct 2012 08:05:00 +0000</pubDate>
      
      <guid>/questions/15106/how-do-i-see-traffic-to-and-from-a-machine/</guid>
      <description>How do I see traffic to and from a machine?  0 I had hoped I could enter the (local) ip of the machine in the &#34;filter:&#34; box, but i&#39;m just told that isn&#39;t valid.
machine ip helpasked 19 Oct &#39;12, 08:05
territ
1●1●1●1
accept rate: 0%
Thanks guys!
(21 Oct &#39;12, 10:52) territ  
One Answer:
  
2ip.addr== is the filter you are looking for
BTW: Google / Wireshark Wiki / several other resources are your friends.</description>
    </item>
    
    <item>
      <title>Including packets from a conversation not matching the filter</title>
      <link>/questions/15114/including-packets-from-a-conversation-not-matching-the-filter/</link>
      <pubDate>Fri, 19 Oct 2012 15:56:00 +0000</pubDate>
      
      <guid>/questions/15114/including-packets-from-a-conversation-not-matching-the-filter/</guid>
      <description>Including packets from a conversation not matching the filter  0 I am trying to determine the amount of data received and transmitted back to a remote telematic device that communicates over GPRS on port TCP X to find out if my wireless carrier is overcharging me. The trick is that the server receives data on that same port from several units.
Capture filter: tcp port X Display filter: tcp contains &#34;</description>
    </item>
    
    <item>
      <title>TLS_EMPTY_RENEGOTIATION_INFO_SCSV query</title>
      <link>/questions/15117/tls_empty_renegotiation_info_scsv-query/</link>
      <pubDate>Sat, 20 Oct 2012 09:56:00 +0000</pubDate>
      
      <guid>/questions/15117/tls_empty_renegotiation_info_scsv-query/</guid>
      <description>TLS_EMPTY_RENEGOTIATION_INFO_SCSV query  0 I used wireshark to capture a SSL handshake and when I inspected the Client Hello packet and went to the Cipher Suites heading and I saw the following cipher:
Cipher Suite: TLS EMPTY RENEGOTIATION INFO SCSV (0x00ff)
(There should be an underscore where those spaces are)
I only see that when I inspect a SSL handshake if FireFox initiates the handshake, but if I used Chrome or Internet Explorer I don&#39;t see that.</description>
    </item>
    
    <item>
      <title>how to display flowid alongwith frame number for each packet of a pcap using tshark/wireshark</title>
      <link>/questions/15118/how-to-display-flowid-alongwith-frame-number-for-each-packet-of-a-pcap-using-tsharkwireshark/</link>
      <pubDate>Sat, 20 Oct 2012 22:06:00 +0000</pubDate>
      
      <guid>/questions/15118/how-to-display-flowid-alongwith-frame-number-for-each-packet-of-a-pcap-using-tsharkwireshark/</guid>
      <description>how to display flowid alongwith frame number for each packet of a pcap using tshark/wireshark  0 Is there any concept of flow id in tshark ? When i searched for filters, i found out that tcp.stream exists but its equivalent for udp i.e udp.stream doesn&#39;t exist. When i open a pcap, by default it shows the frame number, ip addresses, info etc. In one column i also need the flow id of each packet alongwith the frame number.</description>
    </item>
    
    <item>
      <title>Seeking help</title>
      <link>/questions/15119/seeking-help/</link>
      <pubDate>Sat, 20 Oct 2012 23:29:00 +0000</pubDate>
      
      <guid>/questions/15119/seeking-help/</guid>
      <description>Seeking help  0 Hi, I am new to wireshark. If someone help me to solve out my network issue, its highly appreciated. I have a network printer. It has static IP Address. Whenever some computers logged into the network, the printer get restarted and loses the connectivity. After reboots, stay connected some more time and again rebooted. It happens through out the day until those &#39;unknown users&#39; get off.</description>
    </item>
    
    <item>
      <title>gsm_map Malformed (in SRI response)</title>
      <link>/questions/15120/gsm_map-malformed-in-sri-response/</link>
      <pubDate>Sun, 21 Oct 2012 02:42:00 +0000</pubDate>
      
      <guid>/questions/15120/gsm_map-malformed-in-sri-response/</guid>
      <description>gsm_map Malformed (in SRI response)  0 Hi I have problem with GSM_MAP in SRI response message, the message come with gsm_map Malformed. can someone help me how i can see the message in full view.
[Malformed Packet: GSM_MAP] Expert Info (Error/Malformed): Malformed Packet (Exception occurred) Malformed Packet (Exception occurred) Severity level: Error Group: Malformed
I have wireshark version 1.8.3
Thanks a lot
gsm_mapasked 21 Oct &#39;12, 02:42
LIOR
1●2●2●2</description>
    </item>
    
    <item>
      <title>gsm_map BER (in SRI request)</title>
      <link>/questions/15125/gsm_map-ber-in-sri-request/</link>
      <pubDate>Sun, 21 Oct 2012 06:11:00 +0000</pubDate>
      
      <guid>/questions/15125/gsm_map-ber-in-sri-request/</guid>
      <description>gsm_map BER (in SRI request)  0 Hi Hi I have problem with GSM_MAP in SRI request message, the message come with BER can someone help me how i can see the message in full view.
BER: Dissector for OID:0.34.5 not implemented. Contact Wireshark developers if you want this supported
I have wireshark version 1.8.3
Thanks a lot
gsm_mapasked 21 Oct &#39;12, 06:11
LIOR
1●2●2●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>unknown codec within GSM I/F BSSMAP &amp;quot;Assignment Complete&amp;quot; message</title>
      <link>/questions/15137/unknown-codec-within-gsm-if-bssmap-assignment-complete-message/</link>
      <pubDate>Sun, 21 Oct 2012 15:47:00 +0000</pubDate>
      
      <guid>/questions/15137/unknown-codec-within-gsm-if-bssmap-assignment-complete-message/</guid>
      <description>unknown codec within GSM I/F BSSMAP &amp;ldquo;Assignment Complete&amp;rdquo; message  0 In some cases I see the following field description within a GSM I/F BSSMAP &#34;Assignment Complete&#34; message: &#34;Unknown codec - the rest of the dissection my be suspect&#34;. I think that this is a wireshark application terminology (and not GSM...).
Under what conditions we are to get this field description?Is this a bug?
bssmap codec typeasked 21 Oct &#39;12, 15:47</description>
    </item>
    
    <item>
      <title>Wireshark version 1.8.0 or above does not decode MPLS over PPP.</title>
      <link>/questions/15139/wireshark-version-180-or-above-does-not-decode-mpls-over-ppp/</link>
      <pubDate>Sun, 21 Oct 2012 17:58:00 +0000</pubDate>
      
      <guid>/questions/15139/wireshark-version-180-or-above-does-not-decode-mpls-over-ppp/</guid>
      <description>Wireshark version 1.8.0 or above does not decode MPLS over PPP.  0 Wireshark version 1.8.0 or above does not decode MPLS over PPP in the Packet Details Pane, however, Wireshark version 1.6.5 works well.
the screenshot of version 1.9.0 the screenshot of version 1.6.5 ppp mplsasked 21 Oct &#39;12, 17:58
mildblues
21●2●3●6
accept rate: 0%
 edited 21 Oct &#39;12, 18:06 
  
2 Answers:</description>
    </item>
    
    <item>
      <title>what am i looking at &amp;amp; compat</title>
      <link>/questions/15141/what-am-i-looking-at-compat/</link>
      <pubDate>Sun, 21 Oct 2012 22:35:00 +0000</pubDate>
      
      <guid>/questions/15141/what-am-i-looking-at-compat/</guid>
      <description>what am i looking at &amp;amp; compat  0 i was wondering if someone can clear up what these digits are. i can understand the traffic info in portion and i can read the information about send/recieve and addresses in portion but i have no idea what these values indicate:
0000 b8 e6 25 30 57 89 74 e5 43 9f 6d 16 08 06 00 01 ..%0W.t. C.m.....
this line is followed by sequentially numbered lies 0010, 0020 and similar values across the board.</description>
    </item>
    
    <item>
      <title>bytes missing in capture file</title>
      <link>/questions/15146/bytes-missing-in-capture-file/</link>
      <pubDate>Mon, 22 Oct 2012 02:16:00 +0000</pubDate>
      
      <guid>/questions/15146/bytes-missing-in-capture-file/</guid>
      <description>bytes missing in capture file  0 Network guys set up a span port with some traffic to my box. Currently I am observing strange behaviour.
Consequently and repeatedly I see &#34;X bytes missing in capture file&#34;. I have done such scenario: Open an URL in my browser and tap F5 or ctrl-F5. File is opened correctly.
In capture file I see: ET /pc/resources/Ocean/images/logo.gif HTTP/1.1 Host: 10.5.34.230:8080 User-Agent: Mozilla/5.0 (Windows NT 5.</description>
    </item>
    
    <item>
      <title>How to get my protocol statistics in the Protocol Hierarchy Statistics</title>
      <link>/questions/15147/how-to-get-my-protocol-statistics-in-the-protocol-hierarchy-statistics/</link>
      <pubDate>Mon, 22 Oct 2012 02:55:00 +0000</pubDate>
      
      <guid>/questions/15147/how-to-get-my-protocol-statistics-in-the-protocol-hierarchy-statistics/</guid>
      <description>How to get my protocol statistics in the Protocol Hierarchy Statistics  0 After following the steps in the tutorial i expected that the Protocol Hierarchical Statistics would have been extended with the stats details. This is not the case however. Although with tshark i can see that the details are being collected. Is there a way to expand the phs to show the details?
tshark -r /home/kurt/wireshark/foo_test.pcap -z foo,tree -z io,phs OOPS: dissector table &amp;quot;sctp.</description>
    </item>
    
    <item>
      <title>Distributing Wireshark</title>
      <link>/questions/15154/distributing-wireshark/</link>
      <pubDate>Mon, 22 Oct 2012 06:04:00 +0000</pubDate>
      
      <guid>/questions/15154/distributing-wireshark/</guid>
      <description>Distributing Wireshark  0 I have a product that is tied to a new protocol. The release date is a ways away (1-2 years) and development is being done in various places. I intend to contribute everything back to Wireshark, but I was wondering in the meantime what my options are for distributing my version. The development is being done internally, and also with 3rd parties, which is where I have my concern.</description>
    </item>
    
    <item>
      <title>what kind of data store wireshark</title>
      <link>/questions/15157/what-kind-of-data-store-wireshark/</link>
      <pubDate>Mon, 22 Oct 2012 06:48:00 +0000</pubDate>
      
      <guid>/questions/15157/what-kind-of-data-store-wireshark/</guid>
      <description>what kind of data store wireshark  0 I all, sorry for my noob question but i&#39;m in a trouble, someone is running wireshark in the network and I want to know certally what kind of data he can see, I know he can access passwords, but I want to know if he can access documents in the net or some other data, with data collected with wireshark.
What kind of data collect wireshark, Can I reconstruct office, txt, database transacctions, with data collected.</description>
    </item>
    
    <item>
      <title>Win2008R2 64bit WireShark APPCRASH</title>
      <link>/questions/15158/win2008r2-64bit-wireshark-appcrash/</link>
      <pubDate>Mon, 22 Oct 2012 07:16:00 +0000</pubDate>
      
      <guid>/questions/15158/win2008r2-64bit-wireshark-appcrash/</guid>
      <description>Win2008R2 64bit WireShark APPCRASH  0 I cannot get any version of WireShark v1.8.3 (32bit or 64bit) to run on a Win2008R2. The error below occurs when the WireShark is starting, how can I get it to work??? I also tried to go back a version and still it wouldn&#39;t work...
Problem signature: Problem Event Name: APPCRASH Application Name: wireshark.exe Application Version: 1.8.3.45256 Application Timestamp: 506b148f Fault Module Name: StackHash_3184 Fault Module Version: 6.</description>
    </item>
    
    <item>
      <title>SSL decryption works only on the first client request. Remaining packets are not decrypted</title>
      <link>/questions/15160/ssl-decryption-works-only-on-the-first-client-request-remaining-packets-are-not-decrypted/</link>
      <pubDate>Mon, 22 Oct 2012 07:40:00 +0000</pubDate>
      
      <guid>/questions/15160/ssl-decryption-works-only-on-the-first-client-request-remaining-packets-are-not-decrypted/</guid>
      <description>SSL decryption works only on the first client request. Remaining packets are not decrypted  0 Hi all,
I am trying to decrypt an SSL session which is running on my test environment and I am partially successful in that. The problem is that every time to successfully decrypt an SSL capture, I need to restart my browser and the first transaction gets decrypted properly. The subsequent requests from client system were not decrypted as expected.</description>
    </item>
    
    <item>
      <title>Reseting configuration</title>
      <link>/questions/15172/reseting-configuration/</link>
      <pubDate>Mon, 22 Oct 2012 11:26:00 +0000</pubDate>
      
      <guid>/questions/15172/reseting-configuration/</guid>
      <description>Reseting configuration  0 Hi. I have installed Wireshark on a Mac with OS X 10.8. At first run it asked for the X11 app... and I selected by mistake the Automator app. The problem now is that every time I run the Wireshark app it opens X11 (that it finally found without asking again) and the Automator apps (!!!)... I have uninstalled/installed Wireshark many many times with no results... How can I delete all the settings so it will ask again for X11?</description>
    </item>
    
    <item>
      <title>List of servers that send amf packet</title>
      <link>/questions/15183/list-of-servers-that-send-amf-packet/</link>
      <pubDate>Tue, 23 Oct 2012 03:35:00 +0000</pubDate>
      
      <guid>/questions/15183/list-of-servers-that-send-amf-packet/</guid>
      <description>List of servers that send amf packet  0 I have written a dissector for amf packets. I want to capture it using wireshark. Can any one provide me with the list of servers that send amf packets???????
amfasked 23 Oct &#39;12, 03:35
Akhil
53●27●28●31
accept rate: 0%
  
One Answer:
  
0google is your friend:
http://bit.ly/S02oUI
leads to AMF testing made easy, if you mean Action Message Format (AMF).</description>
    </item>
    
    <item>
      <title>Filter a password from a client that use a freemailprovider?</title>
      <link>/questions/15185/filter-a-password-from-a-client-that-use-a-freemailprovider/</link>
      <pubDate>Tue, 23 Oct 2012 04:58:00 +0000</pubDate>
      
      <guid>/questions/15185/filter-a-password-from-a-client-that-use-a-freemailprovider/</guid>
      <description>Filter a password from a client that use a freemailprovider?  0 How can I for example filter a password from I client that is loging on www.hotmail.com? Which filter do I use?
passwordasked 23 Oct &#39;12, 04:58
marsal
1●3●3●5
accept rate: 0%
what do you want to achieve?
(23 Oct &#39;12, 05:37) Kurt Knochner ♦No at the school we got the work,nothing illegal at all. The qestion is if that is possible to see or not (using Wireshark).</description>
    </item>
    
    <item>
      <title>Wireshark core dumped on startup</title>
      <link>/questions/15187/wireshark-core-dumped-on-startup/</link>
      <pubDate>Tue, 23 Oct 2012 05:18:00 +0000</pubDate>
      
      <guid>/questions/15187/wireshark-core-dumped-on-startup/</guid>
      <description>Wireshark core dumped on startup  0 Hi! I have a problem that wireshark crashes on startup. After this problem I tried to uninstall it completely and to delete all files regarding wireshark (after &#34;find / | grep -i wireshark&#34;) and then reinstall it but that did not help. The first step I guess would be to locate the core dump but I cannot find it - where could it be located?</description>
    </item>
    
    <item>
      <title>Lua dissector and &amp;quot;tshark -e data.data&amp;quot;</title>
      <link>/questions/15194/lua-dissector-and-tshark-e-datadata/</link>
      <pubDate>Tue, 23 Oct 2012 06:28:00 +0000</pubDate>
      
      <guid>/questions/15194/lua-dissector-and-tshark-e-datadata/</guid>
      <description>Lua dissector and &amp;ldquo;tshark -e data.data&amp;rdquo;  0 For a private protocol over TCP, I am writing a Lua-based dissector. The dissector is very much in the spirit of the first part of http://wiki.wireshark.org/Lua/Dissectors. Within Wireshark, this dissector works fine, but if I use
tshark -X lua_script:foo.lua ... -e data.data ...to simply dump the whole TCP PDU onto stdout, I don&#39;t get anything. But, of course, if I remove the -X.</description>
    </item>
    
    <item>
      <title>Implementing a basic packet counter and incorrect order detector using dissectors and Lua</title>
      <link>/questions/15196/implementing-a-basic-packet-counter-and-incorrect-order-detector-using-dissectors-and-lua/</link>
      <pubDate>Tue, 23 Oct 2012 08:31:00 +0000</pubDate>
      
      <guid>/questions/15196/implementing-a-basic-packet-counter-and-incorrect-order-detector-using-dissectors-and-lua/</guid>
      <description>Implementing a basic packet counter and incorrect order detector using dissectors and Lua  1 I am trying to implement, using Lua, a dissector which tells me whether the packets sent are arriving or not. To achieve this, on top of UDP I have implemented a custom protocol with a field &#34;ID&#34; which is auto-incremented by one on each packet.
I got the dissector to process the fields, but I am not able to make it read the previous packet ID and report whether the current packet ID is in the expected order.</description>
    </item>
    
    <item>
      <title>Why doesn&amp;#x27;t the Mac OS X 10.6&#43; installer write /Library/Wireshark?</title>
      <link>/questions/15207/why-doesnt-the-mac-os-x-106-installer-write-librarywireshark/</link>
      <pubDate>Tue, 23 Oct 2012 22:53:00 +0000</pubDate>
      
      <guid>/questions/15207/why-doesnt-the-mac-os-x-106-installer-write-librarywireshark/</guid>
      <description>Why doesn&amp;rsquo;t the Mac OS X 10.6+ installer write /Library/Wireshark?  0 From the installer&#39;s README:
The installer writes to the following locations:
...
• /Library/Wireshark. A wrapper script and symbolic links which will let you run Wireshark and its associated utilities from the command line. You can access them directly or by adding /Library/Wireshark to your PATH.
...
How do I uninstall?
2. Remove /Library/Wireshark
I&#39;m on Mac OS X 10.</description>
    </item>
    
    <item>
      <title>How do I use wxLua from Wireshark in Windows?</title>
      <link>/questions/15215/how-do-i-use-wxlua-from-wireshark-in-windows/</link>
      <pubDate>Wed, 24 Oct 2012 02:33:00 +0000</pubDate>
      
      <guid>/questions/15215/how-do-i-use-wxlua-from-wireshark-in-windows/</guid>
      <description>How do I use wxLua from Wireshark in Windows?  0 Could you please provide some detailed instruction on &#34;This is where you would do any fancy GUI stuff with Wireshark&#39;s GUI calls or with, e.g., wxWidgets (via wxLua) or Qt (via lqt).&#34;? How do I use wxLua for example? I tried to copy wx.dll from wxLua installer to the Program Files\Wireshark library, but Wireshark crashed as soon as I tried to evaluate &#39;require &#34;</description>
    </item>
    
    <item>
      <title>Packet loss and Jitter in a Skype communication</title>
      <link>/questions/15221/packet-loss-and-jitter-in-a-skype-communication/</link>
      <pubDate>Wed, 24 Oct 2012 04:47:00 +0000</pubDate>
      
      <guid>/questions/15221/packet-loss-and-jitter-in-a-skype-communication/</guid>
      <description>Packet loss and Jitter in a Skype communication  0 Hi, I captured the traffic during a skype conversation in the two end points. Then I have decoded the UDP&#39;s packets with an RTP protocol, in this way i&#39;m able to see the timestamps of each packet. But, when I go to the option Telephony--&amp;gt;RTP--&amp;gt;show all the streams.., in the fields : loss packets and jitter appears always a 0, and I don&#39;t know why.</description>
    </item>
    
    <item>
      <title>tshark: tcp.data cannot always output data</title>
      <link>/questions/15235/tshark-tcpdata-cannot-always-output-data/</link>
      <pubDate>Wed, 24 Oct 2012 18:56:00 +0000</pubDate>
      
      <guid>/questions/15235/tshark-tcpdata-cannot-always-output-data/</guid>
      <description>tshark: tcp.data cannot always output data  0 I captured 802.11 trace with both MAC and network layer data.
I use tshark to output the packet detail data
tshark -T fields -e frame.number -e wlan.sa -e wlan.da -e tcp.data
But, for some packets, the tcp.data can output the data content, but not all of them. I cannot figure it out.
I can use wireshark to browse the trace and check the data with no problem at all.</description>
    </item>
    
    <item>
      <title>How to disable tmp file in wireshark</title>
      <link>/questions/15243/how-to-disable-tmp-file-in-wireshark/</link>
      <pubDate>Thu, 25 Oct 2012 01:35:00 +0000</pubDate>
      
      <guid>/questions/15243/how-to-disable-tmp-file-in-wireshark/</guid>
      <description>How to disable tmp file in wireshark  0 When starting a capture, all packets arrive in memory, but also in a temp file. The write speed to disk is probably a limiting factor on how fast wireshark can collect the data. I loose packets as soon as traffic exceeds 400Mbps on a 10 gigabit/s network card. I have a Xeon processor at 2.8Ghz and 4GByte RAM at 1066Mhz, so I don&#39;t think the writing to RAM is the limiting factor.</description>
    </item>
    
    <item>
      <title>Auto-save by using consol</title>
      <link>/questions/15247/auto-save-by-using-consol/</link>
      <pubDate>Thu, 25 Oct 2012 05:54:00 +0000</pubDate>
      
      <guid>/questions/15247/auto-save-by-using-consol/</guid>
      <description>Auto-save by using consol  0 Hi, I&#39;m Seok-jae Yun from Korea.
I have a question about using command line(in DOS)
I want to sort data filtering with 40000 UDP port.
So, I input &#34;wireshark.exe A201205130000.dat -R udp.port==40000 -w please.snoop&#34;
but, the Wireshark only filter data, but didn&#39;t save as &#34;please.snooop&#34;
how can I filter data and save it?
Thank you. Seok-jae, Yun
console line commandasked 25 Oct &#39;12, 05:54</description>
    </item>
    
    <item>
      <title>Why the tcp.flags.ack=1,but no data received!</title>
      <link>/questions/15283/why-the-tcpflagsack1but-no-data-received/</link>
      <pubDate>Thu, 25 Oct 2012 18:10:00 +0000</pubDate>
      
      <guid>/questions/15283/why-the-tcpflagsack1but-no-data-received/</guid>
      <description>Why the tcp.flags.ack=1,but no data received!  0 i captured many tcp packets,why the server mark the tcp.flags.ack=1,but not received any packets from client?
ackasked 25 Oct &#39;12, 18:10
chinasan
0●6●6●8
accept rate: 0%
  
One Answer:
  
3Not sure if I get the question right, but I guess you wonder why the ACK flag would be set even though the client sent no data in its packets?</description>
    </item>
    
    <item>
      <title>does have libwireshark static library(libwireshark.a) on linux ?</title>
      <link>/questions/15285/does-have-libwireshark-static-librarylibwiresharka-on-linux/</link>
      <pubDate>Thu, 25 Oct 2012 18:53:00 +0000</pubDate>
      
      <guid>/questions/15285/does-have-libwireshark-static-librarylibwiresharka-on-linux/</guid>
      <description>does have libwireshark static library(libwireshark.a) on linux ?  0 I compiled wireshark on linux successfully, but not found libwireshark static library(libwireshark.a) ,only found libwireshark.so libwireshark_generated.a libwireshark_asmopt.a.
secondary development wireshark on linux, there are errors as follows(why?):
 undefined symbol: proto_item_fill_label (./scandissectpkt.so) undefined symbol: g_sprintf (./scandissectpkt.so) undefined symbol: g_assertion_message_expr (./scandissectpkt.so) undefined symbol: register_all_protocol_handoffs (./scandissectpkt.so) undefined symbol: register_all_protocols (./scandissectpkt.so) undefined symbol: epan_init (./scandissectpkt.so) undefined symbol: epan_dissect_init (./scandissectpkt.so) undefined symbol: frame_data_set_before_dissect (./scandissectpkt.so) undefined symbol: epan_dissect_run (.</description>
    </item>
    
    <item>
      <title>Does Wireshark uses a pseudo-header for VRRPv3 IPv4 checksum calculation?</title>
      <link>/questions/15291/does-wireshark-uses-a-pseudo-header-for-vrrpv3-ipv4-checksum-calculation/</link>
      <pubDate>Fri, 26 Oct 2012 03:44:00 +0000</pubDate>
      
      <guid>/questions/15291/does-wireshark-uses-a-pseudo-header-for-vrrpv3-ipv4-checksum-calculation/</guid>
      <description>Does Wireshark uses a pseudo-header for VRRPv3 IPv4 checksum calculation?  0 According to draft-ietf-vrrp-ipv6-spec-08 (VRRPv3) IPv4 is defined in RFC3768 (VRRPv2).
&#34;This protocol is intended for use with IPv6 routers only. VRRP for IPv4 is defined in VRRP-V4.&#34; , sentence from draft-ietf-vrrp-ipv6-spec-08, section 1.1 - Scope
It appears that Wireshark uses the pseudo-header in the checksum calculation for IPv4 and for IPv6. For me the pseudo-header should be used for IPv6 as defined in the draft but should not be used in IPv4 since it doesn&#39;t appear in the checksum calculation defined in the section 5.</description>
    </item>
    
    <item>
      <title>Is there any  C libray for amf compatible with wireshark ?????</title>
      <link>/questions/15292/is-there-any-c-libray-for-amf-compatible-with-wireshark/</link>
      <pubDate>Fri, 26 Oct 2012 04:00:00 +0000</pubDate>
      
      <guid>/questions/15292/is-there-any-c-libray-for-amf-compatible-with-wireshark/</guid>
      <description>Is there any C libray for amf compatible with wireshark ?????  0 I want a c library for deserializing amf0 and amf3 packet. I have gone through libamfx, as it is in cpp its hard to understand. Is there any other library compatible with wireshark??????
library amfasked 26 Oct &#39;12, 04:00
Akhil
53●27●28●31
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How to filter out MAC addresses with tcpdump</title>
      <link>/questions/15293/how-to-filter-out-mac-addresses-with-tcpdump/</link>
      <pubDate>Fri, 26 Oct 2012 05:14:00 +0000</pubDate>
      
      <guid>/questions/15293/how-to-filter-out-mac-addresses-with-tcpdump/</guid>
      <description>How to filter out MAC addresses with tcpdump  0 Hi all.
I am running tcpdump on DD-WRT routers in order to capture uplink data from mobile phones. I would like to listen only to some mac addresses. To do this I tried to run the command using a syntax similar to Wireshark:
tcpdump -i prism0 ether src[0:3] 5c:95:ae -s0 -w | nc 192.168.1.147 31337
so that I can listen to all the devices that have as initial mac address 5c:95:ae.</description>
    </item>
    
    <item>
      <title>pcap to au-file in command line</title>
      <link>/questions/15294/pcap-to-au-file-in-command-line/</link>
      <pubDate>Fri, 26 Oct 2012 06:32:00 +0000</pubDate>
      
      <guid>/questions/15294/pcap-to-au-file-in-command-line/</guid>
      <description>pcap to au-file in command line  0 i wondering to know is there any way to convert a pcap file containing RTP packets to au-file in command line? I know i can do it with wireshark GUI but i m trying to write a script in python so i think i need to do that through command line.
audio scriptasked 26 Oct &#39;12, 06:32
reza
1●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>display filter for hostname version 1.8.3</title>
      <link>/questions/15295/display-filter-for-hostname-version-183/</link>
      <pubDate>Fri, 26 Oct 2012 09:41:00 +0000</pubDate>
      
      <guid>/questions/15295/display-filter-for-hostname-version-183/</guid>
      <description>display filter for hostname version 1.8.3  0 I am at a loss. I am trying to do the following as either a capture filter or a display filter and neither works:
host pjsip.lab
According to everything I have read it looks right, but it won&#39;t apply.
Any help would be great.
Robert
filter host hostnameasked 26 Oct &#39;12, 09:41
Robert11314
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark on Wifi</title>
      <link>/questions/15296/wireshark-on-wifi/</link>
      <pubDate>Fri, 26 Oct 2012 10:08:00 +0000</pubDate>
      
      <guid>/questions/15296/wireshark-on-wifi/</guid>
      <description>Wireshark on Wifi  0 Hello, I am no guru when it comes to sniifers so I need some guidance. I want to run a sniffer (Wireshak) on my PC (LAN Ethernet) or laptop (Wifi 802.11b/g) to capture/sniff all data on my home network. I have D-Link WRT110 router with WPA2, with some laptops and smartphones connected to it. I want to check what my kids are doing, the web sites they visit, the chat rooms and even reading the chat history (like Whatsapp on smartphones).</description>
    </item>
    
    <item>
      <title>Qualcomm Killer Wireless N 1103 interface for wireshark</title>
      <link>/questions/15297/qualcomm-killer-wireless-n-1103-interface-for-wireshark/</link>
      <pubDate>Fri, 26 Oct 2012 10:51:00 +0000</pubDate>
      
      <guid>/questions/15297/qualcomm-killer-wireless-n-1103-interface-for-wireshark/</guid>
      <description>Qualcomm Killer Wireless N 1103 interface for wireshark  0 Hey, do you have a &#34;How to&#34; to code an interface for a network card.
Qualcomm Killer Wireless N 1103 isn&#39;t supported and i want to get it work.
Thx Mojita
networkinterfacesasked 26 Oct &#39;12, 10:51
mojita
1●1●1●1
accept rate: 0%
 edited 27 Oct &#39;12, 13:40 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:</description>
    </item>
    
    <item>
      <title>Retransmit issue</title>
      <link>/questions/15305/retransmit-issue/</link>
      <pubDate>Fri, 26 Oct 2012 23:05:00 +0000</pubDate>
      
      <guid>/questions/15305/retransmit-issue/</guid>
      <description>Retransmit issue  0 HI,
My server send packet to 202.162 but the packet retransmit again..Kindly advice... Is my server fault ? Thanks in advance..
retransmissionasked 26 Oct &#39;12, 23:05
suarez123
1●9●9●11
accept rate: 0%
 edited 27 Oct &#39;12, 05:30 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
4Looks like the server is unwilling to respond after the initial three way handshake, or the packets do not make it through at all.</description>
    </item>
    
    <item>
      <title>RTP Wrong Timestamps reports in clean capture</title>
      <link>/questions/15314/rtp-wrong-timestamps-reports-in-clean-capture/</link>
      <pubDate>Sat, 27 Oct 2012 07:15:00 +0000</pubDate>
      
      <guid>/questions/15314/rtp-wrong-timestamps-reports-in-clean-capture/</guid>
      <description>RTP Wrong Timestamps reports in clean capture  0 I have an RTP capture using G711 codec, with all sequence numbers increasing steadily by 1 for each packet, and all timestamps increasing steadily by 160 for each packet. When using the RTP Stream Analysis, Decode, Wireshark reports a number of Wrong Timestamps.
Can someone suggest what could cause this behavior?
decode_rtp wrong_timestampsasked 27 Oct &#39;12, 07:15
trevron
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to distinguish between IS-683 and IS-637 over Ansi sms-BearerData</title>
      <link>/questions/15319/how-to-distinguish-between-is-683-and-is-637-over-ansi-sms-bearerdata/</link>
      <pubDate>Sun, 28 Oct 2012 02:22:00 +0000</pubDate>
      
      <guid>/questions/15319/how-to-distinguish-between-is-683-and-is-637-over-ansi-sms-bearerdata/</guid>
      <description>How to distinguish between IS-683 and IS-637 over Ansi sms-BearerData  0 How to distinguish between IS-683 and IS-637 over Ansi sms-BearerData
is-683asked 28 Oct &#39;12, 02:22
Emi
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Calculate throughput using WireShark and compare to theoretical bandwidth</title>
      <link>/questions/15320/calculate-throughput-using-wireshark-and-compare-to-theoretical-bandwidth/</link>
      <pubDate>Sun, 28 Oct 2012 06:13:00 +0000</pubDate>
      
      <guid>/questions/15320/calculate-throughput-using-wireshark-and-compare-to-theoretical-bandwidth/</guid>
      <description>Calculate throughput using WireShark and compare to theoretical bandwidth  0 hi, I would like to know how to solve this problem using wireshark. Problem Download big file and calculate throughput, compare to theoretical bandwidth - Theoretical: Transmission time (in seconds) = Size of file (in bits) / Bandwidth (in bits/second) and Throughput: Throughput (in bits) = Size of file (in bits) / Transmission time (in seconds).
using throughput wiresharkasked 28 Oct &#39;12, 06:13</description>
    </item>
    
    <item>
      <title>Ignoring the first X bytes of a packet</title>
      <link>/questions/15337/ignoring-the-first-x-bytes-of-a-packet/</link>
      <pubDate>Mon, 29 Oct 2012 07:27:00 +0000</pubDate>
      
      <guid>/questions/15337/ignoring-the-first-x-bytes-of-a-packet/</guid>
      <description>Ignoring the first X bytes of a packet  2 1Hello, community. I&#39;m capturing packets where the first X bytes (a special header) are not covered by any dissector available. Therefore, the rest of the package is not dissected anymore. Is it possible to instruct Wireshark to ignore the first X bytes and proceed further? Or is the only feasible option to write an own dissector for the first part of the package - the first X bytes?</description>
    </item>
    
    <item>
      <title>IKE decryption with fragmented messages</title>
      <link>/questions/15339/ike-decryption-with-fragmented-messages/</link>
      <pubDate>Mon, 29 Oct 2012 09:58:00 +0000</pubDate>
      
      <guid>/questions/15339/ike-decryption-with-fragmented-messages/</guid>
      <description>IKE decryption with fragmented messages  0 Hi,
this Wireshark has a problem decrypting IKE messages when message 5 and 6 are fragmented and reassembled in Wireshark? I used the described method numerous times with OpenSwan and it worked like a charm. Then I changed to certificate based authentication and the payload exceeded the 1500 byte packet size. Although I enter ICOOKIE and enc_key as the times before, I still see only encrypted data.</description>
    </item>
    
    <item>
      <title>No TCP traffic captured?  Diagnosing?</title>
      <link>/questions/15340/no-tcp-traffic-captured-diagnosing/</link>
      <pubDate>Mon, 29 Oct 2012 11:39:00 +0000</pubDate>
      
      <guid>/questions/15340/no-tcp-traffic-captured-diagnosing/</guid>
      <description>No TCP traffic captured? Diagnosing?  0 All I want to do is capture an ftp transaction on a private system. Strictly debug. I have a very straightforward setup:
laptop -&amp;gt; laptop&#39;s ethernet -&amp;gt; hub device running ftp client -&amp;gt; same hub device running the ftp server -&amp;gt; same hub.
My laptop is a Dell XPS1530 running Windows 7 64bit, Wireshark 1.8.2. I&#39;m using the built in ethernet port as well as another usb to ethernet adaptor (connected to another network).</description>
    </item>
    
    <item>
      <title>Compiling with gnutls</title>
      <link>/questions/15341/compiling-with-gnutls/</link>
      <pubDate>Mon, 29 Oct 2012 11:46:00 +0000</pubDate>
      
      <guid>/questions/15341/compiling-with-gnutls/</guid>
      <description>Compiling with gnutls  0 Can Wireshark be compiled with libgnutls version greater than 3? I&#39;m trying to compile on OpenSuSE 12.1, which has libgnutls 3.0.3 and am getting errors when I run configure. If it can be compiled with libgnutls version greater than 3, how can I force configure to accept the version?
libgnutlsasked 29 Oct &#39;12, 11:46
swadlow
6●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Is there any document for amf deserialization other than the amf specification????</title>
      <link>/questions/15347/is-there-any-document-for-amf-deserialization-other-than-the-amf-specification/</link>
      <pubDate>Mon, 29 Oct 2012 20:52:00 +0000</pubDate>
      
      <guid>/questions/15347/is-there-any-document-for-amf-deserialization-other-than-the-amf-specification/</guid>
      <description>Is there any document for amf deserialization other than the amf specification????  0 I am writing a plugin for AMF. I have gone through AMF specification but its not at all helpful to write deserialization code. Is there any other document which contains detailed explanation for deserialization??????
amfasked 29 Oct &#39;12, 20:52
Akhil
53●27●28●31
accept rate: 0% 
  
One Answer:
  
0 The best place to learn about that is Adobes open source implementation: BlazeDS</description>
    </item>
    
    <item>
      <title>Is pyamf library compatible with wireshark????</title>
      <link>/questions/15351/is-pyamf-library-compatible-with-wireshark/</link>
      <pubDate>Tue, 30 Oct 2012 02:17:00 +0000</pubDate>
      
      <guid>/questions/15351/is-pyamf-library-compatible-with-wireshark/</guid>
      <description>Is pyamf library compatible with wireshark????  0 I am writing a dissector for amf. Is Is pyamf library compatible with wireshark????. If yes how should i call it ic my code??
amfasked 30 Oct &#39;12, 02:17
Akhil
53●27●28●31
accept rate: 0%
  
One Answer:
  
0pyamf is a python library, so there is no way to use it &#39;out of the box&#39; in a Wireshark dissector.</description>
    </item>
    
    <item>
      <title>How to capture 802.11ac packets with wireshark?</title>
      <link>/questions/15368/how-to-capture-80211ac-packets-with-wireshark/</link>
      <pubDate>Tue, 30 Oct 2012 07:17:00 +0000</pubDate>
      
      <guid>/questions/15368/how-to-capture-80211ac-packets-with-wireshark/</guid>
      <description>How to capture 802.11ac packets with wireshark?  0 Hi! I am new to wireshark and I am curently trying to figure out if there is any modification that needs to be done to the source code in order to capture and analyze 802.11ac packets. I found something on the internet about some VHT radiotaps that need to be added. Also, I suppose I need a capture card in order to be able to use wireshark on 802.</description>
    </item>
    
    <item>
      <title>what http version is my browser running?</title>
      <link>/questions/15372/what-http-version-is-my-browser-running/</link>
      <pubDate>Tue, 30 Oct 2012 09:08:00 +0000</pubDate>
      
      <guid>/questions/15372/what-http-version-is-my-browser-running/</guid>
      <description>what http version is my browser running?  0 I&#39;m a beginner to learning wireshark, so please go easy on me. How can I find out if my browser is running HTTP version 1.0 or 1.1? Also, how can I find out what version of HTTP the server running?
Is there a specific part of wireshark which displays this information every time?
Thanks
version http serverasked 30 Oct &#39;12, 09:08</description>
    </item>
    
    <item>
      <title>Dump raw packet &amp;#x27;data&amp;#x27; field only?</title>
      <link>/questions/15374/dump-raw-packet-data-field-only/</link>
      <pubDate>Tue, 30 Oct 2012 09:19:00 +0000</pubDate>
      
      <guid>/questions/15374/dump-raw-packet-data-field-only/</guid>
      <description>Dump raw packet &amp;lsquo;data&amp;rsquo; field only?  0 Here&#39;s the problem:
I have some network traffic pcap files. I need the raw data layer packets from these files, which I can get (in one file) by right-clicking the &#39;data&#39; layer, and &#39;Export selected packet bytes...&#39;, but I then have to combine these raw files for all packets in the capture.
I can print just the data, in ASCII format, using tshark:</description>
    </item>
    
    <item>
      <title>Capturing VLAN Tags with Intel Pro/1000 CT NIC Card</title>
      <link>/questions/15391/capturing-vlan-tags-with-intel-pro1000-ct-nic-card/</link>
      <pubDate>Tue, 30 Oct 2012 12:06:00 +0000</pubDate>
      
      <guid>/questions/15391/capturing-vlan-tags-with-intel-pro1000-ct-nic-card/</guid>
      <description>Capturing VLAN Tags with Intel Pro/1000 CT NIC Card  0 Hi,
I am running CentOS 6.2 using the default e1000 driver for my Intel Pro/1000 CT Gb NIC card.
I am running Dumpcap to capture packets from this interface.
I am seeing NO packets being captured.
I looked at this site: http://wiki.wireshark.org/CaptureSetup/VLAN
I was unable to determine a resolution for issue.
Any guidance or assistance will be greatly appreciated.</description>
    </item>
    
    <item>
      <title>How can I deploy Wireshark silently/unattended using Group Policy?</title>
      <link>/questions/15414/how-can-i-deploy-wireshark-silentlyunattended-using-group-policy/</link>
      <pubDate>Wed, 31 Oct 2012 03:28:00 +0000</pubDate>
      
      <guid>/questions/15414/how-can-i-deploy-wireshark-silentlyunattended-using-group-policy/</guid>
      <description>How can I deploy Wireshark silently/unattended using Group Policy?  0 I would like to deploy Wireshark to multiple desktops/laptops using Group Policy but need the installer to be in msi format to do this. Could you please advise how I can extract the msi from the Wireshark exe and the commands/properties I should use in order to install it silently/unattended?
policy unattended group silent msiasked 31 Oct &#39;12, 03:28</description>
    </item>
    
    <item>
      <title>how to use wireshark to bypass the wifi with default login page?</title>
      <link>/questions/15416/how-to-use-wireshark-to-bypass-the-wifi-with-default-login-page/</link>
      <pubDate>Wed, 31 Oct 2012 03:37:00 +0000</pubDate>
      
      <guid>/questions/15416/how-to-use-wireshark-to-bypass-the-wifi-with-default-login-page/</guid>
      <description>how to use wireshark to bypass the wifi with default login page?  -1 i can connect to public wifi here with no password but theres a login page wherever i go to browse the net. u need an account but i have no account as it is expensive. how can i use wireshark to this?
login pageasked 31 Oct &#39;12, 03:37
FierceX
0●1●1●1
accept rate: 0%
are you really asking us to help you cheating your provider by telling you how to steal wifi accounts?</description>
    </item>
    
    <item>
      <title>Every Packet has 802.11 Protocol</title>
      <link>/questions/15421/every-packet-has-80211-protocol/</link>
      <pubDate>Wed, 31 Oct 2012 08:27:00 +0000</pubDate>
      
      <guid>/questions/15421/every-packet-has-80211-protocol/</guid>
      <description>Every Packet has 802.11 Protocol  0 I&#39;m using Wireshark on Backtrack and have a Broadcom 4322 Wifi Card running in monitor mode (airmon-ng). When I&#39;m capturing the data of an open network, all packets seem to have the same protocol: 802.11. Also, I can&#39;t read any data in this packets. I guess that these packets actually belong to another protocol (http, tcp,...), has anybody an idea how i can get to that data?</description>
    </item>
    
    <item>
      <title>Embedded image serial or parallel?</title>
      <link>/questions/15436/embedded-image-serial-or-parallel/</link>
      <pubDate>Wed, 31 Oct 2012 15:47:00 +0000</pubDate>
      
      <guid>/questions/15436/embedded-image-serial-or-parallel/</guid>
      <description>Embedded image serial or parallel?  0 here is a test site i&#39;m using to learn wireshark: bitly.com/qPLPXp
I was asked whether my web browser downloads the images download in serial, or in parallel?
first image is hosted by that website itself &amp;amp; the second image is on another server.
how can I tell if they were downloaded in serial or parallel?
Thank you
serial parallelasked 31 Oct &#39;12, 15:47</description>
    </item>
    
    <item>
      <title>how to tell which &amp;quot;interface&amp;quot; is associated with which computer?</title>
      <link>/questions/15437/how-to-tell-which-interface-is-associated-with-which-computer/</link>
      <pubDate>Wed, 31 Oct 2012 18:12:00 +0000</pubDate>
      
      <guid>/questions/15437/how-to-tell-which-interface-is-associated-with-which-computer/</guid>
      <description>how to tell which &amp;ldquo;interface&amp;rdquo; is associated with which computer?  0 how to tell which &#34;interface&#34; is associated with which computer?
interfaceasked 31 Oct &#39;12, 18:12
wiresharkhel...
30●9●9●13
accept rate: 0%
what do you mean by an &#34;interface&#34;?
(01 Nov &#39;12, 02:28) Kurt Knochner ♦   </description>
    </item>
    
    <item>
      <title>how to tell which computers are connected to the network if the computer is hidden via &amp;quot;file and printer sharing for ms networks&amp;quot; under properties under network connections</title>
      <link>/questions/15438/how-to-tell-which-computers-are-connected-to-the-network-if-the-computer-is-hidden-via-file-and-printer-sharing-for-ms-networks-under-properties-under-network-connections/</link>
      <pubDate>Wed, 31 Oct 2012 18:14:00 +0000</pubDate>
      
      <guid>/questions/15438/how-to-tell-which-computers-are-connected-to-the-network-if-the-computer-is-hidden-via-file-and-printer-sharing-for-ms-networks-under-properties-under-network-connections/</guid>
      <description>how to tell which computers are connected to the network if the computer is hidden via &amp;ldquo;file and printer sharing for ms networks&amp;rdquo; under properties under network connections  0 how to tell which computers are connected to the network if the computer is hidden via &#34;file and printer sharing for ms networks&#34; under properties under network connections
networkasked 31 Oct &#39;12, 18:14
wiresharkhel...
30●9●9●13
accept rate: 0%</description>
    </item>
    
    <item>
      <title>how to filter by webpages visited -- the capture log has green, red, and other coded lines</title>
      <link>/questions/15440/how-to-filter-by-webpages-visited-the-capture-log-has-green-red-and-other-coded-lines/</link>
      <pubDate>Wed, 31 Oct 2012 18:18:00 +0000</pubDate>
      
      <guid>/questions/15440/how-to-filter-by-webpages-visited-the-capture-log-has-green-red-and-other-coded-lines/</guid>
      <description>how to filter by webpages visited &amp;ndash; the capture log has green, red, and other coded lines  0 how to filter by webpages visited -- the capture log has green, red, and other coded lines
capture-filterasked 31 Oct &#39;12, 18:18
wiresharkhel...
30●9●9●13
accept rate: 0%
  
One Answer:
  
0You can use this display filter:
http.request.full_uri contains &#34;xxxxxx&#34;
Replace the xxxx with the websites or pages you are looking for.</description>
    </item>
    
    <item>
      <title>[closed] How to collect packets into flows based on 5-tuples offline</title>
      <link>/questions/15441/how-to-collect-packets-into-flows-based-on-5-tuples-offline/</link>
      <pubDate>Wed, 31 Oct 2012 20:16:00 +0000</pubDate>
      
      <guid>/questions/15441/how-to-collect-packets-into-flows-based-on-5-tuples-offline/</guid>
      <description>[closed] How to collect packets into flows based on 5-tuples offline  0 Hi I have some pcap files I need to puts these files in flows base instead of packets base by using 5-tuple (Src port, dst port,src ip, dst ip, protocol). is there any C code can do that, and calculate the statistical features such as mean interarrival time for the flow great thank
wiresharkasked 31 Oct &#39;12, 20:16</description>
    </item>
    
    <item>
      <title>How to puts packets into flows based on 5-tuples offline</title>
      <link>/questions/15442/how-to-puts-packets-into-flows-based-on-5-tuples-offline/</link>
      <pubDate>Wed, 31 Oct 2012 20:17:00 +0000</pubDate>
      
      <guid>/questions/15442/how-to-puts-packets-into-flows-based-on-5-tuples-offline/</guid>
      <description>How to puts packets into flows based on 5-tuples offline  0 Hi I have some pcap files I need to puts these files in flows base instead of packets base by using 5-tuple (Src port, dst port,src ip, dst ip, protocol). is there any C code can do that, and calculate the statistical features such as mean interarrival time for the flow great thank
statisticsasked 31 Oct &#39;12, 20:17</description>
    </item>
    
    <item>
      <title>Wireshark is not capturing amf messages generated by Blazer(AMF message generator)</title>
      <link>/questions/15443/wireshark-is-not-capturing-amf-messages-generated-by-blazeramf-message-generator/</link>
      <pubDate>Wed, 31 Oct 2012 23:39:00 +0000</pubDate>
      
      <guid>/questions/15443/wireshark-is-not-capturing-amf-messages-generated-by-blazeramf-message-generator/</guid>
      <description>Wireshark is not capturing amf messages generated by Blazer(AMF message generator)  0 I have written a plugin for amf and its dissects amf traffic from tv.adobe.com successfully.
But it doesn&#39;t dissects the amf messages generated by Blazer(AMF message generator).
I don&#39;t know whether wireshark is able to capture those message ???????
amfasked 31 Oct &#39;12, 23:39
Akhil
53●27●28●31
accept rate: 0%
 wikified 01 Nov &#39;12, 21:09</description>
    </item>
    
    <item>
      <title>Different results for the same communication (RTP)</title>
      <link>/questions/15445/different-results-for-the-same-communication-rtp/</link>
      <pubDate>Thu, 01 Nov 2012 01:36:00 +0000</pubDate>
      
      <guid>/questions/15445/different-results-for-the-same-communication-rtp/</guid>
      <description>Different results for the same communication (RTP)  0 Hi! I was capturing a RTP communication between two PC, where in each of one the wireshark was sniffing. Finally when the communication finished I stopped the wireshark and then I went to Telephony--&amp;gt;RTP--&amp;gt;Show All Stream, and the values that had each computer in both ways, were different in each computer. Why this happens if they were capturing the same communication? why one computer show me that there are more jitter than the other one?</description>
    </item>
    
    <item>
      <title>How to capture &amp;amp; analyze network traffic for jdbc mssql &amp;quot;connection recv failed&amp;quot; error</title>
      <link>/questions/15462/how-to-capture-analyze-network-traffic-for-jdbc-mssql-connection-recv-failed-error/</link>
      <pubDate>Thu, 01 Nov 2012 05:54:00 +0000</pubDate>
      
      <guid>/questions/15462/how-to-capture-analyze-network-traffic-for-jdbc-mssql-connection-recv-failed-error/</guid>
      <description>How to capture &amp;amp; analyze network traffic for jdbc mssql &amp;ldquo;connection recv failed&amp;rdquo; error  0 One of our customers has intermittent database connection problems. The error logs periodically show messages like this:
 A database error occurred. : Software caused connection abort: recv failedat which point someone must restart the application. (Connection pooling doesn&#39;t recover from the error)
This post describes a problem; one of the answers points to wireshark.</description>
    </item>
    
    <item>
      <title>Seeing TCP http [RST, ACK]</title>
      <link>/questions/15463/seeing-tcp-http-rst-ack/</link>
      <pubDate>Thu, 01 Nov 2012 06:27:00 +0000</pubDate>
      
      <guid>/questions/15463/seeing-tcp-http-rst-ack/</guid>
      <description>Seeing TCP http [RST, ACK]  1 I am analyzing throughput on a network and am running an HTTP GET file of 400MB from one of our servers. The TCP connection appears to get set up correctly, but part way through, I am seeing a RST,ACK followed by &#39;Continuation or non-HTTP traffic&#39; entries. These continuation packets just end after a bunch of them with no ACKS from the other end and no apparent termination of the TCP connection following the continuation packets.</description>
    </item>
    
    <item>
      <title>Wireless HTTP GET/POST not seen in 802.11g mode ?</title>
      <link>/questions/15468/wireless-http-getpost-not-seen-in-80211g-mode/</link>
      <pubDate>Thu, 01 Nov 2012 07:49:00 +0000</pubDate>
      
      <guid>/questions/15468/wireless-http-getpost-not-seen-in-80211g-mode/</guid>
      <description>Wireless HTTP GET/POST not seen in 802.11g mode ?  0 Hi
I am using Wireshark to sniff a wireless trafic with open authentification and I have a problem with viewing the GET/POST with 802.11g ? but when using 802.11b I can show them !
I use BTR 5 R3 ALF AWUS036H
any help ? thank you !
wireless 802.11 post http getasked 01 Nov &#39;12, 07:49
Noury
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Persistently Capturing VLAN Tags with Intel Pro/1000 CT NIC Card under CentOS 6.3</title>
      <link>/questions/15476/persistently-capturing-vlan-tags-with-intel-pro1000-ct-nic-card-under-centos-63/</link>
      <pubDate>Thu, 01 Nov 2012 12:11:00 +0000</pubDate>
      
      <guid>/questions/15476/persistently-capturing-vlan-tags-with-intel-pro1000-ct-nic-card-under-centos-63/</guid>
      <description>Persistently Capturing VLAN Tags with Intel Pro/1000 CT NIC Card under CentOS 6.3  0 I am in need to capture packets that contain VLAN tags on my Intel Pro/1000 CT NIC Card.
When I try to capture packets using the command: tcpdump -ni eth2 vlan
I do NOT capture any packets.
I then issue the command: ifconfig eth2 mtu 1522
I then try to capture packets using the command: tcpdump -ni eth2 vlan</description>
    </item>
    
    <item>
      <title>How do I check whether my switches are supplying all the RFC-defined IPFIX information</title>
      <link>/questions/15477/how-do-i-check-whether-my-switches-are-supplying-all-the-rfc-defined-ipfix-information/</link>
      <pubDate>Thu, 01 Nov 2012 12:18:00 +0000</pubDate>
      
      <guid>/questions/15477/how-do-i-check-whether-my-switches-are-supplying-all-the-rfc-defined-ipfix-information/</guid>
      <description>How do I check whether my switches are supplying all the RFC-defined IPFIX information  0 Okay, so to fine-tune my add-on &#34;me too&#34; reply, I&#39;m not looking for a &#34;Follow ___ stream&#34; capability, so much as being able to decipher the IETF IPFIX implementation. In my situation today, I&#39;m needing to detect whether my Nortel Ethernet switches are, in fact, providing info for all the rfc-defined/formatted fields.
ipfixasked 01 Nov &#39;12, 12:18</description>
    </item>
    
    <item>
      <title>how to capture IPP protocol on a specific printer</title>
      <link>/questions/15478/how-to-capture-ipp-protocol-on-a-specific-printer/</link>
      <pubDate>Thu, 01 Nov 2012 12:32:00 +0000</pubDate>
      
      <guid>/questions/15478/how-to-capture-ipp-protocol-on-a-specific-printer/</guid>
      <description>how to capture IPP protocol on a specific printer  0 Hi all, new to wireshark. Looking to see if its possible to capture IPP packets to a specific printer, we have an app that needs to connect to te printer via IPP. The printer supports IPP and i can connect a laptop running wireshark to the same hub as the source app and were the printer is, just need a bit of help as to how to set this up Thanks</description>
    </item>
    
    <item>
      <title>How stop the dissection when tvb buffer ends  ?????</title>
      <link>/questions/15483/how-stop-the-dissection-when-tvb-buffer-ends/</link>
      <pubDate>Thu, 01 Nov 2012 22:49:00 +0000</pubDate>
      
      <guid>/questions/15483/how-stop-the-dissection-when-tvb-buffer-ends/</guid>
      <description>How stop the dissection when tvb buffer ends ?????  0 I want to stop the dissection of the packet when tvb buffer ends.
Is there any API for stop the dissection of that packet??????
tvbuff_tasked 01 Nov &#39;12, 22:49
Akhil
53●27●28●31
accept rate: 0%
What do you mean? The &#34;normal&#34; thing is that the dissector keeps track of how many bytes that should be dissected either from length information in the protocol or by checking the (reported) length of the tvb.</description>
    </item>
    
    <item>
      <title>iax protocol</title>
      <link>/questions/15484/iax-protocol/</link>
      <pubDate>Fri, 02 Nov 2012 00:45:00 +0000</pubDate>
      
      <guid>/questions/15484/iax-protocol/</guid>
      <description>iax protocol  0 wireshark doesn&#39;t capture iax protocol. asterisk version is 1.8.4.2
iaxasked 02 Nov &#39;12, 00:45
kleinehexe
1●1●1●1
accept rate: 0% 
  
One Answer:
  
0If the packets isn&#39;t captured there is something wrong with your capture setup, if the packets captured isn&#39;t recognised as IAX it might be due to preference settings such as configuring the ports used or you may have to use &#34;</description>
    </item>
    
    <item>
      <title>Capturing Omron FINS protocol: only responses are captured</title>
      <link>/questions/15489/capturing-omron-fins-protocol-only-responses-are-captured/</link>
      <pubDate>Fri, 02 Nov 2012 03:36:00 +0000</pubDate>
      
      <guid>/questions/15489/capturing-omron-fins-protocol-only-responses-are-captured/</guid>
      <description>Capturing Omron FINS protocol: only responses are captured  0 I want to look at the communication between a Win7 box and a PLC device. They speak the Omron FINS protocol over ethernet. However, Wireshark 1.8.3 is only able to capture the responses of the PLC, not my requests. There aren&#39;t any problems with other protocols - they got captured correctly.
The source PC is running Win7 x64 with Wireshark 1.</description>
    </item>
    
    <item>
      <title>how to display an array in proto_tree?????</title>
      <link>/questions/15490/how-to-display-an-array-in-proto_tree/</link>
      <pubDate>Fri, 02 Nov 2012 04:09:00 +0000</pubDate>
      
      <guid>/questions/15490/how-to-display-an-array-in-proto_tree/</guid>
      <description>how to display an array in proto_tree?????  0 I want to dispaly an array of guint8 in proto_tree.
is there any api for this??????
proto_treeasked 02 Nov &#39;12, 04:09
Akhil
53●27●28●31
accept rate: 0%
  
One Answer:
  
0 No, you would have to construct the proto_tree your self and put the guint&#39;s in there individualy in a loop.
answered 02 Nov &#39;12, 04:25
Anders ♦</description>
    </item>
    
    <item>
      <title>IKE decryption with certificates</title>
      <link>/questions/15497/ike-decryption-with-certificates/</link>
      <pubDate>Fri, 02 Nov 2012 06:25:00 +0000</pubDate>
      
      <guid>/questions/15497/ike-decryption-with-certificates/</guid>
      <description>IKE decryption with certificates  0 Hi,
I noticed that this method (see this question) to decrypt IKE (v1) packets doesn&#39;t work when certificate are used instead of PSK. At first, I thought it would be the fragmentation as phase 1 message 5 and 6 exceeded the 1500 byte size and got fragmented into two packets. But after enabling JUMBO frames, the problem remained the same. I haven&#39;t changed all other algorithms (still 3DES, MD5 etc.</description>
    </item>
    
    <item>
      <title>Dissector only processes first packet</title>
      <link>/questions/15503/dissector-only-processes-first-packet/</link>
      <pubDate>Fri, 02 Nov 2012 08:00:00 +0000</pubDate>
      
      <guid>/questions/15503/dissector-only-processes-first-packet/</guid>
      <description>Dissector only processes first packet  0 I&#39;m writing my first dissector based on the example in the Developers Guide and README.developer.
I register my dissector for a certain port using
dissector_add_uint(&#34;udp.port&#34;, FOO_PORT, handle);
I notice that it only gets applied to the first packet that matches the port and I can&#39;t apply it to other packets, not even using &#34;Decode As&#34;.
How can I figure out what the problem might be ?</description>
    </item>
    
    <item>
      <title>Decode double-precision float in big-endian order</title>
      <link>/questions/15504/decode-double-precision-float-in-big-endian-order/</link>
      <pubDate>Fri, 02 Nov 2012 09:30:00 +0000</pubDate>
      
      <guid>/questions/15504/decode-double-precision-float-in-big-endian-order/</guid>
      <description>Decode double-precision float in big-endian order  0 I used WireShark to capture this double-precision float from ethernet: 40 39 64 15 85 15 4f 4f Basic format understanding: [sign bit][11 bit exponent][52 bit mantissa] = 64 bit value I believe it&#39;s in big-endian order, equivalent to approximately 52,000 decimal. No matter how I order the bytes it never comes out right.
Does the data look reasonable? How to decode properly?</description>
    </item>
    
    <item>
      <title>VLAN Tagging Intel 82579LM and Wireshark 1.8.3</title>
      <link>/questions/15524/vlan-tagging-intel-82579lm-and-wireshark-183/</link>
      <pubDate>Sun, 04 Nov 2012 07:29:00 +0000</pubDate>
      
      <guid>/questions/15524/vlan-tagging-intel-82579lm-and-wireshark-183/</guid>
      <description>VLAN Tagging Intel 82579LM and Wireshark 1.8.3  0 Hi all, I&#39;m use wireshark 1.8.3 and a dell E6410 with intel 82579lm network adapter. I can&#39;t see any vlan information in a capture although I have configured tagging in the networkcard settings and the networkconnection is working very well. What I have to do in addition? Greetings Hartmut
vlan intel tagging 82579lmasked 04 Nov &#39;12, 07:29
Hartmut
6●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>data.data shows only 24byte</title>
      <link>/questions/15531/datadata-shows-only-24byte/</link>
      <pubDate>Mon, 05 Nov 2012 00:23:00 +0000</pubDate>
      
      <guid>/questions/15531/datadata-shows-only-24byte/</guid>
      <description>data.data shows only 24byte  1 I want to create a txt-file with the data of my filtered UDP-packets. When i create a custom colu**mn with the field-type &#34;data.data&#34; it shows my filtered packet-data but only the first 24byte and &#34;...&#34;
Is it possible to create a txt-file with the full frame-content (without the header information)?
Thanks a lot!
data.dataasked 05 Nov &#39;12, 00:23
Sharkline
16●1●1●3
accept rate: 0%
 edited 05 Nov &#39;12, 00:24</description>
    </item>
    
    <item>
      <title>How can I get a list of all the VLAN IDs in a capture?</title>
      <link>/questions/15532/how-can-i-get-a-list-of-all-the-vlan-ids-in-a-capture/</link>
      <pubDate>Mon, 05 Nov 2012 00:41:00 +0000</pubDate>
      
      <guid>/questions/15532/how-can-i-get-a-list-of-all-the-vlan-ids-in-a-capture/</guid>
      <description>How can I get a list of all the VLAN IDs in a capture?  1 1is it possible to have only one entry in packet table for specific vlan id even if we got 1000 packets of that vlan id , diiferent or same protocol &amp;amp; whatever be contents of that packet ?
Currently , we have to capture lot of packets then sort by vlan id &amp;amp; scroll through a long list to find what diferent vlan id&#39;s we received on our system.</description>
    </item>
    
    <item>
      <title>Meaning of the TCP dump entry</title>
      <link>/questions/15539/meaning-of-the-tcp-dump-entry/</link>
      <pubDate>Mon, 05 Nov 2012 02:55:00 +0000</pubDate>
      
      <guid>/questions/15539/meaning-of-the-tcp-dump-entry/</guid>
      <description>Meaning of the TCP dump entry  0 Hello all,
I am monitoring a remote system. The TCP dump shows the following entry. Does anybody has any idea what this entry means??
 29 2.199163 10.142.4.10 62.254.196.34 TCP 54 41620 &amp;gt; 18081 [RST] Seq=4360 Win=49680 Len=0 30 20216171 62.254.196.34 10.142.4.10 TCP 60 18081 &amp;gt; 41620 [RST] Seq=6849 Win=0 Len=0
Its too urgent please revert to this
Thanks, Raj
wiresharkasked 05 Nov &#39;12, 02:55</description>
    </item>
    
    <item>
      <title>ICMP PING checksum [correct]</title>
      <link>/questions/15543/icmp-ping-checksum-correct/</link>
      <pubDate>Mon, 05 Nov 2012 08:21:00 +0000</pubDate>
      
      <guid>/questions/15543/icmp-ping-checksum-correct/</guid>
      <description>ICMP PING checksum [correct]  0 When looking at the ICMP (not IP) info from a PING conversation, what does the &#39;[correct]&#39; next to &#39;checksum&#39; pertain to? It appears the checksum being displayed is with respect to the data being sent; if that&#39;s the case, how can the PING request say [correct] when it hasn&#39;t received anything?
What is being checked to generate the [correct], not just on the requesting side, but both?</description>
    </item>
    
    <item>
      <title>Capture file and rewrite after time period.</title>
      <link>/questions/15545/capture-file-and-rewrite-after-time-period/</link>
      <pubDate>Mon, 05 Nov 2012 08:50:00 +0000</pubDate>
      
      <guid>/questions/15545/capture-file-and-rewrite-after-time-period/</guid>
      <description>Capture file and rewrite after time period.  0 Is there a setting to setup a cature file and log for a select period of time and rewrite file after time expires?
capture period file timeasked 05 Nov &#39;12, 08:50
hijazisj
1●1●1●1
accept rate: 0%
  
One Answer:
  
0yes, go to the Capture Options dialog in the GUI.
Capture -&amp;gt; Options
Then choose the option use multiple files.</description>
    </item>
    
    <item>
      <title>Supported ciphers for decoding SSL in Wireshark ?</title>
      <link>/questions/15555/supported-ciphers-for-decoding-ssl-in-wireshark/</link>
      <pubDate>Mon, 05 Nov 2012 15:04:00 +0000</pubDate>
      
      <guid>/questions/15555/supported-ciphers-for-decoding-ssl-in-wireshark/</guid>
      <description>Supported ciphers for decoding SSL in Wireshark ?  0 I have been playing with decoding SSL, in Wireshark/Tshark between version 1.0-1.9 (what ships with CentOS 5 and what I could build on CentOS 6).
Apart from plain finger trouble and trying to get the correct SSL key format in ~/.wireshark/ for different versions of Wireshark, and not realizing that the decrypted data appears in an initially hidden pane rather than where it would normally appear in a non-SSL, I notice decryption only works for some ciphers.</description>
    </item>
    
    <item>
      <title>Open closed ports</title>
      <link>/questions/15556/open-closed-ports/</link>
      <pubDate>Mon, 05 Nov 2012 18:15:00 +0000</pubDate>
      
      <guid>/questions/15556/open-closed-ports/</guid>
      <description>Open closed ports  0 After capturing packets of an nmap scan: nmap –PN –scanflags PSHSYN –g 53 –p 22,80 [target] I found one respond from the target with ACK and RST flags set on port 80 I also found 4 responds from the target with ACK and SYN flags set on port 22
Does it indicate that the ports are open or closed ? I was thinking that if you get a respond with ACK and RST flags set for port 80 it means that it is closed, however I am not sure if port 22 is closed or open.</description>
    </item>
    
    <item>
      <title>How to generate amf packets????</title>
      <link>/questions/15557/how-to-generate-amf-packets/</link>
      <pubDate>Mon, 05 Nov 2012 20:17:00 +0000</pubDate>
      
      <guid>/questions/15557/how-to-generate-amf-packets/</guid>
      <description>How to generate amf packets????  0 I am writing an amf plugin for wireshark. I need an amf packet generator to test my plugin. Is there any tool / website which generates amf packets?????
amfasked 05 Nov &#39;12, 20:17
Akhil
53●27●28●31
accept rate: 0%
Maybe the first link in Kurt&#39;s answer here could be relevant to you?: http://ask.wireshark.org/questions/15183/list-of-servers-that-send-amf-packet
(05 Nov &#39;12, 21:09) SidRI tried (Blazer -Amf testing made easy) but it throws an exception :AMF CONNECTION FAILED.</description>
    </item>
    
    <item>
      <title>headless automate export object when capturing packeting</title>
      <link>/questions/15560/headless-automate-export-object-when-capturing-packeting/</link>
      <pubDate>Tue, 06 Nov 2012 00:09:00 +0000</pubDate>
      
      <guid>/questions/15560/headless-automate-export-object-when-capturing-packeting/</guid>
      <description>headless automate export object when capturing packeting  0 Hello,
Is there possible to run wireshark and exporting http objects (file -&amp;gt; export -&amp;gt; objects -&amp;gt; http feature), and automate saving these objects to files under the structed path in GET header while wireshark is caputing packet and running in headless mode.
How?
Thanks,
headless objects export http automationasked 06 Nov &#39;12, 00:09
wiresharknew...
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Relation between packets and sequence number &#43; know the moment of packet lost</title>
      <link>/questions/15563/relation-between-packets-and-sequence-number-know-the-moment-of-packet-lost/</link>
      <pubDate>Tue, 06 Nov 2012 01:06:00 +0000</pubDate>
      
      <guid>/questions/15563/relation-between-packets-and-sequence-number-know-the-moment-of-packet-lost/</guid>
      <description>Relation between packets and sequence number + know the moment of packet lost  0 Hi, I can&#39;t understand the relation between packet and sequence, because when I go to analyse the RTP packets with the option RTP stream analysis, in the column paket starts the packet with the number 33 and the seq number with the number 38761, but if I continue analysing, in the packet 29146 has the number of sequence equal to 0.</description>
    </item>
    
    <item>
      <title>how to limit access of wireshark to 1 of several nics</title>
      <link>/questions/15577/how-to-limit-access-of-wireshark-to-1-of-several-nics/</link>
      <pubDate>Tue, 06 Nov 2012 04:49:00 +0000</pubDate>
      
      <guid>/questions/15577/how-to-limit-access-of-wireshark-to-1-of-several-nics/</guid>
      <description>how to limit access of wireshark to 1 of several nics  0 how can i limit wiresharks activity to 1 particular ethernet nic of several on a given station? we&#39;re in a classroom situation and we have 1 nic connected to a network which is local to the classroom. another nic is connected to the campus network. i don&#39;t want the class to have the option of sniffing on the campus network.</description>
    </item>
    
    <item>
      <title>Windows build suddenly failed after svn sync</title>
      <link>/questions/15580/windows-build-suddenly-failed-after-svn-sync/</link>
      <pubDate>Tue, 06 Nov 2012 06:06:00 +0000</pubDate>
      
      <guid>/questions/15580/windows-build-suddenly-failed-after-svn-sync/</guid>
      <description>Windows build suddenly failed after svn sync  0 I did an svn update on the code directory and now the build fails. The code built fine previously along with the plugin I&#39;ve written, and I&#39;m sure I&#39;ve not made any changes to any other .c or .h files. This is what I get before build stops:
c:\wireshark\epan\except.h(96) : error C2054: expected &#39;(&#39; to follow &#39;WS_MSVC_NO RETURN&#39;
c:\wireshark\epan\except.h(96) : error C2085: &#39;except_rethrow&#39; : not in formal p arameter list</description>
    </item>
    
    <item>
      <title>Lua: How can I evaluate a ProtoField in an IF-statement?</title>
      <link>/questions/15586/lua-how-can-i-evaluate-a-protofield-in-an-if-statement/</link>
      <pubDate>Tue, 06 Nov 2012 08:05:00 +0000</pubDate>
      
      <guid>/questions/15586/lua-how-can-i-evaluate-a-protofield-in-an-if-statement/</guid>
      <description>Lua: How can I evaluate a ProtoField in an IF-statement?  0 I am writing a Lua script, which I&#39;ve included in init.lua, to decode some data.
I&#39;m reading the byte before an RTP header to determine how to decode the header. If the byte is 1, I want to decode it one way; otherwise in another way.
This is the code:
MYPROTO = Proto (&amp;quot;myproto&amp;quot;, &amp;quot;My Protocol&amp;quot;) local f = MYPROTO.</description>
    </item>
    
    <item>
      <title>How to update wireshark without first uninstalling an older version</title>
      <link>/questions/15588/how-to-update-wireshark-without-first-uninstalling-an-older-version/</link>
      <pubDate>Tue, 06 Nov 2012 08:39:00 +0000</pubDate>
      
      <guid>/questions/15588/how-to-update-wireshark-without-first-uninstalling-an-older-version/</guid>
      <description>How to update wireshark without first uninstalling an older version  0 Hello, I&#39;d like to update wireshark (on windows xp) but without first uninstalling the previous version in order not to lose my configurations. Can someone tell how?
Many thanks in advance.
configuration update installasked 06 Nov &#39;12, 08:39
nouvelle
6●2●2●3
accept rate: 0%
 edited 06 Nov &#39;12, 12:55 
grahamb ♦
19.8k●3●30●206
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Decrypting multiple WPA connections</title>
      <link>/questions/15592/decrypting-multiple-wpa-connections/</link>
      <pubDate>Tue, 06 Nov 2012 10:47:00 +0000</pubDate>
      
      <guid>/questions/15592/decrypting-multiple-wpa-connections/</guid>
      <description>Decrypting multiple WPA connections  0 I&#39;ve been fiddling around with wireshark capturing packets from my (WPA2 protected) wlan.
I got it to decrypt traffic when it see the four handshakes from a device, but it if another device authenticates, it wont decrypt traffic from that device.
So it goes like this: I have set up the passphrase in preferences, nic is monitor mode.
Start capturing.Restart my iphone&#39;s wifiEAPOL packets apear and subsequent traffic from my iphone is decryptedRestart my (other) laptop&#39;s wifiEAPOL packets appear but the traffic from this device doesn&#39;t get encryptedIf i do this the other way around: stop capturing, restart capturing, restart my laptop&#39;s wifi and then my iphone&#39;s.</description>
    </item>
    
    <item>
      <title>wireshark in ubuntu with intel6205 capture very less frame under 5 G 11N</title>
      <link>/questions/15597/wireshark-in-ubuntu-with-intel6205-capture-very-less-frame-under-5-g-11n/</link>
      <pubDate>Tue, 06 Nov 2012 18:05:00 +0000</pubDate>
      
      <guid>/questions/15597/wireshark-in-ubuntu-with-intel6205-capture-very-less-frame-under-5-g-11n/</guid>
      <description>wireshark in ubuntu with intel6205 capture very less frame under 5 G 11N  0 i am doing a test using my ubuntu box which used intel 6205, once i set the ap into wide channel under 5GHZ, the wireshark capture speed seems like be very slow, then i did a compare, i found that indeed for 11N 40MHZ frame wireshark with 6205 only can capture 50% frame than other card, if possible can i know if this a wireshark problem or the card limitation, indeed i already upgrade the kernel to 3.</description>
    </item>
    
    <item>
      <title>Ubuntu 12.04 can not set wlan0 into monitor mode in wireshark 1.6</title>
      <link>/questions/15600/ubuntu-1204-can-not-set-wlan0-into-monitor-mode-in-wireshark-16/</link>
      <pubDate>Tue, 06 Nov 2012 20:45:00 +0000</pubDate>
      
      <guid>/questions/15600/ubuntu-1204-can-not-set-wlan0-into-monitor-mode-in-wireshark-16/</guid>
      <description>Ubuntu 12.04 can not set wlan0 into monitor mode in wireshark 1.6  0 I can set wlan0 into monitor mode by: iwconfig wlan0 mode monitor. However, I can not check the box of capture packets in monitor mode in wireshark.
The error is &#34;The capabilities of the capture device &#34;mon0&#34; could not be obtained (That device doesn&#39;t support monitor mode). Please check to make sure you have sufficient permissions, and that you have the proper interface or pipe specified.</description>
    </item>
    
    <item>
      <title>How to debug my plugin on Ubuntu linux?</title>
      <link>/questions/15602/how-to-debug-my-plugin-on-ubuntu-linux/</link>
      <pubDate>Tue, 06 Nov 2012 21:15:00 +0000</pubDate>
      
      <guid>/questions/15602/how-to-debug-my-plugin-on-ubuntu-linux/</guid>
      <description>How to debug my plugin on Ubuntu linux?  0 I am writing an amf plugin . I want to debug it during live packet capture. Is it possible?
debug ubuntu linuxasked 06 Nov &#39;12, 21:15
Akhil
53●27●28●31
accept rate: 0%
 edited 09 Nov &#39;12, 02:29 
Kurt Knochner ♦
24.8k●10●39●237
  
One Answer:
  
0Sure, although processing the captured packets will necessarily be inhibited while you have the program halted in the debugger.</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t compile wireshark</title>
      <link>/questions/15603/cant-compile-wireshark/</link>
      <pubDate>Tue, 06 Nov 2012 22:10:00 +0000</pubDate>
      
      <guid>/questions/15603/cant-compile-wireshark/</guid>
      <description>can&amp;rsquo;t compile wireshark  0 I got an error while compiling wireshark.
erf.c erf.c(654) : error C2220: warning treated as error - no &#39;object&#39; file generated erf.c(654) : warning C4244: &#39;=&#39; : conversion from &#39;gint64&#39; to &#39;int&#39;, possible lo ss of data mp2t.c mp2t.c(121) : error C2220: warning treated as error - no &#39;object&#39; file generated
mp2t.c(121) : warning C4244: &#39;=&#39; : conversion from &#39;guint64&#39; to &#39;int&#39;, possible loss of data Generating Code.</description>
    </item>
    
    <item>
      <title>Couldn&amp;#x27;t find debug console option in EDIT|Preference</title>
      <link>/questions/15606/couldnt-find-debug-console-option-in-editpreference/</link>
      <pubDate>Tue, 06 Nov 2012 22:28:00 +0000</pubDate>
      
      <guid>/questions/15606/couldnt-find-debug-console-option-in-editpreference/</guid>
      <description>Couldn&amp;rsquo;t find debug console option in EDIT|Preference  0 I want to debug my plugin but couldn&#39;t find debug console option in EDIT|Preference
debug_consoleasked 06 Nov &#39;12, 22:28
Akhil
53●27●28●31
accept rate: 0%
 edited 07 Nov &#39;12, 00:30 
grahamb ♦
19.8k●3●30●206
  
2 Answers:
  
0I have said the same in the other question of yours. Go to &#34;Edit-&amp;gt;Preference&#34;. In the option &#34;Open a console window&#34;</description>
    </item>
    
    <item>
      <title>On understanding reason for TCP connection reset.</title>
      <link>/questions/15607/on-understanding-reason-for-tcp-connection-reset/</link>
      <pubDate>Tue, 06 Nov 2012 23:33:00 +0000</pubDate>
      
      <guid>/questions/15607/on-understanding-reason-for-tcp-connection-reset/</guid>
      <description>On understanding reason for TCP connection reset.  0 My java application is facing an intermittent connection problem, and I asked a question at:
http://stackoverflow.com/questions/13158040/diagnose-intermittent-connection-timeoutAs per the advice, I started looking at network analysis tools and have this file, a conversation from a wireshark capture,
http://www.filedropper.com/abcde
I want to understand why the connection reset occurs. Thanks.
reset tcpasked 06 Nov &#39;12, 23:33
Abhijeet Kas...
1●1●1●2
accept rate: 0%
 edited 06 Nov &#39;12, 23:51</description>
    </item>
    
    <item>
      <title>How to know which is the next layer on SCCP -  RANAP or BSSAP (not according SSN)</title>
      <link>/questions/15611/how-to-know-which-is-the-next-layer-on-sccp-ranap-or-bssap-not-according-ssn/</link>
      <pubDate>Wed, 07 Nov 2012 00:14:00 +0000</pubDate>
      
      <guid>/questions/15611/how-to-know-which-is-the-next-layer-on-sccp-ranap-or-bssap-not-according-ssn/</guid>
      <description>How to know which is the next layer on SCCP - RANAP or BSSAP (not according SSN)  0 Hi. When I have only one frame of SCCP - according what can I know which is the next protocol RANAP or BSSAP. I don&#39;t want to rely on the SSN because not always I have the CR message. Thanks, Zeev
sccpasked 07 Nov &#39;12, 00:14
zeev
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to tell dissector to read AFTER my protocol?</title>
      <link>/questions/15614/how-to-tell-dissector-to-read-after-my-protocol/</link>
      <pubDate>Wed, 07 Nov 2012 01:03:00 +0000</pubDate>
      
      <guid>/questions/15614/how-to-tell-dissector-to-read-after-my-protocol/</guid>
      <description>How to tell dissector to read AFTER my protocol?  0 Hi,
I have create a protocol between UDP and RTP, so the packet I want to capture with wireshark looks like this : ( IP, UDP, [my protocol], RTP )
I have written a lua file to include decoding of my protocol. After I decode my protocol I want to call a dissector to decode the RTP part. The problem is that it thinks it should start reading RTP after the UDP packet, and not after my protocol (which is 20 bytes )</description>
    </item>
    
    <item>
      <title>error  while dissecting mac-lte packets</title>
      <link>/questions/15616/error-while-dissecting-mac-lte-packets/</link>
      <pubDate>Wed, 07 Nov 2012 02:20:00 +0000</pubDate>
      
      <guid>/questions/15616/error-while-dissecting-mac-lte-packets/</guid>
      <description>error while dissecting mac-lte packets  0 Hi, i am using Wireshark Version 1.4.3. I have downloaded mac_lte_logger.c. For its compilation I used packet-mac-lte.h which is present under /usr/local/src/wireshark-1.4.3/epan/dissectors/ But during compilation I got the error:
packet-mac-lte.h:148: error: expected ‘)’ before ‘*’ token
Since it was not able to find the definition of &#34;packet_info&#34; in following lines:
/ Accessor function to check if a frame was considered to be ReTx / int is_mac_lte_frame_retx(packet_info *pinfo, guint8 direction);</description>
    </item>
    
    <item>
      <title>GPRS Packets</title>
      <link>/questions/15617/gprs-packets/</link>
      <pubDate>Wed, 07 Nov 2012 02:20:00 +0000</pubDate>
      
      <guid>/questions/15617/gprs-packets/</guid>
      <description>GPRS Packets  0 IS wireshark able to decode GPRS packets completely? Also what is the format of GPRS packets?
gprsasked 07 Nov &#39;12, 02:20
Hira
1●1●1●1
accept rate: 0%
  
One Answer:
  
0It depends at what reference point see http://wiki.wireshark.org/GsmProtocolFamily
Wireshark can&#39;t capture packets at all the reference points you may need something else to produce the pcap file(s). You probably need to study the 3GPP specs.</description>
    </item>
    
    <item>
      <title>sample capture for ISIS routing protocol</title>
      <link>/questions/15626/sample-capture-for-isis-routing-protocol/</link>
      <pubDate>Wed, 07 Nov 2012 03:04:00 +0000</pubDate>
      
      <guid>/questions/15626/sample-capture-for-isis-routing-protocol/</guid>
      <description>sample capture for ISIS routing protocol  0 hello I thank you for your good site I have a problem about ISIS routing protocol I need a sample capture of ISIS routing protocol to see it thanks
12345asked 07 Nov &#39;12, 03:04
simineh
1●2●2●2
accept rate: 0%
  
One Answer:
  
1Does this link help? http://packetlife.net/captures/protocol/isis/
answered 07 Nov &#39;12, 03:10
SidR
245●12●17●22
accept rate: 30%</description>
    </item>
    
    <item>
      <title>wireshark doesnt capture OSPF packet</title>
      <link>/questions/15641/wireshark-doesnt-capture-ospf-packet/</link>
      <pubDate>Wed, 07 Nov 2012 06:13:00 +0000</pubDate>
      
      <guid>/questions/15641/wireshark-doesnt-capture-ospf-packet/</guid>
      <description>wireshark doesnt capture OSPF packet  0 My coworker using same Wireshark (Version 1.8.3 (SVN Rev 45256 from /trunk-1.8)) and same physical monitor interface but different laptop. But my wireshark could not capture OSPF packet. anybody has similar experence? My laptop is Toshiba Dynabook with Intel(R) 82579LM Gigabit Network Connection.
ospfasked 07 Nov &#39;12, 06:13
cheng531
1●1●1●1
accept rate: 0%
As there is no &#34;special&#34; reason why you should not see OSPF packets, I have some questions:</description>
    </item>
    
    <item>
      <title>Overlapping TCP Sack options</title>
      <link>/questions/15646/overlapping-tcp-sack-options/</link>
      <pubDate>Wed, 07 Nov 2012 07:13:00 +0000</pubDate>
      
      <guid>/questions/15646/overlapping-tcp-sack-options/</guid>
      <description>Overlapping TCP Sack options  0 Hi,
I&#39;m facing a strange issue. We have two systems communicating via RFC, but this communication breaks everytime with the following issue:
The Client receives an TCP ACK with an SLE=2734286 and SLR=2777173 Client then starts a retransmission of the &#34;missing&#34; packages Then receives a TCP DUP ACK with SACK: 2777089-2777173 2734286-2777173
This is weird, isnt it? The SACK parameters are overlapping. The Client then sends again the missing packages but always receives the TCP DUP ACK.</description>
    </item>
    
    <item>
      <title>VoIP call flow analysis won&amp;#x27;t scale</title>
      <link>/questions/15647/voip-call-flow-analysis-wont-scale/</link>
      <pubDate>Wed, 07 Nov 2012 07:37:00 +0000</pubDate>
      
      <guid>/questions/15647/voip-call-flow-analysis-wont-scale/</guid>
      <description>VoIP call flow analysis won&amp;rsquo;t scale  0 When looking at graphical flow analysis the vertical dividers are selectable as if they would scale to the width of available text but nothing happens. As a result the text overlaps, gets cut off, and is very difficult to read.
Is there any solution for this?
flow display voipasked 07 Nov &#39;12, 07:37
TomEverett
1●2●2●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark trace files missing the last portion of the capture</title>
      <link>/questions/15655/wireshark-trace-files-missing-the-last-portion-of-the-capture/</link>
      <pubDate>Wed, 07 Nov 2012 10:25:00 +0000</pubDate>
      
      <guid>/questions/15655/wireshark-trace-files-missing-the-last-portion-of-the-capture/</guid>
      <description>Wireshark trace files missing the last portion of the capture  0 Hi all. Big fan, and user, of the &#39;shark, but haven&#39;t had a need to post in quite a while...
I have run into a strange problem - perhaps someone has some ideas. Here it is...
I&#39;m in the U.S., and I&#39;m working with colleagues in India, who are running wireshark on their workstations, and sending me the files when they are done.</description>
    </item>
    
    <item>
      <title>How to determine offset filter?</title>
      <link>/questions/15668/how-to-determine-offset-filter/</link>
      <pubDate>Wed, 07 Nov 2012 15:55:00 +0000</pubDate>
      
      <guid>/questions/15668/how-to-determine-offset-filter/</guid>
      <description>How to determine offset filter?  0 I need to capture NLTMv1 and v2 traffic. Does this require an offset and if so how does one go about determining the offset value for a filter?
ntlm offsetasked 07 Nov &#39;12, 15:55
ry6
0●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How to capturing HTTP POST endpoint hosted on multiple boxes?</title>
      <link>/questions/15669/how-to-capturing-http-post-endpoint-hosted-on-multiple-boxes/</link>
      <pubDate>Wed, 07 Nov 2012 16:05:00 +0000</pubDate>
      
      <guid>/questions/15669/how-to-capturing-http-post-endpoint-hosted-on-multiple-boxes/</guid>
      <description>How to capturing HTTP POST endpoint hosted on multiple boxes?  0 I am running a Java application upon my Ubuntu box that is making API calls to endpoint https://int.tangocard.com.
This endpoint has multiple hosts when I ping-ed it:
54.243.76.18323.23.233.11650.17.183.3954.243.72.138This API endpoint has DigiCert certificate, and the data communication is using HTTP POST using Basic Authentication, and the body requests and responses are JSON.
I am trying to capture these HTTP POST requests &amp;amp; responses, I have tried using the following as the filter, but nothing is getting captured:</description>
    </item>
    
    <item>
      <title>Wireshark display increasing trace file</title>
      <link>/questions/15674/wireshark-display-increasing-trace-file/</link>
      <pubDate>Wed, 07 Nov 2012 20:17:00 +0000</pubDate>
      
      <guid>/questions/15674/wireshark-display-increasing-trace-file/</guid>
      <description>Wireshark display increasing trace file  0 I have a trace file which is keep growing till trace stops. My requirement is to display the growing trace file in Wireshrk so that user can get the real time packet capturing experience. I have Wireshark Version 1.6.0rc2. How can I achieve this using command line parameters? Please suggest.
rtpasked 07 Nov &#39;12, 20:17
manojdeoli
1●5●5●6
accept rate: 0%
 edited 07 Nov &#39;12, 20:18</description>
    </item>
    
    <item>
      <title>Refresh open File in Wireshark</title>
      <link>/questions/15676/refresh-open-file-in-wireshark/</link>
      <pubDate>Wed, 07 Nov 2012 22:49:00 +0000</pubDate>
      
      <guid>/questions/15676/refresh-open-file-in-wireshark/</guid>
      <description>Refresh open File in Wireshark  0 Hello All, I have the following problem that iam trying to work out with the help of Wireshark
I have log files that keep getting updated.Using text2pcap the files are being processed and viewed in the wireshark.As the files keep getting updated dynamically I am required to process the log files every few minutes to view the latest messages. Can anybody suggest if there is any way Wireshark can refresh the opened file automatically whenever the contents change or if there is any workaround to achieve the same affect instead of manually refreshing using CTRL+R.</description>
    </item>
    
    <item>
      <title>How to debug wireshark using EMACS?????</title>
      <link>/questions/15679/how-to-debug-wireshark-using-emacs/</link>
      <pubDate>Thu, 08 Nov 2012 00:08:00 +0000</pubDate>
      
      <guid>/questions/15679/how-to-debug-wireshark-using-emacs/</guid>
      <description>How to debug wireshark using EMACS?????  0 I want to debug my plugin. How can i do it using EMACS????
debug emacsasked 08 Nov &#39;12, 00:08
Akhil
53●27●28●31
accept rate: 0%
  
One Answer:
  
1EMACS can&#39;t debug an application by itself, but can run a debugger. This is nothing to do with Wireshark so I suggest you look for help elsewhere on a more suitable forum for using EMACS to debug applications.</description>
    </item>
    
    <item>
      <title>wrong vlan outer tag shown?</title>
      <link>/questions/15682/wrong-vlan-outer-tag-shown/</link>
      <pubDate>Thu, 08 Nov 2012 00:22:00 +0000</pubDate>
      
      <guid>/questions/15682/wrong-vlan-outer-tag-shown/</guid>
      <description>wrong vlan outer tag shown?  0 I am doing dot1q tunnel and I use double tagging. I tag the frame with outer vlan 220, but in Wireshark, it shows vlan 1195.
Is it any conversion from 220 to 1195? or what i am seeing is not the outer vlan? Thanks!
the photo is attached: https://docs.google.com/file/d/0B6xwIiuptf5NZl90V0dlWWIzUUU/edit
vlan idasked 08 Nov &#39;12, 00:22
bennettfan
6●2●2●4
accept rate: 0%
 edited 08 Nov &#39;12, 07:16</description>
    </item>
    
    <item>
      <title>[closed] SIMPLE decoding</title>
      <link>/questions/15702/simple-decoding/</link>
      <pubDate>Thu, 08 Nov 2012 02:58:00 +0000</pubDate>
      
      <guid>/questions/15702/simple-decoding/</guid>
      <description>[closed] SIMPLE decoding  0 Please, I beg you, can someone help me with this?
I think all the tutorials and stuff out there are totally confusing, cant somebody provide a SIMPLE example for a SIMPLE problem.
IP, UDP, [My protocol], RTP
Say my protocol is ONE byte, for simplicity. How can I display this byte, and then have the normal RTP display? I do not understand this.
The result I want to have is (seen in wireshark) :</description>
    </item>
    
    <item>
      <title>How can i add debug symbols to wireshark?</title>
      <link>/questions/15705/how-can-i-add-debug-symbols-to-wireshark/</link>
      <pubDate>Thu, 08 Nov 2012 04:14:00 +0000</pubDate>
      
      <guid>/questions/15705/how-can-i-add-debug-symbols-to-wireshark/</guid>
      <description>How can i add debug symbols to wireshark?  0 I am debugging wireshark using gdb. How can i add debug symbols to wireshark?
gdbasked 08 Nov &#39;12, 04:14
Akhil
53●27●28●31
accept rate: 0%
  
One Answer:
  
0 As you would do with any other program, by adding option &#39;-g&#39; to the gcc compiler.
gcc -g
However, you don&#39;t have to care about that, as the standard build process will add &#39;-g&#39; to the CFLAGS variable and thus your compiled binary will have debug symbols, unless you change the build process.</description>
    </item>
    
    <item>
      <title>Wireshark 1.8.3 x64 phoning home?</title>
      <link>/questions/15711/wireshark-183-x64-phoning-home/</link>
      <pubDate>Thu, 08 Nov 2012 05:57:00 +0000</pubDate>
      
      <guid>/questions/15711/wireshark-183-x64-phoning-home/</guid>
      <description>Wireshark 1.8.3 x64 phoning home?  0 I have Wireshark 1.8.3 on two machines, one a Win7 x64 box and the other Win XP SP3 (32-bit).
Between 1 and 3 times per day the Win7 X64 machine tries to connect to TCP port 61899 of www.wireshark.org (174.137.42.75). My routers firewall blocks these attempts but WTF?
Is there some option to disable this &#34;phoning home&#34;?
BTW Wireshark is NOT running during these attempts.</description>
    </item>
    
    <item>
      <title>Newbie Question: How to See the Contents of a Packet via Wireshark</title>
      <link>/questions/15719/newbie-question-how-to-see-the-contents-of-a-packet-via-wireshark/</link>
      <pubDate>Thu, 08 Nov 2012 06:49:00 +0000</pubDate>
      
      <guid>/questions/15719/newbie-question-how-to-see-the-contents-of-a-packet-via-wireshark/</guid>
      <description>Newbie Question: How to See the Contents of a Packet via Wireshark  0 Hello, I am very new to Wireshark and have not been able to find this exact info online so I thought I&#39;d ask here.
How can someone see the contents of a packet with Wireshark? I am doing an activity for school and being brand new to the program I could use some help figuring that out.</description>
    </item>
    
    <item>
      <title>Only able to capture broadcast packets in monitor mode</title>
      <link>/questions/15724/only-able-to-capture-broadcast-packets-in-monitor-mode/</link>
      <pubDate>Thu, 08 Nov 2012 07:41:00 +0000</pubDate>
      
      <guid>/questions/15724/only-able-to-capture-broadcast-packets-in-monitor-mode/</guid>
      <description>Only able to capture broadcast packets in monitor mode  0 I&#39;m setting my WLAN interface to monitor mode using &#34;airmon-ng start wlan0&#34; and it reports back that monitor mode has been started. However captures on mon0 only show broadcast or multicast packets.
How reliable is airmons claim that monitor mode is on ?
wlan airmon monitor modeasked 08 Nov &#39;12, 07:41
Jan
6●2●2●5
accept rate: 0%
 edited 08 Nov &#39;12, 08:03</description>
    </item>
    
    <item>
      <title>Strangly high memory consumption when using capture filters</title>
      <link>/questions/15725/strangly-high-memory-consumption-when-using-capture-filters/</link>
      <pubDate>Thu, 08 Nov 2012 07:52:00 +0000</pubDate>
      
      <guid>/questions/15725/strangly-high-memory-consumption-when-using-capture-filters/</guid>
      <description>Strangly high memory consumption when using capture filters  0 Hi folks,
I need to do a long term capture on a server under high load and try to find session initiations with a TCP(SYN) that were not answered(SYN,ACK).
Since there is a high load on this server i thougt that I probably need capture filters so that i dont run out of memory on the server.
What i did was to add a capture filter that said &#34;</description>
    </item>
    
    <item>
      <title>How to decrypt SSL using DigiCert Root Certificate within HTTPS POST traffic from Java App?</title>
      <link>/questions/15729/how-to-decrypt-ssl-using-digicert-root-certificate-within-https-post-traffic-from-java-app/</link>
      <pubDate>Thu, 08 Nov 2012 08:39:00 +0000</pubDate>
      
      <guid>/questions/15729/how-to-decrypt-ssl-using-digicert-root-certificate-within-https-post-traffic-from-java-app/</guid>
      <description>How to decrypt SSL using DigiCert Root Certificate within HTTPS POST traffic from Java App?  0 Hi
I am able to capture traffic between a Java app using HttpsURLConnection POST to API endpoint https://int.tangocard.com
For security, this endpoint uses a DigiCert Root Certificate.
I tried adding this DigiCert Root Certificate to RSA Key List within SSL Protocol preferences, but that did not decrypt Ecrypted Application Data within Secure Socket Layer of captured traffic.</description>
    </item>
    
    <item>
      <title>Tshark conversation statistics</title>
      <link>/questions/15730/tshark-conversation-statistics/</link>
      <pubDate>Thu, 08 Nov 2012 08:42:00 +0000</pubDate>
      
      <guid>/questions/15730/tshark-conversation-statistics/</guid>
      <description>Tshark conversation statistics  0 Hello:
I am trying to use tshark to gather statistics of the conversations between endpoints in a trace file. I would like to get an output similar to what I obtain using Wireshark-&amp;gt; Statistics -&amp;gt; Conversations. For the same trace file, Wireshark takes about 1 minute to compute the statistics. Tshark keeps running and does not finish.. Here is the command I am running:
C:\Program Files\Wireshark&amp;gt;tshark -q -z conv,ip -r &#34;</description>
    </item>
    
    <item>
      <title>Wireshark logs only client and server info?</title>
      <link>/questions/15738/wireshark-logs-only-client-and-server-info/</link>
      <pubDate>Thu, 08 Nov 2012 10:36:00 +0000</pubDate>
      
      <guid>/questions/15738/wireshark-logs-only-client-and-server-info/</guid>
      <description>Wireshark logs only client and server info?  0 Hello, I just want to know if Wireshark only collects information of client and server right? in between client and server there are many network components/elements. do we see that information also? for e.g. in wireshark log I see server is sending slow data but is it possible some router(or any network element in between client and server)may be slow?
Thanks, Manju</description>
    </item>
    
    <item>
      <title>how to find nodes with wrong subnet mask</title>
      <link>/questions/15740/how-to-find-nodes-with-wrong-subnet-mask/</link>
      <pubDate>Thu, 08 Nov 2012 12:16:00 +0000</pubDate>
      
      <guid>/questions/15740/how-to-find-nodes-with-wrong-subnet-mask/</guid>
      <description>how to find nodes with wrong subnet mask  0 how would i filter a capture to find what nodes have the wrong subnet mask? i.e my network is 10.128.5.x / 255.255.255.0 but a client is misconfigured using 255.255.0.0
subnet capture-filter maskasked 08 Nov &#39;12, 12:16
pcmonkey
1●1●1●1
accept rate: 0%
  
3 Answers:
  
1You can find wrong subnetmasks either by finding for ARP requests that are looking for MAC addresses of IP addresses they should not be able to reach directly (which is your case), or by finding ICMP redirect messages from default gateways that tell clients to talk to the target node directly (if the mask is too narrow).</description>
    </item>
    
    <item>
      <title>install wireshark 1.8.3 in ubuntu 12.04</title>
      <link>/questions/15753/install-wireshark-183-in-ubuntu-1204/</link>
      <pubDate>Thu, 08 Nov 2012 20:45:00 +0000</pubDate>
      
      <guid>/questions/15753/install-wireshark-183-in-ubuntu-1204/</guid>
      <description>install wireshark 1.8.3 in ubuntu 12.04  0 To enable capture traffic on multiple interfaces at once, I tried to install wireshark 1.8.3. However, I encountered the following errors:
capture-pcap-util.c:274:1: error: static declaration of ‘pcap_datalink_name_to_val’ follows non-static declaration /usr/local/include/pcap/pcap.h:326:5: note: previous declaration of ‘pcap_datalink_name_to_val’ was here capture-pcap-util.c:289:1: error: static declaration of ‘pcap_datalink_val_to_name’ follows non-static declaration /usr/local/include/pcap/pcap.h:327:13: note: previous declaration of ‘pcap_datalink_val_to_name’ was here
After doing some search, I found someone can fix it by reinstall libpcap-dev, or the following commands: step 1:rm &amp;amp; rmdir any file in &#39;/usr/include/pcap&#39;;&#39;/usr/local/include/pcap&#39;</description>
    </item>
    
    <item>
      <title>How to convert a file of type application/octet-stream to .pcap?</title>
      <link>/questions/15760/how-to-convert-a-file-of-type-applicationoctet-stream-to-pcap/</link>
      <pubDate>Fri, 09 Nov 2012 01:23:00 +0000</pubDate>
      
      <guid>/questions/15760/how-to-convert-a-file-of-type-applicationoctet-stream-to-pcap/</guid>
      <description>How to convert a file of type application/octet-stream to .pcap?  1 I want to convert a file of type application/octet-stream to .pcap. I tried using text2pcap but its output on terminal is &#34;Read 0 potential packets, wrote 0 packets&#34;
pcapasked 09 Nov &#39;12, 01:23
Akhil
53●27●28●31
accept rate: 0%
 edited 09 Nov &#39;12, 01:23 
  
One Answer:
  
0without further information you can&#39;t, because application/octet-stream is just a MIME type to encode data in several protocols.</description>
    </item>
    
    <item>
      <title>What mean the radio field in follow tcp stream?</title>
      <link>/questions/15772/what-mean-the-radio-field-in-follow-tcp-stream/</link>
      <pubDate>Fri, 09 Nov 2012 07:47:00 +0000</pubDate>
      
      <guid>/questions/15772/what-mean-the-radio-field-in-follow-tcp-stream/</guid>
      <description>What mean the radio field in follow tcp stream?  0 I select the Follow TCP Stream for analyzis a communication, in the first section (A-&amp;gt;B) in red color, the first is a GET (URL), next there is a field: radio= radio&amp;amp;email then there is a email address what mean it? IT is &#34;re-link&#34; me and it attempts send a mail?
follow.tcp.streamasked 09 Nov &#39;12, 07:47
jgarzam
1●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>check sequentiality in destination addresses from a specific source address</title>
      <link>/questions/15776/check-sequentiality-in-destination-addresses-from-a-specific-source-address/</link>
      <pubDate>Fri, 09 Nov 2012 08:21:00 +0000</pubDate>
      
      <guid>/questions/15776/check-sequentiality-in-destination-addresses-from-a-specific-source-address/</guid>
      <description>check sequentiality in destination addresses from a specific source address  0 Hi, I need a piece of code that can check if there is a source address sending a SYN packet to sequential ip addresses while capturing packets using tshark withen a small period of time,say 1 minute. thanks
luaasked 09 Nov &#39;12, 08:21
Leena
51●17●18●21
accept rate: 0%
I just want to note that I want the code in Lua in order to make the process while running the program at the same time with capturing, I&#39;m working with tshark.</description>
    </item>
    
    <item>
      <title>how to use wireshark library and glib library ?</title>
      <link>/questions/15786/how-to-use-wireshark-library-and-glib-library/</link>
      <pubDate>Sat, 10 Nov 2012 00:03:00 +0000</pubDate>
      
      <guid>/questions/15786/how-to-use-wireshark-library-and-glib-library/</guid>
      <description>how to use wireshark library and glib library ?  0 I make myown dynamic library(myown.so) according to libs of wiresahrk and glib.
(libglib-2.0.a libglib-2.0.a libgthread-2.0.a libairpdcap.a libdfilter.a libdissectors.a libftypes.a libwireshark.a libwiretap.a libwsutil.a libwireshark_asmopt.a libwireshark_generated.a libdirtydissectors.a )
include path(glib-2.0,wireshark,wireshark/epan).
myown.so can be made successfully, but loaded fail.
ldd -r myown.so, errors are as follow:
undefined symbol: proto_item_fill_label (./myown.so)
undefined symbol: g_sprintf (./myown.so)
undefined symbol: g_assertion_message_expr (./myown.so)
undefined symbol: register_all_protocol_handoffs (./myown.so)</description>
    </item>
    
    <item>
      <title>which static library define epan_init, etc?</title>
      <link>/questions/15787/which-static-library-define-epan_init-etc/</link>
      <pubDate>Sat, 10 Nov 2012 00:09:00 +0000</pubDate>
      
      <guid>/questions/15787/which-static-library-define-epan_init-etc/</guid>
      <description>which static library define epan_init, etc?  0 which wireshark static library on linux define
epan_init,proto_item_fill_label,g_sprintf,g_assertion_message_expr,register_all_protocol_handoffs,register_all_protocols,frame_data_set_before_dissect,g_malloc0thank you very much.
epan_initasked 10 Nov &#39;12, 00:09
ylda_ljm0620
31●10●10●13
accept rate: 0%
 edited 10 Nov &#39;12, 06:07 
Jaap ♦
11.7k●16●101
  
One Answer:
  
1Whether a library is static or dynamic depends on how it&#39;s built, not what it defines.
The libraries that define those functions are:</description>
    </item>
    
    <item>
      <title>ARP replies appear with delay in Wireshark output</title>
      <link>/questions/15792/arp-replies-appear-with-delay-in-wireshark-output/</link>
      <pubDate>Sat, 10 Nov 2012 17:34:00 +0000</pubDate>
      
      <guid>/questions/15792/arp-replies-appear-with-delay-in-wireshark-output/</guid>
      <description>ARP replies appear with delay in Wireshark output  0 If I send an ICMP &#34;echo request&#34; from 10.10.10.2 to 10.10.10.1, then according to tcpdump and Wireshark, 10.10.10.1 sends ICMP &#34;echo reply&#34; before ARP reply from 10.10.10.2 is received:
02:36:14.689050 00:1a:6b:6c:0c:cc &amp;gt; ff:ff:ff:ff:ff:ff, ethertype ARP (0x0806), length 60: Request who-has 10.10.10.1 tell 10.10.10.2, length 46 02:36:14.689079 00:1d:09:f0:92:ab &amp;gt; 00:1a:6b:6c:0c:cc, ethertype ARP (0x0806), length 42: Reply 10.10.10.1 is-at 00:1d:09:f0:92:ab, length 28 02:36:14.</description>
    </item>
    
    <item>
      <title>Capturing WhatsApp chat messages</title>
      <link>/questions/15793/capturing-whatsapp-chat-messages/</link>
      <pubDate>Sun, 11 Nov 2012 00:48:00 +0000</pubDate>
      
      <guid>/questions/15793/capturing-whatsapp-chat-messages/</guid>
      <description>Capturing WhatsApp chat messages  0 Any more help here? I am particularly interested in looking at WhatsApp chats on Blackberry. I know there are certain whatsapp chats being deleted and I won wondering:
Is there a way to auto backup or auto save WhatApp chats on their device which can be retrieved after they delete the chats? I have access the the phone and can install whatever app I need-How can intercep or sniffer Whatsapp on Blackberry using Wifi?</description>
    </item>
    
    <item>
      <title>Capture http Get request</title>
      <link>/questions/15805/capture-http-get-request/</link>
      <pubDate>Sun, 11 Nov 2012 16:11:00 +0000</pubDate>
      
      <guid>/questions/15805/capture-http-get-request/</guid>
      <description>Capture http Get request  0 Here is the first line of a captured get request, qqCcEv#[email protected]^PGET / HTTP/1.1
Here is another first line- to the same site, [email protected] #PGET / HTTP/1.1
The wierd qq.. bytes before the &#39;GET&#39;, what are they for? I am getting drastically different responses depending on their content.
get http wiresharkasked 11 Nov &#39;12, 16:11
jmu2101
6●3●3●6
accept rate: 0%
The wierd qq.. bytes before the &#39;GET&#39;, what are they for?</description>
    </item>
    
    <item>
      <title>How is my plugin registered when wireshark loads? and which routine calls my plugin?</title>
      <link>/questions/15809/how-is-my-plugin-registered-when-wireshark-loads-and-which-routine-calls-my-plugin/</link>
      <pubDate>Sun, 11 Nov 2012 19:50:00 +0000</pubDate>
      
      <guid>/questions/15809/how-is-my-plugin-registered-when-wireshark-loads-and-which-routine-calls-my-plugin/</guid>
      <description>How is my plugin registered when wireshark loads? and which routine calls my plugin?  0 How is my plugin registered when wireshark loads? and which routine calls my plugin?
pluginasked 11 Nov &#39;12, 19:50
Akhil
53●27●28●31
accept rate: 0%
  
One Answer:
  
1 See epan/plugins.c
answered 12 Nov &#39;12, 04:14
Jaap ♦
11.7k●16●101
accept rate: 14%
Thanks a lot Jaap.
(13 Nov &#39;12, 19:55) Akhil     </description>
    </item>
    
    <item>
      <title>All TCP connections end with RST</title>
      <link>/questions/15815/all-tcp-connections-end-with-rst/</link>
      <pubDate>Mon, 12 Nov 2012 02:21:00 +0000</pubDate>
      
      <guid>/questions/15815/all-tcp-connections-end-with-rst/</guid>
      <description>All TCP connections end with RST  0 Hi. I&#39;m doing an analysis on a network and while doing a capture from client&#39;s end I found out that all TCP connections end with reset packets.
The network looks like: Client - Firewall - Load balancer(+SSL acceleration) - Server
So when I&#39;m capturing traffic from a client I see that the TCP traffic is flowing fine and client ACKs packet&#39;s normally. After the last segment is ACKed nothing happens for a ~5 seconds and then the rest of the connection always goes like this:</description>
    </item>
    
    <item>
      <title>Display MAC address in the packet list</title>
      <link>/questions/15824/display-mac-address-in-the-packet-list/</link>
      <pubDate>Mon, 12 Nov 2012 07:25:00 +0000</pubDate>
      
      <guid>/questions/15824/display-mac-address-in-the-packet-list/</guid>
      <description>Display MAC address in the packet list  0 I am using the filter &#34;bootp.option.type==1 and bootp.option.value==01&#34; to find the DHCP Discovers. When I export the results to a csv file, I get IP addresses all-zeros (No IP yet) and all-ones (broadcast) To know what station is doing this, I need the MAC address of the sender. How can I define the fields that are displayed in the packet list view to include MAC addresses?</description>
    </item>
    
    <item>
      <title>Dissector selection for protocols</title>
      <link>/questions/15828/dissector-selection-for-protocols/</link>
      <pubDate>Mon, 12 Nov 2012 07:58:00 +0000</pubDate>
      
      <guid>/questions/15828/dissector-selection-for-protocols/</guid>
      <description>Dissector selection for protocols  0 Hello, community, I read the developer documentation about writing own plugins for Wireshark. However, there is still one thing I did not understand. Heuristic dissectors use some heuristics to see whether the packet in question is of the protocol they can dissect. But how do normal dissectors know? As far as I understood, they register on the special protocol header, but the exact procedure is not clear for me.</description>
    </item>
    
    <item>
      <title>Wireshark Preferences on windows 64 Bits</title>
      <link>/questions/15831/wireshark-preferences-on-windows-64-bits/</link>
      <pubDate>Mon, 12 Nov 2012 11:00:00 +0000</pubDate>
      
      <guid>/questions/15831/wireshark-preferences-on-windows-64-bits/</guid>
      <description>Wireshark Preferences on windows 64 Bits  0 Hi,
I&#39;m using Wireshark 1.8.3 on Windows 7 64 Bits. I&#39;m trying to specify Kerberos keytab file in the Wireshark--&amp;gt;Edit--&amp;gt;Preferences--&amp;gt;Protocols--&amp;gt;krb5. But the Wireshark GUI does not show the keytab filename path or parameter; I just see Reassemble Kerberos over TCP parameter.
following the wiki, It should be possible to specify a keytab : &#34;Specifying the keytab file to use You can specify the filename of the keytab file to use in the KRB5 preferences.</description>
    </item>
    
    <item>
      <title>What equipment can I use to capture bluetooth packets?</title>
      <link>/questions/15837/what-equipment-can-i-use-to-capture-bluetooth-packets/</link>
      <pubDate>Mon, 12 Nov 2012 17:22:00 +0000</pubDate>
      
      <guid>/questions/15837/what-equipment-can-i-use-to-capture-bluetooth-packets/</guid>
      <description>What equipment can I use to capture bluetooth packets?  0 1http://wiki.wireshark.org/CaptureSetup/Bluetooth This page mentioned that I can use wireshark capture Bluetooth package,can I use a Bluetooth adapter to capture?
wireless equipment bluetoothasked 12 Nov &#39;12, 17:22
kanon2000
1●1●2●2
accept rate: 0%
  
One Answer:
  
1As that page says, &#34;Bluetooth capture support is supported on Linux in Wireshark with libpcap 0.9.6 and later, if the kernel includes the BlueZ Bluetooth stack; starting with the 2.</description>
    </item>
    
    <item>
      <title>window7 automatically remove the outer vlan tag?</title>
      <link>/questions/15842/window7-automatically-remove-the-outer-vlan-tag/</link>
      <pubDate>Mon, 12 Nov 2012 22:22:00 +0000</pubDate>
      
      <guid>/questions/15842/window7-automatically-remove-the-outer-vlan-tag/</guid>
      <description>window7 automatically remove the outer vlan tag?  0 JDSU traffic generator is used to generate traffic(outer vlan 500,inner vlan 50) to pc(window7) and the packet captured in wireshark is shown: http://cloudshark.org/captures/d302f8040a52
JDSU traffic generator is used to generate traffic(outer vlan 500,inner vlan 50) to JDSU-MTS5800 and the packet captured in wireshark inside JDSU-MTS5800 is shown: http://cloudshark.org/captures/7e88043f2e0d
The traffic generator is the same and with the same configuration. However, the packet capture result is different.</description>
    </item>
    
    <item>
      <title>Limiting Column Width</title>
      <link>/questions/15852/limiting-column-width/</link>
      <pubDate>Tue, 13 Nov 2012 01:13:00 +0000</pubDate>
      
      <guid>/questions/15852/limiting-column-width/</guid>
      <description>Limiting Column Width  1 Wireshark has the wonderful &#34;Info&#34; column that shows the most important information for a packet.
I am working on a trace file where the web server receives rather long GET requests with 400+ Byte long URIs.
When using the function &#34;Resize Column&#34; all fields on the right side of the Info column will go out of side. Scrolling &#34;thousands&#34; of pixel is no fun.
Is there aware of quick way to resize the column to something useful?</description>
    </item>
    
    <item>
      <title>Compiling same plugins for different Wireshark versions</title>
      <link>/questions/15856/compiling-same-plugins-for-different-wireshark-versions/</link>
      <pubDate>Tue, 13 Nov 2012 02:25:00 +0000</pubDate>
      
      <guid>/questions/15856/compiling-same-plugins-for-different-wireshark-versions/</guid>
      <description>Compiling same plugins for different Wireshark versions  0 Hello, I have a Wireshark plugin here working properly for Wireshark 1.7. On Wireshark 1.8, I get some dissection errors. I know that plugins are usually not compatible with Wireshark versions they were not compiled for. So, I decided to recompile my plugin. I have a Linux system where the stuff is supposed to run. Now, what does it exactly mean to compile the plugin for another version of Wireshark?</description>
    </item>
    
    <item>
      <title>how the function dissect_http works?</title>
      <link>/questions/15857/how-the-function-dissect_http-works/</link>
      <pubDate>Tue, 13 Nov 2012 02:36:00 +0000</pubDate>
      
      <guid>/questions/15857/how-the-function-dissect_http-works/</guid>
      <description>how the function dissect_http works?  0 i want to do some data mining work on some key fields of the network packets, then I have downloaded the sourcecode of wireshark-1.6.4,and try to use tshark to analyze some packets.but i need to do some change or just define a new struct to store my own variables,i have to find out where is the field i need and copy their value to my own variables.</description>
    </item>
    
    <item>
      <title>Modbus TCP/IP Problem detectable with WireShark?</title>
      <link>/questions/15859/modbus-tcpip-problem-detectable-with-wireshark/</link>
      <pubDate>Tue, 13 Nov 2012 04:21:00 +0000</pubDate>
      
      <guid>/questions/15859/modbus-tcpip-problem-detectable-with-wireshark/</guid>
      <description>Modbus TCP/IP Problem detectable with WireShark?  0 Hello,
Here is my problem. In an industrial automation environment we have one Modbus Master system and serveral Modbus slave&#39;s (13 x PLC&#39;s/PC devices). Modbus communication is working, but frequently (twice per hour) we lose the connection to one of the devices (everytime a different device). This takes a couple of seconds (10-20 sec) and then the communication starts again. We can see that the frequency of missing the connection is related to the number of slaves active on the network.</description>
    </item>
    
    <item>
      <title>New user needs help identifying IP address to setup Ethernet Network</title>
      <link>/questions/15873/new-user-needs-help-identifying-ip-address-to-setup-ethernet-network/</link>
      <pubDate>Tue, 13 Nov 2012 08:22:00 +0000</pubDate>
      
      <guid>/questions/15873/new-user-needs-help-identifying-ip-address-to-setup-ethernet-network/</guid>
      <description>New user needs help identifying IP address to setup Ethernet Network  0 Please help me as I&#39;m fairly new to this type of thing. I have a Windows 7 laptop and I need to use a cross-over cable to connect to another device via FTP. I need to download firmware to the memory of that device. Any way, the FTP of that device is unknown. Can I use Wireshark to capture that IP address so that I can setup the ethernet network and then use my cross-over cable to connect and make the needed file transfer?</description>
    </item>
    
    <item>
      <title>GSM call trace script</title>
      <link>/questions/15878/gsm-call-trace-script/</link>
      <pubDate>Tue, 13 Nov 2012 10:47:00 +0000</pubDate>
      
      <guid>/questions/15878/gsm-call-trace-script/</guid>
      <description>GSM call trace script  0 i was wondering if someone has filter/script to capture GSM call trace with IMSI and MSISDN. would be great if you can share.
gsmasked 13 Nov &#39;12, 10:47
newbie29
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>HTTP transmission or not???</title>
      <link>/questions/15879/http-transmission-or-not/</link>
      <pubDate>Tue, 13 Nov 2012 13:34:00 +0000</pubDate>
      
      <guid>/questions/15879/http-transmission-or-not/</guid>
      <description>HTTP transmission or not???  0 I found a really weird statistics on wireshark. For a video transmission on Android I opened up the stats for protocol hierarchy, the stats shows that the 3MB video doesn&#39;t go through HTTP.
However, when I clicked &#34;save the objects&#34; , wireshard shows the 3MB as &#34;video/mp4&#34; through HTTP. (It&#39;s like it resembles the packages).
Now I&#39;m confused whether the video on Android is sent through HTTP or not.</description>
    </item>
    
    <item>
      <title>Wireshark filter for window size</title>
      <link>/questions/15885/wireshark-filter-for-window-size/</link>
      <pubDate>Wed, 14 Nov 2012 00:55:00 +0000</pubDate>
      
      <guid>/questions/15885/wireshark-filter-for-window-size/</guid>
      <description>Wireshark filter for window size  0 Hi. Is there a way to graph packets&#39; window size. What I want to do is to see how TCP stream&#39;s receive window size changes in the I/O graph. I&#39;m aware of the tcp.window_size and tcp.window_size_value filters but those just graph every packet that has any window size in the first place. Thanks.
-Rakki
filter window tcp sizeasked 14 Nov &#39;12, 00:55
rakki</description>
    </item>
    
    <item>
      <title>I want to  prepare High Level Design Doc and Low Level Design Doc for wireshark dissector.</title>
      <link>/questions/15889/i-want-to-prepare-high-level-design-doc-and-low-level-design-doc-for-wireshark-dissector/</link>
      <pubDate>Wed, 14 Nov 2012 01:44:00 +0000</pubDate>
      
      <guid>/questions/15889/i-want-to-prepare-high-level-design-doc-and-low-level-design-doc-for-wireshark-dissector/</guid>
      <description>I want to prepare High Level Design Doc and Low Level Design Doc for wireshark dissector.  0 What should i include in high and low level design documents. I am also looking for work flow diagram for dissector.
documentation designasked 14 Nov &#39;12, 01:44
Akhil
53●27●28●31
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Text2Pcap headers</title>
      <link>/questions/15890/text2pcap-headers/</link>
      <pubDate>Wed, 14 Nov 2012 02:08:00 +0000</pubDate>
      
      <guid>/questions/15890/text2pcap-headers/</guid>
      <description>Text2Pcap headers  0 Hi, I would like to know does text2pcap utility inserts dummy L2, L3 and L4 headers before each packet automatically or we need to provide the options like -i -e etc?
text2pcapasked 14 Nov &#39;12, 02:08
manojdeoli
1●5●5●6
accept rate: 0%
  
One Answer:
  
0Text2pcap doesn&#39;t do anything unless you tell it to. See its manual for details.
answered 14 Nov &#39;12, 04:17</description>
    </item>
    
    <item>
      <title>ftp data: sector erase failed</title>
      <link>/questions/15891/ftp-data-sector-erase-failed/</link>
      <pubDate>Wed, 14 Nov 2012 02:43:00 +0000</pubDate>
      
      <guid>/questions/15891/ftp-data-sector-erase-failed/</guid>
      <description>ftp data: sector erase failed  0 Hi All,
I see this string &#34;ftp data: sector erase failed&#34; in wireshark after which retransmission happen for the same serial number and finally FTP aborts with error 0x50c6480 &#34;(tFtpdServ1): sent 426 Data connection error&#34; Has anyone seen such an issue and resolved it??
Regards Sona
ftpasked 14 Nov &#39;12, 02:43
Sunita K
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>dissector for compressed RTP header</title>
      <link>/questions/15900/dissector-for-compressed-rtp-header/</link>
      <pubDate>Wed, 14 Nov 2012 05:40:00 +0000</pubDate>
      
      <guid>/questions/15900/dissector-for-compressed-rtp-header/</guid>
      <description>dissector for compressed RTP header  0 Ok, Here is another question. A thousand points to whoever can help me.
Lets say my protocol consist of only one byte. This byte indicates if this is a compressed RTP header or Uncompressed RTP header following.
Now, if it is a uncompressed header, I want to apply the rtp dissector. (which I now know, thank you Jaap)
However, if it is a compressed header, I want to add my own decoding (since there does not exist an dissector for rtp compressed)</description>
    </item>
    
    <item>
      <title>Capturing UDP packets affects network performance</title>
      <link>/questions/15901/capturing-udp-packets-affects-network-performance/</link>
      <pubDate>Wed, 14 Nov 2012 06:06:00 +0000</pubDate>
      
      <guid>/questions/15901/capturing-udp-packets-affects-network-performance/</guid>
      <description>Capturing UDP packets affects network performance  0 is it possible that Wireshark is slowing down my network application, when im sniffing udp packets?
down udp slow slowdownasked 14 Nov &#39;12, 06:06
alexg
1●1●1●2
accept rate: 0%
is Wireshark running on the same system as your &#34;network application&#34;? If so, the system resources that wireshark needs (CPU, RAM, disk) will be unavailable for your &#34;network application&#34; and then it might affect the performance of that application.</description>
    </item>
    
    <item>
      <title>Export Control</title>
      <link>/questions/15909/export-control/</link>
      <pubDate>Wed, 14 Nov 2012 10:39:00 +0000</pubDate>
      
      <guid>/questions/15909/export-control/</guid>
      <description>Export Control  0 Do you have an export control tag/data for the Wireshark product?
control exportasked 14 Nov &#39;12, 10:39
allybean2001
1●1●1●1
accept rate: 0%
  
One Answer:
  
2See http://www.wireshark.org/export.html
answered 14 Nov &#39;12, 11:15
Anders ♦
4.6k●9●52
accept rate: 17%
     </description>
    </item>
    
    <item>
      <title>Use telnet filter on arbitrary ports?</title>
      <link>/questions/15912/use-telnet-filter-on-arbitrary-ports/</link>
      <pubDate>Wed, 14 Nov 2012 13:49:00 +0000</pubDate>
      
      <guid>/questions/15912/use-telnet-filter-on-arbitrary-ports/</guid>
      <description>Use telnet filter on arbitrary ports?  0 Is it possible to apply Wireshark&#39;s telnet data filter to any ports other than 23? I&#39;ve been trying to analyse traffic to several non-standard ports and I haven&#39;t been able to get it working.
filter port telnetasked 14 Nov &#39;12, 13:49
rarkham
6●1●1●3
accept rate: 0%
  
One Answer:
  
3 You need to tell Wireshark, that the other port is to be decoded as telnet.</description>
    </item>
    
    <item>
      <title>Producing jitter values with tshark</title>
      <link>/questions/15913/producing-jitter-values-with-tshark/</link>
      <pubDate>Wed, 14 Nov 2012 14:15:00 +0000</pubDate>
      
      <guid>/questions/15913/producing-jitter-values-with-tshark/</guid>
      <description>Producing jitter values with tshark  0 Hi all, is it at all possible with tshark to scan a pcap file, and like the -z rtp,streams flag, find the RTP streams, and then output the jitter and delta values for each packet?
I basically want the same CSV that in wireshark you can get from telephony -&amp;gt; rtp -&amp;gt; Analysis -&amp;gt; save as CSV, but from tshark, I&#39;ll be using tshark in a script to produce RRD graphs for VOIP monitoring purposes.</description>
    </item>
    
    <item>
      <title>wireshark compile error after modification</title>
      <link>/questions/15918/wireshark-compile-error-after-modification/</link>
      <pubDate>Wed, 14 Nov 2012 19:19:00 +0000</pubDate>
      
      <guid>/questions/15918/wireshark-compile-error-after-modification/</guid>
      <description>wireshark compile error after modification  0 this is the error info, i intent to put a picture here, but the system tell me &#39;file uploading requires karma &amp;gt; 60&#39;,i don&#39;t know how to solve this, so i have to click all the following error info.uh, painful.
make[2]:Entering directory &amp;#39;/home/wireshark_dissect/wireshark-1.6.4-output-formated&amp;#39; /usr/bin/perl ./make-version.pl . Version configuration file version.conf not found. Using defaults. svnversion.h unchanged. cp tools/idl2wrs.sh idl2wrs chmod +x idl2wrs /usr/bin/perl .</description>
    </item>
    
    <item>
      <title>I want to test my dissector using the code coverage tool lcov</title>
      <link>/questions/15923/i-want-to-test-my-dissector-using-the-code-coverage-tool-lcov/</link>
      <pubDate>Thu, 15 Nov 2012 01:55:00 +0000</pubDate>
      
      <guid>/questions/15923/i-want-to-test-my-dissector-using-the-code-coverage-tool-lcov/</guid>
      <description>I want to test my dissector using the code coverage tool lcov  0 What are the steps for testing dissector using lcov?
test-questionasked 15 Nov &#39;12, 01:55
Akhil
53●27●28●31
accept rate: 0%
  
One Answer:
  
1 please read the following Wiki for a first idea.
http://wiki.wireshark.org/Development/CodeCoverage
Regards
Kurt
answered 15 Nov &#39;12, 02:43
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15% 
Thanks Kurt
(15 Nov &#39;12, 20:25) Akhil     </description>
    </item>
    
    <item>
      <title>How to export hex and timestamp</title>
      <link>/questions/15928/how-to-export-hex-and-timestamp/</link>
      <pubDate>Thu, 15 Nov 2012 06:42:00 +0000</pubDate>
      
      <guid>/questions/15928/how-to-export-hex-and-timestamp/</guid>
      <description>How to export hex and timestamp  0 Hi all,
I want to export raw hexadecimal values and timestamp of all my selected packets.
Unfortunately exporting as &#34;C arrays&#34; does not shows the timestamp and also includes quite annoying ASCII representation.
Moreover the exported file is not in a format like &#34;one packet per line&#34;. All this makes my life quite difficult trying to tokenize strings with sed and tr...</description>
    </item>
    
    <item>
      <title>Lua code broke after update to wireshark 1.8.3</title>
      <link>/questions/15933/lua-code-broke-after-update-to-wireshark-183/</link>
      <pubDate>Thu, 15 Nov 2012 11:49:00 +0000</pubDate>
      
      <guid>/questions/15933/lua-code-broke-after-update-to-wireshark-183/</guid>
      <description>Lua code broke after update to wireshark 1.8.3  -3 http://code.google.com/p/packet-bnetp/issues/detail?id=5
This code worked fine on wireshark 1.4.4 but crashes wireshark after update to 1.8.3.
How to fix it?Why the heck wireshark compelety crashes? Doesn&#39;t it walidate calls from lua wrapper? It should be too &#34;thin&#34; wrapper.lua crashasked 15 Nov &#39;12, 11:49
xpeh
-3●3●3●5
accept rate: 0%
2Nice comment you made on the issue you linked to.
Wireshark is GPL and the source is freely available for modification and improvement by anyone.</description>
    </item>
    
    <item>
      <title>Why is this connection hung up</title>
      <link>/questions/15941/why-is-this-connection-hung-up/</link>
      <pubDate>Thu, 15 Nov 2012 13:48:00 +0000</pubDate>
      
      <guid>/questions/15941/why-is-this-connection-hung-up/</guid>
      <description>Why is this connection hung up  0 Hello,
First of all, let me say that I am not network trained at all. So, I am in way over my head.
We have a server that a learner was accessing to take an assessment. The learner says that the assessment hung up and wouldn&#39;t do anything. I happened to be running some Wireshark captures at the time. I thought that I was figuring some stuff out, but I&#39;ve just been blown away.</description>
    </item>
    
    <item>
      <title>Interested in capturing wifi packets in promiscous mode on Windows?</title>
      <link>/questions/15948/interested-in-capturing-wifi-packets-in-promiscous-mode-on-windows/</link>
      <pubDate>Thu, 15 Nov 2012 17:02:00 +0000</pubDate>
      
      <guid>/questions/15948/interested-in-capturing-wifi-packets-in-promiscous-mode-on-windows/</guid>
      <description>Interested in capturing wifi packets in promiscous mode on Windows?  0 I am making a program that takes packets from one network source and sending it to receivers, also with other protocols.
It would in particular allow to see packets in wireshark on windows if you can capture it e.g. with Commview WiFi drivers (they support many cards with atheros chipset). Or capture packets in backtrack on VM with Windows as host OS (you can forward your network cart to the VM, but only if it&#39;s a USB device and you are using VMWare VM).</description>
    </item>
    
    <item>
      <title>Which software can capture data in monitor mode on Windows?</title>
      <link>/questions/15949/which-software-can-capture-data-in-monitor-mode-on-windows/</link>
      <pubDate>Thu, 15 Nov 2012 17:15:00 +0000</pubDate>
      
      <guid>/questions/15949/which-software-can-capture-data-in-monitor-mode-on-windows/</guid>
      <description>Which software can capture data in monitor mode on Windows?  0 Let&#39;s make a list.
CommView Wifi - supports Atheros chipsets.
Microsoft Network Monitor - supports &amp;lt;unknown&amp;gt;
%your suggestion%
windows promiscuous-modeasked 15 Nov &#39;12, 17:15
xpeh
-3●3●3●5
accept rate: 0%
 edited 16 Nov &#39;12, 00:15 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
2 Wireshark - with AirPCap adaptor
answered 16 Nov &#39;12, 00:17</description>
    </item>
    
    <item>
      <title>SMB &amp;amp; 0xC0000035 STATUS_OBJECT_NAME_COLLISION</title>
      <link>/questions/15954/smb-0xc0000035-status_object_name_collision/</link>
      <pubDate>Fri, 16 Nov 2012 02:02:00 +0000</pubDate>
      
      <guid>/questions/15954/smb-0xc0000035-status_object_name_collision/</guid>
      <description>SMB &amp;amp; 0xC0000035 STATUS_OBJECT_NAME_COLLISION  0 Hi,
I did spot this error thanks to wireshark but i dont have a clue of what the hell i can do to make this error to disapear.
It was a copy of a file from a src to a dst and when trying to copy it, got this error telling me that the file name already exist.
So what ? This is R/W. Can&#39;t he write over it.</description>
    </item>
    
    <item>
      <title>Where can i find the executable file of wireshark in wireshark directory?</title>
      <link>/questions/15955/where-can-i-find-the-executable-file-of-wireshark-in-wireshark-directory/</link>
      <pubDate>Fri, 16 Nov 2012 02:08:00 +0000</pubDate>
      
      <guid>/questions/15955/where-can-i-find-the-executable-file-of-wireshark-in-wireshark-directory/</guid>
      <description>Where can i find the executable file of wireshark in wireshark directory?  0 I my testing my dissector using kcahegrind. For testing i need executable file.
testingasked 16 Nov &#39;12, 02:08
Akhil
53●27●28●31
accept rate: 0%
  
3 Answers:
  
1LOL search for wireshark.exe ffs -.-
answered 16 Nov &#39;12, 02:16
gateau
16●1●1●2
accept rate: 0%
didn&#39;t find wireshark.exe
I found wireshark.exe.manifest.in
are both same</description>
    </item>
    
    <item>
      <title>Sniffing IPMI packets using a Beagle i2c USB adapter under Ubuntu</title>
      <link>/questions/15962/sniffing-ipmi-packets-using-a-beagle-i2c-usb-adapter-under-ubuntu/</link>
      <pubDate>Fri, 16 Nov 2012 05:05:00 +0000</pubDate>
      
      <guid>/questions/15962/sniffing-ipmi-packets-using-a-beagle-i2c-usb-adapter-under-ubuntu/</guid>
      <description>Sniffing IPMI packets using a Beagle i2c USB adapter under Ubuntu  0 Hello everybody,
I&#39;m trying to read IPMI packets transmitted by two devices under Ubuntu Environment. I have physical access to the i2c bus to which I connect using a Beagle i2c usb adapter by TotalPhase. The i2c monitor application is correctly configured (usb udev). What I want to do now is to make Wireshark communicating with the Beagle to read IPMI commands on the bus.</description>
    </item>
    
    <item>
      <title>Matching HTTP traffic to TCP</title>
      <link>/questions/15969/matching-http-traffic-to-tcp/</link>
      <pubDate>Fri, 16 Nov 2012 08:16:00 +0000</pubDate>
      
      <guid>/questions/15969/matching-http-traffic-to-tcp/</guid>
      <description>Matching HTTP traffic to TCP  0 I&#39;ve a hunt for an answer to this question but can&#39;t find it...
I&#39;ve got a pcap for a webpage loading and I want to match the HTTP requests to TCP conversations
The HTTP requests have a cookie that&#39;s larger than the TCP segment size and I want to check whether the client is waiting for an ACK before sending the rest of the HTTP request.</description>
    </item>
    
    <item>
      <title>How do I save one VOIP call easily?</title>
      <link>/questions/15971/how-do-i-save-one-voip-call-easily/</link>
      <pubDate>Fri, 16 Nov 2012 08:45:00 +0000</pubDate>
      
      <guid>/questions/15971/how-do-i-save-one-voip-call-easily/</guid>
      <description>How do I save one VOIP call easily?  0 I use tcpdump to capture traffic from my asterisk server that has multiple simultaneous calls on it at the same time. When I use wireshark I can easily listen to one call by clicking Telephony -&amp;gt; Voip calls.
But when I want to take that one call and save it as it&#39;s own stream, I continually have problems. It&#39;s not easy.</description>
    </item>
    
    <item>
      <title>linux non-root question</title>
      <link>/questions/15974/linux-non-root-question/</link>
      <pubDate>Fri, 16 Nov 2012 10:24:00 +0000</pubDate>
      
      <guid>/questions/15974/linux-non-root-question/</guid>
      <description>linux non-root question  0 how do you configure a linux install to allow non-root users priviledges
linux-supportasked 16 Nov &#39;12, 10:24
newton3
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Running Wireshark as you is a nice start.
For Debian users, look here.
answered 16 Nov &#39;12, 12:10
Jaap ♦
11.7k●16●101
accept rate: 14%
     </description>
    </item>
    
    <item>
      <title>sample capture for EGP</title>
      <link>/questions/15975/sample-capture-for-egp/</link>
      <pubDate>Fri, 16 Nov 2012 11:13:00 +0000</pubDate>
      
      <guid>/questions/15975/sample-capture-for-egp/</guid>
      <description>sample capture for EGP  0 hello I thank you very much for your good site Excuse me, I need a sample capture for EGP routing protocl, to make this porotocol to give to my college for a exercise project please if you can, give me a sample capture of this protocol to see it&#39;s structure thank you a lot
sample capture egp protocolasked 16 Nov &#39;12, 11:13
simineh
1●2●2●2</description>
    </item>
    
    <item>
      <title>SSL Dissector - TLSv1 versus SSL</title>
      <link>/questions/15995/ssl-dissector-tlsv1-versus-ssl/</link>
      <pubDate>Fri, 16 Nov 2012 16:40:00 +0000</pubDate>
      
      <guid>/questions/15995/ssl-dissector-tlsv1-versus-ssl/</guid>
      <description>SSL Dissector - TLSv1 versus SSL  1 I have two separate PCAP files. Both of these PCAP files contain a ClientHello of protocol TLS version 1.0.
How come one of the captures says the ClientHello packet is &#34;SSL&#34; protocol, and the other capture says the ClientHello is &#34;TLSv1&#34; protocol?
tls sslasked 16 Nov &#39;12, 16:40
shauer
16●1●1●2
accept rate: 0%
can you post those two conversations on cloudshark.org (or similar)?</description>
    </item>
    
    <item>
      <title>slow response while copying</title>
      <link>/questions/15998/slow-response-while-copying/</link>
      <pubDate>Fri, 16 Nov 2012 20:20:00 +0000</pubDate>
      
      <guid>/questions/15998/slow-response-while-copying/</guid>
      <description>slow response while copying  0 Hello, I am copy a file from the server (10.10.10.1) to my PC (10.10.20.1). The connection between the server and my PC is through the MPLS could. It took me more than 14 hours to copy the file (300MB). That is not right. I am using Wireshark to capture the traffic but I am not sure what I am looking at because I do not see any TCP handshakes.</description>
    </item>
    
    <item>
      <title>stream number for udp</title>
      <link>/questions/15999/stream-number-for-udp/</link>
      <pubDate>Sat, 17 Nov 2012 00:15:00 +0000</pubDate>
      
      <guid>/questions/15999/stream-number-for-udp/</guid>
      <description>stream number for udp  0 i want to ask the wireshark developers if there is any plan to add the udp stream numbers like we have for tcp streams. and was there any specific reason to use stream numbers only for tcp ?
tshark wiresharkasked 17 Nov &#39;12, 00:15
viks
16●4●4●7
accept rate: 0%
  
One Answer:
  
0Since TCP is a connection orientated protocol with a distinctive session start and end, it is possible to determine which session/stream a packet belongs to by looking at the TCP headers alone.</description>
    </item>
    
    <item>
      <title>Iam a newbie</title>
      <link>/questions/16006/iam-a-newbie/</link>
      <pubDate>Sun, 18 Nov 2012 04:46:00 +0000</pubDate>
      
      <guid>/questions/16006/iam-a-newbie/</guid>
      <description>Iam a newbie  0 How can I captuer ping, tracert, arp, dhcp please help iam newbie ( and iam using laptop wifi)
capturesasked 18 Nov &#39;12, 04:46
Blzs
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Compiling problem installing a dissector plugin to wireshark</title>
      <link>/questions/16009/compiling-problem-installing-a-dissector-plugin-to-wireshark/</link>
      <pubDate>Sun, 18 Nov 2012 07:30:00 +0000</pubDate>
      
      <guid>/questions/16009/compiling-problem-installing-a-dissector-plugin-to-wireshark/</guid>
      <description>Compiling problem installing a dissector plugin to wireshark  1 Hello,
I need to add an available dissector plugin (called IPMB) to wireshark.
In order to do it I&#39;m following the README.plugin procedure. Since the plugin source files are given, I just make the suggested modifications to the Makefile.am, Cmaketlist.txt etc... Then, from the wireshark source directory I execute:
./autogen.sh ./configure make
The compiling process correctly starts but after a while I get this error concerning the new plugin directory:</description>
    </item>
    
    <item>
      <title>Capture cell phone text messages with Wireshark?</title>
      <link>/questions/16010/capture-cell-phone-text-messages-with-wireshark/</link>
      <pubDate>Sun, 18 Nov 2012 08:13:00 +0000</pubDate>
      
      <guid>/questions/16010/capture-cell-phone-text-messages-with-wireshark/</guid>
      <description>Capture cell phone text messages with Wireshark?  0 Is it possible to capture cell phone text messages with Wireshark if they are connected to the wire less?
texting sms captureasked 18 Nov &#39;12, 08:13
tranqmorne
1●1●1●1
accept rate: 0%
  
One Answer:
  
0not if they&#39;re cellular messages (SMS), because they are transfered via GSM/UMTs etc. You can probably capture stuff like WhatsApp messages, but they should be encrypted in most cases.</description>
    </item>
    
    <item>
      <title>IP based transfer</title>
      <link>/questions/16012/ip-based-transfer/</link>
      <pubDate>Sun, 18 Nov 2012 09:52:00 +0000</pubDate>
      
      <guid>/questions/16012/ip-based-transfer/</guid>
      <description>IP based transfer  0 Anyone have any ideas on analyzing a purely IP based transfer? I&#39;m analyzing a trace file supposedly of a low throughput for replication over the WAN. The trace only show IP with no TCP so I&#39;m not sure what flags to look for. I believe the customer is using a Brocade storage router.
Screenshot
ipasked 18 Nov &#39;12, 09:52
ws2006
1●12●12●14
accept rate: 0%
 edited 18 Nov &#39;12, 14:14</description>
    </item>
    
    <item>
      <title>Not able to connect my ITI modem</title>
      <link>/questions/16013/not-able-to-connect-my-iti-modem/</link>
      <pubDate>Sun, 18 Nov 2012 10:41:00 +0000</pubDate>
      
      <guid>/questions/16013/not-able-to-connect-my-iti-modem/</guid>
      <description>Not able to connect my ITI modem  0 HI Team ,
how can i connect wireshark with ITI modem to get the network sta. to check network utilazation.
Thanks Dev
modem itiThis question is marked &#34;community wiki&#34;.asked 18 Nov &#39;12, 10:41
devanshumathur
1●1●1●1
accept rate: 0%
 edited 22 Nov &#39;12, 10:20 
Guy Harris ♦♦
17.4k●3●35●196
can you please add some details?
what is an &#34;ITI modem&#34;?how is the modem related to Wireshark?</description>
    </item>
    
    <item>
      <title>Problems with WiFi</title>
      <link>/questions/16023/problems-with-wifi/</link>
      <pubDate>Sun, 18 Nov 2012 14:33:00 +0000</pubDate>
      
      <guid>/questions/16023/problems-with-wifi/</guid>
      <description>Problems with WiFi  0 Posted on Petri but just thought might be worth giving it a shot here. Suddenly my laptop connected to my home WiFi stopped displaying websites. The thing is I can still ping both external IPs and urls. I tried system restore in case some update affected my NIC, deleted temporary internet files, reset my AP to factory and reconfigured, enabled WiFi on my router and tested with that to no avail, updated the driver from manufacturer&#39;s web site, scanned the laptop with Malwarebytes, disabled the firewall and run in safe mode with networking.</description>
    </item>
    
    <item>
      <title>Global variable misused in the code</title>
      <link>/questions/16029/global-variable-misused-in-the-code/</link>
      <pubDate>Sun, 18 Nov 2012 18:54:00 +0000</pubDate>
      
      <guid>/questions/16029/global-variable-misused-in-the-code/</guid>
      <description>Global variable misused in the code  0 Two days ago i got this problem when i add a global varible to the original wireshark source code, it tells me there is a compile error like this:
in load_cap_file: tshark.c:2585: undefined reference to &#39;fp&#39;, tshark.c:2840:undefined reference to &#39;fp&#39; ... recursive error ....
Infact, i just add a global varible FILE* fp=NULL；in the file packet.c, and then extern FILE* fp; in the tshark.</description>
    </item>
    
    <item>
      <title>What is the job of auto generated file plugin.c in plugin/amf folder?</title>
      <link>/questions/16032/what-is-the-job-of-auto-generated-file-pluginc-in-pluginamf-folder/</link>
      <pubDate>Sun, 18 Nov 2012 21:48:00 +0000</pubDate>
      
      <guid>/questions/16032/what-is-the-job-of-auto-generated-file-pluginc-in-pluginamf-folder/</guid>
      <description>What is the job of auto generated file plugin.c in plugin/amf folder?  0 I am writing a plugin for amf. The following file is auto generated.
--------8&amp;lt;-------------------------------------------------------------- /* * Do not modify this file. * * It is created automatically by Makefile or Makefile.nmake. */ #ifdef HAVE_CONFIG_H
include &amp;quot;config.h&amp;quot; #endif
#include &amp;lt;gmodule.h&amp;gt;
#include &amp;quot;moduleinfo.h&amp;quot;
#ifndef ENABLE_STATIC G_MODULE_EXPORT const gchar version[] = VERSION;
/* Start the functions we need for the plugin stuff */</description>
    </item>
    
    <item>
      <title>TCP Window Updates</title>
      <link>/questions/16039/tcp-window-updates/</link>
      <pubDate>Mon, 19 Nov 2012 01:14:00 +0000</pubDate>
      
      <guid>/questions/16039/tcp-window-updates/</guid>
      <description>TCP Window Updates  0 Hi,
I have a case example of a connection that I thought would be a great way to start learning Wireshark. However I have a number of questions.
First of the issue is when trying to download an image from a webserver it takes an extremely long time. This connection is however going through an F5. If : I download the image directly from the server it is fine.</description>
    </item>
    
    <item>
      <title>Getting list of interfaces - problem</title>
      <link>/questions/16042/getting-list-of-interfaces-problem/</link>
      <pubDate>Mon, 19 Nov 2012 02:08:00 +0000</pubDate>
      
      <guid>/questions/16042/getting-list-of-interfaces-problem/</guid>
      <description>Getting list of interfaces - problem  0 Hi, i have a problem with versions 1.6.11 and 1.8.3, i am trying to get the list of the interfaces and instead of getting the list to standard output, i get it on the std error. I don&#39;t have this error on version 1.4.1 and it is works with the same code. Thanks My code:
 ProcessStartInfo startInfo = new ProcessStartInfo(m_sTsharkPath); startInfo.Arguments = &amp;quot;-D&amp;quot;; startInfo.</description>
    </item>
    
    <item>
      <title>Error during plugin compilation.</title>
      <link>/questions/16043/error-during-plugin-compilation/</link>
      <pubDate>Mon, 19 Nov 2012 02:15:00 +0000</pubDate>
      
      <guid>/questions/16043/error-during-plugin-compilation/</guid>
      <description>Error during plugin compilation.  0 I am getting the following error during compilation:::::::: undefined reference to `proto_register_amf&#39;
how should I fix it?
errorasked 19 Nov &#39;12, 02:15
Akhil
53●27●28●31
accept rate: 0%
 edited 19 Nov &#39;12, 02:15 
   </description>
    </item>
    
    <item>
      <title>Changing log times using tshark</title>
      <link>/questions/16044/changing-log-times-using-tshark/</link>
      <pubDate>Mon, 19 Nov 2012 02:20:00 +0000</pubDate>
      
      <guid>/questions/16044/changing-log-times-using-tshark/</guid>
      <description>Changing log times using tshark  0 Hi all,
I have been running tshark on a clean ubuntu server for a few weeks, but i&#39;ve noticed something odd in the timestamps of each logfile, while i setup the duration to be each hour..
for example:
Nov 19 04:05 example1.cap
Nov 19 05:05 example2.cap
Nov 19 06:05 example3.cap
Nov 19 08:59 example4.cap
Nov 19 09:59 example5.cap
As can be seen there´s a time gap between example3.</description>
    </item>
    
    <item>
      <title>RTMPT plugin shows RTMPT chunk data not RTMPT data? Is de-chunking implemented in RTMPT dissector ??</title>
      <link>/questions/16045/rtmpt-plugin-shows-rtmpt-chunk-data-not-rtmpt-data-is-de-chunking-implemented-in-rtmpt-dissector/</link>
      <pubDate>Mon, 19 Nov 2012 02:23:00 +0000</pubDate>
      
      <guid>/questions/16045/rtmpt-plugin-shows-rtmpt-chunk-data-not-rtmpt-data-is-de-chunking-implemented-in-rtmpt-dissector/</guid>
      <description>RTMPT plugin shows RTMPT chunk data not RTMPT data? Is de-chunking implemented in RTMPT dissector ??  0 RTMPT plugin only shows chuncked data , it doesn&#39;t show un-chuncked data. ALL headers which it shows are chuncked data header not RTMPT headers. Is de-chuncking implemented in dissector or is their any way i can see RTMPT de-chuncked packed in dissector ?
rtmptasked 19 Nov &#39;12, 02:23
ishan
1●2●2●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>SNMP request/response  not appearing on wireshark</title>
      <link>/questions/16047/snmp-requestresponse-not-appearing-on-wireshark/</link>
      <pubDate>Mon, 19 Nov 2012 02:41:00 +0000</pubDate>
      
      <guid>/questions/16047/snmp-requestresponse-not-appearing-on-wireshark/</guid>
      <description>SNMP request/response not appearing on wireshark  0 Hello,
In my application, I am sending SNMP GET requests to multiple SNMP devices. Randomly for some of the devices, I am not getting the SNMP GET response. I looked at the wireshark capture and it contained SNMP request/response for those devices for which the SNMP response was received successfully. For the devices for which SNMP response was not received, wireshark capture does not even show any SNMP GET request.</description>
    </item>
    
    <item>
      <title>.pcap parse question:  &amp;quot;len&amp;quot; verses &amp;quot;length&amp;quot;?</title>
      <link>/questions/16050/pcap-parse-question-len-verses-length/</link>
      <pubDate>Mon, 19 Nov 2012 05:45:00 +0000</pubDate>
      
      <guid>/questions/16050/pcap-parse-question-len-verses-length/</guid>
      <description>.pcap parse question: &amp;ldquo;len&amp;rdquo; verses &amp;ldquo;length&amp;rdquo;?  0 I am writing a Delphi (Pascal) app that will do some custom parsing of a .pcap file. The .pcap file is written by Wireshare/winpcap. I found C++ sample code for parsing the .pcap file, and I converted the C++ structs to Delphi records. And I&#39;ve got my app mostly done. But, one thing that I&#39;m just not getting...
The headers for the Ethernet header, IP header and TCP header comes out to 54 bytes, assuming of course the packet in question is an Ethernet TCP/IP packet.</description>
    </item>
    
    <item>
      <title>Why data transfer gets capped around 37k?</title>
      <link>/questions/16052/why-data-transfer-gets-capped-around-37k/</link>
      <pubDate>Mon, 19 Nov 2012 07:27:00 +0000</pubDate>
      
      <guid>/questions/16052/why-data-transfer-gets-capped-around-37k/</guid>
      <description>Why data transfer gets capped around 37k?  1 I am running UltraVNC on windows 7 as server and Mac OSX as client. I have connected them to the same network so effective latency was zero but to simulate real life like conditions, I introduced a latency of 100ms using ipfw on Mac.
Now the performance was really bad and I took a dump which is uploaded at cloudshark.org. I saw that the data transfer gets capped at about 37 kilobytes per 100ms in this graph.</description>
    </item>
    
    <item>
      <title>How to know the sender of the ACK</title>
      <link>/questions/16059/how-to-know-the-sender-of-the-ack/</link>
      <pubDate>Mon, 19 Nov 2012 09:34:00 +0000</pubDate>
      
      <guid>/questions/16059/how-to-know-the-sender-of-the-ack/</guid>
      <description>How to know the sender of the ACK  0 I&#39;d like to know the sender of the ACK received.
I mean, if the ACK received is from the layer itself (TCP, etc..) or from the server I&#39;ve just contacted (e.g. they received the package, and they sent me an ACK confirming they received it.)
In the ACK data, how can I know this kind of information. Could it be the source port?</description>
    </item>
    
    <item>
      <title>Can I benefit from Lua API to make an intrusion detection?</title>
      <link>/questions/16075/can-i-benefit-from-lua-api-to-make-an-intrusion-detection/</link>
      <pubDate>Mon, 19 Nov 2012 11:04:00 +0000</pubDate>
      
      <guid>/questions/16075/can-i-benefit-from-lua-api-to-make-an-intrusion-detection/</guid>
      <description>Can I benefit from Lua API to make an intrusion detection?  0 Hi, Can I benefit from the Lua API to make a program that make kind of intrusion detection in real time, by running a lua program that filters specific packets,extract some fields from them and make some process on them to detect some cases of intrusion, could this be a working idea???
luaasked 19 Nov &#39;12, 11:04</description>
    </item>
    
    <item>
      <title>I want to deploy my amf plugin on another machine.</title>
      <link>/questions/16093/i-want-to-deploy-my-amf-plugin-on-another-machine/</link>
      <pubDate>Mon, 19 Nov 2012 22:44:00 +0000</pubDate>
      
      <guid>/questions/16093/i-want-to-deploy-my-amf-plugin-on-another-machine/</guid>
      <description>I want to deploy my amf plugin on another machine.  0 What are the steps of deploying plugin on linux and windows?
Where can i find the binary executable of my plugin?
deployasked 19 Nov &#39;12, 22:44
Akhil
53●27●28●31
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Bytes in Flight more than the size of tcp window.</title>
      <link>/questions/16103/bytes-in-flight-more-than-the-size-of-tcp-window/</link>
      <pubDate>Tue, 20 Nov 2012 03:38:00 +0000</pubDate>
      
      <guid>/questions/16103/bytes-in-flight-more-than-the-size-of-tcp-window/</guid>
      <description>Bytes in Flight more than the size of tcp window.  0 I have a situation where the server is Mac OS X and client is windows 7. The dump is taken on windows machine. I see that the negotiated window size is 32k (see syn packets) on both windows and mac but the bytes in flight are much more than that. Same is reported by cloudshark&#39;s graphs of data/time. In this case the tcp send and receive buffers were set at default on both windows and mac.</description>
    </item>
    
    <item>
      <title>no capture mpls frame</title>
      <link>/questions/16112/no-capture-mpls-frame/</link>
      <pubDate>Tue, 20 Nov 2012 05:58:00 +0000</pubDate>
      
      <guid>/questions/16112/no-capture-mpls-frame/</guid>
      <description>no capture mpls frame  0 Hello
I have a network for testing MPLS protocol.(PC-Switch-RouterLER1-Sw-LSR1-Sw-RLSR2-sw-RLER2-sw-PC) I have monitoring each segment to see MPLS label with Wireshark.
Last year this pratice operate!
This year Wireshark capture packet except the frame with MPLS label.
How configure Wireshark to capture frame with MPLS?
Christophe Varin
mplsasked 20 Nov &#39;12, 05:58
Christophe85
6●1●1●2
accept rate: 0%
 edited 20 Nov &#39;12, 06:27 
Jaap ♦</description>
    </item>
    
    <item>
      <title>pcap to txt</title>
      <link>/questions/16113/pcap-to-txt/</link>
      <pubDate>Tue, 20 Nov 2012 06:19:00 +0000</pubDate>
      
      <guid>/questions/16113/pcap-to-txt/</guid>
      <description>pcap to txt  0 Hi !
If pcap can be converted to txt by using: &#34;tshark -V -r original.pcap &amp;gt; file_to_convert.txt&#34; and pcap can be converted to txt: &#34;text2pcap.exe -e 0x800 file_to_convert.txt result.pcap&#34;, why does the resulted file have a different dimension from the original one?
Is there something that I could change in order to make it right ?
Thank you !
convert txt pcap conversion wiresharkasked 20 Nov &#39;12, 06:19</description>
    </item>
    
    <item>
      <title>Is sender&amp;#x27;s send buffer throttled by tcp?</title>
      <link>/questions/16120/is-senders-send-buffer-throttled-by-tcp/</link>
      <pubDate>Tue, 20 Nov 2012 08:51:00 +0000</pubDate>
      
      <guid>/questions/16120/is-senders-send-buffer-throttled-by-tcp/</guid>
      <description>Is sender&amp;rsquo;s send buffer throttled by tcp?  0 I have a situation where the client is Ubuntu 12.04 and Mac OS X is the server. Now I took some dumps and saw that even when Linux is ready to receive more data, mac is not sending it. Note that the recv buffers of both Linux and Mac are enough to handle bigger amount of data.
In all scenarios, I am sure that mac always has more data to send then why is it not sending even when Bytes in flight is less than the receive window size of Linux.</description>
    </item>
    
    <item>
      <title>Excessive ARP requests from one PC</title>
      <link>/questions/16137/excessive-arp-requests-from-one-pc/</link>
      <pubDate>Tue, 20 Nov 2012 16:13:00 +0000</pubDate>
      
      <guid>/questions/16137/excessive-arp-requests-from-one-pc/</guid>
      <description>Excessive ARP requests from one PC  0 I am fairly new at this so any extra information that may help me learn is appreciated.
My laptop (which Wireshark is running on) seems to be sending a lot of ARP requests. It seems to be starting at 10.0.0.1 and runs all the way through to 10.0.0.255, asking about each ip multiple times. After it finishes it will stop for something like 15 seconds before starting over again.</description>
    </item>
    
    <item>
      <title>Set Headers Placed in Invite Packet?</title>
      <link>/questions/16138/set-headers-placed-in-invite-packet/</link>
      <pubDate>Tue, 20 Nov 2012 21:52:00 +0000</pubDate>
      
      <guid>/questions/16138/set-headers-placed-in-invite-packet/</guid>
      <description>Set Headers Placed in Invite Packet?  0 I formed the sip servlet request, for this request i created setHeader, in wireshark Invite packet I verified the set header but there was no content named as header.
how to verify the formed setHeader in Invite Packet?
headers setasked 20 Nov &#39;12, 21:52
Dinesh babu
1●1●1●2
accept rate: 0%
Is this a Wireshark question or a question regarding the SIP library you use?</description>
    </item>
    
    <item>
      <title>&amp;quot;Capture session could not be initiated&amp;quot;, but then it can be</title>
      <link>/questions/16139/capture-session-could-not-be-initiated-but-then-it-can-be/</link>
      <pubDate>Tue, 20 Nov 2012 22:09:00 +0000</pubDate>
      
      <guid>/questions/16139/capture-session-could-not-be-initiated-but-then-it-can-be/</guid>
      <description>&amp;ldquo;Capture session could not be initiated&amp;rdquo;, but then it can be  0 I&#39;m using wireshark 1.6.7 on Linux Mint 13 &#34;Maya&#34; Xfce on an old Dell 23 bit PC. The Wifi harward is a Linksys USB Wifi adapter (WUSB600N).
First, I run airmon-ng in a terminal session to create the mon0 device that is in monitor mode. Then I run wireshark (not as root because I set unix capabilities for dumpcap).</description>
    </item>
    
    <item>
      <title>Wireshark capture displays inner IP when traffic is IPinIP</title>
      <link>/questions/16140/wireshark-capture-displays-inner-ip-when-traffic-is-ipinip/</link>
      <pubDate>Tue, 20 Nov 2012 22:26:00 +0000</pubDate>
      
      <guid>/questions/16140/wireshark-capture-displays-inner-ip-when-traffic-is-ipinip/</guid>
      <description>Wireshark capture displays inner IP when traffic is IPinIP  0 Hello All,
The traffic captured is Ethernet/IP/IP It is basically a IP in IP packets.
But when I viewed the captured file, I observed the Inner IP displayed in the Upper Pane of the Wireshark capture screen.
I think this is a bug ... It should display outer Ip because that is important than inner IP. Please let us know if there is a way to view the packets based on outer IP.</description>
    </item>
    
    <item>
      <title>wireshark VoIP Call</title>
      <link>/questions/16141/wireshark-voip-call/</link>
      <pubDate>Tue, 20 Nov 2012 22:41:00 +0000</pubDate>
      
      <guid>/questions/16141/wireshark-voip-call/</guid>
      <description>wireshark VoIP Call  0 Hello. What does the yellow line on the screenshot?
voipasked 20 Nov &#39;12, 22:41
anso02
1●1●1●1
accept rate: 0%
  
One Answer:
  
2See this question.
answered 20 Nov &#39;12, 23:32
Jaap ♦
11.7k●16●101
accept rate: 14%
thank you.
(20 Nov &#39;12, 23:49) anso02If this answers your question then, as per QA etiquette, please click the check
(21 Nov &#39;12, 04:19) Jaap ♦     </description>
    </item>
    
    <item>
      <title>Develop a SIP&amp;amp;RTP display filter</title>
      <link>/questions/16154/develop-a-siprtp-display-filter/</link>
      <pubDate>Wed, 21 Nov 2012 04:27:00 +0000</pubDate>
      
      <guid>/questions/16154/develop-a-siprtp-display-filter/</guid>
      <description>Develop a SIP&amp;amp;RTP display filter  0 Hi,
I&#39;m trying to find out the way to make a display filter that includes two different, but related, protocols. I mean, SIP messages contains information about RTP ports. What I am doing now is:
Filter a SIP flowAnalyse which ports RTP is usingAdd this information to the display filterFilter again.I&#39;d like to develop a filter to do it automatically but I&#39;ve seen nothing similar.</description>
    </item>
    
    <item>
      <title>Wireshark plugin binary compatibility in Linux</title>
      <link>/questions/16155/wireshark-plugin-binary-compatibility-in-linux/</link>
      <pubDate>Wed, 21 Nov 2012 05:20:00 +0000</pubDate>
      
      <guid>/questions/16155/wireshark-plugin-binary-compatibility-in-linux/</guid>
      <description>Wireshark plugin binary compatibility in Linux  0 Suppose I create a Wireshark plugin in Ubuntu (say version 12.04, but I would prefer an answer for any general system), how compatible will it be across all Wireshark versions in different Linux platforms like Fedora, Mint, etc?
Also, could it possibly be compatible with Wireshark in older versions of Ubuntu like 11.04?
linux binary_compatibility pluginsasked 21 Nov &#39;12, 05:20
SidR
245●12●17●22</description>
    </item>
    
    <item>
      <title>Soap Messages Not Decrypted</title>
      <link>/questions/16163/soap-messages-not-decrypted/</link>
      <pubDate>Wed, 21 Nov 2012 08:44:00 +0000</pubDate>
      
      <guid>/questions/16163/soap-messages-not-decrypted/</guid>
      <description>Soap Messages Not Decrypted  0 Hello,
A little context, I&#39;m viewing the packet capture of a web service call, and the web service uses SSL. Service request/response is standard SOAP message.
Question is, why is it that when I add my key file to Wireshark(via Preferences --&amp;gt; SSL Protocol, which is a .p12 with both the private and public keys) that when I choose to &#34;Follow SSL Stream&#34; I can see the Soap request decrypted, but the response is still encrypted?</description>
    </item>
    
    <item>
      <title>Tshark, missing answer domain name in display filter for PTR records</title>
      <link>/questions/16167/tshark-missing-answer-domain-name-in-display-filter-for-ptr-records/</link>
      <pubDate>Wed, 21 Nov 2012 09:21:00 +0000</pubDate>
      
      <guid>/questions/16167/tshark-missing-answer-domain-name-in-display-filter-for-ptr-records/</guid>
      <description>Tshark, missing answer domain name in display filter for PTR records  0 OS: Ubuntu 10.04.4 LTS Tshark: 1.2.7
I&#39;m trying to sniff all DNS traffic and output queries and answers to a text file for parsing. All queries for &#39;A&#39; records return the needed information: response name, address and ttl. Queries for PTR records do not display all fields (the fields dns.resp.addr, dns.resp.name, and dns.resp.primaryname return no values).
What can be done to output the info to a text file?</description>
    </item>
    
    <item>
      <title>Need help decoding network traffic.</title>
      <link>/questions/16169/need-help-decoding-network-traffic/</link>
      <pubDate>Wed, 21 Nov 2012 09:25:00 +0000</pubDate>
      
      <guid>/questions/16169/need-help-decoding-network-traffic/</guid>
      <description>Need help decoding network traffic.  -1 Due to not expose my question here, and the fact that google has snapped up this, I&#39;m removing what was written here just in case my research would be snapped up and used by my classmates.
I don&#39;t know how to delete an entire question, so I&#39;m doing it this way.
If this is not allowed, I could post my original question here again.</description>
    </item>
    
    <item>
      <title>wireshark not seeing packets</title>
      <link>/questions/16177/wireshark-not-seeing-packets/</link>
      <pubDate>Wed, 21 Nov 2012 12:40:00 +0000</pubDate>
      
      <guid>/questions/16177/wireshark-not-seeing-packets/</guid>
      <description>wireshark not seeing packets  0 First off I only use wireless so when selecting the network card there is only one that has traffic on it (pretty sure Im not selecting the wrong one with such limited options).
Next I will fill in a filter options (usually by port):
tcp.port == 23
Then I use the terminal (Mac 10.8) to open a telnet session
But I see no traffic. If I turn off the filter I see traffic but no way to see (if they are there) my telnet traffic</description>
    </item>
    
    <item>
      <title>how to find previous frame in dissector</title>
      <link>/questions/16183/how-to-find-previous-frame-in-dissector/</link>
      <pubDate>Wed, 21 Nov 2012 15:01:00 +0000</pubDate>
      
      <guid>/questions/16183/how-to-find-previous-frame-in-dissector/</guid>
      <description>how to find previous frame in dissector  0 I&#39;m extending the radiotap dissector to calculate the inter frame space since the previous frame, so I need to reference the previous frame in the dissector. What is the correct way to do this? I&#39;m currently using a global reference to cfile, and call to frame_data_sequence_find, but this global reference is a problem at link time.
cfile search dissectorasked 21 Nov &#39;12, 15:01</description>
    </item>
    
    <item>
      <title>how do i add a new conversation type</title>
      <link>/questions/16184/how-do-i-add-a-new-conversation-type/</link>
      <pubDate>Wed, 21 Nov 2012 15:03:00 +0000</pubDate>
      
      <guid>/questions/16184/how-do-i-add-a-new-conversation-type/</guid>
      <description>how do i add a new conversation type  0 Where do I need to add code to do this?
conversation developerasked 21 Nov &#39;12, 15:03
protocolmagic
1●3●3●4
accept rate: 0%
You need to be more specific about wht you are trying to do. What do you mean by new conversation type?
(22 Nov &#39;12, 07:17) Anders ♦I have made a patch to the 802.11 dissector to export the receiver and transmitter address for every frame.</description>
    </item>
    
    <item>
      <title>Alfa AWUS036NHA Compatability (Atheros AR9271)</title>
      <link>/questions/16187/alfa-awus036nha-compatability-atheros-ar9271/</link>
      <pubDate>Wed, 21 Nov 2012 19:15:00 +0000</pubDate>
      
      <guid>/questions/16187/alfa-awus036nha-compatability-atheros-ar9271/</guid>
      <description>Alfa AWUS036NHA Compatability (Atheros AR9271)  0 Having read somewhere that the AWUS036NHA was a good unit for monitoring in promiscuous mode, I bought one.
But, I am not seeing anything on it at all. Not even the traffic in and out of this computer. The LAN and the Intel chipset both work as expected.
This is on W7 64 bit.
Am I missing something obvious in the configuration?
Might it work on XP?</description>
    </item>
    
    <item>
      <title>Extract data from router</title>
      <link>/questions/16192/extract-data-from-router/</link>
      <pubDate>Wed, 21 Nov 2012 23:45:00 +0000</pubDate>
      
      <guid>/questions/16192/extract-data-from-router/</guid>
      <description>Extract data from router  0 Hello, can WIRESHARK use to extract data from a router? The router (Sunny Home Manager) collect data from energy meter and send to Sunny Portal. Can we extract the data directly without go through the portal?
routerasked 21 Nov &#39;12, 23:45
tangjh88
1●1●1●1
accept rate: 0%
 edited 22 Nov &#39;12, 04:30 
Jaap ♦
11.7k●16●101
  
One Answer:</description>
    </item>
    
    <item>
      <title>filtering inner header</title>
      <link>/questions/16196/filtering-inner-header/</link>
      <pubDate>Thu, 22 Nov 2012 01:57:00 +0000</pubDate>
      
      <guid>/questions/16196/filtering-inner-header/</guid>
      <description>filtering inner header  0 I have captured thousand of ERSPAN packets which are in the form of IP IP tunnels. I would like to filter the packets which have ttl == 1 on inner IP header. But wireshark filters on the outer header as well. Is there any way to create filter for for the inside header ONLY.
THanks
Umair
filter ipip erspanasked 22 Nov &#39;12, 01:57
umairali
1●1●1●2</description>
    </item>
    
    <item>
      <title>Remote capture from Windows to Linux</title>
      <link>/questions/16198/remote-capture-from-windows-to-linux/</link>
      <pubDate>Thu, 22 Nov 2012 03:41:00 +0000</pubDate>
      
      <guid>/questions/16198/remote-capture-from-windows-to-linux/</guid>
      <description>Remote capture from Windows to Linux  0 I need to set up a remote capture from Windows 7 to Linux machine. The Windows 7 machine has authentication enabled. Can someone please help and provide the necessary command to do this?
Currently I am trying to start the remote capture daemon using this command in Linux machine, but this is not successful. ./rpcapd -b windows_IP_Addr -p port_number
-Thanks
rpcapd capture remoteasked 22 Nov &#39;12, 03:41</description>
    </item>
    
    <item>
      <title>Asc file in Wireshark</title>
      <link>/questions/16208/asc-file-in-wireshark/</link>
      <pubDate>Thu, 22 Nov 2012 05:09:00 +0000</pubDate>
      
      <guid>/questions/16208/asc-file-in-wireshark/</guid>
      <description>Asc file in Wireshark  0 Is it possible to &#39;make&#39; Wireshark read asc files (CAN trace files) ? What would the sollution consist of (just the idea)?
asc ascii can wiresharkasked 22 Nov &#39;12, 05:09
AvL
1●2●2●4
accept rate: 0%
  
One Answer:
  
0A wiretap module to read that file type and possibly a WTAP_ENCAP to match. WTAP_ENCAP_SOCKETCAN exists.
answered 22 Nov &#39;12, 07:12</description>
    </item>
    
    <item>
      <title>How to filter the whole TCP streams based on inner protocol condition</title>
      <link>/questions/16216/how-to-filter-the-whole-tcp-streams-based-on-inner-protocol-condition/</link>
      <pubDate>Thu, 22 Nov 2012 07:48:00 +0000</pubDate>
      
      <guid>/questions/16216/how-to-filter-the-whole-tcp-streams-based-on-inner-protocol-condition/</guid>
      <description>How to filter the whole TCP streams based on inner protocol condition  0 Hi guys,
I would like to learn, how to filter multiple whole TCP streams based on inner protocol condition, e.g. HTTP header values.
E.g. I have a capture from a proxy with lot of users, and I want to see only TCP streams which are connecting to www.google.com. The point here is to see the whole TCP stream, not only the frames containing HTTP header with &#34;</description>
    </item>
    
    <item>
      <title>Voip Capture</title>
      <link>/questions/16217/voip-capture/</link>
      <pubDate>Thu, 22 Nov 2012 07:56:00 +0000</pubDate>
      
      <guid>/questions/16217/voip-capture/</guid>
      <description>Voip Capture  0 Hi,
I made this capture and i want to understand it:
Max delta = 35.92 ms at packet no. 83135 Max jitter = 3.91 ms. Mean jitter = 1.03 ms. Max skew = 26.09 ms. Total RTP packets = 1436 (expected 1436) Lost RTP packets = -2872 (-200.00%) Sequence errors = 2872 Duration 28.68 s (-17389 ms clock drift, corresponding to 3149 Hz (-60.63%),what does it mean this?</description>
    </item>
    
    <item>
      <title>What&amp;#x27;s wrong with this sequence number?</title>
      <link>/questions/16222/whats-wrong-with-this-sequence-number/</link>
      <pubDate>Thu, 22 Nov 2012 14:29:00 +0000</pubDate>
      
      <guid>/questions/16222/whats-wrong-with-this-sequence-number/</guid>
      <description>What&amp;rsquo;s wrong with this sequence number?  0 I have a problem with HTTP Keep-Alive connections. Below is a typical example, but it also manifests itself when attempting to browse websites with reasonably complex page structures. These sites can be accessed as expected from other machines connected to the same router/adsl modem, including the one this trace came from when booted into another OS.
The strange aspect is the high relative seq number in packet 53334.</description>
    </item>
    
    <item>
      <title>ERROR: The contents of C:&amp;#92;wireshark-win32-libs&amp;#92;current_tag.txt is (unknown). It should be 2011-06-27.</title>
      <link>/questions/16230/error-the-contents-of-cwireshark-win32-libscurrent_tagtxt-is-unknown-it-should-be-2011-06-27/</link>
      <pubDate>Thu, 22 Nov 2012 21:26:00 +0000</pubDate>
      
      <guid>/questions/16230/error-the-contents-of-cwireshark-win32-libscurrent_tagtxt-is-unknown-it-should-be-2011-06-27/</guid>
      <description>ERROR: The contents of C:\wireshark-win32-libs\current_tag.txt is (unknown). It should be 2011-06-27.  0 I am developing amf plugin for wireshark in windows.
when i run the following command: nmake -f Makefile.nmake verify_tools
The output is as follows:
C:\wireshark&amp;gt; nmake -f Makefile.nmake verify_tools Microsoft (R) Program Maintenance Utility Version 10.00.40219.01 Copyright (C) Microsoft Corporation. All rights reserved.
ERROR: The contents of C:\wireshark-win32-libs\current_tag.txt is (unknown). It should be 2011-06-27.
Checking for required applications: cl: /cygdrive/c/Program Files (x86)/Microsoft Visual Studio 10.</description>
    </item>
    
    <item>
      <title>MATE display filter for SIP calls</title>
      <link>/questions/16235/mate-display-filter-for-sip-calls/</link>
      <pubDate>Fri, 23 Nov 2012 00:26:00 +0000</pubDate>
      
      <guid>/questions/16235/mate-display-filter-for-sip-calls/</guid>
      <description>MATE display filter for SIP calls  0 Hi,
I&#39;ve deployed a MATE configuration file to filter SIP signalling + media. Using the filter: mate.session.callid == &#34;mycallid&#34; I only get SIP signalling but no media. I can get SIP+media with the following filter only: mate.session.media_port == &#34;myport&#34;. Is it possible to fix the configuration file to get media filtering by call-id?
Pdu sip_pdu Proto sip Transport udp/ip { Extract callid From sip.</description>
    </item>
    
    <item>
      <title>Is there any difference between libpcap&amp;#x27;s Packet buffer and wireshark&amp;#x27;s tvbuff</title>
      <link>/questions/16241/is-there-any-difference-between-libpcaps-packet-buffer-and-wiresharks-tvbuff/</link>
      <pubDate>Fri, 23 Nov 2012 04:21:00 +0000</pubDate>
      
      <guid>/questions/16241/is-there-any-difference-between-libpcaps-packet-buffer-and-wiresharks-tvbuff/</guid>
      <description>Is there any difference between libpcap&amp;rsquo;s Packet buffer and wireshark&amp;rsquo;s tvbuff  0 Is there any difference between libpcap&#39;s Packet buffer and wireshark&#39;s tvbuff ???
tvbuff_tasked 23 Nov &#39;12, 04:21
Akhil
53●27●28●31
accept rate: 0%
 edited 23 Nov &#39;12, 09:26 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
0as that&#39;s totally different data structures, it might be better to ask if there is anything they have in common ;-).</description>
    </item>
    
    <item>
      <title>DVB-S2 dissector missing in 1.8.3</title>
      <link>/questions/16246/dvb-s2-dissector-missing-in-183/</link>
      <pubDate>Fri, 23 Nov 2012 08:43:00 +0000</pubDate>
      
      <guid>/questions/16246/dvb-s2-dissector-missing-in-183/</guid>
      <description>DVB-S2 dissector missing in 1.8.3  0 I&#39;m not able to find the DVB-S2 protocol in the protocol setting dialogue in Wireshark 1.8.3, consequently, I&#39;m not able to enable it. However, it does exist in my local build(rev:46080). DVB-S2 dissector seems to have been created during rev:44110, whereas 1.8.3 is svn rev 45256. What is the reason for this? Is there any way I can see DVB-S2 packets in 1.8.3?</description>
    </item>
    
    <item>
      <title>How do I search for packets containing  4 digits plus ;</title>
      <link>/questions/16247/how-do-i-search-for-packets-containing-4-digits-plus/</link>
      <pubDate>Fri, 23 Nov 2012 09:53:00 +0000</pubDate>
      
      <guid>/questions/16247/how-do-i-search-for-packets-containing-4-digits-plus/</guid>
      <description>How do I search for packets containing 4 digits plus ;  0 How in Wireshark do I find TCP packets containing in their data a string consisting of 4 digits plus a semicolon? I have tried matches with strings \d\d\d\d; and [0-9]{4}; and various others but it rejects them all as not a valid byte string.
Thanks - Rowan
matches regexasked 23 Nov &#39;12, 09:53
Rowan
1●3●3●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>TDS (SQL Server) protocol getting byte order wrong?</title>
      <link>/questions/16264/tds-sql-server-protocol-getting-byte-order-wrong/</link>
      <pubDate>Sat, 24 Nov 2012 08:58:00 +0000</pubDate>
      
      <guid>/questions/16264/tds-sql-server-protocol-getting-byte-order-wrong/</guid>
      <description>TDS (SQL Server) protocol getting byte order wrong?  0 I have the same &#34;TDS5 query[Mailformed Packet]&#34; but when I look at the TDS packet, the decoded length for token 0x21 is 822083584(equivalent to hex 0x31000000) but the byte stream associated with it is 0x00000031. There are exactly 0x31 bytes of data followed the length field. I wonder that the TDS decoder mix up on the big/little endian in the interpretation.</description>
    </item>
    
    <item>
      <title>How do I extract all the &amp;quot;data&amp;quot; sections?</title>
      <link>/questions/16268/how-do-i-extract-all-the-data-sections/</link>
      <pubDate>Sat, 24 Nov 2012 15:37:00 +0000</pubDate>
      
      <guid>/questions/16268/how-do-i-extract-all-the-data-sections/</guid>
      <description>How do I extract all the &amp;ldquo;data&amp;rdquo; sections?  0 I&#39;m trying to analyse the protocol used to communicate with a device. The host computer just opens a connection to the device on port 9100, and leaves in open. It then communicates with the device very like a serial device (I suspect that the protocol is more or less unchanged from the old serial version of the device). To analyse the bytes sent and received, I need to capture them and ignore all the ethernet, tcp and ip &#34;</description>
    </item>
    
    <item>
      <title>decrypting WPA2 Traffic of a client</title>
      <link>/questions/16271/decrypting-wpa2-traffic-of-a-client/</link>
      <pubDate>Sun, 25 Nov 2012 04:13:00 +0000</pubDate>
      
      <guid>/questions/16271/decrypting-wpa2-traffic-of-a-client/</guid>
      <description>decrypting WPA2 Traffic of a client  0 Hello,
i&#39;m trying to decrypt the packets of my android-smartphone which is connected to my AP. I setup the wpa-pwd in the decryption settings. The Decryption works with the wireshark example capture file, so i can see the decrypted Packets in that capture.
The Problem is that i only get EAPOL Packets 1,2,3 when i capture the 4 Way Handshake between my smartphone and the AP, but the 4th is Missing.</description>
    </item>
    
    <item>
      <title>Visual studio 2010 - webtest</title>
      <link>/questions/16272/visual-studio-2010-webtest/</link>
      <pubDate>Sun, 25 Nov 2012 04:44:00 +0000</pubDate>
      
      <guid>/questions/16272/visual-studio-2010-webtest/</guid>
      <description>Visual studio 2010 - webtest  0 Hi, in fiddler ther is an option to create webtest from the caputering request and responses. there is an option in wireshark to do also? if there is, pls explain how.
thanks, Naomi
fiddler visual-studio wiresharkasked 25 Nov &#39;12, 04:44
Naomia
1●1●1●3
accept rate: 0%
 edited 25 Nov &#39;12, 05:00 
  
One Answer:
  
0There is no comparable option in Wireshark.</description>
    </item>
    
    <item>
      <title>How to capture Wi-Fi traffic from another machine</title>
      <link>/questions/16273/how-to-capture-wi-fi-traffic-from-another-machine/</link>
      <pubDate>Sun, 25 Nov 2012 05:10:00 +0000</pubDate>
      
      <guid>/questions/16273/how-to-capture-wi-fi-traffic-from-another-machine/</guid>
      <description>How to capture Wi-Fi traffic from another machine  0 My network topology is as below:
Internet ------ Wireless Router --(Via WIRED LAN)-- PC (with Wireshark) | |--(Via Wifi WPA2-PSK)-- Android PhoneI can capture http traffic on my PC (wired directly with Wireless router), but not for my Android Phone. By filtering with the MAC address of my Android as source, only DHCP,ICMPv6,ARP are captured. How can I setup Wireshark to capture http traffic on my Android?</description>
    </item>
    
    <item>
      <title>Why are the bytes &amp;#x27;00 00&amp;#x27; but Wireshark shows an ip total length of 2016?</title>
      <link>/questions/16279/why-are-the-bytes-00-00-but-wireshark-shows-an-ip-total-length-of-2016/</link>
      <pubDate>Sun, 25 Nov 2012 12:13:00 +0000</pubDate>
      
      <guid>/questions/16279/why-are-the-bytes-00-00-but-wireshark-shows-an-ip-total-length-of-2016/</guid>
      <description>Why are the bytes &amp;lsquo;00 00&amp;rsquo; but Wireshark shows an ip total length of 2016?  0 The ip total length field gives the value in bytes of the ip header along with the data it contains. However, in the below image the byes are 00 00 but Wireshark has a total length 0f 2016. Can someone clue me in on how that is calculated?
ipasked 25 Nov &#39;12, 12:13</description>
    </item>
    
    <item>
      <title>Strange RTT graph</title>
      <link>/questions/16291/strange-rtt-graph/</link>
      <pubDate>Mon, 26 Nov 2012 00:13:00 +0000</pubDate>
      
      <guid>/questions/16291/strange-rtt-graph/</guid>
      <description>Strange RTT graph  0 Hi!
What is the reason of this kind of RTT graph?
BR.rttasked 26 Nov &#39;12, 00:13
Nurik
1●1●1●1
accept rate: 0%
can you please add a &#34;Throughput Graph&#34; and a &#34;Time-Sequence Graph (tcptrace)&#34;.
(26 Nov &#39;12, 02:33) Kurt Knochner ♦Throuput graph(04 Dec &#39;12, 04:23) NurikTime-Sequence Graph (tcptrace)(04 Dec &#39;12, 04:24) Nurik  
2 Answers:
  
1The vertical &#34;lines&#34; in your RTT graph might be wrongly assumed high delay packets, when wireshark is checking a certain sequence number for the time it takes TCP to ACK the data.</description>
    </item>
    
    <item>
      <title>capture packets with ZTE HSPA Modem MF195</title>
      <link>/questions/16299/capture-packets-with-zte-hspa-modem-mf195/</link>
      <pubDate>Mon, 26 Nov 2012 02:13:00 +0000</pubDate>
      
      <guid>/questions/16299/capture-packets-with-zte-hspa-modem-mf195/</guid>
      <description>capture packets with ZTE HSPA Modem MF195  0 Hi All,
I discovered wireshark tool since 2 weeks and i&#39;m facing some issues to use that tool with ZTE Modem MF195. I try with Huawei E367, and the wireshark is detected the interface automatically.
I need help about to use wireshark tool with ZTE HSPA Modem (MF195).
BR,
capturedasked 26 Nov &#39;12, 02:13
Djo
11●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>IP4 Errors - I got sometimes lags in games</title>
      <link>/questions/16306/ip4-errors-i-got-sometimes-lags-in-games/</link>
      <pubDate>Mon, 26 Nov 2012 03:41:00 +0000</pubDate>
      
      <guid>/questions/16306/ip4-errors-i-got-sometimes-lags-in-games/</guid>
      <description>IP4 Errors - I got sometimes lags in games  0 This might be cause of sth is bad configurated. Could you check my log? The internet provider says everything is ok by them.
http://www.speedyshare.com/zR7Bp/log-2
Since im not so good at reading the log its .ps exported from the program.
ip4 errorasked 26 Nov &#39;12, 03:41
kavvson
1●1●1●2
accept rate: 0%
 edited 26 Nov &#39;12, 03:47 
That&#39;s a Postscript file.</description>
    </item>
    
    <item>
      <title>MAP Operations Dissecting Problem In Wireshark</title>
      <link>/questions/16313/map-operations-dissecting-problem-in-wireshark/</link>
      <pubDate>Mon, 26 Nov 2012 06:10:00 +0000</pubDate>
      
      <guid>/questions/16313/map-operations-dissecting-problem-in-wireshark/</guid>
      <description>MAP Operations Dissecting Problem In Wireshark  0 When I invoke the Supplementary Services like Register SS or Erase SS or Active SS or Deactive SS or Interrogate SS operation from VLR to HLR for version 1 then wireshark show two GSM components while it should be only one component.
Another question is that why wireshark not shows the application context for V1 in TCAP section of the wireshark.
Thanks</description>
    </item>
    
    <item>
      <title>filter for comparing values of two different fields of GTP protocol</title>
      <link>/questions/16321/filter-for-comparing-values-of-two-different-fields-of-gtp-protocol/</link>
      <pubDate>Mon, 26 Nov 2012 07:43:00 +0000</pubDate>
      
      <guid>/questions/16321/filter-for-comparing-values-of-two-different-fields-of-gtp-protocol/</guid>
      <description>filter for comparing values of two different fields of GTP protocol  0 Hi, Just wanted to know that whether there is a way to build a filter, where values of two fields can be compared. For example: if we want to filter gtp-c packets where gtp.teid_data is equal to gtp.teid_cp
Thanks in advance.
Ravi
display-filterasked 26 Nov &#39;12, 07:43
RAVI_TANDON
10●4●4●7
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Anybody used a ProfiTAP with Wireshark? (aggregation via USB)</title>
      <link>/questions/16332/anybody-used-a-profitap-with-wireshark-aggregation-via-usb/</link>
      <pubDate>Mon, 26 Nov 2012 11:16:00 +0000</pubDate>
      
      <guid>/questions/16332/anybody-used-a-profitap-with-wireshark-aggregation-via-usb/</guid>
      <description>Anybody used a ProfiTAP with Wireshark? (aggregation via USB)  0 Hi guys
New to Wireshark and new to the forum.
I&#39;m looking at getting a general purpose, low(ish) cost full-duplex TAP. I&#39;d like to avoid needing two NICs on my laptop and this looks like a good option:
http://www.moesarc.co.uk/network_taps_profitap1.html
Does anyone have any good or bad experiences of using this with Wireshark?
Many thanks.
Stu
profitap tapasked 26 Nov &#39;12, 11:16</description>
    </item>
    
    <item>
      <title>Dual Wireshark processes</title>
      <link>/questions/16340/dual-wireshark-processes/</link>
      <pubDate>Mon, 26 Nov 2012 15:37:00 +0000</pubDate>
      
      <guid>/questions/16340/dual-wireshark-processes/</guid>
      <description>Dual Wireshark processes  0 Is it possible to use one laptop to capture two different sniffs from two different vlans and if so, what NICS and windows OS does Wireshark support for this? We need to capture two different segments from one router at the same time and only want to use one laptop to do this. Is it possible, or will we need four separate laptops?
multi-process dualasked 26 Nov &#39;12, 15:37</description>
    </item>
    
    <item>
      <title>Install wireshark on Ubuntu</title>
      <link>/questions/16343/install-wireshark-on-ubuntu/</link>
      <pubDate>Mon, 26 Nov 2012 20:50:00 +0000</pubDate>
      
      <guid>/questions/16343/install-wireshark-on-ubuntu/</guid>
      <description>Install wireshark on Ubuntu  3 2Hi,
Can we install wireshark on Ubuntu machine. Please share the download link if that is possible.
ubuntuasked 26 Nov &#39;12, 20:50
Gagandeep
46●1●2●3
accept rate: 0%
 edited 26 Nov &#39;12, 22:44 
Guy Harris ♦♦
17.4k●3●35●196
  
2 Answers:
  
4I was successful with the set of commands below:
sudo apt-get install wireshark sudo groupadd wireshark sudo usermod -a -G wireshark YOUR_USER_NAME sudo chgrp wireshark /usr/bin/dumpcap sudo chmod 750 /usr/bin/dumpcap sudo setcap cap_net_raw,cap_net_admin=eip /usr/bin/dumpcap sudo getcap /usr/bin/dumpcapanswered 05 Dec &#39;13, 20:43</description>
    </item>
    
    <item>
      <title>List of source IP Addresses</title>
      <link>/questions/16353/list-of-source-ip-addresses/</link>
      <pubDate>Tue, 27 Nov 2012 13:32:00 +0000</pubDate>
      
      <guid>/questions/16353/list-of-source-ip-addresses/</guid>
      <description>List of source IP Addresses  0 How can I obtain a list of all source IP addresses from the captured data?
ipasked 27 Nov &#39;12, 13:32
cdisler
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Go to &#34;Statistics -&amp;gt; endpoints&#34; and click on the &#34;IPv4&#34; (or &#34;IPv6&#34;) tab. You can also export to CSV by clicking on &#34;Copy&#34;...
... or you can use tshark with &#34;</description>
    </item>
    
    <item>
      <title>analyzing packets</title>
      <link>/questions/16356/analyzing-packets/</link>
      <pubDate>Tue, 27 Nov 2012 15:34:00 +0000</pubDate>
      
      <guid>/questions/16356/analyzing-packets/</guid>
      <description>analyzing packets  0 I am new to wireshark, and am trying to learn as much as possible, and wasn&#39;t sure where to start. I heard somewhere from doing research online that the books can&#39;t teach/show you everything, so a good place to get started is to look around, use it, and to get familiar with it. I noticed on the wireshark site that they have some captures. i thought it would be interesting to see what a virus/trojan looked like.</description>
    </item>
    
    <item>
      <title>Wireshark Functionality</title>
      <link>/questions/16357/wireshark-functionality/</link>
      <pubDate>Tue, 27 Nov 2012 15:42:00 +0000</pubDate>
      
      <guid>/questions/16357/wireshark-functionality/</guid>
      <description>Wireshark Functionality  0 The Company that I work for wants to know some specific information about the open source Wireshark product.
From what I&#39;ve researched it looks like it will do everything that I will state below, but my boss wants me to ask people who have used it before to make sure that it can do some key things.
These include:
Customizing the reader to interpret unrecognized packet types - It looks like creating a dissector plugin would work for this.</description>
    </item>
    
    <item>
      <title>Wireshark 1.4.11 Still Supported?</title>
      <link>/questions/16358/wireshark-1411-still-supported/</link>
      <pubDate>Tue, 27 Nov 2012 16:05:00 +0000</pubDate>
      
      <guid>/questions/16358/wireshark-1411-still-supported/</guid>
      <description>Wireshark 1.4.11 Still Supported?  0 Is Wireshark 1.4.11 currently still supported? If not, when did support end for this version
Thank you.
end-of-life 1.4.11asked 27 Nov &#39;12, 16:05
bahglee
1●1●1●2
accept rate: 0%
 edited 27 Nov &#39;12, 18:04 
Guy Harris ♦♦
17.4k●3●35●196
  
2 Answers:
  
2No; Support ended August 30, 2012
See LifeCycle
answered 27 Nov &#39;12, 16:13
Bill Meier ♦♦
3.2k●1●8●50</description>
    </item>
    
    <item>
      <title>get most common sender of packets in a trace file</title>
      <link>/questions/16365/get-most-common-sender-of-packets-in-a-trace-file/</link>
      <pubDate>Tue, 27 Nov 2012 20:56:00 +0000</pubDate>
      
      <guid>/questions/16365/get-most-common-sender-of-packets-in-a-trace-file/</guid>
      <description>get most common sender of packets in a trace file  0 I am trying to find out the host that has sent the most TCP packets in a trace file, regardless of destination. Is there a way to do that with Wireshark?
filter ip tcpasked 27 Nov &#39;12, 20:56
user9909
6●1●1●3
accept rate: 0%
  
One Answer:
  
2 Yes, there is:
Set the display filter to &#34;</description>
    </item>
    
    <item>
      <title>how do i turn off optimization in the build process</title>
      <link>/questions/16366/how-do-i-turn-off-optimization-in-the-build-process/</link>
      <pubDate>Tue, 27 Nov 2012 21:35:00 +0000</pubDate>
      
      <guid>/questions/16366/how-do-i-turn-off-optimization-in-the-build-process/</guid>
      <description>how do i turn off optimization in the build process  0 to enable better single step debugging.
debug make makefile gccasked 27 Nov &#39;12, 21:35
protocolmagic
1●3●3●4
accept rate: 0%
  
One Answer:
  
6Given that the question is tagged with &#39;gcc&#39; ...
You can disable optimization the same way(s) as for any autofoo make process.... :)
One way:
CFLAGS=&amp;#39;-g -O0&amp;#39; ./configure ## season to taste with configure options as neededanswered 28 Nov &#39;12, 05:36</description>
    </item>
    
    <item>
      <title>Capture File Anonymization</title>
      <link>/questions/16367/capture-file-anonymization/</link>
      <pubDate>Tue, 27 Nov 2012 23:39:00 +0000</pubDate>
      
      <guid>/questions/16367/capture-file-anonymization/</guid>
      <description>Capture File Anonymization  0 Are there any good capture Anonymization you would recommend ?
anonimization scrubbingasked 27 Nov &#39;12, 23:39
bart80
11●12●13●16
accept rate: 0%
 converted 27 Nov &#39;12, 23:45 
SYN-bit ♦♦
17.1k●9●57●245
I converted your &#34;comment&#34; to a new &#34;question&#34; as more people might be interested and this way the answers can be found more easily.
(27 Nov &#39;12, 23:46) SYN-bit ♦♦  
One Answer:</description>
    </item>
    
    <item>
      <title>Identify buffering time in a wireshark trace</title>
      <link>/questions/16370/identify-buffering-time-in-a-wireshark-trace/</link>
      <pubDate>Wed, 28 Nov 2012 01:18:00 +0000</pubDate>
      
      <guid>/questions/16370/identify-buffering-time-in-a-wireshark-trace/</guid>
      <description>Identify buffering time in a wireshark trace  0 Hi All,
I&#39;m trying to use wireshark to check the buffering time for a youtube video. I was thinking that, the buffering time started from GET /watch?v=LNMWgmvdLws HTTP/1.1 but i cannot identify which message said the video start to play.
I need help for that. Thanks in advance!
BR
analysisasked 28 Nov &#39;12, 01:18
Djo
11●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How can I get packet size summary by tshark ?</title>
      <link>/questions/16371/how-can-i-get-packet-size-summary-by-tshark/</link>
      <pubDate>Wed, 28 Nov 2012 01:23:00 +0000</pubDate>
      
      <guid>/questions/16371/how-can-i-get-packet-size-summary-by-tshark/</guid>
      <description>How can I get packet size summary by tshark ?  1 I am using wireshark 1.6.11 on Fedora 17. I can see summary of packets grouped by their size from statistics --&amp;gt; packet lengths --&amp;gt; create state (without any filter)
Is there a way to get this on command line or any script that you might be aware of ?
I tried using various options with -z but no luck till now.</description>
    </item>
    
    <item>
      <title>Capture filter for multiple host combination</title>
      <link>/questions/16388/capture-filter-for-multiple-host-combination/</link>
      <pubDate>Wed, 28 Nov 2012 06:52:00 +0000</pubDate>
      
      <guid>/questions/16388/capture-filter-for-multiple-host-combination/</guid>
      <description>Capture filter for multiple host combination  0 I need a capture filter like the one mentioned below: /usr/sbin/tshark -i any (host IP1 or host IP2 or host IP3 and (host IP4 or host IP5)) and (udp or sctp) -w &#34;file.pcap&#34;
In nutshell, I want udp and sctp packets that are sent from/to IP1 or IP2 and between IP3-IP4 and IP3-IP5.
Now problem is the way tshark processes these filters. I am not being able to get the capture.</description>
    </item>
    
    <item>
      <title>Wireshark as a Protocol Analyzer</title>
      <link>/questions/16396/wireshark-as-a-protocol-analyzer/</link>
      <pubDate>Wed, 28 Nov 2012 10:34:00 +0000</pubDate>
      
      <guid>/questions/16396/wireshark-as-a-protocol-analyzer/</guid>
      <description>Wireshark as a Protocol Analyzer  0 I was reading a Networking book that talks about packet sniffers and protocol analyzers. The book was basically saying these are two diffrent things but often get confused between one another. My question is; Is wireshark a Packet Sniffer or Protocol Analyzer or a combination of the two? I did also read some products really are both a paket sniffer and protocol analyzer.</description>
    </item>
    
    <item>
      <title>Reply status: No Exception (0)</title>
      <link>/questions/16400/reply-status-no-exception-0/</link>
      <pubDate>Wed, 28 Nov 2012 11:46:00 +0000</pubDate>
      
      <guid>/questions/16400/reply-status-no-exception-0/</guid>
      <description>Reply status: No Exception (0)  0 I am new to wireshark and trying to troubleshoot a network issue. I see the following in my capture results:
0.008 10.76.128.37 10.78.200.136 GIOP 90 GIOP 1.2 Reply s=12 id=14135068: No Exception Transmission Control Protocol, Src Port: lrs-paging (3700), Dst Port: 60613 (60613), Seq: 575, Ack: 513, Len: 41 General Inter-ORB Protocol Magic number: GIOP Version: 1.2 Message Flags: 0x00, (Big Endian) Message type: Reply Message size: 12 General Inter-ORB Protocol Reply Request id: 14135068 Reply status: No Exception (0) ServiceContextList Sequence length: 0Does this indicate a connection issue?</description>
    </item>
    
    <item>
      <title>Does wireshark capture the packet if the packet was dropped at ethernet layer?</title>
      <link>/questions/16411/does-wireshark-capture-the-packet-if-the-packet-was-dropped-at-ethernet-layer/</link>
      <pubDate>Wed, 28 Nov 2012 22:58:00 +0000</pubDate>
      
      <guid>/questions/16411/does-wireshark-capture-the-packet-if-the-packet-was-dropped-at-ethernet-layer/</guid>
      <description>Does wireshark capture the packet if the packet was dropped at ethernet layer?  0 If suppose two parties are involved in a network communication over UDP/IP say P1 and P2. For a query made by P2, P1 responds with the response. If for some reason, the response was dropped by P2 at ethernet layer, does the wireshark running on P2&#39;s machine capture the response?
Thanks in advance.
packet-captureasked 28 Nov &#39;12, 22:58</description>
    </item>
    
    <item>
      <title>Searching/Filtering Comments on packets in Pcap ng file</title>
      <link>/questions/16420/searchingfiltering-comments-on-packets-in-pcap-ng-file/</link>
      <pubDate>Thu, 29 Nov 2012 06:46:00 +0000</pubDate>
      
      <guid>/questions/16420/searchingfiltering-comments-on-packets-in-pcap-ng-file/</guid>
      <description>Searching/Filtering Comments on packets in Pcap ng file  0 I have added a few comments on a packet capture file in the Pcap NG format. Is there a way to filter/search for these comments?
Thanks, Brian
pcap comments ngasked 29 Nov &#39;12, 06:46
brwiese
26●11●12●11
accept rate: 50%
  
3 Answers:
  
1The best way in Wireshark is to use a display filter like this one:</description>
    </item>
    
    <item>
      <title>Graphing Using TShark</title>
      <link>/questions/16422/graphing-using-tshark/</link>
      <pubDate>Thu, 29 Nov 2012 07:02:00 +0000</pubDate>
      
      <guid>/questions/16422/graphing-using-tshark/</guid>
      <description>Graphing Using TShark  0 Hello.
I want to be able to generate an xml graph output like that generated in Wireshark using TShark. I don&#39;t need any filters for the moment, just the basic output. However I do need the graph to show time of day, and be in bits/second.
Can anyone offer any help?
graph tsharkasked 29 Nov &#39;12, 07:02
chazzquire
6●2●2●2
accept rate: 0%
can you please add some information about the xml graph output you are talking about (how do you generate it in Wireshark)?</description>
    </item>
    
    <item>
      <title>When does a code revision get part of the stable release / release candidate?</title>
      <link>/questions/16429/when-does-a-code-revision-get-part-of-the-stable-release-release-candidate/</link>
      <pubDate>Thu, 29 Nov 2012 07:51:00 +0000</pubDate>
      
      <guid>/questions/16429/when-does-a-code-revision-get-part-of-the-stable-release-release-candidate/</guid>
      <description>When does a code revision get part of the stable release / release candidate?  0 Code fix for BUG 7713 was accepted in trunk as revision# 44895. I was interested to know, how and when does the fix get released in the stable release or get part of the release candidate.
releaseasked 29 Nov &#39;12, 07:51
nikhilkalu
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>1.8.4 doesn&amp;#x27;t install on new computers</title>
      <link>/questions/16434/184-doesnt-install-on-new-computers/</link>
      <pubDate>Thu, 29 Nov 2012 09:47:00 +0000</pubDate>
      
      <guid>/questions/16434/184-doesnt-install-on-new-computers/</guid>
      <description>1.8.4 doesn&amp;rsquo;t install on new computers  0 You guys know you missed something in 1.8.4 right?
New install of 1.8.3 a couple days ago, no problem
New install of 1.8.4 (two different laptops) today... &#34;missing msvrc100.dll&#34;
installationasked 29 Nov &#39;12, 09:47
uncleboarder
1●2●2●3
accept rate: 0%
Can you provide a little more detail? Which version(s) of Windows? 32-bit or 64-bit?
(29 Nov &#39;12, 10:11) Gerald Combs ♦♦</description>
    </item>
    
    <item>
      <title>Filtering specific IP</title>
      <link>/questions/16439/filtering-specific-ip/</link>
      <pubDate>Thu, 29 Nov 2012 13:34:00 +0000</pubDate>
      
      <guid>/questions/16439/filtering-specific-ip/</guid>
      <description>Filtering specific IP  1 1I am new to wireshark and would like to know the easiest way of Filtering all traffic coming and going from a specific IP address on out network. any help would be greatly appreciated.
filteringasked 29 Nov &#39;12, 13:34
ksimpson
16●1●2●2
accept rate: 0%
  
One Answer:
  
2You can use a capture filter
host 10.10.10.1
or a display filter
ip.addr == 10.</description>
    </item>
    
    <item>
      <title>Associating synchrophasor config2 frame with data frame</title>
      <link>/questions/16442/associating-synchrophasor-config2-frame-with-data-frame/</link>
      <pubDate>Thu, 29 Nov 2012 14:04:00 +0000</pubDate>
      
      <guid>/questions/16442/associating-synchrophasor-config2-frame-with-data-frame/</guid>
      <description>Associating synchrophasor config2 frame with data frame  0 I am using wireshark to capture synchrophasor data. However, the config2 frame is sent over a separate TCP port, and the data frame is sent over a separate UDP port.
Is it possible to associate the config2 frame with the data frame(s) in this situation?
I have seen it work when the two are sent over the same port.
synchrophasorasked 29 Nov &#39;12, 14:04</description>
    </item>
    
    <item>
      <title>How to show all wbxml tag?</title>
      <link>/questions/16445/how-to-show-all-wbxml-tag/</link>
      <pubDate>Thu, 29 Nov 2012 17:59:00 +0000</pubDate>
      
      <guid>/questions/16445/how-to-show-all-wbxml-tag/</guid>
      <description>How to show all wbxml tag?  0 Many wbxml tags are not shown on Wireshark. (but still many other tags are shown)
It just show &#34;Requested token code page not defined for this content type&#34;
How to solve this problem.
tag wbxmlasked 29 Nov &#39;12, 17:59
edgar
1●1●1●1
accept rate: 0%
  
One Answer:
  
0By adding code to the wbmxl dissector I suspect.
answered 29 Nov &#39;12, 23:05</description>
    </item>
    
    <item>
      <title>High Number of Unknown Ethertypes</title>
      <link>/questions/16449/high-number-of-unknown-ethertypes/</link>
      <pubDate>Thu, 29 Nov 2012 19:50:00 +0000</pubDate>
      
      <guid>/questions/16449/high-number-of-unknown-ethertypes/</guid>
      <description>High Number of Unknown Ethertypes  0 I&#39;m seeing approx 60 different unknown ethertypes from a capture of about 5000 frames. We recently set our switch SPAN ports to trunks to capture dot1Q tags. Jumbo frames were also recently enabled. I&#39;m not sure if these changes could have anything to do with it. Some frames do show vlan tags. The interfaces are error free. There is a SPAN aggregator device between the network switches and linux capture server.</description>
    </item>
    
    <item>
      <title>3gpp version of protocol supported by a version of wireshark</title>
      <link>/questions/16450/3gpp-version-of-protocol-supported-by-a-version-of-wireshark/</link>
      <pubDate>Thu, 29 Nov 2012 20:28:00 +0000</pubDate>
      
      <guid>/questions/16450/3gpp-version-of-protocol-supported-by-a-version-of-wireshark/</guid>
      <description>3gpp version of protocol supported by a version of wireshark  0 How do we find out the 3GPP spec version of a wireless protocol supported by wireshark?
For example Wireshark 1.6.3 support S1AP protocol. How do we find out which version of the 3GPP specification it maps to? is it December 2012?
3gpp version specasked 29 Nov &#39;12, 20:28
Ajith
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Error Graphing Using TShark</title>
      <link>/questions/16455/error-graphing-using-tshark/</link>
      <pubDate>Fri, 30 Nov 2012 03:45:00 +0000</pubDate>
      
      <guid>/questions/16455/error-graphing-using-tshark/</guid>
      <description>Error Graphing Using TShark  0 I&#39;m getting a strange error running the following Tshark command in Windows Command Prompt:
tshark -q -r capture.cap -t ad -z io,stat,10,ip.src==213.248.117.35 &amp;gt; output.txt
Towards the end of the capture I am getting a huge number of bytes but no packets.
| 2012-11-26 16:32:02 | 0 | 14403224366743552 | | 2012-11-26 16:32:12 | 0 | 14403224366743552 | | 2012-11-26 16:32:22 | 0 | 14403224366743552 | | 2012-11-26 16:32:32 | 0 | 14403224366743552 | | 2012-11-26 16:32:42 | 0 | 14403224366743552 |When I run the same graph in Wireshark I do not have that problem.</description>
    </item>
    
    <item>
      <title>Getting wireshark working on os x mountain lion</title>
      <link>/questions/16471/getting-wireshark-working-on-os-x-mountain-lion/</link>
      <pubDate>Fri, 30 Nov 2012 21:17:00 +0000</pubDate>
      
      <guid>/questions/16471/getting-wireshark-working-on-os-x-mountain-lion/</guid>
      <description>Getting wireshark working on os x mountain lion  0 Hi, I&#39;m a new OS X Mountain Lion user, and I installed Xquartz like I was told to for an X server, but Wireshark keeps invoking the X11.app, which prompts me to install Xquartz. I feel that I must be doing something wrong.
Help appreciated.
osx xquartz wiresharkasked 30 Nov &#39;12, 21:17
msoulier
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How do I find cause of packet overruns?</title>
      <link>/questions/16480/how-do-i-find-cause-of-packet-overruns/</link>
      <pubDate>Sat, 01 Dec 2012 12:12:00 +0000</pubDate>
      
      <guid>/questions/16480/how-do-i-find-cause-of-packet-overruns/</guid>
      <description>How do I find cause of packet overruns?  0 I&#39;ve just been stuck with solving an issue on a clients backup server. &#34;Backup performance is awful&#34; was my only description before being dumped into this situation on this beautiful (albeit cold) Saturday.
Anyways, we were seeing output packet drops at the switch (cisco 4509). Disabled QoS on all server ports and that immediately stopped.
However, the &#34;interface details&#34; tab in Wireshark shows an ever increasing value under statistics &#34;</description>
    </item>
    
    <item>
      <title>How to calculate SNR values?</title>
      <link>/questions/16489/how-to-calculate-snr-values/</link>
      <pubDate>Sun, 02 Dec 2012 18:27:00 +0000</pubDate>
      
      <guid>/questions/16489/how-to-calculate-snr-values/</guid>
      <description>How to calculate SNR values?  0 Hello, I have difficulties in calculating SNR values using wireshark. Software Network Stumbler can do it but I can&#39;t save those values into file. Can I do it using Wireshark? Please I need your help. Thank you.
snrasked 02 Dec &#39;12, 18:27
Tyanium
1●4●4●5
accept rate: 0%
  
One Answer:
  
0see this similar question:
http://ask.wireshark.org/questions/3330/get-snr-from-wlan-capture
Regards
Kurt
answered 02 Dec &#39;12, 23:22</description>
    </item>
    
    <item>
      <title>Which is best tool for network traffic dumping, reading the same and again sending it back to the network</title>
      <link>/questions/16495/which-is-best-tool-for-network-traffic-dumping-reading-the-same-and-again-sending-it-back-to-the-network/</link>
      <pubDate>Mon, 03 Dec 2012 01:56:00 +0000</pubDate>
      
      <guid>/questions/16495/which-is-best-tool-for-network-traffic-dumping-reading-the-same-and-again-sending-it-back-to-the-network/</guid>
      <description>Which is best tool for network traffic dumping, reading the same and again sending it back to the network  0 Hiii,
I had an application (basically a server) that has to accept large amount of data filled in different2 structures from multiple clients for UDP packets.I want to dump this data in such a format that is easy to read back from that file and again send it back to the server, ( I MAY SAY A RECORD AND REPLAY TYPE MODULE).</description>
    </item>
    
    <item>
      <title>Strange ICMP (?) Packets</title>
      <link>/questions/16496/strange-icmp-packets/</link>
      <pubDate>Mon, 03 Dec 2012 02:39:00 +0000</pubDate>
      
      <guid>/questions/16496/strange-icmp-packets/</guid>
      <description>Strange ICMP (?) Packets  0 I&#39;m pinging my local desktop from a server (Solarwinds Log &amp;amp; Event Manager Virtual Appliance) and when I type &#34;ICMP&#34; into the display filter nothing shows up. However, when I do a &#34;ip.host == 10.96.4.130&#34; in the display filter I start seeing syn + rst/ack packets.
Can anyone tell me why these aren&#39;t showing up as regular ICMP packets? When I get a colleague to ping my machine they show up ok, as ICMP, so I don&#39;t think it&#39;s a setting on my local host.</description>
    </item>
    
    <item>
      <title>network design</title>
      <link>/questions/16501/network-design/</link>
      <pubDate>Mon, 03 Dec 2012 06:31:00 +0000</pubDate>
      
      <guid>/questions/16501/network-design/</guid>
      <description>network design  0 Hello everyone, I am told to make a network and I am bumping into some difficulty in the design. I am told to make a IP plan simply put it&#39;s a long list with all the numbers involved in the network, so far I have everything written down I just can&#39;t figure out what to do with the router. this is the physical drawing I made of my network.</description>
    </item>
    
    <item>
      <title>display filter for multi-tagged packets (vlan/mpls)?</title>
      <link>/questions/16502/display-filter-for-multi-tagged-packets-vlanmpls/</link>
      <pubDate>Mon, 03 Dec 2012 08:14:00 +0000</pubDate>
      
      <guid>/questions/16502/display-filter-for-multi-tagged-packets-vlanmpls/</guid>
      <description>display filter for multi-tagged packets (vlan/mpls)?  0 as far as i can see there is no way to distinguish multiple vlan (and mpls) tags with a display filter. e.g. in a double-tagged frame both vlan-ids are named &#34;vlan.id&#34; and i can not set a specific filter for the second tag. is there a way to do this, like &#34;vlan[2].id&#34; maybe? i know i can use something like &#34;frame[18:04]==00:78:81:00&#34; but if i want to check if the cfi-bit in the second tag is set i have to use &#34;</description>
    </item>
    
    <item>
      <title>Download Issue</title>
      <link>/questions/16504/download-issue/</link>
      <pubDate>Mon, 03 Dec 2012 09:11:00 +0000</pubDate>
      
      <guid>/questions/16504/download-issue/</guid>
      <description>Download Issue  0 Newby question, perhaps this is the wrong forum for this...
We are a Dell shop. I am unable to download drivers from Dell&#39;s support site. The download starts, I get about 300k of data, and then the time remaining just increments until I get a network error.
I&#39;ve tried it with IE, Firefox, and Chrome. All do the same thing. I&#39;ve tried it on different PC&#39;s within our network, same thing.</description>
    </item>
    
    <item>
      <title># of conntections between two ip</title>
      <link>/questions/16507/of-conntections-between-two-ip/</link>
      <pubDate>Mon, 03 Dec 2012 12:02:00 +0000</pubDate>
      
      <guid>/questions/16507/of-conntections-between-two-ip/</guid>
      <description># of conntections between two ip  0 new to wireshark and teacher hasn&#39;t responded to me, Im trying to find out how many connections(sessions) happen between two IP&#39;s. im using filter ip.src==xxx.xxx.xxx.xxx&amp;amp;&amp;amp;ip.dst==xxx.xxx.xxx.xxx&amp;amp;&amp;amp;tcp.syn==1&amp;amp;&amp;amp;tcp.ack==0 but Im pretty sure thats not what I need. any info would help
connectionasked 03 Dec &#39;12, 12:02
EMEDINA
1●1●1●1
accept rate: 0%
  
One Answer:
  
0EMEDINA, All you want to see is the number of TCP connections between two PC&#39;s?</description>
    </item>
    
    <item>
      <title>Wireshark decode SMTP</title>
      <link>/questions/16511/wireshark-decode-smtp/</link>
      <pubDate>Mon, 03 Dec 2012 13:01:00 +0000</pubDate>
      
      <guid>/questions/16511/wireshark-decode-smtp/</guid>
      <description>Wireshark decode SMTP  0 I&#39;m analyzing a SMTP transfer and not sure what Wireshark is reporting in the Info section of &#34;D: DATA fragment, xx bytes&#34;. Has anyone seen this before?
smtpasked 03 Dec &#39;12, 13:01
ws2006
1●12●12●14
accept rate: 0%
  
One Answer:
  
1The content of an email (headers + body) is sent after the SMTP DATA command. If that content is larger than one TCP segment, Wireshark will show every packet that belongs to the DATA &#34;</description>
    </item>
    
    <item>
      <title>Intel 6205 Promiscuous Mode with iwlwifi driver on Ubuntu 12.04</title>
      <link>/questions/16513/intel-6205-promiscuous-mode-with-iwlwifi-driver-on-ubuntu-1204/</link>
      <pubDate>Mon, 03 Dec 2012 14:06:00 +0000</pubDate>
      
      <guid>/questions/16513/intel-6205-promiscuous-mode-with-iwlwifi-driver-on-ubuntu-1204/</guid>
      <description>Intel 6205 Promiscuous Mode with iwlwifi driver on Ubuntu 12.04  0 Wireshark allows me to check the &#39;promiscuous mode&#39; checkbox, but I&#39;m not seeing all traffic from other IPs... any ideas?
intel6205 ubuntuasked 03 Dec &#39;12, 14:06
lambertconfo...
1●1●1●1
accept rate: 0%
  
One Answer:
  
1You need monitor mode, to see traffic of other stations in a wireless network.
http://wiki.wireshark.org/CaptureSetup/WLAN
Regards
Kurt
answered 05 Dec &#39;12, 12:48</description>
    </item>
    
    <item>
      <title>need help reading pcapng file</title>
      <link>/questions/16516/need-help-reading-pcapng-file/</link>
      <pubDate>Mon, 03 Dec 2012 16:00:00 +0000</pubDate>
      
      <guid>/questions/16516/need-help-reading-pcapng-file/</guid>
      <description>need help reading pcapng file  0 EDIT 2 i can open.pcapng with notepad. some stuff is in plain english. i see it connecting to another website&#39;s iis server. huh :( some weird charectors so i would guess thats the code. gonna try and see what else i can get from this stream capture. any thoughts appreciated.
EDIT: how can i view udp packets? i need to look at what commands are being run in java with a udp field i belive.</description>
    </item>
    
    <item>
      <title>linux remote interface</title>
      <link>/questions/16521/linux-remote-interface/</link>
      <pubDate>Mon, 03 Dec 2012 20:33:00 +0000</pubDate>
      
      <guid>/questions/16521/linux-remote-interface/</guid>
      <description>linux remote interface  0 does wreshark-1.8.4 can use remote interface?
interfaces remoteasked 03 Dec &#39;12, 20:33
gbcbooks
1●1●1●1
accept rate: 0%
  
One Answer:
  
0As a client (running the Wireshark GUI, or tshark on Linux): Yes, with a recent version of Wireshark (and libpcap).
http://wiki.wireshark.org/CaptureSetup/WinPcapRemote
As a &#34;capturing server&#34;: please check the following questions fur further information.
http://ask.wireshark.org/questions/13059/capturing-from-multiple-pipes
http://ask.wireshark.org/questions/13217/remote-packet-capture-on-remote-linux-machine
http://ask.wireshark.org/questions/12728/remote-capture-from-linux-to-windows
http://ask.wireshark.org/questions/13012/remote-packet-capturing-from-command-prompt
Regards
Kurt
answered 04 Dec &#39;12, 08:22</description>
    </item>
    
    <item>
      <title>tshark with Java Application</title>
      <link>/questions/16522/tshark-with-java-application/</link>
      <pubDate>Tue, 04 Dec 2012 00:27:00 +0000</pubDate>
      
      <guid>/questions/16522/tshark-with-java-application/</guid>
      <description>tshark with Java Application  0 Hi Everybody,
This command is used with command line correctly: C:\Program Files\Wireshark&amp;gt;tshark -i 1 -w &#34;C:\workspace\runExternal\myTestCap.pcap&#34; -T text -V &amp;gt; &#34;C:\workspace\runExternal\myTestCap.txt&#34;
But I cannot run this with my Java Application.
Can you help me how I can use this?
torichelliasked 04 Dec &#39;12, 00:27
kilicelli
1●1●1●1
accept rate: 0%
Here is the code; I want to listen my network and see the bytes like text format, and with continuousFileReader method I read the this(&#34;</description>
    </item>
    
    <item>
      <title>[Q] Dissector Sub Items</title>
      <link>/questions/16524/q-dissector-sub-items/</link>
      <pubDate>Tue, 04 Dec 2012 01:18:00 +0000</pubDate>
      
      <guid>/questions/16524/q-dissector-sub-items/</guid>
      <description>[Q] Dissector Sub Items  0 Hi Forum,
I am trying to write a dissector for a protocol. I cannot figure out how to display a sub tree PLUS box and sub fields.
I have created a simple example of what I have done.
My protocol has UINT16 message length followed FCOD (UNIT8). I want to use this FCODE as a subtree and have a PLUS box and sub fields, but I have been unable to get it to work.</description>
    </item>
    
    <item>
      <title>Extract only the data layer of jabber/xml protocol using tshark</title>
      <link>/questions/16526/extract-only-the-data-layer-of-jabberxml-protocol-using-tshark/</link>
      <pubDate>Tue, 04 Dec 2012 02:11:00 +0000</pubDate>
      
      <guid>/questions/16526/extract-only-the-data-layer-of-jabberxml-protocol-using-tshark/</guid>
      <description>Extract only the data layer of jabber/xml protocol using tshark  0 Hi fellows,
In order to get only the data of each TCP packets ( separated from the headers ) it is sufficient to use the data field.
A command such as tshark -r test.pcap -T fields -e data is enough. Now the tricky part comes when i try to do the same for XMPP packets. Those packet don&#39;t have a &#34;</description>
    </item>
    
    <item>
      <title>Example for dumping network traffic using  tshark and then read it back</title>
      <link>/questions/16527/example-for-dumping-network-traffic-using-tshark-and-then-read-it-back/</link>
      <pubDate>Tue, 04 Dec 2012 02:31:00 +0000</pubDate>
      
      <guid>/questions/16527/example-for-dumping-network-traffic-using-tshark-and-then-read-it-back/</guid>
      <description>Example for dumping network traffic using tshark and then read it back  0 Hello, I am new to use tshark. I want to dump the network traffic and then read the dumped file. Is there is some link or some sample examples through which i may get help. warm regards, monz
tshark wiresharkasked 04 Dec &#39;12, 02:31
monz
1●2●2●2
accept rate: 0%
 edited 04 Dec &#39;12, 13:51</description>
    </item>
    
    <item>
      <title>Capture filter not filtering</title>
      <link>/questions/16529/capture-filter-not-filtering/</link>
      <pubDate>Tue, 04 Dec 2012 03:18:00 +0000</pubDate>
      
      <guid>/questions/16529/capture-filter-not-filtering/</guid>
      <description>Capture filter not filtering  0 I have 1.8.3 version of Wireshark and I can&#39;t apply capture filters. I typed &#34;port 80&#34; (w/o quotes) and then I start capture, but all traffic is capturing. What is strange is that if I reopen capture filters window filter string input is empty.
filter captureasked 04 Dec &#39;12, 03:18
Coolmax
1●1●1●1
accept rate: 0%
 converted to question 04 Dec &#39;12, 10:42</description>
    </item>
    
    <item>
      <title>window close notification</title>
      <link>/questions/16530/window-close-notification/</link>
      <pubDate>Tue, 04 Dec 2012 04:03:00 +0000</pubDate>
      
      <guid>/questions/16530/window-close-notification/</guid>
      <description>window close notification  0 Hi, I have a requirement to launch the multiple wireshark instances for multiple trace files from my application. For example, number M subscribers are monitored in number N nodes/server, it will lead to N*M wireshark windows opened. Because of these many wireshark instance memory consumption is huge.
I would like to threshold the number of wireshark instances to be opened at a time (for ex. 10 instances).</description>
    </item>
    
    <item>
      <title>Fast-retransmission when received one duplicate ack?</title>
      <link>/questions/16535/fast-retransmission-when-received-one-duplicate-ack/</link>
      <pubDate>Tue, 04 Dec 2012 04:32:00 +0000</pubDate>
      
      <guid>/questions/16535/fast-retransmission-when-received-one-duplicate-ack/</guid>
      <description>Fast-retransmission when received one duplicate ack?  0 I found a tcp packets as follows: The third packets is a dup ack packets(includeing sack option,indicate some packets is not received),then the server retransmission the packet soon.According to the RFC,above 3 duplicate acks,the tcp sender then can retransmission the packets,why the strange happened:Fast-retransmission when received one duplicate ack?
1. &amp;quot;10.0.30.146&amp;quot; &amp;quot;10.50.0.45&amp;quot; &amp;quot;TCP&amp;quot; &amp;quot;15974 &amp;gt; 2806 [ACK] Seq=31116425 Ack=1 Win=5040 Len=1260&amp;quot; 2. &amp;quot;10.</description>
    </item>
    
    <item>
      <title>Duplicate Ack</title>
      <link>/questions/16542/duplicate-ack/</link>
      <pubDate>Tue, 04 Dec 2012 07:13:00 +0000</pubDate>
      
      <guid>/questions/16542/duplicate-ack/</guid>
      <description>Duplicate Ack  0 What is the assumption when analyzing the Dup Ack to know whether if packets are actually getting dropped on the network? A single transaction is showing 20% of Dup Ack but no retransmissions.
dup ackasked 04 Dec &#39;12, 07:13
ws2006
1●12●12●14
accept rate: 0% 
@ws2006: I just spotted that this is question number 10 you are asking here and you didn&#39;t accept any of the answers that the community gave to you in your previous threads.</description>
    </item>
    
    <item>
      <title>How to change lua io.output (custom log file) every 5 minutes</title>
      <link>/questions/16550/how-to-change-lua-iooutput-custom-log-file-every-5-minutes/</link>
      <pubDate>Tue, 04 Dec 2012 08:59:00 +0000</pubDate>
      
      <guid>/questions/16550/how-to-change-lua-iooutput-custom-log-file-every-5-minutes/</guid>
      <description>How to change lua io.output (custom log file) every 5 minutes  0 Hi, I&#39;m using tshark and lua to extract datafields from diameter protocol in endless loop and saving them into log file. It works great. But now I need to create new logfile every 5 minutes. I can change io.output inside tap.packet functions but it&#39;s not accurate since it&#39;s called only when there is a packet. I check How to use a timer in lua, but I&#39;m not able to combine it with my code.</description>
    </item>
    
    <item>
      <title>USB wireless adapter which supports promiscuous mode (as opposed to monitor mode) in BackTrack</title>
      <link>/questions/16551/usb-wireless-adapter-which-supports-promiscuous-mode-as-opposed-to-monitor-mode-in-backtrack/</link>
      <pubDate>Tue, 04 Dec 2012 12:55:00 +0000</pubDate>
      
      <guid>/questions/16551/usb-wireless-adapter-which-supports-promiscuous-mode-as-opposed-to-monitor-mode-in-backtrack/</guid>
      <description>USB wireless adapter which supports promiscuous mode (as opposed to monitor mode) in BackTrack  0 Hi to all! As the title says, I&#39;m looking for an USB wireless adapter which supports promiscuous mode to work with Wireshark in BackTrack. I have an ALFA AWUS036H, but it (seems it) can be put only in monitor mode. I&#39;m looking for an USB adapter, since I&#39;m running BackTrack in a Virtual machine. Thanks in advance for your help!</description>
    </item>
    
    <item>
      <title>Reconstruct TCP conversation</title>
      <link>/questions/16558/reconstruct-tcp-conversation/</link>
      <pubDate>Tue, 04 Dec 2012 16:51:00 +0000</pubDate>
      
      <guid>/questions/16558/reconstruct-tcp-conversation/</guid>
      <description>Reconstruct TCP conversation  0 I am trying to reconstruct a TCP conversation from the first SYN to the FIN in order to troubleshoot an application response issue.
If I use &#34;Follow TCP Stream&#34; in Wireshark, it starts from the first packet captured always. It doesn&#39;t list time or number packets: it is very difficult to figure out
I need to be able to select a SYN packet from with the capture and then see all subsequent packets in the exchange.</description>
    </item>
    
    <item>
      <title>is there tshark format config file? or setting?</title>
      <link>/questions/16559/is-there-tshark-format-config-file-or-setting/</link>
      <pubDate>Tue, 04 Dec 2012 17:17:00 +0000</pubDate>
      
      <guid>/questions/16559/is-there-tshark-format-config-file-or-setting/</guid>
      <description>is there tshark format config file? or setting?  0 I&#39;m use tshark to read .pcap in linux
i want result text to insert \t(tab delimiter of coumn) as same command
&#34;tshark -tad - n -r xxxx.pcap&#34;
now
result text{
2012-12-05 09:39:20.770766 xxxxxx -&amp;gt; xxxxx LLMNR 86 Standard query A isatap
}
want result text{
1 2012-12-05 09:39:20.770766 xxxxxx -&amp;gt; xxxxx LLMNR 86 Standard query A isatap
}
Is there any way without change command ?</description>
    </item>
    
    <item>
      <title>How to filter a large group of different ip addresses?</title>
      <link>/questions/16565/how-to-filter-a-large-group-of-different-ip-addresses/</link>
      <pubDate>Tue, 04 Dec 2012 23:30:00 +0000</pubDate>
      
      <guid>/questions/16565/how-to-filter-a-large-group-of-different-ip-addresses/</guid>
      <description>How to filter a large group of different ip addresses?  0 Hi every body, I want to know how I could filter a large group of ip addresses (in a Listener) which I can&#39;t filter them using a network notation like(ip.addr==10.0.0.0\8) because they are from different networks, and it will be too long to write them manually like this(ip.addr==141.55.12.13 or ip.addr==212.67.108.5 or ....) Thanks
lua wiresharkasked 04 Dec &#39;12, 23:30</description>
    </item>
    
    <item>
      <title>TCP capture filter performance</title>
      <link>/questions/16572/tcp-capture-filter-performance/</link>
      <pubDate>Wed, 05 Dec 2012 00:56:00 +0000</pubDate>
      
      <guid>/questions/16572/tcp-capture-filter-performance/</guid>
      <description>TCP capture filter performance  0 I think it may be a naive question, but I also want to make sure of this; I&#39;m wondering if this could affect pefromance of a tap or the program speed: I want to filter syn packets using(tcp.flags.syn==1), I know it is implicitly filter the tcp protocal, is there any need to mention the TCP protocol explicitly again inside the filter of the tap??</description>
    </item>
    
    <item>
      <title>How to save the capture options?</title>
      <link>/questions/16576/how-to-save-the-capture-options/</link>
      <pubDate>Wed, 05 Dec 2012 01:40:00 +0000</pubDate>
      
      <guid>/questions/16576/how-to-save-the-capture-options/</guid>
      <description>How to save the capture options?  0 Hi,
I use Wireshark version 1.8.4.
Each time I would take a capture I enter Capture &amp;gt;&amp;gt; Options and change the default parameters of &#39;Capture files&#39; like enable &#39;use multiple files&#39; option, setting &#39;next file every 200M&#39;, browsing to a folder on Desktop where I want all the capture files to be saved at.
Is there any way to save those parameters so each time I open the Wireshark and take a capture, it will be based on those settings?</description>
    </item>
    
    <item>
      <title>Interface data from file</title>
      <link>/questions/16579/interface-data-from-file/</link>
      <pubDate>Wed, 05 Dec 2012 02:59:00 +0000</pubDate>
      
      <guid>/questions/16579/interface-data-from-file/</guid>
      <description>Interface data from file  0 Hello,
can I somehow simulate an interface with a file? That is, I have a file with sniffed data (not sniffed with Wireshark) that consists of a bunch of hex numbers which symbolize the data going through the interface. Can I somehow input this data in Wireshark and dissect it with the protocols that I wish?
Thank you very much!
Best regards, Matheus Priebe Bertram</description>
    </item>
    
    <item>
      <title>Wireshark crash</title>
      <link>/questions/16582/wireshark-crash/</link>
      <pubDate>Wed, 05 Dec 2012 04:10:00 +0000</pubDate>
      
      <guid>/questions/16582/wireshark-crash/</guid>
      <description>Wireshark crash  0 Hi What is the meaning of wireshark crash?? does it mean that wireshark stopped and can&#39;t save the captured data, or it means the software itself is carshed and it doesn&#39;t work any more? what are the common mistakes that cause the crash other than running wireshark for along time (Briefly). Thanks
wiresharkasked 05 Dec &#39;12, 04:10
Leena
51●17●18●21
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>erspan - truncated packet - size</title>
      <link>/questions/16591/erspan-truncated-packet-size/</link>
      <pubDate>Wed, 05 Dec 2012 05:40:00 +0000</pubDate>
      
      <guid>/questions/16591/erspan-truncated-packet-size/</guid>
      <description>erspan - truncated packet - size  0 I setup a erspan session with mtu 256 (truncates packets).
Am i correct that wireshark will report the actual received data when giving throughput and packet size statistics ? (As opposed to look at info in ip/tcp header.(
Does this mean i have to enable jumbo frames, and tunnel full packets using erspan to get a accurate picture ?
jumbo erspanasked 05 Dec &#39;12, 05:40</description>
    </item>
    
    <item>
      <title>TCP Stream output in Pdml format</title>
      <link>/questions/16592/tcp-stream-output-in-pdml-format/</link>
      <pubDate>Wed, 05 Dec 2012 06:42:00 +0000</pubDate>
      
      <guid>/questions/16592/tcp-stream-output-in-pdml-format/</guid>
      <description>TCP Stream output in Pdml format  0 Hi, I use tshark to get tcp stream in ascii format by using tshark -r read.pcap -z follow,tcp,stream,1 -q I want to output the the http request and response in pdml format. (or in xml format) like &amp;lt;conn srcip=&#34;0.0.0.0&#34; dstip=&#34;0.0.0.0&#34;/&amp;gt;&amp;lt;msg proto=&#34;http&#34;&amp;gt;&amp;lt;field method=&#34;&#34;&amp;gt; and so on.
Can any one help me how to access the code of tshark to output the protocol tree while following the tcp stream?</description>
    </item>
    
    <item>
      <title>HELP! Looking at a specific (HTTPS) TCP stream (1936 packets) I start to get Malformed Packet: SSL after packet 782</title>
      <link>/questions/16597/help-looking-at-a-specific-https-tcp-stream-1936-packets-i-start-to-get-malformed-packet-ssl-after-packet-782/</link>
      <pubDate>Wed, 05 Dec 2012 08:23:00 +0000</pubDate>
      
      <guid>/questions/16597/help-looking-at-a-specific-https-tcp-stream-1936-packets-i-start-to-get-malformed-packet-ssl-after-packet-782/</guid>
      <description>HELP! Looking at a specific (HTTPS) TCP stream (1936 packets) I start to get Malformed Packet: SSL after packet 782  0 All,
we&#39;re baffled with an issue encountered. We&#39;re monitoring (using tshark) off an inline TAP sitting between a client browser (pc) and web server. I can see the 3-way handshake incl. the SSL v3 handshake thereafter. I can see the GET / requests from client to server incl. the &#39;Continuation or non-HTTP traffic&#39; from the server back to the client (in producing the HTTP response).</description>
    </item>
    
    <item>
      <title>Branch office latency over MPLS</title>
      <link>/questions/16599/branch-office-latency-over-mpls/</link>
      <pubDate>Wed, 05 Dec 2012 09:44:00 +0000</pubDate>
      
      <guid>/questions/16599/branch-office-latency-over-mpls/</guid>
      <description>Branch office latency over MPLS  0 Note: fairly green at Wireshark
Scenario: We have branch offices connected to our main office via MPLS VPN. Branch offices use thin clients and VoIP phones. Users RDP to virtual desktop on ESX Server.
On random days and random times these branch offices have one minute outages where their RDP session will say &#34;Reconnecting&#34; and the voice call is lost. After a minute the RDP sessions and VoIP are fine.</description>
    </item>
    
    <item>
      <title>Windows file sharing protocol</title>
      <link>/questions/16602/windows-file-sharing-protocol/</link>
      <pubDate>Wed, 05 Dec 2012 10:36:00 +0000</pubDate>
      
      <guid>/questions/16602/windows-file-sharing-protocol/</guid>
      <description>Windows file sharing protocol  0 I understand the capture of a ftp as it uses tcp handshake to setup the communication. But for Windows file sharing, like copy a file from the server to the PC via the WAN. I am not sure what is a normal traffic pattern for Windows copy.
Is there a Wireshark trace file of a normal behavior of a Windows copy file?What protocol does Windows copy uses?</description>
    </item>
    
    <item>
      <title>tap functions in Lua script</title>
      <link>/questions/16604/tap-functions-in-lua-script/</link>
      <pubDate>Wed, 05 Dec 2012 11:01:00 +0000</pubDate>
      
      <guid>/questions/16604/tap-functions-in-lua-script/</guid>
      <description>tap functions in Lua script  0 Hi. I want to ask about the tap.packet functions. I have two listeners one for outbound traffic and the other for the inbound. Unfortunately, the examples of using Lua with wireshark are limited and I didn&#39;t find documentation talks about the scope of tap functions and why they are written like that; I mean the use of local init_listener()function or any other function the script start with, and why it is local and functions like: tap.</description>
    </item>
    
    <item>
      <title>Getting Tshark up to wire speed for NFS packet captures</title>
      <link>/questions/16613/getting-tshark-up-to-wire-speed-for-nfs-packet-captures/</link>
      <pubDate>Wed, 05 Dec 2012 14:11:00 +0000</pubDate>
      
      <guid>/questions/16613/getting-tshark-up-to-wire-speed-for-nfs-packet-captures/</guid>
      <description>Getting Tshark up to wire speed for NFS packet captures  1 1I am trying to use tshark for reassembling and extracting NFS payloads. Because of the large amount of data I am processing (and some security concerns) I can not do this processing offline so I am trying to get tshark to run at or as close to wire speed as possible. I initially tried using tshark to do the packet capture but it was dropping too many packets so I am using another pcap based tool to do the packet capture (and successfully capturing and writing packets at wire speed) and then I am piping the output of tshark to another process that does processing on the payloads.</description>
    </item>
    
    <item>
      <title>1.8.4 version support airopeek ?</title>
      <link>/questions/16617/184-version-support-airopeek/</link>
      <pubDate>Wed, 05 Dec 2012 15:09:00 +0000</pubDate>
      
      <guid>/questions/16617/184-version-support-airopeek/</guid>
      <description>1.8.4 version support airopeek ?  0 I was using wireshark 1.6.12 and decoding AIROPEEK package ok. After upgrading to 1.8.4, that option is gone from &#34;Decode As...&#34; option. Am I missing something here?
airopeekasked 05 Dec &#39;12, 15:09
dbdiep
16●2●2●3
accept rate: 0%
I have the same question... Can anyone please answer? Thanks!
(04 Jan &#39;13, 10:13) difanI don&#39;t have an &#34;airopeek&#34; capture file at hand to test with. Could you post one on www.</description>
    </item>
    
    <item>
      <title>When building a dissector: How to declare an error?</title>
      <link>/questions/16627/when-building-a-dissector-how-to-declare-an-error/</link>
      <pubDate>Thu, 06 Dec 2012 02:15:00 +0000</pubDate>
      
      <guid>/questions/16627/when-building-a-dissector-how-to-declare-an-error/</guid>
      <description>When building a dissector: How to declare an error?  0 Hey, I&#39;m building a dissector and I would like to know if it is possible to explicitly declare about errors. for example: If something&#39;s length should be 0, but it doesn&#39;t, then I want to say &#34;error, something is wrong&#34;
Thanks ahead.
dissector wiresharkasked 06 Dec &#39;12, 02:15
hudac
61●11●13●17
accept rate: 50%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Calculate the average sending bit rate for Voice/Video Calls</title>
      <link>/questions/16631/calculate-the-average-sending-bit-rate-for-voicevideo-calls/</link>
      <pubDate>Thu, 06 Dec 2012 04:20:00 +0000</pubDate>
      
      <guid>/questions/16631/calculate-the-average-sending-bit-rate-for-voicevideo-calls/</guid>
      <description>Calculate the average sending bit rate for Voice/Video Calls  0 I made an Voice/Video phone call in an easy Asterisk environment User1000--------Asterisk Server---------User2000
Then I captured the traffic using wireshark.
Code: Voice G.711 Video H.263
So, How to calculate the &#39;average sending bit rate&#39; for voice / video ? Someone told me that the Wireshark--&amp;gt;Statistics--&amp;gt;protocol hierarchy could do this. So, I went to see the details of it. But there are only &#39;Mbit/s&#39; and &#39;End Mbit/s&#39;.</description>
    </item>
    
    <item>
      <title>WireShark crashing with C&#43;&#43; errors</title>
      <link>/questions/16635/wireshark-crashing-with-c-errors/</link>
      <pubDate>Thu, 06 Dec 2012 06:47:00 +0000</pubDate>
      
      <guid>/questions/16635/wireshark-crashing-with-c-errors/</guid>
      <description>WireShark crashing with C++ errors  0 Running WS 1.6.12(SVN REV 46251 from/Trunk -1.6) on W2K3 server, 4gig ram, Just doing basic capture from-to an IPAddress, buffer 10 meg, each file 10meg. After around 45 min (6meg file size) Wireshark crashes with C++ error. Found lots of errors related to C++ crashes when searching Google, but none matching my configs or even having a resolve for the issue. Any thoughts?</description>
    </item>
    
    <item>
      <title>Unable To Save Decryption Keys</title>
      <link>/questions/16641/unable-to-save-decryption-keys/</link>
      <pubDate>Thu, 06 Dec 2012 09:39:00 +0000</pubDate>
      
      <guid>/questions/16641/unable-to-save-decryption-keys/</guid>
      <description>Unable To Save Decryption Keys  0 I am running Wireshark 1.8.2 on a Windows 7 x64 client and I am trying to add a new wireless decription key for WPA-PWD. After specifying the type, passphrase and SSID, I click the Ok button and the key shows up in the &#34;Decryption Key Management&#34; window as a new key. I then click the Ok button which closes the window but then when I go back to the decryption keys, it is gone.</description>
    </item>
    
    <item>
      <title>Analyze a wifi camera</title>
      <link>/questions/16642/analyze-a-wifi-camera/</link>
      <pubDate>Thu, 06 Dec 2012 09:53:00 +0000</pubDate>
      
      <guid>/questions/16642/analyze-a-wifi-camera/</guid>
      <description>Analyze a wifi camera  0 Is it possible to analyze the communication from a wifi CCTV camera. It does not communicate with the FTP server on internet. I think it don&#39;t even try to do, and that is the problem. Can I monitor the handshake from the camera to the router and out? May be with a Ethernet cable from camera to router via a HUB and play &#39;Man in the middle&#39;.</description>
    </item>
    
    <item>
      <title>How to make my dissector relevant to other versions</title>
      <link>/questions/16644/how-to-make-my-dissector-relevant-to-other-versions/</link>
      <pubDate>Thu, 06 Dec 2012 10:26:00 +0000</pubDate>
      
      <guid>/questions/16644/how-to-make-my-dissector-relevant-to-other-versions/</guid>
      <description>How to make my dissector relevant to other versions  0 Hey, I built a dissector for my WireShark version (after doing all that steps of installing cygwin etc. for building WireShark). Now, my dissector works only on my build of WireShark (ver 1.9 ... ), and not on, lets say, the newest WireShark version 1.8.4 that I can download from www.wireshark.org.
I saw that it is possible to create an installer of my version, which I can spread, and then my dissector will also work for others.</description>
    </item>
    
    <item>
      <title>installing Tshark</title>
      <link>/questions/16646/installing-tshark/</link>
      <pubDate>Thu, 06 Dec 2012 10:45:00 +0000</pubDate>
      
      <guid>/questions/16646/installing-tshark/</guid>
      <description>installing Tshark  0 Hi,
I&#39;m trying to install latest tshark. Currently I&#39;m using CentOS 5.x and it seems that there&#39;s no rpm for CentOS. Is there any link for downloading tshark source code or RPM for CentOS? I don&#39;t need to install wireshark but tshark!!
What I want to to is using frame.time_epoch filter but my current version, 1.0.15, doesn&#39;t provide this filter.
tsharkasked 06 Dec &#39;12, 10:45
fates</description>
    </item>
    
    <item>
      <title>New Office Environment (NOE) RFC</title>
      <link>/questions/16653/new-office-environment-noe-rfc/</link>
      <pubDate>Thu, 06 Dec 2012 12:22:00 +0000</pubDate>
      
      <guid>/questions/16653/new-office-environment-noe-rfc/</guid>
      <description>New Office Environment (NOE) RFC  0 I&#39;m looking for any kind of documentation regarding the structure of NOE protocol communications. Wireshark supports the NOE protocol, so I&#39;m wondering if you guys can help point me in the right direction. I&#39;ve looked around for RFCs and whatnot, but apparently I&#39;m not using the right search criteria. Any help would be extremely appreciated.
environment noe rfc office newasked 06 Dec &#39;12, 12:22</description>
    </item>
    
    <item>
      <title>VoWLAN jitter and packet loss</title>
      <link>/questions/16663/vowlan-jitter-and-packet-loss/</link>
      <pubDate>Thu, 06 Dec 2012 17:24:00 +0000</pubDate>
      
      <guid>/questions/16663/vowlan-jitter-and-packet-loss/</guid>
      <description>VoWLAN jitter and packet loss  0 Hi,
I&#39;m doing a test in a WLAN with 5 computers connected to the AP, but only both of them are doing a VoIP call between them.
The computer A has the follow characteristics: Windows 7 home premium, Processador:2,13GhZ, Ram:4G, Wireless speed : between 65 and 130 Mbps.
Computer B: Windows XP Professional, Service Pack 3, Processor: 1&#39;5&#39;GHz, Ram :1,99G, Wireless speed: 54Mbps</description>
    </item>
    
    <item>
      <title>DNS fragment over TCP</title>
      <link>/questions/16670/dns-fragment-over-tcp/</link>
      <pubDate>Thu, 06 Dec 2012 22:19:00 +0000</pubDate>
      
      <guid>/questions/16670/dns-fragment-over-tcp/</guid>
      <description>DNS fragment over TCP  0 I captured some dns packets over tcp,some dns fragment packets are found.why these dns packets should be fragmented (not ip layer fragments,just dns payload fragment)but the length&amp;lt;1500?
fragment tcp dnsasked 06 Dec &#39;12, 22:19
chinasan
0●6●6●8
accept rate: 0%
1can you please post a screenshot of that &#34;dns fragement&#34; message?
(07 Dec &#39;12, 05:43) Kurt Knochner ♦A picture can not be attached without reason,just description as follows: The first dns payload is &#34;</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t capture http post from web server</title>
      <link>/questions/16674/cant-capture-http-post-from-web-server/</link>
      <pubDate>Fri, 07 Dec 2012 01:14:00 +0000</pubDate>
      
      <guid>/questions/16674/cant-capture-http-post-from-web-server/</guid>
      <description>Can&amp;rsquo;t capture http post from web server  0 Hello, I have an IIS web server (IP=Y.Y.Y.Y) running under Windows 2008 R2. One test ASP.NET application is running under this IIS instance.
I access this web application from a client (IP=X.X.X.X) from which I capture traffic with Wireshark and I see all HTTP requests (GET and POST).
In the mean time I capture traffic on the server with Wireshark too but I only see GET requests coming from the client, not POST requests.</description>
    </item>
    
    <item>
      <title>Worm traffic trace</title>
      <link>/questions/16675/worm-traffic-trace/</link>
      <pubDate>Fri, 07 Dec 2012 03:15:00 +0000</pubDate>
      
      <guid>/questions/16675/worm-traffic-trace/</guid>
      <description>Worm traffic trace  0 Hi I need samples of differnt worms&#39; traffic capture, that I can use them safely. Any body knows where I can find something like that?? and what procedures should be taken when I handle some traces like these??or even any other forum where I can ask . There are two sample captures in wireshark.org, I&#39;m interested in slammer.pcap but I tried once to download it and there was a warning of opening this file, what I should do when I work with such files safely, I have a program that has to detect the scanning activity of worms and I need a capture to try it with to know if it is working with.</description>
    </item>
    
    <item>
      <title>RFC 4733 rtpevents</title>
      <link>/questions/16688/rfc-4733-rtpevents/</link>
      <pubDate>Fri, 07 Dec 2012 08:08:00 +0000</pubDate>
      
      <guid>/questions/16688/rfc-4733-rtpevents/</guid>
      <description>RFC 4733 rtpevents  0 Will Wireshark differentiate RFC 4733 from 2833 events? I know 4733 obsoletes 2833, but does 4733 still display as 2833?
rfc 4733 rtpevent 2833 dtmfasked 07 Dec &#39;12, 08:08
tlockard
1●1●1●1
accept rate: 0%
  
One Answer:
  
0It looks like the code in Wireshar to dissect rtp events is very basic and that RFC 4733 extends RFC 2833 so Wireshark will dissect RFC 4733 rtp_events as RFC 2833 but none of the extensions.</description>
    </item>
    
    <item>
      <title>Split pcap file into smaller pcap file (according to tcp flow)</title>
      <link>/questions/16690/split-pcap-file-into-smaller-pcap-file-according-to-tcp-flow/</link>
      <pubDate>Fri, 07 Dec 2012 08:21:00 +0000</pubDate>
      
      <guid>/questions/16690/split-pcap-file-into-smaller-pcap-file-according-to-tcp-flow/</guid>
      <description>Split pcap file into smaller pcap file (according to tcp flow)  0 I need to find a way to split a large pcap file into separated pcap files. What I want to find is a application like Splitcap but I need a application which runs on Linux. Tcpflow or Tcptrace don&#39;t generate pcap file as their output. The output pcap file should contains a tcp flow.
If there&#39;s an application, please let me know.</description>
    </item>
    
    <item>
      <title>What blocks the addition of an interface?</title>
      <link>/questions/16703/what-blocks-the-addition-of-an-interface/</link>
      <pubDate>Fri, 07 Dec 2012 12:15:00 +0000</pubDate>
      
      <guid>/questions/16703/what-blocks-the-addition-of-an-interface/</guid>
      <description>What blocks the addition of an interface?  0 I can not add an interface by IP address. would a baraccuda web filter affect this?
interface addition problemasked 07 Dec &#39;12, 12:15
dbar
1●2●2●2
accept rate: 0%
I can not add an interface by IP address.
what does that mean?what did you do to &#34;add an interface&#34;?what is your OS versionwhat is your Wireshark version?(07 Dec &#39;12, 12:38) Kurt Knochner ♦Can&#39;t get list of interfaces: Is the server properly installed on 192.</description>
    </item>
    
    <item>
      <title>Must WinPCap be installed on all interfaces that are looked at?</title>
      <link>/questions/16704/must-winpcap-be-installed-on-all-interfaces-that-are-looked-at/</link>
      <pubDate>Fri, 07 Dec 2012 12:18:00 +0000</pubDate>
      
      <guid>/questions/16704/must-winpcap-be-installed-on-all-interfaces-that-are-looked-at/</guid>
      <description>Must WinPCap be installed on all interfaces that are looked at?  0 Must WinPCap be installed on all interfaces that are looked at?
winpcapasked 07 Dec &#39;12, 12:18
dbar
1●2●2●2
accept rate: 0%
  
One Answer:
  
0No.
UPDATE
If you are talking about remote capturing (see your other question), then: yes, you must install WinPcap on every remote system and start rpcad there.
Regards</description>
    </item>
    
    <item>
      <title>Wireshark Capture Crashing</title>
      <link>/questions/16705/wireshark-capture-crashing/</link>
      <pubDate>Fri, 07 Dec 2012 12:25:00 +0000</pubDate>
      
      <guid>/questions/16705/wireshark-capture-crashing/</guid>
      <description>Wireshark Capture Crashing  0 I&#39;m trying to setup wireshark on a server in our environment. I have downloaded the most current version at this time 1.8.4 and installed the WinPcap that comes with it.
I have tried a few different settings to see if i can get different behavior, i have been unsuccessful.
I have set the following parameters and it will work for about 20 minutes and then wireshark crashes with C++ runtime issues.</description>
    </item>
    
    <item>
      <title>Analyse suspicious url</title>
      <link>/questions/16714/analyse-suspicious-url/</link>
      <pubDate>Fri, 07 Dec 2012 14:56:00 +0000</pubDate>
      
      <guid>/questions/16714/analyse-suspicious-url/</guid>
      <description>Analyse suspicious url  0 I got this suspicious URL in my mailbox of which I&#39;m 99% sure that it&#39;s not sent (intentionally in any case) by the person who is listed as the sender. Can I use Wireshark to analyse what this URL actually does without harming (downloading spyware, malware, cookies, ...) my computer in any way? Perhaps by capturing my wlan device and running curl on this URL? If so, what should I be looking for specifically?</description>
    </item>
    
    <item>
      <title>Understanding DCERPC and &amp;quot;TCP segment of a reassembled PDU&amp;quot;</title>
      <link>/questions/16715/understanding-dcerpc-and-tcp-segment-of-a-reassembled-pdu/</link>
      <pubDate>Fri, 07 Dec 2012 15:48:00 +0000</pubDate>
      
      <guid>/questions/16715/understanding-dcerpc-and-tcp-segment-of-a-reassembled-pdu/</guid>
      <description>Understanding DCERPC and &amp;ldquo;TCP segment of a reassembled PDU&amp;rdquo;  0 I&#39;m trying to understand how a PC application (which is unsupported and undocumented) talks to a device. The trace seems to consist mostly of DCERPC packets and TCP packets marked &#34;TCP segment of a reassembled PDU&#34;. What I expect to be happening here is either the download of a lot of records from a database to the device, or some sort of synchronisation of a database in the device with the master database on the PC.</description>
    </item>
    
    <item>
      <title>how do you capture network packets on android similar to ios?</title>
      <link>/questions/16719/how-do-you-capture-network-packets-on-android-similar-to-ios/</link>
      <pubDate>Fri, 07 Dec 2012 20:10:00 +0000</pubDate>
      
      <guid>/questions/16719/how-do-you-capture-network-packets-on-android-similar-to-ios/</guid>
      <description>how do you capture network packets on android similar to ios?  0 With an iPad/iPod/iPhone I know you can get the network packets while using the chargeing cable connected to a mac. Is there a way to do this with and android tablet or phone?
android ios cableasked 07 Dec &#39;12, 20:10
guardian
1●1●1●2
accept rate: 0%
 edited 07 Dec &#39;12, 20:11 
  
One Answer:</description>
    </item>
    
    <item>
      <title>display packet from host 127.0.0.1 port 31001</title>
      <link>/questions/16720/display-packet-from-host-127001-port-31001/</link>
      <pubDate>Fri, 07 Dec 2012 22:25:00 +0000</pubDate>
      
      <guid>/questions/16720/display-packet-from-host-127001-port-31001/</guid>
      <description>display packet from host 127.0.0.1 port 31001  0 I have a receiver on usb that sends packets to host 127.0.0.1, port 31001. How can I get wireshark to display these packets? I am not interested in capturing, just displaying to insure the receiver is sending packets ok.
recvraddressasked 07 Dec &#39;12, 22:25
krychak4a
6●1●1●3
accept rate: 0%
  
One Answer:
  
2 You can&#39;t display packets unless something has captured them.</description>
    </item>
    
    <item>
      <title>How to capture data sent from specific internal ip addresses.</title>
      <link>/questions/16726/how-to-capture-data-sent-from-specific-internal-ip-addresses/</link>
      <pubDate>Sat, 08 Dec 2012 12:58:00 +0000</pubDate>
      
      <guid>/questions/16726/how-to-capture-data-sent-from-specific-internal-ip-addresses/</guid>
      <description>How to capture data sent from specific internal ip addresses.  0 I only need to capture data from the internal ip address: 192.168.0.13 How can I configure Wireshark to capture only from that internal ip?
internetThis question is marked &#34;community wiki&#34;.asked 08 Dec &#39;12, 12:58
SNLThe_Office
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Go to the capture options dialog and double click on the network card entry of the card you want to capture on.</description>
    </item>
    
    <item>
      <title>Error: Unable to open wireshark</title>
      <link>/questions/16727/error-unable-to-open-wireshark/</link>
      <pubDate>Sat, 08 Dec 2012 12:58:00 +0000</pubDate>
      
      <guid>/questions/16727/error-unable-to-open-wireshark/</guid>
      <description>Error: Unable to open wireshark  0 Hi Ive downlaoded wireshark to my computer a couple of months ago now. Within in the last few weeks i have had trouble with it opneing saying there is an error message saying &#34;The application was unable to start correctly (0xc000007b) Click Ok to close the application&#34; Bearing in mind i have had no previous trouble and then all of a sudden the wirsehark just doesnt operate.</description>
    </item>
    
    <item>
      <title>how do i get network usage for server to a client on 23/4/2009</title>
      <link>/questions/16732/how-do-i-get-network-usage-for-server-to-a-client-on-2342009/</link>
      <pubDate>Sun, 09 Dec 2012 00:42:00 +0000</pubDate>
      
      <guid>/questions/16732/how-do-i-get-network-usage-for-server-to-a-client-on-2342009/</guid>
      <description>how do i get network usage for server to a client on 23/4/2009  0 Are there any commands to get the network usage on given date in windows xp? i want to gather the statistics of network usage for 192.168.20.1 to 192.168.20.254 on date 23/4/2009
netstatasked 09 Dec &#39;12, 00:42
Maykin
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Did you capture the packets of these two IP addresses on that day, or did you have a netflow/sflow probe reporting traffic statistics on the same day to a netflow collector?</description>
    </item>
    
    <item>
      <title>while building a dissector, Is it possible to declare an error on the upper box?</title>
      <link>/questions/16733/while-building-a-dissector-is-it-possible-to-declare-an-error-on-the-upper-box/</link>
      <pubDate>Sun, 09 Dec 2012 02:24:00 +0000</pubDate>
      
      <guid>/questions/16733/while-building-a-dissector-is-it-possible-to-declare-an-error-on-the-upper-box/</guid>
      <description>while building a dissector, Is it possible to declare an error on the upper box?  0 Hey, I&#39;m building a dissector and wanted to know if it is possible declare an error on the upper box, where all the packets are (tcp ...)
By declaring I mean to get the color of the column red...
I know it is possible to declare and color the column in red on the middle box (where the description of the packets is found), but I want to see if it is also possible to the upper box.</description>
    </item>
    
    <item>
      <title>Wireshark does not capture network data on Windows 7 and Windows 2008</title>
      <link>/questions/16739/wireshark-does-not-capture-network-data-on-windows-7-and-windows-2008/</link>
      <pubDate>Sun, 09 Dec 2012 20:01:00 +0000</pubDate>
      
      <guid>/questions/16739/wireshark-does-not-capture-network-data-on-windows-7-and-windows-2008/</guid>
      <description>Wireshark does not capture network data on Windows 7 and Windows 2008  0 I am using the stable build - Wireshark 1.6.2 on Windows 7 32 Bit and Windows 2008 32 Bit Operating Systems. To analyse the captured network data and the service elements I am using Merge DPM. Network data is captured on Windows 7 (i.e. Wireshark running on Windows 7)and saved in .cap format NA Sniffer 2.00x so that Merge DPM can read the file.</description>
    </item>
    
    <item>
      <title>Dynamically create labels for hf_register_info</title>
      <link>/questions/16745/dynamically-create-labels-for-hf_register_info/</link>
      <pubDate>Mon, 10 Dec 2012 03:13:00 +0000</pubDate>
      
      <guid>/questions/16745/dynamically-create-labels-for-hf_register_info/</guid>
      <description>Dynamically create labels for hf_register_info  0 Hi Forum
I have a protocol that I am dissecting and I have been creating and registering each field in a hf_register_info to get the correct labels X00001 and X00002 etc for the fields.
Data (1000 entries) X0001: 0001 X0002: 4525static hf_register_info hf[] = { { &amp;amp;hf_X00001, { &#34;X00001&#34;, &#34;FOO.X00001&#34;, FT_UINT16, BASE_DEC, NULL, 0x0,NULL, HFILL } }, ... { &amp;amp;hf_X99999, { &#34;X99999&#34;, &#34;FOO.X99999&#34;, FT_UINT16, BASE_DEC, NULL, 0x0,NULL, HFILL } } }</description>
    </item>
    
    <item>
      <title>Dup ACKs question</title>
      <link>/questions/16750/dup-acks-question/</link>
      <pubDate>Mon, 10 Dec 2012 09:52:00 +0000</pubDate>
      
      <guid>/questions/16750/dup-acks-question/</guid>
      <description>Dup ACKs question  0 1I have a capture of the beginning of a file transfer where there is a number of duplicate ACKs. This capture was taken between the client and server.
 1: 15:56:07.240527 172.16.1.1.51629 &amp;gt; 192.168.1.100.80: S 1044283510:1044283510(0) win 8192 &amp;lt;mss 1460,nop,wscale 2,nop,nop,sackOK&amp;gt; 2: 15:56:07.240740 192.168.1.100.80 &amp;gt; 172.16.1.1.51629: S 1864868747:1864868747(0) ack 1044283511 win 4140 &amp;lt;mss 1380,nop,wscale 0,sackOK,eol&amp;gt; 3: 15:56:07.241290 172.16.1.1.51629 &amp;gt; 192.168.1.100.80: . ack 1864868748 win 16560 4: 15:56:07.</description>
    </item>
    
    <item>
      <title>Wireshark (WinPCap) does not see Intel X520-DA2 10 GbE NIC teaming intermittently</title>
      <link>/questions/16751/wireshark-winpcap-does-not-see-intel-x520-da2-10-gbe-nic-teaming-intermittently/</link>
      <pubDate>Mon, 10 Dec 2012 10:29:00 +0000</pubDate>
      
      <guid>/questions/16751/wireshark-winpcap-does-not-see-intel-x520-da2-10-gbe-nic-teaming-intermittently/</guid>
      <description>Wireshark (WinPCap) does not see Intel X520-DA2 10 GbE NIC teaming intermittently  0 I am running a team of two 10 GigE ports on Intel X520-DA2 network card. They work well in tandem and achieve the desired throughput. However, I see an intermittent issue whereby WireShark and my own application (using WinPCap) only show the underlying ports, failing to recognize the team adapter.
Details: Intel 17.4 NIC drivers on Windows Server 2008 R2 with all patches.</description>
    </item>
    
    <item>
      <title>Reading packet data in wireshark</title>
      <link>/questions/16752/reading-packet-data-in-wireshark/</link>
      <pubDate>Mon, 10 Dec 2012 11:16:00 +0000</pubDate>
      
      <guid>/questions/16752/reading-packet-data-in-wireshark/</guid>
      <description>Reading packet data in wireshark  0 Hello team,
i captured some openflow packets ,and i want to read the data inside Data (47 bytes) its in hexadecimal .Can i read and analyse the content of that data ?
thanks in advance
openflowasked 10 Dec &#39;12, 11:16
Tyler
1●1●1●1
accept rate: 0%
  
One Answer:
  
0I think we need some additional information:
i captured some openflow packets</description>
    </item>
    
    <item>
      <title>What is the Content-type of wireshark .cap file?</title>
      <link>/questions/16758/what-is-the-content-type-of-wireshark-cap-file/</link>
      <pubDate>Mon, 10 Dec 2012 19:55:00 +0000</pubDate>
      
      <guid>/questions/16758/what-is-the-content-type-of-wireshark-cap-file/</guid>
      <description>What is the Content-type of wireshark .cap file?  0 I use .cgi to capture files, and I want to download the file from the server side. I do not know the content-type of the .cap file, or is anyone know how to do? The file in server side can open successfully, but the downloaded file can not be opened. My .cgi code is:
#!/bin/sh #================================================= # Main # ================================================ fileis2=`ls /mnt/nfs/capture/` file_size=`ls -l /mnt/nfs/capture/$fileis2 | awk &amp;#39;{print $5}&amp;#39;` #echo $file_size echo -e &amp;quot;Content-Type:application/octet-stream&amp;quot; echo -e &amp;quot;Accept-Ranges:bytes&amp;quot; echo -e &amp;quot;Content-Length:$file_size&amp;quot; echo -e &amp;quot;Content-Disposition:attachment;filename=$fileis2\n&amp;quot; cat $fileis2And what I think that cause the problem is the Content-Type.</description>
    </item>
    
    <item>
      <title>How to filter data by Capture Filter</title>
      <link>/questions/16769/how-to-filter-data-by-capture-filter/</link>
      <pubDate>Tue, 11 Dec 2012 07:51:00 +0000</pubDate>
      
      <guid>/questions/16769/how-to-filter-data-by-capture-filter/</guid>
      <description>How to filter data by Capture Filter  0 Hi,
I would like to know who login on application and I see that by fltering the port 1100 and I have this type of line : 192.168.101.xxx 192.168.101.10 TCP 55482 &amp;gt; mctp [PSH, ACK] Seq=1352 Ack=195886 Win=65656 Len=163 But there are too many lines with this filter I need to filter data for this string &#34;LoginData&#34; but not after, during the capture, to not have too much lines (270Mb for one hour, and I want to make statistics on one month).</description>
    </item>
    
    <item>
      <title>Server 2008 send RST packet</title>
      <link>/questions/16770/server-2008-send-rst-packet/</link>
      <pubDate>Tue, 11 Dec 2012 08:08:00 +0000</pubDate>
      
      <guid>/questions/16770/server-2008-send-rst-packet/</guid>
      <description>Server 2008 send RST packet  0 Hi
We have the problem, that all our Win7 X64 computer have a dissconnect to the 2008 R2 servers with mapped drives. We don&#39;t have this problem with WinXP, only with Win7 und not just to one server. After login, the script map all the drives, but after while the mapped drives have a red X in the Explorer on the Win7 clients, WinXP never has any disconnected drives.</description>
    </item>
    
    <item>
      <title>tcp.analysis.retransmission</title>
      <link>/questions/16771/tcpanalysisretransmission/</link>
      <pubDate>Tue, 11 Dec 2012 10:18:00 +0000</pubDate>
      
      <guid>/questions/16771/tcpanalysisretransmission/</guid>
      <description>tcp.analysis.retransmission  0 Hi, Can anyone tell me that How is the tcp.analysis.retransmission works? Is it analysis only on time interval or other thing?
retransmissionasked 11 Dec &#39;12, 10:18
Saruul
6●1●1●3
accept rate: 0%
  
One Answer:
  
4 It is triggered when a packet containing a sequence is seen that should have arrived earlier, which means that there must have been a gap in the packet sequence that the &#34;</description>
    </item>
    
    <item>
      <title>pcap_next_ex never returns</title>
      <link>/questions/16774/pcap_next_ex-never-returns/</link>
      <pubDate>Tue, 11 Dec 2012 10:43:00 +0000</pubDate>
      
      <guid>/questions/16774/pcap_next_ex-never-returns/</guid>
      <description>pcap_next_ex never returns  0 This is probably more of a WinPcap question, but I call pcap_next_ex as follows:
int iRes = pcap_next_ex(pPcapDev, &amp;amp;pHdr, (const u_char**)&amp;amp;pubFrmBuf);
and it never returns.
But sending works:
pcap_sendpacket(pPcapDev, pubBuf, (int)ulLen);
Has anyone else seen this or know why pcap_next_ex fails to return an error at least.
Thanks, Brian
returns never pcap_next_exasked 11 Dec &#39;12, 10:43
brwiese
26●11●12●11
accept rate: 50%
  
One Answer:</description>
    </item>
    
    <item>
      <title>tshark crashing because of temp pcap files in /tmp</title>
      <link>/questions/16779/tshark-crashing-because-of-temp-pcap-files-in-tmp/</link>
      <pubDate>Tue, 11 Dec 2012 13:17:00 +0000</pubDate>
      
      <guid>/questions/16779/tshark-crashing-because-of-temp-pcap-files-in-tmp/</guid>
      <description>tshark crashing because of temp pcap files in /tmp  0 I am trying to run tshark for an extended period of time to reassemble NFS requests that I capture using tcpdump (with pf_ring). I am streaming the pcap to standard out from tcpdump (using -w -) and into tshark (using -i -). It seems that tshark calls dumpcap to do the packet capture (even from stdin) and then dumpcap writes the packets to the /tmp directory and then tshark reads from there.</description>
    </item>
    
    <item>
      <title>Can i filter ICMP PING for requests that never received a Reply?</title>
      <link>/questions/16780/can-i-filter-icmp-ping-for-requests-that-never-received-a-reply/</link>
      <pubDate>Tue, 11 Dec 2012 13:20:00 +0000</pubDate>
      
      <guid>/questions/16780/can-i-filter-icmp-ping-for-requests-that-never-received-a-reply/</guid>
      <description>Can i filter ICMP PING for requests that never received a Reply?  0 I have a large capture with thousands of PINGS. I know at one time i saw Request timed out on the node i was monitoring, indicating it never received a reply for those PINGS. Can i use a Wireshark filter to find the Requests that never received a Reply?
icmp filtersasked 11 Dec &#39;12, 13:20
philliplew</description>
    </item>
    
    <item>
      <title>Wireshark Decrypt SSL traffic</title>
      <link>/questions/16788/wireshark-decrypt-ssl-traffic/</link>
      <pubDate>Tue, 11 Dec 2012 19:08:00 +0000</pubDate>
      
      <guid>/questions/16788/wireshark-decrypt-ssl-traffic/</guid>
      <description>Wireshark Decrypt SSL traffic  0 Trying to decrypt SSL traffic inside Wireshark
Wireshark setup is using: 192.168.2.60(server),443(port),http(protocol - have also tried data) and associated private key
SSL decrypt log/output:
========================================================
ssl_association_remove removing TCP 443 - data handle 0375D520 Private key imported: KeyID 9a:64:14:cf:59:cf:a1:7a:55:4b:fb:c1:c4:66:b3:35:... ssl_load_key: swapping p and q parameters and recomputing u ssl_init IPv4 addr &amp;#39;192.168.2.60&amp;#39; (192.168.2.60) port &amp;#39;443&amp;#39; filename &amp;#39;C:\theta\theta2.rsa.pem&amp;#39; password(only for p12 file) &amp;#39;&amp;#39; ssl_init private key file C:\theta\theta2.</description>
    </item>
    
    <item>
      <title>unable to run tshark 1.9.0-SVN-46516</title>
      <link>/questions/16797/unable-to-run-tshark-190-svn-46516/</link>
      <pubDate>Wed, 12 Dec 2012 05:39:00 +0000</pubDate>
      
      <guid>/questions/16797/unable-to-run-tshark-190-svn-46516/</guid>
      <description>unable to run tshark 1.9.0-SVN-46516  0 Hi,
I have Linux 2.6.26.8-57.fc8 i686 i686 i386 GNU/Linux.
I downloaded src of wireshark 1.9.0-SVN-46516 from net and configured using ./configure --disable-gtktest --disable-wireshark --disable-warnings-as-errors.
Then i did make which went through fine.
Upon executing ./tshark from the directory, i get following error.
/export/home/atsuser/Tools/wireshark/wireshark-1.9.0-SVN-46516/.libs/lt-tshark: Symbol `prefs&amp;#39; has different size in shared object, consider re-linking tshark: Couldn&#39;t load module /export/home/atsuser/Tools/wireshark/wireshark-1.9.0-SVN-46516/plugins/wimaxasncp/.libs/wimaxasncp.so: /export/home/atsuser/Tools/wireshark/wireshark-1.9.0-SVN-46516/plugins/wimaxasncp/.libs/wimaxasncp.so: undefined symbol: eap_type_vals_ext
tshark: Couldn&#39;t load module /export/home/atsuser/Tools/wireshark/wireshark-1.</description>
    </item>
    
    <item>
      <title>Trace of a phone call</title>
      <link>/questions/16801/trace-of-a-phone-call/</link>
      <pubDate>Wed, 12 Dec 2012 06:36:00 +0000</pubDate>
      
      <guid>/questions/16801/trace-of-a-phone-call/</guid>
      <description>Trace of a phone call  0 With the attached trace you can see a phone call from packet 710 14:06:43.761721 192.168.140.231 192.168.100.231 H.225.0 1012 CS: setup OpenLogicalChannel CS: setup OpenLogicalChannel
To me it looks like 1720 is open and responding, Alcatel says differently and that&#39;s the problem.
From a phone call perspective the extension is dialed from 192.168.140.231&#39;s location to 192.168.100.231 and the call connects, there&#39;s dead air for about 5 seconds, then the call disconnects.</description>
    </item>
    
    <item>
      <title>WireShark bundle !without! WinPCAP</title>
      <link>/questions/16812/wireshark-bundle-without-winpcap/</link>
      <pubDate>Wed, 12 Dec 2012 08:28:00 +0000</pubDate>
      
      <guid>/questions/16812/wireshark-bundle-without-winpcap/</guid>
      <description>WireShark bundle !without! WinPCAP  0 Dear Developers,
Is the WireShark installer officially available without WinPCap and other 3rd party libraries for download? We would like to introduce the tool at the company but without the capturing functionality. We only need it to open and analyze PCAP files.
Thank you, Attila
winpcap without wiresharkasked 12 Dec &#39;12, 08:28
nemmas
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Unable to set Promiscuous Mode</title>
      <link>/questions/16813/unable-to-set-promiscuous-mode/</link>
      <pubDate>Wed, 12 Dec 2012 08:36:00 +0000</pubDate>
      
      <guid>/questions/16813/unable-to-set-promiscuous-mode/</guid>
      <description>Unable to set Promiscuous Mode  0 Hello all:
I&#39;m unable to get Wireshark to view &#34;promiscuously&#34; on my home LAN. Home LAN consists of:
MINT 13 Mate machine one Ubuntu machine (11 something I think) one mac os X laptop and two windows xp boxes
I&#39;m working from the MINT machine (13) and have successfully configured wireshark ( I think ) such that I should be able to successfully capture all the traffic on my network.</description>
    </item>
    
    <item>
      <title>tshark output with port number</title>
      <link>/questions/16827/tshark-output-with-port-number/</link>
      <pubDate>Thu, 13 Dec 2012 02:00:00 +0000</pubDate>
      
      <guid>/questions/16827/tshark-output-with-port-number/</guid>
      <description>tshark output with port number  0 greetings!
I&#39;d like to know if it&#39;s possible to make tshark output packets with port number. For example, I use the following command:
tshark -R &#34;ip.addr==1.1.1.1&#34;
and I get:
163.742781 2.2.2.2 -&amp;gt; 1.1.1.1 SIP Request: INVITE sip:[email protected];user=phone
163.743301 1.1.1.1 -&amp;gt; 2.2.2.2 ICMP Destination unreachable (Port unreachable)
and here I don&#39;t see what port the INVITE was sent to. Is there an option to have a port in the output?</description>
    </item>
    
    <item>
      <title>cannot decode RTP and SKINNY VOIP capture</title>
      <link>/questions/16831/cannot-decode-rtp-and-skinny-voip-capture/</link>
      <pubDate>Thu, 13 Dec 2012 04:03:00 +0000</pubDate>
      
      <guid>/questions/16831/cannot-decode-rtp-and-skinny-voip-capture/</guid>
      <description>cannot decode RTP and SKINNY VOIP capture  0 Hi all,
I hope someone can help, I have a Cisco uc540 system with a Ciscosf300 24 POE switch. I have interface gig 4 setup as a span port to SPAN vlan 100 (the voice VLAN).
I can see plenty of rtp and SKINNY traffic, but when i go to telephony and voip, I can see the call, the from and to numbers, the call will not decode.</description>
    </item>
    
    <item>
      <title>VoIP Roaming Call</title>
      <link>/questions/16835/voip-roaming-call/</link>
      <pubDate>Thu, 13 Dec 2012 05:32:00 +0000</pubDate>
      
      <guid>/questions/16835/voip-roaming-call/</guid>
      <description>VoIP Roaming Call  0 Roaming calls and RTP path minimization. The issue is that roaming calls are separated into different parts in Wireshark looking like multiple calls instead of a single call. Here is my comment to a person more knowledgable than myself, with their follow up answer. My question is &#34;why can&#39;t Wireshark understand that this is one phone call (roaming mobile call) and display it as a single call?</description>
    </item>
    
    <item>
      <title>How do you capture from firewall?</title>
      <link>/questions/16839/how-do-you-capture-from-firewall/</link>
      <pubDate>Thu, 13 Dec 2012 08:08:00 +0000</pubDate>
      
      <guid>/questions/16839/how-do-you-capture-from-firewall/</guid>
      <description>How do you capture from firewall?  0 I have a WatchGuard XTM 505 Firewall appliance. I need to see the amount of data flow that comes in and out of the network over time to establish what kind of throughput the WAN connection demands. We are considering T1 as this is the best option available in our area. The point of this is to establish if we need two Bonded T1s or if a single T1 will work for our purposes.</description>
    </item>
    
    <item>
      <title>Issues in capturing Wireshark filters</title>
      <link>/questions/16843/issues-in-capturing-wireshark-filters/</link>
      <pubDate>Thu, 13 Dec 2012 09:22:00 +0000</pubDate>
      
      <guid>/questions/16843/issues-in-capturing-wireshark-filters/</guid>
      <description>Issues in capturing Wireshark filters  0 I am trying to launch wireshark from the cli with the following options...
wireshark -k -i eth2 -a filesize:1000000 -f &amp;lt;capture filter=&#34;&#34;&amp;gt; The issue I have is that I want to use a pre-defined wireshark filter... when I run the above with the actual filter in the cli cmd it works, when I use a pre-defined one it fails..
Working example:
wireshark -k -i eth2 -a filesize:1000000 -f &#34;</description>
    </item>
    
    <item>
      <title>questions matching &amp;#x27;how to convert RTP amr packet to wav file and also these IP streams are</title>
      <link>/questions/16844/questions-matching-how-to-convert-rtp-amr-packet-to-wav-file-and-also-these-ip-streams-are/</link>
      <pubDate>Thu, 13 Dec 2012 09:49:00 +0000</pubDate>
      
      <guid>/questions/16844/questions-matching-how-to-convert-rtp-amr-packet-to-wav-file-and-also-these-ip-streams-are/</guid>
      <description>questions matching &amp;lsquo;how to convert RTP amr packet to wav file and also these IP streams are  0 What would easier way to decode RTP amr packet to wav file. The RTP packets are encoded in IPSEC tunnel but if we know the keys to deocde it?
decode rtp packetasked 13 Dec &#39;12, 09:49
Dees
1●3●3●3
accept rate: 0%
hm.. what exactly is your question?
(14 Dec &#39;12, 07:43) Kurt Knochner ♦</description>
    </item>
    
    <item>
      <title>Packet timestamps with capinfos/tshark (lauched from cygwin) are off by several hours</title>
      <link>/questions/16846/packet-timestamps-with-capinfostshark-lauched-from-cygwin-are-off-by-several-hours/</link>
      <pubDate>Thu, 13 Dec 2012 12:31:00 +0000</pubDate>
      
      <guid>/questions/16846/packet-timestamps-with-capinfostshark-lauched-from-cygwin-are-off-by-several-hours/</guid>
      <description>Packet timestamps with capinfos/tshark (lauched from cygwin) are off by several hours  0 I have a cap file captured with tcpdump on a Linux system. The first paket is known to be dated Thu Dec 06 11:47:00. This is what I see when I run capinfos -a or tcpdump -r on Linux, and also when I open the file in Wireshark on Windows.
When I run capinfos -m on Windows, I am told the time of the first packet is Thu Dec 06 16:47:00 2012.</description>
    </item>
    
    <item>
      <title>LTE RRC: how to prepare data?</title>
      <link>/questions/16847/lte-rrc-how-to-prepare-data/</link>
      <pubDate>Thu, 13 Dec 2012 12:53:00 +0000</pubDate>
      
      <guid>/questions/16847/lte-rrc-how-to-prepare-data/</guid>
      <description>LTE RRC: how to prepare data?  0 Hello!
I am trying to use wireshark to decode LTE protocols data, captured from the system. It works for S1 (going to hex, then tex2pcap, then tshark -V).
But, something is lost with RRC, I can not get it tunning:
Maybe I should add something to RRC, like direction?
Best regards, thanks, HNY
Iztok
example in hex, RC_CONNECTION_REQUEST
000000 58 55 95 97 74 06 zz</description>
    </item>
    
    <item>
      <title>How to view sent/received packets for the application layer?</title>
      <link>/questions/16848/how-to-view-sentreceived-packets-for-the-application-layer/</link>
      <pubDate>Thu, 13 Dec 2012 13:56:00 +0000</pubDate>
      
      <guid>/questions/16848/how-to-view-sentreceived-packets-for-the-application-layer/</guid>
      <description>How to view sent/received packets for the application layer?  0 Hello everyone
I have a school project that i&#39;m working on, and some of the questions are to: Show the number of packets sent and received for each application layer. Can anyone please assist me with this.
Thanks in advance
application layer packetsasked 13 Dec &#39;12, 13:56
ahad917
1●1●1●1
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Dumpcap timestamp	discrepancy</title>
      <link>/questions/16849/dumpcap-timestamp-discrepancy/</link>
      <pubDate>Thu, 13 Dec 2012 14:19:00 +0000</pubDate>
      
      <guid>/questions/16849/dumpcap-timestamp-discrepancy/</guid>
      <description>Dumpcap timestamp discrepancy  0 Hi,
I am trying to capture packet data to a file using dumpcap script in libpcap format on centos 6.2.
When left the capture script running for an extended period of time (weeks/months) it seems the timestamps recorded in our captures slowly drift backwards. The timestamp recorded in the filename as each new file is created matches the system time relatively well (from observation; i.e. when BAT_99717_20090415222212.</description>
    </item>
    
    <item>
      <title>botnet traffic capture wanted</title>
      <link>/questions/16853/botnet-traffic-capture-wanted/</link>
      <pubDate>Thu, 13 Dec 2012 14:39:00 +0000</pubDate>
      
      <guid>/questions/16853/botnet-traffic-capture-wanted/</guid>
      <description>botnet traffic capture wanted  0 hi i want please any pucket captured by wireshark for any botnet using http protocol like (spyeye , bobax , clickbot , rustock)
botnetasked 13 Dec &#39;12, 14:39
mais
1●1●1●1
accept rate: 0%
 converted to question 14 Dec &#39;12, 02:04 
grahamb ♦
19.8k●3●30●206
please answer me and thanks for help me
(13 Dec &#39;12, 14:42) mais  
One Answer:</description>
    </item>
    
    <item>
      <title>Limit ethernet devices</title>
      <link>/questions/16857/limit-ethernet-devices/</link>
      <pubDate>Thu, 13 Dec 2012 17:25:00 +0000</pubDate>
      
      <guid>/questions/16857/limit-ethernet-devices/</guid>
      <description>Limit ethernet devices  0 Hi there,
Is possible to limit capture devices only to group members? like wireshark group can capture only on ethernet device eth0 where another group can capture only on eth1 ?
(i&#39;ve already done the http://wiki.wireshark.org/CaptureSetup/CapturePrivileges)
br.
Pidgreen
ethernet security linux dumpcap limitingasked 13 Dec &#39;12, 17:25
pidgreen
1●1●1●1
accept rate: 0%
You&#39;ll have to specify the platform. On Linux I&#39;m not sure, since it&#39;s capability based, on MAC OSX it may be possible through bpf permissions.</description>
    </item>
    
    <item>
      <title>editcap does not produce a pcap file</title>
      <link>/questions/16861/editcap-does-not-produce-a-pcap-file/</link>
      <pubDate>Fri, 14 Dec 2012 00:24:00 +0000</pubDate>
      
      <guid>/questions/16861/editcap-does-not-produce-a-pcap-file/</guid>
      <description>editcap does not produce a pcap file  0 Hi,
Using Wireshark (version 1.8.4) on Windows 7, I captured a couple of hundred packets in a pcap file. (using pcap and not pcapng format). Then I used the editcap command line utility as below to retain only 184th packet.
editcap -r in.pcap out.pcap 184
I copied these two pcap files onto a Fedora Linux machine.
$ file in.pcap
small.pcap: tcpdump capture file (little-endian) - version 2.</description>
    </item>
    
    <item>
      <title>ASN2WRS does not compile</title>
      <link>/questions/16863/asn2wrs-does-not-compile/</link>
      <pubDate>Fri, 14 Dec 2012 02:08:00 +0000</pubDate>
      
      <guid>/questions/16863/asn2wrs-does-not-compile/</guid>
      <description>ASN2WRS does not compile  0 Hello, I tried to compile my own dissector yesterday. I&#39;m quite new to the matter, so I copied already available configuration files (Makefile, .cnf) from the inap dissector, changed the name there and removed asn files which I do not use. Then I put the name of my asn file in. After execution of make I got additional files in the directory: parsetab.py, -exp.cnf. Nothing else.</description>
    </item>
    
    <item>
      <title>Unable to download file in HTTPS</title>
      <link>/questions/16866/unable-to-download-file-in-https/</link>
      <pubDate>Fri, 14 Dec 2012 04:21:00 +0000</pubDate>
      
      <guid>/questions/16866/unable-to-download-file-in-https/</guid>
      <description>Unable to download file in HTTPS  0 Hi
We are facing some issue in which client(browser IE8) intermittently fails to download file over HTTPS. First time it successfully downloads the file on subsequent attempt it downloads the file partially 50MB out of 133 MB and says download is successful.
wireshark dump says that after some time client sends FIN, ACK
download https file intermittentasked 14 Dec &#39;12, 04:21
lodha13</description>
    </item>
    
    <item>
      <title>When is a duplicate ACK not involved in retranmission</title>
      <link>/questions/16870/when-is-a-duplicate-ack-not-involved-in-retranmission/</link>
      <pubDate>Fri, 14 Dec 2012 05:24:00 +0000</pubDate>
      
      <guid>/questions/16870/when-is-a-duplicate-ack-not-involved-in-retranmission/</guid>
      <description>When is a duplicate ACK not involved in retranmission  0 I have a capture file made on a unix server which has duplicate ACK&#39;s in there which are very close in time (0.000012) to the original packet it is a duplicate for. Nor do the DUP acks in this trace ever trigger a retransmission.
http://www.cs.unc.edu/~jeffay/dirt/FAQ/dupacks.html
So I stumbled on the above link, stating that &#34;the book&#34; actually has an explanation.</description>
    </item>
    
    <item>
      <title>wireshark and centos 5.7</title>
      <link>/questions/16882/wireshark-and-centos-57/</link>
      <pubDate>Fri, 14 Dec 2012 07:03:00 +0000</pubDate>
      
      <guid>/questions/16882/wireshark-and-centos-57/</guid>
      <description>wireshark and centos 5.7  0 Hello,
I use centos 5.7, I wish to install the wireshark source code. When I set up the lastest version with a checkout of http: // anonsvn.wireshark.org / wireshark / trunk, he asks me to install some packages which exists only in higher versions then 5.7. Do you know what wireshark version i have to install (http: // anonsvn.wireshark.org /)? Thank you
centos5.7asked 14 Dec &#39;12, 07:03</description>
    </item>
    
    <item>
      <title>Connections reset, they claim on our side.  Am I reading this log correctly?  Not very familiar with wireshark</title>
      <link>/questions/16908/connections-reset-they-claim-on-our-side-am-i-reading-this-log-correctly-not-very-familiar-with-wireshark/</link>
      <pubDate>Fri, 14 Dec 2012 11:20:00 +0000</pubDate>
      
      <guid>/questions/16908/connections-reset-they-claim-on-our-side-am-i-reading-this-log-correctly-not-very-familiar-with-wireshark/</guid>
      <description>Connections reset, they claim on our side. Am I reading this log correctly? Not very familiar with wireshark  0 We We have a client who uses a web service to pull a report from us. About 5-10% of the time they do not get this report. We are not seeing the request come through on our side at all when this happens. They claim we are closing the connection prematurely.</description>
    </item>
    
    <item>
      <title>Link Layer Protocol ?</title>
      <link>/questions/16910/link-layer-protocol/</link>
      <pubDate>Fri, 14 Dec 2012 11:41:00 +0000</pubDate>
      
      <guid>/questions/16910/link-layer-protocol/</guid>
      <description>Link Layer Protocol ?  0 If I look at a packet, how can I tell what the link-layer protocol is? Where is it shown in wireshark??
Many thanks.. Sorry if this is an obvious question.
protocol layer linkasked 14 Dec &#39;12, 11:41
smc20
6●3●3●5
accept rate: 0%
  
One Answer:
  
1I would say it is the first layer of the packet you should look at ;-)</description>
    </item>
    
    <item>
      <title>GPRS-NS in MPLS, MPLS/IP, MPLS/GRE</title>
      <link>/questions/16926/gprs-ns-in-mpls-mplsip-mplsgre/</link>
      <pubDate>Sat, 15 Dec 2012 05:45:00 +0000</pubDate>
      
      <guid>/questions/16926/gprs-ns-in-mpls-mplsip-mplsgre/</guid>
      <description>GPRS-NS in MPLS, MPLS/IP, MPLS/GRE  0 Hello, seems tool dont offer me Decode as &#34;GPRS-NS&#34; protocol inside MPLS packet. In fact we have GPRS-NS packets transferred in MPLS network but can&#39;t inspect them. I can sent an example of tcpdump file.
gprs-ns mplsasked 15 Dec &#39;12, 05:45
vlradler
1●1●1●1
accept rate: 0%
Please file an enhancement request at bugs.wireshark.org and attach an example capture file.
(15 Dec &#39;12, 07:07) Bill Meier ♦♦   </description>
    </item>
    
    <item>
      <title>My dissector which was compiled with 1.8, doesn&amp;#x27;t work on official 1.8</title>
      <link>/questions/16928/my-dissector-which-was-compiled-with-18-doesnt-work-on-official-18/</link>
      <pubDate>Sat, 15 Dec 2012 07:18:00 +0000</pubDate>
      
      <guid>/questions/16928/my-dissector-which-was-compiled-with-18-doesnt-work-on-official-18/</guid>
      <description>My dissector which was compiled with 1.8, doesn&amp;rsquo;t work on official 1.8  1 Hey, I compiled (VS2010) my dissector with the 1.8 trunk release and even tried it the the 1.8.4 official source release but it still doesn&#39;t work with the official 1.8.4 release.
The dissector works only for the release that I build him for: If I build it with trunk 1.8, It only works for my own build.</description>
    </item>
    
    <item>
      <title>How many TCP connections were required to load this site - page 491</title>
      <link>/questions/16934/how-many-tcp-connections-were-required-to-load-this-site-page-491/</link>
      <pubDate>Sat, 15 Dec 2012 12:06:00 +0000</pubDate>
      
      <guid>/questions/16934/how-many-tcp-connections-were-required-to-load-this-site-page-491/</guid>
      <description>How many TCP connections were required to load this site - page 491  0 Ch.20 - page 491 - http-google2011.pcapng says we browsed to www,google.com. How Many TCP connections were required to load this site.
My Ans. is 6 tcp connections or packets 1-6 is that correct? to verify I checked client http request: packet #4 GET / HTTP/1.1 details show: Host: www.google.com and packet 6 (server response shows) HTTP/1.</description>
    </item>
    
    <item>
      <title>TextWindow.new() doesn&amp;#x27;t work well?</title>
      <link>/questions/16942/textwindownew-doesnt-work-well/</link>
      <pubDate>Sun, 16 Dec 2012 07:37:00 +0000</pubDate>
      
      <guid>/questions/16942/textwindownew-doesnt-work-well/</guid>
      <description>TextWindow.new() doesn&amp;rsquo;t work well?  0 Hi everybody I tried to show a window containing a message using TextWindow.new() but it always gave me a message that tshark stopped working when I run the file, the try is in a lua file that doesn&#39;t containing anything except TextWindow.new() and its method functions like append and so on, What&#39;s the problem? I did this because I wanted to try it alone before I merge it inside a big lua file.</description>
    </item>
    
    <item>
      <title>64-bit Wireshark build fails in Windows</title>
      <link>/questions/16952/64-bit-wireshark-build-fails-in-windows/</link>
      <pubDate>Sun, 16 Dec 2012 22:13:00 +0000</pubDate>
      
      <guid>/questions/16952/64-bit-wireshark-build-fails-in-windows/</guid>
      <description>64-bit Wireshark build fails in Windows  0 I copied a 32-bit build code(after running distclean) and changed &#34;WIRESHARK_TARGET_PLATFORM=win64&#34; in the config.nmake file.
Then I setup the build environment using the command: &#34;CALL &#34;C:\Program Files\Microsoft SDKs\Windows\v7.1\Bin\SetEnv.cmd&#34; /x64&#34;
Then, after running the commands:
nmake -f Makefile.nmake distclean
nmake -f Makefile.nmake setup
nmake -f Makefile.nmake distclean
in that order, when I build the code I get the following error:
 Microsoft (R) Program Maintenance Utility Version 10.</description>
    </item>
    
    <item>
      <title>error: &amp;#x27;dissect_...&amp;#x27; undeclared here (not in a function)</title>
      <link>/questions/16962/error-dissect_-undeclared-here-not-in-a-function/</link>
      <pubDate>Mon, 17 Dec 2012 02:36:00 +0000</pubDate>
      
      <guid>/questions/16962/error-dissect_-undeclared-here-not-in-a-function/</guid>
      <description>error: &amp;lsquo;dissect_&amp;hellip;&amp;rsquo; undeclared here (not in a function)  0 Hello, community. I keep getting this error in the ...fn.c file while compiling my dissector. What would be the reason for it?
Best regards Ewgenij
function undeclared compiler errorasked 17 Dec &#39;12, 02:36
Ewgenijkkg
66●8●9●15
accept rate: 60%
  
2 Answers:
  
0 OK, I figured it out :-) My main ASN.1 file imported structure definitions from other ASN.</description>
    </item>
    
    <item>
      <title>Analyzing HTTP protocol using Tshark</title>
      <link>/questions/16964/analyzing-http-protocol-using-tshark/</link>
      <pubDate>Mon, 17 Dec 2012 03:23:00 +0000</pubDate>
      
      <guid>/questions/16964/analyzing-http-protocol-using-tshark/</guid>
      <description>Analyzing HTTP protocol using Tshark  2 2Hello! I&#39;m trying to analyze HTTP requests and responses using Tshark and following command.
 /usr/local/bin/tshark -R &amp;quot;http.response or http.request&amp;quot; \ -T fields -E separator=&amp;quot;|&amp;quot; \ -e frame.time_epoch \ -e ip.src \ -e tcp.srcport \ -e ip.dst \ -e tcp.dstport \ -e http.request.version \ -e http.request.method \ -e http.host \ -e http.request.uri \ -e http.user_agent \ -e http.response.code \ -e http.content_type \ -e http.</description>
    </item>
    
    <item>
      <title>Heuristic dissector works with 1.6.x but not with 1.8.x</title>
      <link>/questions/16973/heuristic-dissector-works-with-16x-but-not-with-18x/</link>
      <pubDate>Mon, 17 Dec 2012 07:02:00 +0000</pubDate>
      
      <guid>/questions/16973/heuristic-dissector-works-with-16x-but-not-with-18x/</guid>
      <description>Heuristic dissector works with 1.6.x but not with 1.8.x  0 I&#39;ve developed a very simple heuristic dissector for a proprietary protocol using Wireshark 1.6.8. It works flawlessly and the heuristics identify the payload on top of TCP.
The same sources compile fine with Wireshark 1.8.4 but Wireshark appears to be unable to identify the payload. The frames are identified if and only if I force it with &#39;Dissect as..&#39;.</description>
    </item>
    
    <item>
      <title>802.11ac capture</title>
      <link>/questions/16980/80211ac-capture/</link>
      <pubDate>Mon, 17 Dec 2012 08:58:00 +0000</pubDate>
      
      <guid>/questions/16980/80211ac-capture/</guid>
      <description>802.11ac capture  0 Hey
Are there any adapters supporting 802.11ac packet capture today? Any that wireshark supports?
JP
adapter 802.11acasked 17 Dec &#39;12, 08:58
JP-NYC
1●1●1●1
accept rate: 0%
  
One Answer:
  
0That&#39;s not primarily a problem of Wireshark, but rather a problem of driver support for the OS.
Windows
The driver needs to be compliant with WinPcap to be able to capture packets in promiscuous mode.</description>
    </item>
    
    <item>
      <title>how to create sub dissectors</title>
      <link>/questions/16981/how-to-create-sub-dissectors/</link>
      <pubDate>Mon, 17 Dec 2012 09:04:00 +0000</pubDate>
      
      <guid>/questions/16981/how-to-create-sub-dissectors/</guid>
      <description>how to create sub dissectors  0 Hey, I&#39;m building a dissector which is the main dissector. After I read some variable, according to it, I want to continue dissecting with a suitable sub dissector. I didn&#39;t find any simple example about &#34;sub dissectors&#34;.
Alternatively, I thought about continue dissecting with the same dissector (because it is the same protocol, just different versions), with somehow writing inside the main dissector all of the dissecting options for each version.</description>
    </item>
    
    <item>
      <title>SSL and encrypted alert</title>
      <link>/questions/16986/ssl-and-encrypted-alert/</link>
      <pubDate>Mon, 17 Dec 2012 11:13:00 +0000</pubDate>
      
      <guid>/questions/16986/ssl-and-encrypted-alert/</guid>
      <description>SSL and encrypted alert  0 I&#39;ve configured an Apache server as a front for a Tomcat. On the httpd server, I&#39;ve configured an https connection. This connection is mandatory, so all requests made using http are redirected to the https schema.
My site is really slow using this environment. I suppose that there is a misconfiguration somewhere, but I don&#39;t know where.
I&#39;ve made a capture with Wireshark, and I see some encrypted alert.</description>
    </item>
    
    <item>
      <title>how to check QOS marking in the media capture packet</title>
      <link>/questions/16994/how-to-check-qos-marking-in-the-media-capture-packet/</link>
      <pubDate>Mon, 17 Dec 2012 12:37:00 +0000</pubDate>
      
      <guid>/questions/16994/how-to-check-qos-marking-in-the-media-capture-packet/</guid>
      <description>how to check QOS marking in the media capture packet  0 Hi,
I am trying to find what QOS marking endpoint is sending and receiving on the media captured packets, Kindly advise what field in the SIP SDP I can a look to find QOS marking?
Thanks,
ZB
rtpasked 17 Dec &#39;12, 12:37
zubik2
26●1●1●1
accept rate: 100%
  
One Answer:
  
0 Never mind, I figured it out.</description>
    </item>
    
    <item>
      <title>Unknown protocol analysis</title>
      <link>/questions/16996/unknown-protocol-analysis/</link>
      <pubDate>Mon, 17 Dec 2012 14:57:00 +0000</pubDate>
      
      <guid>/questions/16996/unknown-protocol-analysis/</guid>
      <description>Unknown protocol analysis  0 Hello,
I have a piece of software &#34;CDRVBLiveClient.exe&#34; that is used to pull call detail data off of a Nortel BCM 50. This is a sample VB application that came with the BCM 50 hardware. However, this hardware is long since out of service, as a result I cannot obtain the API documentation that would allow me to create my own application. This piece of software requires only three inputs - IP address (of the hardware), username, and password.</description>
    </item>
    
    <item>
      <title>runtime error after changing the detail type of time field</title>
      <link>/questions/17000/runtime-error-after-changing-the-detail-type-of-time-field/</link>
      <pubDate>Mon, 17 Dec 2012 17:50:00 +0000</pubDate>
      
      <guid>/questions/17000/runtime-error-after-changing-the-detail-type-of-time-field/</guid>
      <description>runtime error after changing the detail type of time field  0 The wireshark version is &#39;1.8.1&#39;.
After I changed the detail type of time field to &#39;U-time..xxx&#39; Whenever I open the file, runtime error occurs.
The content of runtime error is following
Runtime Error! Program:C\Program Files\Wireshark\wireshark.exe This application has requested the Runtime to terminate it in an unusual way. Please contact the application&#39;s support team for more information.
I removed the wireshark and re-installed but the problem is remained, still.</description>
    </item>
    
    <item>
      <title>[closed] Crawl HTTP protocol (关于抓取HTTP协议的问题)</title>
      <link>/questions/17001/crawl-http-protocol-http/</link>
      <pubDate>Mon, 17 Dec 2012 17:59:00 +0000</pubDate>
      
      <guid>/questions/17001/crawl-http-protocol-http/</guid>
      <description>[closed] Crawl HTTP protocol (关于抓取HTTP协议的问题)  0 非常抱歉，我的英语不是很好，所以只能写中文了。在使用wireshark过程中我遇到一个问题，就是我想在抓包之前设置过滤，只抓取HTTP协议的数据包，为什么我在对网卡进行设置的时候在过滤条件中输入HTTP显示的就是经色，这表示这个设置不对的，但是输入TCP之类的都可以。我想问一下这是什么原因？
(As translated by Google): I&#39;m sorry, my English is not very good, and we can only write Chinese. Use wireshark process, I encountered a problem, is that I would like to set up filters in Ethereal before, only to grab the HTTP protocol packet, why when I set the NIC to input HTTP is shown by the color filter conditions this means that the settings wrong, but can enter the TCP like.</description>
    </item>
    
    <item>
      <title>UAT - Help - ZigBee</title>
      <link>/questions/17020/uat-help-zigbee/</link>
      <pubDate>Tue, 18 Dec 2012 05:20:00 +0000</pubDate>
      
      <guid>/questions/17020/uat-help-zigbee/</guid>
      <description>UAT - Help - ZigBee  0 Hello Guys,
I would like to know if it is possible to add record at the UAT by the dissectors (according to the packets), not only in Edit-&amp;gt;prefs. I want to use in ZigBee, adding Keys automatically, like the command &#34;Transport-Key&#34;, I want to save the key permanently, not only in the current session.
I hope to hear from you.
Regards, Guilherme Zanforlin.</description>
    </item>
    
    <item>
      <title>Unrecognized fields and dumping the analyzes to a file</title>
      <link>/questions/17042/unrecognized-fields-and-dumping-the-analyzes-to-a-file/</link>
      <pubDate>Tue, 18 Dec 2012 09:01:00 +0000</pubDate>
      
      <guid>/questions/17042/unrecognized-fields-and-dumping-the-analyzes-to-a-file/</guid>
      <description>Unrecognized fields and dumping the analyzes to a file  0 Hi,
We&#39;re planning on extending an existing dissector, to support a new protocol extension. In order to see that all &#34;holes&#34; had been implemented, we have a pcap file that contains packets which should be all correctly analyzed by our extension.
Is there a way to dump the analyzes of the Wireshark to a file and not only to display them by the GUI ?</description>
    </item>
    
    <item>
      <title>detecting botnet possible?</title>
      <link>/questions/17058/detecting-botnet-possible/</link>
      <pubDate>Wed, 19 Dec 2012 07:31:00 +0000</pubDate>
      
      <guid>/questions/17058/detecting-botnet-possible/</guid>
      <description>detecting botnet possible?  0 Hi, some scriptkiddy is bragging about having my PC in his botnet. I don&#39;t really know what to do or even if I&#39;m really in his botnet, so I&#39;d like to check that point first.
Is it possible to detect a botnet via wireshark? If yes, how would I know I&#39;m infected?
Thanks in advance fellows...
detect infection botnetasked 19 Dec &#39;12, 07:31
QAI
0●1●1●3</description>
    </item>
    
    <item>
      <title>WinPcap not receiving data</title>
      <link>/questions/17059/winpcap-not-receiving-data/</link>
      <pubDate>Wed, 19 Dec 2012 07:40:00 +0000</pubDate>
      
      <guid>/questions/17059/winpcap-not-receiving-data/</guid>
      <description>WinPcap not receiving data  0 I have an odd situation and will try to explain with detail what I am seeing and would really appreciate some help fixing this.
On 2 pc&#39;s my setup is Windows 7 Ultimate, Service Pack 1 and have WinPcap 4.1.2 and Windows 7 Professional, SP1 and WinPcap 4.1.2 on a third pc. The PC&#39;s with Windows 7 Ultimate, Service Pack have Symantec EndPoint Protection version 11.</description>
    </item>
    
    <item>
      <title>RDP connection drops intermittently</title>
      <link>/questions/17067/rdp-connection-drops-intermittently/</link>
      <pubDate>Wed, 19 Dec 2012 09:07:00 +0000</pubDate>
      
      <guid>/questions/17067/rdp-connection-drops-intermittently/</guid>
      <description>RDP connection drops intermittently  0 Hey Guys
Thanks for reading my questions, this forum is my last resort as I am out of ideas.
We have users that connect to a remote server outside of our network to perform some admin tasks and everything has been working fine until a few weeks ago. Users started complaining that their RDP session keeps freezing then drops completely with the error message &#34;</description>
    </item>
    
    <item>
      <title>Dissecting CLNP over X.25 (ISO 8473-3) with the ICAO&amp;#x27;s LREF header compression</title>
      <link>/questions/17071/dissecting-clnp-over-x25-iso-8473-3-with-the-icaos-lref-header-compression/</link>
      <pubDate>Wed, 19 Dec 2012 10:59:00 +0000</pubDate>
      
      <guid>/questions/17071/dissecting-clnp-over-x25-iso-8473-3-with-the-icaos-lref-header-compression/</guid>
      <description>Dissecting CLNP over X.25 (ISO 8473-3) with the ICAO&amp;rsquo;s LREF header compression  0 Hello, I want to analyse the CLNP PDU coming from X.25 (SNCDF). In packat-clnp.c we have dissector_add_uint(&#34;x.25.spi&#34;, NLPID_ISO8473_CLNP, clnp_handle); So we add the dissector referecend by clnp_handle to the dissector table referenced by x.25.spi for the unit NLPID_ISO8473_CLNP. so why we don&#39;t have the detail of the CLNP PDU??
Thank you
x.25 sndcf clnpasked 19 Dec &#39;12, 10:59</description>
    </item>
    
    <item>
      <title>Alfa AWUS036NH can&amp;#x27;t set monitor mode in Mac OS</title>
      <link>/questions/17077/alfa-awus036nh-cant-set-monitor-mode-in-mac-os/</link>
      <pubDate>Wed, 19 Dec 2012 12:49:00 +0000</pubDate>
      
      <guid>/questions/17077/alfa-awus036nh-cant-set-monitor-mode-in-mac-os/</guid>
      <description>Alfa AWUS036NH can&amp;rsquo;t set monitor mode in Mac OS  0 Hello,
I&#39;m using Alfa AWUS036NH, Wireshark 1.8.4 and Mac OS 10.8.2. I can&#39;t set monitor mode, that&#39;s what I get:
a disabled checkbox :(
Is there any way to turn on monitor mode with this card and mac os?
best regards, Rorax
os mac alfa monitor modeasked 19 Dec &#39;12, 12:49
rorax
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>FDST protocol</title>
      <link>/questions/17081/fdst-protocol/</link>
      <pubDate>Wed, 19 Dec 2012 22:40:00 +0000</pubDate>
      
      <guid>/questions/17081/fdst-protocol/</guid>
      <description>FDST protocol  0 Can you add FDST protocol to your program? Please. It would be create?
Sorry for my &#34;not so good&#34; english.
Могли бы Вы добавить поддержку протокола FDST в вашу программу?
fdstasked 19 Dec &#39;12, 22:40
Curecool
6●2●2●4
accept rate: 0%
  
One Answer:
  
0Please file an enhancement bug at bugs.wireshark.org. Please also add details about that protocol (links, specs, etc.) as google does not return anything usefull for &#34;</description>
    </item>
    
    <item>
      <title>Want to learn WireShark</title>
      <link>/questions/17083/want-to-learn-wireshark/</link>
      <pubDate>Thu, 20 Dec 2012 02:01:00 +0000</pubDate>
      
      <guid>/questions/17083/want-to-learn-wireshark/</guid>
      <description>Want to learn WireShark  0 Hello Everybody,
 I want to learn troubleshooting using wireshark like slow network file copies and lot more. What is the best way to learn.Thanks Skak
learningasked 20 Dec &#39;12, 02:01
skak
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Google for Wireshark tutorials, there are plenty out there. Also, here&#39;s a video showing the basics.
answered 20 Dec &#39;12, 03:50</description>
    </item>
    
    <item>
      <title>Packet ordering when capturing on multiple interfaces</title>
      <link>/questions/17089/packet-ordering-when-capturing-on-multiple-interfaces/</link>
      <pubDate>Thu, 20 Dec 2012 03:43:00 +0000</pubDate>
      
      <guid>/questions/17089/packet-ordering-when-capturing-on-multiple-interfaces/</guid>
      <description>Packet ordering when capturing on multiple interfaces  0 A colleague asked and I didn&#39;t really know the answer:
When capturing on multiple interfaces which is the preferred sorting order so that packets are displayed in order of arrival at the capturing machine? Sorting by time appears to give the best results, sorting by Frame No. leads to inconsistent results.
If sorting by time is best, is even that guaranteed to display the packets in arrival order, or are there &#34;</description>
    </item>
    
    <item>
      <title>Difference between running a Lua script in Wireshark and/or tshark</title>
      <link>/questions/17094/difference-between-running-a-lua-script-in-wireshark-andor-tshark/</link>
      <pubDate>Thu, 20 Dec 2012 05:14:00 +0000</pubDate>
      
      <guid>/questions/17094/difference-between-running-a-lua-script-in-wireshark-andor-tshark/</guid>
      <description>Difference between running a Lua script in Wireshark and/or tshark  0 Thanks @kurt,@helloworld, another question: what is the difference in running the script from wireshark or tshark? what are the benefits of each way?
Comment: I converted the comment from this question: http://ask.wireshark.org/questions/16942/textwindownew-doesnt-work-well
lua tshark wiresharkasked 20 Dec &#39;12, 05:14
Leena
51●17●18●21
accept rate: 0%
 edited 20 Dec &#39;12, 07:50 
Kurt Knochner ♦
24.8k●10●39●237</description>
    </item>
    
    <item>
      <title>How to upgrade wireshark from 3gpp release 9 to release 10?</title>
      <link>/questions/17115/how-to-upgrade-wireshark-from-3gpp-release-9-to-release-10/</link>
      <pubDate>Thu, 20 Dec 2012 21:11:00 +0000</pubDate>
      
      <guid>/questions/17115/how-to-upgrade-wireshark-from-3gpp-release-9-to-release-10/</guid>
      <description>How to upgrade wireshark from 3gpp release 9 to release 10?  0 I want to upgrade my wireshark to support LTE Release 10. Please guide me how to start ?
3gpp release10 lteasked 20 Dec &#39;12, 21:11
Scorp
1●1●1●1
accept rate: 0%
  
2 Answers:
  
2Hi, I think the development version mostly does that. But basically you would have to compare all the dissectors for the LTE protocols with the respective protocol specification and make updates where needed.</description>
    </item>
    
    <item>
      <title>Issue about crawl HTTP</title>
      <link>/questions/17118/issue-about-crawl-http/</link>
      <pubDate>Thu, 20 Dec 2012 22:52:00 +0000</pubDate>
      
      <guid>/questions/17118/issue-about-crawl-http/</guid>
      <description>Issue about crawl HTTP  0 I met a problem while using wireshark, which was that i only wanted to crawl the data package of HTTP by setting a filter, but when i input HTTP in filtering condition as setting the network card, why it showed red meaning the setting was wrong, but input TCP etc. , it showed right. please tell me what is the reason. Though filtering condition can be set to be tcp port 80, it can only crawl the HTTP passed the 80 port.</description>
    </item>
    
    <item>
      <title>TCP ACKed unseen segment</title>
      <link>/questions/17132/tcp-acked-unseen-segment/</link>
      <pubDate>Fri, 21 Dec 2012 06:34:00 +0000</pubDate>
      
      <guid>/questions/17132/tcp-acked-unseen-segment/</guid>
      <description>TCP ACKed unseen segment  0 1Why do wireshark say &#34;TCP ACKed unseen segment&#34; in frame 718 (see below) when the segment has been seen in frame 713 ??
No. Time Source Destination Protocol Length Info 712 14:18:42.604065 10.11.78.193 10.168.1.11 TLSv1 1434 Ignored Unknown Record Frame 712: 1434 bytes on wire (11472 bits), 1434 bytes captured (11472 bits) Ethernet II, Src: Cisco_ff:fc:f0 (00:08:e3:ff:fc:f0), Dst: Hewlett-_77:98:28 (18:a9:05:77:98:28) Internet Protocol Version 4, Src: 10.</description>
    </item>
    
    <item>
      <title>Why would NAT cause ZeroWindowProbeAck?</title>
      <link>/questions/17134/why-would-nat-cause-zerowindowprobeack/</link>
      <pubDate>Fri, 21 Dec 2012 07:19:00 +0000</pubDate>
      
      <guid>/questions/17134/why-would-nat-cause-zerowindowprobeack/</guid>
      <description>Why would NAT cause ZeroWindowProbeAck?  0 I have an embedded device that is running an http server that returns [TCP ZeroWindowProbeAck] packets if and only if the gateway/router that the server lives on has NAT turned on.
More details:
The embedded device is using Z-World Rabbit Web Server and the router is a Digi ConnectPort - the ConnectPort LAN lives on 10.10.6.1.
In the ConnectPort there is a setting called Enable Network Address Translation (NAT).</description>
    </item>
    
    <item>
      <title>Wireshark not capturing packets from notebook</title>
      <link>/questions/17137/wireshark-not-capturing-packets-from-notebook/</link>
      <pubDate>Fri, 21 Dec 2012 09:24:00 +0000</pubDate>
      
      <guid>/questions/17137/wireshark-not-capturing-packets-from-notebook/</guid>
      <description>Wireshark not capturing packets from notebook  0 Hi. I got a TCP/IP hardware device (a printer) communicating with a Windows server. I want to monitor the packets between the printer and the server. During my tests, I kept a window running &#34;ping -t&#34; to be sure there was some activity (ICMP packets).
When I run Wireshark on this server, I see all the packets - TCP (commands and answers) and ICMP (ping).</description>
    </item>
    
    <item>
      <title>Special characters displayed differently</title>
      <link>/questions/17141/special-characters-displayed-differently/</link>
      <pubDate>Fri, 21 Dec 2012 11:37:00 +0000</pubDate>
      
      <guid>/questions/17141/special-characters-displayed-differently/</guid>
      <description>Special characters displayed differently  0 I am using Wireshark to capture traffic from an application we are testing. Currently the UN/PWD&#39;s are transmitted via http. I can capture the username just fine. However, the the password contains the # which wireshark either omits to display or shows the % in place of the #.
The # is valid as the UN/PWD combination works.
passwordasked 21 Dec &#39;12, 11:37
rojasj</description>
    </item>
    
    <item>
      <title>how to unhide a interface</title>
      <link>/questions/17144/how-to-unhide-a-interface/</link>
      <pubDate>Fri, 21 Dec 2012 12:30:00 +0000</pubDate>
      
      <guid>/questions/17144/how-to-unhide-a-interface/</guid>
      <description>how to unhide a interface  0 I am running wireshark 1.8.4 on windows pro I am attempting to do remote capture on a Linux 5 box. I was able to get the remote interface and I hide it. Now if I go to manage interfaces it does not show up but it shows up in the interface list. I need to delete it but I can&#39;t because it doesn&#39;t show up it the remote interface list.</description>
    </item>
    
    <item>
      <title>Large rtt or packets lost factors,which affects tcp performance most?</title>
      <link>/questions/17156/large-rtt-or-packets-lost-factorswhich-affects-tcp-performance-most/</link>
      <pubDate>Sat, 22 Dec 2012 01:12:00 +0000</pubDate>
      
      <guid>/questions/17156/large-rtt-or-packets-lost-factorswhich-affects-tcp-performance-most/</guid>
      <description>Large rtt or packets lost factors,which affects tcp performance most?  0 Usually,when we check one tcp flow traffic and evaluate if the packets lost or large rtt exit.If the two factors both exit,how to judge which effect the tcp throughput seriously? Does anybody know the good way to judge this?
large rtt packets lostasked 22 Dec &#39;12, 01:12
chinasan
0●6●6●8
accept rate: 0%
 edited 22 Dec &#39;12, 03:03</description>
    </item>
    
    <item>
      <title>Getting capture stats manually</title>
      <link>/questions/17159/getting-capture-stats-manually/</link>
      <pubDate>Sat, 22 Dec 2012 03:26:00 +0000</pubDate>
      
      <guid>/questions/17159/getting-capture-stats-manually/</guid>
      <description>Getting capture stats manually  0 Hello to all, I am curious how can i get the stats from a packet capture manually ( instead of going to statistics-&amp;gt;summary menu), such as packet count, total bytes, and avg MBit/sec.
It&#39;s just an educational question, i don&#39;t want to use it in real life.
Thanks!!!
bytes statistics manually packet wiresharkasked 22 Dec &#39;12, 03:26
EvilDude
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Difference between RST/ACK and RST responses in a Null scan</title>
      <link>/questions/17164/difference-between-rstack-and-rst-responses-in-a-null-scan/</link>
      <pubDate>Sat, 22 Dec 2012 08:33:00 +0000</pubDate>
      
      <guid>/questions/17164/difference-between-rstack-and-rst-responses-in-a-null-scan/</guid>
      <description>Difference between RST/ACK and RST responses in a Null scan  0 From what I have researched so far on NULL scans, there are 2 conflicting answers regarding the results of the NULL scan.
In a NULL scan, some sources state that if RST/ACK response is received from the server, that means the server is closed.
However, other sources state RST/ACK as only RST. Is there a difference between the 2 of them ?</description>
    </item>
    
    <item>
      <title>&amp;quot;Duplicate protocol name&amp;quot; errors on Wireshark on OS X</title>
      <link>/questions/17179/duplicate-protocol-name-errors-on-wireshark-on-os-x/</link>
      <pubDate>Sat, 22 Dec 2012 14:52:00 +0000</pubDate>
      
      <guid>/questions/17179/duplicate-protocol-name-errors-on-wireshark-on-os-x/</guid>
      <description>&amp;ldquo;Duplicate protocol name&amp;rdquo; errors on Wireshark on OS X  0 i am also not able to run wireshark, after i installed the x11 update. I gor error messages on the command line:
(wireshark-bin:8895): Gtk-WARNING **: Unable to locate theme engine in module_path: &amp;quot;clearlooks&amp;quot;, 23:33:23 Err Duplicate protocol name &amp;quot;Coseventcomm Dissector Using GIOP API&amp;quot;! This might be caused by an inappropriate plugin or a development error. Peers-iMac-4:asl peer$ pwdMaybe a development error?</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t filter MAC address in a CAP file, help?</title>
      <link>/questions/17180/cant-filter-mac-address-in-a-cap-file-help/</link>
      <pubDate>Sat, 22 Dec 2012 15:02:00 +0000</pubDate>
      
      <guid>/questions/17180/cant-filter-mac-address-in-a-cap-file-help/</guid>
      <description>Can&amp;rsquo;t filter MAC address in a CAP file, help?  0 Hey guys, I have 80 gigs of capture logs in CAP files. I need to filter a specific MAC address from those in order to save the files to a much smaller file size. For some reason, I am able to find the MAC address by looking at the Source address from within 1 of the CAP files but if I try to filter that MAC address from the file it finds nothing.</description>
    </item>
    
    <item>
      <title>Running tshark as a root, dofile file is disabled problem</title>
      <link>/questions/17190/running-tshark-as-a-root-dofile-file-is-disabled-problem/</link>
      <pubDate>Sun, 23 Dec 2012 03:53:00 +0000</pubDate>
      
      <guid>/questions/17190/running-tshark-as-a-root-dofile-file-is-disabled-problem/</guid>
      <description>Running tshark as a root, dofile file is disabled problem  1 Whenever i try to analyze packets using tshark on Ubuntu with root permission i got the following error, however when i switch to user profile (su berkey), there is no problem. Why this occurs? is there a solution?
tshark: Lua: Error during loading: [string &#34;/usr/share/wireshark/init.lua&#34;]:45: dofile has been disabled Running as user &#34;root&#34; and group &#34;root&#34;. This could be dangerous.</description>
    </item>
    
    <item>
      <title>How can I export data from TCPstream Graph and calculate the Throughput</title>
      <link>/questions/17192/how-can-i-export-data-from-tcpstream-graph-and-calculate-the-throughput/</link>
      <pubDate>Sun, 23 Dec 2012 05:38:00 +0000</pubDate>
      
      <guid>/questions/17192/how-can-i-export-data-from-tcpstream-graph-and-calculate-the-throughput/</guid>
      <description>How can I export data from TCPstream Graph and calculate the Throughput  0 Dear All
I need to create a file that allows me to calculate the throughput of the network and check with the values ​​of the graph TCPStream. How can I export the graph data TCPStream.
I have calculated the throughput considering the following formula:
throughput = packet length / (time of arrival of the packet - time of arrival of the previous packet).</description>
    </item>
    
    <item>
      <title>XP dropping Ethernet packets seen by Wireshark</title>
      <link>/questions/17193/xp-dropping-ethernet-packets-seen-by-wireshark/</link>
      <pubDate>Sun, 23 Dec 2012 06:22:00 +0000</pubDate>
      
      <guid>/questions/17193/xp-dropping-ethernet-packets-seen-by-wireshark/</guid>
      <description>XP dropping Ethernet packets seen by Wireshark  0 I have some hardware connected by Ethernet to an XP system via a USB adaptor. The hardware is sending a UDP broadcast packet to the XP every 3 seconds. Wireshark running on the XP system sees these packets:
Frame 1 (342 bytes on wire, 342 bytes captured)
Ethernet II, Src: 40:5f:c2:b9:21:d1 (40:5f:c2:b9:21:d1), Dst: Broadcast (ff:ff:ff:ff:ff:ff)
Internet Protocol, Src: 0.0.0.0 (0.0.0.0), Dst: 0.</description>
    </item>
    
    <item>
      <title>How to edit the resulting file dump?</title>
      <link>/questions/17194/how-to-edit-the-resulting-file-dump/</link>
      <pubDate>Sun, 23 Dec 2012 06:44:00 +0000</pubDate>
      
      <guid>/questions/17194/how-to-edit-the-resulting-file-dump/</guid>
      <description>How to edit the resulting file dump?  0 How to edit the resulting file dump. Trim the time until the right moment. I need to send it to technical support, but with this program I unfortunately did not work.
edit editcap pcapasked 23 Dec &#39;12, 06:44
Kallikanzarosa
1●1●1●3
accept rate: 0%
 edited 27 Dec &#39;12, 07:56 
multipleinte...
1.3k●15●23●40
  
One Answer:
  
2Have a look at editcap which comes with Wireshark.</description>
    </item>
    
    <item>
      <title>sniff wpa2 network</title>
      <link>/questions/17200/sniff-wpa2-network/</link>
      <pubDate>Sun, 23 Dec 2012 12:48:00 +0000</pubDate>
      
      <guid>/questions/17200/sniff-wpa2-network/</guid>
      <description>sniff wpa2 network  1 I need to sniff HTTP traffic on WPA2 network at home. I am running wireshark 1.8.2 on debian linux. I have TPLink TL-WN722N usb wireless adaptor on this machine. I have put this adaptor in monitor mode and also specified WPA2 password in preferences. I captured packets on mon0 interface. It does not show any HTTP packets. I am not sure whether it was able to decrypt packets successfully.</description>
    </item>
    
    <item>
      <title>The NPF driver isn&amp;#x27;t running.  You may have trouble capturing or listing interfaces.</title>
      <link>/questions/17235/the-npf-driver-isnt-running-you-may-have-trouble-capturing-or-listing-interfaces/</link>
      <pubDate>Mon, 24 Dec 2012 09:08:00 +0000</pubDate>
      
      <guid>/questions/17235/the-npf-driver-isnt-running-you-may-have-trouble-capturing-or-listing-interfaces/</guid>
      <description>The NPF driver isn&amp;rsquo;t running. You may have trouble capturing or listing interfaces.  0  i just installed in and started it for the first time and it gave me this errorThe NPF driver isn&#39;t running. You may have trouble capturing or listing interfaces.
then when i tried to list the available interfaces ..it gave me an error saying There are no interfaces on which a capture can be done.</description>
    </item>
    
    <item>
      <title>Tick interval question</title>
      <link>/questions/17245/tick-interval-question/</link>
      <pubDate>Wed, 26 Dec 2012 11:57:00 +0000</pubDate>
      
      <guid>/questions/17245/tick-interval-question/</guid>
      <description>Tick interval question  0 Hello. I am doing some testing of UDP video streams that are being multicasted. I am playing back 8 streams while capturing with wireshark. When I generate an IO graph using a tick interval of 1sec, I get the expected avg of just under 140Mbps (8 streams @ ~17Mbps each). I am playing around with the tick interval and I don&#39;t understand why the bandwidth seems to increase with every decrease of the tick interval?</description>
    </item>
    
    <item>
      <title>Wireless packet captures 802.11 IEEE</title>
      <link>/questions/17247/wireless-packet-captures-80211-ieee/</link>
      <pubDate>Wed, 26 Dec 2012 16:56:00 +0000</pubDate>
      
      <guid>/questions/17247/wireless-packet-captures-80211-ieee/</guid>
      <description>Wireless packet captures 802.11 IEEE  0 Hi All,
I was looking through site in the network and trying to get as much wireless packet captures for my own study that I can download or check online. I just had luck with the few that are available here. If you now about any site with sever wireless captures to study behaviors like association/reassociation, beaconing, EAP authentication , roaming would be very helpfull.</description>
    </item>
    
    <item>
      <title>Can not hear anything from VoIP stream with many red Ds</title>
      <link>/questions/17248/can-not-hear-anything-from-voip-stream-with-many-red-ds/</link>
      <pubDate>Wed, 26 Dec 2012 18:51:00 +0000</pubDate>
      
      <guid>/questions/17248/can-not-hear-anything-from-voip-stream-with-many-red-ds/</guid>
      <description>Can not hear anything from VoIP stream with many red Ds  0 I did a VoIP filter with G.729 codec. However, after I decoded the stream and played them, I could not hear anything. There were many Ds (Drop by Jitter Buffer) in these stream, which you can see in the image. Does many red Ds make the voice quality lower? Can I do furthermore on these data?Any help is highly appreciate.</description>
    </item>
    
    <item>
      <title>VLAN tag with Intel 82579LM</title>
      <link>/questions/17251/vlan-tag-with-intel-82579lm/</link>
      <pubDate>Thu, 27 Dec 2012 00:31:00 +0000</pubDate>
      
      <guid>/questions/17251/vlan-tag-with-intel-82579lm/</guid>
      <description>VLAN tag with Intel 82579LM  0 Hello,
I would like to see VLAN tags in Wireshark when using SPAN on switch. switch is configured properly to send output packets with their tags. OS is Windows t Pro x64, Laptop is Thinkpad X230.
when I am edit registry &#34;MonitorMode=1&#34;/&#34;MonitorModeEnabled=1&#34;, I see that Wireshark not show tagged packet at all. untagged packets displayed properly without any issue.
if I remove &#34;MonitorMode&#34;/&#34;MonitorModeEnabled&#34;, than all packets is displayed but without tagged information.</description>
    </item>
    
    <item>
      <title>x509 decode with tshark</title>
      <link>/questions/17260/x509-decode-with-tshark/</link>
      <pubDate>Thu, 27 Dec 2012 02:14:00 +0000</pubDate>
      
      <guid>/questions/17260/x509-decode-with-tshark/</guid>
      <description>x509 decode with tshark  0 Hello. I have a great problem using tshark. A have a pcap file with SSL certificate. After pressing «Decode as -&amp;gt; Certificate » in Wireshark i see something like picture below. Every field have its real name.
But when im trying to open and decode this cert file in tshark – a see something like the next picture – fields are decoded correctly, but I don`t see field names – subjectPublicKey e.</description>
    </item>
    
    <item>
      <title>Is it possible to setup a capture filter for syslog.msg data only</title>
      <link>/questions/17278/is-it-possible-to-setup-a-capture-filter-for-syslogmsg-data-only/</link>
      <pubDate>Thu, 27 Dec 2012 12:39:00 +0000</pubDate>
      
      <guid>/questions/17278/is-it-possible-to-setup-a-capture-filter-for-syslogmsg-data-only/</guid>
      <description>Is it possible to setup a capture filter for syslog.msg data only  0 I&#39;m looking to capture packets that match only have syslog info matching the filter &#34;successful&#34;. Because of the number of packets coming to the device, I&#39;m not looking for a display filter but a CAPTURE FILTER.
I have the first part easy as &#34;port syslog&#34; but must missing the last part. In the display filter I would use &#34;</description>
    </item>
    
    <item>
      <title>tcp reset by the server due to 2 consecutive SYNs</title>
      <link>/questions/17280/tcp-reset-by-the-server-due-to-2-consecutive-syns/</link>
      <pubDate>Thu, 27 Dec 2012 13:07:00 +0000</pubDate>
      
      <guid>/questions/17280/tcp-reset-by-the-server-due-to-2-consecutive-syns/</guid>
      <description>tcp reset by the server due to 2 consecutive SYNs  0 Hi,
I have a sequence of tcp connection establishment as follows:
client sends a syn to serverclient do not hear a response within 2.996secondsclient initiates a second syn to serverserver acknowledges for the syn. not sure if its for the first syn or second syn. but looking at the timestamp its matching with the second synclient receives a RST,ACK.</description>
    </item>
    
    <item>
      <title>Help recording VoIP Calls?</title>
      <link>/questions/17291/help-recording-voip-calls/</link>
      <pubDate>Thu, 27 Dec 2012 19:14:00 +0000</pubDate>
      
      <guid>/questions/17291/help-recording-voip-calls/</guid>
      <description>Help recording VoIP Calls?  0 Hello everyone,
I am trying to create an audio installation for an art show next season which requires live sampling of phone conversations from willing participants. I have turned to Wireshark as a means of recording these calls wirelessly. So far, I have tried to use the &#34;VoIP Calls&#34; feature under the Telephony menu to capture conversations and record them, but the calls i&#39;m making are not being picked up by Wireshark.</description>
    </item>
    
    <item>
      <title>BFD with MPLS packets are not proper in wireshark.[Not visible]</title>
      <link>/questions/17296/bfd-with-mpls-packets-are-not-proper-in-wiresharknot-visible/</link>
      <pubDate>Fri, 28 Dec 2012 00:02:00 +0000</pubDate>
      
      <guid>/questions/17296/bfd-with-mpls-packets-are-not-proper-in-wiresharknot-visible/</guid>
      <description>BFD with MPLS packets are not proper in wireshark.[Not visible]  0 1Hi Team, i am new to this tool. my question looks silly. sorry for that :).
How to check/analyze BFD in MPLS packet through wireshark 1.6 version. or suggest any alternate solution.
thanks Rajesh Kumar v
wireshark mpls rajesh bfdasked 28 Dec &#39;12, 00:02
Rajesh Kumar V
1●1●2●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>compiling wireshark with lua enabled</title>
      <link>/questions/17306/compiling-wireshark-with-lua-enabled/</link>
      <pubDate>Fri, 28 Dec 2012 08:51:00 +0000</pubDate>
      
      <guid>/questions/17306/compiling-wireshark-with-lua-enabled/</guid>
      <description>compiling wireshark with lua enabled  0 Hi,
I want to compile wireshark 1.8.0 version with lua enabled on centos 6.2.
Here are the steps that I tried, 1) downloaded and extracted the wireshark source.
2) ./configure --with-lua=/usr/
3) make
4) created and rpm and installed it in the same system
when i launch wireshark in about me section it says compiled without lua, although the .configure command output did say configured with lua library = yes.</description>
    </item>
    
    <item>
      <title>Show connection upload speed with IO Graphs</title>
      <link>/questions/17313/show-connection-upload-speed-with-io-graphs/</link>
      <pubDate>Sat, 29 Dec 2012 06:02:00 +0000</pubDate>
      
      <guid>/questions/17313/show-connection-upload-speed-with-io-graphs/</guid>
      <description>Show connection upload speed with IO Graphs  0 hi,
im looking for a way to graph only the upload or download traffic for one connection, is this possible?
what ive found:
how fast a connection is at the moment(probably up+download speed combined): http://ask.wireshark.org/questions/1242/speed-of-sending-and-receiving-packets selecting a filter A-&amp;gt;B or B-&amp;gt;A both showed the same value for my test application.
or how much data was downloaded by conversation x http://ask.wireshark.org/questions/82/can-wireshark-monitor-bandwidth-usage-per-applicationprocess
connection.speedasked 29 Dec &#39;12, 06:02</description>
    </item>
    
    <item>
      <title>rawshark output format for 802.11 and radiotap headers</title>
      <link>/questions/17317/rawshark-output-format-for-80211-and-radiotap-headers/</link>
      <pubDate>Sun, 30 Dec 2012 02:25:00 +0000</pubDate>
      
      <guid>/questions/17317/rawshark-output-format-for-80211-and-radiotap-headers/</guid>
      <description>rawshark output format for 802.11 and radiotap headers  0 1Hi,
I want to use rawshark to read packets from pipe and print some useful information for me.
Here&#39;s the scenario. 1. Remote machine with wireless interface in monitor mode capturing with tcpdump and pipe to netcat 2. Another remote machine read from machine 1 netcat stream and pipes data to rawshark 3. rawshark have to output parsed information in useful for me format.</description>
    </item>
    
    <item>
      <title>how to use wireshark with Tata Photon Plus on Linux?</title>
      <link>/questions/17318/how-to-use-wireshark-with-tata-photon-plus-on-linux/</link>
      <pubDate>Sun, 30 Dec 2012 05:01:00 +0000</pubDate>
      
      <guid>/questions/17318/how-to-use-wireshark-with-tata-photon-plus-on-linux/</guid>
      <description>how to use wireshark with Tata Photon Plus on Linux?  0 Hello, I have a Tata photon plus (EC1260) device. How can I use wireshark in combination with this device
Thank you
linux tataphoton+ wiresharkasked 30 Dec &#39;12, 05:01
Bharathi
1●1●1●1
accept rate: 0%
 edited 24 Jul &#39;13, 12:34 
Guy Harris ♦♦
17.4k●3●35●196
  
2 Answers:
  
0As you did not mention your OS, I assume Windows, as there is only Tata Photon software for Windows.</description>
    </item>
    
    <item>
      <title>Decode telnet session information</title>
      <link>/questions/17319/decode-telnet-session-information/</link>
      <pubDate>Sun, 30 Dec 2012 11:12:00 +0000</pubDate>
      
      <guid>/questions/17319/decode-telnet-session-information/</guid>
      <description>Decode telnet session information  0 Hello, I am using Wireshark for couples weeks. As I learning and searching the possibility... I would like to know If I can capture the password for a user created from a telnet.
Ok here is the scenario. I have modem/router doing test at home. I can login to the device via telnet and wireshark is able to find the username and password easily. After, I wanted to go furthers.</description>
    </item>
    
    <item>
      <title>Your Download contained a Trojan Dropper!</title>
      <link>/questions/17325/your-download-contained-a-trojan-dropper/</link>
      <pubDate>Mon, 31 Dec 2012 01:02:00 +0000</pubDate>
      
      <guid>/questions/17325/your-download-contained-a-trojan-dropper/</guid>
      <description>Your Download contained a Trojan Dropper!  0 Why does this download come with a trojan dropper that AVG found?
trojan infected virusasked 31 Dec &#39;12, 01:02
NetworkInformer
1●1●1●1
accept rate: 0%
  
2 Answers:
  
2as you did not mention what you downloaded and where, it is hard to say why your AV product believes to have found something. Can you please add more details?</description>
    </item>
    
    <item>
      <title>wireshark is not showing the contents of the message body</title>
      <link>/questions/17336/wireshark-is-not-showing-the-contents-of-the-message-body/</link>
      <pubDate>Mon, 31 Dec 2012 03:22:00 +0000</pubDate>
      
      <guid>/questions/17336/wireshark-is-not-showing-the-contents-of-the-message-body/</guid>
      <description>wireshark is not showing the contents of the message body  0 can any please tell me are there any setting preferences to change how message body content is shown??
body messageasked 31 Dec &#39;12, 03:22
gantashalavenki
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Please enable the following setting to see &#39;raw text&#39; in SIP messages.
Edit -&amp;gt; Preferences -&amp;gt; SIP -&amp;gt; Display raw text for SIP Messages</description>
    </item>
    
    <item>
      <title>Wireshark fails to decipher application data out of SSL</title>
      <link>/questions/17341/wireshark-fails-to-decipher-application-data-out-of-ssl/</link>
      <pubDate>Mon, 31 Dec 2012 04:56:00 +0000</pubDate>
      
      <guid>/questions/17341/wireshark-fails-to-decipher-application-data-out-of-ssl/</guid>
      <description>Wireshark fails to decipher application data out of SSL  0 I&#39;ve looked around for similar logs, but found no actual solution. Dump was taken using
tcpdump -s 0 -i eth0 -v -w dump.pcapLog: pastebin Dump: cloudshark
I&#39;m out of ideas what may be wrong, some time earlier it worked as usual, but now it does not.
ssl tlsv1asked 31 Dec &#39;12, 04:56
Alexey Pelykh
6●1●1●2
accept rate: 0%
 edited 31 Dec &#39;12, 05:26</description>
    </item>
    
    <item>
      <title>Installing Wireshark on Mountain LIon</title>
      <link>/questions/17364/installing-wireshark-on-mountain-lion/</link>
      <pubDate>Mon, 31 Dec 2012 16:03:00 +0000</pubDate>
      
      <guid>/questions/17364/installing-wireshark-on-mountain-lion/</guid>
      <description>Installing Wireshark on Mountain LIon  0 i&#39;m installing wireshark 1.8.4 64 bit on OSX 10.8.2 macbook pro 2.7 GHz Intel Core i7. Installed XQuartz - installed the wireshark and after clicking through on the install the program is nowhere to be found. Its like it never installed - cannot locate it applications or in the directory in terminal.
Any ideas?
mountain lion 10.8.2 osxasked 31 Dec &#39;12, 16:03
fullondan</description>
    </item>
    
    <item>
      <title>SSL transfer inexplicable holdoff?</title>
      <link>/questions/17365/ssl-transfer-inexplicable-holdoff/</link>
      <pubDate>Mon, 31 Dec 2012 17:02:00 +0000</pubDate>
      
      <guid>/questions/17365/ssl-transfer-inexplicable-holdoff/</guid>
      <description>SSL transfer inexplicable holdoff?  0 First, I apologize for the cropped picture... I tried to get everything relevent. Len=0 on all Red-&amp;gt;Blue packets.
So yeah, Red is a workstation downloading a file over SSL from distant server Blue. I have no access or control over distant server blue, nor any of the infrastructure beyond the first two hops. There&#39;s some NAT and IOS based firewalls on my end, but other than that, it&#39;s all &#34;</description>
    </item>
    
    <item>
      <title>udp traffic analyzer</title>
      <link>/questions/17369/udp-traffic-analyzer/</link>
      <pubDate>Tue, 01 Jan 2013 01:41:00 +0000</pubDate>
      
      <guid>/questions/17369/udp-traffic-analyzer/</guid>
      <description>udp traffic analyzer  0 hi..i want to know something about wireshark.pls tell me how i can analyize udp traffic in wireshark i want to measure packet delay,thrughput,jitter n packet loss from source to destination.i think wireshark is best tool for tcp traffic.plzz help me if its possible in wireshark.plz i&#39;m totaly interested in udp traffic.plzz ans me
udp trafficasked 01 Jan &#39;13, 01:41
ahsan
1●1●1●1
accept rate: 0%
 edited 04 Jan &#39;13, 12:18</description>
    </item>
    
    <item>
      <title>Install Wireshark / WinPcap on Windows 8</title>
      <link>/questions/17374/install-wireshark-winpcap-on-windows-8/</link>
      <pubDate>Tue, 01 Jan 2013 13:38:00 +0000</pubDate>
      
      <guid>/questions/17374/install-wireshark-winpcap-on-windows-8/</guid>
      <description>Install Wireshark / WinPcap on Windows 8  0 I have a laptop with Win 8 64 bit. When I tried to install I got a WinPcap error. Any recommendations...
winpcap windows8asked 01 Jan &#39;13, 13:38
japarke
1●1●1●1
accept rate: 0%
 edited 02 Jan &#39;13, 05:17 
Jaap ♦
11.7k●16●101
  
One Answer:
  
1as you did not mention the error, I assume it&#39;s the &#34;</description>
    </item>
    
    <item>
      <title>Cannot open a capture file</title>
      <link>/questions/17393/cannot-open-a-capture-file/</link>
      <pubDate>Wed, 02 Jan 2013 12:01:00 +0000</pubDate>
      
      <guid>/questions/17393/cannot-open-a-capture-file/</guid>
      <description>Cannot open a capture file  0 When trying to open a capture file I get an error: &#34;This application has requested the Runitime to terminate it in an unusual way. Please contact the application&#39;s support team for more information.&#34;
failure open fileasked 02 Jan &#39;13, 12:01
MMArtinezNCH
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1Sounds like either a bug or OutOfMemory, how big is the pcap file that you are opening?</description>
    </item>
    
    <item>
      <title>How to further decode Airpeek encapsulated packet</title>
      <link>/questions/17398/how-to-further-decode-airpeek-encapsulated-packet/</link>
      <pubDate>Wed, 02 Jan 2013 13:37:00 +0000</pubDate>
      
      <guid>/questions/17398/how-to-further-decode-airpeek-encapsulated-packet/</guid>
      <description>How to further decode Airpeek encapsulated packet  0 Hi there,
I captured some wireless traffic through the Cisco Wireless controller. It encapsulates the traffic in the Airpeek format. I decoded the packets with Airpeek however it only decoded up to the layer 2 header which is the &#34;IEEE 802.11 Data&#34;. The rest (IP header, TCP/UDP header, ...etc) is not decoded and it is just listed as &#34;Data&#34;... Is there way to even decode this part?</description>
    </item>
    
    <item>
      <title>What does large delta time tells?</title>
      <link>/questions/17405/what-does-large-delta-time-tells/</link>
      <pubDate>Wed, 02 Jan 2013 18:42:00 +0000</pubDate>
      
      <guid>/questions/17405/what-does-large-delta-time-tells/</guid>
      <description>What does large delta time tells?  0 I have quite a lot of high delta times from receiving multicast. What does it mean in general? How did the delta time calculated?
multicastasked 02 Jan &#39;13, 18:42
bryanevil
1●2●2●3
accept rate: 0%
  
One Answer:
  
0The &#34;delta time&#34; is exactly whatever you originally created the column to be:
If you created the column it using Edit !</description>
    </item>
    
    <item>
      <title>How to tell packet loss is happen locally?</title>
      <link>/questions/17406/how-to-tell-packet-loss-is-happen-locally/</link>
      <pubDate>Wed, 02 Jan 2013 19:45:00 +0000</pubDate>
      
      <guid>/questions/17406/how-to-tell-packet-loss-is-happen-locally/</guid>
      <description>How to tell packet loss is happen locally?  0 We have a program for receive udp multicast broadcast, the packet rate it will receive can be up to 3000 packet/sec. ~1500bytes max. size per packet.
Our situation is that we are experiencing packet loss when it hit that rate. Assuming packet never loss during network transportation, we want to know are the packets loss cause by overflow in the network card buffer, or is the network card not fast enough, and it dropped the packets?</description>
    </item>
    
    <item>
      <title>Is data represent by wireshark in windows and linux FC5 is different?</title>
      <link>/questions/17412/is-data-represent-by-wireshark-in-windows-and-linux-fc5-is-different/</link>
      <pubDate>Thu, 03 Jan 2013 03:34:00 +0000</pubDate>
      
      <guid>/questions/17412/is-data-represent-by-wireshark-in-windows-and-linux-fc5-is-different/</guid>
      <description>Is data represent by wireshark in windows and linux FC5 is different?  0 My Windows-7 machine received UDP packet which further trace by wireshark , my first UDP packet start with data &#34;2c991002&#34; and this is correct data which i am expecting.
same exercise i am doing on fedora-5 machine and show my first UDP packet start with data &#34;043dd720&#34;
why this data differ is linux based wireshark have different data representation scheme.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t find 104apci filter</title>
      <link>/questions/17415/cant-find-104apci-filter/</link>
      <pubDate>Thu, 03 Jan 2013 08:16:00 +0000</pubDate>
      
      <guid>/questions/17415/cant-find-104apci-filter/</guid>
      <description>Can&amp;rsquo;t find 104apci filter  0 Hi!
I have done two installations of wireshark Version 1.8.3, 32bit . One in a virtual machine (w-xp) and one in my host machine (w-7).
I want to capture telegrams for the iec 60870-5-104 protocol. I can find this filter (104apci) on the virtual machin by pressing &#34;Expression&#34; in Wireshark. But not on the host machine.
I have used the same installation files. How can I get that filter on my host machine?</description>
    </item>
    
    <item>
      <title>Losing Packets??</title>
      <link>/questions/17420/losing-packets/</link>
      <pubDate>Thu, 03 Jan 2013 14:27:00 +0000</pubDate>
      
      <guid>/questions/17420/losing-packets/</guid>
      <description>Losing Packets??  0 I&#39;m getting SEVERAL entries in my packet capture that I beleive indicate lost packets. TCP Dup ACK &amp;amp; TCP Retrasmission to be specific. I see there is a problem here, but can someone walk me step by step through identifying what the cause of this is? I&#39;m assuming that somewhere within the capture it will tell me the workstation or piece of equipment that is causing this problem?</description>
    </item>
    
    <item>
      <title>Identifying traffic bursts</title>
      <link>/questions/17431/identifying-traffic-bursts/</link>
      <pubDate>Fri, 04 Jan 2013 02:44:00 +0000</pubDate>
      
      <guid>/questions/17431/identifying-traffic-bursts/</guid>
      <description>Identifying traffic bursts  0 Hello!
I have an issue in our LAN (ca. 50 clients).
I encounter high traffic bursts (traffic peaks at a very short timeframe). The problem is, that because of that we have quality issues with our VoIP lines as the router cannot handle the QoS queues during these bursts.
The bursts come irregularly every 10 seconds. I can use a monitoring port to monitor the total traffic in the LAN with Wireshark.</description>
    </item>
    
    <item>
      <title>Help for TCP bogus frame</title>
      <link>/questions/17444/help-for-tcp-bogus-frame/</link>
      <pubDate>Fri, 04 Jan 2013 09:10:00 +0000</pubDate>
      
      <guid>/questions/17444/help-for-tcp-bogus-frame/</guid>
      <description>Help for TCP bogus frame  0 Hello, Can you tell me what is the problem for the trame between an embedded system (IP 1923.168.0.34) and IE in a PC (IP:192.168.0.252) I don&#39;t understand why IE have not send ACK after the number 6 packet.
Thanks
http tcpasked 04 Jan &#39;13, 09:10
aamgr
6●1●1●4
accept rate: 0%
 edited 04 Jan &#39;13, 09:32 
grahamb ♦
19.8k●3●30●206</description>
    </item>
    
    <item>
      <title>Wireshark on Acer C7 running ChrUbuntu</title>
      <link>/questions/17448/wireshark-on-acer-c7-running-chrubuntu/</link>
      <pubDate>Fri, 04 Jan 2013 10:36:00 +0000</pubDate>
      
      <guid>/questions/17448/wireshark-on-acer-c7-running-chrubuntu/</guid>
      <description>Wireshark on Acer C7 running ChrUbuntu  1 Hi- I recently installed ChrUbuntu on my Acer C7 ChromeBook in a dual boot configuration. While running ChrUbuntu I downloaded and installed Wireshark. It does not see any ethernet adapters, wireless or wired. Has anybody tried this and if so how did you get it to work? Thanks!
c-7 chrubuntu acerasked 04 Jan &#39;13, 10:36
snivvy
16●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark and pcaps</title>
      <link>/questions/17451/wireshark-and-pcaps/</link>
      <pubDate>Fri, 04 Jan 2013 11:39:00 +0000</pubDate>
      
      <guid>/questions/17451/wireshark-and-pcaps/</guid>
      <description>Wireshark and pcaps  0 How do I use Wireshark to look at pcaps?How do I tcp-dump and how do I use the tcp-dump to look at pcaps?How do I tcp-prep to turn the pcaps into something that can be replayed?How do I tcp-replay to play the traffic on the network against firewalls and servers?replay dump tcp pcaps prepasked 04 Jan &#39;13, 11:39
dalawh
1●3●3●5
accept rate: 0%
 edited 04 Jan &#39;13, 11:49</description>
    </item>
    
    <item>
      <title>ZigBee packets</title>
      <link>/questions/17456/zigbee-packets/</link>
      <pubDate>Fri, 04 Jan 2013 12:37:00 +0000</pubDate>
      
      <guid>/questions/17456/zigbee-packets/</guid>
      <description>ZigBee packets  0 Hi all,
I have digi s2b module, which is used as coordinator for the network. Also, I have XBP24 module, which is used as transceiver. I want to capture the packets between the two modules. I search on the net, but I found that each sniffer is compatible with its hardware. Can anybody help with this?
zigbeeasked 04 Jan &#39;13, 12:37
Bill
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark command line?</title>
      <link>/questions/17457/wireshark-command-line/</link>
      <pubDate>Fri, 04 Jan 2013 12:38:00 +0000</pubDate>
      
      <guid>/questions/17457/wireshark-command-line/</guid>
      <description>Wireshark command line?  0 Was wireshark meant to be used with command lines or was it meant to be used with the GUI provided? Is there a good command line guide?
gui command lineasked 04 Jan &#39;13, 12:38
dalawh
1●3●3●5
accept rate: 0%
  
One Answer:
  
1Wireshark is meant to be used with the GUI, although there are some command line options available (see the output of &#34;</description>
    </item>
    
    <item>
      <title>all ip list</title>
      <link>/questions/17472/all-ip-list/</link>
      <pubDate>Sat, 05 Jan 2013 01:55:00 +0000</pubDate>
      
      <guid>/questions/17472/all-ip-list/</guid>
      <description>all ip list  0 Hi all, you can show on the screen a list of all active ip in LAN including printers? thank you very much.. greetings
ip listasked 05 Jan &#39;13, 01:55
Andy
1●1●1●2
accept rate: 0%
  
One Answer:
  
2If you set up your capture in a way that you can see all traffic (see: http://wiki.wireshark.org/CaptureSetup), then wireshark can show you a list of all IP addresses that were seen the network during capture.</description>
    </item>
    
    <item>
      <title>Wireshark does not see traffic from other devices (VirtualBox)</title>
      <link>/questions/17476/wireshark-does-not-see-traffic-from-other-devices-virtualbox/</link>
      <pubDate>Sat, 05 Jan 2013 13:57:00 +0000</pubDate>
      
      <guid>/questions/17476/wireshark-does-not-see-traffic-from-other-devices-virtualbox/</guid>
      <description>Wireshark does not see traffic from other devices (VirtualBox)  0 Hello,
I feel like i searched the whole internet and found almost no solution.
I use Wireshark on Backtrack in VirtualBox on a OSX System. But wireshark only sees the traffic from the Backtrack distribution. No traffic from the host itself or my mobile phone.
When I sniff on the same port (eth1) with ettercap I see everything I think.</description>
    </item>
    
    <item>
      <title>Decode 802.11 traffic to TCP/IP packets</title>
      <link>/questions/17480/decode-80211-traffic-to-tcpip-packets/</link>
      <pubDate>Sun, 06 Jan 2013 17:51:00 +0000</pubDate>
      
      <guid>/questions/17480/decode-80211-traffic-to-tcpip-packets/</guid>
      <description>Decode 802.11 traffic to TCP/IP packets  0 Hi all,
My intention is to monitor the activities between 2 wireless stations.
I can successfully capture the wireless (802.11) traffic and decrypt them.
Now I see a lot of LLC packets. Is it possible for Wireshark to decode such packets and give me the TCP/IP packets?
Thanks !
BR, NewWireShark
802.11asked 06 Jan &#39;13, 17:51
newwireshark
1●2●2●2
accept rate: 0%
Can you post the capture to an accessible webpage (such as cloudshark or Google-Drive)?</description>
    </item>
    
    <item>
      <title>Optimal way to capture 802.11 traffic</title>
      <link>/questions/17483/optimal-way-to-capture-80211-traffic/</link>
      <pubDate>Sun, 06 Jan 2013 22:42:00 +0000</pubDate>
      
      <guid>/questions/17483/optimal-way-to-capture-80211-traffic/</guid>
      <description>Optimal way to capture 802.11 traffic  1 Hi,
I have a small WLAN and I am interested in capturing and storing all wireless traffic for later statistical analysis. The analysis will be conducted on 802.11 layer 2 level. It is important to capture ALL wireless traffic going to and from the AP (control and management frames too).
Googling and looking at previous questions here I have concluded that one way to go is having a dedicated machine with a wireless card in promiscuous mode somewhere near the AP acting as a monitor node.</description>
    </item>
    
    <item>
      <title>Installing a recent Wireshark on Linux</title>
      <link>/questions/17488/installing-a-recent-wireshark-on-linux/</link>
      <pubDate>Mon, 07 Jan 2013 04:32:00 +0000</pubDate>
      
      <guid>/questions/17488/installing-a-recent-wireshark-on-linux/</guid>
      <description>Installing a recent Wireshark on Linux  0 Hi guys
We have a VMware box in our server room and I have set up a SUSE Linux VM where one of the interfaces has a wandering network lead connected to a suitable switch/hub so that we can effectively sample network traffic by patching it into wherever we need.
So far so good. It works. BUT.. its an old version (1.4.10) and I&#39;d like a more recent version!</description>
    </item>
    
    <item>
      <title>How to handle an unexpected value in a value_string?</title>
      <link>/questions/17493/how-to-handle-an-unexpected-value-in-a-value_string/</link>
      <pubDate>Mon, 07 Jan 2013 06:25:00 +0000</pubDate>
      
      <guid>/questions/17493/how-to-handle-an-unexpected-value-in-a-value_string/</guid>
      <description>How to handle an unexpected value in a value_string?  0 Hello,
I want to know how to handle an unexpected value in a value_string array. For example my array looks like the following:
static const value_string example[] = { {0, &amp;quot;result1&amp;quot;}, {1, &amp;quot;result2&amp;quot;}, {2, &amp;quot;result3&amp;quot;}, {0, NULL} };If I have a value like 4, I have a STATUS_ACCESS_VIOLATION error. For me the last element {0, NULL} should avoid this unexpected behaviour, but it seems that it doesn&#39;t.</description>
    </item>
    
    <item>
      <title>Network Usage</title>
      <link>/questions/17501/network-usage/</link>
      <pubDate>Mon, 07 Jan 2013 08:59:00 +0000</pubDate>
      
      <guid>/questions/17501/network-usage/</guid>
      <description>Network Usage  1 Hi, I may want to use this software, but I have a quick question I&#39;d like to ask before I think about using it. When Installed will the scanning of this software slow down traffic? Due to our location, our bandwidth is rather limited. so we can&#39;t really risk a hefty chunk out of users bandwidth.
So that is basically my question. Will users be affected by this software scanning the packets they&#39;re sending/recieving</description>
    </item>
    
    <item>
      <title>What is wrong with SYN&#43;ACK causing SYN retransmission but looks fine in WireShark?</title>
      <link>/questions/17502/what-is-wrong-with-synack-causing-syn-retransmission-but-looks-fine-in-wireshark/</link>
      <pubDate>Mon, 07 Jan 2013 09:16:00 +0000</pubDate>
      
      <guid>/questions/17502/what-is-wrong-with-synack-causing-syn-retransmission-but-looks-fine-in-wireshark/</guid>
      <description>What is wrong with SYN+ACK causing SYN retransmission but looks fine in WireShark?  0 While working with an embedded TCPIP stack, I modified the stack not to switch to the new IP address immediately when the DHCP lease is obtained so the system can coordinate with another system that the IP address is changing and reconnect.
When the system comes up in static IP mode, I can connect to it from my Linux 3.</description>
    </item>
    
    <item>
      <title>How can I make my dissector handle multiple ports?</title>
      <link>/questions/17504/how-can-i-make-my-dissector-handle-multiple-ports/</link>
      <pubDate>Mon, 07 Jan 2013 09:44:00 +0000</pubDate>
      
      <guid>/questions/17504/how-can-i-make-my-dissector-handle-multiple-ports/</guid>
      <description>How can I make my dissector handle multiple ports?  0 My Dissector will use multiple ports across our network. How can I define them?
packet-bppcp.c dissector_add_uint(&amp;quot;tcp.port&amp;quot;, BPPCP_PORT, bppcp_handle); packet-bppcp.h #define BPPCP_PORT 26810 /* 4006 4181 4192 45634 7003 9010 9020 */multi_portsasked 07 Jan &amp;lsquo;13, 09:44
jballard1979
20●7●7●10
accept rate: 0%
 edited 07 Jan &amp;lsquo;13, 11:30 
Guy Harris ♦♦
17.4k●3●35●196

 
One Answer:</description>
    </item>
    
    <item>
      <title>Custom Dissector - Duplicate Protocol found:</title>
      <link>/questions/17535/custom-dissector-duplicate-protocol-found/</link>
      <pubDate>Mon, 07 Jan 2013 14:20:00 +0000</pubDate>
      
      <guid>/questions/17535/custom-dissector-duplicate-protocol-found/</guid>
      <description>Custom Dissector - Duplicate Protocol found:  0 I continuously am forced to delete the below from ...\wireshark\epan\dissectors\register.c Is there another way to swat this fly from my face?
/-----------------------------------------------------------------------------------------/ {extern void proto_register_bppcp (void); if(cb) (*cb)(RA_REGISTER, &#34;proto_register_bppcp&#34;, client_data); proto_register_bppcp ();}
&amp;amp;,
{extern void proto_reg_handoff_bppcp (void); if(cb) (*cb)(RA_HANDOFF, &#34;proto_reg_handoff_bppcp&#34;, client_data); proto_reg_handoff_bppcp ();}
duplicate dissector register.casked 07 Jan &#39;13, 14:20
jballard1979
20●7●7●10
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark on Ubuntu on VMware Player</title>
      <link>/questions/17546/wireshark-on-ubuntu-on-vmware-player/</link>
      <pubDate>Mon, 07 Jan 2013 21:02:00 +0000</pubDate>
      
      <guid>/questions/17546/wireshark-on-ubuntu-on-vmware-player/</guid>
      <description>Wireshark on Ubuntu on VMware Player  0 I recently installed Wireshark for Ubuntu on VMware Player. I had a problem with the interface, but that was solved when I ran Wireshark as root using sudo. I heard that was bad. How do I run it as a user with the interfaces appearing?
I also get the below error when I decide to write it to a file. Any idea how to resolve this?</description>
    </item>
    
    <item>
      <title>Microsoft Network Monitor cap file can be opened by Wireshark but save as function is disabled</title>
      <link>/questions/17547/microsoft-network-monitor-cap-file-can-be-opened-by-wireshark-but-save-as-function-is-disabled/</link>
      <pubDate>Mon, 07 Jan 2013 21:42:00 +0000</pubDate>
      
      <guid>/questions/17547/microsoft-network-monitor-cap-file-can-be-opened-by-wireshark-but-save-as-function-is-disabled/</guid>
      <description>Microsoft Network Monitor cap file can be opened by Wireshark but save as function is disabled  0 I need to capture wireless traffic in monitor mode, so use Microsoft Network Monitor 3.4. To me, it seems to be the only solution on Windows 7, without extra hardware like airpcap. (REMARK: Wireshark does not support monitor mode on Windows platforms.)
The cap file generated by Network Monitor can be opened by Wireshark and displayed correctly.</description>
    </item>
    
    <item>
      <title>Packet capturing application for the iPhone?</title>
      <link>/questions/17559/packet-capturing-application-for-the-iphone/</link>
      <pubDate>Tue, 08 Jan 2013 04:25:00 +0000</pubDate>
      
      <guid>/questions/17559/packet-capturing-application-for-the-iphone/</guid>
      <description>Packet capturing application for the iPhone?  0 Does anyone know if there is a packet capturing application for the iPhone?
iphoneasked 08 Jan &#39;13, 04:25
ToNyW87
1●2●2●2
accept rate: 0%
 converted to question 11 Jan &#39;13, 14:15 
Guy Harris ♦♦
17.4k●3●35●196
see my comment in the following question:
http://ask.wireshark.org/questions/10010/can-wireshark-be-installed-on-an-ipad-or-iphone
If you jailbreak the phone, you can install tcpdump and/or pirni.
(08 Jan &#39;13, 04:29) Kurt Knochner ♦I don&#39;t really want to jailbreak my phone and I don&#39;t have Mac so what would you recommend doing?</description>
    </item>
    
    <item>
      <title>Protocol registration in spite of protocol being disabled</title>
      <link>/questions/17563/protocol-registration-in-spite-of-protocol-being-disabled/</link>
      <pubDate>Tue, 08 Jan 2013 06:41:00 +0000</pubDate>
      
      <guid>/questions/17563/protocol-registration-in-spite-of-protocol-being-disabled/</guid>
      <description>Protocol registration in spite of protocol being disabled  0 Hello. I observed a quite strange behaviour. If I disable dissectors over [Analyze-&amp;gt;Enabled Protocols] panel, they still are registered on their BTP/UDP/TCP... ports in [Internals-&amp;gt;Dissector tables-&amp;gt;Integer tables]. Is it a bug or a feature? :-)
Best regards
Ewgenij
register disabled dissector protocol registrationasked 08 Jan &#39;13, 06:41
Ewgenijkkg
66●8●9●15
accept rate: 60%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Server resource usage</title>
      <link>/questions/17573/server-resource-usage/</link>
      <pubDate>Tue, 08 Jan 2013 08:56:00 +0000</pubDate>
      
      <guid>/questions/17573/server-resource-usage/</guid>
      <description>Server resource usage  0 How does Wireshark affects server resources? Is it safe to put on a production server? We are experiencing time-outs in accessing the server. We want to see what&#39;s in the packets that&#39;s why we are planning to install wireshark on the server. Is this advisable? What is the alternative way to look/capture packets to the server? Thank you.
wiresharkasked 08 Jan &#39;13, 08:56
bbmh123
1●1●1●2</description>
    </item>
    
    <item>
      <title>Start proto_tree_add_item( bppcp_tree @ the End of my Data Stream:</title>
      <link>/questions/17580/start-proto_tree_add_item-bppcp_tree-the-end-of-my-data-stream/</link>
      <pubDate>Tue, 08 Jan 2013 13:56:00 +0000</pubDate>
      
      <guid>/questions/17580/start-proto_tree_add_item-bppcp_tree-the-end-of-my-data-stream/</guid>
      <description>Start proto_tree_add_item( bppcp_tree @ the End of my Data Stream:  0 Via my dissector, I need to add an item to the End of my Data Block.
How can I do this?
Like so?
/ ODH TERMINATOR / bppcp_sub_item = proto_tree_add_item( bppcp_tree, hf_bppcp_cr, tvb, 0, 0, FALSE ); proto_tree_add_item( bppcp_tree, hf_bppcp_cr, tvb, 0, 0, FALSE );
endofdatablockasked 08 Jan &#39;13, 13:56
jballard1979
20●7●7●10
accept rate: 0%
 edited 08 Jan &#39;13, 16:01</description>
    </item>
    
    <item>
      <title>Wirshark capturing only the traffic between DNS &amp;amp; Client</title>
      <link>/questions/17586/wirshark-capturing-only-the-traffic-between-dns-client/</link>
      <pubDate>Tue, 08 Jan 2013 21:16:00 +0000</pubDate>
      
      <guid>/questions/17586/wirshark-capturing-only-the-traffic-between-dns-client/</guid>
      <description>Wirshark capturing only the traffic between DNS &amp;amp; Client  0 While capturing the traffic using Wireshark, it captures only the traffic between the Client &amp;amp; the DNS server. We want to capture the traffic between the Client and the actual application server. In addition to that, the application we are trying to capture is SSL, in this case, we need to provide the certificate of the application server or the DNS server.</description>
    </item>
    
    <item>
      <title>Guess the TCP payload format</title>
      <link>/questions/17587/guess-the-tcp-payload-format/</link>
      <pubDate>Thu, 10 Jan 2013 13:12:00 +0000</pubDate>
      
      <guid>/questions/17587/guess-the-tcp-payload-format/</guid>
      <description>Guess the TCP payload format  0 I&#39;m trying to guess the communication protocol between a program and a webserver. I&#39;ve already captured the packets and gotten the Ethernet, IP and TCP layers, and now I want to make sense of the payload. It makes no sense in ASCII.
I&#39;m reasonably sure the payload is not encrypted, and I&#39;m guessing it&#39;s mainly compressed in some way. I&#39;m also guessing it&#39;s something fairly mainstream and something that was available years ago already.</description>
    </item>
    
    <item>
      <title>graph analysis - part of the graph freezes while scrolling</title>
      <link>/questions/17596/graph-analysis-part-of-the-graph-freezes-while-scrolling/</link>
      <pubDate>Fri, 11 Jan 2013 06:09:00 +0000</pubDate>
      
      <guid>/questions/17596/graph-analysis-part-of-the-graph-freezes-while-scrolling/</guid>
      <description>graph analysis - part of the graph freezes while scrolling  0 Hi, on windows 8 when scrolling down the graph analysis in VoIP calls, the lower half of the graph freezes, an no new information is shown there, resizing the window refreshes the friezed part. However, after scrolling the problem still exists....
EDIT# I have found that the problem exists on 1.8.x - on 1.6.x it&#39;s ok.
graph voip analisisasked 11 Jan &#39;13, 06:09</description>
    </item>
    
    <item>
      <title>new download</title>
      <link>/questions/17597/new-download/</link>
      <pubDate>Fri, 11 Jan 2013 06:52:00 +0000</pubDate>
      
      <guid>/questions/17597/new-download/</guid>
      <description>new download  0 Looking to download a trial of your software to see if it will do what I need? will I be able to view traffic on a switch that I think im having problems with? can I use your software to monitor and capture information on a switch? please let me know Thank you.
capture switchasked 11 Jan &#39;13, 06:52
jcgvette
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Comunication over VPN (2 Servers)</title>
      <link>/questions/17604/comunication-over-vpn-2-servers/</link>
      <pubDate>Fri, 11 Jan 2013 08:06:00 +0000</pubDate>
      
      <guid>/questions/17604/comunication-over-vpn-2-servers/</guid>
      <description>Comunication over VPN (2 Servers)  0 Hey guys,
I have a little problem and only wanted to know if I&#39;m right.
MachineA: 192.168.11.17 - http://www.cloudshark.org/captures/d93b8cda3ebd
Sorry for Checksum Offload here!
MachineB: 192.168.13.17 - http://www.cloudshark.org/captures/6fec5b3aa134
There&#39;s only the one stream in my trace file. What&#39;s going on there?
Regards Leo
vpn traceasked 11 Jan &#39;13, 08:06
DasLeo
1●1●1●2
accept rate: 0%
What exactly is the question ?
It looks like the captures are of a connection between the two machines as seen at each machine.</description>
    </item>
    
    <item>
      <title>I/O Graph Auto-Scroll</title>
      <link>/questions/17605/io-graph-auto-scroll/</link>
      <pubDate>Fri, 11 Jan 2013 08:14:00 +0000</pubDate>
      
      <guid>/questions/17605/io-graph-auto-scroll/</guid>
      <description>I/O Graph Auto-Scroll  0 In the past, I/O graphs used to auto-scroll. How do I make this happen with Wireshark 1.8.4? Setting the main packet list to auto-scroll has no effect.
graphasked 11 Jan &#39;13, 08:14
dpward
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Currently, I/O graphs do not auto-scroll. This is a known bug, reported in July 2012. If you want to encourage someone to tackle the fix, you might want to go here and vote for it.</description>
    </item>
    
    <item>
      <title>Can connect to certain hosts on segment, not others</title>
      <link>/questions/17608/can-connect-to-certain-hosts-on-segment-not-others/</link>
      <pubDate>Fri, 11 Jan 2013 09:13:00 +0000</pubDate>
      
      <guid>/questions/17608/can-connect-to-certain-hosts-on-segment-not-others/</guid>
      <description>Can connect to certain hosts on segment, not others  0 I have a server sitting on a 192.168.194.0/24 network and a vpn connection to 10.0.3.0/24. There is no problem with the vpn.
From my server at 192.168.194.10 I can ping the inside of the remote firewall at 10.0.3.2.
I can also ping a remote server at 10.0.3.7.
I can also ping an XP workstation at 10.0.3.59
I however cannot ping a printer 10.</description>
    </item>
    
    <item>
      <title>capture between iPhone and Panasanoc TV over wireless</title>
      <link>/questions/17612/capture-between-iphone-and-panasanoc-tv-over-wireless/</link>
      <pubDate>Fri, 11 Jan 2013 10:11:00 +0000</pubDate>
      
      <guid>/questions/17612/capture-between-iphone-and-panasanoc-tv-over-wireless/</guid>
      <description>capture between iPhone and Panasanoc TV over wireless  0 Hi everyone,
Wireshark is a new thing to me and i am trying to capture the conversation between my iPhone and my Panasonic TV over TCP/IP. For example i have my phone in 192.168.1.11 and my TV in 192.168.1.18, but i am not able to set the wireshark to capture the packets between this two IPs.. I only can see everything that is sent to/from my windows PC (192.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t decrypt WPA2 http trafic</title>
      <link>/questions/17616/cant-decrypt-wpa2-http-trafic/</link>
      <pubDate>Fri, 11 Jan 2013 11:37:00 +0000</pubDate>
      
      <guid>/questions/17616/cant-decrypt-wpa2-http-trafic/</guid>
      <description>Can&amp;rsquo;t decrypt WPA2 http trafic  0 Hello,
I use a WPA2-PSK encryption, I have Wireshark 1.6.12 running on Fedora 17. The fact is that when I try to capture packets directly with wireshark in promiscuous mode, after obtaining the 4-way handshake (the 1/4 handshake is always a malformed packet): I have no decrypted HTTP trafic.
Thank you.
wiresharkasked 11 Jan &#39;13, 11:37
nole
11●1●2●3
accept rate: 0%
 edited 18 Jan &#39;13, 05:08</description>
    </item>
    
    <item>
      <title>dissector_add_</title>
      <link>/questions/17623/dissector_add_/</link>
      <pubDate>Fri, 11 Jan 2013 13:04:00 +0000</pubDate>
      
      <guid>/questions/17623/dissector_add_/</guid>
      <description>dissector_add_  0 I want to base the handoff call off the Data packet instead of using the below port exception.
Thoughts?
void proto_reg_handoff_bppcp(void) { dissector_handle_t bppcp_handle;
 data_handle = find_dissector(&amp;quot;data&amp;quot;); bppcp_handle = create_dissector_handle(dissect_bppcp, proto_bppcp); dissector_add_uint(&amp;quot;tcp.port&amp;quot;, global_bppcp_port, bppcp_handle);port handoff noasked 11 Jan &#39;13, 13:04
jballard1979
20●7●7●10
accept rate: 0% 
  
One Answer:
  
0nevermind, I&#39;ll use the below! :)
heur_dissector_add
answered 11 Jan &#39;13, 13:15</description>
    </item>
    
    <item>
      <title>How to set up devices to capture data</title>
      <link>/questions/17625/how-to-set-up-devices-to-capture-data/</link>
      <pubDate>Fri, 11 Jan 2013 13:33:00 +0000</pubDate>
      
      <guid>/questions/17625/how-to-set-up-devices-to-capture-data/</guid>
      <description>How to set up devices to capture data  0 I have a device that runs an embedded web server that I would like to capture packets from.
Since I can&#39;t run Wireshark from the device, I am guessing that I will need to setup a PC (that&#39;s running Wireshark) in front of the server. If my guess is correct, then I&#39;m stuck on how to setup the PC to capture packets going in/out of the server - (I searched this forum, but couldn&#39;t find any info on how to do this).</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t Decrypt TLSv1 Traffic</title>
      <link>/questions/17630/cant-decrypt-tlsv1-traffic/</link>
      <pubDate>Fri, 11 Jan 2013 16:27:00 +0000</pubDate>
      
      <guid>/questions/17630/cant-decrypt-tlsv1-traffic/</guid>
      <description>Can&amp;rsquo;t Decrypt TLSv1 Traffic  1 Hi,
I’m using Wireshark v1.8.4.
I’m trying to learn about SSL package decryption using wireshark. I have downloaded sample capture file and private key (snakeoil2_070531.tgz) from http://wiki.wireshark.org/SSL and successfully decrypted the package.
Then I tried to configure my own Apache Tomcat server to use SSL. When I capture the traffic to/from my Apache Tomcat server, Wireshark said that its protocol is “TLSv1” instead of “SSLv3”.</description>
    </item>
    
    <item>
      <title>END OF DATA ITEM:</title>
      <link>/questions/17632/end-of-data-item/</link>
      <pubDate>Fri, 11 Jan 2013 16:40:00 +0000</pubDate>
      
      <guid>/questions/17632/end-of-data-item/</guid>
      <description>END OF DATA ITEM:  0 In my dissector, add_item for my protocol data starting @ offset += 17;. The next function code after starts 3 bytes from the end. Example below:
hf_funky_data STARTS @ offset += 17 :START DATA: 38 43 31 39 33 44 30 33 46 30 30 30 30 :STOP DATA:
hf_funky_id always STARTS 3 bytes from the END: :START ID: 39 31 34 :END:
How do I setup my dissector so it stops 3 Bytes short, it always starts at the correct byte but always runs to the last byte in the data packet.</description>
    </item>
    
    <item>
      <title>Wireshark not seeing any packets on other devices on my MacBook Air</title>
      <link>/questions/17634/wireshark-not-seeing-any-packets-on-other-devices-on-my-macbook-air/</link>
      <pubDate>Fri, 11 Jan 2013 17:29:00 +0000</pubDate>
      
      <guid>/questions/17634/wireshark-not-seeing-any-packets-on-other-devices-on-my-macbook-air/</guid>
      <description>Wireshark not seeing any packets on other devices on my MacBook Air  0 Running wireshark for the first time. In capture interfaces, I see en0, p2p0 and lo0. I select en0 and it doesn&#39;t show any packets from any other devices connected to the network.
I feel like a missed a step. Any ideas? Thanks!
osx mac macbookairasked 11 Jan &#39;13, 17:29
James Hess
1●1●1●2
accept rate: 0%
 edited 13 Jan &#39;13, 00:21</description>
    </item>
    
    <item>
      <title>[Solved] Packet Capture vs Browser Request</title>
      <link>/questions/17635/solved-packet-capture-vs-browser-request/</link>
      <pubDate>Fri, 11 Jan 2013 21:35:00 +0000</pubDate>
      
      <guid>/questions/17635/solved-packet-capture-vs-browser-request/</guid>
      <description>[Solved] Packet Capture vs Browser Request  0 I&#39;ve noticed that Wireshark isn&#39;t able to capture certain browser GET requests. For example, TamperData (Firefox addon) shows a GET request for a URL. In Wireshark that URL is not seen as an HTTP.REQUEST.URI, rather it is found as an XML.ATTRIBUTE. I&#39;m wondering where I am having the disconnect understanding this.
Thanks
Update: NGREP is able to capture the HTTP GET request.</description>
    </item>
    
    <item>
      <title>no outgoing packets</title>
      <link>/questions/17638/no-outgoing-packets/</link>
      <pubDate>Sat, 12 Jan 2013 06:03:00 +0000</pubDate>
      
      <guid>/questions/17638/no-outgoing-packets/</guid>
      <description>no outgoing packets  0 Hello. I have fresh install of Windows 7 x64 with Wireshark 1.8.4 and last time I noticed that outgoing packets aren&#39;t displayed at all no matter which network interface I choose (wired, wireless, VPN). I also have Cisco VPN Client and SonicWALL Global VPN Client installed which may cause problems but it used to work previously. Did anybody have similar problem? What can I do to display outgoing packets again?</description>
    </item>
    
    <item>
      <title>can i use dial up modem?</title>
      <link>/questions/17640/can-i-use-dial-up-modem/</link>
      <pubDate>Sat, 12 Jan 2013 08:27:00 +0000</pubDate>
      
      <guid>/questions/17640/can-i-use-dial-up-modem/</guid>
      <description>can i use dial up modem?  0 can i use dial up modem in wireshark
dial upasked 12 Jan &#39;13, 08:27
Shivam Kulsh...
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Maybe.
See PPP capture setup for some (techy, maybe not up to date) info.
I&#39;d have verify this, but ISTR that you might be better off using Microsoft Netmon to capture PPP data and then use Wireshark to dissect the captured data.</description>
    </item>
    
    <item>
      <title>Strange information in packets</title>
      <link>/questions/17643/strange-information-in-packets/</link>
      <pubDate>Sat, 12 Jan 2013 09:28:00 +0000</pubDate>
      
      <guid>/questions/17643/strange-information-in-packets/</guid>
      <description>Strange information in packets  0 I have Wireshark running on a Thinkpad T42 laptop which is connected to web server on an embedded device on a LAN. The laptop is connected to the server via web browser (Firefox).
In the &#34;Info&#34; column in Wireshark, I&#39;m seeing many packets that contain strange names such as:
radio-smorbplus-iioppicknfsHere&#39;s just a snippet of the Wireshark session - notice, in the info column, these strange names:</description>
    </item>
    
    <item>
      <title>Webserver session being closed repeatedly</title>
      <link>/questions/17651/webserver-session-being-closed-repeatedly/</link>
      <pubDate>Sun, 13 Jan 2013 10:08:00 +0000</pubDate>
      
      <guid>/questions/17651/webserver-session-being-closed-repeatedly/</guid>
      <description>Webserver session being closed repeatedly  0 Hi all:
I have a surveillance DVR that hosts a webserver through port 8880 and I&#39;ve been having trouble accessing its webpage, its extremely slow to load components. I captured its traffic and I&#39;m seeing a lot of TCP FIN packets being sent and the connection re-established, the server&#39;s page eventually loads though, just want to get some insight as to a cause. Please let my know anything else you would need to know as I&#39;m sure what I&#39;ve provided is not enough.</description>
    </item>
    
    <item>
      <title>No new log file is created after restart PC</title>
      <link>/questions/17655/no-new-log-file-is-created-after-restart-pc/</link>
      <pubDate>Sun, 13 Jan 2013 21:12:00 +0000</pubDate>
      
      <guid>/questions/17655/no-new-log-file-is-created-after-restart-pc/</guid>
      <description>No new log file is created after restart PC  0 When I use the link below to automatically start wireshark when starting the PC, wireshark will not create a new log file each time the computer is restarted:
&#34;C:\Program Files (x86)\Wireshark\wireshark.exe&#34; -i &#34;\Device\NPF_{59A6CEB4-F94B-47ED-A6FF-7F61ED6EED06}&#34; -k -w &#34;C:\Users\receptie1\Desktop\SHARE\capture.pcap&#34; -B10 -b:5000
Please provide me a solution. Thank you.
new logfile reboot afterasked 13 Jan &#39;13, 21:12
Ruben
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Licence of editcap</title>
      <link>/questions/17660/licence-of-editcap/</link>
      <pubDate>Mon, 14 Jan 2013 05:42:00 +0000</pubDate>
      
      <guid>/questions/17660/licence-of-editcap/</guid>
      <description>Licence of editcap  0 Hi,
I am just wondering why there is no licence header in editcap.c such as in mergecap, capinfo etc. The man pages states &#34;Editcap is part of the Wireshark distribution.&#34; like to one of mergecap etc. also does.
Isn&#39;t it licenced under GPL?
editcap licenceasked 14 Jan &#39;13, 05:42
FiroDev
16●1●1●4
accept rate: 0%
  
2 Answers:
  
1 I just contacted the original author and he confirmed his intention is that it is GPLv2+.</description>
    </item>
    
    <item>
      <title>TCAP Decoding Bug</title>
      <link>/questions/17661/tcap-decoding-bug/</link>
      <pubDate>Mon, 14 Jan 2013 06:05:00 +0000</pubDate>
      
      <guid>/questions/17661/tcap-decoding-bug/</guid>
      <description>TCAP Decoding Bug  0 Hi !
I can see that Wireshark has a problem decoding TCAP packet (showing only DATA and hex stream), if tcap packet is longer than 127 bytes. Usually TCAP is set of tag/len/data constructors, where tag and len are 1-byte, but they support extensions as well (len high bit is set to 1 and continuing on a next bytes)
tcap map ss7 capasked 14 Jan &#39;13, 06:05</description>
    </item>
    
    <item>
      <title>send parameters from X.25</title>
      <link>/questions/17662/send-parameters-from-x25/</link>
      <pubDate>Mon, 14 Jan 2013 06:26:00 +0000</pubDate>
      
      <guid>/questions/17662/send-parameters-from-x25/</guid>
      <description>send parameters from X.25  0 Hello, I have to dissect some protocols as X.25, sndcp (sndcf)... In X.25 I have the number of circuit VC and the dictionary of compression. In SNDCP, I have the information concerning the compression or not of data and before to dissect the other protocols i have to uncompress the data. To do this, i want to send the VC and the dictionary as parameters from X.</description>
    </item>
    
    <item>
      <title>CALL DISSECTOR BASED ON IP:</title>
      <link>/questions/17671/call-dissector-based-on-ip/</link>
      <pubDate>Mon, 14 Jan 2013 11:41:00 +0000</pubDate>
      
      <guid>/questions/17671/call-dissector-based-on-ip/</guid>
      <description>CALL DISSECTOR BASED ON IP:  0 Is it possible to Call my custom Dissector based on 4 different IP addresses?
ip dissectorasked 14 Jan &#39;13, 11:41
jballard1979
20●7●7●10
accept rate: 0%
  
2 Answers:
  
1 Does your protocol run directly atop IP (in which case it should have an IP protocol number assigned to it), or does it run atop a protocol that runs atop IP, such as TCP or UDP?</description>
    </item>
    
    <item>
      <title>WPA-PWD Decryption Key Format</title>
      <link>/questions/17672/wpa-pwd-decryption-key-format/</link>
      <pubDate>Mon, 14 Jan 2013 11:58:00 +0000</pubDate>
      
      <guid>/questions/17672/wpa-pwd-decryption-key-format/</guid>
      <description>WPA-PWD Decryption Key Format  0 Hi! Tried to put my WPA key in Wireshark -&amp;gt; Preferences -&amp;gt; Protocols -&amp;gt; IEEE 802.11, using the format:
Some\Pa55:Free Internet!
&#34;Free Internet!&#34; really is the name of my AP, and it&#39;s given me problems before with other (CLI) apps because of the whitespace and the bang, but quoting generally solves that. Also, my real password does have a backslash in it. Since it doesn&#39;t seem to be working, and I&#39;ve tried it both SSID first, and password first, (Wireshark says it will ignore invalid formats), I am wondering if any of these &#34;</description>
    </item>
    
    <item>
      <title>Export to csv on the fly.</title>
      <link>/questions/17675/export-to-csv-on-the-fly/</link>
      <pubDate>Mon, 14 Jan 2013 13:51:00 +0000</pubDate>
      
      <guid>/questions/17675/export-to-csv-on-the-fly/</guid>
      <description>Export to csv on the fly.  0 I have incoming streaming data packets. I need to
Isolate the packets from a certain ip.Filter only those of certain lengthFrom those filtered packets I need to filter the last 7 bytes.The data should be inserted on the fly to a comma based csv file.Is this possible with Wireshark?
csvasked 14 Jan &#39;13, 13:51
berkz
1●1●1●2
accept rate: 0%
 edited 14 Jan &#39;13, 13:56</description>
    </item>
    
    <item>
      <title>Dissecting UTF8String encoded with ASN.1</title>
      <link>/questions/17686/dissecting-utf8string-encoded-with-asn1/</link>
      <pubDate>Tue, 15 Jan 2013 00:17:00 +0000</pubDate>
      
      <guid>/questions/17686/dissecting-utf8string-encoded-with-asn1/</guid>
      <description>Dissecting UTF8String encoded with ASN.1  0 Hello, community. In the ASN.1 definition I work with there is a value defined as an UTF8String. ~/epan/dissectors/packet-per.c does not contain any function dissecting it. Thus, I suppose I have to write my own one and to add it to packet-per.c
How can I do that? I looked to other string dissectors. In many of them function &#34;dissect_per_restricted_character_string_sorted&#34; is used with differences in the last three parameters.</description>
    </item>
    
    <item>
      <title>Tshark how to capture to a file and print text on screen</title>
      <link>/questions/17696/tshark-how-to-capture-to-a-file-and-print-text-on-screen/</link>
      <pubDate>Tue, 15 Jan 2013 06:45:00 +0000</pubDate>
      
      <guid>/questions/17696/tshark-how-to-capture-to-a-file-and-print-text-on-screen/</guid>
      <description>Tshark how to capture to a file and print text on screen  0 Hello I have problem with saving Tshark output to a pcap and in paralel print text on the screen. I know that there is -P option but it seems it is not working. I&#39;m trying to run following command using LINUX (ubuntu 12.10 and tshark 1.7.0):
tshark -P -i eth0 -f tcp -w /tmp/eth0.pcapThank you in advance</description>
    </item>
    
    <item>
      <title>How to call own dissector again?</title>
      <link>/questions/17699/how-to-call-own-dissector-again/</link>
      <pubDate>Tue, 15 Jan 2013 07:39:00 +0000</pubDate>
      
      <guid>/questions/17699/how-to-call-own-dissector-again/</guid>
      <description>How to call own dissector again?  0 Is it possible to call the own dissector again? The protocol that i want to dissect, starts sometimes again in the same packet. Is there a good way to call the dissector again or are there other ways?
again call_dissector twiceasked 15 Jan &#39;13, 07:39
sphinxs
0●1●1●2
accept rate: 0%
  
One Answer:
  
1If you mean that, in whatever lower-level protocol your protocol runs atop, a single lower-level protocol packet can contain more than one packet for your protocol, the way you should, in general, do that is to have your dissector loop through the contents of the lower-level protocol packet&#39;s payload (that&#39;s what&#39;s in the tvbuff it&#39;s handed) and keep dissecting packets until it runs out.</description>
    </item>
    
    <item>
      <title>dumpcap dll&amp;#x27;s</title>
      <link>/questions/17703/dumpcap-dlls/</link>
      <pubDate>Tue, 15 Jan 2013 08:37:00 +0000</pubDate>
      
      <guid>/questions/17703/dumpcap-dlls/</guid>
      <description>dumpcap dll&amp;rsquo;s  0 I want to use dumpcap.exe in my code(running Windows 7). Which dlls(probably from Wireshark folders) do I have to add to the exe? The command should be something like that dumpcap -a 30 -f &#34;udp and dst 192.168.2.1&#34; -i &#34;my capture inteface&#34; -p -w &#34;outfile&#34;
Regards I. Lesher
dumpcapasked 15 Jan &#39;13, 08:37
triplebit
1●7●7●7
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Can I change the default font color?</title>
      <link>/questions/17705/can-i-change-the-default-font-color/</link>
      <pubDate>Tue, 15 Jan 2013 11:58:00 +0000</pubDate>
      
      <guid>/questions/17705/can-i-change-the-default-font-color/</guid>
      <description>Can I change the default font color?  1 Hello,
Does anyone know if I can change the font color of a selected packet in Wireshark? I am on a Mac, and when I select a packet the font turns white, and the background turns a light blue, which makes it difficult to see packet data, or description.
I&#39;d like keep the font color black, or something more contrasting in the packet list, packet details, and packet byte windows.</description>
    </item>
    
    <item>
      <title>How can I capture Bluetooth traffic with Bluetooth format?</title>
      <link>/questions/17710/how-can-i-capture-bluetooth-traffic-with-bluetooth-format/</link>
      <pubDate>Tue, 15 Jan 2013 15:34:00 +0000</pubDate>
      
      <guid>/questions/17710/how-can-i-capture-bluetooth-traffic-with-bluetooth-format/</guid>
      <description>How can I capture Bluetooth traffic with Bluetooth format?  0 Currently I can capture the Bluetooth traffic using Wireshark. The way I did is following: Node A creates a PAN and paired with Node B. Then There will be an interface named pan0 in A and B. I choose pan0 as the captured interface in Wireshark, all the udp/tcp traffic can be captured.
However, the traffic is encapsulated in Ethernet format, which losses a lot of information from the Bluetooth mac layer.</description>
    </item>
    
    <item>
      <title>Decoding WireShark Traffic Capture</title>
      <link>/questions/17711/decoding-wireshark-traffic-capture/</link>
      <pubDate>Tue, 15 Jan 2013 16:36:00 +0000</pubDate>
      
      <guid>/questions/17711/decoding-wireshark-traffic-capture/</guid>
      <description>Decoding WireShark Traffic Capture  0 Hi All,
We are using an ASP application and sometimes the application does not let the user type data in a given field. This issue occurs on different fields and screens of the program. We have opened support tickets with the vendor on this issue and they are claiming the reason the user can&#39;t type is because packets are being lost between the client computer and the ASP server.</description>
    </item>
    
    <item>
      <title>print&amp;quot;Memory corrupted&amp;quot;.</title>
      <link>/questions/17713/printmemory-corrupted/</link>
      <pubDate>Tue, 15 Jan 2013 19:44:00 +0000</pubDate>
      
      <guid>/questions/17713/printmemory-corrupted/</guid>
      <description>print&amp;quot;Memory corrupted&amp;quot;.  0 when I open a *.pcap, then it popup a cmd window, print&#34;Memory corrupted&#34;. why? and how can I fix the bug.
corrupted memoryasked 15 Jan &#39;13, 19:44
smilezuzu
20●32●32●37
accept rate: 0%
Is this a unchanged Wireshark version? Which version is it? How was the .pcap created/transported to the system if ftp was used it should be transfered in binary mode as the file is binary and ftp might mangle it if transfered in ASCII.</description>
    </item>
    
    <item>
      <title>How to filter by Info column?</title>
      <link>/questions/17718/how-to-filter-by-info-column/</link>
      <pubDate>Wed, 16 Jan 2013 06:48:00 +0000</pubDate>
      
      <guid>/questions/17718/how-to-filter-by-info-column/</guid>
      <description>How to filter by Info column?  1 Is it possible to filter a Wireshark session by the Info column? If so, how?
For example: I would like to filter packets with an expression that looks something like:
Filter: info.contains== GET / foo.cgi?a=bar
Update
The answer by Syn_bit is good and fine. However, using that syntax I&#39;m unable to filter the info column if the data in the info column is within [brackets].</description>
    </item>
    
    <item>
      <title>tshark conversation statistic not resolving hostnames</title>
      <link>/questions/17724/tshark-conversation-statistic-not-resolving-hostnames/</link>
      <pubDate>Wed, 16 Jan 2013 12:33:00 +0000</pubDate>
      
      <guid>/questions/17724/tshark-conversation-statistic-not-resolving-hostnames/</guid>
      <description>tshark conversation statistic not resolving hostnames  0 Executing the -z conv,ip command does not display the hostnames (like in wireshark). This happens on Fedora 17 and Windows 7. I execute the command, and after a bit of traffic was monitored, I stop tshark with Ctrl-C. After this the conversation table is printed.
Linux:
command: tshark -i 1 -N n -f &#34;tcp or udp&#34; -z conv,ipOS: Fedora 17 x86tshark version: 1.</description>
    </item>
    
    <item>
      <title>Getting Encrypt Alert from Client after Application Data exchange</title>
      <link>/questions/17727/getting-encrypt-alert-from-client-after-application-data-exchange/</link>
      <pubDate>Wed, 16 Jan 2013 15:58:00 +0000</pubDate>
      
      <guid>/questions/17727/getting-encrypt-alert-from-client-after-application-data-exchange/</guid>
      <description>Getting Encrypt Alert from Client after Application Data exchange  0 I am getting a Encryption alert from the client after the server and client have exchanged application data. The Error codes do not seem consistent between the Alert Description Types. Why would the client send an alert after several application packets have passed successfully? Thank you in advance. Dan
from tsclient encrypt alertasked 16 Jan &#39;13, 15:58
DanS
1●1●1●1</description>
    </item>
    
    <item>
      <title>Retransmissions</title>
      <link>/questions/17730/retransmissions/</link>
      <pubDate>Wed, 16 Jan 2013 19:12:00 +0000</pubDate>
      
      <guid>/questions/17730/retransmissions/</guid>
      <description>Retransmissions  0 I get hundreds of these when i copy from my windows 2003 server at one site to a windows 2008 r2 server at another. Any idea on what&#39;s going on or how to troubleshoot it?
10193 0.000000000 192.168.20.30 192.168.183.10 TCP 1514 [TCP Fast Retransmission] [TCP segment of a reassembled PDU] 10203 0.003003000 192.168.20.30 192.168.183.10 TCP 1514 [TCP Retransmission] [TCP segment of a reassembled PDU]Its also at https://www.cloudshark.org/captures/a198e1dad32c</description>
    </item>
    
    <item>
      <title>DEC to IP Address</title>
      <link>/questions/17749/dec-to-ip-address/</link>
      <pubDate>Thu, 17 Jan 2013 07:38:00 +0000</pubDate>
      
      <guid>/questions/17749/dec-to-ip-address/</guid>
      <description>DEC to IP Address  0 Hi,
In one of my protocols I receive an integer which represents an ip address. Like this :
180619876... (which means) = AC40A64 = 10.196.10.1
So I would like to have this integer display the ip address. That is, from 180619876 to 10.196.10.1
Is this possible, is there some easy way?
Thank you in advance,
BR
ip dec addressasked 17 Jan &#39;13, 07:38
harkap</description>
    </item>
    
    <item>
      <title>Can rawshark output the text field of HTTP traffic?</title>
      <link>/questions/17752/can-rawshark-output-the-text-field-of-http-traffic/</link>
      <pubDate>Thu, 17 Jan 2013 10:33:00 +0000</pubDate>
      
      <guid>/questions/17752/can-rawshark-output-the-text-field-of-http-traffic/</guid>
      <description>Can rawshark output the text field of HTTP traffic?  0 I&#39;m trying to get rawshark to output the text of an HTTP stream. I&#39;m running the following:
cat wlan.pcap | rawshark -r - -d proto:radiotap -d proto:http -s -F tcp.dstport -F ip.src -F http.host -F tcp.data -F textIt outputs the tcp.dstport, ip.src, and http.host but fails to output tcp.data and text reliably.
rawsharkasked 17 Jan &#39;13, 10:33
joeferner
11●1●1●2</description>
    </item>
    
    <item>
      <title>I see ICMP but not TCP packets (with managed switch)</title>
      <link>/questions/17758/i-see-icmp-but-not-tcp-packets-with-managed-switch/</link>
      <pubDate>Thu, 17 Jan 2013 11:27:00 +0000</pubDate>
      
      <guid>/questions/17758/i-see-icmp-but-not-tcp-packets-with-managed-switch/</guid>
      <description>I see ICMP but not TCP packets (with managed switch)  0 Hi,
I was trying to see packets from a server to a hardware device (a printer), but I was told it would not work on a switched media unless I tried some of the configurations explained on http://wiki.wireshark.org/CaptureSetup/Ethernet
So I got a managed switch (MikroTik RB250GS), as recommended and configured Port Mirroring to copy packets to/from Port3 (where I connected my printer) to Port5 (where I had my notebook with Wireshark).</description>
    </item>
    
    <item>
      <title>How do I capture packets from Yahoo Messenger?</title>
      <link>/questions/17760/how-do-i-capture-packets-from-yahoo-messenger/</link>
      <pubDate>Thu, 17 Jan 2013 12:49:00 +0000</pubDate>
      
      <guid>/questions/17760/how-do-i-capture-packets-from-yahoo-messenger/</guid>
      <description>How do I capture packets from Yahoo Messenger?  0 How do I capture packets from Yahoo Messenger only? Or maybe I have to set a filter after capture? I know very little about Wireshark - am working on the Windows platform.
messenger yahooasked 17 Jan &#39;13, 12:49
marcerickson
11●1●1●2
accept rate: 0%
  
One Answer:
  
0If you know what port Yahoo Messenger uses or what IP address you&#39;re communicating with, you can set a capture filter for either the port or the IP address.</description>
    </item>
    
    <item>
      <title>Libpcap won&amp;#x27;t capture multiple interfaces simultaneously.</title>
      <link>/questions/17767/libpcap-wont-capture-multiple-interfaces-simultaneously/</link>
      <pubDate>Fri, 18 Jan 2013 01:43:00 +0000</pubDate>
      
      <guid>/questions/17767/libpcap-wont-capture-multiple-interfaces-simultaneously/</guid>
      <description>Libpcap won&amp;rsquo;t capture multiple interfaces simultaneously.  0 Hello.
I have an application which uses libpcap and captures the traffic on multiple interfaces. I do have three interfaces eth0, eth1 and wlan0 . When my interface eth1 is down, libpcap works on eth0 as expected. But with eth1 on , it never works. If I enable eth0 and eth1 both then capture on eth1 works and on eth0 interface it wont works.</description>
    </item>
    
    <item>
      <title>Add New proto_add_item Loop:</title>
      <link>/questions/17774/add-new-proto_add_item-loop/</link>
      <pubDate>Fri, 18 Jan 2013 05:54:00 +0000</pubDate>
      
      <guid>/questions/17774/add-new-proto_add_item-loop/</guid>
      <description>Add New proto_add_item Loop:  0 My Packet Data: 04 1A 0C 68 00 01 00 00 4D 15 00 04 9D F6 10 3A | 9E 0E 95 34 9E 33 38 D3 75 31 74 63 5E 07:
Node: 04 1A Counter: 0C 68 Type: 00 01 Channel: 00 00 RTU: 4D 15 Number of Register(s): 00 04 Register: 9D F6 Register Data: 10 3A
I need my Dissector to loop through and add the below until the total Number of Register(s) 00 04 is satisfied: &#34;</description>
    </item>
    
    <item>
      <title>Problem with our Web site</title>
      <link>/questions/17776/problem-with-our-web-site/</link>
      <pubDate>Fri, 18 Jan 2013 06:41:00 +0000</pubDate>
      
      <guid>/questions/17776/problem-with-our-web-site/</guid>
      <description>Problem with our Web site  0 Thank you. I have a small Web site that makes a Ajax &#34;GET&#34; request every 200ms to a Web server. The Web site wait for a small document (750 bytes) from the server, it displays the document data before to send a new request to the server. The document is updated periodically every 200ms by another process (priority superior than web server&#39;one). There is no synchronization between two processes.</description>
    </item>
    
    <item>
      <title>How to view multiple streams?</title>
      <link>/questions/17777/how-to-view-multiple-streams/</link>
      <pubDate>Fri, 18 Jan 2013 09:29:00 +0000</pubDate>
      
      <guid>/questions/17777/how-to-view-multiple-streams/</guid>
      <description>How to view multiple streams?  0 I&#39;m aware of the Wireshark feature which allows us to view a single stream that a particular packet is associated with. However, I would like to view multiple streams in the order that they were captured.
Is this possible? If so, how?
Edit for clarity
I&#39;m looking for a way to view multiple streams in a single &#34;Follow TCP Stream&#34; window. You know how you can right-click on a packet and select &#34;</description>
    </item>
    
    <item>
      <title>File export as &amp;quot;Plain Text File&amp;quot; feature missing?</title>
      <link>/questions/17784/file-export-as-plain-text-file-feature-missing/</link>
      <pubDate>Fri, 18 Jan 2013 17:17:00 +0000</pubDate>
      
      <guid>/questions/17784/file-export-as-plain-text-file-feature-missing/</guid>
      <description>File export as &amp;ldquo;Plain Text File&amp;rdquo; feature missing?  0 I just installed Vewrsion 1.8.4 64 bit for Windows 7. It seems to be able to capture from the machine&#39;s ethernet port, and save/load pcap files, but I can&#39;t find the File Export to plain text file option anywhere.
Has this feature been removed?
export feature feature-requestasked 18 Jan &#39;13, 17:17
gordwait
1●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>BICC and H.248 filter for a single call</title>
      <link>/questions/17787/bicc-and-h248-filter-for-a-single-call/</link>
      <pubDate>Fri, 18 Jan 2013 23:13:00 +0000</pubDate>
      
      <guid>/questions/17787/bicc-and-h248-filter-for-a-single-call/</guid>
      <description>BICC and H.248 filter for a single call  0 Hi,
I have a .pcap files with BSSAP, H.248 and BICC calls. Now I can filter out single BICC call by CIC number , but wondering if there is any way to see the corresponding H.248 messages.
Please advice.
Best Regards Suman
filter a single callasked 18 Jan &#39;13, 23:13
suman
11●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>I want to hide ICMP</title>
      <link>/questions/17789/i-want-to-hide-icmp/</link>
      <pubDate>Sat, 19 Jan 2013 06:25:00 +0000</pubDate>
      
      <guid>/questions/17789/i-want-to-hide-icmp/</guid>
      <description>I want to hide ICMP  0 Hello there,
Is there any possibilities to hide this ICMP? I just only to see syslog on my screen.
One more thing is there any fastest way to save this syslog? via text file, notepad, Ms word etc. Its urgent please do help.
Thank you.
icmpasked 19 Jan &#39;13, 06:25
FirstSystems
11●1●1●2
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>packet-parlay.c ... defined but not used</title>
      <link>/questions/17797/packet-parlayc-defined-but-not-used/</link>
      <pubDate>Sun, 20 Jan 2013 15:36:00 +0000</pubDate>
      
      <guid>/questions/17797/packet-parlayc-defined-but-not-used/</guid>
      <description>packet-parlay.c &amp;hellip; defined but not used  0 Hello,
I&#39;m [trying to] install wireshark-1.8.4 on CentOS 6.3. Version details:
[[email protected] wireshark-1.8.4]# uname -r 2.6.32-279.19.1.el6.x86_64
I have uncompressed the bz2 and run ./configure (all passed OK after yum-ming a couple of packages). When I run &#39;make&#39; the output stops at:
packet-parlay.c:82294: warning: &#39;decode_org_csapi_fw_TpLoadPolicy_st&#39; defined but not used packet-parlay.c:82360: warning: &#39;decode_org_csapi_fw_TpLoadInitVal_st&#39; defined but not used packet-parlay.c:83511: warning: &#39;decode_org_csapi_ui_TpUIEventInfo_st&#39; defined but not used</description>
    </item>
    
    <item>
      <title>Fuzzing - Wireshark Continuation or non-HTTP traffic (Regarding Buffer overflow)</title>
      <link>/questions/17802/fuzzing-wireshark-continuation-or-non-http-traffic-regarding-buffer-overflow/</link>
      <pubDate>Sun, 20 Jan 2013 23:01:00 +0000</pubDate>
      
      <guid>/questions/17802/fuzzing-wireshark-continuation-or-non-http-traffic-regarding-buffer-overflow/</guid>
      <description>Fuzzing - Wireshark Continuation or non-HTTP traffic (Regarding Buffer overflow)  0 Hi, I am currently doing a test out of some security vulnerabilities, which the call fuzzing. As I am trying to figure out how to know where a web server is crashed from buffer overflow and its minimum bytes to crash it. So I used a Wireshark to view the traffic packet coming in and out.
After doing the fuzzing technique, I obtain a result of this and I am not sure of which is the part that crash the server.</description>
    </item>
    
    <item>
      <title>How can i make the wireshark.deb on Ubuntu?</title>
      <link>/questions/17803/how-can-i-make-the-wiresharkdeb-on-ubuntu/</link>
      <pubDate>Sun, 20 Jan 2013 23:10:00 +0000</pubDate>
      
      <guid>/questions/17803/how-can-i-make-the-wiresharkdeb-on-ubuntu/</guid>
      <description>How can i make the wireshark.deb on Ubuntu?  0 How can i make the wireshark.deb on Ubuntu? in my step: 1,down the wireshark-1.8.3 code and decompress it. 2,./configure. 3,make. 4,?? how to make the .deb?
Thanks!
deb ubuntuasked 20 Jan &#39;13, 23:10
smilezuzu
20●32●32●37
accept rate: 0%
  
One Answer:
  
1make debian-package
answered 21 Jan &#39;13, 05:45
Jaap ♦
11.7k●16●101
accept rate: 14%
when i run &#34;</description>
    </item>
    
    <item>
      <title>Why doesn&amp;#x27;t Wireshark reassemble HTTP POST messages in my converted raw IP capture</title>
      <link>/questions/17805/why-doesnt-wireshark-reassemble-http-post-messages-in-my-converted-raw-ip-capture/</link>
      <pubDate>Mon, 21 Jan 2013 07:08:00 +0000</pubDate>
      
      <guid>/questions/17805/why-doesnt-wireshark-reassemble-http-post-messages-in-my-converted-raw-ip-capture/</guid>
      <description>Why doesn&amp;rsquo;t Wireshark reassemble HTTP POST messages in my converted raw IP capture  0 Hi guys!
I&#39;m stuck with a problem with Wireshark.
Background: I got a file filled with Raw Ip Packets captured by a third party device. In order to make it readable by Wireshark i wrote a little C program converting the raw ip format into a wireshark readable one. It worked well for 99% of the cases.</description>
    </item>
    
    <item>
      <title>How can I capture packets on the &amp;quot;carrier side&amp;quot;of DSL using Wireshark?</title>
      <link>/questions/17819/how-can-i-capture-packets-on-the-carrier-sideof-dsl-using-wireshark/</link>
      <pubDate>Mon, 21 Jan 2013 11:16:00 +0000</pubDate>
      
      <guid>/questions/17819/how-can-i-capture-packets-on-the-carrier-sideof-dsl-using-wireshark/</guid>
      <description>How can I capture packets on the &amp;ldquo;carrier side&amp;quot;of DSL using Wireshark?  0 I&#39;m having an issue with my carrier regarding dropped packets. The packet type is a very specific SIP/SDF packet, specifically an &#34;INVITE&#34; message from an IP PBX to a remote IP phone. The PBX sends these invites reliably (proven by Wireshark, thank you Wireshark!) but do not arrive reliably.
The remote IP phone &#34;sometimes&#34; receives these packets, and when it does, reliably replies to the PBX.</description>
    </item>
    
    <item>
      <title>What can cause multiple SYN Packets in same stream</title>
      <link>/questions/17831/what-can-cause-multiple-syn-packets-in-same-stream/</link>
      <pubDate>Mon, 21 Jan 2013 15:38:00 +0000</pubDate>
      
      <guid>/questions/17831/what-can-cause-multiple-syn-packets-in-same-stream/</guid>
      <description>What can cause multiple SYN Packets in same stream  0 1I have a laptop that is connected to a micro web server device via an old hub (Netgear EN104).
The IP Assignments are:
Micro web server: 10.10.6.106 Laptop: 10.10.6.222I am noticing that, on occasion, the laptop will send two SYN packets in the same stream and the server will only ACK one of them. The multiple SYN packets remind me of a type of DoS tactic, but in this case I know for sure that nothing malicious is causing the multiple SYN requests.</description>
    </item>
    
    <item>
      <title>How to filter out streams that contain multiple SYN packets</title>
      <link>/questions/17833/how-to-filter-out-streams-that-contain-multiple-syn-packets/</link>
      <pubDate>Mon, 21 Jan 2013 15:47:00 +0000</pubDate>
      
      <guid>/questions/17833/how-to-filter-out-streams-that-contain-multiple-syn-packets/</guid>
      <description>How to filter out streams that contain multiple SYN packets  0 1I am troubleshooting communication problems that my micro web server is encountering.
I may have found a clue to the problem that I mention in this post.
To cut to the chase, I&#39;m looking for a way to search/filter my Wireshark capture where I can quickly find ALL streams that contain more than one SYN request/packet.
For example:</description>
    </item>
    
    <item>
      <title>TCP information segmented at NIC making wireshark capture less interesting</title>
      <link>/questions/17835/tcp-information-segmented-at-nic-making-wireshark-capture-less-interesting/</link>
      <pubDate>Mon, 21 Jan 2013 16:00:00 +0000</pubDate>
      
      <guid>/questions/17835/tcp-information-segmented-at-nic-making-wireshark-capture-less-interesting/</guid>
      <description>TCP information segmented at NIC making wireshark capture less interesting  0 I would like to see the &#34;normal&#34; behavior of TCP in wireshark, but I have discovered that (to save CPU) TCP sends large chunks of information to the NIC and the NIC actually performs the segmentation (based on MTU). From what I have read so far wireshark captures traffic data between TCP (the CPU) and the NIC, so the &#34;</description>
    </item>
    
    <item>
      <title>Unable to rebuild after editing files</title>
      <link>/questions/17846/unable-to-rebuild-after-editing-files/</link>
      <pubDate>Mon, 21 Jan 2013 18:20:00 +0000</pubDate>
      
      <guid>/questions/17846/unable-to-rebuild-after-editing-files/</guid>
      <description>Unable to rebuild after editing files  0 Thanks!
Today,I get another trouble (using Ubuntu):
when I finished edition of source code in dissectors.and then run make in path:/wireshark-1.8.3. there is nothing to do.what command should i to give if i want make the change .Regards!
make compiling dissectorasked 21 Jan &#39;13, 18:20
smilezuzu
20●32●32●37
accept rate: 0%
 converted to question 31 Jan &#39;13, 02:44 
grahamb ♦
19.8k●3●30●206</description>
    </item>
    
    <item>
      <title>GLIBC_2.15&amp;#x27; not found</title>
      <link>/questions/17851/glibc_215-not-found/</link>
      <pubDate>Mon, 21 Jan 2013 23:05:00 +0000</pubDate>
      
      <guid>/questions/17851/glibc_215-not-found/</guid>
      <description>GLIBC_2.15&#39; not found  0 when i start to run wireshark1.8.3 on ubuntu 11.10. I get those error. and the program is stop. 1:wireshark: error while loading shared libraries: libcares.so.2: cannot open shared object file: No such file or directory 2:wireshark: /lib/i386-linux-gnu/libc.so.6: version `GLIBC_2.15&#39; not found (required by wireshark)
could you tell me how to fix this? thanks.
glibc_2.15 ubuntuasked 21 Jan &#39;13, 23:05
smilezuzu
20●32●32●37
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Extraction of packet content</title>
      <link>/questions/17852/extraction-of-packet-content/</link>
      <pubDate>Tue, 22 Jan 2013 03:18:00 +0000</pubDate>
      
      <guid>/questions/17852/extraction-of-packet-content/</guid>
      <description>Extraction of packet content  0 Dear all,
I am new in packet sniffing and processing.
I would like to ask you if there is an easy way to filter packets according to their content.
For example if payload consists of temperature data, do you think that a query such that (if data &amp;gt; 30deg) is possible?
Thank you in advance
content data routingasked 22 Jan &#39;13, 03:18
Foued
11●1●3</description>
    </item>
    
    <item>
      <title>Wireshark Decryption?</title>
      <link>/questions/17854/wireshark-decryption/</link>
      <pubDate>Tue, 22 Jan 2013 04:05:00 +0000</pubDate>
      
      <guid>/questions/17854/wireshark-decryption/</guid>
      <description>Wireshark Decryption?  0 Hello,
First of all, I am very new to this and I am having difficulties.
I have some questions about the decryption feature.
Is this only used when in monitoring mode to capture wireless traffic?
How do I know what my key is?
Also, when wireshark is used to capture the traffic on a local machine, ie the machine it is running on, does it need an encryption key?</description>
    </item>
    
    <item>
      <title>Dissecting UTF8String encoded with ASN.1 using a Wireshark plugin</title>
      <link>/questions/17856/dissecting-utf8string-encoded-with-asn1-using-a-wireshark-plugin/</link>
      <pubDate>Tue, 22 Jan 2013 06:29:00 +0000</pubDate>
      
      <guid>/questions/17856/dissecting-utf8string-encoded-with-asn1-using-a-wireshark-plugin/</guid>
      <description>Dissecting UTF8String encoded with ASN.1 using a Wireshark plugin  0 Hello, community. In Dissecting UTF8String encoded with ASN.1 it was about built-in Wireshark dissectors dissecting UTF6AString values coded in ASN.1. That issue was successfully clarified. But what about plugins. There is a source file ~/plugins/asn1/packet-asn1.c where UTF8String is mentioned but not processed. Is it the file to be worked on?
BR
Ewgenij
utf8 dissect utf8string asn1asked 22 Jan &#39;13, 06:29</description>
    </item>
    
    <item>
      <title>router retransmitting packets</title>
      <link>/questions/17859/router-retransmitting-packets/</link>
      <pubDate>Tue, 22 Jan 2013 07:26:00 +0000</pubDate>
      
      <guid>/questions/17859/router-retransmitting-packets/</guid>
      <description>router retransmitting packets  0 I would like help figuring out the cause &amp;amp; solution to a packet retransmission issue. I am getting lots of &#34;TCP out-of order&#34;, &#34;TCP DUP-ACK&#34;, &amp;amp; &#34;TCP Retransmission&#34;. This occurs mostly (90%) between two devices communicating within the same VLAN. So client A (192.168.12.151) sends message to client B (192.168.12.100), through a Sonicwall router (192.168.11.200). Sonicwall router set up 4 VLANS, trunk to Layer 3 switch.</description>
    </item>
    
    <item>
      <title>count connected computer to ap</title>
      <link>/questions/17862/count-connected-computer-to-ap/</link>
      <pubDate>Tue, 22 Jan 2013 11:03:00 +0000</pubDate>
      
      <guid>/questions/17862/count-connected-computer-to-ap/</guid>
      <description>count connected computer to ap  0 I sysadmin of high school In my school I have about 9 ap with the same ssid and password ,also roaming enable the ap connect to central switch. The ap not config as router Who can I know which computer connect to spiffily ap or the number computer that connect to spiffily ap
capture-filterasked 22 Jan &#39;13, 11:03
Miki
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Extracting and dissecting small packets</title>
      <link>/questions/17864/extracting-and-dissecting-small-packets/</link>
      <pubDate>Tue, 22 Jan 2013 11:54:00 +0000</pubDate>
      
      <guid>/questions/17864/extracting-and-dissecting-small-packets/</guid>
      <description>Extracting and dissecting small packets  0 Hi Forum
I am writing a protocol dissector. The protocol data packets are small and always prefixed with a message length. Multiple messages are contained inside one TCP packet.
To date I have process the tvb buffer and called tvb_new_subset with the length and offset to -1 and processed the new packet. But this leads me to a problem is the message length (currently unused in my approach) is actually greater than the fields I am aware of in the packet I end up starting thinking I have a new message before I have consumed all the previous packet.</description>
    </item>
    
    <item>
      <title>TCP Retransmits on Windows Server for slow connections</title>
      <link>/questions/17865/tcp-retransmits-on-windows-server-for-slow-connections/</link>
      <pubDate>Tue, 22 Jan 2013 12:08:00 +0000</pubDate>
      
      <guid>/questions/17865/tcp-retransmits-on-windows-server-for-slow-connections/</guid>
      <description>TCP Retransmits on Windows Server for slow connections  0 I&#39;m trying to understand why there are seemingly &#39;aggressive&#39; TCP retransmits seen in the capture below:
The server is a Windows 2008 R2 server, the client is connecting over a &#34;slow&#34; GPRS or 3G connection. Notice how the server will retransmit packet number 5 after 0.36s and then again after 0.6 seconds. Doubling the timeout (this seems to be consistent with some logic built into how TCP calculates the retry timeout).</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t capture local traffic</title>
      <link>/questions/17869/cant-capture-local-traffic/</link>
      <pubDate>Tue, 22 Jan 2013 13:52:00 +0000</pubDate>
      
      <guid>/questions/17869/cant-capture-local-traffic/</guid>
      <description>Can&amp;rsquo;t capture local traffic  0 I&#39;ve been using Wireshark for a long time with no problem, but can&#39;t get it to work right with this new server. I used to be able to see all my internal traffic. If I pinged eth0 or a TAP, I could see the ping. I can&#39;t anymore. The ping works, but Wireshark isn&#39;t capturing it. This is making troubleshooting other problems difficult. What am I doing wrong?</description>
    </item>
    
    <item>
      <title>Why can&amp;#x27;t I see the capture filter field in the capture options dialog?</title>
      <link>/questions/17870/why-cant-i-see-the-capture-filter-field-in-the-capture-options-dialog/</link>
      <pubDate>Tue, 22 Jan 2013 14:28:00 +0000</pubDate>
      
      <guid>/questions/17870/why-cant-i-see-the-capture-filter-field-in-the-capture-options-dialog/</guid>
      <description>Why can&amp;rsquo;t I see the capture filter field in the capture options dialog?  0 I&#39;m attempting to apply a capture filter to only capture packets to/from a particular IP:
HOST 201.3.72.34
I&#39;ve used the capture filters dialog to add a new filter. When I open the capture options dialog there is no field to select or apply capture filters. The user guide contains a screenshot of the field but it&#39;s not in my version: http://www.</description>
    </item>
    
    <item>
      <title>Issue with tshark -o</title>
      <link>/questions/17881/issue-with-tshark-o/</link>
      <pubDate>Tue, 22 Jan 2013 22:59:00 +0000</pubDate>
      
      <guid>/questions/17881/issue-with-tshark-o/</guid>
      <description>Issue with tshark -o  0 Hai,
I am trying to capture packets using tshark from JAVA (OS: Ubuntu).
From terminal i can run below command successfully. tshark -i any -o column.format:&#34;&#34;source&#34;, &#34;%s&#34;, &#34;srcport&#34;, &#34;%uS&#34;&#34; -f &#34;port 80 or port 443&#34;
But from JAVA its throwing below message tshark: Invalid -o flag &#34;column.format:&#34;&#34;source&#34;,&#34;
But i can invoke commands like &#34;tshark -i any&#34; from java with out any issues. Is there any other thing i need to correct to get the exact output from JAVA.</description>
    </item>
    
    <item>
      <title>Dissecting protocol that has message direction based dissectors</title>
      <link>/questions/17883/dissecting-protocol-that-has-message-direction-based-dissectors/</link>
      <pubDate>Tue, 22 Jan 2013 23:23:00 +0000</pubDate>
      
      <guid>/questions/17883/dissecting-protocol-that-has-message-direction-based-dissectors/</guid>
      <description>Dissecting protocol that has message direction based dissectors  0 Hi Forum,
I am writing a dissector for a protocol that has different dissectors depending on the direction of the traffic.
The protocol is Length|FCode|Data. For the same FCode value the Data is dissected differently depending on its direction. Ie device to host and host to device. Sending request and response using same function code value.
How is this typically handled?</description>
    </item>
    
    <item>
      <title>Oracle SQLNET Tracing</title>
      <link>/questions/17894/oracle-sqlnet-tracing/</link>
      <pubDate>Wed, 23 Jan 2013 05:10:00 +0000</pubDate>
      
      <guid>/questions/17894/oracle-sqlnet-tracing/</guid>
      <description>Oracle SQLNET Tracing  0 Hello!
This question is about using Wireshark to read the contents of TNS packets. I have no problem tracing an Oracle session, decoding the TNS, and finding the query text (select from some table). What puzzles me is why I see &#34;ORA-01403: no data found&#34; in the response from the database server even when the query has a result set. Have I missed a set-up step?</description>
    </item>
    
    <item>
      <title>C&#43;&#43; Runtime error</title>
      <link>/questions/17896/c-runtime-error/</link>
      <pubDate>Wed, 23 Jan 2013 07:02:00 +0000</pubDate>
      
      <guid>/questions/17896/c-runtime-error/</guid>
      <description>C++ Runtime error  0 I have installed wireshark on 2 computers, One is W-7 Pro sp-1 32 bit and the other is Windows XP Pro sp-3 32 bit. After a few minutes of capture, I receive an error message &#34;This application has requested the Runtime to terminate it in an unusual way. Please contact the application&#39;s support team fro more information.&#34; I have setup wireshark to capture the local interface, use multiple files next every 1 megabyte and to stop the capture after 10 hours.</description>
    </item>
    
    <item>
      <title>Remote Interfaces does not save.</title>
      <link>/questions/17898/remote-interfaces-does-not-save/</link>
      <pubDate>Wed, 23 Jan 2013 07:22:00 +0000</pubDate>
      
      <guid>/questions/17898/remote-interfaces-does-not-save/</guid>
      <description>Remote Interfaces does not save.  1 Hi All,
I have successfully configured remote interfaces using rpcdap on remote Linux server from my windows machine. However I have notice that once I configure the remote interfaces when I close wireshark and reopen it it disappears. Is there a way to save this configuration as I have multiple servers and would hate to input them every time.
I know from the wireshark documentation it states for remote interfaces that &#34;</description>
    </item>
    
    <item>
      <title>How do I view all streams in &amp;quot;Follow Tcp Streams?&amp;quot;</title>
      <link>/questions/17903/how-do-i-view-all-streams-in-follow-tcp-streams/</link>
      <pubDate>Wed, 23 Jan 2013 11:12:00 +0000</pubDate>
      
      <guid>/questions/17903/how-do-i-view-all-streams-in-follow-tcp-streams/</guid>
      <description>How do I view all streams in &amp;ldquo;Follow Tcp Streams?&amp;quot;  0 I have a number of tcpdump traces. With one I could view the entire set of HTTP streams in &#34;Follow TCP Stream&#34;, and the rest not. I&#39;d like to be able to see all streams as in the first case and not sure how to make that happen. I tried various filters, e.g., &#39;tcp.stream ge 0&#39;, but it seems like wireshark would automatically reset to its own filter - &#39;tcp.</description>
    </item>
    
    <item>
      <title>Using Capture Filter &amp;quot;host 10.0.0.30&amp;quot; only captures Destination packets</title>
      <link>/questions/17910/using-capture-filter-host-100030-only-captures-destination-packets/</link>
      <pubDate>Wed, 23 Jan 2013 14:36:00 +0000</pubDate>
      
      <guid>/questions/17910/using-capture-filter-host-100030-only-captures-destination-packets/</guid>
      <description>Using Capture Filter &amp;ldquo;host 10.0.0.30&amp;rdquo; only captures Destination packets  0 I am trying to capture packets to and from host 10.0.0.30. In the Capture Options Dialogue box I entered a Capture Filter with Filter String: host 10.0.0.30 When viewing the captured File I only see packets that were destined for the 10.0.0.30 address. Do I need to do something different to get both directions? FYI, when I look at a capture file with no Capture Options I see packets to and from the 10.</description>
    </item>
    
    <item>
      <title>Can you create a GEOIP database of your own companies RFC1918 IP&amp;#x27;s?</title>
      <link>/questions/17911/can-you-create-a-geoip-database-of-your-own-companies-rfc1918-ips/</link>
      <pubDate>Wed, 23 Jan 2013 14:38:00 +0000</pubDate>
      
      <guid>/questions/17911/can-you-create-a-geoip-database-of-your-own-companies-rfc1918-ips/</guid>
      <description>Can you create a GEOIP database of your own companies RFC1918 IP&amp;rsquo;s?  0 I am wondering is there a way to generate your own GeoIP database for your companies own RFC1918 IP&#39;s? What I am trying to do is take our office locations city, Office IP subent/s, and Lat/Lon and make my own database so that I can see the interconnectivity of my own companies commuications.
This way I can go to the Endpoints Map and see the relation quicker.</description>
    </item>
    
    <item>
      <title>When message decode in rrc level ,then, the code stream is not been view.</title>
      <link>/questions/17917/when-message-decode-in-rrc-level-then-the-code-stream-is-not-been-view/</link>
      <pubDate>Wed, 23 Jan 2013 22:23:00 +0000</pubDate>
      
      <guid>/questions/17917/when-message-decode-in-rrc-level-then-the-code-stream-is-not-been-view/</guid>
      <description>When message decode in rrc level ,then, the code stream is not been view.  0 When message decode in rrc level ,then, the code stream is not been view. condition: WINOWS XP,wireshark-1.8.3.
the wonder is that could not been seen in UBUNTU.
who can help how to fix the problem? thanks.
code rrc streamasked 23 Jan &#39;13, 22:23
smilezuzu
20●32●32●37
accept rate: 0%
The question is to vauge to answer.</description>
    </item>
    
    <item>
      <title>Display successive data on one row when dissecting</title>
      <link>/questions/17925/display-successive-data-on-one-row-when-dissecting/</link>
      <pubDate>Thu, 24 Jan 2013 03:12:00 +0000</pubDate>
      
      <guid>/questions/17925/display-successive-data-on-one-row-when-dissecting/</guid>
      <description>Display successive data on one row when dissecting  0 Hi Forum,
I would like to know how dissect and display data in as successive fields on a single row using.
My data N | followed by n bytes - ie 1001020304050607080910
I wish to dissect and display as Count : 10 Values : [1,2,3,4,5,6,7,8,9,10].
The current dissector I am using
 {&amp;amp;hf_count, {&amp;quot;Count&amp;quot;, &amp;quot;&amp;quot;, FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL}}, {&amp;amp;hf_value,{&amp;quot;Value&amp;quot;, &amp;quot;&amp;quot;, FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL}}, proto_tree_add_item(.</description>
    </item>
    
    <item>
      <title>Wireshark crashed when using the &amp;quot;stop capture after&amp;quot; feature</title>
      <link>/questions/17928/wireshark-crashed-when-using-the-stop-capture-after-feature/</link>
      <pubDate>Thu, 24 Jan 2013 06:40:00 +0000</pubDate>
      
      <guid>/questions/17928/wireshark-crashed-when-using-the-stop-capture-after-feature/</guid>
      <description>Wireshark crashed when using the &amp;ldquo;stop capture after&amp;rdquo; feature  0 Hi everybody,
yesterday i made capture session with three wireshark machines and i used the &#34;stop capture&#34; and &#34;use multiple files&#34; option on all machines. At the end of the capture time, all machines were unuseable, wireshark shows &#34;closing file please wait&#34; and thats it. After killing wireshark the pcs are working normal. I use the 1.8.4 version. Perhaps anybody knows or have seen this too?</description>
    </item>
    
    <item>
      <title>Expert window messages collides with packet list</title>
      <link>/questions/17932/expert-window-messages-collides-with-packet-list/</link>
      <pubDate>Thu, 24 Jan 2013 07:09:00 +0000</pubDate>
      
      <guid>/questions/17932/expert-window-messages-collides-with-packet-list/</guid>
      <description>Expert window messages collides with packet list  0 Hi everybody,
Another little incomprehension. Right in this moment I analyze a capture file from a customer. I use the following display filter &#34;!eth.type == 0x8922 &amp;amp;&amp;amp; !arp &amp;amp;&amp;amp; !stp &amp;amp;&amp;amp; !nbns &amp;amp;&amp;amp; !bootp&#34;. When I open the expert info window I see a lot of bad checksum errors. If I choose a packet number from this window, the packet is not shown, because the filter works.</description>
    </item>
    
    <item>
      <title>Network switch ports failing - how to test?</title>
      <link>/questions/17934/network-switch-ports-failing-how-to-test/</link>
      <pubDate>Thu, 24 Jan 2013 07:56:00 +0000</pubDate>
      
      <guid>/questions/17934/network-switch-ports-failing-how-to-test/</guid>
      <description>Network switch ports failing - how to test?  0 I have a real odd situation when upgrading the network hardware in our office. I&#39;m replacing a couple of small unmanaged switches and installing some web managed switches. The network is flat and consists of about 60 windows XP, 7 and 2008 hosts.
The existing switches consists of a TrendNET GB Switch with a uplink to two netgear 10/100 switches. I installed a Dell web managed 48 port GB switch, with an uplink to the Trendnet.</description>
    </item>
    
    <item>
      <title>How does wireshark detects online-messenger traffic?</title>
      <link>/questions/17937/how-does-wireshark-detects-online-messenger-traffic/</link>
      <pubDate>Thu, 24 Jan 2013 10:32:00 +0000</pubDate>
      
      <guid>/questions/17937/how-does-wireshark-detects-online-messenger-traffic/</guid>
      <description>How does wireshark detects online-messenger traffic?  0 I have been working on how to find use of online messenger (e.g imo.im, ebuddy) using wireshark. I&#39;m doing , as i need to build SIEM (security information event management) use-cases which detects usage of online web-messenger.
To do little about of research, i went on a few online web-messenger and turned on the wireshark in the background. After a couple of minutes of browsing the online messenger sites , i stopped the wireshark and went straight on analysis.</description>
    </item>
    
    <item>
      <title>Using Wireshark, how can you tell whether an instant-message Website has been accessed?</title>
      <link>/questions/17939/using-wireshark-how-can-you-tell-whether-an-instant-message-website-has-been-accessed/</link>
      <pubDate>Thu, 24 Jan 2013 12:07:00 +0000</pubDate>
      
      <guid>/questions/17939/using-wireshark-how-can-you-tell-whether-an-instant-message-website-has-been-accessed/</guid>
      <description>Using Wireshark, how can you tell whether an instant-message Website has been accessed?  0 I have been working on how to find use of online messenger (e.g imo.im, ebuddy) using wireshark. I&#39;m doing , as i need to build SIEM (security information event management) use-cases which detects usage of online web-messenger.
To do little about of research, i went on a few online web-messenger and turned on the wireshark in the background.</description>
    </item>
    
    <item>
      <title>Wireshark not releasing memory back to OS while open...</title>
      <link>/questions/17941/wireshark-not-releasing-memory-back-to-os-while-open/</link>
      <pubDate>Thu, 24 Jan 2013 12:39:00 +0000</pubDate>
      
      <guid>/questions/17941/wireshark-not-releasing-memory-back-to-os-while-open/</guid>
      <description>Wireshark not releasing memory back to OS while open&amp;hellip;  1 Hi all, I am running some tests with Wireshark 1.8.4 on OSX (10.8.6). Long story short:
Open 700MB capture with default settings except Sub-dissector reassembly disabledWireshark memory usage at a nice 700 MB or soFollow stream that is hugeFollow stream pop-up window displaysMemory usage now at 3GB (meh, not great, but OK)Close follow stream pop-up and clear tcp.stream filterMemory usage now at 2.</description>
    </item>
    
    <item>
      <title>Wireshark crashes when capturing packets over a 10hr period</title>
      <link>/questions/17945/wireshark-crashes-when-capturing-packets-over-a-10hr-period/</link>
      <pubDate>Thu, 24 Jan 2013 16:46:00 +0000</pubDate>
      
      <guid>/questions/17945/wireshark-crashes-when-capturing-packets-over-a-10hr-period/</guid>
      <description>Wireshark crashes when capturing packets over a 10hr period  0 Hi,
I have a need to capture packets continuously (with a filter) in a ring buffer with each file size set to 300Mb and maximum of 4 files. This is all done to capture a particular rare instance of a packet failure.
I left my wireshark capture running overnight and then when I came back to look the following morning, the wireshark had crashed and had popped up a Visual Studio 2005 debug dialog to debug the crash.</description>
    </item>
    
    <item>
      <title>Is it a bad thing to see many [TCP Port numbers reused]?</title>
      <link>/questions/17955/is-it-a-bad-thing-to-see-many-tcp-port-numbers-reused/</link>
      <pubDate>Fri, 25 Jan 2013 14:13:00 +0000</pubDate>
      
      <guid>/questions/17955/is-it-a-bad-thing-to-see-many-tcp-port-numbers-reused/</guid>
      <description>Is it a bad thing to see many [TCP Port numbers reused]?  0 Here is a Wireshark capture that contains many [TCP Port numbers reused] packets.
You&#39;ll notice that the reused port messages begin at frame 47727 and continue on for the rest of the capture.
Understandably, every stream that contains a reused port message has a corresponding stream that occurred prior and that has the same client side port number.</description>
    </item>
    
    <item>
      <title>Menu bar stats remain after uninstall</title>
      <link>/questions/17957/menu-bar-stats-remain-after-uninstall/</link>
      <pubDate>Fri, 25 Jan 2013 17:06:00 +0000</pubDate>
      
      <guid>/questions/17957/menu-bar-stats-remain-after-uninstall/</guid>
      <description>Menu bar stats remain after uninstall  0 I&#39;ve followed the instructions to uninstall Wireshark, but the menu bar stats are still there in Mac 10.6.8. How do I get rid of those menu items on the top right of my Mac screen? Thanks.
man uninstallasked 25 Jan &#39;13, 17:06
JakeF
11●1●1●2
accept rate: 0%
  
One Answer:
  
0By finding out what software put them there, and either telling it not to put them there or removing that software.</description>
    </item>
    
    <item>
      <title>Mysterious dup acks, retransmissions with PCs at just two sites with HTTPS</title>
      <link>/questions/17960/mysterious-dup-acks-retransmissions-with-pcs-at-just-two-sites-with-https/</link>
      <pubDate>Sat, 26 Jan 2013 01:23:00 +0000</pubDate>
      
      <guid>/questions/17960/mysterious-dup-acks-retransmissions-with-pcs-at-just-two-sites-with-https/</guid>
      <description>Mysterious dup acks, retransmissions with PCs at just two sites with HTTPS  0 This problem is pretty fantastic - and is driving me nuts.
We have a server in a farm up at an ISP that that recently moved from old to new hardware to bring it into line with other identical servers in the farm. After the hardware move we checked everything was OK with being able to upload files up via HTTPS to this server - and all was good.</description>
    </item>
    
    <item>
      <title>Display HTTP content as text using tshark</title>
      <link>/questions/17961/display-http-content-as-text-using-tshark/</link>
      <pubDate>Sat, 26 Jan 2013 04:25:00 +0000</pubDate>
      
      <guid>/questions/17961/display-http-content-as-text-using-tshark/</guid>
      <description>Display HTTP content as text using tshark  0 Hi, I am using tshark to monitor http traffic on a server. I would like to display some of the IP fields, some of the HTTP headers and the HTTP content if it is textual. Is there a way to do this with tshark? Thanks David
http tsharkasked 26 Jan &#39;13, 04:25
David Sackstein
31●4●4●8
accept rate: 0%</description>
    </item>
    
    <item>
      <title>FRAMES percentage</title>
      <link>/questions/17965/frames-percentage/</link>
      <pubDate>Sat, 26 Jan 2013 08:26:00 +0000</pubDate>
      
      <guid>/questions/17965/frames-percentage/</guid>
      <description>FRAMES percentage  0 How do I ascertain the percentage of management frames vs data frames?
Edit: changed all upper case characters to resonable cases. Hint : you should check if your CAPS lock key is stuck, or if someone stole all your lower case letters ;-)
percentasked 26 Jan &#39;13, 08:26
SEGACIOUSBLONDE
11●1●1●2
accept rate: 0%
 edited 26 Jan &#39;13, 08:36 
Jasper ♦♦
23.8k●5●51●284</description>
    </item>
    
    <item>
      <title>What do dropped packets look like ?</title>
      <link>/questions/17975/what-do-dropped-packets-look-like/</link>
      <pubDate>Sat, 26 Jan 2013 20:39:00 +0000</pubDate>
      
      <guid>/questions/17975/what-do-dropped-packets-look-like/</guid>
      <description>What do dropped packets look like ?  0 Im using wireshark to measure command to response times as I slam a server with high rate messaging. Every once in a while a message is an outlier duration wise. It may be just dropped packets as seen at http://cloudshark.org/captures/0995a4524824 . Thanks for inputs.
packets droppedasked 26 Jan &#39;13, 20:39
dogma
11●1●1●4
accept rate: 0%
 edited 26 Jan &#39;13, 20:45</description>
    </item>
    
    <item>
      <title>Ubuntu 12.04 monitoring error</title>
      <link>/questions/17976/ubuntu-1204-monitoring-error/</link>
      <pubDate>Sun, 27 Jan 2013 00:12:00 +0000</pubDate>
      
      <guid>/questions/17976/ubuntu-1204-monitoring-error/</guid>
      <description>Ubuntu 12.04 monitoring error  0 after I set up my group and permissions i tried running wireshark in monitoring mode. I checked the box next to monitoring mode in the preferences hit ok then apply then I revived an error box that said Can&#39;t open preferences file &#34;/home/reaper/.wireshark/preferences&#34;: Permission denied
Then i had to reset my connection because I wasn&#39;t able to surf the web afterwards. Any ideas how to fix this?</description>
    </item>
    
    <item>
      <title>RTP packet  loss</title>
      <link>/questions/17977/rtp-packet-loss/</link>
      <pubDate>Sun, 27 Jan 2013 02:46:00 +0000</pubDate>
      
      <guid>/questions/17977/rtp-packet-loss/</guid>
      <description>RTP packet loss  0 Hi, I have a Wireshark RTP trace, taken between 2 telecomm nodes A and B. Currently I am observing packet loss on A( as per statistics in A node) upon taking the interface traces,I could see Wrong sequence number on each of the streams between B to A(where B is source and A is Destination).
So my queries are
1.) Packet loss is considered by wrong sequence number on each stream individually or Please confirm the allocation of sequence number for multi stream bidirectional communication.</description>
    </item>
    
    <item>
      <title>how do i trace my remote machine Activity through wireshark</title>
      <link>/questions/17983/how-do-i-trace-my-remote-machine-activity-through-wireshark/</link>
      <pubDate>Sun, 27 Jan 2013 05:14:00 +0000</pubDate>
      
      <guid>/questions/17983/how-do-i-trace-my-remote-machine-activity-through-wireshark/</guid>
      <description>how do i trace my remote machine Activity through wireshark  0 how do i trace my remote machine Activity through wireshark...?
remote-monitoringasked 27 Jan &#39;13, 05:14
kaushal
1●2●2●3
accept rate: 0%
  
One Answer:
  
0First of all, you need to capture the packets the remote machine sends and receives. Maybe this URL can help with the basic setup to do that:
http://wiki.wireshark.org/CaptureSetup/Ethernet
If all else fails you could install Wireshark on the remote machine, but that is always a &#34;</description>
    </item>
    
    <item>
      <title>Webservice seems to pause in wireshark and then wake up and respond</title>
      <link>/questions/17985/webservice-seems-to-pause-in-wireshark-and-then-wake-up-and-respond/</link>
      <pubDate>Sun, 27 Jan 2013 10:14:00 +0000</pubDate>
      
      <guid>/questions/17985/webservice-seems-to-pause-in-wireshark-and-then-wake-up-and-respond/</guid>
      <description>Webservice seems to pause in wireshark and then wake up and respond  0 Our https webservice response time has gone from about 3 seconds to 16 seconds. Running wireshark (which I am new to so I can&#39;t read efficiently but am trying) what I seem to see is that we get an encrypted handshake msg from our data vendor (no. 1231). We ack it in no. 1240. Then it almost seems that our webservice goes to sleep or something (don&#39;t know what), then about 15 seconds later it finally at no.</description>
    </item>
    
    <item>
      <title>Can tshark display textual HTTP content during capture?</title>
      <link>/questions/17987/can-tshark-display-textual-http-content-during-capture/</link>
      <pubDate>Sun, 27 Jan 2013 11:19:00 +0000</pubDate>
      
      <guid>/questions/17987/can-tshark-display-textual-http-content-during-capture/</guid>
      <description>Can tshark display textual HTTP content during capture?  1 Hi SYN-bit I posted this question on ask.wireshark.org: http://ask.wireshark.org/questions/17961/display-http-content-as-text-using-tshark Jasper suggested I ask you whether you can help here. The question basically is, is it possible to get tshark to emit the content of a (textual) HTTP conversation live, that is not on a set of packets that have already been captured? Thanks! David
live http tsharkasked 27 Jan &#39;13, 11:19</description>
    </item>
    
    <item>
      <title>RTP dissector in Lua not chained with SDP setup info present and post-dissector not saved in pdml</title>
      <link>/questions/17989/rtp-dissector-in-lua-not-chained-with-sdp-setup-info-present-and-post-dissector-not-saved-in-pdml/</link>
      <pubDate>Sun, 27 Jan 2013 12:56:00 +0000</pubDate>
      
      <guid>/questions/17989/rtp-dissector-in-lua-not-chained-with-sdp-setup-info-present-and-post-dissector-not-saved-in-pdml/</guid>
      <description>RTP dissector in Lua not chained with SDP setup info present and post-dissector not saved in pdml  0 Hi, I&#39;m pretty much a Wireshark noob, but..
I&#39;m trying to analyze some RTP streams, some of which are set up by SIP (with some additional features).
I&#39;m writing packet dissectors in Lua, but there are a couple of problems. As far as I can tell, if I use a chained dissector and add it to the udp dissector table where udp.</description>
    </item>
    
    <item>
      <title>Hi. I got problem with &amp;quot;closing file waiting....&amp;quot;</title>
      <link>/questions/17993/hi-i-got-problem-with-closing-file-waiting/</link>
      <pubDate>Sun, 27 Jan 2013 18:10:00 +0000</pubDate>
      
      <guid>/questions/17993/hi-i-got-problem-with-closing-file-waiting/</guid>
      <description>Hi. I got problem with &amp;ldquo;closing file waiting&amp;hellip;.&amp;quot;  0 When I make multiple file as 100mb.. It appeared on currently capturing session. It seems to be temporary message... but it&#39;s not finished until I close Wireshark.... please help me.. It happened to stable version of Wireshark 1.8.4
closing fileasked 27 Jan &#39;13, 18:10
SSH
11●1●1●2
accept rate: 0%
 edited 28 Jan &#39;13, 11:21 
cmaynard ♦♦
9.4k●10●38●142</description>
    </item>
    
    <item>
      <title>Disable dumpcap / WireShark as Protocol Analyzer only</title>
      <link>/questions/18003/disable-dumpcap-wireshark-as-protocol-analyzer-only/</link>
      <pubDate>Mon, 28 Jan 2013 08:39:00 +0000</pubDate>
      
      <guid>/questions/18003/disable-dumpcap-wireshark-as-protocol-analyzer-only/</guid>
      <description>Disable dumpcap / WireShark as Protocol Analyzer only  0 Hi,
Is there any way to use WireShark as a Protocol Analyzer only and disable the hability to &#34;sniffing&#34; the network?
My idea is to relase the software for some engeneer people here but I don&#39;t want then to grab new data, only to analyze &#34;already captured data&#34; for Wireshark.
Is that possible?
winpcap sniffer disable dumpcap analyzerasked 28 Jan &#39;13, 08:39</description>
    </item>
    
    <item>
      <title>SSL or not SSL</title>
      <link>/questions/18013/ssl-or-not-ssl/</link>
      <pubDate>Mon, 28 Jan 2013 12:26:00 +0000</pubDate>
      
      <guid>/questions/18013/ssl-or-not-ssl/</guid>
      <description>SSL or not SSL  0 We have built a WCF Self-Hosted application that has a SSL cert attached to port 15014. All of that works like it should but it seems that i want to make sure i truly see the SSL handshake so I captured soem packets and what worries me is that it only hsows TCP and no SSLv?. IF i am trying to go to https://servername:15014 and should it not show some sort of SSL functionality in wireshark and not just TCP?</description>
    </item>
    
    <item>
      <title>ACK in segment greater than SLE and SRE</title>
      <link>/questions/18019/ack-in-segment-greater-than-sle-and-sre/</link>
      <pubDate>Mon, 28 Jan 2013 21:23:00 +0000</pubDate>
      
      <guid>/questions/18019/ack-in-segment-greater-than-sle-and-sre/</guid>
      <description>ACK in segment greater than SLE and SRE  0 Can ACK in segment be greater than LE and RE? Actually I observe such behaviour a lot [TCP Dup ACK 6126#1] 55160 &amp;gt; 80 [ACK] Seq=3817 Ack=4157995 Win=123236 Len=0 SLE=4149831 SRE=4151291
We&#39;re trying to troubleshoot strange issue of client-browsers sometimes receiving crashed data over HTTP. Client and server both have 10g NICs in pure 10g environment. Client - VM (esxi).</description>
    </item>
    
    <item>
      <title>How can I capture non-data packets (Beacon, Associate, etc.) on OS X?</title>
      <link>/questions/18023/how-can-i-capture-non-data-packets-beacon-associate-etc-on-os-x/</link>
      <pubDate>Tue, 29 Jan 2013 03:14:00 +0000</pubDate>
      
      <guid>/questions/18023/how-can-i-capture-non-data-packets-beacon-associate-etc-on-os-x/</guid>
      <description>How can I capture non-data packets (Beacon, Associate, etc.) on OS X?  0 I installed the Wireshark on my MAC and tried to sniff the air for WLAN packets (802.11) I see packets that looks like a higher level than what I expected For ex. I do not see Beacons or do not see Association packets when I closed and opened my WiFi. On the other hand, I do see DNS packets and NBNC packets.</description>
    </item>
    
    <item>
      <title>Tshark Command to make a xml file of wireshark data</title>
      <link>/questions/18024/tshark-command-to-make-a-xml-file-of-wireshark-data/</link>
      <pubDate>Tue, 29 Jan 2013 03:18:00 +0000</pubDate>
      
      <guid>/questions/18024/tshark-command-to-make-a-xml-file-of-wireshark-data/</guid>
      <description>Tshark Command to make a xml file of wireshark data  0 Hey. I am new to wireshark &amp;amp; need some help. How can I make a xml file of wireshark data using tshark command? Tshark does not allow me to write anything initially. How to write a command on it?
xml command tshark file wiresharkasked 29 Jan &#39;13, 03:18
Hamra Rehan
1●2●3●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>SS7 BSSAP Protocol</title>
      <link>/questions/18030/ss7-bssap-protocol/</link>
      <pubDate>Tue, 29 Jan 2013 04:06:00 +0000</pubDate>
      
      <guid>/questions/18030/ss7-bssap-protocol/</guid>
      <description>SS7 BSSAP Protocol  0 I wonder how does Wireshark know that there is BSSAP underlying the SCCP protocol ?
ss7 bssapasked 29 Jan &#39;13, 04:06
ahmediukas
21●5●6●10
accept rate: 0%
  
One Answer:
  
1 By the sub system number, SSN 98 is tied to BSSAP, changable by a protocol preference.
answered 29 Jan &#39;13, 05:58
Anders ♦
4.6k●9●52
accept rate: 17%
Isnt SSN specified as 250 (BSC) and 251 (MSC) ?</description>
    </item>
    
    <item>
      <title>Is there a way to export wireshark statistics data</title>
      <link>/questions/18031/is-there-a-way-to-export-wireshark-statistics-data/</link>
      <pubDate>Tue, 29 Jan 2013 04:36:00 +0000</pubDate>
      
      <guid>/questions/18031/is-there-a-way-to-export-wireshark-statistics-data/</guid>
      <description>Is there a way to export wireshark statistics data  0 Background:
My requirements are to analyze network traffic from pcap files and present data in a graphical format for quick consumption. Wireshark is the most common choice that is recommended by many to analyze data from pcap files, but its graphical capabilities are limited
What I would eventually want would be to extract data from pcap files in a understandable structure and then run statistical analysis on it depending on the requirements of my users.</description>
    </item>
    
    <item>
      <title>SGS interface</title>
      <link>/questions/18037/sgs-interface/</link>
      <pubDate>Tue, 29 Jan 2013 06:42:00 +0000</pubDate>
      
      <guid>/questions/18037/sgs-interface/</guid>
      <description>SGS interface  0 Hello,
I&#39;m trying to decode SG interface, but i can&#39;t, I see that there is a correction to can do it, but i don&#39;t know how can load.
Please could you send me info? how can I load this correction or how can I decode SG interface?
SG interface (MSS&amp;lt;---&amp;gt;MME)
BR, Raúl
sg_protocolasked 29 Jan &#39;13, 06:42
ratienz
1●1●1●2
accept rate: 0%
Which protocols(s) are used on that interface?</description>
    </item>
    
    <item>
      <title>cisco switchport input errors</title>
      <link>/questions/18041/cisco-switchport-input-errors/</link>
      <pubDate>Tue, 29 Jan 2013 09:08:00 +0000</pubDate>
      
      <guid>/questions/18041/cisco-switchport-input-errors/</guid>
      <description>cisco switchport input errors  0 As of last week, I started receiving numerous input errors on three switchports of a cisco 3750 12 port fiber switch. For example, 21439 input errors, 3 CRC. Switchports on other switches connected to this fiber switch show 0 input errors. I am monitoring three ports in question and captured 5 minutes of traffic. What is the best way to analyze capture to possibly determine source of input errors?</description>
    </item>
    
    <item>
      <title>Spanning tree for bridges</title>
      <link>/questions/18042/spanning-tree-for-bridges/</link>
      <pubDate>Tue, 29 Jan 2013 09:18:00 +0000</pubDate>
      
      <guid>/questions/18042/spanning-tree-for-bridges/</guid>
      <description>Spanning tree for bridges  0 18 2012-11-08 07:58:03.331868 3comEuro_6c:a0:2c Spanning-tree-(for-bridges)_00 STP 120 MST. Root = 32768/0/00:1e:c1:6c:9f:fa Cost = 0 Port = 0x8032Why does this appear/occur every 2 seconds on my network? Is it really necessary for it to occur every 2 seconds?
spanningtree stpasked 29 Jan &#39;13, 09:18
cherokee
1●1●1●1
accept rate: 0%
 edited 29 Jan &#39;13, 09:22 
SYN-bit ♦♦
17.1k●9●57●245
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Extracting Segmented SOAP XML Payload</title>
      <link>/questions/18046/extracting-segmented-soap-xml-payload/</link>
      <pubDate>Tue, 29 Jan 2013 09:50:00 +0000</pubDate>
      
      <guid>/questions/18046/extracting-segmented-soap-xml-payload/</guid>
      <description>Extracting Segmented SOAP XML Payload  0 The following script:http://ask.wireshark.org/questions/4639/extracting-soap-xml-payload/4835 allows extracting soap messages. However, it fails to do so when the message is distributed over several TCP segments. Any hint to solve this problem?
lua http desegment soap tsharkasked 29 Jan &#39;13, 09:50
masgad
5●1●1●4
accept rate: 0%
 edited 29 Jan &#39;13, 10:30 
Please upload a sample capture on http://cloudshark.org, and post a link here. What version of tshark are you using?</description>
    </item>
    
    <item>
      <title>Capturing on Windows Server 2003 runs out of memory very quickly</title>
      <link>/questions/18052/capturing-on-windows-server-2003-runs-out-of-memory-very-quickly/</link>
      <pubDate>Tue, 29 Jan 2013 12:02:00 +0000</pubDate>
      
      <guid>/questions/18052/capturing-on-windows-server-2003-runs-out-of-memory-very-quickly/</guid>
      <description>Capturing on Windows Server 2003 runs out of memory very quickly  0 I have been testing Wireshark v1.8.4, 32-bit version on Windows 2003 Server (32-bit, 2gig memory), Windows XP (32-bit 2gig memory) and Windows 7 (64-bit 4gig memory). All just monitoring short packets. The Windows 2003 Server use up memory much faster, and does not release it when you &#34;restart&#34; the capture or when you are capturing to disk, limit 10MB.</description>
    </item>
    
    <item>
      <title>Merge/Compare -- client/server files</title>
      <link>/questions/18053/mergecompare-clientserver-files/</link>
      <pubDate>Tue, 29 Jan 2013 12:12:00 +0000</pubDate>
      
      <guid>/questions/18053/mergecompare-clientserver-files/</guid>
      <description>Merge/Compare &amp;ndash; client/server files  0 Hi,
I have two capture files, client facing and server facing. There is a device in the middle that is dropping packets and I have identified the device, however, I require a little more evidence. I would like to know if there is a way to merge these two files together and &#34;see&#34; with a graph or other method, that lines up the missing packets.</description>
    </item>
    
    <item>
      <title>iSCSI Communication appears incorrect handshaking</title>
      <link>/questions/18054/iscsi-communication-appears-incorrect-handshaking/</link>
      <pubDate>Tue, 29 Jan 2013 12:13:00 +0000</pubDate>
      
      <guid>/questions/18054/iscsi-communication-appears-incorrect-handshaking/</guid>
      <description>iSCSI Communication appears incorrect handshaking  0 I have a customer that&#39;s having performance problems. Looking at their trace it seems clear why. See first 50 packets at link below. This pattern basically repeats itself. http://cloudshark.org/captures/68a28bf0fd38
client IP = 172.18.1.14 Storage IP = 172.18.1.15 All on same switch and same VLAN. First of all the client sends a read LUN request in frame 8. This looks fine. But I&#39;m not sure why he keeps sending ACKS.</description>
    </item>
    
    <item>
      <title>Gaps in RTP Playback</title>
      <link>/questions/18058/gaps-in-rtp-playback/</link>
      <pubDate>Tue, 29 Jan 2013 15:52:00 +0000</pubDate>
      
      <guid>/questions/18058/gaps-in-rtp-playback/</guid>
      <description>Gaps in RTP Playback  0 I&#39;ve come across a number of VoIP calls that when decoded in wireshark show an odd time distortion between the two audio legs.
For instance leg A -&amp;gt; B shows audio beginning at 2 seconds and continues until 32 seconds. Leg A &amp;lt;- B shows a small amount of audio up until 2 second, then a yellow bar in the playback window, then no activity until say 35 seconds, another yellow bar, and then audio until 65 seconds.</description>
    </item>
    
    <item>
      <title>Permission to use the icon</title>
      <link>/questions/18075/permission-to-use-the-icon/</link>
      <pubDate>Tue, 29 Jan 2013 22:54:00 +0000</pubDate>
      
      <guid>/questions/18075/permission-to-use-the-icon/</guid>
      <description>Permission to use the icon  0 Hello
We work on Windows Package Manager (http://code.google.com/p/windows-package-manager/) released under GNU GPL license. It helps to find and install software, keep a system up-to-date and uninstall it if no longer necessary.
I&#39;d like to ask for permission to copy the &#39;Wireshark&#39; icon (wireshark-1.8.5/image/wsicon32.png) to Npackd web server and use it for &#39;Wireshark&#39; package identifying icon.
Thank You
Evgeny
iconasked 29 Jan &#39;13, 22:54</description>
    </item>
    
    <item>
      <title>What causes this UDP stream to truncate?</title>
      <link>/questions/18077/what-causes-this-udp-stream-to-truncate/</link>
      <pubDate>Wed, 30 Jan 2013 00:01:00 +0000</pubDate>
      
      <guid>/questions/18077/what-causes-this-udp-stream-to-truncate/</guid>
      <description>What causes this UDP stream to truncate?  0 We have a server sending a large UDP stream to another server for processing. The server is connected to a Layer3 switch. From there, the packets pass through another internal router to get to the destination server.
By the time it gets to the proper network segment, a Wireshark capture shows the UDP stream is truncated by about 100 bytes. It starts off from the sending server at 1558 bytes (this is data only) and arrives at 1458 bytes.</description>
    </item>
    
    <item>
      <title>tcp_dissect_pdus doesn&amp;#x27;t work well - TCP segment of a reassembled PDU</title>
      <link>/questions/18082/tcp_dissect_pdus-doesnt-work-well-tcp-segment-of-a-reassembled-pdu/</link>
      <pubDate>Wed, 30 Jan 2013 01:14:00 +0000</pubDate>
      
      <guid>/questions/18082/tcp_dissect_pdus-doesnt-work-well-tcp-segment-of-a-reassembled-pdu/</guid>
      <description>tcp_dissect_pdus doesn&amp;rsquo;t work well - TCP segment of a reassembled PDU  0 Hey, I&#39;m wrote a wireshark dissector named PLUGIN.
Now when I&#39;m testing it, for some reason a packet of type X can be seen on the wireshark as PLUGIN (like it should), and some other packets afterwards, of the same type X cannot be seen as PLUGIN.
The other packets can be found in the .pcap as [TCP segment of a reassembled PDU]</description>
    </item>
    
    <item>
      <title>TLS&amp;#92;_RSA&amp;#92;_CAMELLIA&amp;#92;_256&amp;#92;_CBC&amp;#92;_SHA decryption</title>
      <link>/questions/18087/tls_rsa_camellia_256_cbc_sha-decryption/</link>
      <pubDate>Wed, 30 Jan 2013 02:45:00 +0000</pubDate>
      
      <guid>/questions/18087/tls_rsa_camellia_256_cbc_sha-decryption/</guid>
      <description>TLS\_RSA\_CAMELLIA\_256\_CBC\_SHA decryption  1 Hi everyone!
Does Wireshark support ssl RSA-CAMELLIA cipher decryption? I&#39;m trying to decrypt a pcap log (with the well known RSA private key) of a https session between Firefox and my local server and I got the following error:
dissect_ssl3_hnd_srv_hello can&#39;t find cipher suite 0x84
Now, cipher suite number 0x84 is: TLS_RSA_CAMELLIA_256_CBC_SHA1
So do I have to specify any flag during the building of the programm to enable camellia?</description>
    </item>
    
    <item>
      <title>IO Throughput using only the Headers</title>
      <link>/questions/18091/io-throughput-using-only-the-headers/</link>
      <pubDate>Wed, 30 Jan 2013 03:43:00 +0000</pubDate>
      
      <guid>/questions/18091/io-throughput-using-only-the-headers/</guid>
      <description>IO Throughput using only the Headers  0 I have a device that it receiving a large amount of traffic on its gigabit link. I&#39;m slightly worried about running a standard capture on it as it may create performance issues for the device. My question is what methods can I use to limit the amount of traffic I have to capture, that would still allow me to report the statistics within wireshark or tshark.</description>
    </item>
    
    <item>
      <title>Error when opening Wireshark</title>
      <link>/questions/18094/error-when-opening-wireshark/</link>
      <pubDate>Wed, 30 Jan 2013 04:20:00 +0000</pubDate>
      
      <guid>/questions/18094/error-when-opening-wireshark/</guid>
      <description>Error when opening Wireshark  0 Hi guys,
When I want to open Wireshark I get this error : error while loading shared libraries: libpcap.so.0.8: cannot open shared object file: No such file or directory
I tried apt-get install libpcap08 unsucessfully.
Any ideas ? I took a look on plenty websites including searching for the libcap error itself but still nothing :(
libpcapasked 30 Jan &#39;13, 04:20
Nymeria
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How do I decode BCDs in Lua?</title>
      <link>/questions/18106/how-do-i-decode-bcds-in-lua/</link>
      <pubDate>Wed, 30 Jan 2013 08:24:00 +0000</pubDate>
      
      <guid>/questions/18106/how-do-i-decode-bcds-in-lua/</guid>
      <description>How do I decode BCDs in Lua?  0 In my Lua dissector, I have to decode BCDs. I see no readily available tools for this in Wireshark Lua. Can someone explain how I can do this?
For example, a BCD of 0x12345678 is sent on the wire as 0x21436587. I have to dissect it and show it as 12345678.
bcd luaasked 30 Jan &#39;13, 08:24
Aruna Sirigere
6●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Playback of captured session</title>
      <link>/questions/18107/playback-of-captured-session/</link>
      <pubDate>Wed, 30 Jan 2013 09:17:00 +0000</pubDate>
      
      <guid>/questions/18107/playback-of-captured-session/</guid>
      <description>Playback of captured session  0 Hi:
Can wireshark playback a captured tcpip session between a client and a server? For the playback can the ip addresses be changed, for example the client and server are moved to a different subnet. Can the capture and playback use a mac address instead of an ip address?
Thank you!
playbackasked 30 Jan &#39;13, 09:17
rkidd
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>filter first 3 hex values of source mac address</title>
      <link>/questions/18118/filter-first-3-hex-values-of-source-mac-address/</link>
      <pubDate>Wed, 30 Jan 2013 11:52:00 +0000</pubDate>
      
      <guid>/questions/18118/filter-first-3-hex-values-of-source-mac-address/</guid>
      <description>filter first 3 hex values of source mac address  0 NEWBIE
the mac address consists out of 6 hex values. But I want to only filter is on the first 3 hex values (brand info)
Is there some kind of wild card I can use, example: ether.src == 00:20:4a:8f:3d:b1
00:20:4a:8f:3d:b1 = Pronet_8f:3d:b1
mac-adddress capture-filterasked 30 Jan &#39;13, 11:52
mear1628
11●1●1●2
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>What does the SMB Pipe protocol do?</title>
      <link>/questions/18128/what-does-the-smb-pipe-protocol-do/</link>
      <pubDate>Wed, 30 Jan 2013 13:15:00 +0000</pubDate>
      
      <guid>/questions/18128/what-does-the-smb-pipe-protocol-do/</guid>
      <description>What does the SMB Pipe protocol do?  0 Looking for a description on what the SMB Pipe protocol does.
Thanks!
smbasked 30 Jan &#39;13, 13:15
Honest Tea
1●1●1●1
accept rate: 0%
  
One Answer:
  
1From the dissector code
* Routines for SMB named pipe packet dissection
So, the dissector detects and dissects access to named pipes through SMB.
For a brief description of SMB named pipes, see here:</description>
    </item>
    
    <item>
      <title>tcpdump -R not filtering live captures</title>
      <link>/questions/18130/tcpdump-r-not-filtering-live-captures/</link>
      <pubDate>Wed, 30 Jan 2013 13:56:00 +0000</pubDate>
      
      <guid>/questions/18130/tcpdump-r-not-filtering-live-captures/</guid>
      <description>tcpdump -R not filtering live captures  0 The man page for tshark implies -R will work on live captures but my output files are not filtered.
tshark -b filesize:50000 -R &#39;(mgcp||sip||sdp||rtpevent)&#39; -i any -w tshark.cap
tshark is not filtering the dumpcap data at all. I would like to filter the data to limit the size of the pcap files.
Thanks
CentOS 2.6.18-238.9.1.el5 #1 SMP Tue Apr 12 18:10:13 EDT 2011 x86_64 x86_64 x86_64 GNU/Linux</description>
    </item>
    
    <item>
      <title>rrc code stream can&amp;#x27;t display in XP, but in ubuntu is ok.</title>
      <link>/questions/18159/rrc-code-stream-cant-display-in-xp-but-in-ubuntu-is-ok/</link>
      <pubDate>Thu, 31 Jan 2013 02:20:00 +0000</pubDate>
      
      <guid>/questions/18159/rrc-code-stream-cant-display-in-xp-but-in-ubuntu-is-ok/</guid>
      <description>rrc code stream can&amp;rsquo;t display in XP, but in ubuntu is ok.  0 rrc code stream can&#39;t display in XP, but in ubuntu is ok. wireshark 1.8.3.or wireshark 1.8.4。
xp code rrc stream ubuntuasked 31 Jan &#39;13, 02:20
smilezuzu
20●32●32●37
accept rate: 0%
  
One Answer:
  
0Please check the reply Anders gave you in your previous post (https://ask.wireshark.org/questions/17917/when-message-decode-in-rrc-level-then-the-code-stream-is-not-been-view). Unless you give us more information about what you are doing, and ideally posting a pcap sample file on cloudshark for example, it&#39;s gonna be hard to help you.</description>
    </item>
    
    <item>
      <title>if the new version of wireshark should have the decipher function in umts_rlc AM and UM?</title>
      <link>/questions/18161/if-the-new-version-of-wireshark-should-have-the-decipher-function-in-umts_rlc-am-and-um/</link>
      <pubDate>Thu, 31 Jan 2013 02:24:00 +0000</pubDate>
      
      <guid>/questions/18161/if-the-new-version-of-wireshark-should-have-the-decipher-function-in-umts_rlc-am-and-um/</guid>
      <description>if the new version of wireshark should have the decipher function in umts_rlc AM and UM?  0 if the new version of wireshark should have the decipher function in umts_rlc AM and UM?
I&#39;m desired to have new wireshark which could help me to decipher in ciphered message.
decipher um am rlcasked 31 Jan &#39;13, 02:24
smilezuzu
20●32●32●37
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How routers handle IPv4 TTL value 0</title>
      <link>/questions/18176/how-routers-handle-ipv4-ttl-value-0/</link>
      <pubDate>Thu, 31 Jan 2013 04:20:00 +0000</pubDate>
      
      <guid>/questions/18176/how-routers-handle-ipv4-ttl-value-0/</guid>
      <description>How routers handle IPv4 TTL value 0  0 I have a following setup:
If I send IPv4 packets with TTL value 0 from T60 I receive:
ICMP time exceeded in-transit..message from 10.10.10.2(R1) as I should. Now if I send IPv4 packets with TTL value 1 from T60 I receive once again:
ICMP time exceeded in-transitmessage from 10.10.10.2(R1). If I change TTL to 2, then I receive
ICMP time exceeded in-transit.</description>
    </item>
    
    <item>
      <title>Decrypting Kerberos tickets</title>
      <link>/questions/18178/decrypting-kerberos-tickets/</link>
      <pubDate>Thu, 31 Jan 2013 04:28:00 +0000</pubDate>
      
      <guid>/questions/18178/decrypting-kerberos-tickets/</guid>
      <description>Decrypting Kerberos tickets  0 I&#39;m doing a network capture using wireshark targeting some Kerberos traffic (ticket cache is flushed, then a request is made to a file server - thus generating the AS-REQ/AS-REP/TGS-REQ/TGS-REP sequences) and I&#39;d like to see the encrypted parts of the tickets (eg timestamps used as authenticators). I&#39;ve found http://i1.blogs.msdn.com/b/spatdsg/archive/2009/03/26/more-kerberos-fun-with-pac-s.aspx which is pretty straightforward. However, by doing the steps presented there, the encrypted part is never decrypted.</description>
    </item>
    
    <item>
      <title>IO Graph dns.time when filtering for dns.time&amp;lt;=.1 (tried 0.1 too) less than a tenth of a second</title>
      <link>/questions/18182/io-graph-dnstime-when-filtering-for-dnstime1-tried-01-too-less-than-a-tenth-of-a-second/</link>
      <pubDate>Thu, 31 Jan 2013 07:19:00 +0000</pubDate>
      
      <guid>/questions/18182/io-graph-dnstime-when-filtering-for-dnstime1-tried-01-too-less-than-a-tenth-of-a-second/</guid>
      <description>IO Graph dns.time when filtering for dns.time&amp;lt;=.1 (tried 0.1 too) less than a tenth of a second  0 I have a file that has 1 million packets captured in it. When loading in the file, I filtered it with the filter of dns.time&amp;lt;=0.1. I then tried to create a graph via Statistics|IO Graph. I set the Y access to Unit:Advanced... Set Filter:dns.time&amp;lt;=0.1, Calc:AVG(*)dns.time. The capture shows that the time span (x Axis) shows 260s.</description>
    </item>
    
    <item>
      <title>Getting specific SOAP-information</title>
      <link>/questions/18185/getting-specific-soap-information/</link>
      <pubDate>Thu, 31 Jan 2013 08:14:00 +0000</pubDate>
      
      <guid>/questions/18185/getting-specific-soap-information/</guid>
      <description>Getting specific SOAP-information  0 Hey,
I want to get information out of SOAP... In the SOAP-Body is a node called:
&amp;lt;ns1:writeReport [..just a lot of unnecessary things..] xmlns:ns1=&amp;#39;http://writeReport.[domain].de&amp;#39;&amp;gt;In this node is an other node called:
&amp;lt;PartnerID&amp;gt; 123456789 &amp;lt;/PartnerID&amp;gt;I just want to get the information of the PartnerID with &amp;gt;tShark&amp;lt;. How do I do this?
When I try to use this parameter:
-X env:EnvelopeI just get the names of the nodes, but not the content inside.</description>
    </item>
    
    <item>
      <title>Need help in trying to figure out where packets are getting dropped</title>
      <link>/questions/18186/need-help-in-trying-to-figure-out-where-packets-are-getting-dropped/</link>
      <pubDate>Thu, 31 Jan 2013 09:15:00 +0000</pubDate>
      
      <guid>/questions/18186/need-help-in-trying-to-figure-out-where-packets-are-getting-dropped/</guid>
      <description>Need help in trying to figure out where packets are getting dropped  0 We have several remote sites connecting to a central location. Each remote site has its own file and print server hosted at the central location as virtual machines. Recently, we&#39;ve been having problems pulling data from one of these servers (e.g., getting directory listing containing large amounts of files and folders), but only from machines at the central site.</description>
    </item>
    
    <item>
      <title>Utility to sort pcap or pcapng capture file based on timestamp?</title>
      <link>/questions/18190/utility-to-sort-pcap-or-pcapng-capture-file-based-on-timestamp/</link>
      <pubDate>Thu, 31 Jan 2013 14:38:00 +0000</pubDate>
      
      <guid>/questions/18190/utility-to-sort-pcap-or-pcapng-capture-file-based-on-timestamp/</guid>
      <description>Utility to sort pcap or pcapng capture file based on timestamp?  0 Hello: I am using a PC with two NICs to capture both directions of traffic using a Gigamon Copper tap. Unfortunately it appears that one of the NICs is faster than the other in writing to the unified capture file and I have a large number of &#34;TCP ACKed unseen segment&#34; tagged packets in the file. If I sort by time stamp the packets are in the correct order but Wireshark appears to interpret based on the packet number rather than the time stamp.</description>
    </item>
    
    <item>
      <title>How do I make a dissector handle a particular EtherType (Ethernet type field) value?</title>
      <link>/questions/18191/how-do-i-make-a-dissector-handle-a-particular-ethertype-ethernet-type-field-value/</link>
      <pubDate>Thu, 31 Jan 2013 14:46:00 +0000</pubDate>
      
      <guid>/questions/18191/how-do-i-make-a-dissector-handle-a-particular-ethertype-ethernet-type-field-value/</guid>
      <description>How do I make a dissector handle a particular EtherType (Ethernet type field) value?  0 I have a custom packet that can be encapsulated in a TCP/IP or Ethernet protocol. The problem im having is adding my heuristic dissector in at the lowest level so the TCP/IP and Ethernet sections of the packets are decoded by their respective dissectors first before coming to my dissector.
If i use heur_dissector_add(&#34;eth&#34;,(heur_dissector_t) dissect_PROTONAME, proto_PROTONAME); it adds it in at the ethernet level but because the eth dissector tries all the heuristic dissectors first before it tries itself the destination and source MAC addresses aren&#39;t decoded.</description>
    </item>
    
    <item>
      <title>In wireshark1.8.3.XP. the soft can&amp;#x27;t remember the path which have just used.</title>
      <link>/questions/18203/in-wireshark183xp-the-soft-cant-remember-the-path-which-have-just-used/</link>
      <pubDate>Thu, 31 Jan 2013 18:33:00 +0000</pubDate>
      
      <guid>/questions/18203/in-wireshark183xp-the-soft-cant-remember-the-path-which-have-just-used/</guid>
      <description>In wireshark1.8.3.XP. the soft can&amp;rsquo;t remember the path which have just used.  0 In wireshark1.8.3.XP. the soft can&#39;t remember the path which have just used.
so the way to load a *.pcap are: 1,menu-&amp;gt;file-&amp;gt;open. 2,open button.(in the main interface)
but I used to open a *.pcap through the remembered path direct (in the main interface).
could you fix this .
in version wireshark1.6.4, there is no this problem.
load path remember fileasked 31 Jan &#39;13, 18:33</description>
    </item>
    
    <item>
      <title>Capture Traffic Between Two Machines</title>
      <link>/questions/18227/capture-traffic-between-two-machines/</link>
      <pubDate>Fri, 01 Feb 2013 08:01:00 +0000</pubDate>
      
      <guid>/questions/18227/capture-traffic-between-two-machines/</guid>
      <description>Capture Traffic Between Two Machines  0 WS 1.8.4 - I&#39;m wondering how I can capture traffic only between two machines? I basically want the capture filter to get all tcp/ip traffic between just two machines in both directions. Then I&#39;ll use a display filter to drill deeper than that.
I&#39;ve tried the following commands and close variants (substituting &amp;amp;&amp;amp; for and, etc.)
(ip.src 10.0.0.1 and ip.dst 10.0.0.2) or (ip.dst 10.</description>
    </item>
    
    <item>
      <title>Capture data and modify before transfer (local)</title>
      <link>/questions/18233/capture-data-and-modify-before-transfer-local/</link>
      <pubDate>Fri, 01 Feb 2013 10:29:00 +0000</pubDate>
      
      <guid>/questions/18233/capture-data-and-modify-before-transfer-local/</guid>
      <description>Capture data and modify before transfer (local)  0 Capture data and modify before transfer (local), I have a PC running a software that transfer data to one PLC, that application had some bugs that I would like to filter and avoid transfer wrong data to the PLC, here is an example: ^XA ^[email protected],80,20,B:CYRI_UB.FNT^FO90,80^FDManufacturing Plant^FS ^FO200,400^BY3^BCN,100,Y,N,N^FDDANIEL^FS ^FO350,190^BXN,10,200^FDDANIEL^FS ^FO50,35^GB800,540,4^FS ^XZ
I wanto to filter and transfer as follow
^XA ^FO200,400^BY3^BCN,100,Y,N,N^FDARTURO^FS ^FO350,190^BXN,10,200^FDJUAN^FS ^FO50,35^GB800,540,4^FS ^XZ</description>
    </item>
    
    <item>
      <title>Wireshark Packet Forwarding</title>
      <link>/questions/18239/wireshark-packet-forwarding/</link>
      <pubDate>Fri, 01 Feb 2013 13:22:00 +0000</pubDate>
      
      <guid>/questions/18239/wireshark-packet-forwarding/</guid>
      <description>Wireshark Packet Forwarding  0 1Will Wireshark enable packet forwarding to tcp socket instead of file ? (e.g. Resend captured packets to ip:port using &#34;some&#34; protocol) ?
forwarding feature-request packet wiresharkasked 01 Feb &#39;13, 13:22
ahmediukas
21●5●6●10
accept rate: 0%
  
2 Answers:
  
2 No. Wireshark always writes captured packets to file. In some cases you can also direct the incoming packets to a pipe IIRC, but that will not resend them anywhere else.</description>
    </item>
    
    <item>
      <title>Real-time forward of data to another application</title>
      <link>/questions/18250/real-time-forward-of-data-to-another-application/</link>
      <pubDate>Fri, 01 Feb 2013 17:50:00 +0000</pubDate>
      
      <guid>/questions/18250/real-time-forward-of-data-to-another-application/</guid>
      <description>Real-time forward of data to another application  0 Hi I am looking for a network sniffer tool that can pick specific packets generated by one application and forward them to another application in real-time (pass through or forward.The application that generates the data is a point of sales (POS)system serving 30 cash registers. The application that need the data is a queue management system that predicts how many checkout lanes need to be open in real-time.</description>
    </item>
    
    <item>
      <title>What&amp;#x27;s the Lua equivalent of col_set_fence()?</title>
      <link>/questions/18255/whats-the-lua-equivalent-of-col_set_fence/</link>
      <pubDate>Sat, 02 Feb 2013 17:54:00 +0000</pubDate>
      
      <guid>/questions/18255/whats-the-lua-equivalent-of-col_set_fence/</guid>
      <description>What&amp;rsquo;s the Lua equivalent of col_set_fence()?  0 What&#39;s the equivalent Lua function for col_set_fence(), which is available in C?
luaasked 02 Feb &#39;13, 17:54
net_sounds
1●1●1●1
accept rate: 0%
 edited 03 Feb &#39;13, 10:07 
helloworld
3.1k●4●20●41
  
One Answer:
  
0There is currently no such function in Lua. The Lua API for the Column class is described the user manual. You can request this enhancement at http://bugs.</description>
    </item>
    
    <item>
      <title>Capture all packets in promiscuous mode ?</title>
      <link>/questions/18259/capture-all-packets-in-promiscuous-mode/</link>
      <pubDate>Sun, 03 Feb 2013 11:18:00 +0000</pubDate>
      
      <guid>/questions/18259/capture-all-packets-in-promiscuous-mode/</guid>
      <description>Capture all packets in promiscuous mode ?  0 What is the Golden Gate Bridge ? It&#39;s a bridge.
What does the check box &#34;Capture all packets in promiscuous mode&#34; do ? &#34;This checkbox allows you to specify that Wireshark should put all interfaces in promiscuous mode when capturing&#34;.
So, what is promiscuous mode ?
bridge promiscuous-mode goldenasked 03 Feb &#39;13, 11:18
wstest
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Malware sending the local MAC address to remote computer</title>
      <link>/questions/18260/malware-sending-the-local-mac-address-to-remote-computer/</link>
      <pubDate>Sun, 03 Feb 2013 12:26:00 +0000</pubDate>
      
      <guid>/questions/18260/malware-sending-the-local-mac-address-to-remote-computer/</guid>
      <description>Malware sending the local MAC address to remote computer  0 hello I examined a Trojan downloader and I found that it sends the Local MAC address to a remote computer. can you please help me to understand the process using wireshark. BTW I use IDA Pro.
mac trojan idapro downloader.asked 03 Feb &#39;13, 12:26
Mimou Fares
11●1●1●3
accept rate: 0% 
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Capture and Store voice traffic into a Database</title>
      <link>/questions/18261/capture-and-store-voice-traffic-into-a-database/</link>
      <pubDate>Sun, 03 Feb 2013 12:37:00 +0000</pubDate>
      
      <guid>/questions/18261/capture-and-store-voice-traffic-into-a-database/</guid>
      <description>Capture and Store voice traffic into a Database  0 I am looking for a expert Wireshark Developer to help me in customizing Wireshark.
I want to create an add-on application to Wireshark to collect the data packets related to each individual telephone call, convert the packets into individual audio files (one audio file per telephone call) and then store (and retrieve) the audio files from a Database. This should run on a Linux platform.</description>
    </item>
    
    <item>
      <title>Dynamic Header field names</title>
      <link>/questions/18269/dynamic-header-field-names/</link>
      <pubDate>Sun, 03 Feb 2013 17:54:00 +0000</pubDate>
      
      <guid>/questions/18269/dynamic-header-field-names/</guid>
      <description>Dynamic Header field names  0 Is there any way to change the header names in a dissector depending on the data that&#39;s dissected? or to have the header names extracted from a pre-initialized array?
example: array[]={&#34;NewHeading1&#34;,&#34;NewHeading2&#34;};
OLD DISPLAY:
-Frame 17300........
-Ethernet II,.......
-MYPROTOCOL
-Heading1
-SubHeading1 -SubHeading2-Heading2
-SubHeading1
-SubHeading2NEW DISPLAY:
-Frame 17300&amp;hellip;&amp;hellip;..
-Ethernet II,&amp;hellip;&amp;hellip;.
-MYPROTOCOL
-NewHeading1
-SubHeading1
-SubHeading2-NewHeading2
-SubHeading1
-SubHeading2header dynamicasked 03 Feb &amp;lsquo;13, 17:54
StealthUE
66●7●7●13
accept rate: 100%</description>
    </item>
    
    <item>
      <title>Throughput</title>
      <link>/questions/18272/throughput/</link>
      <pubDate>Sun, 03 Feb 2013 23:01:00 +0000</pubDate>
      
      <guid>/questions/18272/throughput/</guid>
      <description>Throughput  0 Hello,
I have captured the Wire-shark file on a microwave Link interface , Which is feeding a 3G Site, Having Low throughput Issue. Its using UDP Frames for sending the User Data towards Core on the MW link, though the Traffic generated from Subscriber is TCP. But frames are having Length of Below Hundred Bytes.near 87 Bytes..Can i Conclude that throughput can be a Issue as Frames are getting fragmented for delivery.</description>
    </item>
    
    <item>
      <title>Is there any tshark command to capture packets on a remote(windows) PC</title>
      <link>/questions/18274/is-there-any-tshark-command-to-capture-packets-on-a-remotewindows-pc/</link>
      <pubDate>Mon, 04 Feb 2013 01:50:00 +0000</pubDate>
      
      <guid>/questions/18274/is-there-any-tshark-command-to-capture-packets-on-a-remotewindows-pc/</guid>
      <description>Is there any tshark command to capture packets on a remote(windows) PC  0 Hi, i am trying to capture packets on a remote (windows)machine from my linux machine. please suggest me a tshark command to capture packets on a remote windows interface.
tsharkasked 04 Feb &#39;13, 01:50
anil1982
11●1●1●2
accept rate: 0%
  
One Answer:
  
1Please read the wiki about remote capturing. Quick hint: You need to start rpcapd (WinPcap install directory) on Windows</description>
    </item>
    
    <item>
      <title>tshark: That string looks like a valid display filter; however, it isn&amp;#x27;t a valid</title>
      <link>/questions/18278/tshark-that-string-looks-like-a-valid-display-filter-however-it-isnt-a-valid/</link>
      <pubDate>Mon, 04 Feb 2013 06:41:00 +0000</pubDate>
      
      <guid>/questions/18278/tshark-that-string-looks-like-a-valid-display-filter-however-it-isnt-a-valid/</guid>
      <description>tshark: That string looks like a valid display filter; however, it isn&amp;rsquo;t a valid  0 here is the command I tried to use:
tshark -i eth1 -f diameterAnd the output:
tshark: Invalid capture filter: &amp;quot;diameter&amp;quot;! That string looks like a valid display filter; however, it isn&amp;#39;t a valid capture filter (syntax error). Note that display filters and capture filters don&amp;#39;t have the same syntax, o you can&amp;#39;t use most display filter expressions as capture filters.</description>
    </item>
    
    <item>
      <title>how to filter tcap.tid with matches ?</title>
      <link>/questions/18279/how-to-filter-tcaptid-with-matches/</link>
      <pubDate>Mon, 04 Feb 2013 06:48:00 +0000</pubDate>
      
      <guid>/questions/18279/how-to-filter-tcaptid-with-matches/</guid>
      <description>how to filter tcap.tid with matches ?  0 tcap.tid == 05:95:27:01 I want to filter the tcap.tid begin with 05:::** ,I use tcap.tid contains 05 to filter,ther many GSM_MAP message.I use tcap.tid matches &#34;^05&#34; ,filter nothing
matches pcre filter perlasked 04 Feb &#39;13, 06:48
anshaohui
16●1●1●4
accept rate: 0%
 edited 04 Feb &#39;13, 19:33 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
1 Try tcap.</description>
    </item>
    
    <item>
      <title>Dropped TCP ACK or dropped TCP SYN, ACK</title>
      <link>/questions/18283/dropped-tcp-ack-or-dropped-tcp-syn-ack/</link>
      <pubDate>Mon, 04 Feb 2013 07:18:00 +0000</pubDate>
      
      <guid>/questions/18283/dropped-tcp-ack-or-dropped-tcp-syn-ack/</guid>
      <description>Dropped TCP ACK or dropped TCP SYN, ACK  0 I have a web server with 10 IP Addresses and about 10,000 clients. Every couple of months I will get one client that can&#39;t connect to one IP Address. All other clients can connect and the one client having trouble with the one IP Address can connect to call the other IP Addresses on the server. The problem last for a couple of months and clears on it&#39;s own.</description>
    </item>
    
    <item>
      <title>Start and end of slow-start phase</title>
      <link>/questions/18287/start-and-end-of-slow-start-phase/</link>
      <pubDate>Mon, 04 Feb 2013 09:56:00 +0000</pubDate>
      
      <guid>/questions/18287/start-and-end-of-slow-start-phase/</guid>
      <description>Start and end of slow-start phase  0 I have a good understanding of slow-start phase, namely how it only lets a few packets send at first, however this amount increments until the max is found in order to avoid congestion.
For the graph below however, how do I identify when the slow-start phase ends? I&#39;m assuming it starts right in the begining at 0 seconds, which is when the connection would be established.</description>
    </item>
    
    <item>
      <title>how do I capture activity on the router</title>
      <link>/questions/18294/how-do-i-capture-activity-on-the-router/</link>
      <pubDate>Mon, 04 Feb 2013 12:41:00 +0000</pubDate>
      
      <guid>/questions/18294/how-do-i-capture-activity-on-the-router/</guid>
      <description>how do I capture activity on the router  0 My wireless router does not show up in my list. How do I make it show up as a device that I want to monitor?
routerasked 04 Feb &#39;13, 12:41
appups785
11●1●1●2
accept rate: 0%
What is this list you mention? The interface list shown in Wireshark?
(04 Feb &#39;13, 12:46) grahamb ♦   </description>
    </item>
    
    <item>
      <title>Wireshark app associated with Safari on OS X</title>
      <link>/questions/18297/wireshark-app-associated-with-safari-on-os-x/</link>
      <pubDate>Mon, 04 Feb 2013 14:37:00 +0000</pubDate>
      
      <guid>/questions/18297/wireshark-app-associated-with-safari-on-os-x/</guid>
      <description>Wireshark app associated with Safari on OS X  0 I have a problem of the pop-up window saying that Wireshark is open, its window can be.... In fact it was my mistake when I firstly run Wireshark, I clicked &#34;Safari&#34; when it asked to select application. I didn&#39;t look carefully the question &#34;Where is X11?&#39; Since then, as soon as I open Wireshark, Safari opens and the pop-up window appears.</description>
    </item>
    
    <item>
      <title>Like as langrabber</title>
      <link>/questions/18299/like-as-langrabber/</link>
      <pubDate>Mon, 04 Feb 2013 18:53:00 +0000</pubDate>
      
      <guid>/questions/18299/like-as-langrabber/</guid>
      <description>Like as langrabber  0 Hello!!
I like the software lan grabber. The software captures all packages and analyzes all content. The software knows all data files and saves based on filters.
You can save all you want, jpeg, flv, wmv, html, css and a lot of other supported files.
But the software is older and have a lot of bugs running in Windows 8. With Wireshark, is it possible to do the same?</description>
    </item>
    
    <item>
      <title>Capture or Filter only sent (TX) traffic</title>
      <link>/questions/18300/capture-or-filter-only-sent-tx-traffic/</link>
      <pubDate>Mon, 04 Feb 2013 18:55:00 +0000</pubDate>
      
      <guid>/questions/18300/capture-or-filter-only-sent-tx-traffic/</guid>
      <description>Capture or Filter only sent (TX) traffic  0 Is it possible to use capture filters to capture only traffic sent from a device running Wireshark and ignore any packets received?
Also when viewing a capture file from another device - it is possible to use display filters for the same purpose?
traffic tx filtersasked 04 Feb &#39;13, 18:55
rocket72
11●1●1●2
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>some fp message can&amp;#x27;t been decode.</title>
      <link>/questions/18311/some-fp-message-cant-been-decode/</link>
      <pubDate>Tue, 05 Feb 2013 01:57:00 +0000</pubDate>
      
      <guid>/questions/18311/some-fp-message-cant-been-decode/</guid>
      <description>some fp message can&amp;rsquo;t been decode.  0 On wireshark1.8.5. the frame:2724 can&#39;t been decode to fp level.
my step: 1,filter use sctp. 2,decode the sctp:data frame as nbap.
many fp over udp have been decoded. but some are can&#39;t.
could you tell me how to attach a *.pcap in here?
Thanks!
rlc nbapasked 05 Feb &#39;13, 01:57
smilezuzu
20●32●32●37
accept rate: 0%
Post it to a file hosting site, preferably one that doesn&#39;t have a download delay or other annoying feature.</description>
    </item>
    
    <item>
      <title>Sniff IP of a mac-adress, help with filter</title>
      <link>/questions/18321/sniff-ip-of-a-mac-adress-help-with-filter/</link>
      <pubDate>Tue, 05 Feb 2013 07:54:00 +0000</pubDate>
      
      <guid>/questions/18321/sniff-ip-of-a-mac-adress-help-with-filter/</guid>
      <description>Sniff IP of a mac-adress, help with filter  0 Hi,
I have a NAS connected to a switch. From that same switch I have a wireless router connected. I want to know the IP of my NAS by sniffing it. I have the MAC address of the NAS but I need the IP to be able to connect to it.
I am on a laptop now connected wirelessly to the router.</description>
    </item>
    
    <item>
      <title>Accessing header fields</title>
      <link>/questions/18339/accessing-header-fields/</link>
      <pubDate>Tue, 05 Feb 2013 16:38:00 +0000</pubDate>
      
      <guid>/questions/18339/accessing-header-fields/</guid>
      <description>Accessing header fields  0 Is there a way to change the header field names in the &#34;hf_ register_info&#34; while dissecting??
header hf_register_infoasked 05 Feb &#39;13, 16:38
StealthUE
66●7●7●13
accept rate: 100%
  
One Answer:
  
2No, nor should there be; a field should stand for one and only one particular thing.
If you want to add new fields while dissecting (which has the disadvantage that a filter used before the new fields have been added, such as a read filter, won&#39;t necessarily work), you could call proto_register_field_array() in a dissector.</description>
    </item>
    
    <item>
      <title>Increasing the size of an array (realloc)</title>
      <link>/questions/18348/increasing-the-size-of-an-array-realloc/</link>
      <pubDate>Tue, 05 Feb 2013 19:55:00 +0000</pubDate>
      
      <guid>/questions/18348/increasing-the-size-of-an-array-realloc/</guid>
      <description>Increasing the size of an array (realloc)  0 Can you use realloc to resize an array? or do i have to do it the manual way??. At the moment realloc crashes wireshark but i may be using incorrectly
array resizeasked 05 Feb &#39;13, 19:55
StealthUE
66●7●7●13
accept rate: 100%
  
One Answer:
  
1What do you mean by &#34;array&#34;? A C array defined as, say int foo[20] cannot be resized at all.</description>
    </item>
    
    <item>
      <title>Tshark IO stat analysis with v1.8.5</title>
      <link>/questions/18355/tshark-io-stat-analysis-with-v185/</link>
      <pubDate>Wed, 06 Feb 2013 02:18:00 +0000</pubDate>
      
      <guid>/questions/18355/tshark-io-stat-analysis-with-v185/</guid>
      <description>Tshark IO stat analysis with v1.8.5  0 I&#39;m using a command such as the following to:
tshark.exe -q -z &#34;io,stat,60,ip.src==myhost.co.uk&#34; -r Monday.pcap &amp;gt; MonOutboundStats.txt
With the aim of determining how much traffic is going out from &#34;myhost.co.uk&#34;. However, when I look at the resulting stats file it doesn&#39;t add up. The first few rows make sense but then I get the same figure repeated in column 2 (118799631). If I understand correctly, the first column is unfiltered and should show me the total IO (both in and outbound).</description>
    </item>
    
    <item>
      <title>Passwords and personal info</title>
      <link>/questions/18360/passwords-and-personal-info/</link>
      <pubDate>Wed, 06 Feb 2013 06:47:00 +0000</pubDate>
      
      <guid>/questions/18360/passwords-and-personal-info/</guid>
      <description>Passwords and personal info  0 I work at a University and one of the professors wants IT to install Wireshark in one of the teaching labs for a class. We are concerned that the students will take this opportunity to sniff out password packets and other personal information.
When packets are captured, can the contents actually be viewed, or are they encrypted?
passwordsasked 06 Feb &#39;13, 06:47
rfcomm2k
1●1●1●2</description>
    </item>
    
    <item>
      <title>list open files with ip or machine name</title>
      <link>/questions/18366/list-open-files-with-ip-or-machine-name/</link>
      <pubDate>Wed, 06 Feb 2013 08:23:00 +0000</pubDate>
      
      <guid>/questions/18366/list-open-files-with-ip-or-machine-name/</guid>
      <description>list open files with ip or machine name  0 I would like to know if there is a way to list the open files in the network - if so can I also list the machine name with it
files machine open name userasked 06 Feb &#39;13, 08:23
gmail
11●1●1●2
accept rate: 0%
 edited 06 Feb &#39;13, 09:10 
grahamb ♦
19.8k●3●30●206
Do you mean &#34;list, on a client machine, what files it has open on various file servers&#34;</description>
    </item>
    
    <item>
      <title>Monitoring network for small business</title>
      <link>/questions/18371/monitoring-network-for-small-business/</link>
      <pubDate>Wed, 06 Feb 2013 10:43:00 +0000</pubDate>
      
      <guid>/questions/18371/monitoring-network-for-small-business/</guid>
      <description>Monitoring network for small business  0 We are looking for monitoring the network in our small business(43 users) including 3 servers and know where the bandwidth is being used. In addition, we need to know the curve of the internet usage per usage over the time and check if there is any virus that is using the bandwidth and on which PC which is shuting down the network. We need to have a trial of the software showing the curves.</description>
    </item>
    
    <item>
      <title>Errors when installing Wireshark 1.8.5 on Ubuntu 10.10</title>
      <link>/questions/18372/errors-when-installing-wireshark-185-on-ubuntu-1010/</link>
      <pubDate>Wed, 06 Feb 2013 11:42:00 +0000</pubDate>
      
      <guid>/questions/18372/errors-when-installing-wireshark-185-on-ubuntu-1010/</guid>
      <description>Errors when installing Wireshark 1.8.5 on Ubuntu 10.10  0 in ubuntu10.10 i have tried to install wireshark 1.8.5 by following ways:
from synaptic managersudo apt-get install wiresharkand download wireshark1.8.5.tar in that ./configure make make installbut it does not get installed. Each time it shows errors. plz help me.
ubuntuasked 06 Feb &#39;13, 11:42
yumwel
1●1●1●1
accept rate: 0%
 edited 07 Feb &#39;13, 16:53 
Kurt Knochner ♦
24.8k●10●39●237</description>
    </item>
    
    <item>
      <title>What are the first 40 bytes in this capture file?</title>
      <link>/questions/18380/what-are-the-first-40-bytes-in-this-capture-file/</link>
      <pubDate>Wed, 06 Feb 2013 16:34:00 +0000</pubDate>
      
      <guid>/questions/18380/what-are-the-first-40-bytes-in-this-capture-file/</guid>
      <description>What are the first 40 bytes in this capture file?  0 Hello,
Somebody sent me a sample GOOSE packet they captured. The beginning of the file:
d4 c3 b2 a1 02 00 04 00 00 00 00 00 00 00 00 00 ff ff 00 00 01 00 00 00 13 ac fd 50 88 f3 0b 00 34 00 00 00 34 00 00 00 01 80 c2 00 00 00 00 26 99 1d a0 91 00 26 42 42 03 00 00 00 00 00 60 64 00 26 99 1d a0 80 00 00 00 00 60 64 00 26 99 1d a0 80 80 47 00 00 14 00 02 00 0f 00 13 ac fd 50 30 4a 0d 00 a1 00 00 00 a1 00 00 00 01 a0 f4 04 9c 5f 00 a0 f4 04 9c 5f 88 b8</description>
    </item>
    
    <item>
      <title>apply tshark patch to filter dynamic http header fields</title>
      <link>/questions/18382/apply-tshark-patch-to-filter-dynamic-http-header-fields/</link>
      <pubDate>Wed, 06 Feb 2013 17:17:00 +0000</pubDate>
      
      <guid>/questions/18382/apply-tshark-patch-to-filter-dynamic-http-header-fields/</guid>
      <description>apply tshark patch to filter dynamic http header fields  0 I was wondering if someone could help me getting this patch to work. I am interested in the ability to parse out the x-wap-profile field that this user was able to accomplish. I am unsure how I need to compile or what the process is so that I can use tshark in the manner described in the wireshark Bug referenced below.</description>
    </item>
    
    <item>
      <title>802.11 wpa-pwd decryption not working 1.8.2</title>
      <link>/questions/18384/80211-wpa-pwd-decryption-not-working-182/</link>
      <pubDate>Wed, 06 Feb 2013 20:30:00 +0000</pubDate>
      
      <guid>/questions/18384/80211-wpa-pwd-decryption-not-working-182/</guid>
      <description>802.11 wpa-pwd decryption not working 1.8.2  0 I have been searching around for someone else who has had the same issue for a little while and have given up. I was attempting to decrypt the traffic on my network which is using WPA (Personal) with Wireshark&#39;s built-in decryption key&#39;s tool and have been unsuccessful so far.
I then tried decrypting the wpa-Induction.pcap (http://wiki.wireshark.org/HowToDecrypt802.11) capture file and had no luck. Before I revert to a previous version of Wireshark where decryption was working (according to other posts here), does anyone have any suggestions to resolve this issue?</description>
    </item>
    
    <item>
      <title>Help with Filters for Detecting Fast Flux in DNS Queries</title>
      <link>/questions/18394/help-with-filters-for-detecting-fast-flux-in-dns-queries/</link>
      <pubDate>Thu, 07 Feb 2013 04:34:00 +0000</pubDate>
      
      <guid>/questions/18394/help-with-filters-for-detecting-fast-flux-in-dns-queries/</guid>
      <description>Help with Filters for Detecting Fast Flux in DNS Queries  0 Hi,
I am trying to filter pcap files to allow me to analyse them to determine if there are any fast flux networks using my domain name servers.
The filters i am using with tshark right now are: -e ip.src (This will show the source of the request, the client) -e dns.qry.name (This will show the domain being quieried) -e dns.</description>
    </item>
    
    <item>
      <title>Telnet from cmd line to ip address 25</title>
      <link>/questions/18398/telnet-from-cmd-line-to-ip-address-25/</link>
      <pubDate>Thu, 07 Feb 2013 06:09:00 +0000</pubDate>
      
      <guid>/questions/18398/telnet-from-cmd-line-to-ip-address-25/</guid>
      <description>Telnet from cmd line to ip address 25  0 New to wireshark :} When I do a telnet fqdn 25 - I see the traffic on port 587 and not 25. I thought that I should be able to see the traffic destinated for port 25 being &#34;redirected&#34; to 587. But I do not. The first packet from my machine is to port 587 ? I am not understanding this.</description>
    </item>
    
    <item>
      <title>Wireshark and a 8-bit display on Windows server 2007?</title>
      <link>/questions/18403/wireshark-and-a-8-bit-display-on-windows-server-2007/</link>
      <pubDate>Thu, 07 Feb 2013 07:03:00 +0000</pubDate>
      
      <guid>/questions/18403/wireshark-and-a-8-bit-display-on-windows-server-2007/</guid>
      <description>Wireshark and a 8-bit display on Windows server 2007?  0 I have installed Wireshark on a windows server 2007 SP2 but the Wireshark UI doesnt display correctly. The display settings are 8-bit with no option to change. Is wireshark not compatible with 8-bit display settings and/or is there a fix for this problem?
Thanks in advance
-Karl
color colour 8-bit display monitorasked 07 Feb &#39;13, 07:03
Karhoo
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Risk assessment issues</title>
      <link>/questions/18406/risk-assessment-issues/</link>
      <pubDate>Thu, 07 Feb 2013 07:48:00 +0000</pubDate>
      
      <guid>/questions/18406/risk-assessment-issues/</guid>
      <description>Risk assessment issues  0 Issue 1: Security Configuration Wireshark starts a Windows service (titled “NPF Service”) which enabled network traffic sniffing on the Windows OS it is running on. This service continues to run after the Wireshark software has been shut down. It will continue to run (and can be used to sniff network traffic) until the machine is shut down or rebooted.
How would I be able to shutdown the NPF service upon exiting Wireshark?</description>
    </item>
    
    <item>
      <title>Webwatcher</title>
      <link>/questions/18416/webwatcher/</link>
      <pubDate>Thu, 07 Feb 2013 13:52:00 +0000</pubDate>
      
      <guid>/questions/18416/webwatcher/</guid>
      <description>Webwatcher  0 Hello! I&#39;m new to wireshark, but I am very thankful for the program.
I knew someone was monitoring my PC, but after dozens of anti-viruses came up empty, I turned to wireshark. I quickly recognized an odd IP address sending/receiving data from my computer. Turns out the IP belonged to webwatcher, a hidden remote monitoring service.
Is there anyway to decode the information contained beyond the IP address.</description>
    </item>
    
    <item>
      <title>Which is newer - 1.8.0rc2 or 1.8.5?</title>
      <link>/questions/18417/which-is-newer-180rc2-or-185/</link>
      <pubDate>Thu, 07 Feb 2013 14:42:00 +0000</pubDate>
      
      <guid>/questions/18417/which-is-newer-180rc2-or-185/</guid>
      <description>Which is newer - 1.8.0rc2 or 1.8.5?  0 Current development version (1.8.0rc2) appears to have older version name than current stable release (1.8.5). What am I missing?
versionsThis question is marked &#34;community wiki&#34;.asked 07 Feb &#39;13, 14:42
sholmes
1●1●1●1
accept rate: 0%
  
2 Answers:
  
2I haven&#39;t made any 1.9.x releases yet, so the latest official development version is still the most recent prerelease for 1.</description>
    </item>
    
    <item>
      <title>No decryption of ISAKMP packets?</title>
      <link>/questions/18418/no-decryption-of-isakmp-packets/</link>
      <pubDate>Thu, 07 Feb 2013 14:55:00 +0000</pubDate>
      
      <guid>/questions/18418/no-decryption-of-isakmp-packets/</guid>
      <description>No decryption of ISAKMP packets?  0 I&#39;d like to see decryption of encrypted ISAKMP traffic. I entered the cookie and the key into the IKEv1 Decryption Table, but in the ISAKMP packets, the &#34;Encrypted Data&#34; doesn&#39;t have the clicky-box to expand and see it decrypted. I&#39;m using Wireshark 1.8.4 with GCrypt on Windows 7. Is there something else I need to do?
isakmp gcrypt decryption ike ikev1asked 07 Feb &#39;13, 14:55</description>
    </item>
    
    <item>
      <title>expert info</title>
      <link>/questions/18428/expert-info/</link>
      <pubDate>Thu, 07 Feb 2013 16:32:00 +0000</pubDate>
      
      <guid>/questions/18428/expert-info/</guid>
      <description>expert info  0 Is there a way to use wireshark/tshark with options to generate the &#34;analyze-&amp;gt;expert info&#34; output for an input/existing PCAP file?
thanks
info expertasked 07 Feb &#39;13, 16:32
donlex
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Unfortunately that functionality is not implemented. The best you can do is this:
tshark -nr input.pcap -z expert -q
and/or
tshark -nr input.pcap -R &#34;expert&#34; -T fields -e frame.</description>
    </item>
    
    <item>
      <title>How do I set up Wireshark for Linux?</title>
      <link>/questions/18435/how-do-i-set-up-wireshark-for-linux/</link>
      <pubDate>Thu, 07 Feb 2013 21:35:00 +0000</pubDate>
      
      <guid>/questions/18435/how-do-i-set-up-wireshark-for-linux/</guid>
      <description>How do I set up Wireshark for Linux?  0 how to set up wireshark for linux?
linux wiresharkasked 07 Feb &#39;13, 21:35
neha
1●3●3●3
accept rate: 0%
 edited 07 Feb &#39;13, 21:59 
Guy Harris ♦♦
17.4k●3●35●196
  
2 Answers:
  
1The major Linux distributions have Wireshark in their collections of packages; the way you&#39;d find and install the Wireshark package depends on which distribution you&#39;re using.</description>
    </item>
    
    <item>
      <title>tshark - Issues with IP Defragmentation - SIP</title>
      <link>/questions/18443/tshark-issues-with-ip-defragmentation-sip/</link>
      <pubDate>Fri, 08 Feb 2013 02:12:00 +0000</pubDate>
      
      <guid>/questions/18443/tshark-issues-with-ip-defragmentation-sip/</guid>
      <description>tshark - Issues with IP Defragmentation - SIP  1 I have a problem reading pcap files that have fragmented packets with tshark. My expectaion is tshark will re-assemble the fragmented IP packets before it passes them to the higher layer dissectors. But this doesnt appear to happen. If I open the same file with the Wireshark GUI application it does this fine.
Should I be able to do this with tshark on the command line?</description>
    </item>
    
    <item>
      <title>I need to get broadcast message from IP Camera</title>
      <link>/questions/18451/i-need-to-get-broadcast-message-from-ip-camera/</link>
      <pubDate>Fri, 08 Feb 2013 14:49:00 +0000</pubDate>
      
      <guid>/questions/18451/i-need-to-get-broadcast-message-from-ip-camera/</guid>
      <description>I need to get broadcast message from IP Camera  0 This is a partial report from Wireshark, I need to do this in my program. How would I get same info with winsock?
No. Time Source Destination Protocol Length Info 67 20.309244000 192.168.1.27 192.168.1.20 MDNS 214 Standard query response 0x0000 PTR ipcamera(id:E8ABFA182279, alias:Und Deck - Wireless)._http._tcp.local Frame 67: 214 bytes on wire (1712 bits), 214 bytes captured (1712 bits) on interface 0 Interface id: 0 WTAP_ENCAP: 1 Arrival Time: Feb 8, 2013 13:59:18.</description>
    </item>
    
    <item>
      <title>Unknown bytes in GOOSE packet</title>
      <link>/questions/18452/unknown-bytes-in-goose-packet/</link>
      <pubDate>Fri, 08 Feb 2013 15:40:00 +0000</pubDate>
      
      <guid>/questions/18452/unknown-bytes-in-goose-packet/</guid>
      <description>Unknown bytes in GOOSE packet  0 I can read ALMOST every byte now in the pcap file mentioned in this question, thanks to Guy_Harris.c. All but 5 bytes. 5 bytes.
Frame 2 of this file is a GOOSE package, according to Wireshark. The length is 161 bytes:
01 a0 f4 04 9c 5f 00 a0 f4 04 9c 5f 88 b8 00 00 00 93 00 00 00 00 61 81 88</description>
    </item>
    
    <item>
      <title>tcp/ftp performance</title>
      <link>/questions/18454/tcpftp-performance/</link>
      <pubDate>Fri, 08 Feb 2013 16:37:00 +0000</pubDate>
      
      <guid>/questions/18454/tcpftp-performance/</guid>
      <description>tcp/ftp performance  0 Trying to follow a ftp stream and figure out why transferring the same file to different machines have different finish times. the FTP-DATA bytes show 32768, but if you add the acknowledgement numbers, the byte count does not add up. I could be totaly off base so I am asking the experts I am assuming the value of example: packet 151 - 156, I would subtract the last ack value packet 154 from ack value of packet 151.</description>
    </item>
    
    <item>
      <title>UDP Port 5353 filter</title>
      <link>/questions/18459/udp-port-5353-filter/</link>
      <pubDate>Fri, 08 Feb 2013 17:46:00 +0000</pubDate>
      
      <guid>/questions/18459/udp-port-5353-filter/</guid>
      <description>UDP Port 5353 filter  0 How do I set filter to see only traffic on UDP 5353?
capture-filterasked 08 Feb &#39;13, 17:46
BHill
11●2●2●4
accept rate: 0%
 edited 08 Feb &#39;13, 23:10 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
2Capture filter: &#34;udp port 5353&#34;
Display filter: &#34;udp.port==5353&#34;
answered 08 Feb &#39;13, 19:54
Jim Aragon
7.2k●7●33●118
accept rate: 24%
     </description>
    </item>
    
    <item>
      <title>simulate low-bandwidth or high-latency</title>
      <link>/questions/18467/simulate-low-bandwidth-or-high-latency/</link>
      <pubDate>Sat, 09 Feb 2013 04:16:00 +0000</pubDate>
      
      <guid>/questions/18467/simulate-low-bandwidth-or-high-latency/</guid>
      <description>simulate low-bandwidth or high-latency  0 How can I generate network traffic and measure the performance of the network? What tools/addons are recommended for Wireshark? Also, how to simulate low-bandwidth or high-latency?
latency measurements tools performanceasked 09 Feb &#39;13, 04:16
JDB
6●1●1●2
accept rate: 0%
 edited 11 Feb &#39;13, 07:25 
cmaynard ♦♦
9.4k●10●38●142
  
4 Answers:
  
1Wireshark is a network protocol analyser and cannot generate traffic nor simulate network issues.</description>
    </item>
    
    <item>
      <title>DNS leak: Looking up own hostname with DNS queries</title>
      <link>/questions/18469/dns-leak-looking-up-own-hostname-with-dns-queries/</link>
      <pubDate>Sat, 09 Feb 2013 10:13:00 +0000</pubDate>
      
      <guid>/questions/18469/dns-leak-looking-up-own-hostname-with-dns-queries/</guid>
      <description>DNS leak: Looking up own hostname with DNS queries  0 1I was checking a proxied program for DNS leaks with tshark when I noticed this:
13.170066 10.0.2.15 -&amp;gt; 192.168.1.1 DNS 66 Standard query 0xd473 A [hostname] 13.753496 10.0.2.15 -&amp;gt; 192.168.1.1 DNS 66 Standard query 0x7bb4 A [hostname]where [hostname] is the hostname of the machine the program and tshark are running on, 10.0.2.15 is the local machine, and 192.168.1.1 is the router.</description>
    </item>
    
    <item>
      <title>Unable to capture DICOM packets with USB-Ethernet adapter</title>
      <link>/questions/18472/unable-to-capture-dicom-packets-with-usb-ethernet-adapter/</link>
      <pubDate>Sat, 09 Feb 2013 18:31:00 +0000</pubDate>
      
      <guid>/questions/18472/unable-to-capture-dicom-packets-with-usb-ethernet-adapter/</guid>
      <description>Unable to capture DICOM packets with USB-Ethernet adapter  0 Hello - I&#39;ve been using my laptop with built in ethernet card to capture DICOM packets for a long time now. I recently purchased a new laptop that doesn&#39;t have a built in Ethernet card but has a USB-Ethernet adapter. I&#39;m now unable to capture DICOM packets with the new USB-Ethernet adapter. I have searched everywhere on the internet and can&#39;t seem to find any answers.</description>
    </item>
    
    <item>
      <title>Vastly different transfer speeds on custom .net transfer</title>
      <link>/questions/18474/vastly-different-transfer-speeds-on-custom-net-transfer/</link>
      <pubDate>Sun, 10 Feb 2013 05:05:00 +0000</pubDate>
      
      <guid>/questions/18474/vastly-different-transfer-speeds-on-custom-net-transfer/</guid>
      <description>Vastly different transfer speeds on custom .net transfer  0 Hello All, Thanks for reading. I was wondering if you could take a look at these logs and tell me what&#39;s happening.
I&#39;ll admit straight away I know almost nothing of networking other than the basics like setting up routers and port forwarding. Nothing low level.
The problem is that I get very different transfer speeds throughout the day. The logs show a transfer of about 200KB and it can range from ~2 seconds to 20+ seconds.</description>
    </item>
    
    <item>
      <title>After capturing starts I cannot browse the internet</title>
      <link>/questions/18475/after-capturing-starts-i-cannot-browse-the-internet/</link>
      <pubDate>Sun, 10 Feb 2013 07:19:00 +0000</pubDate>
      
      <guid>/questions/18475/after-capturing-starts-i-cannot-browse-the-internet/</guid>
      <description>After capturing starts I cannot browse the internet  0 Hello to everybody, I&#39;m running wireshark on Ubuntu 12.04.2 and it looks really great. The only problem is that once I&#39;ve started it and it&#39;s capturing network traffic I&#39;m no longer able to surf in the internet. The problem remains even after that I close the program. So I can close and start wireshark as many times as I want, it always works, but after the first time I start it I cannot surf the web anymore.</description>
    </item>
    
    <item>
      <title>Info column auto-wrapping</title>
      <link>/questions/18480/info-column-auto-wrapping/</link>
      <pubDate>Sun, 10 Feb 2013 15:23:00 +0000</pubDate>
      
      <guid>/questions/18480/info-column-auto-wrapping/</guid>
      <description>Info column auto-wrapping  1 When I set the info column with either col_set_str(); or col_append_fstr(); it doesn&#39;t auto wrap the sentence onto the next line when the info column is full. Is there a function I can use to fix this or will I have to determine the length of the string and insert new line feeds where necessary??
info columnasked 10 Feb &#39;13, 15:23
StealthUE
66●7●7●13
accept rate: 100%</description>
    </item>
    
    <item>
      <title>read a pdp context</title>
      <link>/questions/18483/read-a-pdp-context/</link>
      <pubDate>Mon, 11 Feb 2013 01:43:00 +0000</pubDate>
      
      <guid>/questions/18483/read-a-pdp-context/</guid>
      <description>read a pdp context  0 Hello,
I have a question regarding a wireshark trace&#39;s. I want to see the PDP CONTEXT in the trace but i don&#39;t know how to do ? below how i make my test :
The mobile is under FEMTOCELL coverage(the wireshark is configured with this femto. The Femt is an amplifier home network).
i launch the trace i activate the data on the mobile i launch a navigation</description>
    </item>
    
    <item>
      <title>Viewing RSSI value in Wireshark</title>
      <link>/questions/18484/viewing-rssi-value-in-wireshark/</link>
      <pubDate>Mon, 11 Feb 2013 06:11:00 +0000</pubDate>
      
      <guid>/questions/18484/viewing-rssi-value-in-wireshark/</guid>
      <description>Viewing RSSI value in Wireshark  0 In Wireshark Version 1.8.2, I tried Edit -&amp;gt; Preferences... -&amp;gt; Columns -&amp;gt; Press &#34;Add&#34; button -&amp;gt; As &#34;Field type&#34; I choose &#34;IEEE 802.11 RSSI&#34; and finally I choose name &#34;RSSI&#34; and click on &#34;Apply&#34; button. The column appeared but there are no values in the column.
After reading (http://ask.wireshark.org/questions/14963/how-to-get-the-field-did-unknown-4041-into-the-column), I compiled Wireshark Version 1.8.5 from source but still no values are appearing.
The data was previously collected using pcap and I&#39;m now opening it in Wireshark, how can I view the RSSI values ?</description>
    </item>
    
    <item>
      <title>Filter DNS queries without matched responses</title>
      <link>/questions/18487/filter-dns-queries-without-matched-responses/</link>
      <pubDate>Mon, 11 Feb 2013 08:41:00 +0000</pubDate>
      
      <guid>/questions/18487/filter-dns-queries-without-matched-responses/</guid>
      <description>Filter DNS queries without matched responses  0 1I receive seldom messages during stress test about timed out DNS requests from c-ares used in download manager as part of libcurl. I have huge pcap and need to identify such failed DNS queries. Is it possible with Wireshark&#39;s expression language?
dnsasked 11 Feb &#39;13, 08:41
Andrey Staro...
6●1●2●2
accept rate: 0%
  
2 Answers:
  
3 Perhaps the following as a Wireshark display filter will work:</description>
    </item>
    
    <item>
      <title>Adding multiple items to a tree</title>
      <link>/questions/18490/adding-multiple-items-to-a-tree/</link>
      <pubDate>Mon, 11 Feb 2013 09:59:00 +0000</pubDate>
      
      <guid>/questions/18490/adding-multiple-items-to-a-tree/</guid>
      <description>Adding multiple items to a tree  0 We have a temporary packet that we we&#39;re trying to do some quick dissecting on.
basically we read a field and its value determines what the next 10 or so fields are. Is there a way to overlay text for those next 10 fields, something like this:
some string { &#34;first&#34;, &#34;second&#34;, ....
}
proto_tree_add_item(some_tree, next_ten_fields, tvb, offset, 10, TRUE);
and have the following appear in the tree:</description>
    </item>
    
    <item>
      <title>Comparing Packets</title>
      <link>/questions/18514/comparing-packets/</link>
      <pubDate>Mon, 11 Feb 2013 15:11:00 +0000</pubDate>
      
      <guid>/questions/18514/comparing-packets/</guid>
      <description>Comparing Packets  1 1I am looking for a way to do a &#34;stare and compare&#34; packet analysis. I have a situation with a SIP carrier who is sending an INVITE for a number that works and others that do not. They seem identical in format and such but I noticed that they were slightly different sizes (1109 for the one that worked and 1112 for the ones that don&#39;t work).</description>
    </item>
    
    <item>
      <title>Calling Lua Dissectors from Lua Dissector</title>
      <link>/questions/18517/calling-lua-dissectors-from-lua-dissector/</link>
      <pubDate>Mon, 11 Feb 2013 16:15:00 +0000</pubDate>
      
      <guid>/questions/18517/calling-lua-dissectors-from-lua-dissector/</guid>
      <description>Calling Lua Dissectors from Lua Dissector  0 1I&#39;m dealing with two custom protocols that use the same GRE protocol type. Each protocol currently has a separate Lua dissector (I&#39;d like to keep it this way). I&#39;m writing a script in Lua to perform some heuristics to determine which of the custom protocols is being used, with the idea that I&#39;ll pass the packet off to the appropriate Lua dissector. I&#39;ve got all of the heuristics written, but I can&#39;t quite figure how to call a dissector written in Lua from another dissector written in Lua.</description>
    </item>
    
    <item>
      <title>the windows of Wireshark doesn&amp;#x27;t  emerge</title>
      <link>/questions/18526/the-windows-of-wireshark-doesnt-emerge/</link>
      <pubDate>Mon, 11 Feb 2013 21:54:00 +0000</pubDate>
      
      <guid>/questions/18526/the-windows-of-wireshark-doesnt-emerge/</guid>
      <description>the windows of Wireshark doesn&amp;rsquo;t emerge  0 i am having a similar problem which is when i started the Wireshark another windows emerged asking me to choose the program to run the Wirshark
macasked 11 Feb &#39;13, 21:54
bandar
11●1●1●2
accept rate: 0%
I think the OP&#39;s system is OS X of some form as they had originally posted the question as an &#34;answer&#34; to http://ask.wireshark.org/questions/9617/wireshark-wont-start-on-osx-lion
(12 Feb &#39;13, 00:35) grahamb ♦   </description>
    </item>
    
    <item>
      <title>Number of fields to output</title>
      <link>/questions/18527/number-of-fields-to-output/</link>
      <pubDate>Mon, 11 Feb 2013 22:32:00 +0000</pubDate>
      
      <guid>/questions/18527/number-of-fields-to-output/</guid>
      <description>Number of fields to output  0 Hi,
I&#39;m using TSHARK with the -T fields option and it worked great until I had a few more fields to output.
If I delete a few of the fields ( NO matter which ones) it works.
Is there a number of maximum (12) fields that wireshark can output at once?
If so how can I change that?
fields tshark maximumasked 11 Feb &#39;13, 22:32</description>
    </item>
    
    <item>
      <title>compilation on linux</title>
      <link>/questions/18532/compilation-on-linux/</link>
      <pubDate>Tue, 12 Feb 2013 02:10:00 +0000</pubDate>
      
      <guid>/questions/18532/compilation-on-linux/</guid>
      <description>compilation on linux  0 can anyone tell me that how to compile wireshark on linux??
compilation wiresharkasked 12 Feb &#39;13, 02:10
neha
1●3●3●3
accept rate: 0%
  
One Answer:
  
3Please see here: http://www.wireshark.org/docs/wsug_html_chunked/ChBuildInstallUnixBuild.html
Regards
Kurt
answered 12 Feb &#39;13, 02:32
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15% 
thanx kurt. but this is not helping me out. i am using fedora version
(12 Feb &#39;13, 03:25) nehait&#39;s exactly the same on fedora !</description>
    </item>
    
    <item>
      <title>Finding services in Wireshark?</title>
      <link>/questions/18551/finding-services-in-wireshark/</link>
      <pubDate>Tue, 12 Feb 2013 07:00:00 +0000</pubDate>
      
      <guid>/questions/18551/finding-services-in-wireshark/</guid>
      <description>Finding services in Wireshark?  0 Hi all,
I&#39;m a Wireshark beginner and I have a question about it:
How does one go about finding services in Wireshark, specifically, the question is asking &#39;What services are running in the network capture?&#39;
Would this relate to the application layer and services that run within it? Any help would be greatly appreciated
Lambert
question beginner wiresharkasked 12 Feb &#39;13, 07:00
Lambert84
1●1●1●1</description>
    </item>
    
    <item>
      <title>Viewing RSSI value using wireshark windows version</title>
      <link>/questions/18568/viewing-rssi-value-using-wireshark-windows-version/</link>
      <pubDate>Tue, 12 Feb 2013 15:57:00 +0000</pubDate>
      
      <guid>/questions/18568/viewing-rssi-value-using-wireshark-windows-version/</guid>
      <description>Viewing RSSI value using wireshark windows version  0 I try to view RSSI value in wireshark windows version (v1.8.5). So what is the first thing that I should do? Thx
qweasked 12 Feb &#39;13, 15:57
awi216
10●3●3●6
accept rate: 0%
  
One Answer:
  
1 The first thing that you should do is either
download and install Microsoft Network Monitor, use it to capture traffic, and either read its captures in Network Monitor or save them and read them in Wireshark;buy an AirPcap adapter and use it to capture traffic in WiresharkWinPcap doesn&#39;t support capturing in monitor mode, or capturing with any radio information such as signal strength, with regular 802.</description>
    </item>
    
    <item>
      <title>how to convert tcp to sctp</title>
      <link>/questions/18570/how-to-convert-tcp-to-sctp/</link>
      <pubDate>Tue, 12 Feb 2013 21:16:00 +0000</pubDate>
      
      <guid>/questions/18570/how-to-convert-tcp-to-sctp/</guid>
      <description>how to convert tcp to sctp  0 hello,
how to convert tcp packets passing to become SCTP ​​packet?
sctpasked 12 Feb &#39;13, 21:16
cocet
1●1●1●1
accept rate: 0%
  
One Answer:
  
0I don&#39;t get the question, they are two different protocols. What&#39;s the connection to Wireshark?
answered 12 Feb &#39;13, 21:27
Anders ♦
4.6k●9●52
accept rate: 17%
     </description>
    </item>
    
    <item>
      <title>Homeplug AV mgmt frame format</title>
      <link>/questions/18573/homeplug-av-mgmt-frame-format/</link>
      <pubDate>Tue, 12 Feb 2013 22:55:00 +0000</pubDate>
      
      <guid>/questions/18573/homeplug-av-mgmt-frame-format/</guid>
      <description>Homeplug AV mgmt frame format  0 Hi, does wireshark supports decoding of homeplug 1.1 spec mgmt frames ? i understand that , wireshark supports intellon proprietory format and shows actual homeplug mgmt frame encapsulated in intellon frames. can you please share me any mgmt frame capture showing association frames i have wireshark 1.7.2.
thanks for your time -rajan
homeplugmgmtasked 12 Feb &#39;13, 22:55
rajan5
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How do I find my BPF file/folder on my OS X mountain lion?</title>
      <link>/questions/18580/how-do-i-find-my-bpf-filefolder-on-my-os-x-mountain-lion/</link>
      <pubDate>Wed, 13 Feb 2013 04:55:00 +0000</pubDate>
      
      <guid>/questions/18580/how-do-i-find-my-bpf-filefolder-on-my-os-x-mountain-lion/</guid>
      <description>How do I find my BPF file/folder on my OS X mountain lion?  0 The disk image only has the package installer and a read me file. I keep on reading that I need to gain privilege on my BPF or ChmodBPF files, but I cannot find them anywhere.
Currently trying to analyze my network, but all I see is my own traffic. I&#39;m trying to monitor the entire traffic off of my home network.</description>
    </item>
    
    <item>
      <title>Why is wireshark slow with wireshark not responding errors</title>
      <link>/questions/18591/why-is-wireshark-slow-with-wireshark-not-responding-errors/</link>
      <pubDate>Wed, 13 Feb 2013 08:33:00 +0000</pubDate>
      
      <guid>/questions/18591/why-is-wireshark-slow-with-wireshark-not-responding-errors/</guid>
      <description>Why is wireshark slow with wireshark not responding errors  0 Hi, I&#39;ve installed wireshark on 2 windows 7 computers. Both do the same thing when I run it. They will capture packets and then the screen freezes with a &#34;wireshark not responding error&#34;. If I wait long enough it will respond again, but if I click on a packet, or scroll the screen down, it will happen again.
not respondingasked 13 Feb &#39;13, 08:33</description>
    </item>
    
    <item>
      <title>GOOSE: Why display floating-point in hex?</title>
      <link>/questions/18597/goose-why-display-floating-point-in-hex/</link>
      <pubDate>Wed, 13 Feb 2013 09:05:00 +0000</pubDate>
      
      <guid>/questions/18597/goose-why-display-floating-point-in-hex/</guid>
      <description>GOOSE: Why display floating-point in hex?  0 Feature request:
When displaying the data of a GOOSE packet, could you please display the value of the floating number to the right of the hex value? I have to admit I am a little slow to convert in my head so I can see that 0840600000 is f3.5 :=)
Thanks
floating display pointasked 13 Feb &#39;13, 09:05
ecs1749
21●7●8●11
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Screen lock up under Windows 7 while capturing packets</title>
      <link>/questions/18598/screen-lock-up-under-windows-7-while-capturing-packets/</link>
      <pubDate>Wed, 13 Feb 2013 09:10:00 +0000</pubDate>
      
      <guid>/questions/18598/screen-lock-up-under-windows-7-while-capturing-packets/</guid>
      <description>Screen lock up under Windows 7 while capturing packets  0 I am running Wireshark ver 1.8.0rc2 (SVN Rev 43337 from /trunk-1.8) under Windows 7 SP 1. While capturing GOOSE packets, if I try to move the window, the screen locks up. I have to pop up the task manager to either kill it (sometimes it frees up and becomes responsive again).
lock screen up capturing whileasked 13 Feb &#39;13, 09:10</description>
    </item>
    
    <item>
      <title>RSSI in wireless mesh (batman.adv - openmesh product) - human intruder detection system</title>
      <link>/questions/18600/rssi-in-wireless-mesh-batmanadv-openmesh-product-human-intruder-detection-system/</link>
      <pubDate>Wed, 13 Feb 2013 09:41:00 +0000</pubDate>
      
      <guid>/questions/18600/rssi-in-wireless-mesh-batmanadv-openmesh-product-human-intruder-detection-system/</guid>
      <description>RSSI in wireless mesh (batman.adv - openmesh product) - human intruder detection system  0 Hi all..
Now I&#39;m working on my degree final year project on building intruder system base on WIFI signal, and more precisely using the RSSI. As we all know human body contain water, and water can interrupt radio signal. Previously my friend have successfully prove that, yes there are significant change of the RSSI when human existence in the testing environment.</description>
    </item>
    
    <item>
      <title>SQL Database Store</title>
      <link>/questions/18601/sql-database-store/</link>
      <pubDate>Wed, 13 Feb 2013 10:49:00 +0000</pubDate>
      
      <guid>/questions/18601/sql-database-store/</guid>
      <description>SQL Database Store  0 A similar question was asked in 10/2011 so I&#39;ll test the waters again to see if anything has changed since then.
Has an extension or plugin been developed that supports taking filtered packets and storing them directly into a database (yes, the schema would need to be compatible with the export)? I have tested the C5 Sigma code and while it works well, the latency incurred in creating a PCAPNG file, closing the file while opening another PCAPNG file, then launching the C5 Sigma to store the data plus the complexity of writing O/S script code to orchestrate this process on a continuing basis doesn&#39;t fit well with the intended application.</description>
    </item>
    
    <item>
      <title>Trying to find lost packets (segments)</title>
      <link>/questions/18602/trying-to-find-lost-packets-segments/</link>
      <pubDate>Wed, 13 Feb 2013 10:58:00 +0000</pubDate>
      
      <guid>/questions/18602/trying-to-find-lost-packets-segments/</guid>
      <description>Trying to find lost packets (segments)  0 Is there a way that when you run wireshark to ONLY capture lost segments. Or how do I set it to ONLY capture TCP when running the capture?
segment lostasked 13 Feb &#39;13, 10:58
Dejavu
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Is there a way that when you run wireshark to ONLY capture lost segments.
well, as the segment is lost there is no way to capture it with wireshark ;-)) Why do you want to do that?</description>
    </item>
    
    <item>
      <title>val_to_str function return</title>
      <link>/questions/18612/val_to_str-function-return/</link>
      <pubDate>Wed, 13 Feb 2013 14:19:00 +0000</pubDate>
      
      <guid>/questions/18612/val_to_str-function-return/</guid>
      <description>val_to_str function return  0 val_to_str(int1,data,&#34;%s&#34;);
when using this function it works fine but if int1 isn&#39;t found in the value_string structure then it crashes wireshark. The value_string structure looks like this:
static const value_string data[] = { { 0x01, &#34;Test1&#34; }, { 0x03, &#34;Test2&#34; }, { 0, NULL } };
so if the value 0x02 was used then wireshark would crash. I thought it would return NULL if the value wasnt found.</description>
    </item>
    
    <item>
      <title>Cannot retrieve field for radius.Framed_IP_Address using Tshark.</title>
      <link>/questions/18621/cannot-retrieve-field-for-radiusframed_ip_address-using-tshark/</link>
      <pubDate>Wed, 13 Feb 2013 19:01:00 +0000</pubDate>
      
      <guid>/questions/18621/cannot-retrieve-field-for-radiusframed_ip_address-using-tshark/</guid>
      <description>Cannot retrieve field for radius.Framed_IP_Address using Tshark.  0 Hi,
I am having an issue with retrieving the value for the field radius.Framed_IP_Address but all other fields seem to be returned fine.
Here is the command I&#39;m running and sample output.
$tshark -i eth1 -T fields -e radius.Event_Timestamp -e radius.User_Name -e radius.Acct_Status_Type -e radius.Acct_Session_Id -e radius.Calling_Station_Id -e radius.Framed_IP_Address -E separator=&amp;quot;|&amp;quot;I have confirmed that there is a value for the AVP for Framed-IP-Address by viewing the output.</description>
    </item>
    
    <item>
      <title>Same source and destination MAC address</title>
      <link>/questions/18632/same-source-and-destination-mac-address/</link>
      <pubDate>Thu, 14 Feb 2013 04:01:00 +0000</pubDate>
      
      <guid>/questions/18632/same-source-and-destination-mac-address/</guid>
      <description>Same source and destination MAC address  0 What will the Ethernet switch do, if my NIC transmits an Ethernet frame with same source and destination MAC address?
ethernet mac switch addressasked 14 Feb &#39;13, 04:01
ssp
11●1●1●2
accept rate: 0%
  
One Answer:
  
1Normally a switch will never forward a packet out a port on which it was received, whether it was destined for the same mac address or not.</description>
    </item>
    
    <item>
      <title>PPP compressed data not displayed uncompressed</title>
      <link>/questions/18633/ppp-compressed-data-not-displayed-uncompressed/</link>
      <pubDate>Thu, 14 Feb 2013 08:09:00 +0000</pubDate>
      
      <guid>/questions/18633/ppp-compressed-data-not-displayed-uncompressed/</guid>
      <description>PPP compressed data not displayed uncompressed  0 I am connected via pptp vpn over an ethernet connection to a server. I need to analyze packets to and from the server for a certain application. The application packets on the vpn link are captured as &#34;PPP - Compressed datagram&#34;. The payload packets are not uncompressed in the packet listing so I can not see the actual payload. Is there a setting or plugin that will uncompress the payloads so I can see the actual data?</description>
    </item>
    
    <item>
      <title>Can we change license to GPL v3 to allow linking to libgnutls?</title>
      <link>/questions/18635/can-we-change-license-to-gpl-v3-to-allow-linking-to-libgnutls/</link>
      <pubDate>Thu, 14 Feb 2013 09:00:00 +0000</pubDate>
      
      <guid>/questions/18635/can-we-change-license-to-gpl-v3-to-allow-linking-to-libgnutls/</guid>
      <description>Can we change license to GPL v3 to allow linking to libgnutls?  0 As the title requests, is there any reason to not change to GPLv3? As Gerald has commented on in the past (found on this site thanks to Google), and as discussed in various other places ( https://bugzilla.novell.com/show_bug.cgi?id=775737 ) the license for dependencies used for decrypting SSL traffic has moved to GPLv3 and as a result it is no longer permissible to link to those libraries from something using GPLv2, or something (I am not a lawyer).</description>
    </item>
    
    <item>
      <title>Need to capture limited network traffic</title>
      <link>/questions/18639/need-to-capture-limited-network-traffic/</link>
      <pubDate>Thu, 14 Feb 2013 13:02:00 +0000</pubDate>
      
      <guid>/questions/18639/need-to-capture-limited-network-traffic/</guid>
      <description>Need to capture limited network traffic  0 I am trying to monitor traffic on a specific subnet. How can I only monitor/save packets from that subnet and only record packets headed to a specific destination IP or IPs.
Thanks
Michael Smith
subnetasked 14 Feb &#39;13, 13:02
enochgenesis
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Have a look at the capture filter page on the wiki.</description>
    </item>
    
    <item>
      <title>How to write dissector for http request body with special header?</title>
      <link>/questions/18642/how-to-write-dissector-for-http-request-body-with-special-header/</link>
      <pubDate>Thu, 14 Feb 2013 14:24:00 +0000</pubDate>
      
      <guid>/questions/18642/how-to-write-dissector-for-http-request-body-with-special-header/</guid>
      <description>How to write dissector for http request body with special header?  1 Hi,
I want to write a dissector for http request body when a certain header present in the request (for example protocol: my protocol). Can somebody give me direction of how to do that?
Thanks
dissectorasked 14 Feb &#39;13, 14:24
seannguyen
16●3●3●5
accept rate: 0%
 edited 15 Feb &#39;13, 08:47 
grahamb ♦
19.8k●3●30●206</description>
    </item>
    
    <item>
      <title>Visual C&#43;&#43; error on WinXP</title>
      <link>/questions/18645/visual-c-error-on-winxp/</link>
      <pubDate>Thu, 14 Feb 2013 22:18:00 +0000</pubDate>
      
      <guid>/questions/18645/visual-c-error-on-winxp/</guid>
      <description>Visual C++ error on WinXP  0 Dear Sir,
My environemnt is Windows XP with SP3 and using WireShark version 1.8.5 &amp;amp; 1.6.13. All of versions will occur same question &#34;Visual C++ error&#34;.
I don&#39;t know this is a limitation of Wireshark of shareware or any request I need to prepare?
Regards, Kuoyang
questionasked 14 Feb &#39;13, 22:18
Kuoyang
11●1●1●3
accept rate: 0%
You have to explain the problem better, when do you get the error?</description>
    </item>
    
    <item>
      <title>wpa-psk decryption is not working with tshark (wireshark 1.8.1)</title>
      <link>/questions/18647/wpa-psk-decryption-is-not-working-with-tshark-wireshark-181/</link>
      <pubDate>Thu, 14 Feb 2013 23:32:00 +0000</pubDate>
      
      <guid>/questions/18647/wpa-psk-decryption-is-not-working-with-tshark-wireshark-181/</guid>
      <description>wpa-psk decryption is not working with tshark (wireshark 1.8.1)  0 I am trying to decrypt captured wpa-psk traffic with tshark, but it&#39;s not recognizing the option I&#39;m trying to override. This option allows me to specify a PSK to use for decrypting. I&#39;m using tshark 1.8.1 with windows xp. # tshark -o wlan.wep_key1:wpa-pwd:validation tshark: -o flag &#34;wlan.wep_key1:wpa-pwd:validation&#34; specifies unknown preference. PSK decyption was working in earlier version of wireshark</description>
    </item>
    
    <item>
      <title>gsm_sms protocol source code</title>
      <link>/questions/18648/gsm_sms-protocol-source-code/</link>
      <pubDate>Thu, 14 Feb 2013 23:48:00 +0000</pubDate>
      
      <guid>/questions/18648/gsm_sms-protocol-source-code/</guid>
      <description>gsm_sms protocol source code  0 Hi, I would like to know how gsm_sms protocol is identified in a packet. I mean the low level interpretation of filter &#34;gsm_sms&#34;. I am trying to use this filter in jpcap and it does not support, hence i need to write the filter in java.
Thanks for the reply.
gsm_sms jpcapasked 14 Feb &#39;13, 23:48
srk
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How to decode a packet received through wireshark &amp;amp; resolving some errors</title>
      <link>/questions/18649/how-to-decode-a-packet-received-through-wireshark-resolving-some-errors/</link>
      <pubDate>Fri, 15 Feb 2013 00:52:00 +0000</pubDate>
      
      <guid>/questions/18649/how-to-decode-a-packet-received-through-wireshark-resolving-some-errors/</guid>
      <description>How to decode a packet received through wireshark &amp;amp; resolving some errors  0 1We are capturing traffic using JN5148EK010 nodes via Wireshark. The packets received are shown in the screenshot provided.
I want to know how to decode the data?An error occurs after capturing a few packets, whose screenshot is also provided. How to resolve this error?Another error (refer to third screenshot) occurred. How to resolve that?Kindly help.
Please check the screenshots on the following link: http://stackoverflow.</description>
    </item>
    
    <item>
      <title>How can I capture RTP packets from youtube?</title>
      <link>/questions/18651/how-can-i-capture-rtp-packets-from-youtube/</link>
      <pubDate>Fri, 15 Feb 2013 03:15:00 +0000</pubDate>
      
      <guid>/questions/18651/how-can-i-capture-rtp-packets-from-youtube/</guid>
      <description>How can I capture RTP packets from youtube?  0 I am not able to catch RTP packets from youtube. I have tried checking &#34;Try to decode RTP outside of conversions&#34;, but it didnt help. I tried decoding UDP packet as RTP. After decoding, I am not able to do RTP stream analysis.
decode_rtpasked 15 Feb &#39;13, 03:15
Autotest
11●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Capture Filters under Windows 2008 Server</title>
      <link>/questions/18654/capture-filters-under-windows-2008-server/</link>
      <pubDate>Fri, 15 Feb 2013 06:56:00 +0000</pubDate>
      
      <guid>/questions/18654/capture-filters-under-windows-2008-server/</guid>
      <description>Capture Filters under Windows 2008 Server  0 I recently updated to Wireshark 1.8.5 and now I can not get a capture filter to work.
I go to Capture -&amp;gt; Capture Filters and select a saved filter (host xxx.xxx.xxx.xxx) and click OK. When I try to start the capture, it captures all packets on the interface.
I have tried double clicking on the Capture Filter name in the dialog box. I have also tried to apply while a current capture is in process and when the capture is stopped - all to no avail.</description>
    </item>
    
    <item>
      <title>Network slowness</title>
      <link>/questions/18670/network-slowness/</link>
      <pubDate>Sat, 16 Feb 2013 17:11:00 +0000</pubDate>
      
      <guid>/questions/18670/network-slowness/</guid>
      <description>Network slowness  0 Hello,
I have a client that is experiencing network slowness issues to my server (199.19.128.229) from my pcap. can you please help me identifying any problems. Thank you for your cooperation.
[email protected]
pcapasked 16 Feb &#39;13, 17:11
dukeminus
11●1●1●2
accept rate: 0%
2Hi James, that is not exactly how this site works. You may find a lot of help here in analyzing your data when you ask specific questions on where you are stuck in your analysis.</description>
    </item>
    
    <item>
      <title>Constructing new tvbuff from other data</title>
      <link>/questions/18671/constructing-new-tvbuff-from-other-data/</link>
      <pubDate>Sat, 16 Feb 2013 17:31:00 +0000</pubDate>
      
      <guid>/questions/18671/constructing-new-tvbuff-from-other-data/</guid>
      <description>Constructing new tvbuff from other data  0 Can anyone suggest any examples of dissectors that combine two tvbs together? because I need to remove some unwanted data before processing. Also, if I remove the unwanted data from the tvb and pass that off to say the eth dissector for further processing would the &#34;Packet Bytes&#34; window be updated with the new tvb or will it display the previous one?</description>
    </item>
    
    <item>
      <title>RS485 sniffing</title>
      <link>/questions/18680/rs485-sniffing/</link>
      <pubDate>Sun, 17 Feb 2013 07:30:00 +0000</pubDate>
      
      <guid>/questions/18680/rs485-sniffing/</guid>
      <description>RS485 sniffing  0 I have two pieces of equipment that communicate with each of other via two RS485 signals (one for each direction). Think of a small box with displays, buttons and rotary encoders controlling a microprocessor on the other end. I eventually want to be able to replace the box with a PC or other controller box but first I need to read and log all of the data transmitted so I can emulate it.</description>
    </item>
    
    <item>
      <title>Do I need airpcap on my Mac to monitor my router?</title>
      <link>/questions/18683/do-i-need-airpcap-on-my-mac-to-monitor-my-router/</link>
      <pubDate>Sun, 17 Feb 2013 08:19:00 +0000</pubDate>
      
      <guid>/questions/18683/do-i-need-airpcap-on-my-mac-to-monitor-my-router/</guid>
      <description>Do I need airpcap on my Mac to monitor my router?  0 I am trying to monitor my own network, using a Mac running OS X 10.8, as I have multiple devices that connects to my router. Do I need an airpcap to monitor my own Apple Extreme?
airpcapasked 17 Feb &#39;13, 08:19
Trungy
1●1●1●1
accept rate: 0%
 edited 17 Feb &#39;13, 16:53 
Guy Harris ♦♦
17.4k●3●35●196</description>
    </item>
    
    <item>
      <title>is the rlc reassembly take too much time?</title>
      <link>/questions/18694/is-the-rlc-reassembly-take-too-much-time/</link>
      <pubDate>Sun, 17 Feb 2013 19:52:00 +0000</pubDate>
      
      <guid>/questions/18694/is-the-rlc-reassembly-take-too-much-time/</guid>
      <description>is the rlc reassembly take too much time?  0 When I open a .pcap on wireshark1.8.5. Is take very long time. about 15 minute, size of the .pcap is 90 MB.
why it took so long time?
In the *.pcap, there are many rlc rrc message.is the rlc reassembly step take too much time ?
Thanks!
reassembly rrc rlc timeasked 17 Feb &#39;13, 19:52
smilezuzu
20●32●32●37
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Problem with smi_modules : I would like to set &amp;quot;all&amp;quot;</title>
      <link>/questions/18702/problem-with-smi_modules-i-would-like-to-set-all/</link>
      <pubDate>Mon, 18 Feb 2013 04:59:00 +0000</pubDate>
      
      <guid>/questions/18702/problem-with-smi_modules-i-would-like-to-set-all/</guid>
      <description>Problem with smi_modules : I would like to set &amp;ldquo;all&amp;rdquo;  0 Hi, I don&#39;t know if it is possible, but I am working under Windows Environment with Wireshark For name resolution, I&#39;m using smi_modules functionality, by entering the name of the MIBs I need to decode snmp logs, one by one. I would like to know if it is possible to set something like &#34;all&#34; in smi_modules file or anywhere else in order to avoid listing every MIB files I need.</description>
    </item>
    
    <item>
      <title>Non byte aligned dissecting: how to have the same output as proto_tree_add_item() ?</title>
      <link>/questions/18703/non-byte-aligned-dissecting-how-to-have-the-same-output-as-proto_tree_add_item/</link>
      <pubDate>Mon, 18 Feb 2013 05:29:00 +0000</pubDate>
      
      <guid>/questions/18703/non-byte-aligned-dissecting-how-to-have-the-same-output-as-proto_tree_add_item/</guid>
      <description>Non byte aligned dissecting: how to have the same output as proto_tree_add_item() ?  0 Hi all,
I&#39;m dissecting non byte aligned fields. I use proto_tree_add_bits_item() it works pretty well but I would like to have the same output as proto_tree_add_item().
I don&#39;t want to have the output like: ..10 1010 10.. .... &#34;value&#34; But : value: 10 1010 10 (Like byte aligned standard output).
My problem is that this output is very difficult to read because my fields are not aligned at all (once 6 bits, once 2 bits, once 18 bits .</description>
    </item>
    
    <item>
      <title>reconstructing HTTP object</title>
      <link>/questions/18704/reconstructing-http-object/</link>
      <pubDate>Mon, 18 Feb 2013 05:33:00 +0000</pubDate>
      
      <guid>/questions/18704/reconstructing-http-object/</guid>
      <description>reconstructing HTTP object  0 Hello, Is there any method to reconstruct HTTP objects using tshark (not wireshark)? Otherwise, could you tell me any other tools to do this?
Thanks.
http tsharkasked 18 Feb &#39;13, 05:33
fates
35●4●5●9
accept rate: 0%
  
One Answer:
  
1Is there any method to reconstruct HTTP objects using tshark
I guess you are talking about an export of &#39;objects&#39; transmitted via HTTP (files, videos, images, etc.</description>
    </item>
    
    <item>
      <title>Examples of PPP</title>
      <link>/questions/18709/examples-of-ppp/</link>
      <pubDate>Mon, 18 Feb 2013 09:40:00 +0000</pubDate>
      
      <guid>/questions/18709/examples-of-ppp/</guid>
      <description>Examples of PPP  0 Hallo,Can anybody give me examples of PPP traffic , with bsd-compression, with deflate-compression and with some others types of compression?
pppasked 18 Feb &#39;13, 09:40
Kokolbin
1●1●1●1
accept rate: 0%
  
One Answer:
  
0There is a pcap file on packetlife.net with VJ compression (PPP_TCP_compression.cap).
http://packetlife.net/captures/protocol/ppp/
Regards
Kurt
answered 18 Feb &#39;13, 14:50
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15%</description>
    </item>
    
    <item>
      <title>How to export http.data with tshark?</title>
      <link>/questions/18710/how-to-export-httpdata-with-tshark/</link>
      <pubDate>Mon, 18 Feb 2013 10:07:00 +0000</pubDate>
      
      <guid>/questions/18710/how-to-export-httpdata-with-tshark/</guid>
      <description>How to export http.data with tshark?  0 Hi,
I want to read tcpdump capture file and export just http request body as individual byte array. How to do that? I tried this
tshark -r mycapture.cap -R &amp;#39;http.request and (http contains &amp;quot;customheader:&amp;quot;)&amp;#39; -T fields -e data -w data.capBut it save all the requests with headers (I just want the http body only). Also it doesn&#39;t save http body as individual file.</description>
    </item>
    
    <item>
      <title>Troubleshooting Write AndX Response and Request</title>
      <link>/questions/18712/troubleshooting-write-andx-response-and-request/</link>
      <pubDate>Mon, 18 Feb 2013 13:14:00 +0000</pubDate>
      
      <guid>/questions/18712/troubleshooting-write-andx-response-and-request/</guid>
      <description>Troubleshooting Write AndX Response and Request  0 We are having an issue where moving files from one office to another is drastically different. If the file is in office X, and I am transferring it to office Y, the process is much slower going from X to Y, then it is from Y to X. To give you an idea, from X to Y, Windows was showing an average speed of 800KB/sec.</description>
    </item>
    
    <item>
      <title>capture port-mirrored(SPAN) traffic on a VM where interface is bridged with tap interface on host</title>
      <link>/questions/18722/capture-port-mirroredspan-traffic-on-a-vm-where-interface-is-bridged-with-tap-interface-on-host/</link>
      <pubDate>Mon, 18 Feb 2013 15:13:00 +0000</pubDate>
      
      <guid>/questions/18722/capture-port-mirroredspan-traffic-on-a-vm-where-interface-is-bridged-with-tap-interface-on-host/</guid>
      <description>capture port-mirrored(SPAN) traffic on a VM where interface is bridged with tap interface on host  0 First of all, sorry about bit clunky title. Tried to make it as informational as possible.
I have a following topology in GNS3:
&#34;SW&#34; is a Cisco 3640 router with NM-16ESW 16-port 10/100 EtherSwitch Network Module. Port Fa0/0 of &#34;SW&#34; is an access port in VLAN 5. I have mirrored both Rx and Tx traffic of port Fa0/0 to port Fa0/10:</description>
    </item>
    
    <item>
      <title>How did the rlc reassemble the SDU in wireshark?</title>
      <link>/questions/18729/how-did-the-rlc-reassemble-the-sdu-in-wireshark/</link>
      <pubDate>Tue, 19 Feb 2013 02:15:00 +0000</pubDate>
      
      <guid>/questions/18729/how-did-the-rlc-reassemble-the-sdu-in-wireshark/</guid>
      <description>How did the rlc reassemble the SDU in wireshark?  0 1,How did the rlc reassemble the code from mac in wireshark? you should tell me the main step of reassemble in wireshark.
2,Is the wireshark malloc memory for each rlc SDU? because when the wireshark decode a big *.pcap,it will occupy a big memory.
is the wireshark reassemble the rlc code stream from mac like this step? 1,decode each rlc code and malloc new memory for each rlc SDU.</description>
    </item>
    
    <item>
      <title>problem in opening large size wireshark file</title>
      <link>/questions/18730/problem-in-opening-large-size-wireshark-file/</link>
      <pubDate>Tue, 19 Feb 2013 03:50:00 +0000</pubDate>
      
      <guid>/questions/18730/problem-in-opening-large-size-wireshark-file/</guid>
      <description>problem in opening large size wireshark file  0 Hi,
I have a file captured as tcpdump which is the network traffic for about 1 Hour and the file size is about 1G. When I want to open the file using wireshark it takes long time and at the end via error message wireshark will be closed.
Do you have any solution to open the whole file? Can I open it if I have a PC with higher RAM?</description>
    </item>
    
    <item>
      <title>VOIP:  Why do DTMF events not show up on Wireshark capture</title>
      <link>/questions/18733/voip-why-do-dtmf-events-not-show-up-on-wireshark-capture/</link>
      <pubDate>Tue, 19 Feb 2013 07:41:00 +0000</pubDate>
      
      <guid>/questions/18733/voip-why-do-dtmf-events-not-show-up-on-wireshark-capture/</guid>
      <description>VOIP: Why do DTMF events not show up on Wireshark capture  0 Why do DTMF events (pressing key on phone) not show up in Wireshark capture of a Cisco IP phone. I press various keys during the phone menu after a call connects, but they don&#39;t show up. The call and menu choices were successfully completed.
dtmf voipasked 19 Feb &#39;13, 07:41
RAS
16●1●1●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How can I limit each packet to certain byte size (slice how much I capture)?</title>
      <link>/questions/18741/how-can-i-limit-each-packet-to-certain-byte-size-slice-how-much-i-capture/</link>
      <pubDate>Tue, 19 Feb 2013 09:40:00 +0000</pubDate>
      
      <guid>/questions/18741/how-can-i-limit-each-packet-to-certain-byte-size-slice-how-much-i-capture/</guid>
      <description>How can I limit each packet to certain byte size (slice how much I capture)?  0 1I&#39;ve tried selecting the &#34;Limit each packet to&#34; field checkbox so I can slice off the amount of data captured so my capture files will be smaller. I don&#39;t need all the payload, but all the headers really. I&#39;m using wireshark version 1.6.8. I can check the box and start capturing, but the packets are still full size.</description>
    </item>
    
    <item>
      <title>Wireshark for Ubuntu Linux on a stand alone machine</title>
      <link>/questions/18742/wireshark-for-ubuntu-linux-on-a-stand-alone-machine/</link>
      <pubDate>Tue, 19 Feb 2013 09:53:00 +0000</pubDate>
      
      <guid>/questions/18742/wireshark-for-ubuntu-linux-on-a-stand-alone-machine/</guid>
      <description>Wireshark for Ubuntu Linux on a stand alone machine  0 I need to install Wireshark on a stand-alone Ubuntu machine (without Internet access). The answers from here all points to getting packages via wget and so forth. Is there a complete package somewhere that I can download and copy over to this machine (via flash drive)?
Thanks,
alone stand ubuntuasked 19 Feb &#39;13, 09:53
ecs1749
21●7●8●11
accept rate: 0%</description>
    </item>
    
    <item>
      <title>wireshark won&amp;#x27;t start on mountain lion</title>
      <link>/questions/18743/wireshark-wont-start-on-mountain-lion/</link>
      <pubDate>Tue, 19 Feb 2013 10:11:00 +0000</pubDate>
      
      <guid>/questions/18743/wireshark-wont-start-on-mountain-lion/</guid>
      <description>wireshark won&amp;rsquo;t start on mountain lion  0 hi, i have installed wireshark and Xquartz for x11. and when i load wireshark, all i get is a xterm window on the upper left corner. I followed all the instructions that were provided here: http://www.wireshark.org/docs/wsug_html_chunked/ChBuildInstallBeforeBuild.html and the referenced links to gtk. Does anyone know what&#39; i&#39;m missing?
mountain-lionThis question is marked &#34;community wiki&#34;.asked 19 Feb &#39;13, 10:11
bennett
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark in MAC OS?</title>
      <link>/questions/18758/wireshark-in-mac-os/</link>
      <pubDate>Tue, 19 Feb 2013 16:35:00 +0000</pubDate>
      
      <guid>/questions/18758/wireshark-in-mac-os/</guid>
      <description>Wireshark in MAC OS?  0 Hello,
I have a MAC OS X Version 10.7. I cannot function with Wireshark. I cannot even initiate the program. How can solve this any suggestion.
I try to open , the wireshark icon pops at the bottom of the screen and then it dissapears.
Any one can you help.
Thanks Bharat C P
development mac crashasked 19 Feb &#39;13, 16:35
BharatNT2IE
6●5●5●8
accept rate: 0%</description>
    </item>
    
    <item>
      <title>dissectors fail to work on later version of centos after compilation and link okay</title>
      <link>/questions/18759/dissectors-fail-to-work-on-later-version-of-centos-after-compilation-and-link-okay/</link>
      <pubDate>Wed, 20 Feb 2013 01:02:00 +0000</pubDate>
      
      <guid>/questions/18759/dissectors-fail-to-work-on-later-version-of-centos-after-compilation-and-link-okay/</guid>
      <description>dissectors fail to work on later version of centos after compilation and link okay  0 for historical reasons we used version 1.0.8 wireshark ( I think it was the officially delivered one with a specific version of redhat we were using) I created a set of dissectors specific to ATC interfaces. (AFTN,FMTP etc) These were compiled under centos and windows and worked well with both under wireshark 1.0.8.
We have now upgraded(!</description>
    </item>
    
    <item>
      <title>Can Wireshark decode frame type 0x2d (reserved)</title>
      <link>/questions/18762/can-wireshark-decode-frame-type-0x2d-reserved/</link>
      <pubDate>Wed, 20 Feb 2013 02:52:00 +0000</pubDate>
      
      <guid>/questions/18762/can-wireshark-decode-frame-type-0x2d-reserved/</guid>
      <description>Can Wireshark decode frame type 0x2d (reserved)  0 A WLAN packet capture using the AirPcap card and then opened in Wireshark was unable to decode the frame type 0x2d (a &#34;reserved&#34; frame type).
I did notice that the FCS was incorrect and wondered if this was a factor. So I changed the preferences but to no avail:
Edit &amp;gt; Preferences (802.11 Radiotap) “Assume bit 14 means FCS in header” – made no difference.</description>
    </item>
    
    <item>
      <title>tcp flow control</title>
      <link>/questions/18768/tcp-flow-control/</link>
      <pubDate>Wed, 20 Feb 2013 04:38:00 +0000</pubDate>
      
      <guid>/questions/18768/tcp-flow-control/</guid>
      <description>tcp flow control  0 How can I see tcp slow-start flow control in the wireshark.. I transfer a file (100 M) between two computers on filezilla client/server to see how the window size increase but I didn&#39;t see it .. what should I do ??
tcpasked 20 Feb &#39;13, 04:38
Maher Moualla
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Slow-start is not negotiated or explicitly exchanged between hosts.</description>
    </item>
    
    <item>
      <title>Source Port went from 443 to astergatefax</title>
      <link>/questions/18773/source-port-went-from-443-to-astergatefax/</link>
      <pubDate>Wed, 20 Feb 2013 08:34:00 +0000</pubDate>
      
      <guid>/questions/18773/source-port-went-from-443-to-astergatefax/</guid>
      <description>Source Port went from 443 to astergatefax  0 I have been running captures for a couple of weeks to our web service in the cloud. It using https/ssl on port 443. On the previous captures, we would send our inquiry through port 443 to the destination port of 443.
Today I see in the capture that our source port has changed from 443 to 9107 and in wireshark it says &#34;</description>
    </item>
    
    <item>
      <title>What may cause zlib decompression to fail?</title>
      <link>/questions/18778/what-may-cause-zlib-decompression-to-fail/</link>
      <pubDate>Wed, 20 Feb 2013 09:57:00 +0000</pubDate>
      
      <guid>/questions/18778/what-may-cause-zlib-decompression-to-fail/</guid>
      <description>What may cause zlib decompression to fail?  0 I am trying to analyze HTTP traffic where the HTTP body is zlib encoded. The packet details pane shows:
Hypertext Transfer Protocol POST /xxs/ HTTP/1.1\r\n Content-Type: text/xml; charset=&amp;quot;utf-8&amp;quot;\r\n SOAPAction: \r\n Content-Encoding: zlib\r\n Text-Length: 550\r\n Content-Length: 312\r\n Connection: Close\r\n \r\n Content-encoded entity body (zlib): 312 bytes [Error: Decompression failed] Data (312 bytes)So for some reason the decompression of the zlip compressed data is failing.</description>
    </item>
    
    <item>
      <title>How does Wireshark know the protocol underlying the SCCP ?</title>
      <link>/questions/18783/how-does-wireshark-know-the-protocol-underlying-the-sccp/</link>
      <pubDate>Wed, 20 Feb 2013 11:11:00 +0000</pubDate>
      
      <guid>/questions/18783/how-does-wireshark-know-the-protocol-underlying-the-sccp/</guid>
      <description>How does Wireshark know the protocol underlying the SCCP ?  0 I&#39;m asking how does Wireshark know that there is BSSAP underlying the SCCP protocol ?
According to what can I know which is the next protocol (RANAP or BSSAP for example..). I don&#39;t want to rely on the SSN because they are not always present.
Thanks, Radhwen
sccp ss7 wireshark sigtranasked 20 Feb &#39;13, 11:11
Radhwen Khelia
11●2●2●3</description>
    </item>
    
    <item>
      <title>problem with dissecting a large pcap file as FAST</title>
      <link>/questions/18785/problem-with-dissecting-a-large-pcap-file-as-fast/</link>
      <pubDate>Wed, 20 Feb 2013 13:29:00 +0000</pubDate>
      
      <guid>/questions/18785/problem-with-dissecting-a-large-pcap-file-as-fast/</guid>
      <description>problem with dissecting a large pcap file as FAST  0 I have a 200GB pcap file which I need to decode as FAST. As wireshark cannot open that huge file, I have to split the file into smaller files and decode each file and it has to be done using a script because I will end up with around 1000 files. So I need to be able to decode a file through a command line interface.</description>
    </item>
    
    <item>
      <title>Writing PCAP file from mainframe ( z/os )</title>
      <link>/questions/18788/writing-pcap-file-from-mainframe-zos/</link>
      <pubDate>Wed, 20 Feb 2013 15:06:00 +0000</pubDate>
      
      <guid>/questions/18788/writing-pcap-file-from-mainframe-zos/</guid>
      <description>Writing PCAP file from mainframe ( z/os )  0 I am trying to write a packet trace file in PCAP format from a packet trace I&#39;ve captured on z/os. I am trying to mimic what IBM does with IPCS conversion to SNIFFER/PCAP format.
IBM uses the following global header which in no way matches up to the PCAP format: (note: the first part of the file is &#39;TRSNIFF DATA&#39; in ascii.</description>
    </item>
    
    <item>
      <title>detecting bottleneck devices</title>
      <link>/questions/18789/detecting-bottleneck-devices/</link>
      <pubDate>Wed, 20 Feb 2013 16:06:00 +0000</pubDate>
      
      <guid>/questions/18789/detecting-bottleneck-devices/</guid>
      <description>detecting bottleneck devices  0 I have a client who wants to find out which devices on the network are the network traffic hogs. Does this software have feature that shows the network devices and the traffic each device is using in real-time over over a time period.
I don&#39;t need a very complicated software but just features to display network devices and bandwidth usage for device.
device bandwidth network utilizationasked 20 Feb &#39;13, 16:06</description>
    </item>
    
    <item>
      <title>Logging End Point  Data</title>
      <link>/questions/18793/logging-end-point-data/</link>
      <pubDate>Wed, 20 Feb 2013 23:10:00 +0000</pubDate>
      
      <guid>/questions/18793/logging-end-point-data/</guid>
      <description>Logging End Point Data  0 I want to write a batch script that automatically creates a log periodically with the endpoint communication data which is found on Statistics &amp;gt; EndPoints &amp;gt; ipv4
automated endpoints logging periodicasked 20 Feb &#39;13, 23:10
AshwinSethi
0●2●2●5
accept rate: 0%
  
One Answer:
  
2 Have a look at tshark statistics. If that provides what you need then setup a loop with dumpcap with ringbuffer set to duration to write a file and have tshark process it for you.</description>
    </item>
    
    <item>
      <title>Odd Server 2003 File Sharing Problem</title>
      <link>/questions/18803/odd-server-2003-file-sharing-problem/</link>
      <pubDate>Thu, 21 Feb 2013 10:59:00 +0000</pubDate>
      
      <guid>/questions/18803/odd-server-2003-file-sharing-problem/</guid>
      <description>Odd Server 2003 File Sharing Problem  0 Hi,
We are having a very weird issue that has been going on for a number of months on our network. We currently have a 3 Windows Server 2003 servers that have connectivity issues between them.
We have a .Net app that monitors a folder via a network share on another server and the .net app seems to hang periodically for about 33 seconds.</description>
    </item>
    
    <item>
      <title>Does Wireshark connect to Echelon LonWorks network?</title>
      <link>/questions/18804/does-wireshark-connect-to-echelon-lonworks-network/</link>
      <pubDate>Thu, 21 Feb 2013 11:13:00 +0000</pubDate>
      
      <guid>/questions/18804/does-wireshark-connect-to-echelon-lonworks-network/</guid>
      <description>Does Wireshark connect to Echelon LonWorks network?  0 How can I get Wireshark to connect to a Echelon LonWorks network? I have an Echelon TP/FT-10 USB to LonWorks interface. When I run Wireshark it does not see the Echelon TP/FT-10 interface. How do I &#34;add&#34; this interface to Wireshark?
interface 802.15.4 lonworksasked 21 Feb &#39;13, 11:13
jerry
11●1●1●2
accept rate: 0%
 edited 22 Sep &#39;13, 13:44 
Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>dumpcap outfile save location</title>
      <link>/questions/18809/dumpcap-outfile-save-location/</link>
      <pubDate>Fri, 22 Feb 2013 03:24:00 +0000</pubDate>
      
      <guid>/questions/18809/dumpcap-outfile-save-location/</guid>
      <description>dumpcap outfile save location  0 C:\Program Files\Wireshark&amp;gt;dumpcap -i \Device\NPF_{9E7AF7D7-A7CE-4350-882B-7223F2B9A333} -b duration:10 -b files:10 -a duration:200 -w outfile.pcap Capturing on \Device\NPF_{9E7AF7D7-A7CE-4350-882B-7223F2B9A333} File: outfile_00001_20130222164538.pcap Packets: 25 File: outfile_00002_20130222164548.pcap Packets: 44 File: outfile_00003_20130222164558.pcap Packets: 72 File: outfile_00004_20130222164608.pcap Packets: 104 File: outfile_00005_20130222164618.pcap Packets: 118 File: outfile_00006_20130222164628.pcap Packets: 141 File: outfile_00007_20130222164638.pcap Packets: 204 File: outfile_00008_20130222164648.pcap Packets: 251 File: outfile_00009_20130222164658.pcap Packets: 278 File: outfile_00010_20130222164708.pcap Packets: 381 File: outfile_00011_20130222164718.pcap Packets: 513 File: outfile_00012_20130222164728.pcap Packets: 607 File: outfile_00013_20130222164738.</description>
    </item>
    
    <item>
      <title>Unable to see ROHC decoded message in pdcp-lte message</title>
      <link>/questions/18813/unable-to-see-rohc-decoded-message-in-pdcp-lte-message/</link>
      <pubDate>Fri, 22 Feb 2013 06:33:00 +0000</pubDate>
      
      <guid>/questions/18813/unable-to-see-rohc-decoded-message-in-pdcp-lte-message/</guid>
      <description>Unable to see ROHC decoded message in pdcp-lte message  0 I am not able to see any ROHC fields on applying filter pdcp-lte. I tried the filter pdcp-lte.rohc but no messages showed up on applying this filter. Is there any separate dissector for ROHC decoding, apart from the standard pdcp-lte package? I am using wireshark verion 1.4.0 on linux.
pdcp-lte rohcasked 22 Feb &#39;13, 06:33
dr1
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Why does the &amp;quot;decode as&amp;quot; dialog only shows entrys for link layer.</title>
      <link>/questions/18814/why-does-the-decode-as-dialog-only-shows-entrys-for-link-layer/</link>
      <pubDate>Fri, 22 Feb 2013 06:35:00 +0000</pubDate>
      
      <guid>/questions/18814/why-does-the-decode-as-dialog-only-shows-entrys-for-link-layer/</guid>
      <description>Why does the &amp;ldquo;decode as&amp;rdquo; dialog only shows entrys for link layer.  0 I am working on different plugin dissectors to dissect following Protocol stack: Ethernet -&amp;gt; ProtoA -&amp;gt; ProtoB or C.
In the proto_register_a() funktion i call:
register_dissector_table(&#34;a.next&#34;,&#34;A next protocol&#34;, FT_UINT16, BASE_HEX);
In the proto_reg_handoff_a() funktion i call:
dissector_add(&#34;ethertype&#34;, ETHERTYPE_A, a_handle);
In the proto_reg_handoff_b() funktion i call:
dissector_add(&#34;a.next&#34;, A_NEXT_VALUE_B, b_handle);
In the proto_reg_handoff_c() funktion i call:
dissector_add(&#34;a.next&#34;, A_NEXT_VALUE_C, c_handle);</description>
    </item>
    
    <item>
      <title>SYN is answered by a strange ACK, RST is ignored. Windows</title>
      <link>/questions/18817/syn-is-answered-by-a-strange-ack-rst-is-ignored-windows/</link>
      <pubDate>Fri, 22 Feb 2013 09:54:00 +0000</pubDate>
      
      <guid>/questions/18817/syn-is-answered-by-a-strange-ack-rst-is-ignored-windows/</guid>
      <description>SYN is answered by a strange ACK, RST is ignored. Windows  0 This is from a customer, cannot send the whole log. One side is our communications device, another is Windows Server 2008.
http://imgur.com/gxpolJ3
This happens very rarely, but we see it.
Windows replies with &#39;2470&#39;, seq is 1 instead of 0, and it is ACK instead of SYN-ACK, and it acks a packet that is never seen (not in all the previous communication either).</description>
    </item>
    
    <item>
      <title>Server 2003 file listing problem Part 2</title>
      <link>/questions/18825/server-2003-file-listing-problem-part-2/</link>
      <pubDate>Fri, 22 Feb 2013 15:09:00 +0000</pubDate>
      
      <guid>/questions/18825/server-2003-file-listing-problem-part-2/</guid>
      <description>Server 2003 file listing problem Part 2  0 Hi,
I have the following wireshark log and was hoping for some assistance figuring out what is happening:
44120 2013-02-21 10:27:34.667718000 408.146329000 53.248.98.60 53.248.98.58 SMB 326 Trans2 Response, FIND_FIRST2, Files: . ..
44125 2013-02-21 10:27:34.776725000 408.255336000 53.248.98.58 53.248.98.60 SMB 97 Logoff AndX Request
44126 2013-02-21 10:27:34.776874000 408.255485000 53.248.98.60 53.248.98.58 SMB 97 Logoff AndX Response
44127 2013-02-21 10:27:34.776896000 408.255507000 53.248.98.58 53.248.98.60 SMB 93 Tree Disconnect Request</description>
    </item>
    
    <item>
      <title>DHCPv6 option56 NTP Server option  is unknown by Wireshark</title>
      <link>/questions/18828/dhcpv6-option56-ntp-server-option-is-unknown-by-wireshark/</link>
      <pubDate>Sat, 23 Feb 2013 00:39:00 +0000</pubDate>
      
      <guid>/questions/18828/dhcpv6-option56-ntp-server-option-is-unknown-by-wireshark/</guid>
      <description>DHCPv6 option56 NTP Server option is unknown by Wireshark  0 I have download the newest stable release 1.8.5
dhcpv6asked 23 Feb &#39;13, 00:39
wengjianqi
1●1●1●2
accept rate: 0%
  
One Answer:
  
1Correct, this is not implemented. You should file an enhancement bug at bugs.wireshark.org requesting implementation of dissection for RFC 5908. Or create a patch yourself and file that :)
answered 23 Feb &#39;13, 02:51</description>
    </item>
    
    <item>
      <title>rlc reassemble process will take a long time.</title>
      <link>/questions/18843/rlc-reassemble-process-will-take-a-long-time/</link>
      <pubDate>Mon, 25 Feb 2013 02:14:00 +0000</pubDate>
      
      <guid>/questions/18843/rlc-reassemble-process-will-take-a-long-time/</guid>
      <description>rlc reassemble process will take a long time.  0 I have find that the rlc reassemble process will take a long time.
if you have a *.pcap over 50M,and it most frame is rlc,and then ,it will take you too long time to decode the file.
And by debug ,I sure that the most of time is use to reassemble.
is here anybody can fix it?
Thanks!
slowly reassemble rlc tooasked 25 Feb &#39;13, 02:14</description>
    </item>
    
    <item>
      <title>couple of messages in one frame</title>
      <link>/questions/18849/couple-of-messages-in-one-frame/</link>
      <pubDate>Mon, 25 Feb 2013 06:18:00 +0000</pubDate>
      
      <guid>/questions/18849/couple-of-messages-in-one-frame/</guid>
      <description>couple of messages in one frame  0 I wrote a dissector,
I found one packet which contains couple of different/indifferent messages inside it,
Can someone point on the problem ? Is this even a problem ?
I reassemble TCP packets...
This is the function of dissection: (FRAME_HEADER_LEN = 8)
static void dissect_PROTOC(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree) { //Reassembling TCP fragments tcp_dissect_pdus(tvb, pinfo, tree, TRUE, FRAME_HEADER_LEN, get_PROTOC_message_len, dissect_PROTOC_message); }</description>
    </item>
    
    <item>
      <title>Router appears to block proper TCP Session Teardown (FIN, ACK), Ever See This?</title>
      <link>/questions/18858/router-appears-to-block-proper-tcp-session-teardown-fin-ack-ever-see-this/</link>
      <pubDate>Mon, 25 Feb 2013 11:52:00 +0000</pubDate>
      
      <guid>/questions/18858/router-appears-to-block-proper-tcp-session-teardown-fin-ack-ever-see-this/</guid>
      <description>Router appears to block proper TCP Session Teardown (FIN, ACK), Ever See This?  0 We have several Cisco (Linksys) RV082 routers in our networks. I have been trying to run down a problem with a new application that appears to be network related. After 3 weeks of investigation, it appears our RV082 router is terminating some TCP conversations before the full teardown handshake can take place. I have done simultaneous packet capture on both sides of the router and compared the conversations/sessions.</description>
    </item>
    
    <item>
      <title>Understanding Time display format</title>
      <link>/questions/18859/understanding-time-display-format/</link>
      <pubDate>Mon, 25 Feb 2013 12:21:00 +0000</pubDate>
      
      <guid>/questions/18859/understanding-time-display-format/</guid>
      <description>Understanding Time display format  0 Can anyone please explain me what a wireshark user can achieve setting these parameters separately? Seconds since beginning of the capture Seconds since previous captured packet Seconds since previous displayed packet
The first option is straight forward but i would like to know the difference between displayed packet vs captured packet.
Thanks in Advance
timedisplayformatasked 25 Feb &#39;13, 12:21
krishnayeddula
629●35●41●48
accept rate: 6%</description>
    </item>
    
    <item>
      <title>Use multiple files option not working with Wireshark 1.8.4 SVN Rev 46250</title>
      <link>/questions/18868/use-multiple-files-option-not-working-with-wireshark-184-svn-rev-46250/</link>
      <pubDate>Mon, 25 Feb 2013 15:39:00 +0000</pubDate>
      
      <guid>/questions/18868/use-multiple-files-option-not-working-with-wireshark-184-svn-rev-46250/</guid>
      <description>Use multiple files option not working with Wireshark 1.8.4 SVN Rev 46250  0 Hi, I enabled following options in Capture Files feature. Enabled Use Multiple files Next file every 1 MB Next file every 10 seconds and Stop capture after 4 files but i still saw multiple captures(more than 4) got generated.
multiple-files wiresharkasked 25 Feb &#39;13, 15:39
krishnayeddula
629●35●41●48
accept rate: 6%
It works on my WinXP system. What is your OS?</description>
    </item>
    
    <item>
      <title>How to use wireshark to plot traffic between 2 endpoint IP</title>
      <link>/questions/18871/how-to-use-wireshark-to-plot-traffic-between-2-endpoint-ip/</link>
      <pubDate>Mon, 25 Feb 2013 17:39:00 +0000</pubDate>
      
      <guid>/questions/18871/how-to-use-wireshark-to-plot-traffic-between-2-endpoint-ip/</guid>
      <description>How to use wireshark to plot traffic between 2 endpoint IP  0 I have seen statistics in wireshark but what I really want is to plot a line graph showing the traffic between 1 source IP and 1 destination IP. Wonder if wireshark can help me plot this.
plot nodes statistics graphasked 25 Feb &#39;13, 17:39
user5462
1●1●1●1
accept rate: 0%
 edited 25 Feb &#39;13, 18:45 
cmaynard ♦♦</description>
    </item>
    
    <item>
      <title>Wireshark error with &amp;quot;TCP Acked unseen segment&amp;quot;?</title>
      <link>/questions/18877/wireshark-error-with-tcp-acked-unseen-segment/</link>
      <pubDate>Tue, 26 Feb 2013 04:36:00 +0000</pubDate>
      
      <guid>/questions/18877/wireshark-error-with-tcp-acked-unseen-segment/</guid>
      <description>Wireshark error with &amp;ldquo;TCP Acked unseen segment&amp;rdquo;?  0 Hey,
I&#39;ve got a question about the message &#34;TCP Acked unseen segment&#34;. We made a trace and we&#39;ve got this message, but the segment was traced also. So could there be a bug with Wireshark?
The trace is saved on cloudshark: http://www.cloudshark.org/captures/a47e3794dd1a
Thanks for your help!
Best regards, dranigl
unseen_segment bugasked 26 Feb &#39;13, 04:36
dranigl
14●6●6●8
accept rate: 0%</description>
    </item>
    
    <item>
      <title>PDU fails to re-assemble after lost packet.</title>
      <link>/questions/18879/pdu-fails-to-re-assemble-after-lost-packet/</link>
      <pubDate>Tue, 26 Feb 2013 06:24:00 +0000</pubDate>
      
      <guid>/questions/18879/pdu-fails-to-re-assemble-after-lost-packet/</guid>
      <description>PDU fails to re-assemble after lost packet.  0 I have created a dissector for meteorological messages under a specific interface designated COREMET which consists of GRIB messages and METAR messages. These messages are sent across TCP/IP from one unix box to another. The GRIB messages are in excess of 1.0 Mbyte and are split over many messages. MTU is around 1500. When everything is correct the dissector works fine. However we have an issue where a packet was lost during transmission.</description>
    </item>
    
    <item>
      <title>Can wireshark give me a graphic report of the network traffic i&amp;#x27;ve captured on the network?</title>
      <link>/questions/18884/can-wireshark-give-me-a-graphic-report-of-the-network-traffic-ive-captured-on-the-network/</link>
      <pubDate>Tue, 26 Feb 2013 11:01:00 +0000</pubDate>
      
      <guid>/questions/18884/can-wireshark-give-me-a-graphic-report-of-the-network-traffic-ive-captured-on-the-network/</guid>
      <description>Can wireshark give me a graphic report of the network traffic i&amp;rsquo;ve captured on the network?  0 i&#39;d like to know if wireshark has the capability to print out a graphic report of the network traffic that i&#39;ve captured. Please advise...
reportsasked 26 Feb &#39;13, 11:01
theronin
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Yes, there are several ways to get a &#39;report&#39;. It depends on what you need.</description>
    </item>
    
    <item>
      <title>Dissector source code</title>
      <link>/questions/18885/dissector-source-code/</link>
      <pubDate>Tue, 26 Feb 2013 11:12:00 +0000</pubDate>
      
      <guid>/questions/18885/dissector-source-code/</guid>
      <description>Dissector source code  1 If I write a dissector for my proprietary protocol and I give the dissectors to my customers do I have to make the source available?
dissector licenseasked 26 Feb &#39;13, 11:12
gmeloney
16●1●1●2
accept rate: 0%
  
One Answer:
  
1Yes, as you are using or interfacing with code of Wireshark which is licensed according to GPL. So, you need to make your code available as well.</description>
    </item>
    
    <item>
      <title>What is the difference between RST and RST,ACK?</title>
      <link>/questions/18886/what-is-the-difference-between-rst-and-rstack/</link>
      <pubDate>Tue, 26 Feb 2013 11:15:00 +0000</pubDate>
      
      <guid>/questions/18886/what-is-the-difference-between-rst-and-rstack/</guid>
      <description>What is the difference between RST and RST,ACK?  0 I&#39;ve always wondered: What is the difference between a TCP RST and a RST,ACK?
thanks,
Geoff
rst ack packet-captureasked 26 Feb &#39;13, 11:15
GeoffP
40●2●3●7
accept rate: 0%
  
One Answer:
  
0 I&#39;m trying to refrain myself from answering with just &#34;The ACK&#34;...
answered 26 Feb &#39;13, 11:34
SYN-bit ♦♦
17.1k●9●57●245
accept rate: 20%
1OK, I guess I failed at that ;-)</description>
    </item>
    
    <item>
      <title>Export data for all received pacekts</title>
      <link>/questions/18896/export-data-for-all-received-pacekts/</link>
      <pubDate>Tue, 26 Feb 2013 14:17:00 +0000</pubDate>
      
      <guid>/questions/18896/export-data-for-all-received-pacekts/</guid>
      <description>Export data for all received pacekts  0 Hello
I&#39;ve got a capture from a device that has sent me 64K worth of data, and I&#39;d like to export all of the data bytes to a bin file, or something of the like.
Right now I have my filter set to ip.addr == 192.168.111.110
and I&#39;d like to get all the data of each packet exported to a file.
I don&#39;t want to go to the data portion of each packet and select File --&amp;gt; Export --&amp;gt; Selected pacekt bytes.</description>
    </item>
    
    <item>
      <title>How to setup 3G/4G capture interface</title>
      <link>/questions/18901/how-to-setup-3g4g-capture-interface/</link>
      <pubDate>Tue, 26 Feb 2013 16:25:00 +0000</pubDate>
      
      <guid>/questions/18901/how-to-setup-3g4g-capture-interface/</guid>
      <description>How to setup 3G/4G capture interface  0 I have a 3G-4G wireless connection to the internet through Verizon via a cell tower. I cannot figure out how the setup the interface to capture packets.
interfaceasked 26 Feb &#39;13, 16:25
GrayRyder
26●2●2●4
accept rate: 0% 
 edited 26 Feb &#39;13, 17:48 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
0If you&#39;re on a UN*X, as long as you know the name of the interface, it should Just Work, although it&#39;ll probably capture PPP traffic or raw IP traffic, NOT low-level mobile phone protocol traffic.</description>
    </item>
    
    <item>
      <title>How do you use tshark with multiple ssl keys?</title>
      <link>/questions/18908/how-do-you-use-tshark-with-multiple-ssl-keys/</link>
      <pubDate>Tue, 26 Feb 2013 23:03:00 +0000</pubDate>
      
      <guid>/questions/18908/how-do-you-use-tshark-with-multiple-ssl-keys/</guid>
      <description>How do you use tshark with multiple ssl keys?  0 I understand it&#39;s possible to do SSL decryption with tshark by giving a key rule with the ssl.keys_list preferences option. However I&#39;ve only seen examples with a single key, and I can&#39;t find any real documentation for it. Is it possible to use tshark with multiple key rules, like you can in the Wireshark GUI?
ssl tshark decryptionasked 26 Feb &#39;13, 23:03</description>
    </item>
    
    <item>
      <title>TCP checksum validation (off) doesn&amp;#x27;t show my messages</title>
      <link>/questions/18909/tcp-checksum-validation-off-doesnt-show-my-messages/</link>
      <pubDate>Tue, 26 Feb 2013 23:10:00 +0000</pubDate>
      
      <guid>/questions/18909/tcp-checksum-validation-off-doesnt-show-my-messages/</guid>
      <description>TCP checksum validation (off) doesn&amp;rsquo;t show my messages  0 Hey, I wrote a dissector,
Some of my messages are not seen by the wireshark, even though the information is inside the .pcap file, and I can see a specific message that doesn&#39;t be dissected as my protocol, as &#34;[TCP segment of a reassembled PDU]&#34;.
When I turn on the option in the TCP preferences &#34;Validate the TCP checksum if possible.</description>
    </item>
    
    <item>
      <title>Broken TCP. The acknowledge field is nonzero while the ack flag is not set</title>
      <link>/questions/18910/broken-tcp-the-acknowledge-field-is-nonzero-while-the-ack-flag-is-not-set/</link>
      <pubDate>Tue, 26 Feb 2013 23:56:00 +0000</pubDate>
      
      <guid>/questions/18910/broken-tcp-the-acknowledge-field-is-nonzero-while-the-ack-flag-is-not-set/</guid>
      <description>Broken TCP. The acknowledge field is nonzero while the ack flag is not set  0 Hi,
My TN3270 printer server sometimes disconnect from IBM communication server. Printer server IP is 10.100.12.105, communication server IP is 10.99.16.22. The server TCP port is 2023. The communication server will sent PSH,ACK to printer server every 20 seconds if no data sent to printer server to print, and the printer server will sent ACK to communication server.</description>
    </item>
    
    <item>
      <title>Nb RTP multiplex packets stream analysis &amp;quot;RTP Version!=2 not supported&amp;quot;</title>
      <link>/questions/18926/nb-rtp-multiplex-packets-stream-analysis-rtp-version2-not-supported/</link>
      <pubDate>Wed, 27 Feb 2013 03:58:00 +0000</pubDate>
      
      <guid>/questions/18926/nb-rtp-multiplex-packets-stream-analysis-rtp-version2-not-supported/</guid>
      <description>Nb RTP multiplex packets stream analysis &amp;ldquo;RTP Version!=2 not supported&amp;rdquo;  0 Hi All,
Trying to save RTP multiplex packets payloads to raw file. Any clues if it can be done?
stream rtp analysis multiplexasked 27 Feb &#39;13, 03:58
Dees123
1●1●1●2
accept rate: 0%
 edited 01 Mar &#39;13, 13:53 
Jaap ♦
11.7k●16●101
  
2 Answers:
  
1I don&#39;t think so, because the compressed RTP headers cannot be handled.</description>
    </item>
    
    <item>
      <title>What does this error mean?</title>
      <link>/questions/18933/what-does-this-error-mean/</link>
      <pubDate>Wed, 27 Feb 2013 11:23:00 +0000</pubDate>
      
      <guid>/questions/18933/what-does-this-error-mean/</guid>
      <description>What does this error mean?  1 Can any one explain the follow Wireshark error?
Can&amp;#39;t get list of interfaces: Is the server properly installed on ip? connect() failed: No connection could be made because the target machine actively refused it. (code 10061)I can ftp into server using host name and password.
rpcapasked 27 Feb &#39;13, 11:23
GrayRyder
26●2●2●4
accept rate: 0%
 edited 27 Feb &#39;13, 11:40 
Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>Sniff Exchange Activesync login</title>
      <link>/questions/18935/sniff-exchange-activesync-login/</link>
      <pubDate>Wed, 27 Feb 2013 12:36:00 +0000</pubDate>
      
      <guid>/questions/18935/sniff-exchange-activesync-login/</guid>
      <description>Sniff Exchange Activesync login  0 Hi,
I have this (non-rooted) company android phone with Exchange Activesync. I want to copy the account to my private phone but can&#39;t see the password. Is there a way to capture this data while on my private WiFI network when syncing so that I can sniff the password?
Thanks! Mike
activesync exchangeasked 27 Feb &#39;13, 12:36
sjmurf
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark stuck at loading module preference...</title>
      <link>/questions/18938/wireshark-stuck-at-loading-module-preference/</link>
      <pubDate>Wed, 27 Feb 2013 13:00:00 +0000</pubDate>
      
      <guid>/questions/18938/wireshark-stuck-at-loading-module-preference/</guid>
      <description>Wireshark stuck at loading module preference&amp;hellip;  0 Looks like my wireshark application got stuck at loading module preference(99%) Restarted the tool Restarted my windows machine Uninstalled and installed the application but futile
hang wiresharkasked 27 Feb &#39;13, 13:00
krishnayeddula
629●35●41●48
accept rate: 6%
what is your OS version?what is your Wireshark version?can you add a screenshot?(27 Feb &#39;13, 13:16) Kurt Knochner ♦Kurt, Windows 7 home Premium Wireshark 1.8.4 Any permission required to upload .</description>
    </item>
    
    <item>
      <title>PPP wireshark capture</title>
      <link>/questions/18940/ppp-wireshark-capture/</link>
      <pubDate>Wed, 27 Feb 2013 13:41:00 +0000</pubDate>
      
      <guid>/questions/18940/ppp-wireshark-capture/</guid>
      <description>PPP wireshark capture  0 We need a wireshark that captures ppp in a windows environment. What version do we need to download?
capture pppasked 27 Feb &#39;13, 13:41
reachromano
11●1●1●2
accept rate: 0%
  
2 Answers:
  
0See WinPcap FAQ here: https://www.winpcap.org/misc/faq.htm#Q-5
answered 27 Feb &#39;13, 13:45
Pascal Quantin
5.5k●10●60
accept rate: 30%
  
0Microsoft&#39;s Network Monitor can capture PPP traffic and the captures can then be opened in Wireshark.</description>
    </item>
    
    <item>
      <title>SIP phone data capture</title>
      <link>/questions/18949/sip-phone-data-capture/</link>
      <pubDate>Wed, 27 Feb 2013 16:37:00 +0000</pubDate>
      
      <guid>/questions/18949/sip-phone-data-capture/</guid>
      <description>SIP phone data capture  0 I am trying to monitor sip traffif for NEC sip telephone sets and nothing shows up. I need ports 5080-5081, and 10020-10083. How can I monitor all traffic from 1 ip address?
sipasked 27 Feb &#39;13, 16:37
mserino
11●2●2●3
accept rate: 0%
  
One Answer:
  
0For starters: http://wiki.wireshark.org/CaptureSetup/Ethernet
answered 27 Feb &#39;13, 23:42
Jaap ♦
11.7k●16●101
accept rate: 14%</description>
    </item>
    
    <item>
      <title>I seem to be having an issue with recovering an html page from wireshark, for a class project!</title>
      <link>/questions/18950/i-seem-to-be-having-an-issue-with-recovering-an-html-page-from-wireshark-for-a-class-project/</link>
      <pubDate>Wed, 27 Feb 2013 17:34:00 +0000</pubDate>
      
      <guid>/questions/18950/i-seem-to-be-having-an-issue-with-recovering-an-html-page-from-wireshark-for-a-class-project/</guid>
      <description>I seem to be having an issue with recovering an html page from wireshark, for a class project!  -1 As i mentioned i need to extract html code of a website from a wire shark capture file and save it as an html file so it will display relatively the same as if i was on the site but it just displays random characters, i understand how to follow tcp streams and that&#39;s how i am saving these specific packets but each test ends in failure.</description>
    </item>
    
    <item>
      <title>tshark running background linux</title>
      <link>/questions/18953/tshark-running-background-linux/</link>
      <pubDate>Wed, 27 Feb 2013 20:34:00 +0000</pubDate>
      
      <guid>/questions/18953/tshark-running-background-linux/</guid>
      <description>tshark running background linux  0 Im running this tshark filter and cannot get it to start in background or at least run without an active session. Is there some limitation im missing with tshark? Is there anything I can do to get this to run with me having to ssh and manually start the command? OS= Linux/Debian Squeeze. tshark -R &#34;http.request ==1 and http.user_agent&#34; -T fields -e ip.addr -e http.</description>
    </item>
    
    <item>
      <title>HTTP traffic sniffing</title>
      <link>/questions/18963/http-traffic-sniffing/</link>
      <pubDate>Thu, 28 Feb 2013 00:53:00 +0000</pubDate>
      
      <guid>/questions/18963/http-traffic-sniffing/</guid>
      <description>HTTP traffic sniffing  0 I have question about using Wireshark filter. I want to sniff HTTP traffic on destination IP for this case: in our company we have many computers and of course communication server (Microsoft server). All of computers are in domain! So, my question: have computers in domain higher level of security?
I have try to sniff dest. ip, and as result get back only ARP packages. Then I try with this filter: (ip.</description>
    </item>
    
    <item>
      <title>How did I to know the time cost of each function in wireshark?</title>
      <link>/questions/18964/how-did-i-to-know-the-time-cost-of-each-function-in-wireshark/</link>
      <pubDate>Thu, 28 Feb 2013 01:11:00 +0000</pubDate>
      
      <guid>/questions/18964/how-did-i-to-know-the-time-cost-of-each-function-in-wireshark/</guid>
      <description>How did I to know the time cost of each function in wireshark?  0 How did I to know the time cost of each function in wireshark? and then I can debug the which function have take so long time when wireshark running.
1,In linux ,I want to use gprof to detect the function. So I change the makefile:add -pg to compile and link process.but it is not work.I can&#39;t get the gmon.</description>
    </item>
    
    <item>
      <title>error: passing argument 1 of &amp;#x27;new_create_dissector_handle&amp;#x27; from incompatible pointer type</title>
      <link>/questions/18969/error-passing-argument-1-of-new_create_dissector_handle-from-incompatible-pointer-type/</link>
      <pubDate>Thu, 28 Feb 2013 06:00:00 +0000</pubDate>
      
      <guid>/questions/18969/error-passing-argument-1-of-new_create_dissector_handle-from-incompatible-pointer-type/</guid>
      <description>error: passing argument 1 of &amp;lsquo;new_create_dissector_handle&amp;rsquo; from incompatible pointer type  0 I wrote a plugin for wireshark 1.7.1 which was working fine then. When i tried same source with 1.9.0 , it gives me following error while make install.
packet-extl2.c: In function &#39;proto_reg_handoff_extl2&#39;:
packet-extl2.c:265: error: passing argument 1 of &#39;new_create_dissector_handle&#39; from incompatible pointer type
packet-extl2.c:266: error: implicit declaration of function &#39;dissector_add&#39;
make[3]: [packet-extl2.lo] Error 1
make[3]: Leaving directory /root/wireshark/wireshark-1.9.0/plugins/extl2&#39; make[2]: *** [install-recursive] Error 1 make[2]: Leaving directory/root/wireshark/wireshark-1.</description>
    </item>
    
    <item>
      <title>When writing to file with tshark using display filter, not all TCP segments are saved.</title>
      <link>/questions/18975/when-writing-to-file-with-tshark-using-display-filter-not-all-tcp-segments-are-saved/</link>
      <pubDate>Thu, 28 Feb 2013 07:05:00 +0000</pubDate>
      
      <guid>/questions/18975/when-writing-to-file-with-tshark-using-display-filter-not-all-tcp-segments-are-saved/</guid>
      <description>When writing to file with tshark using display filter, not all TCP segments are saved.  0 When a application like SIP has a message that spans multiple TCP segments, if I filter on the application using the wireshark GUI, then export displayed packets as a new file, it successfully saves all the TCP segments that form each SIP request/response.
However, if I do the same thing via tshark, it does NOT save all the segments, and I&#39;m left in incomplete data.</description>
    </item>
    
    <item>
      <title>How to stop wireshark using command line interface in centos 6.3?</title>
      <link>/questions/18978/how-to-stop-wireshark-using-command-line-interface-in-centos-63/</link>
      <pubDate>Thu, 28 Feb 2013 07:17:00 +0000</pubDate>
      
      <guid>/questions/18978/how-to-stop-wireshark-using-command-line-interface-in-centos-63/</guid>
      <description>How to stop wireshark using command line interface in centos 6.3?  0 I have a script that I run to perform some testing and while I start that script I want to issue a command to start wireshark which I have.
Now I want to add a line at the end of the script to STOP wireshark. Can anyone guide me on how to stop wireshark in cli?
My script executes sometimes in 1 hour and sometimes in 20min so my time is not definitive.</description>
    </item>
    
    <item>
      <title>Win7, IE 8, Client Cert Auth with TLSv1.2 enabled NOT WORKING</title>
      <link>/questions/18983/win7-ie-8-client-cert-auth-with-tlsv12-enabled-not-working/</link>
      <pubDate>Thu, 28 Feb 2013 08:52:00 +0000</pubDate>
      
      <guid>/questions/18983/win7-ie-8-client-cert-auth-with-tlsv12-enabled-not-working/</guid>
      <description>Win7, IE 8, Client Cert Auth with TLSv1.2 enabled NOT WORKING  0 Hi All,
I am troubleshooting the not working scenario in which we have sucessful client cert authentication from Win7, IE8 and TLS1.0 enabled - but as soon as in Advanced tab of Internet Options TLS v1.2 is also selected the communication if failing.
Client&#39;s machine has client certificate installed, and also the root CA is installed in Trusted Root store</description>
    </item>
    
    <item>
      <title>Some help for a NewB</title>
      <link>/questions/18990/some-help-for-a-newb/</link>
      <pubDate>Thu, 28 Feb 2013 12:10:00 +0000</pubDate>
      
      <guid>/questions/18990/some-help-for-a-newb/</guid>
      <description>Some help for a NewB  0 I have a ESXi VM Host running a VM of CentOS and a Windows 7 VM. My question is multi tiered and I apologize in advance if these questions could be answered elsewhere, I&#39;m kinda in a crunch. (New boss - new &#34;Important Project&#34; - sure u been there before)
From the CentOS VM I need to run TShark and set a script to only make 400MB files and dump them to a folder which can then be read by my Win7 VM running Netwitness.</description>
    </item>
    
    <item>
      <title>Older version</title>
      <link>/questions/18995/older-version/</link>
      <pubDate>Thu, 28 Feb 2013 18:18:00 +0000</pubDate>
      
      <guid>/questions/18995/older-version/</guid>
      <description>Older version  0 I currently have an older version of wireshark installed on my PC, I was wondering should I install a newer version right over the top of the older version or uninstall the older version first and then install the newer version.
versionasked 28 Feb &#39;13, 18:18
jimjimalabim
20●2●2●5
accept rate: 0%
  
One Answer:
  
2 You can simply install the newer version over the top of what is already installed.</description>
    </item>
    
    <item>
      <title>How to use gprof in wireshark development.</title>
      <link>/questions/18996/how-to-use-gprof-in-wireshark-development/</link>
      <pubDate>Thu, 28 Feb 2013 18:34:00 +0000</pubDate>
      
      <guid>/questions/18996/how-to-use-gprof-in-wireshark-development/</guid>
      <description>How to use gprof in wireshark development.  0 I&#39;m development on the wireshark1.8.5.
I have to find the function which cost a lot of time when wireshark is running.
Thanks!
profile gprofasked 28 Feb &#39;13, 18:34
smilezuzu
20●32●32●37
accept rate: 0%
or how to use performance profile on vs2010 to find out ?
(28 Feb &#39;13, 18:36) smilezuzuIf you are using Linux, you could do &#39;valgrind --tool=callgrind --trace-children=yes ./wireshark&#39; then afterwards browse the biggest of the resulting callgrind files using kcachegrind.</description>
    </item>
    
    <item>
      <title>Is there a way to edit a pcap file to remove addresses?</title>
      <link>/questions/18998/is-there-a-way-to-edit-a-pcap-file-to-remove-addresses/</link>
      <pubDate>Thu, 28 Feb 2013 18:45:00 +0000</pubDate>
      
      <guid>/questions/18998/is-there-a-way-to-edit-a-pcap-file-to-remove-addresses/</guid>
      <description>Is there a way to edit a pcap file to remove addresses?  0 I have a saved pcap file that needs to be edited to remove address. Then save the file back as pcap so the Wireshark features can be used.
I’m exporting the file. Export -&amp;gt; Export Packet Dissection -&amp;gt; as Plain Text file. Make the changes. Now I need to import the file and save as pcap.</description>
    </item>
    
    <item>
      <title>How to commit my code to wireshark SVN repository?</title>
      <link>/questions/18999/how-to-commit-my-code-to-wireshark-svn-repository/</link>
      <pubDate>Thu, 28 Feb 2013 18:51:00 +0000</pubDate>
      
      <guid>/questions/18999/how-to-commit-my-code-to-wireshark-svn-repository/</guid>
      <description>How to commit my code to wireshark SVN repository?  0 My task is add more function to wireshark ,especially the FP RLC RRC and RLCdeciphering.
I have basically accomplished the rlc RLC deciphering function.
How do to commit my code to the wireshark SVN repository?
svn commit repositoryasked 28 Feb &#39;13, 18:51
smilezuzu
20●32●32●37
accept rate: 0%
  
2 Answers:
  
1I believe this link explains it.</description>
    </item>
    
    <item>
      <title>The time used to compile is so long after I edit the rlc code.</title>
      <link>/questions/19001/the-time-used-to-compile-is-so-long-after-i-edit-the-rlc-code/</link>
      <pubDate>Thu, 28 Feb 2013 19:09:00 +0000</pubDate>
      
      <guid>/questions/19001/the-time-used-to-compile-is-so-long-after-i-edit-the-rlc-code/</guid>
      <description>The time used to compile is so long after I edit the rlc code.  0 I&#39;m a developer in the wireshark.
I&#39;m fixing the FP MAC RLC dissector bug in XP.
The time used to compile is so long after I edit the rlc code.
How to fixed it?
compile rlcasked 28 Feb &#39;13, 19:09
smilezuzu
20●32●32●37
accept rate: 0%
The time used to compile is so long after I edit the rlc code.</description>
    </item>
    
    <item>
      <title>Rogue Traffic</title>
      <link>/questions/19006/rogue-traffic/</link>
      <pubDate>Thu, 28 Feb 2013 20:31:00 +0000</pubDate>
      
      <guid>/questions/19006/rogue-traffic/</guid>
      <description>Rogue Traffic  0 Hi ,
we have captured some wire shark traces from our equipment which is connected on L3 switch.
in the logs We are able to see the other devices communication/traffic (TCP messages) which is connected in same L3 switch.
Is this generic ...?
or gives some idea about traffic flow on L3 Switch with protocols.
rogue traffic tcpasked 28 Feb &#39;13, 20:31
Lokanadhareddy
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>IP checksum offload error</title>
      <link>/questions/19013/ip-checksum-offload-error/</link>
      <pubDate>Thu, 28 Feb 2013 22:58:00 +0000</pubDate>
      
      <guid>/questions/19013/ip-checksum-offload-error/</guid>
      <description>IP checksum offload error  0 I have RDP session setup between 2 clients but I am getting checksum error when they are doing TCP 3 way handshake at the time of ACK I see below error.
Can someone please help me understand why I am getting that? Header checksum: 0x0000 [incorrect, should be 0xb46a (may be caused by &#34;IP checksum offload&#34;?)]
Thanks for help.
ip checksum offload errorasked 28 Feb &#39;13, 22:58</description>
    </item>
    
    <item>
      <title>What is backing_length, reported_length ?</title>
      <link>/questions/19015/what-is-backing_length-reported_length/</link>
      <pubDate>Thu, 28 Feb 2013 23:28:00 +0000</pubDate>
      
      <guid>/questions/19015/what-is-backing_length-reported_length/</guid>
      <description>What is backing_length, reported_length ?  0 void tvb_set_subset ( tvbuff_t * tvb, tvbuff_t * backing, const gint backing_offset, const gint backing_length, const gint reported_length )What is backing_length, reported_length here ?
Please help.
dissector tvbasked 28 Feb &#39;13, 23:28
yogeshg
41●22●23●26
accept rate: 0%
 edited 01 Mar &#39;13, 02:54 
Jaap ♦
11.7k●16●101
  
One Answer:
  
3 This function makes tvb a subset of backing.</description>
    </item>
    
    <item>
      <title>dissecting packets using libwireshark in multithreaded environment</title>
      <link>/questions/19016/dissecting-packets-using-libwireshark-in-multithreaded-environment/</link>
      <pubDate>Thu, 28 Feb 2013 23:59:00 +0000</pubDate>
      
      <guid>/questions/19016/dissecting-packets-using-libwireshark-in-multithreaded-environment/</guid>
      <description>dissecting packets using libwireshark in multithreaded environment  0 hello all,
I am using libwireshark.so (shared library for wireshark)v1.6.5 for dissecting network packets, now i want to make my application multithreaded.
so, is it possible to use libworeshark in a multithreaded environment, because every time i am executing the multithreaded application for dissecting packets, first thread works fine, after then no thread can dissect data.
development libwireshark dissection multithreaded c++asked 28 Feb &#39;13, 23:59</description>
    </item>
    
    <item>
      <title>Wireshark support for infiniband</title>
      <link>/questions/19017/wireshark-support-for-infiniband/</link>
      <pubDate>Fri, 01 Mar 2013 01:57:00 +0000</pubDate>
      
      <guid>/questions/19017/wireshark-support-for-infiniband/</guid>
      <description>Wireshark support for infiniband  0 Does Wireshark(tshark) support infiniband packet capturing? (ex, capturing on IP over IB and Ethernet over IB, etc). If yes, whether Solaris is supported? i.e If I compile Wireshark latest bits, will I be able to capture IP over IB packets on Solaris? Thanks in advance.
Regards, Chand
ipoib infinibandasked 01 Mar &#39;13, 01:57
Chand
11●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Remove WinCap from the Install pack</title>
      <link>/questions/19024/remove-wincap-from-the-install-pack/</link>
      <pubDate>Fri, 01 Mar 2013 04:03:00 +0000</pubDate>
      
      <guid>/questions/19024/remove-wincap-from-the-install-pack/</guid>
      <description>Remove WinCap from the Install pack  0 Hi,
Is there any way to have an install package for WireShark that don&#39;t deploy the WinCap (without the option to install WinCap?)
I will not give the option to capture the traffic since I will provide the traffic packages to my team. I will not relly then to uninstall the WinCap after deploy the WireShark.
Is that possible? To remove WinCap option from the install package?</description>
    </item>
    
    <item>
      <title>Dissect traffic between Lutron RadioRa2 and Alarm.com</title>
      <link>/questions/19042/dissect-traffic-between-lutron-radiora2-and-alarmcom/</link>
      <pubDate>Fri, 01 Mar 2013 09:54:00 +0000</pubDate>
      
      <guid>/questions/19042/dissect-traffic-between-lutron-radiora2-and-alarmcom/</guid>
      <description>Dissect traffic between Lutron RadioRa2 and Alarm.com  0 I am looking at the Wireshark trace from a Lutron RadioRa2 repeater communicating with Alarm.com (209.222.135.33) over UDP port 1130. If I follow UDP stream in wireshark, I am getting gibberish.
Is there a way to decrypt and see what information is being sent to Alarm.com?
Thanks
radiora2 casp lutronasked 01 Mar &#39;13, 09:54
net_tech
116●30●33●37
accept rate: 13%
 edited 01 Mar &#39;13, 22:25</description>
    </item>
    
    <item>
      <title>When a 802.11 frame should contain a LLC header?</title>
      <link>/questions/19046/when-a-80211-frame-should-contain-a-llc-header/</link>
      <pubDate>Fri, 01 Mar 2013 10:13:00 +0000</pubDate>
      
      <guid>/questions/19046/when-a-80211-frame-should-contain-a-llc-header/</guid>
      <description>When a 802.11 frame should contain a LLC header?  1 1Well, the title of the question is the question itself :P
I have been looking for the answer into the 802.11-2007 and 2012 standards, but I didn&#39;t find anything.
Hope you&#39;ll be able to help me with this.
I supose that maybe must be a combination of flag values in the MAC (Medium Access Control) header, which determines if the frame needs to carry the LLC header.</description>
    </item>
    
    <item>
      <title>Why can one machine capture transmit and receive traffic but another machine only captures transmit traffic off of the same port mirror?</title>
      <link>/questions/19049/why-can-one-machine-capture-transmit-and-receive-traffic-but-another-machine-only-captures-transmit-traffic-off-of-the-same-port-mirror/</link>
      <pubDate>Fri, 01 Mar 2013 10:30:00 +0000</pubDate>
      
      <guid>/questions/19049/why-can-one-machine-capture-transmit-and-receive-traffic-but-another-machine-only-captures-transmit-traffic-off-of-the-same-port-mirror/</guid>
      <description>Why can one machine capture transmit and receive traffic but another machine only captures transmit traffic off of the same port mirror?  0 This is a very odd problem we have run into...
We have configured a many-to-one port mirror on a switch to forward all traffic from the mirrored servers to a Linux monitor server. We tested the many-to-one port mirror with laptops pinging each other and used another laptop running Wireshark 1.</description>
    </item>
    
    <item>
      <title>tcpdump text output to pcap</title>
      <link>/questions/19054/tcpdump-text-output-to-pcap/</link>
      <pubDate>Fri, 01 Mar 2013 11:06:00 +0000</pubDate>
      
      <guid>/questions/19054/tcpdump-text-output-to-pcap/</guid>
      <description>tcpdump text output to pcap  1 I have a raw tcpdump text file like
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes 17:22:24.464282 IP 1.4.0.2.50425 &amp;gt; 1.4.1.75.8009: P 3284624349:3284624961(612) ack 4160875603 win 602 &amp;lt;nop,nop,timestamp 1267965975 3686849135&amp;gt; 17:22:24.464353 IP 1.4.0.2.50425 &amp;gt; 1.4.1.75.8009: P 612:1401(789) ack 1 win 602 &amp;lt;nop,nop,timestamp 1267965975 3686849135&amp;gt;Where Wireshark responds to opening the file &#34;</description>
    </item>
    
    <item>
      <title>Can you use wireshark to see what is happening on other computers on same network as you?</title>
      <link>/questions/19060/can-you-use-wireshark-to-see-what-is-happening-on-other-computers-on-same-network-as-you/</link>
      <pubDate>Fri, 01 Mar 2013 11:33:00 +0000</pubDate>
      
      <guid>/questions/19060/can-you-use-wireshark-to-see-what-is-happening-on-other-computers-on-same-network-as-you/</guid>
      <description>Can you use wireshark to see what is happening on other computers on same network as you?  0 Hi
I am new to wireshark and i am doing a computer course at college. I am very interested in learning wireshark however i am just wondering if this software can be used to see what is happening on other computers on the same network as you? I have heard some rumours that you need to be on a wired netowrk to do so.</description>
    </item>
    
    <item>
      <title>TCP statistics</title>
      <link>/questions/19083/tcp-statistics/</link>
      <pubDate>Fri, 01 Mar 2013 16:38:00 +0000</pubDate>
      
      <guid>/questions/19083/tcp-statistics/</guid>
      <description>TCP statistics  0 Hello, Do the TCP conversations shown in Statistics-&amp;gt;Conversations-&amp;gt;TCP separate individual TCP sessions between the same hosts and same ports (each with its own SYN FIN etc.) ? Or will it aggregate them into a single entry? I would like to know if it is possible to obtain a summary of each individual TCP session.
Thank you in advance! Hugo
statistics tcp wiresharkasked 01 Mar &#39;13, 16:38</description>
    </item>
    
    <item>
      <title>Cant see TFTP packets on capture</title>
      <link>/questions/19086/cant-see-tftp-packets-on-capture/</link>
      <pubDate>Fri, 01 Mar 2013 22:42:00 +0000</pubDate>
      
      <guid>/questions/19086/cant-see-tftp-packets-on-capture/</guid>
      <description>Cant see TFTP packets on capture  0 Hi, i am hoping there is a quick answer to this question. I used wireshark a few times in the past im starting to use it again to trace TFTP session between Cisco phone and switch via SPAN. I cannot see the TFTP packets leaving the phone or coming back from the router!
I see the packet counters incrementing on the bottom task bar of Wireshark but 0 displayed on screen.</description>
    </item>
    
    <item>
      <title>Convert .pcap using dumpcap</title>
      <link>/questions/19099/convert-pcap-using-dumpcap/</link>
      <pubDate>Sat, 02 Mar 2013 20:55:00 +0000</pubDate>
      
      <guid>/questions/19099/convert-pcap-using-dumpcap/</guid>
      <description>Convert .pcap using dumpcap  0 Hi,
I&#39;m Automatically capturing logs in .pcap format using below command dumpcap.exe -i 4 -a files:3 -a filesize:5 -w test.pcap
how can convert this files to .txt format automatically using dumpcap command....
convert dumpcap .pcapasked 02 Mar &#39;13, 20:55
Irsh
1●2●2●2
accept rate: 0%
  
One Answer:
  
0dumpcap always writes pcapng or pcap files by default, depending on the version of the executable, so the &#34;</description>
    </item>
    
    <item>
      <title>What is  the meaning of subdissector? what is the relationship between a dissector and their subdissectors?</title>
      <link>/questions/19100/what-is-the-meaning-of-subdissector-what-is-the-relationship-between-a-dissector-and-their-subdissectors/</link>
      <pubDate>Sun, 03 Mar 2013 00:47:00 +0000</pubDate>
      
      <guid>/questions/19100/what-is-the-meaning-of-subdissector-what-is-the-relationship-between-a-dissector-and-their-subdissectors/</guid>
      <description>What is the meaning of subdissector? what is the relationship between a dissector and their subdissectors?  1 Hi, I&#39;m a newcomer of wireshark.I want to know what the meaning of subdissector, what the relationship between a dissector and their subdissectors.
Thank&#39;s a lot!
subdissectorasked 03 Mar &#39;13, 00:47
qqgeet
21●2●2●6
accept rate: 0%
 edited 03 Mar &#39;13, 03:42 
grahamb ♦
19.8k●3●30●206
  
One Answer:</description>
    </item>
    
    <item>
      <title>tshark export statistics in csv format</title>
      <link>/questions/19103/tshark-export-statistics-in-csv-format/</link>
      <pubDate>Sun, 03 Mar 2013 11:06:00 +0000</pubDate>
      
      <guid>/questions/19103/tshark-export-statistics-in-csv-format/</guid>
      <description>tshark export statistics in csv format  0 Hello. Is there a way to get a CSV file with the output of tshark&#39;s -z conv,ip similar to the one I get in Wireshark-&amp;gt;Statistics-&amp;gt;Conversations-&amp;gt;IP-&amp;gt;Copy? I was going through the help, but I could only find how to do it for exporting certain fields of pcap files, and not for statistics. Thank you!
statistics tshark csvasked 03 Mar &#39;13, 11:06
hugosp
1●3●3●6</description>
    </item>
    
    <item>
      <title>NetBT traffic for server</title>
      <link>/questions/19107/netbt-traffic-for-server/</link>
      <pubDate>Sun, 03 Mar 2013 13:03:00 +0000</pubDate>
      
      <guid>/questions/19107/netbt-traffic-for-server/</guid>
      <description>NetBT traffic for server  0 Hello
We are looking at disabling Netbios over TCP/IP on some of our Windows 2008 application servers. Since we don&#39;t use WINS, the server will be sending broadcasts for name resolution as far as I understand.
What I&#39;d like to do is capture Netbios over TCP traffic using Wireshark
Server IP: 192.168.20.5 / 24
Is it just a case of display filtering on 137?</description>
    </item>
    
    <item>
      <title>AirPcap how good is it?</title>
      <link>/questions/19109/airpcap-how-good-is-it/</link>
      <pubDate>Sun, 03 Mar 2013 17:13:00 +0000</pubDate>
      
      <guid>/questions/19109/airpcap-how-good-is-it/</guid>
      <description>AirPcap how good is it?  0 Is anyone using AirPcap? If so what version? How does it work, good, bad? What else can you tell me about it? Will it work with other programs besides wireshark?
airpcapasked 03 Mar &#39;13, 17:13
jimjimalabim
20●2●2●5
accept rate: 0%
  
One Answer:
  
1 Is anyone using AirPcap?
I&#39;m sure many of the people on this site are using (or have used) AirPcap.</description>
    </item>
    
    <item>
      <title>Header checksum Error even when Disabling checksum validation in Wireshark</title>
      <link>/questions/19116/header-checksum-error-even-when-disabling-checksum-validation-in-wireshark/</link>
      <pubDate>Sun, 03 Mar 2013 22:46:00 +0000</pubDate>
      
      <guid>/questions/19116/header-checksum-error-even-when-disabling-checksum-validation-in-wireshark/</guid>
      <description>Header checksum Error even when Disabling checksum validation in Wireshark  0 Hi all ,
i need your help please , i sniffed my packets and saw many error evrey seconds , i read about it and saw it excaly match the problem with checksum validation in Wireshark. i turn it off and still it doesn&#39;t go away , i still see all Red packets in my network. any Suggestions?</description>
    </item>
    
    <item>
      <title>Cisco AnnyConnect Secure mobility client VPN</title>
      <link>/questions/19119/cisco-annyconnect-secure-mobility-client-vpn/</link>
      <pubDate>Mon, 04 Mar 2013 04:57:00 +0000</pubDate>
      
      <guid>/questions/19119/cisco-annyconnect-secure-mobility-client-vpn/</guid>
      <description>Cisco AnnyConnect Secure mobility client VPN  0 Hi,
Windows 8 64b, Wireshark 1.8.5
instalation OKCisco AnnyConnect Secure mobility client VPN - not visible adapter -&amp;gt; nothing captured in this VPN
Can you help me? Or can some new version of Wireshark, compatible with win8, help me?
Pavel
cisco annyconnectasked 04 Mar &#39;13, 04:57
kailer
6●1●1●3
accept rate: 0%
  
2 Answers:
  
2 More a WinPCap issue than Wireshark.</description>
    </item>
    
    <item>
      <title>Is it possible to find how data are encoded on a LAN connection?</title>
      <link>/questions/19124/is-it-possible-to-find-how-data-are-encoded-on-a-lan-connection/</link>
      <pubDate>Mon, 04 Mar 2013 07:33:00 +0000</pubDate>
      
      <guid>/questions/19124/is-it-possible-to-find-how-data-are-encoded-on-a-lan-connection/</guid>
      <description>Is it possible to find how data are encoded on a LAN connection?  0 Hello everybody,
I would like to know if it is possible to understand the data sent on a package through a LAN.
Let me explain you my problem, I have two devices connected thanks to a local network (10baseT) and using the IP/TCP protocol. As advised on the Internet, I captured package by using Wireshark and laptop that I connected to the hub located between the two devices.</description>
    </item>
    
    <item>
      <title>[closed] Is it possible to find out how data are encrypted on a LAN connection?</title>
      <link>/questions/19125/is-it-possible-to-find-out-how-data-are-encrypted-on-a-lan-connection/</link>
      <pubDate>Mon, 04 Mar 2013 07:35:00 +0000</pubDate>
      
      <guid>/questions/19125/is-it-possible-to-find-out-how-data-are-encrypted-on-a-lan-connection/</guid>
      <description>[closed] Is it possible to find out how data are encrypted on a LAN connection?  0 Hello everybody,
I would like to know if it is possible to understand the data sent on a package through a LAN.
Let me explain you my problem, I have two devices connected thanks to a local network (10baseT) and using the IP/TCP protocol. As advised on the Internet, I captured package by using Wireshark and laptop that I connected to the hub located between the two devices.</description>
    </item>
    
    <item>
      <title>Listening to wireless traffic through wired connection to router</title>
      <link>/questions/19129/listening-to-wireless-traffic-through-wired-connection-to-router/</link>
      <pubDate>Mon, 04 Mar 2013 08:52:00 +0000</pubDate>
      
      <guid>/questions/19129/listening-to-wireless-traffic-through-wired-connection-to-router/</guid>
      <description>Listening to wireless traffic through wired connection to router  0 Hey I was wondering if it is possible on my desktop pc with wired connection to router, no wireless, to listen to all the wifi traffic that goes to the router? So I eg. can listen to the traffic that comes from my smartphone or laptop from my desktop pc?
If possible, can it be unencrypted data as I have the wired connection to the router, or will it always be encrypted when having a wpa secure network?</description>
    </item>
    
    <item>
      <title>How to get fields from another dissector?</title>
      <link>/questions/19131/how-to-get-fields-from-another-dissector/</link>
      <pubDate>Mon, 04 Mar 2013 10:06:00 +0000</pubDate>
      
      <guid>/questions/19131/how-to-get-fields-from-another-dissector/</guid>
      <description>How to get fields from another dissector?  0 Hello, I am writing a dissector to decode COTP payload data and I would like to get data from other dissectors for my decoding purposes. Specifically I would like to get clnp.type, clnp.dsap, clnp.ssap values for use in my dissector.
dissectortable dissector parentasked 04 Mar &#39;13, 10:06
atmatn
11●1●1●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>tshark memory consumption and temporary file usage</title>
      <link>/questions/19133/tshark-memory-consumption-and-temporary-file-usage/</link>
      <pubDate>Mon, 04 Mar 2013 11:24:00 +0000</pubDate>
      
      <guid>/questions/19133/tshark-memory-consumption-and-temporary-file-usage/</guid>
      <description>tshark memory consumption and temporary file usage  0 Hi all,
I am using tshark to sniff http traffic on a very busy server. Over the course of a number of hours I see a drastic increase in memory usage and the size of the temporary file increases rapidly. Eventually the process fills the disk and memory is so high that the tool grinds to a halt.
This is the command line I am using:</description>
    </item>
    
    <item>
      <title>Improving performance</title>
      <link>/questions/19135/improving-performance/</link>
      <pubDate>Mon, 04 Mar 2013 11:34:00 +0000</pubDate>
      
      <guid>/questions/19135/improving-performance/</guid>
      <description>Improving performance  0 Hi all,
I am using tshark to sniff HTTP content on a very busy server and I see that the CPU usage of the tshark process is very high.
This is the command line I am using:
tshark.exe -i3 -l -f &#34;tcp port 80&#34; -O http -d tcp.port==80,http -o &#34;ip.use_geoip:FALSE&#34; -R &#34;not tcp.analysis.duplicate_ack&#34; -T fields -e ip.host -e tcp.port -e http.request.full_uri -e http.request.method -e http.response.code -e http.</description>
    </item>
    
    <item>
      <title>Application Connecting/ Disconnecting</title>
      <link>/questions/19139/application-connecting-disconnecting/</link>
      <pubDate>Mon, 04 Mar 2013 16:57:00 +0000</pubDate>
      
      <guid>/questions/19139/application-connecting-disconnecting/</guid>
      <description>Application Connecting/ Disconnecting  0 Hello
I have two Windows 2008 Servers that function as a client/server application.
ServerA is the client ServerB is the server
ServerA needs to connect to ServerB, however keeps reporting frequent Disconnections in the Application log. I ran continous ping from ServerA to ServerB which was fine. The latency was ok too.
I figure the next step is to launch WS for more detailed info, but could anyone give me any pointers on what I&#39;m looking for?</description>
    </item>
    
    <item>
      <title>how do I use the maxmind Geo IP databases when using tshark?</title>
      <link>/questions/19140/how-do-i-use-the-maxmind-geo-ip-databases-when-using-tshark/</link>
      <pubDate>Mon, 04 Mar 2013 18:54:00 +0000</pubDate>
      
      <guid>/questions/19140/how-do-i-use-the-maxmind-geo-ip-databases-when-using-tshark/</guid>
      <description>how do I use the maxmind Geo IP databases when using tshark?  0 Hi, How do I use the maxmind Geo IP databases when using tshark, using the terminal (or how do tell tshark to refer to the downloaded database files)? There is no gui on the system so I cannot add using wireshark.
Thanks, qwerfdsa
terminal geoip tshark command-lineasked 04 Mar &#39;13, 18:54
qwerfdsa
16●2●2●5
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Not decrypting both sides of the DHCP handshake</title>
      <link>/questions/19141/not-decrypting-both-sides-of-the-dhcp-handshake/</link>
      <pubDate>Mon, 04 Mar 2013 21:48:00 +0000</pubDate>
      
      <guid>/questions/19141/not-decrypting-both-sides-of-the-dhcp-handshake/</guid>
      <description>Not decrypting both sides of the DHCP handshake  1 1Hello.
I have AirPcap/Wireshark running on windows (both xp-32bit and 7-64bit).
I need to capture the DHCP handshake in order to get further with the support desk of two wireless AP vendors (how far down the rabbit hole am I? A long way :)
I need to solve this as the WiFi module in the product we are developing doesn&#39;t always complete the DHCP handshake with certain AP vendor&#39;s equipment, and their response is &#34;</description>
    </item>
    
    <item>
      <title>Working dissector for 1.7.1 not working for 1.9.0</title>
      <link>/questions/19143/working-dissector-for-171-not-working-for-190/</link>
      <pubDate>Tue, 05 Mar 2013 00:06:00 +0000</pubDate>
      
      <guid>/questions/19143/working-dissector-for-171-not-working-for-190/</guid>
      <description>Working dissector for 1.7.1 not working for 1.9.0  0 Hi Experts,
I don&#39;t know what changes wireshark underwent which has rendered my plugin useless in 1.9.0. I am not getting any compiler/install error but still my plugin is not working and i suspect it has to do with some recent changes of wireshark.
One of the few new changes i did was to add &#34;void* data_U_&#34; in dissector function arguments and post this change atleast i am not getting install error.</description>
    </item>
    
    <item>
      <title>RST message for program request</title>
      <link>/questions/19145/rst-message-for-program-request/</link>
      <pubDate>Tue, 05 Mar 2013 03:46:00 +0000</pubDate>
      
      <guid>/questions/19145/rst-message-for-program-request/</guid>
      <description>RST message for program request  0 Hi, I;m Using program where it Requests data from a remote server and it gives data. (see Link)
I have written a Custom Program to above remote server where it sends request but doesn&#39;t get data . It send a RST and drops the session. (see Link)
Please let me know what is the issue (WireShark Logs are attached in the Links)
rst dropping session packet wiresharkasked 05 Mar &#39;13, 03:46</description>
    </item>
    
    <item>
      <title>TRILL Sub-TLVs under Router Capability TLV</title>
      <link>/questions/19148/trill-sub-tlvs-under-router-capability-tlv/</link>
      <pubDate>Tue, 05 Mar 2013 05:07:00 +0000</pubDate>
      
      <guid>/questions/19148/trill-sub-tlvs-under-router-capability-tlv/</guid>
      <description>TRILL Sub-TLVs under Router Capability TLV  0 Hi~ The TRILL Sub-TLVs under Router Capability TLV As per RFC 6326 section 2.3
The TRILL_VERSION is 13
The VLAN_GROUP is 14
I can&#39;t display the packet in wireshark
trill wiresharkasked 05 Mar &#39;13, 05:07
aries_fang
1●1●1●2
accept rate: 0%
 edited 05 Mar &#39;13, 05:15 
  
One Answer:
  
0These seem to be not-yet-implemented. You&#39;re welcome to provide, through bugs.</description>
    </item>
    
    <item>
      <title>How can i know how much time it took to file to get downloaded with wireshark.</title>
      <link>/questions/19152/how-can-i-know-how-much-time-it-took-to-file-to-get-downloaded-with-wireshark/</link>
      <pubDate>Tue, 05 Mar 2013 07:16:00 +0000</pubDate>
      
      <guid>/questions/19152/how-can-i-know-how-much-time-it-took-to-file-to-get-downloaded-with-wireshark/</guid>
      <description>How can i know how much time it took to file to get downloaded with wireshark.  1 HI all ,
I downloaded a file and in wireshark i saw the GET request of the filename , i want to know how much time it took to the file to get downloaded to my computer . How can i see that throw wireshark ,
can anyone please help me ?</description>
    </item>
    
    <item>
      <title>How to use Wireshark and Cain &amp;amp; Abel to ARP Poison home network??</title>
      <link>/questions/19155/how-to-use-wireshark-and-cain-abel-to-arp-poison-home-network/</link>
      <pubDate>Tue, 05 Mar 2013 10:20:00 +0000</pubDate>
      
      <guid>/questions/19155/how-to-use-wireshark-and-cain-abel-to-arp-poison-home-network/</guid>
      <description>How to use Wireshark and Cain &amp;amp; Abel to ARP Poison home network??  0 Hi Guys
I am wondering if there is a tutorial or something out there that tells me how to use Wireshark and Cain &amp;amp; Abel to ARP Poison my home network?
Thanks
wiresharkasked 05 Mar &#39;13, 10:20
danbyization
1●2●2●2
accept rate: 0%
  
3 Answers:
  
0if there is a tutorial or something out there</description>
    </item>
    
    <item>
      <title>Some capture filters do not work in WShark!</title>
      <link>/questions/19160/some-capture-filters-do-not-work-in-wshark/</link>
      <pubDate>Tue, 05 Mar 2013 10:48:00 +0000</pubDate>
      
      <guid>/questions/19160/some-capture-filters-do-not-work-in-wshark/</guid>
      <description>Some capture filters do not work in WShark!  0 Hello, Some time ago I used the filter &#34;net&#34; for specific networks eg &#34;192.168.1.0/24 net&#34; and &#34;src&#34; for origin hosts, example : 192.168.1. 100, but none of these work for me now. Have they removed these filters? What is the alternative to these? Thanks in advance!
capture capture-filter display-filterasked 05 Mar &#39;13, 10:48
zig69
11●3●3●6
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Can wireshark decode sy protocol ?</title>
      <link>/questions/19180/can-wireshark-decode-sy-protocol/</link>
      <pubDate>Tue, 05 Mar 2013 12:50:00 +0000</pubDate>
      
      <guid>/questions/19180/can-wireshark-decode-sy-protocol/</guid>
      <description>Can wireshark decode sy protocol ?  0 Can wireshark decode sy protocol ? Especially Ericsson Sy version.
sy protocolasked 05 Mar &#39;13, 12:50
Stl
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Wireshark understands at least some of both Sy and Ericsson Sy (I&#39;m assuming you&#39;re talking about the Diameter interface Sy here). If you find the support lacking, please file bugs with sample captures so the support can be improved.</description>
    </item>
    
    <item>
      <title>facebook chat</title>
      <link>/questions/19185/facebook-chat/</link>
      <pubDate>Tue, 05 Mar 2013 13:55:00 +0000</pubDate>
      
      <guid>/questions/19185/facebook-chat/</guid>
      <description>facebook chat  0 Hi guys. I&#39;ve sniffed some packet right now. What&#39;s the filter to use to read facebook chat? thanks
facebookasked 05 Mar &#39;13, 13:55
Rax Ozen
1●1●1●1
accept rate: 0%
  
One Answer:
  
0AFIAK Facebook does a redirect to HTTPS, so the traffic is encrypted and you won&#39;t be able to read the communication. If you want to analyze HTTPS traffic (without access to the crypto keys) you need a plugin for the browser (e.</description>
    </item>
    
    <item>
      <title>wireshark crashes</title>
      <link>/questions/19189/wireshark-crashes/</link>
      <pubDate>Tue, 05 Mar 2013 14:37:00 +0000</pubDate>
      
      <guid>/questions/19189/wireshark-crashes/</guid>
      <description>wireshark crashes  0 Hello,
I am trying to perform FAST decoding in 32-bit wireshark on linux and the size of the pcap file is about 1.2MB (20,000 packets). I start decoding and I am able to decode part of the file but wireshark suddenly crashes and gets closed. As I used to be able to decode 100,000 packets and I am using the same machine and wireshark version, I am wondering what might be problem.</description>
    </item>
    
    <item>
      <title>laptop&amp;#x27;s NICs (wired) that support promiscuous mode natively</title>
      <link>/questions/19195/laptops-nics-wired-that-support-promiscuous-mode-natively/</link>
      <pubDate>Tue, 05 Mar 2013 18:24:00 +0000</pubDate>
      
      <guid>/questions/19195/laptops-nics-wired-that-support-promiscuous-mode-natively/</guid>
      <description>laptop&amp;rsquo;s NICs (wired) that support promiscuous mode natively  0 I need to purchase a laptop that&#39;s NIC supports promiscuous mode. I can&#39;t find a list of wired NICS. There are plenty of lists that show wireless. Any suggestions on the right laptop or NIC manafactuers?
Thanks
Adam
laptop promiscuous-modeasked 05 Mar &#39;13, 18:24
xenon
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Every ethernet (wired) NIC supports promiscuous mode, at least I never had any problems with ethernet NICs.</description>
    </item>
    
    <item>
      <title>Bad ISP service</title>
      <link>/questions/19217/bad-isp-service/</link>
      <pubDate>Wed, 06 Mar 2013 07:29:00 +0000</pubDate>
      
      <guid>/questions/19217/bad-isp-service/</guid>
      <description>Bad ISP service  0 Hi
I am a new wireshark user. I would like to know if there is anyway that I can use wireshark to measure bandwidth usage. IE our provider is telling us we are getting x amount of bandwidth but our users keep complaining the internet is slow. Any ideas would be great.
wanasked 06 Mar &#39;13, 07:29
nycjay01
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How widespread is gratuitous ARP implementation?</title>
      <link>/questions/19224/how-widespread-is-gratuitous-arp-implementation/</link>
      <pubDate>Wed, 06 Mar 2013 08:32:00 +0000</pubDate>
      
      <guid>/questions/19224/how-widespread-is-gratuitous-arp-implementation/</guid>
      <description>How widespread is gratuitous ARP implementation?  0 When I change the IPv4 address on my Juniper router interface, it causes router to send out the gratuitous ARP message:
17:30:25.567297 00:19:e2:9f:ed:f0 &amp;gt; ff:ff:ff:ff:ff:ff, ethertype ARP (0x0806), length 60: Request who-has 10.10.10.126 tell 10.10.10.126, length 46 17:32:39.938593 00:19:e2:9f:ed:f0 &amp;gt; ff:ff:ff:ff:ff:ff, ethertype ARP (0x0806), length 60: Request who-has 10.10.10.65 tell 10.10.10.65, length 46As you can see, I first set the IPv4 address to 10.</description>
    </item>
    
    <item>
      <title>src host capture filter not working!</title>
      <link>/questions/19232/src-host-capture-filter-not-working/</link>
      <pubDate>Wed, 06 Mar 2013 09:49:00 +0000</pubDate>
      
      <guid>/questions/19232/src-host-capture-filter-not-working/</guid>
      <description>src host capture filter not working!  0 Hi.I need to see packets coming from OR going to ip xxx.xxx.xxx.xxx using capture filter but src host capture filter not working for me! I write src host 192.168.1.100 (My IP) and I capture traffic to or from my IP address but I want to capture only traffic from this IP.Also, is there any way to see the capture process, the number of captured packets, etc as in Tshark (linux terminal):</description>
    </item>
    
    <item>
      <title>Site Error - Uploading images not possible</title>
      <link>/questions/19233/site-error-uploading-images-not-possible/</link>
      <pubDate>Wed, 06 Mar 2013 09:51:00 +0000</pubDate>
      
      <guid>/questions/19233/site-error-uploading-images-not-possible/</guid>
      <description>Site Error - Uploading images not possible  1 Hi,
there seems to be a problem while uploading an image to the site.
Error uploading file. Please contact the site administrator. Thank you. [Errno 13] Permission denied: &amp;#39;/web/ask.wireshark.org/osqa/forum/upfiles/Capture_pck.jpg&amp;#39;Thanks for fixing it!
UPDATE: Filed Bug https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8444
UPDATE#2: Test upload. If you see an image, it works....
UPDATE#3: Unfortunately no image is visible, hence it still does not work.
UPDATE#4: it works again, see images above.</description>
    </item>
    
    <item>
      <title>SYN - SYN/ACK - ACK</title>
      <link>/questions/19235/syn-synack-ack/</link>
      <pubDate>Wed, 06 Mar 2013 09:52:00 +0000</pubDate>
      
      <guid>/questions/19235/syn-synack-ack/</guid>
      <description>SYN - SYN/ACK - ACK  0 Hello, I&#39;m troubleshooting an issue where I need to figure out if the some SYN/ACK that I&#39;m seeing are in response to an specific SYN.
I took to independent captures, in two different locations and simultaneously, I can see the SYN from my laptop, but I don&#39;t see any SYN/ACK anywhere in the same capture, when I check the other capture I notice that there are many SYN/ACK but I don&#39;t know how to match one of those SYN/ACK to the SYN that the computer sent.</description>
    </item>
    
    <item>
      <title>Why am I not seeing any activity to or from my handheld device?</title>
      <link>/questions/19249/why-am-i-not-seeing-any-activity-to-or-from-my-handheld-device/</link>
      <pubDate>Wed, 06 Mar 2013 15:05:00 +0000</pubDate>
      
      <guid>/questions/19249/why-am-i-not-seeing-any-activity-to-or-from-my-handheld-device/</guid>
      <description>Why am I not seeing any activity to or from my handheld device?  0 I asked this here: http://stackoverflow.com/questions/15259602/why-am-i-seeing-no-conversations-between-my-desktop-and-my-handheld-apps-with-wi
Basically: my handheld device (the app in question is a Windows CE/Compact Framework .Net 1.1 C# app) is physically attached to my desktop via usb cable; on the desktop, a &#34;server&#34; app (Windows Forms, .NET 4) is running. They communicate with each other, but Wireshark seems to be oblivious to this (no packets passed to or from the handheld device are shown).</description>
    </item>
    
    <item>
      <title>Comparing http.request.method==GET and File &amp;gt;Export Objects&amp;gt;HTTP</title>
      <link>/questions/19258/comparing-httprequestmethodget-and-file-export-objectshttp/</link>
      <pubDate>Wed, 06 Mar 2013 19:53:00 +0000</pubDate>
      
      <guid>/questions/19258/comparing-httprequestmethodget-and-file-export-objectshttp/</guid>
      <description>Comparing http.request.method==GET and File &amp;gt;Export Objects&amp;gt;HTTP  0 I tried to open a website that is hosted on Port 80.I captured all the packets related to that particular Site.Here,I am seeing a mismatch between no.of GET Requests initiated(Showing 95) vs Object list in File&amp;gt;Export Objects &amp;gt;HTTP(Showing 28) Is this a real discrepancy? I am under the impression that each GET Request is an object and hence both should be same.</description>
    </item>
    
    <item>
      <title>Unable To Decrypt a part of application message.</title>
      <link>/questions/19269/unable-to-decrypt-a-part-of-application-message/</link>
      <pubDate>Thu, 07 Mar 2013 03:10:00 +0000</pubDate>
      
      <guid>/questions/19269/unable-to-decrypt-a-part-of-application-message/</guid>
      <description>Unable To Decrypt a part of application message.  0 Hi All,
I am not able to Decrypt some of the avps(in Diameter protocol). My problem is a few avps(diameter protocol)/IE(in 3GPP protocol) of a message is encrypted using AES-CBC Algorithms. Is there any options to decrypt the IEs/AVPs of a 3GPP/Diameter message. Please suggest, how to set the keys and all other parameters to decrypt these IEs. If this feature is not supported in Wireshark,then please suggest is there any ways to decrypt these parameters of the message.</description>
    </item>
    
    <item>
      <title>How to know, How much data transfer occurred in captured pcap file.</title>
      <link>/questions/19274/how-to-know-how-much-data-transfer-occurred-in-captured-pcap-file/</link>
      <pubDate>Thu, 07 Mar 2013 08:11:00 +0000</pubDate>
      
      <guid>/questions/19274/how-to-know-how-much-data-transfer-occurred-in-captured-pcap-file/</guid>
      <description>How to know, How much data transfer occurred in captured pcap file.  0 Can any one please tell me, How can I get to know, how much data is transferred in captured pcap file.
I know, we can check through statistics -&amp;gt; summary, but not sure whether it&#39;s a correct way to check data transferred or not.
Please help.
transfer pcap statistics dataasked 07 Mar &#39;13, 08:11
adtmv7
11●1●1●3</description>
    </item>
    
    <item>
      <title>Will ack.no of last packet from client (minus) seq.no of syn-ack from server give us how much data transferred from server to client?</title>
      <link>/questions/19283/will-ackno-of-last-packet-from-client-minus-seqno-of-syn-ack-from-server-give-us-how-much-data-transferred-from-server-to-client/</link>
      <pubDate>Thu, 07 Mar 2013 12:30:00 +0000</pubDate>
      
      <guid>/questions/19283/will-ackno-of-last-packet-from-client-minus-seqno-of-syn-ack-from-server-give-us-how-much-data-transferred-from-server-to-client/</guid>
      <description>Will ack.no of last packet from client (minus) seq.no of syn-ack from server give us how much data transferred from server to client?  0 I am looking a way to compute the data transfer from server to client.
Seq.no of syn-ack from server is 0(relative seq enabled) Ack.no of last packet from client is 158068267
By subtracting 158068267 from 0 we will get total number of bytes transferred from server to client.</description>
    </item>
    
    <item>
      <title>CFLOW adding new fields</title>
      <link>/questions/19288/cflow-adding-new-fields/</link>
      <pubDate>Thu, 07 Mar 2013 13:19:00 +0000</pubDate>
      
      <guid>/questions/19288/cflow-adding-new-fields/</guid>
      <description>CFLOW adding new fields  0 Adding different fields to a CFLOW
cflowasked 07 Mar &#39;13, 13:19
CFLOWextension
1●1●1●1
accept rate: 0%
What was the question?
(07 Mar &#39;13, 14:05) Jaap ♦   </description>
    </item>
    
    <item>
      <title>What is tns.port?</title>
      <link>/questions/19290/what-is-tnsport/</link>
      <pubDate>Thu, 07 Mar 2013 14:05:00 +0000</pubDate>
      
      <guid>/questions/19290/what-is-tnsport/</guid>
      <description>What is tns.port?  0 I was looking at the sqloracle dissector (packet-sqloracle.c) and I noticed that it doesn&#39;t register a TCP port; instead, it registers tns.port, as follows:
dissector_add_uint(&amp;quot;tns.port&amp;quot;, TCP_PORT_TNS, sqloracle_handle);What is tns.port?
Is this dissector able to be used, or is it there &#34;in case someone wants to use it in the future&#34;?
sqloracle dissectorasked 07 Mar &#39;13, 14:05
moshe
21●1●2●5
accept rate: 0%
 edited 07 Mar &#39;13, 14:05</description>
    </item>
    
    <item>
      <title>how to decode l2tpv3 trace ？ which protocol should be chosen in &amp;quot;decode as&amp;quot; menu ?</title>
      <link>/questions/19297/how-to-decode-l2tpv3-trace-which-protocol-should-be-chosen-in-decode-as-menu/</link>
      <pubDate>Fri, 08 Mar 2013 01:03:00 +0000</pubDate>
      
      <guid>/questions/19297/how-to-decode-l2tpv3-trace-which-protocol-should-be-chosen-in-decode-as-menu/</guid>
      <description>how to decode l2tpv3 trace ？ which protocol should be chosen in &amp;ldquo;decode as&amp;rdquo; menu ?  0 how to decode l2tpv3 trace ？ which protocol should be chosen in &#34;decode as&#34; menu ?
thanks
l2tpv3asked 08 Mar &#39;13, 01:03
Stanley Wu
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>get an image from pcapng file by c# program</title>
      <link>/questions/19298/get-an-image-from-pcapng-file-by-c-program/</link>
      <pubDate>Fri, 08 Mar 2013 01:28:00 +0000</pubDate>
      
      <guid>/questions/19298/get-an-image-from-pcapng-file-by-c-program/</guid>
      <description>get an image from pcapng file by c# program  0 I have network stream that i sniffing by wireshak.
for ex I sniff cats image from google images, by wireshark.
save the sniff in pcapng file, it save in binary file . now I want to show the image one by one
when get the stream from FF D8 to FF D9 the image seem to be less segments then the original image</description>
    </item>
    
    <item>
      <title>Is this a PCAP file?</title>
      <link>/questions/19300/is-this-a-pcap-file/</link>
      <pubDate>Fri, 08 Mar 2013 09:27:00 +0000</pubDate>
      
      <guid>/questions/19300/is-this-a-pcap-file/</guid>
      <description>Is this a PCAP file?  0 I received a file that&#39;s suppose to be a pcap file. Previously, I was directed to http://wiki.wireshark.org/Development/LibpcapFileFormat and was told a PCAP file should begin with a magic number of 0xa1b2c3d4 (byte ordering issue noted). With this file, I don&#39;t see that. It begins with 0a 0d 0d 0a and yet Wireshark has no trouble reading the file. Likewise, pcaputils.py fails and said it&#39;s an invalid tcpdump header neither.</description>
    </item>
    
    <item>
      <title>Want to insert comment in wireshark capture file.</title>
      <link>/questions/19303/want-to-insert-comment-in-wireshark-capture-file/</link>
      <pubDate>Fri, 08 Mar 2013 09:46:00 +0000</pubDate>
      
      <guid>/questions/19303/want-to-insert-comment-in-wireshark-capture-file/</guid>
      <description>Want to insert comment in wireshark capture file.  0 I&#39;m relatively new to wireshark. I&#39;m using an older Fedora wireshark-gnome for some debugging and testing of another system. I would like to be able to insert a comment or text note into the capture file before performing an action on the system being tested (where wireshark will capture the results). I did not see anything like this is in the GUI.</description>
    </item>
    
    <item>
      <title>help with deciphering log....router crash issue</title>
      <link>/questions/19305/help-with-deciphering-logrouter-crash-issue/</link>
      <pubDate>Fri, 08 Mar 2013 10:27:00 +0000</pubDate>
      
      <guid>/questions/19305/help-with-deciphering-logrouter-crash-issue/</guid>
      <description>help with deciphering log&amp;hellip;.router crash issue  0 i&#39;m about out of hair to pull out. We are having a issue with our router (internally crashing - which drops our internet - its been replaced 3x&#39;s and the last time a totally diff style router. They say its on our end which at this point i agree. sometimes its 10-15x a day sometimes its never. not sure where to even start, figured packets was a good start.</description>
    </item>
    
    <item>
      <title>Filter Incoming Connection Attempts</title>
      <link>/questions/19306/filter-incoming-connection-attempts/</link>
      <pubDate>Fri, 08 Mar 2013 10:30:00 +0000</pubDate>
      
      <guid>/questions/19306/filter-incoming-connection-attempts/</guid>
      <description>Filter Incoming Connection Attempts  0 With tcpdump if I want to capture all TCP connection attempts (whether successful or not) I use the following capture filter: tcp[tcpflags] &amp;amp; (tcp-syn) != 0 and if I want capture the start and end packetes (The SYN and FIN packets) of each TCP conversation that involves a non-local host I use: tcp[tcpflags] &amp;amp; (tcp-syn|tcp-fin) != 0 and not src and dst net localnet How can I do these examples using Wireshark GUI (Creating capture filters)?</description>
    </item>
    
    <item>
      <title>Can you decode custom UDP packets?</title>
      <link>/questions/19308/can-you-decode-custom-udp-packets/</link>
      <pubDate>Fri, 08 Mar 2013 11:11:00 +0000</pubDate>
      
      <guid>/questions/19308/can-you-decode-custom-udp-packets/</guid>
      <description>Can you decode custom UDP packets?  0 I have a Xilinx board pushing out periodic UDP messages to the network with a computer running WireShark that is picking up all of the messages that the FPGA is generating. The data section of the UDP packet is not simple to decode so troubleshooting while just looking at the HEX ins&#39;t a very easy task. Is it possible to create my own decoder so that custom fields can be populated with human readable text?</description>
    </item>
    
    <item>
      <title>tshark with -Tfield: How to make address resolution and output format work?</title>
      <link>/questions/19311/tshark-with-tfield-how-to-make-address-resolution-and-output-format-work/</link>
      <pubDate>Fri, 08 Mar 2013 11:58:00 +0000</pubDate>
      
      <guid>/questions/19311/tshark-with-tfield-how-to-make-address-resolution-and-output-format-work/</guid>
      <description>tshark with -Tfield: How to make address resolution and output format work?  1 Hi, Is there a way to make MAC address resolution work in tshark output? I use this command:
c:\Program Files\Wireshark&amp;gt;tshark -T fields -Eheader=y -Eseparator=, -Eaggregator=\s -eframe.number -eframe.time_relative -ewlan.sa -ewlan.fc.type_subtype -ewlan.da -r sample80211.pkt
And the output lines looks like the line below:
22,20.556985855,00:0d:67:30:3c:1c,0x08,ff:ff:ff:ff:ff:ff
I cannot get the mac address resolved using global manuf file when -Tfields is used with -e.</description>
    </item>
    
    <item>
      <title>How to apply a Patch with TortoiseSVN</title>
      <link>/questions/19317/how-to-apply-a-patch-with-tortoisesvn/</link>
      <pubDate>Fri, 08 Mar 2013 14:39:00 +0000</pubDate>
      
      <guid>/questions/19317/how-to-apply-a-patch-with-tortoisesvn/</guid>
      <description>How to apply a Patch with TortoiseSVN  0 Hi
How can I apply a Patch to Wireshark using TortoiseSVN application?
patchasked 08 Mar &#39;13, 14:39
steve21
11●5●5●7
accept rate: 0%
  
One Answer:
  
0Not really a Wireshark question.
Anyway a patch file modifies the source code of an application not the binary. You&#39;ll need to get a Wireshark development environment setup first, check you can build an unmodified version, then apply the patch and rebuild.</description>
    </item>
    
    <item>
      <title>Capture network traffic for wired C.E. devices</title>
      <link>/questions/19322/capture-network-traffic-for-wired-ce-devices/</link>
      <pubDate>Fri, 08 Mar 2013 16:08:00 +0000</pubDate>
      
      <guid>/questions/19322/capture-network-traffic-for-wired-ce-devices/</guid>
      <description>Capture network traffic for wired C.E. devices  0 I often need to capture traffic for various consumer electronic devices to determine what API calls are being made along with the response.
This is quite easy to do with my MacBook and wifi capable devices. I simply connect the ethernet cable to my laptop and share my ethernet connection over my wifi. I connect the C.E. device through the shared wifi on my MacBook and capture all traffic on my computer with WireShark.</description>
    </item>
    
    <item>
      <title>why few HTTP objects can&amp;#x27;t be saved to disk?</title>
      <link>/questions/19324/why-few-http-objects-cant-be-saved-to-disk/</link>
      <pubDate>Fri, 08 Mar 2013 17:27:00 +0000</pubDate>
      
      <guid>/questions/19324/why-few-http-objects-cant-be-saved-to-disk/</guid>
      <description>why few HTTP objects can&amp;rsquo;t be saved to disk?  0 I tried to capture objects from adobe.com website. Triggered wireshark and browsed for a minute, saved the capture. When I tried to export all the objects to the disk I got an error message saying &#34;some files could not be saved&#34;
Got couple of questions here:
Reason for the error message.What kind of objects Wireshark can&#39;t save to disk?Why we are not able to save objects &#34;</description>
    </item>
    
    <item>
      <title>mysterious IP address</title>
      <link>/questions/19331/mysterious-ip-address/</link>
      <pubDate>Sat, 09 Mar 2013 17:24:00 +0000</pubDate>
      
      <guid>/questions/19331/mysterious-ip-address/</guid>
      <description>mysterious IP address  0 Hi
I really need some advice , my firewall is blocking the following 192.168.211.178 which is sending from within my network a udp packet. The address cannot be ping and is not registered in my DNS, running wireshark i only see a repeating udp packet from this address every 30 seconds. Also the UDP packet source port is 1111, the mac address is from tyancomp these are the only types of packets from this mac address or IP.</description>
    </item>
    
    <item>
      <title>TCP- induced “Continuation” question.</title>
      <link>/questions/19335/tcp-induced-continuation-question/</link>
      <pubDate>Sat, 09 Mar 2013 18:48:00 +0000</pubDate>
      
      <guid>/questions/19335/tcp-induced-continuation-question/</guid>
      <description>TCP- induced “Continuation” question.  0 My homework is asking this question: Are there any HTTP status lines in the transmitted data associated with a TCP- induced “Continuation”? The text previous to the question states: In the packet-listing window, you should see your HTTP GET message, followed by a multiple-packet response to your HTTP GET request. This multiple-packet response deserves a bit of explanation. Recall from Section 2.2 (see Figure 2.</description>
    </item>
    
    <item>
      <title>How to find torrent name</title>
      <link>/questions/19338/how-to-find-torrent-name/</link>
      <pubDate>Sun, 10 Mar 2013 04:06:00 +0000</pubDate>
      
      <guid>/questions/19338/how-to-find-torrent-name/</guid>
      <description>How to find torrent name  0 Hi. Can I find the name of the torrents are downloading with any technique ?
capture.bittorrent torrentasked 10 Mar &#39;13, 04:06
apant
1●1●1●1
accept rate: 0%
  
One Answer:
  
0That depends:
If you have the packets where someone is loading the torrent description file (usually via web browser or via magnet link), you can find the file name inside that file.</description>
    </item>
    
    <item>
      <title>TCPdSTAT for Wireshark?</title>
      <link>/questions/19340/tcpdstat-for-wireshark/</link>
      <pubDate>Sun, 10 Mar 2013 14:10:00 +0000</pubDate>
      
      <guid>/questions/19340/tcpdstat-for-wireshark/</guid>
      <description>TCPdSTAT for Wireshark?  0 I have been working with some fun forensic command line tools. I have realized that while wireshark is fabulously powerful, it is not the easiest to get a &#34;baseline&#34; network reading or easily analyze network traffic for forensic evidence. I have used TCPdSTAT for a while, but it seems to be under developed for PCAP-NG file formats (at least as far as i can tell). I have since been working on one of my own LUA scripts as a TCPdSTAT-esque port.</description>
    </item>
    
    <item>
      <title>SAG (SBC)?</title>
      <link>/questions/19343/sag-sbc/</link>
      <pubDate>Sun, 10 Mar 2013 16:16:00 +0000</pubDate>
      
      <guid>/questions/19343/sag-sbc/</guid>
      <description>SAG (SBC)?  0 What do the SAG letters at sag-lookup-on-redirect mean?
sbc sip sag ipasked 10 Mar &#39;13, 16:16
sharkie
11●1●1●2
accept rate: 0%
  
2 Answers:
  
0I have the answer. It&#39;s Session Agent Group.
http://www.markholloway.com/blog/?p=1684
answered 10 Mar &#39;13, 16:25
sharkie
11●1●1●2
accept rate: 0%
  
0Umm... that&#39;s not really a Wireshark question. :) Probably more appropriate on community.acmepacket.com. Did you see this in wireshark from a capture file somehow?</description>
    </item>
    
    <item>
      <title>How to filter out header error IP packets</title>
      <link>/questions/19348/how-to-filter-out-header-error-ip-packets/</link>
      <pubDate>Mon, 11 Mar 2013 00:14:00 +0000</pubDate>
      
      <guid>/questions/19348/how-to-filter-out-header-error-ip-packets/</guid>
      <description>How to filter out header error IP packets  0 I am using wireshark windows. 2 client connected via one rounter. The client received header error IP packet occasionally.
now I am wondering whether wireshark can help to get the detail faulty IP packet. Thanks.
wiresharkThis question is marked &#34;community wiki&#34;.asked 11 Mar &#39;13, 00:14
ericsson
1●1●1●1
accept rate: 0%
Maybe, but you&#39;ll have to specify what this &#39;header error IP packet&#39; is.</description>
    </item>
    
    <item>
      <title>Import from.. UDP port</title>
      <link>/questions/19350/import-from-udp-port/</link>
      <pubDate>Mon, 11 Mar 2013 02:46:00 +0000</pubDate>
      
      <guid>/questions/19350/import-from-udp-port/</guid>
      <description>Import from.. UDP port  0 I&#39;m looking for similar feature than what is Wireshark - Import from text file.
But instead from text file I would like to send packets to IP/UDP port which wireshark then listens. Then the packet payload contains the information to be decoded by Wireshark.
This looks quite easy to implement functionality (for the great masters.., not for me) . Just specify port to listen and Encapsulation type.</description>
    </item>
    
    <item>
      <title>MAC address display filter not displaying any packets</title>
      <link>/questions/19352/mac-address-display-filter-not-displaying-any-packets/</link>
      <pubDate>Mon, 11 Mar 2013 04:27:00 +0000</pubDate>
      
      <guid>/questions/19352/mac-address-display-filter-not-displaying-any-packets/</guid>
      <description>MAC address display filter not displaying any packets  0 Hi,
This is a bit of a dumb question but I have been struggling with this for an hour or so without getting a resolution. I have a capture file containing WiFi packets. I want to filter out all packets not going to or from a particular access point. There are thousands of packets in the trace so I just want to watch what is happening between my 4 clients and the access point.</description>
    </item>
    
    <item>
      <title>RFC4733 DTMF ebits and event duration</title>
      <link>/questions/19357/rfc4733-dtmf-ebits-and-event-duration/</link>
      <pubDate>Mon, 11 Mar 2013 10:54:00 +0000</pubDate>
      
      <guid>/questions/19357/rfc4733-dtmf-ebits-and-event-duration/</guid>
      <description>RFC4733 DTMF ebits and event duration  0 I have seen an issue where the DTMF digits that were being press, some of the digits were being triplicated. Example: user presses 79546 and what it was being interpretted as was 77795. The only thing different we could find was that the event duration increases by 80 on each of the three end bits for the 7. A patch was put in to mask the last two digits, and it worked.</description>
    </item>
    
    <item>
      <title>Running Wireshark from Red Hat command line?</title>
      <link>/questions/19361/running-wireshark-from-red-hat-command-line/</link>
      <pubDate>Mon, 11 Mar 2013 12:18:00 +0000</pubDate>
      
      <guid>/questions/19361/running-wireshark-from-red-hat-command-line/</guid>
      <description>Running Wireshark from Red Hat command line?  0 I am running Red Hat Enterprise Linux Server release 5.6 (x86_64), and I installed Wireshark 1.0.15.
I installed Wireshark by:
yum install wiresharkNow when I try running following command line:
wireshark -c 100 -k -Q -w –I receive:
(wireshark:25796): Gtk-WARNING **: cannot open display:Any ideas why it won&#39;t run from the command line? Do you need the GUI for Wireshark to work from the command line?</description>
    </item>
    
    <item>
      <title>How do we differentiate simple g711a codec or  codec with silence suppressor in wireshark?</title>
      <link>/questions/19372/how-do-we-differentiate-simple-g711a-codec-or-codec-with-silence-suppressor-in-wireshark/</link>
      <pubDate>Mon, 11 Mar 2013 23:57:00 +0000</pubDate>
      
      <guid>/questions/19372/how-do-we-differentiate-simple-g711a-codec-or-codec-with-silence-suppressor-in-wireshark/</guid>
      <description>How do we differentiate simple g711a codec or codec with silence suppressor in wireshark?  0 How do we differentiate simple g711a codec or codec with silence suppressor in wireshark?
codecasked 11 Mar &#39;13, 23:57
archu
11●4●4●7
accept rate: 0%
 edited 12 Mar &#39;13, 01:29 
Jaap ♦
11.7k●16●101
  
One Answer:
  
1You&#39;ll see jumps in the RTP time stamps, while the sequence numbers are monotone incrementing.</description>
    </item>
    
    <item>
      <title>which one is best way to look for all Ipddress that was there during communication</title>
      <link>/questions/19374/which-one-is-best-way-to-look-for-all-ipddress-that-was-there-during-communication/</link>
      <pubDate>Tue, 12 Mar 2013 01:33:00 +0000</pubDate>
      
      <guid>/questions/19374/which-one-is-best-way-to-look-for-all-ipddress-that-was-there-during-communication/</guid>
      <description>which one is best way to look for all Ipddress that was there during communication  0 For example I have one pcapng file how can we check for all Ip address that was during communication
wiresharkasked 12 Mar &#39;13, 01:33
m_1607
35●12●13●16
accept rate: 0%
  
One Answer:
  
1 You mean you want a list of all IPs that are in the pcapng file? Just run Wireshark, and go to Statistics/Endpoints.</description>
    </item>
    
    <item>
      <title>nmake errors</title>
      <link>/questions/19378/nmake-errors/</link>
      <pubDate>Tue, 12 Mar 2013 02:53:00 +0000</pubDate>
      
      <guid>/questions/19378/nmake-errors/</guid>
      <description>nmake errors  0 hi,i am new to wireshark trying to build a disssector.i&#39;ve downloaded all the required tools-vs2010ee,pyton,cygwin,svntortoise.i am not able to download from trunk through svn in my company,though it worked in my home.so i just copy pastedinto c:\wireshark.i am not able to verify the tools or install libraries using nmake. i am getting different errors at differnt times. 1)nmake not recognized as an internal or external command 2)nmake cannot make &#39;-f&#39; stop(checked with minus/hyphen solution,but in vain) 3)your moon-man&#34;</description>
    </item>
    
    <item>
      <title>Debug console: no printout at all</title>
      <link>/questions/19380/debug-console-no-printout-at-all/</link>
      <pubDate>Tue, 12 Mar 2013 03:30:00 +0000</pubDate>
      
      <guid>/questions/19380/debug-console-no-printout-at-all/</guid>
      <description>Debug console: no printout at all  0 Hi All,
I&#39;m trying to debug my dissector plugin using debug console http://wiki.wireshark.org/Development/Tips
No g_print nor just printf nor ostream std::cout doesn&#39;t work.
Just writing to the file - it works but it&#39;s not so useful like console.
What could be the reason ?
Which secret flag should I check ?
I compiled Wireshark 1.9.0 ( svn rev 48261) for Windows,
activated debug console as &#34;</description>
    </item>
    
    <item>
      <title>How to filter one way communication( packets/IPs)</title>
      <link>/questions/19381/how-to-filter-one-way-communication-packetsips/</link>
      <pubDate>Tue, 12 Mar 2013 03:33:00 +0000</pubDate>
      
      <guid>/questions/19381/how-to-filter-one-way-communication-packetsips/</guid>
      <description>How to filter one way communication( packets/IPs)  0 Hello
 I have a capture file and in it there are some IP which have only one way traffic means traffic comes to destination but when destination reply back to source that packets are not there in that capture file. So tell me how I can find the missing packets which has no reply (means only one way traffic)Like I have Client and server</description>
    </item>
    
    <item>
      <title>PLC PRIME protocol dissector</title>
      <link>/questions/19386/plc-prime-protocol-dissector/</link>
      <pubDate>Tue, 12 Mar 2013 07:31:00 +0000</pubDate>
      
      <guid>/questions/19386/plc-prime-protocol-dissector/</guid>
      <description>PLC PRIME protocol dissector  0 Hello,
I have worked with some teammates on a dissector for PLC PRIME protocol. Just to check before going further, is there anyone else working on a dissector for PLC PRIME and has the intention to add it to wireshark?
Thanks
prime plcasked 12 Mar &#39;13, 07:31
mihaIzKamnea
11●1●1●2
accept rate: 0%
  
One Answer:
  
0You&#39;ll probably get a better response on the dev mailing list.</description>
    </item>
    
    <item>
      <title>tshark -T fields output same info and format as -T text -x</title>
      <link>/questions/19388/tshark-t-fields-output-same-info-and-format-as-t-text-x/</link>
      <pubDate>Tue, 12 Mar 2013 08:08:00 +0000</pubDate>
      
      <guid>/questions/19388/tshark-t-fields-output-same-info-and-format-as-t-text-x/</guid>
      <description>tshark -T fields output same info and format as -T text -x  1 1Hello,
I am trying to write a script that will remove duplicate packets (layer 3 and above) by comparing the data in two consecutive packets (or along a sliding window) and if they are identical, it will throw out the duplicates. The packets are not 100% duplicates since the MACs and TTLs are different, but from layer 3 and above they are identical.</description>
    </item>
    
    <item>
      <title>Wireshark fails to open with windows 7</title>
      <link>/questions/19398/wireshark-fails-to-open-with-windows-7/</link>
      <pubDate>Tue, 12 Mar 2013 11:41:00 +0000</pubDate>
      
      <guid>/questions/19398/wireshark-fails-to-open-with-windows-7/</guid>
      <description>Wireshark fails to open with windows 7  0 With Wireshark 1.8.5 and 1.8.6 sometimes wireshark will not open. The icon on the taskbar will become become highlighted for a few seconds then dissapear. If I look at the running processes wireshark is listed but I can not interact with it. If I kill the process tree and try to reopen Wireshark the same thing will happen. I must restart in order to open a usable Wireshark.</description>
    </item>
    
    <item>
      <title>Behaviour when no capture filters are defined.</title>
      <link>/questions/19405/behaviour-when-no-capture-filters-are-defined/</link>
      <pubDate>Tue, 12 Mar 2013 13:22:00 +0000</pubDate>
      
      <guid>/questions/19405/behaviour-when-no-capture-filters-are-defined/</guid>
      <description>Behaviour when no capture filters are defined.  0 Question: If I delete all Capture Filters from Wireshark and then start a Capture session, will Wireshark log all network interactions or none at all?
Thanks
capture-filterasked 12 Mar &#39;13, 13:22
John Goldorak
6●1●1●2
accept rate: 0%
  
One Answer:
  
1 It will capture everything. Filters mean &#34;leave something out&#34;, so if there&#39;s no filter, Wireshark will capture it all.</description>
    </item>
    
    <item>
      <title>Wireshark from the command line</title>
      <link>/questions/19407/wireshark-from-the-command-line/</link>
      <pubDate>Tue, 12 Mar 2013 14:05:00 +0000</pubDate>
      
      <guid>/questions/19407/wireshark-from-the-command-line/</guid>
      <description>Wireshark from the command line  0 I tried modifying this for my own purposes:
@echo on set start=0 set /p end= Enter number of 30-minute increments to loop: set filenum=1 set filestart=&amp;quot;c:\tempWScap\result&amp;quot; set fileend=&amp;quot;.pcapng&amp;quot;
:loop if %start%==%end% goto stop set &amp;quot;filestring=%filestart%%filenum%%fileend%&amp;quot; &amp;quot;C:\program files\wireshark\wireshark.exe&amp;quot; -i &amp;quot;\Device\NPF_{5423F6E4-1BC8-4F55-625E-B2F995D893D1}&amp;quot; -a duration:180 -w %filestring% -k set /a start=%start%+1 set /a filenum=%filenum%+1
PING 127.0.0.1 -n 1800
goto loop
:stopThis works fine but I want it to quit wireshark after the capture is over.</description>
    </item>
    
    <item>
      <title>How can I see how long takes from when the HTTP GET message was sent until the HTTP OK  reply was received</title>
      <link>/questions/19410/how-can-i-see-how-long-takes-from-when-the-http-get-message-was-sent-until-the-http-ok-reply-was-received/</link>
      <pubDate>Tue, 12 Mar 2013 20:50:00 +0000</pubDate>
      
      <guid>/questions/19410/how-can-i-see-how-long-takes-from-when-the-http-get-message-was-sent-until-the-http-ok-reply-was-received/</guid>
      <description>How can I see how long takes from when the HTTP GET message was sent until the HTTP OK reply was received  0 Thank you for your help
capture http packetasked 12 Mar &#39;13, 20:50
feierqi
1●1●1●1
accept rate: 0%
  
3 Answers:
  
2Set your time display format to &#34;Seconds Since Beginning of Capture.&#34; (View &amp;gt; Time Display Format &amp;gt; Seconds Since Beginning of Capture.</description>
    </item>
    
    <item>
      <title>how to get only the headers of a packet</title>
      <link>/questions/19411/how-to-get-only-the-headers-of-a-packet/</link>
      <pubDate>Tue, 12 Mar 2013 21:01:00 +0000</pubDate>
      
      <guid>/questions/19411/how-to-get-only-the-headers-of-a-packet/</guid>
      <description>how to get only the headers of a packet  0 Hi,
Is there any way to use display filters to get only the headers for a packet and not the contents/payload (e.g. which seem to follow the content-length header in SIP) using tshark. It is possible to select individual headers but I know not any way to exclude the payload.
Thanks, qwerfdsa
payload tshark display-filterasked 12 Mar &#39;13, 21:01</description>
    </item>
    
    <item>
      <title>Wireshark only sniffs my device&amp;#x27;s (Mac OS X) traffic on my wifi network. Monitor mode not helping</title>
      <link>/questions/19413/wireshark-only-sniffs-my-devices-mac-os-x-traffic-on-my-wifi-network-monitor-mode-not-helping/</link>
      <pubDate>Tue, 12 Mar 2013 22:33:00 +0000</pubDate>
      
      <guid>/questions/19413/wireshark-only-sniffs-my-devices-mac-os-x-traffic-on-my-wifi-network-monitor-mode-not-helping/</guid>
      <description>Wireshark only sniffs my device&amp;rsquo;s (Mac OS X) traffic on my wifi network. Monitor mode not helping  0 The packets coming through are all from my own device, but the other devices connected to my wireless network (a PC, and a mobile phone) are not showing up at all. I did some research, and put it in &#34;monitor mode&#34;, but doing that changes the way the captured data looks. They are no longer color coded, they are just plain text, and it doesn&#39;t seem to be tracking any of the information I want, all the results are now protocol: 802.</description>
    </item>
    
    <item>
      <title>Please let me know which wireshark version support the below CDMA parameter - ANSI MAP</title>
      <link>/questions/19418/please-let-me-know-which-wireshark-version-support-the-below-cdma-parameter-ansi-map/</link>
      <pubDate>Tue, 12 Mar 2013 23:18:00 +0000</pubDate>
      
      <guid>/questions/19418/please-let-me-know-which-wireshark-version-support-the-below-cdma-parameter-ansi-map/</guid>
      <description>Please let me know which wireshark version support the below CDMA parameter - ANSI MAP  0 Please let me know which wireshark version support the below CDMA parameter - ANSI MAP:::
CDMAPSMMList --CDMAServiceOneWayDelay2 --CDMATargetMAHOList --CDMATargetMAHOInfo --TargetCellID --CDMAPilotStrength --CDMATargetOneWayDelay --CDMATargetMAHOList --CDMATargetMAHOInfo --TargetCellID --CDMAPilotStrength --CDMATargetOneWayDelay
cdma parameterasked 12 Mar &#39;13, 23:18
moorthyforu
11●1●1●3
accept rate: 0%
  
One Answer:
  
0You can check here http://anonsvn.wireshark.org/viewvc/trunk/asn1/ansi_map/ansi_map.asn?revision=38159&amp;amp;view=markup
answered 12 Mar &#39;13, 23:54</description>
    </item>
    
    <item>
      <title>Can I capture the traffic in a switch using wireshark</title>
      <link>/questions/19419/can-i-capture-the-traffic-in-a-switch-using-wireshark/</link>
      <pubDate>Tue, 12 Mar 2013 23:37:00 +0000</pubDate>
      
      <guid>/questions/19419/can-i-capture-the-traffic-in-a-switch-using-wireshark/</guid>
      <description>Can I capture the traffic in a switch using wireshark  0 Hello i want to use some traffic measurement software to study self similarity of a network. The measurement will be the traffic in the core switch. I know wireshark can capture the traffic in the interface only but not the whole traffic in the switch/router. Does wireshark support SNMP or not? Can i capture the traffic in the switch using wire shark.</description>
    </item>
    
    <item>
      <title>How to see console messages in wireshark linux ?</title>
      <link>/questions/19420/how-to-see-console-messages-in-wireshark-linux/</link>
      <pubDate>Tue, 12 Mar 2013 23:42:00 +0000</pubDate>
      
      <guid>/questions/19420/how-to-see-console-messages-in-wireshark-linux/</guid>
      <description>How to see console messages in wireshark linux ?  0 http://wiki.wireshark.org/Development/Tips
Above link shows how can we use printf to debug in console. But i am not able to see console in linux. Please help.
debugger wiresharkasked 12 Mar &#39;13, 23:42
yogeshg
41●22●23●26
accept rate: 0%
I mean , should proto_tree_add_debug_text display in gdb output ?
(12 Mar &#39;13, 23:50) yogeshg  
One Answer:
  
1Open a console, launch Wireshark from it, see the console output.</description>
    </item>
    
    <item>
      <title>The contents of C:&amp;#92;wireshark-win32-libs&amp;#92;current_tag.txt is (unknown)</title>
      <link>/questions/19425/the-contents-of-cwireshark-win32-libscurrent_tagtxt-is-unknown/</link>
      <pubDate>Wed, 13 Mar 2013 01:09:00 +0000</pubDate>
      
      <guid>/questions/19425/the-contents-of-cwireshark-win32-libscurrent_tagtxt-is-unknown/</guid>
      <description>The contents of C:\wireshark-win32-libs\current_tag.txt is (unknown)  0 hi all,after proper installation as mentioned in developer guide,and running this command in cmd prompt: C:\wireshark&amp;gt; nmake -f Makefile.nmake verify_tools,i get this error..
Microsoft (R) Program Maintenance Utility Version 10.00.40219.01 Copyright (C) Microsoft Corporation. All rights reserved. ERROR: The contents of C:\wireshark-win32-libs\current_tag.txt is (unknown). It should be 2013-02-19.
Checking for required applications: cl: /cygdrive/c/Program Files (x86)/Microsoft Visual Studio 10.0/VC/BIN/cl link: /cygdrive/c/Program Files (x86)/Microsoft Visual Studio 10.</description>
    </item>
    
    <item>
      <title>Tshark performance problem</title>
      <link>/questions/19433/tshark-performance-problem/</link>
      <pubDate>Wed, 13 Mar 2013 02:32:00 +0000</pubDate>
      
      <guid>/questions/19433/tshark-performance-problem/</guid>
      <description>Tshark performance problem  0 I execute tshark command. Process is too slow. Sometimes take more than 6-7 seconds. Pcap file is really small (~500bytes). Actually strange thing is that re-execute same command consequently, process duration is decreasing dramatically (about 1 second). After wait for a while (without execution command), re-run same command and process completion duration increase again. Why process behave like that? How to solve this problem?
Command :</description>
    </item>
    
    <item>
      <title>RTP Multiplex dissector</title>
      <link>/questions/19435/rtp-multiplex-dissector/</link>
      <pubDate>Wed, 13 Mar 2013 02:48:00 +0000</pubDate>
      
      <guid>/questions/19435/rtp-multiplex-dissector/</guid>
      <description>RTP Multiplex dissector  0 Hello guys,
I need to decode RTP Multiplex streams using Wireshark. Presently we can decode only Non -Multiplexed RTP streams in wireshark.
Also I need to know the steps to add dissector in Wireshark.
Thanks// Vikas
ipmuxasked 13 Mar &#39;13, 02:48
Viki
11●2●2●4
accept rate: 0%
  
2 Answers:
  
2See the source code section of http://wiki.wireshark.org/SendingFilesToWireshark?highlight=%28submit%29
answered 13 Mar &#39;13, 05:30</description>
    </item>
    
    <item>
      <title>QtShark (wireshark-qt) doesn&amp;#x27;t use the saved preferences</title>
      <link>/questions/19446/qtshark-wireshark-qt-doesnt-use-the-saved-preferences/</link>
      <pubDate>Wed, 13 Mar 2013 06:29:00 +0000</pubDate>
      
      <guid>/questions/19446/qtshark-wireshark-qt-doesnt-use-the-saved-preferences/</guid>
      <description>QtShark (wireshark-qt) doesn&amp;rsquo;t use the saved preferences  0 QtShark doesn&#39;t use the preferences I set.
The preferences file gets altered when using the preferences gui, but the values are completely ignored.
Manually editing the file doesn&#39;t work either.
[email protected]:~$ qtshark FIX: packet list heading menu sensitivity /usr/local/lib/libwireshark.so.0: undefined symbol: py_create_dissector_handle 14:25:21.435 Dbg plugin_dir: /usr/local/lib/wireshark/plugins/1.9.2-SVN-48274 14:25:21.473 Dbg FIX: timestamp types should be set elsewhere 14:25:21.473 Capture Msg Capture Interface List .</description>
    </item>
    
    <item>
      <title>KNXnet/IP plugin error</title>
      <link>/questions/19459/knxnetip-plugin-error/</link>
      <pubDate>Wed, 13 Mar 2013 10:04:00 +0000</pubDate>
      
      <guid>/questions/19459/knxnetip-plugin-error/</guid>
      <description>KNXnet/IP plugin error  0 Hi, I&#39;m using Wireshark on a Win 8 OS to check the datagrams of a KNX software, and also using a .dll plugin already developed and distributed by http://knxnetipdissect.sourceforge.net/
But I haven&#39;t get it to work fine. I&#39;ve installed 64 and 32 bit version, and applying the compatibility to Win 7 and it&#39;s still not working.
The site says that I should copy the plugin to the Plugin folder inside the Wireshark folder from windows.</description>
    </item>
    
    <item>
      <title>Can wireshark display preamble?</title>
      <link>/questions/19463/can-wireshark-display-preamble/</link>
      <pubDate>Wed, 13 Mar 2013 10:52:00 +0000</pubDate>
      
      <guid>/questions/19463/can-wireshark-display-preamble/</guid>
      <description>Can wireshark display preamble?  0 Suppose I have a list of packets which will be written as PCAP file. The packets contains 8 bytes preamble. Currently I don&#39;t write those 8 bytes to the PCAP. I am just wondering if it is possible to write preamble to the PCAP?
Thanks.
preambleasked 13 Mar &#39;13, 10:52
kintaro
6●2●2●4
accept rate: 0%
  
2 Answers:
  
1 Note there&#39;s a link type which has all this included: LINKTYPE_NETANALYZER_TRANSPARENT, see the TCP dump site.</description>
    </item>
    
    <item>
      <title>Need a 100 mb hub non switched</title>
      <link>/questions/19475/need-a-100-mb-hub-non-switched/</link>
      <pubDate>Wed, 13 Mar 2013 14:30:00 +0000</pubDate>
      
      <guid>/questions/19475/need-a-100-mb-hub-non-switched/</guid>
      <description>Need a 100 mb hub non switched  0 I need to monitor a PBX for SIP traffic and do not have a monitor port. The switch will only run at 100 mb. Netgear makes a 10/100 hub the ds104 or ds108. Will this work? It appears to be un switched? Has anyone else found a 100 mb hub that did work?
sipasked 13 Mar &#39;13, 14:30
mserino
11●2●2●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Only seeing RTS/CTS frames to/from Android Phone &amp;amp; AP</title>
      <link>/questions/19480/only-seeing-rtscts-frames-tofrom-android-phone-ap/</link>
      <pubDate>Wed, 13 Mar 2013 16:14:00 +0000</pubDate>
      
      <guid>/questions/19480/only-seeing-rtscts-frames-tofrom-android-phone-ap/</guid>
      <description>Only seeing RTS/CTS frames to/from Android Phone &amp;amp; AP  0 Hi everyone,
I&#39;m stuck here. Trying to sniff packets to/from a phone whose WiFi is associated to my AP using a laptop with Wireshark associated on the same network.
I&#39;ve configured Wireshark with my AP&#39;s WPA password/SSID, and I can even see the 4 Key messages passed between my phone&#39;s WiFi and the AP. However, from that point on, I only see &#34;</description>
    </item>
    
    <item>
      <title>how can we ignore many packets in one go</title>
      <link>/questions/19486/how-can-we-ignore-many-packets-in-one-go/</link>
      <pubDate>Wed, 13 Mar 2013 22:15:00 +0000</pubDate>
      
      <guid>/questions/19486/how-can-we-ignore-many-packets-in-one-go/</guid>
      <description>how can we ignore many packets in one go  0 1I mean we have to select one packet then right click and select ignore packet
how can we select lets say 20 questions and ignore those ?
wiresharkasked 13 Mar &#39;13, 22:15
m_1607
35●12●13●16
accept rate: 0%
  
One Answer:
  
1 Specify a display filter matching the packets you want to ignore and apply that.</description>
    </item>
    
    <item>
      <title>Why was the IP fragment size required to be a multiple of 8 bytes?</title>
      <link>/questions/19489/why-was-the-ip-fragment-size-required-to-be-a-multiple-of-8-bytes/</link>
      <pubDate>Thu, 14 Mar 2013 00:29:00 +0000</pubDate>
      
      <guid>/questions/19489/why-was-the-ip-fragment-size-required-to-be-a-multiple-of-8-bytes/</guid>
      <description>Why was the IP fragment size required to be a multiple of 8 bytes?  1 In order to calculate Fragment Offset we need to divide the data block by 8.
How we landed up on the digit 8?
Is it total length of packet &amp;lt;2 to the power 16&amp;gt; (divided by) fragment offset &amp;lt;2 to the power 13&amp;gt; gives us 8
(or)
Is it 2 to the power 16(total packet length) divided by 8 gives 2 to the power 13(fragment offset length)</description>
    </item>
    
    <item>
      <title>How do I create filter for dropped packets and display results</title>
      <link>/questions/19491/how-do-i-create-filter-for-dropped-packets-and-display-results/</link>
      <pubDate>Thu, 14 Mar 2013 02:04:00 +0000</pubDate>
      
      <guid>/questions/19491/how-do-i-create-filter-for-dropped-packets-and-display-results/</guid>
      <description>How do I create filter for dropped packets and display results  0 I am trying to isolate faulty equipment in a network. My idea is that if I can measure dropped packets between various components on the network I can ultimately isolate the bad component by narrowing the beginning and end points of the analysis.
What I don&#39;t understand is how to &#34;append a filter to a conversation&#34;. There is an answered question about how to create the filter in your database but I can&#39;t figure out how to append a filter to a particular conversation.</description>
    </item>
    
    <item>
      <title>bash not recognized</title>
      <link>/questions/19494/bash-not-recognized/</link>
      <pubDate>Thu, 14 Mar 2013 04:59:00 +0000</pubDate>
      
      <guid>/questions/19494/bash-not-recognized/</guid>
      <description>bash not recognized  0 hi,while following the step by step guide for build environment,i get this error:
c:\wireshark&amp;gt; nmake -f Makefile.nmake verify_tools Microsoft (R) Program Maintenance Utility Version 10.00.30319.01 Copyright (C) Microsoft Corporation. All rights reserved.
&#39;bash&#39; is not recognized as an internal or external command, operable program or batch file. &#39;bash&#39; is not recognized as an internal or external command, operable program or batch file. NMAKE : fatal error U1077: &#39;bash&#39; : return code &#39;0x1&#39; Stop.</description>
    </item>
    
    <item>
      <title>How Wireshark plots TCP throughput graph?</title>
      <link>/questions/19496/how-wireshark-plots-tcp-throughput-graph/</link>
      <pubDate>Thu, 14 Mar 2013 05:18:00 +0000</pubDate>
      
      <guid>/questions/19496/how-wireshark-plots-tcp-throughput-graph/</guid>
      <description>How Wireshark plots TCP throughput graph?  1 Dear wireshark experts, could you help me to understand one thing? I did perfomance test with iperf. During test I collected dump on iperf client side. My question is: Which formula is used by Wireshark for creating TCP throughput graph? According to wireshark, avarege RTT value of TCP stream is 0,04 sec and TCP window (on server) is stable and equal 2048K bytes But in this case Bandwidth of TCP stream should be around 400 Mbps (TCPwindow / RTT).</description>
    </item>
    
    <item>
      <title>Using Wireshark to sniff local ODBC driver activity</title>
      <link>/questions/19509/using-wireshark-to-sniff-local-odbc-driver-activity/</link>
      <pubDate>Thu, 14 Mar 2013 08:03:00 +0000</pubDate>
      
      <guid>/questions/19509/using-wireshark-to-sniff-local-odbc-driver-activity/</guid>
      <description>Using Wireshark to sniff local ODBC driver activity  0 Hello I am not satisfied with the ODBC driver embedded tracing tool in the ODBC manager of Windows 7 and was wondering how I could use Wireshark to monitor the activity over ODBC drivers? I read that some of you did use it but I was not able to monitor anything related to this kind of traffic. I am using Windows 7 and my ODBC client and database (Mysql or SQLserver Express) are on the same PC.</description>
    </item>
    
    <item>
      <title>Only SYN packets(outgoing) captures</title>
      <link>/questions/19511/only-syn-packetsoutgoing-captures/</link>
      <pubDate>Thu, 14 Mar 2013 08:28:00 +0000</pubDate>
      
      <guid>/questions/19511/only-syn-packetsoutgoing-captures/</guid>
      <description>Only SYN packets(outgoing) captures  0 Hi all, i am using Wireshark 1.8, and the problem is that, i am unable to capture the packets other than SYN. that is i am sure the connectivity is working fine, i can use HTTp web pages also, but while capturing i am only getting the SYN packet. nothing else. i am using 2950 cisco switch. Then i tried to run Wireshark for the interface in my PC, without using monitoring configurations in the switch, then i am able to see all the packets.</description>
    </item>
    
    <item>
      <title>How can i capture and play back thick windows client  server interactions</title>
      <link>/questions/19522/how-can-i-capture-and-play-back-thick-windows-client-server-interactions/</link>
      <pubDate>Thu, 14 Mar 2013 15:43:00 +0000</pubDate>
      
      <guid>/questions/19522/how-can-i-capture-and-play-back-thick-windows-client-server-interactions/</guid>
      <description>How can i capture and play back thick windows client server interactions  0 Hi All I am not a networking nerd. But I am trying to capture and play back thick windows client &amp;lt;--&amp;gt; server interactions.(TCP/IP and ODBC).
Basically i want to capture client server interactions and use them to play back within multiple threads to simulate concurrent user sessions of the client server interaction.
Is it possible to use wireshark for this?</description>
    </item>
    
    <item>
      <title>Can Wireshark monitor database request and response times?</title>
      <link>/questions/19524/can-wireshark-monitor-database-request-and-response-times/</link>
      <pubDate>Thu, 14 Mar 2013 21:45:00 +0000</pubDate>
      
      <guid>/questions/19524/can-wireshark-monitor-database-request-and-response-times/</guid>
      <description>Can Wireshark monitor database request and response times?  0 Hi All,
I have an application written in &#34;Progress-4GL&#34;. It gets connected to Progress DB whenever a request is raised through the application. I want to do performance testing on this request response chain. Performance in the sense, if 10 users are accessing the DB then what will be the throughput. If the number of users is increased to 50 then what will be the throughput.</description>
    </item>
    
    <item>
      <title>how to apply a capture filter?</title>
      <link>/questions/19526/how-to-apply-a-capture-filter/</link>
      <pubDate>Thu, 14 Mar 2013 23:11:00 +0000</pubDate>
      
      <guid>/questions/19526/how-to-apply-a-capture-filter/</guid>
      <description>how to apply a capture filter?  1 Hi, in the latest version : 1.8.6 I can create a capture filter (Capture --&amp;gt; Capture filter --&amp;gt; new) : port 516 but how can I apply this capture filter. when I start capture, there are not any options to select the filter. and it will capture all the packets
using the old version, it can select capture filter.
apply capture-filterasked 14 Mar &#39;13, 23:11</description>
    </item>
    
    <item>
      <title>[closed] RTP Multiplexing Plugin</title>
      <link>/questions/19527/rtp-multiplexing-plugin/</link>
      <pubDate>Fri, 15 Mar 2013 00:28:00 +0000</pubDate>
      
      <guid>/questions/19527/rtp-multiplexing-plugin/</guid>
      <description>[closed] RTP Multiplexing Plugin  0 Hi Expert,
I am not a very experienced user of wireshark yet.I need to decode RTP Multiplex streams using Wireshark. As i understand wireshark not able to decode RTP Multiplexing packets,To decode RTP Multiplexing packet we need to load some dissector. So can you please let me know step by step how to load new plugin in wireshark for RTP multiplexing as i m not a coding software engineer.</description>
    </item>
    
    <item>
      <title>Lot of traffic to 173.194.41.67</title>
      <link>/questions/19537/lot-of-traffic-to-1731944167/</link>
      <pubDate>Fri, 15 Mar 2013 06:12:00 +0000</pubDate>
      
      <guid>/questions/19537/lot-of-traffic-to-1731944167/</guid>
      <description>Lot of traffic to 173.194.41.67  0 I am running wireshark on my laptop and am seeing a lot of traffic going to and from the above IP address.
It all follows roughly the same format
cadsi-lm &amp;gt; https [ACK] SEQ = 2063 ACK= 4052 WIN=65740 LEN = 0 atex-elmd &amp;gt; https [ACK] SEQ = 2063 ACK= 4052 WIN=65740 LEN = 0 f-ser &amp;gt; https [ACK] SEQ = 2063 ACK= 4052 WIN=65740 LEN = 0 cad-key &amp;gt; https [ACK] SEQ = 2063 ACK= 4052 WIN=65740 LEN = 0 iclpv-pm&amp;gt; https [ACK] SEQ = 2063 ACK= 4052 WIN=65740 LEN = 0 cichlid &amp;gt; https [ACK] SEQ = 2063 ACK= 4052 WIN=65740 LEN = 0 molly &amp;gt; https [ACK] SEQ = 2063 ACK= 4052 WIN=65740 LEN = 0so on and so forth - there seems to be slight variations in the IP address</description>
    </item>
    
    <item>
      <title>editcap behavior confirmation</title>
      <link>/questions/19542/editcap-behavior-confirmation/</link>
      <pubDate>Fri, 15 Mar 2013 11:19:00 +0000</pubDate>
      
      <guid>/questions/19542/editcap-behavior-confirmation/</guid>
      <description>editcap behavior confirmation  0 Hi all,
Got a packet capture with 10 packets and the time interval between 1st and last packet is 2.315 seconds.
Time stamps of 10 packets respectively {51.770989000;51.771761000;51.771783000;51.771880000;51.774776000;51.774966000; 51.774985000;51.775097000;54.085199000;54.085748000}
Now, I gave the following editcap command which creates trace files with 1 second worth of capture.
editcap -i 1 padding.pcap 1_padding.pcapng
This command created 3 trace files and the second trace file is having 0 packets.</description>
    </item>
    
    <item>
      <title>Automatically showing replies for DIAMETER protocol, when using display filter</title>
      <link>/questions/19543/automatically-showing-replies-for-diameter-protocol-when-using-display-filter/</link>
      <pubDate>Fri, 15 Mar 2013 13:17:00 +0000</pubDate>
      
      <guid>/questions/19543/automatically-showing-replies-for-diameter-protocol-when-using-display-filter/</guid>
      <description>Automatically showing replies for DIAMETER protocol, when using display filter  0 When analyzing a large packet capture of DIAMETER traffic, I often filter based on a certain value. Is there any way to automatically show the replies to the packets matching the display filter? Currently I have to select each packet, and then add the frame number to the display filter. It&#39;s very tedious.
For example, my display filter will be something like &#34;</description>
    </item>
    
    <item>
      <title>Installation network stack changes</title>
      <link>/questions/19545/installation-network-stack-changes/</link>
      <pubDate>Fri, 15 Mar 2013 14:15:00 +0000</pubDate>
      
      <guid>/questions/19545/installation-network-stack-changes/</guid>
      <description>Installation network stack changes  0 I am seeing Network Stack differences on a mac Mini OS X Mountain Lion after installing WireShark.
What does Wireshark change in the system that might also effect my applications. Default socket buffer sizes? or something like that?
What I saw before installing Wireshark were errors in a TCP/IP connection under heavy load ( maxing out the 100MB switch between the two machines ).</description>
    </item>
    
    <item>
      <title>Language/framework to analyze or categorize capture results?</title>
      <link>/questions/19551/languageframework-to-analyze-or-categorize-capture-results/</link>
      <pubDate>Fri, 15 Mar 2013 21:54:00 +0000</pubDate>
      
      <guid>/questions/19551/languageframework-to-analyze-or-categorize-capture-results/</guid>
      <description>Language/framework to analyze or categorize capture results?  0 I am attempting to analyze capture results obtained from running a single application once using HTTP Ajax polling (comet) and once using Websockets. I would like to determine the difference in overhead between the two (so things like HTTP headers or resending requests, handshakes, etc.).
What would be the best way to approach this? I was thinking that using a scripting language with a framework that understands the libpcap format (such as Python/scapy).</description>
    </item>
    
    <item>
      <title>t-shark throwing error message:CaptureChild-WARNING</title>
      <link>/questions/19552/t-shark-throwing-error-messagecapturechild-warning/</link>
      <pubDate>Fri, 15 Mar 2013 22:36:00 +0000</pubDate>
      
      <guid>/questions/19552/t-shark-throwing-error-messagecapturechild-warning/</guid>
      <description>t-shark throwing error message:CaptureChild-WARNING  0 Hi all,
I tried executing the command tshark -qz hosts to retrieve all the IPtoHOST pertaining to a particular web click.
I got the information i am looking for and at the same time i am seeing following error message:
(tshark.exe:1204): CaptureChild-WARNING : sync_pipe_stop: forcing child to exit**
If possible please let me know the reason behind this error message.
tsharkasked 15 Mar &#39;13, 22:36</description>
    </item>
    
    <item>
      <title>dissecting PPP compressed packets to discover rtsp address</title>
      <link>/questions/19554/dissecting-ppp-compressed-packets-to-discover-rtsp-address/</link>
      <pubDate>Sat, 16 Mar 2013 03:17:00 +0000</pubDate>
      
      <guid>/questions/19554/dissecting-ppp-compressed-packets-to-discover-rtsp-address/</guid>
      <description>dissecting PPP compressed packets to discover rtsp address  0 Hi there I&#39;m trying to find the rtsp URL for a video using Wireshark. I am only able to connect to the site and play the video using a VPN. I start Wireshark sniffing on wlan0 and when I stop the capture and sort the captured packets by protocol, I don&#39;t see any that are listed RTSP. However, there are a whole heap of PPP compressed datagrams.</description>
    </item>
    
    <item>
      <title>Trying to capture traffic over local fiber metro e circuit?</title>
      <link>/questions/19557/trying-to-capture-traffic-over-local-fiber-metro-e-circuit/</link>
      <pubDate>Sat, 16 Mar 2013 09:44:00 +0000</pubDate>
      
      <guid>/questions/19557/trying-to-capture-traffic-over-local-fiber-metro-e-circuit/</guid>
      <description>Trying to capture traffic over local fiber metro e circuit?  0 Hello - we are trying to capture traffic that passes over a Metro E circuit that connects two local offices on seperate networks (office1 is 192.168.1.xx and office2 is 192.168.10.xx). The Metro E circuit connects to an interface/port on a SonicWall router at each of the two respective locations.
We would like to configure Wireshark to capture packets over a 24 hour period of time so we can identify what IP addresses are generating the large intermittent packet fluctuations which are travelling over this Metro E circuit and exceed the designated bandwidth of the circuit.</description>
    </item>
    
    <item>
      <title>Error while make</title>
      <link>/questions/19558/error-while-make/</link>
      <pubDate>Sat, 16 Mar 2013 09:51:00 +0000</pubDate>
      
      <guid>/questions/19558/error-while-make/</guid>
      <description>Error while make  0 Hello! I run ./configure and all seems ok. When run &#34;make&#34; i get the following error:
In file included from airpcap_dlg.c:44:0: ../../pcap.h:276:7: error: conflicting types for ‘bpf_filter’ /usr/local/include/pcap/bpf.h:1274:14: note: previous declaration of ‘bpf_filter’ was here ../../pcap.h:277:5: error: conflicting types for ‘bpf_validate’ /usr/local/include/pcap/bpf.h:1273:12: note: previous declaration of ‘bpf_validate’ was here airpcap_dlg.c: In function ‘on_merge_bt_clicked’: airpcap_dlg.c:2406:11: warning: variable ‘n_curr_adapter_keys’ set but not used [-Wunused-but-set-variable] airpcap_dlg.c:2405:11: warning: variable ‘n_driver_keys’ set but not used [-Wunused-but-set-variable] airpcap_dlg.</description>
    </item>
    
    <item>
      <title>Pause frame flood</title>
      <link>/questions/19559/pause-frame-flood/</link>
      <pubDate>Sat, 16 Mar 2013 09:52:00 +0000</pubDate>
      
      <guid>/questions/19559/pause-frame-flood/</guid>
      <description>Pause frame flood  0 Every couple of weeks our network gets hit by a pause frame flood that effectively brings down our entire network. This has happened at least five times now since I started my new job as sole IT-technician at a manufacturing plant. Our network is entirely made up of dumb L2 switches so locating the offending device has proven to be tricky.
So far I have only managed to find which port on our central patch panel the packet are coming from, .</description>
    </item>
    
    <item>
      <title>Is it possible to find the names of local Wi-Fi devices?</title>
      <link>/questions/19569/is-it-possible-to-find-the-names-of-local-wi-fi-devices/</link>
      <pubDate>Sat, 16 Mar 2013 12:59:00 +0000</pubDate>
      
      <guid>/questions/19569/is-it-possible-to-find-the-names-of-local-wi-fi-devices/</guid>
      <description>Is it possible to find the names of local Wi-Fi devices?  0 Hi I want to know if it possible to find wireless devices like cellphones which are not connected or connected to an access point(it means i want name of devices which are On but not connected) and also distinguish between them by ssid or name of device or etc. Can i do this and what is requirements for this if answer is yes?</description>
    </item>
    
    <item>
      <title>SSL decryption log file</title>
      <link>/questions/19570/ssl-decryption-log-file/</link>
      <pubDate>Sat, 16 Mar 2013 13:34:00 +0000</pubDate>
      
      <guid>/questions/19570/ssl-decryption-log-file/</guid>
      <description>SSL decryption log file  0 I&#39;m totally new to Wireshark, and I don&#39;t know much about network protocols in general. Here&#39;s my situation: I&#39;m trying to decrypt an SSL packet capture session. The traffic I&#39;m trying to decrypt comes from the internet, and goes to an application running on my PC. I&#39;ve found a number of different private keys and certificate files in the application directory, and I&#39;m not really sure which one would be the right one to use, but that&#39;s kind of beside the point right now.</description>
    </item>
    
    <item>
      <title>Default profile</title>
      <link>/questions/19575/default-profile/</link>
      <pubDate>Sat, 16 Mar 2013 15:50:00 +0000</pubDate>
      
      <guid>/questions/19575/default-profile/</guid>
      <description>Default profile  0 Is there a way to set the Wireshark default profile back to its defaults?
Thanks.
Owen
default profileasked 16 Mar &#39;13, 15:50
Owen
21●3●3●6
accept rate: 0%
In the upcoming version 2.4 it&#39;s possible to reset the Default profile by &#34;Removing&#34; the profile in the &#34;Configuration Profiles&#34; dialog.
(14 Feb &#39;17, 12:44) stig ♦  
One Answer:
  
4 The preferences that constitute your default profile consist of a series of files, as do all profiles.</description>
    </item>
    
    <item>
      <title>Newbie : Testing a port using Portqry.exe and Wireshark</title>
      <link>/questions/19583/newbie-testing-a-port-using-portqryexe-and-wireshark/</link>
      <pubDate>Sun, 17 Mar 2013 00:05:00 +0000</pubDate>
      
      <guid>/questions/19583/newbie-testing-a-port-using-portqryexe-and-wireshark/</guid>
      <description>Newbie : Testing a port using Portqry.exe and Wireshark  0 Hello All,
I am a newbie in networking and wireshark.
To test a port, I am using portqry.exe on a sender server and capturing packets on the receving PC.
Please advise if my suspicion of a network issue is reasonable. Thanks.
portqry.exe -n 10.20.30.40 -e 68 -p udp -sp 4011 - I understand portqry sends a dummy packet to host (-n) at port (-e) from port(-sp) using protocol (-p) - 10.</description>
    </item>
    
    <item>
      <title>SSL decryption mystery</title>
      <link>/questions/19588/ssl-decryption-mystery/</link>
      <pubDate>Sun, 17 Mar 2013 09:02:00 +0000</pubDate>
      
      <guid>/questions/19588/ssl-decryption-mystery/</guid>
      <description>SSL decryption mystery  0 I&#39;m trying to decrypt SSL packets that are coming from the internet to an application in Windows, and I can&#39;t get the decryption to work. Below are the things that I&#39;ve checked out (thanks again to Sake Blok&#39;s presentation for giving me these ideas):
--I may be wrong about this, but I believe that the cipher selected by the server is not Diffie-Hellman based. From the server hello, the cipher is TLS_RSA_WITH_AES_128_CBC_SHA.</description>
    </item>
    
    <item>
      <title>how to find out application layer protocols ?</title>
      <link>/questions/19597/how-to-find-out-application-layer-protocols/</link>
      <pubDate>Sun, 17 Mar 2013 14:46:00 +0000</pubDate>
      
      <guid>/questions/19597/how-to-find-out-application-layer-protocols/</guid>
      <description>how to find out application layer protocols ?  0 hie i am new to use wireshark can any one help me in finding these ans
how to find out application layer protocols among tcp packets in the capture?? why does other protocols listed in the tcp protocol list??
wiresharkasked 17 Mar &#39;13, 14:46
arajai
1●1●1●1
accept rate: 0%
  
One Answer:
  
1you can go to Menu and click</description>
    </item>
    
    <item>
      <title>how to get source code</title>
      <link>/questions/19600/how-to-get-source-code/</link>
      <pubDate>Sun, 17 Mar 2013 19:23:00 +0000</pubDate>
      
      <guid>/questions/19600/how-to-get-source-code/</guid>
      <description>how to get source code  0 I work in a classified computer area and we cannot install software that is not on the list of authorized software. If I can get source code then I can build and run the code. I tried this page: http://www.wireshark.org/download.html# but nothing there will download the source code. How do I get a copy of the source code. Windows 7. Visual Studio if possible.</description>
    </item>
    
    <item>
      <title>throughput measurement, graph</title>
      <link>/questions/19617/throughput-measurement-graph/</link>
      <pubDate>Mon, 18 Mar 2013 07:14:00 +0000</pubDate>
      
      <guid>/questions/19617/throughput-measurement-graph/</guid>
      <description>throughput measurement, graph  0 Hi, Im currently working on my Bachelor theses, and have a problem. The goal is to show differences among TCP variants. As far as know, the biggest difference is based on Congestion Avoidance, which Id like to demonstrate by unplugging one site of the communication and than take a look at how quickly those different TCP types can recover from that &#34;disconnection&#34;. To determine that, i need a very exact output (graph) that would show that.</description>
    </item>
    
    <item>
      <title>I can&amp;#x27;t saved a filter capture; save as option is gray out?</title>
      <link>/questions/19623/i-cant-saved-a-filter-capture-save-as-option-is-gray-out/</link>
      <pubDate>Mon, 18 Mar 2013 12:35:00 +0000</pubDate>
      
      <guid>/questions/19623/i-cant-saved-a-filter-capture-save-as-option-is-gray-out/</guid>
      <description>I can&amp;rsquo;t saved a filter capture; save as option is gray out?  0 Hello
I&#39;m having troubleshoot saving this capture, I applied the filter wlan.addr == 30:F7:0D:4C:FB:9F and then save as to save only the displayed packets, but the option is gray out. I tried editcap, but I wasn&#39;t able to save it either.
Any help is very much appreciated.
Thanks.
filesave capture-filterasked 18 Mar &#39;13, 12:35
wil1323
6●2●2●5</description>
    </item>
    
    <item>
      <title>PC randomly responds to other devices packets with an &amp;quot;ICMP redirect&amp;quot;</title>
      <link>/questions/19629/pc-randomly-responds-to-other-devices-packets-with-an-icmp-redirect/</link>
      <pubDate>Mon, 18 Mar 2013 21:22:00 +0000</pubDate>
      
      <guid>/questions/19629/pc-randomly-responds-to-other-devices-packets-with-an-icmp-redirect/</guid>
      <description>PC randomly responds to other devices packets with an &amp;ldquo;ICMP redirect&amp;rdquo;  0 I have an HP laptop that I use for Wireshark that randomly responds to packets for other devices with ICMP redirects. It only happens when Wireshark is running. I used another Wireshark PC to capture it coming from the HP PC. The redirects even indicate the correct IP and MAC destination in the packet. It just feels like telling the originator he was right, but send it again.</description>
    </item>
    
    <item>
      <title>how to find missing http response</title>
      <link>/questions/19632/how-to-find-missing-http-response/</link>
      <pubDate>Mon, 18 Mar 2013 23:27:00 +0000</pubDate>
      
      <guid>/questions/19632/how-to-find-missing-http-response/</guid>
      <description>how to find missing http response  0 Hello i have cap file so how can find those packets which response didn&#39;t came.
Thanks
Regards Mudasser
missing http response findasked 18 Mar &#39;13, 23:27
togreatmind
1●2●3●4
accept rate: 0%
 edited 19 Mar &#39;13, 10:08 
grahamb ♦
19.8k●3●30●206
  
2 Answers:
  
0What protocol you are looking at to find missing response?
If it is to find missing HTTP response packets for HTTP requests</description>
    </item>
    
    <item>
      <title>how to filter RTP packet of a single call in wireshark ?</title>
      <link>/questions/19636/how-to-filter-rtp-packet-of-a-single-call-in-wireshark/</link>
      <pubDate>Tue, 19 Mar 2013 00:25:00 +0000</pubDate>
      
      <guid>/questions/19636/how-to-filter-rtp-packet-of-a-single-call-in-wireshark/</guid>
      <description>how to filter RTP packet of a single call in wireshark ?  0 how to filter RTP packet of a single call in wireshark ?
filterasked 19 Mar &#39;13, 00:25
archu
11●4●4●7
accept rate: 0%
  
2 Answers:
  
0Find the setup information (SDP?) and filter on IP/port combination.
answered 19 Mar &#39;13, 02:41
Anders ♦
4.6k●9●52
accept rate: 17%
  
0Go to Telephony---&amp;gt;Voip calls.</description>
    </item>
    
    <item>
      <title>Wireshark shows duplicates of each Uplink frame (but not DL)</title>
      <link>/questions/19639/wireshark-shows-duplicates-of-each-uplink-frame-but-not-dl/</link>
      <pubDate>Tue, 19 Mar 2013 05:40:00 +0000</pubDate>
      
      <guid>/questions/19639/wireshark-shows-duplicates-of-each-uplink-frame-but-not-dl/</guid>
      <description>Wireshark shows duplicates of each Uplink frame (but not DL)  0 Sending TCP DL (iperf) traffic from a network server to an IBM Thinkpad running wireshark 1.8.6.
DL traffic looks normal, but each UL packet (whether Syn or ACK) sourced from the laptop pc appears twice in wireshark (same TCP sequence number and same IP ID), but typically 20-30 microseconds difference in time stamps.
The tester is remote, so I haven&#39;t been able to physically inspect his computer, but I do not see this on any other computers.</description>
    </item>
    
    <item>
      <title>Decoding of EGD (Ethernet Global Data)</title>
      <link>/questions/19645/decoding-of-egd-ethernet-global-data/</link>
      <pubDate>Tue, 19 Mar 2013 07:44:00 +0000</pubDate>
      
      <guid>/questions/19645/decoding-of-egd-ethernet-global-data/</guid>
      <description>Decoding of EGD (Ethernet Global Data)  0 I have a couple of addresses in a PLC that I am writing to and reading from over Modbus TCP. However, the data itself is being sent on EGD. When I apply the filter for showing EGD, I can see the data packet (usually 88 bytes long) but I cannot make out anything of the content. Is there a way to dissect the contents of the data packet and verify that data I send from my system is actually being sent correctly by reading the contents of the data packet?</description>
    </item>
    
    <item>
      <title>Large number of TCP RST</title>
      <link>/questions/19653/large-number-of-tcp-rst/</link>
      <pubDate>Tue, 19 Mar 2013 10:03:00 +0000</pubDate>
      
      <guid>/questions/19653/large-number-of-tcp-rst/</guid>
      <description>Large number of TCP RST  0 I&#39;m seeing a large number of tcp rst and am not quite sure what is causing it. I would appreciate any help. Below is that capture.
No. Time Source Destination Protocol Length Info 2939 2013-03-15 15:40:40.304765 10.1.4.2 208.89.168.x TCP 60 50090 &amp;gt; Frame 2939: 60 bytes on wire (480 bits), 60 bytes captured (480 bits) WTAP_ENCAP: 1 Arrival Time: Mar 15, 2013 15:40:40.304765000 Mountain Daylight Time [Time shift for this packet: 0.</description>
    </item>
    
    <item>
      <title>The US$ 100 challenge: WPA2 decryption</title>
      <link>/questions/19664/the-us-100-challenge-wpa2-decryption/</link>
      <pubDate>Tue, 19 Mar 2013 17:49:00 +0000</pubDate>
      
      <guid>/questions/19664/the-us-100-challenge-wpa2-decryption/</guid>
      <description>The US$ 100 challenge: WPA2 decryption  0 The US$ 100 challenge: WPA2 decryption
The first person who solve successfully and post here the solution of my problem becomes US$ 100. What you have to solve: I have many encrypted WPA2 WiFi sniffed in a pcap file with the 4-way handshake, and I know the SSID and WPA2 Key. I like to convert the WPA2 pcap file to a decrypted pcap file with all protocols decrypted.</description>
    </item>
    
    <item>
      <title>Retransmission on LAN</title>
      <link>/questions/19665/retransmission-on-lan/</link>
      <pubDate>Tue, 19 Mar 2013 21:28:00 +0000</pubDate>
      
      <guid>/questions/19665/retransmission-on-lan/</guid>
      <description>Retransmission on LAN  0 Hi All,
I am new with Wireshark. I did test via my LAN and get the result like the data below : ****************************************************************************************** 1 2013-03-20 03:55:50.803 172.17.3.41 172.17.3.61 TCP 66 51844 &amp;gt; ssh [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1 2 2013-03-20 03:55:50.804 172.17.3.61 172.17.3.41 TCP 66 ssh &amp;gt; 51844 [SYN, ACK] Seq=0 Ack=1 Win=14600 Len=0 MSS=1460 SACK_PERM=1 WS=64 3 2013-03-20 03:55:50.804 172.17.3.41 172.17.3.61 TCP 54 51844 &amp;gt; ssh [ACK] Seq=1 Ack=1 Win=65536 Len=0 4 2013-03-20 03:55:50.</description>
    </item>
    
    <item>
      <title>Wireshark capture packets from one AP</title>
      <link>/questions/19669/wireshark-capture-packets-from-one-ap/</link>
      <pubDate>Wed, 20 Mar 2013 03:25:00 +0000</pubDate>
      
      <guid>/questions/19669/wireshark-capture-packets-from-one-ap/</guid>
      <description>Wireshark capture packets from one AP  0 I want to capture packets from a specific AP. How can I do that in Wireshark? I also want to get the RSSI values. I am new to wireshark, please guide me
capture accesspoint wiresharkasked 20 Mar &#39;13, 03:25
ships
1●1●1●1
accept rate: 0%
  
One Answer:
  
0You might consider using &#39;airodump-ng&#39; (http://www.aircrack-ng.org/doku.php?id=airodump-ng) instead of wireshark for capturing wireless-traffic.</description>
    </item>
    
    <item>
      <title>Can you tell us what is the use of voice initial playout buffer delay?</title>
      <link>/questions/19671/can-you-tell-us-what-is-the-use-of-voice-initial-playout-buffer-delay/</link>
      <pubDate>Wed, 20 Mar 2013 04:35:00 +0000</pubDate>
      
      <guid>/questions/19671/can-you-tell-us-what-is-the-use-of-voice-initial-playout-buffer-delay/</guid>
      <description>Can you tell us what is the use of voice initial playout buffer delay?  0 Can you tell us what is the use of voice initial playout buffer delay?
bufferasked 20 Mar &#39;13, 04:35
archu
11●4●4●7
accept rate: 0%
 edited 20 Mar &#39;13, 04:36 
  
One Answer:
  
0It determines how long speech data is hold up before playout commences. This allows for speech packets to arrive &#39;late&#39; without interfering with the playout of the speech, resulting in a better listening experience.</description>
    </item>
    
    <item>
      <title>How to show real-time packet in terminal?</title>
      <link>/questions/19674/how-to-show-real-time-packet-in-terminal/</link>
      <pubDate>Wed, 20 Mar 2013 06:18:00 +0000</pubDate>
      
      <guid>/questions/19674/how-to-show-real-time-packet-in-terminal/</guid>
      <description>How to show real-time packet in terminal?  0 Hi all,
I just installed wireshark on my ubuntu 12.04. Is it possible to see the real-time packet in terminal rather than in the GUI?
I did &#34;[email protected]:~$ sudo wireshark -i eth0 -S -l -k&#34;, but it opened a wireshark GUI and begin to capture and show all the packets in the GUI, but I want the packets also show up in the terminal.</description>
    </item>
    
    <item>
      <title>error when running wireshark on Ubuntu as non root user</title>
      <link>/questions/19675/error-when-running-wireshark-on-ubuntu-as-non-root-user/</link>
      <pubDate>Wed, 20 Mar 2013 06:26:00 +0000</pubDate>
      
      <guid>/questions/19675/error-when-running-wireshark-on-ubuntu-as-non-root-user/</guid>
      <description>error when running wireshark on Ubuntu as non root user  0 hi all,
When I issue &#34;sudo wireshark -i eth0&#34; on my ubuntu 12.04, a error window occur said &#34;Lua: Error during loading: [string &#34;/usr/share/wireshark/init.lua&#34;]: 45:dofile has been disabled.&#34;
What does it mean and how to resolve this issue?
thanks!
privileges root setcap linuxasked 20 Mar &#39;13, 06:26
SteveZhou
191●27●30●34
accept rate: 0%
 edited 10 Sep &#39;13, 04:58</description>
    </item>
    
    <item>
      <title>Most Packets exchanged</title>
      <link>/questions/19678/most-packets-exchanged/</link>
      <pubDate>Wed, 20 Mar 2013 06:57:00 +0000</pubDate>
      
      <guid>/questions/19678/most-packets-exchanged/</guid>
      <description>Most Packets exchanged  0 Which two computers exchanged most of the total packets between each other? can anyone give me expression for these question? thanks in advance.
wireshark1.2.5asked 20 Mar &#39;13, 06:57
Sunith Kumar
0●1●1●2
accept rate: 0%
  
One Answer:
  
1 Wireshark -&amp;gt; Statistics Menu -&amp;gt; Conversations.
answered 20 Mar &#39;13, 07:00
Jasper ♦♦
23.8k●5●51●284
accept rate: 18%
thnks a lot
(20 Mar &#39;13, 07:03) Sunith KumarHow to check which computer system transmitted the host bytes?</description>
    </item>
    
    <item>
      <title>Can I read a pcap file format and write out a text file on the command line?</title>
      <link>/questions/19681/can-i-read-a-pcap-file-format-and-write-out-a-text-file-on-the-command-line/</link>
      <pubDate>Wed, 20 Mar 2013 07:10:00 +0000</pubDate>
      
      <guid>/questions/19681/can-i-read-a-pcap-file-format-and-write-out-a-text-file-on-the-command-line/</guid>
      <description>Can I read a pcap file format and write out a text file on the command line?  0 Hi I want to know if it is possible to export a pcap file to a text file using the command line?
export feature command-lineasked 20 Mar &#39;13, 07:10
kris cooke
11●1●1●2
accept rate: 0%
 edited 20 Mar &#39;13, 17:36 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:</description>
    </item>
    
    <item>
      <title>how to choose an interface?</title>
      <link>/questions/19701/how-to-choose-an-interface/</link>
      <pubDate>Wed, 20 Mar 2013 17:58:00 +0000</pubDate>
      
      <guid>/questions/19701/how-to-choose-an-interface/</guid>
      <description>how to choose an interface?  0 i recently downloaded wireshark and im new to the system. I was expirementing with it and was wondering how to know which interface to choose to collect packets off of my router. how do I know which one is my router. I tried the one receiving packets and tried to log onto something on my laptop while on the network to retrieve the password but it didn&#39;t show up in the packet.</description>
    </item>
    
    <item>
      <title>How to find upload values from two Ip Addresses</title>
      <link>/questions/19706/how-to-find-upload-values-from-two-ip-addresses/</link>
      <pubDate>Thu, 21 Mar 2013 06:32:00 +0000</pubDate>
      
      <guid>/questions/19706/how-to-find-upload-values-from-two-ip-addresses/</guid>
      <description>How to find upload values from two Ip Addresses  0 Hi,
I am using statistics ---&amp;gt; Conversations option in the Wireshark. Aim to to find how much upload is being done in-between two IP Addresses.
Source IP is 10.99.18.20 and the destination is 10.99.18.86, I took exactly 5 minutes of capture and then stopped it.
Form Conversation it showed me ~ 218111 Bytes of data. But I am not sure how to calculate the Upload value and how much bandwidth is consumed from this number.</description>
    </item>
    
    <item>
      <title>Quick Question.  Need help monitor mobile devices connect to my network</title>
      <link>/questions/19709/quick-question-need-help-monitor-mobile-devices-connect-to-my-network/</link>
      <pubDate>Thu, 21 Mar 2013 08:06:00 +0000</pubDate>
      
      <guid>/questions/19709/quick-question-need-help-monitor-mobile-devices-connect-to-my-network/</guid>
      <description>Quick Question. Need help monitor mobile devices connect to my network  0 Hello, I have a situation that I have to research. The short story is my niece has had to come stay with us after getting into trouble numerous times. My wife decided to give her a cell phone. Against my better judgement, we did and now I need to monitor her while she is under my roof. In reading thru your website I saw that Wireshark has the capabilities to track wireless devices that communicate with the network.</description>
    </item>
    
    <item>
      <title>Adding a range of ports to be mapped to http</title>
      <link>/questions/19711/adding-a-range-of-ports-to-be-mapped-to-http/</link>
      <pubDate>Thu, 21 Mar 2013 08:53:00 +0000</pubDate>
      
      <guid>/questions/19711/adding-a-range-of-ports-to-be-mapped-to-http/</guid>
      <description>Adding a range of ports to be mapped to http  0 Hi,
So this is similar to http://ask.wireshark.org/questions/6294/using-wireshark-to-debug-http-traffic-on-a-non-standard-port and http://ask.wireshark.org/questions/12360/mapping-a-well-known-protocol-to-a-custom-port.
The difference is, I don&#39;t have one or two ports that I would like to add as HTTP. I need to add a range, something like 8000-26000.
Is this possible?
http mapping portasked 21 Mar &#39;13, 08:53
pattimus-prime
11●1●1●5
accept rate: 100%
  
One Answer:</description>
    </item>
    
    <item>
      <title>WAN Link Tuning</title>
      <link>/questions/19717/wan-link-tuning/</link>
      <pubDate>Thu, 21 Mar 2013 09:47:00 +0000</pubDate>
      
      <guid>/questions/19717/wan-link-tuning/</guid>
      <description>WAN Link Tuning  0 Im currently looking at the necessary TCP settings I could use to increase the throughput of a WAN link. The current download speed is 1.78Mbps and a ping is showing a 300ms RTT.
So far the following settings I was thinking of deploying were SACK and Nagle. However Im not sure what the Window Scale should be set to (or if used at all). Im also thinking of lowering the MTU based on the PMTU to avoid any fragmentation, but still waiting on confirmation on the PMTU.</description>
    </item>
    
    <item>
      <title>Decoding unicode characters in Wireshark file</title>
      <link>/questions/19719/decoding-unicode-characters-in-wireshark-file/</link>
      <pubDate>Thu, 21 Mar 2013 11:04:00 +0000</pubDate>
      
      <guid>/questions/19719/decoding-unicode-characters-in-wireshark-file/</guid>
      <description>Decoding unicode characters in Wireshark file  0 hi,
I have a Wireshark capture file that contains some XML encoded in UTF8. Unfortunately Wireshark doesn&#39;t play well with UTF8 so I have strings like ×©×\231×\227×\225×ª in my file. How can I decode these or, even better, let Wireshark decode these on the fly?
utf8asked 21 Mar &#39;13, 11:04
cortado
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Help, I do not understand what I am seeing</title>
      <link>/questions/19720/help-i-do-not-understand-what-i-am-seeing/</link>
      <pubDate>Thu, 21 Mar 2013 11:14:00 +0000</pubDate>
      
      <guid>/questions/19720/help-i-do-not-understand-what-i-am-seeing/</guid>
      <description>Help, I do not understand what I am seeing  0 I have a NAS that is running slow, has been. When I run Wireshark while opening a file on that appliance I am seeing lots and lots of the examples below. (To me it looks like way to many)
90[TCP Dup ACK 8796#16] 6873&amp;gt;microsoft-ds [ACK] seq=27065 Ack=8756344 Win=1619 Len=0 SRE=8824884 SLE=88161
1514 [TCP segment of a reasembled PDU]
dup ackasked 21 Mar &#39;13, 11:14</description>
    </item>
    
    <item>
      <title>Could &amp;quot;tsclient&amp;quot; on my network indicate an attack?</title>
      <link>/questions/19726/could-tsclient-on-my-network-indicate-an-attack/</link>
      <pubDate>Thu, 21 Mar 2013 11:49:00 +0000</pubDate>
      
      <guid>/questions/19726/could-tsclient-on-my-network-indicate-an-attack/</guid>
      <description>Could &amp;ldquo;tsclient&amp;rdquo; on my network indicate an attack?  1 &#34;tsclient&#34; recently appeared on a Windows 8 machine we have on our network. Reading around, it sounds like this is typically used for remote desktop applications. However, I haven&#39;t used any remote desktop services. (Unless some indirect application uses them? xbox glass?)
Could the appearance of tsclient indicate some sort of attack on my network? If so, what steps should I take to investigate?</description>
    </item>
    
    <item>
      <title>Capture retaining only conversation data</title>
      <link>/questions/19727/capture-retaining-only-conversation-data/</link>
      <pubDate>Thu, 21 Mar 2013 11:56:00 +0000</pubDate>
      
      <guid>/questions/19727/capture-retaining-only-conversation-data/</guid>
      <description>Capture retaining only conversation data  0 I have a need to set up a capture for 24 hours and what I am interested in keeping is just the information in the Statistics | Conversations | TCP or UDP tabs, just interested in what IPs are talking to each other and what ports were used. There will be a lot of data if I try to keep all of the packets, is there a way to just have the capture running, retain the conversation information, and not save the data?</description>
    </item>
    
    <item>
      <title>editcap improvement for &amp;quot;duplicate&amp;quot; i.e retransmissions of 802.11 frames</title>
      <link>/questions/19729/editcap-improvement-for-duplicate-ie-retransmissions-of-80211-frames/</link>
      <pubDate>Thu, 21 Mar 2013 12:24:00 +0000</pubDate>
      
      <guid>/questions/19729/editcap-improvement-for-duplicate-ie-retransmissions-of-80211-frames/</guid>
      <description>editcap improvement for &amp;ldquo;duplicate&amp;rdquo; i.e retransmissions of 802.11 frames  0 A WLAN capture executed in monitor mode shows lots of wireless retransmissions occuring. Editcap is not able to remove the duplicates since the packets are not actually duplicates, the radiotap header changes for each packet. Could it be possible to improve editcap to specify from which header the duplicate analysis should be done? E.g. look for duplicates while ignoring header X,Y,Z (in decapsulation order).</description>
    </item>
    
    <item>
      <title>Capture Packets from a Phone or ipod</title>
      <link>/questions/19734/capture-packets-from-a-phone-or-ipod/</link>
      <pubDate>Thu, 21 Mar 2013 14:22:00 +0000</pubDate>
      
      <guid>/questions/19734/capture-packets-from-a-phone-or-ipod/</guid>
      <description>Capture Packets from a Phone or ipod  0 Just got wireshark and i am currently trying it out. All the packets are going through my computer but not my phone (it is connected via wireless), however no packets are coming from that device. I want to find out how to view those packets
phone packetsasked 21 Mar &#39;13, 14:22
Infamous
11●1●1●2
accept rate: 0%
1You&#39;re using your computer as a WiFi hotspot?</description>
    </item>
    
    <item>
      <title>Porting wireshark dissector from linux to windows machine..??</title>
      <link>/questions/19742/porting-wireshark-dissector-from-linux-to-windows-machine/</link>
      <pubDate>Thu, 21 Mar 2013 22:42:00 +0000</pubDate>
      
      <guid>/questions/19742/porting-wireshark-dissector-from-linux-to-windows-machine/</guid>
      <description>Porting wireshark dissector from linux to windows machine..??  0 I have some wireshark dissectors on linux m/c and i want to port these disscetors to windows m/c... so please tell me the procedure for that..
wiresharkasked 21 Mar &#39;13, 22:42
neha
1●3●3●3
accept rate: 0%
Build-in dissectors or plugin?
(21 Mar &#39;13, 23:57) Jaap ♦  
One Answer:
  
2As dissector code is OS independent, you would just need to compile it on Windows.</description>
    </item>
    
    <item>
      <title>Dirty pages</title>
      <link>/questions/19745/dirty-pages/</link>
      <pubDate>Fri, 22 Mar 2013 00:16:00 +0000</pubDate>
      
      <guid>/questions/19745/dirty-pages/</guid>
      <description>Dirty pages  1 How to find number of dirty pages using wireshark?
dirty pagesasked 22 Mar &#39;13, 00:16
Geek
26●1●1●3
accept rate: 0%
  
One Answer:
  
2Wireshark watches network traffic.
If your system has a local hard drive or solid-state drive, at least some of the dirty pages are backed by &#34;swap space&#34; (a swap partition or a swap file/paging file/whatever the OS calls it) that&#39;s on the local drive, so if those pages are written to the backing store, that doesn&#39;t involve any network traffic, so Wireshark won&#39;t see it.</description>
    </item>
    
    <item>
      <title>why do we make use of a tap interface for RTP statistics?</title>
      <link>/questions/19751/why-do-we-make-use-of-a-tap-interface-for-rtp-statistics/</link>
      <pubDate>Fri, 22 Mar 2013 07:38:00 +0000</pubDate>
      
      <guid>/questions/19751/why-do-we-make-use-of-a-tap-interface-for-rtp-statistics/</guid>
      <description>why do we make use of a tap interface for RTP statistics?  0 Hi,
What is the need/advantage of using tap interface for calculating RTP statistics? Why not simply read from a RAW socket which will give entire packet information such as FRAME info etc.,
i.e., files tap-rtp-common.c that has rtp-stream_packet. I understand that for some statistics such as jitter, we need frame time information etc., So we need entire frame data and not just UDP info.</description>
    </item>
    
    <item>
      <title>IPv6 Router Solicitation</title>
      <link>/questions/19753/ipv6-router-solicitation/</link>
      <pubDate>Fri, 22 Mar 2013 08:08:00 +0000</pubDate>
      
      <guid>/questions/19753/ipv6-router-solicitation/</guid>
      <description>IPv6 Router Solicitation  0 Hello everyone,
Wireshark is a nice product for analyzing LAN traffic.
There seems to be a hole though in ICMPv6 sniffing implementation: I cannot see anywhere the ability to filter IPv6 Router Solicitation messages.
icmpv6 rsasked 22 Mar &#39;13, 08:08
actionmystique
11●4●4●7
accept rate: 0%
  
3 Answers:
  
1When analyzing IPv6 traffic in Wireshark, you can simply use the filter icmpv6.</description>
    </item>
    
    <item>
      <title>Wireshark - Advertised Window size</title>
      <link>/questions/19762/wireshark-advertised-window-size/</link>
      <pubDate>Fri, 22 Mar 2013 13:35:00 +0000</pubDate>
      
      <guid>/questions/19762/wireshark-advertised-window-size/</guid>
      <description>Wireshark - Advertised Window size  0 Hi, I&#39;m new in here and would like to ask a question. I&#39;m currently working on my Bachelor thesis. I need to change receiver buffer (advertised window). and, except for Wireshark I need to use another application - FlowGrind (to get Congestion window, as that is not present in packet and can`t be seen in Wireshark). The thing is: When I set &#34;receiver buffer size (advertised window) in FlowGrind and then run it, I see different Windows size in Wireshark.</description>
    </item>
    
    <item>
      <title>Wireshark wont capture EAPOL packets</title>
      <link>/questions/19763/wireshark-wont-capture-eapol-packets/</link>
      <pubDate>Fri, 22 Mar 2013 15:01:00 +0000</pubDate>
      
      <guid>/questions/19763/wireshark-wont-capture-eapol-packets/</guid>
      <description>Wireshark wont capture EAPOL packets  1 Hello,
I&#39;m using Wireshark (1.8.6) on Gentoo Linux and I&#39;m using a USB Wifi adapter from TP Link (tl-wn725n).
The thing is that even though I can get some packets with Wireshark I can&#39;t get the authentication ones from my own computer (the wireless card that is integrated).
I&#39;m setting all the necesary preferences on Wireshark, I have the decription key like this: passwd:My-SSID (yes, my SSID has a - on the name)</description>
    </item>
    
    <item>
      <title>Licensing of a wrapper for wireshark.</title>
      <link>/questions/19764/licensing-of-a-wrapper-for-wireshark/</link>
      <pubDate>Fri, 22 Mar 2013 15:22:00 +0000</pubDate>
      
      <guid>/questions/19764/licensing-of-a-wrapper-for-wireshark/</guid>
      <description>Licensing of a wrapper for wireshark.  0 I have a proprietary application performance monitoring product that receives network data, decodes it, correlates it in various ways and then provides statistical, alerting, summary, and other information to users.
I would like to use the Wireshark dissectors to get at a wider variety of protocols.
The intent would be to either: (a) encapsulate the necessary libraries into a DLL which I would give out publicly (i.</description>
    </item>
    
    <item>
      <title>Interfaces related question</title>
      <link>/questions/19768/interfaces-related-question/</link>
      <pubDate>Sat, 23 Mar 2013 06:25:00 +0000</pubDate>
      
      <guid>/questions/19768/interfaces-related-question/</guid>
      <description>Interfaces related question  0 How can I do that wireshark read the interfaces from the /etc/network/interfaces file?
I had inserted there a virtual interface and wireshark don&#39;t see it
interface local wiresharkasked 23 Mar &#39;13, 06:25
Mcgiwer
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Wireshark sees interfaces that are reported to it by libpcap/WinPcap; libpcap/WinPcap report whatever interfaces are reported to it by whatever mechanism libpcap/WinPcap uses to find the interfaces, and those mechanisms are OS-dependent.</description>
    </item>
    
    <item>
      <title>largest based conversation</title>
      <link>/questions/19769/largest-based-conversation/</link>
      <pubDate>Sat, 23 Mar 2013 07:59:00 +0000</pubDate>
      
      <guid>/questions/19769/largest-based-conversation/</guid>
      <description>largest based conversation  0 how to check the size of largest based conversations in TCP and UDP ???
sun1asked 23 Mar &#39;13, 07:59
Ramyarani
1●2●2●2
accept rate: 0%
  
One Answer:
  
0From Menu Bar Statistics &amp;gt; conversations click on tcp or udp and double click on bytes field for largest data stream.
answered 23 Mar &#39;13, 09:45
krishnayeddula
629●35●41●48
accept rate: 6%
     </description>
    </item>
    
    <item>
      <title>packet analysis</title>
      <link>/questions/19770/packet-analysis/</link>
      <pubDate>Sat, 23 Mar 2013 08:18:00 +0000</pubDate>
      
      <guid>/questions/19770/packet-analysis/</guid>
      <description>packet analysis  0 I have just started with wireshark can any one help me out please??
how can i figure out transport layer and application layer protocol&#39;s of any particular packet??
analysis packetasked 23 Mar &#39;13, 08:18
ark
16●4●5●5
accept rate: 0%
  
One Answer:
  
0In the packet list pane follow the column &#34;Protocol&#34; to figure out transport layer and application layer details of particular packet.</description>
    </item>
    
    <item>
      <title>Reading TXT file of SIP capture  with Wireshark</title>
      <link>/questions/19771/reading-txt-file-of-sip-capture-with-wireshark/</link>
      <pubDate>Sat, 23 Mar 2013 08:56:00 +0000</pubDate>
      
      <guid>/questions/19771/reading-txt-file-of-sip-capture-with-wireshark/</guid>
      <description>Reading TXT file of SIP capture with Wireshark  0 I have an Allworx VoIP PBX in the PBX there is a tool section that allows me to capture SIP Messages and save it as a TXT file. I can view the TXT file with notepad. Is there a way with wireshark to just filter this so I see only the one call I would like to look at so its not so confusing on trying to follow the call mainly I am looking to see if its my PBX or provider sending the BYE msg.</description>
    </item>
    
    <item>
      <title>any material to get familiar with wireshark?</title>
      <link>/questions/19779/any-material-to-get-familiar-with-wireshark/</link>
      <pubDate>Sat, 23 Mar 2013 15:25:00 +0000</pubDate>
      
      <guid>/questions/19779/any-material-to-get-familiar-with-wireshark/</guid>
      <description>any material to get familiar with wireshark?  1 1if anyone knew how to get familiar with wireshark expressions (material or tutorial videos) pls let me knew
startupasked 23 Mar &#39;13, 15:25
ark
16●4●5●5
accept rate: 0%
  
4 Answers:
  
4Wireshark Resources
http://sharkfest.wireshark.org/ Wireshark developers and users conference... This year @ UC-Bekely
http://www.wireshark.org/ Regarding latest developments in wireshark
http://ask.wireshark.org/ Wireshark Q&amp;amp;A community
https://blog.wireshark.org/ wireshark blog</description>
    </item>
    
    <item>
      <title>How to use libwireshark.dll (X64) in 64-bit windows project</title>
      <link>/questions/19790/how-to-use-libwiresharkdll-x64-in-64-bit-windows-project/</link>
      <pubDate>Sun, 24 Mar 2013 18:33:00 +0000</pubDate>
      
      <guid>/questions/19790/how-to-use-libwiresharkdll-x64-in-64-bit-windows-project/</guid>
      <description>How to use libwireshark.dll (X64) in 64-bit windows project  0 Hello all: When i use &#34;LoadLibrary(&#34;libwireshark.dll&#34;) in vs2010, loadlibrary failed with error 193, that is : &#34;1% is not a valid Win32 program&#34;. My project is in X64 mode, and libwireshark.dll is built in X64 too. Why?
libwireshark loadlibraryasked 24 Mar &#39;13, 18:33
sunnymato
1●1●1●1
accept rate: 0%
  
One Answer:
  
0What OS are you trying to run this on?</description>
    </item>
    
    <item>
      <title>Is it always that the client send out ARP requests ?</title>
      <link>/questions/19791/is-it-always-that-the-client-send-out-arp-requests/</link>
      <pubDate>Sun, 24 Mar 2013 20:49:00 +0000</pubDate>
      
      <guid>/questions/19791/is-it-always-that-the-client-send-out-arp-requests/</guid>
      <description>Is it always that the client send out ARP requests ?  0 In one of the first few practicals in the Wireshark Analysis book, there&#39;s this file called gen-googlemaps.pcapng which we are supposed to analyse.
I realised that the 1st packet refers to the Asus client broadcasting an ARP request to find out who is the DNS server . But when I did my own simple scan after flushing my DNS cache, my laptop doesn&#39;t seem to broadcast any ARP request to find out who the DNS server is.</description>
    </item>
    
    <item>
      <title>What is the meaning of two-pass analysis?</title>
      <link>/questions/19794/what-is-the-meaning-of-two-pass-analysis/</link>
      <pubDate>Mon, 25 Mar 2013 00:01:00 +0000</pubDate>
      
      <guid>/questions/19794/what-is-the-meaning-of-two-pass-analysis/</guid>
      <description>What is the meaning of two-pass analysis?  0 Hi, In Wireshark 1.8 and later version,Tshark added a option -2(perform a two-pass analysis). What is the meaning of two-pass analysis? Who can introduce it for me?
two-pass tshark analysisasked 25 Mar &#39;13, 00:01
qqgeet
21●2●2●6
accept rate: 0%
 edited 25 Mar &#39;13, 00:03 
  
One Answer:
  
4In a single (linear) pass through a capture file you can only carry information forwards.</description>
    </item>
    
    <item>
      <title>Wireshark stubborn TCP connection</title>
      <link>/questions/19800/wireshark-stubborn-tcp-connection/</link>
      <pubDate>Mon, 25 Mar 2013 04:28:00 +0000</pubDate>
      
      <guid>/questions/19800/wireshark-stubborn-tcp-connection/</guid>
      <description>Wireshark stubborn TCP connection  0 Hi Everyone! I am firwer123 and i just joined Wireshark Q&amp;amp;A!
Firstly, I hope some one could help me one this,
--Source--------Destination---Protocol----------------Length &amp;amp; Information--------------
192.XXX.1.XX----70.39.98.126-------TCP------54 54589 &amp;gt; dhanalakshmi [ACK] Seq=1 Ack=1 Win=17520 Len=0
70.39.98.126----192.XXX.1.XX-------TCP------67 dhanalakshmi &amp;gt; 54589 [PSH, ACK] Seq=1 Ack=74 Win=65462 Len=13
and a few more similar ones..
192.XXX.1.XX is my local machine
70.39.98.126 is that remote server
Above, is a TCP connection that I&#39;ve filtered out of my network traffic and besides that this network activity log came from a program that would contact its server(70.</description>
    </item>
    
    <item>
      <title>Possible to disable the scan portion of wireshark</title>
      <link>/questions/19803/possible-to-disable-the-scan-portion-of-wireshark/</link>
      <pubDate>Mon, 25 Mar 2013 05:24:00 +0000</pubDate>
      
      <guid>/questions/19803/possible-to-disable-the-scan-portion-of-wireshark/</guid>
      <description>Possible to disable the scan portion of wireshark  0 Is it possible to install Wireshark only to read PCAP files. Our management doesn&#39;t want any network scanner software available to anyone on the network. We get sent pcap files when there is an issue for our dns poduct users and can&#39;t process them. I&#39;m trying to justify having wireshark on my system, for local use only!!!
read pcapasked 25 Mar &#39;13, 05:24</description>
    </item>
    
    <item>
      <title>The wireshark for retransmission judgment mechanism</title>
      <link>/questions/19806/the-wireshark-for-retransmission-judgment-mechanism/</link>
      <pubDate>Mon, 25 Mar 2013 06:41:00 +0000</pubDate>
      
      <guid>/questions/19806/the-wireshark-for-retransmission-judgment-mechanism/</guid>
      <description>The wireshark for retransmission judgment mechanism  0 hi： my wireshark version is Version 1.8.6 (SVN Rev 48142 from /trunk-1.8) Found in the analysis of the data package software for TCP retransmission judgment problems, can help explain whether the software is how to determine the retransmission.
How do I upload the data packet to the forum？
Thank you.
retransmissionasked 25 Mar &#39;13, 06:41
mengsunny
11●4●4●6
accept rate: 0%
You can use http://www.</description>
    </item>
    
    <item>
      <title>Contacts for Support</title>
      <link>/questions/19816/contacts-for-support/</link>
      <pubDate>Mon, 25 Mar 2013 09:43:00 +0000</pubDate>
      
      <guid>/questions/19816/contacts-for-support/</guid>
      <description>Contacts for Support  0 Is there a phone number to call to speak to a Tech? I&#39;m am trying to isolate particular devices to monitor. I have set up Wireshark and have been monitoring for about a week. The time stamp is not something I can translate and I had captured all traffic on the network. If there is a way to filter after the capture then I need to learn how.</description>
    </item>
    
    <item>
      <title>Modbus RTU TCP/IP</title>
      <link>/questions/19818/modbus-rtu-tcpip/</link>
      <pubDate>Mon, 25 Mar 2013 10:32:00 +0000</pubDate>
      
      <guid>/questions/19818/modbus-rtu-tcpip/</guid>
      <description>Modbus RTU TCP/IP  0 I am a field service technician and I am wanting to capture Modbus RTU TCP/IP polls and responses on a SCADA network. I have downloaded the wireshark program and I am testing it on our in house network. I have another machine polling across the network using mod bus rtu tcp/ip polls and a end device is answering. I cannot see any of this communications going on.</description>
    </item>
    
    <item>
      <title>can vmware player run on chrubuntu</title>
      <link>/questions/19820/can-vmware-player-run-on-chrubuntu/</link>
      <pubDate>Mon, 25 Mar 2013 12:06:00 +0000</pubDate>
      
      <guid>/questions/19820/can-vmware-player-run-on-chrubuntu/</guid>
      <description>can vmware player run on chrubuntu  -2 Hi,
Does anyone know if VMware Player can run on an Acer A7 running Chrubuntu?
(The kernal module updater is looking for files and maybe I just don&#39;t know the path?)
chrubuntu vmwareasked 25 Mar &#39;13, 12:06
Dan Danville
-1●1●1●2
accept rate: 0%
3How exactly is this a wireshark related question?
I think http://superuser.com/ would be a more appropriate place to ask your question.</description>
    </item>
    
    <item>
      <title>Why does file sets require an already saved arbitrary file for it to work ?</title>
      <link>/questions/19825/why-does-file-sets-require-an-already-saved-arbitrary-file-for-it-to-work/</link>
      <pubDate>Mon, 25 Mar 2013 21:08:00 +0000</pubDate>
      
      <guid>/questions/19825/why-does-file-sets-require-an-already-saved-arbitrary-file-for-it-to-work/</guid>
      <description>Why does file sets require an already saved arbitrary file for it to work ?  0 Under capture options, I have to browse for a valid saved arbitrary Wireshark file under &#34;browse&#34; for file sets to work.
If I manually enter the file title for instance, setTest01 , file sets wouldn&#39;t work even after setting the proper conditions like &#34; Next file every 1 min &#34; etc.
Confused. Guidance is appreciated :) .</description>
    </item>
    
    <item>
      <title>I can&amp;#x27;t figure out why i can&amp;#x27;t capture 802.11 encrypted packets</title>
      <link>/questions/19832/i-cant-figure-out-why-i-cant-capture-80211-encrypted-packets/</link>
      <pubDate>Tue, 26 Mar 2013 01:53:00 +0000</pubDate>
      
      <guid>/questions/19832/i-cant-figure-out-why-i-cant-capture-80211-encrypted-packets/</guid>
      <description>I can&amp;rsquo;t figure out why i can&amp;rsquo;t capture 802.11 encrypted packets  0 Hi, i&#39;m on ubuntu 12.04 and i have an issue regarding the capture of 802.11 Wpa encrypted packets. Testing my card i have found that IF the network is unencrypted i can pick up all the packets from all the clients. IF the network is encrypted i can catch EAPOL authentication of other clients and nothing else. My problem is not decrypting the traffic, because i&#39;ve found that i can decrypt the test file from the Wireshark wiki, my problem is that if the network is encrypted i can&#39;t capture packets AT ALL.</description>
    </item>
    
    <item>
      <title>TCP protocol filter</title>
      <link>/questions/19833/tcp-protocol-filter/</link>
      <pubDate>Tue, 26 Mar 2013 03:22:00 +0000</pubDate>
      
      <guid>/questions/19833/tcp-protocol-filter/</guid>
      <description>TCP protocol filter  0 In order to capture the start and end packets (the SYN and FIN packets) of each TCP conversation, the following TCP filter is applied - tcp[tcpflags] &amp;amp; (tcp-syn|tcp-fin) = 1 .
Hopefully the above is in fact correct.
What is the purpose of the [tcpflags] in the filter ? Is it simply part of the syntax and thus a must-have whenever a filter concerning tcp flags are used ?</description>
    </item>
    
    <item>
      <title>Why is there a limit of only 600 characters for comments on ask.wireshark.org?</title>
      <link>/questions/19841/why-is-there-a-limit-of-only-600-characters-for-comments-on-askwiresharkorg/</link>
      <pubDate>Tue, 26 Mar 2013 08:17:00 +0000</pubDate>
      
      <guid>/questions/19841/why-is-there-a-limit-of-only-600-characters-for-comments-on-askwiresharkorg/</guid>
      <description>Why is there a limit of only 600 characters for comments on ask.wireshark.org?  0 I was wondering why there is a limit of only 600 characters per comment. Answers are not similarly limited.
This question comes up because I recently converted Joke&#39;s answer to this question to a comment since it wasn&#39;t actually an answer to the question being asked. But she would not have been able to add that comment herself since it exceeds the current maximum character limitation for comments.</description>
    </item>
    
    <item>
      <title>ICMP display filter checksum_bad ignored</title>
      <link>/questions/19844/icmp-display-filter-checksum_bad-ignored/</link>
      <pubDate>Tue, 26 Mar 2013 09:30:00 +0000</pubDate>
      
      <guid>/questions/19844/icmp-display-filter-checksum_bad-ignored/</guid>
      <description>ICMP display filter checksum_bad ignored  0 I was searching for icmp.checksum_bad==1 and found no matches, which was seemingly a good thing; however, when I changed the filter to icmp.checksum_bad==0, I also got no matches. My conclusion is that Wireshark is not computing checksum_bad either way, and is ignoring the display filter specification.
My question is thus: is there a way to get Wireshark to calculate icmp.checksum_bad properly, so that I can rely on it to locate icmp checksum errors?</description>
    </item>
    
    <item>
      <title>File Analyzed</title>
      <link>/questions/19849/file-analyzed/</link>
      <pubDate>Tue, 26 Mar 2013 12:06:00 +0000</pubDate>
      
      <guid>/questions/19849/file-analyzed/</guid>
      <description>File Analyzed  0 I had a file sent to me from a client who is having intermittent problems with data corruption. I am looking for someone to hire to evaluate their file and let me know if you can see what could be causing their trouble. Is help like this possible?
Thanks
consultantasked 26 Mar &#39;13, 12:06
ouajl26
11●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>WireShark eats up memory at an alarming rate for version after 1.6.5</title>
      <link>/questions/19852/wireshark-eats-up-memory-at-an-alarming-rate-for-version-after-165/</link>
      <pubDate>Tue, 26 Mar 2013 12:39:00 +0000</pubDate>
      
      <guid>/questions/19852/wireshark-eats-up-memory-at-an-alarming-rate-for-version-after-165/</guid>
      <description>WireShark eats up memory at an alarming rate for version after 1.6.5  0 I&#39;ve now tested 5 different version of WireShark on my Windows 2008 R2 Servers. The only version that I found to not eat up memory at an alarming rate is the 64 Bit of 1.6.5. I&#39;ve tried 1.6.14, 1.8.2, 1.8.6 and they all are eating up memory at a crazy rate even when the packet rate is not that high.</description>
    </item>
    
    <item>
      <title>ISCSI:Multiple connections in a tcp session</title>
      <link>/questions/19856/iscsimultiple-connections-in-a-tcp-session/</link>
      <pubDate>Tue, 26 Mar 2013 15:39:00 +0000</pubDate>
      
      <guid>/questions/19856/iscsimultiple-connections-in-a-tcp-session/</guid>
      <description>ISCSI:Multiple connections in a tcp session  0 I am new to iscsi protocol.Came across an aspect of it in RFC stating multiple iscsi connection support in same TCP Session.How to identify all these multiple connections? In HTTP World we can relate it to multiple GET requests within a same TCP Session.How can one relate this in iscsi world?
iscsiasked 26 Mar &#39;13, 15:39
krishnayeddula
629●35●41●48
accept rate: 6%
Came across an aspect of it in RFC stating multiple iscsi connection support in same TCP Session.</description>
    </item>
    
    <item>
      <title>Live TCP stream capture to a file</title>
      <link>/questions/19857/live-tcp-stream-capture-to-a-file/</link>
      <pubDate>Tue, 26 Mar 2013 17:47:00 +0000</pubDate>
      
      <guid>/questions/19857/live-tcp-stream-capture-to-a-file/</guid>
      <description>Live TCP stream capture to a file  0 Is there a way to have wireshark capture a live tcp stream and send that stream to a file when the stream is closed? Im fairly new to Wireshark and have not been able to accomplish this task.
tcpasked 26 Mar &#39;13, 17:47
pgfdbug
11●1●1●2
accept rate: 0%
 edited 26 Mar &#39;13, 17:49 
  
One Answer:</description>
    </item>
    
    <item>
      <title>window updates</title>
      <link>/questions/19861/window-updates/</link>
      <pubDate>Tue, 26 Mar 2013 20:52:00 +0000</pubDate>
      
      <guid>/questions/19861/window-updates/</guid>
      <description>window updates  0 I have a capture and the network has redundancy built in. I and doing some captures for a client to help them determine why they are losing connection. in the capture, I see a Lott of window updates 740 I see duplicate acks 98 and I see TCP missed segment captured 98
My question is will a huge number of window updates cause a problem on the network?</description>
    </item>
    
    <item>
      <title>How do I run a Lua script with tshark?</title>
      <link>/questions/19865/how-do-i-run-a-lua-script-with-tshark/</link>
      <pubDate>Wed, 27 Mar 2013 05:32:00 +0000</pubDate>
      
      <guid>/questions/19865/how-do-i-run-a-lua-script-with-tshark/</guid>
      <description>How do I run a Lua script with tshark?  0 I get an error when I try to run a Lua script with:
tshark -q -z io,phs -Xlua_script:trace_stats.lua -r &amp;lt;trace.pcap&amp;gt;What is wrong with this command?
lua wiresharkasked 27 Mar &#39;13, 05:32
Ashraf
16●6●6●10
accept rate: 0%
 edited 27 Mar &#39;13, 15:41 
helloworld
3.1k●4●20●41
What is the error message?
(27 Mar &#39;13, 06:35) helloworldWorks fine for me.
Can you do a &#34;</description>
    </item>
    
    <item>
      <title>How to create ICMP filters with both type and code ?</title>
      <link>/questions/19866/how-to-create-icmp-filters-with-both-type-and-code/</link>
      <pubDate>Wed, 27 Mar 2013 06:14:00 +0000</pubDate>
      
      <guid>/questions/19866/how-to-create-icmp-filters-with-both-type-and-code/</guid>
      <description>How to create ICMP filters with both type and code ?  0 ICMP filter filtering only Destination Unreachable(type) - icmp[0] == 3 .
ICMP filter filtering Destination Unreachable(type),Destination host unreachable(code) - icmp[0:2] == ?
Regards Dinged
capture-filter icmpasked 27 Mar &#39;13, 06:14
Dinged
36●7●7●11
accept rate: 0%
  
2 Answers:
  
4 The capture filter you are probably thinking of is:
icmp[0:2]==0x0301But to be more descriptive, you could use something like this instead:</description>
    </item>
    
    <item>
      <title>Malformed Packet (no3 of 4-way-handshake)</title>
      <link>/questions/19884/malformed-packet-no3-of-4-way-handshake/</link>
      <pubDate>Wed, 27 Mar 2013 12:54:00 +0000</pubDate>
      
      <guid>/questions/19884/malformed-packet-no3-of-4-way-handshake/</guid>
      <description>Malformed Packet (no3 of 4-way-handshake)  0 Hello,
Since last week I’ve been trying to capture the 4-way-handshake of my own router without success. I tried on different PCs, on different distances to the router, even on different routers, and I even ordered an additional wifi-card that was recommended for use with backtrack. The result is always the same. In Wireshark:
In the top section it always shows that exactly 1 or 4, 2 of 4 and 4 of 4 are malformed and always exactly on 3 of 4 it does not show this message.</description>
    </item>
    
    <item>
      <title>u_char identifier and abs_time_to_str</title>
      <link>/questions/19887/u_char-identifier-and-abs_time_to_str/</link>
      <pubDate>Wed, 27 Mar 2013 14:59:00 +0000</pubDate>
      
      <guid>/questions/19887/u_char-identifier-and-abs_time_to_str/</guid>
      <description>u_char identifier and abs_time_to_str  0 I am trying to adapt an old code packet-gtpcdr.c into new version of wireshark but failed during compilation.
If I rename the u_char to gchar the complilation continue. I am not sure if this is correct.
/* TAG undefined */ int decode_tlv_undefined (tvbuff_t *tvb, proto_tree *tree, int offset) { proto_tree *tlv_tree; proto_item *te; u_char length, tag; tag = tvb_get_guint8 (tvb, offset); length = tvb_get_guint8 (tvb, offset + 1); te = proto_tree_add_text (tree, tvb, offset, length + 2, &amp;quot;TAG %d (undefined)&amp;quot;, tag); tlv_tree = proto_item_add_subtree (te, ett_gtp_cdr_undefined); proto_tree_add_text (tlv_tree, tvb, offset, 1, &amp;quot;Type: %d&amp;quot;, tag); proto_tree_add_text (tlv_tree, tvb, offset + 1, 1, &amp;quot;Length: %d&amp;quot;, length); proto_tree_add_text (tlv_tree, tvb, offset + 2, length, &amp;quot;Value&amp;quot;);Which additional value should I add for abs_time_to_str?</description>
    </item>
    
    <item>
      <title>BAD_ADRESSES</title>
      <link>/questions/19895/bad_adresses/</link>
      <pubDate>Thu, 28 Mar 2013 02:26:00 +0000</pubDate>
      
      <guid>/questions/19895/bad_adresses/</guid>
      <description>BAD_ADRESSES  0 hi All;
we have an issue last 2 days, Machines on networks get Ip adress but could not access to domaine. When checkd the DHCP server, we found out a list of BAD_ADRESS, even if those ip is not assigned. we Checked out the network if for other DHCP servers using wireshark ( Bootp == 2 Filetr), we found that all ip offers are from the principal DHCP Server.</description>
    </item>
    
    <item>
      <title>can i use wireshark to reverse engineer a specific http REST request?</title>
      <link>/questions/19898/can-i-use-wireshark-to-reverse-engineer-a-specific-http-rest-request/</link>
      <pubDate>Thu, 28 Mar 2013 05:23:00 +0000</pubDate>
      
      <guid>/questions/19898/can-i-use-wireshark-to-reverse-engineer-a-specific-http-rest-request/</guid>
      <description>can i use wireshark to reverse engineer a specific http REST request?  0 the original question is asked here: http://stackoverflow.com/questions/15679883/how-to-reverse-engineer-an-http-api-call-using-rest-console
but basically i was wondering if wireshark would give me more information than chrome rest console does?
thanks!
api http restasked 28 Mar &#39;13, 05:23
abbood
1●1●1●1
accept rate: 0% 
  
2 Answers:
  
0Yep, it would, because if you capture the full communication you&#39;ll see everything that is going back and forth.</description>
    </item>
    
    <item>
      <title>About the TCP connection state changes</title>
      <link>/questions/19899/about-the-tcp-connection-state-changes/</link>
      <pubDate>Thu, 28 Mar 2013 05:38:00 +0000</pubDate>
      
      <guid>/questions/19899/about-the-tcp-connection-state-changes/</guid>
      <description>About the TCP connection state changes  0 Hi： Ask about the state of the TCP protocol changes：
After the client sends a SYN packet, received RST packet on the server side, connection status changes and subsequent behavior?After the client sends a SYN packet, did not receive any packets,connection status changes and subsequent behavior?After the client sends a SYN packet received from the server-side packet SYN flag bit is not set，connection status changes and subsequent behavior?</description>
    </item>
    
    <item>
      <title>How do I fix &amp;quot;_version already defined in packet-gtpcdr.obj&amp;quot; error?</title>
      <link>/questions/19905/how-do-i-fix-_version-already-defined-in-packet-gtpcdrobj-error/</link>
      <pubDate>Thu, 28 Mar 2013 07:24:00 +0000</pubDate>
      
      <guid>/questions/19905/how-do-i-fix-_version-already-defined-in-packet-gtpcdrobj-error/</guid>
      <description>How do I fix &amp;ldquo;_version already defined in packet-gtpcdr.obj&amp;rdquo; error?  0 Thanks for you support. Could someone hep me for the following complile error?
link -dll /out:gtpcdr.dll /NOLOGO /INCREMENTAL:no /DEBUG /MACHINE:x86 /SafeSEH /DYNAMICBASE /FIXED:no packet-gtpcdr.obj plugin.obj ..\..\epan\libwireshark.lib C:\wireshark-win32-libs-1.8\gtk2\lib\glib-2.0.lib C:\wireshark-win32-libs-1.8\gtk2\lib\gmodule-2.0.lib C:\wireshark-win32-libs-1.8\gtk2\lib\gobject-2.0.lib gtpcdr.res plugin.obj : error LNK2005: _version already defined in packet-gtpcdr.obj Creating library gtpcdr.lib and object gtpcdr.exp gtpcdr.dll : fatal error LNK1169: one or more multiply defined symbols found NMAKE : fatal error U1077: &amp;#39;&amp;quot;c:\Program Files (x86)\Microsoft Visual Studio 10.</description>
    </item>
    
    <item>
      <title>Dissector for ICCP/TASE.2</title>
      <link>/questions/19908/dissector-for-iccptase2/</link>
      <pubDate>Thu, 28 Mar 2013 11:30:00 +0000</pubDate>
      
      <guid>/questions/19908/dissector-for-iccptase2/</guid>
      <description>Dissector for ICCP/TASE.2  0 I&#39;m looking for a way to read ICCP/TASE.2 packets. I&#39;ve seen anecdotal evidence that Wireshark supports this protocol, but can&#39;t find anything concrete from Wireshark&#39;s documentation or Q&amp;amp;A.
When I view pcaps with ICCP packets through Wireshark, they&#39;re displayed down to the MMS protocol, which is shown full of various errors (primarily &#34;BER Error: Wrong field in SEQUENCE&#34;). We&#39;ve tried Wireshark versions up to 1.8.3, but the release notes for later versions don&#39;t indicate the addition of ICCP/TASE.</description>
    </item>
    
    <item>
      <title>How can I FIND OUT HOW TO monitor my home wireless connectivity?</title>
      <link>/questions/19928/how-can-i-find-out-how-to-monitor-my-home-wireless-connectivity/</link>
      <pubDate>Fri, 29 Mar 2013 07:04:00 +0000</pubDate>
      
      <guid>/questions/19928/how-can-i-find-out-how-to-monitor-my-home-wireless-connectivity/</guid>
      <description>How can I FIND OUT HOW TO monitor my home wireless connectivity?  0 No-one has answered my question (below) in the four days since I posted it, maybe because it&#39;s not DIRECTLY relevant to Wireshark. If that&#39;s the case, I&#39;m sorry - is there another more general website where I might get an answer?
My home wireless connection seems to fail every few minutes for a few seconds. Mostly it reconnects without my intervention, but sometimes I have to go to the Wireless Network Connection dialog box and click &#34;</description>
    </item>
    
    <item>
      <title>Can I configure Wireshark to work with xampp</title>
      <link>/questions/19929/can-i-configure-wireshark-to-work-with-xampp/</link>
      <pubDate>Fri, 29 Mar 2013 07:52:00 +0000</pubDate>
      
      <guid>/questions/19929/can-i-configure-wireshark-to-work-with-xampp/</guid>
      <description>Can I configure Wireshark to work with xampp  0 I recently installed xampp (Apache Friend) on my laptop and I wanted to capture GET requests made by my browser. I installed Wireshark, but cannot see hoe to configure it to do what I want. It lists 4 interfaces, and I tried each one.
The &#39;interfaces&#39; shows 4 choices, and I tried each one.
apache xamppasked 29 Mar &#39;13, 07:52</description>
    </item>
    
    <item>
      <title>Estimating/modeling TCP latency</title>
      <link>/questions/19939/estimatingmodeling-tcp-latency/</link>
      <pubDate>Fri, 29 Mar 2013 10:23:00 +0000</pubDate>
      
      <guid>/questions/19939/estimatingmodeling-tcp-latency/</guid>
      <description>Estimating/modeling TCP latency  0 I&#39;m using TCP to send messages among two linux hosts on the same subnet at a fixed period and I can see occasional cases where a &#34;fast retransmission&#34; occurs and the application appears to see significant jitter as a result.
A single segment looks like it may have been lost and the subsequent ones all back upare queued for delivery to the application/head of line blocking -- classic case where TCP was not the right tool for the job.</description>
    </item>
    
    <item>
      <title>How can one determine within a dissector if tshark or Wireshark is being run?</title>
      <link>/questions/19946/how-can-one-determine-within-a-dissector-if-tshark-or-wireshark-is-being-run/</link>
      <pubDate>Fri, 29 Mar 2013 16:02:00 +0000</pubDate>
      
      <guid>/questions/19946/how-can-one-determine-within-a-dissector-if-tshark-or-wireshark-is-being-run/</guid>
      <description>How can one determine within a dissector if tshark or Wireshark is being run?  0 The load time for NFSv4 captures can be reduced by up to 2.5 times by skipping the &#39;proto_&#39; routines during the initial load (first pass) of the capture in Wireshark. However, if &#39;!tree&#39; is used to detect if this is the first pass, &#39;Find&#39;s for text in the Info column fails because during a Find, &#39;tree&#39; is temporarily set to NULL.</description>
    </item>
    
    <item>
      <title>Wireshark SRT doesn&amp;#x27;t like repeated LDAP MessageIDs - any workarounds?</title>
      <link>/questions/19948/wireshark-srt-doesnt-like-repeated-ldap-messageids-any-workarounds/</link>
      <pubDate>Fri, 29 Mar 2013 22:40:00 +0000</pubDate>
      
      <guid>/questions/19948/wireshark-srt-doesnt-like-repeated-ldap-messageids-any-workarounds/</guid>
      <description>Wireshark SRT doesn&amp;rsquo;t like repeated LDAP MessageIDs - any workarounds?  0 The LDAP RFC allows Message-IDs to be reused, as long as the earlier request bearing the Message-ID has been completed.
This plays havoc with Wireshark&#39;s Service Response Time analysis for LDAP. It appears that the code simply determines the elapsed time between the first &#34;use in query&#34; and last &#34;use in response&#34; of each Message-ID, like so (capital letters are where SRT determines its measurement):</description>
    </item>
    
    <item>
      <title>tcpdump to get mac address of all lan machine</title>
      <link>/questions/19949/tcpdump-to-get-mac-address-of-all-lan-machine/</link>
      <pubDate>Fri, 29 Mar 2013 23:09:00 +0000</pubDate>
      
      <guid>/questions/19949/tcpdump-to-get-mac-address-of-all-lan-machine/</guid>
      <description>tcpdump to get mac address of all lan machine  0 I have a machine connected to LAN switch.
How can i get mac address of all other LAN machines.
enabled promiscuous mode then tried following command
tcpdump -i eth1 -vvv -qe
11:31:07.670442 84:2b:2b:0a:78:68 (oui Unknown) &amp;gt; Broadcast, ARP, length 42: Ethernet (len 6), IPv4 (len 4), Request who-has 192.168.30.36 tell 192.168.30.32, length 28
It is not showing any ARP reply.</description>
    </item>
    
    <item>
      <title>clean interface for stack development</title>
      <link>/questions/19952/clean-interface-for-stack-development/</link>
      <pubDate>Sat, 30 Mar 2013 02:31:00 +0000</pubDate>
      
      <guid>/questions/19952/clean-interface-for-stack-development/</guid>
      <description>clean interface for stack development  0 Hi,
I&#39;m porting an embedded TCP-stack. I&#39;d like to use wireshark to test my implementation. The problem is that there is a lot of traffic on my notebooks ethernet interface. I cant use filters, because it is possible that the frames that are sent are corrupt so i would not see them.
Any idea how I can obtain an interface where the only traffic is the one i want?</description>
    </item>
    
    <item>
      <title>Odd UDP output from router to 192.168.1.255 -- any ideas?</title>
      <link>/questions/19956/odd-udp-output-from-router-to-1921681255-any-ideas/</link>
      <pubDate>Sat, 30 Mar 2013 08:30:00 +0000</pubDate>
      
      <guid>/questions/19956/odd-udp-output-from-router-to-1921681255-any-ideas/</guid>
      <description>Odd UDP output from router to 192.168.1.255 &amp;ndash; any ideas?  0 Hello I&#39;m trying to understand a piece of Wireshark output. Every five seconds it records this same transaction, showing the router broadcasting to 192.168.1.255 on UDP port 9246:
192.168.1.1 192.168.1.255 UDP 100 Source port: 9246 Destination port: 9246
The follow UDP stream gives lines of this:
&#34;ism://192.168.1.1:9246/?nameGateway=GwcVoice&amp;amp;sslMthd=none.ism://192.168.1.1:9246/?&#34;
Any clues as to what might be causing this behaviour much appreciated.</description>
    </item>
    
    <item>
      <title>promiscuous mode on WLAN</title>
      <link>/questions/19973/promiscuous-mode-on-wlan/</link>
      <pubDate>Sun, 31 Mar 2013 10:39:00 +0000</pubDate>
      
      <guid>/questions/19973/promiscuous-mode-on-wlan/</guid>
      <description>promiscuous mode on WLAN  0 Dear all,
I&#39;m encountering the following problem. I&#39;m trying to run promiscuous mode on the standard network adapter on the macbook air running Mountain Lion. As you well know, MBAir does not have a LAN input thus the capture mode should always work over wifi. The issue is that I ONLY capture the packets from the localhost and thus none of the packets of the rest of IPs from the same network.</description>
    </item>
    
    <item>
      <title>LAN slowdown</title>
      <link>/questions/19975/lan-slowdown/</link>
      <pubDate>Sun, 31 Mar 2013 13:26:00 +0000</pubDate>
      
      <guid>/questions/19975/lan-slowdown/</guid>
      <description>LAN slowdown  0 Hello, may any expert can help me please?
My LAN runs very slow and I am trying to find out why. Please see the capture I made with Wireshark (see below the link to download the file), where it seems there are wrong or repeated packets or lost packets.
I know the cable is fine, as sometimes I reached high speeds, I believe it is something with the router, the terminals, or any other thing.</description>
    </item>
    
    <item>
      <title>How can I fix error 0xc000007b on startup?</title>
      <link>/questions/19977/how-can-i-fix-error-0xc000007b-on-startup/</link>
      <pubDate>Sun, 31 Mar 2013 16:02:00 +0000</pubDate>
      
      <guid>/questions/19977/how-can-i-fix-error-0xc000007b-on-startup/</guid>
      <description>How can I fix error 0xc000007b on startup?  0 When I open the program, I get this error: 0xc000007b.
I have windows 7 home premium x64.
How I can resolve?
windows crashasked 31 Mar &#39;13, 16:02
asdflol
1●1●1●1
accept rate: 0%
 edited 01 Apr &#39;13, 07:17 
grahamb ♦
19.8k●3●30●206
  
4 Answers:
  
1I&#39;m assuming that you are getting this error when you try to start Wireshark.</description>
    </item>
    
    <item>
      <title>how to study to use Wireshark ?</title>
      <link>/questions/19980/how-to-study-to-use-wireshark/</link>
      <pubDate>Sun, 31 Mar 2013 20:25:00 +0000</pubDate>
      
      <guid>/questions/19980/how-to-study-to-use-wireshark/</guid>
      <description>how to study to use Wireshark ?  0 i&#39;m interesting in network analysis.i start use Wireshark but i don&#39;t understand how to use when i get packets. what kind of programming should i study to understand packets from wireshark ?
helpasked 31 Mar &#39;13, 20:25
csycisco
1●1●1●1
accept rate: 0%
  
3 Answers:
  
1You do not need to study any programming to understand packets. You need to learn about how networks and protocols work.</description>
    </item>
    
    <item>
      <title>help Isolate slow file transfers</title>
      <link>/questions/19982/help-isolate-slow-file-transfers/</link>
      <pubDate>Sun, 31 Mar 2013 22:06:00 +0000</pubDate>
      
      <guid>/questions/19982/help-isolate-slow-file-transfers/</guid>
      <description>help Isolate slow file transfers  0 We are facing slow file transfer issue with Lync 2010 client. Whenever two peer to Peer clients they share file rate at which file transfer takes place is 2 mbps But if we try to share same file using Skype we get 15 mbps speed.
need your help how we can isolate why Lync is slown in file sharing as compared to Skype.</description>
    </item>
    
    <item>
      <title>How do we find out ISUP messages which belongs to the same call?</title>
      <link>/questions/19984/how-do-we-find-out-isup-messages-which-belongs-to-the-same-call/</link>
      <pubDate>Mon, 01 Apr 2013 01:22:00 +0000</pubDate>
      
      <guid>/questions/19984/how-do-we-find-out-isup-messages-which-belongs-to-the-same-call/</guid>
      <description>How do we find out ISUP messages which belongs to the same call?  0 I have a pcap file which contains ISUP frames. How do i find out the ISUP messages of a same call? what are the common things which identify the the ISUP messages of a single call uniquely.
message isup wiresharkasked 01 Apr &#39;13, 01:22
Manoj G
40●3●4●10
accept rate: 33%
 edited 01 Apr &#39;13, 01:27</description>
    </item>
    
    <item>
      <title>Malformed Packet for ICMPv6 Redirect Message</title>
      <link>/questions/19988/malformed-packet-for-icmpv6-redirect-message/</link>
      <pubDate>Mon, 01 Apr 2013 05:55:00 +0000</pubDate>
      
      <guid>/questions/19988/malformed-packet-for-icmpv6-redirect-message/</guid>
      <description>Malformed Packet for ICMPv6 Redirect Message  0 Hi!
I always get a &#34;Malformed Packet&#34; for ICMP Redirect Message. Does anyone have an idea why or what the problem is?
Screenshot: http://postimg.org/image/6a27pizr1/
BR DarkEye
redirect icmpv6 icmp ipv6asked 01 Apr &#39;13, 05:55
TheDarkEye
16●1●1●4
accept rate: 0%
 edited 01 Apr &#39;13, 06:01 
  
One Answer:
  
0 That&#39;s not the Redirect that gives you the error, it&#39;s the Echo inside the redirected header ICMP field that gets the dissector spooked when it&#39;s cut short.</description>
    </item>
    
    <item>
      <title>No seeing wlan traffic while connected to eth</title>
      <link>/questions/19994/no-seeing-wlan-traffic-while-connected-to-eth/</link>
      <pubDate>Mon, 01 Apr 2013 14:28:00 +0000</pubDate>
      
      <guid>/questions/19994/no-seeing-wlan-traffic-while-connected-to-eth/</guid>
      <description>No seeing wlan traffic while connected to eth  0 setup:
1 pc connected to a switch ( with wlan ) ( 192.168.1.10 ) 1 notebook connected to the same switch via wlan ( 192.168.1.20 )
question:
why is it not possible to see the traffic from the notebook which is connected to the same switch ? i have to use cain/able to arp-poison the connection to the router to re-route the traffic, but shouldnt it be possible to see the traffic just with the promisc.</description>
    </item>
    
    <item>
      <title>Automated TCP Reassembler?</title>
      <link>/questions/19995/automated-tcp-reassembler/</link>
      <pubDate>Mon, 01 Apr 2013 15:34:00 +0000</pubDate>
      
      <guid>/questions/19995/automated-tcp-reassembler/</guid>
      <description>Automated TCP Reassembler?  0 1Hello fellow Wireshark Ninjas,
I have been thinking about making a plugin for Wireshark (LUA) that automatically parses through a PCAP file, reassembles any known file types by file header details, and then saves them in a directory. Any ideas on how to get started? I have successfully created a few LUA scripts, one even sets up the proper directories for the files I wish to reassemble.</description>
    </item>
    
    <item>
      <title>Reassembling TCP fragments doesn&amp;#x27;t reassemble some packets</title>
      <link>/questions/20001/reassembling-tcp-fragments-doesnt-reassemble-some-packets/</link>
      <pubDate>Tue, 02 Apr 2013 00:15:00 +0000</pubDate>
      
      <guid>/questions/20001/reassembling-tcp-fragments-doesnt-reassemble-some-packets/</guid>
      <description>Reassembling TCP fragments doesn&amp;rsquo;t reassemble some packets  0 I wrote a dissector named PROTOC.
for some reasons this dissector doesn&#39;t reassemble all of the protocol&#39;s packets which can be found as [TCP segment of a reassembled PDU], But there is no trace to the reassembled PDU. Example can be seen at the attached link below of the .pcap, where TYPE D is shown at the beginning of the file (type 4)(line 1 or 3), and TYPE E cannot be shown at the end of the file (type 5)(line 6312)</description>
    </item>
    
    <item>
      <title>Ethernet activity not seen by Wireshark</title>
      <link>/questions/20008/ethernet-activity-not-seen-by-wireshark/</link>
      <pubDate>Tue, 02 Apr 2013 01:41:00 +0000</pubDate>
      
      <guid>/questions/20008/ethernet-activity-not-seen-by-wireshark/</guid>
      <description>Ethernet activity not seen by Wireshark  0 I have a USB-Ethernet adaptor connecting my Windows XP PC to an external device. Wiresharc (running on the same PC) sees all the activity I expect between the PC and the device. When both the PC and the device are idle (sending no Ethernet packets on that interface) I usually (but not always) see frantic, continuous activity on the adaptor (its lights are flashing), but Wireshark detects nothing.</description>
    </item>
    
    <item>
      <title>How can i filter particular web browsing http packet transitions?</title>
      <link>/questions/20010/how-can-i-filter-particular-web-browsing-http-packet-transitions/</link>
      <pubDate>Tue, 02 Apr 2013 03:20:00 +0000</pubDate>
      
      <guid>/questions/20010/how-can-i-filter-particular-web-browsing-http-packet-transitions/</guid>
      <description>How can i filter particular web browsing http packet transitions?  0 Hii. I am trying to extract all packet transition for a particular website visit (for example : google). I am considering websites which takes contents from different servers. Is it possible to filter our whole bunch of packets of a particular website visit apart from multiple webvisit packet existence? Is there any way to determine the ending of a whole web page loaded?</description>
    </item>
    
    <item>
      <title>Response Time ICMP</title>
      <link>/questions/20016/response-time-icmp/</link>
      <pubDate>Tue, 02 Apr 2013 06:17:00 +0000</pubDate>
      
      <guid>/questions/20016/response-time-icmp/</guid>
      <description>Response Time ICMP  0 Hello,
I realized that the icmp echo reply messages, wireshark shows a field called &#34;Response Time&#34;.
Since the ICMP header field carries no reply such as wireshark can discover time travel package?
att
icmpasked 02 Apr &#39;13, 06:17
victorrebli
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Wireshark is able to calculate the &#34;response time&#34; based on the time stamp of the echo request and echo response packet.</description>
    </item>
    
    <item>
      <title>What is the minimum inter frame gap for a fibre channel phy?</title>
      <link>/questions/20023/what-is-the-minimum-inter-frame-gap-for-a-fibre-channel-phy/</link>
      <pubDate>Tue, 02 Apr 2013 09:59:00 +0000</pubDate>
      
      <guid>/questions/20023/what-is-the-minimum-inter-frame-gap-for-a-fibre-channel-phy/</guid>
      <description>What is the minimum inter frame gap for a fibre channel phy?  0 I saw some document saying that the minimum inter frame gap is 20 bytes but some say it is 24 bytes (I assume it include the SOF). Just wonder what is the standard minimum inter frame gap for a fibre channel phy?
Thanks.
fibre-channelasked 02 Apr &#39;13, 09:59
kintaro
6●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>School wireshark</title>
      <link>/questions/20026/school-wireshark/</link>
      <pubDate>Tue, 02 Apr 2013 10:35:00 +0000</pubDate>
      
      <guid>/questions/20026/school-wireshark/</guid>
      <description>School wireshark  0 I have run Wireshark on my school but can i read passwords or a remote desktop IP or something? And which filters should i use?
school wiresharkasked 02 Apr &#39;13, 10:35
anony1
1●1●1●1
accept rate: 0%
what is your use case?
(02 Apr &#39;13, 10:41) Kurt Knochner ♦  
One Answer:
  
0That depends on the network setup at your school. If they&#39;re still on steam powered technology like hubs (okay, not really steam powered, but it feels that way) then you might be able to capture packets of other computers.</description>
    </item>
    
    <item>
      <title>I can not capture my fortiClient interface</title>
      <link>/questions/20037/i-can-not-capture-my-forticlient-interface/</link>
      <pubDate>Wed, 03 Apr 2013 02:17:00 +0000</pubDate>
      
      <guid>/questions/20037/i-can-not-capture-my-forticlient-interface/</guid>
      <description>I can not capture my fortiClient interface  0 Hi all,
I have a Windows 7 PC running wireshark. I connect to another network using Fortinet FortiClient. I need to capture the traffic going through this interface but I can not see this interface in the interfaces list. Reinstalling wireshark didnt help.
Do anybody knows how can I add FortiClient interface to wireshark and capture?
SSL VPN Forticlient version : 4.</description>
    </item>
    
    <item>
      <title>Calculate page load time in Wireshark?</title>
      <link>/questions/20049/calculate-page-load-time-in-wireshark/</link>
      <pubDate>Wed, 03 Apr 2013 04:16:00 +0000</pubDate>
      
      <guid>/questions/20049/calculate-page-load-time-in-wireshark/</guid>
      <description>Calculate page load time in Wireshark?  0 Hello!
I am trying to measure page load performance from a mobile smartphone. I have installed tpacketcapture on my Android phone, I then navigate to a particular website and stop capturing. I then load the .pcap files into wireshark. But how can I determine the total load time for a particular webpage from Wireshark?
Thanks, I do know much about Wireshark, any help would be much appreciated</description>
    </item>
    
    <item>
      <title>how to add custom protocol dissector for layer 1 (ethernet) protcol</title>
      <link>/questions/20052/how-to-add-custom-protocol-dissector-for-layer-1-ethernet-protcol/</link>
      <pubDate>Wed, 03 Apr 2013 06:38:00 +0000</pubDate>
      
      <guid>/questions/20052/how-to-add-custom-protocol-dissector-for-layer-1-ethernet-protcol/</guid>
      <description>how to add custom protocol dissector for layer 1 (ethernet) protcol  0 Hi,
I uses a custom protocol format to save packets, the full ethernet frame(eth-&amp;gt;ip-&amp;gt;tcp..) is prepended by my custom protocol header,
I want to add plugin in wireshark that displays My custom header and its subfields &amp;amp; then the actual protcol hierarchy like in order
MyProtcolName
-subheaderinfo1
-subheaderinfo2
Ethernet
ip
&amp;amp; so on,
Is it possible in wireshark to add protocol over layer1 protocols?</description>
    </item>
    
    <item>
      <title>how can i capture</title>
      <link>/questions/20056/how-can-i-capture/</link>
      <pubDate>Wed, 03 Apr 2013 07:50:00 +0000</pubDate>
      
      <guid>/questions/20056/how-can-i-capture/</guid>
      <description>how can i capture  0 how can i capture packages from a remote computer?
capture computer fromasked 03 Apr &#39;13, 07:50
Roberto Ramo...
1●1●1●1
accept rate: 0%
 edited 03 Apr &#39;13, 11:16 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
0Have you seen this page in the Wireshark Wiki?
answered 03 Apr &#39;13, 14:23
Jasper ♦♦
23.8k●5●51●284
accept rate: 18%
     </description>
    </item>
    
    <item>
      <title>Wireshark &amp;#x27;fixes&amp;#x27; network issue - but how?</title>
      <link>/questions/20057/wireshark-fixes-network-issue-but-how/</link>
      <pubDate>Wed, 03 Apr 2013 07:57:00 +0000</pubDate>
      
      <guid>/questions/20057/wireshark-fixes-network-issue-but-how/</guid>
      <description>Wireshark &amp;lsquo;fixes&amp;rsquo; network issue - but how?  0 Hi All.
Here&#39;s the situation. My company has two sites. The two sites are connected via a sonicwall VPN. We have a licence server that provides software licences via UDP port 5093 at one of the sites. Clients local to that site can pull licences without a problem. Clients at the remote site cannot.
If i start wireshark on a remote client and perform a packet capture of all traffic on UDP 5093.</description>
    </item>
    
    <item>
      <title>Persistent connection from questionable IP address on port 443</title>
      <link>/questions/20061/persistent-connection-from-questionable-ip-address-on-port-443/</link>
      <pubDate>Wed, 03 Apr 2013 09:28:00 +0000</pubDate>
      
      <guid>/questions/20061/persistent-connection-from-questionable-ip-address-on-port-443/</guid>
      <description>Persistent connection from questionable IP address on port 443  0 For a small business setup, I have a Windows 2008 server acting as AD domain controller and Exchange 2007 server. I&#39;ve recently begun to look further into all network activity and notice something unusual to me involving this server. There is a persistent connection between it and a Verizon wireless IP address (174.254.24.191, 174.240.0.73, 174.254.1.124 to name a few) always geolocated in Las Vegas.</description>
    </item>
    
    <item>
      <title>iptrace aix - editcap and tshark</title>
      <link>/questions/20062/iptrace-aix-editcap-and-tshark/</link>
      <pubDate>Wed, 03 Apr 2013 09:39:00 +0000</pubDate>
      
      <guid>/questions/20062/iptrace-aix-editcap-and-tshark/</guid>
      <description>iptrace aix - editcap and tshark  0 Hello, I often have to look at aix iptrace and cannot use editcap to split the trace unless I specify the -F nettl option. I prefer to use the pcapng format these days for its annotation features. Is there any reason why aic iptraces cannot be converted into pcapng?
iptrace pcapng editcap aix tsharkasked 03 Apr &#39;13, 09:39
mrEEde
3.9k●15●22●70
accept rate: 20%</description>
    </item>
    
    <item>
      <title>Constant RTT in slow start</title>
      <link>/questions/20071/constant-rtt-in-slow-start/</link>
      <pubDate>Wed, 03 Apr 2013 19:44:00 +0000</pubDate>
      
      <guid>/questions/20071/constant-rtt-in-slow-start/</guid>
      <description>Constant RTT in slow start  0 Hello everybody,
I&#39;m analyzing a round trip time graph that was acquired by using wireshark. It&#39;s a slow start algorithm, so I am looking at an increasing RTT at the beginning, but around sequence number 130000, RTT becomes constant, then starts increasing again. I&#39;m trying to find what causes this.
Thanks
rtt graph wiresharkasked 03 Apr &#39;13, 19:44
Cemil Toygan...
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>what is the process to contribute a plugin to wireshark community</title>
      <link>/questions/20072/what-is-the-process-to-contribute-a-plugin-to-wireshark-community/</link>
      <pubDate>Wed, 03 Apr 2013 23:24:00 +0000</pubDate>
      
      <guid>/questions/20072/what-is-the-process-to-contribute-a-plugin-to-wireshark-community/</guid>
      <description>what is the process to contribute a plugin to wireshark community  0 I want to contribute my amf plugin to wireshark community. Please provide me with the details of the contribution process
community wiresharkasked 03 Apr &#39;13, 23:24
Akhil
53●27●28●31
accept rate: 0%
  
One Answer:
  
2From the &#34;Develop -&amp;gt; Get Involved&#34; page on the Wireshark website:
If you have changes you want included in Wireshark, please attach it to a bug report and mark it for review.</description>
    </item>
    
    <item>
      <title>monitoring icmp using tcpdump</title>
      <link>/questions/20073/monitoring-icmp-using-tcpdump/</link>
      <pubDate>Wed, 03 Apr 2013 23:29:00 +0000</pubDate>
      
      <guid>/questions/20073/monitoring-icmp-using-tcpdump/</guid>
      <description>monitoring icmp using tcpdump  0 i am new to tcpdump
when i used
tcpdump -i cloudbr0 icmp
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on cloudbr0, link-type EN10MB (Ethernet), capture size 65535 bytes
11:20:42.844355 IP 112.X.X.13 &amp;gt; 115.X.X.62: ICMP echo request, id 512, seq 25623, length 8
i believe this means 112.X.X.13 is making ICMP request to 115.X.X.62
But none of the above ip belongs to me nor to my virtual machines.</description>
    </item>
    
    <item>
      <title>Is there a way to decode the MIME type message/cpim (rfc3862)?</title>
      <link>/questions/20077/is-there-a-way-to-decode-the-mime-type-messagecpim-rfc3862/</link>
      <pubDate>Thu, 04 Apr 2013 04:25:00 +0000</pubDate>
      
      <guid>/questions/20077/is-there-a-way-to-decode-the-mime-type-messagecpim-rfc3862/</guid>
      <description>Is there a way to decode the MIME type message/cpim (rfc3862)?  0 If not, how can a development of a wireshark extension be requested/promoted?
cpimasked 04 Apr &#39;13, 04:25
AndroidAndy
1●1●1●1
accept rate: 0%
  
One Answer:
  
0The best you can do is provide a developer with all the data he or she needs to make and test such a thing. Therefore you can file an enhancement bug with this request, references to relevant standards, and most importantly sample capture files.</description>
    </item>
    
    <item>
      <title>capture only gsm_sms protocol</title>
      <link>/questions/20079/capture-only-gsm_sms-protocol/</link>
      <pubDate>Thu, 04 Apr 2013 06:58:00 +0000</pubDate>
      
      <guid>/questions/20079/capture-only-gsm_sms-protocol/</guid>
      <description>capture only gsm_sms protocol  0 Hello!
I need to capture only (!!!) gsm_sms protocol from the SS7 stream with the help of the tshark. But unfortunately I could not find any useful information in Internet how to create such filter. Maybe somebody could help me with this? Any examples or links...
Any help will be appreciated! Thanks!
gsm_sms tshark ss7asked 04 Apr &#39;13, 06:58
domeno
21●6●6●11
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Build issue on Windows 7, 64bit with MSVC2010</title>
      <link>/questions/20083/build-issue-on-windows-7-64bit-with-msvc2010/</link>
      <pubDate>Thu, 04 Apr 2013 09:09:00 +0000</pubDate>
      
      <guid>/questions/20083/build-issue-on-windows-7-64bit-with-msvc2010/</guid>
      <description>Build issue on Windows 7, 64bit with MSVC2010  0 Hi,
I have a build issue when building Wireshark on Windows 7, 64bit and MSVC2010. The error log returned is:
Build Log Build started: Project: packaging, Configuration: PortableApps|Win32 Command Lines Creating temporary file &amp;quot;C:\Users\RICHAR~1\AppData\Local\Temp\BAT00000357762912.bat&amp;quot; with contents [ @echo off nmake -f Makefile.nmake packaging_papps
if errorlevel 1 goto VCReportError
goto VCEnd
:VCReportError
echo Project : error PRJ0019: A tool returned an error code from &amp;quot;Performing Makefile project actions&amp;quot;</description>
    </item>
    
    <item>
      <title>Strange Delay</title>
      <link>/questions/20086/strange-delay/</link>
      <pubDate>Thu, 04 Apr 2013 10:42:00 +0000</pubDate>
      
      <guid>/questions/20086/strange-delay/</guid>
      <description>Strange Delay  0 I am trying to get TCP and HTML working on &#34;Friendyarm&#34; board. The delays that I see in Wireshark are long. I get a &#34;syn&#34; packet and it shows that I sent the &#34;syn&#34; &#34;ack&#34; packet back 256 milliseconds later. There is no reason for this delay. It then gets worse. After getting the &#34;ack&#34; followed by the &#34;psh&#34; &#34;ack&#34; packet (with the HTML GET request) my response shows up about 3 seconds later - and meanwhile IE resets the connection.</description>
    </item>
    
    <item>
      <title>Where is the 1.9.X codebase branches?</title>
      <link>/questions/20093/where-is-the-19x-codebase-branches/</link>
      <pubDate>Thu, 04 Apr 2013 15:34:00 +0000</pubDate>
      
      <guid>/questions/20093/where-is-the-19x-codebase-branches/</guid>
      <description>Where is the 1.9.X codebase branches?  0 With SVN browser, I see releases only up to 1.8.6, but it looks like the latest is 1.9.3 with a development release at 1.9.2.
Where would the 1.9.X be if we wanted to do work forked off of those?
1.9 repository trunkasked 04 Apr &#39;13, 15:34
joeEmbed
16●2●2●3
accept rate: 0%
  
2 Answers:
  
0trunk
answered 04 Apr &#39;13, 16:15</description>
    </item>
    
    <item>
      <title>p2p set top box tracking</title>
      <link>/questions/20097/p2p-set-top-box-tracking/</link>
      <pubDate>Thu, 04 Apr 2013 22:37:00 +0000</pubDate>
      
      <guid>/questions/20097/p2p-set-top-box-tracking/</guid>
      <description>p2p set top box tracking  0 I was shown a demonstration of wireshark a few months ago. We were trying to trace the ip addresses and country of origin from a p2p iptv set top box. I&#39;m not sure if he had any add ons to the wireshark software. I want to set up the same scenario. The stb was connected to the internet and to a laptop via a small 3 way switch.</description>
    </item>
    
    <item>
      <title>Packet Cable Lawful Intercept marking on VoIP capture</title>
      <link>/questions/20098/packet-cable-lawful-intercept-marking-on-voip-capture/</link>
      <pubDate>Thu, 04 Apr 2013 23:11:00 +0000</pubDate>
      
      <guid>/questions/20098/packet-cable-lawful-intercept-marking-on-voip-capture/</guid>
      <description>Packet Cable Lawful Intercept marking on VoIP capture  0 While running a pcap on a Samsung VoIP set, I saw that packets that I know were part of an audio stream were simply identified as UDP and not rtp. A closer look showed 2 IP headers, the first one was in the usual place and the second was sandwiched between the data portion and another part of the header shown as &#34;</description>
    </item>
    
    <item>
      <title>capturing packets on Windows 7 when a data card is being used</title>
      <link>/questions/20099/capturing-packets-on-windows-7-when-a-data-card-is-being-used/</link>
      <pubDate>Thu, 04 Apr 2013 23:37:00 +0000</pubDate>
      
      <guid>/questions/20099/capturing-packets-on-windows-7-when-a-data-card-is-being-used/</guid>
      <description>capturing packets on Windows 7 when a data card is being used  0 hello I am a starter for wireshark.I am trying to capture packets using a reliance data card and my os is windows 7.In the interfaces list the ip of this datacard is not being shown .Can u help me Yamini
capture windows7 packetsasked 04 Apr &#39;13, 23:37
yamini
1●1●1●1
accept rate: 0%
 edited 06 Apr &#39;13, 10:42</description>
    </item>
    
    <item>
      <title>How to get Profinet IO payload to .csv</title>
      <link>/questions/20108/how-to-get-profinet-io-payload-to-csv/</link>
      <pubDate>Fri, 05 Apr 2013 04:19:00 +0000</pubDate>
      
      <guid>/questions/20108/how-to-get-profinet-io-payload-to-csv/</guid>
      <description>How to get Profinet IO payload to .csv  0 Hello
What are the magic words with tshark (or some other way) to get Profinet IO log as csv format with IO payload?
I can transform the log to csv and I&#39;ve tried all the display filter fields for pn_io http://www.wireshark.org/docs/dfref/p/pn_io.html and others, but I can&#39;t get the payload. Some field which seemed to contain payload (by field name) prints just word &#39;data&#39;.</description>
    </item>
    
    <item>
      <title>problem with tcp/ip decoding</title>
      <link>/questions/20109/problem-with-tcpip-decoding/</link>
      <pubDate>Fri, 05 Apr 2013 04:38:00 +0000</pubDate>
      
      <guid>/questions/20109/problem-with-tcpip-decoding/</guid>
      <description>problem with tcp/ip decoding  0 Hi, I noticed this question as &#34;problem with tcp/ip decoding&#34;, but may be dog is buried elsewhere. I have a streams with asterix radar data. For reading I am using wireshark 1.0.7 with built-in asterix plugin. The decoding gives nothing readable. I have testing streams and the asterix plugin works perfectly for them. What I noticed that in my streams wireshark properly recognize the the TCP and IP header&#39;s lengths as 20 bytes but correspondence numbers in the header are wrong:</description>
    </item>
    
    <item>
      <title>no Remote interfaces tab</title>
      <link>/questions/20110/no-remote-interfaces-tab/</link>
      <pubDate>Fri, 05 Apr 2013 04:45:00 +0000</pubDate>
      
      <guid>/questions/20110/no-remote-interfaces-tab/</guid>
      <description>no Remote interfaces tab  0 Hi, I am using Wireshark 1.8.6 under Virtual machine with Win XP for remote capturing and there is no problems. But when I&#39;ve tried to do this under host Debian (Wheezy) operating system with the Wireshark 1.8.2 there is no Remote Interfaces tab at all.
interfaces remote tabasked 05 Apr &#39;13, 04:45
furna
11●2●2●3
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Trying to ID data within packets.</title>
      <link>/questions/20118/trying-to-id-data-within-packets/</link>
      <pubDate>Fri, 05 Apr 2013 09:09:00 +0000</pubDate>
      
      <guid>/questions/20118/trying-to-id-data-within-packets/</guid>
      <description>Trying to ID data within packets.  0 Hello! We use a product called Deepfreeze to restart and shutdown PC&#39;s. There are 1200 PC&#39;s reporting to the Deepfreeze server / console. I have a test environment with one PC reporting to a test server that mirrors our current configuration.
We have an issue where workstations are restarting / shutting down &#34;on their own&#34;. Unfortunately due to the nature of workplace (us vs them) and the finger pointing has started.</description>
    </item>
    
    <item>
      <title>Slow downloading of data</title>
      <link>/questions/20119/slow-downloading-of-data/</link>
      <pubDate>Fri, 05 Apr 2013 10:12:00 +0000</pubDate>
      
      <guid>/questions/20119/slow-downloading-of-data/</guid>
      <description>Slow downloading of data  0 We are facing issue with slow downloading of data from any website whether inside our network or on internet. Could someone please help me with document that could help us isolate cause of issue.
download wiresharkasked 05 Apr &#39;13, 10:12
m_1607
35●12●13●16
accept rate: 0%
 edited 06 Apr &#39;13, 08:54 
grahamb ♦
19.8k●3●30●206
slow downloading of data from any website
do you mean low download rate or slow start of connections?</description>
    </item>
    
    <item>
      <title>iSCSI troubleshooting help</title>
      <link>/questions/20120/iscsi-troubleshooting-help/</link>
      <pubDate>Fri, 05 Apr 2013 11:30:00 +0000</pubDate>
      
      <guid>/questions/20120/iscsi-troubleshooting-help/</guid>
      <description>iSCSI troubleshooting help  0 Currently, I am troubleshooting a iSCSI performance issue which looks like is a buffer capacity issue on my switches. I see messages on my captures which have &#34;TCP Dup ACK&#34; and &#34;TCP Previous segment not captured&#34;. My environment consists of vmware hypervisor using software iscsi initiators connecting over a low-end catalyst 2960S switch to VNX SAN.
What I would like to determine from my captures is getting a metric of when packets start to drop.</description>
    </item>
    
    <item>
      <title>Help about wireshark</title>
      <link>/questions/20123/help-about-wireshark/</link>
      <pubDate>Sat, 06 Apr 2013 03:36:00 +0000</pubDate>
      
      <guid>/questions/20123/help-about-wireshark/</guid>
      <description>Help about wireshark  0 Hi,
I am a student in Croatia at the Faculty of traffic and transport science and I am doing a degree work about wireshark. I already have some books, but could You please send me some materials or books about wireshark on my e-mail or tell we wich is the best book or materials to study with so I could best present wireshark and it&#39;s features?</description>
    </item>
    
    <item>
      <title>Voip capture on a Grandstream GXP2000</title>
      <link>/questions/20136/voip-capture-on-a-grandstream-gxp2000/</link>
      <pubDate>Sat, 06 Apr 2013 10:26:00 +0000</pubDate>
      
      <guid>/questions/20136/voip-capture-on-a-grandstream-gxp2000/</guid>
      <description>Voip capture on a Grandstream GXP2000  0 I want to capture SIP packets from a Grandstream GXP2000. All the tutorials I see is to capture local packets on a local machine, is it possible to capture the data if I know the local ip of the unit and the port used?
gxp2000 voipasked 06 Apr &#39;13, 10:26
irishbiker
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Capturing UDP packets sent from my own app</title>
      <link>/questions/20139/capturing-udp-packets-sent-from-my-own-app/</link>
      <pubDate>Sat, 06 Apr 2013 13:37:00 +0000</pubDate>
      
      <guid>/questions/20139/capturing-udp-packets-sent-from-my-own-app/</guid>
      <description>Capturing UDP packets sent from my own app  0 Hi, I got a problem using Wireshark.
I am writing an app which connects to a device via UDP protocol and receives some of its data. I could really use knowledge of what I am sending and receiving, since there is something wrong with the app.
While I am connected to the Internet, Wireshark works just fine, but when I switch the cable to connect to the device I cannot capture anything (well, there is something, but I can&#39;t see the packets I am sending using the app).</description>
    </item>
    
    <item>
      <title>TCP exchange works but no web page</title>
      <link>/questions/20140/tcp-exchange-works-but-no-web-page/</link>
      <pubDate>Sat, 06 Apr 2013 16:12:00 +0000</pubDate>
      
      <guid>/questions/20140/tcp-exchange-works-but-no-web-page/</guid>
      <description>TCP exchange works but no web page  0 I am working on a small embedded web server for a &#34;friendlyarm&#34; with no OS.
http://www.cttestset.com/gothru.JPG
As shown in this picture it appears to go thru the connection negotiation just fine but IE still says it can&#39;t show the webpage. Any ideas ?
server ie tcp wiresharkasked 06 Apr &#39;13, 16:12
Vernon Lermond
1●2●2●2
accept rate: 0%
that Screenshot doesn&#39;t help much because it doesn&#39;t show decoded HTTP, probably because you didn&#39;t use port 80 or any other well known HTTP port on your server.</description>
    </item>
    
    <item>
      <title>How to display &amp;quot; Full request URI&amp;quot; in the Columns please?</title>
      <link>/questions/20143/how-to-display-full-request-uri-in-the-columns-please/</link>
      <pubDate>Sat, 06 Apr 2013 19:58:00 +0000</pubDate>
      
      <guid>/questions/20143/how-to-display-full-request-uri-in-the-columns-please/</guid>
      <description>How to display &amp;quot; Full request URI&amp;quot; in the Columns please?  0 Hi, I got a problem using Wireshark. When I used wireshark to capture packets,only display seven columns,number,time,source IP,destination IP,protocal,length,infomation.I want to display &#34;Full request URI&#34;,But there are no &#34;Full reques URI&#34; in the &#34;Display All&#34; which contained in the &#34;Displayed columns&#34;.How to display &#34; Full request URI&#34; in the Columns please?
Tips:I had seen someone&#39;s wireshark that could display &#34;</description>
    </item>
    
    <item>
      <title>&amp;quot;View Menu &amp;gt; Name Resolution &amp;gt; Resolve Name&amp;quot; doesn&amp;#x27;t seem to work</title>
      <link>/questions/20151/view-menu-name-resolution-resolve-name-doesnt-seem-to-work/</link>
      <pubDate>Sun, 07 Apr 2013 07:21:00 +0000</pubDate>
      
      <guid>/questions/20151/view-menu-name-resolution-resolve-name-doesnt-seem-to-work/</guid>
      <description>&amp;ldquo;View Menu &amp;gt; Name Resolution &amp;gt; Resolve Name&amp;rdquo; doesn&amp;rsquo;t seem to work  0 My understanding from the documentation at http://www.wireshark.org/docs/wsug_html_chunked/ChUseViewMenuSection.html is that clicking &#34;View Menu &amp;gt; Name Resolution &amp;gt; Resolve Name&#34; should perform name resolution on the currently selected packet. This is, or would be, a very useful feature, as I typically don&#39;t want to turn on network name resolution to prevent the additional reverse DNS queries during a capture, for a couple reasons.</description>
    </item>
    
    <item>
      <title>Monitoring wifi access.</title>
      <link>/questions/20152/monitoring-wifi-access/</link>
      <pubDate>Sun, 07 Apr 2013 10:35:00 +0000</pubDate>
      
      <guid>/questions/20152/monitoring-wifi-access/</guid>
      <description>Monitoring wifi access.  0 My son is a normal teenager and i have a feeling he is accessing inappropriate sites. Is there a way i can see the sites he is accessing on his ipad by looking at my wifi?
access wifiasked 07 Apr &#39;13, 10:35
BrooklynBoy77
1●1●1●1
accept rate: 0%
  
One Answer:
  
1Yes, if you
have a wifi card and operating system that allows Wireshark to capture the WiFi radio layer.</description>
    </item>
    
    <item>
      <title>Windows size 256</title>
      <link>/questions/20156/windows-size-256/</link>
      <pubDate>Sun, 07 Apr 2013 17:08:00 +0000</pubDate>
      
      <guid>/questions/20156/windows-size-256/</guid>
      <description>Windows size 256  0 I have a server that is running and the user says that the application is running very slowly. I did a capture and I found that the window size for the server was very small, but there were no window updates, no zero windows, and no full windows. I suggested that he optimize the TCP/IP setting on the server to improve the performance. I will paste a few frames so you can get an idea of what I am talking about.</description>
    </item>
    
    <item>
      <title>amin protocol compilation</title>
      <link>/questions/20162/amin-protocol-compilation/</link>
      <pubDate>Sun, 07 Apr 2013 23:45:00 +0000</pubDate>
      
      <guid>/questions/20162/amin-protocol-compilation/</guid>
      <description>amin protocol compilation  0 while compiling the AMIN protocol,the command nmake all gives these errors:
packet-amin.c packet-amin.c(78) : error C2220: warning treated as error - no &amp;#39;object&amp;#39; file generated packet-amin.c(78) : warning C4013: &amp;#39;dissector_add&amp;#39; undefined; assuming extern returning int NMAKE : fatal error U1077: &amp;#39;&amp;quot;C:\Program Files\Microsoft Visual Studio 10.0\VC\Bin\cl.EXE&amp;quot;&amp;#39; : return code &amp;#39;0x2&amp;#39;.i had removed &#34;,0&#34; from plugin.rc file in amin dir as suggested somewhere.but still build doesn&#39;t work. somebody.</description>
    </item>
    
    <item>
      <title>SNMP and Destination IP Address</title>
      <link>/questions/20174/snmp-and-destination-ip-address/</link>
      <pubDate>Mon, 08 Apr 2013 07:01:00 +0000</pubDate>
      
      <guid>/questions/20174/snmp-and-destination-ip-address/</guid>
      <description>SNMP and Destination IP Address  0 Hello All,
Just starting out using Wireshark and I have all kinds of SNMP traffic from a inside source going to several destination IP addresses in the private subnet range that are not IP&#39;s that I use in my network. Why would these addresses show?
Thanks in advance.
snmpwiresharkasked 08 Apr &#39;13, 07:01
mccullrr
1●1●1●1
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Can Wireshark get around AP isolation?</title>
      <link>/questions/20177/can-wireshark-get-around-ap-isolation/</link>
      <pubDate>Mon, 08 Apr 2013 07:18:00 +0000</pubDate>
      
      <guid>/questions/20177/can-wireshark-get-around-ap-isolation/</guid>
      <description>Can Wireshark get around AP isolation?  0 If a network router has been set to isolate every client (clients cannot see or communicate with each other) like in a VPN, will Wireshark be able to read the packets of other computers on the network?
access accesspointasked 08 Apr &#39;13, 07:18
Charlie Kucu...
16●1●1●4
accept rate: 0%
  
One Answer:
  
2 Your question title is:</description>
    </item>
    
    <item>
      <title>Query on tcp segment of a reassembled pdu option</title>
      <link>/questions/20193/query-on-tcp-segment-of-a-reassembled-pdu-option/</link>
      <pubDate>Mon, 08 Apr 2013 12:14:00 +0000</pubDate>
      
      <guid>/questions/20193/query-on-tcp-segment-of-a-reassembled-pdu-option/</guid>
      <description>Query on tcp segment of a reassembled pdu option  0 I am aware of what this feature does but i would like to know more on when to enable this feature and when to disable it.
When i enable the tcp reassembly i am not seeing any HTTP 200 OK Responses but seeing tcp segment of reassembled pdu.
When i disable the tcp reassembly i am seeing HTTP 200 OK response.</description>
    </item>
    
    <item>
      <title>http-google101.pcapng</title>
      <link>/questions/20195/http-google101pcapng/</link>
      <pubDate>Mon, 08 Apr 2013 12:25:00 +0000</pubDate>
      
      <guid>/questions/20195/http-google101pcapng/</guid>
      <description>http-google101.pcapng  0 I just purchased wirehark 101 essentials. I am trying to figure out where is http-google101.pcapng.
Can someone help me out
Thanks
book supplementsasked 08 Apr &#39;13, 12:25
rikshaw
11●2●2●3
accept rate: 0%
 edited 08 Apr &#39;13, 13:10 
Jasper ♦♦
23.8k●5●51●284
  
One Answer:
  
4Go to
http://wiresharkbook.com/wireshark101.html
on left side of the page you see the book supplements.Please feel free to download them(includes lot of pcap traces associated to the book) and you can find your http-google101.</description>
    </item>
    
    <item>
      <title>Unable to set a display filter for a MAC address</title>
      <link>/questions/20200/unable-to-set-a-display-filter-for-a-mac-address/</link>
      <pubDate>Mon, 08 Apr 2013 13:39:00 +0000</pubDate>
      
      <guid>/questions/20200/unable-to-set-a-display-filter-for-a-mac-address/</guid>
      <description>Unable to set a display filter for a MAC address  0 Using Wireshark with a wireless interface card, I have been foiled at using display filters for a MAC address.
After capturing traffic and seeing the desired MAC address in many Source and Destination rows, the right-click &amp;gt; Apply as Filter &amp;gt; Selected command fills in the Filter: field with the apparently correct eth.src statement with the desired MAC address, but this causes all displayed rows to go blank.</description>
    </item>
    
    <item>
      <title>Detecting Wireshark usage</title>
      <link>/questions/20201/detecting-wireshark-usage/</link>
      <pubDate>Mon, 08 Apr 2013 13:52:00 +0000</pubDate>
      
      <guid>/questions/20201/detecting-wireshark-usage/</guid>
      <description>Detecting Wireshark usage  0 Is it possible to determine if Wireshark is being used on my network. I&#39;ve found Wireshark installed on an office machine and would like to know if there is a way for me to determine if this machine is being used to capture packets on our network short of manually searching for saved captures on the machine. It would be best if I didn&#39;t have to have access to the actual machine running Wireshark to determine it.</description>
    </item>
    
    <item>
      <title>capture file on web http-google101.pcapng not similar to the one in Wireshark101 essentials book</title>
      <link>/questions/20214/capture-file-on-web-http-google101pcapng-not-similar-to-the-one-in-wireshark101-essentials-book/</link>
      <pubDate>Mon, 08 Apr 2013 16:07:00 +0000</pubDate>
      
      <guid>/questions/20214/capture-file-on-web-http-google101pcapng-not-similar-to-the-one-in-wireshark101-essentials-book/</guid>
      <description>capture file on web http-google101.pcapng not similar to the one in Wireshark101 essentials book  0 It looks like the http-google101.pcapng capture does not look similar to the one in the Wireshark 101 essentials book. Please look at Frames 10 and 11. The book shows as getting valid response but the capture file has lot of TCP segmented PDU information
FYI&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
goodasked 08 Apr &#39;13, 16:07
rikshaw
11●2●2●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Any plan for analytics support in wireshark?</title>
      <link>/questions/20222/any-plan-for-analytics-support-in-wireshark/</link>
      <pubDate>Mon, 08 Apr 2013 16:49:00 +0000</pubDate>
      
      <guid>/questions/20222/any-plan-for-analytics-support-in-wireshark/</guid>
      <description>Any plan for analytics support in wireshark?  0 Hi Developers,
Any plan for Analytics support in wireshark ? As lots and lots of applications are getting developed in each and every category(Games,Social Networking,News,Financials,Adult content etc..) and it might be good that if wireshark gives a nice overview with charts(Bar/pie etc..)to make end user more informed about traffic patterns.
analytics wiresharkasked 08 Apr &#39;13, 16:49
krishnayeddula
629●35●41●48
accept rate: 6%</description>
    </item>
    
    <item>
      <title>RTP Statistics</title>
      <link>/questions/20234/rtp-statistics/</link>
      <pubDate>Tue, 09 Apr 2013 05:03:00 +0000</pubDate>
      
      <guid>/questions/20234/rtp-statistics/</guid>
      <description>RTP Statistics  0 After capturing some RTP traffic i see the following
Now i&amp;#39;m having troubles intepreting the Mean Jitter value. (looked on the forum but not alot info about it) So three questions
 Sot he max delta is the time difference between the packets correct? The mean jitter is a calculation between the max delta and max jitter? What is max skew?  Thanks in advance!
Sicartpasked 09 Apr &amp;lsquo;13, 05:03</description>
    </item>
    
    <item>
      <title>TCP analysis</title>
      <link>/questions/20240/tcp-analysis/</link>
      <pubDate>Tue, 09 Apr 2013 10:16:00 +0000</pubDate>
      
      <guid>/questions/20240/tcp-analysis/</guid>
      <description>TCP analysis  0 Hi all,
Could anyone please explain the difference between &#34;tcp.analysis.lost_segment&#34; and &#34;tcp.analysis.ack_lost_segment&#34;?. My goal is to make some counting on what is the percentage of lost packet during tcp communication. Or, if you have any better idea how to do this.
Thank you VERY MUCH,
radim
loss packet tcpasked 09 Apr &#39;13, 10:16
radim0574
11●3●3●4
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How to Packet capture in TCP Offload engines?</title>
      <link>/questions/20254/how-to-packet-capture-in-tcp-offload-engines/</link>
      <pubDate>Tue, 09 Apr 2013 15:54:00 +0000</pubDate>
      
      <guid>/questions/20254/how-to-packet-capture-in-tcp-offload-engines/</guid>
      <description>How to Packet capture in TCP Offload engines?  0 I am working on TCP Offload engine(for Iscsi). I am looking a way to capture those offloaded(to the chip) packets(TCP and Iscsi) with wireshark. My colleagues are saying that only 3rd party test equipment is the alternative(which sits in between iscsi initiator and iscsi target) for looking in to packets. I want to double confirm with experts here.Thanks.
iscsi tcpoffloadasked 09 Apr &#39;13, 15:54</description>
    </item>
    
    <item>
      <title>WLAN Capture setup</title>
      <link>/questions/20257/wlan-capture-setup/</link>
      <pubDate>Tue, 09 Apr 2013 17:26:00 +0000</pubDate>
      
      <guid>/questions/20257/wlan-capture-setup/</guid>
      <description>WLAN Capture setup  0 i&#39;m after the same goal: identifying a single machine on the network that may be using a lot of bandwidth. i have Wireshark doing a Capture in Promiscuous mode, supposedly capturing all the traffic on the WLAN. but my phone, which has been streaming Pandora for hours, only shows as having transmitted 138 bytes. can anyone point me in the right direction to improve my reading?</description>
    </item>
    
    <item>
      <title>RTP and RTCP Multiplex dissector</title>
      <link>/questions/20258/rtp-and-rtcp-multiplex-dissector/</link>
      <pubDate>Tue, 09 Apr 2013 19:40:00 +0000</pubDate>
      
      <guid>/questions/20258/rtp-and-rtcp-multiplex-dissector/</guid>
      <description>RTP and RTCP Multiplex dissector  0 According to RFC 5761: &#34;Multiplexing RTP Data and Control Packets on a Single Port&#34;, RTP and RTCP packets are on the same ports.Can wireshark decode RTCP packets from the Multiplex packets?
rtcp rtp multiplexasked 09 Apr &#39;13, 19:40
west
1●1●1●1
accept rate: 0%
 edited 11 Apr &#39;13, 04:10 
Jaap ♦
11.7k●16●101
  
One Answer:
  
0There is already an enhancement bug to implement that functionality</description>
    </item>
    
    <item>
      <title>IP packets list as data</title>
      <link>/questions/20263/ip-packets-list-as-data/</link>
      <pubDate>Wed, 10 Apr 2013 00:25:00 +0000</pubDate>
      
      <guid>/questions/20263/ip-packets-list-as-data/</guid>
      <description>IP packets list as data  0 What is the expression to find all of the IP packets listed as Data??
ip dataasked 10 Apr &#39;13, 00:25
Ramyarani
1●2●2●2
accept rate: 0%
 edited 10 Apr &#39;13, 03:57 
Jaap ♦
11.7k●16●101
I don&#39;t understand. Can you please add more details? What are you interested? A list of IP addresses in a capture file?
(10 Apr &#39;13, 05:32) Kurt Knochner ♦   </description>
    </item>
    
    <item>
      <title>Split bundled packets into single</title>
      <link>/questions/20264/split-bundled-packets-into-single/</link>
      <pubDate>Wed, 10 Apr 2013 01:08:00 +0000</pubDate>
      
      <guid>/questions/20264/split-bundled-packets-into-single/</guid>
      <description>Split bundled packets into single  0 Hi,
I am wondering if there is an easy way to split bundled packets into separate. For example, I have a file which looks like this :
[IP][UDP][Header][Payload][Header2][Payloa2][Header3][Payload3][Header4][Payload4]
So it is one IP packet which has 4 smaller packets bundled into one, on one row in wireshark. I would like to put each individual packet on a separate line. So that the file looks like this :</description>
    </item>
    
    <item>
      <title>UDP port 1025 works in XP, but not Win 7</title>
      <link>/questions/20269/udp-port-1025-works-in-xp-but-not-win-7/</link>
      <pubDate>Wed, 10 Apr 2013 03:31:00 +0000</pubDate>
      
      <guid>/questions/20269/udp-port-1025-works-in-xp-but-not-win-7/</guid>
      <description>UDP port 1025 works in XP, but not Win 7  0 Hi,
I&#39;m trying to capture packets from my embedded board (IP 192.168.66.190, port 1025) using UDP. It&#39;s working fine in Windows XP, but it doesn&#39;t work in Windows 7. Wireshark is still able to detect the packets coming in, but there is nothing when a UDP listener is started on the same port.
1025 windows udp port 7asked 10 Apr &#39;13, 03:31</description>
    </item>
    
    <item>
      <title>programatically export the ssl session key</title>
      <link>/questions/20283/programatically-export-the-ssl-session-key/</link>
      <pubDate>Wed, 10 Apr 2013 07:08:00 +0000</pubDate>
      
      <guid>/questions/20283/programatically-export-the-ssl-session-key/</guid>
      <description>programatically export the ssl session key  0 1i am new to wireshark and trying to get a little exposer. Is there any way to export SSL session key through command line.
Please help me....
\Thanks in advance... :)
program exportasked 10 Apr &#39;13, 07:08
Amby
1●2●3●4
accept rate: 0%
  
3 Answers:
  
4As @SYN-bit said, there is no CLI option to do that.
But, you could run tshark with a SSL debug file and then extract the SSL session keys from the debug file.</description>
    </item>
    
    <item>
      <title>wireshark promiscuous mode</title>
      <link>/questions/20298/wireshark-promiscuous-mode/</link>
      <pubDate>Wed, 10 Apr 2013 20:28:00 +0000</pubDate>
      
      <guid>/questions/20298/wireshark-promiscuous-mode/</guid>
      <description>wireshark promiscuous mode  0 I am still seeing packets when i set this capture filter
!ether host ab:cd:ef:gh:ij:kl (packets not destined to my mac) and promiscuous mode disabled on the interface.
The protocols captured were IGMPV2 and SSDP. Would like to know the reason.Thanks
promiscuous-modeasked 10 Apr &#39;13, 20:28
krishnayeddula
629●35●41●48
accept rate: 6%
  
One Answer:
  
2 You are seeing this traffic because it&#39;s multicast traffic.</description>
    </item>
    
    <item>
      <title>Wireshark Win 7 x64 not showing incoming frames over 1518 bytes size despite of big MTU</title>
      <link>/questions/20310/wireshark-win-7-x64-not-showing-incoming-frames-over-1518-bytes-size-despite-of-big-mtu/</link>
      <pubDate>Thu, 11 Apr 2013 02:25:00 +0000</pubDate>
      
      <guid>/questions/20310/wireshark-win-7-x64-not-showing-incoming-frames-over-1518-bytes-size-despite-of-big-mtu/</guid>
      <description>Wireshark Win 7 x64 not showing incoming frames over 1518 bytes size despite of big MTU  0 I have changed the MTU to 1600 and do several tests with different setups. I get to capture and see in Wireshark &#34;big&#34; outgoing frames (i.e. 1600 bytes) but fail to see incoming &#34;big&#34; frames, despite I am totally certain those frames get the network adapter.
Any help would be very much appreciated.</description>
    </item>
    
    <item>
      <title>Capture email packets</title>
      <link>/questions/20312/capture-email-packets/</link>
      <pubDate>Thu, 11 Apr 2013 02:36:00 +0000</pubDate>
      
      <guid>/questions/20312/capture-email-packets/</guid>
      <description>Capture email packets  0 Hi, I am trying to capture email packets on my wired network but i dont get any. But alot of other network traffic is captured. The email client is hotmail. What might be the problem? :(
packets emailasked 11 Apr &#39;13, 02:36
Metall
11●2●2●3
accept rate: 0%
  
One Answer:
  
1Hotmail would mean that you access your email by web browser, which would mean that the data is transported via HTTP, not POP/IMAP, in case you&#39;re expecting these two protocols.</description>
    </item>
    
    <item>
      <title>how do i capture all traffic on a switch</title>
      <link>/questions/20328/how-do-i-capture-all-traffic-on-a-switch/</link>
      <pubDate>Thu, 11 Apr 2013 04:47:00 +0000</pubDate>
      
      <guid>/questions/20328/how-do-i-capture-all-traffic-on-a-switch/</guid>
      <description>how do i capture all traffic on a switch  0 I am trying to capture all traffic passing through a switch but i got only my traffic with the switch not other devices traffic though the port i used is configured as VLAN with other computers. Our instructor told us it is a WireShark setting issue, how do i change the setting to capture all traffic on that switch ?</description>
    </item>
    
    <item>
      <title>Using a Lua Script to Unbundle SCTP Multi-Chunk Packets and Generate Custom One-Line Summaries for Each Chunk</title>
      <link>/questions/20340/using-a-lua-script-to-unbundle-sctp-multi-chunk-packets-and-generate-custom-one-line-summaries-for-each-chunk/</link>
      <pubDate>Thu, 11 Apr 2013 08:36:00 +0000</pubDate>
      
      <guid>/questions/20340/using-a-lua-script-to-unbundle-sctp-multi-chunk-packets-and-generate-custom-one-line-summaries-for-each-chunk/</guid>
      <description>Using a Lua Script to Unbundle SCTP Multi-Chunk Packets and Generate Custom One-Line Summaries for Each Chunk  0 Hello everyone.
I&#39;ve got some question(s) regarding the usage of Lua to unbundle SCTP multi-chunk packets and create custom one-line summaries for each chunk.
The Question(s)
1) Is it possible to use a Lua script to retrieve specific fields within the dissection tree?
I&#39;m thinking of a Lua script because I&#39;ve seen that it is passed a reference to the dissection tree in some methods.</description>
    </item>
    
    <item>
      <title>WireShark ARP capture</title>
      <link>/questions/20342/wireshark-arp-capture/</link>
      <pubDate>Thu, 11 Apr 2013 11:00:00 +0000</pubDate>
      
      <guid>/questions/20342/wireshark-arp-capture/</guid>
      <description>WireShark ARP capture  0 i have a homework assignment that says:
Define a Display filter that finds the ARP queries and ARP responses Narrow down the filter so that only these ARP packets are shown that were necessary for opening your chosen webpage (the rest of the captured ARP packets that were exchanged between the nodes of LAN, should be left out of the list).
The thing is when i put arp in display filter, i get all arp packets.</description>
    </item>
    
    <item>
      <title>How to capture SIP / RTP traffic over wireless LAN? Is it possible to decrypt the SIP / RTP frame headers?</title>
      <link>/questions/20344/how-to-capture-sip-rtp-traffic-over-wireless-lan-is-it-possible-to-decrypt-the-sip-rtp-frame-headers/</link>
      <pubDate>Thu, 11 Apr 2013 11:21:00 +0000</pubDate>
      
      <guid>/questions/20344/how-to-capture-sip-rtp-traffic-over-wireless-lan-is-it-possible-to-decrypt-the-sip-rtp-frame-headers/</guid>
      <description>How to capture SIP / RTP traffic over wireless LAN? Is it possible to decrypt the SIP / RTP frame headers?  0 Hi Experts,
Am trying to capture SIP / RTP traffic from my wireless laptop. I&#39;m making a SIP call over Wireless. I can capture the 802.11 packets with appropriate QoS settings. But i dont&#39; see any SIP / RTP packets captured by the Wireshark.
Are we able to capture the SIP / RTP packets over WLAN?</description>
    </item>
    
    <item>
      <title>Creating custom column from multiple fields?</title>
      <link>/questions/20357/creating-custom-column-from-multiple-fields/</link>
      <pubDate>Thu, 11 Apr 2013 17:40:00 +0000</pubDate>
      
      <guid>/questions/20357/creating-custom-column-from-multiple-fields/</guid>
      <description>Creating custom column from multiple fields?  0 I work with packet captures from multiple wireless devices. Some of them use the radiotap headers to insert information like signal strength, channel, data rate, etc. Others use wlan headers for the same.
Currently I have multiple custom columns for each, one using the radiotap headers and one with the wlan headers, and I either have both sets displaying (one being blank and taking up screen space) or I have to switch back and forth between which ones are displayed.</description>
    </item>
    
    <item>
      <title>There are no SSL packets when I am capturing packets during the event of connecting to vpn using vpn client.</title>
      <link>/questions/20366/there-are-no-ssl-packets-when-i-am-capturing-packets-during-the-event-of-connecting-to-vpn-using-vpn-client/</link>
      <pubDate>Thu, 11 Apr 2013 20:55:00 +0000</pubDate>
      
      <guid>/questions/20366/there-are-no-ssl-packets-when-i-am-capturing-packets-during-the-event-of-connecting-to-vpn-using-vpn-client/</guid>
      <description>There are no SSL packets when I am capturing packets during the event of connecting to vpn using vpn client.  0 Hello;
There are no SSL packets when I am capturing packets during the event of connecting to vpn using vpn client. Is this obvious? I am not sure if it is. What i did is - With active internet connection only (no browser open doing nothing), I started wireshark capture.</description>
    </item>
    
    <item>
      <title>Wireshark filter &amp;quot;tcp&amp;quot; is also showing SIP packets</title>
      <link>/questions/20369/wireshark-filter-tcp-is-also-showing-sip-packets/</link>
      <pubDate>Fri, 12 Apr 2013 01:59:00 +0000</pubDate>
      
      <guid>/questions/20369/wireshark-filter-tcp-is-also-showing-sip-packets/</guid>
      <description>Wireshark filter &amp;ldquo;tcp&amp;rdquo; is also showing SIP packets  0 Hi all,
Why I type &#34; TCP &#34; in filter box in order to get TCP message,it still display SIP/SDP message ?
could you help me to find the reasion ?
thanks
filterasked 12 Apr &#39;13, 01:59
vhungvi
1●1●1●2
accept rate: 0%
 edited 16 Apr &#39;13, 00:12 
  
2 Answers:
  
1Type &#39;tcp&#39; in the display filter box, then click the &#39;Apply&#39; button.</description>
    </item>
    
    <item>
      <title>Capture POP3 packets</title>
      <link>/questions/20370/capture-pop3-packets/</link>
      <pubDate>Fri, 12 Apr 2013 02:23:00 +0000</pubDate>
      
      <guid>/questions/20370/capture-pop3-packets/</guid>
      <description>Capture POP3 packets  0 Hello
Im trying to analyze the POP3 traffic on my network but Wireshark doesn&#39;t capture anything on port 110 nor 995. What does this mean? Why can&#39;t I see any packets? Shouldn&#39;t I be able to even though they are encrypted?
Thank you
pop3asked 12 Apr &#39;13, 02:23
Metall
11●2●2●3
accept rate: 0%
  
One Answer:
  
2Yes, you should be if your capture setup is correct.</description>
    </item>
    
    <item>
      <title>Credit card data</title>
      <link>/questions/20382/credit-card-data/</link>
      <pubDate>Fri, 12 Apr 2013 07:45:00 +0000</pubDate>
      
      <guid>/questions/20382/credit-card-data/</guid>
      <description>Credit card data  0 Hi can Wireshark detect packets containing credit card information and block if necessary? thanks.
credit credit-cardasked 12 Apr &#39;13, 07:45
sxhutch
11●1●1●2
accept rate: 0%
  
One Answer:
  
3You could probably create a regular expression filter that matches data that looks like a credit card string, but you&#39;d need to build that expression first (or maybe find it somewhere). Blocking isn&#39;t possible; for that you need a data leakage prevention device that is put inline into the connection.</description>
    </item>
    
    <item>
      <title>I can&amp;#x27;t export SSL keys with a capture with more than one certificate configured</title>
      <link>/questions/20384/i-cant-export-ssl-keys-with-a-capture-with-more-than-one-certificate-configured/</link>
      <pubDate>Fri, 12 Apr 2013 10:04:00 +0000</pubDate>
      
      <guid>/questions/20384/i-cant-export-ssl-keys-with-a-capture-with-more-than-one-certificate-configured/</guid>
      <description>I can&amp;rsquo;t export SSL keys with a capture with more than one certificate configured  0 Hello, I&#39;m analysing the communication between a printer with its own certificate and a server with its own certificate (HTTPs). I&#39;m trying to test a client-server application environment and there&#39;s custom software installed inside the printer and inside the server. I&#39;ve configured 3 RSA Keys List entries: one for the server (443 port) and 2 for the printer (443 and 7627 ports).</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t install successfully on OS X 10.6.8</title>
      <link>/questions/20387/cant-install-successfully-on-os-x-1068/</link>
      <pubDate>Fri, 12 Apr 2013 13:28:00 +0000</pubDate>
      
      <guid>/questions/20387/cant-install-successfully-on-os-x-1068/</guid>
      <description>Can&amp;rsquo;t install successfully on OS X 10.6.8  0 I have XQuartz 2.7.4 installed and running. Installed Wireshark 10.6.8 (64bit). Trying to execute either from command line or from App icon gives the following error message. Any suggestions for next steps?
2013-04-12 16:22:01.218 defaults[503:903] The domain/default pair of (kCFPreferencesAnyApplication, AppleAquaColorVariant) does not exist 2013-04-12 16:22:01.242 defaults[504:903] The domain/default pair of (kCFPreferencesAnyApplication, AppleHighlightColor) does not exist dyld: Library not loaded: /usr/X11/lib/libpng12.0.dylib Referenced from: /Applications/Wireshark.</description>
    </item>
    
    <item>
      <title>large packet problem</title>
      <link>/questions/20389/large-packet-problem/</link>
      <pubDate>Sat, 13 Apr 2013 17:08:00 +0000</pubDate>
      
      <guid>/questions/20389/large-packet-problem/</guid>
      <description>large packet problem  0 We are having a issue with a client not being about to access a server. I don’t see a packet size large then 1518 going across the network, we think that may be the issue, we are seeing RST ACK and Retransmissions together I am not sure what that means, can anyone tell me what is retransmitting and why looking at the trace?
https://www.cloudshark.org/captures/103e92950859
mtu packet_sizeasked 13 Apr &#39;13, 17:08</description>
    </item>
    
    <item>
      <title>Why captured other unicast transmission on a switch? (NOT broadcast and NOT multicast)</title>
      <link>/questions/20390/why-captured-other-unicast-transmission-on-a-switch-not-broadcast-and-not-multicast/</link>
      <pubDate>Sun, 14 Apr 2013 01:35:00 +0000</pubDate>
      
      <guid>/questions/20390/why-captured-other-unicast-transmission-on-a-switch-not-broadcast-and-not-multicast/</guid>
      <description>Why captured other unicast transmission on a switch? (NOT broadcast and NOT multicast)  0 I&#39;ve been searching Internet and this forum for a few days, but still can&#39;t find the answer - why do I see a lot of transmission from 2 servers in the LAN? I work connected on the switch, no mirror port or anything like that, the packets are not brodcast packets nor multicast ... Very strange, can&#39;t figure why.</description>
    </item>
    
    <item>
      <title>Where is the Netgroup packet filter driver?</title>
      <link>/questions/20391/where-is-the-netgroup-packet-filter-driver/</link>
      <pubDate>Sun, 14 Apr 2013 02:42:00 +0000</pubDate>
      
      <guid>/questions/20391/where-is-the-netgroup-packet-filter-driver/</guid>
      <description>Where is the Netgroup packet filter driver?  0 Can we download this netgroup packet filter driver somewhere? It seems I am missing the driver.
windows winpcap driverasked 14 Apr &#39;13, 02:42
mples
11●1●1●2
accept rate: 0%
 converted to question 14 Apr &#39;13, 14:40 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
0The driver is provided by WinPCap. WinPCap is installed as part of the Wireshark installer, but can be downloaded and installed separately from here.</description>
    </item>
    
    <item>
      <title>How to Make the monitor computer shutup?</title>
      <link>/questions/20399/how-to-make-the-monitor-computer-shutup/</link>
      <pubDate>Sun, 14 Apr 2013 19:29:00 +0000</pubDate>
      
      <guid>/questions/20399/how-to-make-the-monitor-computer-shutup/</guid>
      <description>How to Make the monitor computer shutup?  0 I have had to disable my modems firewall, to get VOIP working. I&#39;d like to check what traffic is hitting my router and what its doing with it. I have put a hub between the modem and the router, this is out in Public IP world, not even DMZ. I have stolen a public IP for my monitors network card (static, no gateway).</description>
    </item>
    
    <item>
      <title>Losing connection</title>
      <link>/questions/20403/losing-connection/</link>
      <pubDate>Sun, 14 Apr 2013 22:22:00 +0000</pubDate>
      
      <guid>/questions/20403/losing-connection/</guid>
      <description>Losing connection  0 I have a very large capture of a server losing connection from the network for a second once a day, but everything is working fine from that point according to the user. Took a large capture of the communication, and I copy and paste a few lines here. I see the same dup ack and then a retransmission. I looked at the dup ack number which all point back to 445056 frame and the retransmission give a reason of unknown packet type.</description>
    </item>
    
    <item>
      <title>Download tracking</title>
      <link>/questions/20410/download-tracking/</link>
      <pubDate>Mon, 15 Apr 2013 03:32:00 +0000</pubDate>
      
      <guid>/questions/20410/download-tracking/</guid>
      <description>Download tracking  0 How to tracke downloadings in network using wireshrk?
urgent-helpasked 15 Apr &#39;13, 03:32
Gaurav Tiwari
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0I don&#39;t recommend trying to do that unless you have a small scope of applications you want to track downloads for, and know how to filter on downloads.
It is usually easier to enforce users to go through a proxy and use the proxy logs to track user activity.</description>
    </item>
    
    <item>
      <title>psprserver protocol with tcp 2354</title>
      <link>/questions/20412/psprserver-protocol-with-tcp-2354/</link>
      <pubDate>Mon, 15 Apr 2013 04:26:00 +0000</pubDate>
      
      <guid>/questions/20412/psprserver-protocol-with-tcp-2354/</guid>
      <description>psprserver protocol with tcp 2354  0 hi, i sniff on my external router and found alot duplicate ack and Ignored Unknown Record in the secure socket layer. The Destination port is to : psprserver (2354). ? i have try google to find out that protocol but no info is found.
protocolasked 15 Apr &#39;13, 04:26
splibytes
11●4●4●5
accept rate: 0%
  
One Answer:
  
1It is probably just the ephemeral port your client uses, and which is only used temporarily.</description>
    </item>
    
    <item>
      <title>The win7 environment that packet is greater than the maximum Ethernet size</title>
      <link>/questions/20413/the-win7-environment-that-packet-is-greater-than-the-maximum-ethernet-size/</link>
      <pubDate>Mon, 15 Apr 2013 04:39:00 +0000</pubDate>
      
      <guid>/questions/20413/the-win7-environment-that-packet-is-greater-than-the-maximum-ethernet-size/</guid>
      <description>The win7 environment that packet is greater than the maximum Ethernet size  0 During the data analysis process, the client packet greater than the size of the Ethernet standard. Can help explain why. https://www.cloudshark.org/captures/8e164cd10b06 thank you.
analysis tcpasked 15 Apr &#39;13, 04:39
mengsunny
11●4●4●6
accept rate: 0%
  
One Answer:
  
1You captured on the PC with the IP address 21.235.28.153, which had &#34;TCP large send offloading&#34;</description>
    </item>
    
    <item>
      <title>Creating multiple entries in the GUI for single parsed buffer</title>
      <link>/questions/20422/creating-multiple-entries-in-the-gui-for-single-parsed-buffer/</link>
      <pubDate>Mon, 15 Apr 2013 08:00:00 +0000</pubDate>
      
      <guid>/questions/20422/creating-multiple-entries-in-the-gui-for-single-parsed-buffer/</guid>
      <description>Creating multiple entries in the GUI for single parsed buffer  0 Hi,
I am a newbie so please direct me to existing data if such exists (I was not succesful at finding).
I am implementing a new proprietary protocolto view my company&#39;s device traces. The protocol packets arrive packed in a buffer on a specific UDP port.
My wish is to show each packet as a new entry in the main GUI even though they arrive inside a single buffer.</description>
    </item>
    
    <item>
      <title>[PSH,ACK] wireshark capture</title>
      <link>/questions/20423/pshack-wireshark-capture/</link>
      <pubDate>Mon, 15 Apr 2013 09:04:00 +0000</pubDate>
      
      <guid>/questions/20423/pshack-wireshark-capture/</guid>
      <description>[PSH,ACK] wireshark capture  0 I am capturing a https traffic from a PC to the web application and I am seeing an ACK follow by a PSH,ACK from the source to destination and vice versa:
PC [ACK] -&amp;gt; WebApp PC [PSH,ACK] -&amp;gt; WebApp WebApp [ACK] -&amp;gt; PC WebApp [PSH,ACK] -&amp;gt; PC
What does it mean? Thanks
pshasked 15 Apr &#39;13, 09:04
character9
16●10●10●12
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Short PDU in Iso Session Protocol 8327-1 (X.225)</title>
      <link>/questions/20426/short-pdu-in-iso-session-protocol-8327-1-x225/</link>
      <pubDate>Mon, 15 Apr 2013 10:11:00 +0000</pubDate>
      
      <guid>/questions/20426/short-pdu-in-iso-session-protocol-8327-1-x225/</guid>
      <description>Short PDU in Iso Session Protocol 8327-1 (X.225)  0 I just git-ted the source, looked into epan/dissectors/packet-ses.c and found only references to the canonical PDUs, those that one can find in the &#34;T-REC-X.225-199511-I!!PDF-E.pdf&#34;.
Is there any support for the short-PDUs, namely the ones contained in the Amendment 1 to the original protocol spec?
I don&#39;t understand when it is supposed to be used and I cannot even find either a library or a generated pcap about that.</description>
    </item>
    
    <item>
      <title>high value in &amp;quot;bytes in flight&amp;quot; and alot retranmission</title>
      <link>/questions/20429/high-value-in-bytes-in-flight-and-alot-retranmission/</link>
      <pubDate>Mon, 15 Apr 2013 10:22:00 +0000</pubDate>
      
      <guid>/questions/20429/high-value-in-bytes-in-flight-and-alot-retranmission/</guid>
      <description>high value in &amp;ldquo;bytes in flight&amp;rdquo; and alot retranmission  0 Hi, after reading on &#34;bytes in flight&#34;, if in my network i saw a high value under &#34;bytes in flight&#34; and sub sequences a lot retransmission, does it mean the remote side is no processing the data fast enough, so the acknowledgment are no being able send back. Due to this it cause the client to retransmit the data again ?</description>
    </item>
    
    <item>
      <title>Bit Rate Measurements</title>
      <link>/questions/20447/bit-rate-measurements/</link>
      <pubDate>Mon, 15 Apr 2013 21:52:00 +0000</pubDate>
      
      <guid>/questions/20447/bit-rate-measurements/</guid>
      <description>Bit Rate Measurements  0 A software engineer in my group is using Wireshark to help in some CAN bus performance testing. He tells me that the bit rate as reported by Wireshark exceeds the CAN bus configured bit rate, For example, the CAN bus configured bit rate is 100 Kbps and the measured bit rate (as reported by Wireshark) is 111 Kbps. How can this be?
bit bitrateasked 15 Apr &#39;13, 21:52</description>
    </item>
    
    <item>
      <title>all FP message can&amp;#x27;t been decode in the first time.</title>
      <link>/questions/20454/all-fp-message-cant-been-decode-in-the-first-time/</link>
      <pubDate>Tue, 16 Apr 2013 01:36:00 +0000</pubDate>
      
      <guid>/questions/20454/all-fp-message-cant-been-decode-in-the-first-time/</guid>
      <description>all FP message can&amp;rsquo;t been decode in the first time.  0 1,In debug mode,first time hit dissect_fp(),the input parameter:tree is always 0x00000000, then all FP message can&#39;t been decode in the first time.
why???
fp dissect_fp time tree firstasked 16 Apr &#39;13, 01:36
smilezuzu
20●32●32●37
accept rate: 0%
  
One Answer:
  
0Wireshark uses a two pass dissection strategy. The first (and the only linear) pass allows the dissector to setup state information, while in subsequent passes it may be asked for presentation details (a tree).</description>
    </item>
    
    <item>
      <title>FIFO vs CBWFQ throughput graph comparison</title>
      <link>/questions/20456/fifo-vs-cbwfq-throughput-graph-comparison/</link>
      <pubDate>Tue, 16 Apr 2013 02:18:00 +0000</pubDate>
      
      <guid>/questions/20456/fifo-vs-cbwfq-throughput-graph-comparison/</guid>
      <description>FIFO vs CBWFQ throughput graph comparison  0 Hi
I&#39;m trying to analyse these two throughput graphs for a dissertation. Could anyone shed some light on what this actually means. FIFO looks worse (and it should be) than CBWFQ, but what does this actually mean.
I&#39;m testing QoS schemes and this result comes from a congested 2MB serial link to see how each perform sending RTP, FTP and ICMP at the same time.</description>
    </item>
    
    <item>
      <title>Round trip time graph comparison</title>
      <link>/questions/20457/round-trip-time-graph-comparison/</link>
      <pubDate>Tue, 16 Apr 2013 02:31:00 +0000</pubDate>
      
      <guid>/questions/20457/round-trip-time-graph-comparison/</guid>
      <description>Round trip time graph comparison  0 Hi
I&#39;m trying to compare these round trip time graphs. Can anyone explain what is happening here with the two graphs please?
https://dl.dropboxusercontent.com/u/39248217/RTT%20CBWFQ.jpg https://dl.dropboxusercontent.com/u/39248217/RTT%20FIFO.jpg
Thanks very much Dan
rtt statistics qos tcp graphsasked 16 Apr &#39;13, 02:31
dscott1709
11●3●3●5
accept rate: 0%
  
One Answer:
  
0As I already mentioned in your other question
http://ask.wireshark.org/questions/20456/fifo-vs-cbwfq-throughput-graph-comparisonit is hard to interpret a graph without any information about the QoS policy used and some information about the rest of the traffic that passed the monitored device (and line).</description>
    </item>
    
    <item>
      <title>Jitter graph analysis needed for RTP stream</title>
      <link>/questions/20458/jitter-graph-analysis-needed-for-rtp-stream/</link>
      <pubDate>Tue, 16 Apr 2013 02:43:00 +0000</pubDate>
      
      <guid>/questions/20458/jitter-graph-analysis-needed-for-rtp-stream/</guid>
      <description>Jitter graph analysis needed for RTP stream  0 Hi
I have a couple of RTP streams using FIFO as the QoS strategy on one and CBWFQ on the other for performance comparison. Using Wireshark I have ran the RTP stream analysis to get the jitter and delta values in graph format.
https://dl.dropboxusercontent.com/u/39248217/RTP%20jitter%20CBWFQ.jpg https://dl.dropboxusercontent.com/u/39248217/RTP%20jitter%20FIFO.jpg
I&#39;ve edited the Y-axis so it fits into the graph, but FIFO has much higher values (indicating poorer performance) but just wondered what is happening here?</description>
    </item>
    
    <item>
      <title>Capture of gprs packets through usrp 2</title>
      <link>/questions/20460/capture-of-gprs-packets-through-usrp-2/</link>
      <pubDate>Tue, 16 Apr 2013 03:15:00 +0000</pubDate>
      
      <guid>/questions/20460/capture-of-gprs-packets-through-usrp-2/</guid>
      <description>Capture of gprs packets through usrp 2  0 Hi I&#39;m using USRP kit to deploy a gsm network and then integrate gprs service into it to later capture gprs packtets. For now just the gsm network has been deployed and i began to capture its packets but unfortunately, i can not find any method to capeter my communication. I found out that wireshark is dependent on OS. I&#39;m working on Linux 12.</description>
    </item>
    
    <item>
      <title>Query : How to decode MTP3 Message Over TCP using TALI??</title>
      <link>/questions/20472/query-how-to-decode-mtp3-message-over-tcp-using-tali/</link>
      <pubDate>Tue, 16 Apr 2013 08:48:00 +0000</pubDate>
      
      <guid>/questions/20472/query-how-to-decode-mtp3-message-over-tcp-using-tali/</guid>
      <description>Query : How to decode MTP3 Message Over TCP using TALI??  0 I want to know how can I decode MTP3 messages encapsulated in TCP using TALI header (rfc 3094) in WireShark??
TALI is enabled in &#34;Enabled Protocol&#34; list on WireShark. But there is no option &#34;Decode as -&amp;gt; TALI&#34; on WireShark. I am using WireShark version 1.8.3 on Windows.
TALI PCAP file uploaded on cloudshark.org
http://cloudshark.org/captures/cf084e5e7a74
tali mtp3 tcpasked 16 Apr &#39;13, 08:48</description>
    </item>
    
    <item>
      <title>Directory Traversal</title>
      <link>/questions/20473/directory-traversal/</link>
      <pubDate>Tue, 16 Apr 2013 09:02:00 +0000</pubDate>
      
      <guid>/questions/20473/directory-traversal/</guid>
      <description>Directory Traversal  1 hello how can I Find a host in a trace file that appears to be attempting Directory Traversal attack and get its IP address? tnx
attackasked 16 Apr &#39;13, 09:02
parna
26●1●1●4
accept rate: 0%
  
One Answer:
  
1I would start with this display filter:
http contains &#34;../..&#34;
Then look at the source IP address column.
Regards
Kurt
answered 16 Apr &#39;13, 13:52</description>
    </item>
    
    <item>
      <title>Multiple UDP Payload Protocols</title>
      <link>/questions/20477/multiple-udp-payload-protocols/</link>
      <pubDate>Tue, 16 Apr 2013 12:40:00 +0000</pubDate>
      
      <guid>/questions/20477/multiple-udp-payload-protocols/</guid>
      <description>Multiple UDP Payload Protocols  0 I have a UDP payload dissector (1) I&#39;ve developed that works just fine. Occasionally, there will be data that is not part of dissector 1 and is a different protocol that was attached to the same UDP payload.
I&#39;ve written another dissector for type 2.
Is there a way for the 2nd dissector to automatically dissect the remaining bytes? Dissector 1 returns the number of bytes it actually used and I was hoping wireshark would try other protocols on the remaining bytes.</description>
    </item>
    
    <item>
      <title>Wireshark with Impinj readers</title>
      <link>/questions/20480/wireshark-with-impinj-readers/</link>
      <pubDate>Tue, 16 Apr 2013 14:29:00 +0000</pubDate>
      
      <guid>/questions/20480/wireshark-with-impinj-readers/</guid>
      <description>Wireshark with Impinj readers  0 How would Wireshark be used to capture RFID tag data from the Impinj Speedway Revolution R420 or R220 in order to write it out to a database or send it to the cloud?
capture data impinj outputasked 16 Apr &#39;13, 14:29
vimpinj
11●1●1●2
accept rate: 0%
 edited 16 Apr &#39;13, 14:47 
grahamb ♦
19.8k●3●30●206
  
One Answer:</description>
    </item>
    
    <item>
      <title>Malformed Packets</title>
      <link>/questions/20481/malformed-packets/</link>
      <pubDate>Tue, 16 Apr 2013 14:56:00 +0000</pubDate>
      
      <guid>/questions/20481/malformed-packets/</guid>
      <description>Malformed Packets  0 Hi There
I am seeing a large amount of malformed packets on our network. The source hardware address is 00:00:00:00:00:00 and the destination is also 00:00:00:00:00:00. Does anyone have any idea how I can trace these packets? The packet length is 60 - the same as an arp request??
Any ideas? I&#39;ve drawn a total blank on this one...
Many thanks Phill
packets malformedasked 16 Apr &#39;13, 14:56</description>
    </item>
    
    <item>
      <title>Static linking of libpcap while compilation of tshark</title>
      <link>/questions/20499/static-linking-of-libpcap-while-compilation-of-tshark/</link>
      <pubDate>Tue, 16 Apr 2013 23:24:00 +0000</pubDate>
      
      <guid>/questions/20499/static-linking-of-libpcap-while-compilation-of-tshark/</guid>
      <description>Static linking of libpcap while compilation of tshark  0 Hi,
I am compiling tshark (1.6.4) without wireshark. I am using following configure option:
./configure --with-ssl=/usr --with-krb5 --disable-wireshark --disable-gtk2 --disable-editcap --disable-idl2wrs --disable-ipv6 --enable-setuid-install --libdir=/usr/lib64
On my build server libpcap-devel 1.3.0 is installed. But on production system (on which tshark rpm will be installed) have libpcap 0.9.4 version installed. When I instal tshark rpm (created on build server) on production system, it gives error message that libpcap.</description>
    </item>
    
    <item>
      <title>Whether Wireshark will be more than protocol analyser?</title>
      <link>/questions/20512/whether-wireshark-will-be-more-than-protocol-analyser/</link>
      <pubDate>Wed, 17 Apr 2013 04:50:00 +0000</pubDate>
      
      <guid>/questions/20512/whether-wireshark-will-be-more-than-protocol-analyser/</guid>
      <description>Whether Wireshark will be more than protocol analyser?  1 Whether Wireshark will be more than protocol analyser? Currently it is, but is it official way? Wireshark can open files like MP3, JPG, GIF, PNG and XMLs. Could we treat Wireshark as &#34;file format analyser&#34;? Than can be added support to open text-file and binary files? Is it possible to send file format dissector? (for example &#34;.tar&#34;, &#34;.dll&#34;).
It will be nice to see that features.</description>
    </item>
    
    <item>
      <title>Create an extended ICMPv6 dissector</title>
      <link>/questions/20518/create-an-extended-icmpv6-dissector/</link>
      <pubDate>Wed, 17 Apr 2013 05:54:00 +0000</pubDate>
      
      <guid>/questions/20518/create-an-extended-icmpv6-dissector/</guid>
      <description>Create an extended ICMPv6 dissector  0 Hello, I&#39;m trying to implement a dissector for a modification of a message from the ICMPv6 protocol. The modification is basically using an 8-bit reserved field in the ARO (Address Registration Option) message and populating it with 3 new values (4 + 2 + 2 bits).
From this documentation link, I can see that Wireshark supports the following ARO related filters: icmpv6.opt.aro.eui64, icmpv6.opt.aro.registration_lifetime and icmpv6.</description>
    </item>
    
    <item>
      <title>Is Split-Packets possible in ISUP Protocol?</title>
      <link>/questions/20522/is-split-packets-possible-in-isup-protocol/</link>
      <pubDate>Wed, 17 Apr 2013 07:47:00 +0000</pubDate>
      
      <guid>/questions/20522/is-split-packets-possible-in-isup-protocol/</guid>
      <description>Is Split-Packets possible in ISUP Protocol?  0 1ISUP Protocol data are sent as IP packets. Generally, a big IP packet can split in to 2 and we may get as 2 parts.
Will such thing happens in ISUP protocol?
I guess, normally split-packets shouldn&#39;t happen in ISUP. If no split packets in ISUP protocol, how it is taken care?
ip ss7 isupasked 17 Apr &#39;13, 07:47
Manoj G
40●3●4●10</description>
    </item>
    
    <item>
      <title>Wireshark - Problem Decrypting SSL Traffic via ERSPAN</title>
      <link>/questions/20536/wireshark-problem-decrypting-ssl-traffic-via-erspan/</link>
      <pubDate>Wed, 17 Apr 2013 17:21:00 +0000</pubDate>
      
      <guid>/questions/20536/wireshark-problem-decrypting-ssl-traffic-via-erspan/</guid>
      <description>Wireshark - Problem Decrypting SSL Traffic via ERSPAN  0 Hi experts,
I have a question regarding Wireshark ability to decrypt SSL traffic via ERSPAN.
We have ERSPAN mirroring session from our web server A to another server B. Our software on server B seems to have problem decrypting some of the traffic being mirrored from server A. Packet captures were conducted on both servers to determine root cause.
On Server A, I can see a full handshake with Client Key Exchange frame, and the subsequent traffic is decrypted as HTTP.</description>
    </item>
    
    <item>
      <title>delete saved filter from filter bar</title>
      <link>/questions/20537/delete-saved-filter-from-filter-bar/</link>
      <pubDate>Wed, 17 Apr 2013 20:37:00 +0000</pubDate>
      
      <guid>/questions/20537/delete-saved-filter-from-filter-bar/</guid>
      <description>delete saved filter from filter bar  3 I just installed v1.8.6. The filter bar has an option to save the current filter. Once saved under a name, the filter shows up on the filter bar to the right of the &#34;Save&#34; button.
But there is no way to delete or override a saved filter. Even when I use the same name, another filter shows up with the same name. I can&#39;t find the delete option anywhere.</description>
    </item>
    
    <item>
      <title>Can we get a decrypted .pcap from an encrypted .pcap file through some command if i have private key</title>
      <link>/questions/20538/can-we-get-a-decrypted-pcap-from-an-encrypted-pcap-file-through-some-command-if-i-have-private-key/</link>
      <pubDate>Wed, 17 Apr 2013 21:36:00 +0000</pubDate>
      
      <guid>/questions/20538/can-we-get-a-decrypted-pcap-from-an-encrypted-pcap-file-through-some-command-if-i-have-private-key/</guid>
      <description>Can we get a decrypted .pcap from an encrypted .pcap file through some command if i have private key  0 I have private key. All i want is if i get an encrypted .pcap file, I should be able to decrypt it using private key and generate a decrypted .pcap file which i can share with other without sharing private key
Please help me out.
Thanks in advance....
ssl pcap tshark encryptedasked 17 Apr &#39;13, 21:36</description>
    </item>
    
    <item>
      <title>Right interface to use with tshark under windows</title>
      <link>/questions/20545/right-interface-to-use-with-tshark-under-windows/</link>
      <pubDate>Wed, 17 Apr 2013 23:19:00 +0000</pubDate>
      
      <guid>/questions/20545/right-interface-to-use-with-tshark-under-windows/</guid>
      <description>Right interface to use with tshark under windows  0 In linux I use ifconfig to figure out which interface to listen to when capturing packets
I know tshark -D gives me an interface list, but how can I know which one maps to which network?
$ /cygdrive/c/Program\ Files/Wireshark/tshark.exe -D 1. \Device\NPF_{0B6A8C2B-B33C-4D84-9EAC-486FA6DCE537} (Microsoft) 2. \Device\NPF_{A0C97C2A-33C3-4EDD-A257-A19E6F70D0A6} (Intel(R) 82579LM Gigabit Network Connection)I am specifically interested in recording traffic received from a specific peer.</description>
    </item>
    
    <item>
      <title>Wire shark traces info</title>
      <link>/questions/20555/wire-shark-traces-info/</link>
      <pubDate>Thu, 18 Apr 2013 01:40:00 +0000</pubDate>
      
      <guid>/questions/20555/wire-shark-traces-info/</guid>
      <description>Wire shark traces info  0 I have set the codec to be used as G.711A and chosen media encryption as AES in PBX.Now when i make a p2p audio call between my endpoints the Wireshark traces shows payload type as unknown.Is it the expected behavior? If i choose other encryption method such as 1-srtp then the payload type shows the codec used.
expert-info traces wiresharkasked 18 Apr &#39;13, 01:40</description>
    </item>
    
    <item>
      <title>Tshark command for the wireshark operation</title>
      <link>/questions/20563/tshark-command-for-the-wireshark-operation/</link>
      <pubDate>Thu, 18 Apr 2013 03:47:00 +0000</pubDate>
      
      <guid>/questions/20563/tshark-command-for-the-wireshark-operation/</guid>
      <description>Tshark command for the wireshark operation  0 Hi, We are using Wireshark to analyse some SIP messages. Some of the SIP messages are coming as &#34;Malformed packets&#34; (15 0.429555 2606:ae00:93a0:3cf3:0:25:410f:901 2001:1890:1001:2c00::7:5 IPA 1909 unknown 0x47 [Malformed Packet]). If I do the following step I can get the actual message. Right click the msg -&amp;gt; select the option Decode As... -&amp;gt; Select the option &#34;Do not decode&#34; -&amp;gt; Select the option &#34;</description>
    </item>
    
    <item>
      <title>How do I extract buffer values from a ProtoField?</title>
      <link>/questions/20566/how-do-i-extract-buffer-values-from-a-protofield/</link>
      <pubDate>Thu, 18 Apr 2013 04:29:00 +0000</pubDate>
      
      <guid>/questions/20566/how-do-i-extract-buffer-values-from-a-protofield/</guid>
      <description>How do I extract buffer values from a ProtoField?  0 Let&#39;s say I have an packet that looks like this:
[ ETH, IP, myHeader ]MyHeader is my own protocol which consists of myHeader.x1 (the first three bits) and myHeader.x2 (the next 5 bits).
What I want to do is loop through the whole pcap file to find all the frames, where a condition is fulfilled that myHeader.x1 AND myHeader.x2 are of a certain value.</description>
    </item>
    
    <item>
      <title>Source and Destination IP Address All 00:00:00:00:00:00</title>
      <link>/questions/20572/source-and-destination-ip-address-all-000000000000/</link>
      <pubDate>Thu, 18 Apr 2013 07:27:00 +0000</pubDate>
      
      <guid>/questions/20572/source-and-destination-ip-address-all-000000000000/</guid>
      <description>Source and Destination IP Address All 00:00:00:00:00:00  0 I&#39;ve had this problem for a while now. When I do a capture I get a lot of packets that they Source, Destination, MAC address and Data all come back with only zeros. The only thing on the Network that seems to have a problem with these packets is the boot process on some of our Mitel VoIP phone&#39;s. Any ideas where to go with this?</description>
    </item>
    
    <item>
      <title>How to create and save profiles?</title>
      <link>/questions/20577/how-to-create-and-save-profiles/</link>
      <pubDate>Thu, 18 Apr 2013 08:32:00 +0000</pubDate>
      
      <guid>/questions/20577/how-to-create-and-save-profiles/</guid>
      <description>How to create and save profiles?  0 I can&#39;t figure out how to create and save a profile. I&#39;m using Version 1.6.11 (SVN Rev 45257 from /trunk-1.6) on Windows 7. If I open the Edit:Configuration Profiles menu item the only options are New, Copy, Delete, OK, Apply, and Cancel (no Save button). If I select any of the existing profiles my current preferences (what I&#39;m trying to save) get replaced with ones from the profile I load.</description>
    </item>
    
    <item>
      <title>How to disable E100 Encapsulation protocol permanently?</title>
      <link>/questions/20579/how-to-disable-e100-encapsulation-protocol-permanently/</link>
      <pubDate>Thu, 18 Apr 2013 08:36:00 +0000</pubDate>
      
      <guid>/questions/20579/how-to-disable-e100-encapsulation-protocol-permanently/</guid>
      <description>How to disable E100 Encapsulation protocol permanently?  0 The dissector is attempting to apply a E100 protocol to my proprietary UDP packets and displaying &#34;Malformed Packet&#34; when it does that. I found that I can right click that line in the display and select &#34;Temporarily disable this protocol&#34; to prevent this during the rest of the session but I&#39;d like to disable this protocol permanently. Unfortunately I don&#39;t see &#34;</description>
    </item>
    
    <item>
      <title>tshark -D on dual port card (WinXP)</title>
      <link>/questions/20580/tshark-d-on-dual-port-card-winxp/</link>
      <pubDate>Thu, 18 Apr 2013 08:56:00 +0000</pubDate>
      
      <guid>/questions/20580/tshark-d-on-dual-port-card-winxp/</guid>
      <description>tshark -D on dual port card (WinXP)  0 On a WInXP computer, I need to programatically read the results of tshark -D and identify the port I want to use based on the description. Unfortunately the board is is a dual port card, so the second port is identified with (Intel(R)... #2), but tshark does not display the #2. Any suggestions, or is this a change request.
tshark winxpasked 18 Apr &#39;13, 08:56</description>
    </item>
    
    <item>
      <title>unknow invokedata blob</title>
      <link>/questions/20586/unknow-invokedata-blob/</link>
      <pubDate>Thu, 18 Apr 2013 11:22:00 +0000</pubDate>
      
      <guid>/questions/20586/unknow-invokedata-blob/</guid>
      <description>unknow invokedata blob  0 hello
i make a trace when a platform sent a invoke data messages in MAP 1 (sendparameters- UTU), but everytime when i see the GSM mobile application part , the package cant decode - i always have InvokeData blob. Do you know how i can solve this? maybe i have a wrong configuration in the wireshark?
Thanks a lot
invokedatablobasked 18 Apr &#39;13, 11:22
Ray</description>
    </item>
    
    <item>
      <title>How do you correct C&#43;&#43; Run Time errors when opening I/O Graph</title>
      <link>/questions/20588/how-do-you-correct-c-run-time-errors-when-opening-io-graph/</link>
      <pubDate>Thu, 18 Apr 2013 12:47:00 +0000</pubDate>
      
      <guid>/questions/20588/how-do-you-correct-c-run-time-errors-when-opening-io-graph/</guid>
      <description>How do you correct C++ Run Time errors when opening I/O Graph  0 I am in a Wireshark training class wit Laura Chappell now and WS consistently encounters a C++ Error were the App has requested the Run Time to terminate in an unusual way.
I&#39;m running Wireshark 1.8.6 SVN Rev 48142 on HP Playbook with Windows XP SP3. I&#39;m not logging anyting in the event logs and Dr. Watson is not picking anything up.</description>
    </item>
    
    <item>
      <title>Use tshark to get smpp operations results</title>
      <link>/questions/20589/use-tshark-to-get-smpp-operations-results/</link>
      <pubDate>Thu, 18 Apr 2013 13:08:00 +0000</pubDate>
      
      <guid>/questions/20589/use-tshark-to-get-smpp-operations-results/</guid>
      <description>Use tshark to get smpp operations results  1 1Hello,
Is it possible to use tshark command to get the same results of the action to clic in Telephony menu -&amp;gt; SMPP Operations Any advice is appreciated. Thank you for your response.
Luis
smpp tsharkasked 18 Apr &#39;13, 13:08
lgonzalezsa
31●1●2●5
accept rate: 0%
  
2 Answers:
  
2 Please try this.
tshark -nr input.pcap -q -z smpp_commands,tree</description>
    </item>
    
    <item>
      <title>Dissecting bitfields larger than 32 bits</title>
      <link>/questions/20599/dissecting-bitfields-larger-than-32-bits/</link>
      <pubDate>Thu, 18 Apr 2013 16:12:00 +0000</pubDate>
      
      <guid>/questions/20599/dissecting-bitfields-larger-than-32-bits/</guid>
      <description>Dissecting bitfields larger than 32 bits  1 I am writing a dissector for a protocol which contains bitfields that are larger than 32 bits. For instance there is one bitfield that is 48-bits long, with other bitfields being 80-bits long. Setting the bitmask for the field in the header_field_info structure does not work since the bitmask is only 32-bits long.
I believe that there are a number of possible ways to proceed:</description>
    </item>
    
    <item>
      <title>what is the error message? could you check for me?</title>
      <link>/questions/20611/what-is-the-error-message-could-you-check-for-me/</link>
      <pubDate>Thu, 18 Apr 2013 23:56:00 +0000</pubDate>
      
      <guid>/questions/20611/what-is-the-error-message-could-you-check-for-me/</guid>
      <description>what is the error message? could you check for me?  0 Hi,
Please check for me below link:
is it block the 443? but i can telnet with 443.
what is the root cause of this issue?
http://www.sendspace.com/file/qyv69e
Please help me, thanks.
ko htwe
tagsasked 18 Apr &#39;13, 23:56
aungkohtwe
6●2●2●3
accept rate: 0%
  
2 Answers:
  
0The screen shot doesn&#39;t tell much except there is a reset coming back as an answer to a SYN, so it looks like the session is refused.</description>
    </item>
    
    <item>
      <title>Numerical Keypad comma vs. decimal point</title>
      <link>/questions/20617/numerical-keypad-comma-vs-decimal-point/</link>
      <pubDate>Fri, 19 Apr 2013 00:59:00 +0000</pubDate>
      
      <guid>/questions/20617/numerical-keypad-comma-vs-decimal-point/</guid>
      <description>Numerical Keypad comma vs. decimal point  0 When I try to use the numpad (numerical keypad) and hit the decimal point key Wireshark gives me a comma instead of a dot. While I agree that, that is the default for my country, it isn&#39;t how I have Windows setup. Excel and the built in Windows 7 calculator both re-act &#34;correctly&#34; and use a dot instead of a comma when I use the &#34;</description>
    </item>
    
    <item>
      <title>Malformed packet: Possible encoding error full length not decoded, open type length 2, decoded 1</title>
      <link>/questions/20626/malformed-packet-possible-encoding-error-full-length-not-decoded-open-type-length-2-decoded-1/</link>
      <pubDate>Fri, 19 Apr 2013 06:52:00 +0000</pubDate>
      
      <guid>/questions/20626/malformed-packet-possible-encoding-error-full-length-not-decoded-open-type-length-2-decoded-1/</guid>
      <description>Malformed packet: Possible encoding error full length not decoded, open type length 2, decoded 1  0 Hi,
I am seeing following error line in H323 setup message, this issue came after added H245SecurityCapability header.
&#34;Possible encoding error full length not decoded, open type length 2, decoded 1&#34;
Please any one tell me know what is this error and solution.
I am not able to upload the image file.
Thanks Vinayraj</description>
    </item>
    
    <item>
      <title>unencrypted username and password</title>
      <link>/questions/20631/unencrypted-username-and-password/</link>
      <pubDate>Fri, 19 Apr 2013 09:24:00 +0000</pubDate>
      
      <guid>/questions/20631/unencrypted-username-and-password/</guid>
      <description>unencrypted username and password  0 hello i want to find an unencrypted username and password. but i am interested in a real username and password, and not login attempts that failed. and get user name and password.
i can do it with tcp follow stream , but i want do it with filter and command in wireshark. (not manually)
tnx for your help.
unencrypted username and passwordasked 19 Apr &#39;13, 09:24</description>
    </item>
    
    <item>
      <title>tcp mss inconsistency in different capture points</title>
      <link>/questions/20633/tcp-mss-inconsistency-in-different-capture-points/</link>
      <pubDate>Fri, 19 Apr 2013 09:55:00 +0000</pubDate>
      
      <guid>/questions/20633/tcp-mss-inconsistency-in-different-capture-points/</guid>
      <description>tcp mss inconsistency in different capture points  0 Analysis process, the client is found in the TCP connection is established, the MSS value is not the same in different capture points. client side packet: http://www.cloudshark.org/captures/0c7d36890433 server side packet: http://www.cloudshark.org/captures/1d460ea5291d
Help to explain
thanks.
mss tcpasked 19 Apr &#39;13, 09:55
mengsunny
11●4●4●6
accept rate: 0%
In the client side capture MSS value is 1460. In the server side capture MSS value is 1380.</description>
    </item>
    
    <item>
      <title>I/O Statistics packet count for reassembled messages</title>
      <link>/questions/20639/io-statistics-packet-count-for-reassembled-messages/</link>
      <pubDate>Fri, 19 Apr 2013 10:15:00 +0000</pubDate>
      
      <guid>/questions/20639/io-statistics-packet-count-for-reassembled-messages/</guid>
      <description>I/O Statistics packet count for reassembled messages  1 How does Wireshark count packets for reassembled Diameter/SCTP messages? Reassembly is enabled for both layers. If a single Diameter message takes 2 packets, are both packets counted? If the graph is filtered by diameter.cmd.code and this would include multi-packet reassembled messages, are all packets counted, or just the first packet (that actually contains the cmd.code)? Thanks!
reassembly statistics packet diameterasked 19 Apr &#39;13, 10:15</description>
    </item>
    
    <item>
      <title>Why cannot see  tcp protocol when packet sniffing?</title>
      <link>/questions/20642/why-cannot-see-tcp-protocol-when-packet-sniffing/</link>
      <pubDate>Fri, 19 Apr 2013 14:25:00 +0000</pubDate>
      
      <guid>/questions/20642/why-cannot-see-tcp-protocol-when-packet-sniffing/</guid>
      <description>Why cannot see tcp protocol when packet sniffing?  0 1I am trying to siniff the pakets by uploading a text file to http://gaia.cs.umass.edu/wireshark-labs/TCP-wireshark-file1.html. But when I start and upload that file, I can only see NBNS protocol(and 3 packets are sent).Why cannot see the tcp protocol?I have already chosen the interfaces at the beginning and I am using wireless Internet.I also have made some Google search but couldn&#39;t find any useful thing.</description>
    </item>
    
    <item>
      <title>Fix not decoded</title>
      <link>/questions/20643/fix-not-decoded/</link>
      <pubDate>Fri, 19 Apr 2013 14:34:00 +0000</pubDate>
      
      <guid>/questions/20643/fix-not-decoded/</guid>
      <description>Fix not decoded  0 I did a packet capture of FIX traffic. The traffic is from multiple sources. What I noticed unusual is it decoded FIX for half the traffic and not the other half. The only difference is the port the traffic was running on. The port it did not decode was TCP 5000. How do I tell it port 5000 is FIX
fixasked 19 Apr &#39;13, 14:34</description>
    </item>
    
    <item>
      <title>Remote interface Not Able to connect</title>
      <link>/questions/20646/remote-interface-not-able-to-connect/</link>
      <pubDate>Fri, 19 Apr 2013 17:15:00 +0000</pubDate>
      
      <guid>/questions/20646/remote-interface-not-able-to-connect/</guid>
      <description>Remote interface Not Able to connect  0 I am Trying to connect My PABX in wire shark using Remote Interface with Port number 5060 , But It&#39;s not connection .
Can any one help me , how to connect PABX network card.
interface remoteasked 19 Apr &#39;13, 17:15
Raamc
1●1●1●1
accept rate: 0%
  
One Answer:
  
0You need to start rpcapd on the remote machine (if it is a windows system).</description>
    </item>
    
    <item>
      <title>Decoding TD.35</title>
      <link>/questions/20649/decoding-td35/</link>
      <pubDate>Sat, 20 Apr 2013 00:03:00 +0000</pubDate>
      
      <guid>/questions/20649/decoding-td35/</guid>
      <description>Decoding TD.35  0 Can someone explain how to decode TD.35 data format or someone tell where can i find the specification of the TD.35 data format?
The following is the sample data,
30272017111544749011353876999672 0021 353876999672 0000801208061845300000000000000000000000000000 30272017111544749011353876999673 0021 353876999673 0000801208061754310000000000000000000000000000ss7 td.35 sigtranasked 20 Apr &#39;13, 00:03
Manoj G
40●3●4●10
accept rate: 33%
 edited 20 Apr &#39;13, 00:06 
  
2 Answers:
  
0As far as I can tell (with a few minutes of searching), the TD.</description>
    </item>
    
    <item>
      <title>SSL &amp;quot;key exchange 0 different from KEX_RSA&amp;quot; but using RSA</title>
      <link>/questions/20667/ssl-key-exchange-0-different-from-kex_rsa-but-using-rsa/</link>
      <pubDate>Sat, 20 Apr 2013 20:20:00 +0000</pubDate>
      
      <guid>/questions/20667/ssl-key-exchange-0-different-from-kex_rsa-but-using-rsa/</guid>
      <description>SSL &amp;ldquo;key exchange 0 different from KEX_RSA&amp;rdquo; but using RSA  0 I&#39;m trying to decrypt a small TLSv1.2 stream, using Wireshark 1.8.6 Win64 (stock build from wireshark.org). I&#39;ve configured the server&#39;s private key in the preferences. I have prior experience with SSL/TLS and OpenSSL, so I&#39;m reasonably sure all of this is correct.
The SSL debug log shows the &#34;key exchange 0 different from KEX_RSA&#34; message immediately before complaining it can&#39;t decrypt the pre-master secret.</description>
    </item>
    
    <item>
      <title>One file. Multiple DLT USER packets. Is it possible?</title>
      <link>/questions/20680/one-file-multiple-dlt-user-packets-is-it-possible/</link>
      <pubDate>Sun, 21 Apr 2013 08:27:00 +0000</pubDate>
      
      <guid>/questions/20680/one-file-multiple-dlt-user-packets-is-it-possible/</guid>
      <description>One file. Multiple DLT USER packets. Is it possible?  0 Hello everyone, I&#39;m trying to log RRC messages. There are few RRC protocols: &#34;rrc.ul.ccch&#34; &#34;rrc.dl.ccch&#34; &#34;rrc.ul.dcch&#34; &#34;rrc.dl.dcch&#34;
I&#39;m getting all kind of messages, one after the other, and I want to use wireshark as a log to all the messages that I&#39;ve captured. Meaning, I want to create one file that will hold all the messages received in the protocols above, in the same order they were received.</description>
    </item>
    
    <item>
      <title>TCP segment with more than 30000bytes in wireshark log, how it&amp;#x27;s possible???</title>
      <link>/questions/20689/tcp-segment-with-more-than-30000bytes-in-wireshark-log-how-its-possible/</link>
      <pubDate>Sun, 21 Apr 2013 19:57:00 +0000</pubDate>
      
      <guid>/questions/20689/tcp-segment-with-more-than-30000bytes-in-wireshark-log-how-its-possible/</guid>
      <description>TCP segment with more than 30000bytes in wireshark log, how it&amp;rsquo;s possible???  1 when I tested the FTP and monitored the log through wireshark, I found something very strange. since it started, the TCP segment size has been more than 30000bytes even the MSS which shared before was 1400 bytes. how the TCP send a segment to destination with this kind of big bytes.
tcp-segmentasked 21 Apr &#39;13, 19:57</description>
    </item>
    
    <item>
      <title>H.323 packets interfacing</title>
      <link>/questions/20691/h323-packets-interfacing/</link>
      <pubDate>Sun, 21 Apr 2013 23:54:00 +0000</pubDate>
      
      <guid>/questions/20691/h323-packets-interfacing/</guid>
      <description>H.323 packets interfacing  0 Dear, Kindly guide me, I want to capture video streaming packets (H.323). I have installed Wireshark 1.8.6. We connected videocon hardware to a LAN switch and computer with wireshark installed to same LAN switch. The remote hardware is connected to the same LAN switch through WLAN. We are unable to get packets H.323, H225 or H245 and even RTP. Pl guide so that we can can these, pl.</description>
    </item>
    
    <item>
      <title>TCP connection hangs on Debian</title>
      <link>/questions/20693/tcp-connection-hangs-on-debian/</link>
      <pubDate>Mon, 22 Apr 2013 01:28:00 +0000</pubDate>
      
      <guid>/questions/20693/tcp-connection-hangs-on-debian/</guid>
      <description>TCP connection hangs on Debian  0 Hi,
Some tcp connections hang sometimes and I can&#39;t find the problem. When Maven is downloading libraries from maven repo, sometimes it blocks in one of the downloads, making the entire build hang. It is difficult to reproduce as it only happens rarely, but I was able to capture it on wireshark (with tshark).
This is the end of the build output:
[INFO] Unable to find resource &amp;#39;org.</description>
    </item>
    
    <item>
      <title>How do I create multiple table entries for a single UDP packet?</title>
      <link>/questions/20694/how-do-i-create-multiple-table-entries-for-a-single-udp-packet/</link>
      <pubDate>Mon, 22 Apr 2013 01:55:00 +0000</pubDate>
      
      <guid>/questions/20694/how-do-i-create-multiple-table-entries-for-a-single-udp-packet/</guid>
      <description>How do I create multiple table entries for a single UDP packet?  0 Hi,
I hope this is the right place to ask my question...
I wish to be able to receive a single UDP packet that contains several packets of my protocol and show each of those internal packet in the main GUI table as a standalone packet.
I know that Wireshark does not support this.
So i thought to resend it internally over socket in the machine after dissection so that the parsed packets are resent and captured by Wireshark and thus achieve my goal, but that does not work on Windows due to loopback limitations in that OS and I do need the application to be cross-platform.</description>
    </item>
    
    <item>
      <title>lua tap for bundled packets</title>
      <link>/questions/20696/lua-tap-for-bundled-packets/</link>
      <pubDate>Mon, 22 Apr 2013 02:01:00 +0000</pubDate>
      
      <guid>/questions/20696/lua-tap-for-bundled-packets/</guid>
      <description>lua tap for bundled packets  0 Hi,
Lets say I have a packet that looks like this :
[ETH, IP, HEADER, PAYLOAD, HEADER, PAYLOAD]
My Header consists of header.x1 header.x2 and header.x3 and payload is payload.x1 and payload.x2.
I want to use a lua tap to calculate how many [header, payload] packets a file consists of. So in this case, it is just one IP packet, but consist of two packets with [header, payload].</description>
    </item>
    
    <item>
      <title>TCP Option 171 added in SYN packet</title>
      <link>/questions/20697/tcp-option-171-added-in-syn-packet/</link>
      <pubDate>Mon, 22 Apr 2013 02:14:00 +0000</pubDate>
      
      <guid>/questions/20697/tcp-option-171-added-in-syn-packet/</guid>
      <description>TCP Option 171 added in SYN packet  0 Hello, just came across a tcp option 171 : 0xab
http://www.cloudshark.org/captures/1d460ea5291d shows the option added in frame 2 at the capture point as the client&#39;s syn packet gets forwarded to the server.
Maximum segment size: 1380 bytes No-Operation (NOP) Type: 1 Window scale: 8 (multiply by 256) No-Operation (NOP) Type: 1 No-Operation (NOP) TCP SACK Permitted Option: True Unknown (0xab) (6 bytes) : ab 06 00 00 00 2f 01 01</description>
    </item>
    
    <item>
      <title>plugin compilation issue</title>
      <link>/questions/20700/plugin-compilation-issue/</link>
      <pubDate>Mon, 22 Apr 2013 03:15:00 +0000</pubDate>
      
      <guid>/questions/20700/plugin-compilation-issue/</guid>
      <description>plugin compilation issue  0 I was able to compile amin as well as foo dissector, but the dissector that I had written is not getting compiled as well as (amin,foo also not working). Error when doing nmake all is:
Making plugin.c (using python) Updating plugin.c NMAKE : fatal error U1073: don&amp;#39;t know how to make &amp;#39;..\..\epan\libwireshark.lib&amp;#39;stop.Can anybody help promptly?
compile pluginasked 22 Apr &#39;13, 03:15
ajain
14●6●7●11
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Why RST, ACK after ACK</title>
      <link>/questions/20706/why-rst-ack-after-ack/</link>
      <pubDate>Mon, 22 Apr 2013 07:08:00 +0000</pubDate>
      
      <guid>/questions/20706/why-rst-ack-after-ack/</guid>
      <description>Why RST, ACK after ACK  0 Hi,
Why would you normally see RST, ACK packets apparently in the middle of a transaction?
https://www.cloudshark.org/captures/3b405a6ad37b
Thanks
reset ack after tcp wiresharkasked 22 Apr &#39;13, 07:08
Mikecl
11●1●1●3
accept rate: 0%
 edited 22 Apr &#39;13, 07:26 
the link to cloudshark.org does not work.
UPDATE: I fixed the link
(22 Apr &#39;13, 07:12) Kurt Knochner ♦  
One Answer:</description>
    </item>
    
    <item>
      <title>Dissecting packets with a protocol running atop UDP</title>
      <link>/questions/20712/dissecting-packets-with-a-protocol-running-atop-udp/</link>
      <pubDate>Mon, 22 Apr 2013 08:28:00 +0000</pubDate>
      
      <guid>/questions/20712/dissecting-packets-with-a-protocol-running-atop-udp/</guid>
      <description>Dissecting packets with a protocol running atop UDP  0 Wireshark semi-noob here.
I have two devices that talk to each other over 802.11, and I need to reverse engineer the protocol (we are emulating one of the devices, and don&#39;t have full docs).
The protocol is more or less ASCII strings over UDP over wireless, i. e. text strings, SQL queries, etc.
I am able to sniff packets that I know are part of the dialog between client and server.</description>
    </item>
    
    <item>
      <title>Is it possible to drop DeAuth Packets?</title>
      <link>/questions/20713/is-it-possible-to-drop-deauth-packets/</link>
      <pubDate>Mon, 22 Apr 2013 09:41:00 +0000</pubDate>
      
      <guid>/questions/20713/is-it-possible-to-drop-deauth-packets/</guid>
      <description>Is it possible to drop DeAuth Packets?  0 Is it possible to drop / reject deAuthentication packets ??? If yes how?? Beacause I want to prevent DeAuthentication attack performed on my wireless LAN.. Can scapy tool with python can help to solve this problem?
python scapy deauthenticationasked 22 Apr &#39;13, 09:41
aki4891
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Is it possible to drop / reject deAuthentication packets ?</description>
    </item>
    
    <item>
      <title>RTP DTMF digits are no longer displayed in VoIP graph analysis</title>
      <link>/questions/20714/rtp-dtmf-digits-are-no-longer-displayed-in-voip-graph-analysis/</link>
      <pubDate>Mon, 22 Apr 2013 12:06:00 +0000</pubDate>
      
      <guid>/questions/20714/rtp-dtmf-digits-are-no-longer-displayed-in-voip-graph-analysis/</guid>
      <description>RTP DTMF digits are no longer displayed in VoIP graph analysis  0 I discovered today that, Wireshark 1.8.6 does not display RFC2833 DTMF telephony events in VoIP call graph analysis anymore.
It was a very convenient way to see, which DTMF digits are transmitted in the RTP packets. This example displays 7 DTMF digits and is taken with wireshark 1.8.3. The same trace shows only &#34;RTP (telephone-event)&#34; and not which digit is transmitted anymore as of (at least) wireshark 1.</description>
    </item>
    
    <item>
      <title>please check for me.</title>
      <link>/questions/20723/please-check-for-me/</link>
      <pubDate>Mon, 22 Apr 2013 19:39:00 +0000</pubDate>
      
      <guid>/questions/20723/please-check-for-me/</guid>
      <description>please check for me.  0 link text No. 1 is the wireshark file.
link text
No.2 is the error file. Could you check for me between 203.126.29.157 and 192.168.0.2 any packet lost?
Because I see with red color line.
Thanks, Ko Htwe
loss sip tcp packet packetlossasked 22 Apr &#39;13, 19:39
aungkohtwe
6●2●2●3
accept rate: 0%
 edited 06 Mar &#39;14, 10:57 
cmaynard ♦♦
9.4k●10●38●142</description>
    </item>
    
    <item>
      <title>How to specify path of libgcc during tshark compilation??</title>
      <link>/questions/20724/how-to-specify-path-of-libgcc-during-tshark-compilation/</link>
      <pubDate>Mon, 22 Apr 2013 19:47:00 +0000</pubDate>
      
      <guid>/questions/20724/how-to-specify-path-of-libgcc-during-tshark-compilation/</guid>
      <description>How to specify path of libgcc during tshark compilation??  0 Hi,
I am compiling tshark 1.6.14 on Solaris 10. On Solaris 10 server, libgcc 3.4.3 version is installed. Tshark is not getting compiled with libgcc 3.4.3 due to tshark issue 7637.
As mentioned in bug 7637, I am now compiling tshark with libgcc 4.2.4. I compiled libgcc 4.2.4 and installed it in /opt/libgcc-4.2.4 directory. I don&#39;t want to install libgcc in default directory (/usr) as this server is being used for compilation of many other software.</description>
    </item>
    
    <item>
      <title>C37.118 - 2011</title>
      <link>/questions/20726/c37118-2011/</link>
      <pubDate>Mon, 22 Apr 2013 21:14:00 +0000</pubDate>
      
      <guid>/questions/20726/c37118-2011/</guid>
      <description>C37.118 - 2011  0 Does any release package of Wireshark be available for IEEE C37.118 - 2011?
IEEE C37.118 - 2011---IEEE Standard for Synchrophasor Measurements and Data Transfer for Power Systems.
2011 - c37.118asked 22 Apr &#39;13, 21:14
Hector
16●1●1●4
accept rate: 0%
 edited 22 Apr &#39;13, 21:17 
  
One Answer:
  
0 The C37.118 dissector&#39;s been there since Wireshark 1.6, but it was checked in during early 2009, and there don&#39;t appear to have been any protocol updates since then, so if there are post-2009 revisions, they&#39;re probably not supported.</description>
    </item>
    
    <item>
      <title>rtp packets missing from capture</title>
      <link>/questions/20728/rtp-packets-missing-from-capture/</link>
      <pubDate>Mon, 22 Apr 2013 22:39:00 +0000</pubDate>
      
      <guid>/questions/20728/rtp-packets-missing-from-capture/</guid>
      <description>rtp packets missing from capture  0 Hi i used packeTH to create an RTP stream for G7231 payload and wireshark to capture the traffic.I am building UDP packets with RTP payload on one end (windows 7) and on the wireshark(other end windows 7) but I can only see IP packets(info column= IP fragmented protocol). Decode as option can be applied only if we can see as UDP packets, right? so what should be done if its showing only as IP packets?</description>
    </item>
    
    <item>
      <title>Create delta column - pkt timestamp &amp;amp; FIX SendingTime</title>
      <link>/questions/20734/create-delta-column-pkt-timestamp-fix-sendingtime/</link>
      <pubDate>Tue, 23 Apr 2013 06:49:00 +0000</pubDate>
      
      <guid>/questions/20734/create-delta-column-pkt-timestamp-fix-sendingtime/</guid>
      <description>Create delta column - pkt timestamp &amp;amp; FIX SendingTime  0 Could someone let me know if it&#39;s possible to create a column that displays the delta between a packet&#39;s arrival time and the FIX SendingTime in the payload? I have the two timestamps in adjacent columns - just not sure how to add a delta column.
Many thanks,
Tim
fixasked 23 Apr &#39;13, 06:49
Timchampion
6●3●3●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>will wireshark move to native mac windowing instead of X11?</title>
      <link>/questions/20738/will-wireshark-move-to-native-mac-windowing-instead-of-x11/</link>
      <pubDate>Tue, 23 Apr 2013 08:57:00 +0000</pubDate>
      
      <guid>/questions/20738/will-wireshark-move-to-native-mac-windowing-instead-of-x11/</guid>
      <description>will wireshark move to native mac windowing instead of X11?  0 X11 bulky and the interface is pretty crappy all the way around. any chance wireshark will have a native mac GUI display written for it?
thanks
-avi
mac guiasked 23 Apr &#39;13, 08:57
rotorboy
1●1●1●1
accept rate: 0%
  
One Answer:
  
1There are no plans for a native OSX port, but work is progressing on a QT port.</description>
    </item>
    
    <item>
      <title>diameter response time</title>
      <link>/questions/20740/diameter-response-time/</link>
      <pubDate>Tue, 23 Apr 2013 10:48:00 +0000</pubDate>
      
      <guid>/questions/20740/diameter-response-time/</guid>
      <description>diameter response time  0 I need the response time for each CCA paquet, so i&#39;m trying with: tshark -r TraficoDiameter.pcap -d tcp.port==6553,diameter -R &#34;diameter.cmd.code == 272 &amp;amp;&amp;amp; diameter.resp_time&#34; -e diameter.resp_time -e frame.time_epoch -E separator=&#34;;&#34; -T fields
this result is giving me: resp_time;epoch:time, but some packets have several CCR so the result is: resp_time,resp_time,resp_time,...;epoch:time
there is a way to separate all resp_time with his own epoch time?
diameterasked 23 Apr &#39;13, 10:48</description>
    </item>
    
    <item>
      <title>SSH Capture question</title>
      <link>/questions/20741/ssh-capture-question/</link>
      <pubDate>Tue, 23 Apr 2013 12:16:00 +0000</pubDate>
      
      <guid>/questions/20741/ssh-capture-question/</guid>
      <description>SSH Capture question  0 I am currently reviewing some SSH captures for a client. We are trying to validate the SSH version that is in use Cisco&#39;s SSH v 1.99 (OpenSSH). I am trying to create a case that outlines if certain features are in place then it must be SSH v1.99 (e.g. DH Key exchange, DSA auth method, etc).
One question I do have is within the capture I am noticing under the SSH protocol section there is an indicator or a &#34;</description>
    </item>
    
    <item>
      <title>Wireshark&amp;#x27;s Application template for Google Summer Of Code</title>
      <link>/questions/20742/wiresharks-application-template-for-google-summer-of-code/</link>
      <pubDate>Tue, 23 Apr 2013 12:17:00 +0000</pubDate>
      
      <guid>/questions/20742/wiresharks-application-template-for-google-summer-of-code/</guid>
      <description>Wireshark&amp;rsquo;s Application template for Google Summer Of Code  0 Hello,
(I&#39;m french, so I excuse for my possible mistakes :))
I want to participate of the GSoC 2013, and I&#39;m really interested by several Wireshark projets.
But, I don&#39;t find the &#34;Application Template&#34; who give the informations that wireshark want for study our proposal.
For exemple the &#34;Application Template&#34; of Nmap : http://www.google-melange.com/gsoc/org/google/gsoc2013/nmap or OWASP : https://www.owasp.org/index.php/GSoC_SAT
Or maybe Wireshark don&#39;t want a special &#34;</description>
    </item>
    
    <item>
      <title>link type 136 (not able to read pcap captures from juniper service interface)</title>
      <link>/questions/20743/link-type-136-not-able-to-read-pcap-captures-from-juniper-service-interface/</link>
      <pubDate>Tue, 23 Apr 2013 14:16:00 +0000</pubDate>
      
      <guid>/questions/20743/link-type-136-not-able-to-read-pcap-captures-from-juniper-service-interface/</guid>
      <description>link type 136 (not able to read pcap captures from juniper service interface)  0 hi all:
i captured some data and stored as pcap format on a service interface of juniper mx960 (sp-1/0/0) but i am not able to open them up since i keep getting following errors:
&#34;The file &amp;lt;whatever-name.pcap&amp;gt; is capture of for a network type that Wireshark doesn&#39;t support (pcap: network type 136 unknown or unsupported)&#34;</description>
    </item>
    
    <item>
      <title>Help analyzing ftp connection problem</title>
      <link>/questions/20751/help-analyzing-ftp-connection-problem/</link>
      <pubDate>Tue, 23 Apr 2013 15:28:00 +0000</pubDate>
      
      <guid>/questions/20751/help-analyzing-ftp-connection-problem/</guid>
      <description>Help analyzing ftp connection problem  0 I have 2 PCs on a network one Win7 192.168.1.64 and the other XP 192.168.1.69. I am running Filezilla server on both. Typing ftp 192.168.69 on the win7 machine is detected by Filezilla on the XP PC, but typing ftp 192.168.1.64 on the XP PC causes no response whatever from filezilla on the win7 PC. Moreover Wireshark does not appear to detect any packets arriving on the Win 7 PC.</description>
    </item>
    
    <item>
      <title>SFTP Decryption</title>
      <link>/questions/20753/sftp-decryption/</link>
      <pubDate>Tue, 23 Apr 2013 15:47:00 +0000</pubDate>
      
      <guid>/questions/20753/sftp-decryption/</guid>
      <description>SFTP Decryption  0 Is it possible to decrypt sftp with Wireshark?
decrypt sftpasked 23 Apr &#39;13, 15:47
Steve Fenter
11●3●3●4
accept rate: 0%
  
One Answer:
  
1No that&#39;s not implemented yet.
answered 23 Apr &#39;13, 20:46
Anders ♦
4.6k●9●52
accept rate: 17%
     </description>
    </item>
    
    <item>
      <title>Connect Direct Secure Plus decryption</title>
      <link>/questions/20754/connect-direct-secure-plus-decryption/</link>
      <pubDate>Tue, 23 Apr 2013 15:51:00 +0000</pubDate>
      
      <guid>/questions/20754/connect-direct-secure-plus-decryption/</guid>
      <description>Connect Direct Secure Plus decryption  0 Is it possible to decrypt Connect Direct Secure Plus with Wireshark?
plus secure connect decryption directasked 23 Apr &#39;13, 15:51
Steve Fenter
11●3●3●4
accept rate: 0%
  
One Answer:
  
0Although Connect Direct Secure Plus uses TLS, there is no decryption support for that protocol in Wireshark.
Apparently they use a variation of Diffie Hellman to establish a crypto key, which makes it impossible harder to decrypt the data stream, as there is no way to generate the required session key, unless either party (client or server) discloses that key.</description>
    </item>
    
    <item>
      <title>trouble building stand-alone osx app for mountain lion</title>
      <link>/questions/20756/trouble-building-stand-alone-osx-app-for-mountain-lion/</link>
      <pubDate>Tue, 23 Apr 2013 22:33:00 +0000</pubDate>
      
      <guid>/questions/20756/trouble-building-stand-alone-osx-app-for-mountain-lion/</guid>
      <description>trouble building stand-alone osx app for mountain lion  0 I have tried for several days to build an OSX app that can run on other systems. I can run both cli and app wireshark on my build machine (mountain lion). But when i try to run the app on another mountain lion machine, there are libraries missing, etc. I&#39;ve added some of those libs manually, but now i seem to have dependencies on two different versions of libiconv.</description>
    </item>
    
    <item>
      <title>about protocol recognizing</title>
      <link>/questions/20761/about-protocol-recognizing/</link>
      <pubDate>Wed, 24 Apr 2013 04:49:00 +0000</pubDate>
      
      <guid>/questions/20761/about-protocol-recognizing/</guid>
      <description>about protocol recognizing  0 iec-104 runs on 2407 port and recogizes as &#34;orion&#34; protocol. it is bad because of wireshark cant dicipher data. how can i adjust this program to recognize correctly this protocol on port 2407?
Sorry for bad-bad english))
iec-104asked 24 Apr &#39;13, 04:49
Curecool
6●2●2●4
accept rate: 0%
  
One Answer:
  
2 Right click on any of the packets and select: &#39;Decode As&#39;</description>
    </item>
    
    <item>
      <title>how do I determine protocols in a network capture</title>
      <link>/questions/20764/how-do-i-determine-protocols-in-a-network-capture/</link>
      <pubDate>Wed, 24 Apr 2013 06:23:00 +0000</pubDate>
      
      <guid>/questions/20764/how-do-i-determine-protocols-in-a-network-capture/</guid>
      <description>how do I determine protocols in a network capture  0 Hi there,
I&#39;m completely new to wireshark and I would like to know the correct way to determine all of the protocols the are used on the network in a specific capture, please can someone help me?
protcols networkasked 24 Apr &#39;13, 06:23
harry82
1●2●2●3
accept rate: 0%
  
2 Answers:
  
3the best way:</description>
    </item>
    
    <item>
      <title>Need to capture 3 IP address at remote location</title>
      <link>/questions/20771/need-to-capture-3-ip-address-at-remote-location/</link>
      <pubDate>Wed, 24 Apr 2013 09:57:00 +0000</pubDate>
      
      <guid>/questions/20771/need-to-capture-3-ip-address-at-remote-location/</guid>
      <description>Need to capture 3 IP address at remote location  0 I need to use wireshark to capture packets to and from 3 specific IP addresses. I have never used Wireshark before. I would like to set the capture to monitor the 3 IP addresses for 5 days. I an at a loss trying to set it up from my machine. Thanks in advance.
specific ip remote wiresharkasked 24 Apr &#39;13, 09:57</description>
    </item>
    
    <item>
      <title>Command line for uninstalling Wireshark on Windows</title>
      <link>/questions/20773/command-line-for-uninstalling-wireshark-on-windows/</link>
      <pubDate>Wed, 24 Apr 2013 10:35:00 +0000</pubDate>
      
      <guid>/questions/20773/command-line-for-uninstalling-wireshark-on-windows/</guid>
      <description>Command line for uninstalling Wireshark on Windows  0 I have some old servers that have old versions of WireShark installed.
I need a command line to uninstall Wireshark. I&#39;m going to use SCCM to push this command to a group of servers. Is there a msiexec command that I could run? I need to uninstall any version.
windows uninstall wiresharkasked 24 Apr &#39;13, 10:35
claudiup
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>AMR-WB type not detected properly</title>
      <link>/questions/20774/amr-wb-type-not-detected-properly/</link>
      <pubDate>Wed, 24 Apr 2013 11:31:00 +0000</pubDate>
      
      <guid>/questions/20774/amr-wb-type-not-detected-properly/</guid>
      <description>AMR-WB type not detected properly  0 I have wireshark capture for VoIP with AMR-WB. My capture does not have SIP transactions. So I have set the RTP preference field to decode the RTP packets with appropriate payload type as AMR-WB, octat aligned. I am able to see decoded packets. However, the protocol field shows it as only AMR. The field type bits are properly decoded though to AMR-WB 12.2 kbits.</description>
    </item>
    
    <item>
      <title>how to determine the network topology in a capture</title>
      <link>/questions/20777/how-to-determine-the-network-topology-in-a-capture/</link>
      <pubDate>Wed, 24 Apr 2013 12:26:00 +0000</pubDate>
      
      <guid>/questions/20777/how-to-determine-the-network-topology-in-a-capture/</guid>
      <description>how to determine the network topology in a capture  0 Hi guys,
I&#39;m new to wireshark and I need to know how figure out the network topology from a wireshark capture, please can someone shed some light on the subject
many thanks
H
network topologyasked 24 Apr &#39;13, 12:26
harry82
1●2●2●3
accept rate: 0%
what do you mean (exactly) by &#39;network topology&#39;?
(24 Apr &#39;13, 14:29) Kurt Knochner ♦</description>
    </item>
    
    <item>
      <title>SMB INVALID DEVICE REQUEST</title>
      <link>/questions/20779/smb-invalid-device-request/</link>
      <pubDate>Wed, 24 Apr 2013 12:56:00 +0000</pubDate>
      
      <guid>/questions/20779/smb-invalid-device-request/</guid>
      <description>SMB INVALID DEVICE REQUEST  0 Getting a SMB error during a filetransfer that I don&#39;t understand. Anyone able to shed some light on this error? Here is the trace: https://www.cloudshark.org/captures/7b5be0802a2c device request smb invalidasked 24 Apr &#39;13, 12:56
mrEEde2
336●4●6●14
accept rate: 20%
  
2 Answers:
  
2 Frame 28 is a response to frame 27, which is an FSCTL_REQUEST_FILTER_OPLOCK ioctl request on file \Eigene Dateien\ind$.</description>
    </item>
    
    <item>
      <title>Capture SNR value using tcpdump</title>
      <link>/questions/20789/capture-snr-value-using-tcpdump/</link>
      <pubDate>Wed, 24 Apr 2013 22:15:00 +0000</pubDate>
      
      <guid>/questions/20789/capture-snr-value-using-tcpdump/</guid>
      <description>Capture SNR value using tcpdump  0 Hi everyone. Does anybody know how to capture SNR value of a WiFi link using tcpdump? I tried capturing using wireshark by showing the signal and noise but those values never exists during capturing. Thanks
snrasked 24 Apr &#39;13, 22:15
Tyanium
1●4●4●5
accept rate: 0%
What version of what OS is this? (For Linux, that means both &#34;what version of the kernel&#34; and &#34;</description>
    </item>
    
    <item>
      <title>Do you need a Four-way Handshake for each client?</title>
      <link>/questions/20796/do-you-need-a-four-way-handshake-for-each-client/</link>
      <pubDate>Thu, 25 Apr 2013 06:24:00 +0000</pubDate>
      
      <guid>/questions/20796/do-you-need-a-four-way-handshake-for-each-client/</guid>
      <description>Do you need a Four-way Handshake for each client?  0 Thank you for your time.
When decrypting 802.11 traffic I understand that we need all 4 portions of the handshake to decrypt the capture file. Assuming that my handshake is valid for that particular session of collection.
Do I need a handshake for each client or will one handshake be able to decrypt multiple clients at the time of collection?</description>
    </item>
    
    <item>
      <title>How to calculate bandwidth requirments based upon flows per minute (fpm)?</title>
      <link>/questions/20802/how-to-calculate-bandwidth-requirments-based-upon-flows-per-minute-fpm/</link>
      <pubDate>Thu, 25 Apr 2013 08:53:00 +0000</pubDate>
      
      <guid>/questions/20802/how-to-calculate-bandwidth-requirments-based-upon-flows-per-minute-fpm/</guid>
      <description>How to calculate bandwidth requirments based upon flows per minute (fpm)?  0 I want to know how can one calculate bandwidth requirements based upon flows and viceversa.
Meaning if I had to achieve total of 50,000 netflows what is the bandwidth requirement to produce this number? Is there a formula for this. I&#39;m using this to size up flow analyzer appliance. If its license says supports 50,000 flows what does this means.</description>
    </item>
    
    <item>
      <title>tshark string search on Windows</title>
      <link>/questions/20805/tshark-string-search-on-windows/</link>
      <pubDate>Thu, 25 Apr 2013 10:38:00 +0000</pubDate>
      
      <guid>/questions/20805/tshark-string-search-on-windows/</guid>
      <description>tshark string search on Windows  0 Hi,
When using
c:\tshark -r input frame contains &#34;aaa&#34; -w output
everything is fine.
When the string is &#34;aaa bbb&#34; I get an error on windows 7 saying &#34;bbb&#34; was unexpected in this context.
Any clue what is the issue?
Thanks, zf
tsharkasked 25 Apr &#39;13, 10:38
zfme
16●1●1●3
accept rate: 0%
 edited 25 Apr &#39;13, 11:46 
Kurt Knochner ♦
24.8k●10●39●237</description>
    </item>
    
    <item>
      <title>Mate filter for MySQL</title>
      <link>/questions/20812/mate-filter-for-mysql/</link>
      <pubDate>Thu, 25 Apr 2013 16:04:00 +0000</pubDate>
      
      <guid>/questions/20812/mate-filter-for-mysql/</guid>
      <description>Mate filter for MySQL  0 Hi guys I&#39;m having a little trouble with my mate filter for MySQL I&#39;m trying to write the start and stop conditions, but can&#39;t seem to work out how we find the last packet - it&#39;s quite clear in the packet list, but I can&#39;t build the Gop or the Gog from it.
Gop mysql_req On mysql_pdu Match (mysql_addr, mysql_addr, mysql_port, mysql_port,mysql_command, mysql_eof) { Start (mysql_command = 3); Stop (mysql_eof = 254); };I would have thought the start would be the query (mysql_command = 3) and the stop would be mysql_eof = 254, but I never get a completed gop</description>
    </item>
    
    <item>
      <title>Decoding Pilot packet</title>
      <link>/questions/20814/decoding-pilot-packet/</link>
      <pubDate>Thu, 25 Apr 2013 21:07:00 +0000</pubDate>
      
      <guid>/questions/20814/decoding-pilot-packet/</guid>
      <description>Decoding Pilot packet  0 Hi I am using Wireshark &#34;Version 1.8.6 (SVN Rev 48142 from /trunk-1.8)&#34; on Mac OS 10.7.5 . I want decode a &#34;Pilot&#34; packet but not seeing any option to in &#34;Decode As&#34; list. Is there any provision I can decode a packet as Pilot ? I Is that any Plugin I would need to install for the same ?
decode_as pilotasked 25 Apr &#39;13, 21:07</description>
    </item>
    
    <item>
      <title>Wireshark crashing</title>
      <link>/questions/20816/wireshark-crashing/</link>
      <pubDate>Fri, 26 Apr 2013 09:14:00 +0000</pubDate>
      
      <guid>/questions/20816/wireshark-crashing/</guid>
      <description>Wireshark crashing  0 Hey All,
I am getting an issue with WireShark crashing after around 50 minutes of caputring.
I read some posts saying this was down to a memory issue but I have monitored the server and although memory consumption by wireshark reachs a few GB it nevers maxes out the available memory. I even tried having it split the captures into 10mb files and it still crashes around 50 minutes.</description>
    </item>
    
    <item>
      <title>Active Directory User Account Capture</title>
      <link>/questions/20821/active-directory-user-account-capture/</link>
      <pubDate>Sat, 27 Apr 2013 07:23:00 +0000</pubDate>
      
      <guid>/questions/20821/active-directory-user-account-capture/</guid>
      <description>Active Directory User Account Capture  0 I am novice user of Wireshark and I am trying to track down a PC where an unauthorized user is trying to logon to our network. I have searched numerous capture files and have not found any Active Directory user accounts. Is this information not contained in a packet? If it, how do I extract the information.
active directory account userasked 27 Apr &#39;13, 07:23</description>
    </item>
    
    <item>
      <title>Multicast stream analysis in tshark</title>
      <link>/questions/20823/multicast-stream-analysis-in-tshark/</link>
      <pubDate>Sat, 27 Apr 2013 18:34:00 +0000</pubDate>
      
      <guid>/questions/20823/multicast-stream-analysis-in-tshark/</guid>
      <description>Multicast stream analysis in tshark  0 Hello to all. In wireshark GUI version we have &#34;Multicast stream analysis&#34;, is there convenient way to do the same task in tshark?
console tsharkasked 27 Apr &#39;13, 18:34
markotitel
11●1●1●2
accept rate: 0%
 edited 27 Apr &#39;13, 20:44 
Guy Harris ♦♦
17.4k●3●35●196
   </description>
    </item>
    
    <item>
      <title>Can Wireshark capture on a PPP interface?</title>
      <link>/questions/20824/can-wireshark-capture-on-a-ppp-interface/</link>
      <pubDate>Sat, 27 Apr 2013 20:20:00 +0000</pubDate>
      
      <guid>/questions/20824/can-wireshark-capture-on-a-ppp-interface/</guid>
      <description>Can Wireshark capture on a PPP interface?  0 I recently purchased wireless modem, it uses ppp interface. Wireshark does not identify this interface. So, Can wireshark work on ppp interface?
on interfaces ppp wiresharkasked 27 Apr &#39;13, 20:20
Dhira
1●2●2●3
accept rate: 0%
 edited 27 Apr &#39;13, 20:43 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
2On some versions of UN*X? Yes.
On Windows Vista and later (and 64-bit XP)?</description>
    </item>
    
    <item>
      <title>all conversation(ip&amp;#x27;s) within one session</title>
      <link>/questions/20826/all-conversationips-within-one-session/</link>
      <pubDate>Sat, 27 Apr 2013 23:01:00 +0000</pubDate>
      
      <guid>/questions/20826/all-conversationips-within-one-session/</guid>
      <description>all conversation(ip&amp;rsquo;s) within one session  0 how can we find out all conversation pertaining to one session,say for e.g.during a communication betweeen a-b,in between the session a also commmunicates with C lets say for authenticatioin,how could we find out this with just reading wireshark capture.Kishan
iteoffeasked 27 Apr &#39;13, 23:01
kishan pandey
221●28●29●36
accept rate: 28%
  
2 Answers:
  
0 You could use the items in the statistics menu of Wireshark, e.</description>
    </item>
    
    <item>
      <title>6lowpan/IPv6 RFC4944 data on 802.15.4 frames</title>
      <link>/questions/20827/6lowpanipv6-rfc4944-data-on-802154-frames/</link>
      <pubDate>Sun, 28 Apr 2013 00:17:00 +0000</pubDate>
      
      <guid>/questions/20827/6lowpanipv6-rfc4944-data-on-802154-frames/</guid>
      <description>6lowpan/IPv6 RFC4944 data on 802.15.4 frames  0 I can capture 802.15.4 frames containing IPv6 packets in RFC4944 format using TIs CC2531 hardware and their SmartRF sniffer. I&#39;ve been able to convert them to PCAP format such that wireshark can decode the 802.15.4 headers, but I&#39;m not able to get it to decode the IPv6 packet contents.
I know that Wireshark supports RFC4944. I see it work fine with the example captures on http://wiki.</description>
    </item>
    
    <item>
      <title>UDP to RTP- streaming video</title>
      <link>/questions/20832/udp-to-rtp-streaming-video/</link>
      <pubDate>Sun, 28 Apr 2013 03:58:00 +0000</pubDate>
      
      <guid>/questions/20832/udp-to-rtp-streaming-video/</guid>
      <description>UDP to RTP- streaming video  0 hi, I&#39;m testing the arbiter of an especial switch by streaming and playing a video on 2 ports.I need a software to measure the delay and quantify it. The application I have used is VLC player. I could do the streaming test by setting only the RTP protocol on VLC. But when I play the video on another PC and capture the packets by Wireshark, I could see UDP packets, and I can&#39;t measure the delay!</description>
    </item>
    
    <item>
      <title>rtp statistics on a loopback capture</title>
      <link>/questions/20837/rtp-statistics-on-a-loopback-capture/</link>
      <pubDate>Mon, 29 Apr 2013 04:37:00 +0000</pubDate>
      
      <guid>/questions/20837/rtp-statistics-on-a-loopback-capture/</guid>
      <description>rtp statistics on a loopback capture  0 Im trying to run TShark with a loopback capture and get a table of RTP statistics using: c:\tshark.exe -q -r &amp;lt;pcap file=&#34;&#34;&amp;gt; -z rtp,streams.
for some reason I get an empty table. This is not the case for a non-loopback pcap file.
if I open the file with wireshark and decode as RTP I can see the RTP streams. Does anyone know why I can&#39;t get the statistics for this file?</description>
    </item>
    
    <item>
      <title>GTPv2C Release 10 ( 29.274v10.10) IE Decode</title>
      <link>/questions/20838/gtpv2c-release-10-29274v1010-ie-decode/</link>
      <pubDate>Mon, 29 Apr 2013 06:53:00 +0000</pubDate>
      
      <guid>/questions/20838/gtpv2c-release-10-29274v1010-ie-decode/</guid>
      <description>GTPv2C Release 10 ( 29.274v10.10) IE Decode  0 Hi Wireshark,
I want to know that does any version of wireshark decodes the newly introduced IEs of GTPv2C (like Node Features, EPC Timer, Signalling Priority Indication etc)? Wireshark can identify the IEs, but not further decoding!! Please mention the version.
Thanks in advance!!
gtpv2c release10asked 29 Apr &#39;13, 06:53
baila
21●10●11●15
accept rate: 0%
 edited 29 Apr &#39;13, 06:54</description>
    </item>
    
    <item>
      <title>Cannot run Wireshark 1.8.6 on ML 10.8.3</title>
      <link>/questions/20844/cannot-run-wireshark-186-on-ml-1083/</link>
      <pubDate>Mon, 29 Apr 2013 11:56:00 +0000</pubDate>
      
      <guid>/questions/20844/cannot-run-wireshark-186-on-ml-1083/</guid>
      <description>Cannot run Wireshark 1.8.6 on ML 10.8.3  0 Hi gang,
I have used WS for a good while, and really appreciate all it does for me. I just changed companies and went to install it on my new machine, and am having the most frustrating time getting even the simplest of things to work.
I downloaded and installed XQuartz (2.7.4), rebooted and was never able to launch it. The icon would show in the dock and disappear immediately.</description>
    </item>
    
    <item>
      <title>Why Wireshark is not showing high layer packets like ICMP/IP/UDP?</title>
      <link>/questions/20845/why-wireshark-is-not-showing-high-layer-packets-like-icmpipudp/</link>
      <pubDate>Mon, 29 Apr 2013 12:38:00 +0000</pubDate>
      
      <guid>/questions/20845/why-wireshark-is-not-showing-high-layer-packets-like-icmpipudp/</guid>
      <description>Why Wireshark is not showing high layer packets like ICMP/IP/UDP?  0 I am using Wireshark for 802.11g sniffing. The AP is not using any encryption. I can see the beacons, the probe requests and even ARP communications from one station. But no ICMP/IP/UDP/TCP layer data packets are shown. Actually, if I filter out the beacon signal of my AP, I can see no packets at all, even I know clearly that same station is doing Ping right now using wireless interface.</description>
    </item>
    
    <item>
      <title>Need The Most Experienced Person Here To Recommend On Which Is The Best Source For Learning How to Read Packets</title>
      <link>/questions/20848/need-the-most-experienced-person-here-to-recommend-on-which-is-the-best-source-for-learning-how-to-read-packets/</link>
      <pubDate>Tue, 30 Apr 2013 00:24:00 +0000</pubDate>
      
      <guid>/questions/20848/need-the-most-experienced-person-here-to-recommend-on-which-is-the-best-source-for-learning-how-to-read-packets/</guid>
      <description>Need The Most Experienced Person Here To Recommend On Which Is The Best Source For Learning How to Read Packets  0 hi basic question, in short, what is the very best single source/guide for learning the basic skill of how to read packets? as of the date you are reading this. one link is perfect.
specially i would at least (minimal need) like to know how to read what sites i visited, probably one of the most casual basic need and use of wireshark.</description>
    </item>
    
    <item>
      <title>Is it possible to decrypt an SSL Session post capture</title>
      <link>/questions/20855/is-it-possible-to-decrypt-an-ssl-session-post-capture/</link>
      <pubDate>Tue, 30 Apr 2013 11:43:00 +0000</pubDate>
      
      <guid>/questions/20855/is-it-possible-to-decrypt-an-ssl-session-post-capture/</guid>
      <description>Is it possible to decrypt an SSL Session post capture  0 I know its possibly to decrypt an SSL session, but is it possible to decrypt an SSL session post capture?
I have a capture that was done with another product that they have no idea if or how to configure it to decrypt the SSL session. And putting wireshark on the network so far isn&#39;t happening, but I do have the SSL keys so the obvious question that I came up with, can I do it on that saved capture file?</description>
    </item>
    
    <item>
      <title>How to write a dissector for a protocol that runs on top of TCP or UDP both</title>
      <link>/questions/20858/how-to-write-a-dissector-for-a-protocol-that-runs-on-top-of-tcp-or-udp-both/</link>
      <pubDate>Tue, 30 Apr 2013 23:10:00 +0000</pubDate>
      
      <guid>/questions/20858/how-to-write-a-dissector-for-a-protocol-that-runs-on-top-of-tcp-or-udp-both/</guid>
      <description>How to write a dissector for a protocol that runs on top of TCP or UDP both  0 I&#39;m a long time developer who is new to wireshark. I&#39;m actually trying to update the built in C12.22 dissector that is for TCP currently to also use UDP as well, everything else the same. If someone could just send me a new x64 1.8.6 asn1.dll that would be super awesome. If not please tell me how to setup a new dissector or modify the C12.</description>
    </item>
    
    <item>
      <title>my ssh terminal hangs when I try remote capture on Linux.</title>
      <link>/questions/20859/my-ssh-terminal-hangs-when-i-try-remote-capture-on-linux/</link>
      <pubDate>Tue, 30 Apr 2013 23:39:00 +0000</pubDate>
      
      <guid>/questions/20859/my-ssh-terminal-hangs-when-i-try-remote-capture-on-linux/</guid>
      <description>my ssh terminal hangs when I try remote capture on Linux.  0 I issue following commands:
1) mkfifo /tmp/pipe 2) ssh [email protected] &#34;tcpdump -i em1 -s 0 -U -w - not port 22&#34; &amp;gt; /tmp/pipe
strange thing is that when I tried it first time it worked fine. But when I tried it for second time my ssh terminal hangs when I issue second command.
(I also tried by restarting both the systems but I am having same problem)</description>
    </item>
    
    <item>
      <title>how to display the packet&amp;#x27;s CRC in the GUI and how to edit CRC with bad value</title>
      <link>/questions/20862/how-to-display-the-packets-crc-in-the-gui-and-how-to-edit-crc-with-bad-value/</link>
      <pubDate>Wed, 01 May 2013 00:50:00 +0000</pubDate>
      
      <guid>/questions/20862/how-to-display-the-packets-crc-in-the-gui-and-how-to-edit-crc-with-bad-value/</guid>
      <description>how to display the packet&amp;rsquo;s CRC in the GUI and how to edit CRC with bad value  0 I want to generate a cap file with bad CRC packets using wireshark. I recorded the traffic I want but: 1. I don&#39;t see the CRC in the wireshark GUI and couldn&#39;t find where to enable this view 2. I cant find a way to &#34;corrupt&#34; the CRC of all packets in the cap file</description>
    </item>
    
    <item>
      <title>File from Juniper SSG5 &amp;quot;snoop&amp;quot; not opening correctly in Wireshark</title>
      <link>/questions/20878/file-from-juniper-ssg5-snoop-not-opening-correctly-in-wireshark/</link>
      <pubDate>Wed, 01 May 2013 10:19:00 +0000</pubDate>
      
      <guid>/questions/20878/file-from-juniper-ssg5-snoop-not-opening-correctly-in-wireshark/</guid>
      <description>File from Juniper SSG5 &amp;ldquo;snoop&amp;rdquo; not opening correctly in Wireshark  0 I&#39;m running Wireshark 1.8.6. I&#39;ve done this process before, using the snoop command on a Juniper SSG router, capturing the screen output of the snoop to a text file, then opening it in Wireshark. However, today, every packet appears corrupt (wrong timestamp, wrong protocol info, etc.). Here&#39;s a sample of what I&#39;m trying to open. It &#34;looks&#34; the same as files I&#39;ve previously used, but something must be hinky.</description>
    </item>
    
    <item>
      <title>Citrix server capture showing Duplicate Acks and Retransmits</title>
      <link>/questions/20882/citrix-server-capture-showing-duplicate-acks-and-retransmits/</link>
      <pubDate>Wed, 01 May 2013 12:34:00 +0000</pubDate>
      
      <guid>/questions/20882/citrix-server-capture-showing-duplicate-acks-and-retransmits/</guid>
      <description>Citrix server capture showing Duplicate Acks and Retransmits  0 I have a client complaining of delays in printing to a printer connected off of a Citrix server. Wireshark capture on the Citrix server shows a ton of Dup ACKs and retransmits. The Duplicate Acks appear to be happening to fast to be real. I am hoping someone can help analyze this capture http://www.cloudshark.org/captures/2046db994407
I&#39;m trying to determine a possible cause of the dup acks.</description>
    </item>
    
    <item>
      <title>Checking of open ports of a remote IP .</title>
      <link>/questions/20889/checking-of-open-ports-of-a-remote-ip/</link>
      <pubDate>Wed, 01 May 2013 22:26:00 +0000</pubDate>
      
      <guid>/questions/20889/checking-of-open-ports-of-a-remote-ip/</guid>
      <description>Checking of open ports of a remote IP .  0 For instance, my current ip address is 192.168.2.33 , but I want to check for open ports of the ip address 191.168.1.44 .
If I enter netstat -an on my machine, it checks for open ports on my machine and not the remote machine right ?
How do I use netstat to probe the remote ip at 191.168.1.44 instead ?</description>
    </item>
    
    <item>
      <title>getting Expert Info (Warn/Undecoded): Unknown bit(s): 0x01</title>
      <link>/questions/20890/getting-expert-info-warnundecoded-unknown-bits-0x01/</link>
      <pubDate>Wed, 01 May 2013 23:44:00 +0000</pubDate>
      
      <guid>/questions/20890/getting-expert-info-warnundecoded-unknown-bits-0x01/</guid>
      <description>getting Expert Info (Warn/Undecoded): Unknown bit(s): 0x01  0 Hi, i&#39;m using wireshark Version 1.10.0rc1 and i getting this error in my ssl packet Expert Info (Warn/Undecoded): Unknown bit(s): 0x01 was it safe to ignore it? seem like the dissector cant decode that info
info bits expect unknowasked 01 May &#39;13, 23:44
splibytes
11●4●4●5
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Regular Expressions for parsing with IP spam source</title>
      <link>/questions/20893/regular-expressions-for-parsing-with-ip-spam-source/</link>
      <pubDate>Thu, 02 May 2013 01:06:00 +0000</pubDate>
      
      <guid>/questions/20893/regular-expressions-for-parsing-with-ip-spam-source/</guid>
      <description>Regular Expressions for parsing with IP spam source  0 Hello,
I&#39;m trying to see email address with regular expression from a specific source IP that is doing spam from the corporate office.
I m using EnCase Software for data analysis and I need to create a full listing email and IP destination.
Is there a way to capture frame who contains Email Address and to see them in a column ?</description>
    </item>
    
    <item>
      <title>high fragmentation will cause retranmission</title>
      <link>/questions/20894/high-fragmentation-will-cause-retranmission/</link>
      <pubDate>Thu, 02 May 2013 02:38:00 +0000</pubDate>
      
      <guid>/questions/20894/high-fragmentation-will-cause-retranmission/</guid>
      <description>high fragmentation will cause retranmission  0 Hi, when i try to stream a video i can see it lagging, when i try to capture using wire-shark. i saw a lot retransmission and duplicate ack?
so my question is , if i have a lot fragment or miss match MTU where by the switch are using Long Frame Size(Bytes) : 9216 while my firewall only using MTU 1500, can this be the cause of the high retransmission?</description>
    </item>
    
    <item>
      <title>Different PPP compressions</title>
      <link>/questions/20899/different-ppp-compressions/</link>
      <pubDate>Thu, 02 May 2013 03:55:00 +0000</pubDate>
      
      <guid>/questions/20899/different-ppp-compressions/</guid>
      <description>Different PPP compressions  0 Hi In PPP CCP there is an option to enable Deflate(zlib), BSD and Magnalink compressions. What happens if they negotiate and agree on all three? How those packets would look like, and which compression algorithm would they use? I&#39;m curious, the MPPC&#39;s rfc was clear, but the rfc-s about this, isn&#39;t.
ppp compressionasked 02 May &#39;13, 03:55
KisKer
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>cannot decrypt Fix protocol over SSL</title>
      <link>/questions/20910/cannot-decrypt-fix-protocol-over-ssl/</link>
      <pubDate>Thu, 02 May 2013 09:44:00 +0000</pubDate>
      
      <guid>/questions/20910/cannot-decrypt-fix-protocol-over-ssl/</guid>
      <description>cannot decrypt Fix protocol over SSL  0 Hello
Im using wireshark 1.6.8
Im tring to decode FIX traffic over TLSV1
So, On the SSL Decrypt dialog we fill the
&amp;lt;-ip-&amp;gt;
&amp;lt;-port-&amp;gt;
&amp;lt;-FIX-&amp;gt;
&amp;lt;-path\to\key-&amp;gt;
But after clicking on ok , we get the following error appear
&#34;error in column &#39;Protocol&#39;: Could not find dissector for: &#39;FIX&#39;&#34;
the same problem also when we write &amp;lt;-fix-&amp;gt; in place of &amp;lt;-FIX-&amp;gt;
Thanks for help.</description>
    </item>
    
    <item>
      <title>Packet capture issues between servers</title>
      <link>/questions/20913/packet-capture-issues-between-servers/</link>
      <pubDate>Thu, 02 May 2013 09:56:00 +0000</pubDate>
      
      <guid>/questions/20913/packet-capture-issues-between-servers/</guid>
      <description>Packet capture issues between servers  0 Hi, I am trying to capture traffic/dropped packets between two servers, I have wireshark installed on server1 (example; 192.168.1.1)
I clicked on the interface I want to capture, and then in the filter box I put in the below...
I have in there &#34;host 192.168.1.1 and host 192.168.1.2&#34; I tried it with the &#34;&#34; and without
It gives me the error: &#34;hostname 192.168.1.1 and hostname 192.</description>
    </item>
    
    <item>
      <title>TCP MSS not advertised Win2k8 r2 Capture</title>
      <link>/questions/20917/tcp-mss-not-advertised-win2k8-r2-capture/</link>
      <pubDate>Thu, 02 May 2013 12:35:00 +0000</pubDate>
      
      <guid>/questions/20917/tcp-mss-not-advertised-win2k8-r2-capture/</guid>
      <description>TCP MSS not advertised Win2k8 r2 Capture  0 Hello. I am running Windows 2008 r2 and have noticed that some of our machines do not advertise the MSS value in the TCP header information. This is odd. Anyone know what may be causing this problem? It is causing internet connectivity problems.
windows mss tcpasked 02 May &#39;13, 12:35
rogermitan
1●1●1●1
accept rate: 0%
 edited 31 May &#39;13, 02:03</description>
    </item>
    
    <item>
      <title>&amp;quot;Not compatible&amp;quot; - regardless if I choose 32 or 64</title>
      <link>/questions/20921/not-compatible-regardless-if-i-choose-32-or-64/</link>
      <pubDate>Thu, 02 May 2013 22:13:00 +0000</pubDate>
      
      <guid>/questions/20921/not-compatible-regardless-if-i-choose-32-or-64/</guid>
      <description>&amp;ldquo;Not compatible&amp;rdquo; - regardless if I choose 32 or 64  0 Hello,
I am trying to install Wireshark on Win 7 64-bit but I am getting the following error message when trying to install. And I have tried both the 32-bit and 64-bit executables. Any ideas on what is going wrong here?
&#34;The version of this file is not compatible with the version of Windows you&#39;re running. Check your computer&#39;s system information to see whether you need an x86 (32-bit) or x64 (64-bit) version of the program, and then contact the software publisher.</description>
    </item>
    
    <item>
      <title>How can I convert an .xml file to a .pcap file</title>
      <link>/questions/20924/how-can-i-convert-an-xml-file-to-a-pcap-file/</link>
      <pubDate>Fri, 03 May 2013 02:42:00 +0000</pubDate>
      
      <guid>/questions/20924/how-can-i-convert-an-xml-file-to-a-pcap-file/</guid>
      <description>How can I convert an .xml file to a .pcap file  0 How can I convert an .xml file to a .pcap file,so that I can analyze the protocols I get.
xml pcapasked 03 May &#39;13, 02:42
kiyomi
1●1●1●2
accept rate: 0%
  
One Answer:
  
0That depends on the structure and the content of the XML file. If the XML file contains the raw packet bytes, you could extract those bytes from the XML file and write those bytes in a format that text2pacp understands.</description>
    </item>
    
    <item>
      <title>Is Wireshark the tool I need?</title>
      <link>/questions/20925/is-wireshark-the-tool-i-need/</link>
      <pubDate>Fri, 03 May 2013 02:44:00 +0000</pubDate>
      
      <guid>/questions/20925/is-wireshark-the-tool-i-need/</guid>
      <description>Is Wireshark the tool I need?  0 Greetings Wireshark Wizes! Tonight I downloaded the tool and read through some of the documentation. Without tunneling too much further, I wanted to see if the pros think there is gold at the end of my tunnel. What I&#39;m looking for is this: A background TCP monitoring program that will alert me and run a script when a certain IP sends me a packet, or when a certain packet is received regardless of the source.</description>
    </item>
    
    <item>
      <title>missing value: field in decode</title>
      <link>/questions/20934/missing-value-field-in-decode/</link>
      <pubDate>Fri, 03 May 2013 10:19:00 +0000</pubDate>
      
      <guid>/questions/20934/missing-value-field-in-decode/</guid>
      <description>missing value: field in decode  0 I&#39;m running multiple versions of Wireshark and noticed that the &#34;Value:&#34; field typically located under the &#34;Length:&#34; field for DHCP decodes is missing on Version 1.8.6 for Windows. Is there any way to turn this field back on?
dhcp valueasked 03 May &#39;13, 10:19
onebithead
1●1●1●1
accept rate: 0%
  
One Answer:
  
0The Value item is now a hidden tree item and thus you cannot see it.</description>
    </item>
    
    <item>
      <title>Wireshark capturing only incoming traffic on Windows 7</title>
      <link>/questions/20937/wireshark-capturing-only-incoming-traffic-on-windows-7/</link>
      <pubDate>Fri, 03 May 2013 11:21:00 +0000</pubDate>
      
      <guid>/questions/20937/wireshark-capturing-only-incoming-traffic-on-windows-7/</guid>
      <description>Wireshark capturing only incoming traffic on Windows 7  0 Wireshark capturing only incoming traffic. For example, when i ping a site I only see the reply packets. Wireshark version is 1.8.6 running on a windows 7 x64 OS and WinCap is version 4.1.2. I uninstalled wireshark and also cleaned the registry and still having the same issue. Not really sure that it&#39;s the NIC because I have both Microsoft Network Monitor 3.</description>
    </item>
    
    <item>
      <title>Airopeek sniffer capture (.pkt) and tags</title>
      <link>/questions/20939/airopeek-sniffer-capture-pkt-and-tags/</link>
      <pubDate>Fri, 03 May 2013 11:56:00 +0000</pubDate>
      
      <guid>/questions/20939/airopeek-sniffer-capture-pkt-and-tags/</guid>
      <description>Airopeek sniffer capture (.pkt) and tags  0 Hi,
The wireshark code doesn&#39;t interpret all the tags present in the sniffer capture (.pkt). Where can I find the description of each tag present in such kind of file? Thanks in advance.
airopeek wiresharkasked 03 May &#39;13, 11:56
Silwer star
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Please take a look at the PeekRdr Sample Application and the included documentation.</description>
    </item>
    
    <item>
      <title>tshark output to csv help (bandwidth)</title>
      <link>/questions/20941/tshark-output-to-csv-help-bandwidth/</link>
      <pubDate>Fri, 03 May 2013 13:11:00 +0000</pubDate>
      
      <guid>/questions/20941/tshark-output-to-csv-help-bandwidth/</guid>
      <description>tshark output to csv help (bandwidth)  0 I am trying to figure how to output what was the bandwidth useage at the time the packets were logged. This is what my command line looks like.
tshark -nr 3.pcap -T fields -E separator=, -E header=y -e frame.number -e frame.time -e frame.len -e eth.type -e eth.src -e eth.dst -e ip.len -e ip.id -e ip.flags -e ip.dst -e ip.src -e ip.proto -e ip.</description>
    </item>
    
    <item>
      <title>Apple Airport Extreme / Time Capsule &amp;#x27;Enable Default Host&amp;#x27; option</title>
      <link>/questions/20952/apple-airport-extreme-time-capsule-enable-default-host-option/</link>
      <pubDate>Sat, 04 May 2013 12:47:00 +0000</pubDate>
      
      <guid>/questions/20952/apple-airport-extreme-time-capsule-enable-default-host-option/</guid>
      <description>Apple Airport Extreme / Time Capsule &amp;lsquo;Enable Default Host&amp;rsquo; option  0 Hey,
So this is the setup... I&#39;ve got a Time Capsule and I&#39;ve set the &#39;Enable default host&#39; option which, from what I understand, redirects ALL traffic unaltered to a given IP address.
All works as expected i.e. not a lot of traffic before to loads of traffic after activating. However, all the traffic now has the default host IP address removing the intended machines IP address.</description>
    </item>
    
    <item>
      <title>tshark memory consumption increasing continuously</title>
      <link>/questions/20954/tshark-memory-consumption-increasing-continuously/</link>
      <pubDate>Sun, 05 May 2013 02:30:00 +0000</pubDate>
      
      <guid>/questions/20954/tshark-memory-consumption-increasing-continuously/</guid>
      <description>tshark memory consumption increasing continuously  0 Hi,
I written an application in C Language which uses tshark to apply the display filter. Application sends PDUs to tshark over stdin and receive filtered PDUs over stdout. I am using following command while launching tshark in child process
tshark -r - -R &#34;Filter Expression&#34; -w - -q -s0
This application runs continuously which send around 4000 PDUs/sec to thsark for filtering.</description>
    </item>
    
    <item>
      <title>tshark: excluding multiple ip addresses ?</title>
      <link>/questions/20956/tshark-excluding-multiple-ip-addresses/</link>
      <pubDate>Sun, 05 May 2013 06:49:00 +0000</pubDate>
      
      <guid>/questions/20956/tshark-excluding-multiple-ip-addresses/</guid>
      <description>tshark: excluding multiple ip addresses ?  0 I can&#39;t work out the correct syntax for excluding multiple ip addresses with tshark. I&#39;m running tshark on a centos 6 server which is command line only. I can exclude a single ip address from the scoll by using:
/usr/sbin/tshark -R &#34;ip.addr!=176.31.239.201&#34; &amp;lt;-- this command excludes 176.31.239.201 but I&#39;d also like to exclude several other ip addresses but nothing works.
tsharkasked 05 May &#39;13, 06:49</description>
    </item>
    
    <item>
      <title>How to capture packets and then search for specific string and export</title>
      <link>/questions/20961/how-to-capture-packets-and-then-search-for-specific-string-and-export/</link>
      <pubDate>Sun, 05 May 2013 10:13:00 +0000</pubDate>
      
      <guid>/questions/20961/how-to-capture-packets-and-then-search-for-specific-string-and-export/</guid>
      <description>How to capture packets and then search for specific string and export  0 Hi, I wish to capture automatically specific lines from a packet. I know what the packet header is. How do I do this (with Tshark I assume). I could simply settle for just exporting then entire packet to a text file and then using an independent parser.
Thank you for any help!
specific automaticallyasked 05 May &#39;13, 10:13</description>
    </item>
    
    <item>
      <title>specify disabled_protos file on command line</title>
      <link>/questions/20965/specify-disabled_protos-file-on-command-line/</link>
      <pubDate>Sun, 05 May 2013 13:36:00 +0000</pubDate>
      
      <guid>/questions/20965/specify-disabled_protos-file-on-command-line/</guid>
      <description>specify disabled_protos file on command line  1 How do I make tshark read a disabled_protos file (or any other config file) specified by name on the command line, rather than finding it in any of the stock locations? -C is the closest thing I&#39;ve found to what I want, but that looks in ~/.wireshark/ for the profile directory, whereas I want to keep my custom configuration files with the project they belong to.</description>
    </item>
    
    <item>
      <title>What is autonoc reset?</title>
      <link>/questions/20968/what-is-autonoc-reset/</link>
      <pubDate>Sun, 05 May 2013 14:14:00 +0000</pubDate>
      
      <guid>/questions/20968/what-is-autonoc-reset/</guid>
      <description>What is autonoc reset?  0 Hi,
Wireshark is outputing a black background with pink(?) letters with this:
[TCP Dup ACK] http -&amp;gt; autonoc [ACK] seq=597 ack=672 win=67000
And just bellow, follow a red background with yellow letters with this:
autonoc -&amp;gt; http [RST] seq=672 win=0 len=0
What could be this?
autonoc resetasked 05 May &#39;13, 14:14
skd
6●1●1●3
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>mac address</title>
      <link>/questions/20971/mac-address/</link>
      <pubDate>Sun, 05 May 2013 17:27:00 +0000</pubDate>
      
      <guid>/questions/20971/mac-address/</guid>
      <description>mac address  0 why does destination mac address 00:00:00:00:00:00 is reported for different types of ip add&#39;s even though it is not corresponding any of the ip&#39;s i am using??? what does this mac address means ?? is it like failing securely ???? someone help me out please
mac-addressasked 05 May &#39;13, 17:27
ark
16●4●5●5
accept rate: 0%
  
One Answer:
  
0Depending on what capture it is you are looking at, it is not necessarily the real MAC addresses that you see.</description>
    </item>
    
    <item>
      <title>ip addresses analysis</title>
      <link>/questions/20972/ip-addresses-analysis/</link>
      <pubDate>Sun, 05 May 2013 18:24:00 +0000</pubDate>
      
      <guid>/questions/20972/ip-addresses-analysis/</guid>
      <description>ip addresses analysis  0 how can we find out server ip address from the pcap file using wireshark ??? can we create specific filter columns (like protocol, source, destination... etc..) in the packets pane???? pls let me knew
ipasked 05 May &#39;13, 18:24
ark
16●4●5●5
accept rate: 0%
  
2 Answers:
  
1The server is usually the IP the TCP SYN packets are sent to, while the source of the SYN packets in the client.</description>
    </item>
    
    <item>
      <title>tshark -Tfields, identify SSL record types accurately</title>
      <link>/questions/20974/tshark-tfields-identify-ssl-record-types-accurately/</link>
      <pubDate>Sun, 05 May 2013 20:14:00 +0000</pubDate>
      
      <guid>/questions/20974/tshark-tfields-identify-ssl-record-types-accurately/</guid>
      <description>tshark -Tfields, identify SSL record types accurately  0 I&#39;m using tshark -Tfields to print a packet trace in a machine-readable format, and one of the things I need to extract is the SSL record type for each record in the packet, if the packet contains SSL records. If I print the ssl.record.content_type and ssl.handshake.type fields, they do not seem to be consistent with each other: specifically, for this packet trace</description>
    </item>
    
    <item>
      <title>Wireshark1.8.5 filter:SELECTED doesn&amp;#x27;t work.</title>
      <link>/questions/20977/wireshark185-filterselected-doesnt-work/</link>
      <pubDate>Mon, 06 May 2013 01:17:00 +0000</pubDate>
      
      <guid>/questions/20977/wireshark185-filterselected-doesnt-work/</guid>
      <description>Wireshark1.8.5 filter:SELECTED doesn&amp;rsquo;t work.  0 wireshark 1.8.5. The filter function.
If I do these:
Right click - &amp;gt; apply a filter - &amp;gt; selected udp.
It will come to:!(udp).
selectedasked 06 May &#39;13, 01:17
smilezuzu
20●32●32●37
accept rate: 0%
Where is the screen do you right-click? The packet list (and in which column) or the packet details (and which row)?
Did you now by accident rightclick and then selected &#34;</description>
    </item>
    
    <item>
      <title>How  create WiresharkPortable installation kit ?</title>
      <link>/questions/20982/how-create-wiresharkportable-installation-kit/</link>
      <pubDate>Mon, 06 May 2013 03:09:00 +0000</pubDate>
      
      <guid>/questions/20982/how-create-wiresharkportable-installation-kit/</guid>
      <description>How create WiresharkPortable installation kit ?  0 Hi, could you suggest how create installation kit for &#34;Wireshark Portable&#34;, please ? (I&#39;m able to create &#34;ordinary&#34; installation by nmake /f Makefile.nmake packaging, however I very need &#34;portable&#34; version). Thank you a lot in advance
portableasked 06 May &#39;13, 03:09
Yuriy
11●2●2●4
accept rate: 0%
  
One Answer:
  
1nmake -f Makefile.nmake packaging_papps
answered 06 May &#39;13, 04:44</description>
    </item>
    
    <item>
      <title>Time stamp format</title>
      <link>/questions/20987/time-stamp-format/</link>
      <pubDate>Mon, 06 May 2013 09:40:00 +0000</pubDate>
      
      <guid>/questions/20987/time-stamp-format/</guid>
      <description>Time stamp format  0 Hello I have captured a file using wireshark on windows. I have run a listener on that captured file and i use pinfo.abs_ts the time stamp i got is 1367758370.5337 1367758370.5337
1367758370.5344
1367758370.5344
1367758370.5347
1367758370.5347
1367758370.5416
1367758370.5417
1367758370.542
1367758370.542
1367758370.5429
1367758370.543
if any one could tell the meaning of those time stamps forma and how to convert it, note that i care to know the milliseconds and seconds Thank you</description>
    </item>
    
    <item>
      <title>tshark capture filter for len parameter</title>
      <link>/questions/20990/tshark-capture-filter-for-len-parameter/</link>
      <pubDate>Mon, 06 May 2013 12:00:00 +0000</pubDate>
      
      <guid>/questions/20990/tshark-capture-filter-for-len-parameter/</guid>
      <description>tshark capture filter for len parameter  0 How do I set a capture filter in tshark so that only packets with len &amp;gt; 0 would be registered? I tried using greater and less commands but it didn&#39;t work.
filter capture tsharkasked 06 May &#39;13, 12:00
Loco1989
16●1●1●4
accept rate: 0%
  
2 Answers:
  
1 From your comment on @joemc&#39;s answer it turns out you mean the length of the TCP payload.</description>
    </item>
    
    <item>
      <title>Can I create a column that shows the RTP Timestamp delta from one packet to the next</title>
      <link>/questions/20997/can-i-create-a-column-that-shows-the-rtp-timestamp-delta-from-one-packet-to-the-next/</link>
      <pubDate>Mon, 06 May 2013 17:15:00 +0000</pubDate>
      
      <guid>/questions/20997/can-i-create-a-column-that-shows-the-rtp-timestamp-delta-from-one-packet-to-the-next/</guid>
      <description>Can I create a column that shows the RTP Timestamp delta from one packet to the next  0 I&#39;d like to create a column that shows the change in time stamps from one RTP packet to the next. Is this possible in wireshark?
This is a screenshot of the RTP timestamp column
I would like another column that displays the difference between these values. So in this case, the values in the new column would be 160.</description>
    </item>
    
    <item>
      <title>How to remove vlan tag from trace?</title>
      <link>/questions/21001/how-to-remove-vlan-tag-from-trace/</link>
      <pubDate>Tue, 07 May 2013 04:34:00 +0000</pubDate>
      
      <guid>/questions/21001/how-to-remove-vlan-tag-from-trace/</guid>
      <description>How to remove vlan tag from trace?  0 Hello,
I have a H248 pcap trace with double vlan tag:
802.1Q Virtual LAN, PRI: 0, CFI: 0, ID: 999
802.1Q Virtual LAN, PRI: 0, CFI: 0, ID: 473
And my question if there any way to remove one vlan tag, or both tags from the trace?.
Thanks beforehand for your answer.
h248 vlan tag removeThis question is marked &#34;community wiki&#34;.asked 07 May &#39;13, 04:34</description>
    </item>
    
    <item>
      <title>capture stopped</title>
      <link>/questions/21004/capture-stopped/</link>
      <pubDate>Tue, 07 May 2013 09:40:00 +0000</pubDate>
      
      <guid>/questions/21004/capture-stopped/</guid>
      <description>capture stopped  0 when i was using wireshark capturing on an ethernet the capture suddenly stopped and showed me this message: the network adapter on which capture was being done is no longer running . The capture stopped.
capture stoppedasked 07 May &#39;13, 09:40
Ashraf
16●6●6●10
accept rate: 0%
the capture suddenly stopped
what exactly is suddenly? 1 second, 1 minute, 1 hour?
If this an onboard nic or some USB dongle or a PCCARD nic?</description>
    </item>
    
    <item>
      <title>TCP DUP ACK/TCP Retransmission</title>
      <link>/questions/21006/tcp-dup-acktcp-retransmission/</link>
      <pubDate>Tue, 07 May 2013 10:46:00 +0000</pubDate>
      
      <guid>/questions/21006/tcp-dup-acktcp-retransmission/</guid>
      <description>TCP DUP ACK/TCP Retransmission  0 1I did some orginal captures on a computer sitting outside our firewall and saw alot of TCP DUP ACK/TCP Retransmission while web browsing. Thought I was having an ISP issue but their testing is indicating no trouble. I thought this message indicated dropped frames. Am I incorrect?
I did another capture between two computers on a 24 port switch, no Internet, no connection other than to each other.</description>
    </item>
    
    <item>
      <title>Decrypting TLS messages which is using Diffie hellman algorithm</title>
      <link>/questions/21011/decrypting-tls-messages-which-is-using-diffie-hellman-algorithm/</link>
      <pubDate>Tue, 07 May 2013 21:28:00 +0000</pubDate>
      
      <guid>/questions/21011/decrypting-tls-messages-which-is-using-diffie-hellman-algorithm/</guid>
      <description>Decrypting TLS messages which is using Diffie hellman algorithm  0 From the Client I am logging all the master secret key for all the sessions.Using that key how to generate the .key file and is that be possible to decrypt the DHE messages in wireshark using Master secret key? Wireshark will be able to understand the way of decrypting DHE?
decryption openssl diffie-hellmanThis question is marked &#34;community wiki&#34;.asked 07 May &#39;13, 21:28</description>
    </item>
    
    <item>
      <title>PSH FIN ACK PACKET along with data</title>
      <link>/questions/21019/psh-fin-ack-packet-along-with-data/</link>
      <pubDate>Wed, 08 May 2013 02:32:00 +0000</pubDate>
      
      <guid>/questions/21019/psh-fin-ack-packet-along-with-data/</guid>
      <description>PSH FIN ACK PACKET along with data  0 In a capture i saw a packet with PSH FIN ACK flag set,question is with fin bit set in a packet can we still send date in it.
Thankx KISHAN
ack psh fin packetasked 08 May &#39;13, 02:32
kishan pandey
221●28●29●36
accept rate: 28%
  
One Answer:
  
1 Sure. A packet that contains the last remaining bytes of information may have a piggy backed FIN, and often also contains a PSH when there&#39;s nothing else coming after it to speed up processing it on the receivers side.</description>
    </item>
    
    <item>
      <title>Filter help</title>
      <link>/questions/21021/filter-help/</link>
      <pubDate>Wed, 08 May 2013 04:30:00 +0000</pubDate>
      
      <guid>/questions/21021/filter-help/</guid>
      <description>Filter help  0 Hello,
I&#39;m a novice user. I suspect my computer&#39;s been hacked. With help, I&#39;ve captured a trace of my router traffic, and want to filter the results in Wireshark.
What should I enter in the filter field? I&#39;m trying to achieve two things:
filter out &#39;noise&#39; (anything that would definitely NOT be related to suspicious activity)filter out traffic on my &#39;guest&#39; account so I only see traffic on &#39;my wifi&#39; account.</description>
    </item>
    
    <item>
      <title>font is not found and show up as squares</title>
      <link>/questions/21024/font-is-not-found-and-show-up-as-squares/</link>
      <pubDate>Wed, 08 May 2013 05:34:00 +0000</pubDate>
      
      <guid>/questions/21024/font-is-not-found-and-show-up-as-squares/</guid>
      <description>font is not found and show up as squares  1 Installing Wireshark on Mountain Lion with X11 installed, Wireshark opens, but all of the fonts show up as squares. I get a pile of errors when I run Wireshark from the X11 terminal. Some examples are below:
(Wireshark-bin:17459): GdkPixbuf-WARNING : Error loading XPM image loader: Image type &#39;xpm&#39; is not supported (Wireshark-bin:17459): GLib-GObject-CRITICAL : g_object_ref: assertion G_IS_OBJECT (object)&#39; failed (Wireshark-bin:17459): Gdk-CRITICAL **: gdk_window_set_icon_list: assertionGDK_IS_PIXBUF (pixbuf)&#39; failed (Wireshark-bin:17459): Pango-CRITICAL **: No modules found: No builtin or dynamically loaded modules were found.</description>
    </item>
    
    <item>
      <title>Capture Filter Multiple IP Addresses</title>
      <link>/questions/21026/capture-filter-multiple-ip-addresses/</link>
      <pubDate>Wed, 08 May 2013 06:34:00 +0000</pubDate>
      
      <guid>/questions/21026/capture-filter-multiple-ip-addresses/</guid>
      <description>Capture Filter Multiple IP Addresses  0 Hello,
I need to capture all the traffic from 12 IP addresses. I am using WS1.8 and running on Windows 2003. These are all on an internal network with 4 separate sub-nets (10.128.12.xx, 10.128.80.xx, 10.128.56.xx, 10.128.20.xx). On the first sub-net, I need to specify 2 IPs directly, on the remaining sub-nets I could grab all the traffic from the sub-net.
I have tried to enter them as by stringing together &#34;</description>
    </item>
    
    <item>
      <title>TCPDump ISN/SEQ during 3way handshake</title>
      <link>/questions/21031/tcpdump-isnseq-during-3way-handshake/</link>
      <pubDate>Wed, 08 May 2013 07:46:00 +0000</pubDate>
      
      <guid>/questions/21031/tcpdump-isnseq-during-3way-handshake/</guid>
      <description>TCPDump ISN/SEQ during 3way handshake  0 Im trying to compare some seq numbers from a wireshark output with the same capture being read in by tcpdump. Quick question, in terms of the numbers (i.e S 181839597:181839597) within the inital 3 way handshake, what do this relate to. Also is anyone able to explain the difference in relative and absoulte seq numbers and how they are difference in wireshark compared to tcpdump, as the seq number I obtained from wireshark Im unable to find when issuing a tcpdump -r &amp;lt;cap.</description>
    </item>
    
    <item>
      <title>Regarding subdirector tcp reassembly</title>
      <link>/questions/21037/regarding-subdirector-tcp-reassembly/</link>
      <pubDate>Wed, 08 May 2013 09:33:00 +0000</pubDate>
      
      <guid>/questions/21037/regarding-subdirector-tcp-reassembly/</guid>
      <description>Regarding subdirector tcp reassembly  0 I am little confused about this reassembly option in wireshark.What exactly we achieve by enabling/disabling this option?
reassembly tcpasked 08 May &#39;13, 09:33
krishnayeddula
629●35●41●48
accept rate: 6%
  
One Answer:
  
1 Reassembly means that Wireshark will gather all TCP (or whatever protocol the reassembly is used for, but it&#39;s usually TCP) segments that are part of a request or answer and combine them for the next layer dissector.</description>
    </item>
    
    <item>
      <title>Custom Tag Dissector in LUA</title>
      <link>/questions/21038/custom-tag-dissector-in-lua/</link>
      <pubDate>Wed, 08 May 2013 10:58:00 +0000</pubDate>
      
      <guid>/questions/21038/custom-tag-dissector-in-lua/</guid>
      <description>Custom Tag Dissector in LUA  0 Hi,
I am trying to build a custom tag Dissector in Lua for the type of packets mentioned in the link below. There are other custom tags like these with different Ether types. http://webmedia.company.ja.net/content/documents/shared/networkshop310309/reid_carrierethernet.pdf.
So the packet looks like One or more VLAN tag is followed by one or more custom tags. These tags are indicated by the corresponding ether type values (2 bytes) followed by 2 or 4 bytes specific to the tags.</description>
    </item>
    
    <item>
      <title>Wireshark install on WIndows - what changes are made to IP Stack and/or existing .dlls?</title>
      <link>/questions/21041/wireshark-install-on-windows-what-changes-are-made-to-ip-stack-andor-existing-dlls/</link>
      <pubDate>Wed, 08 May 2013 14:53:00 +0000</pubDate>
      
      <guid>/questions/21041/wireshark-install-on-windows-what-changes-are-made-to-ip-stack-andor-existing-dlls/</guid>
      <description>Wireshark install on WIndows - what changes are made to IP Stack and/or existing .dlls?  0 In trying to track down HTTP protocol errors, we installed Wireshark on 3 Windows 2008 R2 servers. Prior to installing Wireshark, specific HTTP traffic would fail. Immediately upon installing Wireshark, the problematic HTTP traffic worked as expected. Even after uninstalling Wireshark, the initially problematic HTTP traffic continued to work.
I&#39;m wondering if the Wireshark installation makes changes to the IP stack or any existing .</description>
    </item>
    
    <item>
      <title>MAC prefixes for MS NLB - personalized manuf</title>
      <link>/questions/21050/mac-prefixes-for-ms-nlb-personalized-manuf/</link>
      <pubDate>Wed, 08 May 2013 23:24:00 +0000</pubDate>
      
      <guid>/questions/21050/mac-prefixes-for-ms-nlb-personalized-manuf/</guid>
      <description>MAC prefixes for MS NLB - personalized manuf  0 Hello, I just ran into an issue with wireshark suggesting a machine was talking to a Microsoft NLB when it fact it wasn&#39;t. The reasion is the manuf file in the global configurtion folder containing following entries:
02-BF-00-00-00-00/16 MS-NLB-VirtServer 02-01-00-00-00-00/16 MS-NLB-PhysServer-01 02-02-00-00-00-00/16 MS-NLB-PhysServer-02 ... 02-1e-00-00-00-00/16 MS-NLB-PhysServer-30 02-1f-00-00-00-00/16 MS-NLB-PhysServer-31 02-20-00-00-00-00/16 MS-NLB-PhysServer-32It took me quite some time and embarassing discussions to figure that one out.</description>
    </item>
    
    <item>
      <title>Can wireshark monitor per application easily?</title>
      <link>/questions/21059/can-wireshark-monitor-per-application-easily/</link>
      <pubDate>Thu, 09 May 2013 09:08:00 +0000</pubDate>
      
      <guid>/questions/21059/can-wireshark-monitor-per-application-easily/</guid>
      <description>Can wireshark monitor per application easily?  0 I know I can add some application tagging in iptables and filter on that, but I&#39;m wondering if there&#39;s any easy way to see the traffic of 1 application specifically.
It would save me a lot of noise filtering when debugging since some of the work I do involves encrypted protocols with random ports...
filter application filtering some idsscoasked 09 May &#39;13, 09:08</description>
    </item>
    
    <item>
      <title>Can Wireshark help track down who is sending spam</title>
      <link>/questions/21064/can-wireshark-help-track-down-who-is-sending-spam/</link>
      <pubDate>Thu, 09 May 2013 09:56:00 +0000</pubDate>
      
      <guid>/questions/21064/can-wireshark-help-track-down-who-is-sending-spam/</guid>
      <description>Can Wireshark help track down who is sending spam  0 For the last 24 hours, I have seen email in the queue that is spam. My firewall is preventing most of them from being sent out. I have done the following to try and remove the problem. I shut down all the computers in the building down 1 at a time, including servers. The only computer running was the exchange server and the firewall.</description>
    </item>
    
    <item>
      <title>udp multiple packet with same ip id</title>
      <link>/questions/21066/udp-multiple-packet-with-same-ip-id/</link>
      <pubDate>Thu, 09 May 2013 10:01:00 +0000</pubDate>
      
      <guid>/questions/21066/udp-multiple-packet-with-same-ip-id/</guid>
      <description>udp multiple packet with same ip id  0 Multiple udp packets in a same session are showing same ip identification no. but has different data interestingly no fragmention also.
udpasked 09 May &#39;13, 10:01
kishan pandey
221●28●29●36
accept rate: 28%
Can you post a capture file somewhere, perhaps www.cloudshark.org? Of course, it should not contain any confidential data.
(09 May &#39;13, 10:43) Jim AragonNo sir i cannot due to limitation</description>
    </item>
    
    <item>
      <title>Protocol identification</title>
      <link>/questions/21072/protocol-identification/</link>
      <pubDate>Thu, 09 May 2013 13:53:00 +0000</pubDate>
      
      <guid>/questions/21072/protocol-identification/</guid>
      <description>Protocol identification  0 Is there a way to identify the protocol based on the captured data by wireshark? Data from 7 multicast packets captured is shown below.
p.#1 4c 45 49 00 00 ff 09 a3 00 1c 00 30 00 72 1c 16 b5 81 9d 47 ee 18 fb 40 b7 38 ef c5 95 a6 d3 34 00 06 00 00 00 00 00 03 00 00 00 0c 05 01 04 00 18 c1 35 08 06 00 00 00 00 01 16 eb p.</description>
    </item>
    
    <item>
      <title>udp packet loss</title>
      <link>/questions/21080/udp-packet-loss/</link>
      <pubDate>Thu, 09 May 2013 23:15:00 +0000</pubDate>
      
      <guid>/questions/21080/udp-packet-loss/</guid>
      <description>udp packet loss  0 how do i find packet loss in this udp packets can i merge 2 files and then with compare option and ip.id filter,is it possible?Thanks
udpasked 09 May &#39;13, 23:15
kishan pandey
221●28●29●36
accept rate: 28%
  
One Answer:
  
0 You can do this:
tshark -ni file_1.pcap -T fields -e ip.id -e frame.number | sort &amp;gt; file_1.txt
tshark -ni file_2.pcap -T fields -e ip.</description>
    </item>
    
    <item>
      <title>PPI 802.11ac MAC&#43;PHY header?</title>
      <link>/questions/21087/ppi-80211ac-macphy-header/</link>
      <pubDate>Fri, 10 May 2013 09:38:00 +0000</pubDate>
      
      <guid>/questions/21087/ppi-80211ac-macphy-header/</guid>
      <description>PPI 802.11ac MAC+PHY header?  0 Could you point me to any current effort to define a standard PPI 802.11ac MAC+PHY header?
header ppi 802.11acasked 10 May &#39;13, 09:38
darylkaiser
11●1●1●2
accept rate: 0%
  
One Answer:
  
0No, but I could point you to a Radiotap field that has some 802.11ac properties.
answered 10 May &#39;13, 11:30
Guy Harris ♦♦
17.4k●3●35●196
accept rate: 19%
     </description>
    </item>
    
    <item>
      <title>How do i read my capture for looking for errors on a bad switch port</title>
      <link>/questions/21091/how-do-i-read-my-capture-for-looking-for-errors-on-a-bad-switch-port/</link>
      <pubDate>Fri, 10 May 2013 21:08:00 +0000</pubDate>
      
      <guid>/questions/21091/how-do-i-read-my-capture-for-looking-for-errors-on-a-bad-switch-port/</guid>
      <description>How do i read my capture for looking for errors on a bad switch port  0 Hello,
After configuring Port mirroring on a HP Procurve switch I was able to have my Wireshark program installed on a Windows 7 box connected to the Procurve on port 10 setup to monitor a PC in port 11 which is getting thousands of Rx errors on the port 11 interface as I see on the HP Web GUI Port counters for the HP switch.</description>
    </item>
    
    <item>
      <title>Wireshark isn&amp;#x27;t recognizing the Skinny protocol</title>
      <link>/questions/21098/wireshark-isnt-recognizing-the-skinny-protocol/</link>
      <pubDate>Sun, 12 May 2013 20:02:00 +0000</pubDate>
      
      <guid>/questions/21098/wireshark-isnt-recognizing-the-skinny-protocol/</guid>
      <description>Wireshark isn&amp;rsquo;t recognizing the Skinny protocol  0 Hi,
I am using the latest version of wireshark 1.8.6, after open the packet capture file, in the Protocol column, it shows TCP instead of Skinny, I know this frame is skinny traffic, maybe new bug for wireshark 1.8.6? I can provide screen dump and packet capture file.
Regards
Kevin
skinny tcpasked 12 May &#39;13, 20:02
TAC
11●1●1●4
accept rate: 0%
 edited 13 May &#39;13, 15:45</description>
    </item>
    
    <item>
      <title>how to view all frames who have delay for more than or less than 5 ms.</title>
      <link>/questions/21101/how-to-view-all-frames-who-have-delay-for-more-than-or-less-than-5-ms/</link>
      <pubDate>Mon, 13 May 2013 02:28:00 +0000</pubDate>
      
      <guid>/questions/21101/how-to-view-all-frames-who-have-delay-for-more-than-or-less-than-5-ms/</guid>
      <description>how to view all frames who have delay for more than or less than 5 ms.  0 how to view all frames who have delay for more than or less than 5 ms?
timestamp deltaasked 13 May &#39;13, 02:28
kishan pandey
221●28●29●36
accept rate: 28%
  
One Answer:
  
1 You could try filtering on &#34;frame.time_delta &amp;lt; 0.005&#34; (or &#34;&amp;gt; 0.005&#34; respectively), but very often that is only giving you a list of frames that is too large and not really telling you anything.</description>
    </item>
    
    <item>
      <title>TCP OPTION 0x26 added to SYN packet</title>
      <link>/questions/21112/tcp-option-0x26-added-to-syn-packet/</link>
      <pubDate>Mon, 13 May 2013 06:00:00 +0000</pubDate>
      
      <guid>/questions/21112/tcp-option-0x26-added-to-syn-packet/</guid>
      <description>TCP OPTION 0x26 added to SYN packet  0 Hello,
I just came across this very strange unknown TCP option:
Options: (28 bytes), Maximum segment size, No-Operation (NOP), No-Operation (NOP), SACK permitted, End of Option List (EOL)
 Maximum segment size: 1460 bytes No-Operation (NOP) No-Operation (NOP) TCP SACK Permitted Option: True Unknown (0x26) (18 bytes) End of Option List (EOL)It is 18 bytes long and contains the MAC address and IP address of the PC:</description>
    </item>
    
    <item>
      <title>Unknown RST,ACK packet causing hung connections on the client side</title>
      <link>/questions/21121/unknown-rstack-packet-causing-hung-connections-on-the-client-side/</link>
      <pubDate>Mon, 13 May 2013 21:07:00 +0000</pubDate>
      
      <guid>/questions/21121/unknown-rstack-packet-causing-hung-connections-on-the-client-side/</guid>
      <description>Unknown RST,ACK packet causing hung connections on the client side  0 We are having random connection crashes on one of the http clients (X.X.X.X) connecting to an app server (Y.Y.Y.Y). There are 2 ASA firewalls in between performing NAT. Data flow is normal for a while but suddenly it stops. Packet capture shows that from client&#39;s perspective the connection was never terminated. Here is what I found so far:</description>
    </item>
    
    <item>
      <title>Determine IP Addresses on Wireless Network.</title>
      <link>/questions/21131/determine-ip-addresses-on-wireless-network/</link>
      <pubDate>Tue, 14 May 2013 06:28:00 +0000</pubDate>
      
      <guid>/questions/21131/determine-ip-addresses-on-wireless-network/</guid>
      <description>Determine IP Addresses on Wireless Network.  0 I would like to capture the traffic of one wireless device on my wireless network. I have placed a switch between the Wireless router and my DSL modem and am port forwarding traffic to a laptop. When I capture traffic all I see is the IP address of the Wireless router. Is there a way to capture just the traffic of the one wireless device?</description>
    </item>
    
    <item>
      <title>TUP dissector/plugin</title>
      <link>/questions/21134/tup-dissectorplugin/</link>
      <pubDate>Tue, 14 May 2013 07:12:00 +0000</pubDate>
      
      <guid>/questions/21134/tup-dissectorplugin/</guid>
      <description>TUP dissector/plugin  0 Hello,
I´m trying to decode some TUP traffic, but wireshark cant decode it, because it lacks the proper dissector. As i dont have the skill to code a dissector myself, i would like to know if anybody has done so already, and if he/she could post the code here.
Thank you very much.
tup ss7 dissectorasked 14 May &#39;13, 07:12
Renan
26●4●4●8
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Packet analyser on PPP interface</title>
      <link>/questions/21136/packet-analyser-on-ppp-interface/</link>
      <pubDate>Tue, 14 May 2013 09:13:00 +0000</pubDate>
      
      <guid>/questions/21136/packet-analyser-on-ppp-interface/</guid>
      <description>Packet analyser on PPP interface  0 Is there any packet analyser on PPP interface?
analyser packetasked 14 May &#39;13, 09:13
Dhira
1●2●2●3
accept rate: 0%
what is your OS?
(14 May &#39;13, 09:39) Kurt Knochner ♦OS: Windows 8
(16 May &#39;13, 01:13) Dhira  
2 Answers:
  
0Kinda confused by the question. However you can analyze a PPP session off a client if you can get between the Client and Server to sniff the traffic.</description>
    </item>
    
    <item>
      <title>802.11 Capture in Ad hoc mode.</title>
      <link>/questions/21142/80211-capture-in-ad-hoc-mode/</link>
      <pubDate>Tue, 14 May 2013 12:43:00 +0000</pubDate>
      
      <guid>/questions/21142/80211-capture-in-ad-hoc-mode/</guid>
      <description>802.11 Capture in Ad hoc mode.  0 We have set of AirPcap Nx. We interface the device with Wireshark to capture the 802.11n packets.
In the infrastructure mode, we can get the values for the 802.11 QoS parameters ( AC parameters). But in the ad Hoc Mode we could not.
It is empty. Could you advice please.
qos ad parameters hocThis question is marked &#34;community wiki&#34;.asked 14 May &#39;13, 12:43</description>
    </item>
    
    <item>
      <title>PC AND SSN IN SCCP message decode wrong</title>
      <link>/questions/21148/pc-and-ssn-in-sccp-message-decode-wrong/</link>
      <pubDate>Wed, 15 May 2013 07:48:00 +0000</pubDate>
      
      <guid>/questions/21148/pc-and-ssn-in-sccp-message-decode-wrong/</guid>
      <description>PC AND SSN IN SCCP message decode wrong  0 Hi
I am experience a decode issue , When i take a look at the Calling Party Address in SCCP message. It showed ,PC=7420,ssn is unknown ,the code showed 43 fc 1c 73 02, it should decode like 02-73-1c,ssn=252,check the preference of MTP3 already modify to ANSI.
Not sure how to fix this issue.
sccp decode ssnasked 15 May &#39;13, 07:48</description>
    </item>
    
    <item>
      <title>Latency for SMB protocol over internet IPSEC</title>
      <link>/questions/21149/latency-for-smb-protocol-over-internet-ipsec/</link>
      <pubDate>Wed, 15 May 2013 11:25:00 +0000</pubDate>
      
      <guid>/questions/21149/latency-for-smb-protocol-over-internet-ipsec/</guid>
      <description>Latency for SMB protocol over internet IPSEC  0 Hi anyone have issues after migrating from a dedicated point to point link like FR or T1 to a high latency 300ms+ INET IPSEC connection with a SMB file copy ??
attached is a very chatty pcap
latency over hi link smbasked 15 May &#39;13, 11:25
franki21
1●1●1●2
accept rate: 0%
  
2 Answers:
  
0a high latency 300ms</description>
    </item>
    
    <item>
      <title>Float values in GOOSE Protocol</title>
      <link>/questions/21169/float-values-in-goose-protocol/</link>
      <pubDate>Wed, 15 May 2013 23:11:00 +0000</pubDate>
      
      <guid>/questions/21169/float-values-in-goose-protocol/</guid>
      <description>Float values in GOOSE Protocol  0 Hello,
I am working a product which supports IEC-61850 GOOSE protocol. I am using Wireshark for Packet analysis.
According to similar question on forum: here http://ask.wireshark.org/questions/18597/goose-why-display-floating-point-in-hex
I found that, Wireshark displays Float values as Hex becuase, &#34; FloatingPoint ::= OCTET STRING as it&#39;s defined as OCTET STRING it will be displayed in hex.&#34;. The authour has suggested to &#34;One could pssibly redifine the field in the .</description>
    </item>
    
    <item>
      <title>Combine ending part of packet with starting part of the next packet. (to dissect later on.))</title>
      <link>/questions/21171/combine-ending-part-of-packet-with-starting-part-of-the-next-packet-to-dissect-later-on/</link>
      <pubDate>Thu, 16 May 2013 01:26:00 +0000</pubDate>
      
      <guid>/questions/21171/combine-ending-part-of-packet-with-starting-part-of-the-next-packet-to-dissect-later-on/</guid>
      <description>Combine ending part of packet with starting part of the next packet. (to dissect later on.))  0 Hi all; We have developed a dissector to analyze a log file filled with TCP packets. Each packet contains one or more messages that are previously specified with starting and ending keywords(bytes).
But we faced with a problem. Some messages starts at the end of a packet and continues at the start of the next packet.</description>
    </item>
    
    <item>
      <title>Dissection</title>
      <link>/questions/21175/dissection/</link>
      <pubDate>Thu, 16 May 2013 02:26:00 +0000</pubDate>
      
      <guid>/questions/21175/dissection/</guid>
      <description>Dissection  0 My dissector code is able to detect packets(i can see in protocol column)but its not able to dissect fields of query packet or response packet .Written code taking reference from &#34;foo&#34;.
static void dissect_mc(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree) { char st[]= gint offset = 0; int packettype; packettype=classify_mc_packet(pinfo); col_set_str(pinfo-&amp;gt;cinfo, COL_PROTOCOL, &amp;quot;MC&amp;quot;); /* Clear out stuff in the info column */ col_clear(pinfo-&amp;gt;cinfo,COL_INFO); if (packettype==QUERY_PACKET) { if (tree) {/* we are being asked for details */ proto_item *ti = NULL; proto_tree *mc_tree = NULL; ti = proto_tree_add_item(tree, proto_mc, tvb, 0, -1, ENC_NA); mc_tree = proto_item_add_subtree(ti, ett_mc); proto_tree_add_item(mc_tree, hf_mc_subheader, tvb, offset, 1, ENC_LITTLE_ENDIAN); offset += 1; proto_tree_add_item(mc_tree, hf_mc_pcnumber, tvb, offset, 1, ENC_LITTLE_ENDIAN); offset += 1; proto_tree_add_item(mc_tree, hf_mc_monitortimer, tvb, offset, 2, ENC_LITTLE_ENDIAN); offset += 2; proto_tree_add_item(mc_tree, hf_mc_headdevnumber, tvb, offset, 4, ENC_LITTLE_ENDIAN); offset += 4; proto_tree_add_item(mc_tree, hf_mc_devicename, tvb, offset, 2, ENC_LITTLE_ENDIAN); offset += 2; proto_tree_add_item(mc_tree, hf_mc_devicepoints, tvb, offset, 1, ENC_LITTLE_ENDIAN); offset += 1; proto_tree_add_item(mc_tree, hf_mc_terminator, tvb, offset, 1, ENC_LITTLE_ENDIAN); offset += 1;  } } else if (packettype==RESPONSE_PACKET) { if(tree) { proto_item *ti = NULL; proto_tree *mc_tree = NULL; ti = proto_tree_add_item(tree, proto_mc, tvb, 0, -1, ENC_NA); mc_tree = proto_item_add_subtree(ti, ett_mc); proto_tree_add_item(mc_tree, hf_mc_subheader, tvb, offset, 1, ENC_LITTLE_ENDIAN); offset += 1; proto_tree_add_item(mc_tree, hf_mc_subheader, tvb, offset, 1, ENC_LITTLE_ENDIAN); offset += 2; } else return; }&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;p&amp;gt;other functions seem to be right.</description>
    </item>
    
    <item>
      <title>STATUS_ACCESS_VIOLATION when using tvb_memcpy / Displaying Fixed Point Numbers</title>
      <link>/questions/21182/status_access_violation-when-using-tvb_memcpy-displaying-fixed-point-numbers/</link>
      <pubDate>Thu, 16 May 2013 06:15:00 +0000</pubDate>
      
      <guid>/questions/21182/status_access_violation-when-using-tvb_memcpy-displaying-fixed-point-numbers/</guid>
      <description>STATUS_ACCESS_VIOLATION when using tvb_memcpy / Displaying Fixed Point Numbers  0 I have an issue where the information I&#39;m trying to display a fixed point number from the message. However, the way the message is sent is that the value is basically a short int (signed 16 bit int) multiplied by 10^-2. Since there are no accessors to pull a 16 bit signed int from the buffer I used tvb_memcpy to place the bits into a gint16 variable.</description>
    </item>
    
    <item>
      <title>Do all ethernet frames contain an LLC header?</title>
      <link>/questions/21186/do-all-ethernet-frames-contain-an-llc-header/</link>
      <pubDate>Thu, 16 May 2013 09:21:00 +0000</pubDate>
      
      <guid>/questions/21186/do-all-ethernet-frames-contain-an-llc-header/</guid>
      <description>Do all ethernet frames contain an LLC header?  0 Hello,
As the title states: do all ethernet frames contain an LLC header? In other words, is 802.2 mandatory?
When doing pcap using wireshark, the llc filter shows no results.
If LLC is not mandatory, when is it used, and what indicates whether that header is in the frame.
Note that http://www.ieee802.org/2/ states that 802.2 has been disbanded.
Thank you.</description>
    </item>
    
    <item>
      <title>OS X Mountain Lion won&amp;#x27;t launch</title>
      <link>/questions/21187/os-x-mountain-lion-wont-launch/</link>
      <pubDate>Thu, 16 May 2013 10:03:00 +0000</pubDate>
      
      <guid>/questions/21187/os-x-mountain-lion-wont-launch/</guid>
      <description>OS X Mountain Lion won&amp;rsquo;t launch  0 I have followed and tried all of the advise that I could find here still with no luck. I keep Getting the &#34;While Wireshark is open .......&#34; Dialog but then nada.
In terminal I am seeing this on any attempt at a launch; .wireshark/.fccache-new: No such file or directory
Any ideas?
macosxasked 16 May &#39;13, 10:03
cunning1
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to capture the information just for one IP ADDRESS? (T-SHARK)</title>
      <link>/questions/21191/how-to-capture-the-information-just-for-one-ip-address-t-shark/</link>
      <pubDate>Thu, 16 May 2013 11:21:00 +0000</pubDate>
      
      <guid>/questions/21191/how-to-capture-the-information-just-for-one-ip-address-t-shark/</guid>
      <description>How to capture the information just for one IP ADDRESS? (T-SHARK)  0 Dears
I need to capture just the traffic from one ip address in a network (in/out)
I use this command in linux : tshark -i 3 -f &#34;host x.x.x.x&#34; -w test.pcap
I capture all the traffic when i used that command without the -f &#34;host x.x.x.x&#34;
Could you help me?
Thanks in advance.
BR
ip.addr capture-filter tsharkasked 16 May &#39;13, 11:21</description>
    </item>
    
    <item>
      <title>Extracting RTP payload and dumping to a ts file</title>
      <link>/questions/21193/extracting-rtp-payload-and-dumping-to-a-ts-file/</link>
      <pubDate>Thu, 16 May 2013 12:17:00 +0000</pubDate>
      
      <guid>/questions/21193/extracting-rtp-payload-and-dumping-to-a-ts-file/</guid>
      <description>Extracting RTP payload and dumping to a ts file  0 Hi guys,
I&#39;ve looked around but haven&#39;t been able to find anything that works.
How would I extract the RTP payload and dump it to a ts file via the command line interface? Through the GUI, I can simply Decode as RTP and then &#39;Save payload&#39; for the filtered packets, but haven&#39;t been able to succeed with doing this through tshark.</description>
    </item>
    
    <item>
      <title>How to run a wireless network from a pc using an exsisting wireless network connection?</title>
      <link>/questions/21198/how-to-run-a-wireless-network-from-a-pc-using-an-exsisting-wireless-network-connection/</link>
      <pubDate>Thu, 16 May 2013 21:37:00 +0000</pubDate>
      
      <guid>/questions/21198/how-to-run-a-wireless-network-from-a-pc-using-an-exsisting-wireless-network-connection/</guid>
      <description>How to run a wireless network from a pc using an exsisting wireless network connection?  0 Pretty much as the question says. I know a wireless network can be created with linux on a computer with a wireless adapter, i did that once. Of course it had no internet. What I would like to do, is create a wireless accessable network that routes from my desktop or laptop pc, and run the internet from my wireless internet connection from my router into the new wireless connection ran from pc.</description>
    </item>
    
    <item>
      <title>Find unknown IP address for Access Point</title>
      <link>/questions/21199/find-unknown-ip-address-for-access-point/</link>
      <pubDate>Thu, 16 May 2013 22:00:00 +0000</pubDate>
      
      <guid>/questions/21199/find-unknown-ip-address-for-access-point/</guid>
      <description>Find unknown IP address for Access Point  0 I have a BelAir 100 Access Point that I set a static IP on and I think I typed it incorrect and now I can&#39;t log into it. There is no way that I know of to factory reset it. I have tried wireshark and and all I get are some bogus packets when it boots, I think it looks for a proprietary controller on boot up, then it is silent.</description>
    </item>
    
    <item>
      <title>use case for (copy | as a filter )option</title>
      <link>/questions/21200/use-case-for-copy-as-a-filter-option/</link>
      <pubDate>Thu, 16 May 2013 22:04:00 +0000</pubDate>
      
      <guid>/questions/21200/use-case-for-copy-as-a-filter-option/</guid>
      <description>use case for (copy | as a filter )option  0 Going through Laura chappel&#39;s WCNA guide and came across copy | as filter option. Any use case for this feature is appreciated.When do we need to buffer the filter?
display filtersasked 16 May &#39;13, 22:04
krishnayeddula
629●35●41●48
accept rate: 6%
  
One Answer:
  
1 I can think of many use cases, but the one I had that made me develop this functionality was this:</description>
    </item>
    
    <item>
      <title>col_append_fstr doesn&amp;#x27;t append. Why?</title>
      <link>/questions/21205/col_append_fstr-doesnt-append-why/</link>
      <pubDate>Fri, 17 May 2013 00:01:00 +0000</pubDate>
      
      <guid>/questions/21205/col_append_fstr-doesnt-append-why/</guid>
      <description>col_append_fstr doesn&amp;rsquo;t append. Why?  0 Hi all;
After the reassembling developments we&#39;ve made in our dissector plugin, col__ append__ fstr doesn&#39;t work correctly anymore. It does not append, it works like col__ add__fstr and displays the last item only.
col append fstr(pinfo-&amp;gt;cinfo, COL __ INFO, &#34;%s(%d) &#34;, message_name, messageId);
Why would it be?
add col_append_str appendasked 17 May &#39;13, 00:01
barisalis
16●3●3●7
accept rate: 100%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How to display multiline COL_INFO ?</title>
      <link>/questions/21208/how-to-display-multiline-col_info/</link>
      <pubDate>Fri, 17 May 2013 00:54:00 +0000</pubDate>
      
      <guid>/questions/21208/how-to-display-multiline-col_info/</guid>
      <description>How to display multiline COL_INFO ?  0 I need the INFO_ COL to be displayed in multiple line if the text does not fit into width of the column. I couldn&#39;t find any option inside Edit/Preferences. (Note: Version 1.6.7)
col_info multilineasked 17 May &#39;13, 00:54
barisalis
16●3●3●7
accept rate: 100%
  
One Answer:
  
2You can&#39;t. The INFO column is supposed to be a single line.</description>
    </item>
    
    <item>
      <title>ACK Duplicate</title>
      <link>/questions/21209/ack-duplicate/</link>
      <pubDate>Fri, 17 May 2013 01:01:00 +0000</pubDate>
      
      <guid>/questions/21209/ack-duplicate/</guid>
      <description>ACK Duplicate  0 We have two servers which are used for data replication between them.
Issues
1.During replication the connectivity is getting down/slow regularly and packet is getting lost.Please find the below logs for your kind![alt text][1] reference.
8954069.0: ethernet0/1(i) len=70:002451aefc00-&amp;gt;00239c82b805/8100/0800, tag 635 10.1.1.1 -&amp;gt; 192.1.1.1/6 vhl=45, tos=00, id=47907, frag=4000, ttl=63 tlen=52 tcp:ports 57105-&amp;gt;10560, seq=2650136876, ack=314843383, flag=8010/ACK 00 23 9c 82 b8 05 00 24 51 ae fc 00 81 00 02 7b .</description>
    </item>
    
    <item>
      <title>See SSL data sent to and from activation server</title>
      <link>/questions/21212/see-ssl-data-sent-to-and-from-activation-server/</link>
      <pubDate>Fri, 17 May 2013 02:54:00 +0000</pubDate>
      
      <guid>/questions/21212/see-ssl-data-sent-to-and-from-activation-server/</guid>
      <description>See SSL data sent to and from activation server  0 Would I be able to setup WireShark to interpret the SSL data that is sent and received from a remote activation server?
sslasked 17 May &#39;13, 02:54
lookoverthere
1●1●1●1
accept rate: 0%
  
One Answer:
  
0If by &#34;remote activation server&#34; you mean a server which you manage yourself, then yes. You can use the private key of the server to decrypt the SSL session.</description>
    </item>
    
    <item>
      <title>RTP over TLS connection can&amp;#x27;t be decrypted in wireshark?</title>
      <link>/questions/21215/rtp-over-tls-connection-cant-be-decrypted-in-wireshark/</link>
      <pubDate>Fri, 17 May 2013 03:27:00 +0000</pubDate>
      
      <guid>/questions/21215/rtp-over-tls-connection-cant-be-decrypted-in-wireshark/</guid>
      <description>RTP over TLS connection can&amp;rsquo;t be decrypted in wireshark?  0 I tried to decrypt RTP data over TCP in Wireshark. Though in the debug logs I&#39;m getting decrypted fragments like the following,
dissect_ssl enter frame #102 (already visited) conversation = 05666758, ssl_session = 00000000 record: offset = 0, reported_length_remaining = 101 dissect_ssl3_record: content_type 23 Application Data association_find: TCP port 23500 found 00000000 association_find: TCP port 443 found 04D24DD8 dissect_ssl3_record decrypted len 69 decrypted app data fragment: .</description>
    </item>
    
    <item>
      <title>How to find out in which wireshark release is my bug fixed?</title>
      <link>/questions/21219/how-to-find-out-in-which-wireshark-release-is-my-bug-fixed/</link>
      <pubDate>Fri, 17 May 2013 05:06:00 +0000</pubDate>
      
      <guid>/questions/21219/how-to-find-out-in-which-wireshark-release-is-my-bug-fixed/</guid>
      <description>How to find out in which wireshark release is my bug fixed?  0 Hi!
I had opened two Bugzillas a few months ago which got fixed. However, I just installed v 1.8.2 in my Debian machine and I still don&#39;t see the fixes in there.
Is there a way to find out in which release will I get the fix? Is there a way to request for those fixes to be included to the next release?</description>
    </item>
    
    <item>
      <title>Bytes in flight</title>
      <link>/questions/21228/bytes-in-flight/</link>
      <pubDate>Fri, 17 May 2013 09:29:00 +0000</pubDate>
      
      <guid>/questions/21228/bytes-in-flight/</guid>
      <description>Bytes in flight  0 Hi all,i have one query that in a normal tcp communication without sack lets say if server sends 3 segments of data each having 1290 bytes of data which client never receives(lost in transit) so upon receiving dup ack server is retransmitting 1290 bytes of data but in seq+ack analysis menu &#34;Bytes in Flight&#34; is showing 4384 bytes but question is sender has just send 1290 bytes.</description>
    </item>
    
    <item>
      <title>TCP ACKed unseen segment - wireshark bug?</title>
      <link>/questions/21230/tcp-acked-unseen-segment-wireshark-bug/</link>
      <pubDate>Fri, 17 May 2013 10:03:00 +0000</pubDate>
      
      <guid>/questions/21230/tcp-acked-unseen-segment-wireshark-bug/</guid>
      <description>TCP ACKed unseen segment - wireshark bug?  1 This is a screenshot of a complete &#39;echo&#39; conversation between a PC and an embedded device with a small 64 byte window size. It looks like wireshark loses track of the conversation when the embedded device ACKs the zero window probe and opens its window on #136. Is this the same bug as reported here?
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8404
Larger image link
unseen_segment zerowindowprobeasked 17 May &#39;13, 10:03</description>
    </item>
    
    <item>
      <title>Use last dissector data</title>
      <link>/questions/21231/use-last-dissector-data/</link>
      <pubDate>Fri, 17 May 2013 10:15:00 +0000</pubDate>
      
      <guid>/questions/21231/use-last-dissector-data/</guid>
      <description>Use last dissector data  0 Hi,
I´m developing a plugin for TUP, and to decode the CIC field i need to use the last byte from the previous dissector (MTP3 in my case), as it´s last four bits are part of the 12 bit CIC field from my TUP messages.. I need to , somehow, &#34;share&#34; this last byte between the dissectors How can i do that?
Thanks,
tup chained-dissector mtp3asked 17 May &#39;13, 10:15</description>
    </item>
    
    <item>
      <title>WireShark Portable</title>
      <link>/questions/21233/wireshark-portable/</link>
      <pubDate>Fri, 17 May 2013 11:46:00 +0000</pubDate>
      
      <guid>/questions/21233/wireshark-portable/</guid>
      <description>WireShark Portable  0 Love the program and I was wondering if there is a way to make it to automatically remove Pcap without the prompt when you quit the program.
wiresharkasked 17 May &#39;13, 11:46
bowmarc
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Go to Edit -&amp;gt; Preferences and select the &#34;User Interface&#34; item on the left side tree. Then deselect &#34;Confirm unsaved capture files&#34;</description>
    </item>
    
    <item>
      <title>How to view, filter, search a raw capture running on RedHat Linux / Command line analysis like usage of GUI</title>
      <link>/questions/21240/how-to-view-filter-search-a-raw-capture-running-on-redhat-linux-command-line-analysis-like-usage-of-gui/</link>
      <pubDate>Fri, 17 May 2013 13:14:00 +0000</pubDate>
      
      <guid>/questions/21240/how-to-view-filter-search-a-raw-capture-running-on-redhat-linux-command-line-analysis-like-usage-of-gui/</guid>
      <description>How to view, filter, search a raw capture running on RedHat Linux / Command line analysis like usage of GUI  0 I basically want to type in a string to search a raw capture within Linux vs GUI. How is the possible? what are all the commands(within reason)?
capture analysis linuxasked 17 May &#39;13, 13:14
Vurcos
1●1●1●1
accept rate: 0%
  
One Answer:
  
0You could try the following display filter:</description>
    </item>
    
    <item>
      <title>wireshark expert needed - URGENT</title>
      <link>/questions/21243/wireshark-expert-needed-urgent/</link>
      <pubDate>Fri, 17 May 2013 14:26:00 +0000</pubDate>
      
      <guid>/questions/21243/wireshark-expert-needed-urgent/</guid>
      <description>wireshark expert needed - URGENT  0 we have a pesky problem with our Internet up and download speed. this problem has brought our business to it&#39;s knees. I&#39;ve spoken to a half-dozen tech support people... including our ISP and no one can diagnose the problem.
our isp says it is caused by outgoing traffic from one or both of our computers. Wireshark may be able to identify the problem but I don&#39;t know how to use it.</description>
    </item>
    
    <item>
      <title>Capture messages of remote cisco 7609 router interface on Linux</title>
      <link>/questions/21252/capture-messages-of-remote-cisco-7609-router-interface-on-linux/</link>
      <pubDate>Sat, 18 May 2013 07:35:00 +0000</pubDate>
      
      <guid>/questions/21252/capture-messages-of-remote-cisco-7609-router-interface-on-linux/</guid>
      <description>Capture messages of remote cisco 7609 router interface on Linux  0 Hi, As the title says, i need to capture messages coming on a interface in cisco router from my linux system, IS there anyway? What configuration is required in cisco router
router cisco remoteasked 18 May &#39;13, 07:35
Chandra Sekhar
11●1●1●2
accept rate: 0%
  
One Answer:
  
0I&#39;m pretty sure your Linux system is connected to the 7609 via a switch (either separate access switch or directly to a switch blade in the 7609).</description>
    </item>
    
    <item>
      <title>rpcapd allowed hosts list format in linux?</title>
      <link>/questions/21256/rpcapd-allowed-hosts-list-format-in-linux/</link>
      <pubDate>Sat, 18 May 2013 23:34:00 +0000</pubDate>
      
      <guid>/questions/21256/rpcapd-allowed-hosts-list-format-in-linux/</guid>
      <description>rpcapd allowed hosts list format in linux?  0 I&#39;m using rpcapd on my Tomato router to access all packets from a Wireshark client on my network. rpcapd works great and I can see traffic for each bridge I select in remote connection in Wireshark. I am using null authentication at the moment, and I would of course like to create an allowed hosts lists with the: rpcapd -l allowed_host_list but for some reason no format I use in this list is accepted during the connection in Wireshark.</description>
    </item>
    
    <item>
      <title>How does wireshark determine the protocol?</title>
      <link>/questions/21257/how-does-wireshark-determine-the-protocol/</link>
      <pubDate>Sun, 19 May 2013 01:25:00 +0000</pubDate>
      
      <guid>/questions/21257/how-does-wireshark-determine-the-protocol/</guid>
      <description>How does wireshark determine the protocol?  0 We have just ventured into wireshark. We notice the protocol field. How does wireshark determines the protocol is it based on the port number or level 3 protocol numbers? For instance DNS what does it look out for?
protocol wiresharkasked 19 May &#39;13, 01:25
newbie14
26●3●3●8
accept rate: 0%
  
One Answer:
  
3About the same way your system is recognizing which process to send the received packets to.</description>
    </item>
    
    <item>
      <title>Interface for Zigbee (jennic)</title>
      <link>/questions/21263/interface-for-zigbee-jennic/</link>
      <pubDate>Sun, 19 May 2013 08:10:00 +0000</pubDate>
      
      <guid>/questions/21263/interface-for-zigbee-jennic/</guid>
      <description>Interface for Zigbee (jennic)  0 Dear Sir,
I have wireless sensor network which work on IEEE 802.15.4 which i use Jennic JN51349 evaluation board
I set the microcontroller as sniffer, and i run the sniffer server, and then i make an interface ( Microsoft Loopback adapter)
but when I running the wireshark for capture and analyze the data,, I got no data capture by wire shark when I see the interface details, there is no packet received</description>
    </item>
    
    <item>
      <title>why is wireshark so superior and yet free</title>
      <link>/questions/21264/why-is-wireshark-so-superior-and-yet-free/</link>
      <pubDate>Sun, 19 May 2013 08:44:00 +0000</pubDate>
      
      <guid>/questions/21264/why-is-wireshark-so-superior-and-yet-free/</guid>
      <description>why is wireshark so superior and yet free  0 Given the sorry state of what goes for network analysis these days, it is refreshing to deal with a product (Wireshark) and its support staff that appear to understand networking and how it works. I would be happy to pay for your product and find it superior to anything else out there as a general sniffer. This is not a complaint we all love free and it makes it easy to share IP traces with clients when all they have to do is download Wireshark rather than purchase it to view the IP trace.</description>
    </item>
    
    <item>
      <title>How to export or display capture traffic in this format? - Ethernet II excluded</title>
      <link>/questions/21265/how-to-export-or-display-capture-traffic-in-this-format-ethernet-ii-excluded/</link>
      <pubDate>Sun, 19 May 2013 11:25:00 +0000</pubDate>
      
      <guid>/questions/21265/how-to-export-or-display-capture-traffic-in-this-format-ethernet-ii-excluded/</guid>
      <description>How to export or display capture traffic in this format? - Ethernet II excluded  0 4500 0028 596c 4000 8006 d127 0a3b 00a3 36ef 8e6f c12f 0050 1817 84d1 7a9b 5b14 5011 0fc69 bb90 000
was makfocasked 19 May &#39;13, 11:25
OMara
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1Well, wireshark (with &amp;gt;2million lines of code) is a bit overkill for that, why not use a simple perl script:</description>
    </item>
    
    <item>
      <title>Ethernet II with bad FCS</title>
      <link>/questions/21272/ethernet-ii-with-bad-fcs/</link>
      <pubDate>Sun, 19 May 2013 13:02:00 +0000</pubDate>
      
      <guid>/questions/21272/ethernet-ii-with-bad-fcs/</guid>
      <description>Ethernet II with bad FCS  0 Did somebody get this packet? If you did, could you give me pcap file?
ethernetasked 19 May &#39;13, 13:02
DariaS
11●3●3●6
accept rate: 0%
I&#39;m sorry, but what exactly is your question?
(20 May &#39;13, 03:36) Kurt Knochner ♦I recon he/she is asking for a sample trace file containing a frame with a broken Ethernet FCS.
(20 May &#39;13, 12:56) Jasper ♦♦</description>
    </item>
    
    <item>
      <title>Http failure indicated by the user</title>
      <link>/questions/21279/http-failure-indicated-by-the-user/</link>
      <pubDate>Sun, 19 May 2013 16:18:00 +0000</pubDate>
      
      <guid>/questions/21279/http-failure-indicated-by-the-user/</guid>
      <description>Http failure indicated by the user  0 https://www.cloudshark.org/captures/c80a58e1dccb To start with; the one server is the inside on the network and the others is in DMZ 2 a firewall separates them. I have a user complaining that from time to time they lose connection to and http session, But there no indication of a http upload disconnection. Is seeing in the three way handshake, but I also see a bunch of NOPS, through the trace, but everything looks good.</description>
    </item>
    
    <item>
      <title>openbsd compiling errors</title>
      <link>/questions/21282/openbsd-compiling-errors/</link>
      <pubDate>Sun, 19 May 2013 19:31:00 +0000</pubDate>
      
      <guid>/questions/21282/openbsd-compiling-errors/</guid>
      <description>openbsd compiling errors  0 During the gmake process while attempting to compile ver 1.8.7 of wireshark on an OpenBSD 5.3 platform I get the following errors:
cc1: out of memory allocating 4072 bytes after a total of 0 bytes gmake[5]: *** [packet-parlay.lo] Error 1 gmake[5]: Leaving directory &amp;#39;/home/..../wireshark-1.8.7/epan/dissectors gmake[5]: *** [all-recursive] Error 1 gmake[5]: Leaving directory &amp;#39;/home/..../wireshark-1.8.7/epan/dissectors gmake[5]: *** [all] Error 2Any thoughts?
compiling openbsd errorsasked 19 May &#39;13, 19:31</description>
    </item>
    
    <item>
      <title>ip of machine where wireshark is running</title>
      <link>/questions/21297/ip-of-machine-where-wireshark-is-running/</link>
      <pubDate>Mon, 20 May 2013 03:59:00 +0000</pubDate>
      
      <guid>/questions/21297/ip-of-machine-where-wireshark-is-running/</guid>
      <description>ip of machine where wireshark is running  0 Hi Friends, Can we find out ip add./mac-add of capture device by looking at capture file.Sometimes vendor provides us capture file and by looking into it , is there a way we can find out on which ip/mac that capture was taken.
wiresharkasked 20 May &#39;13, 03:59
kishan pandey
221●28●29●36
accept rate: 28%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>dll error when open  Wireshark</title>
      <link>/questions/21306/dll-error-when-open-wireshark/</link>
      <pubDate>Mon, 20 May 2013 07:01:00 +0000</pubDate>
      
      <guid>/questions/21306/dll-error-when-open-wireshark/</guid>
      <description>dll error when open Wireshark  0 After installing Wireshark 1.8.6.48142 and trying to launch, I get &#34;error signature &#34;libgobject-2.0.0.dll &#34;. Re-installing the application are the same problem. how to solve this problem?? thanks~~
dll errorasked 20 May &#39;13, 07:01
HBK
1●1●1●1
accept rate: 0%
 edited 20 May &#39;13, 10:27 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
0If you downloaded the installer from http://www.</description>
    </item>
    
    <item>
      <title>What is the capture filter for a specific IPv4 subnet?</title>
      <link>/questions/21312/what-is-the-capture-filter-for-a-specific-ipv4-subnet/</link>
      <pubDate>Mon, 20 May 2013 08:18:00 +0000</pubDate>
      
      <guid>/questions/21312/what-is-the-capture-filter-for-a-specific-ipv4-subnet/</guid>
      <description>What is the capture filter for a specific IPv4 subnet?  0 What is the capture filter for a specific IPv4 subnet? I had thought that this would do:
net 192.168.1.0However, I don&#39;t capture any traffic with this filter at all (where I know there is traffic, since I can see some on that subnet when capturing without the filter).
filter capture_filter ipv4asked 20 May &#39;13, 08:18
multipleinte...
1.3k●15●23●40
accept rate: 12%</description>
    </item>
    
    <item>
      <title>wireshark troubleshooting forum</title>
      <link>/questions/21315/wireshark-troubleshooting-forum/</link>
      <pubDate>Mon, 20 May 2013 08:44:00 +0000</pubDate>
      
      <guid>/questions/21315/wireshark-troubleshooting-forum/</guid>
      <description>wireshark troubleshooting forum  0 Is there any forum where one can share his analysis and experiences with wireshark troubleshooting, I mean how problems were solved with wireshark?
troubleshooting wiresharkasked 20 May &#39;13, 08:44
kishan pandey
221●28●29●36
accept rate: 28%
 edited 24 Jun &#39;13, 07:04 
cmaynard ♦♦
9.4k●10●38●142
  
3 Answers:
  
2why not post a question here and then answer it yourself to describe what you did and how?</description>
    </item>
    
    <item>
      <title>Capture SOAP traffic from a virtual Windows to Mac OS X host?</title>
      <link>/questions/21319/capture-soap-traffic-from-a-virtual-windows-to-mac-os-x-host/</link>
      <pubDate>Mon, 20 May 2013 09:44:00 +0000</pubDate>
      
      <guid>/questions/21319/capture-soap-traffic-from-a-virtual-windows-to-mac-os-x-host/</guid>
      <description>Capture SOAP traffic from a virtual Windows to Mac OS X host?  0 My host is a Mac OS X 10.8 machine with a virtual Windows 8 residing in Parallels 8. The Mac&#39;s ethernet address is 172.168.10.100, the Win machine shows 172.168.10.115 and is &#34;pc-rrupp-win8.testdomain.com&#34;. Parallel&#39;s is setup to use &#34;bridged network over Ethernet&#34;. On the Windows machine, I&#39;m running a web service which is called from a Mono C# application that is running on the Mac host.</description>
    </item>
    
    <item>
      <title>Post a solution</title>
      <link>/questions/21320/post-a-solution/</link>
      <pubDate>Mon, 20 May 2013 09:59:00 +0000</pubDate>
      
      <guid>/questions/21320/post-a-solution/</guid>
      <description>Post a solution  0 Like a tab &#34;Ask a question&#34; we have here there should be one more available with &#34;Post a solution&#34; like i am doing today with my troubleshooting experience with wirehsark,which otherwise would have been very difficult to solve.The issue i&#39;m mentioning was going on from more than a month and it took less than some 2 hourse to solve with wireshark, Few days back i got an issue where we have 2 servers behind netscaler loadbalancer and they were working fine but the moment the user was adding 3rd server all request to that server was getting rejected(as per application log on that 3rd server).</description>
    </item>
    
    <item>
      <title>monitor 24/7 but retain only 15 minutes?</title>
      <link>/questions/21323/monitor-247-but-retain-only-15-minutes/</link>
      <pubDate>Mon, 20 May 2013 11:36:00 +0000</pubDate>
      
      <guid>/questions/21323/monitor-247-but-retain-only-15-minutes/</guid>
      <description>monitor 24/7 but retain only 15 minutes?  0 I need to investigate a problem I am having with my phone system. However the problem cannot be reproduced intentionally so I there is no way that I can plan ahead to capture traffic.
Is it possible to leave wireshark on 24/7 but only keep a specified amount of transactions, or say even like 20 minutes of data? This way when the problem does occur again, I will have a capture of hopefully, of what&#39;s going down.</description>
    </item>
    
    <item>
      <title>How do I know the Release date for each version?</title>
      <link>/questions/21333/how-do-i-know-the-release-date-for-each-version/</link>
      <pubDate>Mon, 20 May 2013 14:57:00 +0000</pubDate>
      
      <guid>/questions/21333/how-do-i-know-the-release-date-for-each-version/</guid>
      <description>How do I know the Release date for each version?  0 I am looking to see where I can find the release dates for each version of WireShark. I see the Security Advisories have dates, but the Release Notes do not.
release updateasked 20 May &#39;13, 14:57
nsweet24
11●1●1●2
accept rate: 0%
  
One Answer:
  
1From the announce mailing list archive? See the Gmane archives.</description>
    </item>
    
    <item>
      <title>Using &amp;quot;;&amp;quot; character in tshark display filter</title>
      <link>/questions/21335/using-character-in-tshark-display-filter/</link>
      <pubDate>Mon, 20 May 2013 16:03:00 +0000</pubDate>
      
      <guid>/questions/21335/using-character-in-tshark-display-filter/</guid>
      <description>Using &amp;ldquo;;&amp;rdquo; character in tshark display filter  0 I&#39;m trying to write a display filter in tshark where the value I&#39;m searaching for includes the &#34;;&#34; character. The problem is this character seems to have some special significance with tshark and it complains that it was unexpected. This is true even when the display filter is cleanly encapsulated in quotation marks. For example:
tshark -r file.pcap -R &#34;diameter.Session-Id==a;b;c;d&#34;
Also tried:</description>
    </item>
    
    <item>
      <title>I can&amp;#x27;t capture in monitor mode</title>
      <link>/questions/21339/i-cant-capture-in-monitor-mode/</link>
      <pubDate>Mon, 20 May 2013 22:10:00 +0000</pubDate>
      
      <guid>/questions/21339/i-cant-capture-in-monitor-mode/</guid>
      <description>I can&amp;rsquo;t capture in monitor mode  0 hi,
Even i had the same problem, when i gave iwconfig my wifi couldnt recognize any interface and when i select monitor mode in wireshark, it throws a error saying my device doesnt support this. What could be the problem??
Plz help..
monitor-modeasked 20 May &#39;13, 22:10
praveen_ind
1●1●1●1
accept rate: 0%
 converted 21 May &#39;13, 11:16 
Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t save the decrypted data in wireshark</title>
      <link>/questions/21341/cant-save-the-decrypted-data-in-wireshark/</link>
      <pubDate>Tue, 21 May 2013 00:21:00 +0000</pubDate>
      
      <guid>/questions/21341/cant-save-the-decrypted-data-in-wireshark/</guid>
      <description>Can&amp;rsquo;t save the decrypted data in wireshark  0 I tried to save the decrypted data as a pcap file. But when I opened it it&#39;s still a encrypted one.Will it be possible to save the decrypted wireshark file? Thanks in Advance
decryption ssl wiresharkasked 21 May &#39;13, 00:21
Kalai
16●5●5●10
accept rate: 0%
  
One Answer:
  
1 Will it be possible to save the decrypted wireshark file?</description>
    </item>
    
    <item>
      <title>How to decode mpeg ts payload?</title>
      <link>/questions/21344/how-to-decode-mpeg-ts-payload/</link>
      <pubDate>Tue, 21 May 2013 03:32:00 +0000</pubDate>
      
      <guid>/questions/21344/how-to-decode-mpeg-ts-payload/</guid>
      <description>How to decode mpeg ts payload?  0 Hello,
I need to decode mpeg ts payload in a .pcap file (UDPs with mpegts).
Especially I need PAT/PMT information data. The PAT (Program Association Table) stores the PIDs of all PMTs. I need the PIDs of these PMTs.
What I done is to decode the UDP packets as mp2t. So far so good, but I get only the headers of ISO/IEC 13818-1 like &#34;</description>
    </item>
    
    <item>
      <title>How do I register a field?</title>
      <link>/questions/21348/how-do-i-register-a-field/</link>
      <pubDate>Tue, 21 May 2013 09:59:00 +0000</pubDate>
      
      <guid>/questions/21348/how-do-i-register-a-field/</guid>
      <description>How do I register a field?  0 Thanks!
I used the private_data method and it worked perfectly.
Another thing i would like to do is register the CIC i got, using proto_register function, to allow me to filter the capture files using cic as criteria.
Is that possible?
Sorry if this is a dumb question, my experience with wireshark is really limited.
What i did to build and show the cic is this:</description>
    </item>
    
    <item>
      <title>How to learn wireshark</title>
      <link>/questions/21355/how-to-learn-wireshark/</link>
      <pubDate>Tue, 21 May 2013 11:41:00 +0000</pubDate>
      
      <guid>/questions/21355/how-to-learn-wireshark/</guid>
      <description>How to learn wireshark  0 Hi Everyone I&#39;m new to the forum and I wanted to know can anyone tell me the best way to learn how to use wire shark. I want to learn how to decode the packets and I&#39;ve never used wire shark before so all of this is new to me. Thanks in advance for the help and I look forward to the response to the question.</description>
    </item>
    
    <item>
      <title>Failure to recognize LDAP if not port 389?</title>
      <link>/questions/21358/failure-to-recognize-ldap-if-not-port-389/</link>
      <pubDate>Tue, 21 May 2013 15:41:00 +0000</pubDate>
      
      <guid>/questions/21358/failure-to-recognize-ldap-if-not-port-389/</guid>
      <description>Failure to recognize LDAP if not port 389?  1 I am using AD LDS (Active Directory Lightweight Services) and connecting to it using ldp.exe (from microsoft). I am using port 50000. I am able to authenticate successfully and capture the traffic. However, wireshark interprets as TCP not LDAP and in the info field it does not say bind request, etc. Is this due to the port that I am using?</description>
    </item>
    
    <item>
      <title>unzip: /cygdrive/c/Turbo/TC/BIN/unzip.. How to change it to point to cygwin</title>
      <link>/questions/21361/unzip-cygdrivecturbotcbinunzip-how-to-change-it-to-point-to-cygwin/</link>
      <pubDate>Tue, 21 May 2013 17:02:00 +0000</pubDate>
      
      <guid>/questions/21361/unzip-cygdrivecturbotcbinunzip-how-to-change-it-to-point-to-cygwin/</guid>
      <description>unzip: /cygdrive/c/Turbo/TC/BIN/unzip.. How to change it to point to cygwin  0 Hi,
when I run nmake -f Makefile.namke verify_tools, unzip package is currently pointing to
 unzip: /cygdrive/c/Turbo/TC/BIN/unzipBecause of which I&#39;m getting following err while running nmake -f Makefile.nmake setup
 ERROR: Couldn&amp;#39;t unpack &amp;#39;/cygdrive/c/Wireshark-win32-libs/gtk+-bundle_2.24.14-1.1_win32ws.zip&amp;#39; NMAKE : fatal error U1077: &#39;c:\cygwin\bin\bash.EXE&#39; : return code &#39;0x1&#39; Stop.I have included cygwin (C:\cygwin\bin) in my path env variable. I also can see unzip is being installed in /usr/bin/unzip.</description>
    </item>
    
    <item>
      <title>Recursively dissect data fields</title>
      <link>/questions/21372/recursively-dissect-data-fields/</link>
      <pubDate>Wed, 22 May 2013 06:27:00 +0000</pubDate>
      
      <guid>/questions/21372/recursively-dissect-data-fields/</guid>
      <description>Recursively dissect data fields  0 I&#39;m writing a dissector for what is essentially a Google Protocol Buffers message. The details aren&#39;t important; I end up with a number of fields of bytes. All this is working well.
Now, sometimes, and not intrinsically recognizable from the data, a field of bytes may itself be a full message. Is it possible to register the dissector so that I can select just the one data field and say &#34;</description>
    </item>
    
    <item>
      <title>Client awareness in fetching multiple HTTP objects pertaining to a website</title>
      <link>/questions/21380/client-awareness-in-fetching-multiple-http-objects-pertaining-to-a-website/</link>
      <pubDate>Wed, 22 May 2013 14:57:00 +0000</pubDate>
      
      <guid>/questions/21380/client-awareness-in-fetching-multiple-http-objects-pertaining-to-a-website/</guid>
      <description>Client awareness in fetching multiple HTTP objects pertaining to a website  0 Hi,
I got a basic doubt regarding opening TCP connections to fetch multiple HTTP objects pertaining to a website.
Here is an example:
I clicked www.disney.com and captured port 53(DNS) packets associated to that site
Sample queries included
A www.disney.com
A a.dilcdn.com
A ajax.googleapis.com
A cdnvideo.dolimg.com
etc..........
Here, on my browser i typed only www.disney.com but my doubt is who will inform to client that in order to get full page it needs to open connections to a.</description>
    </item>
    
    <item>
      <title>&amp;quot;A Field extractor must be defined before Taps or Dissectors get called&amp;quot; when I try to create an SSL Tap</title>
      <link>/questions/21387/a-field-extractor-must-be-defined-before-taps-or-dissectors-get-called-when-i-try-to-create-an-ssl-tap/</link>
      <pubDate>Wed, 22 May 2013 17:31:00 +0000</pubDate>
      
      <guid>/questions/21387/a-field-extractor-must-be-defined-before-taps-or-dissectors-get-called-when-i-try-to-create-an-ssl-tap/</guid>
      <description>&amp;ldquo;A Field extractor must be defined before Taps or Dissectors get called&amp;rdquo; when I try to create an SSL Tap  0 Hi,
I&#39;m prototyping a listener in LUA using the &#39;Evaluate Lua&#39; window in WireShark. My goal is to access the SSL Certificate that gets exchanged during the TLS/SSL handshake. Per the data I&#39;ve googled I have tried this:
ssl_cert_Info = Field.new(&amp;quot;ssl.handshake.certificate&amp;quot;); function simplelistenerssl() local window2 = TextWindow.new(&amp;quot;SSL Window&amp;quot;); local tap = Listener.</description>
    </item>
    
    <item>
      <title>Adding/appending packets comment in pcapng file</title>
      <link>/questions/21388/addingappending-packets-comment-in-pcapng-file/</link>
      <pubDate>Wed, 22 May 2013 20:35:00 +0000</pubDate>
      
      <guid>/questions/21388/addingappending-packets-comment-in-pcapng-file/</guid>
      <description>Adding/appending packets comment in pcapng file  0 Hi,
I would like to add comment inside the &#34;packet comments&#34; field of pcapng using a script.
Use case would be something like: if dns.ttl &amp;lt; 120 sec: add_comments(&#34;Short TLL&#34;)
I&#39;ve been reading and it&#39;s probably doable using a LUA script but before today I never wrote a line of LUA. I would like to know if it is indeed doable and if someone could send me in the right direction to get that done.</description>
    </item>
    
    <item>
      <title>How to calculate the difference between two NSTime values in LUA</title>
      <link>/questions/21389/how-to-calculate-the-difference-between-two-nstime-values-in-lua/</link>
      <pubDate>Wed, 22 May 2013 20:54:00 +0000</pubDate>
      
      <guid>/questions/21389/how-to-calculate-the-difference-between-two-nstime-values-in-lua/</guid>
      <description>How to calculate the difference between two NSTime values in LUA  0 I&#39;ve been writing a lua dissector and would like to display the time interval between the arrival of two different packets.
I have created some NSTime variables like so:
first_nstime = NSTime(pinfo.abs_ts)I then put all of these values (from all of the packets in the capture) into a table which gets referenced later when I want to get the interval between the last packet and the current packet.</description>
    </item>
    
    <item>
      <title>SINR doesn&amp;#x27;t appeared even in monitor mode</title>
      <link>/questions/21390/sinr-doesnt-appeared-even-in-monitor-mode/</link>
      <pubDate>Wed, 22 May 2013 22:10:00 +0000</pubDate>
      
      <guid>/questions/21390/sinr-doesnt-appeared-even-in-monitor-mode/</guid>
      <description>SINR doesn&amp;rsquo;t appeared even in monitor mode  0 Hi everyone. I&#39;m currently try to sniff a WiFi SINR value using TCPDump. I put my adapter on monitor mode already but when i try to capture any traffic. Nothing is captured. Can anyone give me a solution?
[[email protected] ~]# iwconfig lo no wireless extensions.
eth0 no wireless extensions.
wifi0 no wireless extensions.
pan0 no wireless extensions.
ath0 IEEE 802.11g ESSID:&#34;</description>
    </item>
    
    <item>
      <title>What is this mean? IEEE802_11_RADIO is not one of the DLTs supported by this device</title>
      <link>/questions/21391/what-is-this-mean-ieee802_11_radio-is-not-one-of-the-dlts-supported-by-this-device/</link>
      <pubDate>Wed, 22 May 2013 22:36:00 +0000</pubDate>
      
      <guid>/questions/21391/what-is-this-mean-ieee802_11_radio-is-not-one-of-the-dlts-supported-by-this-device/</guid>
      <description>What is this mean? IEEE802_11_RADIO is not one of the DLTs supported by this device  0 Hi, I put this command on terminal also shown the result below. Does it mean that even though I change into monitor mode, it would still impossible to get radio information using tcpdump?
[[email protected] ~]# tcpdump -i ath0 -y IEEE802_11_RADIO tcpdump: IEEE802_11_RADIO is not one of the DLTs supported by this device [[email protected] ~]# tcpdump -i ath0 -y IEEE802_11_RADIO_AVS tcpdump: IEEE802_11_RADIO_AVS is not one of the DLTs supported by this devicesinr tcpdumpasked 22 May &#39;13, 22:36</description>
    </item>
    
    <item>
      <title>Couldn&amp;#x27;t extract encrypted Application data from pcap using Perl Netpacket module</title>
      <link>/questions/21392/couldnt-extract-encrypted-application-data-from-pcap-using-perl-netpacket-module/</link>
      <pubDate>Wed, 22 May 2013 23:54:00 +0000</pubDate>
      
      <guid>/questions/21392/couldnt-extract-encrypted-application-data-from-pcap-using-perl-netpacket-module/</guid>
      <description>Couldn&amp;rsquo;t extract encrypted Application data from pcap using Perl Netpacket module  0 I tried to extract the encrypted application data using the perl Netpacket module.I am able to see the ports but couldn&#39;t see the encrypted data.Any Modules are there to see the encrypted app data or any unpack function is required to read that?
decryption perl pcap netpacketasked 22 May &#39;13, 23:54
Kalai
16●5●5●10
accept rate: 0%
 edited 23 May &#39;13, 06:25</description>
    </item>
    
    <item>
      <title>IPv6 decryption support for SSL</title>
      <link>/questions/21397/ipv6-decryption-support-for-ssl/</link>
      <pubDate>Thu, 23 May 2013 01:55:00 +0000</pubDate>
      
      <guid>/questions/21397/ipv6-decryption-support-for-ssl/</guid>
      <description>IPv6 decryption support for SSL  0 Hi, I am trying to decrypt SSL IPv6 packets by supplying all the correct information (Full format of IPV6 address, the RSA key, port &amp;amp; protocol). But still I am seeing that the application data contained in the SSL record is still encrypted &amp;amp; not in decrypted format. The same works fine with IPv4 packets. I found the below link on the internet wherein other users too have brought this to notice, but unfortunately I am not able to find if this issue is resolved &amp;amp; if yes, then which version it was resolved.</description>
    </item>
    
    <item>
      <title>Promiscous network: capture traffic of iPhone from pc using Fritzbox 7390</title>
      <link>/questions/21406/promiscous-network-capture-traffic-of-iphone-from-pc-using-fritzbox-7390/</link>
      <pubDate>Thu, 23 May 2013 07:03:00 +0000</pubDate>
      
      <guid>/questions/21406/promiscous-network-capture-traffic-of-iphone-from-pc-using-fritzbox-7390/</guid>
      <description>Promiscous network: capture traffic of iPhone from pc using Fritzbox 7390  0 Hello,
I am new at these things and i need help.
I have a Fritzbox 7390. My PC is conencted by a switch to the lan and my iPhone is conencted through wifi.
From Wireshark, that i installed on my pc, i cannot see the iPhone interface.
Can someone help me how to do it?
thanks
fritzbox promiscousasked 23 May &#39;13, 07:03</description>
    </item>
    
    <item>
      <title>Can a heuristic dissector be applied to the entire TCP connection?</title>
      <link>/questions/21412/can-a-heuristic-dissector-be-applied-to-the-entire-tcp-connection/</link>
      <pubDate>Thu, 23 May 2013 07:53:00 +0000</pubDate>
      
      <guid>/questions/21412/can-a-heuristic-dissector-be-applied-to-the-entire-tcp-connection/</guid>
      <description>Can a heuristic dissector be applied to the entire TCP connection?  0 I have a TCP session consisting of multiple packets. When I select any one of them and say &#34;Decode as...&#34; for my dissector, the dissector is properly applied to all packets in the entire session.
I can write a heuristic detector for my dissector that will match only the first packet in the sequence. However, when I do this, only the first packet is decoded by my dissector, and the remaining packets don&#39;t get dissected.</description>
    </item>
    
    <item>
      <title>How to know that RTP dynamic payload type carries video or voice codec ?</title>
      <link>/questions/21415/how-to-know-that-rtp-dynamic-payload-type-carries-video-or-voice-codec/</link>
      <pubDate>Thu, 23 May 2013 08:20:00 +0000</pubDate>
      
      <guid>/questions/21415/how-to-know-that-rtp-dynamic-payload-type-carries-video-or-voice-codec/</guid>
      <description>How to know that RTP dynamic payload type carries video or voice codec ?  0 Hello I&#39;m newbie here. I need to know about RTP payload type. I&#39;ve got dynamic RTP payload type on my wireshark when I did video call using yahoo messenger.
Then it appears many RTP protocols and the info shows: PT=DynamicRTP-Type-123 and also PT=DynamicRTP-Type-97
Since it dynamic payload type, how could I know which RTP protocol carries video packets and which carries voice packets?</description>
    </item>
    
    <item>
      <title>HELP! Capturing an entire e-mail using Wireshark</title>
      <link>/questions/21418/help-capturing-an-entire-e-mail-using-wireshark/</link>
      <pubDate>Thu, 23 May 2013 09:48:00 +0000</pubDate>
      
      <guid>/questions/21418/help-capturing-an-entire-e-mail-using-wireshark/</guid>
      <description>HELP! Capturing an entire e-mail using Wireshark  0 Hi all! I created an e-mail anti spam system and I need to test it against an anti spam product that I hired. I duplicated the port from where my e-mail&#39;s packages comes, so now my homemade system and the oficial product receive both the same packages. My system needs to &#34;see&#34; the entire e-mail in order to classify it. Now I&#39;m running an offline test, so I captured all packages from this port with Wireshark.</description>
    </item>
    
    <item>
      <title>How to find some informations in protocol TCP and UDP. Please read.</title>
      <link>/questions/21422/how-to-find-some-informations-in-protocol-tcp-and-udp-please-read/</link>
      <pubDate>Thu, 23 May 2013 13:34:00 +0000</pubDate>
      
      <guid>/questions/21422/how-to-find-some-informations-in-protocol-tcp-and-udp-please-read/</guid>
      <description>How to find some informations in protocol TCP and UDP. Please read.  0 Hi everyone! :D
So my teacher about Network subject (unfortunatelly it&#39;s not my best) gave me 2 (easy for you).tcpd files:file 1, file 2. And I have to catch some information from this packets:
what kind of services was used ? any mistakes ? what was sent ?used adresses and protocols (take care about class of adresses and translation of adresses (NAT) and transport protocolswhich systems was installed on the computers (for example: client - Windwos, server: Linux)how distance (number of routers) was between deviceswhere was started scanner (server, client or for example 3 routers far from server)time of made captureconfiguration of local network (for example default router, adressed MAC)how its possible to repeat captured comunication (give program or make a printscreen)(additional) catch packets received and sent through the program tracepath or traceroute(additional) catch question sent to DNS serverI already did point 1,2 (except NAT),6,7(only MAC).</description>
    </item>
    
    <item>
      <title>How to filter TCP SO_KEEPALIVE packets?</title>
      <link>/questions/21423/how-to-filter-tcp-so_keepalive-packets/</link>
      <pubDate>Thu, 23 May 2013 15:06:00 +0000</pubDate>
      
      <guid>/questions/21423/how-to-filter-tcp-so_keepalive-packets/</guid>
      <description>How to filter TCP SO_KEEPALIVE packets?  0 I would like to look for packets sent between to Linux 2.6.32 systems that are coming from the kernel due to sockets that have SO_KEEPALIVE set having been idle long enough to cause keep alive packets to be sent. What filter expression should I use? I&#39;d prefer a capture filter but if only a display filter works I can use that instead. Thanks</description>
    </item>
    
    <item>
      <title>capture who is sending outgoing video stream</title>
      <link>/questions/21425/capture-who-is-sending-outgoing-video-stream/</link>
      <pubDate>Thu, 23 May 2013 15:28:00 +0000</pubDate>
      
      <guid>/questions/21425/capture-who-is-sending-outgoing-video-stream/</guid>
      <description>capture who is sending outgoing video stream  0 Hi, I&#39;m new to wireshark, but I get the concept of what it does, I hope.... I am an IT consultant and have been hired by a company to see who is streaming a TV program from their network. they have been contacted by the TV station that an IP on their network has been doing this to a bit torrent. I have placed my switch with the port mirroring on the lan between the last switch and the router/firewall.</description>
    </item>
    
    <item>
      <title>tshark -e output - how to bind value to a protocol container?</title>
      <link>/questions/21428/tshark-e-output-how-to-bind-value-to-a-protocol-container/</link>
      <pubDate>Thu, 23 May 2013 21:00:00 +0000</pubDate>
      
      <guid>/questions/21428/tshark-e-output-how-to-bind-value-to-a-protocol-container/</guid>
      <description>tshark -e output - how to bind value to a protocol container?  0 Hello,
I&#39;m using tshark to decode a protocol where I want to map the values of one attribute to the values of another by using the -T fields option and a -e flag for both attributes. The problem I have is that a single IP packet in this case can have multiple instances of this same protocol in the stack, and one of those two attributes doesn&#39;t have to be present in both messages in the single packet, so the output I get for some packets will be:</description>
    </item>
    
    <item>
      <title>Serial/IP Converter Help</title>
      <link>/questions/21430/serialip-converter-help/</link>
      <pubDate>Thu, 23 May 2013 21:30:00 +0000</pubDate>
      
      <guid>/questions/21430/serialip-converter-help/</guid>
      <description>Serial/IP Converter Help  0 Hope someone can help, I&#39;m a pretty new to wireshark and trying to get this figured out.
A little backstory on the install,
PC IP 10.23.1.122 Serial/IP Converters port:4660
I already have a serial to IP converter up and running on this job under the IP 10.23.1.120 and everything works great. Tried to add a second converter under 10.23.1.121 and it doesn&#39;t work but I can ping it and it responds.</description>
    </item>
    
    <item>
      <title>How to capture wireless traffic in specific channel?</title>
      <link>/questions/21433/how-to-capture-wireless-traffic-in-specific-channel/</link>
      <pubDate>Fri, 24 May 2013 00:28:00 +0000</pubDate>
      
      <guid>/questions/21433/how-to-capture-wireless-traffic-in-specific-channel/</guid>
      <description>How to capture wireless traffic in specific channel?  0 I am new to wireshark. I am trying to capture wireless traffic on one specific channel using wlan.channel filter. But it is not working. I am using version 1.8.7 for wireshark.
Can you please let me know exact filter to be used for the same?
dynamicasked 24 May &#39;13, 00:28
RajeAmit
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>&amp;quot;Can&amp;#x27;t dissect FP frame because no per-frame info was attached! over TCP</title>
      <link>/questions/21438/cant-dissect-fp-frame-because-no-per-frame-info-was-attached-over-tcp/</link>
      <pubDate>Fri, 24 May 2013 02:43:00 +0000</pubDate>
      
      <guid>/questions/21438/cant-dissect-fp-frame-because-no-per-frame-info-was-attached-over-tcp/</guid>
      <description>&amp;ldquo;Can&amp;rsquo;t dissect FP frame because no per-frame info was attached! over TCP  0 Hi ,i am unable to dissect fp frame packet over tcp anw we got the error &#34;&#34;Can&#39;t dissect FP frame because no per-frame info was attached!&#34; plz responce
umts-fpThis question is marked &#34;community wiki&#34;.asked 24 May &#39;13, 02:43
Ranjeet Nag
11●3●3●6
accept rate: 0%
 edited 24 May &#39;13, 02:49 
  
2 Answers:</description>
    </item>
    
    <item>
      <title>[closed] Got a error &amp;quot;Can&amp;#x27;t dissect FP frame because no per-frame info was attached! &amp;quot; over TCP</title>
      <link>/questions/21439/got-a-error-cant-dissect-fp-frame-because-no-per-frame-info-was-attached-over-tcp/</link>
      <pubDate>Fri, 24 May 2013 02:45:00 +0000</pubDate>
      
      <guid>/questions/21439/got-a-error-cant-dissect-fp-frame-because-no-per-frame-info-was-attached-over-tcp/</guid>
      <description>[closed] Got a error &amp;ldquo;Can&amp;rsquo;t dissect FP frame because no per-frame info was attached! &amp;quot; over TCP  0 Hi i got a error &#34;Can&#39;t dissect FP frame because no per-frame info was attached!&#34; when we sent a fp frame packet over TCP. plz responce
umts-fpasked 24 May &#39;13, 02:45
Ranjeet Nag
11●3●3●6
accept rate: 0%
 edited 24 May &#39;13, 06:46 
 The question has been closed for the following reason &amp;ldquo;Duplicate Question&amp;rdquo; by grahamb 24 May &amp;lsquo;13, 03:29    </description>
    </item>
    
    <item>
      <title>google search display filter</title>
      <link>/questions/21447/google-search-display-filter/</link>
      <pubDate>Fri, 24 May 2013 09:13:00 +0000</pubDate>
      
      <guid>/questions/21447/google-search-display-filter/</guid>
      <description>google search display filter  0 Hi,
i am a newbie and are playing with wireshark.
I am trying to write a displayfilter that shows the google seach request done during the capture session.
as example i did a seach on google for &#34;tablet&#34;and &#34;Ferrari&#34; and now i want to create a filter that show me the seaches on google.
I tried this
http.host contains google http.request.uri contains google
But stil i dont see the words i have seached for.</description>
    </item>
    
    <item>
      <title>Filter for [SYN] packages without [SYN,ACK] respons</title>
      <link>/questions/21453/filter-for-syn-packages-without-synack-respons/</link>
      <pubDate>Fri, 24 May 2013 11:24:00 +0000</pubDate>
      
      <guid>/questions/21453/filter-for-syn-packages-without-synack-respons/</guid>
      <description>Filter for [SYN] packages without [SYN,ACK] respons  0 Our company is frequently involved in troubleshooting connection issues after a firewall implementation. Most of the times the firewall is blocking connections on ports which we were not aware of during investigation. Is it possible to have a filter which displays all TCP connection attempts , being [SYN] packages, which are NOT followed by a {SYN,ACK] acknowledgment from the destination host? This way we can quickly filter on connection attempts being blocked by the firewall.</description>
    </item>
    
    <item>
      <title>Dropped packets: not overload, but bad FCS?</title>
      <link>/questions/21470/dropped-packets-not-overload-but-bad-fcs/</link>
      <pubDate>Sat, 25 May 2013 01:16:00 +0000</pubDate>
      
      <guid>/questions/21470/dropped-packets-not-overload-but-bad-fcs/</guid>
      <description>Dropped packets: not overload, but bad FCS?  0 Hi!
The short question is: How i can capture frames with bad FCS on Linux? (i read that it is almost impossible, but i really need it).
The long story: I develop open-source FPGA-based Ethernet-to-serial converter (constant-speed bit flow, not async RS232-style). It sometimes show massive packet loss. I need to debug it and search a way to analyze all incoming traffic include damaged packets.</description>
    </item>
    
    <item>
      <title>How  does one  enable Decrypt 802.11?</title>
      <link>/questions/21478/how-does-one-enable-decrypt-80211/</link>
      <pubDate>Sun, 26 May 2013 06:49:00 +0000</pubDate>
      
      <guid>/questions/21478/how-does-one-enable-decrypt-80211/</guid>
      <description>How does one enable Decrypt 802.11?  0 Monitor mode (type 802.11 plus radiotap header) Wireshark edit&amp;gt;preferences no option to Decrypt802.11
Object: attempting to use monitor mode to decode my own LAN traffic as promiscuous mode does not show all my wifi router LAN traffic, that I am interested in (as pointed out in the Wireshark web site).
Running wireshark version 1.6.7 (very recently downloaded from Ubuntu software centre) on Ubuntu 12.</description>
    </item>
    
    <item>
      <title>Programs can&amp;#x27;t access the internet</title>
      <link>/questions/21480/programs-cant-access-the-internet/</link>
      <pubDate>Sun, 26 May 2013 11:26:00 +0000</pubDate>
      
      <guid>/questions/21480/programs-cant-access-the-internet/</guid>
      <description>Programs can&amp;rsquo;t access the internet  0 Hello, I have a problem with my program&#39;s internet connection,It&#39;s look like it can connect but it&#39;s doesn&#39;t get loading.I can use Firefox,but IE can&#39;t access to the internet, and the application on the windows 8&#39;s start page also can&#39;t connect to the internet at all.Steam, iTunes, IDM all are not function properly.I tried to reinstall windows 8 and windows 7, but problem still exist.</description>
    </item>
    
    <item>
      <title>Best Practice?  Updating Wireshark version on Mac OS X</title>
      <link>/questions/21484/best-practice-updating-wireshark-version-on-mac-os-x/</link>
      <pubDate>Sun, 26 May 2013 21:26:00 +0000</pubDate>
      
      <guid>/questions/21484/best-practice-updating-wireshark-version-on-mac-os-x/</guid>
      <description>Best Practice? Updating Wireshark version on Mac OS X  0 I would like to update to 1.8.7 from 1.8.6. I assume the simplest method is to simply download the DMG file, but not sure whether to install on top of the current version or uninstall the older version and then install. Does anyone have a recommendation?
mac upgradeasked 26 May &#39;13, 21:26
Glen2013
0●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Physical carrier sensing in 802.11?</title>
      <link>/questions/21486/physical-carrier-sensing-in-80211/</link>
      <pubDate>Mon, 27 May 2013 02:01:00 +0000</pubDate>
      
      <guid>/questions/21486/physical-carrier-sensing-in-80211/</guid>
      <description>Physical carrier sensing in 802.11?  0 I have two questions about IEEE 802.11 MAC protocol.
1) I want to know that physical carrier sense mechanism is adopted for non-RTS packets (CTS, DATA and ACK) or not? For more clarity please consider following scenario:
Suppose that node A sends a RTS packet for node B and node B receives this RTS without collision and also node B is not within a pre-established NAV state.</description>
    </item>
    
    <item>
      <title>ascii value display</title>
      <link>/questions/21488/ascii-value-display/</link>
      <pubDate>Mon, 27 May 2013 03:37:00 +0000</pubDate>
      
      <guid>/questions/21488/ascii-value-display/</guid>
      <description>ascii value display  0 how to display character value for a field in my protocol dissection ?i am getting the decimal value ,but want to convert to a character..plz explain
asciiasked 27 May &#39;13, 03:37
ajain
14●6●7●11
accept rate: 0%
 edited 27 May &#39;13, 04:46 
  
One Answer:
  
3Use FT_STRING field type. Here is an example taken from doc/README.developer:
static hf_register_info hf[] = { {&amp;amp;hf_cstring, {&amp;quot;C String&amp;quot;, &amp;quot;c.</description>
    </item>
    
    <item>
      <title>VoIP RTP player waveform screen blank</title>
      <link>/questions/21490/voip-rtp-player-waveform-screen-blank/</link>
      <pubDate>Mon, 27 May 2013 05:16:00 +0000</pubDate>
      
      <guid>/questions/21490/voip-rtp-player-waveform-screen-blank/</guid>
      <description>VoIP RTP player waveform screen blank  0 Occasionally when I want to play back/analyze voip rtp traffic, I end up with no waveforms. I have this happen on Windows, Linux, and OS X platforms.
Screenshot available at http://www.apple2pl.us/screenshot.png
Is there something that I&#39;m not doing that I should be?
player waveform rtp voip blankasked 27 May &#39;13, 05:16
cracklincrotch
11●1●1●3
accept rate: 0% 
 edited 27 May &#39;13, 05:17</description>
    </item>
    
    <item>
      <title>How TCP handle small packets</title>
      <link>/questions/21491/how-tcp-handle-small-packets/</link>
      <pubDate>Mon, 27 May 2013 08:52:00 +0000</pubDate>
      
      <guid>/questions/21491/how-tcp-handle-small-packets/</guid>
      <description>How TCP handle small packets  0 How does TCP handle application&#39;s small packets? We are currently using an application which is generating small packets all the time. Data length are 98% at 50 Bytes for each packets. On the LAN, it&#39;s not too bad, 16 seconds for a single session. However for those remote users(through MPLS WAN), it takes 3 minutes to finish a single session.
I am just woundering what I can adjust to let the application get better performance.</description>
    </item>
    
    <item>
      <title>SGsAP IMSI DETACH INDICATION packet decoding problem</title>
      <link>/questions/21515/sgsap-imsi-detach-indication-packet-decoding-problem/</link>
      <pubDate>Tue, 28 May 2013 00:49:00 +0000</pubDate>
      
      <guid>/questions/21515/sgsap-imsi-detach-indication-packet-decoding-problem/</guid>
      <description>SGsAP IMSI DETACH INDICATION packet decoding problem  0 I am using Wireshark Version 1.8.7. In SGsAP IMSI DETACH INDICATION packet in IMSI detach from non-EPS service type IE the IEI and length is correct but the content is wrong.It says IMSI detach from EPS service type: UE initiated IMSI detach from EPS services (2),but it should be IMSI detach from Non EPS service type: Combined UE initiated IMSI detach from EPS and Non EPS services (2).</description>
    </item>
    
    <item>
      <title>Help needed in NAS msg container</title>
      <link>/questions/21516/help-needed-in-nas-msg-container/</link>
      <pubDate>Tue, 28 May 2013 00:56:00 +0000</pubDate>
      
      <guid>/questions/21516/help-needed-in-nas-msg-container/</guid>
      <description>Help needed in NAS msg container  0 I am using wireshark Version 1.8.7. In case of SGsAP Uplink Unitdata or SGsAP Downlink Unitdata packet in NAS msg container IE for TP-MTI in TPDU SMS-SUBMIT-REPORT the spec says the field TP-Failure-Cause is mandatory.But the wireshark does not show so.It never show TP-Failure-Causs field.Is it right?
nas message containerasked 28 May &#39;13, 00:56
swap
11●5●5●6
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How we dissect FP-HSDSCH buffer over tcp by using dissect_fp()</title>
      <link>/questions/21519/how-we-dissect-fp-hsdsch-buffer-over-tcp-by-using-dissect_fp/</link>
      <pubDate>Tue, 28 May 2013 06:29:00 +0000</pubDate>
      
      <guid>/questions/21519/how-we-dissect-fp-hsdsch-buffer-over-tcp-by-using-dissect_fp/</guid>
      <description>How we dissect FP-HSDSCH buffer over tcp by using dissect_fp()  0 Hi i have a buffer of Dounlink Fp-HSDSCH buffer , want to dissect this buffer using dissect_fp() over tcp function, but it gives error&#34;per-packet info was not persent&#34;
dissect_fp fp umts-fpasked 28 May &#39;13, 06:29
Ranjeet Nag
11●3●3●6
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>How to update to wireshark 1.6.7 to latest version on ububtu 12.04</title>
      <link>/questions/21526/how-to-update-to-wireshark-167-to-latest-version-on-ububtu-1204/</link>
      <pubDate>Tue, 28 May 2013 09:20:00 +0000</pubDate>
      
      <guid>/questions/21526/how-to-update-to-wireshark-167-to-latest-version-on-ububtu-1204/</guid>
      <description>How to update to wireshark 1.6.7 to latest version on ububtu 12.04  0 I have wireshark 1.6.7 on ubuntu 12.04. How can i upgrade my wireshark to latest stable release
updateasked 28 May &#39;13, 09:20
tronatorx
1●1●1●1
accept rate: 0%
  
One Answer:
  
01.6.7 is the latest version available from the distro repositories for 12.04. As shown in the answers to this similar question, you can either compile from source or install from a third-party ppa.</description>
    </item>
    
    <item>
      <title>Is it possible to exporting/share profiles?</title>
      <link>/questions/21529/is-it-possible-to-exportingshare-profiles/</link>
      <pubDate>Tue, 28 May 2013 11:02:00 +0000</pubDate>
      
      <guid>/questions/21529/is-it-possible-to-exportingshare-profiles/</guid>
      <description>Is it possible to exporting/share profiles?  0 The profile definitions is an extremely versatile feature, and I have begun creating a variety of them depending on what view of the collected data I am interested in. What I have been unable to do is to share a &#34;crafted profile&#34; with co-workers or my work station at home. Is there a method to replicate a profile definition from one host to others?</description>
    </item>
    
    <item>
      <title>Can same filter macros be used from multiple profiles?</title>
      <link>/questions/21532/can-same-filter-macros-be-used-from-multiple-profiles/</link>
      <pubDate>Tue, 28 May 2013 11:12:00 +0000</pubDate>
      
      <guid>/questions/21532/can-same-filter-macros-be-used-from-multiple-profiles/</guid>
      <description>Can same filter macros be used from multiple profiles?  0 I am getting into the habit of switching between various profiles while examining a single capture, but doing so changes the set of defined filter macros. Can a single macro definition be setup to be accessible from multiple profiles?
profiles display-filterasked 28 May &#39;13, 11:12
EngAtWork
11●2●2●2
accept rate: 0%
  
2 Answers:
  
0Manually, yes.</description>
    </item>
    
    <item>
      <title>[RST, ACK] Sent to both Server and client, but neither is the sender</title>
      <link>/questions/21540/rst-ack-sent-to-both-server-and-client-but-neither-is-the-sender/</link>
      <pubDate>Tue, 28 May 2013 14:53:00 +0000</pubDate>
      
      <guid>/questions/21540/rst-ack-sent-to-both-server-and-client-but-neither-is-the-sender/</guid>
      <description>[RST, ACK] Sent to both Server and client, but neither is the sender  0 On the client we see the following sequence: 455 752.488904 47.29.0.122 24.114.118.166 TCP 76 50776 &amp;gt; http-alt [**SYN**] Seq=0 Win=5840 Len=0 MSS=1460 SACK_PERM=1 TSval=3355706 TSecr=0 WS=32 466 755.488538 47.29.0.122 24.114.118.166 TCP 76 50776 &amp;amp;gt; http-alt [**SYN**] Seq=0 Win=5840 Len=0 MSS=1460 SACK_PERM=1 TSval=3358706 TSecr=0 WS=32 467 755.507154 24.114.118.166 47.29.0.122 TCP 56 http-alt &amp;amp;gt; 50776 [**ACK**] Seq=1 Ack=1 Win=49680 Len=0 468 758.</description>
    </item>
    
    <item>
      <title>Tshark storing only a piece of data.data field</title>
      <link>/questions/21542/tshark-storing-only-a-piece-of-datadata-field/</link>
      <pubDate>Tue, 28 May 2013 15:34:00 +0000</pubDate>
      
      <guid>/questions/21542/tshark-storing-only-a-piece-of-datadata-field/</guid>
      <description>Tshark storing only a piece of data.data field  0 Looking for a way to store a portion of the data.data field. I&#39;ve tried things like data.data[0:10] or data[0:10] but in those cases nothing gets stored.
Thanks in advance!
tshark data.dataasked 28 May &#39;13, 15:34
hsingh419
11●1●1●3
accept rate: 0% 
  
2 Answers:
  
1You can look at editcap with the -s &amp;lt;snaplength&amp;gt; option to cut a given number of bytes.</description>
    </item>
    
    <item>
      <title>Extracting specific information column wise</title>
      <link>/questions/21554/extracting-specific-information-column-wise/</link>
      <pubDate>Wed, 29 May 2013 02:34:00 +0000</pubDate>
      
      <guid>/questions/21554/extracting-specific-information-column-wise/</guid>
      <description>Extracting specific information column wise  0 Hi i have a wire shark capture, in which there are specific information in each packet which i can see after decoding it as RTP. now i need those data into a csv file for further investigations. what is the procedure for getting those data in csv format.
extractasked 29 May &#39;13, 02:34
pranav s
11●1●1●2
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>proto_tree_add_item</title>
      <link>/questions/21555/proto_tree_add_item/</link>
      <pubDate>Wed, 29 May 2013 02:39:00 +0000</pubDate>
      
      <guid>/questions/21555/proto_tree_add_item/</guid>
      <description>proto_tree_add_item  0 HI,i want to see the source code of proto_tree_add_item function..
dissectorasked 29 May &#39;13, 02:39
ajain
14●6●7●11
accept rate: 0%
  
One Answer:
  
1For trunk (as of r49607), line 1792 in proto.c. For other versions, just look around in the repository.
answered 29 May &#39;13, 03:10
grahamb ♦
19.8k●3●30●206
accept rate: 22%
 edited 29 May &#39;13, 03:12 
     </description>
    </item>
    
    <item>
      <title>editcap doesn&amp;#x27;t seem to work in the new version I installed 1.8.7</title>
      <link>/questions/21560/editcap-doesnt-seem-to-work-in-the-new-version-i-installed-187/</link>
      <pubDate>Wed, 29 May 2013 06:43:00 +0000</pubDate>
      
      <guid>/questions/21560/editcap-doesnt-seem-to-work-in-the-new-version-i-installed-187/</guid>
      <description>editcap doesn&amp;rsquo;t seem to work in the new version I installed 1.8.7  0 Hi,
I am using the following command to convert from the pcap I&#39;ve got to MTP2 (E1). It worked fine in previous versions but in 1.8.7 it simply doesn&#39;t encapsulate it;
editcap.exe -T mtp2 &#34;file.pcap&#34; &#34;file_converted.pcap&#34;
Thank you, Diana
editcapasked 29 May &#39;13, 06:43
Dianalab9
26●16●16●20
accept rate: 0%
 edited 31 May &#39;13, 22:08</description>
    </item>
    
    <item>
      <title>editcap from Linux cooked capture to Ethernet packet</title>
      <link>/questions/21562/editcap-from-linux-cooked-capture-to-ethernet-packet/</link>
      <pubDate>Wed, 29 May 2013 07:08:00 +0000</pubDate>
      
      <guid>/questions/21562/editcap-from-linux-cooked-capture-to-ethernet-packet/</guid>
      <description>editcap from Linux cooked capture to Ethernet packet  0 Hi,
I am trying to convert/ encapsulation from Linux cooked capture to Ethernet packet; I am trying to use editcap and text2pcap - but don&#39;t get the desired result. can anyone advice?
Thanks in advanced, Diana
editcapasked 29 May &#39;13, 07:08
Dianalab9
26●16●16●20
accept rate: 0%
  
2 Answers:
  
2 Editcap, alone, won&#39;t help here. As I stated in a comment on your other related question, editcap does NOT transform the contents of packets; it will not, for example, take packets with Linux cooked capture headers, remove the cooked capture headers, construct Ethernet headers by:</description>
    </item>
    
    <item>
      <title>Visual studio solution file</title>
      <link>/questions/21567/visual-studio-solution-file/</link>
      <pubDate>Wed, 29 May 2013 08:31:00 +0000</pubDate>
      
      <guid>/questions/21567/visual-studio-solution-file/</guid>
      <description>Visual studio solution file  0 Hello,
has somebody created a .sln file to use Visual Studio IDE for Wireshark ? At present I use simple text editor + make, but it is not really convenient.
Thank you a lot in advance, Yuriy
visual-studioasked 29 May &#39;13, 08:31
Yuriy
11●2●2●4
accept rate: 0%
  
One Answer:
  
1Not really, there is one in the source tree but it&#39;s long out of date.</description>
    </item>
    
    <item>
      <title>More columns in endpoint statistics</title>
      <link>/questions/21577/more-columns-in-endpoint-statistics/</link>
      <pubDate>Wed, 29 May 2013 10:07:00 +0000</pubDate>
      
      <guid>/questions/21577/more-columns-in-endpoint-statistics/</guid>
      <description>More columns in endpoint statistics  0 Hi,
Is it possible to add more or edit/remove columns in Statistic-&amp;gt;Endpoints-&amp;gt;UDP? Are there column preferences somewhere for these columns? Thanks.
udp endpoints columns statisticssasked 29 May &#39;13, 10:07
nseq
1●1●1●1
accept rate: 0%
  
One Answer:
  
0No, it isn&#39;t possible through any column preference, but other columns could be added if they are useful and someone is willing to make the necessary code changes.</description>
    </item>
    
    <item>
      <title>Capture Filter for range of MAC addresses</title>
      <link>/questions/21586/capture-filter-for-range-of-mac-addresses/</link>
      <pubDate>Wed, 29 May 2013 19:30:00 +0000</pubDate>
      
      <guid>/questions/21586/capture-filter-for-range-of-mac-addresses/</guid>
      <description>Capture Filter for range of MAC addresses  0 I&#39;m attempting to create a capture filter for a range of MAC addresses.
The range of addresses is: 0009fbx6 where x can be any number
mac capture-filterasked 29 May &#39;13, 19:30
Mpking
8●3●3●6
accept rate: 0%
  
One Answer:
  
1You can create a filter that manually looks at the mac address fields in the ethernet header. Here is what the normal &#34;</description>
    </item>
    
    <item>
      <title>SSL HANDSHAKE</title>
      <link>/questions/21592/ssl-handshake/</link>
      <pubDate>Thu, 30 May 2013 05:18:00 +0000</pubDate>
      
      <guid>/questions/21592/ssl-handshake/</guid>
      <description>SSL HANDSHAKE  0 Hi,In our ssl setup i am seeing mulitple ssl client hello with sslv2 request but my netscaler is replying them with TLSV1 because sslv2 is not allowed,will this create any issue?
sslasked 30 May &#39;13, 05:18
kishan pandey
221●28●29●36
accept rate: 28%
  
One Answer:
  
0 It will only be an issue for clients that ONLY support SSLv2, but since SSLv2 is vulnerable in several ways, no client should use SSLv2 anyways these days :-)</description>
    </item>
    
    <item>
      <title>Filter for TCP source port in IPv6</title>
      <link>/questions/21594/filter-for-tcp-source-port-in-ipv6/</link>
      <pubDate>Thu, 30 May 2013 05:57:00 +0000</pubDate>
      
      <guid>/questions/21594/filter-for-tcp-source-port-in-ipv6/</guid>
      <description>Filter for TCP source port in IPv6  0 Hello,
I&#39;m trying to create a capture filter for my TCP packets. I want to filter for packets with a specific source port, lets say port 1.
My filter is &#34;tcp src port 1&#34;, and I also tried &#34;tcp and src port 1&#34;.
However, this works perfectly when I use IPv4. But when I use IPv6, it doesn&#39;t. I don&#39;t capture any packets, although the TCP header is exactly the same, I just exchanged the IP-layer.</description>
    </item>
    
    <item>
      <title>Viewing connection issues with Wireshark</title>
      <link>/questions/21604/viewing-connection-issues-with-wireshark/</link>
      <pubDate>Thu, 30 May 2013 08:39:00 +0000</pubDate>
      
      <guid>/questions/21604/viewing-connection-issues-with-wireshark/</guid>
      <description>Viewing connection issues with Wireshark  0 Hi all, I have tried to use WireShark to view traffic on certain connections to help identify why connections seemingly randomly reset. The issue seems to be, that if a connection becomes idle, no data is sent or received for some time (for example sitting idle on an irc server and only ping/ponging) the connection &#34;dies&#34; and the client will disconnect the next time it tries to write to the connection.</description>
    </item>
    
    <item>
      <title>dead link on http://wiki.wireshark.org/LDAP</title>
      <link>/questions/21606/dead-link-on-httpwikiwiresharkorgldap/</link>
      <pubDate>Thu, 30 May 2013 09:01:00 +0000</pubDate>
      
      <guid>/questions/21606/dead-link-on-httpwikiwiresharkorgldap/</guid>
      <description>dead link on http://wiki.wireshark.org/LDAP  0 see summarization of ldap link at bottom
link deadasked 30 May &#39;13, 09:01
malhenry
21●5●5●9
accept rate: 0%
  
One Answer:
  
2 Thanks for the hint, I removed the dead link.
(If you create an account, you can edit the wiki yourself too, may for the next time?)
answered 30 May &#39;13, 09:08
SYN-bit ♦♦
17.1k●9●57●245
accept rate: 20%</description>
    </item>
    
    <item>
      <title>LDAP: connection string</title>
      <link>/questions/21609/ldap-connection-string/</link>
      <pubDate>Thu, 30 May 2013 09:05:00 +0000</pubDate>
      
      <guid>/questions/21609/ldap-connection-string/</guid>
      <description>LDAP: connection string  0 Is there a way in wireshark that I can see the LDAP connection string? ie. LDAP://server:port/....
I have captured the traffic and see LDAP packets, but not sure where to look for this string.
Thanks.
ldapasked 30 May &#39;13, 09:05
malhenry
21●5●5●9
accept rate: 0%
I am trying to debug a failed bind request...thanks.
(30 May &#39;13, 09:07) malhenry  
2 Answers:</description>
    </item>
    
    <item>
      <title>Multinetted Topology Question</title>
      <link>/questions/21624/multinetted-topology-question/</link>
      <pubDate>Thu, 30 May 2013 15:15:00 +0000</pubDate>
      
      <guid>/questions/21624/multinetted-topology-question/</guid>
      <description>Multinetted Topology Question  0 Load Balancer port is connected to a switch and switch in turn connected to 3 servers in 3 VLANS(VlanX,VlanY,VlanZ).The port on the loadbalancer connected to switch is multinetted(hosting all 3 subnets of Servers and a tagged port which is member of all three VLANs).
If a server in VLANX needs to ping server in VLANY then packet needs to come to loadbalancer(As LB is configured as the default gateway )and LB will route it to destination system which is in VLANY.</description>
    </item>
    
    <item>
      <title>what&amp;#x27;s the meaning of &amp;quot;C： S: &amp;quot; of the package?</title>
      <link>/questions/21630/whats-the-meaning-of-c-s-of-the-package/</link>
      <pubDate>Thu, 30 May 2013 20:38:00 +0000</pubDate>
      
      <guid>/questions/21630/whats-the-meaning-of-c-s-of-the-package/</guid>
      <description>what&amp;rsquo;s the meaning of &amp;ldquo;C： S: &amp;quot; of the package?  0 some packages like these:
The following dialog illustrates how a client and server can start a TLS session:
S: &amp;lt;waits for=&#34;&#34; connection=&#34;&#34; on=&#34;&#34; tcp=&#34;&#34; port=&#34;&#34; 25=&#34;&#34;&amp;gt;
C: &amp;lt;opens connection=&#34;&#34;&amp;gt;
S: 220 mail.imc.org SMTP service ready
C: EHLO mail.ietf.org
S: 250-mail.imc.org offers a warm hug of welcome
S: 250 STARTTLS
packge tagasked 30 May &#39;13, 20:38
vivianlawrence
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark isn&amp;#x27;t detecting my 3G modem</title>
      <link>/questions/21633/wireshark-isnt-detecting-my-3g-modem/</link>
      <pubDate>Thu, 30 May 2013 22:11:00 +0000</pubDate>
      
      <guid>/questions/21633/wireshark-isnt-detecting-my-3g-modem/</guid>
      <description>Wireshark isn&amp;rsquo;t detecting my 3G modem  0 My Huawei 3G USB modem is not listed on the interface list. I am using Wireshark(1.8.7) on Windows8-64bit. My device is Huawei E1550(model)..
This device used to work with Wireshark(1.6.8) on windows7-32bit....
huawei modem 3gasked 30 May &#39;13, 22:11
ska00sh
1●1●1●1
accept rate: 0%
 edited 31 May &#39;13, 11:28 
Guy Harris ♦♦
17.4k●3●35●196
  
2 Answers:</description>
    </item>
    
    <item>
      <title>how to view GSM/MAP Operation with tshark statistics</title>
      <link>/questions/21641/how-to-view-gsmmap-operation-with-tshark-statistics/</link>
      <pubDate>Fri, 31 May 2013 01:37:00 +0000</pubDate>
      
      <guid>/questions/21641/how-to-view-gsmmap-operation-with-tshark-statistics/</guid>
      <description>how to view GSM/MAP Operation with tshark statistics  1 I want to view statistics with tshark command the same way it&#39;s done on Wireshark with GSM/MAP Operation Statistics window, which is on Telephony-&amp;gt;GSM-&amp;gt;GSM/MAP Operation. When I view tshark -z help I see only sctp or gsm_a, which are not equal to MAP operation statistics.
Can anyone help with this?
statistics gsm tshark gsm_mapasked 31 May &#39;13, 01:37
Edmond
181●3●6●14</description>
    </item>
    
    <item>
      <title>Display Filter</title>
      <link>/questions/21648/display-filter/</link>
      <pubDate>Fri, 31 May 2013 04:31:00 +0000</pubDate>
      
      <guid>/questions/21648/display-filter/</guid>
      <description>Display Filter  0 I&#39;ve created list of ip.dst, with I do not need to view, using command &#34;Apply as Filter - and not selected&#34; by context menu: here it is:
(((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((!(ip.dst == 213.155.152.137)) &amp;amp;&amp;amp; !(ip.dst == 192.168.1.1)) &amp;amp;&amp;amp; !(ip.dst == 192.168.1.3)) &amp;amp;&amp;amp; !(ip.dst == 31.170.163.90)) &amp;amp;&amp;amp; !(ip.dst == 31.170.164.249)) &amp;amp;&amp;amp; !(ip.dst == 213.155.152.160)) &amp;amp;&amp;amp; !(ip.dst == 173.194.40.24)) &amp;amp;&amp;amp; !(ip.dst == 173.194.39.87)) &amp;amp;&amp;amp; !(ip.dst == 173.194.39.175)) &amp;amp;&amp;amp; !(ip.dst == 80.239.149.82)) &amp;amp;&amp;amp; !</description>
    </item>
    
    <item>
      <title>Which device/setup could create duplicate tcp acks ?</title>
      <link>/questions/21649/which-devicesetup-could-create-duplicate-tcp-acks/</link>
      <pubDate>Fri, 31 May 2013 04:50:00 +0000</pubDate>
      
      <guid>/questions/21649/which-devicesetup-could-create-duplicate-tcp-acks/</guid>
      <description>Which device/setup could create duplicate tcp acks ?  0 Hello, i´m troubeshooting an network issue in our network environment. What i see is a high number (up to 400%) of duplicated tcp acknowledgements in our traffic. The timestamps of these packet are neary equal. The percentage of regular tcp packets is real low ( &amp;lt;1%). So the only duplicated packets are the tcp acks.
This are three packets i´ve captured:</description>
    </item>
    
    <item>
      <title>SSL DH GROUP</title>
      <link>/questions/21650/ssl-dh-group/</link>
      <pubDate>Fri, 31 May 2013 05:01:00 +0000</pubDate>
      
      <guid>/questions/21650/ssl-dh-group/</guid>
      <description>SSL DH GROUP  0 In what condition ssl will use diffi helman keys because generally it uses RSA.
sslasked 31 May &#39;13, 05:01
kishan pandey
221●28●29●36
accept rate: 28%
  
One Answer:
  
0That depends on the configuration of the client and/or the server as well as on the capabilities (software release) of either.
Regards
Kurt
answered 31 May &#39;13, 07:57
Kurt Knochner ♦
24.8k●10●39●237</description>
    </item>
    
    <item>
      <title>RTP call flow discrimination</title>
      <link>/questions/21652/rtp-call-flow-discrimination/</link>
      <pubDate>Fri, 31 May 2013 05:58:00 +0000</pubDate>
      
      <guid>/questions/21652/rtp-call-flow-discrimination/</guid>
      <description>RTP call flow discrimination  0 Hi all,
What about two RTP flows (two calls: another call just a few seconds after the first call with the same caller-callee) with the same IPs and ports (is it possible ???):
first call (at time t): caller: IP:192.168.100.6 port:3000 &amp;lt;-&amp;gt; callee: IP:192.168.100.7 port 12687
second call (at t+10 second, for example): caller: IP:192.168.100.6 port:3000 &amp;lt;-&amp;gt; callee: IP:192.168.100.7 port 12687
In this case, how to descriminate both flows .</description>
    </item>
    
    <item>
      <title>Oversized ethernet frames on Crubuntu Chromebook</title>
      <link>/questions/21653/oversized-ethernet-frames-on-crubuntu-chromebook/</link>
      <pubDate>Fri, 31 May 2013 07:31:00 +0000</pubDate>
      
      <guid>/questions/21653/oversized-ethernet-frames-on-crubuntu-chromebook/</guid>
      <description>Oversized ethernet frames on Crubuntu Chromebook  0 I have a Chromebook that is running chrubuntu. I&#39;ve tried capturing my traffic (on my host) with Wireshark and tcpdump with the same result - I&#39;m getting a lot of frames that are over 1700 bytes in size. This is highly unusual as the network doesn&#39;t support jumbo frames and the MTU on the NIC is set to 1500. Wireshark also complains that these packets have a ethernet frame check sequence error.</description>
    </item>
    
    <item>
      <title>Is there a way to only show streams?</title>
      <link>/questions/21666/is-there-a-way-to-only-show-streams/</link>
      <pubDate>Fri, 31 May 2013 08:14:00 +0000</pubDate>
      
      <guid>/questions/21666/is-there-a-way-to-only-show-streams/</guid>
      <description>Is there a way to only show streams?  0 By default, Wireshark shows the entire packet breakdown in the order that it captured the packets split across three frames. Pretty much the only thing I ever do with Wireshark is reverse engineer captured HTTP requests. This basically amounts to Wireshark&#39;s default UI getting in the way of seeing the request and response - all three frames of the main UI are nearly useless to me.</description>
    </item>
    
    <item>
      <title>Possible Proxy server issues</title>
      <link>/questions/21671/possible-proxy-server-issues/</link>
      <pubDate>Fri, 31 May 2013 08:52:00 +0000</pubDate>
      
      <guid>/questions/21671/possible-proxy-server-issues/</guid>
      <description>Possible Proxy server issues  0 Noob middleware guys here. We have a websphere app that works fine externally, but from within the office it consistantly gets &#39;page cannot be displayed&#39; errors. We suspect the app and proxy server are not playing well together. A network guy traced all machines involved for me as I recreated the issue. I&#39;ve opened them in Wireshark ... and am stuck. Can anyone suggest the best way to filter, pick out errors, anything I should try first to start troubleshooting.</description>
    </item>
    
    <item>
      <title>WIRESHARK GRAPH</title>
      <link>/questions/21678/wireshark-graph/</link>
      <pubDate>Fri, 31 May 2013 09:27:00 +0000</pubDate>
      
      <guid>/questions/21678/wireshark-graph/</guid>
      <description>WIRESHARK GRAPH  0 How to read output from tcp stevens graph?
tcpasked 31 May &#39;13, 09:27
kishan pandey
221●28●29●36
accept rate: 28%
  
One Answer:
  
0It&#39;s TCP sequence numbers as they increment over time. It&#39;s a useful spotcheck for some TCP performance problems. For example if there is packet loss and Wireshark is in a spot to catch the retransmissions, you&#39;ll see the same Y value at two or more spots on the graph rather than a constant incline.</description>
    </item>
    
    <item>
      <title>tshark truncated records - why can&amp;#x27;t we get the full record?</title>
      <link>/questions/21688/tshark-truncated-records-why-cant-we-get-the-full-record/</link>
      <pubDate>Sun, 02 Jun 2013 00:46:00 +0000</pubDate>
      
      <guid>/questions/21688/tshark-truncated-records-why-cant-we-get-the-full-record/</guid>
      <description>tshark truncated records - why can&amp;rsquo;t we get the full record?  0 I understand how to see the full non-truncated record (in my case it&#39;s the actual HTML page that I&#39;m trying to read, and it contains long lines) in Wireshark - it&#39;s a clicking operation to copy into the buffer. But I want to do the same in tshark, so as to automate it. So far from Google I&#39;ve found at least one person asking this, and the response was that the 240 char limit is hardcoded and would not be feasible to make dynamic, therefore you would have to make your own build of Wireshark.</description>
    </item>
    
    <item>
      <title>Hex Dump off slightly</title>
      <link>/questions/21692/hex-dump-off-slightly/</link>
      <pubDate>Sun, 02 Jun 2013 09:45:00 +0000</pubDate>
      
      <guid>/questions/21692/hex-dump-off-slightly/</guid>
      <description>Hex Dump off slightly  0 Hello,
I am developing a program using libpcap to capture Beacon Frames, Probe Requests and Probe Responses from my wireless interface that I specify. When I try and hex dump the packet and look at the packet it is slightly off compared to what I am seeing in Wireshark, so I was wondering why this is and if you guys do something special to the hex dump before you dump it?</description>
    </item>
    
    <item>
      <title>dns.time from FIRST DNS Request</title>
      <link>/questions/21694/dnstime-from-first-dns-request/</link>
      <pubDate>Sun, 02 Jun 2013 15:50:00 +0000</pubDate>
      
      <guid>/questions/21694/dnstime-from-first-dns-request/</guid>
      <description>dns.time from FIRST DNS Request  0 I am trying to track down the source of some browsing issues and I believe I have narrowed it down to a DNS issue. I can filter on a specific transaction ID and manually calculate the time between the first request and the reply, but I am looking for a way to automatically calculate the data and create an IO graph. Using dns.time only shows the time since the last request and the reply, whereas I would like to see the time between the first request and reply.</description>
    </item>
    
    <item>
      <title>Am I able to use Wireshark given this condition?</title>
      <link>/questions/21695/am-i-able-to-use-wireshark-given-this-condition/</link>
      <pubDate>Sun, 02 Jun 2013 18:32:00 +0000</pubDate>
      
      <guid>/questions/21695/am-i-able-to-use-wireshark-given-this-condition/</guid>
      <description>Am I able to use Wireshark given this condition?  0 Hi guys,
I am currently living in a hostel and connect to the internet via the hostel&#39;s centralized router.
I am trying out a software and wish to find out whether it calls home, that is, capture data packets from my OS and send them to the software vendor.
Can I use Wireshark to see whether the software in question send data packets back to the software vendor?</description>
    </item>
    
    <item>
      <title>Decrypting the Encrypted Data taken from wireshark</title>
      <link>/questions/21699/decrypting-the-encrypted-data-taken-from-wireshark/</link>
      <pubDate>Sun, 02 Jun 2013 22:58:00 +0000</pubDate>
      
      <guid>/questions/21699/decrypting-the-encrypted-data-taken-from-wireshark/</guid>
      <description>Decrypting the Encrypted Data taken from wireshark  0 I&#39;m using Perl Rijndael(Aes) module to decrypt the Data which is taken from Wireshark. The cipher suite used is TLS_DHE_RSA_AES_256_CBC_SHA. I want to do the same as like wireshark is decrypting the packets.I fed Client write key and Client IV which is taken from the wireshark debug logs to the Perl module.First 16 bytes of the data are not decrypted properly Rest of the bytes are decrypted fine.</description>
    </item>
    
    <item>
      <title>Can a client (application) tell the server it&amp;#x27;s receive window is full?</title>
      <link>/questions/21702/can-a-client-application-tell-the-server-its-receive-window-is-full/</link>
      <pubDate>Mon, 03 Jun 2013 00:17:00 +0000</pubDate>
      
      <guid>/questions/21702/can-a-client-application-tell-the-server-its-receive-window-is-full/</guid>
      <description>Can a client (application) tell the server it&amp;rsquo;s receive window is full?  0 Hi all,
i&#39;ve got a trace where it looks like a client tells the server it&#39;s receive window is full... Then the server backs of and ACKs all outstanding/received data (then we see it&#39;s rec window deplete) and then sends a window update to the client to start sending again. The client sends data quickly thinks the rec window of the server is full again, throttles back but server (again!</description>
    </item>
    
    <item>
      <title>Issue with HTTP</title>
      <link>/questions/21711/issue-with-http/</link>
      <pubDate>Mon, 03 Jun 2013 02:46:00 +0000</pubDate>
      
      <guid>/questions/21711/issue-with-http/</guid>
      <description>Issue with HTTP  0 we are facing slowness issue with only one of our website .
It is not opening any webpages.
When running Wireshark from client PC we see intial 3 way handshake is fine , but after that suddenly we are getting destination host unreachable and TCP-Out-of-order.
16 24.621544 192.168.1.10 10.150.0.40 TCP 985 [TCP segment of a reassembled PDU] 17 24.621754 10.150.0.40 192.168.1.10 ICMP 81 Destination unreachable (Fragmentation needed) 18 24.</description>
    </item>
    
    <item>
      <title>Dissector for Oracle JMS</title>
      <link>/questions/21714/dissector-for-oracle-jms/</link>
      <pubDate>Mon, 03 Jun 2013 06:20:00 +0000</pubDate>
      
      <guid>/questions/21714/dissector-for-oracle-jms/</guid>
      <description>Dissector for Oracle JMS  0 Hi So, does wireshark have dissectors for Oracle JMS API? If yes, please give me some info about it. Thanks in advance.
regards
oracle jms dissectorasked 03 Jun &#39;13, 06:20
Jakub
11●1●1●2
accept rate: 0%
 converted to question 06 Jun &#39;13, 05:22 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
0Please see the answer to the following question:
http://ask.wireshark.org/questions/13989/how-to-configure-wireshark-to-decodedisect-jms</description>
    </item>
    
    <item>
      <title>How to display some UDP missing packets?</title>
      <link>/questions/21715/how-to-display-some-udp-missing-packets/</link>
      <pubDate>Mon, 03 Jun 2013 09:08:00 +0000</pubDate>
      
      <guid>/questions/21715/how-to-display-some-udp-missing-packets/</guid>
      <description>How to display some UDP missing packets?  0 Hello, I want to watch some packets of an unknown protocol which relies on UDP, but Wireshark doesn&#39;t display these packets. Why does Wireshark do this? What can I do? I can&#39;t believe I must write a dissector to display it. Wireshark should at least display the payload under UDP protocol.
udp packets missingasked 03 Jun &#39;13, 09:08
anon321123
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Prolonged Capture / chatty network</title>
      <link>/questions/21718/prolonged-capture-chatty-network/</link>
      <pubDate>Mon, 03 Jun 2013 12:14:00 +0000</pubDate>
      
      <guid>/questions/21718/prolonged-capture-chatty-network/</guid>
      <description>Prolonged Capture / chatty network  0 I want to do a prolonged capture (24 hours) segmented into either 24 or 48 capture files (depending on size).
Here is my issue... I&#39;m scanning an uplink port on a main switch that basically captures all local / inbound /outbound traffic.
We don&#39;t have a huge network (~ 200 workstation/servers + ~50 other network devices), but my dump files are pretty huge.</description>
    </item>
    
    <item>
      <title>Slow NFS dup ack</title>
      <link>/questions/21722/slow-nfs-dup-ack/</link>
      <pubDate>Mon, 03 Jun 2013 19:19:00 +0000</pubDate>
      
      <guid>/questions/21722/slow-nfs-dup-ack/</guid>
      <description>Slow NFS dup ack  0 Hi,
I am experiencing slow performance from my VNX NFS server (primarily reads). When performing a TCP capture on the VNX (server) and HP (client) I notice there are many &#34;dup ack&#34; and &#34;out of order&#34; packets. Currently I have jumbo frames configured on both the VNX and HP servers, I have been assured that jumbo frames are configured on all switches between the devices.</description>
    </item>
    
    <item>
      <title>MAC (reverse) name resolution in tshark</title>
      <link>/questions/21730/mac-reverse-name-resolution-in-tshark/</link>
      <pubDate>Mon, 03 Jun 2013 23:52:00 +0000</pubDate>
      
      <guid>/questions/21730/mac-reverse-name-resolution-in-tshark/</guid>
      <description>MAC (reverse) name resolution in tshark  1 Hi,
I have few MAC addresses where the OUI portions have been resolved: e.g. Intel_05:04:03.
Is it possible to use tshark to get the actual MAC address for each of my “name resolved” address? E.g. get 02:A0:C9:05:04:03 from Intel_05:04:03?
If this is not possible with tshark, what would would be the easiest way to achieve this on a linux host?
Many thanks.</description>
    </item>
    
    <item>
      <title>How can I read the whole WLAN?</title>
      <link>/questions/21733/how-can-i-read-the-whole-wlan/</link>
      <pubDate>Tue, 04 Jun 2013 01:55:00 +0000</pubDate>
      
      <guid>/questions/21733/how-can-i-read-the-whole-wlan/</guid>
      <description>How can I read the whole WLAN?  0 Hey, I&#39;m new to Wireshark and I want to use it to improve my understanding of networks and protocols. What I want to do is: receive all packages in my WLAN for example packages sent/received by my phone.
Is there a way to do that? &#34;Capture all in promiscuous mode&#34; doesn&#39;t seem to do it. So how can I get this work?</description>
    </item>
    
    <item>
      <title>How can I capture traffic of devices which are connected to my Wifi Modem?</title>
      <link>/questions/21742/how-can-i-capture-traffic-of-devices-which-are-connected-to-my-wifi-modem/</link>
      <pubDate>Tue, 04 Jun 2013 11:15:00 +0000</pubDate>
      
      <guid>/questions/21742/how-can-i-capture-traffic-of-devices-which-are-connected-to-my-wifi-modem/</guid>
      <description>How can I capture traffic of devices which are connected to my Wifi Modem?  0 I am a new user of Wireshark, any one please help me that how I capture the traffic of devices which are cnnected to my Wifi modem. These devices may be mobiles or PC/laptops.
captureasked 04 Jun &#39;13, 11:15
MuhammadToseef
11●1●1●3
accept rate: 0%
 edited 04 Jun &#39;13, 11:17</description>
    </item>
    
    <item>
      <title>DNS query for ssh hostname</title>
      <link>/questions/21754/dns-query-for-ssh-hostname/</link>
      <pubDate>Tue, 04 Jun 2013 18:09:00 +0000</pubDate>
      
      <guid>/questions/21754/dns-query-for-ssh-hostname/</guid>
      <description>DNS query for ssh hostname  0 Hi all, I installed a Redhat system and configured hostname for the machine say redhatlinux6.4. From Window2K8 server i tried to putty this machine with hostname but not IP address(I ensured /etc/hosts on windows system is not having hostname to IP mapping of Linux machine) as expected the putty connection failed but i didn&#39;t find any dns queries in wireshark which i am hoping to get generated by the client to find out the ipaddress of the hostname.</description>
    </item>
    
    <item>
      <title>Disabling generated field</title>
      <link>/questions/21764/disabling-generated-field/</link>
      <pubDate>Wed, 05 Jun 2013 07:18:00 +0000</pubDate>
      
      <guid>/questions/21764/disabling-generated-field/</guid>
      <description>Disabling generated field  0 Hello, is it possible to disable generated fields in packet details windows? E.g. disabling Response To, Response time, Timestamp relative in ICMP echo request. I would like to view only &#34;pure&#34; header without automatic generated fields. Thanks
field generatedasked 05 Jun &#39;13, 07:18
couker
6●1●1●2
accept rate: 0%
  
One Answer:
  
1 No, it&#39;s not.
answered 05 Jun &#39;13, 09:59</description>
    </item>
    
    <item>
      <title>Filter FTP</title>
      <link>/questions/21765/filter-ftp/</link>
      <pubDate>Wed, 05 Jun 2013 08:18:00 +0000</pubDate>
      
      <guid>/questions/21765/filter-ftp/</guid>
      <description>Filter FTP  0 Hi, I have been asked to run Wireshark on a server using an FTP filter but can&#39;t seem to find the right way to do this....can anyone assist?
ftp server wiresharkasked 05 Jun &#39;13, 08:18
sharwal
11●3●3●4
accept rate: 0%
  
One Answer:
  
0On display filter For FTP Control connection do tcp.port==21 and For FTP Data connection do tcp.port==20 For both(tcp.port==21 || tcp.</description>
    </item>
    
    <item>
      <title>Capture traffic while filtering</title>
      <link>/questions/21771/capture-traffic-while-filtering/</link>
      <pubDate>Wed, 05 Jun 2013 10:00:00 +0000</pubDate>
      
      <guid>/questions/21771/capture-traffic-while-filtering/</guid>
      <description>Capture traffic while filtering  0 Hi, I want to start Wireshark and continue saving to a text file WHILE the capture/filter is running...but it seems I can only save the capture once I stop it, is there any way to save it while it is running?
capture filtering ftpasked 05 Jun &#39;13, 10:00
sharwal
11●3●3●4
accept rate: 0%
  
One Answer:
  
0Yes. Assuming you have the latest version, click on the Capture Interfaces button on the far left-hand side, select the interface(s) you want to capture, and click Options.</description>
    </item>
    
    <item>
      <title>Soft Phone Unregistering</title>
      <link>/questions/21778/soft-phone-unregistering/</link>
      <pubDate>Wed, 05 Jun 2013 13:19:00 +0000</pubDate>
      
      <guid>/questions/21778/soft-phone-unregistering/</guid>
      <description>Soft Phone Unregistering  0 Hi Experts,
I am hoping to get some advice on what I am seeing in the trace:
http://www.cloudshark.org/captures/b519beceeb7a
We have a soft phone that keeps getting disconnected and hence a wireshark capture was attempted.
I am trying to understand the significance of packets 93-96 with regards to it being unseen segments/uncaptured segments.
For packet 93, the sequence number is 2161 with the len as 54. I guess I would expect to see the ACK to be 2215 and not 2259 in packet 94.</description>
    </item>
    
    <item>
      <title>stream graph for rtt</title>
      <link>/questions/21781/stream-graph-for-rtt/</link>
      <pubDate>Wed, 05 Jun 2013 15:56:00 +0000</pubDate>
      
      <guid>/questions/21781/stream-graph-for-rtt/</guid>
      <description>stream graph for rtt  0 Hi, while using stream graph for rtt it shows a single point in graph for the selected packet.if i mark packets it shows pints for the marked packets in the graph. How to get graph for the whole pcap file or for a set of packets in the file?
rtt streamgraphasked 05 Jun &#39;13, 15:56
SThomas
1●2●2●3
accept rate: 0% 
 edited 05 Jun &#39;13, 15:57</description>
    </item>
    
    <item>
      <title>I need monitoring tcp-, udp-session at network segment. How can I do it?</title>
      <link>/questions/21792/i-need-monitoring-tcp-udp-session-at-network-segment-how-can-i-do-it/</link>
      <pubDate>Thu, 06 Jun 2013 04:02:00 +0000</pubDate>
      
      <guid>/questions/21792/i-need-monitoring-tcp-udp-session-at-network-segment-how-can-i-do-it/</guid>
      <description>I need monitoring tcp-, udp-session at network segment. How can I do it?  0 Hello,
Can i to monitor tcp-, udp-session with wireshark?
session per second.syssion by hour, by day?Thank&#39;s
sessionsasked 06 Jun &#39;13, 04:02
junglend
1●1●1●2
accept rate: 0%
 edited 10 Jun &#39;13, 08:25 
Kurt Knochner ♦
24.8k●10●39●237
If I understand the question, you want to graph the number of sessions establishes per second? The number of sessions that are being established per second?</description>
    </item>
    
    <item>
      <title>How to print decibel values?</title>
      <link>/questions/21812/how-to-print-decibel-values/</link>
      <pubDate>Fri, 07 Jun 2013 00:00:00 +0000</pubDate>
      
      <guid>/questions/21812/how-to-print-decibel-values/</guid>
      <description>How to print decibel values?  0 Wireshark capture results show -127.876344 dBm corresponding to HEX values D6 5B CC D8. Please, let me know how to incorporate this conversion in my dissector file.
dbmasked 07 Jun &#39;13, 00:00
sunshine
16●5●5●9
accept rate: 0%
Can you paste some (4-5) samples with their hexadecimal reprensentation
(08 Jun &#39;13, 02:00) mrEEde2There are several places where Wireshark reports a value in dBm. Some of them encode it as an 8-bit value, so it only corresponds to one hex digit.</description>
    </item>
    
    <item>
      <title>How is RTT calculated</title>
      <link>/questions/21813/how-is-rtt-calculated/</link>
      <pubDate>Fri, 07 Jun 2013 00:49:00 +0000</pubDate>
      
      <guid>/questions/21813/how-is-rtt-calculated/</guid>
      <description>How is RTT calculated  0 i would like to know how wireshark is calculating rtt? is it cosidering delayed ack&#39;s, piggybacked acks and retransmitted packets.If it is not considered how do i incoorporate/filter these in calcuting rtt
calculation rttasked 07 Jun &#39;13, 00:49
SThomas
1●2●2●3
accept rate: 0%
 converted 07 Jun &#39;13, 01:48 
grahamb ♦
19.8k●3●30●206
  
2 Answers:
  
1The Wireshark initial Round Trip Time (iRTT) value is calculated when the first two packets of a TCP handshake are seen {SYN, SYN/ACK}.</description>
    </item>
    
    <item>
      <title>Slow download speed</title>
      <link>/questions/21814/slow-download-speed/</link>
      <pubDate>Fri, 07 Jun 2013 06:11:00 +0000</pubDate>
      
      <guid>/questions/21814/slow-download-speed/</guid>
      <description>Slow download speed  0 We are facing slow download speed issue with one of our server .
Running trace from client PC shows below output.
Could someone please help identify cause of this slow download speed.
10.225.0.10 is IP of client.
192.168.1.10 IP of Server
72 0.131254000 0.000000000 10.225.0.10 192.168.1.10 TCP 66 64104 &amp;gt; http [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=4 SACK_PERM=1 73 0.000001000 0.000000000 10.225.0.10 192.168.1.10 TCP 66 64103 &amp;gt; http [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=4 SACK_PERM=1 74 0.</description>
    </item>
    
    <item>
      <title>how to get decoded data of jn5148 using eclipse</title>
      <link>/questions/21815/how-to-get-decoded-data-of-jn5148-using-eclipse/</link>
      <pubDate>Fri, 07 Jun 2013 06:23:00 +0000</pubDate>
      
      <guid>/questions/21815/how-to-get-decoded-data-of-jn5148-using-eclipse/</guid>
      <description>how to get decoded data of jn5148 using eclipse  0 I am a newbie . we are using NXP &#39;s jn518 ek 010 and I am using jennet stack . we are using win 7 and for application development we are using eclipse . our project task is to get the temperature , humidity and luminosity sensors value on PC , from which decision making will be proceeded. can any one guide me how to get these values in human readable format?</description>
    </item>
    
    <item>
      <title>incoming TCP Retransmissions saturate WAN</title>
      <link>/questions/21842/incoming-tcp-retransmissions-saturate-wan/</link>
      <pubDate>Sun, 09 Jun 2013 07:16:00 +0000</pubDate>
      
      <guid>/questions/21842/incoming-tcp-retransmissions-saturate-wan/</guid>
      <description>incoming TCP Retransmissions saturate WAN  0 My internet slowed to a halt, and after checking the obvious things I suspected a DOS attack. Wireshark shows an astronomical number of TCP retransmissions coming from an IP on the internet. What does this mean?Pcap file: http://www.cloudshark.org/captures/64f2c70a977c
dos dsl retransmissions tcpasked 09 Jun &#39;13, 07:16
staticchanger
11●1●1●3
accept rate: 0%
 edited 09 Jun &#39;13, 10:36 
indeed looks like DOS, especially since the delta times in no way fit retransmission intervals.</description>
    </item>
    
    <item>
      <title>my network adapter doesn&amp;#x27;t support any wifi hack soft</title>
      <link>/questions/21843/my-network-adapter-doesnt-support-any-wifi-hack-soft/</link>
      <pubDate>Sun, 09 Jun 2013 07:56:00 +0000</pubDate>
      
      <guid>/questions/21843/my-network-adapter-doesnt-support-any-wifi-hack-soft/</guid>
      <description>my network adapter doesn&amp;rsquo;t support any wifi hack soft  0 hai guys,my network adapters are:&#34;QUALCOMM ATHEROS AR5BWB222&#34;, and some like &#34;MICROSOFT KERNAL DEBUG NETWORK ADAPTOR&#34;IN WIN 7&amp;amp;WIN 8 had 4gb ram, INTEL I3 PROCESSOR at ACER WITH supported drivers for both respectively and adapters are working fine,I had tried many many wifi hack soft like wire shark,port analyzer,network stumbler,commview for wifi,air crack,winpcap,airpcap,ether detect,cfos.but neither soft didn&#39;t capture any packets,I WANT ANY SOFT THAT CAN CAPTURE PACKETS AND SAVE.</description>
    </item>
    
    <item>
      <title>add P25 to default build of Wireshark?</title>
      <link>/questions/21858/add-p25-to-default-build-of-wireshark/</link>
      <pubDate>Sun, 09 Jun 2013 12:28:00 +0000</pubDate>
      
      <guid>/questions/21858/add-p25-to-default-build-of-wireshark/</guid>
      <description>add P25 to default build of Wireshark?  0 Would it be possible for any of the developer people of the Macintosh OSX flavor of Wireshark to add the APCO P25 decoder to its default build in a future release in the near future? I&#39;m not smart enough to do it. More information at op25.osmocom.org(slash)trac(slash)wiki.png(slash)wiki(slash)WireSharkPage as to where to obtain the P25 source code. Thanx
p25 addasked 09 Jun &#39;13, 12:28</description>
    </item>
    
    <item>
      <title>txpower dBm rate</title>
      <link>/questions/21864/txpower-dbm-rate/</link>
      <pubDate>Sun, 09 Jun 2013 21:06:00 +0000</pubDate>
      
      <guid>/questions/21864/txpower-dbm-rate/</guid>
      <description>txpower dBm rate  0 Hey I am interested in sniffing packets and monitoring their tx power dBm rate on linux. How do i do that? I tried many things: - I right click on the columns tool bar and click &#34;edit columns Details&#34; select &#34;ieee802.11 Tx rate&#34; - the column does not show me anything - no information. - I tried to filter the packets by a certain tx power using radiotap.</description>
    </item>
    
    <item>
      <title>wireshark auditing</title>
      <link>/questions/21872/wireshark-auditing/</link>
      <pubDate>Mon, 10 Jun 2013 04:24:00 +0000</pubDate>
      
      <guid>/questions/21872/wireshark-auditing/</guid>
      <description>wireshark auditing  0 Hi,
i have dedicated linux server for running wireshark in order to do network analysis when needed. It has very restrictive access but anyway we would like to achieve some sort of logging of what and when are users capturing using wireshark on this machine. Since wireshark and its utilites are not providing any logging capabilities i wonder how can we achieve logging.
I was thinking about writing warpper around /usb/bin/dumpcap in order to generate syslog messages and spawn the real dumpcap binary.</description>
    </item>
    
    <item>
      <title>Upgrade 1.8.7 to 1.10.0: Wireshark leaves a permission mess</title>
      <link>/questions/21885/upgrade-187-to-1100-wireshark-leaves-a-permission-mess/</link>
      <pubDate>Mon, 10 Jun 2013 09:54:00 +0000</pubDate>
      
      <guid>/questions/21885/upgrade-187-to-1100-wireshark-leaves-a-permission-mess/</guid>
      <description>Upgrade 1.8.7 to 1.10.0: Wireshark leaves a permission mess  0 Hi there,
here I&#39;m on Windows 7 x64 Professional. Wireshark 1.8.7 was installed and I just recently downloaded 1.10.0 (the checksums were correct). I started the setup which wanted to uninstall 1.8.7 first (just as usual when upgrading Wireshark). This seems to go fine, but as soon as the installer starts, it shows me this error:
Well, the problem seems to be a complete permission fuckup of my folder C:\Program Files\Wireshark - now I don&#39;t have any rights to access this folder.</description>
    </item>
    
    <item>
      <title>Lua script eating memory</title>
      <link>/questions/21898/lua-script-eating-memory/</link>
      <pubDate>Mon, 10 Jun 2013 12:17:00 +0000</pubDate>
      
      <guid>/questions/21898/lua-script-eating-memory/</guid>
      <description>Lua script eating memory  0 I have run a Lua script on tshark on many capture files i have, but if i run this files sequentially i see that the number of packets is decreasing means that i am loosing some data. So I had to restart CMD every time to run the Lua script throw tshark. I asking is this from the memory eating effect?? if so is there any garbage collection tool for cleaning the memory ?</description>
    </item>
    
    <item>
      <title>filter for streaming video content</title>
      <link>/questions/21899/filter-for-streaming-video-content/</link>
      <pubDate>Mon, 10 Jun 2013 12:37:00 +0000</pubDate>
      
      <guid>/questions/21899/filter-for-streaming-video-content/</guid>
      <description>filter for streaming video content  0 i want to filter out streaming media...audio,video,flash. will http.type.content=video or flash catch the offenders and sites?? or is there more to it. I think I should be seeing more, than what I am getting returned.
media filtersasked 10 Jun &#39;13, 12:37
mickeyhr
1●1●1●1
accept rate: 0%
  
One Answer:
  
0or is there more to it.
There is much more to it, as there is no unique standard for &#34;</description>
    </item>
    
    <item>
      <title>random access read and dissection of packets from a pcap file</title>
      <link>/questions/21900/random-access-read-and-dissection-of-packets-from-a-pcap-file/</link>
      <pubDate>Mon, 10 Jun 2013 12:42:00 +0000</pubDate>
      
      <guid>/questions/21900/random-access-read-and-dissection-of-packets-from-a-pcap-file/</guid>
      <description>random access read and dissection of packets from a pcap file  0 Hello all,
I&#39;m trying to do random access read on a growing pcap file, (program keeps track of previous EOF and then try to restart reading from this mark on growing file), for this i&#39;m using fseek and ftell functions. But problem i&#39;m facing is that, when i go to read the file second time ,from previous EOF, pcap_open_offline shows error &#34;</description>
    </item>
    
    <item>
      <title>ldap simple bind</title>
      <link>/questions/21902/ldap-simple-bind/</link>
      <pubDate>Mon, 10 Jun 2013 14:23:00 +0000</pubDate>
      
      <guid>/questions/21902/ldap-simple-bind/</guid>
      <description>ldap simple bind  0 When I look at an LDAP v3 bind request in the packet details pane under authentication: simple (0), I see simple: followed by a 20 digit number. What does this represent?
Thanks
malhenry ldapasked 10 Jun &#39;13, 14:23
malhenry
21●5●5●9
accept rate: 0%
I am referring to the 20 digit number.
(10 Jun &#39;13, 14:24) malhenry  
2 Answers:
  
1 I see simple: followed by a 20 digit number.</description>
    </item>
    
    <item>
      <title>Can wireshark decrypted abbreviated TLS/SSL handshakes?</title>
      <link>/questions/21911/can-wireshark-decrypted-abbreviated-tlsssl-handshakes/</link>
      <pubDate>Tue, 11 Jun 2013 03:14:00 +0000</pubDate>
      
      <guid>/questions/21911/can-wireshark-decrypted-abbreviated-tlsssl-handshakes/</guid>
      <description>Can wireshark decrypted abbreviated TLS/SSL handshakes?  0 In my particular case, there seem to be multiple abbreviated handshakes performed after the initial session creating full handshake, and these use multiple additional ports. Decryption is failing, and I am seeing &#34;mac failed&#34; errors in the ssl debug log. I&#39;m wondering if this is caused by the abbreviated handshakes? I can&#39;t really post the pcap as there&#39;s some sensitive info. in there.</description>
    </item>
    
    <item>
      <title>On Windows, can&amp;#x27;t capture traffic my machine is sending to itself</title>
      <link>/questions/21912/on-windows-cant-capture-traffic-my-machine-is-sending-to-itself/</link>
      <pubDate>Tue, 11 Jun 2013 03:17:00 +0000</pubDate>
      
      <guid>/questions/21912/on-windows-cant-capture-traffic-my-machine-is-sending-to-itself/</guid>
      <description>On Windows, can&amp;rsquo;t capture traffic my machine is sending to itself  0 Hi,
I couldn&#39;t capture SNTP packets using wireshark v1.10.0 running system (same system is using tool running as both server and client)can anyone help me out of this problem? thanks in advance, monisha
windows loopbackasked 11 Jun &#39;13, 03:17
monisha
11●2●2●3
accept rate: 0%
 edited 15 Jun &#39;13, 16:31 
Guy Harris ♦♦
17.4k●3●35●196
did you use any capture filter?</description>
    </item>
    
    <item>
      <title>audit a log file</title>
      <link>/questions/21927/audit-a-log-file/</link>
      <pubDate>Tue, 11 Jun 2013 09:47:00 +0000</pubDate>
      
      <guid>/questions/21927/audit-a-log-file/</guid>
      <description>audit a log file  0 Sir&#39;s is there someone or somewhere that I can get an audit on my logfile? I don&#39;t really know how to read this, but I believe that a computer in my office is attacking my computer and would like to verify it.
auditasked 11 Jun &#39;13, 09:47
Sol Weinstein
11●1●1●3
accept rate: 0%
 edited 11 Jun &#39;13, 09:47 
  
One Answer:</description>
    </item>
    
    <item>
      <title>Capturing the Local Area Connection</title>
      <link>/questions/21928/capturing-the-local-area-connection/</link>
      <pubDate>Tue, 11 Jun 2013 10:35:00 +0000</pubDate>
      
      <guid>/questions/21928/capturing-the-local-area-connection/</guid>
      <description>Capturing the Local Area Connection  0 When I go to capture the &#34;Local Area Connection&#34;, it just says at the bottom.. &#34;capturing in progess..&#34;. It seems to take a very long time and I don&#39;t see anything within the first 10 minutes. I am assuming it is really not capturing, correct?
When I go to capture &#34;Wireless Connection&#34; it gives me data right away.
Please advise.
Thank you, Peggy</description>
    </item>
    
    <item>
      <title>Is wireshark a tool for out-of-band or in-band network monitoring?</title>
      <link>/questions/21933/is-wireshark-a-tool-for-out-of-band-or-in-band-network-monitoring/</link>
      <pubDate>Tue, 11 Jun 2013 12:27:00 +0000</pubDate>
      
      <guid>/questions/21933/is-wireshark-a-tool-for-out-of-band-or-in-band-network-monitoring/</guid>
      <description>Is wireshark a tool for out-of-band or in-band network monitoring?  0 Is wireshark a tool for out-of-band or in-band network monitoring? How can you tell ? I&#39;m very new to wireshark and need help?
monitoring networkasked 11 Jun &#39;13, 12:27
thomas c
1●1●1●1
accept rate: 0%
  
3 Answers:
  
0Wireshark is a network analysis tool not necessarily a network monitoring tool. It is primarily used to analyze network capture files (troubleshooting network problems of all kinds) no matter how and where those capture files were generated.</description>
    </item>
    
    <item>
      <title>telnet authentication</title>
      <link>/questions/21937/telnet-authentication/</link>
      <pubDate>Tue, 11 Jun 2013 16:13:00 +0000</pubDate>
      
      <guid>/questions/21937/telnet-authentication/</guid>
      <description>telnet authentication  0 how can i determine telnet username from captured traffic between user and server
allasked 11 Jun &#39;13, 16:13
black zone
11●1●1●2
accept rate: 0%
  
One Answer:
  
2Telnet is clear text, so if you can find a packet of the telnet communication (which should be easy enough) you can either read the packet contents until you find the typed password, or use the &#34;</description>
    </item>
    
    <item>
      <title>wireshark commandline</title>
      <link>/questions/21944/wireshark-commandline/</link>
      <pubDate>Tue, 11 Jun 2013 20:44:00 +0000</pubDate>
      
      <guid>/questions/21944/wireshark-commandline/</guid>
      <description>wireshark commandline  0 When following command executed
wireshark -i \DEVICE\NPF_{42C75388-2A3B-4C42-B581-F1E7604B7255} -k -f port 80 -c 10
wireshark:You can&#39;t specify both a live capture and a capture file to be read.
Any reason for this message
commandlineasked 11 Jun &#39;13, 20:44
krishnayeddula
629●35●41●48
accept rate: 6%
 edited 11 Jun &#39;13, 20:54 
  
One Answer:
  
2 You need to contain the capture filter in quotes:</description>
    </item>
    
    <item>
      <title>Search by specific bit in data field</title>
      <link>/questions/21957/search-by-specific-bit-in-data-field/</link>
      <pubDate>Wed, 12 Jun 2013 06:27:00 +0000</pubDate>
      
      <guid>/questions/21957/search-by-specific-bit-in-data-field/</guid>
      <description>Search by specific bit in data field  0 Hi, I am looking for filter expression that will enable search per specific bit in data filed. Do you have any idea?
mortonasked 12 Jun &#39;13, 06:27
morton
11●3●3●5
accept rate: 0%
  
3 Answers:
  
0I assume you are looking for a display filter. You can check for a specific bit value by using the &#34;&amp;amp;&#34; operator.</description>
    </item>
    
    <item>
      <title>high packets per second under LLC protocol</title>
      <link>/questions/21964/high-packets-per-second-under-llc-protocol/</link>
      <pubDate>Wed, 12 Jun 2013 09:30:00 +0000</pubDate>
      
      <guid>/questions/21964/high-packets-per-second-under-llc-protocol/</guid>
      <description>high packets per second under LLC protocol  0 Greetings all, I was doing a sniff with wireshark and noticed my network was sending between 400-800 packets per second with over 98% of them under the &#39;OTHER&#39; label when sniffing. They were labeled with the protocol LLC and my log was flooded with the screenshot below.
Can anyone provide some insight as to what may be causing so many packets being generated on my network?</description>
    </item>
    
    <item>
      <title>filtering on SMPP gives no result</title>
      <link>/questions/21965/filtering-on-smpp-gives-no-result/</link>
      <pubDate>Wed, 12 Jun 2013 10:36:00 +0000</pubDate>
      
      <guid>/questions/21965/filtering-on-smpp-gives-no-result/</guid>
      <description>filtering on SMPP gives no result  0 A colleague of mine wants to investigate a problem related to SMPP, and he took a snoop on the node, and when opening it with wireshark, he can see plenty of packets, then filtering on SMPP, there is nothing anymore. If I take that same snoop, load it in Wireshark, use the same filter, I can see all SMPP related packets, including bind, submit_SM that was used for his test, etc.</description>
    </item>
    
    <item>
      <title>What am I looking at?</title>
      <link>/questions/21972/what-am-i-looking-at/</link>
      <pubDate>Wed, 12 Jun 2013 12:50:00 +0000</pubDate>
      
      <guid>/questions/21972/what-am-i-looking-at/</guid>
      <description>What am I looking at?  0 Hello all,
We have been having some serious performance problems from one of our applications. One of the suspects is the communication between our apps server and our SQL server. So I got a wireshark capture between the two and there is red everywhere, but I don&#39;t know what I&#39;m looking at. I&#39;m not a network guy, but I am digging to see if I can help fix this problem.</description>
    </item>
    
    <item>
      <title>Arrival time vs GOOSE timestamp</title>
      <link>/questions/21976/arrival-time-vs-goose-timestamp/</link>
      <pubDate>Wed, 12 Jun 2013 13:19:00 +0000</pubDate>
      
      <guid>/questions/21976/arrival-time-vs-goose-timestamp/</guid>
      <description>Arrival time vs GOOSE timestamp  0 I am writing a Python program to decode captured GOOSE packets and ran into a little problem. I get a perfect match between my program and Wireshark for the packet arrival time (part of the frame header). In addition, I have a match for the year, month ... down to seconds part of the GOOSE message time. However, I am not getting a match for the decimal part of the time stamp.</description>
    </item>
    
    <item>
      <title>Decode China ss7 failed.</title>
      <link>/questions/21990/decode-china-ss7-failed/</link>
      <pubDate>Wed, 12 Jun 2013 20:37:00 +0000</pubDate>
      
      <guid>/questions/21990/decode-china-ss7-failed/</guid>
      <description>Decode China ss7 failed.  0 Hi, I found it is failed when the wireshark(version 1.10.0) decode rounting lable message of the signalling system 7 (The codec used 24 bits for DPC and OPC,however,The wireshark decode DPC and OPC uses 14 bits at present).How can I do to slove the problem? Thanks in advance.
Best regards, Jason
decode ss7 dpc opcasked 12 Jun &#39;13, 20:37
JasonCui
11●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to Use Tshark to extract tcp hex portion</title>
      <link>/questions/21991/how-to-use-tshark-to-extract-tcp-hex-portion/</link>
      <pubDate>Wed, 12 Jun 2013 23:21:00 +0000</pubDate>
      
      <guid>/questions/21991/how-to-use-tshark-to-extract-tcp-hex-portion/</guid>
      <description>How to Use Tshark to extract tcp hex portion  0 Is there any way to extract tcp segment out of each captured packet from command line and displaying only packet bytes(hex) of and not ASCII?
tshark -x is giving both hex and ASCII dump of all the layers.
tsharkasked 12 Jun &#39;13, 23:21
krishnayeddula
629●35●41●48
accept rate: 6%
 edited 12 Jun &#39;13, 23:22 
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark IO Graph</title>
      <link>/questions/21992/wireshark-io-graph/</link>
      <pubDate>Thu, 13 Jun 2013 01:33:00 +0000</pubDate>
      
      <guid>/questions/21992/wireshark-io-graph/</guid>
      <description>Wireshark IO Graph  0 Can we present tcp streams in wireshark IO Graph?
graph io wiresharkasked 13 Jun &#39;13, 01:33
kishan pandey
221●28●29●36
accept rate: 28%
  
2 Answers:
  
0I&#39;m not exactly sure what you are asking for, so here we go:
If you are asking for an IO graph for one stream:
open the IO graph: Statistics -&amp;gt; IO graphenter the filter for your stream: tcp.</description>
    </item>
    
    <item>
      <title>Export Packet Range</title>
      <link>/questions/21993/export-packet-range/</link>
      <pubDate>Thu, 13 Jun 2013 02:11:00 +0000</pubDate>
      
      <guid>/questions/21993/export-packet-range/</guid>
      <description>Export Packet Range  0 When I open a capture and filter it with a complex filter, the status bar of Wireshark displays:
&#34;Packets: 973007 . Displayed: 15339 (1,6%)&#34;
When I try to export only the filtered packets, the export packet range (where I can select either &#39;all packets&#39;, &#39;selected packets&#39;, &#39;marked packets&#39; and so on) the column titled Displayed counts 39032 packets ... which in my opinion should be 15339.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t capture HTTP on my Wi-Fi network</title>
      <link>/questions/22002/cant-capture-http-on-my-wi-fi-network/</link>
      <pubDate>Thu, 13 Jun 2013 04:37:00 +0000</pubDate>
      
      <guid>/questions/22002/cant-capture-http-on-my-wi-fi-network/</guid>
      <description>Can&amp;rsquo;t capture HTTP on my Wi-Fi network  0 Hello! I am new to Wireshark, and I&#39;m using an Alfa AWUS036h USB Wireless adapter on Backtrack5 r3. I set up the alfa card and set it to monitor mode. Then i ran Wireshark, using the mon0 interface i created. Then i used airodump-ng and found the channel to use.
The adapter manages to capture packets, but only with protocol 802.11, NBNS, UDP, and SSDP (And some other protocols, but these are the ones that are captures the most).</description>
    </item>
    
    <item>
      <title>Wireshark fails to run on my SPARC server</title>
      <link>/questions/22004/wireshark-fails-to-run-on-my-sparc-server/</link>
      <pubDate>Thu, 13 Jun 2013 04:58:00 +0000</pubDate>
      
      <guid>/questions/22004/wireshark-fails-to-run-on-my-sparc-server/</guid>
      <description>Wireshark fails to run on my SPARC server  0 Hi, I have installed the wireshark server on my sparc server. after installing when I am launching the wireshark it gets launched successfully.
But after I do do the tcsh to set the DISPLAY I gets the below error. what could be the reason:
ld.so.1: wireshark: fatal: relocation error: file /usr/local/lib/libwireshark.so.1: symbol g_int64_equal: referenced symbol not found Killed
launch wiresharkasked 13 Jun &#39;13, 04:58</description>
    </item>
    
    <item>
      <title>S1AP Protocol - ciphered NAS</title>
      <link>/questions/22008/s1ap-protocol-ciphered-nas/</link>
      <pubDate>Thu, 13 Jun 2013 06:16:00 +0000</pubDate>
      
      <guid>/questions/22008/s1ap-protocol-ciphered-nas/</guid>
      <description>S1AP Protocol - ciphered NAS  0 Hello,
We have two frames we&#39;re looking at in Wireshark. Both have NAS with security header &#34;Integrity Protected and ciphered&#34;. In one of them, the rest is decoded as &#34;ciphered message&#34; and in the other one we can see the plain NAS header and the rest of the NAS message. Our question is: How can Wireshark determine how to decode86 the message right after the first security header (looks like it knows somehow if the rest is really ciphered or it&#39;s decodable) Thanks, Diana and Rotem</description>
    </item>
    
    <item>
      <title>packets overlapping</title>
      <link>/questions/22012/packets-overlapping/</link>
      <pubDate>Thu, 13 Jun 2013 06:57:00 +0000</pubDate>
      
      <guid>/questions/22012/packets-overlapping/</guid>
      <description>packets overlapping  0 I have found in pcap file of wireshark that some packets overlap in time on the wire. For example certain packet is 1514 bytes long and another packet goes only five micro seconds after him. So on 100Mb/s link this packet should last approximately 120 micro seconds but another packet goes only 5 mikro seconds after the begining of first packet. How is this possible?
overlappingasked 13 Jun &#39;13, 06:57</description>
    </item>
    
    <item>
      <title>wireshark_Reset,ACK in the trace</title>
      <link>/questions/22017/wireshark_resetack-in-the-trace/</link>
      <pubDate>Thu, 13 Jun 2013 09:24:00 +0000</pubDate>
      
      <guid>/questions/22017/wireshark_resetack-in-the-trace/</guid>
      <description>wireshark_Reset,ACK in the trace  0 I have captured some data for a client, and the capture is an ssl3. from what I can tell it looks like the servers are communication using the three way handshake, then the two server communicate over a secure, connection, and then a https connection is initiated by one of the server or the application, and finally transitions process ends with fin -ack -ack -Rst, ack and the process start over.</description>
    </item>
    
    <item>
      <title>Decrypt 802.11 data inside peekremote capture</title>
      <link>/questions/22022/decrypt-80211-data-inside-peekremote-capture/</link>
      <pubDate>Thu, 13 Jun 2013 11:18:00 +0000</pubDate>
      
      <guid>/questions/22022/decrypt-80211-data-inside-peekremote-capture/</guid>
      <description>Decrypt 802.11 data inside peekremote capture  0 I have a peekremote style capture functioning (data from 3 Access points in sniffer mode being sent to my wireshark install on udp5555). Decode As-&amp;gt;Peekremote works to open up the udp 5555 encapsulation and get me the 802.11 headers. I can see EPOL Key exhcanges, but cannot decrypt the 802.11 data after entering the proper wpa-pwd:Passphrase:SSID cobination. (that combination works if I do a raw sniff but I&#39;m using the APs to gather remote data on all 3 channels).</description>
    </item>
    
    <item>
      <title>Where is Wireshark version data stored?</title>
      <link>/questions/22024/where-is-wireshark-version-data-stored/</link>
      <pubDate>Thu, 13 Jun 2013 13:22:00 +0000</pubDate>
      
      <guid>/questions/22024/where-is-wireshark-version-data-stored/</guid>
      <description>Where is Wireshark version data stored?  0 I&#39;m trying to write a script to determine what version of Wireshark is running on a system and install the current version if it&#39;s not already running. What I need to know is where is the version data stored on a Windows system? I have checked the registry key where most programs have it stored and it&#39;s not there.
windows version scriptasked 13 Jun &#39;13, 13:22</description>
    </item>
    
    <item>
      <title>SIPdroid Location(gps) services</title>
      <link>/questions/22026/sipdroid-locationgps-services/</link>
      <pubDate>Thu, 13 Jun 2013 13:50:00 +0000</pubDate>
      
      <guid>/questions/22026/sipdroid-locationgps-services/</guid>
      <description>SIPdroid Location(gps) services  0 Hello I am trying to find where the gps location is located in a SIP message using the SIPdroid app on android. I&#39;ve been searching through wireshark packets for hours and haven&#39;t had any luck.
If anyone has any knowledge about this it will be greatly appreciated. Such as if the location is even in the sip, what it looks like and if wireshark is even capable of picking this up/decoding it.</description>
    </item>
    
    <item>
      <title>Is it possible to trace the attacker through a DDoS?</title>
      <link>/questions/22040/is-it-possible-to-trace-the-attacker-through-a-ddos/</link>
      <pubDate>Fri, 14 Jun 2013 00:16:00 +0000</pubDate>
      
      <guid>/questions/22040/is-it-possible-to-trace-the-attacker-through-a-ddos/</guid>
      <description>Is it possible to trace the attacker through a DDoS?  0 I was recently hit offline by multiple IP&#39;s confirmed but I need to figure out if its possible to trace them to the actual attacker.. There were only 23 IP&#39;s with TCP connections most ranging in the US, and Singapore, and a few in Germany. Is it possible to trace it to the attacker?
tracinganipasked 14 Jun &#39;13, 00:16</description>
    </item>
    
    <item>
      <title>Load all SNMP MIBs</title>
      <link>/questions/22042/load-all-snmp-mibs/</link>
      <pubDate>Fri, 14 Jun 2013 00:46:00 +0000</pubDate>
      
      <guid>/questions/22042/load-all-snmp-mibs/</guid>
      <description>Load all SNMP MIBs  0 Hi, I&#39;m trying to load all Cisco propriatery MIBs in Wireshark. I copied the MIBs in the snmp/mibs folder, and i preferences, I specified ALL (as indicated at http://wiki.wireshark.org/SNMP) I can&#39;t seem to load them all. I used ALL, &#34;ALL&#34; positioned both at the beginning and at the end of the list.
What am I missing? Thanks, Vlad
mib snmpasked 14 Jun &#39;13, 00:46</description>
    </item>
    
    <item>
      <title>How to trace udt trafic ?</title>
      <link>/questions/22043/how-to-trace-udt-trafic/</link>
      <pubDate>Fri, 14 Jun 2013 01:38:00 +0000</pubDate>
      
      <guid>/questions/22043/how-to-trace-udt-trafic/</guid>
      <description>How to trace udt trafic ?  0 Hi, I would like to trace udt trafic but i only see standard ip/udp trames... (Version 1.8.2) In the wiki i read: The UDT dissector is fully functional. ... you may need to manually set the dissector to UDT.
Someone could help me to do this?
Thanks, Bruno.
dissector udtasked 14 Jun &#39;13, 01:38
brunost
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>wireshark v/s NS2 simulator</title>
      <link>/questions/22044/wireshark-vs-ns2-simulator/</link>
      <pubDate>Fri, 14 Jun 2013 02:30:00 +0000</pubDate>
      
      <guid>/questions/22044/wireshark-vs-ns2-simulator/</guid>
      <description>wireshark v/s NS2 simulator  0 what is the main difference between the use of WireShark and NS2? or how can we differentiate functioning of WireShark and NS2 ?
wiresharkasked 14 Jun &#39;13, 02:30
Smit
11●1●1●2
accept rate: 0%
can me to colaboration cisco boson netsim and wreshark? and what are the advantages of incorporation that I do this?
(11 Sep &#39;13, 19:09) Rizal Khadar...and if can do it, can you(admin) send me program of wireshark in my email?</description>
    </item>
    
    <item>
      <title>Specifying custom ISPC to name mapping in Wireshark</title>
      <link>/questions/22049/specifying-custom-ispc-to-name-mapping-in-wireshark/</link>
      <pubDate>Fri, 14 Jun 2013 03:11:00 +0000</pubDate>
      
      <guid>/questions/22049/specifying-custom-ispc-to-name-mapping-in-wireshark/</guid>
      <description>Specifying custom ISPC to name mapping in Wireshark  0 Hello,
Would it be possible to use a specific mapping of ISPC to name of the signalling point operator in Wireshark by specifying it in the configuration or somehow, without needing to specify it in packet-q708.c and recompiling it?
Cheers, zvmduka
q708 ispcasked 14 Jun &#39;13, 03:11
zvmduka
16●1●1●4
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>How to filter for Out of Sequence packets based on IP Identification number?</title>
      <link>/questions/22052/how-to-filter-for-out-of-sequence-packets-based-on-ip-identification-number/</link>
      <pubDate>Fri, 14 Jun 2013 03:36:00 +0000</pubDate>
      
      <guid>/questions/22052/how-to-filter-for-out-of-sequence-packets-based-on-ip-identification-number/</guid>
      <description>How to filter for Out of Sequence packets based on IP Identification number?  0 Hi
I&#39;ve currently got a problem where traffic is being delivered out of sequence over an MPLS link. The traffic is UDP and the only way that I can see the OOS packets is by the IP Identification field. However as the link is a WAN link and the problem is intermitent then there is a lot a lot of traffic to work through.</description>
    </item>
    
    <item>
      <title>Display next dissector data</title>
      <link>/questions/22063/display-next-dissector-data/</link>
      <pubDate>Fri, 14 Jun 2013 07:31:00 +0000</pubDate>
      
      <guid>/questions/22063/display-next-dissector-data/</guid>
      <description>Display next dissector data  0 Hi,
Is it possible to display information dissected by a upper level dissector on the info column, using a lower level plugin? For example, display isup´s calling party number using a modified mtp3 plugin.
Thanks,
display pluginsasked 14 Jun &#39;13, 07:31
Renan
26●4●4●8
accept rate: 0%
  
One Answer:
  
1 Technically yes, it could be done if you recompile Wireshark with some column-related code changes; otherwise no.</description>
    </item>
    
    <item>
      <title>error updating record: Invalid key format</title>
      <link>/questions/22067/error-updating-record-invalid-key-format/</link>
      <pubDate>Fri, 14 Jun 2013 10:05:00 +0000</pubDate>
      
      <guid>/questions/22067/error-updating-record-invalid-key-format/</guid>
      <description>error updating record: Invalid key format  0 Hello! When I try to input a WPA-PSK key in the IEEE 802.11 decryption place, I get the message in the title. I have tried with ssid:password, and password only.
Also, I have input a WEP key earlier (that worked), and even though I delete it and see it dissapear, it reappears if I close the window with OK, and then reopen it.</description>
    </item>
    
    <item>
      <title>hosts file location issue</title>
      <link>/questions/22072/hosts-file-location-issue/</link>
      <pubDate>Fri, 14 Jun 2013 14:03:00 +0000</pubDate>
      
      <guid>/questions/22072/hosts-file-location-issue/</guid>
      <description>hosts file location issue  0 I used to be able to use a hosts file in: C:\Users\myUserID\AppData\Roaming\Wireshark
I just installed 1.10.0 in my Windows 7 32-bit Enterprise system and now Wireshark seems to have this preference:
hosts file in the current profile C:\Users\myUserID\AppData\Roaming\Wireshark\profiles\Analysis (for example)hosts file in the Wireshark program locationI&#39;m not seeing this change in the Release Notes for 1.10.0
hosts location 1.10.0asked 14 Jun &#39;13, 14:03
GaryChaulklin</description>
    </item>
    
    <item>
      <title>Replace content in protocol container</title>
      <link>/questions/22074/replace-content-in-protocol-container/</link>
      <pubDate>Fri, 14 Jun 2013 15:22:00 +0000</pubDate>
      
      <guid>/questions/22074/replace-content-in-protocol-container/</guid>
      <description>Replace content in protocol container  0 I have my doubts that there is an editcap solution for this, but I thought I would pose this question to this audience of packet people:
I need a way to replace or remove the contents of a protocol container. The container can be presented one or more times in a packet, where in all cases the content would need to be replaced or removed.</description>
    </item>
    
    <item>
      <title>Slackware 64bit  Segmentation fault with wireshark-1.10.0</title>
      <link>/questions/22075/slackware-64bit-segmentation-fault-with-wireshark-1100/</link>
      <pubDate>Fri, 14 Jun 2013 15:24:00 +0000</pubDate>
      
      <guid>/questions/22075/slackware-64bit-segmentation-fault-with-wireshark-1100/</guid>
      <description>Slackware 64bit Segmentation fault with wireshark-1.10.0  0 I just built and installed wireshark-1.10.0 (as root) It compiled normally with a few typical warnings.
When I run it (as root) I get a Segmentation fault
When I debug with gdb I get the following backtrace
Program received signal SIGSEGV, Segmentation fault. 0x00007ffff14839fe in genl_register () from /usr/lib64/libnl-genl-3.so.200 (gdb) bt 10 #0 0x00007ffff14839fe in genl_register () from /usr/lib64/libnl-genl-3.so.200 #1 0x00007fffefdda716 in ?</description>
    </item>
    
    <item>
      <title>wireshark has stopped working</title>
      <link>/questions/22080/wireshark-has-stopped-working/</link>
      <pubDate>Fri, 14 Jun 2013 22:57:00 +0000</pubDate>
      
      <guid>/questions/22080/wireshark-has-stopped-working/</guid>
      <description>wireshark has stopped working  0 hi,
when I start wireshark my wi-fi interfaces is not displayed and when I check and apply local interfaces in interface options it is showing &#34;wireshark has stopped working&#34;(A problem caused by the program to stop working correctly. windows will close the program and notify you if solution is available). can I know what problem is this? and how to overcome this problem? I tried with reinstallation also.</description>
    </item>
    
    <item>
      <title>[1.10.0] trying to run on OSX10.5.8 but crashes on load.</title>
      <link>/questions/22081/1100-trying-to-run-on-osx1058-but-crashes-on-load/</link>
      <pubDate>Sat, 15 Jun 2013 00:00:00 +0000</pubDate>
      
      <guid>/questions/22081/1100-trying-to-run-on-osx1058-but-crashes-on-load/</guid>
      <description>[1.10.0] trying to run on OSX10.5.8 but crashes on load.  0 Hey,
Every time I launch WS it crashes with the following report... The interesting line is the last one. Does this need to be filed as a bug?
Process: Wireshark [770] Path: /Software/Security/Wireshark.app/Contents/MacOS/Wireshark Identifier: org.wireshark.Wireshark Version: ??? (???) Code Type: X86 (Native) Parent Process: launchd [99]
Date/Time: 2013-06-15 07:41:54.920 +0100 OS Version: Mac OS X 10.5.8 (9L31a) Report Version: 6 Anonymous UUID: 5DCB56D2-C51F-44C6-9413-40CBF6383CE7</description>
    </item>
    
    <item>
      <title>On Windows, how can I capture packets from my machine to itself?</title>
      <link>/questions/22082/on-windows-how-can-i-capture-packets-from-my-machine-to-itself/</link>
      <pubDate>Sat, 15 Jun 2013 00:09:00 +0000</pubDate>
      
      <guid>/questions/22082/on-windows-how-can-i-capture-packets-from-my-machine-to-itself/</guid>
      <description>On Windows, how can I capture packets from my machine to itself?  0 Hello all,
I want to capture sntp packets from system(windows 8) running as both server and client(using a tool). my question is how can i capture ntp packets from this tool using wireshark in other system(windows xp) while server client tool(both as server and client) is synchronizing time in unicast mode.
thankfully monisha
windows loopbackasked 15 Jun &#39;13, 00:09</description>
    </item>
    
    <item>
      <title>understanding retransmission establishment</title>
      <link>/questions/22089/understanding-retransmission-establishment/</link>
      <pubDate>Sat, 15 Jun 2013 11:21:00 +0000</pubDate>
      
      <guid>/questions/22089/understanding-retransmission-establishment/</guid>
      <description>understanding retransmission establishment  0 Hi all,
I was reviewing the following 3 way handshake and wanted to understand what is destination host saying regarding type of retransmission. From the traces it looks like the source host is telling to use SACK while there is no answer to that from the destination.
05:29:51.675626 IP 24.6.173.220.26385 &amp;gt; 198.66.239.146.80: Flags [S], seq 3242633023, win 8192, options [mss 1460,nop,wscale 2,nop,nop,sackOK], length 0 05:29:51.696997 IP 198.</description>
    </item>
    
    <item>
      <title>The transmission window is now completely full</title>
      <link>/questions/22090/the-transmission-window-is-now-completely-full/</link>
      <pubDate>Sat, 15 Jun 2013 11:29:00 +0000</pubDate>
      
      <guid>/questions/22090/the-transmission-window-is-now-completely-full/</guid>
      <description>The transmission window is now completely full  0 I&#39;m having problems with a extremely slow network response from outside websites. In looking at the Wireshark output, I see what seems to be a very large number of &#34;TCP window full&#34; and &#34;Zero window&#34; occurrences. One of the &#34;window full&#34; events shows up as:
15874 141.816990 64.81.159.15 10.138.30.34 TCP 60 http &amp;gt; unet [ACK] Seq=4714197 Ack=17390 Win=17520 Len=0
15875 141.817027 10.</description>
    </item>
    
    <item>
      <title>use of patch file with pre installed version</title>
      <link>/questions/22095/use-of-patch-file-with-pre-installed-version/</link>
      <pubDate>Sat, 15 Jun 2013 14:22:00 +0000</pubDate>
      
      <guid>/questions/22095/use-of-patch-file-with-pre-installed-version/</guid>
      <description>use of patch file with pre installed version  0 I am using win 7 and a newbie ... so I am afraid to build the wireshark again. I wanted to know that how can I use some patch files with wireshark without rebuilding it (with pre installed wireshark). Is there is a simple method or building the wireshark is the only solution ?
wireshark win7 patchasked 15 Jun &#39;13, 14:22</description>
    </item>
    
    <item>
      <title>capture filter problems: v 1.2.9 on Windows XP WiFi</title>
      <link>/questions/22099/capture-filter-problems-v-129-on-windows-xp-wifi/</link>
      <pubDate>Sat, 15 Jun 2013 17:03:00 +0000</pubDate>
      
      <guid>/questions/22099/capture-filter-problems-v-129-on-windows-xp-wifi/</guid>
      <description>capture filter problems: v 1.2.9 on Windows XP WiFi  0 PC &#39;A&#39; is an old XP machine monitoring my internal WiFi network and helping debug what PC &#39;B&#39; is doing (Wireshark 1.6.2 on Ubuntu 11.10).
Both Wiresharks are in promiscuous capture.
I want to see UDP packets on a specific port directed at PC B, plus an ICMP packet that B sends in response, AND any packets that B sends prior to the received UDP packet (to track down a Firewall problem).</description>
    </item>
    
    <item>
      <title>LTE-RRC packets dissection</title>
      <link>/questions/22101/lte-rrc-packets-dissection/</link>
      <pubDate>Sun, 16 Jun 2013 03:25:00 +0000</pubDate>
      
      <guid>/questions/22101/lte-rrc-packets-dissection/</guid>
      <description>LTE-RRC packets dissection  0 Hello,
Is it possible to dissect by wireshark LTE-RRC packets only according to captured IP packets (without USER_DLT)? What information should be in IP packets in order to dissect LTE-RRC messages?
Now I able to dissect LTE-RRC packets only offline (reading from pcap file that contains USER_DLT)
Thanks, Erez
eshabtaiasked 16 Jun &#39;13, 03:25
eshabtai
11●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>sniffing WIFI</title>
      <link>/questions/22102/sniffing-wifi/</link>
      <pubDate>Sun, 16 Jun 2013 03:42:00 +0000</pubDate>
      
      <guid>/questions/22102/sniffing-wifi/</guid>
      <description>sniffing WIFI  0 Hi everyone,
My home network consists of several PC&#39;s connected via Ethernet...as well as 2 laptops, 2 Ipads and 2 smartphones connected via WIFI (WPA2/TKIP).
Ultimately I plan on using Security Onion to monitor all of my devices; however as a first step I tried to see if I could view all of the traffic via Wireshark, and I am only able to see the traffic from the laptop that I do the sniffing on.</description>
    </item>
    
    <item>
      <title>running capture causes packet duplication on Windows XP / Wireshark 1.2.9</title>
      <link>/questions/22106/running-capture-causes-packet-duplication-on-windows-xp-wireshark-129/</link>
      <pubDate>Sun, 16 Jun 2013 08:56:00 +0000</pubDate>
      
      <guid>/questions/22106/running-capture-causes-packet-duplication-on-windows-xp-wireshark-129/</guid>
      <description>running capture causes packet duplication on Windows XP / Wireshark 1.2.9  0 PC &#39;A&#39; is running Windows &amp;amp; Wireshark as per title; on the WiFi network interface (Broadcom) in promiscuous mode; PC B is connected to the same WiFi network
If, from PC B I ping the IP address of PC A, I get duplicate ICMP responses received at PC B.
The duplicates show up in the Wireshark trace on PC A, ping stats at PC B; and also in a Wireshark trace on PC B if I also run Wireshark there.</description>
    </item>
    
    <item>
      <title>New to this software, trying to diagnose issues with new isp</title>
      <link>/questions/22108/new-to-this-software-trying-to-diagnose-issues-with-new-isp/</link>
      <pubDate>Sun, 16 Jun 2013 17:59:00 +0000</pubDate>
      
      <guid>/questions/22108/new-to-this-software-trying-to-diagnose-issues-with-new-isp/</guid>
      <description>New to this software, trying to diagnose issues with new isp  0 Hi, I&#39;m new to trying to diagnose networking issues, but I&#39;m having lots of trouble with skype and games disconnecting briefly. I just moved, and my apartment complex provides Comcast Xfinity. I&#39;ve been running WireShark for about 20 minutes and I&#39;ve already hit 18 Errors and 13 Warnings, which seems like a lot. I&#39;m not sure where to start in diagnosing these issues, but my goal is to establish a really solid connection.</description>
    </item>
    
    <item>
      <title>Try to obtain RTT average in windows</title>
      <link>/questions/22113/try-to-obtain-rtt-average-in-windows/</link>
      <pubDate>Mon, 17 Jun 2013 03:07:00 +0000</pubDate>
      
      <guid>/questions/22113/try-to-obtain-rtt-average-in-windows/</guid>
      <description>Try to obtain RTT average in windows  0 Hi,
For my internship i have to do network performance.
With wireshark i cannot obtain the RTT average or have all RTT values (i could do the average with excel if i have it).
I tried with statistics -&amp;gt; RTT StreamGraph -&amp;gt; RTT Graph the values appears in a graph but i can&#39;t collect them.
One other try: IO Graph, with filter and unit advanced, AVG(tcp.</description>
    </item>
    
    <item>
      <title>Constant Repetitive DNS Queries</title>
      <link>/questions/22114/constant-repetitive-dns-queries/</link>
      <pubDate>Mon, 17 Jun 2013 05:20:00 +0000</pubDate>
      
      <guid>/questions/22114/constant-repetitive-dns-queries/</guid>
      <description>Constant Repetitive DNS Queries  0 My computer is running Windows 7 pro. When I perform a live capture on my network interface, I see constant DNS queries asking for the mail server at www.yahoo.com. After restarting the machine, logging in, and immediately starting Wireshark, I still see these queries - probably once every 2 or 3 seconds. Has anyone seen anything like this before?
Note: I am trying to reply to your comments, but Akismet thinks all of my comments are spam.</description>
    </item>
    
    <item>
      <title>packet dissection is too slow, on applying read filter, how to optimize</title>
      <link>/questions/22123/packet-dissection-is-too-slow-on-applying-read-filter-how-to-optimize/</link>
      <pubDate>Mon, 17 Jun 2013 13:27:00 +0000</pubDate>
      
      <guid>/questions/22123/packet-dissection-is-too-slow-on-applying-read-filter-how-to-optimize/</guid>
      <description>packet dissection is too slow, on applying read filter, how to optimize  0 so basically i have written a tool,and what it does is
1- capture the packets,write this into a file, initialize epan module
2- open the file using pcap_open_offline(...), then call pcap_loop(...)and in handler function for this apply read filter(for any identity present in request message) on it, call dissection utilities.
3- go to print the packet data, extract message_id.</description>
    </item>
    
    <item>
      <title>GPRS interface</title>
      <link>/questions/22129/gprs-interface/</link>
      <pubDate>Tue, 18 Jun 2013 04:01:00 +0000</pubDate>
      
      <guid>/questions/22129/gprs-interface/</guid>
      <description>GPRS interface  0 Hi experts,
Can i use wireshark to capture GPRS trafic between my laptop Windows 7 OS using a Israeli Cellcom mobile phone connected to PC usb?
I read this at archive by Guy Harris:
&#34;As question 5 in the WinPcap FAQ indicates, PPP devices are not supported on Windows Vista and Windows 7. Mobile phone modems show up as PPP devices, so you cannot capture on them.</description>
    </item>
    
    <item>
      <title>Ioctl Response, Error: FILE_SYSTEM Function: 0x006b</title>
      <link>/questions/22131/ioctl-response-error-file_system-function-0x006b/</link>
      <pubDate>Tue, 18 Jun 2013 04:29:00 +0000</pubDate>
      
      <guid>/questions/22131/ioctl-response-error-file_system-function-0x006b/</guid>
      <description>Ioctl Response, Error: FILE_SYSTEM Function: 0x006b  0 Does anyone have a definition for this error? It&#39;s over protocol SMB2. Preceding it, only a few lines up, I get another error &#34;Ioctl Response, Error: STATUS_NOT_SUPPORTED&#34;
smb2 smbasked 18 Jun &#39;13, 04:29
abigcoorsman
11●1●1●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Wireshark vulnerabilites</title>
      <link>/questions/22133/wireshark-vulnerabilites/</link>
      <pubDate>Tue, 18 Jun 2013 08:30:00 +0000</pubDate>
      
      <guid>/questions/22133/wireshark-vulnerabilites/</guid>
      <description>Wireshark vulnerabilites  0 When my security group rejected offering wireshark within my company they stated the following issues: 1. Denial of service issues
This is version 1.8.6
Any thoughts as to how convince my security group to allow us access to wire
vulnerabilitiy issuesasked 18 Jun &#39;13, 08:30
Rich_Warren
11●1●1●2
accept rate: 0%
  
3 Answers:
  
3Wireshark is vulnerable to crashing from either mal-formed packets (whether malicious or not), or even well-formed packets due to bugs in the Wireshark code.</description>
    </item>
    
    <item>
      <title>How does Wireshark recognize TCP Retransmission packets?</title>
      <link>/questions/22134/how-does-wireshark-recognize-tcp-retransmission-packets/</link>
      <pubDate>Tue, 18 Jun 2013 08:41:00 +0000</pubDate>
      
      <guid>/questions/22134/how-does-wireshark-recognize-tcp-retransmission-packets/</guid>
      <description>How does Wireshark recognize TCP Retransmission packets?  0 Hi guys, I just want to ask you what information that Wireshark needs to check before it recognize that packet is a retransmission packet. If it does based on IP Identification and Transport Layer Checksum value, Wireshark needs to compare the retransmission packet&#39;s data to previous packet&#39;s data, does it not?
recognize retransmission tcp wiresharkasked 18 Jun &#39;13, 08:41
quang20082008
6●2●2●5</description>
    </item>
    
    <item>
      <title>Capture Traffic From Rogue MAC Address Only</title>
      <link>/questions/22142/capture-traffic-from-rogue-mac-address-only/</link>
      <pubDate>Tue, 18 Jun 2013 13:49:00 +0000</pubDate>
      
      <guid>/questions/22142/capture-traffic-from-rogue-mac-address-only/</guid>
      <description>Capture Traffic From Rogue MAC Address Only  0 Looking at the logs on my home router, I&#39;m noticing several MAC addresses I don&#39;t recognize. I have several devices connected to my home network, all of which I know the MAC address for. My suspicion is that someone has hacked my WPA2 password and is using my network to access the internet.
This MAC address (and a few others) seem to be on my network at random times with no discernable pattern.</description>
    </item>
    
    <item>
      <title>Question on Editcap with -t option</title>
      <link>/questions/22145/question-on-editcap-with-t-option/</link>
      <pubDate>Tue, 18 Jun 2013 21:59:00 +0000</pubDate>
      
      <guid>/questions/22145/question-on-editcap-with-t-option/</guid>
      <description>Question on Editcap with -t option  0 I am running following command
editcap -t -0.2 http-disney101.pcapng duplicate.pcapng
I was informed that above command subtracts 0.2 seconds from http-disney101.pcapng and creates a new trace file duplicate.pcapng but in new trace file i am not seeing any packet with new time stamp getting triggered.Am i missing anything here?
editcapasked 18 Jun &#39;13, 21:59
krishnayeddula
629●35●41●48
accept rate: 6%
 edited 19 Jun &#39;13, 20:07</description>
    </item>
    
    <item>
      <title>How to capture NFC packet through wireshark ?</title>
      <link>/questions/22146/how-to-capture-nfc-packet-through-wireshark/</link>
      <pubDate>Tue, 18 Jun 2013 23:04:00 +0000</pubDate>
      
      <guid>/questions/22146/how-to-capture-nfc-packet-through-wireshark/</guid>
      <description>How to capture NFC packet through wireshark ?  0 I want to capture NFC(near field communication) packet, which tool can be competent to do that?
nfc wiresharkasked 18 Jun &#39;13, 23:04
TommyXu
1●2●2●4
accept rate: 0%
 edited 18 Jun &#39;13, 23:05 
  
One Answer:
  
1There is a NFC dissector plugin available at google code.
http://code.google.com/p/wireshark-nfc/
So, you will at least be able to dissect NFC traffic with Wireshark, if you are able to use that plugin with Wireshark (see the instructions on that site) and you have some hardware that is able to generate the NFC capture file (search google for: NFC protocol sniffer).</description>
    </item>
    
    <item>
      <title>SIP INVITE in-dialog</title>
      <link>/questions/22148/sip-invite-in-dialog/</link>
      <pubDate>Wed, 19 Jun 2013 02:35:00 +0000</pubDate>
      
      <guid>/questions/22148/sip-invite-in-dialog/</guid>
      <description>SIP INVITE in-dialog  0 Hi all,
I&#39;m tracing SIP calls, and sometimes I see INVITE messages indicated with &#34;in-dialog&#34;. What does that mean???
Reg,
Gerben
sip in-dialog inviteasked 19 Jun &#39;13, 02:35
glammertink
11●1●1●2
accept rate: 0%
  
One Answer:
  
0This indicator is added to the info column by Wireshark when it finds a &#34;tag&#34; added in one of the headers of an INVITE, SUBSCRIBE or REFER message.</description>
    </item>
    
    <item>
      <title>wireshark settings</title>
      <link>/questions/22149/wireshark-settings/</link>
      <pubDate>Wed, 19 Jun 2013 02:55:00 +0000</pubDate>
      
      <guid>/questions/22149/wireshark-settings/</guid>
      <description>wireshark settings  0 Now I am working with wireshark and facing some problems. I want to communicate two ieds with my pc &amp;amp; want to see the communication between the two ieds. plz tell me the settings which are to be set to see the packets. ieds ip(for client-192.168.0.105,,,for slave-192.168.0.24,,,pc-192.168.0.162)...plz rply me fast,,,,
settings wiresharkasked 19 Jun &#39;13, 02:55
nayan
1●1●1●1
accept rate: 0%
what are ieds?
(19 Jun &#39;13, 02:58) Kurt Knochner ♦I was thinking &#34;</description>
    </item>
    
    <item>
      <title>botnet attack</title>
      <link>/questions/22155/botnet-attack/</link>
      <pubDate>Wed, 19 Jun 2013 06:22:00 +0000</pubDate>
      
      <guid>/questions/22155/botnet-attack/</guid>
      <description>botnet attack  0 Hi all,today in our symmantec siem product we observed botnet log showing destination port as 7000 but strange thing is,it is showing protocol as icmp.as par my knowledge icmp has nothing do with tcp ports?symantec siem products gets this logs from our firewall and in firewall we have only allow icmp eco request and reply service.i am sure it is icmp traffic only but why port is showing,source of traffic is linux machine.</description>
    </item>
    
    <item>
      <title>Reading output between FW and router</title>
      <link>/questions/22157/reading-output-between-fw-and-router/</link>
      <pubDate>Wed, 19 Jun 2013 06:54:00 +0000</pubDate>
      
      <guid>/questions/22157/reading-output-between-fw-and-router/</guid>
      <description>Reading output between FW and router  0 We have a server looking to communicate through both a firewall and a router set up with a VPN to a remote public address on a certain port. The opposite end complains that they can send and receive traffic successfully when they initiate the connection from their end but cannot see traffic when we initiate. The setup is as follows:
Server &amp;gt; Firewall &amp;gt; router (with IPsec VPN tunnel) &amp;gt; Internet &amp;lt; router (with IPsec VPN tunnel) &amp;lt; RemoteServer</description>
    </item>
    
    <item>
      <title>iSCSI from Windows Server 2012</title>
      <link>/questions/22170/iscsi-from-windows-server-2012/</link>
      <pubDate>Wed, 19 Jun 2013 08:23:00 +0000</pubDate>
      
      <guid>/questions/22170/iscsi-from-windows-server-2012/</guid>
      <description>iSCSI from Windows Server 2012  0 Anyone here familiar with iSCSI protocol? I have been sniffing around at some iSCSI traffic and have been working on making a compliant iSCSI server app. Things have been going relatively smoothly until recently. There&#39;s a LOT of setup required before you can even get to doing your first Read and Write commands. I got through a whole bunch of it, comparing the results of my server against a known SAN device.</description>
    </item>
    
    <item>
      <title>How do I track UDP packets from localhost?</title>
      <link>/questions/22172/how-do-i-track-udp-packets-from-localhost/</link>
      <pubDate>Wed, 19 Jun 2013 08:37:00 +0000</pubDate>
      
      <guid>/questions/22172/how-do-i-track-udp-packets-from-localhost/</guid>
      <description>How do I track UDP packets from localhost?  0 Greetings, Gentlemen! I am totally new to Wireshark and Networks too. Please help me to do a simple exercise.
I have coded a simple UDP server-client pair according to Java tutorials: http://docs.oracle.com/javase/tutorial/networking/datagrams/clientServer.html It works. The server is running on my machine and client too. What I want now is to track the packets I send using my fantastic software setup. How can I find them?</description>
    </item>
    
    <item>
      <title>Error since I switched to Spanning port</title>
      <link>/questions/22183/error-since-i-switched-to-spanning-port/</link>
      <pubDate>Wed, 19 Jun 2013 13:01:00 +0000</pubDate>
      
      <guid>/questions/22183/error-since-i-switched-to-spanning-port/</guid>
      <description>Error since I switched to Spanning port  0 HI I&#39;m running wireshark 1.8.6 SVNRev 48142 from trunk-1.8
Running on windows XP professional. Recently I switched to port that spans whole subnet so i can see all traffic. It runs about 5 to 10 minutes then i get a error it says &#34; runtime error! program: C:\Program Files\Wireshark\wireshark.exe This application has requested the runtime to terminate it in a unusual way Please contact the application&#39;s support team for more Infomation.</description>
    </item>
    
    <item>
      <title>wireshark can not open pcap file</title>
      <link>/questions/22188/wireshark-can-not-open-pcap-file/</link>
      <pubDate>Wed, 19 Jun 2013 19:25:00 +0000</pubDate>
      
      <guid>/questions/22188/wireshark-can-not-open-pcap-file/</guid>
      <description>wireshark can not open pcap file  0 I downloaded wireshark source code and built it successfully. Then I try to open an exist pcap file with wireshark.exe. It shows error&#34;The file C:\source\snep_p2p_trace.pcap is a capture for a network type that Wireshark doesn&#39;t support.(pcap:network type 245 unknown or unsupported)&#34;.
nfc wiresharkasked 19 Jun &#39;13, 19:25
TommyXu
1●2●2●4
accept rate: 0%
  
One Answer:
  
1 According to the official list of link-layer header type values, 245 is LINKTYPE_NFC_LLCP, which is supported by Wireshark 1.</description>
    </item>
    
    <item>
      <title>DHCP broadcast packets not displayed</title>
      <link>/questions/22194/dhcp-broadcast-packets-not-displayed/</link>
      <pubDate>Thu, 20 Jun 2013 03:00:00 +0000</pubDate>
      
      <guid>/questions/22194/dhcp-broadcast-packets-not-displayed/</guid>
      <description>DHCP broadcast packets not displayed  0 Hello,
I&#39;m tracing on a TAP the connection of a machine. I want to see the DHCP exchange of this machine. Normally I expect to see the sequence Discover - Offer - Request - Ack. But I see only Offer and Ack, the broadcast messages sent from the machine are not displayed. I tried several Wireshark Version from 1.6 to 1.10 with different WinPcap (4.</description>
    </item>
    
    <item>
      <title>Getting attack on my load balancer of web servers?</title>
      <link>/questions/22198/getting-attack-on-my-load-balancer-of-web-servers/</link>
      <pubDate>Thu, 20 Jun 2013 06:26:00 +0000</pubDate>
      
      <guid>/questions/22198/getting-attack-on-my-load-balancer-of-web-servers/</guid>
      <description>Getting attack on my load balancer of web servers?  0 Hi,
This afternoon I was getting swamped by an attack from a host in Malaysia.
I am pretty new with wireshark. And would like to know if this traffic from the host 175.136.20.105 to my load balancer had any other anomalies. I also noticed that there were a lot of TCP dup acks and zero len acks.
After blocking this IP, my site recovered.</description>
    </item>
    
    <item>
      <title>Wireshark 32</title>
      <link>/questions/22199/wireshark-32/</link>
      <pubDate>Thu, 20 Jun 2013 06:42:00 +0000</pubDate>
      
      <guid>/questions/22199/wireshark-32/</guid>
      <description>Wireshark 32  0 Hi, I downloaded and installed Wireshark 32 bit for Windows XP. When I try to run the Wireshark application, I am receiving the error &#34;The procedure entry point DecodePointer could not be located in the dynamic link library KERNEL32.dll&#34;.
Thanks and Regards, Anamika
kernel32.dll decodepointer windowsxp wiresharkasked 20 Jun &#39;13, 06:42
Anamika117
16●2●2●5
accept rate: 0%
  
2 Answers:
  
3 DecodePointer is a Windows API call that is present in XP SP2 or later.</description>
    </item>
    
    <item>
      <title>Single chunk of TCP data missing from file transfer</title>
      <link>/questions/22205/single-chunk-of-tcp-data-missing-from-file-transfer/</link>
      <pubDate>Thu, 20 Jun 2013 10:58:00 +0000</pubDate>
      
      <guid>/questions/22205/single-chunk-of-tcp-data-missing-from-file-transfer/</guid>
      <description>Single chunk of TCP data missing from file transfer  0 Hi everyone,
I am performing a file transfer using some off the shelf COTS TCP libraries in a C# program. I am transferring a 5Mb randomly generated file. The transmission path traverses a virtual NIC (TAP/TUN), over a radio, and back out another virtual NIC. Sometimes the file is transmitted correctly but sometimes the file is missing one contiguous chunk of data.</description>
    </item>
    
    <item>
      <title>How can you be aware the source of the slow connection problem?</title>
      <link>/questions/22206/how-can-you-be-aware-the-source-of-the-slow-connection-problem/</link>
      <pubDate>Thu, 20 Jun 2013 11:05:00 +0000</pubDate>
      
      <guid>/questions/22206/how-can-you-be-aware-the-source-of-the-slow-connection-problem/</guid>
      <description>How can you be aware the source of the slow connection problem?  0 Hi guys, this is not really a question. I want to know how can you be aware the source of the problem when a slow connection problem appearing. If you have any good idea, trick or tips, please show me and every member of this page know that.
Longing for more. Thanks.
connection slow slowlyasked 20 Jun &#39;13, 11:05</description>
    </item>
    
    <item>
      <title>windows build fails</title>
      <link>/questions/22216/windows-build-fails/</link>
      <pubDate>Thu, 20 Jun 2013 23:05:00 +0000</pubDate>
      
      <guid>/questions/22216/windows-build-fails/</guid>
      <description>windows build fails  0 Can anybody help me...
I cannot build wireshark. This error message allways apears:
bash -o igncr tool/textify.sh &amp;quot;./COPYING&amp;quot; wireshark-gtk2 tools/textify.sh: line 50: u2d: command not found NMAKE : faral error U1077: &amp;#39;c:\cygwin\bin\bash.EXE&amp;#39; : return code &amp;#39;0x7f&amp;#39;I have Win7 and use MSVS2010. Any other mistakes are not known. Hope you guys can help me...
Thanks.
windows failure build errorasked 20 Jun &#39;13, 23:05
Marko1988
1●2●2●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Snooping TCP packets for fixed IP systems</title>
      <link>/questions/22218/snooping-tcp-packets-for-fixed-ip-systems/</link>
      <pubDate>Fri, 21 Jun 2013 02:14:00 +0000</pubDate>
      
      <guid>/questions/22218/snooping-tcp-packets-for-fixed-ip-systems/</guid>
      <description>Snooping TCP packets for fixed IP systems  0 I am not an expert in networking but I am trying to connect two embedded systems in a network to snoop the TCP packets. Both the systems(lets say A and B) has fixed IP address and they communicate on a dedicated port. I am using PC (lets say system C) and Wireshark to snoop the TCP packets for debugging.
1) When I connected these systems(A,B and C) through a switch, I couldn&#39;t see any data on Wireshark.</description>
    </item>
    
    <item>
      <title>How can I interpret this capture in terms of client application failing to successfully connect to server?</title>
      <link>/questions/22220/how-can-i-interpret-this-capture-in-terms-of-client-application-failing-to-successfully-connect-to-server/</link>
      <pubDate>Fri, 21 Jun 2013 06:15:00 +0000</pubDate>
      
      <guid>/questions/22220/how-can-i-interpret-this-capture-in-terms-of-client-application-failing-to-successfully-connect-to-server/</guid>
      <description>How can I interpret this capture in terms of client application failing to successfully connect to server?  0 Hi everyone. I&#39;m an application administrator but my TCP knowledge is minimal. I have done some research trying to work this out on my own but feel like I&#39;m going to need help to make any real progress.
So... here goes. I have one particular customer site from which nobody can successfully connect to our server.</description>
    </item>
    
    <item>
      <title>tshark http get x-forwarded-for ip in one line</title>
      <link>/questions/22225/tshark-http-get-x-forwarded-for-ip-in-one-line/</link>
      <pubDate>Fri, 21 Jun 2013 09:53:00 +0000</pubDate>
      
      <guid>/questions/22225/tshark-http-get-x-forwarded-for-ip-in-one-line/</guid>
      <description>tshark http get x-forwarded-for ip in one line  0 Hey all,
Is it possible to have HTTP GET request and X-forwarded-for IP and the time in 1 single line?
I have difficulties,
tshark -i eth0 -n tcp port 80 -x -R &#39;http.request.method == &#34;GET&#34;&#39; | grep &#34;HTTP GET&#34;
0.158435 10.128.99.11 -&amp;gt; 46.12.12.14 HTTP GET /check.html HTTP/1.0
Appreciate any help given.
tsharkasked 21 Jun &#39;13, 09:53
diden
8●2●2●5
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Multiple NOT clauses in a capture filter</title>
      <link>/questions/22228/multiple-not-clauses-in-a-capture-filter/</link>
      <pubDate>Fri, 21 Jun 2013 13:23:00 +0000</pubDate>
      
      <guid>/questions/22228/multiple-not-clauses-in-a-capture-filter/</guid>
      <description>Multiple NOT clauses in a capture filter  0 I just got back from Sharkfest (my first time) and am wicked fired up to try bold new things with Wireshark. As luck would have it, a perfect real-world problem dropped in my lap just this morning.
Background: Our customer sends medical imaging data (DICOM) to our load balancer on TCP port 104, which forwards it to the machine on which I am running dumpcap, and its counterpart, more or less evenly, when things are working correctly.</description>
    </item>
    
    <item>
      <title>filter for partial IP address</title>
      <link>/questions/22230/filter-for-partial-ip-address/</link>
      <pubDate>Fri, 21 Jun 2013 14:06:00 +0000</pubDate>
      
      <guid>/questions/22230/filter-for-partial-ip-address/</guid>
      <description>filter for partial IP address  1 I would like to create a display filter for an with the last 2 octets of an IP address. In this case I want to filter for the IP address xxx.xxx.149.195 . What is the display filter expression using the offset and slice operators or a wildcard expression that I would need to use?
display-filter wildcard offsetasked 21 Jun &#39;13, 14:06
mrproject
21●1●1●4</description>
    </item>
    
    <item>
      <title>How to pipe tshark output to text file</title>
      <link>/questions/22234/how-to-pipe-tshark-output-to-text-file/</link>
      <pubDate>Fri, 21 Jun 2013 18:33:00 +0000</pubDate>
      
      <guid>/questions/22234/how-to-pipe-tshark-output-to-text-file/</guid>
      <description>How to pipe tshark output to text file  0 I want to pipe the output of following command to a text file for further processing.Please let me know how to do the same..
tshark -r &amp;lt;mypcap&amp;gt; -Tfields -e ip.src -e ip.dst
10.10.10.10 1.1.1.1
2.2.2.2 3.3.3.3
16.1.1.1 11.11.11.1
I want to pipe this output to a text file what field to add to the command
Thanks
tsharkasked 21 Jun &#39;13, 18:33</description>
    </item>
    
    <item>
      <title>Visual C&#43;&#43; Runtime Library Error</title>
      <link>/questions/22243/visual-c-runtime-library-error/</link>
      <pubDate>Sat, 22 Jun 2013 02:07:00 +0000</pubDate>
      
      <guid>/questions/22243/visual-c-runtime-library-error/</guid>
      <description>Visual C++ Runtime Library Error  0 Windows 7 Pro (32-bit) Service Pack 1 Pentium Dual Core E5700 @ 3Ghz 2.00ghz RAM
Wireshark Version 1.10.0
Mirosoft Visual C++ Runtime Library This application has requested the runtime to terminate in an unusual way. Please contact the application&#39;s support team for more information.
Log Name: Application Source: Application Error Event ID: 1000 Level: Error
Faulting application name: Wireshark.exe, version: 1.10.0.49790, time stamp: 0x51af7ca6 Faulting module name: libcairo-2.</description>
    </item>
    
    <item>
      <title>SRTP decryption support?</title>
      <link>/questions/22246/srtp-decryption-support/</link>
      <pubDate>Sat, 22 Jun 2013 12:13:00 +0000</pubDate>
      
      <guid>/questions/22246/srtp-decryption-support/</guid>
      <description>SRTP decryption support?  0 I&#39;m in need of decrypting (to verify via playback) a VoIP conversation issue between an Acme Packet SBC and a Polycom SIP phone (on the Internet) that employs SRTP. Is there any hope that Wireshark one day will have SRTP decryption support? In the meantime, are there any options for decrypting SRTP out there?
Regards Keith
srtpasked 22 Jun &#39;13, 12:13
keithdew
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>SMPP commands,tree  with filter</title>
      <link>/questions/22248/smpp-commandstree-with-filter/</link>
      <pubDate>Sat, 22 Jun 2013 16:37:00 +0000</pubDate>
      
      <guid>/questions/22248/smpp-commandstree-with-filter/</guid>
      <description>SMPP commands,tree with filter  0 there is a way to aply a filter in a command like this: tshark -nr input.pcap -q -z smpp_commands,tree
I have a pcap file with several IPs and I want to make a filter with ip.src==x.x.x.x and then show the smpp_commands,tree.
thanks and regards
filter smpp tree smpp_commandsasked 22 Jun &#39;13, 16:37
fachav2
31●2●2●6
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Capturing Bluetooth on Windows or has anyone actually succeeded on Linux?</title>
      <link>/questions/22250/capturing-bluetooth-on-windows-or-has-anyone-actually-succeeded-on-linux/</link>
      <pubDate>Sat, 22 Jun 2013 18:53:00 +0000</pubDate>
      
      <guid>/questions/22250/capturing-bluetooth-on-windows-or-has-anyone-actually-succeeded-on-linux/</guid>
      <description>Capturing Bluetooth on Windows or has anyone actually succeeded on Linux?  1 1Does it actually work on Windows? http://wiki.wireshark.org/CaptureSetup/NetworkMedia says the only thing that&#39;ll work is Linux w/Affix stack. http://affix.sourceforge.net/ looks hopelessly outdated. The last update to that appears to be from 2005 and the highest Linux kernel mentioned is 2.6.
I couldn&#39;t get Wireshark to capture anything on the BT interface on my Lenovo T61p running Windows 7. It sees the interface but captures nothing when playing audio successfully (via hands-free audio) to a Bluetooth headset.</description>
    </item>
    
    <item>
      <title>I can&amp;#x27;t install WinPCap?? HELP!!</title>
      <link>/questions/22251/i-cant-install-winpcap-help/</link>
      <pubDate>Sat, 22 Jun 2013 19:00:00 +0000</pubDate>
      
      <guid>/questions/22251/i-cant-install-winpcap-help/</guid>
      <description>I can&amp;rsquo;t install WinPCap?? HELP!!  0 Okay, so people on steam keep trying to ddos me and do stupid * and my ISP isn&#39;t doing about it. So, I am trying to take matters into my own hands. I am trying to get WireShark BUT IT WONT WORK. CommView is *** and confusing! So please, it keeps saying I have an older version and I&#39;ve gone through all of youtube saying to delete dll.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t surf internet while wireshark running</title>
      <link>/questions/22253/cant-surf-internet-while-wireshark-running/</link>
      <pubDate>Sun, 23 Jun 2013 09:24:00 +0000</pubDate>
      
      <guid>/questions/22253/cant-surf-internet-while-wireshark-running/</guid>
      <description>Can&amp;rsquo;t surf internet while wireshark running  0 I compiled Wireshark from source code on my debian 7 a few days ago and installed it. I can&#39;t surf internet while Wireshark is running. Even pinging the gateway returns a &#34;Destination unreachable&#34; error. But I don&#39;t have this issue on Windows.
I tried to change capture modes and this didn&#39;t work either. Any idea how to solve this problem? Thanks in advance.</description>
    </item>
    
    <item>
      <title>How can i get real time traffic from wireshark for another classification program?</title>
      <link>/questions/22254/how-can-i-get-real-time-traffic-from-wireshark-for-another-classification-program/</link>
      <pubDate>Sun, 23 Jun 2013 09:34:00 +0000</pubDate>
      
      <guid>/questions/22254/how-can-i-get-real-time-traffic-from-wireshark-for-another-classification-program/</guid>
      <description>How can i get real time traffic from wireshark for another classification program?  0 Please, may I know it is possible? although I can get log file from Wireshark,I want to add real time traffic from Wireshark to another classification program directly. I
floweasked 23 Jun &#39;13, 09:34
zinwin
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Wireshark is not creating any real time traffic. I guess you mean that you want to analyze recordings taken by Wireshark with another tool?</description>
    </item>
    
    <item>
      <title>Tshark Vendor specific dictionary field</title>
      <link>/questions/22259/tshark-vendor-specific-dictionary-field/</link>
      <pubDate>Sun, 23 Jun 2013 18:04:00 +0000</pubDate>
      
      <guid>/questions/22259/tshark-vendor-specific-dictionary-field/</guid>
      <description>Tshark Vendor specific dictionary field  0 Hi,
I&#39;m trying to call an attribute from a vendor specific dictionary included for the following included radius dictionary &#34;dictionary.rfc4679&#34;
How can I call attributes specified in this dictionary as a field in Tshark?
e.g. I want to call the listed attribute
ATTRIBUTE ADSL-Agent-Circuit-Id 1 stringAs a field in the following command:
tshark -i eth1 -T fields -e radius.Event_Timestamp -e &amp;quot;ADSL-Agent-Circuit-Id&amp;quot;Thanks.
radius tshark dictionaryasked 23 Jun &#39;13, 18:04</description>
    </item>
    
    <item>
      <title>ICMP fragmentation</title>
      <link>/questions/22260/icmp-fragmentation/</link>
      <pubDate>Sun, 23 Jun 2013 18:56:00 +0000</pubDate>
      
      <guid>/questions/22260/icmp-fragmentation/</guid>
      <description>ICMP fragmentation  0 If you can&#39;t see the full image, open the image URL in new window.
On Windows 7, ping www.ea.com -l 32000
Why I am not seeing the fragmentation in Wireshark? I set payload to 32000 bytes but Wireshark is only seeing 1472 bytes (1500 bytes IP MTU- 20 bytes IP header - 8 bytes ICMP ECHO header). So where are the rest 30528 bytes?
I am pretty sure those fragments are actually sent because I still get fragment reassembly time exceeded minutes after the ping.</description>
    </item>
    
    <item>
      <title>Doubt in TCP RFC(seg.seq&#43;seg.len-1=last seq no of segment)</title>
      <link>/questions/22263/doubt-in-tcp-rfcsegseqseglen-1last-seq-no-of-segment/</link>
      <pubDate>Sun, 23 Jun 2013 22:21:00 +0000</pubDate>
      
      <guid>/questions/22263/doubt-in-tcp-rfcsegseqseglen-1last-seq-no-of-segment/</guid>
      <description>Doubt in TCP RFC(seg.seq+seg.len-1=last seq no of segment)  0 Below is the trace of client side communication(all the way from first packet to last) from which i am looking to understand a statement in RFC793.
In pg.28 :seg.seq(first seq number of a segment)+seg.len(the no.of octets occupied by data)-1=last seq no of segment
Here my first sequence number is 0 and total amount of data that traversed is 723 bytes but if we apply this formula the last no should be [0+723-1]=722 which is obviously wrong.</description>
    </item>
    
    <item>
      <title>Custom Wireshark dissector for Ethernet</title>
      <link>/questions/22264/custom-wireshark-dissector-for-ethernet/</link>
      <pubDate>Sun, 23 Jun 2013 23:01:00 +0000</pubDate>
      
      <guid>/questions/22264/custom-wireshark-dissector-for-ethernet/</guid>
      <description>Custom Wireshark dissector for Ethernet  0 Hello All,
I want to identify my custom frame based on &#34;Type&#34; field in the Ethernet and I want to dissect it. I was able to dissect the packets based on TCP/UDP port,but don&#39;t know how to do it at Ethernet level. Also after dissecting the custom Ethernet frame I should be able to give control back to Wireshark to dissect the content of Ethernet frame ie.</description>
    </item>
    
    <item>
      <title>.pcap File format</title>
      <link>/questions/22267/pcap-file-format/</link>
      <pubDate>Mon, 24 Jun 2013 01:52:00 +0000</pubDate>
      
      <guid>/questions/22267/pcap-file-format/</guid>
      <description>.pcap File format  0 hey ,
I need to develop a program that saves a file in .pcap format , I have no information about this format , I would like to know the structure of a file .pcap.
Please can anywone help me.
Thank you
pcapasked 24 Jun &#39;13, 01:52
cruz
11●4●4●6
accept rate: 0%
  
2 Answers:
  
4 You could google for it, and find pages like this:</description>
    </item>
    
    <item>
      <title>Validation of display filter</title>
      <link>/questions/22274/validation-of-display-filter/</link>
      <pubDate>Mon, 24 Jun 2013 04:49:00 +0000</pubDate>
      
      <guid>/questions/22274/validation-of-display-filter/</guid>
      <description>Validation of display filter  0 Our current code provides a GUI which will allow users to create filters. These filters are to be used when performing a live capture or an offline capture when reading a pcap file. We also provide the user with a button which will start Wireshark, reading in a file, performing a display filter and going to a specified packet; I.e. &#34;C:\Program Files\Wireshark\Wireshark.exe&#34; -R &#34;tcp or udp&#34;</description>
    </item>
    
    <item>
      <title>Capture time using capinfos</title>
      <link>/questions/22281/capture-time-using-capinfos/</link>
      <pubDate>Mon, 24 Jun 2013 07:47:00 +0000</pubDate>
      
      <guid>/questions/22281/capture-time-using-capinfos/</guid>
      <description>Capture time using capinfos  0 &#39;capinfos &#34;filename&#34; -u&#39; rounds off capture time and does not return decimal places in windows. On Linux, however, it returns time to two decimal places.
Can you please clarify, how capture time upto two decimal places be retrieved using capinfos/tshark in windows environment?
capture-time tshark capinfosasked 24 Jun &#39;13, 07:47
Rajat
1●4●4●4
accept rate: 0%
  
2 Answers:
  
1Adding the -T flag to get table output causes the duration to be printed with full precision on Windows.</description>
    </item>
    
    <item>
      <title>Throughput calculation</title>
      <link>/questions/22282/throughput-calculation/</link>
      <pubDate>Mon, 24 Jun 2013 07:51:00 +0000</pubDate>
      
      <guid>/questions/22282/throughput-calculation/</guid>
      <description>Throughput calculation  0 Assuming I want to calculate throughputs (using commands) by applying different display filters on same file, I have to calculate capture time from &#34;capinfos -u&#34; and bytes from &#34;tshark -z io,stat,time,filter&#34;
Is there any better way that I can get througput directly? I want to specify display filters in single command and get the throughut directly in a single command.
display-filter throughput tshark capinfosasked 24 Jun &#39;13, 07:51</description>
    </item>
    
    <item>
      <title>Capture Packets in Wireless networks</title>
      <link>/questions/22305/capture-packets-in-wireless-networks/</link>
      <pubDate>Tue, 25 Jun 2013 00:25:00 +0000</pubDate>
      
      <guid>/questions/22305/capture-packets-in-wireless-networks/</guid>
      <description>Capture Packets in Wireless networks  0 How do I capture packets in Wireless network. I am connected to data card with Airtel wireless card. Regards, Anamika
wireless packet-captureasked 25 Jun &#39;13, 00:25
Anamika117
16●2●2●5
accept rate: 0%
  
One Answer:
  
0See the wiki page on WLAN captures.
answered 25 Jun &#39;13, 01:50
grahamb ♦
19.8k●3●30●206
accept rate: 22%
     </description>
    </item>
    
    <item>
      <title>USSD session timeout</title>
      <link>/questions/22307/ussd-session-timeout/</link>
      <pubDate>Tue, 25 Jun 2013 01:21:00 +0000</pubDate>
      
      <guid>/questions/22307/ussd-session-timeout/</guid>
      <description>USSD session timeout  0 My USSD conversation session give timeout after 45 second.abourt is coming from MS side but i don&#39;t know which platform need to increase the timer to be avoid from this timeout.
5555asked 25 Jun &#39;13, 01:21
Hafiz
26●2●2●4
accept rate: 0%
1How is this a Wireshark question? You should ask the question in an appropriate support forum for the software you are using.
(25 Jun &#39;13, 01:49) grahamb ♦thank Grhamb</description>
    </item>
    
    <item>
      <title>fatal error C1189: #error :  Your MSVC_VARIANT setting in config.nmake doesn&amp;#x27;t match the MS compiler version!</title>
      <link>/questions/22313/fatal-error-c1189-error-your-msvc_variant-setting-in-confignmake-doesnt-match-the-ms-compiler-version/</link>
      <pubDate>Tue, 25 Jun 2013 04:16:00 +0000</pubDate>
      
      <guid>/questions/22313/fatal-error-c1189-error-your-msvc_variant-setting-in-confignmake-doesnt-match-the-ms-compiler-version/</guid>
      <description>fatal error C1189: #error : Your MSVC_VARIANT setting in config.nmake doesn&amp;rsquo;t match the MS compiler version!  0 Hello guys.
I got some faults, which i described above in the title. I know that i have to change the MSVC_VARIANT in the config.nmake, but nothing helped. I&#39;m doing the steps like described in the developer-guide of wireshark. I had a lot of issues and a lot of troubleshooting too. Another problem is, that i just want to change the $(FrameworkSdkDir) from v7.</description>
    </item>
    
    <item>
      <title>Who has a capture containing a packet with IEEE 802.3 Raw?</title>
      <link>/questions/22314/who-has-a-capture-containing-a-packet-with-ieee-8023-raw/</link>
      <pubDate>Tue, 25 Jun 2013 04:37:00 +0000</pubDate>
      
      <guid>/questions/22314/who-has-a-capture-containing-a-packet-with-ieee-8023-raw/</guid>
      <description>Who has a capture containing a packet with IEEE 802.3 Raw?  0 I need to get this type of frame. If somebody captures it, please, send it to me.
capture 802.3 rawasked 25 Jun &#39;13, 04:37
DariaS
11●3●3●6
accept rate: 0%
 edited 26 Jun &#39;13, 05:30 
grahamb ♦
19.8k●3●30●206
1For those unfamiliar with it, &#34;802.3 Raw&#34; means &#34;the really old mechanism Netware used to send Netware packets directly over 802.</description>
    </item>
    
    <item>
      <title>After Wireshark install other applications not working</title>
      <link>/questions/22316/after-wireshark-install-other-applications-not-working/</link>
      <pubDate>Tue, 25 Jun 2013 04:44:00 +0000</pubDate>
      
      <guid>/questions/22316/after-wireshark-install-other-applications-not-working/</guid>
      <description>After Wireshark install other applications not working  0 I have two servers one Master and one USA, both are sparc. I have installed the wireshark and my application on Master server and accessing them from UAS server.
When wireshark is not installed, my application is running and GUI launches fine but after installing the wireshark my application is not running, there are several other applications also in that server and all of them are not working after wireshark installation.</description>
    </item>
    
    <item>
      <title>Wireless IP traffic using AirPcap</title>
      <link>/questions/22323/wireless-ip-traffic-using-airpcap/</link>
      <pubDate>Tue, 25 Jun 2013 06:56:00 +0000</pubDate>
      
      <guid>/questions/22323/wireless-ip-traffic-using-airpcap/</guid>
      <description>Wireless IP traffic using AirPcap  0 Hi My name is Satwik and I have a AirPcap adapter with me. I currently need to examine few Wireless IP packets and observe their QOS values. I have installed my AIRPCAP adapter andwhile running wireshark it seems to show only beacon frames. Somehow I dont see any actual data packets(say RTP packets/SIP signalling packets). I contacted the Riverbed support team(AirPcap) and they said the hardware has nothing to do with it.</description>
    </item>
    
    <item>
      <title>TTL (Time To Live)</title>
      <link>/questions/22337/ttl-time-to-live/</link>
      <pubDate>Tue, 25 Jun 2013 20:24:00 +0000</pubDate>
      
      <guid>/questions/22337/ttl-time-to-live/</guid>
      <description>TTL (Time To Live)  1 Dear all,
what is the purpose of TTL on the Internet Protocol message? it live which conversation.
regards,
Hafiz!
ip ttlasked 25 Jun &#39;13, 20:24
Hafiz
26●2●2●4
accept rate: 0%
 edited 27 Jun &#39;13, 02:31 
grahamb ♦
19.8k●3●30●206
Hafiz, can you explain what is the flow/test that you are performing, and the error generated to your HS and ussd app? Also, transaction id&#39;s would be appreciated (related to the trace you have provided).</description>
    </item>
    
    <item>
      <title>How does WireShark figure out whether it&amp;#x27;s keep-alive ack or window update??</title>
      <link>/questions/22340/how-does-wireshark-figure-out-whether-its-keep-alive-ack-or-window-update/</link>
      <pubDate>Tue, 25 Jun 2013 22:53:00 +0000</pubDate>
      
      <guid>/questions/22340/how-does-wireshark-figure-out-whether-its-keep-alive-ack-or-window-update/</guid>
      <description>How does WireShark figure out whether it&amp;rsquo;s keep-alive ack or window update??  0 A tcp keep-alive ack packet is transmitted after a tcp keep-alive packet is received. WireShark usually analyzes and indicates both packets correctly. For example, #428 and #429. However, I guess sometimes WireShark&#39;s analysis regards a keep-alive ack packet as a window update packet. For example, look at #2286 which is supposed to be a keep-alive ack packet.</description>
    </item>
    
    <item>
      <title>compile dissector for Wireshark 1.10</title>
      <link>/questions/22355/compile-dissector-for-wireshark-110/</link>
      <pubDate>Wed, 26 Jun 2013 06:10:00 +0000</pubDate>
      
      <guid>/questions/22355/compile-dissector-for-wireshark-110/</guid>
      <description>compile dissector for Wireshark 1.10  0 Hello,
I was devising application-specific dissector and was doing fine with Wireshark 1.8. After update to 1.10 it fails to compile with following compiler output:
/usr/include/wireshark/wiretap/wtap.h:32:30: fatal error: ws_symbol_export.h: No such file or directory
#include &#34;ws_symbol_export.h&#34;
I&#39;m not sure whether it could be headers installation issue. I use standard Extra repository of Arch Linux to install Wireshark, so it shouldn&#39;t be.
compile plugin dissector 1.</description>
    </item>
    
    <item>
      <title>Finding an easy source of ASN.1 definitions for SULP, LPP, and RRLP to update Wireshark</title>
      <link>/questions/22363/finding-an-easy-source-of-asn1-definitions-for-sulp-lpp-and-rrlp-to-update-wireshark/</link>
      <pubDate>Wed, 26 Jun 2013 08:23:00 +0000</pubDate>
      
      <guid>/questions/22363/finding-an-easy-source-of-asn1-definitions-for-sulp-lpp-and-rrlp-to-update-wireshark/</guid>
      <description>Finding an easy source of ASN.1 definitions for SULP, LPP, and RRLP to update Wireshark  0 I&#39;m looking to update the ASN.1 definitions of the SULP, LPP, and RRLP from their respective specifications. However I was wondering if anybody knew of a better source for ASN.1 definitions than the protocol specifications themselves? Copying and pasting from PDF files would be rather tedious.
rrlp lpp sulp asn1asked 26 Jun &#39;13, 08:23</description>
    </item>
    
    <item>
      <title>Measuring Jitter, Twitch.tv video stream</title>
      <link>/questions/22364/measuring-jitter-twitchtv-video-stream/</link>
      <pubDate>Wed, 26 Jun 2013 08:40:00 +0000</pubDate>
      
      <guid>/questions/22364/measuring-jitter-twitchtv-video-stream/</guid>
      <description>Measuring Jitter, Twitch.tv video stream  0 I want to measure the jitter in the packet stream that I receive from watching a twitch.tv stream since I receive huge performance degredation as the day progresses. Since I can&#39;t use any of the telephony tools since it isn&#39;t streamed over RTP is there any way to do this with a normal(TCP/UDP) packet stream?
I&#39;ve done some looking but all the answers seem to be for VoIP services.</description>
    </item>
    
    <item>
      <title>Help with Rogue DHCP Server</title>
      <link>/questions/22369/help-with-rogue-dhcp-server/</link>
      <pubDate>Wed, 26 Jun 2013 11:23:00 +0000</pubDate>
      
      <guid>/questions/22369/help-with-rogue-dhcp-server/</guid>
      <description>Help with Rogue DHCP Server  0 I have a rogue dhcp server and I was able to track down the machine without any problem. However, I can not determine how the machine is handing out addresses. It is a Snow Leopard Mac with Internet Sharing OFF. Also the DHCP Offer is to a specific machine which is actually a backuppc ubuntu server, NOT a broadcast. Does anyone have any ideas what is going on here?</description>
    </item>
    
    <item>
      <title>adding frame.coloring_rule.name as column to packet list</title>
      <link>/questions/22370/adding-framecoloring_rulename-as-column-to-packet-list/</link>
      <pubDate>Wed, 26 Jun 2013 11:41:00 +0000</pubDate>
      
      <guid>/questions/22370/adding-framecoloring_rulename-as-column-to-packet-list/</guid>
      <description>adding frame.coloring_rule.name as column to packet list  0 I have a strange behaviour when adding the coloring rule name as a column in the packet list.
The contents of the field is not always displayed initially. I need to reorder the columns a couple of times to get all frames&#39; coloring rule name to display correctly. Anybody else having the same problem? Is this a known bug/issue?
I&#39;m running 1.</description>
    </item>
    
    <item>
      <title>Get XHR response data from network traffic</title>
      <link>/questions/22373/get-xhr-response-data-from-network-traffic/</link>
      <pubDate>Wed, 26 Jun 2013 13:49:00 +0000</pubDate>
      
      <guid>/questions/22373/get-xhr-response-data-from-network-traffic/</guid>
      <description>Get XHR response data from network traffic  0 I am monitoring one website that as far I know refreshes data on page through ajax queries. At least I do not see the data inside the page source (html) but I see the data that I need to capture and analyze for example in Chrome browser: -&amp;gt; Developer tools -&amp;gt; Network -&amp;gt; XHR -&amp;gt; pick/click one ajax-link that appears to the list -&amp;gt; response Chrome developer tools setting Log XMLHttpRequest must be checked.</description>
    </item>
    
    <item>
      <title>Understanding Frame Flooding on Ethernet Switch</title>
      <link>/questions/22375/understanding-frame-flooding-on-ethernet-switch/</link>
      <pubDate>Wed, 26 Jun 2013 14:56:00 +0000</pubDate>
      
      <guid>/questions/22375/understanding-frame-flooding-on-ethernet-switch/</guid>
      <description>Understanding Frame Flooding on Ethernet Switch  0 We are seeing an issue on one of our Ethernet switches(Juniper QFX3500) .Ports were shared across the team and each member is complaining that on their captures they are seeing the traffic not intended to them.
Further checking the mac table we identified that destination macs were not discovered by the switch and there is an entry i guess that is causing the issue which is shown below.</description>
    </item>
    
    <item>
      <title>Filtering with a regular expression</title>
      <link>/questions/22376/filtering-with-a-regular-expression/</link>
      <pubDate>Wed, 26 Jun 2013 15:28:00 +0000</pubDate>
      
      <guid>/questions/22376/filtering-with-a-regular-expression/</guid>
      <description>Filtering with a regular expression  0 I am trying to do a regex in wireshark on the following http header and want to filter the ones with an empty value.
User-Agent:
in the trace it shows User-Agent: \r\n
I tried a regex like the following to match User-Agent: followed by a space, then end of line.
frame matches &#34;User-Agent:[\s]$&#34;
but it doesnt work.
Can someone advise whats wrong? thanks</description>
    </item>
    
    <item>
      <title>Monitoring the network packets</title>
      <link>/questions/22381/monitoring-the-network-packets/</link>
      <pubDate>Wed, 26 Jun 2013 18:03:00 +0000</pubDate>
      
      <guid>/questions/22381/monitoring-the-network-packets/</guid>
      <description>Monitoring the network packets  0 I have a 2 questions- 1. I need to a write a C program through which I need to monitor the network packets of the Tshark, in the LINUX. How could I do this?? 2. Is it possible to monitor the rate at which the packets are flowing in the network, if yes how could I do this.
Please answer these questions.
capture packet-captureasked 26 Jun &#39;13, 18:03</description>
    </item>
    
    <item>
      <title>15 second delay in client to server</title>
      <link>/questions/22384/15-second-delay-in-client-to-server/</link>
      <pubDate>Wed, 26 Jun 2013 21:29:00 +0000</pubDate>
      
      <guid>/questions/22384/15-second-delay-in-client-to-server/</guid>
      <description>15 second delay in client to server  1 I have two WCF services A and B. Service A calls service B over a TCP binding with security mode set to transport. Here&#39;s a part of network capture for one such calls. There&#39;s a delay of around 15 seconds between two consecutive TCP Packets. This occurs frequently and I am not sure of the cause here. There can be more than one connection between the two services over different port for different calls at a given point in time.</description>
    </item>
    
    <item>
      <title>Mobile packets not able to be captured in wireshark</title>
      <link>/questions/22387/mobile-packets-not-able-to-be-captured-in-wireshark/</link>
      <pubDate>Wed, 26 Jun 2013 22:32:00 +0000</pubDate>
      
      <guid>/questions/22387/mobile-packets-not-able-to-be-captured-in-wireshark/</guid>
      <description>Mobile packets not able to be captured in wireshark  0 Hi,I have installed Wire shark in my system.The system is connected to a router and my mobile is connected to the same router via WiFi.An evaluation board is also connected to the router via Ethernet.An application from my mobile will be sending packets to the evaluation board.But i could not capture those packets send from the mobile.Please help out.</description>
    </item>
    
    <item>
      <title>Decode packets as T.30 messages in wireshark</title>
      <link>/questions/22391/decode-packets-as-t30-messages-in-wireshark/</link>
      <pubDate>Wed, 26 Jun 2013 23:31:00 +0000</pubDate>
      
      <guid>/questions/22391/decode-packets-as-t30-messages-in-wireshark/</guid>
      <description>Decode packets as T.30 messages in wireshark  0 I need to decode a pcap file as T.30 using wireshark. In supported formats, wireshark has listed T.30. So it should be possible to decode the packets as T.30 messages. Could anybody please help me out how?
t.30asked 26 Jun &#39;13, 23:31
narasimha
1●1●1●1
accept rate: 0%
 edited 27 Jun &#39;13, 13:38 
Guy Harris ♦♦
17.4k●3●35●196
In supported formats, wireshark has listed T.</description>
    </item>
    
    <item>
      <title>Obtaining 802.11 RSSI value on Windows</title>
      <link>/questions/22394/obtaining-80211-rssi-value-on-windows/</link>
      <pubDate>Thu, 27 Jun 2013 00:25:00 +0000</pubDate>
      
      <guid>/questions/22394/obtaining-80211-rssi-value-on-windows/</guid>
      <description>Obtaining 802.11 RSSI value on Windows  0 The capture session could not be initiated (failed to set hardware filter to promiscuous mode).
Please check that &#34;\Device\NPF_{5EDA4C43-AB8B-42A7-A83F-447F77167D48}&#34; is the proper interface.
I tried to capture tthe RSSI value but above error appears... what should I do? please help...
windows rssi wifiasked 27 Jun &#39;13, 00:25
zekar
11●1●1●2
accept rate: 0%
 edited 27 Jun &#39;13, 13:33 
Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>throughput burst when wireshark enabled</title>
      <link>/questions/22401/throughput-burst-when-wireshark-enabled/</link>
      <pubDate>Thu, 27 Jun 2013 05:31:00 +0000</pubDate>
      
      <guid>/questions/22401/throughput-burst-when-wireshark-enabled/</guid>
      <description>throughput burst when wireshark enabled  0 Hi!
We&#39;ve faced an interesting issue. When wireshark (or tcpdump) is enabled we see a bust of throughput measured by iperf.
hostA ---- Linux GatewayA --- RouterA ---- L2VPN ---- RouterB ---- Linux GatewayB ---- hostB
The link between routers is 100Mb/s, Linux Gateways are crypto gates making an IPsec tunnel, so doing iperf between the end hosts we see 28 Mb/s with Wireshark on end hosts disabled, and 44 Mb/s - with Wireshark enabled.</description>
    </item>
    
    <item>
      <title>Packets Count</title>
      <link>/questions/22407/packets-count/</link>
      <pubDate>Thu, 27 Jun 2013 07:54:00 +0000</pubDate>
      
      <guid>/questions/22407/packets-count/</guid>
      <description>Packets Count  0 Is it possible to calculate the rate at which the packets are flowing in the network, for example I need to count the number of packets in 5 minutes or 10 minutes.. Which command to be used
captureasked 27 Jun &#39;13, 07:54
rahuulbp
11●2●2●3
accept rate: 0%
  
One Answer:
  
1In Wireshark use Statistics | Summary, for tshark look at the -z options.</description>
    </item>
    
    <item>
      <title>No Packets - Windows XP SP3 - Wireless USB Adapter</title>
      <link>/questions/22412/no-packets-windows-xp-sp3-wireless-usb-adapter/</link>
      <pubDate>Thu, 27 Jun 2013 08:19:00 +0000</pubDate>
      
      <guid>/questions/22412/no-packets-windows-xp-sp3-wireless-usb-adapter/</guid>
      <description>No Packets - Windows XP SP3 - Wireless USB Adapter  0 Hi, everyone. When I go to Capture &amp;gt; Interfaces..., there are interfaces, one of which is related to my wireless adapter. It shows an IP and the number of packets increasing. However, when I choose Start, nothing it shown on the screen, and, on the bottom, it is written &#34;No Packets&#34;. Why is this happening? Thanks in advance!</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t capture packets on GNS3 virtual routers</title>
      <link>/questions/22415/cant-capture-packets-on-gns3-virtual-routers/</link>
      <pubDate>Thu, 27 Jun 2013 08:51:00 +0000</pubDate>
      
      <guid>/questions/22415/cant-capture-packets-on-gns3-virtual-routers/</guid>
      <description>Can&amp;rsquo;t capture packets on GNS3 virtual routers  0 I&#39;m using debian sid and I installed gns3 and wireshark. I have a router connected to 2 Virtual PCs (using Virtual PC Simulator) and I want to capture the packets, but when I start capturing with wireshark I get the following error &#34;End of file on pipe magic during open&#34;.
capture gns3 debian linuxasked 27 Jun &#39;13, 08:51
Magnus
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark versions after 1.4.11 crash when running on Windows 7 32 bit</title>
      <link>/questions/22432/wireshark-versions-after-1411-crash-when-running-on-windows-7-32-bit/</link>
      <pubDate>Thu, 27 Jun 2013 19:29:00 +0000</pubDate>
      
      <guid>/questions/22432/wireshark-versions-after-1411-crash-when-running-on-windows-7-32-bit/</guid>
      <description>Wireshark versions after 1.4.11 crash when running on Windows 7 32 bit  0 I run Wireshark 1.4.11 on Windows 7 32 bit OS and works OK.
I install any later version of Wireshark and installs OK and starts OK but after 5 or minutes it crashes and wants to close indicating Visual C++ error.
I revert back to Wireshark 1.4.11 and it works reliably and stays open for ages without any problems.</description>
    </item>
    
    <item>
      <title>Question on IP fragmentation</title>
      <link>/questions/22451/question-on-ip-fragmentation/</link>
      <pubDate>Fri, 28 Jun 2013 07:23:00 +0000</pubDate>
      
      <guid>/questions/22451/question-on-ip-fragmentation/</guid>
      <description>Question on IP fragmentation  0 I recently read this piece of information in a book which i want to understand more clearly with experts help from here.
&#34;When a Packet gets fragmented all the fragmented packets gets same TTL Value.If they take different path through a network,they may end up with destination with varying TTL Values.When the first fragment arrives at the destination,however the destination host will begin counting down from the TTL Value of that packet in seconds.</description>
    </item>
    
    <item>
      <title>how to analyse trace</title>
      <link>/questions/22456/how-to-analyse-trace/</link>
      <pubDate>Fri, 28 Jun 2013 10:06:00 +0000</pubDate>
      
      <guid>/questions/22456/how-to-analyse-trace/</guid>
      <description>how to analyse trace  0 Dear all,
Kindly help me for below question.
As im new to wireshark,please tell me how to analyse SMSC trace I have complete .pcap file of one successful SMS trace how to find each and every msges which is sending my SMSC &amp;amp; receiving from that trace.
Thanks &amp;amp; regards, Mahesh
wiresharkasked 28 Jun &#39;13, 10:06
Mahesh2454
1●1●1●1
accept rate: 0%
If possible,Please upload your trace to cloudshark so that people here will get a feel of the protocol/packets/messages you want to analyze.</description>
    </item>
    
    <item>
      <title>ldap response time</title>
      <link>/questions/22462/ldap-response-time/</link>
      <pubDate>Fri, 28 Jun 2013 14:28:00 +0000</pubDate>
      
      <guid>/questions/22462/ldap-response-time/</guid>
      <description>ldap response time  0 Please let me know if ldap.time is working on current version of wireshark. I am using Version 1.8.6 (SVN Rev 48142 from /trunk-1.8). Not sure if this is computed correctly in this version.
If not, is there a way to calculate the ldap (req&amp;lt;-&amp;gt;response) time using wireshark and how.
Thanks Ravi
ldapasked 28 Jun &#39;13, 14:28
Ravi_NS
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Some stats questions</title>
      <link>/questions/22464/some-stats-questions/</link>
      <pubDate>Sat, 29 Jun 2013 01:13:00 +0000</pubDate>
      
      <guid>/questions/22464/some-stats-questions/</guid>
      <description>Some stats questions  0 I&#39;m trying to do the following but having some problems. Could someone give me some hints:
How do I graph the total number of http 200 response codes compared to http 500 response codes in the trace?Same as above but only if those responses were for GET requests? Actually is there a way to display complete streams in the trace which had a GET request?in the stats io graphs - can it filter a particular tcp stream?</description>
    </item>
    
    <item>
      <title>Weird stall in TCP on PS3</title>
      <link>/questions/22465/weird-stall-in-tcp-on-ps3/</link>
      <pubDate>Sat, 29 Jun 2013 05:19:00 +0000</pubDate>
      
      <guid>/questions/22465/weird-stall-in-tcp-on-ps3/</guid>
      <description>Weird stall in TCP on PS3  0 The PS3 tcp stack is a particularly fragile piece of software and it often drops incoming packets, resulting in stalled connections. However, here I have a very strange TCP phenomenon that I cannot quite understand. This happens fairly frequently, I have a script that can make it happen at will. I am making a http request for 1000000 bytes to a server some 40ms RTT away.</description>
    </item>
    
    <item>
      <title>Auto start Wireshark with a filter</title>
      <link>/questions/22466/auto-start-wireshark-with-a-filter/</link>
      <pubDate>Sat, 29 Jun 2013 05:39:00 +0000</pubDate>
      
      <guid>/questions/22466/auto-start-wireshark-with-a-filter/</guid>
      <description>Auto start Wireshark with a filter  0 Hey,
im having issues to start wireshark with the filter i need.
I can auto start capturing from the Interface i need. using the -i # and -k
but i cant set the followint filter to be started aswell currently: expert.message contains &#34;GET /bahamut_n/top/&#34;
only that filter has the info that im always looking for - so all the other info that goes back and forth with the server is useless for me so id rather only see that info - not the whole IP stuff.</description>
    </item>
    
    <item>
      <title>Edit MP3 file by selecting range of packets</title>
      <link>/questions/22475/edit-mp3-file-by-selecting-range-of-packets/</link>
      <pubDate>Sat, 29 Jun 2013 16:22:00 +0000</pubDate>
      
      <guid>/questions/22475/edit-mp3-file-by-selecting-range-of-packets/</guid>
      <description>Edit MP3 file by selecting range of packets  0 I&#39;ve captured streaming audio into a trace file, and I can isolate the conversation and save it as an MP3 with no problem and it works great!
Once I&#39;ve saved the MP3 file, I listen to it with Audacity and make a note of some time blocks I&#39;d like to remove. What I&#39;d like to do is be able to surgically select a range of packets (which, in this case, are the commercials) and delete them from the trace file and then re-save all of the packets as a new MP3 file (minus the commercials or any other junk I don&#39;t want as part of my final MP3 file).</description>
    </item>
    
    <item>
      <title>Ethernet frame check sequence incorrect</title>
      <link>/questions/22483/ethernet-frame-check-sequence-incorrect/</link>
      <pubDate>Sun, 30 Jun 2013 02:41:00 +0000</pubDate>
      
      <guid>/questions/22483/ethernet-frame-check-sequence-incorrect/</guid>
      <description>Ethernet frame check sequence incorrect  1 1I am using Wireshark to debug an obscure problem, but on the way I have started seeing an unrelated issue: every packet sent to the monitoring PC is being flagged as having an incorrect frame check sequence (reported as being 0).
This has started happening from the time I reinstalled Wiresharc, before which no such problems were being reported. I am assuming that the reinstallation gave me a newer version of Wireshark; I am currently running Version 1.</description>
    </item>
    
    <item>
      <title>finding the total number of IP addresses</title>
      <link>/questions/22485/finding-the-total-number-of-ip-addresses/</link>
      <pubDate>Sun, 30 Jun 2013 08:44:00 +0000</pubDate>
      
      <guid>/questions/22485/finding-the-total-number-of-ip-addresses/</guid>
      <description>finding the total number of IP addresses  0 How to find the total number of IP addresses observed in a trace?
I tried using &#34;conversations&#34; and &#34;IP addresses&#34;, which are under statistics option, but didn&#39;t work.
ip trace wiresharkasked 30 Jun &#39;13, 08:44
Irock732
11●2●2●4
accept rate: 0%
  
2 Answers:
  
1Try this:
Windows
tshark -nr input.pcap -q -z ip_hosts,tree | find &#34;Addresses&#34;
Linux</description>
    </item>
    
    <item>
      <title>All the http protocol packets captured are ssl protected</title>
      <link>/questions/22487/all-the-http-protocol-packets-captured-are-ssl-protected/</link>
      <pubDate>Sun, 30 Jun 2013 12:40:00 +0000</pubDate>
      
      <guid>/questions/22487/all-the-http-protocol-packets-captured-are-ssl-protected/</guid>
      <description>All the http protocol packets captured are ssl protected  0 I used to get packets in wireshark, where http protocols were not encrypted but recently every packet with application data in my wireshark captured packets is ssl encrypted. There is not even one packet where I can see http protocol(ie when I filter with http, the result is always empty). It&#39;s protocol is always TLsv1.1 and the data is encrypted, for every packet thats supposed to be http.</description>
    </item>
    
    <item>
      <title>6 bit ASCII representation</title>
      <link>/questions/22490/6-bit-ascii-representation/</link>
      <pubDate>Sun, 30 Jun 2013 15:37:00 +0000</pubDate>
      
      <guid>/questions/22490/6-bit-ascii-representation/</guid>
      <description>6 bit ASCII representation  0 Hi, Can I display the raw data in content packet in 6 bit ASCII instead of the 8 bit ASCII which presented as default?
Thank you
6bit asciiasked 30 Jun &#39;13, 15:37
morton
11●3●3●5
accept rate: 0%
 edited 02 Jul &#39;13, 18:13 
cmaynard ♦♦
9.4k●10●38●142
What do you mean by &#34;6-bit ASCII&#34; and &#34;raw data&#34;? ASCII is a 7-bit character set; Wireshark should, in the hex/ASCII dump pane, be displaying printable characters that have the 8th bit clear as their ASCII values and should be displaying everything else, whether it&#39;s non-printable ASCII or is a byte with the 8th bit set, as a &#34;</description>
    </item>
    
    <item>
      <title>Issue with a website - dup ack and retransmissions</title>
      <link>/questions/22507/issue-with-a-website-dup-ack-and-retransmissions/</link>
      <pubDate>Mon, 01 Jul 2013 06:43:00 +0000</pubDate>
      
      <guid>/questions/22507/issue-with-a-website-dup-ack-and-retransmissions/</guid>
      <description>Issue with a website - dup ack and retransmissions  0 I’m currently having a problem with one particular website. The load times just to view the main page can take upwards to 20 seconds. To see what was taking so long I did a packet capture and found many retransmissions and dup ack (seems to make up the majority of the capture). The thing is it only seems to be happening to our office and the website administrator reports no problems from any other customers, this seems like a true statement.</description>
    </item>
    
    <item>
      <title>how do you capture HTTP_VIA response header ?</title>
      <link>/questions/22516/how-do-you-capture-http_via-response-header/</link>
      <pubDate>Mon, 01 Jul 2013 08:29:00 +0000</pubDate>
      
      <guid>/questions/22516/how-do-you-capture-http_via-response-header/</guid>
      <description>how do you capture HTTP_VIA response header ?  0 I used wireshark to capture http headers to detect proxy, but I am not able to see HTTP_VIA header ,so can somebody help me how to see it ? Thanks in advance !!
httpasked 01 Jul &#39;13, 08:29
mg12
1●1●1●1
accept rate: 0%
  
One Answer:
  
1If the VIA header is not there, then the request was either not being proxied or the proxy did not add the VIA header (the VIA header is optional).</description>
    </item>
    
    <item>
      <title>Understanding Continuation or non-HTTP traffic</title>
      <link>/questions/22518/understanding-continuation-or-non-http-traffic/</link>
      <pubDate>Mon, 01 Jul 2013 12:57:00 +0000</pubDate>
      
      <guid>/questions/22518/understanding-continuation-or-non-http-traffic/</guid>
      <description>Understanding Continuation or non-HTTP traffic  0 I&#39;m writing some code to integrate an in-house app into a DVR to retrieve a video file. This is all reverse engineered as there isn&#39;t any official documentation, and I&#39;m having trouble understanding the following sequence of events (captured by playing with the DVR&#39;s Android app).
936 72.985204 192.168.0.1 192.168.0.200 HTTP 468 POST /cgi-bin/supervisor/NetworkBk.cgi HTTP/1.1 (application/x-www-form-urlencoded) 937 72.985368 192.168.0.200 192.168.0.1 TCP 54 mit-ml-dev &amp;gt; 41859 [ACK] Seq=1 Ack=415 Win=65535 Len=0 938 73.</description>
    </item>
    
    <item>
      <title>TFTP Transfer option negotiation failed error 8 packet trace</title>
      <link>/questions/22519/tftp-transfer-option-negotiation-failed-error-8-packet-trace/</link>
      <pubDate>Mon, 01 Jul 2013 13:14:00 +0000</pubDate>
      
      <guid>/questions/22519/tftp-transfer-option-negotiation-failed-error-8-packet-trace/</guid>
      <description>TFTP Transfer option negotiation failed error 8 packet trace  0 Hey guys,
I have been trying to figure out why my netboot TFTP transfers are failing when the client is asking for option negotiation from the TFTP server.
Basically wireshark has helped me determine that the communication goes like this.
Client (port 10545)-&amp;gt; Server (port 69) Read request for file.exe - Transfer type: octet, blksize\000=512\000, tsize\000=0\000 Server (port 52104) -&amp;gt; Client (port 10545) option acknowledgement, blksize\000=512\000, tsize\000=994464\000</description>
    </item>
    
    <item>
      <title>Using hexviewer to look at the pcap file, how do you know the start of frame?</title>
      <link>/questions/22527/using-hexviewer-to-look-at-the-pcap-file-how-do-you-know-the-start-of-frame/</link>
      <pubDate>Mon, 01 Jul 2013 15:16:00 +0000</pubDate>
      
      <guid>/questions/22527/using-hexviewer-to-look-at-the-pcap-file-how-do-you-know-the-start-of-frame/</guid>
      <description>Using hexviewer to look at the pcap file, how do you know the start of frame?  0 I have a question regarding opening the pcap file from wireshark using a hexviewer and looking at the raw data, I can&#39;t find the start frame delimiter. Is the frame format the same as standard 802.11 or is it different? Thanks for your time and help.
hexdataframeformatasked 01 Jul &#39;13, 15:16
emma</description>
    </item>
    
    <item>
      <title>Capture website name of statistics  by Wireshark ?</title>
      <link>/questions/22530/capture-website-name-of-statistics-by-wireshark/</link>
      <pubDate>Mon, 01 Jul 2013 19:16:00 +0000</pubDate>
      
      <guid>/questions/22530/capture-website-name-of-statistics-by-wireshark/</guid>
      <description>Capture website name of statistics by Wireshark ?  0 Hi everyone .
My boss want me to give the report of the top 10 websites usage by employees. I&#39;m thinking of using Wireshark to capture the Http request and store into a database for statistics. Please help ?
Regards
Henry
capture httpasked 01 Jul &#39;13, 19:16
Quốc Huỳnh Trấn
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Jitter formula</title>
      <link>/questions/22540/jitter-formula/</link>
      <pubDate>Tue, 02 Jul 2013 00:19:00 +0000</pubDate>
      
      <guid>/questions/22540/jitter-formula/</guid>
      <description>Jitter formula  0 J(1) = J(0) + (|D(0,1)| - J(0))/16 -----&amp;gt; why this factor 16 is used?
formula jitter rtpasked 02 Jul &#39;13, 00:19
Surajitm
11●3●3●4
accept rate: 0%
 edited 02 Jul &#39;13, 18:12 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
1It&#39;s defined in the RTP RFC3550
Cite:
 This algorithm is the optimal first-order estimator and the gain parameter 1/16 gives a good noise reduction ratio while maintaining a reasonable rate of convergence [22].</description>
    </item>
    
    <item>
      <title>how to print out http request body as text from a package capture file?</title>
      <link>/questions/22551/how-to-print-out-http-request-body-as-text-from-a-package-capture-file/</link>
      <pubDate>Tue, 02 Jul 2013 01:27:00 +0000</pubDate>
      
      <guid>/questions/22551/how-to-print-out-http-request-body-as-text-from-a-package-capture-file/</guid>
      <description>how to print out http request body as text from a package capture file?  0 Hi,
I have a capture that I can read from tshark but I can&#39;t find an option to print out the request body as text to console. Do you know it is possible? If so, can you provide me an example?
Thanks,
tsharkasked 02 Jul &#39;13, 01:27
seannguyen
16●3●3●5
accept rate: 0%
Do you want to print the whole request body or just the requested URL/URI?</description>
    </item>
    
    <item>
      <title>Duplicate Acks and Fast Retransmissions</title>
      <link>/questions/22554/duplicate-acks-and-fast-retransmissions/</link>
      <pubDate>Tue, 02 Jul 2013 06:04:00 +0000</pubDate>
      
      <guid>/questions/22554/duplicate-acks-and-fast-retransmissions/</guid>
      <description>Duplicate Acks and Fast Retransmissions  0 How when analyzing a wireshark capture can it be determined that duplicate ACKs are a result of loss or missing packets versus delay ?
analysisasked 02 Jul &#39;13, 06:04
George Ciampo
1●1●1●1
accept rate: 0%
  
One Answer:
  
4Usually by looking at the time it took for the packet that was requested by Duplicate ACK to finally arrive. You need to consider the round trip time and ask yourself &#34;</description>
    </item>
    
    <item>
      <title>Finding the sequence of closing TCP connection</title>
      <link>/questions/22558/finding-the-sequence-of-closing-tcp-connection/</link>
      <pubDate>Tue, 02 Jul 2013 10:02:00 +0000</pubDate>
      
      <guid>/questions/22558/finding-the-sequence-of-closing-tcp-connection/</guid>
      <description>Finding the sequence of closing TCP connection  0 how to identify the sequence of closing TCP connection from a saved trace?
network networking trace tcp wiresharkasked 02 Jul &#39;13, 10:02
Irock732
11●2●2●4
accept rate: 0%
  
One Answer:
  
0TCP connection will be closed with segments with either FIN flag set or RST Flag set.Check out the tcp segments with these Flags set to start with to identify the closing sequence.</description>
    </item>
    
    <item>
      <title>Decompress gzip POST frame</title>
      <link>/questions/22560/decompress-gzip-post-frame/</link>
      <pubDate>Tue, 02 Jul 2013 10:46:00 +0000</pubDate>
      
      <guid>/questions/22560/decompress-gzip-post-frame/</guid>
      <description>Decompress gzip POST frame  0 I have the following HTTP frame: POST /Usage/Upload?compression=gzip HTTP/1.1 How can I show it decompressed? Please note: It is a POST (to the server) not a GET (from the server)
gzipasked 02 Jul &#39;13, 10:46
Hanky
11●1●1●2
accept rate: 0%
  
One Answer:
  
0POST /Usage/Upload?compression=gzip
sounds like your application is doing the compression, so it&#39;s (most certainly) not the built in compression available in HTTP.</description>
    </item>
    
    <item>
      <title>Site instability - Cloudflare problem</title>
      <link>/questions/22562/site-instability-cloudflare-problem/</link>
      <pubDate>Tue, 02 Jul 2013 11:14:00 +0000</pubDate>
      
      <guid>/questions/22562/site-instability-cloudflare-problem/</guid>
      <description>Site instability - Cloudflare problem  0 Hi,
I just want to report recurrent problems with access to http://ask.wireshark.org during the last two weeks. I often see error messages from Cloudflare like &#34;no live server available, please try later&#34; or something like this:
502 Bad Gateway cloudflare-nginxAre these problems location related (access from different regions of the world), or a general problem with the hosting of the site in the Cloudflare cloud?</description>
    </item>
    
    <item>
      <title>MTP3 - SS7 DPC and OPC are shown identical</title>
      <link>/questions/22567/mtp3-ss7-dpc-and-opc-are-shown-identical/</link>
      <pubDate>Tue, 02 Jul 2013 11:46:00 +0000</pubDate>
      
      <guid>/questions/22567/mtp3-ss7-dpc-and-opc-are-shown-identical/</guid>
      <description>MTP3 - SS7 DPC and OPC are shown identical  0 Hello:
When I decode a MTP3 section (SS7 with CAMEL-v2 protocol), Wireshark indicate that the SOURCE and DESTINATION Point Code are the same (always is the OPC for both values).
Actually, when you see the decodification part below, you look OK (i.e. OPC and DPC are different).
I observed this error -at least - in this versions: Wireshark-win32-1.8.4, Wireshark-win32-1.8.6 and Wireshark-win32-1.</description>
    </item>
    
    <item>
      <title>Filtering 802.11 MAC Addresses</title>
      <link>/questions/22568/filtering-80211-mac-addresses/</link>
      <pubDate>Tue, 02 Jul 2013 12:58:00 +0000</pubDate>
      
      <guid>/questions/22568/filtering-80211-mac-addresses/</guid>
      <description>Filtering 802.11 MAC Addresses  0 I am using an AirPcap with Wireshark for the first time and receiving lots of wireless packets. I am trying to filter by MAC address. So I tried using wlan_mgt.fixed.src_mac_addr == 00:06:66:54:21:75 for the MAC address that is transmitting but when I apply the filter it filters out everything including the packets sent by 00:06:66:54:21:75. So is there a way to filter 802.11 MAC addresses?</description>
    </item>
    
    <item>
      <title>text2pcap &amp;quot;Inconsistent offset. Expecting 0, got 10&amp;quot;</title>
      <link>/questions/22570/text2pcap-inconsistent-offset-expecting-0-got-10/</link>
      <pubDate>Tue, 02 Jul 2013 13:10:00 +0000</pubDate>
      
      <guid>/questions/22570/text2pcap-inconsistent-offset-expecting-0-got-10/</guid>
      <description>text2pcap &amp;ldquo;Inconsistent offset. Expecting 0, got 10&amp;rdquo;  0 I have the following data I&#39;d like to convert to a pcap with text2pcap:
# cat ~/temp.argus 12:00:01.3214 0000 2665 7547 4a0b c0f2 0fed 1a9b 9c1d b9f3 &amp;amp;euGJ........... 0010 7096 d098 7a1f 6255 f92e d9b0 b202 6c03 p...z.bU......l.I attempt to do this by executing the following:
# text2pcap -i 4 -T 65000,80 -d ~/temp.argus ~/test.pcapBut I receive the following error and conversion fails:</description>
    </item>
    
    <item>
      <title>Unhandled exception (group=1, code=6) in Wireshark 1.0.6</title>
      <link>/questions/22576/unhandled-exception-group1-code6-in-wireshark-106/</link>
      <pubDate>Tue, 02 Jul 2013 15:03:00 +0000</pubDate>
      
      <guid>/questions/22576/unhandled-exception-group1-code6-in-wireshark-106/</guid>
      <description>Unhandled exception (group=1, code=6) in Wireshark 1.0.6  -1 Ok so I am updating to the latest Wireshark-win64-1.10.0 But bear in mind, if you didn&#39;t fix it, it ain&#39;t fixed.
TShark 1.0.6 (SVN Rev 27387)
The command that generated this was:
C:\Progra~2\Wireshark\tshark host 199.119.127.205 -S -s 4096 -R &amp;quot;http.request.method == \&amp;quot;POST\&amp;quot;&amp;quot; -w C:\users\markt\Desktop\captures\20130702_%RANDOMSTUFF%.pcapThe file size generated was 2.20 GB (2,366,529,322 bytes)
41384.525053 192.168.1.101 -&amp;gt; 199.119.127.205 HTTP POST /ajax/ping HTTP/1.1 (application/x-www-form-urlencoded) Unhandled exception (group=1, code=6) This application has requested the Runtime to terminate it in an unusual way.</description>
    </item>
    
    <item>
      <title>Question about Passive FTP</title>
      <link>/questions/22585/question-about-passive-ftp/</link>
      <pubDate>Tue, 02 Jul 2013 19:46:00 +0000</pubDate>
      
      <guid>/questions/22585/question-about-passive-ftp/</guid>
      <description>Question about Passive FTP  0 I am aware that firewall will block the incoming data connection(the syn packet with source port 20) in case of Active FTP and therefore enterprises prefers to go with Passive where control and data will be initiated by client.
My question is
Why in passive FTP the client opens data connection to a random port specified by the server rather than to port 20? If ,by any chance someone designs passive ftp server which will send port 20 (in PASV) for data connection will the firewall block that incoming syn-ack(Data connection)from server?</description>
    </item>
    
    <item>
      <title>Show address resolution usage</title>
      <link>/questions/22588/show-address-resolution-usage/</link>
      <pubDate>Wed, 03 Jul 2013 01:08:00 +0000</pubDate>
      
      <guid>/questions/22588/show-address-resolution-usage/</guid>
      <description>Show address resolution usage  0 Hello,
I am in middle of troubleshooting the issue and have noticed couple of things.
I have network name resolution checked for MAC and Network layer, sniffer traces does show name resolution during live captures however, as soon as file is saved and re-opened some entries are missing. So, I have couple of queries :-
Does Name Resolution looks at the current workstation cache and if TTL is small the cache will be deleted so, we don&#39;t see the mapping later on?</description>
    </item>
    
    <item>
      <title>Dissector handle</title>
      <link>/questions/22590/dissector-handle/</link>
      <pubDate>Wed, 03 Jul 2013 02:25:00 +0000</pubDate>
      
      <guid>/questions/22590/dissector-handle/</guid>
      <description>Dissector handle  0 I&#39;m trying to develop my own dissector for some protocol I&#39;ve analysed. I took skeleton dissector from README.developer and filled it. Now that I&#39;m trying to compile it I get following error, and cannot figure out what&#39;s wrong:
/home/andrey/grive/wireshark-dissector-template/packet-intl.c: In function ‘proto_reg_handoff_intl’: /home/andrey/grive/wireshark-dissector-template/packet-intl.c:370:58: warning: passing argument 1 of ‘new_create_dissector_handle’ from incompatible pointer type [enabled by default] proto_intl); ^ In file included from /home/andrey/grive/wireshark-dissector-template/packet-intl.c:46:0: /usr/include/wireshark/epan/packet.h:322:34: note: expected ‘new_dissector_t’ but argument is of type ‘int (*)(struct tvbuff_t *, struct packet_info *, struct proto_tree *)’ WS_DLL_PUBLIC dissector_handle_t new_create_dissector_handle(new_dissector_t dissector,compile dissector 1.</description>
    </item>
    
    <item>
      <title>capturing fcs frames</title>
      <link>/questions/22591/capturing-fcs-frames/</link>
      <pubDate>Wed, 03 Jul 2013 02:28:00 +0000</pubDate>
      
      <guid>/questions/22591/capturing-fcs-frames/</guid>
      <description>capturing fcs frames  0 Trying to capture fcs for Ethernet frame. what be the best bet to capture it would that be netBSD. Any clues folks who have tried it before.
ethernet fcsasked 03 Jul &#39;13, 02:28
Dees
1●3●3●3
accept rate: 0%
  
2 Answers:
  
0Please see my answer to a similar question:
http://ask.wireshark.org/questions/21272/ethernet-ii-with-bad-fcs
If that does not help, please add some details to your question.</description>
    </item>
    
    <item>
      <title>capture filter default</title>
      <link>/questions/22595/capture-filter-default/</link>
      <pubDate>Wed, 03 Jul 2013 04:45:00 +0000</pubDate>
      
      <guid>/questions/22595/capture-filter-default/</guid>
      <description>capture filter default  0 Hello, How can I configure wireshark to have custom, default capture filter? There is option -f for wireshark which lets read custom filter by wireshark, but I could not find how to make this filter in required format (libpcap). Im not programist and I dont know how to play with pcap_compile. Is there an painless way for preparing this filter? Regards, R
capture-filter pcap_compile libpcapasked 03 Jul &#39;13, 04:45</description>
    </item>
    
    <item>
      <title>How to decode Sahara ?</title>
      <link>/questions/22596/how-to-decode-sahara/</link>
      <pubDate>Wed, 03 Jul 2013 05:17:00 +0000</pubDate>
      
      <guid>/questions/22596/how-to-decode-sahara/</guid>
      <description>How to decode Sahara ?  0 WireShark v0.99 was able to decode Sahara. Now in version 1.10, Sahara decoding is no longer available. Is there any way to decode Sahara with the new version?
decode saharaasked 03 Jul &#39;13, 05:17
viperfx15
1●1●1●1
accept rate: 0%
  
One Answer:
  
0I was not able to find a reference to the &#39;Sahara&#39; protocol in the source code of Wireshark 0.</description>
    </item>
    
    <item>
      <title>VS2010 - How to import the source files correct | Add multiple bytes in one item</title>
      <link>/questions/22597/vs2010-how-to-import-the-source-files-correct-add-multiple-bytes-in-one-item/</link>
      <pubDate>Wed, 03 Jul 2013 05:27:00 +0000</pubDate>
      
      <guid>/questions/22597/vs2010-how-to-import-the-source-files-correct-add-multiple-bytes-in-one-item/</guid>
      <description>VS2010 - How to import the source files correct | Add multiple bytes in one item  0 Hello,
I&#39;m new to WireShark devolopment; forgive my noob question ;) I couldn&#39;t found it on this site, so I ask here.
I&#39;m able to build and run WireShark; I can also debug it in VS 2010. But i can&#39;t get rid of the red underlines in VS2010 under many functions. VS2010 can&#39;t find my source files.</description>
    </item>
    
    <item>
      <title>getting PDUs length</title>
      <link>/questions/22600/getting-pdus-length/</link>
      <pubDate>Wed, 03 Jul 2013 06:27:00 +0000</pubDate>
      
      <guid>/questions/22600/getting-pdus-length/</guid>
      <description>getting PDUs length  1 1I want to get the PDUs length, I think it is found here:
tvbuff_t *tvb -&amp;gt; length
or
packet_info *pinfo -&amp;gt; gssapi_decrypted_tvb -&amp;gt; length
But when I compile, I get an error from the compiler:
error C2037: left of &#39;length&#39; specifies undefined struct/union &#39;tvbuff&#39;
Does someone know what it is?
member &#34;length&#34; exists. you can see it here.
Thanks
tvbuff_t pinfo dissector tcp wiresharkasked 03 Jul &#39;13, 06:27</description>
    </item>
    
    <item>
      <title>Protocol Field  when doing SSL decryption using Pre-master-secret</title>
      <link>/questions/22611/protocol-field-when-doing-ssl-decryption-using-pre-master-secret/</link>
      <pubDate>Wed, 03 Jul 2013 07:39:00 +0000</pubDate>
      
      <guid>/questions/22611/protocol-field-when-doing-ssl-decryption-using-pre-master-secret/</guid>
      <description>Protocol Field when doing SSL decryption using Pre-master-secret  0 I am using the pre-master-secret to decrypt SSL web traffic. I can see the reassembled and decrypted packets just fine. It works great! Thanks for this feature, by the way. The negotiated version of TLS is TLSv1 for this session but I sometimes see TLSv1 in the protocol field and sometimes see SSL in the protocol field in the same stream.</description>
    </item>
    
    <item>
      <title>How to add extra dissected packets to info column when reassembling is on</title>
      <link>/questions/22612/how-to-add-extra-dissected-packets-to-info-column-when-reassembling-is-on/</link>
      <pubDate>Wed, 03 Jul 2013 07:57:00 +0000</pubDate>
      
      <guid>/questions/22612/how-to-add-extra-dissected-packets-to-info-column-when-reassembling-is-on/</guid>
      <description>How to add extra dissected packets to info column when reassembling is on  0 I would like to add all of the dissected messages&#39;s type of my protocol Protoc to the Info column.
I&#39;m enabling reassembling of tcp packets. So sometimes, as you can see in the picture, there might be couple of messages of my protocol in one reassembled pdu.
The problem is that only [TYPE A] is shown in the Info column.</description>
    </item>
    
    <item>
      <title>How to check for TIFF files in a capture</title>
      <link>/questions/22618/how-to-check-for-tiff-files-in-a-capture/</link>
      <pubDate>Wed, 03 Jul 2013 12:05:00 +0000</pubDate>
      
      <guid>/questions/22618/how-to-check-for-tiff-files-in-a-capture/</guid>
      <description>How to check for TIFF files in a capture  0 I have a capture of a fax to email which is a bad transmission. The file that is created is a TIFF file that is emailed to a persons inbox. I need to see that file so I can see where the issue is.
ralbo-microasked 03 Jul &#39;13, 12:05
ralbo-micor
1●1●1●2
accept rate: 0%
 edited 03 Jul &#39;13, 12:11</description>
    </item>
    
    <item>
      <title>Decrypt SIP messages on IP phone logged in to lync</title>
      <link>/questions/22630/decrypt-sip-messages-on-ip-phone-logged-in-to-lync/</link>
      <pubDate>Wed, 03 Jul 2013 23:05:00 +0000</pubDate>
      
      <guid>/questions/22630/decrypt-sip-messages-on-ip-phone-logged-in-to-lync/</guid>
      <description>Decrypt SIP messages on IP phone logged in to lync  0 Hi ,
I have to decrypt the SIP messages on wire shark. I have a phone which is logged in to Lync server and is sending packets when there is communication between the phone and server. Please tell me how i can decrypt the messages. I have a .pem file and have given the serverip,port,sip,&amp;lt;file locatoin=&#34;&#34;&amp;gt; in preferences (SSL).</description>
    </item>
    
    <item>
      <title>Dynamically add subtrees</title>
      <link>/questions/22641/dynamically-add-subtrees/</link>
      <pubDate>Thu, 04 Jul 2013 04:59:00 +0000</pubDate>
      
      <guid>/questions/22641/dynamically-add-subtrees/</guid>
      <description>Dynamically add subtrees  0 I&#39;m coding a dissector and want to dynamically add subtrees depending on number of parameters detected in the packet. Is there a way to do that?
dissector 1.10.0asked 04 Jul &#39;13, 04:59
Andrey
21●4●4●7
accept rate: 50%
I&#39;m not certain of your question, most dissectors do something like that anyway as they dissect the packet.
Can you explain with some more detail what you want to achieve?</description>
    </item>
    
    <item>
      <title>So how do you work out the switch port your on?</title>
      <link>/questions/22644/so-how-do-you-work-out-the-switch-port-your-on/</link>
      <pubDate>Thu, 04 Jul 2013 05:33:00 +0000</pubDate>
      
      <guid>/questions/22644/so-how-do-you-work-out-the-switch-port-your-on/</guid>
      <description>So how do you work out the switch port your on?  0 Hi
So i&#39;m a beginner. In a home network, how do you find out what switch port your PC is on?
The wiring was done awhile ago and goes under floor boards etc so cant physically trace the cables.
Thanks.
home switch port networkasked 04 Jul &#39;13, 05:33
Sean87
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>split netscalar large trace file</title>
      <link>/questions/22648/split-netscalar-large-trace-file/</link>
      <pubDate>Thu, 04 Jul 2013 06:00:00 +0000</pubDate>
      
      <guid>/questions/22648/split-netscalar-large-trace-file/</guid>
      <description>split netscalar large trace file  0 How to split large netscalar cap file,it is showing sun snoop file type,tried editcap with no luck
nstraceasked 04 Jul &#39;13, 06:00
kishan pandey
221●28●29●36
accept rate: 28%
  
One Answer:
  
0 Please call editcap with the following option
editcap -F snoop
UPDATE
I&#39;m sorry, I was on the wrong track. -F is just the output file format.</description>
    </item>
    
    <item>
      <title>Import hex dump not working as expected</title>
      <link>/questions/22654/import-hex-dump-not-working-as-expected/</link>
      <pubDate>Thu, 04 Jul 2013 07:13:00 +0000</pubDate>
      
      <guid>/questions/22654/import-hex-dump-not-working-as-expected/</guid>
      <description>Import hex dump not working as expected  0 Hello,
I have created a TCL script that creates a text file containing a wireshark hex dump.
The text file consists of multiple lines similar to this one:
000000 90 b1 1c 99 53 f5 00 18 19 b5 86 44 08 00 4D FE 04 08 E7 5C 1BThis is just the beginning of a line, it contains a TCP packet encapsulated with IPv4 and then ethernet.</description>
    </item>
    
    <item>
      <title>Duplicated code in dissectors</title>
      <link>/questions/22656/duplicated-code-in-dissectors/</link>
      <pubDate>Thu, 04 Jul 2013 07:34:00 +0000</pubDate>
      
      <guid>/questions/22656/duplicated-code-in-dissectors/</guid>
      <description>Duplicated code in dissectors  0 Hi. I have two custom dissectors that i have written. The two protocols i dissect have fields that are very similar to eachother. The headers are different and some other things, but 1 quite large part of the protocol is identical. In my code i have a quite big while-loop that extracts data and adds it to the proto tree, and this loop is identical in both dissectors.</description>
    </item>
    
    <item>
      <title>function tvb_get_ntohs</title>
      <link>/questions/22664/function-tvb_get_ntohs/</link>
      <pubDate>Thu, 04 Jul 2013 10:07:00 +0000</pubDate>
      
      <guid>/questions/22664/function-tvb_get_ntohs/</guid>
      <description>function tvb_get_ntohs  0 hi everyone,
What is the exact role of function &#34;tvb_get_ntohs&#34; , if we write :
ch1 = tvb_get_ntohs(tvb, 0); ch2 = tvb_get_ntohs(tvb, 2);
what does it mean exactly , i know that the tvb is buffer where our data is recorded, but the second element is an offset , What&#39;s that? and what does it mean this offset.
Thank you.
tvbgetasked 04 Jul &#39;13, 10:07
cruz</description>
    </item>
    
    <item>
      <title>How to compare two SIP call traces?</title>
      <link>/questions/22665/how-to-compare-two-sip-call-traces/</link>
      <pubDate>Thu, 04 Jul 2013 10:35:00 +0000</pubDate>
      
      <guid>/questions/22665/how-to-compare-two-sip-call-traces/</guid>
      <description>How to compare two SIP call traces?  0 Hello All,
I have a question as I have started working on Wireshark recently.
I have two capture files and under both the Pcaps, there are so many VoIP calls but I am only interested in one VoIP (SIP) call which is actually somewhat similar in both the captures. The flow of that call includes multiple legs as the call is going through an SBC and also it includes multiple re-invites.</description>
    </item>
    
    <item>
      <title>Start program through Sandbox and watch traffic made by it</title>
      <link>/questions/22668/start-program-through-sandbox-and-watch-traffic-made-by-it/</link>
      <pubDate>Thu, 04 Jul 2013 13:23:00 +0000</pubDate>
      
      <guid>/questions/22668/start-program-through-sandbox-and-watch-traffic-made-by-it/</guid>
      <description>Start program through Sandbox and watch traffic made by it  0 Hi,
I would like to check which connections and where to a program did, but I have problems setting Wireshark up. HTTP only connections aren&#39;t enough, I want to see if it does more than it.
I don&#39;t even know where to see which program did specific traffic in Wireshark so I would really appreciate help. Although I know about Wireshark since months and use it a few times I&#39;m not pro in it.</description>
    </item>
    
    <item>
      <title>For the quadrilionth time - Wireshark(Windows) Cisco MIBS</title>
      <link>/questions/22677/for-the-quadrilionth-time-wiresharkwindows-cisco-mibs/</link>
      <pubDate>Thu, 04 Jul 2013 15:15:00 +0000</pubDate>
      
      <guid>/questions/22677/for-the-quadrilionth-time-wiresharkwindows-cisco-mibs/</guid>
      <description>For the quadrilionth time - Wireshark(Windows) Cisco MIBS  -6 Please forgive the tone, I am so [expletive] angry right now...
For windows the SNMP wireshark page is worthless.
I downloaded the v2 zip from Cisco and unzipped it to c:\users\me\v2I copied all the .my files from step 1 to c:\users\me\mibsThen with Cygwin I got rid of the .my with &#34;for i in ls;do mv $i `echo $i | awk -F.</description>
    </item>
    
    <item>
      <title>In SGsAP Status message the Erroneous message IE showing as extraneous data</title>
      <link>/questions/22682/in-sgsap-status-message-the-erroneous-message-ie-showing-as-extraneous-data/</link>
      <pubDate>Fri, 05 Jul 2013 00:32:00 +0000</pubDate>
      
      <guid>/questions/22682/in-sgsap-status-message-the-erroneous-message-ie-showing-as-extraneous-data/</guid>
      <description>In SGsAP Status message the Erroneous message IE showing as extraneous data  0 I am using Wireshark version 1.10.0rc2. In my SGsAP Status message the Erroneous message IE showing as extraneous data. Though by looking at the hex values i think the IE in the packet is right. It is like -
1b 0b XX XX XX XX XX XX XX XX XX XX XX
sgsapasked 05 Jul &#39;13, 00:32</description>
    </item>
    
    <item>
      <title>Data Structure of address defined in address.h</title>
      <link>/questions/22683/data-structure-of-address-defined-in-addressh/</link>
      <pubDate>Fri, 05 Jul 2013 00:36:00 +0000</pubDate>
      
      <guid>/questions/22683/data-structure-of-address-defined-in-addressh/</guid>
      <description>Data Structure of address defined in address.h  0 Hello! I want to put the protocol information which is dissected by Wireshark into SQL Server. Now I am planning to add codes in the function of add_packet_to_packet_list in file.c. And the place to insert new codes is somewhere after the line of
 row = packet_list_append(cinfo, fdata, &amp;amp;edt.pi);I have figured out that the row equals to the column number minus one.</description>
    </item>
    
    <item>
      <title>capture on bundled port(4 port part of  etherchannel)</title>
      <link>/questions/22687/capture-on-bundled-port4-port-part-of-etherchannel/</link>
      <pubDate>Fri, 05 Jul 2013 02:25:00 +0000</pubDate>
      
      <guid>/questions/22687/capture-on-bundled-port4-port-part-of-etherchannel/</guid>
      <description>capture on bundled port(4 port part of etherchannel)  0 Is it possible to capture on bundled ports accurately,capturing 4 gb on 1 bg interface looks not feasible but still how?
etherchannelasked 05 Jul &#39;13, 02:25
kishan pandey
221●28●29●36
accept rate: 28%
  
One Answer:
  
0It depends where you want to capture.
If you want to capture on a switch, you will have a hard time, because it does not make sense to mirror 4 ports to only one capturing port, as the capturing link can be flooded in case of massive traffic.</description>
    </item>
    
    <item>
      <title>Problems with editcap and &amp;quot;wpan&amp;quot; encapsulation option</title>
      <link>/questions/22689/problems-with-editcap-and-wpan-encapsulation-option/</link>
      <pubDate>Fri, 05 Jul 2013 07:27:00 +0000</pubDate>
      
      <guid>/questions/22689/problems-with-editcap-and-wpan-encapsulation-option/</guid>
      <description>Problems with editcap and &amp;ldquo;wpan&amp;rdquo; encapsulation option  0 Hello everyone. I&#39;m doing some work in wireless sensor networks and right now I have a capture file with some IEEE 802.15.4 frames encapsulated in SLL. The protocols in each frame are: sll:wpan:6lowpan:ipv6:icmpv6
I tried removing the SLL header and changing the encapsulation type using editcap with the following command:
editcap -T wpan -C 16 test.pcap test_wpan.pcap
However, when trying to read the test_wpan.</description>
    </item>
    
    <item>
      <title>Tshark decoding</title>
      <link>/questions/22690/tshark-decoding/</link>
      <pubDate>Fri, 05 Jul 2013 08:12:00 +0000</pubDate>
      
      <guid>/questions/22690/tshark-decoding/</guid>
      <description>Tshark decoding  0 I&#39;m using the command tshark to have a txt file with a dump of some packets. It works but I&#39;ve got a problem. I&#39;ve got UDP packets with proprietary protocol and in some cases wireshark decodes them as wrong protocol and I can see them as malformed packets. Actually they aren&#39;t malformed because of the proprietary protocol. When I dump the packets I can see only the packets not recognized by wireshark and empty data for &#34;</description>
    </item>
    
    <item>
      <title>why 65535 is the limit ?</title>
      <link>/questions/22694/why-65535-is-the-limit/</link>
      <pubDate>Fri, 05 Jul 2013 12:57:00 +0000</pubDate>
      
      <guid>/questions/22694/why-65535-is-the-limit/</guid>
      <description>why 65535 is the limit ?  0 Why this is the limit in ports and others technology ? Why cant more than it ? :/
questionasked 05 Jul &#39;13, 12:57
leo4b
1●1●1●1
accept rate: 0%
  
One Answer:
  
4 65535 is the largest number that can be held in a 16 bit unsigned integer. As this is the size of the port field in TCP/UDP then that limits the range of port numbers.</description>
    </item>
    
    <item>
      <title>arp poisoning attack on port 443</title>
      <link>/questions/22704/arp-poisoning-attack-on-port-443/</link>
      <pubDate>Sun, 07 Jul 2013 23:37:00 +0000</pubDate>
      
      <guid>/questions/22704/arp-poisoning-attack-on-port-443/</guid>
      <description>arp poisoning attack on port 443  0 I am trying to understand the basics behind arp poisoning and here is the setup
Target Machine----&amp;gt;AttackerSystem(running Cain&amp;amp;Abel)----&amp;gt;Defaultgateway
I am able to spoof all the traffic from Target Machine to Internet on port 80 but i would like to know why i am generating ACK,RST for SYN Packets initiated by Target Machine on port 443? I vaguely realize it has to do with encryption and key exchange which my system(Attackersystem) has no ability but looking for a vivid answer.</description>
    </item>
    
    <item>
      <title>Graph Filter limitations</title>
      <link>/questions/22706/graph-filter-limitations/</link>
      <pubDate>Mon, 08 Jul 2013 01:27:00 +0000</pubDate>
      
      <guid>/questions/22706/graph-filter-limitations/</guid>
      <description>Graph Filter limitations  0 I&#39;ve been experimenting with different ways to display certain traffic. First I display traffic trough the IO Graph tool, next I try to add a second line (Red to mark it as unwanted) and add a Filter. The problem however is that the Graph tool does not support as long a filter as regular display filters.
Is this normal behavior? Is there anyway around this? Perhaps any suggestions how to better show all network traffic and highlight certain (unwanted) traffic in graphs?</description>
    </item>
    
    <item>
      <title>Capturing Bluetooth on windows 7</title>
      <link>/questions/22715/capturing-bluetooth-on-windows-7/</link>
      <pubDate>Mon, 08 Jul 2013 02:42:00 +0000</pubDate>
      
      <guid>/questions/22715/capturing-bluetooth-on-windows-7/</guid>
      <description>Capturing Bluetooth on windows 7  0 Hi, How can i capture Bluetooth packets on Windowns 7/XP? Which hardware is required for capturing the packets?
Regards, Manjunath
windows bluetoothasked 08 Jul &#39;13, 02:42
ManjunathMN
1●1●1●1
accept rate: 0%
 edited 10 Jul &#39;13, 07:33 
Kurt Knochner ♦
24.8k●10●39●237
  
One Answer:
  
0There is no Bluetooth support in WinPcap, which means you cannot capture Bluetooth on Windows 7 with Wireshark.</description>
    </item>
    
    <item>
      <title>Backporting a wireshark dissector plugin</title>
      <link>/questions/22722/backporting-a-wireshark-dissector-plugin/</link>
      <pubDate>Mon, 08 Jul 2013 04:22:00 +0000</pubDate>
      
      <guid>/questions/22722/backporting-a-wireshark-dissector-plugin/</guid>
      <description>Backporting a wireshark dissector plugin  0 Hi, i have a custom dissector plugin that i am trying to backport from wireshark 1.11 that i developed it for to wireshark 1.2.18. (It works on 1.11)
Now i get errors while compiling with the old version of wireshark: error C2065 : ENC_BIG_ENDIAN : undeclared identifier
I am using the variable in proto_tree_add_item(tree,id,tvb,offset,length,ENC_BIG_ENDIAN); The same error occurs when i use ENC_NA. I could get rid of the error by replacing ENC_BIG_ENDIAN with FALSE but i am not sure if that is the correct way to do it ?</description>
    </item>
    
    <item>
      <title>filtering capture result for specific programs</title>
      <link>/questions/22723/filtering-capture-result-for-specific-programs/</link>
      <pubDate>Mon, 08 Jul 2013 05:46:00 +0000</pubDate>
      
      <guid>/questions/22723/filtering-capture-result-for-specific-programs/</guid>
      <description>filtering capture result for specific programs  0 Is it possible to filter the capture result for specific programs so that it only shows the packets which that program has sent/recieved ?
capture program filteringasked 08 Jul &#39;13, 05:46
Milad Rad
16●2●2●4
accept rate: 0%
  
One Answer:
  
0No, you can&#39;t unless each program uses specific ports that you can associate to the program, e.g. port 80 being an apache web server process.</description>
    </item>
    
    <item>
      <title>Apple DMAP protocol support</title>
      <link>/questions/22725/apple-dmap-protocol-support/</link>
      <pubDate>Mon, 08 Jul 2013 07:13:00 +0000</pubDate>
      
      <guid>/questions/22725/apple-dmap-protocol-support/</guid>
      <description>Apple DMAP protocol support  0 I&#39;ve written a library for sharing music to iTunes and iPhoto. AFAIK, this implementation is THE implementation that contains the most complete dissection of the Apple proprietary protocols of the DMAP family to date - more complete than the plugin in wireshark is currently supporting. If you should find any interest in it for updating the DAAP/DPAP/DMAP plugin, have a look at it @ https://github.</description>
    </item>
    
    <item>
      <title>Determine the direction of a conversation (client, server)</title>
      <link>/questions/22727/determine-the-direction-of-a-conversation-client-server/</link>
      <pubDate>Mon, 08 Jul 2013 07:38:00 +0000</pubDate>
      
      <guid>/questions/22727/determine-the-direction-of-a-conversation-client-server/</guid>
      <description>Determine the direction of a conversation (client, server)  0 I&#39;m writing a dissector for a TCP-based protocol in C.
Is it possible to determine whether a packet goes in the client-to-server or in the server-to-client direction?
I have set up a conversation state, but I&#39;m not sure what to put into it. I can recognize the first packet in the conversation (client-to-server), and I use that to store pinfo-&amp;gt;srcport and pinfo-&amp;gt;destport in the conversation state, and in future packets I can compare pinfo-&amp;gt;srcport against the stored value in the conversation.</description>
    </item>
    
    <item>
      <title>Wireshark crashes when closing flow graph window</title>
      <link>/questions/22734/wireshark-crashes-when-closing-flow-graph-window/</link>
      <pubDate>Mon, 08 Jul 2013 13:41:00 +0000</pubDate>
      
      <guid>/questions/22734/wireshark-crashes-when-closing-flow-graph-window/</guid>
      <description>Wireshark crashes when closing flow graph window  0 Hello:
I get a crash of Wireshark 1.1.10 (last stable WinXP 32b version - WinXP 5.1.2600) when I close the &#34;Flow Graph&#34; window, while keeping &#34;Traffic Analysis&#34; window open.
Steps to reproduce it:
1.- Open wireshark and load any trace.
2.- Go to &#34;Statistics&#34; and click on &#34;Flow Graph&#34;.
3.- The &#34;Flow Graph&#34; window will open. Leave all the options by default and click OK.</description>
    </item>
    
    <item>
      <title>ICMP not showing up after filtering tcp.port</title>
      <link>/questions/22739/icmp-not-showing-up-after-filtering-tcpport/</link>
      <pubDate>Mon, 08 Jul 2013 16:51:00 +0000</pubDate>
      
      <guid>/questions/22739/icmp-not-showing-up-after-filtering-tcpport/</guid>
      <description>ICMP not showing up after filtering tcp.port  0 I was troubleshooting a network issue on a host remotely, I had the following filter set: ip.addr eq my.ip.addr and tcp.port !=#### I set the tcp.port to not equal the one LogMeIn was using so that I can see other traffic coming from me to the remote host that is not the remote desktop session. But it was filtering out my ICMP traffic to the host as well, not sure what I&#39;m doing wrong here.</description>
    </item>
    
    <item>
      <title>How to Export the pcap file statistics with csv file format.</title>
      <link>/questions/22749/how-to-export-the-pcap-file-statistics-with-csv-file-format/</link>
      <pubDate>Tue, 09 Jul 2013 00:54:00 +0000</pubDate>
      
      <guid>/questions/22749/how-to-export-the-pcap-file-statistics-with-csv-file-format/</guid>
      <description>How to Export the pcap file statistics with csv file format.  0 Hello I&#39;d like to export the pcap ip conversation ststistics to csv file format. I ran the below command But output is not looks like csv format.
&#39;tshark -nr badcase.cap -z conv,ip -q &amp;gt;&amp;gt; aa.csv&#39;
Result
IPv4 Conversations Filter:&amp;lt;no filter=&#34;&#34;&amp;gt; | &amp;lt;- | | -&amp;gt; | | Total | Relative | Duration | | Frames Bytes | | Frames Bytes | | Frames Bytes | Start | | 38.</description>
    </item>
    
    <item>
      <title>Duration filter stop working after random time</title>
      <link>/questions/22754/duration-filter-stop-working-after-random-time/</link>
      <pubDate>Tue, 09 Jul 2013 06:19:00 +0000</pubDate>
      
      <guid>/questions/22754/duration-filter-stop-working-after-random-time/</guid>
      <description>Duration filter stop working after random time  0 Hi !
Sorry for bad english :/ I&#39;m using Dumpcap in command line with different parameters...
sudo nohup dumpcap -P -f &amp;quot;((src 192.1.1.80 and port 25340) and (dst 192.1.1.20 and port 21286)) or ((src 192.1.1.84 and port 25596) and (dst 192.1.1.20 and port 21288)) or ((src 192.1.1.47 and port 80) and (dst 192.1.1.31 and port 80)) or ((src 192.1.1.31 and port 80) and (dst 192.</description>
    </item>
    
    <item>
      <title>Changing the link-layer type of input frames</title>
      <link>/questions/22758/changing-the-link-layer-type-of-input-frames/</link>
      <pubDate>Tue, 09 Jul 2013 06:50:00 +0000</pubDate>
      
      <guid>/questions/22758/changing-the-link-layer-type-of-input-frames/</guid>
      <description>Changing the link-layer type of input frames  0 Hi,
I am writing a dissector plugin for Wireshark, which decapsulates an Ethernet frame with an additional tag between src address and type/length field (like 802.1q). I understood about the wtap_encap dissector table. By default (as far as I know) Wireshark reads the link-layer type from the interface (which is usually 1 =&amp;gt; Ethernet) and that&#39;s the first dissector that it uses.</description>
    </item>
    
    <item>
      <title>unable to build trunk Qt version without GTK&#43;</title>
      <link>/questions/22762/unable-to-build-trunk-qt-version-without-gtk/</link>
      <pubDate>Tue, 09 Jul 2013 07:03:00 +0000</pubDate>
      
      <guid>/questions/22762/unable-to-build-trunk-qt-version-without-gtk/</guid>
      <description>unable to build trunk Qt version without GTK+  0 I&#39;ve downloaded the latest package (wireshark-1.11.0-SVN-50460.tar.bz2) and after running ./configure I get the following output as last lines:
checking for GTK+ - version &amp;gt;= 2.12.0 and &amp;lt; 3.0... no ** Could not run GTK+ test program, checking why... ** The test program failed to compile or link. See the file config.log for the ** exact error that occured. This usually means GTK+ is incorrectly installed.</description>
    </item>
    
    <item>
      <title>wireshark in ubuntu 11.04</title>
      <link>/questions/22765/wireshark-in-ubuntu-1104/</link>
      <pubDate>Tue, 09 Jul 2013 13:09:00 +0000</pubDate>
      
      <guid>/questions/22765/wireshark-in-ubuntu-1104/</guid>
      <description>wireshark in ubuntu 11.04  0 I have tried to install Wireshark in the usual way: #sudo apt-get install wireshark. It didn&#39;t work. I think that&#39;s because Ubuntu 11.04 is not supported anymore. But I need to use it, because my VM with Ubuntu 11.04 is customized to my application. What should I do? Please, I need a step to step procedure, because I`m a dumb user in Ubuntu. Thanks a lot.</description>
    </item>
    
    <item>
      <title>tcp stream help</title>
      <link>/questions/22769/tcp-stream-help/</link>
      <pubDate>Tue, 09 Jul 2013 15:04:00 +0000</pubDate>
      
      <guid>/questions/22769/tcp-stream-help/</guid>
      <description>tcp stream help  0 Can anyone help me with this TCP steam/capture? End result is the client using faxfinder can&#39;t connect to the server.
thanks in advance
http://img547.imageshack.us/img547/6901/m3o.png
faxfinder stream tcp wiresharkasked 09 Jul &#39;13, 15:04
wireuser70
1●1●1●2
accept rate: 0%
Thanks for the prompt replies. I have even more information to share. I ran wireshark captures on the port going to the client on the same switch but I don&#39;t see any of the [syn, ack] from the server.</description>
    </item>
    
    <item>
      <title>Source/client packets don&amp;#x27;t display in wireshark but inbound response packet are seen</title>
      <link>/questions/22771/sourceclient-packets-dont-display-in-wireshark-but-inbound-response-packet-are-seen/</link>
      <pubDate>Tue, 09 Jul 2013 16:28:00 +0000</pubDate>
      
      <guid>/questions/22771/sourceclient-packets-dont-display-in-wireshark-but-inbound-response-packet-are-seen/</guid>
      <description>Source/client packets don&amp;rsquo;t display in wireshark but inbound response packet are seen  0 Weird issue. I used to see all outbound and inbound packets in wireshark on my Lenovo Thinkpad T520 but now I can&#39;t see or capture any outbound packets but I certainly see the inbound/response packets. I am using Win7, fully patched, with 1.8.1 currently but upgrading didn&#39;t help. My colleagues who have T520 models works without issue.</description>
    </item>
    
    <item>
      <title>Visited Websites</title>
      <link>/questions/22779/visited-websites/</link>
      <pubDate>Tue, 09 Jul 2013 18:19:00 +0000</pubDate>
      
      <guid>/questions/22779/visited-websites/</guid>
      <description>Visited Websites  0 How do I view visited websites from a computer on my network. I would like to see what websites my children are viewing. I&#39;m able to start a capture, but the results do not produce website names or URL addresses.
visited websitesasked 09 Jul &#39;13, 18:19
deweywoods
1●1●1●1
accept rate: 0%
  
One Answer:
  
0You can print the URLs with tshark. You need to capture the traffic first with Wireshark or dumpcap and write it to input.</description>
    </item>
    
    <item>
      <title>Function to print out packet protocol info</title>
      <link>/questions/22781/function-to-print-out-packet-protocol-info/</link>
      <pubDate>Tue, 09 Jul 2013 21:45:00 +0000</pubDate>
      
      <guid>/questions/22781/function-to-print-out-packet-protocol-info/</guid>
      <description>Function to print out packet protocol info  0 When I debug Wireshark in VS2010 and I set a breakpoint at the place of : row = packet_list_append(cinfo, fdata, &amp;amp;edt.pi); I have noticed that the parameter of &#34;to_read&#34; means that Wireshark get a number of packets from the capture file in a &#34;while&#34; loop until &#34;to_read&#34; is zero. The column info of each packet is filled in every time the packet is dissected.</description>
    </item>
    
    <item>
      <title>Dissecting stream</title>
      <link>/questions/22782/dissecting-stream/</link>
      <pubDate>Tue, 09 Jul 2013 23:33:00 +0000</pubDate>
      
      <guid>/questions/22782/dissecting-stream/</guid>
      <description>Dissecting stream  0 Hi, I&#39;m developing a dissector for a protocol that turn out to be a stream. How do I dissect PDUs which span across multiple packets. Each PDU consist of 2 parts, message and parameters. Parameters consist of few additional PDUs (number can vary from 0 to 255). All PDUs are basically strings, therefore variable in length.
In documentation I found section &#34;2.7.2 Modifying the pinfo struct&#34;, where it&#39;s described how to deal with such packets.</description>
    </item>
    
    <item>
      <title>Error Control in custom dissector</title>
      <link>/questions/22797/error-control-in-custom-dissector/</link>
      <pubDate>Wed, 10 Jul 2013 04:22:00 +0000</pubDate>
      
      <guid>/questions/22797/error-control-in-custom-dissector/</guid>
      <description>Error Control in custom dissector  0 Hi, i am working on a cutstom dissector plugin for wireshark and i am wondering how error control is implemented with the wireshark API. I have read some of the documentation, mainly README.developer and README.plugin but i cant find anthing there about it.
To give an example of what i want to do: Standard in wireshark if the packet being dissected isn&#39;t following the protocol for any reason it just say &#34;</description>
    </item>
    
    <item>
      <title>How to sniff UDP packets from tablet to wi-fi LED controller</title>
      <link>/questions/22798/how-to-sniff-udp-packets-from-tablet-to-wi-fi-led-controller/</link>
      <pubDate>Wed, 10 Jul 2013 05:49:00 +0000</pubDate>
      
      <guid>/questions/22798/how-to-sniff-udp-packets-from-tablet-to-wi-fi-led-controller/</guid>
      <description>How to sniff UDP packets from tablet to wi-fi LED controller  0 Hello,
I have a wi-fi LED bulb controller that receives UDP packets from my tablet via wi-fi and then translates into RF signals.
I want to sniff the UDP packets sent from tablet to the controller via wi-fi (sniffing from the computer in the same network)
I am totally new to wireshark and somehow cannot get the settings right.</description>
    </item>
    
    <item>
      <title>sql client 10 second freeze after idle 10 minute idle</title>
      <link>/questions/22801/sql-client-10-second-freeze-after-idle-10-minute-idle/</link>
      <pubDate>Wed, 10 Jul 2013 06:35:00 +0000</pubDate>
      
      <guid>/questions/22801/sql-client-10-second-freeze-after-idle-10-minute-idle/</guid>
      <description>sql client 10 second freeze after idle 10 minute idle  0 The scenario is: The situation is this:
i have sql based application client Keep a client &#34;untouched&#34; for 10minutes or more.Come backDo an operation that triggers a dbserver call (This means: write in a socket which is already open to a dbserver instance)What happens now is the following:
The &#34;write&#34; to the socket gets stuck for 18 seconds.Then we get an &#34;</description>
    </item>
    
    <item>
      <title>TCP port range filter</title>
      <link>/questions/22804/tcp-port-range-filter/</link>
      <pubDate>Wed, 10 Jul 2013 06:43:00 +0000</pubDate>
      
      <guid>/questions/22804/tcp-port-range-filter/</guid>
      <description>TCP port range filter  1 Hello,
How might I write a display filter for a tcp port range?
I&#39;m wanting to filter two sets of ranges. TCP/8600-8619 and TCP/8400-8402
thanks,
J
filter range tcpasked 10 Jul &#39;13, 06:43
JTech_17
41●7●7●12
accept rate: 0%
  
2 Answers:
  
0 Please try this:
(tcp.dstport &amp;gt;= 8600 and tcp.dstport &amp;lt;= 8619) or (tcp.dstport &amp;gt;= 8400 and tcp.dstport &amp;lt;= 8402)</description>
    </item>
    
    <item>
      <title>Not able to decrypt SSL data with Private Keys</title>
      <link>/questions/22813/not-able-to-decrypt-ssl-data-with-private-keys/</link>
      <pubDate>Wed, 10 Jul 2013 08:01:00 +0000</pubDate>
      
      <guid>/questions/22813/not-able-to-decrypt-ssl-data-with-private-keys/</guid>
      <description>Not able to decrypt SSL data with Private Keys  0 Hi there,
I m trying to decrypt SSL encrypted data using wireshark, but i m not able to do so. I have provided the RSA keys and the key location in the wireshark, also i m using TLS_RSA_WITH_RC4_128_SHA, so typically Diffie Helmann concept is outta context here. The following is the snap from the debug,
ssl_association_remove removing TCP 443 - http handle 04453A50 Private key imported: KeyID 5d:bf:fb:fa:7f:5a:a7:57:7f:30:80:36:39:15:d5:1a:.</description>
    </item>
    
    <item>
      <title>Filter to remove display of rdp packets</title>
      <link>/questions/22814/filter-to-remove-display-of-rdp-packets/</link>
      <pubDate>Wed, 10 Jul 2013 08:56:00 +0000</pubDate>
      
      <guid>/questions/22814/filter-to-remove-display-of-rdp-packets/</guid>
      <description>Filter to remove display of rdp packets  0 What is the proper filter to use that will prevent the display of rdp, tcp source and destination 3389, packets?
filter rdp remove displayasked 10 Jul &#39;13, 08:56
johnspin
1●1●1●1
accept rate: 0%
  
One Answer:
  
1try &#34;not tcp.port==3389&#34;
answered 10 Jul &#39;13, 08:57
Jasper ♦♦
23.8k●5●51●284
accept rate: 18%
!tcp.port==3389 worked. Thanks.
(10 Jul &#39;13, 09:06) johnspin     </description>
    </item>
    
    <item>
      <title>Auto FTP Upload traces</title>
      <link>/questions/22835/auto-ftp-upload-traces/</link>
      <pubDate>Thu, 11 Jul 2013 01:58:00 +0000</pubDate>
      
      <guid>/questions/22835/auto-ftp-upload-traces/</guid>
      <description>Auto FTP Upload traces  0 Hello.
We have several computers, that is running wireshark and sniffin data packets for us to send to a large Phone Company.
But each day i have to login to these machines, and manually upload the files to our FTP server... and these machines are so slow!
Isnt there a build-in uploader in wireshark, or can someone recommend a 3. party software?
I need the software to upload ONLY files that have been completed (200MB) and delete them afterwards.</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t see &amp;quot;Save Capture File As&amp;quot; dialog box in wireshark</title>
      <link>/questions/22838/cant-see-save-capture-file-as-dialog-box-in-wireshark/</link>
      <pubDate>Thu, 11 Jul 2013 02:19:00 +0000</pubDate>
      
      <guid>/questions/22838/cant-see-save-capture-file-as-dialog-box-in-wireshark/</guid>
      <description>can&amp;rsquo;t see &amp;ldquo;Save Capture File As&amp;rdquo; dialog box in wireshark  0 Hi, I have installed 64 bit 1.10, i see &#34;Save Capture File As&#34; dialog box in wireshark, but without the possibility to display packets etc, Does someone have any idea? Yariv
filesaveasked 11 Jul &#39;13, 02:19
ygolan99
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Saving displayed packets can now be done with &#34;File -&amp;gt; Export Specified Packets.</description>
    </item>
    
    <item>
      <title>discrepancy between PSH and without PSH</title>
      <link>/questions/22843/discrepancy-between-psh-and-without-psh/</link>
      <pubDate>Thu, 11 Jul 2013 03:39:00 +0000</pubDate>
      
      <guid>/questions/22843/discrepancy-between-psh-and-without-psh/</guid>
      <description>discrepancy between PSH and without PSH  0 Hi Team,
I have a problem regarding http connection. I have a server as a host send the data to multiple clients by using http connection. Server A, the connection is good with the higher tps ( Transaction per second ) than the others. Server A having lower tps, i have snoop the both server from host.
SERVER A: &amp;quot;21&amp;quot;,&amp;quot;0.013006&amp;quot;,&amp;quot;10.2.230.48&amp;quot;,&amp;quot;10.251.151.31&amp;quot;,&amp;quot;HTTP&amp;quot;,&amp;quot;267&amp;quot;,&amp;quot;HTTP/1.1 200 OK &amp;quot; &amp;quot;28&amp;quot;,&amp;quot;0.</description>
    </item>
    
    <item>
      <title>HTTP Proxy</title>
      <link>/questions/22844/http-proxy/</link>
      <pubDate>Thu, 11 Jul 2013 04:01:00 +0000</pubDate>
      
      <guid>/questions/22844/http-proxy/</guid>
      <description>HTTP Proxy  0 Hello,
Does Wireshark (1.8.8) have the ability to &#34;discover&#34; if an http proxy device (Websense) is being used? If so, which area of the packet might I find this information so that I can build a filter.
We have multiple network segments and I&#39;m not always sure which segments are using the proxy. We use WCCP to &#34;see&#34; the http packets and then send to the Websense appliances.</description>
    </item>
    
    <item>
      <title>wlan monitoring a ping: inside the network only 2 packets, outside 4</title>
      <link>/questions/22846/wlan-monitoring-a-ping-inside-the-network-only-2-packets-outside-4/</link>
      <pubDate>Thu, 11 Jul 2013 04:42:00 +0000</pubDate>
      
      <guid>/questions/22846/wlan-monitoring-a-ping-inside-the-network-only-2-packets-outside-4/</guid>
      <description>wlan monitoring a ping: inside the network only 2 packets, outside 4  0 I have the following network setup:
PC1 monitor node (not connected to the ssid) PC3 access point PC5 client1 PC6 client2I monitor the traffic on PC1 using Wireshark and PC3 using tcpdump.
When I ping from PC6 to PC5, I can see 4 packets on PC1: 2 Echo requests which travel from PC6 to AP and then to PC5 (mac addresses are adapted on the way) and 2 Echo replies which go the same wa y back.</description>
    </item>
    
    <item>
      <title>No icon image in Desktop - windows 64 bit installer</title>
      <link>/questions/22847/no-icon-image-in-desktop-windows-64-bit-installer/</link>
      <pubDate>Thu, 11 Jul 2013 04:43:00 +0000</pubDate>
      
      <guid>/questions/22847/no-icon-image-in-desktop-windows-64-bit-installer/</guid>
      <description>No icon image in Desktop - windows 64 bit installer  0 I just installed wireshark 1.10.0 stable using the 64 bit installer in my win 7 64 bit machine . Installation is proper and works fine but the Desktop shortcut seems to be missing image file.
Is it a problem with my machine or is the installer missing the icon file.
installerasked 11 Jul &#39;13, 04:43
Arun Balaji
16●1●1●5</description>
    </item>
    
    <item>
      <title>tshark decrypt esp packets with command line arguments</title>
      <link>/questions/22874/tshark-decrypt-esp-packets-with-command-line-arguments/</link>
      <pubDate>Thu, 11 Jul 2013 14:41:00 +0000</pubDate>
      
      <guid>/questions/22874/tshark-decrypt-esp-packets-with-command-line-arguments/</guid>
      <description>tshark decrypt esp packets with command line arguments  0 Hello,
I work with wireshark a lot and I need to decode a LOT of traces that have ESP. It takes a long time to manually enter in all the information necessary in the GUI to decode each different trace, so I am trying to figure out a way to pass the ESP decryption parameters as command line arguments to tshark or wireshark.</description>
    </item>
    
    <item>
      <title>Using libwireshark from c#</title>
      <link>/questions/22880/using-libwireshark-from-c/</link>
      <pubDate>Thu, 11 Jul 2013 22:27:00 +0000</pubDate>
      
      <guid>/questions/22880/using-libwireshark-from-c/</guid>
      <description>Using libwireshark from c#  0 hello
i want to use libwireshark.dll in c# too where can i find the guidance of API
thanks
c# libwiresharkasked 11 Jul &#39;13, 22:27
gedeju
1●1●1●1
accept rate: 0%
 converted to question 12 Jul &#39;13, 00:54 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
0See the answer for a similar question
http://ask.wireshark.org/questions/10923/using-wireshark-libraries-in-c
Regards
Kurt
answered 22 Jul &#39;13, 15:32</description>
    </item>
    
    <item>
      <title>Distribution of Wireshark tool ver 1.6.14 in our product CD as a separate installable</title>
      <link>/questions/22883/distribution-of-wireshark-tool-ver-1614-in-our-product-cd-as-a-separate-installable/</link>
      <pubDate>Thu, 11 Jul 2013 22:58:00 +0000</pubDate>
      
      <guid>/questions/22883/distribution-of-wireshark-tool-ver-1614-in-our-product-cd-as-a-separate-installable/</guid>
      <description>Distribution of Wireshark tool ver 1.6.14 in our product CD as a separate installable  0 Question 1: I would like to know what are the legal and other bindings/agreements if we have to bundle Wireshark tool ver 1.6.14 in our product CD as a separate installable?, But we will not install it as part of the product.
Question 2: Are there any licensing restrictions/bindings that will prevent us from installing/redistributing the wireshark product on our customer sites/locations?</description>
    </item>
    
    <item>
      <title>fragment_table_init (unknown symbol)</title>
      <link>/questions/22884/fragment_table_init-unknown-symbol/</link>
      <pubDate>Thu, 11 Jul 2013 23:38:00 +0000</pubDate>
      
      <guid>/questions/22884/fragment_table_init-unknown-symbol/</guid>
      <description>fragment_table_init (unknown symbol)  0 Hi,
I inherited some dissector code from a former colleague, which runs well under windows (V1.7.2). Now I wanted to port it to linux, using the latest wireshark code base (svn; but problem also occurs with latest stable).
My dissector plugin compiles without problems, but when starting wireshark, I get the error message undefined symbol: fragment_table_init.
Do I have to link my plugin against any library?</description>
    </item>
    
    <item>
      <title>LDAP authentication problems</title>
      <link>/questions/22891/ldap-authentication-problems/</link>
      <pubDate>Fri, 12 Jul 2013 01:49:00 +0000</pubDate>
      
      <guid>/questions/22891/ldap-authentication-problems/</guid>
      <description>LDAP authentication problems  0 hi guys,
I have pretty much the same issue. I have a SERVER (.129) authenticating to an LDAP SERVER (.53)
Sometimes works, sometimes it does not.
I am checking it, and:
SOURCE DESTINATION PROTOCOL INFO .129 .53 TCP ldaps [FIN, ACK] .53 .129 TLSv1 Encrypted alert .129 .53 TCP ldaps [RST] .53 .129 TCP ldaps [FIN, ACK] .129 .53 TCP ldaps [RST] Any comment is very welcome :)</description>
    </item>
    
    <item>
      <title>Crash in Mountain Lion</title>
      <link>/questions/22922/crash-in-mountain-lion/</link>
      <pubDate>Fri, 12 Jul 2013 09:39:00 +0000</pubDate>
      
      <guid>/questions/22922/crash-in-mountain-lion/</guid>
      <description>Crash in Mountain Lion  0 I am trying to use Wireshark on a mac with 10.8.4. The first time I opened it, it said to make sure X11 was installed. X11 no longer comes with mac OS&#39;s (as of the release of Mountain Lion) so I downloaded it from MacUpdate. Apparently, X11 can&#39;t run on 10.8 at all. After a lot of googling, I found that XQuartz was the new version of X11, but it doesn&#39;t seem to help.</description>
    </item>
    
    <item>
      <title>Completely lost on this TCP FTP issue.</title>
      <link>/questions/22928/completely-lost-on-this-tcp-ftp-issue/</link>
      <pubDate>Sat, 13 Jul 2013 09:07:00 +0000</pubDate>
      
      <guid>/questions/22928/completely-lost-on-this-tcp-ftp-issue/</guid>
      <description>Completely lost on this TCP FTP issue.  0 My system in Florida cannot ftp to ftp.childnet.us.
It can ftp to other sites, i.e. ftp.bnl.gov
I can ftp to ftp.childnet.us from outside of our network.
I&#39;ve done about everything I can think of to troubleshoot this. Here&#39;s what&#39;s going on exactly.
1) launch the command:
C:\Windows\system32&amp;gt;ftp ftp.childnet.us
2) Our systems do a 3-way TCP handshake:
96 4.871876000 192.168.180.12 65.240.236.154 TCP 66 51337 &amp;gt; ftp [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=1 SACK_PERM=1 97 4.</description>
    </item>
    
    <item>
      <title>Wireshark 1.10.0 issue with Capture Options Adapter List</title>
      <link>/questions/22933/wireshark-1100-issue-with-capture-options-adapter-list/</link>
      <pubDate>Sat, 13 Jul 2013 13:15:00 +0000</pubDate>
      
      <guid>/questions/22933/wireshark-1100-issue-with-capture-options-adapter-list/</guid>
      <description>Wireshark 1.10.0 issue with Capture Options Adapter List  0 I have an issue on a few PC&#39;s (Windows 7 Home Premium and Professional both 64 bit)not showing the adapters next to their check boxes when in the &#34;Capture Options&#34; menu. See graphic below.
I have uninstalled and reinstalled with no change in results. Its not the end of the world, but am wondering if its something with the application or my PC&#39;s.</description>
    </item>
    
    <item>
      <title>Getting Router IPs with wireshark</title>
      <link>/questions/22934/getting-router-ips-with-wireshark/</link>
      <pubDate>Sat, 13 Jul 2013 13:44:00 +0000</pubDate>
      
      <guid>/questions/22934/getting-router-ips-with-wireshark/</guid>
      <description>Getting Router IPs with wireshark  0 Okay, so an inconsiderate guy on a website that is prejudice toward me (Dislikes me for no reason) somehow got my ip using wireshark and DDoSed my router for around 5 to 10 minutes. I&#39;ve only known 1 other person to know how to do this but he&#39;s doesn&#39;t want to tell me either, he also has proof that he&#39;s done it. I&#39;d like to know, how do you perform something like this?</description>
    </item>
    
    <item>
      <title>Unable to get post methods</title>
      <link>/questions/22942/unable-to-get-post-methods/</link>
      <pubDate>Sun, 14 Jul 2013 00:44:00 +0000</pubDate>
      
      <guid>/questions/22942/unable-to-get-post-methods/</guid>
      <description>Unable to get post methods  0 When I start capturing network Im not able to get POST methods except mine. However its able to track other active IP on the Network. And when I use the program from other computer, same thing happens.
post getasked 14 Jul &#39;13, 00:44
Rishabh Goyal
11●1●1●2
accept rate: 0%
Where are you putting your sniffer(capture)? What type of sniffing option are you using: arp cache poisoning, tap, port mirroring or what?</description>
    </item>
    
    <item>
      <title>Where exactly wireshark does captures packets?</title>
      <link>/questions/22956/where-exactly-wireshark-does-captures-packets/</link>
      <pubDate>Sun, 14 Jul 2013 09:19:00 +0000</pubDate>
      
      <guid>/questions/22956/where-exactly-wireshark-does-captures-packets/</guid>
      <description>Where exactly wireshark does captures packets?  0 Hi,
Could you please explain where exactly does wireshark captures incoming packets? Is it above device driver? Or, in between device driver and network interface?
thanks,
wiresharkasked 14 Jul &#39;13, 09:19
adityaholla
11●1●1●3
accept rate: 0%
  
One Answer:
  
3Basically the capturing framework is placed between the NIC driver and higher layer protocols in the kernel (e.g. TCP/IP).</description>
    </item>
    
    <item>
      <title>Indistinguishable protocol versions</title>
      <link>/questions/22965/indistinguishable-protocol-versions/</link>
      <pubDate>Sun, 14 Jul 2013 23:30:00 +0000</pubDate>
      
      <guid>/questions/22965/indistinguishable-protocol-versions/</guid>
      <description>Indistinguishable protocol versions  0 How can a dissector deal with different versions of a protocol, when the versions can&#39;t really be distinguished from the data stream? The version number isn&#39;t available in the data stream or any associated control stream, and without the version number, it is often not possible to decode the data correctly.
One way is to try to decode a set of possible versions, and to see which ones look reasonable, but this is very circuitous and prone to mistakes.</description>
    </item>
    
    <item>
      <title>Add column for &amp;quot;ACK For&amp;quot; field</title>
      <link>/questions/22968/add-column-for-ack-for-field/</link>
      <pubDate>Mon, 15 Jul 2013 02:32:00 +0000</pubDate>
      
      <guid>/questions/22968/add-column-for-ack-for-field/</guid>
      <description>Add column for &amp;ldquo;ACK For&amp;rdquo; field  1 Can anyone help me guide how can we add coloumn ACK for , where it will say that current packet is acknowledged for Packt no XYZ.
Thank for help.
columnsasked 15 Jul &#39;13, 02:32
m_1607
35●12●13●16
accept rate: 0%
 edited 15 Jul &#39;13, 02:36 
grahamb ♦
19.8k●3●30●206
  
2 Answers:
  
5If I understand your question correctly, you want a column that shows the content of the field &#34;</description>
    </item>
    
    <item>
      <title>Slow download speed server and client.</title>
      <link>/questions/22971/slow-download-speed-server-and-client/</link>
      <pubDate>Mon, 15 Jul 2013 03:41:00 +0000</pubDate>
      
      <guid>/questions/22971/slow-download-speed-server-and-client/</guid>
      <description>Slow download speed server and client.  -1 we are getting very slow spped download from server 192.168.1.1 .
Rest all download speed is good only speed with this server server is slow over port 80
763 0.000096000 0.000096000 10.10.10.1 192.168.1.1 TCP 54 51816 &amp;gt; http [ACK] Seq=1 Ack=1 Win=66048 Len=0 0.000096000 258 762 762 0.117565000 0.319337000 192.168.1.1 10.10.10.1 TCP 66 http &amp;gt; 51816 [SYN, ACK] Seq=0 Ack=1 Win=64240 Len=0 MSS=1380 WS=1 SACK_PERM=1 0.</description>
    </item>
    
    <item>
      <title>download timed out</title>
      <link>/questions/22975/download-timed-out/</link>
      <pubDate>Mon, 15 Jul 2013 10:51:00 +0000</pubDate>
      
      <guid>/questions/22975/download-timed-out/</guid>
      <description>download timed out  0 2 of my servers are trying to download a virus signature file from McAfee site and it just kept timing out. I plugged my PC directly to the switch and I was able to download the file without any problem.
I am using Wireshark to see what is going on with my servers. I saw [tcp dup ack 674#2] and [tcp zerowindow], and [tcp out-of-order]. I am not familiar with those errors.</description>
    </item>
    
    <item>
      <title>wireshark only shows one protocol in capture</title>
      <link>/questions/22980/wireshark-only-shows-one-protocol-in-capture/</link>
      <pubDate>Mon, 15 Jul 2013 15:44:00 +0000</pubDate>
      
      <guid>/questions/22980/wireshark-only-shows-one-protocol-in-capture/</guid>
      <description>wireshark only shows one protocol in capture  0 how come i only get one protocol in wireshark capture.
the protocols i got first time was only &#34;802.11&#34;
the protocols i got 2nd time was only &#34;usb&#34;
i want to capture everything.
i am using alfa wifi device to capture
how do i capture everything, smtp, tcp, dns, ...???????????
capture 802.11-only protocol usb-onlyasked 15 Jul &#39;13, 15:44
Freddy Krueger
1●1●1●1</description>
    </item>
    
    <item>
      <title>discrepancy between async and sync in wireshark</title>
      <link>/questions/22985/discrepancy-between-async-and-sync-in-wireshark/</link>
      <pubDate>Mon, 15 Jul 2013 19:17:00 +0000</pubDate>
      
      <guid>/questions/22985/discrepancy-between-async-and-sync-in-wireshark/</guid>
      <description>discrepancy between async and sync in wireshark  0 Hi Team,
Do we can decide that a transaction is using async / sync by wireshark ? which the button / tools in wireshark we can see sync / async ?
Thanks Wilis
and async sync discrepancy betweenasked 15 Jul &#39;13, 19:17
Wilis
11●2●2●3
accept rate: 0%
What do you mean by &#34;synchronous&#34; and &#34;asynchronous&#34; here?
(15 Jul &#39;13, 20:24) Guy Harris ♦♦Hi Harris,</description>
    </item>
    
    <item>
      <title>http host header with and without port number.</title>
      <link>/questions/22988/http-host-header-with-and-without-port-number/</link>
      <pubDate>Mon, 15 Jul 2013 20:55:00 +0000</pubDate>
      
      <guid>/questions/22988/http-host-header-with-and-without-port-number/</guid>
      <description>http host header with and without port number.  0 Here is the brief description of the issue
Working condition:
When client tried to use method CONNECT a.b.c.d:443 where host header is a.b.c.d:443 things went smooth.
Non-working condition:
When the same client tried to use method CONNECT a.b.c.d:443 where host header is just a.b.c.d(no port number) we are not seeing any further SSL communication.
Is it must to specify host header with port number when the connection is not to default(port 80)?</description>
    </item>
    
    <item>
      <title>Dissector on top of CCSDS Space Packet</title>
      <link>/questions/22990/dissector-on-top-of-ccsds-space-packet/</link>
      <pubDate>Tue, 16 Jul 2013 00:59:00 +0000</pubDate>
      
      <guid>/questions/22990/dissector-on-top-of-ccsds-space-packet/</guid>
      <description>Dissector on top of CCSDS Space Packet  0 Hello,
I have written a dissector that works on top of the Space Packet protocol (packet-ccsds) that at the same time works on top UDP in my application. My question is: As the protocol is not working neither on top of UDP nor on TCP how should I code the protocol registration in this case? More specifically, how should be the &#34;</description>
    </item>
    
    <item>
      <title>Dissect payload data as IP packet in Lua custom dissector</title>
      <link>/questions/22992/dissect-payload-data-as-ip-packet-in-lua-custom-dissector/</link>
      <pubDate>Tue, 16 Jul 2013 02:20:00 +0000</pubDate>
      
      <guid>/questions/22992/dissect-payload-data-as-ip-packet-in-lua-custom-dissector/</guid>
      <description>Dissect payload data as IP packet in Lua custom dissector  0 Hi,
I have a packet which has some header fields and some payload. I&#39;ve successfully written a dissector for the packet. So now I can see my own protocol&#39;s and field values in Wireshark. Now, the payload data for my protocol is basically an IP Packet data. I want to parse that data as IP Packet and show as a subtree inside my protocol.</description>
    </item>
    
    <item>
      <title>mate configuration trouble</title>
      <link>/questions/23002/mate-configuration-trouble/</link>
      <pubDate>Tue, 16 Jul 2013 04:43:00 +0000</pubDate>
      
      <guid>/questions/23002/mate-configuration-trouble/</guid>
      <description>mate configuration trouble  0 Hello, I try to build a mate configuration that for a given sip call I can filter immediately on signaling and media for this call.
therefore I need to create a pdu for every sip call, make gop&#39;s on callid where the start is the invite request line and the end the bye line.
I created a simple mate file for this, although I don&#39;t see a single GOP being created.</description>
    </item>
    
    <item>
      <title>Generated IPV6 Fragment Extension Header makes TCP undetectable in wireshark</title>
      <link>/questions/23012/generated-ipv6-fragment-extension-header-makes-tcp-undetectable-in-wireshark/</link>
      <pubDate>Tue, 16 Jul 2013 06:34:00 +0000</pubDate>
      
      <guid>/questions/23012/generated-ipv6-fragment-extension-header-makes-tcp-undetectable-in-wireshark/</guid>
      <description>Generated IPV6 Fragment Extension Header makes TCP undetectable in wireshark  0 Hello,
I am trying to create random packets using a TCL script. I have encountered the following problem: When creating a TCP packet inside a IPV6 header that has a Fragment Extension Header, Wireshark no longer analyses the data containing the TCP packet (it is labeled simply as &#34;data&#34;).
You can find here an example of a file that I import into Wireshark to check if my generated packets are correct:</description>
    </item>
    
    <item>
      <title>How to develop my own traffic data analyzer through wireshark</title>
      <link>/questions/23018/how-to-develop-my-own-traffic-data-analyzer-through-wireshark/</link>
      <pubDate>Tue, 16 Jul 2013 07:17:00 +0000</pubDate>
      
      <guid>/questions/23018/how-to-develop-my-own-traffic-data-analyzer-through-wireshark/</guid>
      <description>How to develop my own traffic data analyzer through wireshark  0 1In my department, we have implemented a new communication protocol. Now, we want to analyze the data traffic in order to show it clearly to the students.
We think we can develop a new filter, specific to our protocol, in Wireshark, but we are not sure about this possibility. So we have a few question...
Is possible to develop your own wireshark in order to analyse the traffic of your self-created network protocol?</description>
    </item>
    
    <item>
      <title>file too large to open or corrupt?</title>
      <link>/questions/23049/file-too-large-to-open-or-corrupt/</link>
      <pubDate>Tue, 16 Jul 2013 09:47:00 +0000</pubDate>
      
      <guid>/questions/23049/file-too-large-to-open-or-corrupt/</guid>
      <description>file too large to open or corrupt?  0 Been troubleshooting a potential problem with a device that happens randomly. So I&#39;ve been forced to capture almost 8 hours a day.
The incident I was trying to record happened within the last few minutes of the day as I was about to leave/stop capturing for the day. So I have this 1.5gb cap. However when I try to open the file so I can run a filter, wireshark crashes.</description>
    </item>
    
    <item>
      <title>How to monitor internet uptime with Wireshark?</title>
      <link>/questions/23054/how-to-monitor-internet-uptime-with-wireshark/</link>
      <pubDate>Tue, 16 Jul 2013 12:07:00 +0000</pubDate>
      
      <guid>/questions/23054/how-to-monitor-internet-uptime-with-wireshark/</guid>
      <description>How to monitor internet uptime with Wireshark?  0 Hi everyone,
I was told that I could use Wireshark to monitor internet uptime. I&#39;m trying to determine if our internet connection is dropping out sporadically, causing our Verizon network extenders to continuously go down.
Can Wireshark help me with this solution?
Thank you for your time! Ben
uptime internetasked 16 Jul &#39;13, 12:07
Ben Bolduc
16●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Can Wireshark be used to see/show SQL (DB2) statements/expression?</title>
      <link>/questions/23059/can-wireshark-be-used-to-seeshow-sql-db2-statementsexpression/</link>
      <pubDate>Tue, 16 Jul 2013 17:58:00 +0000</pubDate>
      
      <guid>/questions/23059/can-wireshark-be-used-to-seeshow-sql-db2-statementsexpression/</guid>
      <description>Can Wireshark be used to see/show SQL (DB2) statements/expression?  0 I am trying to analyze SQL statements/expressions being sent from a client machine to a DB2 server. I can successfully get a general capture [from Wireshark app] but I have been unable to get any useful output (&#39;readable&#39; info). I figured that after HOURS of &#39;google-ing&#39; this issue, I would have stumbled upon a YouTube vid or a forum entry that explains this wireshark-related process.</description>
    </item>
    
    <item>
      <title>Frame check sequence calculation</title>
      <link>/questions/23071/frame-check-sequence-calculation/</link>
      <pubDate>Wed, 17 Jul 2013 06:22:00 +0000</pubDate>
      
      <guid>/questions/23071/frame-check-sequence-calculation/</guid>
      <description>Frame check sequence calculation  0 Hello,
I am trying to calculate the FCS for ipv4/ipv6 packets.
I use the following algorithm:
I get the hex string of the whole frame (from ethernet layer to data incapsulated inside tcp/udp)I transform it into a binary stringI negate the first 32 bitsI reverse the order of the bits in each byte in the whole frameI xor the first 33 elements of the binary string with 100000100110000010001110110110111 and trim the left zerosI repeat step 5 until my binary string has a length less or equal to 32I negate all the bitsI transform the binary string into a hex stringAnd that is my algorithm.</description>
    </item>
    
    <item>
      <title>Decrypting WPA2 broadcast packets</title>
      <link>/questions/23076/decrypting-wpa2-broadcast-packets/</link>
      <pubDate>Wed, 17 Jul 2013 11:36:00 +0000</pubDate>
      
      <guid>/questions/23076/decrypting-wpa2-broadcast-packets/</guid>
      <description>Decrypting WPA2 broadcast packets  0 I&#39;m trying to decrypt some DHCP packets with WPA-2.
Using my key, I was able to see the side sending the DHCP Discover and Request (decryption is working), but I am unable to decrypt the packets sending the DHCP Offer and Ack. I have toggled all of the various settings but these packets just show up as encrypted data.
The difference is, the packets I CAN decrypt have a transmitter address AND a Receiver address (destination is broadcast).</description>
    </item>
    
    <item>
      <title>source and destination columns</title>
      <link>/questions/23080/source-and-destination-columns/</link>
      <pubDate>Wed, 17 Jul 2013 14:15:00 +0000</pubDate>
      
      <guid>/questions/23080/source-and-destination-columns/</guid>
      <description>source and destination columns  0 with the advent of ipv6, these columns are hard to quickly identify with a particular system. I was wondering if there is an option to use the &#34;ethers&#34; table, when an entry exists, in place of the ip address in either the source or destination columns?
resolution name-resolving hosts name ipv6asked 17 Jul &#39;13, 14:15
proj964
11●4●4●7
accept rate: 0%
 edited 18 Jul &#39;13, 06:08</description>
    </item>
    
    <item>
      <title>IPv6 format source and destination port</title>
      <link>/questions/23095/ipv6-format-source-and-destination-port/</link>
      <pubDate>Thu, 18 Jul 2013 00:20:00 +0000</pubDate>
      
      <guid>/questions/23095/ipv6-format-source-and-destination-port/</guid>
      <description>IPv6 format source and destination port  0 Hi, I am using text2pcap utility to decode the trace message to create libcap capture file. But when I am receiving the trace packets with source and destination addresses in IPv6 format, in that case libcap is not generating proper and on wireshark I am getting &#34;Ethernet Check Sequesnce Incorrect&#34; error, also the IP addresses are not displayed in IPv6 format.
Does any one has hex dump of trace packets which has IPv6 format ip addresses?</description>
    </item>
    
    <item>
      <title>Webserver does not close connections</title>
      <link>/questions/23098/webserver-does-not-close-connections/</link>
      <pubDate>Thu, 18 Jul 2013 03:43:00 +0000</pubDate>
      
      <guid>/questions/23098/webserver-does-not-close-connections/</guid>
      <description>Webserver does not close connections  0 Hi
I have a user who periodically has poor performance when using an on-line database, he connects over the internet using HTTPS. The client connects directly through the firewall missing out the proxy and is using IE8.
I&#39;ve taken a packet trace and I&#39;ve noticed that the TCP streams often aren&#39;t shut down gracefully. The client will ACK the last packet received from the server then there will be a 60 second wait before the client sends a FIN and the connection closes.</description>
    </item>
    
    <item>
      <title>How to analyze sip messages in wireshark logs through tcl automation</title>
      <link>/questions/23100/how-to-analyze-sip-messages-in-wireshark-logs-through-tcl-automation/</link>
      <pubDate>Thu, 18 Jul 2013 04:16:00 +0000</pubDate>
      
      <guid>/questions/23100/how-to-analyze-sip-messages-in-wireshark-logs-through-tcl-automation/</guid>
      <description>How to analyze sip messages in wireshark logs through tcl automation  0 Can anyone help me how to write tcl script for analysing sip messages in wireshark logs... If possible the code
12ab3asked 18 Jul &#39;13, 04:16
megha
1●1●1●1
accept rate: 0%
for analysing sip messages
what are you trying to do?
how good is your knowledge of TCL, tshark and SIP?is this a business/commerical request?(18 Jul &#39;13, 04:49) Kurt Knochner ♦   </description>
    </item>
    
    <item>
      <title>what are all the Reset</title>
      <link>/questions/23109/what-are-all-the-reset/</link>
      <pubDate>Thu, 18 Jul 2013 14:32:00 +0000</pubDate>
      
      <guid>/questions/23109/what-are-all-the-reset/</guid>
      <description>what are all the Reset  0 I have a lot of resets on the network, can someone tell me what are the resets an what do the represent.
https://www.cloudshark.org/captures/0f3c9b705840
wirshark_resetsasked 18 Jul &#39;13, 14:32
ejohnson7
11●9●9●12
accept rate: 0%
thanks in advance
(18 Jul &#39;13, 14:32) ejohnson7  
3 Answers:
  
3 OK, since the 10.97.54.9 is a load-balancer (and presumably the 10.97.54.8 is it&#39;s counterpart in the LB-cluster) it all makes sense.</description>
    </item>
    
    <item>
      <title>UDP port range filter not working</title>
      <link>/questions/23120/udp-port-range-filter-not-working/</link>
      <pubDate>Thu, 18 Jul 2013 15:22:00 +0000</pubDate>
      
      <guid>/questions/23120/udp-port-range-filter-not-working/</guid>
      <description>UDP port range filter not working  0 I am trying to filter the traffic by udp port and find out that range filter is not working.
For example, I have two filters.
Filter 1: udp.port == 48777
Filter 2: (udp.port &amp;gt; 48776) and (udp.port &amp;lt; 48778)
In my point of view, these two filters should give be same results. But in fact filter 2 will give me all udp traffic, regardless of port number.</description>
    </item>
    
    <item>
      <title>Wireshark for Red Hat Enterprise Linux</title>
      <link>/questions/23138/wireshark-for-red-hat-enterprise-linux/</link>
      <pubDate>Fri, 19 Jul 2013 01:04:00 +0000</pubDate>
      
      <guid>/questions/23138/wireshark-for-red-hat-enterprise-linux/</guid>
      <description>Wireshark for Red Hat Enterprise Linux  0 Hi Experts,
The download page on Wireshark page says that Wireshark is available as a standard package for RedHat Enterprise Linux. Does that mean it is pre installed ? Could you please tell me what to do if it is not installed there. I am not a Linux expert, I just have to guide my unix support team on the same. Is it not possible to get a direct installable for RedHat ?</description>
    </item>
    
    <item>
      <title>--with-pcap=directory isn&amp;#x27;t working</title>
      <link>/questions/23150/-with-pcapdirectory-isnt-working/</link>
      <pubDate>Fri, 19 Jul 2013 05:48:00 +0000</pubDate>
      
      <guid>/questions/23150/-with-pcapdirectory-isnt-working/</guid>
      <description>&amp;ndash;with-pcap=directory isn&amp;rsquo;t working  0 I am unable to &#34;configure Wireshark with --with-pcap=directory, &#34;. I have my own compiled libpcap.a.
Please give some details about where i will get the configuration file. I am using ubuntu 10.10-32 bit.
Thanks in advance.
configure libpcapasked 19 Jul &#39;13, 05:48
baila
21●10●11●15
accept rate: 0%
 converted 19 Jul &#39;13, 11:33 
Guy Harris ♦♦
17.4k●3●35●196
Is your libpcap.a in the directory you specified as an argument to the --with-pcap= flag to the configure script?</description>
    </item>
    
    <item>
      <title>Continuation or non-HTTP traffic won&amp;#x27;t produce HTTP</title>
      <link>/questions/23151/continuation-or-non-http-traffic-wont-produce-http/</link>
      <pubDate>Fri, 19 Jul 2013 07:26:00 +0000</pubDate>
      
      <guid>/questions/23151/continuation-or-non-http-traffic-wont-produce-http/</guid>
      <description>Continuation or non-HTTP traffic won&amp;rsquo;t produce HTTP  0 EDIT2:
I made another capture session and uploaded it to cloudshark.org
The GET request for which there is no HTTP response is frame 364
http://cloudshark.org/captures/c36979d903e0
Then I rearranged the frames in this sequence: ...-364-367-365-368-371-369-372-...
I removed frames 366 &amp;amp; 370. Here&#39;s the result:
http://cloudshark.org/captures/5003ae96ae6b
Both captures need SSL keys:
http://pastebin.com/DMcFKW2p
EDIT1:
Following up on SYN-bit&#39;s response, I rearranged the out-of-order packets using editcap and mergecap, but the &#34;</description>
    </item>
    
    <item>
      <title>Capturing http response delays</title>
      <link>/questions/23168/capturing-http-response-delays/</link>
      <pubDate>Fri, 19 Jul 2013 11:33:00 +0000</pubDate>
      
      <guid>/questions/23168/capturing-http-response-delays/</guid>
      <description>Capturing http response delays  0 Can someone tell me how I set this up for capture? I&#39;m trying to discover delayed http responses to http requests from a particular PC on our LAN. It&#39;s IP address is 192.168.1.73. I don&#39;t know the web server&#39;s address yet but I will in a minute so we can just make one up for now for this discussion.
delay http responseasked 19 Jul &#39;13, 11:33</description>
    </item>
    
    <item>
      <title>Apache server issue reset</title>
      <link>/questions/23180/apache-server-issue-reset/</link>
      <pubDate>Fri, 19 Jul 2013 12:35:00 +0000</pubDate>
      
      <guid>/questions/23180/apache-server-issue-reset/</guid>
      <description>Apache server issue reset  0 I have an apache server communicating with a server where the apache serve is ack as a proxy I am seeing reset when the two servers attempt to communicate with each other. I see the same Behavior in frame 6, 12, 17 and 23 just before the reset in each frame REQ: CPING AND A REQ: CPONG. I have no idea what that means can some help me with this pending issue 10.</description>
    </item>
    
    <item>
      <title>capturing (and decoding) open wireless network packets</title>
      <link>/questions/23182/capturing-and-decoding-open-wireless-network-packets/</link>
      <pubDate>Fri, 19 Jul 2013 15:00:00 +0000</pubDate>
      
      <guid>/questions/23182/capturing-and-decoding-open-wireless-network-packets/</guid>
      <description>capturing (and decoding) open wireless network packets  0 hello,
i am trying to capture my open wireless network&#39;s (no password) packets.
I am able to capture wpa2 traffic and decrypt the packets with it&#39;s password. but, when I capture open wifi traffic, i cannot see any readable packet in the capture file.
I am using: -backtrack 5 -AWUS036H card (Realtek RTL8187L chipset)
i tried: &#34;airdecap-ng -b &amp;lt;ap_mac&amp;gt; &amp;lt;capture_file.cap&amp;gt;&#34;
but it didn&#39;t work.</description>
    </item>
    
    <item>
      <title>Decrypting SSL Application Data.</title>
      <link>/questions/23185/decrypting-ssl-application-data/</link>
      <pubDate>Fri, 19 Jul 2013 17:16:00 +0000</pubDate>
      
      <guid>/questions/23185/decrypting-ssl-application-data/</guid>
      <description>Decrypting SSL Application Data.  0 I have a commercial client &amp;gt; server application that uses SSL to encrypt data between the two end-points and I want to decrypt it. FWIW it&#39;s using a non-standard port(it doesn&#39;t use port 443, 389, etc).
In the Edit &amp;gt; Preferences &amp;gt; Protocols &amp;gt; SSL &amp;gt; RSA keys list: field, there&#39;s a parameter to specify a protocol. In the examples I&#39;ve seen the protocol listed is a clear text protocol(like HTTP or LDAP) but I don&#39;t know what the commercial application uses.</description>
    </item>
    
    <item>
      <title>Mac OSX - filters don&amp;#x27;t work</title>
      <link>/questions/23187/mac-osx-filters-dont-work/</link>
      <pubDate>Fri, 19 Jul 2013 17:32:00 +0000</pubDate>
      
      <guid>/questions/23187/mac-osx-filters-dont-work/</guid>
      <description>Mac OSX - filters don&amp;rsquo;t work  2 I get errors when I try filters like &#39;port 443&#39; on Mac OSX.
It says invalid filter error.
I tried most of these and they almost all failed.
http://wiki.wireshark.org/CaptureFilters
macosx filtersasked 19 Jul &#39;13, 17:32
chovy
41●2●2●5
accept rate: 0%
So you typed that into the &#34;Capture Filter&#34; box in the dialog that, for Wireshark 1.8 and later, pops up when you double-click on an interface in the &#34;</description>
    </item>
    
    <item>
      <title>VOIP QoS in monitoring??</title>
      <link>/questions/23188/voip-qos-in-monitoring/</link>
      <pubDate>Fri, 19 Jul 2013 19:05:00 +0000</pubDate>
      
      <guid>/questions/23188/voip-qos-in-monitoring/</guid>
      <description>VOIP QoS in monitoring??  0 Hello WireShark.org I have a small experiment on voice over ip, I &#39;ve done it by asterisk. I have a question about monitoring packets of VoIP when the Qos 802.11e is activated. How can I detect the quality of service is running?? the DSCP(0x00) is not changed when I activet it or don&#39;t.
Thanks very much
802.11e voipasked 19 Jul &#39;13, 19:05
hamad
6●1●1●3</description>
    </item>
    
    <item>
      <title>Packet Source and Destination when in Monitor Mode</title>
      <link>/questions/23203/packet-source-and-destination-when-in-monitor-mode/</link>
      <pubDate>Sun, 21 Jul 2013 02:25:00 +0000</pubDate>
      
      <guid>/questions/23203/packet-source-and-destination-when-in-monitor-mode/</guid>
      <description>Packet Source and Destination when in Monitor Mode  0 Hi, probably a n00b question, but I can&#39;t find an answer to it.
I have my Wireshark instaled on Ubuntu within VmWare Workstation. I activated the monitor mode on mon0 with airmon-ng. When I&#39;m listening on that interface (mon0) all I can see is 802.11 protocol and Source/Destination addresses are not displayed as regular IP addresses so I can&#39;t figure out where does traffic originated from and where is it going (no IP information).</description>
    </item>
    
    <item>
      <title>Desktop client tracking</title>
      <link>/questions/23204/desktop-client-tracking/</link>
      <pubDate>Sun, 21 Jul 2013 02:28:00 +0000</pubDate>
      
      <guid>/questions/23204/desktop-client-tracking/</guid>
      <description>Desktop client tracking  0 I created a desktop client connects to Postgresql database and I want to be sure that this application uses SSL (I don&#39;t want to expose users authentications over the network).
How can I be sure that my desktop client connections over SSL or not?
I couldn&#39;t find a way to make Wireshark track my application&#39;s process so tried to use a simple filter because I know the destination ip and the port but this didn&#39;t help me very much!</description>
    </item>
    
    <item>
      <title>How to convert g729 audio file without http://www.voiceage.com/openinit_g729.php</title>
      <link>/questions/23207/how-to-convert-g729-audio-file-without-httpwwwvoiceagecomopeninit_g729php/</link>
      <pubDate>Sun, 21 Jul 2013 06:29:00 +0000</pubDate>
      
      <guid>/questions/23207/how-to-convert-g729-audio-file-without-httpwwwvoiceagecomopeninit_g729php/</guid>
      <description>How to convert g729 audio file without http://www.voiceage.com/openinit_g729.php  0 How to convert g729 audio file without http://www.voiceage.com/openinit_g729.php
g729This question is marked &#34;community wiki&#34;.asked 21 Jul &#39;13, 06:29
support
11●1●1●3
accept rate: 0%
1Is this a Wireshark question?
If so, please add some information what you captured and why/how you need to convert that data from g729 to what exactly?
(22 Jul &#39;13, 14:46) Kurt Knochner ♦how to play audio/voice in g729 codec capture file by using wireshark , without the software voiceage?</description>
    </item>
    
    <item>
      <title>Trying to identify the source of some traffic</title>
      <link>/questions/23210/trying-to-identify-the-source-of-some-traffic/</link>
      <pubDate>Sun, 21 Jul 2013 10:34:00 +0000</pubDate>
      
      <guid>/questions/23210/trying-to-identify-the-source-of-some-traffic/</guid>
      <description>Trying to identify the source of some traffic  0 Hi there.
I&#39;m trying to use Wireshark to identify whatever software is behind some traffic on my PC. Unfortunately, while I&#39;ve identfied some likely packets, I know virtually nothing about how to read them. I can&#39;t see anything immediately obvious, so can someone tell me how, if it&#39;s even possible?
A little background: I have another PC on my home LAN which is acting as a media centre and network storage.</description>
    </item>
    
    <item>
      <title>Display data in raw</title>
      <link>/questions/23218/display-data-in-raw/</link>
      <pubDate>Mon, 22 Jul 2013 00:16:00 +0000</pubDate>
      
      <guid>/questions/23218/display-data-in-raw/</guid>
      <description>Display data in raw  0 good morning, everyone
i need to display a message in à field , but it is too long , so when it is displayed , it is truncked , so i want to display this message like a raw data like in SIP protocol.
can someone tell me if a special type fot that existe ??
Thank you.
rawasked 22 Jul &#39;13, 00:16
cruz</description>
    </item>
    
    <item>
      <title>How does Wirehark calculate the clock drift for RTP?</title>
      <link>/questions/23220/how-does-wirehark-calculate-the-clock-drift-for-rtp/</link>
      <pubDate>Mon, 22 Jul 2013 03:58:00 +0000</pubDate>
      
      <guid>/questions/23220/how-does-wirehark-calculate-the-clock-drift-for-rtp/</guid>
      <description>How does Wirehark calculate the clock drift for RTP?  0 Hi,
I made an rtp capture and obtained the following statistics :
Max delta = 26,74 ms at packet no. 482 Max jitter = 0,94 ms. Mean jitter = 0,38 ms. Max skew = -6,65 ms. Total RTP packets = 92 (expected 92) Lost RTP packets = 0 (0,00%) Sequence errors = 0 Duration 8,20 s (-1842 ms clock drift, corresponding to 6203 Hz (-22,47%)I do not understand how it calculates -1842 ms clock drift since in the trace there is no difference between the timestamp of wireshark and the timestamp of the RTP stream.</description>
    </item>
    
    <item>
      <title>BACnet messages on UDP ports other than 47808, can they be decoded?</title>
      <link>/questions/23221/bacnet-messages-on-udp-ports-other-than-47808-can-they-be-decoded/</link>
      <pubDate>Mon, 22 Jul 2013 04:39:00 +0000</pubDate>
      
      <guid>/questions/23221/bacnet-messages-on-udp-ports-other-than-47808-can-they-be-decoded/</guid>
      <description>BACnet messages on UDP ports other than 47808, can they be decoded?  0 We have BACnet system configured using ports 47811. While using wireshark for analysis, we found BACnet messages on port 47811 is not recognized.
bacnet udp portsasked 22 Jul &#39;13, 04:39
RP_1985
6●1●1●2
accept rate: 0%
 edited 22 Jul &#39;13, 06:04 
cmaynard ♦♦
9.4k●10●38●142
  
2 Answers:
  
3 Jasper is close, but the packets have to be UDP, and then you can select the BVLC (BACNet Virtual Link Control) protocol.</description>
    </item>
    
    <item>
      <title>How can I reassemble fragments from two different datagrams in the same frame?</title>
      <link>/questions/23222/how-can-i-reassemble-fragments-from-two-different-datagrams-in-the-same-frame/</link>
      <pubDate>Mon, 22 Jul 2013 04:56:00 +0000</pubDate>
      
      <guid>/questions/23222/how-can-i-reassemble-fragments-from-two-different-datagrams-in-the-same-frame/</guid>
      <description>How can I reassemble fragments from two different datagrams in the same frame?  0 Hi,
a problem has occurred with decoding reassembled fragments lately. I&#39;ve searched the FAQ and mailing lists but found nothing about it.
When the last fragment of a datagram would be reassembled in frame x but another fragment of a next datagram would start in the same frame x, the entry of the last fragment of the first datagram will be overwritten by the next fragment of the next datagram.</description>
    </item>
    
    <item>
      <title>Wireshark Tapping plugin</title>
      <link>/questions/23235/wireshark-tapping-plugin/</link>
      <pubDate>Mon, 22 Jul 2013 09:02:00 +0000</pubDate>
      
      <guid>/questions/23235/wireshark-tapping-plugin/</guid>
      <description>Wireshark Tapping plugin  0 Hey,
I am trying to write a tap plugin, I am being quite successful, however, I am facing a problem. I cannot access on the tap all fields of a protocol, in some cases the &#34;abbrev&#34; returns &#34;Text Item&#34; and the value is &#34;Text&#34;.
Anyone can explain me why ?
Thanks in advance.
tapping tap pluginasked 22 Jul &#39;13, 09:02
rogerpt
11●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Why do all mongodb query show as [Malformed Packet: MONGO]?</title>
      <link>/questions/23241/why-do-all-mongodb-query-show-as-malformed-packet-mongo/</link>
      <pubDate>Mon, 22 Jul 2013 10:12:00 +0000</pubDate>
      
      <guid>/questions/23241/why-do-all-mongodb-query-show-as-malformed-packet-mongo/</guid>
      <description>Why do all mongodb query show as [Malformed Packet: MONGO]?  0 When I update Wireshark from 1.8.2 to 1.10.0, all the mongodb query can be showed clearly in version 1.8.2 can not be shown correctly, all the mongo queries were showed as [Malformed Packet: MONGO](Both in ubuntu and windows). The mongodb reply also work as in both version 1.8.2 and 1.10.0.
mongodbasked 22 Jul &#39;13, 10:12
ricky
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How do you capture Serial (COM) communications?</title>
      <link>/questions/23243/how-do-you-capture-serial-com-communications/</link>
      <pubDate>Mon, 22 Jul 2013 10:30:00 +0000</pubDate>
      
      <guid>/questions/23243/how-do-you-capture-serial-com-communications/</guid>
      <description>How do you capture Serial (COM) communications?  0 I want to wireshark the packets being sent and received via the serial port on my computer, it is a windows xp. How can I go about this?
serial-port wiresharkasked 22 Jul &#39;13, 10:30
julianv23
11●1●1●2
accept rate: 0%
  
4 Answers:
  
1If the answer is still actual:
COM port sniffer for Windows - http://www.eltima.com/products/serial-port-monitor/
answered 09 Oct &#39;13, 00:52</description>
    </item>
    
    <item>
      <title>overlapping packets</title>
      <link>/questions/23244/overlapping-packets/</link>
      <pubDate>Mon, 22 Jul 2013 10:48:00 +0000</pubDate>
      
      <guid>/questions/23244/overlapping-packets/</guid>
      <description>overlapping packets  0 I contacted you before 5 weeks asking for help about overlapping outgoing packets in time in wireshark program. And you told me that the problem is in timestamping of outgoing packets. So the packets were timestamped on host and because of that there was delay of actual sending of packets and they were overlapped.
You told me to make outgoing packets be timestamped on the card so they would be more precisely measured.</description>
    </item>
    
    <item>
      <title>Select playback device - help?</title>
      <link>/questions/23248/select-playback-device-help/</link>
      <pubDate>Mon, 22 Jul 2013 12:14:00 +0000</pubDate>
      
      <guid>/questions/23248/select-playback-device-help/</guid>
      <description>Select playback device - help?  0 Hey folks. I have absolutely zero experience with this stuff, and I can&#39;t manage to find any tutorials.
My end goal is replay a single captured packet I saved with wireshark (managed that just fine, saved as .pcap). I&#39;m trying to do this with playcap. I open the file and it prompts me to select a playback device. Is this &#34;playback device&#34; some sort of hardware, or a program?</description>
    </item>
    
    <item>
      <title>Can tshark use &amp;#x27;-e &amp;#x27; values generated within a custom lua disector?</title>
      <link>/questions/23249/can-tshark-use-e-values-generated-within-a-custom-lua-disector/</link>
      <pubDate>Mon, 22 Jul 2013 13:18:00 +0000</pubDate>
      
      <guid>/questions/23249/can-tshark-use-e-values-generated-within-a-custom-lua-disector/</guid>
      <description>Can tshark use &amp;lsquo;-e &#39; values generated within a custom lua disector?  0 Hi,
I am capturing some packets that contains private headers within the payload. I have written a quick &amp;amp; dirty lua dissector to decode these headers and everything works well from inside wireshark. That is I am able to &#34;decode as&#34; and see my proprietary headers within wireshark as expected.
I am now attempting to do the same from cmd line tshark with something like this:</description>
    </item>
    
    <item>
      <title>Promiscuous vs monitor mode</title>
      <link>/questions/23257/promiscuous-vs-monitor-mode/</link>
      <pubDate>Mon, 22 Jul 2013 14:50:00 +0000</pubDate>
      
      <guid>/questions/23257/promiscuous-vs-monitor-mode/</guid>
      <description>Promiscuous vs monitor mode  0 Hi, It looks like my Wireshark is not running in monitor mode. This is in short. Now the extended version :-). I&#39;m, running Wireshark 1.6.7 on Ubuntu 12.04. I activated monitor mode on mon0 interface through airmon. I set Wireshark to listen on mon0. When I open mon0 settings I can see that the &#34;Capture packets in promiscuous mode&#34; is enabled. &#34;Capture packets in monitor mode&#34;</description>
    </item>
    
    <item>
      <title>iSCSI Format Failure from Windows Server 2012</title>
      <link>/questions/23261/iscsi-format-failure-from-windows-server-2012/</link>
      <pubDate>Mon, 22 Jul 2013 15:36:00 +0000</pubDate>
      
      <guid>/questions/23261/iscsi-format-failure-from-windows-server-2012/</guid>
      <description>iSCSI Format Failure from Windows Server 2012  0 I don&#39;t expect anyone to be able to help me with this, but I didn&#39;t expect any help last time I posted a message yet was pleasantly surpised to get a very spot-on answer.
This one is a bit tougher though.
I&#39;ve been working on an iSCSI server, mostly just for fun. Been chipping away at it in my spare time. I&#39;ve managed to get through a lot of things.</description>
    </item>
    
    <item>
      <title>Seeing only management and control frames on 802.11</title>
      <link>/questions/23274/seeing-only-management-and-control-frames-on-80211/</link>
      <pubDate>Mon, 22 Jul 2013 17:53:00 +0000</pubDate>
      
      <guid>/questions/23274/seeing-only-management-and-control-frames-on-80211/</guid>
      <description>Seeing only management and control frames on 802.11  0 I&#39;m capturing in monitor mode, but I&#39;m not seeing any packets where the header claims it&#39;s a data.
802.11asked 22 Jul &#39;13, 17:53
andyhuang
11●1●1●3
accept rate: 0%
 edited 22 Jul &#39;13, 18:05 
Guy Harris ♦♦
17.4k●3●35●196
This is a separate question - the person who asked the question where you added an &#34;answer&#34; that&#39;s actually a question never said whether the problem was that they didn&#39;t see any data frames or that they saw data frames but they were only dissected as 802.</description>
    </item>
    
    <item>
      <title>Fragmented UDP Packets in RTP Session</title>
      <link>/questions/23278/fragmented-udp-packets-in-rtp-session/</link>
      <pubDate>Tue, 23 Jul 2013 00:04:00 +0000</pubDate>
      
      <guid>/questions/23278/fragmented-udp-packets-in-rtp-session/</guid>
      <description>Fragmented UDP Packets in RTP Session  0 Hello,
I have a problem on a video conference system over wan with fragmented udp packets. In a video session are a lot of stops on the screen. I have created a wireshark dump where I have found a lot of the following messages &#34;Fragmented IP protocol (proto=UDP 17, off=0, ID=39a4) [Reassembled in #15794]
The first to solve this problem for me is, to configure qos between both sites.</description>
    </item>
    
    <item>
      <title>How to determine which NIC is being used ?</title>
      <link>/questions/23287/how-to-determine-which-nic-is-being-used/</link>
      <pubDate>Tue, 23 Jul 2013 07:52:00 +0000</pubDate>
      
      <guid>/questions/23287/how-to-determine-which-nic-is-being-used/</guid>
      <description>How to determine which NIC is being used ?  0 I have 3 NICs in a windows box. NIC1 local network. NIC2 slow ISP. NIC3 fast ISP.
What I am trying to do: Capture a couple of thousand packets from all 3 NICs. Then look at a packet that I am interested in and see which NIC is being used.
Example I see a packet with the source address of a pc on my lan.</description>
    </item>
    
    <item>
      <title>capture filter does not capture when active</title>
      <link>/questions/23289/capture-filter-does-not-capture-when-active/</link>
      <pubDate>Tue, 23 Jul 2013 08:17:00 +0000</pubDate>
      
      <guid>/questions/23289/capture-filter-does-not-capture-when-active/</guid>
      <description>capture filter does not capture when active  0 tried multiple wireshark versions. read Help files, wiki and forums but no one seems to have my issue. Now using wireshark 1.10, I can capture packets using my laptop gig port. I can filter SIP traffic and notice it&amp;lt;s using port 5060, and IP phones are using IP addresses in the 10.x.x.x range.
But if i select that same network card, attempt to add a packet filter (ex: net 10.</description>
    </item>
    
    <item>
      <title>Remote capture on linux</title>
      <link>/questions/23293/remote-capture-on-linux/</link>
      <pubDate>Tue, 23 Jul 2013 09:15:00 +0000</pubDate>
      
      <guid>/questions/23293/remote-capture-on-linux/</guid>
      <description>Remote capture on linux  0 Hi all, i have one question regarding remote capture. I am asking it here so that anyone else can also get the relevant discussions.
My question is that why the wireshark versions for linux platform don&#39;t have the option &#34;Remote interface&#34; in Options menu like windows?
Can we enable it by changing configure file during installation?Will it work as similar as of wireshark versions available for windows?</description>
    </item>
    
    <item>
      <title>Exporting packets with Wireshark version 1.10.0</title>
      <link>/questions/23306/exporting-packets-with-wireshark-version-1100/</link>
      <pubDate>Tue, 23 Jul 2013 16:18:00 +0000</pubDate>
      
      <guid>/questions/23306/exporting-packets-with-wireshark-version-1100/</guid>
      <description>Exporting packets with Wireshark version 1.10.0  0 Why when I save an export I have filtered 140,000 packets out of 386,000 packets, when I have the save the displayed packets does it save the whole 386,000 instead of the 140,000? I think this might be a bug with version 1.10.0 Wireshark
filter saveas save exportasked 23 Jul &#39;13, 16:18
philvilla
11●4●4●5
accept rate: 0%
 edited 23 Jul &#39;13, 18:09</description>
    </item>
    
    <item>
      <title>Unable to run dumpcap</title>
      <link>/questions/23316/unable-to-run-dumpcap/</link>
      <pubDate>Tue, 23 Jul 2013 23:54:00 +0000</pubDate>
      
      <guid>/questions/23316/unable-to-run-dumpcap/</guid>
      <description>Unable to run dumpcap  0 Hi,
I am using the windows 7 OS.... and i for the second one command i dont see any output on the CLI..
C:\Users\emohirf&amp;gt;sc query npf
SERVICE_NAME: npf TYPE : 1 KERNEL_DRIVER STATE : 4 RUNNING (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN) WIN32_EXIT_CODE : 0 (0x0) SERVICE_EXIT_CODE : 0 (0x0) CHECKPOINT : 0x0 WAIT_HINT : 0x0
C:\Users\emohirf&amp;gt;dumpcap -D -M &#39;dumpcap&#39; is not recognized as an internal or external command, operable program or batch file.</description>
    </item>
    
    <item>
      <title>Capturing raw bitstream on Ethernet</title>
      <link>/questions/23329/capturing-raw-bitstream-on-ethernet/</link>
      <pubDate>Wed, 24 Jul 2013 08:55:00 +0000</pubDate>
      
      <guid>/questions/23329/capturing-raw-bitstream-on-ethernet/</guid>
      <description>Capturing raw bitstream on Ethernet  0 According to 802.3-2012 (Section 3.3), each octet of a MAC frame is transmitted Least Significant Bit (LSB) first, with the exception of the FCS. Therefore, a DEST MAC of 00:00:00:00:00:02 would be transmitted on the line as 02 00 00 00 00 00 – or 0010 0000 0000 0000 0000 0000 (in Binary). Is there a way to capture the raw binary or hex bit stream as it exists on the wire?</description>
    </item>
    
    <item>
      <title>Providing each packet to wireshark using command line</title>
      <link>/questions/23333/providing-each-packet-to-wireshark-using-command-line/</link>
      <pubDate>Wed, 24 Jul 2013 10:07:00 +0000</pubDate>
      
      <guid>/questions/23333/providing-each-packet-to-wireshark-using-command-line/</guid>
      <description>Providing each packet to wireshark using command line  0 Hello All,
I am right now writing a pcap file to save all packets, as soon as I receive. Then I am opening that pcap into wireshark using wireshark -k -i ${FILE}. Instead of that I want to provide each packet to wireshark? Is that possible?
Also when I provide the pcap file, and after running the command if I append packets in the file would wireshark analyse them also?</description>
    </item>
    
    <item>
      <title>Zero window size .</title>
      <link>/questions/23338/zero-window-size/</link>
      <pubDate>Wed, 24 Jul 2013 11:35:00 +0000</pubDate>
      
      <guid>/questions/23338/zero-window-size/</guid>
      <description>Zero window size .  0 what are the cases in which a host supposed to send Zero window size ?
tcpasked 24 Jul &#39;13, 11:35
ManojMaity
1●1●1●1
accept rate: 0%
  
2 Answers:
  
3Define &#34;supposed to&#34; :-)
Zero Window is used in two situations:
In a TCP reset packet. No problem at allWhen the receiver can&#39;t take more data. This indicates a performance problem of the receiving hardwareanswered 24 Jul &#39;13, 11:58</description>
    </item>
    
    <item>
      <title>Deciphering packet descriptions on USB device (IRP, URB)</title>
      <link>/questions/23352/deciphering-packet-descriptions-on-usb-device-irp-urb/</link>
      <pubDate>Wed, 24 Jul 2013 19:41:00 +0000</pubDate>
      
      <guid>/questions/23352/deciphering-packet-descriptions-on-usb-device-irp-urb/</guid>
      <description>Deciphering packet descriptions on USB device (IRP, URB)  0 Hello all,
I am a new user, first time poster so please bear with me.
I am using Wireshark to analyze USB traffic captured by a program called USBPcap (http://desowin.org/usbpcap/). To give you some background, I am attempting to create a driver for a device whose manufacturer stopped making software for it after XP. To do this, I am attempting to isolate the low-level commands and send them to the device with a laptop running a modern OS using LabVIEW and NI-VISA.</description>
    </item>
    
    <item>
      <title>Dell esg pcba test</title>
      <link>/questions/23361/dell-esg-pcba-test/</link>
      <pubDate>Thu, 25 Jul 2013 10:19:00 +0000</pubDate>
      
      <guid>/questions/23361/dell-esg-pcba-test/</guid>
      <description>Dell esg pcba test  0 Can anyone give me any info on this? It is showing as active on my network. No machines I have match it&#39;s mac addrs. which is, 00:18:8B:8A:3E:1B. The name is Mindless-PC. Thanks for your time.
esg test pcba mindless-pcasked 25 Jul &#39;13, 10:19
ham hamlin
11●1●1●4
accept rate: 0%
 edited 25 Jul &#39;13, 12:39 
Kurt Knochner ♦
24.8k●10●39●237
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark and PXE Server</title>
      <link>/questions/23370/wireshark-and-pxe-server/</link>
      <pubDate>Thu, 25 Jul 2013 16:25:00 +0000</pubDate>
      
      <guid>/questions/23370/wireshark-and-pxe-server/</guid>
      <description>Wireshark and PXE Server  0 Hello
We are sending a UDP Request to the PXE Server but for some reason the PXE Server is not receiving this UDP request. Then we put wireshark on the PXE server and now we see that the PXE Server does receive our UDP Request.
Any thoughts on why this might be happening?
Thanks,
nelsme recognizedasked 25 Jul &#39;13, 16:25
ChrisPXE
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Any reason not to strip symbols from wireshark/libwireshark/libwiretap?</title>
      <link>/questions/23372/any-reason-not-to-strip-symbols-from-wiresharklibwiresharklibwiretap/</link>
      <pubDate>Thu, 25 Jul 2013 18:03:00 +0000</pubDate>
      
      <guid>/questions/23372/any-reason-not-to-strip-symbols-from-wiresharklibwiresharklibwiretap/</guid>
      <description>Any reason not to strip symbols from wireshark/libwireshark/libwiretap?  0 I usually use strip(1) on Unix/Linux systems to strip symbols from executable binaries and libraries, on the general principle that smaller executables = smaller memory footprint = better performance. As long as I&#39;m not debugging/breakpointing the code, there shouldn&#39;t be any need for the symbols anyway...
Doing so to the main components of Wireshark 1.10.0 makes a HUGE difference in the size of the executables:</description>
    </item>
    
    <item>
      <title>Calculating Application Block Size</title>
      <link>/questions/23385/calculating-application-block-size/</link>
      <pubDate>Fri, 26 Jul 2013 03:29:00 +0000</pubDate>
      
      <guid>/questions/23385/calculating-application-block-size/</guid>
      <description>Calculating Application Block Size  0 using Wireshark how can we calculate Application Block size.
Basically I am try to measure throughput for Particular Application like( CIFS ) so trying to understand how we can calculate Application Block Size.
Thanks for help.
applicationasked 26 Jul &#39;13, 03:29
m_1607
35●12●13●16
accept rate: 0%
Can you please add some information regarding &#39;Application Block Size&#39;. What do you mean by that in the context of what protocol?</description>
    </item>
    
    <item>
      <title>Extend GRE dissector</title>
      <link>/questions/23390/extend-gre-dissector/</link>
      <pubDate>Fri, 26 Jul 2013 10:14:00 +0000</pubDate>
      
      <guid>/questions/23390/extend-gre-dissector/</guid>
      <description>Extend GRE dissector  0 Hey,
In a lab setup I need to analyze packets which headers are based on GRE but altered in the way that there are additional TLV-fields being added after the standard GRE header.
I would like to ask for the best way to implement this as a custom disscetor. Is it possible to extend the existing GRE dissector by adding a custom one or do I need to alter the existing GRE dissector source file?</description>
    </item>
    
    <item>
      <title>Manually enter remote capture line</title>
      <link>/questions/23393/manually-enter-remote-capture-line/</link>
      <pubDate>Fri, 26 Jul 2013 16:34:00 +0000</pubDate>
      
      <guid>/questions/23393/manually-enter-remote-capture-line/</guid>
      <description>Manually enter remote capture line  0 In old versions of Wireshark (running on Win32 and Win64), I could open the capture options and type (or paste) rpcap://ip.address/br0 to capture from a remote linux device, which was fast and convenient.
In new versions, there&#39;s a remote capture tab which tries to query the remote endpoint for the list of addresses, and takes forever. The rpcapd installed on my Linux system may be too old to support this query at all.</description>
    </item>
    
    <item>
      <title>Sniffing Ethernet networks</title>
      <link>/questions/23406/sniffing-ethernet-networks/</link>
      <pubDate>Sat, 27 Jul 2013 12:18:00 +0000</pubDate>
      
      <guid>/questions/23406/sniffing-ethernet-networks/</guid>
      <description>Sniffing Ethernet networks  0 I was wondering is it possible to capture the packets of other computers on a cable network ? if so is it possible to do it by windows or like wifi windows can&#39;t sniff packets from other computers and doesn&#39;t support monitor mode ?
ethernet sniff networkasked 27 Jul &#39;13, 12:18
Milad Rad
16●2●2●4
accept rate: 0%
 edited 27 Jul &#39;13, 23:39 
Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>how to handle time stamps with an epoch of January 1, 2000?</title>
      <link>/questions/23408/how-to-handle-time-stamps-with-an-epoch-of-january-1-2000/</link>
      <pubDate>Sat, 27 Jul 2013 21:02:00 +0000</pubDate>
      
      <guid>/questions/23408/how-to-handle-time-stamps-with-an-epoch-of-january-1-2000/</guid>
      <description>how to handle time stamps with an epoch of January 1, 2000?  0 I am working on the zigbee portion of wireshark. Wireshark uses traditional gmtime function, which has epoch year 1970. But Zigbee has its own epoch year 2000 Jan 1st. Hence, when a NTP time 0x00000000 is passed on to wireshark, I expect it to be 2000. Jan .1st. But, when I use tvb_ntp_ts function, it gives me errors.</description>
    </item>
    
    <item>
      <title>WPA decryption</title>
      <link>/questions/23413/wpa-decryption/</link>
      <pubDate>Sun, 28 Jul 2013 07:01:00 +0000</pubDate>
      
      <guid>/questions/23413/wpa-decryption/</guid>
      <description>WPA decryption  0 Hi I want to decrypt my WPA packets which i gathered by sniffing other computer from my network with airodump-ng.
The problem is that even after I have the 4-way handshake packets (they are correct) i don&#39;t know how to extract the PSK so i can put it in the IEEE 802.11 wireshark preferences. However i created the &#34;raw&#34; PSK but after i typed it into WPA decrytpion keys and enabled the decryption it still doesnt want to work.</description>
    </item>
    
    <item>
      <title>How to decode video stream if type is unknown?</title>
      <link>/questions/23416/how-to-decode-video-stream-if-type-is-unknown/</link>
      <pubDate>Sun, 28 Jul 2013 15:05:00 +0000</pubDate>
      
      <guid>/questions/23416/how-to-decode-video-stream-if-type-is-unknown/</guid>
      <description>How to decode video stream if type is unknown?  0 Hi there,
i captured some udp packets while streaming my webcam in order to reassemble them to a video. Unfortunately i even don&#39;t know the type of that video stream. Wireshark is just defining the packets as UDP and no hint concerning RTP or any other streaming format. How can i proceed with my analysis, without knowing the type?</description>
    </item>
    
    <item>
      <title>tshark shows unknown mactype 2147483653</title>
      <link>/questions/23418/tshark-shows-unknown-mactype-2147483653/</link>
      <pubDate>Mon, 29 Jul 2013 00:04:00 +0000</pubDate>
      
      <guid>/questions/23418/tshark-shows-unknown-mactype-2147483653/</guid>
      <description>tshark shows unknown mactype 2147483653  0 Dear support,
we have installed wireshark successfully as a package from sunfreeware.
Now we want to start tshark and we get the following message:
Capturing on lo0 tshark: Can&#39;t install filter (unknown mactype 2147483653). Please report this to the Wireshark developers. (This is not a crash; please do not report it as such.) 0 packets captured
Out platform is sun4v ( T4-1 ).</description>
    </item>
    
    <item>
      <title>PacketreceivePacket failed</title>
      <link>/questions/23424/packetreceivepacket-failed/</link>
      <pubDate>Mon, 29 Jul 2013 03:49:00 +0000</pubDate>
      
      <guid>/questions/23424/packetreceivepacket-failed/</guid>
      <description>PacketreceivePacket failed  0 I am using WinPcap version 4.1.1 and if I start my program, at some point I am seeing PacketReceivePacket failed error message. I am using windows2008. Please let me know why we are seeing this error and what is the workaround for it.
packetreceivepacket winpcapasked 29 Jul &#39;13, 03:49
Sudhagar
11●1●1●2
accept rate: 0%
 edited 29 Jul &#39;13, 09:39 
cmaynard ♦♦
9.4k●10●38●142
Are you using WinPCap in conjunction with Wireshark, or in your own application?</description>
    </item>
    
    <item>
      <title>Feeding the 802.15.4 Dissector</title>
      <link>/questions/23427/feeding-the-802154-dissector/</link>
      <pubDate>Mon, 29 Jul 2013 07:48:00 +0000</pubDate>
      
      <guid>/questions/23427/feeding-the-802154-dissector/</guid>
      <description>Feeding the 802.15.4 Dissector  0 Hello, I&#39;m using Wireshark to read from a pipe and i&#39;m using the native IEEE 802.15.4 dissector, but I&#39;m having trouble feeding Wireshark the proper bytes. I&#39;ve tried to search but I can&#39;t find the right sequence of bytes the dissector is waiting.
Can anyone help me? Thanks in advance.
802.15.4 dissectorasked 29 Jul &#39;13, 07:48
funguy
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t Decrypt TLSv1 Traffic</title>
      <link>/questions/23437/cant-decrypt-tlsv1-traffic/</link>
      <pubDate>Mon, 29 Jul 2013 21:08:00 +0000</pubDate>
      
      <guid>/questions/23437/cant-decrypt-tlsv1-traffic/</guid>
      <description>Can&amp;rsquo;t Decrypt TLSv1 Traffic  0 I’m using Wireshark v1.10.1.
I have provided the private key to Wireshark SSL protocol preference. But the TLS traffic isn’t decrypted. Here is my Wireshark SSL debug file.
Wireshark SSL debug log
ssl_association_remove removing TCP 443 - http handle 03B40638 Private key imported: KeyID 9d:d0:e4:66:dd:8e:fb:cf:ea:e4:96:52:cc:92:29:67:... ssl_load_key: swapping p and q parameters and recomputing u ssl_init IPv4 addr &amp;#39;172.16.0.254&amp;#39; (172.16.0.254) port &amp;#39;443&amp;#39; filename &amp;#39;C:\test\cert.pem&amp;#39; password(only for p12 file) &amp;#39;&amp;#39; ssl_init private key file C:\test\cert.</description>
    </item>
    
    <item>
      <title>Need help with Analyzing slow FTP download speed issue</title>
      <link>/questions/23439/need-help-with-analyzing-slow-ftp-download-speed-issue/</link>
      <pubDate>Tue, 30 Jul 2013 00:53:00 +0000</pubDate>
      
      <guid>/questions/23439/need-help-with-analyzing-slow-ftp-download-speed-issue/</guid>
      <description>Need help with Analyzing slow FTP download speed issue  0 We are facing slow FTP download issue , could someone please assist with things we need to look at that may be causing issue, internet utilization is normal , no B.W hogging is there.
ftp slowasked 30 Jul &#39;13, 00:53
m_1607
35●12●13●16
accept rate: 0%
As said before, this is not a place to seek free consultancy on solving your network issues.</description>
    </item>
    
    <item>
      <title>windows losing packets?</title>
      <link>/questions/23444/windows-losing-packets/</link>
      <pubDate>Tue, 30 Jul 2013 06:06:00 +0000</pubDate>
      
      <guid>/questions/23444/windows-losing-packets/</guid>
      <description>windows losing packets?  0 We are experiencing a strange behaviour in some TCP connection. During a tcp connection we are sending data from compiter A to computer B. (wireshark is capturing packet on computer B) wiresharking the connection we can see the data from A to B , the SEQ number are ok and the ACKs are coming from B to A... after a while we can see the the computer B doesn&#39;t acknoledge the data any more, even if the data are captured by wireshark.</description>
    </item>
    
    <item>
      <title>Use CaptureFilters as DisplayFilters</title>
      <link>/questions/23445/use-capturefilters-as-displayfilters/</link>
      <pubDate>Tue, 30 Jul 2013 06:32:00 +0000</pubDate>
      
      <guid>/questions/23445/use-capturefilters-as-displayfilters/</guid>
      <description>Use CaptureFilters as DisplayFilters  0 I&#39;m wondering if there&#39;s a way in Wireshark to use Capture Filters in the Display Filters input box? I need this because I want to check a Capture Filter on a known PCAP before applying it somewhere else.
Is this at all possible (even through a plugin) ?
capture-filterasked 30 Jul &#39;13, 06:32
Astraa
11●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>SNA dissector not called when DSAP 0xc8</title>
      <link>/questions/23446/sna-dissector-not-called-when-dsap-0xc8/</link>
      <pubDate>Tue, 30 Jul 2013 07:18:00 +0000</pubDate>
      
      <guid>/questions/23446/sna-dissector-not-called-when-dsap-0xc8/</guid>
      <description>SNA dissector not called when DSAP 0xc8  0 Hello, wireshark doesn&#39;t interpret the SNA payload contained in udp1200x packets when the LLC DSAP value is not 4 or 8. Some implementations use other values (always multiple of 4). In the testcase appended to http://www.cloudshark.org/captures/c1e5e07508f4 the DSAP value in Logical-Link Control is C8. Is there an easy way to &#39;decode as&#39; SNA ? Thanks
hprip dsap ee llc snaasked 30 Jul &#39;13, 07:18</description>
    </item>
    
    <item>
      <title>Wireshark SSL and TLSv1 protocol</title>
      <link>/questions/23449/wireshark-ssl-and-tlsv1-protocol/</link>
      <pubDate>Tue, 30 Jul 2013 08:51:00 +0000</pubDate>
      
      <guid>/questions/23449/wireshark-ssl-and-tlsv1-protocol/</guid>
      <description>Wireshark SSL and TLSv1 protocol  0 Hello guys,
I&#39;m working on the issue with my Nagios server. Nagios monitoring was working fine, but for few days already I see these errors:
&#34;CHECK_NRPE: Error - Could not complete SSL handshake. &#34; But theses error not consistent. So, first it gives this error, but after 5 minutes check became OK.
So, I check my configuration, but as no changes was made in last time, find no issues as well.</description>
    </item>
    
    <item>
      <title>How can I tell if my connection is encrypted?</title>
      <link>/questions/23451/how-can-i-tell-if-my-connection-is-encrypted/</link>
      <pubDate>Tue, 30 Jul 2013 12:15:00 +0000</pubDate>
      
      <guid>/questions/23451/how-can-i-tell-if-my-connection-is-encrypted/</guid>
      <description>How can I tell if my connection is encrypted?  0 I setup a VPN using SoftEther VPN software, but I don&#39;t know if my web communications are encrypted. In the software, I have L2TP/IPsec and AES-256-SHA checked off/enabled, but I want to be sure that I&#39;m not transmitting data that isn&#39;t unencrypted. Both of the computers are running Windows 7. I downloaded Wireshark, but I don&#39;t know how I can tell if the packets I send out are secure/encrypted.</description>
    </item>
    
    <item>
      <title>How to filter ip address within TZSP</title>
      <link>/questions/23452/how-to-filter-ip-address-within-tzsp/</link>
      <pubDate>Tue, 30 Jul 2013 13:00:00 +0000</pubDate>
      
      <guid>/questions/23452/how-to-filter-ip-address-within-tzsp/</guid>
      <description>How to filter ip address within TZSP  0 Dear all,
how can I filter src/dst ip address encapsulated within TZSP? I tried righ click on the field and then &#34;apply as a filter&#34; but it filter TZSP ip address, not TZSP payload.
Or is it possible to remove TZSP encapsulation?
Best regards, Alberto
tzspThis question is marked &#34;community wiki&#34;.asked 30 Jul &#39;13, 13:00
nabas
11●1●1●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Would you recommend XQuartz over Apple&amp;#x27;s original X11.app for Mac OS X 10.5?</title>
      <link>/questions/23454/would-you-recommend-xquartz-over-apples-original-x11app-for-mac-os-x-105/</link>
      <pubDate>Tue, 30 Jul 2013 15:00:00 +0000</pubDate>
      
      <guid>/questions/23454/would-you-recommend-xquartz-over-apples-original-x11app-for-mac-os-x-105/</guid>
      <description>Would you recommend XQuartz over Apple&amp;rsquo;s original X11.app for Mac OS X 10.5?  0 I&#39;m running Mac OS X 10.5, and while Wireshark is getting along reasonably well with X11 (version 2.1.6 of X11.app if I recall), XQuartz ( http://xquartz.macosforge.org/landing/ ) offers a newer version (2.6.3) which was originally developed with Apple&#39;s help and from which some enhancements were merged back into the Apple build, but which has since superseded Apple&#39;s build (with the important caveat that you can only have one or the other installed, not both, and they &#39;clobber&#39; each other, in the words of the developers).</description>
    </item>
    
    <item>
      <title>Wireshark and WinPcap</title>
      <link>/questions/23455/wireshark-and-winpcap/</link>
      <pubDate>Tue, 30 Jul 2013 15:13:00 +0000</pubDate>
      
      <guid>/questions/23455/wireshark-and-winpcap/</guid>
      <description>Wireshark and WinPcap  0 Starting with Wireshark 1.10.0 When I try to update it tells me that there is a previous version of WinPcap - there isn&#39;t (I have searched my computer high and low) and the installation aborts. Any ideas?
winpcap abort installationasked 30 Jul &#39;13, 15:13
UriB
11●1●1●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Capturing the packets of two (not all) interfaces // tshark</title>
      <link>/questions/23456/capturing-the-packets-of-two-not-all-interfaces-tshark/</link>
      <pubDate>Tue, 30 Jul 2013 21:31:00 +0000</pubDate>
      
      <guid>/questions/23456/capturing-the-packets-of-two-not-all-interfaces-tshark/</guid>
      <description>Capturing the packets of two (not all) interfaces // tshark  0 Hello!
tshark -D 1. eth0 2. eth2 3. eth3 4. any (Pseudo-device that captures on all interfaces) 5. loCapturing the packets of eth2 and eth3 only is needed with the aid tshark. How I can make it?
two_interfaces tshark capturingasked 30 Jul &#39;13, 21:31
factorial
26●4●4●8
accept rate: 0%
 edited 31 Jul &#39;13, 01:20 
grahamb ♦</description>
    </item>
    
    <item>
      <title>Wireshark plugin / library for pSoS OS.</title>
      <link>/questions/23459/wireshark-plugin-library-for-psos-os/</link>
      <pubDate>Wed, 31 Jul 2013 00:12:00 +0000</pubDate>
      
      <guid>/questions/23459/wireshark-plugin-library-for-psos-os/</guid>
      <description>Wireshark plugin / library for pSoS OS.  0 Like Wireshark has plugins developed for Windows / linux etc, do we have Wireshark library support for pSoS OS also ? If so, where can I get the source code to start integration ?
Else can someone suggest any other free tool using which I can have a packet capture on embedded systems running pSoS OS ?
Thanks in advance.
capture wireshark rtos psos pluginThis question is marked &#34;</description>
    </item>
    
    <item>
      <title>Custom dissector - How to format data?</title>
      <link>/questions/23479/custom-dissector-how-to-format-data/</link>
      <pubDate>Wed, 31 Jul 2013 08:21:00 +0000</pubDate>
      
      <guid>/questions/23479/custom-dissector-how-to-format-data/</guid>
      <description>Custom dissector - How to format data?  1 I followed the online example here: http://www.wireshark.org/docs/wsdg_html_chunked/ChDissectAdd.html and managed to get my custom dissector working correctly. My results look like this in wireshark:
Status Protocol
Serial Number: 0x0000001a57004eaf
Reserved: 0
Product ID: Radio Module (3)
Capabilities: Unknown (52)
Is there a way I can format 0x0000001a57004eaf to look like 00:00:00:1a:57:00:4e:af ?
If I can turn the 8 bytes in a string and format it that might work.</description>
    </item>
    
    <item>
      <title>Use TShark to write Protocol like the column in Wireshark</title>
      <link>/questions/23482/use-tshark-to-write-protocol-like-the-column-in-wireshark/</link>
      <pubDate>Wed, 31 Jul 2013 09:51:00 +0000</pubDate>
      
      <guid>/questions/23482/use-tshark-to-write-protocol-like-the-column-in-wireshark/</guid>
      <description>Use TShark to write Protocol like the column in Wireshark  1 1Hi.
I need to process pcap files and extract data into csv files, including the protocol name. If I do this via Wireshark, the Protocol column is exactly what I need. However, it&#39;s very inconvenient to manually open files and export them. I&#39;ve tried using TShark and it&#39;s great, but the closest thing I&#39;ve found to the Protoocl is frame.</description>
    </item>
    
    <item>
      <title>Wireshark doesn&amp;#x27;t capture 802.11 data packets</title>
      <link>/questions/23489/wireshark-doesnt-capture-80211-data-packets/</link>
      <pubDate>Wed, 31 Jul 2013 12:15:00 +0000</pubDate>
      
      <guid>/questions/23489/wireshark-doesnt-capture-80211-data-packets/</guid>
      <description>Wireshark doesn&amp;rsquo;t capture 802.11 data packets  0 Lately I have been trying to analyze wifi traffic over my own test router. I looked on the wireshark website on how to do this and setup my own testing network.
my network:
-dd-wrt router with WPA2 personal mixed security using tkip+aes.
-kali linux capture machine with wireshark 1.8.5
-android phone for producing traffic
I then put the wireless interface of my kali laptop into monitor mode user airmon-ng</description>
    </item>
    
    <item>
      <title>Dissecting bits instead of bytes</title>
      <link>/questions/23490/dissecting-bits-instead-of-bytes/</link>
      <pubDate>Wed, 31 Jul 2013 12:42:00 +0000</pubDate>
      
      <guid>/questions/23490/dissecting-bits-instead-of-bytes/</guid>
      <description>Dissecting bits instead of bytes  0 I&#39;m trying to get the first 4 bits and the last 4 bits of a byte.
proto_tree_add_bits_item(tree, hf_capability, tvb, bit_offset, 4, ENC_BIG_ENDIAN); proto_tree_add_bits_item(tree, hf_capability, tvb, bit_offset+4, 4, ENC_BIG_ENDIAN); { &amp;amp;amp;hf_capability, { &amp;amp;quot;Capabilities&amp;amp;quot;, &amp;amp;quot;status.capability&amp;amp;quot;, FT_UINT8, BASE_DEC, VALS(capabilitynames), 0x0, NULL, HFILL } },&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;p&amp;gt;When I use this in wireshark, its clearly not happy.&amp;lt;/p&amp;gt;&amp;lt;pre&amp;gt;&amp;lt;code&amp;gt;(lt-wireshark:18421): Pango-WARNING **: Invalid UTF-8 string passed to pango_layout_set_text()&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;p&amp;gt;I think it&#39;s because its not a full 8 bits.</description>
    </item>
    
    <item>
      <title>Can tshark calculate the ethernet Frame Check Sequence?</title>
      <link>/questions/23491/can-tshark-calculate-the-ethernet-frame-check-sequence/</link>
      <pubDate>Wed, 31 Jul 2013 15:38:00 +0000</pubDate>
      
      <guid>/questions/23491/can-tshark-calculate-the-ethernet-frame-check-sequence/</guid>
      <description>Can tshark calculate the ethernet Frame Check Sequence?  0 I&#39;m writing a script where I need tshark to calculate the frame check sequence. I know I can output the existing FCS that is stored in the packet with:
$ tshark -T fields -e eth.fcs -r input.capBut if this FCS is wrong, can tshark calculate the correct one? In wireshark if I open a file where the FCS is wrong, wireshark tells me it&#39;s wrong and outputs the value that it should be.</description>
    </item>
    
    <item>
      <title>Need dissector for G.781 SDH option II</title>
      <link>/questions/23492/need-dissector-for-g781-sdh-option-ii/</link>
      <pubDate>Wed, 31 Jul 2013 16:41:00 +0000</pubDate>
      
      <guid>/questions/23492/need-dissector-for-g781-sdh-option-ii/</guid>
      <description>Need dissector for G.781 SDH option II  0 When capturing Synchronous Ethernet packets the ESMC quality level always says &#34;QL-INV1&#34; - invalid.
After verifying that my signal is valid at QL PRS, I did some searching and found that the dissector is set to use option 1:
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3551 &#34;Added: ESMC support as per G.8264 (Slow Protocol Subtype 0x0a). * QL codes are dissected according to G.781 5.5.1.1 &#34;Option I SDH&#34;</description>
    </item>
    
    <item>
      <title>How do I design a filter based on packet number</title>
      <link>/questions/23493/how-do-i-design-a-filter-based-on-packet-number/</link>
      <pubDate>Wed, 31 Jul 2013 22:51:00 +0000</pubDate>
      
      <guid>/questions/23493/how-do-i-design-a-filter-based-on-packet-number/</guid>
      <description>How do I design a filter based on packet number  0 I discovered that some TCP sessions do not stop after [FIN ACK]. To calculate the real throughput, I have to exclude the packets being sent after [FIN ACK]. I am trying to design a filter to filter out packets after a certain time (or packet number) and before a certain time (or packet number).
What should be the syntax of the filter?</description>
    </item>
    
    <item>
      <title>Editing a .cap-file</title>
      <link>/questions/23494/editing-a-cap-file/</link>
      <pubDate>Thu, 01 Aug 2013 02:08:00 +0000</pubDate>
      
      <guid>/questions/23494/editing-a-cap-file/</guid>
      <description>Editing a .cap-file  0 Hello! I have captured the PPPoE/PPP-Session Packets at my DSL-Router and want to use the .cap file for Trainings. Naturally I want to remove my PAP-ID and Password for Security reasons. How can I edit a .cap-File? I tried the Windows Editor, but it alters something in the file so that Wireshark refuses to open it.
Any suggestions?
.cap editing fileasked 01 Aug &#39;13, 02:08</description>
    </item>
    
    <item>
      <title>Dissector to add column in existing pcap</title>
      <link>/questions/23495/dissector-to-add-column-in-existing-pcap/</link>
      <pubDate>Thu, 01 Aug 2013 04:02:00 +0000</pubDate>
      
      <guid>/questions/23495/dissector-to-add-column-in-existing-pcap/</guid>
      <description>Dissector to add column in existing pcap  1 how to insert extra column in existing pcap to show some information into that
dissectorasked 01 Aug &#39;13, 04:02
gst
26●4●4●7
accept rate: 0%
  
One Answer:
  
2Dissectors can&#39;t add columns. They are (are supposed to be) (mostly) UI-agnostic.
But users can. And users can add a &#34;custom column&#34; which contains any field that a dissector has created (that is, anything that was added with an hf_ variable).</description>
    </item>
    
    <item>
      <title>Plugin compatible with 1.10 and 1.8</title>
      <link>/questions/23498/plugin-compatible-with-110-and-18/</link>
      <pubDate>Thu, 01 Aug 2013 06:40:00 +0000</pubDate>
      
      <guid>/questions/23498/plugin-compatible-with-110-and-18/</guid>
      <description>Plugin compatible with 1.10 and 1.8  1 I currently have two windows plugins compiled separately for the same dissector, one for version 1.8.x and the other for 1.10.x.
If I try using any of these across versions, it throws an error -&amp;gt; &#34;STATUS_ACCESS_VIOLATION: dissector accessed and invalid memory address&#34;.
My question is, how do I compile a plugin so that it would be compatible with both 1.8 and 1.10? Or is it not possible?</description>
    </item>
    
    <item>
      <title>What is the tshark equivalent of the wireshark -P command line option ?</title>
      <link>/questions/23500/what-is-the-tshark-equivalent-of-the-wireshark-p-command-line-option/</link>
      <pubDate>Thu, 01 Aug 2013 07:00:00 +0000</pubDate>
      
      <guid>/questions/23500/what-is-the-tshark-equivalent-of-the-wireshark-p-command-line-option/</guid>
      <description>What is the tshark equivalent of the wireshark -P command line option ?  0 How can I set the path setting for the preferences file on tshark as can be done with the -P wireshark flag ? I want to be able to specify on a tshark command line which preferences file to use.
preferencesasked 01 Aug &#39;13, 07:00
DarrylHymel
11●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Statistics summary is just payload or raw data ?</title>
      <link>/questions/23505/statistics-summary-is-just-payload-or-raw-data/</link>
      <pubDate>Thu, 01 Aug 2013 08:16:00 +0000</pubDate>
      
      <guid>/questions/23505/statistics-summary-is-just-payload-or-raw-data/</guid>
      <description>Statistics summary is just payload or raw data ?  0 Hello,
I&#39;m trying to find payload average for UDP. Can any one explain me whether &#34;Average data rate speed&#34; in Statistics-&amp;gt;Summary-&amp;gt;Traffic is raw data average or just payload average ?
Thanks,
Mahii
payload summaryasked 01 Aug &#39;13, 08:16
mahii
11●1●1●2
accept rate: 0%
 edited 02 Aug &#39;13, 01:24 
  
One Answer:
  
0If you do a simple export of just one or two UDP frames and then look at Statistics-&amp;gt;Summary you will see the &#34;</description>
    </item>
    
    <item>
      <title>Wireshark version &amp;gt; 1.6 for RHEL 5.8</title>
      <link>/questions/23507/wireshark-version-16-for-rhel-58/</link>
      <pubDate>Thu, 01 Aug 2013 10:21:00 +0000</pubDate>
      
      <guid>/questions/23507/wireshark-version-16-for-rhel-58/</guid>
      <description>Wireshark version &amp;gt; 1.6 for RHEL 5.8  0 I need to install wireshark version &amp;gt; 1.6 on RHEL 5.8, but I am not able to find any RPM on net we well as yum is providing very old versions 1.0.15.
I tried compiling source code as well but there are lot of dependencies.
Can anyone please refer a path where I can find the required RPM or an easy way to compile and resolve all dependencies</description>
    </item>
    
    <item>
      <title>How does HTTP caching works in a proxy server?</title>
      <link>/questions/23517/how-does-http-caching-works-in-a-proxy-server/</link>
      <pubDate>Fri, 02 Aug 2013 06:44:00 +0000</pubDate>
      
      <guid>/questions/23517/how-does-http-caching-works-in-a-proxy-server/</guid>
      <description>How does HTTP caching works in a proxy server?  0 It&#39;s my understanding that caching is one of the main utilities of a proxy server. I&#39;m currently trying to develop a simple one and I would like to know exactly how caching works.
Intuitively I think that it&#39;s basically an association between a request and a response. For example: for the following request: &#34;GET google.com&#34; you have the following response: &#34;</description>
    </item>
    
    <item>
      <title>mDNS Protocol filtering</title>
      <link>/questions/23518/mdns-protocol-filtering/</link>
      <pubDate>Fri, 02 Aug 2013 07:22:00 +0000</pubDate>
      
      <guid>/questions/23518/mdns-protocol-filtering/</guid>
      <description>mDNS Protocol filtering  0 I know that for some protocols, such as http, you can just type &#34;http&#34; in the filter box and wireshark will filter it. However, this doesn&#39;t seem to work for many protocols, including MDNS, which is what I&#39;m trying to filter on right now.
Is there a way to filter on what is ACTUALLY displayed in the PROTOCOL column of the list?
filter mdns filtering protocolasked 02 Aug &#39;13, 07:22</description>
    </item>
    
    <item>
      <title>IPv6 Dissecting throws Lua FT not yet supported error! Why?</title>
      <link>/questions/23519/ipv6-dissecting-throws-lua-ft-not-yet-supported-error-why/</link>
      <pubDate>Fri, 02 Aug 2013 09:19:00 +0000</pubDate>
      
      <guid>/questions/23519/ipv6-dissecting-throws-lua-ft-not-yet-supported-error-why/</guid>
      <description>IPv6 Dissecting throws Lua FT not yet supported error! Why?  0 I am using field.IPV6 = ProtoField.ipv6 (&#34;IPv6&#34;, &#34;IPv6 Address&#34;)
subtree:add(IPv6, buffer(offset, 16)
it throws LUA: FT not supported yet error. why do they then have in in the API reference? what&#39;s going on?
lua dissector error ipv6asked 02 Aug &#39;13, 09:19
adityashankar
1●1●1●1
accept rate: 0%
  
3 Answers:
  
1From wslua_tree.c
static int TreeItem_add_item_any(lua_State *L, gboolean little_endian) { .</description>
    </item>
    
    <item>
      <title>2000 Packets on NIC but only 20 or so on capture.</title>
      <link>/questions/23521/2000-packets-on-nic-but-only-20-or-so-on-capture/</link>
      <pubDate>Fri, 02 Aug 2013 22:19:00 +0000</pubDate>
      
      <guid>/questions/23521/2000-packets-on-nic-but-only-20-or-so-on-capture/</guid>
      <description>2000 Packets on NIC but only 20 or so on capture.  -1 Sorry I dont have a screen dump. But there was over 2000 packets on the NIC but wireshark was not detecting it in realtime. I have since upgraded and havent seen this error since.
XP SP3 with updates. Intel desktop board.
I have being trying to track down the cause/source of my ghost radio station stream. When I am transmitting a stream of shoutcast music to the net to a public server I seen to get a loop of my various musics mixing back into my stream, I have only tested on internal LAN for some time now.</description>
    </item>
    
    <item>
      <title>Capture packets from my Broadband Modem</title>
      <link>/questions/23522/capture-packets-from-my-broadband-modem/</link>
      <pubDate>Fri, 02 Aug 2013 23:37:00 +0000</pubDate>
      
      <guid>/questions/23522/capture-packets-from-my-broadband-modem/</guid>
      <description>Capture packets from my Broadband Modem  0 Hi Experts,
I have an UTStarCom ADSL2+ modem in my home for Braodband internet connection.
Is it possbile to capture packets flowing in/out of my modem.
Cheers, Arun
broadband capture broadcast packet inasked 02 Aug &#39;13, 23:37
Arun N
1●1●1●1
accept rate: 0%
  
2 Answers:
  
2Is it possbile to capture packets flowing in/out of my modem.</description>
    </item>
    
    <item>
      <title>how to stop tshark from writing to a temp file?</title>
      <link>/questions/23523/how-to-stop-tshark-from-writing-to-a-temp-file/</link>
      <pubDate>Sat, 03 Aug 2013 04:21:00 +0000</pubDate>
      
      <guid>/questions/23523/how-to-stop-tshark-from-writing-to-a-temp-file/</guid>
      <description>how to stop tshark from writing to a temp file?  0 Hello
I have looked in the forum but i wasn&#39;t able to find the right question here nor answer i&#39;m looking for. I&#39;m using windows 2008 server and using tshark to capture directy from the NIC card and output a CSV text of atributes to the screen. (stdout)
But I got a number of times when tshark stopped working.</description>
    </item>
    
    <item>
      <title>GTPv2 support in wireshark 1.0.15 for RHEL 5</title>
      <link>/questions/23526/gtpv2-support-in-wireshark-1015-for-rhel-5/</link>
      <pubDate>Sat, 03 Aug 2013 11:12:00 +0000</pubDate>
      
      <guid>/questions/23526/gtpv2-support-in-wireshark-1015-for-rhel-5/</guid>
      <description>GTPv2 support in wireshark 1.0.15 for RHEL 5  0 I have a RHEL 5.8 system installed with wireshark 1.0.15, but it does not supports GTPv2 by default.
I cannot upgrade wireshark with higher version as it has lot of dependencies like glib2, gtk+2.12 etc, and those cannot be installed as they interfere with other application on the system.
So, is there any way by which I can just install gtpv2 dissectors on wireshark 1.</description>
    </item>
    
    <item>
      <title>Abis over IUA decoding</title>
      <link>/questions/23531/abis-over-iua-decoding/</link>
      <pubDate>Sat, 03 Aug 2013 19:04:00 +0000</pubDate>
      
      <guid>/questions/23531/abis-over-iua-decoding/</guid>
      <description>Abis over IUA decoding  0 Hi! I have capture file with Abis packets over IUA/SCTP. But the Abis packets are decoded incorrectly because Q.921 SAPI values are used by default in DLCI Parameter of IUA packets. I can&#39;t find how to use the GSM SAPI values in DLCI Parameter of IUA packet.
How the Abis messages that contained in IUA packets can be correctly decoded?
Thank You!
abis gsmasked 03 Aug &#39;13, 19:04</description>
    </item>
    
    <item>
      <title>GSM SMS [Malformed Packet]</title>
      <link>/questions/23532/gsm-sms-malformed-packet/</link>
      <pubDate>Sat, 03 Aug 2013 22:20:00 +0000</pubDate>
      
      <guid>/questions/23532/gsm-sms-malformed-packet/</guid>
      <description>GSM SMS [Malformed Packet]  0 Using Wireshark 1.10.1, the GSM SMS dissector is reporting malformed packet at [GSM Mobile Application] level. A few versions earlier, does not exhibit this issue. Any idea how to resolve it ?
Thanks.
smsasked 03 Aug &#39;13, 22:20
Knight
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Hi,
Please fill a bug on http://bugs.wireshark.org with the pcap file attached so that we can have a look at the GSM MAP packet and check what&#39;s wrong.</description>
    </item>
    
    <item>
      <title>(non-DH cipher) SSL won&amp;#x27;t decrypt even though master secret found</title>
      <link>/questions/23540/non-dh-cipher-ssl-wont-decrypt-even-though-master-secret-found/</link>
      <pubDate>Sun, 04 Aug 2013 14:46:00 +0000</pubDate>
      
      <guid>/questions/23540/non-dh-cipher-ssl-wont-decrypt-even-though-master-secret-found/</guid>
      <description>(non-DH cipher) SSL won&amp;rsquo;t decrypt even though master secret found  0 On Ubuntu Linux, wireshark fails to decrypt an SSL session which does NOT use a DH cipher.
I&#39;m using Firefox with sslkeylogfile.
Looking at the debug file, it appears that wireshark CAN find master secret, yet fails to decrypt.
Here&#39;s the relevant snippet from the debug file:
... checking keylog line: CLIENT_RANDOM 51fec5231f20bd12d79c7de8ea8d55433b99c06c47bf5a087aa1e1fd209bde01 2df2f3ad233352799947aecf5b831e971170f089cf17ec98d82e5e312a8005663920d14f66e21eecdfb2f06efda72f72 found master secret in key log ssl_generate_keyring_material not enough data to generate key (0x31 required 0x37 or 0x57) dissect_ssl3_handshake can&amp;#39;t generate keyring material record: offset = 267, reported_length_remaining = 47 .</description>
    </item>
    
    <item>
      <title>Application going slow same time at night</title>
      <link>/questions/23547/application-going-slow-same-time-at-night/</link>
      <pubDate>Mon, 05 Aug 2013 01:46:00 +0000</pubDate>
      
      <guid>/questions/23547/application-going-slow-same-time-at-night/</guid>
      <description>Application going slow same time at night  0 Working ona project where application users complains about the issue every night almost same time everyday. The issue reported only at night. To my wonder same application works fine and no complaint during night. We disablled all nightly batch to drill down if this might be causing due to nightly batch. However, this is nt the case.
Colllected some network related elements which I need your help on.</description>
    </item>
    
    <item>
      <title>Can we add extra column in existing pcap with help of C language</title>
      <link>/questions/23551/can-we-add-extra-column-in-existing-pcap-with-help-of-c-language/</link>
      <pubDate>Mon, 05 Aug 2013 04:12:00 +0000</pubDate>
      
      <guid>/questions/23551/can-we-add-extra-column-in-existing-pcap-with-help-of-c-language/</guid>
      <description>Can we add extra column in existing pcap with help of C language  0 I want to add extra columns called Ue_Identity in existing pcap not by following manual procedure of wireshark .but with help of c language.I have to do like this when i will run that script as pcpa in put then it will add extra column into that pcap......
columnsasked 05 Aug &#39;13, 04:12
gst
26●4●4●7</description>
    </item>
    
    <item>
      <title>How do I capture packets on a Windows virtual server?</title>
      <link>/questions/23552/how-do-i-capture-packets-on-a-windows-virtual-server/</link>
      <pubDate>Mon, 05 Aug 2013 04:20:00 +0000</pubDate>
      
      <guid>/questions/23552/how-do-i-capture-packets-on-a-windows-virtual-server/</guid>
      <description>How do I capture packets on a Windows virtual server?  0 Using Wireshark of course.
packets virtual serverasked 05 Aug &#39;13, 04:20
dhop
11●1●1●2
accept rate: 0%
 edited 05 Aug &#39;13, 13:43 
cmaynard ♦♦
9.4k●10●38●142
Are you looking to capture on the VM host or in the VM itself?
(05 Aug &#39;13, 12:18) grahamb ♦Looking at capturing in the VM itself. We have two VM host chassis with several virtual servers that were created in each one.</description>
    </item>
    
    <item>
      <title>Opening Wireshark - sizing</title>
      <link>/questions/23554/opening-wireshark-sizing/</link>
      <pubDate>Mon, 05 Aug 2013 05:59:00 +0000</pubDate>
      
      <guid>/questions/23554/opening-wireshark-sizing/</guid>
      <description>Opening Wireshark - sizing  0 Hi,
When first initializing WS gui, is there a way to modify how large/small the &#34;box&#34; by which Wireshark opens? I&#39;m currently using WS-1.10.1. I&#39;ve checked preferences, but didn&#39;t see a sizing option.
thanks,
J
sizingasked 05 Aug &#39;13, 05:59
JTech_17
41●7●7●12
accept rate: 0%
What platform / window manager do you run?
(05 Aug &#39;13, 06:11) Jaap ♦Is this the info you need?Compiled (64-bit) with GTK+ 2.</description>
    </item>
    
    <item>
      <title>HTTP gzip decompression failed (NOT out-of-order)</title>
      <link>/questions/23563/http-gzip-decompression-failed-not-out-of-order/</link>
      <pubDate>Mon, 05 Aug 2013 09:19:00 +0000</pubDate>
      
      <guid>/questions/23563/http-gzip-decompression-failed-not-out-of-order/</guid>
      <description>HTTP gzip decompression failed (NOT out-of-order)  0 As I was experimenting with wireshark and SSL decryption, I ran into a reproducible error.
The SSL server sends back an HTML page and wireshark fails to decrypt:
I get a frame HTTP/1.1 200 OK, inside of which:
Content-encoded entity body (gzip): 77775 bytes [Error: Decompression failed]I had a similar &#34;Decompression failed&#34; problem before with another server having to do with out-of-order frames, but in this capture everything is in-order.</description>
    </item>
    
    <item>
      <title>Find search request</title>
      <link>/questions/23567/find-search-request/</link>
      <pubDate>Mon, 05 Aug 2013 18:24:00 +0000</pubDate>
      
      <guid>/questions/23567/find-search-request/</guid>
      <description>Find search request  0 I would like to find the request that gets the results of a search in the website http://www.paginasamarillas.es, how is this possible with wireshark?
filter capture request results wiresharkasked 05 Aug &#39;13, 18:24
cricobs
1●1●1●3
accept rate: 0%
 edited 05 Aug &#39;13, 18:29 
  
One Answer:
  
1I would start with a
frame matches paginasamarillas.esThis gives you all packets that contain this string, also DNS queries and responses.</description>
    </item>
    
    <item>
      <title>Can we add a column in output of wireshark with the help of C language</title>
      <link>/questions/23568/can-we-add-a-column-in-output-of-wireshark-with-the-help-of-c-language/</link>
      <pubDate>Mon, 05 Aug 2013 22:22:00 +0000</pubDate>
      
      <guid>/questions/23568/can-we-add-a-column-in-output-of-wireshark-with-the-help-of-c-language/</guid>
      <description>Can we add a column in output of wireshark with the help of C language  0 Basically I m sending the data from lua to C in C language I just have to edit the output of wiershark, normally it display the columns No. Time Source Destination Protocol Length Info So after running th program pcap file as input ti should the output as follows in wireshark in same pcap file No.</description>
    </item>
    
    <item>
      <title>Can we change the colour of packets with help of C language.</title>
      <link>/questions/23571/can-we-change-the-colour-of-packets-with-help-of-c-language/</link>
      <pubDate>Mon, 05 Aug 2013 22:57:00 +0000</pubDate>
      
      <guid>/questions/23571/can-we-change-the-colour-of-packets-with-help-of-c-language/</guid>
      <description>Can we change the colour of packets with help of C language.  0 I just want to change the colour of packet by scripting/C language not by following the manual procedure of wireshark....How to do this...
colourasked 05 Aug &#39;13, 22:57
gst
26●4●4●7
accept rate: 0%
 edited 05 Aug &#39;13, 23:22 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
1I just want to change the colour of packet by scripting/C language not by following the manual procedure of wireshark.</description>
    </item>
    
    <item>
      <title>Preferences TCP - providing WindowScale factor</title>
      <link>/questions/23573/preferences-tcp-providing-windowscale-factor/</link>
      <pubDate>Mon, 05 Aug 2013 23:10:00 +0000</pubDate>
      
      <guid>/questions/23573/preferences-tcp-providing-windowscale-factor/</guid>
      <description>Preferences TCP - providing WindowScale factor  0 Just came across the new fantastic feature of telling wireshark what the windowscale factor was when the 3-way handshake is not captured. Edit - Preferences -&amp;gt; Protocols -&amp;gt; TCP What can I do when the window scaling factor is not the same at both ends? Looks like I can only specify one.
windowscale preferences tcpasked 05 Aug &#39;13, 23:10
mrEEde
3.9k●15●22●70
accept rate: 20%</description>
    </item>
    
    <item>
      <title>how to parse the Etag packet (802.1br) using wireshark?</title>
      <link>/questions/23576/how-to-parse-the-etag-packet-8021br-using-wireshark/</link>
      <pubDate>Tue, 06 Aug 2013 01:39:00 +0000</pubDate>
      
      <guid>/questions/23576/how-to-parse-the-etag-packet-8021br-using-wireshark/</guid>
      <description>how to parse the Etag packet (802.1br) using wireshark?  0 hi all,
I want to use the wireshark to parse/identify the Etag packets, but the wireshark cannot do it, i want to know if the tool can support etag/802.1br packets? if support, how should i do ? thanks a lot
parse etag 802.1brasked 06 Aug &#39;13, 01:39
python1983
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Tx and Rx data in capture files</title>
      <link>/questions/23577/tx-and-rx-data-in-capture-files/</link>
      <pubDate>Tue, 06 Aug 2013 03:18:00 +0000</pubDate>
      
      <guid>/questions/23577/tx-and-rx-data-in-capture-files/</guid>
      <description>Tx and Rx data in capture files  0 Simple capture files in tutes etc contain frames both to and from multiple systems. How is that possible, given that a network card being used by Wireshark can only capture from the Rx pair of a cable?
captureasked 06 Aug &#39;13, 03:18
RLH
8●2●2●4
accept rate: 0%
  
2 Answers:
  
2Receiving data doesn&#39;t mean that it is only unidirectional when it comes to the layers above the physical medium.</description>
    </item>
    
    <item>
      <title>Amount Flow</title>
      <link>/questions/23585/amount-flow/</link>
      <pubDate>Tue, 06 Aug 2013 04:59:00 +0000</pubDate>
      
      <guid>/questions/23585/amount-flow/</guid>
      <description>Amount Flow  -1 Hello,
I need to do a flow amount of collect. any way to accomplish this? I have a collection and need to reassemble flows.
flowasked 06 Aug &#39;13, 04:59
Gustavo
0●1●1●1
accept rate: 0%
I think we need more information.
I need to do a flow amount of collect.
What does that mean?
I have a collection and need to reassemble flows.
A collection of what? And what exactly is a flow for you?</description>
    </item>
    
    <item>
      <title>How to colorize VoIP Calls graph selections?</title>
      <link>/questions/23589/how-to-colorize-voip-calls-graph-selections/</link>
      <pubDate>Tue, 06 Aug 2013 06:07:00 +0000</pubDate>
      
      <guid>/questions/23589/how-to-colorize-voip-calls-graph-selections/</guid>
      <description>How to colorize VoIP Calls graph selections?  0 I use Wireshark on various Windows OS&#39;s. I primarily use Wireshark to debug VoIP calls, mainly SIP. When I use the &#34;Telephony-&amp;gt;Voip Calls&#34; to parse out the VoIP calls, then select &#34;Flow&#34; to obtain a graph of a call, when I click on one of the packets it whitens out so I can&#39;t make it out. How can I change the color scheme inside a VoIP call graph so that when I click on a packet, I can still see it through the color scheme instead of it being obliterated?</description>
    </item>
    
    <item>
      <title>Change Cipher Spec is retransmitted. SSL Decryption fails.</title>
      <link>/questions/23590/change-cipher-spec-is-retransmitted-ssl-decryption-fails/</link>
      <pubDate>Tue, 06 Aug 2013 06:24:00 +0000</pubDate>
      
      <guid>/questions/23590/change-cipher-spec-is-retransmitted-ssl-decryption-fails/</guid>
      <description>Change Cipher Spec is retransmitted. SSL Decryption fails.  1 Hello, I have the following case: I am trying to decrypt the communication between a client and a web server. I have the private key and I have setup wireshark correctly since I an able to decrypt most of the traffic. However for I face the following issue: Messages from client to server are not decrypted while messages from server to clients are decrypted correctly.</description>
    </item>
    
    <item>
      <title>Potential Packet Loss</title>
      <link>/questions/23591/potential-packet-loss/</link>
      <pubDate>Tue, 06 Aug 2013 09:35:00 +0000</pubDate>
      
      <guid>/questions/23591/potential-packet-loss/</guid>
      <description>Potential Packet Loss  0 2 sites connected by VPN over WAN link. We are replicating our VMware VMs over link from our head office (Site A) to a hosted service provider (Site B). 10MB fibre at our end and 100MB at their end.
VPN coming from our MS TMG 2010 box (edge firewall mode) to the Hosted Providers Cisco ASA. Have followed recommendation for TMG-Cisco ASA VPN settings (encryption, integrity, DH group etc).</description>
    </item>
    
    <item>
      <title>client latency</title>
      <link>/questions/23592/client-latency/</link>
      <pubDate>Tue, 06 Aug 2013 16:12:00 +0000</pubDate>
      
      <guid>/questions/23592/client-latency/</guid>
      <description>client latency  0 Hi, I came across a trace where my monitoring point is close to the client. I am looking at the response time of the basic TCP handshake SYN- SYN/ACK ACK
My SYN/ACK from the server takes reasonable time but my ACK from the client is sporadic and taking longer time.
what could be the potential reason the client is taking longer time to ACK.
client response timeThis question is marked &#34;</description>
    </item>
    
    <item>
      <title>SIP-I INVITE message is not captured in Wireshark</title>
      <link>/questions/23600/sip-i-invite-message-is-not-captured-in-wireshark/</link>
      <pubDate>Tue, 06 Aug 2013 23:32:00 +0000</pubDate>
      
      <guid>/questions/23600/sip-i-invite-message-is-not-captured-in-wireshark/</guid>
      <description>SIP-I INVITE message is not captured in Wireshark  0 I&#39;m trying to capture a SIP-I call using wireshark, i get all the messages except INVITE. Do you know why the INVITE is not captured? Is is due to MTU issue or something. We can see INVITE properly when we use pure SIP, issue happens to SIP-I INVITE only. Any help to sort this issue is highly appreciated.
sipThis question is marked &#34;</description>
    </item>
    
    <item>
      <title>how to extract server secret key from wireshark capture from server to client</title>
      <link>/questions/23602/how-to-extract-server-secret-key-from-wireshark-capture-from-server-to-client/</link>
      <pubDate>Wed, 07 Aug 2013 00:24:00 +0000</pubDate>
      
      <guid>/questions/23602/how-to-extract-server-secret-key-from-wireshark-capture-from-server-to-client/</guid>
      <description>how to extract server secret key from wireshark capture from server to client  0 how to identify and extract server secret key from wireshark capture
serversecretkeyasked 07 Aug &#39;13, 00:24
Sara
1●1●1●1
accept rate: 0%
  
One Answer:
  
2You are talking about SSL/TLS handshake? If this is the case, the answer is : You can&#39;t because it doesn&#39;t flow. Otherwise you would be able to decrypt the data and to avoid this is one of the major reasons why to use SSL/TLS.</description>
    </item>
    
    <item>
      <title>dissection of a protocol</title>
      <link>/questions/23605/dissection-of-a-protocol/</link>
      <pubDate>Wed, 07 Aug 2013 02:16:00 +0000</pubDate>
      
      <guid>/questions/23605/dissection-of-a-protocol/</guid>
      <description>dissection of a protocol  0 Good morning everyone,
i want to dissect a protocol encapsulated in UDP.
so i don&#39;t know if i should create a plugin or add a new dissector in wireshark.
because i have already create a plugin for this protcole , but when this one is not encapsulated under UDP.
can anyone tell me if i should create a new plugin or a new dissctor , or just modify my plugin</description>
    </item>
    
    <item>
      <title>Decrypting browser HTTPS wrapped into stunnel SSL</title>
      <link>/questions/23606/decrypting-browser-https-wrapped-into-stunnel-ssl/</link>
      <pubDate>Wed, 07 Aug 2013 02:37:00 +0000</pubDate>
      
      <guid>/questions/23606/decrypting-browser-https-wrapped-into-stunnel-ssl/</guid>
      <description>Decrypting browser HTTPS wrapped into stunnel SSL  0 I&#39;m trying to decrypt browser&#39;s HTTPS traffic which passes through stunnel. Essentially, I&#39;ve got HTTPS wrapped into stunnel&#39;s SSL. I realized that wireshark is unable to decrypt SSL within SSL.
I provided wireshark with stunnel&#39;s key as well as sslkeylogfile for HTTPS traffic. I can see that wireshark successfully decrypts the outer layer - stunnel&#39;s SSL, but it fails to inspect the inner HTTPS.</description>
    </item>
    
    <item>
      <title>Remote capture via ssh and pipe</title>
      <link>/questions/23609/remote-capture-via-ssh-and-pipe/</link>
      <pubDate>Wed, 07 Aug 2013 06:54:00 +0000</pubDate>
      
      <guid>/questions/23609/remote-capture-via-ssh-and-pipe/</guid>
      <description>Remote capture via ssh and pipe  0 1Hello Everyone,
i have a new configuration where i try to capture my linux machines and display the traffic with wireshark on windows. On windows i&#39;m using cygwin to receive the data from my linux machines via ssh
$ mkfifo /tmp/capture_1 $ ssh [email protected] &amp;quot;tcpdump -s0 -U -n -w - -i eth0 &amp;#39;not port 22&amp;#39;&amp;quot; &amp;gt; /tmp/capture_1So far everything is working quite well.</description>
    </item>
    
    <item>
      <title>save a capture after decryption?</title>
      <link>/questions/23614/save-a-capture-after-decryption/</link>
      <pubDate>Wed, 07 Aug 2013 09:35:00 +0000</pubDate>
      
      <guid>/questions/23614/save-a-capture-after-decryption/</guid>
      <description>save a capture after decryption?  0 I know you&#39;ve been asked this before and said no, but are there plans to implement this feature? I have several clients that use SSL and while decrypting captures are not a problem, the inability to save it as decrypted is a genuine headache.
sslasked 07 Aug &#39;13, 09:35
Ken Cohen
11●1●1●2
accept rate: 0%
Hi guys!
This thread seem to have gone &#34;</description>
    </item>
    
    <item>
      <title>Point of sale/cash register packets</title>
      <link>/questions/23615/point-of-salecash-register-packets/</link>
      <pubDate>Wed, 07 Aug 2013 09:51:00 +0000</pubDate>
      
      <guid>/questions/23615/point-of-salecash-register-packets/</guid>
      <description>Point of sale/cash register packets  0 Buddy of mine owns a small comic book shop, and he text me and said his register has been declining credit cards. He asked me if I can come over to see what I could do, I restarted his router and modem, but cards kept getting declined (tested it with my credit card) and I connected to his router with my laptop, and decided to see if I can use wireshark and see what the packets are doing (I&#39;m no way a expert with wireshark) and to be honest so much stuff showed up (could be because his computer is on the network too, but I am not sure) how would I filter out just for the cash register?</description>
    </item>
    
    <item>
      <title>An error while capturing with gns 3</title>
      <link>/questions/23620/an-error-while-capturing-with-gns-3/</link>
      <pubDate>Wed, 07 Aug 2013 12:18:00 +0000</pubDate>
      
      <guid>/questions/23620/an-error-while-capturing-with-gns-3/</guid>
      <description>An error while capturing with gns 3  0 I was running gns3 in my laptop and was simulating 3 routers with ospf configured. I started to capture using wireshark but it was showing an error (frame 151 too long (-1 bytes)) can some one give me a suitable solution for this?
gns3 ospfasked 07 Aug &#39;13, 12:18
arjun05
11●1●1●2
accept rate: 0%
 edited 07 Aug &#39;13, 12:53</description>
    </item>
    
    <item>
      <title>My Lua dissector isn&amp;#x27;t finding the CRC32 module</title>
      <link>/questions/23622/my-lua-dissector-isnt-finding-the-crc32-module/</link>
      <pubDate>Wed, 07 Aug 2013 14:43:00 +0000</pubDate>
      
      <guid>/questions/23622/my-lua-dissector-isnt-finding-the-crc32-module/</guid>
      <description>My Lua dissector isn&amp;rsquo;t finding the CRC32 module  0 Hi, I have a .lua file. Can I get please instructions how to add it the wireshark and decode my message correctly (I have wireshark with version 1.8.6)?
I added it to my personal plugins folder and this is the message code every time I launch the program.
Lua: Error during loading: [string &amp;quot;C:\Users\morton.sherwood\AppData\Roaming\Wi...&amp;quot;]:7: module &amp;#39;CRC32&amp;#39; not found: no field package.</description>
    </item>
    
    <item>
      <title>Wireshark with customized Radius dissector crashing on RHEL 6.1 64 bit OS</title>
      <link>/questions/23628/wireshark-with-customized-radius-dissector-crashing-on-rhel-61-64-bit-os/</link>
      <pubDate>Thu, 08 Aug 2013 00:39:00 +0000</pubDate>
      
      <guid>/questions/23628/wireshark-with-customized-radius-dissector-crashing-on-rhel-61-64-bit-os/</guid>
      <description>Wireshark with customized Radius dissector crashing on RHEL 6.1 64 bit OS  0 Hi,
We are using Wireshark 1.0.1, customized RADIUS dissector to suit our requirements. We developed this on RHEL4.7, few years back for one of our clients.
Currently we are moving on to RHEL 6.1 64 bit OS with the same source code and when we try to run our wireshark, it opens up good and when we try to load a capture file, it crashes.</description>
    </item>
    
    <item>
      <title>How much data was sent by cloud webservice?</title>
      <link>/questions/23635/how-much-data-was-sent-by-cloud-webservice/</link>
      <pubDate>Thu, 08 Aug 2013 04:24:00 +0000</pubDate>
      
      <guid>/questions/23635/how-much-data-was-sent-by-cloud-webservice/</guid>
      <description>How much data was sent by cloud webservice?  0 Hi,
I am running an HTTP restful data API) using a cloud based solution. I want to verify the data usage i.e. traffic out of the cloud (I am only charged for data sent out from the cloud. No charge you data going into the cloud).
The reason I am doing this is that I do not trust the billing data from the cloud provider.</description>
    </item>
    
    <item>
      <title>Where can I find SCTP Data Chunk in Dissector Table?</title>
      <link>/questions/23643/where-can-i-find-sctp-data-chunk-in-dissector-table/</link>
      <pubDate>Thu, 08 Aug 2013 06:31:00 +0000</pubDate>
      
      <guid>/questions/23643/where-can-i-find-sctp-data-chunk-in-dissector-table/</guid>
      <description>Where can I find SCTP Data Chunk in Dissector Table?  0 Dear all!
I would like to write a chained dissector for SCTP Data Chunk but I don&#39;t know how can I reach it in the Dissector Table. I know I can do this with SCTP like this:
first: ether_table = DissectorTable.get (&#34;ethertype&#34;) original_dissector = ether_table:get_dissector(0x84)
then in the definition my dissector:
original_dissector:call( buffer, pinfo, tree )
finally:
ether_table:add (0x84, mydiss)</description>
    </item>
    
    <item>
      <title>radiotap.mactime field with Atheros chipset</title>
      <link>/questions/23645/radiotapmactime-field-with-atheros-chipset/</link>
      <pubDate>Thu, 08 Aug 2013 06:59:00 +0000</pubDate>
      
      <guid>/questions/23645/radiotapmactime-field-with-atheros-chipset/</guid>
      <description>radiotap.mactime field with Atheros chipset  0 Hi everybody I try to get the radiotap.mactime field from WiFi dongle with Atheros chipset. With any Atheros based device, I get an empty field, while I get the correct value with a Broadcam chipset. I&#39;m on Linux (Ubuntu 12.4) and I tried all what I could to get this data available to tshark (drivers and firmware are up to date)
Any hints from you guys on this ?</description>
    </item>
    
    <item>
      <title>how do you capture all packets on network?</title>
      <link>/questions/23647/how-do-you-capture-all-packets-on-network/</link>
      <pubDate>Thu, 08 Aug 2013 07:05:00 +0000</pubDate>
      
      <guid>/questions/23647/how-do-you-capture-all-packets-on-network/</guid>
      <description>how do you capture all packets on network?  0 We have a network with a Cisco Lan/WLAN router and ethernet unmanaged Netgear 100MB and 1GB switches. Computers are Win XP Pro and Win 7 Pro. Need to capture all packets and discover cause of problem with POP3 emails intermittent send and recieve errors. We have isolated the problem to something on network is interfering with POP3. New to wireshark capturing.</description>
    </item>
    
    <item>
      <title>A way to figure out router admin url with wireshark?</title>
      <link>/questions/23657/a-way-to-figure-out-router-admin-url-with-wireshark/</link>
      <pubDate>Thu, 08 Aug 2013 09:33:00 +0000</pubDate>
      
      <guid>/questions/23657/a-way-to-figure-out-router-admin-url-with-wireshark/</guid>
      <description>A way to figure out router admin url with wireshark?  0 Hi all, I have a DG860 Arris router, but the router admin url isn&#39;t working. I have read the manual, and it says that I have to go to http://192.168.0.1/, but that brings up an unresponsive page.
I&#39;ve tried other urls like 192.168.1.1, 10.0.0.1, 192.168.2.1, but I get the same result. I have tried it on wireless and on wired.</description>
    </item>
    
    <item>
      <title>Displaying all SIP messages in the call flow window</title>
      <link>/questions/23681/displaying-all-sip-messages-in-the-call-flow-window/</link>
      <pubDate>Fri, 09 Aug 2013 08:04:00 +0000</pubDate>
      
      <guid>/questions/23681/displaying-all-sip-messages-in-the-call-flow-window/</guid>
      <description>Displaying all SIP messages in the call flow window  0 Voip call / flow will display only SIP messages for the conversations selected. If some SIP messages are not deemed as part of those calls, they will not show up in the graphic view. Is there a way to force the display of those messages ?
sipasked 09 Aug &#39;13, 08:04
jml674
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>What is dproxy?</title>
      <link>/questions/23682/what-is-dproxy/</link>
      <pubDate>Fri, 09 Aug 2013 10:41:00 +0000</pubDate>
      
      <guid>/questions/23682/what-is-dproxy/</guid>
      <description>What is dproxy?  0 I am doing some network traces and expecting communication directly between 2 servers. Under the Info column I see conversations between the target port 8004 and dproxy. anybody out there know what dproxy is? I have placed the ip address of the target computer in the local host file to bypass dns. I am using the host file to bypass our F5 load balancer. I would appreciate any help here.</description>
    </item>
    
    <item>
      <title>Reverse Engineering RPCAP</title>
      <link>/questions/23684/reverse-engineering-rpcap/</link>
      <pubDate>Fri, 09 Aug 2013 13:46:00 +0000</pubDate>
      
      <guid>/questions/23684/reverse-engineering-rpcap/</guid>
      <description>Reverse Engineering RPCAP  0 Hello,
I&#39;ve got an application that requires me to attach a script to an existing RPCAP daemon. So I&#39;m working on reverse engineering the RPCAP protocol. Wireshark does a fantastic job of decoding the basic authentication, open request, and filter request packets. But I&#39;m having trouble with the actual data packets. I can parse the rpcap_header and rpcap_pkthdr. But I&#39;m confused as to what comes next.</description>
    </item>
    
    <item>
      <title>how to calculate manually in the window summary?</title>
      <link>/questions/23691/how-to-calculate-manually-in-the-window-summary/</link>
      <pubDate>Sat, 10 Aug 2013 09:39:00 +0000</pubDate>
      
      <guid>/questions/23691/how-to-calculate-manually-in-the-window-summary/</guid>
      <description>how to calculate manually in the window summary?  0 Hallo all,
I began to confusion when reading the results capture the data contained in the summary window. The data have been listed on the summary window when it has completed the capture.
Can someone tell me, how the data is obtained?, and how to calculate it manually packet, between lass and first packet, avg. packet / sec, avg. packet size, byte, avg.</description>
    </item>
    
    <item>
      <title>Capturing url from tcp packets</title>
      <link>/questions/23706/capturing-url-from-tcp-packets/</link>
      <pubDate>Mon, 12 Aug 2013 06:09:00 +0000</pubDate>
      
      <guid>/questions/23706/capturing-url-from-tcp-packets/</guid>
      <description>Capturing url from tcp packets  0 Hi All I have gone through the packet-tcp.c but I am not sure which section deals with extracting the url if it exists in the tcp packets. I have my whole payload packet but I need this specific function.
url dissector tcpasked 12 Aug &#39;13, 06:09
newbie14
26●3●3●8
accept rate: 0%
  
3 Answers:
  
1All I have gone through the packet-tcp.</description>
    </item>
    
    <item>
      <title>Why no contextual menus when &amp;quot;right-clicking&amp;quot;?</title>
      <link>/questions/23712/why-no-contextual-menus-when-right-clicking/</link>
      <pubDate>Mon, 12 Aug 2013 08:45:00 +0000</pubDate>
      
      <guid>/questions/23712/why-no-contextual-menus-when-right-clicking/</guid>
      <description>Why no contextual menus when &amp;ldquo;right-clicking&amp;rdquo;?  1 Problem: I do not get any contextual menus when I ctrl-click (the normal equivalent of &#34;right-click&#34;) on a field in the Wireshark GUI. Nothing happens: the behavior is the same whether I am ctrl-clicking in the Packet List pane or the Packet Details pane. Question: Is there a preference that I need to set to get the correct behavior?
Wireshark runs under XQuartz 2.</description>
    </item>
    
    <item>
      <title>Error building Wireshark from source</title>
      <link>/questions/23713/error-building-wireshark-from-source/</link>
      <pubDate>Mon, 12 Aug 2013 09:19:00 +0000</pubDate>
      
      <guid>/questions/23713/error-building-wireshark-from-source/</guid>
      <description>Error building Wireshark from source  1 1I am trying to build Wireshark from source and I followed all the directions in http://www.wireshark.org/docs/wsdg_html_chunked/ChSetupWin32.html. When building, I get the following error:
Microsoft (R) Program Maintenance Utility Version 10.00.40219.01 Copyright (C) Microsoft Corporation. All rights reserved.
 bison -d -p ascend ascend.y -o ascend.c/usr/bin/bison: m4 subprocess failed NMAKE : fatal error U1077: &#39;c:\cygwin64\bin\bison.EXE&#39; : return code &#39;0x1&#39; Stop. NMAKE : fatal error U1077: &#39;&#34;</description>
    </item>
    
    <item>
      <title>How to understand SSH Key exchange process?</title>
      <link>/questions/23722/how-to-understand-ssh-key-exchange-process/</link>
      <pubDate>Mon, 12 Aug 2013 17:28:00 +0000</pubDate>
      
      <guid>/questions/23722/how-to-understand-ssh-key-exchange-process/</guid>
      <description>How to understand SSH Key exchange process?  0 Hi all,
I want to understand basic functional aspects behind SSH key exchange. I tried to understand looking at RFC but felt little complex for me to comprehend from it.
Here are the 7 Packets I got from t-shark using display filter &#34;ssh.message_code&#34;
SSHv2 Client: Key Exchange Init
SSHv2 Server: Key Exchange Init
SSHv2 Client: Diffie-Hellman Key Exchange Init
SSHv2 Server: Diffie-Hellman Key Exchange Reply</description>
    </item>
    
    <item>
      <title>Wireshark process runs but the GUI window never opens.</title>
      <link>/questions/23725/wireshark-process-runs-but-the-gui-window-never-opens/</link>
      <pubDate>Mon, 12 Aug 2013 20:20:00 +0000</pubDate>
      
      <guid>/questions/23725/wireshark-process-runs-but-the-gui-window-never-opens/</guid>
      <description>Wireshark process runs but the GUI window never opens.  0 Hi, I just installed WireShark today and the installer popped an error on uninstalling the older version of WinPCap. The installer continued anyway and said it completed. When I start it now I get a few little popups that show WireShark trying to load but the GUI never comes up. I can see the wireshark process in ProcessExplorer but nothing else happens.</description>
    </item>
    
    <item>
      <title>how to decode traffic from g729 codec</title>
      <link>/questions/23731/how-to-decode-traffic-from-g729-codec/</link>
      <pubDate>Mon, 12 Aug 2013 23:36:00 +0000</pubDate>
      
      <guid>/questions/23731/how-to-decode-traffic-from-g729-codec/</guid>
      <description>how to decode traffic from g729 codec  0 i have capture one wireshark trace, it is using g.729 codec, How to decode it in wireshark?
codecasked 12 Aug &#39;13, 23:36
archu
11●4●4●7
accept rate: 0%
  
One Answer:
  
1As detailed on the cunningly named Wireshark Wiki page: HowToDecodeG729.
answered 13 Aug &#39;13, 00:49
grahamb ♦
19.8k●3●30●206
accept rate: 22%
     </description>
    </item>
    
    <item>
      <title>linking dissector plugin against shared library (OpenSSL)</title>
      <link>/questions/23743/linking-dissector-plugin-against-shared-library-openssl/</link>
      <pubDate>Tue, 13 Aug 2013 04:54:00 +0000</pubDate>
      
      <guid>/questions/23743/linking-dissector-plugin-against-shared-library-openssl/</guid>
      <description>linking dissector plugin against shared library (OpenSSL)  0 Hi all. Due to the numerous tutorials I found in web, I managed to compile a dissector plugin on Linux. The raw implementation of my plugin works fine now. My new goal is to extend the plugin providing an ECDDSA-signature check &#34;on the fly&#34; of the received data packages. Therefore I tried to link my dissector plugin against the crypto library of OpenSSL, but at his point all my efforts unfortunately failed.</description>
    </item>
    
    <item>
      <title>TCP urgent pointer value not displayed</title>
      <link>/questions/23753/tcp-urgent-pointer-value-not-displayed/</link>
      <pubDate>Tue, 13 Aug 2013 14:19:00 +0000</pubDate>
      
      <guid>/questions/23753/tcp-urgent-pointer-value-not-displayed/</guid>
      <description>TCP urgent pointer value not displayed  0 If the URG flag is set to zero, then the urgent pointer field is disabled. In that case, why is the value of the urgent pointer field not displayed in Wireshark?
field packet-display pointer tcp urgentasked 13 Aug &#39;13, 14:19
HiB
16●3●3●7
accept rate: 0%
 edited 13 Aug &#39;13, 14:37 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:</description>
    </item>
    
    <item>
      <title>Initial SYN handshake</title>
      <link>/questions/23756/initial-syn-handshake/</link>
      <pubDate>Tue, 13 Aug 2013 19:45:00 +0000</pubDate>
      
      <guid>/questions/23756/initial-syn-handshake/</guid>
      <description>Initial SYN handshake  0 During the initial SyN handshake we see a &#34;windows size&#34; field in the trace file. Is that field sent by the client (sender) or the destination (server) ?
My understanding is that the initial SYN in the beginning of the three way handshake is always started from the client (sender), is that correct ?
initial synasked 13 Aug &#39;13, 19:45
Robbie S
26●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>A Wirshark capture of an Ethernet frame showed the following fields. Identify the type of the frame.</title>
      <link>/questions/23757/a-wirshark-capture-of-an-ethernet-frame-showed-the-following-fields-identify-the-type-of-the-frame/</link>
      <pubDate>Tue, 13 Aug 2013 20:06:00 +0000</pubDate>
      
      <guid>/questions/23757/a-wirshark-capture-of-an-ethernet-frame-showed-the-following-fields-identify-the-type-of-the-frame/</guid>
      <description>A Wirshark capture of an Ethernet frame showed the following fields. Identify the type of the frame.  0 A Wirshark capture of an Ethernet frame showed the following fields. Identify the type of the frame.
Hardware type: Ethernet (0x0001) Protocol type: IP (0x0800) Hardware size: 6 Protocol size: 4 Opcode: request (0x0001)
Can anyone tell me what type of frame we are looking at ?
Thanks in advance
hardware ethernet protocol network ipasked 13 Aug &#39;13, 20:06</description>
    </item>
    
    <item>
      <title>Microsoft Visual C&#43;&#43; Runtime Library - Runtime Error</title>
      <link>/questions/23758/microsoft-visual-c-runtime-library-runtime-error/</link>
      <pubDate>Tue, 13 Aug 2013 20:21:00 +0000</pubDate>
      
      <guid>/questions/23758/microsoft-visual-c-runtime-library-runtime-error/</guid>
      <description>Microsoft Visual C++ Runtime Library - Runtime Error  0 Team, I am running Wireshark 1.8.9 software on a Windows 2003 server, running Spirent client and monitoring the connectivity from the server to the Spirent Chassis.
I see &#34;Runtime Error! Program This application has requested the Runtime to terminate it in an unusual way.&#34;
Any thoughts, what could have gone wrong ?
Thanks.
runtimeerrorprogramasked 13 Aug &#39;13, 20:21
leonfrs
1●1●1●1</description>
    </item>
    
    <item>
      <title>how to find the mac &amp;amp; ip address for spartan-3e kit???</title>
      <link>/questions/23764/how-to-find-the-mac-ip-address-for-spartan-3e-kit/</link>
      <pubDate>Tue, 13 Aug 2013 22:41:00 +0000</pubDate>
      
      <guid>/questions/23764/how-to-find-the-mac-ip-address-for-spartan-3e-kit/</guid>
      <description>how to find the mac &amp;amp; ip address for spartan-3e kit???  -1 i want to send data to the spartan-3e kit using ethernet for that i have to assign ip address to the kit
vhdl fpgaasked 13 Aug &#39;13, 22:41
hemanth
0●1●1●1
accept rate: 0%
  
One Answer:
  
2The question has absolutely nothing to do with Wireshark. You&#39;ll probably find the answer, unsurprisingly, in the Xilinx documentation for the Spartan-3e starter kit.</description>
    </item>
    
    <item>
      <title>RTCDC filter</title>
      <link>/questions/23766/rtcdc-filter/</link>
      <pubDate>Wed, 14 Aug 2013 00:06:00 +0000</pubDate>
      
      <guid>/questions/23766/rtcdc-filter/</guid>
      <description>RTCDC filter  0 Hello everyone, I&#39;m trying to capture rtcdc traffic using this test page http://webrtc.googlecode.com/svn/trunk/samples/js/demos/html/dc1.html I use rtcdc filter in wireshark without results, instead of that, the traffic from that web is tagged as UDP traffic. How can I see it as rtcdc traffic?
capture udp datachannel webrtc rtcdcasked 14 Aug &#39;13, 00:06
Miguelo
11●1●1●3
accept rate: 0%
1Are you sure it&#39;s UDP traffic? When I do nslookup webrtc.</description>
    </item>
    
    <item>
      <title>Monitor mode problems</title>
      <link>/questions/23769/monitor-mode-problems/</link>
      <pubDate>Wed, 14 Aug 2013 03:15:00 +0000</pubDate>
      
      <guid>/questions/23769/monitor-mode-problems/</guid>
      <description>Monitor mode problems  0 Hello, I have recently been having trouble with monitor mode on wireshark in Kali Linux. Here&#39;s what happens: On Wireshark I select the capture interface eth1, I then double-click it and change the mode to monitor, I click ok and go START CAPTURE. I then get the error message: The capture session could not be initiated (eth1 SIOCGIWPRIV: Argument list too long) Please check that you have sufficient permissions, and that you have a proper interface or pipe selected.</description>
    </item>
    
    <item>
      <title>SIP messages per user</title>
      <link>/questions/23772/sip-messages-per-user/</link>
      <pubDate>Wed, 14 Aug 2013 08:19:00 +0000</pubDate>
      
      <guid>/questions/23772/sip-messages-per-user/</guid>
      <description>SIP messages per user  0 Hi folks,
is there any possibility in Wireshark by using a special filter or a combination of some to show an overview of the number of SIP messages per user or endpoint? Trying to figure it out for SBC settings but with hundreds of thousands of IP endpoints you&#39;re soon bored somehow.
Greetz Marzen
statistics sip endpointsasked 14 Aug &#39;13, 08:19
Marzen
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Runtime error occurring constantly.</title>
      <link>/questions/23777/runtime-error-occurring-constantly/</link>
      <pubDate>Wed, 14 Aug 2013 10:25:00 +0000</pubDate>
      
      <guid>/questions/23777/runtime-error-occurring-constantly/</guid>
      <description>Runtime error occurring constantly.  0 I am running wireshark version 1.10.1; and capturing layer 2 data. I have capture options configured for local interface, single channel with multiple files enabled. The next file is enabled to start after 1Mb. All other options are disabled. The capture duration between failure is 20 files =/- 3 files. The runtime error is - This application has requested the Runtime to terminate it in an unusual way.</description>
    </item>
    
    <item>
      <title>how to capture telnet traffic in &amp;quot;cooked&amp;quot; (per-line) mode?</title>
      <link>/questions/23778/how-to-capture-telnet-traffic-in-cooked-per-line-mode/</link>
      <pubDate>Wed, 14 Aug 2013 10:48:00 +0000</pubDate>
      
      <guid>/questions/23778/how-to-capture-telnet-traffic-in-cooked-per-line-mode/</guid>
      <description>how to capture telnet traffic in &amp;ldquo;cooked&amp;rdquo; (per-line) mode?  0 Hi Experts,
I found these two captures: http://wiki.wireshark.org/SampleCaptures#Telnet
telnet-cooked.pcap (libpcap) A telnet session in &#34;cooked&#34; (per-line) mode. telnet-raw.pcap (libpcap) A telnet session in &#34;raw&#34; (per-character) mode.
How can I capture traffic just in &#34;cooked&#34; mode?
cooked per-line mode telnetasked 14 Aug &#39;13, 10:48
jomajo
1●3●3●5
accept rate: 100%
  
One Answer:
  
1How can I capture traffic just in &#34;</description>
    </item>
    
    <item>
      <title>Can broadcasted data on NS2 ( Simulation ) can be traced using Wireshark?</title>
      <link>/questions/23780/can-broadcasted-data-on-ns2-simulation-can-be-traced-using-wireshark/</link>
      <pubDate>Wed, 14 Aug 2013 12:02:00 +0000</pubDate>
      
      <guid>/questions/23780/can-broadcasted-data-on-ns2-simulation-can-be-traced-using-wireshark/</guid>
      <description>Can broadcasted data on NS2 ( Simulation ) can be traced using Wireshark?  0 I am new to wireshark.
Is it possible to capture the packets broadcast on NS2 (Network Simulator 2). If Yes then how?
Suppose I am broadcasting a message which can be seen on port no 42. Protocol used is DumbAgent.
broadcast ns2 port simulatorasked 14 Aug &#39;13, 12:02
Lalle
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>What is the alternative of match_strval?</title>
      <link>/questions/23791/what-is-the-alternative-of-match_strval/</link>
      <pubDate>Thu, 15 Aug 2013 01:19:00 +0000</pubDate>
      
      <guid>/questions/23791/what-is-the-alternative-of-match_strval/</guid>
      <description>What is the alternative of match_strval?  1 Hi experts, I fail to build my plugin for wireshark 1.10.1. it report match_strval function undefined. Is there any alternative solution for this.
my plugin call this function like: if(!match_strval(tvb_get_bits8(tvb, bit_offset, 8),xxx_type));
Take Care
match_strvalasked 15 Aug &#39;13, 01:19
gaobrian
16●1●1●3
accept rate: 0%
  
One Answer:
  
4I think it&#39;s been renamed to try_val_to_str() see epan/value_string.[ch]
answered 15 Aug &#39;13, 01:47</description>
    </item>
    
    <item>
      <title>NSA sniffing and encryption</title>
      <link>/questions/23800/nsa-sniffing-and-encryption/</link>
      <pubDate>Thu, 15 Aug 2013 08:18:00 +0000</pubDate>
      
      <guid>/questions/23800/nsa-sniffing-and-encryption/</guid>
      <description>NSA sniffing and encryption  1 With all the NSA sniffing going on, encryption should be the default for any communication, although that does not prevent sniffing data in many cases (google, facebook, etc. handing over data &#39;voluntarily&#39;).
On the other side, using encryption per default will create (besides technical and management overhead) massive problems for network troubleshooting and tools like Wireshark.
I wonder what will be the future of network troubleshooting in this context and how network troubleshooting tools (Wireshark and the like) will look like in 5 years, considering</description>
    </item>
    
    <item>
      <title>DPNSS Decode in 4.5.0</title>
      <link>/questions/23802/dpnss-decode-in-450/</link>
      <pubDate>Thu, 15 Aug 2013 10:01:00 +0000</pubDate>
      
      <guid>/questions/23802/dpnss-decode-in-450/</guid>
      <description>DPNSS Decode in 4.5.0  0 I downloaded 4.5.0 today and notice that DPNSS has disappeared as a decode any reason for this? Does anyone one know the latest version supporting it? Thanks
dpnssasked 15 Aug &#39;13, 10:01
P Gooding
1●1●1●1
accept rate: 0%
My Mistake I meant to say 1.10.1 DPNSS has disappeared from the list of supported protocols as far as I can see. DPNSS should run over LAPD from my memory.</description>
    </item>
    
    <item>
      <title>Understanding two pass analysis with tshark</title>
      <link>/questions/23804/understanding-two-pass-analysis-with-tshark/</link>
      <pubDate>Thu, 15 Aug 2013 10:22:00 +0000</pubDate>
      
      <guid>/questions/23804/understanding-two-pass-analysis-with-tshark/</guid>
      <description>Understanding two pass analysis with tshark  1 I am trying to understand 2 pass analysis with tshark using the latest 1.10.2 (TShark 1.10.2 (SVN Rev 51377 from /trunk-1.10))
The first example starts with a single pass. I use the &#34;-c 1&#34; option to only display a single packet. I am also using a display filter to see packets with frame numbers &amp;gt; 1. The result makes sense. I see frame #2.</description>
    </item>
    
    <item>
      <title>Wireshark dissector for a Google Protocol Buffer defined protocol</title>
      <link>/questions/23808/wireshark-dissector-for-a-google-protocol-buffer-defined-protocol/</link>
      <pubDate>Thu, 15 Aug 2013 15:02:00 +0000</pubDate>
      
      <guid>/questions/23808/wireshark-dissector-for-a-google-protocol-buffer-defined-protocol/</guid>
      <description>Wireshark dissector for a Google Protocol Buffer defined protocol  0 Hi,
I would like to know if anyone has an example of a wireshark dissector for a protocol defined in a .proto file of Google Protocol Buffer. It would help me a lot!
Many Thanks!
dissector wiresharkasked 15 Aug &#39;13, 15:02
André de Melo
11●2●2●5
accept rate: 0%
  
One Answer:
  
2Here we go .</description>
    </item>
    
    <item>
      <title>What is the latest Wireshark for 2.6.18-348.12.1.el5 (Red Hat RHEL5)</title>
      <link>/questions/23811/what-is-the-latest-wireshark-for-2618-348121el5-red-hat-rhel5/</link>
      <pubDate>Thu, 15 Aug 2013 16:23:00 +0000</pubDate>
      
      <guid>/questions/23811/what-is-the-latest-wireshark-for-2618-348121el5-red-hat-rhel5/</guid>
      <description>What is the latest Wireshark for 2.6.18-348.12.1.el5 (Red Hat RHEL5)  0 Hi Everyone, What is the latest Wireshark version for 2.6.18-348.12.1.el5
rhel5 redhatasked 15 Aug &#39;13, 16:23
ESSTEAM
11●1●1●2
accept rate: 0%
 edited 15 Aug &#39;13, 17:11 
Kurt Knochner ♦
24.8k●10●39●237
This is my current version. TShark 1.0.15
Compiled with GLib 2.12.3, with libpcap 0.9.4, with libz 1.2.3, without POSIX capabilities, with libpcre 6.6, with SMI 0.4.5, without ADNS, without Lua, with GnuTLS 1.</description>
    </item>
    
    <item>
      <title>resolve name not working</title>
      <link>/questions/23813/resolve-name-not-working/</link>
      <pubDate>Thu, 15 Aug 2013 16:59:00 +0000</pubDate>
      
      <guid>/questions/23813/resolve-name-not-working/</guid>
      <description>resolve name not working  0 When I right-click on a packet or IP address and choose resolve name nothing happens. The only way I can get DNS resolution in my trace is by going to view &amp;gt; name resolution &amp;gt; enable for network layer.
When I do that I get name resolution for the entice trace, not just a selected packet/IP.
I&#39;m running Windows version 1.10.1
name-resolving dnsasked 15 Aug &#39;13, 16:59</description>
    </item>
    
    <item>
      <title>record in wireshark</title>
      <link>/questions/23817/record-in-wireshark/</link>
      <pubDate>Fri, 16 Aug 2013 01:16:00 +0000</pubDate>
      
      <guid>/questions/23817/record-in-wireshark/</guid>
      <description>record in wireshark  0 hello,
I have a problem with a server. I want to see the traffic on the sever in 4:00 a.m. until 5:00 a.m. I use in port mirror in cisco switch becasuse I can&#39;t use in wireshark on the server. When I use wireshark a lot of time the software stop (not respond).
How I can to record the traffic in specific time?
thanks...
recordingasked 16 Aug &#39;13, 01:16</description>
    </item>
    
    <item>
      <title>Manually resolve hostnames not working</title>
      <link>/questions/23823/manually-resolve-hostnames-not-working/</link>
      <pubDate>Fri, 16 Aug 2013 10:03:00 +0000</pubDate>
      
      <guid>/questions/23823/manually-resolve-hostnames-not-working/</guid>
      <description>Manually resolve hostnames not working  0 I&#39;m using 1.8.7 and noticed that manual resolution of hostnames is not working. Meaning, I&#39;d like to supply my own FQDN for an IP address and not attempt to resolve it using &#39;hosts&#39; or recursively looking up the IPs via DNS, etc.
I was able to make it work by putting arbitrary entries as described here, but that seems less than optimal (having to leave the tool to cut/paste/save entries elswhere and still having to resolve).</description>
    </item>
    
    <item>
      <title>How to filter packets while capturing them using tcpdump on linux based on a diameter AVP value</title>
      <link>/questions/23824/how-to-filter-packets-while-capturing-them-using-tcpdump-on-linux-based-on-a-diameter-avp-value/</link>
      <pubDate>Fri, 16 Aug 2013 10:26:00 +0000</pubDate>
      
      <guid>/questions/23824/how-to-filter-packets-while-capturing-them-using-tcpdump-on-linux-based-on-a-diameter-avp-value/</guid>
      <description>How to filter packets while capturing them using tcpdump on linux based on a diameter AVP value  1 Hello, we have a server that is acting as a diameter server. We would like to capture traffic between the diameter client and our daimeter server and have only those records that have a specific AVP values say...only those packets with a particular IMSI in the corresponding pcap. Is it possible to define such kind of filter when we initiate tcpdump on linux and if so could you provide the sysntax associated with such filters between a souce &amp;amp; destination?</description>
    </item>
    
    <item>
      <title>Get tcp and udp payloads with TSHARK</title>
      <link>/questions/23827/get-tcp-and-udp-payloads-with-tshark/</link>
      <pubDate>Fri, 16 Aug 2013 11:02:00 +0000</pubDate>
      
      <guid>/questions/23827/get-tcp-and-udp-payloads-with-tshark/</guid>
      <description>Get tcp and udp payloads with TSHARK  1 1Hi.
I use tshark to export packet information from a pcap file and it works well. I now need to export the tcp\udp payload as well. I have looked at several answers - http://ask.wireshark.org/questions/3323/printing-tcp-payload-using-tshark-t-fields and http://ask.wireshark.org/questions/12431/how-to-add-data-length-column-in-wireshark-display-or-plot-payload-length-vs-packet-no and they both claim
-e tcp.data
should work. However, I only get an empty field.
I&#39;m using Wireshark 1.10.1 on windows 7 64 bit.
Thanks.</description>
    </item>
    
    <item>
      <title>Installing an old version of Wireshark</title>
      <link>/questions/23834/installing-an-old-version-of-wireshark/</link>
      <pubDate>Fri, 16 Aug 2013 16:17:00 +0000</pubDate>
      
      <guid>/questions/23834/installing-an-old-version-of-wireshark/</guid>
      <description>Installing an old version of Wireshark  0 Hi guys, I need to install from source the 1.0.2 version of wireshark. After running the make command I get the following error:
/usr/bin/ld: gtk/libui.a(sctp_graph_dlg.o): undefined reference to symbol &amp;#39;[email protected]@GLIBC_2.2.5&amp;#39; /usr/bin/ld: note: &amp;#39;[email protected]@GLIBC_2.2.5&amp;#39; is defined in DSO /lib/x86_64-linux-gnu/libm.so.6 so try adding it to the linker command line /lib/x86_64-linux-gnu/libm.so.6: could not read symbols: Invalid operation collect2: error: ld returned 1 exit status make[2]: *** [wireshark] Error 1 make[2]: Leaving directory `/home/andre/Documents/wireshark_source_3/wireshark-1.</description>
    </item>
    
    <item>
      <title>How to filter only Http.cookie before starting</title>
      <link>/questions/23836/how-to-filter-only-httpcookie-before-starting/</link>
      <pubDate>Sat, 17 Aug 2013 13:03:00 +0000</pubDate>
      
      <guid>/questions/23836/how-to-filter-only-httpcookie-before-starting/</guid>
      <description>How to filter only Http.cookie before starting  0 Hello How i can filter only Http.cookie before starting capture?
when i use http filter i dont get any packets, but when i dont choose any filter i get all packets, !
i know that i can use http.cookie filter when capturing, but is there anyway to only capture http.cookie from all sites??
thanks
cookie wireshark http packets. captureasked 17 Aug &#39;13, 13:03</description>
    </item>
    
    <item>
      <title>Exercise One.pcap letters &amp;quot;b&amp;quot; and &amp;quot;g&amp;quot;</title>
      <link>/questions/23839/exercise-onepcap-letters-b-and-g/</link>
      <pubDate>Sun, 18 Aug 2013 09:32:00 +0000</pubDate>
      
      <guid>/questions/23839/exercise-onepcap-letters-b-and-g/</guid>
      <description>Exercise One.pcap letters &amp;ldquo;b&amp;rdquo; and &amp;ldquo;g&amp;rdquo;  -1 I am working on Exercise One.pcap letters &#34;b&#34; and &#34;g&#34; and am having difficulty as I am new to the product.
b) What is happening in frames 3, 4, and 5?
What exactly is a frame and how do I view these frames?
g) After the initial set of packets is received, the client sends out a new request in packet 12. This occurs automatically without any action by the user.</description>
    </item>
    
    <item>
      <title>Capture on Mobile Broadband Interface</title>
      <link>/questions/23845/capture-on-mobile-broadband-interface/</link>
      <pubDate>Sun, 18 Aug 2013 23:53:00 +0000</pubDate>
      
      <guid>/questions/23845/capture-on-mobile-broadband-interface/</guid>
      <description>Capture on Mobile Broadband Interface  0 Is it possible to capture on Mobile Broadband Interface (Windows 7) ? If yes, any specific procedure? It does not appear in the list of available interfaces.
mbnasked 18 Aug &#39;13, 23:53
Rajat
1●4●4●4
accept rate: 0%
  
One Answer:
  
1Unfortunately, no, as per Question 5 in the WinPcap FAQ:
Windows Vista and more recent. It&#39;s not possible to capture on PPP/VPN connections on these operating systems.</description>
    </item>
    
    <item>
      <title>how can I capture traffic between two devices on Wi-Fi</title>
      <link>/questions/23847/how-can-i-capture-traffic-between-two-devices-on-wi-fi/</link>
      <pubDate>Mon, 19 Aug 2013 06:53:00 +0000</pubDate>
      
      <guid>/questions/23847/how-can-i-capture-traffic-between-two-devices-on-wi-fi/</guid>
      <description>how can I capture traffic between two devices on Wi-Fi  0 Hello
I have difficult setup I will try to explain and then ask the question:
(IP-192.168.0.100) -------------- (IP 192.168.0.1) ---------------- (IP 192.168.0.200)
Mobile phone with Wifi --connected -- PC with Wifi USB stick -- connected -- Mobile phone with Wifi
I am running WireShark on my pc and i am capturing traffic that cumming thru the USB port the problem is I cannot see unicast traffic between two mobile devices (between 192.</description>
    </item>
    
    <item>
      <title>Wireshark to capture web traffic</title>
      <link>/questions/23853/wireshark-to-capture-web-traffic/</link>
      <pubDate>Mon, 19 Aug 2013 14:48:00 +0000</pubDate>
      
      <guid>/questions/23853/wireshark-to-capture-web-traffic/</guid>
      <description>Wireshark to capture web traffic  0 Hi all, I&#39;m new to the forum.... I have a Motorola SBG 6580 modem/router/WiFi at home on cable broadband. I have 1 PC which is connected to the 1 of the 4 ports on the router. I have 1 laptop, which is connected wirelessly to the router.
Is it possible to capture any network traffic; in particular web traffic coming out of the laptop?</description>
    </item>
    
    <item>
      <title>Computer sending emails via phishing program.</title>
      <link>/questions/23854/computer-sending-emails-via-phishing-program/</link>
      <pubDate>Mon, 19 Aug 2013 17:12:00 +0000</pubDate>
      
      <guid>/questions/23854/computer-sending-emails-via-phishing-program/</guid>
      <description>Computer sending emails via phishing program.  0 Hi.
So Im currently trying to dig into wireshark, and im now testing if its possible to get email content out of a phishing program (e.g message sent, stored passwords inside program, reciver). Ive found the stream and confirmed that It&#39;s sending the mails to an unknown gmail address. When I try to &#34;follow tcp stream&#34; I just get a bunch of, what seems to be, encoded characters.</description>
    </item>
    
    <item>
      <title>Why no Post messages captured in unsecured web page?</title>
      <link>/questions/23856/why-no-post-messages-captured-in-unsecured-web-page/</link>
      <pubDate>Mon, 19 Aug 2013 23:44:00 +0000</pubDate>
      
      <guid>/questions/23856/why-no-post-messages-captured-in-unsecured-web-page/</guid>
      <description>Why no Post messages captured in unsecured web page?  0 I am posting username and password in a not secured web page (no https).
While logging in to the my account I am using WireShark to try capturing my Post details. The result is that no Post message is captured.
Why is that?
(no ssl\tsl messages captured as expected - the site is not secured as I mentioned, but many tcp transportation on port 80)</description>
    </item>
    
    <item>
      <title>what is the purpose of tcp.pdu.size filter</title>
      <link>/questions/23868/what-is-the-purpose-of-tcppdusize-filter/</link>
      <pubDate>Tue, 20 Aug 2013 02:34:00 +0000</pubDate>
      
      <guid>/questions/23868/what-is-the-purpose-of-tcppdusize-filter/</guid>
      <description>what is the purpose of tcp.pdu.size filter  0 I am working with pdml format. I am trying to determine the octets of a frame using the nodes of a frame in pdml (field, proto). sometimes there is a field (filter) called tcp.pdu.size which value is the octets of the payload. Why this filed is not presented always if tcp contains any upper layer protocol? for example if tcp contains http, then tcp.</description>
    </item>
    
    <item>
      <title>I too am looking for a computer sending out spam how do I find it using wireshark?</title>
      <link>/questions/23870/i-too-am-looking-for-a-computer-sending-out-spam-how-do-i-find-it-using-wireshark/</link>
      <pubDate>Tue, 20 Aug 2013 02:52:00 +0000</pubDate>
      
      <guid>/questions/23870/i-too-am-looking-for-a-computer-sending-out-spam-how-do-i-find-it-using-wireshark/</guid>
      <description>I too am looking for a computer sending out spam how do I find it using wireshark?  0 All the answers I have seen on the web point to internal mail servers but its our web host that looks after our email. So how do I use wireshark to find out which machine is being used as a spam bot? To be clear we have been informed that one of our machines is sending out spam but its our external hosted mail server that is being logged and blocked all the machines in house &#39;appear&#39; to be fine running the usual antivirus, spy bot etc but I&#39;m pretty confident that at least one of our internal machines is compromised.</description>
    </item>
    
    <item>
      <title>Filter to remove non-periodic events</title>
      <link>/questions/23883/filter-to-remove-non-periodic-events/</link>
      <pubDate>Tue, 20 Aug 2013 12:22:00 +0000</pubDate>
      
      <guid>/questions/23883/filter-to-remove-non-periodic-events/</guid>
      <description>Filter to remove non-periodic events  0 I am performing a Wireshark capture for 24 hours at a network endpoint. During these 24 hours, the endpoint communicates with multiple other endpoints, for example IP addresses A through K. The endpoint where the capture is being performed (my endpoint) constantly communicates with endpoints with IP addresses A through J throughout the 24 hours. However, my endpoint only communicates with IP address K only a single time during the 24 hours.</description>
    </item>
    
    <item>
      <title>RST after SYN-ACK</title>
      <link>/questions/23885/rst-after-syn-ack/</link>
      <pubDate>Tue, 20 Aug 2013 15:58:00 +0000</pubDate>
      
      <guid>/questions/23885/rst-after-syn-ack/</guid>
      <description>RST after SYN-ACK  0 Hi, i´m facing a strange behavior for a simple telnet connection test, my station send the SYN packet, that go to a server, receive the [SYN, ACK], and just then send a RST. I believe the SYN,ACK packet its malformed, but i couldnt identify what its wrong. Can anyone help me.
Here is the packet capture, pcap format: https://docs.google.com/file/d/0B9Co4kddbAUWa0lCRlJ2WmJGS2M/edit?usp=sharing
Thanks a lot!
rst ack after synasked 20 Aug &#39;13, 15:58</description>
    </item>
    
    <item>
      <title>Remote capture from Cisco MDS Fibre Switch fails</title>
      <link>/questions/23886/remote-capture-from-cisco-mds-fibre-switch-fails/</link>
      <pubDate>Tue, 20 Aug 2013 17:23:00 +0000</pubDate>
      
      <guid>/questions/23886/remote-capture-from-cisco-mds-fibre-switch-fails/</guid>
      <description>Remote capture from Cisco MDS Fibre Switch fails  0 I&#39;m attempting to capture fibre channel traffic from a Cisco MDS Fibre channel switch via pcap. While attempting to a remote capture I captured the traffic to see why it was failing. Looks like the list interfaces request and reply worked. The authentication worked also. During the remote capture start I got generic updatefilter error 7
I&#39;ll upload the trace. Has anyone done this before?</description>
    </item>
    
    <item>
      <title>Wireshark and IPEnableRouter</title>
      <link>/questions/23888/wireshark-and-ipenablerouter/</link>
      <pubDate>Tue, 20 Aug 2013 18:07:00 +0000</pubDate>
      
      <guid>/questions/23888/wireshark-and-ipenablerouter/</guid>
      <description>Wireshark and IPEnableRouter  0 I&#39;m developing a ARP spoofing tool for Windows and during my tests I turned on the IPEnableRouter option (which is basically the Windows version of the linux IP Forward option).
It worked out great (the victim could access the internet), but I realized that if I started a capture in Wireshark the victim of the ARP spoofing would loose it&#39;s connection to the Internet. Repeated the whole thing a few times and I got the same result on all of them.</description>
    </item>
    
    <item>
      <title>Wireshark won&amp;#x27;t run with multiple capture files</title>
      <link>/questions/23891/wireshark-wont-run-with-multiple-capture-files/</link>
      <pubDate>Wed, 21 Aug 2013 00:58:00 +0000</pubDate>
      
      <guid>/questions/23891/wireshark-wont-run-with-multiple-capture-files/</guid>
      <description>Wireshark won&amp;rsquo;t run with multiple capture files  0 I would like to run wireshark with multiple files of 2 GB each, with max. 50 files. When i start wireshark, the windows flashes and with every flash a file is created, up to 50 files. Then wireshark stops. This happens in the 64 bit and 32 bit version. I&#39;m running windows 7 Pro
multiple-filesasked 21 Aug &#39;13, 00:58
FMvdBergh
11●1●1●3</description>
    </item>
    
    <item>
      <title>Passing data between packets (and not between dissectors)</title>
      <link>/questions/23894/passing-data-between-packets-and-not-between-dissectors/</link>
      <pubDate>Wed, 21 Aug 2013 01:22:00 +0000</pubDate>
      
      <guid>/questions/23894/passing-data-between-packets-and-not-between-dissectors/</guid>
      <description>Passing data between packets (and not between dissectors)  0 Hello,
I am writing a dissector and I would like to recover some information contained in a packet A, which is sent first, and pass it to a packet B. For example, sometimes my protocol have fragmented data (the B packet may be too large and is then concatenated into several smaller packets) but the information on how this packet is fragmented is embedded in the previous packet (the packet A).</description>
    </item>
    
    <item>
      <title>router talking to itself</title>
      <link>/questions/23897/router-talking-to-itself/</link>
      <pubDate>Wed, 21 Aug 2013 02:16:00 +0000</pubDate>
      
      <guid>/questions/23897/router-talking-to-itself/</guid>
      <description>router talking to itself  0 hi router is sending this all the time ..is this normal ?
188 25.296651000 BelkinIn_dc:47:9d BelkinIn_dc:47:9d 0xffff 252 Ethernet IIoxffffasked 21 Aug &#39;13, 02:16
cevery
11●1●1●2
accept rate: 0%
 edited 21 Aug &#39;13, 13:23 
Guy Harris ♦♦
17.4k●3●35●196
That certainly looks odd - not only because the source and destination addresses are the same unicast address (all the entries in the current trunk&#39;s &#34;</description>
    </item>
    
    <item>
      <title>Non controlled llsurfup-https packet and connection reset</title>
      <link>/questions/23902/non-controlled-llsurfup-https-packet-and-connection-reset/</link>
      <pubDate>Wed, 21 Aug 2013 03:36:00 +0000</pubDate>
      
      <guid>/questions/23902/non-controlled-llsurfup-https-packet-and-connection-reset/</guid>
      <description>Non controlled llsurfup-https packet and connection reset  0 Hello,
I&#39;ve a tcp server socket application listening on 1999 port, and several devices connects to it, through their respective internet connections (routers). The problem is that serveral of this devices have an unexpected connection behaviour, that i&#39;m going explain.
Server IP -&amp;gt; listening on port 1999
Device IP -&amp;gt; send request from port 1025
Server &amp;lt;- Device : Send SYN to stablish the connection</description>
    </item>
    
    <item>
      <title>offline use of wireshark...???</title>
      <link>/questions/23903/offline-use-of-wireshark/</link>
      <pubDate>Wed, 21 Aug 2013 03:39:00 +0000</pubDate>
      
      <guid>/questions/23903/offline-use-of-wireshark/</guid>
      <description>offline use of wireshark&amp;hellip;???  0 Can anyone tell me the offline use of wireshark. I am using it for networking purpose but its online so need to know about the each n every case of offline where we can use wireshark.
Thanx in advance...
wiresharkasked 21 Aug &#39;13, 03:39
Eagle Eye
11●1●1●3
accept rate: 0%
  
One Answer:
  
1What do you mean by Online/offline? You can use Wireshark to do live captures or to load capture files that has been taken previously on the capture files you can do more or less the same operations.</description>
    </item>
    
    <item>
      <title>&amp;quot;Unrecognized libpcap format&amp;quot; error when piping to &amp;quot;wireshark -k -i -&amp;quot;</title>
      <link>/questions/23904/unrecognized-libpcap-format-error-when-piping-to-wireshark-k-i-/</link>
      <pubDate>Wed, 21 Aug 2013 04:49:00 +0000</pubDate>
      
      <guid>/questions/23904/unrecognized-libpcap-format-error-when-piping-to-wireshark-k-i-/</guid>
      <description>&amp;ldquo;Unrecognized libpcap format&amp;rdquo; error when piping to &amp;ldquo;wireshark -k -i -&amp;quot;  0 Hi, I have wireshark 1.8.6 on x86 platform. When I try to open a large .pcap file (&amp;gt;3 mb), it gives &#34;Unrecognized libpcap format&#34; error.
I am sending input to wireshark via pipe. below is the cli command:
tail -f pcap_ file_name | /usr/local/bin/wireshark -k -i -Reason for using pipe input is that, pcap file is generating at run time with real traffic on node.</description>
    </item>
    
    <item>
      <title>Couldn&amp;#x27;t load module/undefined symbol</title>
      <link>/questions/23914/couldnt-load-moduleundefined-symbol/</link>
      <pubDate>Wed, 21 Aug 2013 09:09:00 +0000</pubDate>
      
      <guid>/questions/23914/couldnt-load-moduleundefined-symbol/</guid>
      <description>Couldn&amp;rsquo;t load module/undefined symbol  0 I&#39;m currently making a plugin based on the rmt-norm dissector by following the instructions in the README.plugins and I have been able to successfully build the plugin but when I go to start wireshark I get the following message:
&#34;Couldn&#39;t load module /products/wireshark/plugins/1.8.6/newnorm.so: products/wireshark-1.8.6/lib/wireshark/plugins/1.8.6/newnorm.so: undefined symbol: newnorm_ext_parse&#34;.
I&#39;m using the code found in epan/dissectors/packet-rmt-norm.c and its subsequent header files but I haven&#39;t changed anything except for the naming (i.</description>
    </item>
    
    <item>
      <title>Client to Print Server trouble</title>
      <link>/questions/23915/client-to-print-server-trouble/</link>
      <pubDate>Wed, 21 Aug 2013 09:56:00 +0000</pubDate>
      
      <guid>/questions/23915/client-to-print-server-trouble/</guid>
      <description>Client to Print Server trouble  0 I have a remote LAN with multiple printers and some of these devices are taking a long time to spool and complete a print job (one in particular upwards of 10 minutes). I have taken captures from a Windows client on site to 4 different printers, but I can&#39;t really see anything different in any of the 4 captures. Can someone advise what I should be looking for based on the symptoms?</description>
    </item>
    
    <item>
      <title>Certificate Request Size Change</title>
      <link>/questions/23929/certificate-request-size-change/</link>
      <pubDate>Wed, 21 Aug 2013 13:49:00 +0000</pubDate>
      
      <guid>/questions/23929/certificate-request-size-change/</guid>
      <description>Certificate Request Size Change  0 I have two deployments, one is a Virtual Machine, and other is a desktop. I am using WireShark to capture the certificate handshake traffic between a mobile device using SSL to each deployment one at a time. For the virtual machine deployment on cloud --&amp;gt; Device Certificate handshake the size of &#34;certificate Request&#34; is 2374 Bytes. For Desktop connected via LAN to device size of ceritificate is 16000 Bytes.</description>
    </item>
    
    <item>
      <title>My log won&amp;#x27;t decrypt!. WPA2-PSK. Have all 4 EAPOL packets, know SSID and passphrase. Tried entering as wpa-psk and wpa-pwd</title>
      <link>/questions/23934/my-log-wont-decrypt-wpa2-psk-have-all-4-eapol-packets-know-ssid-and-passphrase-tried-entering-as-wpa-psk-and-wpa-pwd/</link>
      <pubDate>Wed, 21 Aug 2013 14:55:00 +0000</pubDate>
      
      <guid>/questions/23934/my-log-wont-decrypt-wpa2-psk-have-all-4-eapol-packets-know-ssid-and-passphrase-tried-entering-as-wpa-psk-and-wpa-pwd/</guid>
      <description>My log won&amp;rsquo;t decrypt!. WPA2-PSK. Have all 4 EAPOL packets, know SSID and passphrase. Tried entering as wpa-psk and wpa-pwd  0 I have a log file from a WPA2-PSK network but Wireshark is not decrypting it for me despite entering the decrypting info as wpa-psk or wpa-pwd. I can see all four EAPOL packets in the log and also know the passphrase and SSID. What am I missing?
wpa-psk decryption wpa2 passphraseasked 21 Aug &#39;13, 14:55</description>
    </item>
    
    <item>
      <title>retransmissions issue</title>
      <link>/questions/23936/retransmissions-issue/</link>
      <pubDate>Wed, 21 Aug 2013 20:42:00 +0000</pubDate>
      
      <guid>/questions/23936/retransmissions-issue/</guid>
      <description>retransmissions issue  0 https://www.cloudshark.org/captures/14bcc5d9a146
In the above link, i have a capture of a client access a server, and i am seeing retransmissions. I check the network and the port that the user is connected to, but there are no errors on the port or the network to the server, but the pattern of the retransmission all begin up at a file that the client cannot find, so it retransmit for the file, needless to say, the user connection to the email server is slow and access to other server are slow.</description>
    </item>
    
    <item>
      <title>wireshark crashes when exporting a PDML file</title>
      <link>/questions/23937/wireshark-crashes-when-exporting-a-pdml-file/</link>
      <pubDate>Wed, 21 Aug 2013 21:31:00 +0000</pubDate>
      
      <guid>/questions/23937/wireshark-crashes-when-exporting-a-pdml-file/</guid>
      <description>wireshark crashes when exporting a PDML file  0 Using wireshark version 1.10.1. Using DNP 3.0 Transport decoder when export as XML - &#34;PDML&#34; wireshark consistently crashes.
pdmlasked 21 Aug &#39;13, 21:31
smajor
1●1●1●1
accept rate: 0%
  
One Answer:
  
1This is a bug, not a question. Please report the bug at the Wireshark Bugzilla site, attaching a capture that illustrates the problem, and then post the bug number back here as a comment.</description>
    </item>
    
    <item>
      <title>LLMNR Query has blank name</title>
      <link>/questions/23940/llmnr-query-has-blank-name/</link>
      <pubDate>Wed, 21 Aug 2013 22:44:00 +0000</pubDate>
      
      <guid>/questions/23940/llmnr-query-has-blank-name/</guid>
      <description>LLMNR Query has blank name  0 I am looking at the following capture and the first thing I notice is that the LLMNR query doesn&#39;t specify a name that it is trying to locally resolve. Is this a bug? See frame 1-12 (excluding 7)
http://www.cloudshark.org/captures/3bfe4764f3f4
llmnrasked 21 Aug &#39;13, 22:44
wireshark12
6●2●2●4
accept rate: 0%
  
One Answer:
  
2 Well, the query DOES specify a name: &#39;blank&#39; is probably not what you are intending to resolve but I don&#39;t see anything wrong with it - protocol-wise answered 21 Aug &#39;13, 23:15</description>
    </item>
    
    <item>
      <title>acking each tcp packet</title>
      <link>/questions/23944/acking-each-tcp-packet/</link>
      <pubDate>Thu, 22 Aug 2013 02:22:00 +0000</pubDate>
      
      <guid>/questions/23944/acking-each-tcp-packet/</guid>
      <description>acking each tcp packet  0 Hi Everyone, We have two unix(a &amp;amp; b) servers communicating with each other,basically &#34;a&#34; is application server who sends authentication request to server &#34;b&#34;.I can see that both are acking each packet with some data in it.This both servers are across different location and communicating through wan link and due to this frequent ack behaviour it is taking long time to login.Any inputs please.</description>
    </item>
    
    <item>
      <title>Identify sequence number errors in UDP captures</title>
      <link>/questions/23945/identify-sequence-number-errors-in-udp-captures/</link>
      <pubDate>Thu, 22 Aug 2013 02:30:00 +0000</pubDate>
      
      <guid>/questions/23945/identify-sequence-number-errors-in-udp-captures/</guid>
      <description>Identify sequence number errors in UDP captures  0 I have a 10 minute period of captures, during which we have seen out of sequence packets being delivered over a UDP channel in a log file. This is on a custom trading platform that does not subscribe to the exchanges retransmission service, so our retail platforms are fine but the custom one is being spanked 2-3 times per hour.
Is there a way I can quickly view where a sequence is broken or packets are missing?</description>
    </item>
    
    <item>
      <title>Slow rendering of a website</title>
      <link>/questions/23947/slow-rendering-of-a-website/</link>
      <pubDate>Thu, 22 Aug 2013 04:26:00 +0000</pubDate>
      
      <guid>/questions/23947/slow-rendering-of-a-website/</guid>
      <description>Slow rendering of a website  0 The following trace shows the capture of IE trying to load cnn.com. From frame 49 onwards things look fine. I cannot see any tell tale signs of problems. There are some retransmits that popup along the way but nothing that help identify the problem outright. What other areas could I focus on here?
http://www.cloudshark.org/captures/3bfe4764f3f4
latencyasked 22 Aug &#39;13, 04:26
wireshark12
6●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Need help interpreting extra ACK package from Win 8 to SQL Server</title>
      <link>/questions/23948/need-help-interpreting-extra-ack-package-from-win-8-to-sql-server/</link>
      <pubDate>Thu, 22 Aug 2013 04:29:00 +0000</pubDate>
      
      <guid>/questions/23948/need-help-interpreting-extra-ack-package-from-win-8-to-sql-server/</guid>
      <description>Need help interpreting extra ACK package from Win 8 to SQL Server  0 Hi!
I&#39;ve got a slightly duplicate of this post on http://social.technet.microsoft.com/Forums/windows/en-US/558553e7-d602-4584-a5dc-97f813890edc/extra-ack-packet-delaying-each-query-with-500-ms-on-windows-8, but I&#39;m hoping some of you guys have some valuable input on this problem.
Thing is, my box with Win8 apparently sends an extra ACK package when I run SQL queries, and it seems like that package is creating a ~500 ms delay. Here&#39;s a short snippet of logs from my box and a Win 7 Box.</description>
    </item>
    
    <item>
      <title>Wi-Fi Interface is &amp;quot;disabled&amp;quot;</title>
      <link>/questions/23958/wi-fi-interface-is-disabled/</link>
      <pubDate>Thu, 22 Aug 2013 06:23:00 +0000</pubDate>
      
      <guid>/questions/23958/wi-fi-interface-is-disabled/</guid>
      <description>Wi-Fi Interface is &amp;ldquo;disabled&amp;rdquo;  0 I can&#39;t run a packet capture on my Wi-Fi interface because it says its disabled. How do I enable it?
packet-captureasked 22 Aug &#39;13, 06:23
michaelthb
1●1●1●2
accept rate: 0%
 edited 22 Aug &#39;13, 06:23 
Which OS are you using? If you saerch this site the question may have been asked before.
(22 Aug &#39;13, 06:59) Anders ♦Where does it say that the interface is &#34;</description>
    </item>
    
    <item>
      <title>LUA API packet payload (info column)</title>
      <link>/questions/23969/lua-api-packet-payload-info-column/</link>
      <pubDate>Thu, 22 Aug 2013 14:54:00 +0000</pubDate>
      
      <guid>/questions/23969/lua-api-packet-payload-info-column/</guid>
      <description>LUA API packet payload (info column)  0 Hello,
I&#39;ve just recently started playing with the API and and I can get data such as source address, destination address, ports, etc but the meat of what I need is in the packet&#39;s payload (the info column in wireshark) and I can&#39;t figure out how to dump the data. Does anyone have an example or two of dumping this data?
Specifically I&#39;m looking to parse the HTTP post and get data.</description>
    </item>
    
    <item>
      <title>tshark http dissection of captured dump</title>
      <link>/questions/23971/tshark-http-dissection-of-captured-dump/</link>
      <pubDate>Thu, 22 Aug 2013 21:22:00 +0000</pubDate>
      
      <guid>/questions/23971/tshark-http-dissection-of-captured-dump/</guid>
      <description>tshark http dissection of captured dump  0 Hi,
please I have the following challenges using Tshark, though I have achieved it in wireshark, but it cost me too many time. So want to autorun tshark to do same. But I have been having difficulty achieving any.
merge and filter series of dumped traffic for sequence of IP addressed (example 10.1.1.2, 10.2.4.12, 10.5.3.6 and so on), combined with same argument (as in &#34;</description>
    </item>
    
    <item>
      <title>Multiple Messages in single frame causing problems while converting to csv using tshark</title>
      <link>/questions/23972/multiple-messages-in-single-frame-causing-problems-while-converting-to-csv-using-tshark/</link>
      <pubDate>Thu, 22 Aug 2013 23:18:00 +0000</pubDate>
      
      <guid>/questions/23972/multiple-messages-in-single-frame-causing-problems-while-converting-to-csv-using-tshark/</guid>
      <description>Multiple Messages in single frame causing problems while converting to csv using tshark  0 Hi, I am trying to extract some information from a wireshark capture using tshark. the problem is that within a single packet there are multiple messages. The messages are of different types and hence all the messages do not contain all the parameters. Due to this I am not able to figure out which parameter belongs to which message type.</description>
    </item>
    
    <item>
      <title>How to export a global data structure defined in epan/dissectors/packet-radius to make it accessible in ui/gtk?</title>
      <link>/questions/23981/how-to-export-a-global-data-structure-defined-in-epandissectorspacket-radius-to-make-it-accessible-in-uigtk/</link>
      <pubDate>Fri, 23 Aug 2013 06:47:00 +0000</pubDate>
      
      <guid>/questions/23981/how-to-export-a-global-data-structure-defined-in-epandissectorspacket-radius-to-make-it-accessible-in-uigtk/</guid>
      <description>How to export a global data structure defined in epan/dissectors/packet-radius to make it accessible in ui/gtk?  0 I have defined a global data structure inside epan/dissector/packet-radius, which I am using to store some radius state handling information. I would like to display the information stored in this data structure inside the Statistics-&amp;gt;Summary dialogue window.
I am not sure how to export the data structure defined in epan/dissector/packet-radius.c to make it available to ui/gtk/summary_dlg.</description>
    </item>
    
    <item>
      <title>tcap tid filters</title>
      <link>/questions/23984/tcap-tid-filters/</link>
      <pubDate>Fri, 23 Aug 2013 12:13:00 +0000</pubDate>
      
      <guid>/questions/23984/tcap-tid-filters/</guid>
      <description>tcap tid filters  0 Hi what is meaning tcap.tid == 2f:00:57:21 , so what is meaning 2f:00:57:21 please thanks
sin73anasked 23 Aug &#39;13, 12:13
sin73an
1●1●1●1
accept rate: 0%
  
One Answer:
  
1The tid is the Transaction ID and 2f:00:57:21 is the filter matching criteria for the 4 bytes that comprise it. The notation used is hexadecimal since this field happens to be an FT_BYTES type, as can be seen using:</description>
    </item>
    
    <item>
      <title>Search Within the Current Packet</title>
      <link>/questions/23987/search-within-the-current-packet/</link>
      <pubDate>Fri, 23 Aug 2013 15:56:00 +0000</pubDate>
      
      <guid>/questions/23987/search-within-the-current-packet/</guid>
      <description>Search Within the Current Packet  0 How do I search for a string or byte sequence within the scope of the current packet?
scope search find packetasked 23 Aug &#39;13, 15:56
araybold
6●1●1●2
accept rate: 0%
  
One Answer:
  
0 AFAIK you can&#39;t. The search will highlight the search string in the hex pane for the first match in the packet, but a new search will look for the next packet in which the search string appears, not the next occurrence in the same packet.</description>
    </item>
    
    <item>
      <title>window sizing always at 65k with .116 sending?  Does only the ack from dst only show scale size?</title>
      <link>/questions/23989/window-sizing-always-at-65k-with-116-sending-does-only-the-ack-from-dst-only-show-scale-size/</link>
      <pubDate>Fri, 23 Aug 2013 18:52:00 +0000</pubDate>
      
      <guid>/questions/23989/window-sizing-always-at-65k-with-116-sending-does-only-the-ack-from-dst-only-show-scale-size/</guid>
      <description>window sizing always at 65k with .116 sending? Does only the ack from dst only show scale size?  0 Hello,
Current transfer test over 10gigabit is around 7.3mbit/s; not so good.
I see my syn and syn ack set rwin multiplier to 11 in the beginning.
The ack&#39;s from .171 show good win values; but my intial send is always at 65336 (default for tcp_wmem). is this normal?
Anything indicative of a window scaling problem for the dismal performance?</description>
    </item>
    
    <item>
      <title>p-bits numbering</title>
      <link>/questions/23990/p-bits-numbering/</link>
      <pubDate>Fri, 23 Aug 2013 18:53:00 +0000</pubDate>
      
      <guid>/questions/23990/p-bits-numbering/</guid>
      <description>p-bits numbering  0 I am using Wireshark version 1.10.1 and I&#39;ve got a p-bit column set up by using Custom -&amp;gt; vlan.priority. This gives me the priority bit in the column but they are spelled out, for example &#34;Best Effort&#34; and &#34;Voice&#34;, but I only want the p-bit numbers 0-7 displayed in the column as it had done in previous versions of wireshark, by using the option L2 COS value (802.</description>
    </item>
    
    <item>
      <title>Mac OS X icon messed up</title>
      <link>/questions/24002/mac-os-x-icon-messed-up/</link>
      <pubDate>Sat, 24 Aug 2013 11:50:00 +0000</pubDate>
      
      <guid>/questions/24002/mac-os-x-icon-messed-up/</guid>
      <description>Mac OS X icon messed up  0 So I recall in talking about a bug that caused Wireshark to crash, one of the developers mentioned the trouble he was having that the icon would not show up correctly in the Applications folder or the Dock. I found out why (well there may be more than one cause, but here is what caused it here).
The file inside the app that stores the icons located inside the app:(/Applications/Wireshark.</description>
    </item>
    
    <item>
      <title>Wireless N losing internet access</title>
      <link>/questions/24012/wireless-n-losing-internet-access/</link>
      <pubDate>Sat, 24 Aug 2013 14:05:00 +0000</pubDate>
      
      <guid>/questions/24012/wireless-n-losing-internet-access/</guid>
      <description>Wireless N losing internet access  0 Have a strange problem.
Using a Intel N 2230 and connecting 802.11n to a router, I lose access to the network at various times.
I&#39;m still shown as connected but I can&#39;t reach any part of the internal network or external internet etc.
Performed a packet capture of the moment it drops, traffic doesn&#39;t seem to strange to me (albeit I&#39;m new to this) apart from a series of packets with SACK_PERM=1.</description>
    </item>
    
    <item>
      <title>No ACK after SYN/ACK</title>
      <link>/questions/24017/no-ack-after-synack/</link>
      <pubDate>Sat, 24 Aug 2013 23:40:00 +0000</pubDate>
      
      <guid>/questions/24017/no-ack-after-synack/</guid>
      <description>No ACK after SYN/ACK  0 I have two captures. In one, I see a handshake from the phone to the Voice Server (working capture). In the non-working one, I do not see an ACK from the client after the SYN/ACK from the Voice Server.
Initially I thought it might be a routing issue since maybe the SYN/ACK from the server is not reaching the client or the ACK from the client is not reaching the server.</description>
    </item>
    
    <item>
      <title>follow tcp stream in wireshark</title>
      <link>/questions/24018/follow-tcp-stream-in-wireshark/</link>
      <pubDate>Sun, 25 Aug 2013 04:26:00 +0000</pubDate>
      
      <guid>/questions/24018/follow-tcp-stream-in-wireshark/</guid>
      <description>follow tcp stream in wireshark  0 I have a trace file with 2000 streams. I open this trace with wireshark in windows. for my work I need to create separate txt files that each file contains a tcp stream. but in wireshark I can see one stream each time by tcp follow and I should save the stream files one by one! how can I have these streams in separate files in easy way?</description>
    </item>
    
    <item>
      <title>304 and 404 errors</title>
      <link>/questions/24022/304-and-404-errors/</link>
      <pubDate>Sun, 25 Aug 2013 07:04:00 +0000</pubDate>
      
      <guid>/questions/24022/304-and-404-errors/</guid>
      <description>304 and 404 errors  0 Hi, I have a problem with Wireshark. The idea is that when listening on HTTP packets they show an error of 304 and 404 and i can&#39;t read the address of the page. I use it on the Back Track 5 R3. Before running the Wiresharka I use the command &#34;echo 1/proc/sys/net/ipv4/ip_forward &amp;gt; and&#34; arpspoof-i eth0-t 192.168.1.1 192.168.1.9 &#34;in order to be able to listen.</description>
    </item>
    
    <item>
      <title>facebook password</title>
      <link>/questions/24023/facebook-password/</link>
      <pubDate>Sun, 25 Aug 2013 08:17:00 +0000</pubDate>
      
      <guid>/questions/24023/facebook-password/</guid>
      <description>facebook password  0 Can I use wireshark to find out the facebook username / password of someone logging on via my home wifi network?
facebookasked 25 Aug &#39;13, 08:17
iraossssssa
11●1●1●2
accept rate: 0%
  
One Answer:
  
0No. It should only be transmitted in an encrypted way, so you can capture the packets but not read them.
answered 25 Aug &#39;13, 09:00
Jasper ♦♦</description>
    </item>
    
    <item>
      <title>Running TShark in a batch file with -r attempts to capture traffic rather than reading the file</title>
      <link>/questions/24025/running-tshark-in-a-batch-file-with-r-attempts-to-capture-traffic-rather-than-reading-the-file/</link>
      <pubDate>Sun, 25 Aug 2013 09:36:00 +0000</pubDate>
      
      <guid>/questions/24025/running-tshark-in-a-batch-file-with-r-attempts-to-capture-traffic-rather-than-reading-the-file/</guid>
      <description>Running TShark in a batch file with -r attempts to capture traffic rather than reading the file  0 tshark -r &amp;lt;file&amp;gt; -Y &amp;quot;(ip.addr==10.1.1.2 or ip.addr==10.2.4.12 or ip.addr==10.5.3.6) and (&amp;quot;http.request.method==GET&amp;quot; or (tcp.flags.syn==1 &amp;amp;&amp;amp; tcp.flags.ack==0 &amp;amp;&amp;amp; tcp.port==443) or (tcp.flags.syn==1 &amp;amp;&amp;amp; tcp.flags.ack==0 &amp;amp;&amp;amp; tcp.port==22) )&amp;quot;When i attempt to autorun this code using batch file process, I discovered that it does not accept it, rather it attempts to capture the traffic on my network.</description>
    </item>
    
    <item>
      <title>Can I use Wireshark to see iPhone/iPad internet use if it is using my wi-fi?</title>
      <link>/questions/24038/can-i-use-wireshark-to-see-iphoneipad-internet-use-if-it-is-using-my-wi-fi/</link>
      <pubDate>Sun, 25 Aug 2013 12:20:00 +0000</pubDate>
      
      <guid>/questions/24038/can-i-use-wireshark-to-see-iphoneipad-internet-use-if-it-is-using-my-wi-fi/</guid>
      <description>Can I use Wireshark to see iPhone/iPad internet use if it is using my wi-fi?  0 I want to be able to see if my wife has another Facebook account and/or email accounts. I don&#39;t necessarily need to see the passwords, just the activity and what is going on. However, she always uses her iPhone 4S or my daughter&#39;s iPad. Please help as I recently determined she was using her primary FB acct to rekindle an old flame and my subsequent distrust is ripping our chance at staying married apart.</description>
    </item>
    
    <item>
      <title>[closed] Internet privacy your answer is questionable</title>
      <link>/questions/24042/internet-privacy-your-answer-is-questionable/</link>
      <pubDate>Sun, 25 Aug 2013 14:46:00 +0000</pubDate>
      
      <guid>/questions/24042/internet-privacy-your-answer-is-questionable/</guid>
      <description>[closed] Internet privacy your answer is questionable  -3 I need a program that tells me, who is looking at my usage on the internet or basic operating usage, i will pay for it.
__security_cookie internetasked 25 Aug &#39;13, 14:46
ldavidw10
-2●1●1●1
accept rate: 0%
 closed 26 Aug &#39;13, 05:54 
multipleinte...
1.3k●15●23●40
I am pist off at internet providers that keep my computer from operating at its maximum because they are looking at all my actions on the keyboard, i do not mind them looking and collecting data at my internet actions but what i do on my daily programs i really thing that is to much.</description>
    </item>
    
    <item>
      <title>Can I filter out frames without renumbering the frames?</title>
      <link>/questions/24045/can-i-filter-out-frames-without-renumbering-the-frames/</link>
      <pubDate>Sun, 25 Aug 2013 16:53:00 +0000</pubDate>
      
      <guid>/questions/24045/can-i-filter-out-frames-without-renumbering-the-frames/</guid>
      <description>Can I filter out frames without renumbering the frames?  0 When I used TShark to filter a capture file, the new output file starts with a new frame numbering, different from the frame number of the original file. Is there a way to indicate/instruct tshark to retain the frame number of the original file and not create a new frame number?
filter numbering tsharkasked 25 Aug &#39;13, 16:53
Hunted</description>
    </item>
    
    <item>
      <title>Duplicate SYN, same source port and same destination port</title>
      <link>/questions/24054/duplicate-syn-same-source-port-and-same-destination-port/</link>
      <pubDate>Mon, 26 Aug 2013 04:38:00 +0000</pubDate>
      
      <guid>/questions/24054/duplicate-syn-same-source-port-and-same-destination-port/</guid>
      <description>Duplicate SYN, same source port and same destination port  0 Hi,
I am looking at a trace to monitor a TCP/IP connection over GPRS and I am noticing that I see two consecutive SYN messages (with a difference of a couple of seconds) everytime there is a connection attempt. I notice that in these 2 SYN messages the source port is always the same, and there is nothing wrong at checksum level.</description>
    </item>
    
    <item>
      <title>Unknown AVP problem</title>
      <link>/questions/24064/unknown-avp-problem/</link>
      <pubDate>Mon, 26 Aug 2013 08:16:00 +0000</pubDate>
      
      <guid>/questions/24064/unknown-avp-problem/</guid>
      <description>Unknown AVP problem  0 I am using wireshark version 1.10.0rc2. I want to capture Diameter stuffs for S6a interface. I am facing problem while decode the Trace-Data AVP having AVP code = 1458.
In wireshark it is showing as AVP Code: 1458 Unknown Unknow AVP, if you know what this is you can add it to the dictionary.xml.
Can any one have a look and please let me know.</description>
    </item>
    
    <item>
      <title>Should the first ACK acknowledge data in Syn-Ack?</title>
      <link>/questions/24068/should-the-first-ack-acknowledge-data-in-syn-ack/</link>
      <pubDate>Mon, 26 Aug 2013 09:55:00 +0000</pubDate>
      
      <guid>/questions/24068/should-the-first-ack-acknowledge-data-in-syn-ack/</guid>
      <description>Should the first ACK acknowledge data in Syn-Ack?  0 If a Syn-Ack with data is seen, should the first ACK acknowledge the data in Syn-Ack?
ackasked 26 Aug &#39;13, 09:55
Sachin Kulkarni
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Yes, if you mean the ACK packet that is part of the three way handshake. It is a direct reaction to the SYN-ACK and has to adjust it&#39;s acknowledge number to whatever was sent in that packet.</description>
    </item>
    
    <item>
      <title>why can&amp;#x27;t wireshark capture UDP from a server?</title>
      <link>/questions/24070/why-cant-wireshark-capture-udp-from-a-server/</link>
      <pubDate>Mon, 26 Aug 2013 11:17:00 +0000</pubDate>
      
      <guid>/questions/24070/why-cant-wireshark-capture-udp-from-a-server/</guid>
      <description>why can&amp;rsquo;t wireshark capture UDP from a server?  0 wireshark can capture upd packets from others, but can&#39;t capture udp packets from one server which sends out udp by HP iLO. I am sure the server can send udp by HP iLO as hostmonitor can receive its udp packets, no any problem. why wireshirk can&#39;t?
thanks, George
capture1asked 26 Aug &#39;13, 11:17
georgeyu100
11●1●1●2
accept rate: 0%
wireshark can capture UDP packets from other server port 161</description>
    </item>
    
    <item>
      <title>decode as http on all ports</title>
      <link>/questions/24072/decode-as-http-on-all-ports/</link>
      <pubDate>Mon, 26 Aug 2013 12:37:00 +0000</pubDate>
      
      <guid>/questions/24072/decode-as-http-on-all-ports/</guid>
      <description>decode as http on all ports  0 Hi want to decode all packets as if they were http. How can i do this? The packets that don&#39;t have an http.request.uri I will just awk out.
At the moment I have been doing it with this bash script iterating over port numbers. I am sure i must be missing something.
Horrific hack:
#!/bin/bash for i in `seq 1 65535`; do tshark -r mycap.</description>
    </item>
    
    <item>
      <title>In what format do you need to download the MaxMind GeoIP databases?</title>
      <link>/questions/24075/in-what-format-do-you-need-to-download-the-maxmind-geoip-databases/</link>
      <pubDate>Mon, 26 Aug 2013 14:35:00 +0000</pubDate>
      
      <guid>/questions/24075/in-what-format-do-you-need-to-download-the-maxmind-geoip-databases/</guid>
      <description>In what format do you need to download the MaxMind GeoIP databases?  0 What format do you have to download to get it to work?
geoipasked 26 Aug &#39;13, 14:35
computeruser1
11●2●2●4
accept rate: 0%
 converted 26 Aug &#39;13, 15:40 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
0Binary format (not CSV format).
answered 26 Aug &#39;13, 15:47
Guy Harris ♦♦
17.4k●3●35●196
accept rate: 19%</description>
    </item>
    
    <item>
      <title>ESP decryption</title>
      <link>/questions/24079/esp-decryption/</link>
      <pubDate>Mon, 26 Aug 2013 20:13:00 +0000</pubDate>
      
      <guid>/questions/24079/esp-decryption/</guid>
      <description>ESP decryption  0 Hello everybody! :)
I&#39;m testing IPSec by pinging two machines which I previously had configured. The thing is that when I try to decrypt ESP Payload (by configuring the SAs in Wireshark) it just decrypts packets in one direction; in fact it&#39;s the one which appears first in the list of SAs. If I switch the list order, then Wireshark updates the captures and decrypts the ones in the other direction, but never both.</description>
    </item>
    
    <item>
      <title>Crashes on startup - mac os x</title>
      <link>/questions/24085/crashes-on-startup-mac-os-x/</link>
      <pubDate>Tue, 27 Aug 2013 01:39:00 +0000</pubDate>
      
      <guid>/questions/24085/crashes-on-startup-mac-os-x/</guid>
      <description>Crashes on startup - mac os x  0 I just installed xQuartz and Wireshark, however when wireshark asked me where X11 was on first start, I accidently choose XCode -- now it just crashes when I start it.
x11 mac wiresharkasked 27 Aug &#39;13, 01:39
chovy
41●2●2●5
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>SSL decrypting with master secret but no session id</title>
      <link>/questions/24086/ssl-decrypting-with-master-secret-but-no-session-id/</link>
      <pubDate>Tue, 27 Aug 2013 02:32:00 +0000</pubDate>
      
      <guid>/questions/24086/ssl-decrypting-with-master-secret-but-no-session-id/</guid>
      <description>SSL decrypting with master secret but no session id  0 RSA Session-ID:xxxx Master-Key:yyyyIs one of the formats for decrypting SSL traffic if I have the master secret. But some sites like google don&#39;t send a Session-ID (Session Id Length 0). The other format for RSA based key exchange with the encrypted pre master key and pre master key I can&#39;t use because I don&#39;t have access to the pre master keys.</description>
    </item>
    
    <item>
      <title>Can I retrieve all the values for the same attribute name (Column name)?</title>
      <link>/questions/24097/can-i-retrieve-all-the-values-for-the-same-attribute-name-column-name/</link>
      <pubDate>Tue, 27 Aug 2013 07:17:00 +0000</pubDate>
      
      <guid>/questions/24097/can-i-retrieve-all-the-values-for-the-same-attribute-name-column-name/</guid>
      <description>Can I retrieve all the values for the same attribute name (Column name)?  0 Hi ,
Currently I am having a .pcap file with the below sample data. Just showing in an xml format..
&amp;lt;packet&amp;gt; &amp;lt;field name=&#34;radius.Class&#34; show=&#34;ABC&#34; value=&#34;ABC&#34;/&amp;gt; &amp;lt;/field&amp;gt; &amp;lt;field name=&#34;radius.Class&#34; show=&#34;DEF&#34; value=&#34;DEF&#34;/&amp;gt; &amp;lt;/field&amp;gt; &amp;lt;field name=&#34;radius.Class&#34; show=&#34;HIJ&#34; value=&#34;HIJ&#34;/&amp;gt; &amp;lt;/field&amp;gt; &amp;lt;/packet&amp;gt;The tshark command that I am using currently is
tshark -r &#34;PCAP Input file location&#34; -T fields -e radius.Class -E separator=, -E header=y &amp;gt; output.</description>
    </item>
    
    <item>
      <title>how to: launch network sniffer application for asdm on mac</title>
      <link>/questions/24100/how-to-launch-network-sniffer-application-for-asdm-on-mac/</link>
      <pubDate>Tue, 27 Aug 2013 08:34:00 +0000</pubDate>
      
      <guid>/questions/24100/how-to-launch-network-sniffer-application-for-asdm-on-mac/</guid>
      <description>how to: launch network sniffer application for asdm on mac  0 I use use the Cisco ASDM firewall management software on my mac quite a lot and all is good. I also use Wireshark to review pcap files exported from Firewalls and routers.
Under Windows ( :-( ) i could launch the wireshark app directly from using the packet capture wizard.
this is set up under &#39;Preferences&#39; then pointing to the application.</description>
    </item>
    
    <item>
      <title>Captures on same network subnet (vlan) not seen</title>
      <link>/questions/24101/captures-on-same-network-subnet-vlan-not-seen/</link>
      <pubDate>Tue, 27 Aug 2013 09:11:00 +0000</pubDate>
      
      <guid>/questions/24101/captures-on-same-network-subnet-vlan-not-seen/</guid>
      <description>Captures on same network subnet (vlan) not seen  0 My network has about 5 network subnets (vlans), all created on the Firewall and trunked on the core switch. Other switches are uplinked to the core switch. A ping from 10.2.100.19 to 10.2.100.16, when filtered on wireshark doesn&#39;t capture this ICMP, while ping from 10.2.100.19 to 172.16.27.225 (another vlan) appeared on wireshark. This was tested with a couple of ips and it seemed activity between same subnet were not been captured.</description>
    </item>
    
    <item>
      <title>RST, ACK at the beginning?</title>
      <link>/questions/24104/rst-ack-at-the-beginning/</link>
      <pubDate>Tue, 27 Aug 2013 09:54:00 +0000</pubDate>
      
      <guid>/questions/24104/rst-ack-at-the-beginning/</guid>
      <description>RST, ACK at the beginning?  0 I&#39;m getting a strange RST, ACK at the beginning of a SOCK transfer.
Client RST, ACK -&amp;gt; Server
1 minute later
Client SYNC -&amp;gt; Server Client SYNC, ACK &amp;lt;- Server Client ACK -&amp;gt; Server Client SOCK -&amp;gt; Server Client SOCK &amp;lt;- Server
It&#39;s strange the RST, ACK seems to be in response to a session which completed 10 minutes earlier. Once, the SYNC is sent everything runs fine.</description>
    </item>
    
    <item>
      <title>Filter capture based on 802.11 signal strength</title>
      <link>/questions/24107/filter-capture-based-on-80211-signal-strength/</link>
      <pubDate>Tue, 27 Aug 2013 10:12:00 +0000</pubDate>
      
      <guid>/questions/24107/filter-capture-based-on-80211-signal-strength/</guid>
      <description>Filter capture based on 802.11 signal strength  0 I am trying to setup a capture filter that allows me to filter wireless traffic based on signal strength. This would be beneficial to do as it would allow me to cut out allot of the noise from AP&#39;s outside of my area. I have been able to accomplish this as a display filter but would really like to limit the capture size.</description>
    </item>
    
    <item>
      <title>How to capture picassa video link</title>
      <link>/questions/24114/how-to-capture-picassa-video-link/</link>
      <pubDate>Tue, 27 Aug 2013 14:21:00 +0000</pubDate>
      
      <guid>/questions/24114/how-to-capture-picassa-video-link/</guid>
      <description>How to capture picassa video link  0 Hi all,
Im trying to use wireshark to capture and reveal a link in this video but in the past couple day i not able to find it. If someone could help i would really appricate.
Here is the video link:
http://phimtt.com/xem-phim/nu-trang-tai-danh-word-twisters-adventures-2008
The format im looking for are:
https://picasaweb.google.com/lh/photo/oLb1wikeW75BUCYthty5JGdsRkDU9D-GZvm2P4XELMM https://picasaweb.google.com/lh/photo/oLb1wikeW75BUCYthty5JGdsRkDU9D-GZvm2P4XELMM?start=15https://picasaweb.google.com/106164294256489669464/Image?authkey=Gv1sRgCKm7hsnPk5aRZQ#5657122599477586178 https://picasaweb.google.com/lh/photo/EXbYzXpUnlELm0FHsEcmbE9c4LVWd6J4g-EJTl_M9Bo
The video is host on picasaweb.google.com
From the video link above: i was able to find this with chrome network tool, but is not valid:</description>
    </item>
    
    <item>
      <title>How to request a new dissector supporting a protocol?</title>
      <link>/questions/24115/how-to-request-a-new-dissector-supporting-a-protocol/</link>
      <pubDate>Tue, 27 Aug 2013 20:35:00 +0000</pubDate>
      
      <guid>/questions/24115/how-to-request-a-new-dissector-supporting-a-protocol/</guid>
      <description>How to request a new dissector supporting a protocol?  0 Hi guys, I&#39;d like to ask that, if we have a mechanism for us to submit a request for supporting a certain protocol? I found that there are some bugs in the bugzilla for this purpose, but I don&#39;t think this is a clear and easy way. Do you have any answer?
Thanks.
requestasked 27 Aug &#39;13, 20:35
polerfox</description>
    </item>
    
    <item>
      <title>How to get the recently hot &amp;amp; popular protocols?</title>
      <link>/questions/24118/how-to-get-the-recently-hot-popular-protocols/</link>
      <pubDate>Wed, 28 Aug 2013 01:57:00 +0000</pubDate>
      
      <guid>/questions/24118/how-to-get-the-recently-hot-popular-protocols/</guid>
      <description>How to get the recently hot &amp;amp; popular protocols?  0 Hi folks,
I&#39;m doing a research on the protocol coverage of Wireshark. And I&#39;d like to ask here, is there any effective way to get the hot and popular protocols up to date? Watching the bugs in Bugzilla may be an approach, but is there any possibility to get data from a widely range? such as the users who are not so professional to file a bug in Bugzilla.</description>
    </item>
    
    <item>
      <title>Remoteapp connection drop</title>
      <link>/questions/24130/remoteapp-connection-drop/</link>
      <pubDate>Wed, 28 Aug 2013 06:29:00 +0000</pubDate>
      
      <guid>/questions/24130/remoteapp-connection-drop/</guid>
      <description>Remoteapp connection drop  0 Hello friends, I&#39;m trying to troubleshoot the remoteapp intermitent connection drop. we have a 3 RDS Servers and one connection Broker and a Hardware loadbalancer. Uers get disconnected randomly and it&#39;s completely random. So i have decided to monitor the connections on one of the RDS servers and i see quite a few colour coded as Black. Can someone have a look at this let me know what is happening here?</description>
    </item>
    
    <item>
      <title>Realtec PCIe GBE Family Controller dropping wired connection</title>
      <link>/questions/24144/realtec-pcie-gbe-family-controller-dropping-wired-connection/</link>
      <pubDate>Wed, 28 Aug 2013 09:25:00 +0000</pubDate>
      
      <guid>/questions/24144/realtec-pcie-gbe-family-controller-dropping-wired-connection/</guid>
      <description>Realtec PCIe GBE Family Controller dropping wired connection  0 On my recently built Windows 7 PC ASUS F2 A85-M Pro motherboard the Realtek PCIe GBE Family Controller keeps dropping a wired connection. Driver version 7.61.612.2012. Has anyone experienced this or know if there is something in the advanced settings that could be miss configured? I do not normally ever power it down but when the connection is lost it requires a restart to reconnect.</description>
    </item>
    
    <item>
      <title>FC malformed packet - no source addr or dest addr. All zeros</title>
      <link>/questions/24145/fc-malformed-packet-no-source-addr-or-dest-addr-all-zeros/</link>
      <pubDate>Wed, 28 Aug 2013 09:35:00 +0000</pubDate>
      
      <guid>/questions/24145/fc-malformed-packet-no-source-addr-or-dest-addr-all-zeros/</guid>
      <description>FC malformed packet - no source addr or dest addr. All zeros  0 1Have you seen this issue? How should I proceed to troubleshoot this issue?
malformedasked 28 Aug &#39;13, 09:35
dtootle
11●1●2●2
accept rate: 0%
  
One Answer:
  
0Is this a real FC frame, or do you just think it is a FC frame, because Wireshark show FC as protocol?
Wireshark shows frames with an ethertype of 0 as FC.</description>
    </item>
    
    <item>
      <title>local network issues</title>
      <link>/questions/24146/local-network-issues/</link>
      <pubDate>Wed, 28 Aug 2013 10:10:00 +0000</pubDate>
      
      <guid>/questions/24146/local-network-issues/</guid>
      <description>local network issues  0 Hi, can someone take a look at the capture and let me know why so many dup acks and perhaps help me determine why my inside lan is so darn slow? this capture is a file transfer of malware bytes from my machine to my lan file server.
thank you
https://www.dropbox.com/s/rivkrj62a3g10a9/tmg%20file%20xfer.pcapng
dup ack lan slow reassembleasked 28 Aug &#39;13, 10:10
netnerd
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>radiotap.dbm_antnoise not found</title>
      <link>/questions/24151/radiotapdbm_antnoise-not-found/</link>
      <pubDate>Wed, 28 Aug 2013 11:18:00 +0000</pubDate>
      
      <guid>/questions/24151/radiotapdbm_antnoise-not-found/</guid>
      <description>radiotap.dbm_antnoise not found  0 First of all, I&#39;m monitoring my wifi network in monitor/promiscuous mode.
On my Mac I have wireshark / tshark v1.10.1
On a debian machine I have tshark 1.10.2
I noticed that on my Mac I can capture &#34;radiotap.dbm_antnoise&#34; which is the antenna noise, but on my debian machine it does not show up (whether I capture as an XML file or specify &#34;radiotap.dbm_antnoise&#34;)
I was originally running an older version of tshark that I&#39;d installed from aptitude, thought that was the problem, so I uninstalled that and just finished compiling 1.</description>
    </item>
    
    <item>
      <title>Network Topology Graph</title>
      <link>/questions/24163/network-topology-graph/</link>
      <pubDate>Thu, 29 Aug 2013 05:43:00 +0000</pubDate>
      
      <guid>/questions/24163/network-topology-graph/</guid>
      <description>Network Topology Graph  0 Is there any wireshark plugin to get network topology graph ????????????
graph topolgyasked 29 Aug &#39;13, 05:43
wiresharkbeg...
11●1●1●2
accept rate: 0%
 converted to question 29 Aug &#39;13, 06:13 
grahamb ♦
19.8k●3●30●206
Your &#34;answer&#34; has been converted to a comment as that&#39;s how this site works. Please read the FAQ for more information.
(29 Aug &#39;13, 06:14) grahamb ♦  
2 Answers:</description>
    </item>
    
    <item>
      <title>Follow TCP stream by layer</title>
      <link>/questions/24165/follow-tcp-stream-by-layer/</link>
      <pubDate>Thu, 29 Aug 2013 07:46:00 +0000</pubDate>
      
      <guid>/questions/24165/follow-tcp-stream-by-layer/</guid>
      <description>Follow TCP stream by layer  0 Hello,
I&#39;m analyzing a 3-layer protocol (3 layers on top of tcp), and I use the &#34;Follow TCP stream&#34; a lot. This option, however, shows all data in layers above TCP. Is there a way to use &#34;Follow TCP stream&#34; without viewing all layers above TCP? Can I choose which layers appear?
Thanks
Nitay
follow.tcp.streamasked 29 Aug &#39;13, 07:46
nitay
11●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>FP appearing as UDP</title>
      <link>/questions/24166/fp-appearing-as-udp/</link>
      <pubDate>Thu, 29 Aug 2013 08:07:00 +0000</pubDate>
      
      <guid>/questions/24166/fp-appearing-as-udp/</guid>
      <description>FP appearing as UDP  0 Hi,
I managed to take a capture of an IuB interace (link between NodeB and RNC) on my laptop. I am expecting to see FP PDUs, however they all appear as UDP. How can I setup/configure Wireshark so that it recognizes that these frames are FP? Wireshark doesn&#39;t give me the option to decode as FP. Do I require additional information to decode these frames?</description>
    </item>
    
    <item>
      <title>TCP Fast Retransmit detected only within 20 ms of DupACK</title>
      <link>/questions/24168/tcp-fast-retransmit-detected-only-within-20-ms-of-dupack/</link>
      <pubDate>Thu, 29 Aug 2013 08:53:00 +0000</pubDate>
      
      <guid>/questions/24168/tcp-fast-retransmit-detected-only-within-20-ms-of-dupack/</guid>
      <description>TCP Fast Retransmit detected only within 20 ms of DupACK  0 Hi,
TCP Fast Retransmit detection is explained as:
/ If there were &amp;gt;=2 duplicate ACKs in the reverse direction (there might be duplicate acks missing from the trace) and if this sequence number matches those ACKs and if the packet occurs within 20ms of the last duplicate ack then this is a fast retransmission /
Why does the retransmitted packet have to occur within 20 ms of DUPACK?</description>
    </item>
    
    <item>
      <title>Ethernet and my Raspberry Pi</title>
      <link>/questions/24169/ethernet-and-my-raspberry-pi/</link>
      <pubDate>Thu, 29 Aug 2013 09:13:00 +0000</pubDate>
      
      <guid>/questions/24169/ethernet-and-my-raspberry-pi/</guid>
      <description>Ethernet and my Raspberry Pi  0 Hello all,
I recently purchased a Raspberry Pi with the hopes of making an inexpensive Bluetooth Packet sniffer. I have WireShark on my Windows PC and am unable to capture BT data(I know it&#39;s not supported). My plan is to capture the data using the Pi and dump the data over Ethernet to my PC. My question is: Will this method allow for a legible readout of the BT data that was captured by the Pi?</description>
    </item>
    
    <item>
      <title>[closed] PMTUD and retransmission - Out-Of-Order?</title>
      <link>/questions/24172/pmtud-and-retransmission-out-of-order/</link>
      <pubDate>Thu, 29 Aug 2013 11:16:00 +0000</pubDate>
      
      <guid>/questions/24172/pmtud-and-retransmission-out-of-order/</guid>
      <description>[closed] PMTUD and retransmission - Out-Of-Order?  0 Hello, I have a trace showing PMTUD in action.
I was surprised to see that the retransmitted segment is not flagged as tcp.analysis.retransmission but as tcp.analysis.out_of_order Here is the trace |frame contains d748:8e30:5e03| I&#39;m talking about frame 73 carrying the same sequence number as 65 but with a reduced MSS.
Shouldn&#39;t this be flagged as a retransmision? Thanks in advance for your input.</description>
    </item>
    
    <item>
      <title>g_close not being recognized as available function in plugin dissector</title>
      <link>/questions/24176/g_close-not-being-recognized-as-available-function-in-plugin-dissector/</link>
      <pubDate>Thu, 29 Aug 2013 14:21:00 +0000</pubDate>
      
      <guid>/questions/24176/g_close-not-being-recognized-as-available-function-in-plugin-dissector/</guid>
      <description>g_close not being recognized as available function in plugin dissector  0 I&#39;m writing a plugin dissector that upon initialization reads a file with a 64bit key and a string to be stored in a hash table. This gets used to identify messages.
I&#39;ve written code in the dissector that uses g_close and strtoll to close the file and read the 64 bit key. The code has the following includes.</description>
    </item>
    
    <item>
      <title>Unable to catch websocket traffic (both directions)</title>
      <link>/questions/24181/unable-to-catch-websocket-traffic-both-directions/</link>
      <pubDate>Thu, 29 Aug 2013 22:39:00 +0000</pubDate>
      
      <guid>/questions/24181/unable-to-catch-websocket-traffic-both-directions/</guid>
      <description>Unable to catch websocket traffic (both directions)  0 Hello,
I have a computer A:
- 192.168.0.1 (physical laptop)
- Glassfish server (websocket endpoint)
- Wireshark
and a computer B:
- VM inside Virtualbox, which A runs (network = bridged)
- 192.168.0.2
Now, when I try to catch websocket traffic (B opens a browser, connects to endpoint A and sends text using JS. Server replies with some text), I can only see ws-traffic from A to B.</description>
    </item>
    
    <item>
      <title>Assign name to ip-address in wireshark for Mac OS</title>
      <link>/questions/24182/assign-name-to-ip-address-in-wireshark-for-mac-os/</link>
      <pubDate>Thu, 29 Aug 2013 22:51:00 +0000</pubDate>
      
      <guid>/questions/24182/assign-name-to-ip-address-in-wireshark-for-mac-os/</guid>
      <description>Assign name to ip-address in wireshark for Mac OS  0 I wonder how could i assign name to ip-address in wireshark for Mac OS
osx macasked 29 Aug &#39;13, 22:51
icomixx
1●1●1●1
accept rate: 0%
Where can I found the directory to add the host file there?
(05 Sep &#39;13, 23:01) icomixx  
One Answer:
  
2The same way you do it on any other OS.</description>
    </item>
    
    <item>
      <title>SAP diag Plug-in invalid Win32 issue</title>
      <link>/questions/24184/sap-diag-plug-in-invalid-win32-issue/</link>
      <pubDate>Fri, 30 Aug 2013 01:46:00 +0000</pubDate>
      
      <guid>/questions/24184/sap-diag-plug-in-invalid-win32-issue/</guid>
      <description>SAP diag Plug-in invalid Win32 issue  0 Hi guys, got invalid Win32 application&#39;s issue running SAP Diag Plug-in from http://blog.ptsecurity.com/2011/10/sap-diag-decompress-plugin-for.html on Win7.
Any Idea, how to capture SAP diag with latest Wireshark on Win7?
Thx Reza666
sapasked 30 Aug &#39;13, 01:46
reza666
1●3●3●4
accept rate: 0%
  
3 Answers:
  
1That plugin is produced by a third party so you&#39;ll have to ask them for support.</description>
    </item>
    
    <item>
      <title>Piping sflowtool into WireShark</title>
      <link>/questions/24195/piping-sflowtool-into-wireshark/</link>
      <pubDate>Fri, 30 Aug 2013 06:59:00 +0000</pubDate>
      
      <guid>/questions/24195/piping-sflowtool-into-wireshark/</guid>
      <description>Piping sflowtool into WireShark  0 From the elevated cmd prompt, I have tried &#34;wireshark -k -i (sflowtool)&#34; and receive error that capture session could not be created: error opening adapter...system cannot find specified file.
How can I get sflowtool piped into WireShark?
pipingasked 30 Aug &#39;13, 06:59
jrupert
11●1●1●2
accept rate: 0%
  
One Answer:
  
1Have you set up the named pipe sflowtool as per the Wireshark Wiki page on capturing over pipes?</description>
    </item>
    
    <item>
      <title>file doesn&amp;#x27;t exist!</title>
      <link>/questions/24196/file-doesnt-exist/</link>
      <pubDate>Fri, 30 Aug 2013 07:05:00 +0000</pubDate>
      
      <guid>/questions/24196/file-doesnt-exist/</guid>
      <description>file doesn&amp;rsquo;t exist!  0 Hi, I wrote this code in cygwin in windows:
file=c:\man.pcap for stream in $(tshark -nlr $file -Y tcp.flags.syn==1 -T fields -e tcp.stream | sort -n | uniq) do echo &amp;quot;Processing stream $stream&amp;quot; tshark -nlr $file -qz &amp;quot;follow,tcp,ascii,$stream&amp;quot; &amp;gt; stream-$stream.log donebut I got this error message: tshark: The file &#34;c:man.pcap&#34; doesn&#39;t exist.
the file &#34;man.pcap&#34; is located in C drive. I haven&#39;t any idea for fix this problem.</description>
    </item>
    
    <item>
      <title>Please explain: Trace capture to the internet blocked by Proxy Server</title>
      <link>/questions/24202/please-explain-trace-capture-to-the-internet-blocked-by-proxy-server/</link>
      <pubDate>Fri, 30 Aug 2013 09:21:00 +0000</pubDate>
      
      <guid>/questions/24202/please-explain-trace-capture-to-the-internet-blocked-by-proxy-server/</guid>
      <description>Please explain: Trace capture to the internet blocked by Proxy Server  0 Hi Everyone,
I captured a trace of my network connection to the internet. I noticed there were a lot of reset packets being sent by the internet server - which was not surprising as my internet browser was not configured with my proxy address settings.
Now, my question is this: If I required access to the proxy server to browse, how come what was being displayed in Wireshark were the Ip addresses of the various internet servers I was trying to connect to?</description>
    </item>
    
    <item>
      <title>Can 802.11 from AirPcap Be Decoded To SIP/RTP?</title>
      <link>/questions/24204/can-80211-from-airpcap-be-decoded-to-siprtp/</link>
      <pubDate>Fri, 30 Aug 2013 09:35:00 +0000</pubDate>
      
      <guid>/questions/24204/can-80211-from-airpcap-be-decoded-to-siprtp/</guid>
      <description>Can 802.11 from AirPcap Be Decoded To SIP/RTP?  0 Testing mobile apps which make phone calls using wifi connection, encountered a problem with audio quality and excessive delay on certain phones. Captured traffic between mobile phone and wifi router using AirPcap, but can not find a way to Decode As SIP/RTP. All packets shown as 802.11 protocol naturally.
Is there a way to decode the wifi packets into the SIP and RTP used for the VoIP call?</description>
    </item>
    
    <item>
      <title>invalid address:port pair</title>
      <link>/questions/24207/invalid-addressport-pair/</link>
      <pubDate>Fri, 30 Aug 2013 10:40:00 +0000</pubDate>
      
      <guid>/questions/24207/invalid-addressport-pair/</guid>
      <description>invalid address:port pair  1 I ran this script:
file=man.pcap for stream in $(tshark -nlr $file -Y tcp.flags.syn==1 -T fields -e tcp.stream | sort -n | uniq) do echo &amp;quot;Processing stream $stream&amp;quot; tshark -nlr $file -qz &amp;quot;follow,tcp,ascii,$stream&amp;quot; &amp;gt; stream-$stream.log donebut I got this message for all streams:
Processing stream 0 tshark: follow - Invalid address:port pair. Processing stream 1 tshark: follow - Invalid address:port pair.
Processing stream 2 tshark: follow - Invalid address:port pair.</description>
    </item>
    
    <item>
      <title>Not filtering out WPA setup packets in capture filter?</title>
      <link>/questions/24217/not-filtering-out-wpa-setup-packets-in-capture-filter/</link>
      <pubDate>Fri, 30 Aug 2013 18:25:00 +0000</pubDate>
      
      <guid>/questions/24217/not-filtering-out-wpa-setup-packets-in-capture-filter/</guid>
      <description>Not filtering out WPA setup packets in capture filter?  0 Hello!
So, I am able to view/decrypt packets over my WPA network as long as I captured the setup packets. However, there are a TON of broadcast packets that junk up the captured packets. I&#39;m just interested in the HTTP traffic. Filtering works fine, but I would much rather set up a capture filter so my logs stop getting so huge and hard to manage.</description>
    </item>
    
    <item>
      <title>&amp;quot;Browser emulation&amp;quot; Is this possible/does this exist?</title>
      <link>/questions/24218/browser-emulation-is-this-possibledoes-this-exist/</link>
      <pubDate>Fri, 30 Aug 2013 18:57:00 +0000</pubDate>
      
      <guid>/questions/24218/browser-emulation-is-this-possibledoes-this-exist/</guid>
      <description>&amp;ldquo;Browser emulation&amp;rdquo; Is this possible/does this exist?  0 Hey!
I have two laptops set up on my network, and I have been using Wireshark to pick up the packets from one on the other. I&#39;m wondering, is there any way to &#34;mirror&#34; the activity of the laptop being sniffed on the sniffing laptop? Like, I get one packet from laptop A and laptop B says &#34;Oh, I am going to pretend this packet is for me!</description>
    </item>
    
    <item>
      <title>follow stream with more information in tshark</title>
      <link>/questions/24220/follow-stream-with-more-information-in-tshark/</link>
      <pubDate>Fri, 30 Aug 2013 23:43:00 +0000</pubDate>
      
      <guid>/questions/24220/follow-stream-with-more-information-in-tshark/</guid>
      <description>follow stream with more information in tshark  0 Hi I want to save 2000 streams in separate txt files but for my work I need each of ascii files involes full information about all packets that made the stream like follow tcp in wireshark!
I ran this script:
 for stream in $(tshark -nlr $file -Y tcp.flags.syn==1 -T fields -e tcp.stream | sort -n | uniq | sed &amp;#39;s/\r//&amp;#39;) do echo &amp;quot;Processing stream $stream&amp;quot; tshark -nlr $file -qz &amp;quot;follow,tcp,ascii,$stream&amp;quot; &amp;gt; stream-$stream.</description>
    </item>
    
    <item>
      <title>Decode GTPv2 TEID as Decimal or Hex?</title>
      <link>/questions/24221/decode-gtpv2-teid-as-decimal-or-hex/</link>
      <pubDate>Sat, 31 Aug 2013 00:41:00 +0000</pubDate>
      
      <guid>/questions/24221/decode-gtpv2-teid-as-decimal-or-hex/</guid>
      <description>Decode GTPv2 TEID as Decimal or Hex?  0 Hello,
When I check GTPv2 message with expanding subtree, it is found that TEID is decoded as decimal as below.
TEID/GRE Key: 34604084

But in top of subtree it is decoded as hex as below.
Fully Qualified Tunnel Endpoint Identifier (F-TEID) : S11 MME GTP-C interface, TEID/GRE Key: 0x02100434, IPv4 10.64.194.1

I&#39;m wondering both should be hex but is there anyone who knows reason of this?</description>
    </item>
    
    <item>
      <title>So I installed wireshark with yum... now what?</title>
      <link>/questions/24222/so-i-installed-wireshark-with-yum-now-what/</link>
      <pubDate>Sat, 31 Aug 2013 01:59:00 +0000</pubDate>
      
      <guid>/questions/24222/so-i-installed-wireshark-with-yum-now-what/</guid>
      <description>So I installed wireshark with yum&amp;hellip; now what?  0 Well this much I&#39;ve done right: Running transaction Installing : GeoIP-1.4.8-6.fc19.x86_64 1/3 Installing : libsmi-0.4.8-11.fc19.x86_64 2/3 Installing : wireshark-1.10.0-2.fc19.x86_64 3/3 Verifying : libsmi-0.4.8-11.fc19.x86_64 1/3 Verifying : wireshark-1.10.0-2.fc19.x86_64 2/3 Verifying : GeoIP-1.4.8-6.fc19.x86_64 3/3
Installed: wireshark.x86_64 0:1.10.0-2.fc19
Dependency Installed: GeoIP.x86_64 0:1.4.8-6.fc19 libsmi.x86_64 0:0.4.8-11.fc19
Complete!Only this is what I get after: [email protected] ~]$ wireshark bash: wireshark: command not found...
fedora19 yumasked 31 Aug &#39;13, 01:59</description>
    </item>
    
    <item>
      <title>Is it possible to filter out specific fields of specific packet types in a live capture?</title>
      <link>/questions/24224/is-it-possible-to-filter-out-specific-fields-of-specific-packet-types-in-a-live-capture/</link>
      <pubDate>Sat, 31 Aug 2013 05:46:00 +0000</pubDate>
      
      <guid>/questions/24224/is-it-possible-to-filter-out-specific-fields-of-specific-packet-types-in-a-live-capture/</guid>
      <description>Is it possible to filter out specific fields of specific packet types in a live capture?  0 Hi,
I am using tshark and I would like to store 802.11 header traffic in text format of a live capture. That means that I would like to &#34;cut&#34; the data portion of data frames so that it won&#39;t be written to my text file but keep everything else (headers of all data, management and control frames).</description>
    </item>
    
    <item>
      <title>Retransmissions</title>
      <link>/questions/24225/retransmissions/</link>
      <pubDate>Sat, 31 Aug 2013 06:13:00 +0000</pubDate>
      
      <guid>/questions/24225/retransmissions/</guid>
      <description>Retransmissions  0 I&#39;m a new user to wireshark. I&#39;ve noticed that there are a lot of retransmissions being repoted. Just wondering if this is normal or not?
12355asked 31 Aug &#39;13, 06:13
Wolf147
11●1●1●3
accept rate: 0%
  
One Answer:
  
1Standard answer: &#34;it depends&#34; ;-)
There are a lot of factors that need to be considered when dealing with retransmissions, e.g.:
What nodes are talking to each other, and what is their network distance?</description>
    </item>
    
    <item>
      <title>Why receiving RST because of many DUP ACKs?</title>
      <link>/questions/24246/why-receiving-rst-because-of-many-dup-acks/</link>
      <pubDate>Sat, 31 Aug 2013 15:41:00 +0000</pubDate>
      
      <guid>/questions/24246/why-receiving-rst-because-of-many-dup-acks/</guid>
      <description>Why receiving RST because of many DUP ACKs?  0 My server works for lots of clients concurrently (client amount is between 300-800 in any moment).
I wrote a server and client implementation and clients getting disconnected somehow, which i dont why. Even i am getting disconnected rarely for this unknown reason. And this is ruining quality.
I logged in to server with WinSCP and made a test like this:</description>
    </item>
    
    <item>
      <title>Decrypt WPA with Tshark</title>
      <link>/questions/24249/decrypt-wpa-with-tshark/</link>
      <pubDate>Sat, 31 Aug 2013 17:45:00 +0000</pubDate>
      
      <guid>/questions/24249/decrypt-wpa-with-tshark/</guid>
      <description>Decrypt WPA with Tshark  0 I use TShark 1.11.0 (SVN Rev 51621 from /trunk).
tshark -r input.pcap -o wlan.enable_decryption:TRUE -o wlan.wep_key1:wpa-psk:passphrase -w output.pcapThrrows specifies unknown preference error. Same if I use -o wlan.wep_key1:wpa-pwd:password:SSID What&#39;s the right command for tshark to decrypt WPA?
decryption wpa tsharkasked 31 Aug &#39;13, 17:45
sslx
16●1●1●3
accept rate: 0%
Hmm, it says the thread has two answers, but if I click it I see no answer.</description>
    </item>
    
    <item>
      <title>tshark: extract rtp payload of the codec G.723</title>
      <link>/questions/24268/tshark-extract-rtp-payload-of-the-codec-g723/</link>
      <pubDate>Sun, 01 Sep 2013 10:27:00 +0000</pubDate>
      
      <guid>/questions/24268/tshark-extract-rtp-payload-of-the-codec-g723/</guid>
      <description>tshark: extract rtp payload of the codec G.723  0 In order to extract the RTP payload from a pcap file captured by wireshark, I&#39;m using tshark with the command
tshark -nr stream.pcap -R &amp;#39;rtp &amp;amp;&amp;amp; ip.dst==192.168.1.64&amp;#39; -T fields -e rtp.payloadthis succeeded with the codecs g.729 and ilbc but with the codec g.723 it wasn&#39;t the case. I think that this problem is due to the fact that the field payload of the rtp protocol doesn&#39;t exist any more (when consulting the wireshark).</description>
    </item>
    
    <item>
      <title>Need help getting started with Wireshark.</title>
      <link>/questions/24269/need-help-getting-started-with-wireshark/</link>
      <pubDate>Sun, 01 Sep 2013 11:32:00 +0000</pubDate>
      
      <guid>/questions/24269/need-help-getting-started-with-wireshark/</guid>
      <description>Need help getting started with Wireshark.  0 Is there anyone who can help me? I&#39;m a software student in Iran and I want study the Wireshark source code. I really enjoy this software but I don&#39;t know where to start? I need your guidance. Please help me get started. Thanks.
newbie novice beginner helpmeasked 01 Sep &#39;13, 11:32
shaghayegh
11●1●1●3
accept rate: 0%
 edited 01 Sep &#39;13, 15:42</description>
    </item>
    
    <item>
      <title>Device to capture data for embedded system</title>
      <link>/questions/24273/device-to-capture-data-for-embedded-system/</link>
      <pubDate>Sun, 01 Sep 2013 19:36:00 +0000</pubDate>
      
      <guid>/questions/24273/device-to-capture-data-for-embedded-system/</guid>
      <description>Device to capture data for embedded system  0 I am developing a embedded ethernet system, wireshark is installed in my PC.
My ethernet system is required to connect to Internet, can someone inform me which particular hub/router can I use to capture my ethernet system traffic.
Regards Sam
router hubasked 01 Sep &#39;13, 19:36
rabbit
1●4●4●5
accept rate: 0%
  
One Answer:
  
1Perhaps have a look at the Wireshark wiki page on Ethernet capture setup first, as it may help you decide which type of device you&#39;re really interested in.</description>
    </item>
    
    <item>
      <title>TCP Retransmission with a delay time of two seconds</title>
      <link>/questions/24275/tcp-retransmission-with-a-delay-time-of-two-seconds/</link>
      <pubDate>Mon, 02 Sep 2013 01:43:00 +0000</pubDate>
      
      <guid>/questions/24275/tcp-retransmission-with-a-delay-time-of-two-seconds/</guid>
      <description>TCP Retransmission with a delay time of two seconds  0 Hello,
I have a VNC client (192.168.0.66) and a VNC server (192.168.0.10) in my network. On the client runs Windows CE 5.0 and on the server VxWorks. The problem is, that the respnse to a touch click on the client is in some cases delayed. The delay time is 500 ms to two seconds.
For problem analysis, I made a capture with wireshark.</description>
    </item>
    
    <item>
      <title>how to use capture wifi packets coming over air using laptop(inbuilt wifi)</title>
      <link>/questions/24281/how-to-use-capture-wifi-packets-coming-over-air-using-laptopinbuilt-wifi/</link>
      <pubDate>Mon, 02 Sep 2013 05:18:00 +0000</pubDate>
      
      <guid>/questions/24281/how-to-use-capture-wifi-packets-coming-over-air-using-laptopinbuilt-wifi/</guid>
      <description>how to use capture wifi packets coming over air using laptop(inbuilt wifi)  0 I want to use wireshark software on windows 7 without external pcap dongle.
wiresharkasked 02 Sep &#39;13, 05:18
maheshbabu
1●1●1●1
accept rate: 0%
  
One Answer:
  
3See the Windows section of this page http://wiki.wireshark.org/CaptureSetup/WLAN for some info.
answered 02 Sep &#39;13, 07:00
Anders ♦
4.6k●9●52
accept rate: 17%
Unfortunately, changing the 802.</description>
    </item>
    
    <item>
      <title>How many retransmissions are considered to be bad</title>
      <link>/questions/24283/how-many-retransmissions-are-considered-to-be-bad/</link>
      <pubDate>Mon, 02 Sep 2013 10:36:00 +0000</pubDate>
      
      <guid>/questions/24283/how-many-retransmissions-are-considered-to-be-bad/</guid>
      <description>How many retransmissions are considered to be bad  0 Hello, my cuestions is if I have captured 2000 packets and I have retransmissions, how many retransmissions percent is considered to be a problem? Thanks
retransmissionsasked 02 Sep &#39;13, 10:36
ogoname
11●3●3●4
accept rate: 0%
  
One Answer:
  
2It depends on how much they hurt you or the people using the network. As a simple way to determine the &#34;</description>
    </item>
    
    <item>
      <title>How do I interpret Wireshark Expert Infos output?</title>
      <link>/questions/24289/how-do-i-interpret-wireshark-expert-infos-output/</link>
      <pubDate>Mon, 02 Sep 2013 15:04:00 +0000</pubDate>
      
      <guid>/questions/24289/how-do-i-interpret-wireshark-expert-infos-output/</guid>
      <description>How do I interpret Wireshark Expert Infos output?  0 I have used version 1.10.1 to capture a 900 mbyte trace file. The trace file is a download of a resultant data set from a Netezza Data Warehouse query. I have run Wireshark Expert Infos against it and the Notes have recorded 128 Duplicate ACK&#39;s run a total of 25938 times. Does this indicate a heavily congested network between the laptop and the Server?</description>
    </item>
    
    <item>
      <title>SGsAP-MM-INFORMATION-REQUEST showing extraneous data.</title>
      <link>/questions/24292/sgsap-mm-information-request-showing-extraneous-data/</link>
      <pubDate>Mon, 02 Sep 2013 22:12:00 +0000</pubDate>
      
      <guid>/questions/24292/sgsap-mm-information-request-showing-extraneous-data/</guid>
      <description>SGsAP-MM-INFORMATION-REQUEST showing extraneous data.  0 Hello, I am using wireshark Version 1.10.1 (SVN Rev 50926 from /trunk-1.10). I used wireshark to capture SGsAP-MM-INFORMATION-REQUEST message with following values: MM information IE length 5, Protocol discriminator 8, MM Information message type 49, Network Daylight Saving Time 2. But wireshark displayed it as an extraneous data, though by looking at the hex values, IE seems to be in correct order with proper value.</description>
    </item>
    
    <item>
      <title>possible to use the MAC info in the Wireshark manuf file as part of display filter?</title>
      <link>/questions/24314/possible-to-use-the-mac-info-in-the-wireshark-manuf-file-as-part-of-display-filter/</link>
      <pubDate>Tue, 03 Sep 2013 08:51:00 +0000</pubDate>
      
      <guid>/questions/24314/possible-to-use-the-mac-info-in-the-wireshark-manuf-file-as-part-of-display-filter/</guid>
      <description>possible to use the MAC info in the Wireshark manuf file as part of display filter?  0 Is it possible to use the MAC info in the Wireshark manuf file as part of display filter?
i.e. wlan.addr contains Apple
This would be much more efficient than building a filter with all 249 MAC prefixes associated with Apple in the manuf file
thanks
tom
manuf display-filterasked 03 Sep &#39;13, 08:51</description>
    </item>
    
    <item>
      <title>802.11 Protocol</title>
      <link>/questions/24315/80211-protocol/</link>
      <pubDate>Tue, 03 Sep 2013 13:50:00 +0000</pubDate>
      
      <guid>/questions/24315/80211-protocol/</guid>
      <description>802.11 Protocol  0 Hi, I have a 802.11 wireless sniffing captured file. How to start with ? How to extract the data out of the pcap ?
802.11asked 03 Sep &#39;13, 13:50
vj kumar
11●2●2●3
accept rate: 0%
  
One Answer:
  
0If the traffic is not encrypted (not on a &#34;protected&#34; networking using WEP or WPA/WPA2), Wireshark should do that for you.
If the traffic is encrypted, you will have to configure Wireshark to decrypt it.</description>
    </item>
    
    <item>
      <title>TCP window Size</title>
      <link>/questions/24316/tcp-window-size/</link>
      <pubDate>Tue, 03 Sep 2013 13:57:00 +0000</pubDate>
      
      <guid>/questions/24316/tcp-window-size/</guid>
      <description>TCP window Size  0 Hello, I have made 2 wireshark captures: 1- A text file of size 10 MB 2- A PDF file of size 16MB
I repeated both these captures, once on a Cloud Virtual Machine and another on a LAN desktop. I am capturing the file Sync between the device and VM/desktop on a laptop that the mobile device is connected to.
What i don&#39;t understand is, how should i measure the window size for each environment using WireShark?</description>
    </item>
    
    <item>
      <title>can&amp;#x27;t start</title>
      <link>/questions/24319/cant-start/</link>
      <pubDate>Tue, 03 Sep 2013 16:36:00 +0000</pubDate>
      
      <guid>/questions/24319/cant-start/</guid>
      <description>can&amp;rsquo;t start  0 if i go to capture then options the start button won&#39;t click. why is this
startingasked 03 Sep &#39;13, 16:36
waffles
1●1●1●1
accept rate: 0%
what do you mean by &#34;won&#39;t click&#34;? Is that button greyed out? If so, there are no interfaces available to capture on.
(03 Sep &#39;13, 23:50) Kurt Knochner ♦  
One Answer:
  
0Is this windows? You need &#34;</description>
    </item>
    
    <item>
      <title>Ubuntu, ath9k, monitor and promiscuous mode - can only capture 802.11 protocol traffic</title>
      <link>/questions/24320/ubuntu-ath9k-monitor-and-promiscuous-mode-can-only-capture-80211-protocol-traffic/</link>
      <pubDate>Tue, 03 Sep 2013 17:25:00 +0000</pubDate>
      
      <guid>/questions/24320/ubuntu-ath9k-monitor-and-promiscuous-mode-can-only-capture-80211-protocol-traffic/</guid>
      <description>Ubuntu, ath9k, monitor and promiscuous mode - can only capture 802.11 protocol traffic  0 I can&#39;t capture any http traffic, not even my own.
Please help.
monitorasked 03 Sep &#39;13, 17:25
Ayush
6●1●1●3
accept rate: 0%
  
One Answer:
  
1 Wireshark will only recognize 802.11 traffic as being IP traffic (and if it doesn&#39;t recognize it as IP traffic, it won&#39;t recognize it as TCP traffic, and if it doesn&#39;t recognize it as TCP traffic, it won&#39;t recognize it as HTTP traffic) if the traffic is either not encrypted (on a non-protected network, not using WEP or WPA/WPA2) or if if it&#39;s encrypted but Wireshark is configured to decrypt it.</description>
    </item>
    
    <item>
      <title>Taking 802.11n captures with Linux and USB wireless probes</title>
      <link>/questions/24323/taking-80211n-captures-with-linux-and-usb-wireless-probes/</link>
      <pubDate>Tue, 03 Sep 2013 21:27:00 +0000</pubDate>
      
      <guid>/questions/24323/taking-80211n-captures-with-linux-and-usb-wireless-probes/</guid>
      <description>Taking 802.11n captures with Linux and USB wireless probes  0 This is my first question so please be nice.
I want to set up my first package capture kit. I need to capture packages on a 802.11n network.
This is what I&#39;m thinking on getting:
Dell D630Linux Distro (any flavor but possibly Fedora)USB N wireless ProbesHUBHere are my questions:
If the laptop I get does not have a 802.11n card, can I still buy a hub and USB N wireless probes and still be able to capture packages?</description>
    </item>
    
    <item>
      <title>Wireshark  VOIP Call Flow Graph partially Froze!</title>
      <link>/questions/24327/wireshark-voip-call-flow-graph-partially-froze/</link>
      <pubDate>Tue, 03 Sep 2013 23:05:00 +0000</pubDate>
      
      <guid>/questions/24327/wireshark-voip-call-flow-graph-partially-froze/</guid>
      <description>Wireshark VOIP Call Flow Graph partially Froze!  1 Hi all; I am using Version 1.10.1 Wireshark and just upgraded my graphics card.However still facing the same problem which is; when I open VOIP call flow graph as I scroll down the flow just the upper part scrolls and the bottom part frozes , so I can&#39;t see the correct flow.I search but couldn&#39;t find a smillar problem ,do somebody have any idea?</description>
    </item>
    
    <item>
      <title>Wireshark and 2008 R2 server reliability issues</title>
      <link>/questions/24335/wireshark-and-2008-r2-server-reliability-issues/</link>
      <pubDate>Wed, 04 Sep 2013 01:10:00 +0000</pubDate>
      
      <guid>/questions/24335/wireshark-and-2008-r2-server-reliability-issues/</guid>
      <description>Wireshark and 2008 R2 server reliability issues  0 I&#39;ve been having reliability issues with multiple Wireshark versions on 2008 server. Initially the GUI would crash mid-capture. So I then started to use tshark, but this suffered the following issue:
When capturing to file the packet counter displayed within cmd prompt would freeze. Pressing any key on the keyboard (i.e. STDIN) would get the counter incrementing again. I assumed it was just the counter freezing, however looking at the capture file there&#39;s a complete gap in capture whilst the screen is frozen.</description>
    </item>
    
    <item>
      <title>Can anyone explain this TCP sequence to me</title>
      <link>/questions/24339/can-anyone-explain-this-tcp-sequence-to-me/</link>
      <pubDate>Wed, 04 Sep 2013 04:40:00 +0000</pubDate>
      
      <guid>/questions/24339/can-anyone-explain-this-tcp-sequence-to-me/</guid>
      <description>Can anyone explain this TCP sequence to me  0 I have developed an application which reads data over a high volume network (2 sensors, both 1khz).
The application reads the packets for a random time, and then crashes due to - what I believe to be - a native buffer overflow.
The following image depicts the exacts packet sequence each time the crash occurs - a large Dup ACK block followed by 2 RST flags.</description>
    </item>
    
    <item>
      <title>Decrypting jpeg image</title>
      <link>/questions/24353/decrypting-jpeg-image/</link>
      <pubDate>Wed, 04 Sep 2013 09:29:00 +0000</pubDate>
      
      <guid>/questions/24353/decrypting-jpeg-image/</guid>
      <description>Decrypting jpeg image  0 I have extracted the output of a pcap file, where it has encrypted jpeg image inside a word .doc &amp;amp; also .jpeg. How can I extract the same ?
jpeg extractingasked 04 Sep &#39;13, 09:29
vj kumar
11●2●2●3
accept rate: 0% 
can you rephrase your question? It is a bit hard to understand what you&#39;re trying to accomplish, and what the problem is.
(04 Sep &#39;13, 13:43) Jasper ♦♦Hi Jasper, I have got a captured pcap of a mail transaction.</description>
    </item>
    
    <item>
      <title>Wireshark will not open on my Mac OS X 10.8 system HELP</title>
      <link>/questions/24366/wireshark-will-not-open-on-my-mac-os-x-108-system-help/</link>
      <pubDate>Wed, 04 Sep 2013 19:04:00 +0000</pubDate>
      
      <guid>/questions/24366/wireshark-will-not-open-on-my-mac-os-x-108-system-help/</guid>
      <description>Wireshark will not open on my Mac OS X 10.8 system HELP  0 First time user of Wireshark. I am a IT student at Penn State Word Campus. I downloaded Wireshark and also downloaded XQuartz. I tried to open Wireshark, but nothing happens. What&#39;s going on?
Please help
helpasked 04 Sep &#39;13, 19:04
raf5328
11●1●1●2
accept rate: 0%
Are there any messages about Wireshark in the Console app (it&#39;s in the Utilities folder under the Applications folder)?</description>
    </item>
    
    <item>
      <title>Extracting data from GTP protocol</title>
      <link>/questions/24370/extracting-data-from-gtp-protocol/</link>
      <pubDate>Wed, 04 Sep 2013 22:15:00 +0000</pubDate>
      
      <guid>/questions/24370/extracting-data-from-gtp-protocol/</guid>
      <description>Extracting data from GTP protocol  1 1Hello,
In the pcap file actual user data is passing through GTP-V1 tunnel.Since the file size is huge (10+GB) Wireshark is not the fastest option.
However, when I open the file with other tool, it does not detect any TCP data because it is encapsulated under GTP.
So , I am wondering if there are means to extract user data from each packet under GTP and form a separate file.</description>
    </item>
    
    <item>
      <title>Modbus TCP/IP</title>
      <link>/questions/24371/modbus-tcpip/</link>
      <pubDate>Thu, 05 Sep 2013 01:13:00 +0000</pubDate>
      
      <guid>/questions/24371/modbus-tcpip/</guid>
      <description>Modbus TCP/IP  0 how to read modbus tcp/ip slave device (192.167.1.3) ID = 1, holding register 45001 ?? its 16 bit register, if i can be also read only bit 3 as watching and analysing.
abodasked 05 Sep &#39;13, 01:13
Abdulrahman
11●1●1●3
accept rate: 0%
 edited 05 Sep &#39;13, 01:18 
can you please rephrase your question. It is unclear (at least to me) what you are asking for.</description>
    </item>
    
    <item>
      <title>&amp;quot;import hex dump&amp;quot; option in Tshark?</title>
      <link>/questions/24372/import-hex-dump-option-in-tshark/</link>
      <pubDate>Thu, 05 Sep 2013 03:55:00 +0000</pubDate>
      
      <guid>/questions/24372/import-hex-dump-option-in-tshark/</guid>
      <description>&amp;ldquo;import hex dump&amp;rdquo; option in Tshark?  0 GUI based wireshark provide &#34;import hex dump&#34;. Command based tshark provide &#34;import hex dump&#34; option? or even a similar function?
thanks.
hexdump tsharkasked 05 Sep &#39;13, 03:55
kingko
1●2●2●2
accept rate: 0%
  
One Answer:
  
0Yes, that&#39;s what text2pcap is for. It&#39;s another command-line tool that&#39;s part of the Wireshark suite.
answered 05 Sep &#39;13, 06:17
cmaynard ♦♦</description>
    </item>
    
    <item>
      <title>Receive only broadcast in mirrored port</title>
      <link>/questions/24374/receive-only-broadcast-in-mirrored-port/</link>
      <pubDate>Thu, 05 Sep 2013 04:34:00 +0000</pubDate>
      
      <guid>/questions/24374/receive-only-broadcast-in-mirrored-port/</guid>
      <description>Receive only broadcast in mirrored port  0 I&#39;m connected on a switch where my port receive traffic of another port monitored. I have tried Wireshark on my Window7 laptop and also with a Fedora LiveCD in another laptop. The only packets I see is broadcast multicast packets.
Also with other laptop and older version of Wireshark I get only broadcast and multicast packets or packets directed to the local pc.</description>
    </item>
    
    <item>
      <title>Change package string and install directory during wireshark build process</title>
      <link>/questions/24379/change-package-string-and-install-directory-during-wireshark-build-process/</link>
      <pubDate>Thu, 05 Sep 2013 07:25:00 +0000</pubDate>
      
      <guid>/questions/24379/change-package-string-and-install-directory-during-wireshark-build-process/</guid>
      <description>Change package string and install directory during wireshark build process  0 I am trying to build wireshark from source in ubuntu 12.04. I have successfully build it with changing the version by adding a version.conf file.Is it possible to change the package string and installation directory?If yes,please tell me the procedure.
source build wiresharkasked 05 Sep &#39;13, 07:25
swap
11●5●5●6
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>removing duplicate SIP messages</title>
      <link>/questions/24381/removing-duplicate-sip-messages/</link>
      <pubDate>Thu, 05 Sep 2013 09:11:00 +0000</pubDate>
      
      <guid>/questions/24381/removing-duplicate-sip-messages/</guid>
      <description>removing duplicate SIP messages  0 I am using a trace file from a SIP network and it contains duplicate SIP messages because multiple trace points are picking up the same SIP message as it travels from one SIP entity to another. Its not possible to filter using VLANs or using the TTL field, as suggested in an older post. From the &#34;Telepony&#34; tab, SIP option, Wireshark is able to tell me that there are 50 &#34;</description>
    </item>
    
    <item>
      <title>Windows Server 2012 network problems</title>
      <link>/questions/24384/windows-server-2012-network-problems/</link>
      <pubDate>Thu, 05 Sep 2013 10:11:00 +0000</pubDate>
      
      <guid>/questions/24384/windows-server-2012-network-problems/</guid>
      <description>Windows Server 2012 network problems  0 I have setup Wireshark to run on a Windows Server 2012 machine. When starting a capture my response times from my remote locations and local traffic return a TTL timeout with the capture nics address. Connections for my users stop. I have setup a span port on my Cisco 3750 stack and triple check my setup to make sure they are setup correctly. I have the latest version of Wireshark and WinPcap.</description>
    </item>
    
    <item>
      <title>Mac OS 10.6.8 Wireshark won&amp;#x27;t start</title>
      <link>/questions/24385/mac-os-1068-wireshark-wont-start/</link>
      <pubDate>Thu, 05 Sep 2013 10:27:00 +0000</pubDate>
      
      <guid>/questions/24385/mac-os-1068-wireshark-wont-start/</guid>
      <description>Mac OS 10.6.8 Wireshark won&amp;rsquo;t start  1 I just installed Wireshark on my MacBook Pro running 10.6.8. When I try to open Wireshark it closes immediately. Attempting to run it from the command line gives the error:
$ ./Applications/Wireshark.app/Contents/MacOS/Wireshark ...  dyld: Library not loaded: /usr/X11/lib/libcairo.2.dylib Referenced from: /Applications/Wireshark.app/Contents/Resources/bin/wireshark-bin Reason: Incompatible library version: wireshark-bin requires version 11003.0.0 or later, but libcairo.2.dylib provides version 10803.0.0Assistance?
macasked 05 Sep &amp;lsquo;13, 10:27</description>
    </item>
    
    <item>
      <title>NT Status: STATUS_UNSUCCESSFUL (0xc0000001)</title>
      <link>/questions/24386/nt-status-status_unsuccessful-0xc0000001/</link>
      <pubDate>Thu, 05 Sep 2013 10:55:00 +0000</pubDate>
      
      <guid>/questions/24386/nt-status-status_unsuccessful-0xc0000001/</guid>
      <description>NT Status: STATUS_UNSUCCESSFUL (0xc0000001)  0 trying to save a scanned file from a Canon copier running MEAP (Multifunctional Embedded Application Platform) to an SMB share on NetApp 2240 (C-Mode) generates a meaningless error on the copier.
Wireshark capture from the scanner side shows a successful 3 way handshake, then SMB protocol negotiation request which gets an error response from NetApp &#34;NT Status: STATUS_UNSUCCESSFUL (0xc0000001)&#34;
What would be an indication that the SMB request from the copier is non-Unicode ?</description>
    </item>
    
    <item>
      <title>How do you cross compile wireshark using MontaVista&amp;#x27;s tools?</title>
      <link>/questions/24394/how-do-you-cross-compile-wireshark-using-montavistas-tools/</link>
      <pubDate>Thu, 05 Sep 2013 12:27:00 +0000</pubDate>
      
      <guid>/questions/24394/how-do-you-cross-compile-wireshark-using-montavistas-tools/</guid>
      <description>How do you cross compile wireshark using MontaVista&amp;rsquo;s tools?  0 I&#39;m wanting to compile wireshark so I can use it on an ARM platform. I keep getting a configuration error &#34;Function &#39;socket&#39; not found.&#34;
I can do a ./configure with no options just fine and make and make install. But when I run the following command, it gives me that error:
CC=/opt/mv_pro_5.0.0/montavista/pro/devkit/arm/v5t_le/bin/arm_v5t_le-gcc ./configure --host=armv5tl-montavista-linux-gnueabi --prefix=/home/user/workdirHelp would be greatly appreciated!</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t install to 32-bit Win 7 machine</title>
      <link>/questions/24399/cant-install-to-32-bit-win-7-machine/</link>
      <pubDate>Thu, 05 Sep 2013 16:21:00 +0000</pubDate>
      
      <guid>/questions/24399/cant-install-to-32-bit-win-7-machine/</guid>
      <description>Can&amp;rsquo;t install to 32-bit Win 7 machine  0 I uninstalled my previous version (1.6.6) and am attempting to install the latest from the website.
On many of the installation files I get an &#34;unable to write to&#34; and then file name error message. All I can do is retry, abort or ignore. If I ignore, installation doesn&#39;t complete.
installationasked 05 Sep &#39;13, 16:21
greekgeek82
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Create a rule set from scratch based on wireshark capture</title>
      <link>/questions/24410/create-a-rule-set-from-scratch-based-on-wireshark-capture/</link>
      <pubDate>Fri, 06 Sep 2013 01:14:00 +0000</pubDate>
      
      <guid>/questions/24410/create-a-rule-set-from-scratch-based-on-wireshark-capture/</guid>
      <description>Create a rule set from scratch based on wireshark capture  0 Hello I&#39;m a new registered user to this site, but have already been using it from time to time when strange questions occured in the past :) So first, thank you for all the help already provided :)
I have been asked a strange question: some users are moving, and my management wonders why we couldn&#39;t capture network traffic on some user&#39;s computer during a day, and use all the data collected to produce a rule set that&#39;ll be pushed on the new firewall to come.</description>
    </item>
    
    <item>
      <title>Having problem with decoding Http Get request</title>
      <link>/questions/24413/having-problem-with-decoding-http-get-request/</link>
      <pubDate>Fri, 06 Sep 2013 01:18:00 +0000</pubDate>
      
      <guid>/questions/24413/having-problem-with-decoding-http-get-request/</guid>
      <description>Having problem with decoding Http Get request  0 Hi All,
I am facing an issue with customer network wherein when i request an HTTP/GET request it is going as a data payload in the TCP request to the server. due to this I am unable to do http based enhancements to the URL. The PSH, ACK flag is set and when I follow the TCP request i see it as a proper GET request</description>
    </item>
    
    <item>
      <title>Get value of node &amp;quot;hf_foo_flags&amp;quot;, &amp;quot;hf_camel_general&amp;quot;, ...etc...</title>
      <link>/questions/24416/get-value-of-node-hf_foo_flags-hf_camel_general-etc/</link>
      <pubDate>Fri, 06 Sep 2013 03:26:00 +0000</pubDate>
      
      <guid>/questions/24416/get-value-of-node-hf_foo_flags-hf_camel_general-etc/</guid>
      <description>Get value of node &amp;ldquo;hf_foo_flags&amp;rdquo;, &amp;ldquo;hf_camel_general&amp;rdquo;, &amp;hellip;etc&amp;hellip;  0 Hi all, I follow the guide of Developers (http://www.wireshark.org/download/docs/developer-guide-a4.pdf) and in the chapter 9, I&#39;m trying to understand the code structure of wireshark. In the code Example 9.8. &#34;Wrapping up the packet dissection&#34;, I see &#34;proto-register-foo(void)&#34; in which we have:
where &#34;hf_foo_flags&#34; is the index for this node. I wonder how we can get the value of this node, in other words, I want to export this value into text file and apply to all of those nodes.</description>
    </item>
    
    <item>
      <title>How to identify RTP delay</title>
      <link>/questions/24420/how-to-identify-rtp-delay/</link>
      <pubDate>Fri, 06 Sep 2013 05:07:00 +0000</pubDate>
      
      <guid>/questions/24420/how-to-identify-rtp-delay/</guid>
      <description>How to identify RTP delay  0 Hello Forum,
Assume following workflow, Client1 made a SIP call -&amp;gt; (network) -&amp;gt; clien2
We have encountered a delay in hearing the voice in client2. I have captured the RTP packets from Client1 and Client2. However I am not able to find a way to identify the delay by compering the RTP packets. May be I do not know how to do it. Please help me, how can I identify the delay by studying the packets.</description>
    </item>
    
    <item>
      <title>1.10.x with Lua</title>
      <link>/questions/24426/110x-with-lua/</link>
      <pubDate>Fri, 06 Sep 2013 07:41:00 +0000</pubDate>
      
      <guid>/questions/24426/110x-with-lua/</guid>
      <description>1.10.x with Lua  0 Is there a built version of 1.10.x with lua enabled? I have downloaded 1.10.2pre1-51630 on osx and it shows without Lua in the about dialog.
If I need to compile myself where can I find some documentstion
compile lua 1.10.0asked 06 Sep &#39;13, 07:41
Hoss
6●1●1●3
accept rate: 0%
I ended up installing 1.11.0-SVN-51797 and that at least works with my script.
(06 Sep &#39;13, 08:04) Hoss</description>
    </item>
    
    <item>
      <title>Diagnosing TCP Retransmission with ever increasing delays</title>
      <link>/questions/24429/diagnosing-tcp-retransmission-with-ever-increasing-delays/</link>
      <pubDate>Fri, 06 Sep 2013 08:25:00 +0000</pubDate>
      
      <guid>/questions/24429/diagnosing-tcp-retransmission-with-ever-increasing-delays/</guid>
      <description>Diagnosing TCP Retransmission with ever increasing delays  0 I&#39;m trying to diagnose some connectivity issues between a remote proxy (EZProxy) which is having trouble connecting to a load balanced webserver.
Looking at a tshark dump from the load balancer, I can see the initial SYN packet to establish a port 80 connection. This is swiftly followed by an Out-Of-Order SYN packet.
Then there&#39;s a sequence of 2 SYN retransmissions after 3 seconds, then again after a further 6 seconds, then 12, 24, 48 and then 96 seconds when finally I see an ACK and an HTTP request packet.</description>
    </item>
    
    <item>
      <title>Unknown user name and P/W</title>
      <link>/questions/24440/unknown-user-name-and-pw/</link>
      <pubDate>Fri, 06 Sep 2013 15:51:00 +0000</pubDate>
      
      <guid>/questions/24440/unknown-user-name-and-pw/</guid>
      <description>Unknown user name and P/W  0 I have an IP camera (IP-06-3) it is hard wired to my router when I connect to it using its IP address it asks for a user name and password I was given the camera so I do not know the answers. Using Wireshark Is it possible to discover the answers to the log on details or remove it so that I can access the camera.</description>
    </item>
    
    <item>
      <title>How to find the connection type of a network from Wireshark trace?</title>
      <link>/questions/24442/how-to-find-the-connection-type-of-a-network-from-wireshark-trace/</link>
      <pubDate>Sat, 07 Sep 2013 07:21:00 +0000</pubDate>
      
      <guid>/questions/24442/how-to-find-the-connection-type-of-a-network-from-wireshark-trace/</guid>
      <description>How to find the connection type of a network from Wireshark trace?  0 I&#39;m doing some analysis on a wireshark network trace. How to find the connection type of the underlying network? (eg: wireless)
Is it possible to obtain this information from packet analysis?
Thanks in advance.
Lasith.
lan packet wiresharkasked 07 Sep &#39;13, 07:21
Lasith Erand...
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Capture filter - tcpdump man page - syntax error?</title>
      <link>/questions/24448/capture-filter-tcpdump-man-page-syntax-error/</link>
      <pubDate>Sat, 07 Sep 2013 12:02:00 +0000</pubDate>
      
      <guid>/questions/24448/capture-filter-tcpdump-man-page-syntax-error/</guid>
      <description>Capture filter - tcpdump man page - syntax error?  0 I have found a capture filter in the tcpdump man page (and replicated in several other places) that does not make sense. The filter is:
tcp[tcpflags] &amp;amp; (tcp-syn|tcp-fin) != 0 and not src and dst 192.168
Unless I misunderstand - the last part (and not src and dst net) is incorrect. The &#34;not&#34; would only negate src - dst would not be negated.</description>
    </item>
    
    <item>
      <title>What does referer field not being present mean?</title>
      <link>/questions/24457/what-does-referer-field-not-being-present-mean/</link>
      <pubDate>Sun, 08 Sep 2013 15:04:00 +0000</pubDate>
      
      <guid>/questions/24457/what-does-referer-field-not-being-present-mean/</guid>
      <description>What does referer field not being present mean?  0 Hi everyone. I am kind of noob to wireshark so please bear with me for stupidity or obvious things. I am examining a network flow in WireShark which causes a drive by download. In some http (GET request) packets, the &#34;Referer&#34; field is not present. What does this mean? I mean how is the user getting to these pages? Is he/she entering it manually?</description>
    </item>
    
    <item>
      <title>chat sniffing</title>
      <link>/questions/24464/chat-sniffing/</link>
      <pubDate>Mon, 09 Sep 2013 00:21:00 +0000</pubDate>
      
      <guid>/questions/24464/chat-sniffing/</guid>
      <description>chat sniffing  0 how can i sniff chat through ip messanger in LAN connection?? i tried &#34;msnms&#34; commnand for this result but packets are not found. so tell me some proper suggestion..
:::;thankyou::::
ip messengerasked 09 Sep &#39;13, 00:21
john6
7●8●8●10
accept rate: 0%
 edited 09 Sep &#39;13, 01:46 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
1Simply put just filter for the corresponding TCP or UDP ports that belong to your chat applications protocol.</description>
    </item>
    
    <item>
      <title>VoIP analysis hardware</title>
      <link>/questions/24470/voip-analysis-hardware/</link>
      <pubDate>Mon, 09 Sep 2013 04:28:00 +0000</pubDate>
      
      <guid>/questions/24470/voip-analysis-hardware/</guid>
      <description>VoIP analysis hardware  -1 my othet project in wire shark is VoIP analysis...so plz tell me which hardware use for the VoIP anlaysis..give me particular hardware name radio analysis...
:::::::::::::thankyou:::::::::::::
hardware voip analysisasked 09 Sep &#39;13, 04:28
john6
7●8●8●10
accept rate: 0%
 edited 09 Sep &#39;13, 05:11 
grahamb ♦
19.8k●3●30●206
What exactly is your question ?
(09 Sep &#39;13, 05:00) Landi1which hardware use for VoIP anlaysis
I usually use a laptop.</description>
    </item>
    
    <item>
      <title>&amp;quot;user_dlt&amp;quot; option in tshark?</title>
      <link>/questions/24474/user_dlt-option-in-tshark/</link>
      <pubDate>Mon, 09 Sep 2013 05:03:00 +0000</pubDate>
      
      <guid>/questions/24474/user_dlt-option-in-tshark/</guid>
      <description>&amp;ldquo;user_dlt&amp;rdquo; option in tshark?  0 GUI based wireshark provide USER_DLT Encapsulation. Command based tshark provide same or even a similar option?
thanks.
user_dlt tsharkasked 09 Sep &#39;13, 05:03
kingko
1●2●2●2
accept rate: 0%
  
One Answer:
  
2Hi,
with tshark you can use the following command line as an example:
tshark.exe&amp;quot; -o &amp;quot;uat:user_dlts:\&amp;quot;User 15 (DLT=162)\&amp;quot;,\&amp;quot;payload protocol\&amp;quot;,\&amp;quot;header size\&amp;quot;,\&amp;quot;header protocol\&amp;quot;,\&amp;quot;trailer size\&amp;quot;,\&amp;quot;trailer protocol\&amp;quot;&amp;quot;answered 09 Sep &#39;13, 07:02
Pascal Quantin</description>
    </item>
    
    <item>
      <title>User monitoring</title>
      <link>/questions/24475/user-monitoring/</link>
      <pubDate>Mon, 09 Sep 2013 05:26:00 +0000</pubDate>
      
      <guid>/questions/24475/user-monitoring/</guid>
      <description>User monitoring  0 Hi,
I&#39;ve been asked to monitor/log the internet usage during work hours of about a dozen employees. I want to leave it capturing for a few days but don&#39;t want run out of memory/space.
My current idea is to capture only DNS traffic, which should give me most of what I need. Is there a better way to capture or a better app/method?
Thanks
monitoring userasked 09 Sep &#39;13, 05:26</description>
    </item>
    
    <item>
      <title>Decrypt SSL</title>
      <link>/questions/24488/decrypt-ssl/</link>
      <pubDate>Mon, 09 Sep 2013 09:31:00 +0000</pubDate>
      
      <guid>/questions/24488/decrypt-ssl/</guid>
      <description>Decrypt SSL  0 I am attempting to decrypt SSL and have the pem file included but I am not able to see the decrypted application data.
dissect_ssl enter frame #15 (first time) conversation = 0000000007C268B8, ssl_session = 0000000007C26EC8 record: offset = 0, reported_length_remaining = 458 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 453, ssl state 0x17 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 34543 found 0000000000000000 association_find: TCP port 443 found 0000000006CF10C0sslasked 09 Sep &#39;13, 09:31</description>
    </item>
    
    <item>
      <title>SSL Handshake Certificate hidden</title>
      <link>/questions/24489/ssl-handshake-certificate-hidden/</link>
      <pubDate>Mon, 09 Sep 2013 10:21:00 +0000</pubDate>
      
      <guid>/questions/24489/ssl-handshake-certificate-hidden/</guid>
      <description>SSL Handshake Certificate hidden  0 i cannot figure out why when i apply the filter ssl.handshake.certificate to a trace i see nothing and others in the same unit with the same trace see the packets. is there a setting to ignore or hide these packets?
ssl handshake hidden certificate opensslasked 09 Sep &#39;13, 10:21
mhumphries73
11●1●1●2
accept rate: 0%
  
3 Answers:
  
0Is your session using a well-known ssl port number like 443?</description>
    </item>
    
    <item>
      <title>Capturing packets on WAN link</title>
      <link>/questions/24491/capturing-packets-on-wan-link/</link>
      <pubDate>Mon, 09 Sep 2013 12:26:00 +0000</pubDate>
      
      <guid>/questions/24491/capturing-packets-on-wan-link/</guid>
      <description>Capturing packets on WAN link  0 How do I capture packets on WAN link and then figure out Latency?
latencyasked 09 Sep &#39;13, 12:26
Nube67
11●1●1●2
accept rate: 0%
two questions:
on the WAN link of what kind of device?Latency of the WAN link?(10 Sep &#39;13, 15:11) Kurt Knochner ♦   </description>
    </item>
    
    <item>
      <title>Memcache and TCP</title>
      <link>/questions/24495/memcache-and-tcp/</link>
      <pubDate>Mon, 09 Sep 2013 21:46:00 +0000</pubDate>
      
      <guid>/questions/24495/memcache-and-tcp/</guid>
      <description>Memcache and TCP  0 When I do a scan on Wireshark. The protocol Memcache comes up at least 100 times every second. Only responding and coming from my PC, none other on the network.
Also noticing (my computer only) that a lot of TCP protocols. lots, There are over 270,000 Protocols within 10 minutes, mostly belonging to TCP and Memcache.
Any help to what this could be would be appreciated, I think that this is the reason my network may be slower than it should be.</description>
    </item>
    
    <item>
      <title>Why would &amp;quot;TCP Full Window&amp;quot; happen?</title>
      <link>/questions/24501/why-would-tcp-full-window-happen/</link>
      <pubDate>Mon, 09 Sep 2013 22:30:00 +0000</pubDate>
      
      <guid>/questions/24501/why-would-tcp-full-window-happen/</guid>
      <description>Why would &amp;ldquo;TCP Full Window&amp;rdquo; happen?  0 I understand that &#34;TCP Full Window&#34; indicates that the sender is sending more data than receiver&#39;s advertised window size? But why would this happen? Shouldn&#39;t the sender just be able to send data &amp;lt;= receiver&#39;s window?
Or is it because wireshark see more data has been queued at the sender side? But how does wireshark know this? send buffer?
window fullasked 09 Sep &#39;13, 22:30</description>
    </item>
    
    <item>
      <title>What is x-flash-version in a HTTP header?</title>
      <link>/questions/24509/what-is-x-flash-version-in-a-http-header/</link>
      <pubDate>Tue, 10 Sep 2013 00:26:00 +0000</pubDate>
      
      <guid>/questions/24509/what-is-x-flash-version-in-a-http-header/</guid>
      <description>What is x-flash-version in a HTTP header?  0 I am analysing a PCAP file and it contains a field &#34;x-flash-version: 10,0,32,18&#34;. What is this field? Does it refer to the flash version on the PC? Where can I find more info about this field?
capture httpasked 10 Sep &#39;13, 00:26
TheRookieLea...
16●2●2●6
accept rate: 0%
  
One Answer:
  
2 Prior to the deprecation of the &#34;</description>
    </item>
    
    <item>
      <title>About Chinese Language Installation</title>
      <link>/questions/24511/about-chinese-language-installation/</link>
      <pubDate>Tue, 10 Sep 2013 00:53:00 +0000</pubDate>
      
      <guid>/questions/24511/about-chinese-language-installation/</guid>
      <description>About Chinese Language Installation  0 I hope to have Chinese installation package
languages chineseasked 10 Sep &#39;13, 00:53
sniperhalo
11●1●1●2
accept rate: 0%
  
One Answer:
  
1There is only an english version of Wireshark. Please read the following article for an explanation.
http://wiki.wireshark.org/Development/Translations
or in Chinese:
http://goo.gl/cBA7Ft
Regards
Kurt
answered 10 Sep &#39;13, 06:35
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15% 
 edited 10 Sep &#39;13, 07:08</description>
    </item>
    
    <item>
      <title>False FCS Error for frame packet size more than 64 bytes</title>
      <link>/questions/24525/false-fcs-error-for-frame-packet-size-more-than-64-bytes/</link>
      <pubDate>Tue, 10 Sep 2013 07:42:00 +0000</pubDate>
      
      <guid>/questions/24525/false-fcs-error-for-frame-packet-size-more-than-64-bytes/</guid>
      <description>False FCS Error for frame packet size more than 64 bytes  1 I am sorry if this is a repeated question regarding FCS Error. We are getting the FCS error for the frame packet size more than 64 bytes. Frame check sequence: 0x4a495453 [incorrect, should be 0xd7636502]
In our ethernet driver there is an option to Make sure the driver does not transmit packet less than minimum(i.e 64 bytes) as per the Ethernet standards.</description>
    </item>
    
    <item>
      <title>decrypt TCP</title>
      <link>/questions/24542/decrypt-tcp/</link>
      <pubDate>Tue, 10 Sep 2013 16:19:00 +0000</pubDate>
      
      <guid>/questions/24542/decrypt-tcp/</guid>
      <description>decrypt TCP  -1 Hello i have capture a TCP packet which contains an ecrypted message cause im trying to learn any good advise???
michaelasked 10 Sep &#39;13, 16:19
michaelondon
10●1●1●3
accept rate: 0%
 edited 10 Sep &#39;13, 20:03 
And what exactly is your question you are asking the wireshark community?
(11 Sep &#39;13, 04:22) mrEEde   </description>
    </item>
    
    <item>
      <title>Using Sum (*) with tcp.seq</title>
      <link>/questions/24543/using-sum-with-tcpseq/</link>
      <pubDate>Tue, 10 Sep 2013 21:00:00 +0000</pubDate>
      
      <guid>/questions/24543/using-sum-with-tcpseq/</guid>
      <description>Using Sum (*) with tcp.seq  0 hello,
If i am using sum(*) function on tcp.seq to graph out tcp sequence number, my y axis values are not equal to corresponding packet sequence number (adding Ack sequence number into it). Any suggestions why or am i missing something?
graphasked 10 Sep &#39;13, 21:00
iWireshark
16●5●5●7
accept rate: 0%
  
One Answer:
  
1When using the advanced options in IO graphs, wireshark will use the function you specify on the field you specify for all packets that fall within the tick interval.</description>
    </item>
    
    <item>
      <title>Resolving protocol names in custom tshark display filter</title>
      <link>/questions/24544/resolving-protocol-names-in-custom-tshark-display-filter/</link>
      <pubDate>Tue, 10 Sep 2013 21:54:00 +0000</pubDate>
      
      <guid>/questions/24544/resolving-protocol-names-in-custom-tshark-display-filter/</guid>
      <description>Resolving protocol names in custom tshark display filter  0 I want to parse the standard header outputs of tshark. Since the default doesn&#39;t work, I am using a custom field parser that does almost the same thing. What I am missing is the resolution of the name of the protocol. My command is:
sudo tshark -b 256 -P -T fields -e frame.time_epoch -e ip.src -e ip.dst -e ip.proto -e ip.</description>
    </item>
    
    <item>
      <title>text2Pcap :- add/modify ip address. by default it keeps dummy header/existing ip address.</title>
      <link>/questions/24547/text2pcap-addmodify-ip-address-by-default-it-keeps-dummy-headerexisting-ip-address/</link>
      <pubDate>Tue, 10 Sep 2013 22:32:00 +0000</pubDate>
      
      <guid>/questions/24547/text2pcap-addmodify-ip-address-by-default-it-keeps-dummy-headerexisting-ip-address/</guid>
      <description>text2Pcap :- add/modify ip address. by default it keeps dummy header/existing ip address.  0 Hello, How can we add/modify ip address of pcap that is generated by text2pcap? which switch/parameter to use ?
text2pcap ip addressasked 10 Sep &#39;13, 22:32
cbhatt
11●1●1●2
accept rate: 0%
  
One Answer:
  
2I&#39;m not sure I understand your question correctly, but if you have a text file that you convert to pcap you can just edit the text file before converting it.</description>
    </item>
    
    <item>
      <title>How to see sequence of parameters for NBAP protocol?</title>
      <link>/questions/24551/how-to-see-sequence-of-parameters-for-nbap-protocol/</link>
      <pubDate>Wed, 11 Sep 2013 01:11:00 +0000</pubDate>
      
      <guid>/questions/24551/how-to-see-sequence-of-parameters-for-nbap-protocol/</guid>
      <description>How to see sequence of parameters for NBAP protocol?  0 Hi,
I have using NBAP (using IP stack over SCTP), I have some wireshark traces, but not able to find exact sequence of data I need to add to created desired packet.
dissector packetasked 11 Sep &#39;13, 01:11
pranitkothari
51●5●6●10
accept rate: 100%
I don&#39;t understand your question, you have NBAP over SCTP but when looking at the trace you only see the SCTP layer + data?</description>
    </item>
    
    <item>
      <title>wslua_count_plugins error</title>
      <link>/questions/24552/wslua_count_plugins-error/</link>
      <pubDate>Wed, 11 Sep 2013 02:49:00 +0000</pubDate>
      
      <guid>/questions/24552/wslua_count_plugins-error/</guid>
      <description>wslua_count_plugins error  0 Hi,
I am trying to compile from the SVN and everything has completed perfectly but when I try to run WireShark I get the following error:
wireshark: symbol lookup error: wireshark: undefined symbol: wslua_count_plugin
Has anyone encountered this at all?
compile source errorsasked 11 Sep &#39;13, 02:49
tmacuk
1●1●1●1
accept rate: 0%
How are you running Wireshark, from the wireshark-gtk directory created during the build, or from an installed version using an installer that you&#39;ve also built?</description>
    </item>
    
    <item>
      <title>[SOLVED] How to build &amp;quot;Wireshark for Linux version&amp;quot; on Windows</title>
      <link>/questions/24553/solved-how-to-build-wireshark-for-linux-version-on-windows/</link>
      <pubDate>Wed, 11 Sep 2013 02:54:00 +0000</pubDate>
      
      <guid>/questions/24553/solved-how-to-build-wireshark-for-linux-version-on-windows/</guid>
      <description>[SOLVED] How to build &amp;ldquo;Wireshark for Linux version&amp;rdquo; on Windows  0 Hi all, I&#39;m trying to build Wireshark on Windows Enviroment. I have already finished the Wireshark Windows version by using nmake and now I&#39;m going to build Linux version. I have some questions to ask:
Can I build the Wireshark for Linux version on Windows OS? because I don&#39;t have server installed Linux right now and one more reason is that my PC already had installed build environment which is quite complicated to prepare.</description>
    </item>
    
    <item>
      <title>Additional L2TPv3 decode for Cable Television Laboratories AVPs</title>
      <link>/questions/24568/additional-l2tpv3-decode-for-cable-television-laboratories-avps/</link>
      <pubDate>Wed, 11 Sep 2013 05:58:00 +0000</pubDate>
      
      <guid>/questions/24568/additional-l2tpv3-decode-for-cable-television-laboratories-avps/</guid>
      <description>Additional L2TPv3 decode for Cable Television Laboratories AVPs  0 Document &#34;CM-SP-DEPI-I08-100611.pdf&#34;, which is available from: link text
Defines most AVPs used in the LTTPv3 SLI messages. It would be great if Wireshark could do a parse of these messages instead of indicating &#34;Vendor-Specific AVP&#34;.
parsingasked 11 Sep &#39;13, 05:58
Dave C
11●1●1●2
accept rate: 0%
  
One Answer:
  
1Raise an enhancment bug including a example trace and a link to the specification.</description>
    </item>
    
    <item>
      <title>Malformed NORM packets</title>
      <link>/questions/24577/malformed-norm-packets/</link>
      <pubDate>Wed, 11 Sep 2013 08:15:00 +0000</pubDate>
      
      <guid>/questions/24577/malformed-norm-packets/</guid>
      <description>Malformed NORM packets  0 When I do a capture using the NORM protocol I receive an error message saying that my CMD CC packets are malformed. I believe I’ve narrowed the problem down to the Congestion Control subtree. When it reaches the Congestion Control part, Wireshark creates hundreds of Congestion Control subtrees filled completely with zeroes, creating a bigger packet than Wireshark is expecting. Here is the section of the code that dissects NORM cmd(cc) packets:</description>
    </item>
    
    <item>
      <title>Cannot receive UDP packet from microcontroller</title>
      <link>/questions/24587/cannot-receive-udp-packet-from-microcontroller/</link>
      <pubDate>Wed, 11 Sep 2013 11:50:00 +0000</pubDate>
      
      <guid>/questions/24587/cannot-receive-udp-packet-from-microcontroller/</guid>
      <description>Cannot receive UDP packet from microcontroller  0 I&#39;m currently working on a UDP communication PC &amp;lt;-&amp;gt; ATmega16 (Atmel microcontroller) through the Ethernet. The ATmega16 controls the ENC28J60 (Ethernet module) through SPI. On the PC there is an application that simulates a UDP server/client.
When the packet is sent from the PC to the ATmega16, the packet is received without errors, but when the ATmega16A sends the UDP packet back to the PC, the packet is lost somewhere (the application doesn’t receive it).</description>
    </item>
    
    <item>
      <title>Displaying gaps or drops in private UDP sequence numbers</title>
      <link>/questions/24594/displaying-gaps-or-drops-in-private-udp-sequence-numbers/</link>
      <pubDate>Wed, 11 Sep 2013 16:09:00 +0000</pubDate>
      
      <guid>/questions/24594/displaying-gaps-or-drops-in-private-udp-sequence-numbers/</guid>
      <description>Displaying gaps or drops in private UDP sequence numbers  0 I&#39;ve seen several topics here that relate to this issue, but none of the solutions have worked for me so far, so hopefully someone can point out where I&#39;m going wrong.
I have a capture with 4 separate UDP streams being received on 4 well known ports, 30300 - 30303.
The UDP packets have a private &#34;sequence number&#34; that increments monotonically for each port.</description>
    </item>
    
    <item>
      <title>epan_dissect_t not being passed to stats_tree correctly</title>
      <link>/questions/24595/epan_dissect_t-not-being-passed-to-stats_tree-correctly/</link>
      <pubDate>Wed, 11 Sep 2013 16:44:00 +0000</pubDate>
      
      <guid>/questions/24595/epan_dissect_t-not-being-passed-to-stats_tree-correctly/</guid>
      <description>epan_dissect_t not being passed to stats_tree correctly  0 I&#39;ve written a protocol dissector plugin for a protocol that uses CORBA for some of its communication. This protocol can send objects that can have any number of member variables and each object has a 64bit id. I have a text file with an text name and ID mapping. I&#39;m able to correctly identify the messages in wireshark during dissection.
I&#39;m trying to to do a stats_tree for this protocol to identify the different object types received.</description>
    </item>
    
    <item>
      <title>Does RTP player decode a 180 Ringing into audible ring back tone?</title>
      <link>/questions/24610/does-rtp-player-decode-a-180-ringing-into-audible-ring-back-tone/</link>
      <pubDate>Thu, 12 Sep 2013 09:12:00 +0000</pubDate>
      
      <guid>/questions/24610/does-rtp-player-decode-a-180-ringing-into-audible-ring-back-tone/</guid>
      <description>Does RTP player decode a 180 Ringing into audible ring back tone?  0 Hi,
The call I am tracing is supposed to use the 180 Ringing SIP message to indicate to the caller that the callee has recevied the invite, and the caller can play ring back tone to the caller&#39;s speaker. This call should not be sending the ring back tone encoded as audio into RTP. When using the RTP player utility to decode the call audio, the player plays out a ring back tone as part of the audio decocde.</description>
    </item>
    
    <item>
      <title>WiFi Display (Miracast) Dissector</title>
      <link>/questions/24611/wifi-display-miracast-dissector/</link>
      <pubDate>Thu, 12 Sep 2013 09:53:00 +0000</pubDate>
      
      <guid>/questions/24611/wifi-display-miracast-dissector/</guid>
      <description>WiFi Display (Miracast) Dissector  0 Hello, I was capturing WLAN packets and analyzing them with Wireshark (1.10.2). I noticed that under IEEE 802.11, Tagged Parameters, I saw the following: Wi-FiAll: P2P Wi-FiAll
For the Wi-FiAll: P2P values are tag number = 221 OUI = 50-6f-9a OUI type = 9
For the Wi-FiAll values are tag number = 221 OUI = 50-6f-9a OUI type = 10 According to the WiFi Display specification, the OUI type of 10 should be WiFi Display.</description>
    </item>
    
    <item>
      <title>What does SLL stand for (as in the context of Linux &amp;quot;cooked&amp;quot; headers)?</title>
      <link>/questions/24613/what-does-sll-stand-for-as-in-the-context-of-linux-cooked-headers/</link>
      <pubDate>Thu, 12 Sep 2013 12:47:00 +0000</pubDate>
      
      <guid>/questions/24613/what-does-sll-stand-for-as-in-the-context-of-linux-cooked-headers/</guid>
      <description>What does SLL stand for (as in the context of Linux &amp;ldquo;cooked&amp;rdquo; headers)?  0 What does SLL stand for? On the Wireshark SLL wiki page, it states that,
For those who are curious, &#34;SLL&#34; stands for &#34;sockaddr_ll&#34;&#34;, but then goes on to say:
This means that information such as the link-layer protocol&#39;s packet type field, if any, isn&#39;t available, so libpcap constructs a synthetic link-layer [emphasis added] header from the address supplied when it does a recvfrom() on the socket.</description>
    </item>
    
    <item>
      <title>Help with wireshark please</title>
      <link>/questions/24619/help-with-wireshark-please/</link>
      <pubDate>Thu, 12 Sep 2013 18:51:00 +0000</pubDate>
      
      <guid>/questions/24619/help-with-wireshark-please/</guid>
      <description>Help with wireshark please  0 Hello,
I am new to Wireshark and need some help.
I have been looking for a tool that can track my network internet usage.. (I.e. what each device is doing and how much data its using)
I was told about wireshark and they it does what I am after, but I am having trouble with working out how to view what I need to.</description>
    </item>
    
    <item>
      <title>missing transmitted packets</title>
      <link>/questions/24621/missing-transmitted-packets/</link>
      <pubDate>Thu, 12 Sep 2013 20:59:00 +0000</pubDate>
      
      <guid>/questions/24621/missing-transmitted-packets/</guid>
      <description>missing transmitted packets  0 I collected the tftp traces at the source network interface using wireshark while downloading a software to destination. When I analysed the TFTP traces I could see missing transmitted packets from the source but could see acknowledgement from the destination. Why is that? Why it couldn&#39;t capture the transmitted packets? Is there any thing wrong in the setting? Are the transmitted packets too fast to capture?</description>
    </item>
    
    <item>
      <title>How to understand &amp;quot;TCP ACKed lost segment&amp;quot; sign</title>
      <link>/questions/24623/how-to-understand-tcp-acked-lost-segment-sign/</link>
      <pubDate>Fri, 13 Sep 2013 00:08:00 +0000</pubDate>
      
      <guid>/questions/24623/how-to-understand-tcp-acked-lost-segment-sign/</guid>
      <description>How to understand &amp;ldquo;TCP ACKed lost segment&amp;rdquo; sign  0 I did a iperf testing between two virtual machines on the same hardware computer. There are lot of &#34;TCP ACKed lost segment&#34; segment displayed. What does this message mean? For example, host A &amp;amp; B
A send sequence 1000 (1byte) to BB acked 1001 with &#34;TCP ACKed lost segment&#34; signDoes it mean that B actually do get the sequence byte 1000 from the perspective of TCP stack, but wireshark didn&#39;t capture sequence 1000 byte?</description>
    </item>
    
    <item>
      <title>[SOLVED] Missing Lib of Socket while building Wireshark</title>
      <link>/questions/24630/solved-missing-lib-of-socket-while-building-wireshark/</link>
      <pubDate>Fri, 13 Sep 2013 02:34:00 +0000</pubDate>
      
      <guid>/questions/24630/solved-missing-lib-of-socket-while-building-wireshark/</guid>
      <description>[SOLVED] Missing Lib of Socket while building Wireshark  0 Hi all, I&#39;m adding a program of socket processing into WireShark source code in order to send data to server. I wrote a C program by Visual Studio 2010 and it runs well with the library for socket as below
But when I add it into Wireshark, there are many errors related to missing lib as shown below
I don&#39;t know how to fix these errors, do we have anything to replace &#34;</description>
    </item>
    
    <item>
      <title>Losing connection with weird behavior.</title>
      <link>/questions/24631/losing-connection-with-weird-behavior/</link>
      <pubDate>Fri, 13 Sep 2013 02:34:00 +0000</pubDate>
      
      <guid>/questions/24631/losing-connection-with-weird-behavior/</guid>
      <description>Losing connection with weird behavior.  0 My game client loses connection from my game server intermittently. (about 0.2% per minute) When connection is dropped, my client received a error code 10053(connaborted) usually.
The number of user is about 100k, so about 200 users are dropped per minute.
I should find the cause, but can&#39;t find the root cause.
Now I have written code to work aroud this problem. When my client detects losing connection, my client tries to connect again.</description>
    </item>
    
    <item>
      <title>How to add &amp;quot;Data rate&amp;quot; columns to display on wireshark?</title>
      <link>/questions/24633/how-to-add-data-rate-columns-to-display-on-wireshark/</link>
      <pubDate>Fri, 13 Sep 2013 02:50:00 +0000</pubDate>
      
      <guid>/questions/24633/how-to-add-data-rate-columns-to-display-on-wireshark/</guid>
      <description>How to add &amp;ldquo;Data rate&amp;rdquo; columns to display on wireshark?  0 I know how to add a new column but I don&#39;t know the field name of data rate. Thanks in advanced!
ratetal dataasked 13 Sep &#39;13, 02:50
kaisan
1●1●1●1
accept rate: 0%
I PrtSc the picture I saw and marked it yellow. Still waiting for the answer&amp;lt;(__)&amp;gt;
(16 Sep &#39;13, 20:24) kaisanStill waiting for the answer&amp;lt;
see the UPDATE in my answer.</description>
    </item>
    
    <item>
      <title>can wireshark evaluate the performance of different versions of TCP</title>
      <link>/questions/24638/can-wireshark-evaluate-the-performance-of-different-versions-of-tcp/</link>
      <pubDate>Fri, 13 Sep 2013 03:06:00 +0000</pubDate>
      
      <guid>/questions/24638/can-wireshark-evaluate-the-performance-of-different-versions-of-tcp/</guid>
      <description>can wireshark evaluate the performance of different versions of TCP  0 sir how to find different vesions of TCP using Wireshark and how to compare the diffrent versions of TCP performance using wireshark pls help
tcpasked 13 Sep &#39;13, 03:06
shaziya islam
11●4●4●5
accept rate: 0%
  
One Answer:
  
3Yes, you can compare different TCP stack types (I guess that&#39;s what you mean with &#34;</description>
    </item>
    
    <item>
      <title>Capture traffic from printer to smtp relay</title>
      <link>/questions/24645/capture-traffic-from-printer-to-smtp-relay/</link>
      <pubDate>Fri, 13 Sep 2013 06:53:00 +0000</pubDate>
      
      <guid>/questions/24645/capture-traffic-from-printer-to-smtp-relay/</guid>
      <description>Capture traffic from printer to smtp relay  0 Hi all, I&#39;ve been searching online for some help to this, but so far I haven&#39;t found an answer (or at least I have not recognized the answer).
I have a MFP (mock IP 192.168.0.20) and a SMTP relay which is setup on our DC/print server (mock IP 192.168.0.10). I&#39;ve installed wireshark and winpcap on the DC/print server.
I&#39;m trying to configure the MFP for scan to email using the SMTP relay on the DC/print server which is pointing to a Office 365 SMTP server.</description>
    </item>
    
    <item>
      <title>How to determine it&amp;#x27;s a switch problem using wireshark.</title>
      <link>/questions/24646/how-to-determine-its-a-switch-problem-using-wireshark/</link>
      <pubDate>Fri, 13 Sep 2013 06:56:00 +0000</pubDate>
      
      <guid>/questions/24646/how-to-determine-its-a-switch-problem-using-wireshark/</guid>
      <description>How to determine it&amp;rsquo;s a switch problem using wireshark.  -1 Hi There, Network background: I got a call from a company to troubleshoot many issues including poor connectivity in sections of their office. The network setup was pretty simple, ISP to router, router to cisco smb 200 managed switch, from it an up link to another cisco smb 16 port switch (not managed) in another room, and finally from it an uplink to another cisco sbm 200 switch in another room (not managed).</description>
    </item>
    
    <item>
      <title>Wireshark protocol definition capability</title>
      <link>/questions/24658/wireshark-protocol-definition-capability/</link>
      <pubDate>Fri, 13 Sep 2013 14:00:00 +0000</pubDate>
      
      <guid>/questions/24658/wireshark-protocol-definition-capability/</guid>
      <description>Wireshark protocol definition capability  0 Subject: Wireshark protocol definition capability I have a question about using Wireshark to capture/decode what I would call application packets inside of TCP or UDP packets. I am working on an enterprise messaging protocol standard that would use the TCP or UDP data payload to transport structured messages between any number of servers. I&#39;m anticipating that if Wireshark can support filter captures of this kind of enterprise messaging that enterprise conversations might be able to be captured and decoded.</description>
    </item>
    
    <item>
      <title>How does wireshark get Rate and channel for 802.11 WLAN packets in a pcap file?</title>
      <link>/questions/24662/how-does-wireshark-get-rate-and-channel-for-80211-wlan-packets-in-a-pcap-file/</link>
      <pubDate>Fri, 13 Sep 2013 16:41:00 +0000</pubDate>
      
      <guid>/questions/24662/how-does-wireshark-get-rate-and-channel-for-80211-wlan-packets-in-a-pcap-file/</guid>
      <description>How does wireshark get Rate and channel for 802.11 WLAN packets in a pcap file?  0 The file format in http://wiki.wireshark.org/Development/LibpcapFileFormat has no field for rate or channel of the packets sniffed, i was wondering how wireshark extracts that information. Also please point me to how wireshark calculates the FCS for each packet.
Thank you.
wlan_rate_pcapasked 13 Sep &#39;13, 16:41
emma
6●2●2●4
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>tcp variants(reno,westwood,bic)</title>
      <link>/questions/24666/tcp-variantsrenowestwoodbic/</link>
      <pubDate>Fri, 13 Sep 2013 21:34:00 +0000</pubDate>
      
      <guid>/questions/24666/tcp-variantsrenowestwoodbic/</guid>
      <description>tcp variants(reno,westwood,bic)  0 sir i asked about that how to evaluate the performance of different variants of TCP ie. like reno ,westwood ,bic etc sir pls help how to differentiate between these variants and how to evaluate the performance of individual variant like for reno throughput and rtt graph plsss help
tcpasked 13 Sep &#39;13, 21:34
shaziya islam
11●4●4●5
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>What happenes when you dump packets from .pcap file ?</title>
      <link>/questions/24667/what-happenes-when-you-dump-packets-from-pcap-file/</link>
      <pubDate>Fri, 13 Sep 2013 22:31:00 +0000</pubDate>
      
      <guid>/questions/24667/what-happenes-when-you-dump-packets-from-pcap-file/</guid>
      <description>What happenes when you dump packets from .pcap file ?  0 i have .pcap file having total 3471 packets , after doing mpeg-ts dump (listener in lua script) it have 5033 packets.. in my output.pcap file can anyone explain this please ?
dumpasked 13 Sep &#39;13, 22:31
pvv
1●1●1●2
accept rate: 0%
 edited 14 Sep &#39;13, 02:33 
Sorry, but you need to explain in more detail what you did.</description>
    </item>
    
    <item>
      <title>count number of submit_sm counts per second</title>
      <link>/questions/24679/count-number-of-submit_sm-counts-per-second/</link>
      <pubDate>Sat, 14 Sep 2013 07:17:00 +0000</pubDate>
      
      <guid>/questions/24679/count-number-of-submit_sm-counts-per-second/</guid>
      <description>count number of submit_sm counts per second  0 Hi all, I have been using wireshark for quite some time..However i am stuck at a place where the requirement is to count the number of Submit_sm packets(SMPP) per second from a tcpdump of 1 hour(30min,15min) to know the TPS(Transactions per second) at which my application is hitting the SMSC. Please suggest me if there is a way out
smppasked 14 Sep &#39;13, 07:17</description>
    </item>
    
    <item>
      <title>how to let wireshark to demonstrates the country name when plot ip addresses</title>
      <link>/questions/24682/how-to-let-wireshark-to-demonstrates-the-country-name-when-plot-ip-addresses/</link>
      <pubDate>Sat, 14 Sep 2013 08:19:00 +0000</pubDate>
      
      <guid>/questions/24682/how-to-let-wireshark-to-demonstrates-the-country-name-when-plot-ip-addresses/</guid>
      <description>how to let wireshark to demonstrates the country name when plot ip addresses  0 As we know, Wireshark has the capability to plot ip addresses on the world map if we configured it with GEOIP database files. It does shows the ip addresses on the map when I click on Statistics-&amp;gt;Endpoints-&amp;gt;IPv4-&amp;gt;MAP, but it does not show country names for the specific ip addresses which it has resolved successfully(I can see the exact country names in the country column of IPv4 tab), why doesn&#39;t it show that on the map too?</description>
    </item>
    
    <item>
      <title>Why would a client not send the [ACK] after receiving the [SYN, ACK] for a TCP handshake and this problem affect multiple clients?</title>
      <link>/questions/24683/why-would-a-client-not-send-the-ack-after-receiving-the-syn-ack-for-a-tcp-handshake-and-this-problem-affect-multiple-clients/</link>
      <pubDate>Sat, 14 Sep 2013 10:05:00 +0000</pubDate>
      
      <guid>/questions/24683/why-would-a-client-not-send-the-ack-after-receiving-the-syn-ack-for-a-tcp-handshake-and-this-problem-affect-multiple-clients/</guid>
      <description>Why would a client not send the [ACK] after receiving the [SYN, ACK] for a TCP handshake and this problem affect multiple clients?  0 I have been investigating a &#34;slow&#34; application complaint. When the issue happens I&#39;ve been told it affects everyone. I did a Wireshark capture on the server and one client. On the server, I saw the [SYN],[SYN, ACK] but no [ACK] when the problem started. I went back to a capture on the client and saw the [SYN], [SYN, ACK] and no [ACK] sent.</description>
    </item>
    
    <item>
      <title>TCP packet length was much greater than MTU</title>
      <link>/questions/24699/tcp-packet-length-was-much-greater-than-mtu/</link>
      <pubDate>Sat, 14 Sep 2013 19:23:00 +0000</pubDate>
      
      <guid>/questions/24699/tcp-packet-length-was-much-greater-than-mtu/</guid>
      <description>TCP packet length was much greater than MTU  0 I am a newbie with TCP, MTU (which I have to play around with) and Wireshark. I sent some data that was over 100k over tcp and used Wireshark to view and confirm the data that I sent. I assume each Wireshark frame corresponds to a TCP segment, am I correct? I noticed the length of some of the frames were 1514, which looked correct, because MTU was 1500 plus some bytes for headers.</description>
    </item>
    
    <item>
      <title>Handling TCP Retransmission in a Wireshark Dissector</title>
      <link>/questions/24701/handling-tcp-retransmission-in-a-wireshark-dissector/</link>
      <pubDate>Sat, 14 Sep 2013 20:20:00 +0000</pubDate>
      
      <guid>/questions/24701/handling-tcp-retransmission-in-a-wireshark-dissector/</guid>
      <description>Handling TCP Retransmission in a Wireshark Dissector  0 I&#39;m working with a Wireshark dissector that interprets an application layer protocol built on top of TCP.
I&#39;m trying to fix a bug in the dissector in which it is trying to reassemble a packet with a TCP retransmitted packet. The retransmitted packet should be ignored because the original has already been dissected.
I&#39;ve stepped through with gdb and looked at the contents of pinfo and pinfo-&amp;gt;fd related to the retransmitted packet, but I couldn&#39;t find anything indicating that it is a retransmission.</description>
    </item>
    
    <item>
      <title>sniff ip messanger chat in LAN connection</title>
      <link>/questions/24703/sniff-ip-messanger-chat-in-lan-connection/</link>
      <pubDate>Sat, 14 Sep 2013 22:21:00 +0000</pubDate>
      
      <guid>/questions/24703/sniff-ip-messanger-chat-in-lan-connection/</guid>
      <description>sniff ip messanger chat in LAN connection  -3 i tried t sniff ip messanger chat using &#34;msnms&#34; command in wireshark....but noone packets shown...plz give me some proper way to sniff chat of ip messanger in LAN connection...i have submit this project in 2 days... if any technique for this project then mail me on &#34;[email protected]&#34;...
::::::thankyou:::::::
sniffing chatasked 14 Sep &#39;13, 22:21
john6
7●8●8●10
accept rate: 0%
 edited 15 Sep &#39;13, 01:08</description>
    </item>
    
    <item>
      <title>File -&amp;gt; Save As function</title>
      <link>/questions/24704/file-save-as-function/</link>
      <pubDate>Sat, 14 Sep 2013 23:02:00 +0000</pubDate>
      
      <guid>/questions/24704/file-save-as-function/</guid>
      <description>File -&amp;gt; Save As function  0 I currently have Wireshark version 1.10.1 and the File -&amp;gt; Save As funtion does not have the features of Selected Packets, Displayed Packets, Range, etc. in order to save filtered packets; it only has the most basic Save As dialog box. This forces me to save the entire array of packet captures to a .pcap file, which may be much larger than what I want.</description>
    </item>
    
    <item>
      <title>[Wireshark-bugs] [Bug 8395] IPsec ESP: add AES-GCM decryption</title>
      <link>/questions/24715/wireshark-bugs-bug-8395-ipsec-esp-add-aes-gcm-decryption/</link>
      <pubDate>Sun, 15 Sep 2013 06:31:00 +0000</pubDate>
      
      <guid>/questions/24715/wireshark-bugs-bug-8395-ipsec-esp-add-aes-gcm-decryption/</guid>
      <description>[Wireshark-bugs] [Bug 8395] IPsec ESP: add AES-GCM decryption  0 I noticed that for AES256, 36 bytes should be supplied as a key (instead of 32 bytes). What is the origin of the extra 4 bytes? And in general, what is the format that should be given for such decryption key?
decryption aes gcmasked 15 Sep &#39;13, 06:31
YuvalAdler
11●1●1●3
accept rate: 0%
I noticed that for AES256, 36 bytes should be supplied as a key (instead of 32 bytes).</description>
    </item>
    
    <item>
      <title>Good source of publicly-available packet captures of 3GPP call flows?</title>
      <link>/questions/24717/good-source-of-publicly-available-packet-captures-of-3gpp-call-flows/</link>
      <pubDate>Sun, 15 Sep 2013 08:59:00 +0000</pubDate>
      
      <guid>/questions/24717/good-source-of-publicly-available-packet-captures-of-3gpp-call-flows/</guid>
      <description>Good source of publicly-available packet captures of 3GPP call flows?  0 I figured I&#39;d make a shout-out request here since I haven&#39;t been able to find a good source of packet capture files for 3GPP call flows, particularly for EPS. I want them as a supplement to a video series I&#39;m putting together on the EPC, and since I plan to make the series public domain I&#39;m restricted from using all the NDA-protected captures I would normally have access to.</description>
    </item>
    
    <item>
      <title>Decrypt wifi/wlan packets when knowing the shared key</title>
      <link>/questions/24724/decrypt-wifiwlan-packets-when-knowing-the-shared-key/</link>
      <pubDate>Sun, 15 Sep 2013 14:35:00 +0000</pubDate>
      
      <guid>/questions/24724/decrypt-wifiwlan-packets-when-knowing-the-shared-key/</guid>
      <description>Decrypt wifi/wlan packets when knowing the shared key  0 I know the key which is used to connect to the wifi. When I type that key in edit-&amp;gt;preferences-&amp;gt;protocol as wp-psw, only the packets which are coming in or from my computer are decrypted. What I need to do in order to decrypt all the packets?
decryption wifi wlanasked 15 Sep &#39;13, 14:35
tttttttttttt2
34●7●9●12
accept rate: 0%
 edited 15 Sep &#39;13, 15:11</description>
    </item>
    
    <item>
      <title>How to get data inside proto_tree *tree</title>
      <link>/questions/24732/how-to-get-data-inside-proto_tree-tree/</link>
      <pubDate>Sun, 15 Sep 2013 21:25:00 +0000</pubDate>
      
      <guid>/questions/24732/how-to-get-data-inside-proto_tree-tree/</guid>
      <description>How to get data inside proto_tree *tree  0 Hi all, I&#39;m looking for a way to get the value inside proto_tree *tree. As i understand, the proto_tree * tree is defined to archive all information which were dissect-ed when it goes through the main program as shown in this figure
After that, all further processes would be done with this tree. So, I wonder how to get the value, information from tree.</description>
    </item>
    
    <item>
      <title>[SOLVED] How to generate Wireshark Binary package for Linux</title>
      <link>/questions/24736/solved-how-to-generate-wireshark-binary-package-for-linux/</link>
      <pubDate>Mon, 16 Sep 2013 01:23:00 +0000</pubDate>
      
      <guid>/questions/24736/solved-how-to-generate-wireshark-binary-package-for-linux/</guid>
      <description>[SOLVED] How to generate Wireshark Binary package for Linux  0 Hi all, I read the developer guide , chapter 3.12 &#34;Binary Packaging&#34; but there are only MAC OS, WIN32. I don&#39;t know whether Debian and Red hat are used for Linux or not. So, could you please tell me how to generate &#34;set up&#34; file for Linux and where it is generated. Thank you so much
binary build linuxasked 16 Sep &#39;13, 01:23</description>
    </item>
    
    <item>
      <title>Capture Multiple Files</title>
      <link>/questions/24745/capture-multiple-files/</link>
      <pubDate>Mon, 16 Sep 2013 04:46:00 +0000</pubDate>
      
      <guid>/questions/24745/capture-multiple-files/</guid>
      <description>Capture Multiple Files  0 Hi guys,
I have a problem with wireshark creating multiple files. I try to capture the network trafic for several days on a system with the following options: -use multiple files -next file every 2 megabytes -ring buffer with 9999 files
unfortunaly this doesn&#39;t work! There are two different things happening. 1. the system opens several wiresharkwindows which all tell me &#34;closing files&#34; but nothing happens.</description>
    </item>
    
    <item>
      <title>How to include LuaExpat for parsing XML files in Lua Scripts?</title>
      <link>/questions/24749/how-to-include-luaexpat-for-parsing-xml-files-in-lua-scripts/</link>
      <pubDate>Mon, 16 Sep 2013 05:41:00 +0000</pubDate>
      
      <guid>/questions/24749/how-to-include-luaexpat-for-parsing-xml-files-in-lua-scripts/</guid>
      <description>How to include LuaExpat for parsing XML files in Lua Scripts?  0 Hi all,
i am writing a Wireshark listener in Lua which needs to process a XML file before registering the listener. For parsing the XML file I used LuaExpat (lxp) and tried the parsing functionality in the Lua interpreter 1 which runs fine. Unfortunately, when Wireshark tries to execute the script it fails:
tshark: Lua: Error during loading: [string &amp;quot;res.</description>
    </item>
    
    <item>
      <title>(call_dissector_only): assertion failed: (handle != NULL)</title>
      <link>/questions/24750/call_dissector_only-assertion-failed-handle-null/</link>
      <pubDate>Mon, 16 Sep 2013 06:14:00 +0000</pubDate>
      
      <guid>/questions/24750/call_dissector_only-assertion-failed-handle-null/</guid>
      <description>(call_dissector_only): assertion failed: (handle != NULL)  0 i , when i capture packets through tshark i am getting the following assertion.
ERROR : file packet.c: line 1831 (call_dissector_only): assertion failed: (handle != NULL) aborting...
Command used: tshark -i eth0 -R radius -V
Please help ,how this issue can be fixed
tsharkasked 16 Sep &#39;13, 06:14
syed
11●1●1●2
accept rate: 0%
1Can you tell us which version of tshark you&#39;re using?</description>
    </item>
    
    <item>
      <title>TCP Segment</title>
      <link>/questions/24756/tcp-segment/</link>
      <pubDate>Mon, 16 Sep 2013 06:52:00 +0000</pubDate>
      
      <guid>/questions/24756/tcp-segment/</guid>
      <description>TCP Segment  0 Hello, I am using Modbus TCP to communicate between 2 computers. On one computer I am using a program call Ignition and on the other is a program that was created in VB6. Now communications mostly work but Ignition sometimes shows Unknown under Quality and sometimes it show good under quality. I found in wireshark that the first packet the Vb6 sends to Ignition is good but at the end of the packet there is a 00 which wireshark is saying is &#34;</description>
    </item>
    
    <item>
      <title>Show Device Description Instead of &amp;quot;Local Area Connection...&amp;quot;</title>
      <link>/questions/24779/show-device-description-instead-of-local-area-connection/</link>
      <pubDate>Mon, 16 Sep 2013 11:24:00 +0000</pubDate>
      
      <guid>/questions/24779/show-device-description-instead-of-local-area-connection/</guid>
      <description>Show Device Description Instead of &amp;ldquo;Local Area Connection&amp;hellip;&amp;quot;  0 Is there a way to force the Interface List to show the Device Description instead of &#34;Local Area Connection..&#34;. Preferably I&#39;d like to compile this in so I never have to deal with this again.
Thanks, Brian
device interface list descriptionasked 16 Sep &#39;13, 11:24
brwiese
26●11●12●11
accept rate: 50%
  
One Answer:
  
2Sure, just go to Edit -&amp;gt; Preferences -&amp;gt; Capture and edit the list of interfaces.</description>
    </item>
    
    <item>
      <title>Remove update &amp;quot;feature&amp;quot;</title>
      <link>/questions/24780/remove-update-feature/</link>
      <pubDate>Mon, 16 Sep 2013 11:26:00 +0000</pubDate>
      
      <guid>/questions/24780/remove-update-feature/</guid>
      <description>Remove update &amp;ldquo;feature&amp;rdquo;  0 Is there a way to disable the update &#34;feature&#34; during compilation of wireshark. We&#39;re in the middle of developing a protocol, and updating to a version that doesn&#39;t contain the dissector is not preferable.
Thanks Brian
update remove featureasked 16 Sep &#39;13, 11:26
brwiese
26●11●12●11
accept rate: 50%
  
One Answer:
  
1In epan/prefs.c:pre_init_prefs(), set prefs.gui_update_enabled = FALSE;
AN UPDATE
So maybe it depends on what you&#39;re trying to accomplish, but I&#39;ve thought of another option as well, bringing the list to the following 3:</description>
    </item>
    
    <item>
      <title>tshark, -Xlua_script: io.flush() doesn&amp;#x27;t seem to work</title>
      <link>/questions/24785/tshark-xlua_script-ioflush-doesnt-seem-to-work/</link>
      <pubDate>Mon, 16 Sep 2013 15:42:00 +0000</pubDate>
      
      <guid>/questions/24785/tshark-xlua_script-ioflush-doesnt-seem-to-work/</guid>
      <description>tshark, -Xlua_script: io.flush() doesn&amp;rsquo;t seem to work  0 io.flush doesn&#39;t seem to do anything from inside a Lua listener. Concretely, my script looks like this in outline:
local ip = Listener.new(&amp;quot;ip&amp;quot;) function ip.packet(pinfo, tvb) ... io.write(string.format(&amp;quot;%d:%d:%.6f:%s:%s:%s:%d:%s:%s:%d:%d:%s\n&amp;quot;, ...)) io.flush() endbut output is still being buffered. This wouldn&#39;t be an issue, except that the tshark process might get killed at any time by higher-level code, and it doesn&#39;t seem to flush pending output when it receives SIGTERM.</description>
    </item>
    
    <item>
      <title>[SOLVED] Error with &amp;quot;autogen.sh&amp;quot; - /usr/share/aclocal &amp;#x27; is already registered with AC_CONFIG_FILES</title>
      <link>/questions/24787/solved-error-with-autogensh-usrshareaclocal-is-already-registered-with-ac_config_files/</link>
      <pubDate>Mon, 16 Sep 2013 18:53:00 +0000</pubDate>
      
      <guid>/questions/24787/solved-error-with-autogensh-usrshareaclocal-is-already-registered-with-ac_config_files/</guid>
      <description>[SOLVED] Error with &amp;ldquo;autogen.sh&amp;rdquo; - /usr/share/aclocal &#39; is already registered with AC_CONFIG_FILES  0 Hi all, I&#39;m trying to build Wireshark for Linux version but I cannot start with the script &#34;autogen.sh&#34;. I have already installed autoconf, automake, lib-tool to fix some errors but it shows another as shown in the figure below
And the output of &#34;sh -x ./autogen.sh&#34; is
It seems that there is a problem with AC_CONFIG_FILES but I don&#39;t know how to fix.</description>
    </item>
    
    <item>
      <title>HTTPS traffic analysis</title>
      <link>/questions/24790/https-traffic-analysis/</link>
      <pubDate>Mon, 16 Sep 2013 19:36:00 +0000</pubDate>
      
      <guid>/questions/24790/https-traffic-analysis/</guid>
      <description>HTTPS traffic analysis  0 I have a device on a local network that’s accessing a WEB site on the server on the same LAN. I can get a capture from both systems, however the communication is encrypted with a certificate from godaddy.com
It looks like I can decrypt the communication if I have access to the private key, but can I capture with a Windows version of Wireshark or I need to use Linux Wireshark with GnuTLS support?</description>
    </item>
    
    <item>
      <title>How do I acquire the RSA private key of a locally installed third party application?</title>
      <link>/questions/24802/how-do-i-acquire-the-rsa-private-key-of-a-locally-installed-third-party-application/</link>
      <pubDate>Tue, 17 Sep 2013 03:42:00 +0000</pubDate>
      
      <guid>/questions/24802/how-do-i-acquire-the-rsa-private-key-of-a-locally-installed-third-party-application/</guid>
      <description>How do I acquire the RSA private key of a locally installed third party application?  0 I&#39;m working on reverse engineering an online game (League of Legends). While a lot of traffic is unencrypted and easily available through your great tool, is some data e.g. the chat, pub-private key encrypted. I know I can add this private key to wireshark to monitor the data, but how can I find the private key?</description>
    </item>
    
    <item>
      <title>dumpcap - how to download the sources and build it on Windows</title>
      <link>/questions/24804/dumpcap-how-to-download-the-sources-and-build-it-on-windows/</link>
      <pubDate>Tue, 17 Sep 2013 03:49:00 +0000</pubDate>
      
      <guid>/questions/24804/dumpcap-how-to-download-the-sources-and-build-it-on-windows/</guid>
      <description>dumpcap - how to download the sources and build it on Windows  0 Hi,
currently i develop a program running on Windows that uses the library WinPcap to sniff some data traffic and write down the captured traffic into files with PCAP format. My program needs to write down the traffic in the newer PcapNG format. As far as i could see, the WinPcap library doesn&#39;t support the PcapNG format.</description>
    </item>
    
    <item>
      <title>capture destination IP</title>
      <link>/questions/24815/capture-destination-ip/</link>
      <pubDate>Tue, 17 Sep 2013 05:59:00 +0000</pubDate>
      
      <guid>/questions/24815/capture-destination-ip/</guid>
      <description>capture destination IP  0 We have a device that is infected and has caused our email to be blacklisted. I&#39;ve downloaded wireshark to see if we can capture the device. We don&#39;t have network support on staff, so this is all new to me. I want to make sure I have the correct set up and syntax. I checked promiscuous mode, then selected capture filter. I get an error trying to set up the filter.</description>
    </item>
    
    <item>
      <title>problem with the installation of wireshark ubuntu “make” failed</title>
      <link>/questions/24834/problem-with-the-installation-of-wireshark-ubuntu-make-failed/</link>
      <pubDate>Tue, 17 Sep 2013 08:23:00 +0000</pubDate>
      
      <guid>/questions/24834/problem-with-the-installation-of-wireshark-ubuntu-make-failed/</guid>
      <description>problem with the installation of wireshark ubuntu “make” failed  0 I am new to wireshark and ubuntu. I need to install wireshark but it seems to have some problems when I type &#34;sudo make&#34; command. here is what I get:
[email protected]:~$ cd wireshark/ [email protected]:~/wireshark$ make LANG=C /usr/bin/perl ./make-version.pl . Version configuration file version.conf not found. Using defaults. This is not a SVN build. svnversion.h is up-to-date. make all-recursive make[1]: Entering directory `/home/dell/wireshark&amp;#39; Making all in tools make[2]: Entering directory `/home/dell/wireshark/tools&amp;#39; Making all in lemon make[3]: Entering directory `/home/dell/wireshark/tools/lemon&amp;#39; make[3]: Nothing to be done for `all&amp;#39;.</description>
    </item>
    
    <item>
      <title>What exactly does the rate(ms) mean in the protocol specific stats window</title>
      <link>/questions/24857/what-exactly-does-the-ratems-mean-in-the-protocol-specific-stats-window/</link>
      <pubDate>Tue, 17 Sep 2013 10:01:00 +0000</pubDate>
      
      <guid>/questions/24857/what-exactly-does-the-ratems-mean-in-the-protocol-specific-stats-window/</guid>
      <description>What exactly does the rate(ms) mean in the protocol specific stats window  0 I&#39;ve created a stats_tree for a protocol that has different object types . This was implemented with a plugin dissector.
When I open Statistics and choose my protocol a window opens up with the columns Topic/Item, Count, Rate(ms), and Percent.
I can make reasonable guesses on this. However, getting confirmation on this will probably help someone out later.</description>
    </item>
    
    <item>
      <title>Capture limit of a laptop</title>
      <link>/questions/24866/capture-limit-of-a-laptop/</link>
      <pubDate>Tue, 17 Sep 2013 12:28:00 +0000</pubDate>
      
      <guid>/questions/24866/capture-limit-of-a-laptop/</guid>
      <description>Capture limit of a laptop  0 I am looking for a replacement for my current laptop / portable capture device. After seeing Chris Greer&#39;s Sharkfest presentation &#34;When does a laptop start dropping packets&#34; (http://www.youtube.com/watch?v=_H7PjWqKV0Q) and then experiencing the inability to get all of the packets first hand during a capture session last week I&#39;m more than leery of laying my money down for something that only functions well as an email machine.</description>
    </item>
    
    <item>
      <title>SYN, then Retransmission, then RSTACK</title>
      <link>/questions/24870/syn-then-retransmission-then-rstack/</link>
      <pubDate>Tue, 17 Sep 2013 15:25:00 +0000</pubDate>
      
      <guid>/questions/24870/syn-then-retransmission-then-rstack/</guid>
      <description>SYN, then Retransmission, then RSTACK  0 Hello people, I have a strange issue. I have an apche mod_proxying an application server. It works, but at any time randomly I get a connection refused from the server resulting a 503 to the user. It doesn&#39;t matter the traffic size, it can happen with 1 user too with just a request to a page. It happens like one request every 10000.</description>
    </item>
    
    <item>
      <title>EtherCAT sub-dissector in Lua</title>
      <link>/questions/24876/ethercat-sub-dissector-in-lua/</link>
      <pubDate>Tue, 17 Sep 2013 19:31:00 +0000</pubDate>
      
      <guid>/questions/24876/ethercat-sub-dissector-in-lua/</guid>
      <description>EtherCAT sub-dissector in Lua  0 Hi,
I want to create an EtherCAT subdissector in Lua, to dissect the payload of the EtherCAT datagrams. Consulting the WireShark documentation didn&#39;t help me out, I know how to build a custom (chain/post-) dissector in Lua but not how to dissect data of an existing protocol.
Post- or Chain dissectors allow me to dissect the data outside of the existing protocol, so my tree items are listed below the EtherCAT dataframes instead of expanding the ecat protocol.</description>
    </item>
    
    <item>
      <title>TCP connection</title>
      <link>/questions/24878/tcp-connection/</link>
      <pubDate>Tue, 17 Sep 2013 21:37:00 +0000</pubDate>
      
      <guid>/questions/24878/tcp-connection/</guid>
      <description>TCP connection  0 Hi, I have a problem in establishing a tcp connection with a device(client) and PC(server) I will list important places in the wireshark to make it comfortable for you.
start - connection established till 106 - full of retransmission. then window size of tcp if full. so data starts sending again..
after this, there is no problem.(no retransmissions)
at 1032 - exit is sent from PC. It closes connection in labview and device also responds for it.</description>
    </item>
    
    <item>
      <title>Error: Failed build dependencies while making rpm</title>
      <link>/questions/24886/error-failed-build-dependencies-while-making-rpm/</link>
      <pubDate>Wed, 18 Sep 2013 01:37:00 +0000</pubDate>
      
      <guid>/questions/24886/error-failed-build-dependencies-while-making-rpm/</guid>
      <description>Error: Failed build dependencies while making rpm  0 Hi all, I &#39;m building the rpm of Wireshark but got this problem: I checked the version of those dependencies and know for sure that satisfies these conditions: About glib2-devel, libcap-devel, zlib-devel, c-ares-devel, lua-devel are also installed. rpm, as you se, is 4.10 gtk-devel: 2.0 and 3.0 Destop-file-utils: I downloaded from web and installed then got a message that inform later version is already installed.</description>
    </item>
    
    <item>
      <title>High TCP ack from source machine  Wireshark captured</title>
      <link>/questions/24904/high-tcp-ack-from-source-machine-wireshark-captured/</link>
      <pubDate>Wed, 18 Sep 2013 05:02:00 +0000</pubDate>
      
      <guid>/questions/24904/high-tcp-ack-from-source-machine-wireshark-captured/</guid>
      <description>High TCP ack from source machine Wireshark captured  0 Hi All,
I am trying to analyze TCP agent based application that mostly using PSH flags. The application suffering fro some latencies that message should not exceed 50msec. Now as the agent is kind of interactive that change messages and not TCP buffered PSH flags nature its could be that communication is idle to up to 5sec. The problem is that i can see that destination sometimes TCP ACK to source around 180~200msec , but i can see the same issue on the source where the Wireshark capture made ,and my question is what i can i understand from high values ACK 180~200 if its exist on the machine where capture taken should i treat such as pure network congestion or some kind of OS environmental issues like blocking antivirus etc.</description>
    </item>
    
    <item>
      <title>Slow Wireless, Dlink router, Browser hijacked</title>
      <link>/questions/24905/slow-wireless-dlink-router-browser-hijacked/</link>
      <pubDate>Wed, 18 Sep 2013 05:09:00 +0000</pubDate>
      
      <guid>/questions/24905/slow-wireless-dlink-router-browser-hijacked/</guid>
      <description>Slow Wireless, Dlink router, Browser hijacked  0 Hi,
My wireless is very slow although I&#39;ve standard settings. Wireless router is Dlink dir 655. A few weeks ago I discovered that my DNS settings on that router had changed (my DNS settings gone, free dns was enabled on the Dlink).
I &#39;ve put back my old settings, cleaned my laptop with several antispyy and malware tools (cleaned lot of weird entry&#39;s and I saw my browser was hijacked) and thought it would all be fine, but no way wireless is still very slow.</description>
    </item>
    
    <item>
      <title>Varan Real Time data network</title>
      <link>/questions/24913/varan-real-time-data-network/</link>
      <pubDate>Wed, 18 Sep 2013 06:51:00 +0000</pubDate>
      
      <guid>/questions/24913/varan-real-time-data-network/</guid>
      <description>Varan Real Time data network  0 Hello
I&#39;m doing maintenance on a Automation and machines that uses Varan Protocol. Can Wireshark recognize this protocol??
http://www.varan-bus.net/index_en.htm
Kraus
varan industrial protocol networkasked 18 Sep &#39;13, 06:51
Kraus
1●1●1●2
accept rate: 0%
 edited 18 Sep &#39;13, 07:08 
Kurt Knochner ♦
24.8k●10●39●237
  
One Answer:
  
0there is no support for VARAN in Wireshark, at least not in the official code base.</description>
    </item>
    
    <item>
      <title>how to know if a file without extension contains PCAP or PCAP-NG formatted data?</title>
      <link>/questions/24916/how-to-know-if-a-file-without-extension-contains-pcap-or-pcap-ng-formatted-data/</link>
      <pubDate>Wed, 18 Sep 2013 07:25:00 +0000</pubDate>
      
      <guid>/questions/24916/how-to-know-if-a-file-without-extension-contains-pcap-or-pcap-ng-formatted-data/</guid>
      <description>how to know if a file without extension contains PCAP or PCAP-NG formatted data?  0 Hi,
i have a trace file which is in either PCAP or PCAP-NG format, but it has no extension.
With a drag-and-drop i can load/open it in Wireshark. The columns (&#39;No.&#39;, &#39;Time&#39;, &#39;Source&#39;, &#39;Destination&#39;, &#39;Protocol&#39;, &#39;Length&#39;, &#39;Info&#39;) and the data look fine, but how can i know in which format (PCAP or PCAP-NG) the file contents is written?</description>
    </item>
    
    <item>
      <title>Wireshark freezes or stalls</title>
      <link>/questions/24921/wireshark-freezes-or-stalls/</link>
      <pubDate>Wed, 18 Sep 2013 08:33:00 +0000</pubDate>
      
      <guid>/questions/24921/wireshark-freezes-or-stalls/</guid>
      <description>Wireshark freezes or stalls  0 Does anyone know why the latest version (1.10.2) of wireshark did not work right? The software would function fine until I click to capture. Once it&#39;s clicked, nothing happens. It does not matter how long I wait, it would not do anything until I have to kill the process. Any suggestion? I&#39;m using wireshark under Windows Server 2008.
stall freezing wiresharkasked 18 Sep &#39;13, 08:33</description>
    </item>
    
    <item>
      <title>dissect credssp</title>
      <link>/questions/24924/dissect-credssp/</link>
      <pubDate>Wed, 18 Sep 2013 09:28:00 +0000</pubDate>
      
      <guid>/questions/24924/dissect-credssp/</guid>
      <description>dissect credssp  0 I am using wireshark currently to capture credssp authentication packets for a RDP protocol implementation. I see that wireshark has dissectors for credssp, but in my captures it will not break down the detail of the TSRequest items like PublicKey, NegoToken or authInfo.
Can the current version do this? I have also been looking at the dissector code to determine if it can be modified to support this, but could use a pointer to some documentation discussing how the dissectors are structured.</description>
    </item>
    
    <item>
      <title>Excessive Retries on CCTV</title>
      <link>/questions/24927/excessive-retries-on-cctv/</link>
      <pubDate>Wed, 18 Sep 2013 13:55:00 +0000</pubDate>
      
      <guid>/questions/24927/excessive-retries-on-cctv/</guid>
      <description>Excessive Retries on CCTV  0 We work in a very CCTV driven enviroment. We have about 10 dedicated PCs to watching either cameras or DVRs over the LAN. The CCTV is on its own VLAN. I am currently spanning the switch port that the CCTV router is on. We are getting flooded with TCP retransmissions and TCP Duplicate packets on that port. It equates to about one retransmission per client per device per second.</description>
    </item>
    
    <item>
      <title>Capture DHCP traffic on the DHCP server side</title>
      <link>/questions/24930/capture-dhcp-traffic-on-the-dhcp-server-side/</link>
      <pubDate>Wed, 18 Sep 2013 17:37:00 +0000</pubDate>
      
      <guid>/questions/24930/capture-dhcp-traffic-on-the-dhcp-server-side/</guid>
      <description>Capture DHCP traffic on the DHCP server side  0 I’m pretty new to Wireshark and trying to TS an issue and want to prove that a PXE DHCP request isn’t being received by the Microsoft DHCP server. I thought it would be a case of:
Start a capture on the DHCP serverKick off the boot process on the client, watch the PXE boot and note the mac addressStop the capture on the DHCP server and filter (eth.</description>
    </item>
    
    <item>
      <title>PC wont take IP given by DHCPACK, tried multiple routers (dhcp servers)</title>
      <link>/questions/24935/pc-wont-take-ip-given-by-dhcpack-tried-multiple-routers-dhcp-servers/</link>
      <pubDate>Wed, 18 Sep 2013 20:19:00 +0000</pubDate>
      
      <guid>/questions/24935/pc-wont-take-ip-given-by-dhcpack-tried-multiple-routers-dhcp-servers/</guid>
      <description>PC wont take IP given by DHCPACK, tried multiple routers (dhcp servers)  0 Hi all,
I have a few machines now that are exhibiting this problem by where i can see the DHCP Discover -&amp;gt; DHCP Offer -&amp;gt; DHCP Request -&amp;gt; DHCP ACK but the client does not take the address given to it. The MAC addresses match so its not like it should not be responding. I have tried multiple cisco routers using both 12.</description>
    </item>
    
    <item>
      <title>[closed] glib installation failing with parse error</title>
      <link>/questions/24937/glib-installation-failing-with-parse-error/</link>
      <pubDate>Wed, 18 Sep 2013 20:45:00 +0000</pubDate>
      
      <guid>/questions/24937/glib-installation-failing-with-parse-error/</guid>
      <description>[closed] glib installation failing with parse error  0 Hi,
We want to install the wireshark development kit, and we have successfully installed autoconf, automake and libtool. But when we tried to install the wireshark, it gave the dependency error on gpk, and gpk had a dependency on glib. We are getting the following error when we try to install glib. Python 2.75 is installed. Please let us know.
[[email protected] glib-2.</description>
    </item>
    
    <item>
      <title>Error: Failed build dependencies while making Deb</title>
      <link>/questions/24940/error-failed-build-dependencies-while-making-deb/</link>
      <pubDate>Wed, 18 Sep 2013 23:31:00 +0000</pubDate>
      
      <guid>/questions/24940/error-failed-build-dependencies-while-making-deb/</guid>
      <description>Error: Failed build dependencies while making Deb  0 Hi all, I&#39;m trying to build Debian-package in Ubuntu by using
$./configure $ make debian-packagebut unfortunately, I got an error with gtk like this:
ERROR: ld.so: object &amp;#39;libfakeroot-sysv.so&amp;#39; from LD_PRELOAD cannot be preloaded: ignored. dpkg-shlibdeps: error: no dependency information found for /usr/local/lib/libgdk-3.so.0 (used by debian/wireshark/usr/bin/wireshark) dh_shlibdeps: dpkg-shlibdeps -Tdebian/wireshark.substvars debian/wireshark/usr/bin/wireshark returned exit code 2 make[1]: *** [binary-arch] Error 2 make[1]: Leaving directory `/media/sonnh/Win7_x64/wireshark&amp;#39; dpkg-buildpackage: error: fakeroot debian/rules binary gave error exit status 2 make: *** [debian-package] Error 2I searched on Internet and it seems that many people got the similar errors.</description>
    </item>
    
    <item>
      <title>Terminate wireshark in an unusual way.</title>
      <link>/questions/24954/terminate-wireshark-in-an-unusual-way/</link>
      <pubDate>Thu, 19 Sep 2013 06:05:00 +0000</pubDate>
      
      <guid>/questions/24954/terminate-wireshark-in-an-unusual-way/</guid>
      <description>Terminate wireshark in an unusual way.  0 Hi There,
I&#39;ve installed wireshark on our server and its running well for sometime. and then its giving an error &#39;Microsoft Visual C++ Runtime Library&#39;. This application has requested the Runtime to terminate it in an unusual way. When I click OK on the dialogue box then it shows Wireshark.ese-Application error. Then wireshark get closed. Before I&#39;ve installed version Wireshark-win64-1.10.1 and then upgraded to Wireshark-win64-1.</description>
    </item>
    
    <item>
      <title>Saving TCP Stream data asks for multiple output files</title>
      <link>/questions/24959/saving-tcp-stream-data-asks-for-multiple-output-files/</link>
      <pubDate>Thu, 19 Sep 2013 09:32:00 +0000</pubDate>
      
      <guid>/questions/24959/saving-tcp-stream-data-asks-for-multiple-output-files/</guid>
      <description>Saving TCP Stream data asks for multiple output files  0 I am trying to save TCP Stream data (from the Follow TCP Stream window). When I have done so in the past, it asks for a single output file and saves the data there. I am trying to do so currently and when I enter a file name, it saves out data (it appears to be all of it) and then asks for another file name.</description>
    </item>
    
    <item>
      <title>Filter for SYN, PSH and RST flags</title>
      <link>/questions/24961/filter-for-syn-psh-and-rst-flags/</link>
      <pubDate>Thu, 19 Sep 2013 10:40:00 +0000</pubDate>
      
      <guid>/questions/24961/filter-for-syn-psh-and-rst-flags/</guid>
      <description>Filter for SYN, PSH and RST flags  0 Hey, I want to add to this question.
I&#39;m actually trying to display the SYN flags using the display function from above, but I am also trying to display the PSH and RST flags at the same time.
This might be a stupid question, but how do I write a display function to combine all three of these?
rst filter psh synasked 19 Sep &#39;13, 10:40</description>
    </item>
    
    <item>
      <title>Frame length = 19764 Bytes</title>
      <link>/questions/24962/frame-length-19764-bytes/</link>
      <pubDate>Thu, 19 Sep 2013 11:15:00 +0000</pubDate>
      
      <guid>/questions/24962/frame-length-19764-bytes/</guid>
      <description>Frame length = 19764 Bytes  1 Hello,
I though that frame size unless classified as jumbo frames were no larger than 1500 bytes. I have frame lengths in my capture as large as 19764 bytes.
None of the servers involved are set to send jumbo frames. How does that happen ?
Thanks, Robbie
frame lengthasked 19 Sep &#39;13, 11:15
Robbie S
26●2●2●4
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>802.11 Channel grayed out on Wireshark 1.10.1 for OS X</title>
      <link>/questions/24966/80211-channel-grayed-out-on-wireshark-1101-for-os-x/</link>
      <pubDate>Thu, 19 Sep 2013 12:32:00 +0000</pubDate>
      
      <guid>/questions/24966/80211-channel-grayed-out-on-wireshark-1101-for-os-x/</guid>
      <description>802.11 Channel grayed out on Wireshark 1.10.1 for OS X  0 I&#39;m trying to do WiFi capture on my Mac, but I can&#39;t seem to select the channel I want to capture on. The 802.11 Channel, Channel Offset, FCS Filter, and Wireless Settings are all grayed out. Here is my configuration:
Wireshark 1.10.1 (SVN Rev 50926)OS X 10.8.5Capture Options:
Link-layer header type: 802.11 plus radiotap headerPromiscuous mode: enabledMonitor mode: enabledosx mac 802.</description>
    </item>
    
    <item>
      <title>Dependencies between throughput and TCP window</title>
      <link>/questions/24978/dependencies-between-throughput-and-tcp-window/</link>
      <pubDate>Thu, 19 Sep 2013 18:31:00 +0000</pubDate>
      
      <guid>/questions/24978/dependencies-between-throughput-and-tcp-window/</guid>
      <description>Dependencies between throughput and TCP window  0 Hi, I have observed an interesting throughput pattern when testing two different WiFi access points &amp;amp; Windows7. In both cases the radio link is perfect. FTP download throughput is always around 50% lower on one of the APs (40 vs 20Mbps).
Both APs show no dup-acks or retransmissions. Link is just perfect. The difference is that when the faster AP is used TCP window keeps increasing all the the to 1.</description>
    </item>
    
    <item>
      <title>Lots of retransmissions, unseen segments and out of order segments</title>
      <link>/questions/24980/lots-of-retransmissions-unseen-segments-and-out-of-order-segments/</link>
      <pubDate>Fri, 20 Sep 2013 00:38:00 +0000</pubDate>
      
      <guid>/questions/24980/lots-of-retransmissions-unseen-segments-and-out-of-order-segments/</guid>
      <description>Lots of retransmissions, unseen segments and out of order segments  0 Hi I am capturing some traffic from multiple 10G interfaces to a laptop connected at 1Gbs. If applied a capture filter to specifically look for the IPs I need to investgate. In my capture files I see a lot of retransmissions, unseen segments and out-of-order segements. Is it possible that wireshark is seeing these due to packets getting lost to to the overload of the 1GBs connection?</description>
    </item>
    
    <item>
      <title>PCAP-NG format, Interface Description Block: Interface ID missing</title>
      <link>/questions/24984/pcap-ng-format-interface-description-block-interface-id-missing/</link>
      <pubDate>Fri, 20 Sep 2013 01:11:00 +0000</pubDate>
      
      <guid>/questions/24984/pcap-ng-format-interface-description-block-interface-id-missing/</guid>
      <description>PCAP-NG format, Interface Description Block: Interface ID missing  0 Reading again the PCAP Next Generation Dump File Format specification, i see a defect in the Interface Description Block paragraph: the figure shows no Interface ID inside the block though this field is described underneath.
This was never fixed? Too bad, it would really have been nicer than numerating the interfaces by their order in the list of Interfae Description Blocks.</description>
    </item>
    
    <item>
      <title>Google Analytics in native apps (iPad)</title>
      <link>/questions/24985/google-analytics-in-native-apps-ipad/</link>
      <pubDate>Fri, 20 Sep 2013 01:14:00 +0000</pubDate>
      
      <guid>/questions/24985/google-analytics-in-native-apps-ipad/</guid>
      <description>Google Analytics in native apps (iPad)  0 Scenario: iPad app with Analytics SDK installed. Data is coming in, reports are showing up with reasonable numbers. However I need to debug single requests Analytics is doing, to make sure, every information bit is send with the right info. Setup is a win7 machine with latest Wireshark. Ad Hoc network, where an iPad is dialing up to get WiFi access through my laptops connection.</description>
    </item>
    
    <item>
      <title>Wireshark display filters comparison with old version</title>
      <link>/questions/24988/wireshark-display-filters-comparison-with-old-version/</link>
      <pubDate>Fri, 20 Sep 2013 01:49:00 +0000</pubDate>
      
      <guid>/questions/24988/wireshark-display-filters-comparison-with-old-version/</guid>
      <description>Wireshark display filters comparison with old version  0 Hi,
We have current automation framework that uses wireshark version 1.2. We would like to use wireshark version 1.6.7. But the problem is, there are some display filters that are changed from 1.2.x to 1.6.7. I would like to get list of filters that are changed so that I can just change those in my automation framework. With out this data, I&#39;ll need to check all current display filters to see whether they are valid or not, which will be tedious!</description>
    </item>
    
    <item>
      <title>Why capture filter icmp6 does not capture ICMPv6 replies?</title>
      <link>/questions/24992/why-capture-filter-icmp6-does-not-capture-icmpv6-replies/</link>
      <pubDate>Fri, 20 Sep 2013 03:01:00 +0000</pubDate>
      
      <guid>/questions/24992/why-capture-filter-icmp6-does-not-capture-icmpv6-replies/</guid>
      <description>Why capture filter icmp6 does not capture ICMPv6 replies?  0 I&#39;m running a couple of LXC containers (Container1 and Container2) on my host, each with a veth (veth1000_1 and veth1001_1) connected through a bridge (mbr1). From Container1 I ping6 Container2 and everything is working, but I can&#39;t manage to capture the icmp6 replies if I filter by protocol on veth1000_1:
tshark -i veth1000_1 captures requests and repliestshark -i veth1000_1 -f icmp6 captures only requeststshark -i mbr1 -f icmp6 captures requests and repliestshark -i eth1.</description>
    </item>
    
    <item>
      <title>does udp have a  server and client approach</title>
      <link>/questions/24996/does-udp-have-a-server-and-client-approach/</link>
      <pubDate>Fri, 20 Sep 2013 04:08:00 +0000</pubDate>
      
      <guid>/questions/24996/does-udp-have-a-server-and-client-approach/</guid>
      <description>does udp have a server and client approach  0 can any one tell me if there is a concept of server and client in udp as it is in tcp??
I have an option like,, as a syn packet needs to be first sent in tcp communication,,there is a server (listener who waits for syn packet) and client(who sends syn packet).but as this is not the case in udp,, there is no client and server.</description>
    </item>
    
    <item>
      <title>Extraneous data in EPS bearer context status IE in Tracking Area update request message</title>
      <link>/questions/25001/extraneous-data-in-eps-bearer-context-status-ie-in-tracking-area-update-request-message/</link>
      <pubDate>Fri, 20 Sep 2013 04:16:00 +0000</pubDate>
      
      <guid>/questions/25001/extraneous-data-in-eps-bearer-context-status-ie-in-tracking-area-update-request-message/</guid>
      <description>Extraneous data in EPS bearer context status IE in Tracking Area update request message  0 why EPS bearer context status IE is decoded successfully but with a tag Extraneous data in tracking area update request message including TA/LA updating and bearer establishment requested.
extraneousasked 20 Sep &#39;13, 04:16
TheMan Catch
1●1●1●1
accept rate: 0%
&#34;Extraneous data&#34; means that there was data left in the message when wireshark finished dissection dye to: - New IE added to message which wireshark does not dissect.</description>
    </item>
    
    <item>
      <title>Some questions @ Wireshark Capture</title>
      <link>/questions/25009/some-questions-wireshark-capture/</link>
      <pubDate>Fri, 20 Sep 2013 04:42:00 +0000</pubDate>
      
      <guid>/questions/25009/some-questions-wireshark-capture/</guid>
      <description>Some questions @ Wireshark Capture  -2 Hi Pls kindly help to see,
Is the frame an outgoing or an incoming frame?Identify the source IP address of the network-layer header in the frame?Identify the destination IP address of the network-layer header in the frame?Calculate the total number of bytes in the whole frame?Estimate the number of bytes in the Ethernet (data-link layer) header?Estimate the number of bytes in the IP header?</description>
    </item>
    
    <item>
      <title>[closed] Padded CC Packet</title>
      <link>/questions/25026/padded-cc-packet/</link>
      <pubDate>Fri, 20 Sep 2013 05:55:00 +0000</pubDate>
      
      <guid>/questions/25026/padded-cc-packet/</guid>
      <description>[closed] Padded CC Packet  0 I&#39;m doing a capture using the NORM protocol dissector and CMD CC packets don&#39;t look right. I&#39;m expecting a packet size around 78 bytes and instead I&#39;m getting a packet size of 2074 bytes. 2004 of those bytes are labeled Payload and they are all zeros. Is there any way to fix the way that Wireshark is padding these packets?
I am using the packet-rmt-norm.</description>
    </item>
    
    <item>
      <title>TCP Window Full</title>
      <link>/questions/25050/tcp-window-full/</link>
      <pubDate>Fri, 20 Sep 2013 11:05:00 +0000</pubDate>
      
      <guid>/questions/25050/tcp-window-full/</guid>
      <description>TCP Window Full  0 What does it mean when I see (from Wireshark captured file) the message [TCP Window Full] from the server? Thanks
window full tcpasked 20 Sep &#39;13, 11:05
character9
16●10●10●12
accept rate: 0%
  
One Answer:
  
2This question has been asked several times before. This is TCP flow control in action. From Section 1.5 of RFC 793:
Flow Control: TCP provides a means for the receiver to govern the amount of data sent by the sender.</description>
    </item>
    
    <item>
      <title>Router sending packet(s) out every 5 seconds / bandwidth is not compromised</title>
      <link>/questions/25057/router-sending-packets-out-every-5-seconds-bandwidth-is-not-compromised/</link>
      <pubDate>Fri, 20 Sep 2013 15:00:00 +0000</pubDate>
      
      <guid>/questions/25057/router-sending-packets-out-every-5-seconds-bandwidth-is-not-compromised/</guid>
      <description>Router sending packet(s) out every 5 seconds / bandwidth is not compromised  0 Hi folks, I have a dd-wrt mini router (Linksys WRT54GS v7) which I am worried may be compromised. It is sending out a packet every 5 seconds somewhere despite the fact that my WiFi is disabled (everything is hard-wired here) and all machines are either off or unplugged.
The simple topology would be:
Router --&amp;gt; Modem --&amp;gt; DSLam --&amp;gt; net provider [The modem is an old SpeedStream DSL modem.</description>
    </item>
    
    <item>
      <title>TCP previous segment not captured, ...</title>
      <link>/questions/25066/tcp-previous-segment-not-captured/</link>
      <pubDate>Sat, 21 Sep 2013 08:25:00 +0000</pubDate>
      
      <guid>/questions/25066/tcp-previous-segment-not-captured/</guid>
      <description>TCP previous segment not captured, &amp;hellip;  0 Hi
I have a scenario where vlan traffic is going through gateway SVI and some specific traffic is routed through Route-map to Cisco ASA placed in the same VLAN, Now using VMware View client when traffic is routed through route-map Vmware View does not work after authentication saying &#34;TCP previous segment not captured&#34; , but when i manually add gateway as ASA, Application works perfectly, i am assuming that some packets are missing within this routing.</description>
    </item>
    
    <item>
      <title>Source/Destination Port: XBOX</title>
      <link>/questions/25074/sourcedestination-port-xbox/</link>
      <pubDate>Sun, 22 Sep 2013 13:54:00 +0000</pubDate>
      
      <guid>/questions/25074/sourcedestination-port-xbox/</guid>
      <description>Source/Destination Port: XBOX  0 I&#39;ve been trying to figure out why, when playing CoD MW3, via Steam I constantly get server timeouts. So I started up WireShark to try and monitor those packets. I noticed that there were packets being sent with with source and destination port saying Xbox. I don&#39;t have an XBox on my network, that I&#39;m aware of. Any idea why this would be?
xboxasked 22 Sep &#39;13, 13:54</description>
    </item>
    
    <item>
      <title>Last Login details for a Telnet session</title>
      <link>/questions/25077/last-login-details-for-a-telnet-session/</link>
      <pubDate>Sun, 22 Sep 2013 15:09:00 +0000</pubDate>
      
      <guid>/questions/25077/last-login-details-for-a-telnet-session/</guid>
      <description>Last Login details for a Telnet session  0 Using WireShark when I do a follow TCP stream on a Telnet packet it just gives a value like : Sat Nov 27 20:11:43 for the Last Login details. How can I get the year corresponding to this date for any telnet packet.
Thanks Abhishek K
telnetasked 22 Sep &#39;13, 15:09
MetalGeek7
1●1●1●1
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Using WireShark over VPN</title>
      <link>/questions/25088/using-wireshark-over-vpn/</link>
      <pubDate>Sun, 22 Sep 2013 18:54:00 +0000</pubDate>
      
      <guid>/questions/25088/using-wireshark-over-vpn/</guid>
      <description>Using WireShark over VPN  0 Hi Guys,
I&#39;m new... Really new. As in, my day job is at 20th Century Fox and this is becoming my night job. I&#39;m testing out Meraki gear for a hotel I&#39;m building (yes, by night). My test site is in Sherman Oaks and I&#39;m located in Beverly Hills. If I tunnel in using VPN, can I run wireshark on my machine in Beverly Hills to assess the &#39;test network&#39; in Sherman Oaks?</description>
    </item>
    
    <item>
      <title>Wireshark, tshark - Out of memory problem</title>
      <link>/questions/25091/wireshark-tshark-out-of-memory-problem/</link>
      <pubDate>Sun, 22 Sep 2013 19:46:00 +0000</pubDate>
      
      <guid>/questions/25091/wireshark-tshark-out-of-memory-problem/</guid>
      <description>Wireshark, tshark - Out of memory problem  0 Hi all, I&#39;m using wireshark and tshark to display data. I search on Internet and know that if we run wireshark day after day without stopping, it could cause two problem:
Temp Data written to disk: We have a workaround by adding an option to write into 5 files with default size, when the new 6 th file generated, it would replace the 1 st file.</description>
    </item>
    
    <item>
      <title>IP checksum</title>
      <link>/questions/25096/ip-checksum/</link>
      <pubDate>Sun, 22 Sep 2013 23:54:00 +0000</pubDate>
      
      <guid>/questions/25096/ip-checksum/</guid>
      <description>IP checksum  0 Is the packet considered invalid and not read by applications if the ip header checksum is wrong?
if so, help me in calculating it..
ipasked 22 Sep &#39;13, 23:54
Raja Balaji
1●4●4●6
accept rate: 0%
  
One Answer:
  
1Is the packet considered invalid and not read by applications if the ip header checksum is wrong?
The OS will drop the packet if the IP checksum is incorrect.</description>
    </item>
    
    <item>
      <title>Filter applies as &amp;#x27;Not selected&amp;#x27; when &amp;#x27;Selected&amp;#x27; is used</title>
      <link>/questions/25097/filter-applies-as-not-selected-when-selected-is-used/</link>
      <pubDate>Mon, 23 Sep 2013 00:44:00 +0000</pubDate>
      
      <guid>/questions/25097/filter-applies-as-not-selected-when-selected-is-used/</guid>
      <description>Filter applies as &amp;lsquo;Not selected&amp;rsquo; when &amp;lsquo;Selected&amp;rsquo; is used  0 I am working on wireshark 1.8.5, and facing this particular issue. Whenever I apply a filter on any field, its being applied as NOT of that. Help.
display-filterasked 23 Sep &#39;13, 00:44
sunshine
16●5●5●9
accept rate: 0%
  
One Answer:
  
3 Hi,
this is a known issue that got fixed in 1.8.6 (see bug 8297).</description>
    </item>
    
    <item>
      <title>Zero packets detected - HP Procurve 5400 series &amp;amp; Marvell Yukon  88E8055</title>
      <link>/questions/25103/zero-packets-detected-hp-procurve-5400-series-marvell-yukon-88e8055/</link>
      <pubDate>Mon, 23 Sep 2013 01:17:00 +0000</pubDate>
      
      <guid>/questions/25103/zero-packets-detected-hp-procurve-5400-series-marvell-yukon-88e8055/</guid>
      <description>Zero packets detected - HP Procurve 5400 series &amp;amp; Marvell Yukon 88E8055  0 Hi all
Hope someone has come across this before and can help me before I tear my hair out!
I have Wireshark set up on a Sony Vaio PCG-4N1M which has a Marvell Yukon 88E8055 NIC and am trying to packet sniff by linking it to a mirror output port on a HP 5400 series switch.</description>
    </item>
    
    <item>
      <title>Not able to install winpcap 4.1.3</title>
      <link>/questions/25105/not-able-to-install-winpcap-413/</link>
      <pubDate>Mon, 23 Sep 2013 02:09:00 +0000</pubDate>
      
      <guid>/questions/25105/not-able-to-install-winpcap-413/</guid>
      <description>Not able to install winpcap 4.1.3  0 My problem is that I have uninstalled 4.1.2 and yet - when I try to install 4.1.3 - I get the message:
A previous version of WinPcap has been detected on this system and cannot be removed because in use by another application.
What shall I do? Now I can&#39;t run WireShark because I don&#39;t have WinPcap in my system ...
:o) Truls</description>
    </item>
    
    <item>
      <title>keep alive packets at the end of the session</title>
      <link>/questions/25108/keep-alive-packets-at-the-end-of-the-session/</link>
      <pubDate>Mon, 23 Sep 2013 03:21:00 +0000</pubDate>
      
      <guid>/questions/25108/keep-alive-packets-at-the-end-of-the-session/</guid>
      <description>keep alive packets at the end of the session  0 Hi, I have captured a TCP session which has TCP keep alive packet at the end. machine A has sent the keep alive packet to machine B and machine B has acknowledged this keep alive packet. But there is no communication after that between them. Does this mean the connection is still open between the two machines? If connection is closed then how to decide when the connection is closed between them?</description>
    </item>
    
    <item>
      <title>Cannot capture l2tp packets using wireshark on windows 7 PC</title>
      <link>/questions/25115/cannot-capture-l2tp-packets-using-wireshark-on-windows-7-pc/</link>
      <pubDate>Mon, 23 Sep 2013 06:51:00 +0000</pubDate>
      
      <guid>/questions/25115/cannot-capture-l2tp-packets-using-wireshark-on-windows-7-pc/</guid>
      <description>Cannot capture l2tp packets using wireshark on windows 7 PC  0 Hi all,
I have one problem, I cannot capture l2tp packets using wireshark on a Windows 7 machine.
Can you please help me ?
Kind regards, Christos
windows 7 l2tp wiresharkasked 23 Sep &#39;13, 06:51
ctsalidis
11●1●1●3
accept rate: 0%
There shopuld be no diffrebce between Win7 and any other OS Wireshark runs on with regards to L2TP, it may be a problem with your capture setup or the farmes recived.</description>
    </item>
    
    <item>
      <title>90% or more of my Packets are BAD CHECKSUM</title>
      <link>/questions/25120/90-or-more-of-my-packets-are-bad-checksum/</link>
      <pubDate>Mon, 23 Sep 2013 09:15:00 +0000</pubDate>
      
      <guid>/questions/25120/90-or-more-of-my-packets-are-bad-checksum/</guid>
      <description>90% or more of my Packets are BAD CHECKSUM  0 Please excuse the newbie nature of my post. I have spent a few weeks trying to &#34;Learn my way&#34; into understanding my issue. But I could use a little mentoring here.
I am the &#34;Tech guy&#34; at a small operation. Whenever anyone tries to grab a a larger web page ( Or requests a series of pages in tabs) the network slows to a halt for everyone.</description>
    </item>
    
    <item>
      <title>upgraded Ubuntu, tons of &amp;#x27;TCP ACKed lost segment&amp;#x27; and other errors...</title>
      <link>/questions/25134/upgraded-ubuntu-tons-of-tcp-acked-lost-segment-and-other-errors/</link>
      <pubDate>Mon, 23 Sep 2013 15:14:00 +0000</pubDate>
      
      <guid>/questions/25134/upgraded-ubuntu-tons-of-tcp-acked-lost-segment-and-other-errors/</guid>
      <description>upgraded Ubuntu, tons of &amp;lsquo;TCP ACKed lost segment&amp;rsquo; and other errors&amp;hellip;  0 I couldn&#39;t find a similar thread, sorry if this is a dup...
I recently upgraded my Ubuntu 12.04 system, running the standard Wireshark 1.6.7, and am betting boatloads of &#34;TCP ACKed lost segment&#34; messages, as well as &#34;TCP Previous segment lost&#34;, and sometimes I&#39;ve even seen FCS errors. Some details about my environment:
Running VirtualBox for my Ubuntu systemsHost OS is Windows 8, Wireshark there runs fine without errorsUpdated VMs are showing the errors aboveOn my lone un-updated Ubuntu system, it runs fine without errorsI&#39;ve uninstalled and reinstalled multiple times with the same issueI&#39;ve compiled from the latest source on an updated system but have the same issueI&#39;m going to try installing a brand new Ubuntu 13.</description>
    </item>
    
    <item>
      <title>Get host name provided in WINS (Nbns) response</title>
      <link>/questions/25142/get-host-name-provided-in-wins-nbns-response/</link>
      <pubDate>Mon, 23 Sep 2013 16:56:00 +0000</pubDate>
      
      <guid>/questions/25142/get-host-name-provided-in-wins-nbns-response/</guid>
      <description>Get host name provided in WINS (Nbns) response  0 I am attempting to generate a list of netbios names and IP addresses from WINS replies.
I would like to find a way to either create custom columns in wireshark and / or get the textual output using tshark. I have not been able to include a slice (IE:frame[55:33]) in a display filter. My Second Stumbling block is that windows encodes (MS calls it compression) the hostname in the reply.</description>
    </item>
    
    <item>
      <title>is wireshark reliable</title>
      <link>/questions/25151/is-wireshark-reliable/</link>
      <pubDate>Tue, 24 Sep 2013 02:24:00 +0000</pubDate>
      
      <guid>/questions/25151/is-wireshark-reliable/</guid>
      <description>is wireshark reliable  0 I have written a code in a device that sends ARP request to get the MAC address of PC and then communicates with it through UDP.
I have an application that makes this happen in a loop.(open the port; ARP request + UDP data packets(few packets); then close the port). the loop is mainly to know the reliability of the device to communicate.
My problem is, I am supposed to get an ARP request continuously.</description>
    </item>
    
    <item>
      <title>Column Sort Order</title>
      <link>/questions/25154/column-sort-order/</link>
      <pubDate>Tue, 24 Sep 2013 03:40:00 +0000</pubDate>
      
      <guid>/questions/25154/column-sort-order/</guid>
      <description>Column Sort Order  0 The ability to sort the column order by clicking on the column header seems to have disappeared. Sort options on right mouse-click are greyed out also. Tried searching &#39;help&#39; and &#39;faq&#39;s&#39; also but not show any results.
column sort orderasked 24 Sep &#39;13, 03:40
Beans
1●1●1●1
accept rate: 0%
Which version and OS, and do you have a screenshot?
(24 Sep &#39;13, 03:41) Jasper ♦♦   </description>
    </item>
    
    <item>
      <title>LDAP SSL decrypt issue</title>
      <link>/questions/25156/ldap-ssl-decrypt-issue/</link>
      <pubDate>Tue, 24 Sep 2013 06:16:00 +0000</pubDate>
      
      <guid>/questions/25156/ldap-ssl-decrypt-issue/</guid>
      <description>LDAP SSL decrypt issue  0 Hi everybody,
I&#39;m trying to debug LDAP SSL communication and experience a problem with SSL decryption. I start my capturing before any handshake so I&#39;m able to see the whole SSL handshake. But after that an application establishes another session which is a short version with ClientHello-&amp;gt;ServerHello, ChangeCipherSpec, Finished. And after that handshake I&#39;m unable to decode client packets while server are still readable.</description>
    </item>
    
    <item>
      <title>Can not decrypt SSL PSK traffic</title>
      <link>/questions/25157/can-not-decrypt-ssl-psk-traffic/</link>
      <pubDate>Tue, 24 Sep 2013 06:20:00 +0000</pubDate>
      
      <guid>/questions/25157/can-not-decrypt-ssl-psk-traffic/</guid>
      <description>Can not decrypt SSL PSK traffic  0 Hi, in our project we use SSL PSK encryption with a 20 byte binary key. I hope we read all available documentation about that but we were not able to decrypt the traffic even when we have the complete traffic and the PSK key.
The example works with a 16 byte text password. As said we use a 20 byte binary password.</description>
    </item>
    
    <item>
      <title>Filters/Expressions??</title>
      <link>/questions/25165/filtersexpressions/</link>
      <pubDate>Tue, 24 Sep 2013 11:03:00 +0000</pubDate>
      
      <guid>/questions/25165/filtersexpressions/</guid>
      <description>Filters/Expressions??  0 Hello, I am very new to this software and was asked to gather some information on packet delivery. We have a machine that is on our DMZ subnet that we are looking to capture the packet sent packet delivered info from. How do I build a filter where we can log the traffic going to and from that machine only from a desktop on the same subnet?</description>
    </item>
    
    <item>
      <title>IE sends [RST,ACK] right after [ACK] from server</title>
      <link>/questions/25166/ie-sends-rstack-right-after-ack-from-server/</link>
      <pubDate>Tue, 24 Sep 2013 11:47:00 +0000</pubDate>
      
      <guid>/questions/25166/ie-sends-rstack-right-after-ack-from-server/</guid>
      <description>IE sends [RST,ACK] right after [ACK] from server  0 Some clients with IE are sending [RST, ACK] response right after receiving [ACK] from the server. Is there are reason why it could be happening? This seems to be not occurring in Firefox.
 1113 2013-09-23 09:49:48.514472000 tor1ws03415.ad.ent.ctc.com cfsecm.ctc.com HTTP 57963 http 653 GET /eclient/ctcCustom/JS/extJS/resources/images/default/tree/elbow.gif HTTP/1.1 1114 2013-09-23 09:49:48.515179000 cfsecm.ctc.com tor1ws03415.ad.ent.ctc.com TCP http 57963 60 http &amp;gt; 57963 [ACK] Seq=108815 Ack=16847 Win=12440 Len=0</description>
    </item>
    
    <item>
      <title>Timestamp issue in 1.10.2 on windows</title>
      <link>/questions/25168/timestamp-issue-in-1102-on-windows/</link>
      <pubDate>Tue, 24 Sep 2013 12:28:00 +0000</pubDate>
      
      <guid>/questions/25168/timestamp-issue-in-1102-on-windows/</guid>
      <description>Timestamp issue in 1.10.2 on windows  1 I have started seeing a strange issue on a new platform I am using. It is a Microsoft hyper-v environment with virtual guests running XP. I installed the latest wireshark/winpcap and started testing some applications but noticed that the timestamps do two very strange things.
A conversation might be &#39;out of sync&#39; by 3.14 seconds. That is, the request will show what appears to be the &#34;</description>
    </item>
    
    <item>
      <title>Malformed packet: EPM</title>
      <link>/questions/25181/malformed-packet-epm/</link>
      <pubDate>Tue, 24 Sep 2013 17:29:00 +0000</pubDate>
      
      <guid>/questions/25181/malformed-packet-epm/</guid>
      <description>Malformed packet: EPM  0 Hi, Is there anyone had experienced to worked on trobleshooting the malformed packet:epm alerts from the expert infos? While i&#39;m working on my trace file I notice these alerts in several frame (about 15 times). I working on the outlook slowdown issue.
packet malformedasked 24 Sep &#39;13, 17:29
lma
1●1●1●1
accept rate: 0%
If possible, please upload a capture file to cloudshark and provide the link to it so someone can perform some analysis on it.</description>
    </item>
    
    <item>
      <title>Using Wireshark to find out what&amp;#x27;s causing slowness in streamiung youtube videos</title>
      <link>/questions/25187/using-wireshark-to-find-out-whats-causing-slowness-in-streamiung-youtube-videos/</link>
      <pubDate>Tue, 24 Sep 2013 22:36:00 +0000</pubDate>
      
      <guid>/questions/25187/using-wireshark-to-find-out-whats-causing-slowness-in-streamiung-youtube-videos/</guid>
      <description>Using Wireshark to find out what&amp;rsquo;s causing slowness in streamiung youtube videos  0 Hello Experts,
I am streaming a youtube video on my system. Sometimes it plays very fast and sometimes it just becomes slow. I want to know how to use wireshark to find out where the problem is coming from. Whether its coming from network fluctuations from my ISP or wherever.
Thank you.
youtubeasked 24 Sep &#39;13, 22:36</description>
    </item>
    
    <item>
      <title>Search In:Packet list not working on a particular interface.</title>
      <link>/questions/25188/search-inpacket-list-not-working-on-a-particular-interface/</link>
      <pubDate>Wed, 25 Sep 2013 01:08:00 +0000</pubDate>
      
      <guid>/questions/25188/search-inpacket-list-not-working-on-a-particular-interface/</guid>
      <description>Search In:Packet list not working on a particular interface.  0 In wireshark 1.8.5, for wimax-btsCapc interface, searching for a packet through Packet list doesn&#39;t show any output. But searching for the same through &#39;Packet Details&#39; option works. Where could be the probable defect?
searchasked 25 Sep &#39;13, 01:08
sunshine
16●5●5●9
accept rate: 0%
  
2 Answers:
  
0Not all packet details are available in the packet list (there is only a summary line), so a &#34;</description>
    </item>
    
    <item>
      <title>Plugin - dlg_utils in dissector</title>
      <link>/questions/25189/plugin-dlg_utils-in-dissector/</link>
      <pubDate>Wed, 25 Sep 2013 01:51:00 +0000</pubDate>
      
      <guid>/questions/25189/plugin-dlg_utils-in-dissector/</guid>
      <description>Plugin - dlg_utils in dissector  0 I&#39;ve been trying to incorporate some GUI utils in a dissector which is being developed as a plugin for Wireshark. The functionalities I need are the ones declared in ui/gtk/dlg_utils.h, specially the function dlg_window_new. I have linked libgtkui.lib (also present in ui/gtk) in the relevant Makefile, but this library apparently requires the linkage of many other ones. Should libgtkui.lib be kind of stand-alone? If it should, what&#39;s been done wrong?</description>
    </item>
    
    <item>
      <title>Wireshark drops outgoing udp traffic!</title>
      <link>/questions/25196/wireshark-drops-outgoing-udp-traffic/</link>
      <pubDate>Wed, 25 Sep 2013 02:31:00 +0000</pubDate>
      
      <guid>/questions/25196/wireshark-drops-outgoing-udp-traffic/</guid>
      <description>Wireshark drops outgoing udp traffic!  0 Hello,
Currently I am using Wireshark 1.10.2 (Win 7-64bit) and I am sending udp traffic to another device through Ethernet port. Other tools like Microsoft Network Monitor (I need Wireshark for some of its packet checking features) work find, but as soon as I start Wireshark listening, it drops outgoing packets. I can see outgoing packets in Wireshark, but they are not send to the end device anymore!</description>
    </item>
    
    <item>
      <title>MAC address resolution in tshark</title>
      <link>/questions/25197/mac-address-resolution-in-tshark/</link>
      <pubDate>Wed, 25 Sep 2013 02:47:00 +0000</pubDate>
      
      <guid>/questions/25197/mac-address-resolution-in-tshark/</guid>
      <description>MAC address resolution in tshark  0 Hi all,
I&#39;m trying to solve a problem directly related with MAC address resolution in tshark. Our purpose is to be able to filter packages from specific brands, for instance Apple, Samsung, etc...
[http://ask.wireshark.org/questions/24314/possible-to-use-the-mac-info-in-the-wireshark-manuf-file-as-part-of-display-filter?page=1&amp;amp;focusedAnswerId=24607#24607][1]
First of all, we&#39;re getting the mac addresses but the MAC resolution doesn&#39;t work at all:
tshark version -&amp;gt; 1.10.2
sudo tshark -i wlan1 -N mntC -T fields -e wlan.</description>
    </item>
    
    <item>
      <title>undefined reference to `tvb_bcd_dig_to_ep_str&amp;#x27;</title>
      <link>/questions/25201/undefined-reference-to-tvb_bcd_dig_to_ep_str/</link>
      <pubDate>Wed, 25 Sep 2013 03:56:00 +0000</pubDate>
      
      <guid>/questions/25201/undefined-reference-to-tvb_bcd_dig_to_ep_str/</guid>
      <description>undefined reference to `tvb_bcd_dig_to_ep_str&#39;  0 I&#39;m compiling the source code with some modification. Before running, my source was built several times successfully, but today when I run it again , there are some errors that I don&#39;t know what the reason is. I commented out new modification I made today but still failed. I modified a lot in the code so, it is quite difficult to comment out all of them, one by one to know where the error is.</description>
    </item>
    
    <item>
      <title>print file</title>
      <link>/questions/25209/print-file/</link>
      <pubDate>Wed, 25 Sep 2013 05:03:00 +0000</pubDate>
      
      <guid>/questions/25209/print-file/</guid>
      <description>print file  0 Tell me, please, where i can read about what information shown in file, created on windows after printing into file?
printasked 25 Sep &#39;13, 05:03
ovo
6●1●1●2
accept rate: 0%
  
One Answer:
  
0 See the docs.
http://www.wireshark.org/docs/wsug_html_chunked/ChIOPrintSection.html
It depends on the options you chose while printing.
If it was a plain text file, that file will contain the ASCII representation of the dissected packets (protocol details) as defined in &#39;Packet Format&#39;.</description>
    </item>
    
    <item>
      <title>Why am I getting DUP ACK from the HOST and retransmissions from the SERVER?</title>
      <link>/questions/25211/why-am-i-getting-dup-ack-from-the-host-and-retransmissions-from-the-server/</link>
      <pubDate>Wed, 25 Sep 2013 06:36:00 +0000</pubDate>
      
      <guid>/questions/25211/why-am-i-getting-dup-ack-from-the-host-and-retransmissions-from-the-server/</guid>
      <description>Why am I getting DUP ACK from the HOST and retransmissions from the SERVER?  0 When I see the trace in wireshark, what I see is the client sending DUP ACK to the server and the server keeps on Retransmitting the data? What does this situation signify? How to correct this?
dupack retransmissionsasked 25 Sep &#39;13, 06:36
Vaibhav Khare
1●1●1●1
accept rate: 0%
 edited 25 Sep &#39;13, 11:21</description>
    </item>
    
    <item>
      <title>tshark can&amp;#x27;t get the ip.src when capture packets on wlan</title>
      <link>/questions/25223/tshark-cant-get-the-ipsrc-when-capture-packets-on-wlan/</link>
      <pubDate>Wed, 25 Sep 2013 09:16:00 +0000</pubDate>
      
      <guid>/questions/25223/tshark-cant-get-the-ipsrc-when-capture-packets-on-wlan/</guid>
      <description>tshark can&amp;rsquo;t get the ip.src when capture packets on wlan  0 hello! Recently, I try to capture packets with tshark. I execute airmon-ng start wlan0 to set my wireless network card to monitor mode, and then excute tshark -i mon0 -Tfields -e frame.time_relative -e frame.len -e radiotap.datarate -e radiotap.dbm_antsignal -e ip.src -e ip.dst -Eseparator=# &amp;gt;channel_6.txt -a duration:10&amp;amp; , but ip.src and ip.dst don&#39;t display anything. I try using -V, and find that IP was not been parsed.</description>
    </item>
    
    <item>
      <title>Can see RTP stream but couldn&amp;#x27;t found SIP or H.323</title>
      <link>/questions/25224/can-see-rtp-stream-but-couldnt-found-sip-or-h323/</link>
      <pubDate>Wed, 25 Sep 2013 09:38:00 +0000</pubDate>
      
      <guid>/questions/25224/can-see-rtp-stream-but-couldnt-found-sip-or-h323/</guid>
      <description>Can see RTP stream but couldn&amp;rsquo;t found SIP or H.323  0 I am trying to analyze some voip traffic in Wireshark. But all I could see are small UDP packets; some containing RTP streams and I can see various codec information like G.711, G.723 etc. But there is no sign of SIP or any other signaling packets. Is it possible to hide SIP or H323 signalling within UDP packets in a way which are undetectable to Wireshark?</description>
    </item>
    
    <item>
      <title>Wireshark support for USB Alfa Network wireless adapter AWUS036NH</title>
      <link>/questions/25229/wireshark-support-for-usb-alfa-network-wireless-adapter-awus036nh/</link>
      <pubDate>Wed, 25 Sep 2013 10:53:00 +0000</pubDate>
      
      <guid>/questions/25229/wireshark-support-for-usb-alfa-network-wireless-adapter-awus036nh/</guid>
      <description>Wireshark support for USB Alfa Network wireless adapter AWUS036NH  0 I have an Alfa Network USB wireless adapter AWUS036NH. Can it be used to capture wireless management traffic in Wireshark? It does not show up in the list of interfaces in Wireshark. I was told it provided support within Windows 7.
captureasked 25 Sep &#39;13, 10:53
mfuszner
11●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>tshark and tcpreplay together?</title>
      <link>/questions/25230/tshark-and-tcpreplay-together/</link>
      <pubDate>Wed, 25 Sep 2013 11:23:00 +0000</pubDate>
      
      <guid>/questions/25230/tshark-and-tcpreplay-together/</guid>
      <description>tshark and tcpreplay together?  0 I&#39;ve got a python script that launches tshark and then uses tcpreplay to inject packets onto a small network. After tshark stops capturing and writes a pcap to disk, I attempt to use another tshark call to translate that capture to text for parsing. This last bit doesn&#39;t work. I see &#39;tshark: Unrecognized libpcap format&#39; on screen. Code looks like this:
# Capture and Translate calls for tshark tsharkCapture = shlex.</description>
    </item>
    
    <item>
      <title>Wireshark and Linux</title>
      <link>/questions/25242/wireshark-and-linux/</link>
      <pubDate>Wed, 25 Sep 2013 13:38:00 +0000</pubDate>
      
      <guid>/questions/25242/wireshark-and-linux/</guid>
      <description>Wireshark and Linux  0 I am trying to open Wireshark in the command prompt using sudo -i Wireshark, but it keeps telling me command not found. When I type in just Wireshark, the program will open. Any idea why I cannot open Wireshark via sudo command?
sudo wireshark linuxasked 25 Sep &#39;13, 13:38
Renee
1●1●1●1
accept rate: 0%
 edited 25 Sep &#39;13, 14:04 
Kurt Knochner ♦
24.8k●10●39●237</description>
    </item>
    
    <item>
      <title>Can videos (or links to videos) be included under a Creative Commons license?</title>
      <link>/questions/25248/can-videos-or-links-to-videos-be-included-under-a-creative-commons-license/</link>
      <pubDate>Wed, 25 Sep 2013 16:17:00 +0000</pubDate>
      
      <guid>/questions/25248/can-videos-or-links-to-videos-be-included-under-a-creative-commons-license/</guid>
      <description>Can videos (or links to videos) be included under a Creative Commons license?  0 We&#39;re developing cybersecurity-related courseware that will be distributed under a Creative Commons license for non-commercial educational institutions. I&#39;d like to include some of the videos (or links/references to those videos) but I wanted to make sure that would be clear to include the videos or references to the videos under a Creative Commons license.
Thanks!</description>
    </item>
    
    <item>
      <title>Wireless Cisco CAPWAP header size</title>
      <link>/questions/25254/wireless-cisco-capwap-header-size/</link>
      <pubDate>Wed, 25 Sep 2013 18:45:00 +0000</pubDate>
      
      <guid>/questions/25254/wireless-cisco-capwap-header-size/</guid>
      <description>Wireless Cisco CAPWAP header size  0 I did a capture with wireshark on the port where our Cisco 3500 AP is connected and I have a ton of errors for the CAPWAP header.
The &#34;Expert Info&#34; Message is (Warn/Malformed): Wrong Calculate length (11) =! header lenght (15) ! (May be try to use Cisco Wireless Controller Support Preference ?)
I did a capture at the end of the day when I was the only one in the office (PC, iPhone, a couple of iPads) and I did it during the middle of the day with a good number of clients connected a lot more Apple products.</description>
    </item>
    
    <item>
      <title>Can only see a bit of iphone traffic, but can see all macbook traffic on third computer</title>
      <link>/questions/25258/can-only-see-a-bit-of-iphone-traffic-but-can-see-all-macbook-traffic-on-third-computer/</link>
      <pubDate>Thu, 26 Sep 2013 00:01:00 +0000</pubDate>
      
      <guid>/questions/25258/can-only-see-a-bit-of-iphone-traffic-but-can-see-all-macbook-traffic-on-third-computer/</guid>
      <description>Can only see a bit of iphone traffic, but can see all macbook traffic on third computer  0 0 down vote favorite
I have three devices on a wireless network. One is a linux desktop, which is running wireshark, and I am trying to use the desktop to monitor the wireless traffic on my network. The other two devices on the network are an iphone and a macbook pro.</description>
    </item>
    
    <item>
      <title>How to disect an additional TCP Option Field?</title>
      <link>/questions/25259/how-to-disect-an-additional-tcp-option-field/</link>
      <pubDate>Thu, 26 Sep 2013 00:16:00 +0000</pubDate>
      
      <guid>/questions/25259/how-to-disect-an-additional-tcp-option-field/</guid>
      <description>How to disect an additional TCP Option Field?  0 Hi All,
I am new to Dissectors in Lua. I have a very good idea on how to dissect an complete header but I am not sure how to go about dissecting a sub-field. For example if I have a TCP Option which is additional to the normal options (MSS,window scale,nop,timestamp,TCP SACK - not necessarily in that order) how will I parse the option?</description>
    </item>
    
    <item>
      <title>Display filter help</title>
      <link>/questions/25271/display-filter-help/</link>
      <pubDate>Thu, 26 Sep 2013 04:34:00 +0000</pubDate>
      
      <guid>/questions/25271/display-filter-help/</guid>
      <description>Display filter help  0 Below are the display filters in wireshark 1.2. I am not able find corresponding filters in Wireshark 1.6.7. Could you please help ?
wlan_mgt.wme.be.ac_param.acm wlan_mgt.wme.bg.ac_param.acm wlan_mgt.wme.video.ac_param.acm wlan_mgt.wme.voice.ac_param.acm wlan_mgt.extchanswitch.new.channumber wlan_mgt.ht.info wlan_mgt.extchanswitch.new.regclass wlan_mgt.extchanswitch.switchmode wlan_mgt.measure.req.repcond wlan_mgt.measure.req.reportmac wlan_mgt.measure.req.reqmode.reserved1 wlan_mgt.measure.req.reqmode.reserved2 wlan_mgt.measure.req.thresholddisplay-filterasked 26 Sep &#39;13, 04:34
Keerthi
11●2●2●4
accept rate: 0%
 edited 26 Sep &#39;13, 09:11 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
2Please check here</description>
    </item>
    
    <item>
      <title>Display filters for AC parameters for different QOS access categories are missing in Wireshark 1.67 version</title>
      <link>/questions/25273/display-filters-for-ac-parameters-for-different-qos-access-categories-are-missing-in-wireshark-167-version/</link>
      <pubDate>Thu, 26 Sep 2013 05:17:00 +0000</pubDate>
      
      <guid>/questions/25273/display-filters-for-ac-parameters-for-different-qos-access-categories-are-missing-in-wireshark-167-version/</guid>
      <description>Display filters for AC parameters for different QOS access categories are missing in Wireshark 1.67 version  0 Hello,
In wireshark 1.2 version, we had display filters such as
wlan_mgt.wme.be.ac_param.ecwmin==7 or wlan_mgt.wme.bg.ac_param.txop_limit==$value
where it will filter out packets with ecwmin=7 in specific access category like BE/Voice/BG/Video.
In wireshark 1.67 or higher, this display filter for each Access category is not provided.
Instead they have just given a filter for each AC parameters common for all QOS access categories like below</description>
    </item>
    
    <item>
      <title>not a valid display filter</title>
      <link>/questions/25274/not-a-valid-display-filter/</link>
      <pubDate>Thu, 26 Sep 2013 05:55:00 +0000</pubDate>
      
      <guid>/questions/25274/not-a-valid-display-filter/</guid>
      <description>not a valid display filter  0 In 1.8.5, One of my protocol &#34;wimax-btsbts&#34; is not getting registered. If I try to apply filter &#39;wimax-btsbts&#39;, wireshark pop-ups a notification saying Wiax-btsbts is not a valid display filter. I have removed the below last lines :
#ifndef ENABLE_STATIC
G_MODULE_EXPORT void
plugin_register(void){
/*register the new protocol, protocol fields, and subtrees */ if (proto_btsBts == -1) { /* execute protocol initialization only once */ proto_register_BTS_BTS(); }}</description>
    </item>
    
    <item>
      <title>ssl_encryption_issue</title>
      <link>/questions/25281/ssl_encryption_issue/</link>
      <pubDate>Thu, 26 Sep 2013 07:02:00 +0000</pubDate>
      
      <guid>/questions/25281/ssl_encryption_issue/</guid>
      <description>ssl_encryption_issue  0 I captured the FaceTime application (from iPAD) traffic and which is in SSL format. I need to get into TLSV1 format to read and understand this format. so I could I get the TLSV1 format from the SSL format. please help me in decrypting the same.
please find the some SSL format packets as shown below.
23 20.393657 115.111.14.7 17.154.239.13 TCP 82 49358 &amp;gt; https [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=16 32 20.</description>
    </item>
    
    <item>
      <title>Trying to find which workstation has trojan zbot on it</title>
      <link>/questions/25283/trying-to-find-which-workstation-has-trojan-zbot-on-it/</link>
      <pubDate>Thu, 26 Sep 2013 09:46:00 +0000</pubDate>
      
      <guid>/questions/25283/trying-to-find-which-workstation-has-trojan-zbot-on-it/</guid>
      <description>Trying to find which workstation has trojan zbot on it  0 My home ip address is blacklisted on http://cbl.abuseat.org/lookup.cgi?ip=63.142.130.18&amp;amp;.pubmit=Lookup and they state that a workstation in my home is infected with the ZeuS trojan, also known as &#34;Zbot&#34; and &#34;WSNPoem&#34;
I delisted my ip address but am back on the list, which affects my email deliverability.
I have spent all morning trying to use Wireshark to sniff the traffic on my entire network looking for the workstation that is communicating with the external ip address that they have identified the information is being sent to, although in this case it is a sinkhole.</description>
    </item>
    
    <item>
      <title>32.298 R 9.6.0 support on wireshark</title>
      <link>/questions/25296/32298-r-960-support-on-wireshark/</link>
      <pubDate>Thu, 26 Sep 2013 20:19:00 +0000</pubDate>
      
      <guid>/questions/25296/32298-r-960-support-on-wireshark/</guid>
      <description>32.298 R 9.6.0 support on wireshark  0 Which version of wireshark support 32.298 Rel 9.6.0.
I am using 10.1 wirshark. It does not decode CDRs of Release 9.6.0
Please help
asn.1 32.298 cdrasked 26 Sep &#39;13, 20:19
JOJO1015
1●1●1●1
accept rate: 0%
  
One Answer:
  
0CDR over GTP, right? I think it should work in trunk. Open a bug report with a small sample file so we can take look and see what might be the problem.</description>
    </item>
    
    <item>
      <title>VoIP calls finding</title>
      <link>/questions/25297/voip-calls-finding/</link>
      <pubDate>Thu, 26 Sep 2013 22:48:00 +0000</pubDate>
      
      <guid>/questions/25297/voip-calls-finding/</guid>
      <description>VoIP calls finding  0 Dear Sirs, Please, could you be so kind to tell me how I could find an exact phone call data in a huge VoIP calls filtered by VoIP calls Tab? My E mails is: [email protected]
finding calls voipasked 26 Sep &#39;13, 22:48
Alex7
11●1●1●2
accept rate: 0%
The fact is that there is no possibility to find specific call within the frame of aready filtered VoIP tab.</description>
    </item>
    
    <item>
      <title>Apps for GSM packet analysis</title>
      <link>/questions/25301/apps-for-gsm-packet-analysis/</link>
      <pubDate>Fri, 27 Sep 2013 00:02:00 +0000</pubDate>
      
      <guid>/questions/25301/apps-for-gsm-packet-analysis/</guid>
      <description>Apps for GSM packet analysis  0 Hi, i wanted to know if these apps &#34;Shark for Root&#34; and &#34;Microsoft Network Analyzer&#34; are able to perform GSM packets capture on a cell phone? later to be transferred to a computer and analyzed on Wireshark.
android gsm wiresharkasked 27 Sep &#39;13, 00:02
Arslan
11●1●1●2
accept rate: 0%
 converted 27 Sep &#39;13, 00:10 
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark crashes upon clicking on fields of expanded trees</title>
      <link>/questions/25304/wireshark-crashes-upon-clicking-on-fields-of-expanded-trees/</link>
      <pubDate>Fri, 27 Sep 2013 02:28:00 +0000</pubDate>
      
      <guid>/questions/25304/wireshark-crashes-upon-clicking-on-fields-of-expanded-trees/</guid>
      <description>Wireshark crashes upon clicking on fields of expanded trees  0 In 1.8.5, for custom Wimax-btsbts interface, wireshark crashes upon clicking on any of the field. Help.
crashasked 27 Sep &#39;13, 02:28
sunshine
16●5●5●9
accept rate: 0%
Can we have crash message ?
(27 Sep &#39;13, 03:13) AfrimUpon debugging through Visual C++,following error msg is dispalyed :
&#34;Unhandled exception at 0x77c478ac in wireshark.exe: 0xC0000005: Access violation reading location 0x00000003.&#34;
Call stack location is somewhere in msvcrt.</description>
    </item>
    
    <item>
      <title>Remote shell troubleshooting</title>
      <link>/questions/25305/remote-shell-troubleshooting/</link>
      <pubDate>Fri, 27 Sep 2013 02:53:00 +0000</pubDate>
      
      <guid>/questions/25305/remote-shell-troubleshooting/</guid>
      <description>Remote shell troubleshooting  0 Hello, everybody.
Please, if this is not the right place, tell me where I should send this question.
A TWAIN driver installed in a workstation uses remote shell (RSH) to connect to a multifunction printer in other subnet in order to scan through the network. A Checkpoint firewall routes packets between both networks and the right ACLs have been configured.
The first command sent by the workstation instructs the MFP to redirect standard error (stderr) console to port 1022.</description>
    </item>
    
    <item>
      <title>Simple block in PCapNg</title>
      <link>/questions/25317/simple-block-in-pcapng/</link>
      <pubDate>Fri, 27 Sep 2013 08:25:00 +0000</pubDate>
      
      <guid>/questions/25317/simple-block-in-pcapng/</guid>
      <description>Simple block in PCapNg  0 Hello, I have included PCapNg files support to my program, so it can open, read and write such files. It works fine when it writes enhanced blocks to the output file, they are seen and interpreted in WireShark correctly. Though when it writes simple blocks the output file starts looking for WireShark as corrupted and it issues an error &#34;pcapng: interface index 3111035224 is not less than interface count 1&#34;</description>
    </item>
    
    <item>
      <title>Microburst analysis for wireshark</title>
      <link>/questions/25318/microburst-analysis-for-wireshark/</link>
      <pubDate>Fri, 27 Sep 2013 08:27:00 +0000</pubDate>
      
      <guid>/questions/25318/microburst-analysis-for-wireshark/</guid>
      <description>Microburst analysis for wireshark  0 Hello,
I am suspecting microbursts happening at time intervals too short to show up in i/o statistics in some pcap files.
Does wireshark have built-in automated search through large captures to find microbursts?
Is there a way to get a better resolution than 0.001s in i/o Graph ?
Thanks.
graphs microburstasked 27 Sep &#39;13, 08:27
Metakent
1●1●1●1
accept rate: 0%
 edited 27 Sep &#39;13, 08:44</description>
    </item>
    
    <item>
      <title>MacBookPro on Airport Extreme WPA2 Password Network Only Sees Its Own Traffic</title>
      <link>/questions/25327/macbookpro-on-airport-extreme-wpa2-password-network-only-sees-its-own-traffic/</link>
      <pubDate>Fri, 27 Sep 2013 19:45:00 +0000</pubDate>
      
      <guid>/questions/25327/macbookpro-on-airport-extreme-wpa2-password-network-only-sees-its-own-traffic/</guid>
      <description>MacBookPro on Airport Extreme WPA2 Password Network Only Sees Its Own Traffic  0 Hi,
I have a MacBookPro3,1 (OS X 10.8.5) on an Airport Extreme network. I am running Wireshark 1.10.2. The problem I have is that I only see traffic directed to/from my system, despite the fact I know that there is other traffic on the WiFi network (such as from an identical MBP next to the one running WireShark and streaming traffic to Apple TV).</description>
    </item>
    
    <item>
      <title>how to use wireshark to capture packets from standard input</title>
      <link>/questions/25329/how-to-use-wireshark-to-capture-packets-from-standard-input/</link>
      <pubDate>Sat, 28 Sep 2013 01:47:00 +0000</pubDate>
      
      <guid>/questions/25329/how-to-use-wireshark-to-capture-packets-from-standard-input/</guid>
      <description>how to use wireshark to capture packets from standard input  0 In our program (written in Java, run on Windows), we have packets captured on our own device, and send to the Java program via a inner callback. Formerly, we decode these packet by ourselves, but there&#39;s some performance problem. Now we want to use Wireshark instead. I&#39;ve found that wireshark can capture packets from standard input, by using the following command line: wireshark -k -i -.</description>
    </item>
    
    <item>
      <title>http.cookie contains “datr”  not working on Wireshark</title>
      <link>/questions/25332/httpcookie-contains-datr-not-working-on-wireshark/</link>
      <pubDate>Sat, 28 Sep 2013 09:56:00 +0000</pubDate>
      
      <guid>/questions/25332/httpcookie-contains-datr-not-working-on-wireshark/</guid>
      <description>http.cookie contains “datr” not working on Wireshark  0 Hi guys After sniffing for 10 minutes, I have stopped the process and when I enter ths ---&amp;gt; http.cookie contains “datr” in the Filter box for search it says ” http.cookie contains “datr” isn’t a valid display filter: ” ” was unexpected in this context. ”
I want to use Wireshark for Facebook
Why is it wrong?? please reply me quickly</description>
    </item>
    
    <item>
      <title>PCAP-NG header data (IDB options) in Wireshark GUI</title>
      <link>/questions/25338/pcap-ng-header-data-idb-options-in-wireshark-gui/</link>
      <pubDate>Sun, 29 Sep 2013 02:36:00 +0000</pubDate>
      
      <guid>/questions/25338/pcap-ng-header-data-idb-options-in-wireshark-gui/</guid>
      <description>PCAP-NG header data (IDB options) in Wireshark GUI  0 My program writes PCAP-NG files. I open them with Wireshark.
Among others, my program writes in the Section Header Block its name and a description of the platform (options shb_ hardware, shb_ os, shb_ userappl) and for each Interface Description Block a description of the network interface and the capture filter (options if_ description and if_ filter).
All these data i can see when i open the dump file with Wireshark and look at Statistics-&amp;gt;Summary.</description>
    </item>
    
    <item>
      <title>Wireshark takes all RAM</title>
      <link>/questions/25343/wireshark-takes-all-ram/</link>
      <pubDate>Sun, 29 Sep 2013 17:29:00 +0000</pubDate>
      
      <guid>/questions/25343/wireshark-takes-all-ram/</guid>
      <description>Wireshark takes all RAM  0 That&#39;s my biggest complain. Sometimes I fire it up to capture sip||rtp and forget about it. When I come back next day my PC feels crippled. Sometimes I don&#39;t notice that problem right away and keep working half a day on barely breathing pc.
Isn&#39;t there some kind of backup file for ongoing capture to dump excessively huge captures? Why is that wireshark.exe ends up eating 4-5GB of ram over a couple of days?</description>
    </item>
    
    <item>
      <title>Bug in RTP dissector if RTP extension is present</title>
      <link>/questions/25345/bug-in-rtp-dissector-if-rtp-extension-is-present/</link>
      <pubDate>Sun, 29 Sep 2013 17:38:00 +0000</pubDate>
      
      <guid>/questions/25345/bug-in-rtp-dissector-if-rtp-extension-is-present/</guid>
      <description>Bug in RTP dissector if RTP extension is present  0 It&#39;s been a while this bug is present and it&#39;s annoying as hell to explain everyone that it&#39;s not our code produces malformed packets but whireshark has this bug.
Basically, when RTP extension is present wireshark shows this:
43 17:14:58.142025 10.0.105.172 64.254.226.140 RTP PT=H264, SSRC=0xEDE18064, Seq=5, Time=0, Mark[Malformed Packet]Here&#39;s sample pcap file with malformed RTP packet (#8)
Wireshark version: Version 1.</description>
    </item>
    
    <item>
      <title>Utilization graph shows more than the actual bandwidth</title>
      <link>/questions/25349/utilization-graph-shows-more-than-the-actual-bandwidth/</link>
      <pubDate>Sun, 29 Sep 2013 18:37:00 +0000</pubDate>
      
      <guid>/questions/25349/utilization-graph-shows-more-than-the-actual-bandwidth/</guid>
      <description>Utilization graph shows more than the actual bandwidth  0 I have a total of T1 link that i was trying to analyze how bandwidth is been used by different applications. What I can see the default graph show a big line, suggesting how the total traffic was when the trace took. Ideally that line should be less than 1.54 Mbps - T1 speed. But i do see spikes above 1.</description>
    </item>
    
    <item>
      <title>Can not browse when run wireshark</title>
      <link>/questions/25353/can-not-browse-when-run-wireshark/</link>
      <pubDate>Sun, 29 Sep 2013 21:16:00 +0000</pubDate>
      
      <guid>/questions/25353/can-not-browse-when-run-wireshark/</guid>
      <description>Can not browse when run wireshark  0 I have Windows 8 Pro. Have installed Wireshark 1.10.2 and WinPcap 4.1.3 on it. when I start the live capture from WiFi, I can not access any site from my browser. What&#39;s wrong? Any error?
capture live browser windows8 errorasked 29 Sep &#39;13, 21:16
rizkihabibie999
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Capture filter - -difference between &amp;quot;host&amp;quot; and &amp;quot;Src&amp;quot;</title>
      <link>/questions/25354/capture-filter-difference-between-host-and-src/</link>
      <pubDate>Sun, 29 Sep 2013 21:21:00 +0000</pubDate>
      
      <guid>/questions/25354/capture-filter-difference-between-host-and-src/</guid>
      <description>Capture filter - -difference between &amp;ldquo;host&amp;rdquo; and &amp;ldquo;Src&amp;rdquo;  0 Hi I&#39;m interested to capture all data leaving certain hosts we are spanning. I&#39;m only interested in the data transmitted from the hosts (either a conversation initiated from the host or a response packet). When I try a filter using &#34;Src x.x.x.x - it appears to work in that I only see traffic with my filtered src address, however I believe I not seeing a bunch of traffic which I should be as when I use the &#34;</description>
    </item>
    
    <item>
      <title>Wireless Connection Problem</title>
      <link>/questions/25358/wireless-connection-problem/</link>
      <pubDate>Sun, 29 Sep 2013 23:58:00 +0000</pubDate>
      
      <guid>/questions/25358/wireless-connection-problem/</guid>
      <description>Wireless Connection Problem  0 Sir I have data dongle(wireless device) to provide wireless internet on my laptop. Can I use wireshark to see the data packet going and coming through my laptop via this data dongle. I tried but in Interface in wireshark it doesnot display wireless connection. Please guide me to see wireless connection in wireshark.
Piyush Sharma
captureproblemsThis question is marked &#34;community wiki&#34;.asked 29 Sep &#39;13, 23:58</description>
    </item>
    
    <item>
      <title>How to see traffic from specific internet line?</title>
      <link>/questions/25359/how-to-see-traffic-from-specific-internet-line/</link>
      <pubDate>Mon, 30 Sep 2013 00:21:00 +0000</pubDate>
      
      <guid>/questions/25359/how-to-see-traffic-from-specific-internet-line/</guid>
      <description>How to see traffic from specific internet line?  0 Hi,
We have 3 internet connection in our organization, how to see traffic from only one internet line in Wireshark. We are ok with display as well as capture filter.
Thanks.
sniffing capture interfaceasked 30 Sep &#39;13, 00:21
pranitkothari
51●5●6●10
accept rate: 100%
  
One Answer:
  
1How to see traffic from specific internet line?
It depends on your setup.</description>
    </item>
    
    <item>
      <title>Force Tshark to ignore Empty pcaps after filtering ?--</title>
      <link>/questions/25360/force-tshark-to-ignore-empty-pcaps-after-filtering-/</link>
      <pubDate>Mon, 30 Sep 2013 00:35:00 +0000</pubDate>
      
      <guid>/questions/25360/force-tshark-to-ignore-empty-pcaps-after-filtering-/</guid>
      <description>Force Tshark to ignore Empty pcaps after filtering ?&amp;ndash;  0 Hello how to make Tshark ignore writing an empty file if the filter in -R doesn&#39;t return any result ?
tsharkasked 30 Sep &#39;13, 00:35
Ziad Kiwan
21●3●3●8
accept rate: 0%
  
One Answer:
  
1 Hello how to make Tshark ignore writing an empty file
by changing the code.
What are you trying to do?</description>
    </item>
    
    <item>
      <title>how to extract Hex data from SSL</title>
      <link>/questions/25371/how-to-extract-hex-data-from-ssl/</link>
      <pubDate>Mon, 30 Sep 2013 04:35:00 +0000</pubDate>
      
      <guid>/questions/25371/how-to-extract-hex-data-from-ssl/</guid>
      <description>how to extract Hex data from SSL  0 Hello, i want to extract the hex data from this SSL but when i type tshark -Vnr -r pcap -R (filter) &amp;gt; textfile i only get the details of the pcap without the hex part so i want to know if there is a way to extract the hex data with the details not the details only, i don&#39;t want to decrypt or anything i just want to extract it to a plain text, thanks.</description>
    </item>
    
    <item>
      <title>Bluetooth Packet tweaking for negative testing</title>
      <link>/questions/25372/bluetooth-packet-tweaking-for-negative-testing/</link>
      <pubDate>Mon, 30 Sep 2013 05:10:00 +0000</pubDate>
      
      <guid>/questions/25372/bluetooth-packet-tweaking-for-negative-testing/</guid>
      <description>Bluetooth Packet tweaking for negative testing  0 Is there any option available in Wireshark to alter a specific Bluetooth RFCOMM packet and to send this altered packet to another Bluetooth Device?
mainly for Bluetooth RFCOMM negative testing.
bluetoothasked 30 Sep &#39;13, 05:10
Ash
1●1●1●1
accept rate: 0%
what you need is Ubertooth
http://www.sharebrained.com/ubertooth/
(30 Sep &#39;13, 07:58) Kurt Knochner ♦  
One Answer:
  
1In brief, no.</description>
    </item>
    
    <item>
      <title>How to decode INAP CS1&#43; in wireshark</title>
      <link>/questions/25373/how-to-decode-inap-cs1-in-wireshark/</link>
      <pubDate>Mon, 30 Sep 2013 05:41:00 +0000</pubDate>
      
      <guid>/questions/25373/how-to-decode-inap-cs1-in-wireshark/</guid>
      <description>How to decode INAP CS1+ in wireshark  0 I have captured a snoop trace between Ericsson CCN and SDP nodes and I am trying to open it in Wireshark. INAP packets are not getting decoded using wireshark.
I have selected SSN 6-252 in INAP protocol preferences section but still no joy...
Pl help if there is any alternate way to open the packet of INAP appln using wireshark...
inapasked 30 Sep &#39;13, 05:41</description>
    </item>
    
    <item>
      <title>Server sending RST Message</title>
      <link>/questions/25374/server-sending-rst-message/</link>
      <pubDate>Mon, 30 Sep 2013 06:46:00 +0000</pubDate>
      
      <guid>/questions/25374/server-sending-rst-message/</guid>
      <description>Server sending RST Message  1 I am developing a server, and client messages are sent through a handset. Server and handset are connected through Wifi.
Client sends a HTTP Post message to server, and server is supposed to reply with a 200 ok. It works in most systems, but in some systems, after the server receives the POST Message, it replies with a TCP RST.
Server IP is: 192.168.1.2 and Client IP is : 192.</description>
    </item>
    
    <item>
      <title>Spam settings for new users</title>
      <link>/questions/25389/spam-settings-for-new-users/</link>
      <pubDate>Mon, 30 Sep 2013 08:07:00 +0000</pubDate>
      
      <guid>/questions/25389/spam-settings-for-new-users/</guid>
      <description>Spam settings for new users  0 Hi admins,
sometimes new users report problems when posting an image or trying to attach a file. Apparently those actions are treated a SPAM.
I wonder how are the spam settings for new users?
Thanks
Kurt
settings upload spamasked 30 Sep &#39;13, 08:07
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15% 
anyone??
See also here: http://ask.wireshark.org/questions/25782/unable-to-add-link-to-other-qa
(09 Oct &#39;13, 01:47) Kurt Knochner ♦I think this is something the guys with two dots behind their name need to answer ;-)</description>
    </item>
    
    <item>
      <title>Are there conditions that can cause Wireshark to &amp;quot;drop&amp;quot; packets?</title>
      <link>/questions/25391/are-there-conditions-that-can-cause-wireshark-to-drop-packets/</link>
      <pubDate>Mon, 30 Sep 2013 08:26:00 +0000</pubDate>
      
      <guid>/questions/25391/are-there-conditions-that-can-cause-wireshark-to-drop-packets/</guid>
      <description>Are there conditions that can cause Wireshark to &amp;ldquo;drop&amp;rdquo; packets?  1 Hi,
I&#39;m using Wireshark 1.8.9 on SLES11 SP1. The environment it is being used in is a lab with very low latencies (~3ms). I&#39;m capturing sequences of packets that consist of sending a single ping to the outside world through 8 sequential collection points, expecting the result of the capture to always consist of 16 packets. Wireshark is reading directly from a single NIC which is supplying the traffic from the 8 collection points.</description>
    </item>
    
    <item>
      <title>Commandline Tools Mac OS X</title>
      <link>/questions/25398/commandline-tools-mac-os-x/</link>
      <pubDate>Mon, 30 Sep 2013 10:08:00 +0000</pubDate>
      
      <guid>/questions/25398/commandline-tools-mac-os-x/</guid>
      <description>Commandline Tools Mac OS X  0 Hi
According to the README in the latest Wireshark.dmg image, the installed should install the command line tools in /Library/Wireshark, but this directory is not even created.
Is there anything I&#39;m missing in the setup process?
cliasked 30 Sep &#39;13, 10:08
f0rd42
11●1●1●2
accept rate: 0%
  
One Answer:
  
1According to the README in the latest Wireshark.dmg image, the installed should install the command line tools in /Library/Wireshark</description>
    </item>
    
    <item>
      <title>Tracking down file deletions on a network share</title>
      <link>/questions/25401/tracking-down-file-deletions-on-a-network-share/</link>
      <pubDate>Mon, 30 Sep 2013 10:12:00 +0000</pubDate>
      
      <guid>/questions/25401/tracking-down-file-deletions-on-a-network-share/</guid>
      <description>Tracking down file deletions on a network share  0 I need to track down who marked what files for deletion when. This is on a network shared drive on a Windows server. If someone can help me set up a capture that will only look for SMB requests and tell me how to crunch that data that would be great!
auditing samba smb deletionasked 30 Sep &#39;13, 10:12
trogdor3000</description>
    </item>
    
    <item>
      <title>Field obfuscation</title>
      <link>/questions/25437/field-obfuscation/</link>
      <pubDate>Tue, 01 Oct 2013 00:36:00 +0000</pubDate>
      
      <guid>/questions/25437/field-obfuscation/</guid>
      <description>Field obfuscation  0 Hi all, for security reasons, I need to obfuscate the MSISDN of my MAP_IAM.pcap files (example). Even if the CRC will not be valid, I need to post-produce a PCAP file having
msisdn: 91726741582XXXinstead of
msisdn: 917267415827F2Could someone point me to in the right direction?
Thanks, Riccardo
field obfuscationasked 01 Oct &#39;13, 00:36
Ric79
31●4●4●9
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Dissector: ignore &amp;quot;0x00&amp;quot; in a string (FT_STRING)?</title>
      <link>/questions/25441/dissector-ignore-0x00-in-a-string-ft_string/</link>
      <pubDate>Tue, 01 Oct 2013 01:45:00 +0000</pubDate>
      
      <guid>/questions/25441/dissector-ignore-0x00-in-a-string-ft_string/</guid>
      <description>Dissector: ignore &amp;ldquo;0x00&amp;rdquo; in a string (FT_STRING)?  0 Hi,
I am writing a custom Wireshark dissector which needs to show some strings. Let me say there is some hex code like &#34;48 65 6c 6c 6f&#34; which is &#34;Hello&#34;. This is interpreted fine by using FT_STRING in the hf_ declaration. If this hex codes contain something like &#34;48 65 6c 6c 6f 00 48 65 6c 6c 6f&#34;, the second &#34;</description>
    </item>
    
    <item>
      <title>Can a Reassembly error be sufficient to kick a client off the system</title>
      <link>/questions/25480/can-a-reassembly-error-be-sufficient-to-kick-a-client-off-the-system/</link>
      <pubDate>Tue, 01 Oct 2013 10:13:00 +0000</pubDate>
      
      <guid>/questions/25480/can-a-reassembly-error-be-sufficient-to-kick-a-client-off-the-system/</guid>
      <description>Can a Reassembly error be sufficient to kick a client off the system  0 We have over 50,000 users on an enterprise application and on occasion users submit a request and the spinning wheel commences and after some time they are kicked out. This is a datacentric databases application that is several tiers deep. The common thread seems to be This would not be enough to kick someone off the system?</description>
    </item>
    
    <item>
      <title>Diameter End-2-End question</title>
      <link>/questions/25481/diameter-end-2-end-question/</link>
      <pubDate>Tue, 01 Oct 2013 11:02:00 +0000</pubDate>
      
      <guid>/questions/25481/diameter-end-2-end-question/</guid>
      <description>Diameter End-2-End question  0 I am using WS on a Diameter trace. I am looking for records that do not have a matching end-to-end value. In the trace file the Diameter packets are identified with a [Request in: xxx] tag or the tag [Answer In: yyy] where xxx and yyy are record numbers. My objective is to find all orphaned Diameter records, meaning the records that do not have a matching end-to-end value or do not have matching Tags (mated Request – Answer).</description>
    </item>
    
    <item>
      <title>pcap anonymisation of msisdn field</title>
      <link>/questions/25483/pcap-anonymisation-of-msisdn-field/</link>
      <pubDate>Tue, 01 Oct 2013 13:05:00 +0000</pubDate>
      
      <guid>/questions/25483/pcap-anonymisation-of-msisdn-field/</guid>
      <description>pcap anonymisation of msisdn field  0 Hi all, I&#39;m trying, for security reasons, to obfuscate some fields of a pcap file (even if CRC will not be valid) The main approach is described here.
tshark -nr myexample.pcap -T fields -e frame.number -e frame.len -e gsm_map.ss.msisdn 1 138 2 218 917267415827f2 3 138 4 138Using this command, I know that the second frame, len 218 bytes, has a msisdn which must be obfuscated.</description>
    </item>
    
    <item>
      <title>using wireshark 1.10.2 with wifi or wlan</title>
      <link>/questions/25490/using-wireshark-1102-with-wifi-or-wlan/</link>
      <pubDate>Tue, 01 Oct 2013 23:17:00 +0000</pubDate>
      
      <guid>/questions/25490/using-wireshark-1102-with-wifi-or-wlan/</guid>
      <description>using wireshark 1.10.2 with wifi or wlan  0 can we use the latest version of wireshark 1.10.2 with wifi or wlan ?
wlan wiresharkasked 01 Oct &#39;13, 23:17
rose
1●1●1●1
accept rate: 0%
 edited 02 Oct &#39;13, 02:06 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
1You can use it the same way that you can use other versions. (And &#34;Wi-Fi&#34; and &#34;WLAN&#34; both refer to IEEE 802.</description>
    </item>
    
    <item>
      <title>Wireshark Filtering SSL record type</title>
      <link>/questions/25492/wireshark-filtering-ssl-record-type/</link>
      <pubDate>Wed, 02 Oct 2013 00:25:00 +0000</pubDate>
      
      <guid>/questions/25492/wireshark-filtering-ssl-record-type/</guid>
      <description>Wireshark Filtering SSL record type  0 Hello, i&#39;m trying to filter some ssl record using ssl.record.content_type==22 but i&#39;m facing a problem if a frame contains 22 and 23 for example, it appears is there a way i can force wireshark to filter the frames that &#34;ONLY&#34; contains 22 not 22 and 23 and w.e ? thanks for the help :)
filter sslasked 02 Oct &#39;13, 00:25
Ziad Kiwan
21●3●3●8</description>
    </item>
    
    <item>
      <title>Tshark and Dissector are in the same project when compiling?</title>
      <link>/questions/25496/tshark-and-dissector-are-in-the-same-project-when-compiling/</link>
      <pubDate>Wed, 02 Oct 2013 02:02:00 +0000</pubDate>
      
      <guid>/questions/25496/tshark-and-dissector-are-in-the-same-project-when-compiling/</guid>
      <description>Tshark and Dissector are in the same project when compiling?  0 Hi all, I&#39;m using both of tshark.c and dissector &#34;packet-camel.c&#34;. i wonder when gcc compiles tshark and Dissector, does it consider them as in the same project? Because when I try to use an extern variable for both of these files, the variable in different files are different. i think that the tshark.c call dissector to do something so that it doesn&#39;t make sense if an extern variable in tshark.</description>
    </item>
    
    <item>
      <title>How do I filter specific sessions from a single capture?</title>
      <link>/questions/25501/how-do-i-filter-specific-sessions-from-a-single-capture/</link>
      <pubDate>Wed, 02 Oct 2013 04:03:00 +0000</pubDate>
      
      <guid>/questions/25501/how-do-i-filter-specific-sessions-from-a-single-capture/</guid>
      <description>How do I filter specific sessions from a single capture?  0 I&#39;m investigating some page timeout issues in a live system. The root problem is a link between Atlassian&#39;s Confluence and Jira; pages in the former time out when embedding content from the latter. This data exchange is primarily JSON and XML over HTTP; a typical single page load might result in 50-70 HTTP requests. Both systems are behind an apache proxy.</description>
    </item>
    
    <item>
      <title>How to capture based on IP header length using a capture filter?</title>
      <link>/questions/25504/how-to-capture-based-on-ip-header-length-using-a-capture-filter/</link>
      <pubDate>Wed, 02 Oct 2013 05:41:00 +0000</pubDate>
      
      <guid>/questions/25504/how-to-capture-based-on-ip-header-length-using-a-capture-filter/</guid>
      <description>How to capture based on IP header length using a capture filter?  0 how to this Display filter syntax convert Capture filter syntax
ip.hdr_len &amp;gt;= 20
ip capture-filter syntaxasked 02 Oct &#39;13, 05:41
stih
11●2●2●6
accept rate: 0%
 edited 02 Oct &#39;13, 08:50 
cmaynard ♦♦
9.4k●10●38●142
  
One Answer:
  
3 The following capture filter should give you what you asked for:
 ip[0]&amp;amp;0x0f &amp;gt;= 5</description>
    </item>
    
    <item>
      <title>Wirehark doesn&amp;#x27;t start on OSX</title>
      <link>/questions/25533/wirehark-doesnt-start-on-osx/</link>
      <pubDate>Wed, 02 Oct 2013 09:10:00 +0000</pubDate>
      
      <guid>/questions/25533/wirehark-doesnt-start-on-osx/</guid>
      <description>Wirehark doesn&amp;rsquo;t start on OSX  0 I have Wireshark as an application in my Applications folder, but when I launched it, I get a &#34;Choose Application&#34; dialog window that lists all of the other installed applications I should consider in order to open Wireshark.app
/Applications/Wireshark.app/contents is the only directory and while I am expecting a GUI interface, I am now wondering if I only have the command-line version installed.</description>
    </item>
    
    <item>
      <title>Wireshark 1.10.2 will not launch from Applications folder in Mac OS 10.8.5</title>
      <link>/questions/25535/wireshark-1102-will-not-launch-from-applications-folder-in-mac-os-1085/</link>
      <pubDate>Wed, 02 Oct 2013 09:30:00 +0000</pubDate>
      
      <guid>/questions/25535/wireshark-1102-will-not-launch-from-applications-folder-in-mac-os-1085/</guid>
      <description>Wireshark 1.10.2 will not launch from Applications folder in Mac OS 10.8.5  0 I just now installed XQuartz 2.7.4 and Wireshark 1.10.2 for the first time. When I try to launch /Applications/Wireshark.app from Finder, I get a &#34;Choose Application&#34; dialogue window listing all of the other apps I should consider in order to open Wireshark.app
From Terminal, I can launch /Applications/Wireshark.app/Contents/Resources/bin/wireshark, which starts X11 and I then get the expected user interface.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t see any packets originating from my IP.</title>
      <link>/questions/25538/cant-see-any-packets-originating-from-my-ip/</link>
      <pubDate>Wed, 02 Oct 2013 09:42:00 +0000</pubDate>
      
      <guid>/questions/25538/cant-see-any-packets-originating-from-my-ip/</guid>
      <description>Can&amp;rsquo;t see any packets originating from my IP.  0 I have a Dell Lattitude E5530 with a Broadcom NetXtreme 57xx Gigibit NIC in it. This isn&#39;t wireless. I just installed Wireshark 1.10.2, this is the first time Wireshark has ever been installed on this laptop. I didn&#39;t add any filters, capture or display. When I run a capture on my NIC, I never see any traffic that originated from my IP addresss.</description>
    </item>
    
    <item>
      <title>File Menu appears in hard-to-read colors</title>
      <link>/questions/25544/file-menu-appears-in-hard-to-read-colors/</link>
      <pubDate>Wed, 02 Oct 2013 11:32:00 +0000</pubDate>
      
      <guid>/questions/25544/file-menu-appears-in-hard-to-read-colors/</guid>
      <description>File Menu appears in hard-to-read colors  0 I have a GUI issue with Wireshark and I&#39;m beginning to think I&#39;m the only one who has this problem. So I&#39;m checking to see if anyone else has this.
When I click the &#34;File&#34; menu (or any other menu), the coloring of the menu items is black text on grey background. Easy to read. When I hover on an option, it changes to black text on dark blue background.</description>
    </item>
    
    <item>
      <title>Duplicate IP address detected but mac doesn&amp;#x27;t exist</title>
      <link>/questions/25554/duplicate-ip-address-detected-but-mac-doesnt-exist/</link>
      <pubDate>Wed, 02 Oct 2013 13:35:00 +0000</pubDate>
      
      <guid>/questions/25554/duplicate-ip-address-detected-but-mac-doesnt-exist/</guid>
      <description>Duplicate IP address detected but mac doesn&amp;rsquo;t exist  0 1I am getting IP address conflicts all over network for months. Trying to locate but not making progress. Wireshark packets indicate duplicate Ip address in use. For example:
duplicate ip address detectect for 192.168.1.1 (cc:52:af:0d:5f:d6) also in use by 02:cb:13:0d:5f:d6) frame (1102).
I look at frame 1102 and sure enough it has an ARP asking who has IP address 192.168.1.254 (happens to be gateway) to please tell 192.</description>
    </item>
    
    <item>
      <title>Can re-transmissions from a single ip identify the source of a problem?</title>
      <link>/questions/25557/can-re-transmissions-from-a-single-ip-identify-the-source-of-a-problem/</link>
      <pubDate>Wed, 02 Oct 2013 14:44:00 +0000</pubDate>
      
      <guid>/questions/25557/can-re-transmissions-from-a-single-ip-identify-the-source-of-a-problem/</guid>
      <description>Can re-transmissions from a single ip identify the source of a problem?  0 WE have a very large enterprise application located in a data-center in Boston. Users are all over the State (WAN MPLS). In analyzing a WireSherk Trace at several clients, the source of all of the transmissions was a load balancer (software CISCO 6509) that front end three Apache servers that distribute the database request into a multi-tier environment.</description>
    </item>
    
    <item>
      <title>All re-transmissions coming from a single source going in one direction.</title>
      <link>/questions/25563/all-re-transmissions-coming-from-a-single-source-going-in-one-direction/</link>
      <pubDate>Wed, 02 Oct 2013 16:52:00 +0000</pubDate>
      
      <guid>/questions/25563/all-re-transmissions-coming-from-a-single-source-going-in-one-direction/</guid>
      <description>All re-transmissions coming from a single source going in one direction.  0 WE have a very large enterprise application located in a data-center in Boston. Users are all over the State (WAN MPLS). In analyzing a WireSherk Trace at several clients, the source of all of the transmissions was a load balancer (software CISCO 6509) that front end three Apache servers that distribute the database request into a multi-tier environment.</description>
    </item>
    
    <item>
      <title>Sort by bandwidth used and show IP address/network name?</title>
      <link>/questions/25575/sort-by-bandwidth-used-and-show-ip-addressnetwork-name/</link>
      <pubDate>Wed, 02 Oct 2013 23:05:00 +0000</pubDate>
      
      <guid>/questions/25575/sort-by-bandwidth-used-and-show-ip-addressnetwork-name/</guid>
      <description>Sort by bandwidth used and show IP address/network name?  0 Hi All,
This is probably an easy one and I may be missing something obvious, but I&#39;m having a hard time configuring WireShark to show me the same type of data that I used to see with Capsa.
I&#39;m just trying to get a simple list of traffic, sorted by the highest amount of bandwidth, and next to that show the IP address/network name of the device that used that bandwidth.</description>
    </item>
    
    <item>
      <title>Is it possible to view plain text tranmission over network with wireshark?</title>
      <link>/questions/25579/is-it-possible-to-view-plain-text-tranmission-over-network-with-wireshark/</link>
      <pubDate>Thu, 03 Oct 2013 00:24:00 +0000</pubDate>
      
      <guid>/questions/25579/is-it-possible-to-view-plain-text-tranmission-over-network-with-wireshark/</guid>
      <description>Is it possible to view plain text tranmission over network with wireshark?  0 Few chat engines, say IRC and Pidgin doesn&#39;t encrypt the package when they send. Is it possible to capture those non encrypted plain text information using wireshark and view those informations?
plain-textasked 03 Oct &#39;13, 00:24
Karthick
21●5●5●9
accept rate: 0%
  
One Answer:
  
2 Wireshark will (hopefully) capture whatever traffic passes through the capturing interfaces.</description>
    </item>
    
    <item>
      <title>Split and then merge again pcap file</title>
      <link>/questions/25585/split-and-then-merge-again-pcap-file/</link>
      <pubDate>Thu, 03 Oct 2013 06:17:00 +0000</pubDate>
      
      <guid>/questions/25585/split-and-then-merge-again-pcap-file/</guid>
      <description>Split and then merge again pcap file  0 Hi all, I split a pcap in 3 small pcap files and then I merged back altogether. I was supposing that the merged one is equal to initial file, but I found many differences. Could someone explain to me why?
Thanks
editcap test_initial.pcap test_A.pcap 1-300 tshark -nr test_initial.pcap -R &amp;quot;frame.number==301&amp;quot; -w test_B.pcap editcap test_initial.pcap test_C.pcap 302-999999999 mergecap -w test_merged.pcap
test_A.pcap
test_B.pcap</description>
    </item>
    
    <item>
      <title>Virus infection</title>
      <link>/questions/25587/virus-infection/</link>
      <pubDate>Thu, 03 Oct 2013 07:09:00 +0000</pubDate>
      
      <guid>/questions/25587/virus-infection/</guid>
      <description>Virus infection  0 Dear Sir/Madam,
is it possible to get the URL or source IP from which virus is spreaded in individual machine that is happened 3 days before, please respond. if you have any doubt call 8925347074 or [email protected]
virus port infectionThis question is marked &#34;community wiki&#34;.asked 03 Oct &#39;13, 07:09
Deepak_learner
11●1●1●2
accept rate: 0%
  
One Answer:
  
0if you have captured the network traffic at that time you might be able to do that.</description>
    </item>
    
    <item>
      <title>Cannot see TCP messages of 3rd party device on my Windows 7 laptop</title>
      <link>/questions/25590/cannot-see-tcp-messages-of-3rd-party-device-on-my-windows-7-laptop/</link>
      <pubDate>Thu, 03 Oct 2013 07:44:00 +0000</pubDate>
      
      <guid>/questions/25590/cannot-see-tcp-messages-of-3rd-party-device-on-my-windows-7-laptop/</guid>
      <description>Cannot see TCP messages of 3rd party device on my Windows 7 laptop  0 I am using a Windows XP laptop with Wireshark to capture all network messages to and from another device. I am using a port-mirroring switch between that device and its regular network connection. When I connect my Windows XP laptop to the output port of the mirroring switch, Wireshark sees and captures all message received by and transmitted by the other device.</description>
    </item>
    
    <item>
      <title>Who send data first after TCP connection is established?</title>
      <link>/questions/25591/who-send-data-first-after-tcp-connection-is-established/</link>
      <pubDate>Thu, 03 Oct 2013 07:58:00 +0000</pubDate>
      
      <guid>/questions/25591/who-send-data-first-after-tcp-connection-is-established/</guid>
      <description>Who send data first after TCP connection is established?  0 Hello everybody.
Maybe is just a silly question but I have no clear answer.
When I see examples of TCP three way handshake (even those shown in RFC 793), the device which first send the SYN segment (client) is always the device which, after connection is estableshed, begins sending data to the device which was listening (server).
But is the opposite possible?</description>
    </item>
    
    <item>
      <title>SMB performance and extra SMB commands appearing</title>
      <link>/questions/25592/smb-performance-and-extra-smb-commands-appearing/</link>
      <pubDate>Thu, 03 Oct 2013 08:01:00 +0000</pubDate>
      
      <guid>/questions/25592/smb-performance-and-extra-smb-commands-appearing/</guid>
      <description>SMB performance and extra SMB commands appearing  0 Hi folks,
We have a performance problem with one of our servers that reads thousands of small XML files from a SMB share and then stitches them together in to a collection of slightly bigger files on the local drive. The problem server can only manage to process about 1 XML file every 2 secs when it used to be doing 10s of files every second.</description>
    </item>
    
    <item>
      <title>TCP:  Previous segment not captured, Is that a connectivity issue?</title>
      <link>/questions/25593/tcp-previous-segment-not-captured-is-that-a-connectivity-issue/</link>
      <pubDate>Thu, 03 Oct 2013 08:21:00 +0000</pubDate>
      
      <guid>/questions/25593/tcp-previous-segment-not-captured-is-that-a-connectivity-issue/</guid>
      <description>TCP: Previous segment not captured, Is that a connectivity issue?  0 Hi guys, I&#39;ve been analyzing the packets sent between one server (172.20.3.188) and some clients, after I put the capture on Wireshark and I saw that there is some messages that say &#34;Protocol TCP. Previous segment not captured&#34; and &#34;TCP: ACKed segment that wasn&#39;t captured (common at capture start)&#34;. Looking on the internet I found that is a connectivity issue, but I&#39;m not so able to understand it at all.</description>
    </item>
    
    <item>
      <title>Capture Traffic from Installer</title>
      <link>/questions/25606/capture-traffic-from-installer/</link>
      <pubDate>Thu, 03 Oct 2013 10:47:00 +0000</pubDate>
      
      <guid>/questions/25606/capture-traffic-from-installer/</guid>
      <description>Capture Traffic from Installer  0 I have an installer that I know downloads other packages from the &#39;net. I&#39;m trying to use WS to discover what those requests are for, but so far I&#39;m not having much luck. I&#39;ve tried to find or filter for requests that I already know are being made, and I can&#39;t even find those. Does anyone know what I might be doing wrong, or what I could do to troubleshoot?</description>
    </item>
    
    <item>
      <title>How does wireshark detect TCP retransmissions?</title>
      <link>/questions/25609/how-does-wireshark-detect-tcp-retransmissions/</link>
      <pubDate>Thu, 03 Oct 2013 14:02:00 +0000</pubDate>
      
      <guid>/questions/25609/how-does-wireshark-detect-tcp-retransmissions/</guid>
      <description>How does wireshark detect TCP retransmissions?  0 I was looking at two traces one from the sending side where I saw the original packet and the retransmitted packet. I can understand how wireshark would flag the second packet as a retransmission in the expert info because it would simply need to look for two packet with the same sequence number. However, in second capture where the first packet is missing and I only see the retransmitted packet, I&#39;m wondering how wireshark was able to detect that the packet was a retransmit?</description>
    </item>
    
    <item>
      <title>How to best analyze two different captures</title>
      <link>/questions/25611/how-to-best-analyze-two-different-captures/</link>
      <pubDate>Thu, 03 Oct 2013 15:32:00 +0000</pubDate>
      
      <guid>/questions/25611/how-to-best-analyze-two-different-captures/</guid>
      <description>How to best analyze two different captures  0 I have two captures from each firewall for two sites connected by VPN tunnel. From the sending side host (site1) capture, Wireshark is reporting many TCP Zero Window and Update flags coming from the receiving side (site 2). Looking at the receiving (site2) capture, there are no TCP Zero Window and Update flags reported but only TCP retransmissions and Dup Ack. Having two sided captures, I would expect to see same TCP Zero Window and Update for the receiving side but that’s not the case.</description>
    </item>
    
    <item>
      <title>How to find encoded value in packet?</title>
      <link>/questions/25625/how-to-find-encoded-value-in-packet/</link>
      <pubDate>Fri, 04 Oct 2013 01:10:00 +0000</pubDate>
      
      <guid>/questions/25625/how-to-find-encoded-value-in-packet/</guid>
      <description>How to find encoded value in packet?  0 Hi,
In following image, selected filed shows &#39;(0)&#39; in front of field name. I have tried hard to understand where it came from, but not able to get where this 0 is encoded. Is there any way to find it out. It&#39;s gsm_map protocol. And its response of ATI message.
Kindly note that image is tampered intentionally to hide information.
In image,</description>
    </item>
    
    <item>
      <title>Running wireshark on Ubuntu through VMware</title>
      <link>/questions/25631/running-wireshark-on-ubuntu-through-vmware/</link>
      <pubDate>Fri, 04 Oct 2013 02:11:00 +0000</pubDate>
      
      <guid>/questions/25631/running-wireshark-on-ubuntu-through-vmware/</guid>
      <description>Running wireshark on Ubuntu through VMware  0 I&#39;m on a windows 7 machine and part of my college labs is to capture data in &#39;monitor mode&#39;, as we know that is not available on the windows 7 version of wireshark. If I install it on Ubuntu through VMware on the windows machine will I be able to use the monitor mode affectingly
vmware linuxasked 04 Oct &#39;13, 02:11
IrishFella</description>
    </item>
    
    <item>
      <title>Modem isnt listed on interface</title>
      <link>/questions/25633/modem-isnt-listed-on-interface/</link>
      <pubDate>Fri, 04 Oct 2013 03:04:00 +0000</pubDate>
      
      <guid>/questions/25633/modem-isnt-listed-on-interface/</guid>
      <description>Modem isnt listed on interface  0 Why wireshark is not show my modem (huawei mobile broadband) on &#34;interface&#34; list, whereas 3 months ago it shows as well ?
the last month i use it on July 2013. It CAN IDENTIFY my modem on interface list, and can captured packets as well. Then I didn&#39;t use wireshark again about 3month. When today i opened my wireshark, it CAN NOT IDENTIFY my modem on my interface list like it did 3 months ago.</description>
    </item>
    
    <item>
      <title>wireshark 1.10.2 on mac osx 10.8.5 with xquartz 2.7.4</title>
      <link>/questions/25638/wireshark-1102-on-mac-osx-1085-with-xquartz-274/</link>
      <pubDate>Fri, 04 Oct 2013 05:02:00 +0000</pubDate>
      
      <guid>/questions/25638/wireshark-1102-on-mac-osx-1085-with-xquartz-274/</guid>
      <description>wireshark 1.10.2 on mac osx 10.8.5 with xquartz 2.7.4  0 Dear community, when I install wireshark 1.10.2 on mac osx 10.8.5 with xquartz 2.7.4, wireshark crash at boot and wont work.
How can I solve this trouble.
Thanks.
Gabriele.
wiresharkasked 04 Oct &#39;13, 05:02
Gabriele Ellena
11●1●1●2
accept rate: 0%
What does the crash report for it in the Console application (look under &#34;User Diagnostic Reports&#34;) say?
(04 Oct &#39;13, 14:14) Guy Harris ♦♦hi, this is what UDR say :</description>
    </item>
    
    <item>
      <title>Does Wireshark understand NPN (or at least NPN extension in SSL)</title>
      <link>/questions/25641/does-wireshark-understand-npn-or-at-least-npn-extension-in-ssl/</link>
      <pubDate>Fri, 04 Oct 2013 06:22:00 +0000</pubDate>
      
      <guid>/questions/25641/does-wireshark-understand-npn-or-at-least-npn-extension-in-ssl/</guid>
      <description>Does Wireshark understand NPN (or at least NPN extension in SSL)  0 I am using wireshark 1.6.7 on windowx XP. It does not seem to understand if the SSL client sends NPN (next protocol negotiation) extension. I tried to run on centos 1.2.15 with the same result. I have googled but it is not clear from the documentation if NPN is recognized or if some patch needs to be applied Thanks for any answers</description>
    </item>
    
    <item>
      <title>What is the capture filter equivalent of the display filter &amp;quot;ip.frag_offset != 0&amp;quot;</title>
      <link>/questions/25645/what-is-the-capture-filter-equivalent-of-the-display-filter-ipfrag_offset-0/</link>
      <pubDate>Fri, 04 Oct 2013 08:19:00 +0000</pubDate>
      
      <guid>/questions/25645/what-is-the-capture-filter-equivalent-of-the-display-filter-ipfrag_offset-0/</guid>
      <description>What is the capture filter equivalent of the display filter &amp;ldquo;ip.frag_offset != 0&amp;rdquo;  0 thank you . i have one more question. ip.frag_offset != 0(Display filter) Converted to Capture filter syntax is ip[7]&amp;amp;0xf != 0 ? i want to know right syntax.
capture capture-filter display-filterasked 04 Oct &#39;13, 08:19
stih
11●2●2●6
accept rate: 0%
 converted 04 Oct &#39;13, 08:34 
SYN-bit ♦♦
17.1k●9●57●245
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Identifying VLANs in 802.1Q Trunking packet captures</title>
      <link>/questions/25653/identifying-vlans-in-8021q-trunking-packet-captures/</link>
      <pubDate>Fri, 04 Oct 2013 11:19:00 +0000</pubDate>
      
      <guid>/questions/25653/identifying-vlans-in-8021q-trunking-packet-captures/</guid>
      <description>Identifying VLANs in 802.1Q Trunking packet captures  0 I have a client with servers connecting to my Cisco Nexus switches on trunked interfaces. The switch ports are configured with a native VLAN, being the server&#39;s primary VLAN for PXE boot, and a second VLAN for VM clients. The client would like to be able to identify the VLANs allowed on the trunk from the server-end, so he can verify the configuration when troubleshooting PXE boot or VM connectivity issues.</description>
    </item>
    
    <item>
      <title>Having output Log in tshark update by deleting the previous line.</title>
      <link>/questions/25659/having-output-log-in-tshark-update-by-deleting-the-previous-line/</link>
      <pubDate>Fri, 04 Oct 2013 18:53:00 +0000</pubDate>
      
      <guid>/questions/25659/having-output-log-in-tshark-update-by-deleting-the-previous-line/</guid>
      <description>Having output Log in tshark update by deleting the previous line.  0 I&#39;m using tshark to capture RSSI values in an attempt at wifi triangulation.
I have it set up so that the log only outputs the RSSI value. The command I&#39;m using is:
&#39;tshark -I -i wlan2 -R &#34;wlan.addr == 58:1f:aa:2a:80:1e &amp;amp;&amp;amp; wlan.addr == Broadcast&#34; -o column.format:&#39;&#34;RSSI&#34;, %e&#39; &amp;gt; /tmp/log.txt&#39;
I&#39;m using python function readline() to grab the first line of the log file and assign the RSSI to a variable to be sent into a triangulation algorithm.</description>
    </item>
    
    <item>
      <title>Question on linebreaks on output from tshark&amp;#x27;s -z io,stat option</title>
      <link>/questions/25662/question-on-linebreaks-on-output-from-tsharks-z-iostat-option/</link>
      <pubDate>Fri, 04 Oct 2013 20:53:00 +0000</pubDate>
      
      <guid>/questions/25662/question-on-linebreaks-on-output-from-tsharks-z-iostat-option/</guid>
      <description>Question on linebreaks on output from tshark&amp;rsquo;s -z io,stat option  0 Hello,
I&#39;ve done up a script that reads a capture file with tshark&#39;s -z io,stat argument, where the goal is to be able to generate statistics on several different display filter search criteria with a single pass on the capture file itself (automatically-generated capture files of predictable name and timestamp, where the script users tshark to get the stats off of that time period and pushes it to a line in a .</description>
    </item>
    
    <item>
      <title>Creating an wlan.ta column does not provide MAC addr. name resolution.</title>
      <link>/questions/25673/creating-an-wlanta-column-does-not-provide-mac-addr-name-resolution/</link>
      <pubDate>Sun, 06 Oct 2013 01:41:00 +0000</pubDate>
      
      <guid>/questions/25673/creating-an-wlanta-column-does-not-provide-mac-addr-name-resolution/</guid>
      <description>Creating an wlan.ta column does not provide MAC addr. name resolution.  0 Hi guys,
I have used wireshark to capture a batch of 802.11 frame from certain access point in my school. Then, I plan to analyze the down link frame from AP to Client. However, wireshark only provide the column titled as Source, which is actually the Mac address of wire part Router. But what I need is the AP Mac address (Transmitter address ) in my case.</description>
    </item>
    
    <item>
      <title>Ip monitoring</title>
      <link>/questions/25675/ip-monitoring/</link>
      <pubDate>Sun, 06 Oct 2013 10:31:00 +0000</pubDate>
      
      <guid>/questions/25675/ip-monitoring/</guid>
      <description>Ip monitoring  0 II want to know how ,my network data usage to find out how we are loosing data .i am over change,past four month. I have 10 PC I network.
ip monitoringasked 06 Oct &#39;13, 10:31
Bal
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Method to verify results based on a graph generated in wireshark</title>
      <link>/questions/25676/method-to-verify-results-based-on-a-graph-generated-in-wireshark/</link>
      <pubDate>Sun, 06 Oct 2013 10:49:00 +0000</pubDate>
      
      <guid>/questions/25676/method-to-verify-results-based-on-a-graph-generated-in-wireshark/</guid>
      <description>Method to verify results based on a graph generated in wireshark  0 I want to write a script where I need to verify the final result (pass/fail) based on a graph generated in wireshark.
Message rate is to be configured for e.g., 25000 and the same is to be verified from graphs.In wireshark, under &#34;Statistics&#34; menu, &#34;IO Graph&#34; is there. There I need to give different filters for &#34;Graph 1&#34;</description>
    </item>
    
    <item>
      <title>Asymmetric TCP performance between data centers</title>
      <link>/questions/25678/asymmetric-tcp-performance-between-data-centers/</link>
      <pubDate>Sun, 06 Oct 2013 14:21:00 +0000</pubDate>
      
      <guid>/questions/25678/asymmetric-tcp-performance-between-data-centers/</guid>
      <description>Asymmetric TCP performance between data centers  0 Hi
Currently having serious asymmetric TCP performance issues between 2 Data Centers over ISP links (10Gbps IP transit into each). From site A (62.115.34.157) to site B (136.179.4.106) performance is good - 350-400Mbps over TCP. However from site B to site A performance is only 10% of this.. 35-40Mbps in general. Serious problem! Using iperf to test throughput in each direction. Note that UDP is fine in each direction - no packet loss and high throughput in both directions.</description>
    </item>
    
    <item>
      <title>Unable to capture passwords with wireshark?</title>
      <link>/questions/25682/unable-to-capture-passwords-with-wireshark/</link>
      <pubDate>Sun, 06 Oct 2013 17:26:00 +0000</pubDate>
      
      <guid>/questions/25682/unable-to-capture-passwords-with-wireshark/</guid>
      <description>Unable to capture passwords with wireshark?  0 To test the capturing of plain text, I have logged into my router (http://192.168.0.1) and given username and password applying http.request.method == &#34;POST&#34; filter. I have clicked on the captured packets and then expand the Hypertext Transfer Protocol field. The POST data were there, but i cant able to see username and passwords there.. Any help would be really helpful. Thank You.</description>
    </item>
    
    <item>
      <title>Showing Live session on Wireshark?</title>
      <link>/questions/25683/showing-live-session-on-wireshark/</link>
      <pubDate>Sun, 06 Oct 2013 17:31:00 +0000</pubDate>
      
      <guid>/questions/25683/showing-live-session-on-wireshark/</guid>
      <description>Showing Live session on Wireshark?  0 I was asked to show a live demo on capturing plain texts on network using wireshark. Nowadays we cant able to see http protocol anywhere, everything got converted to https and I am unsure of showing the demo capturing the plain texts transfer across network. Can someone guide me pls? Also it would be nice if something interesting could be shown to users live that create awarness among people.</description>
    </item>
    
    <item>
      <title>Capturing live IP&amp;#x27;s in a network with its MAC Address?</title>
      <link>/questions/25684/capturing-live-ips-in-a-network-with-its-mac-address/</link>
      <pubDate>Sun, 06 Oct 2013 17:33:00 +0000</pubDate>
      
      <guid>/questions/25684/capturing-live-ips-in-a-network-with-its-mac-address/</guid>
      <description>Capturing live IP&amp;rsquo;s in a network with its MAC Address?  0 Is it possible to capture all live IP Address in a network along with its MAC Address?? If yes, can someone explain me the way to acheive this task pls? Thank you.
ipaddress mac-addressasked 06 Oct &#39;13, 17:33
Karthick
21●5●5●9
accept rate: 0%
  
2 Answers:
  
2It depends almost entirely on how you define &#34;</description>
    </item>
    
    <item>
      <title>Broadband Connection Issue?</title>
      <link>/questions/25687/broadband-connection-issue/</link>
      <pubDate>Sun, 06 Oct 2013 18:09:00 +0000</pubDate>
      
      <guid>/questions/25687/broadband-connection-issue/</guid>
      <description>Broadband Connection Issue?  0 Frequently my broadband connection is getting disconnected. I have raised a fault ticket number several times, but from ISP end they are not giving any proper response. They blindly say it may be due to faulty modem. But the modem / router (NETGEAR DGN1000) which i use is a brand new one. And i dont think that might be the problem. Any way to findout where the packet drops and the issue is in which end?</description>
    </item>
    
    <item>
      <title>Tshark: Cannot run Dissector() while using option &amp;quot;-w&amp;quot;</title>
      <link>/questions/25690/tshark-cannot-run-dissector-while-using-option-w/</link>
      <pubDate>Sun, 06 Oct 2013 21:54:00 +0000</pubDate>
      
      <guid>/questions/25690/tshark-cannot-run-dissector-while-using-option-w/</guid>
      <description>Tshark: Cannot run Dissector() while using option &amp;ldquo;-w&amp;rdquo;  0 Hi all, i&#39;m using tshark command and trying some scenarios but something seems to be strange. I modified the Dissectors() function. here is my concern:
**tshark -i 5**And the program went through my code in Dissectors() but it wrote a large tmp file. So, what happens if I remove the tmp file? I tried but nothing happened, the program still print out anything without tmp file.</description>
    </item>
    
    <item>
      <title>Total Bandwidth usage while file download</title>
      <link>/questions/25693/total-bandwidth-usage-while-file-download/</link>
      <pubDate>Sun, 06 Oct 2013 23:22:00 +0000</pubDate>
      
      <guid>/questions/25693/total-bandwidth-usage-while-file-download/</guid>
      <description>Total Bandwidth usage while file download  0 Hi,
I am playing a youtube video. I have collected the tcpdump. How can I check the total bandwidth using wireshark for the particular youtube video.
bandwidth totalasked 06 Oct &#39;13, 23:22
sysadm270180
11●1●1●2
accept rate: 0%
  
2 Answers:
  
0You could use the statistics menu, e.g. the summary which gives you a total over the whole file or (if you applied a filter to the Youtube stream) also the throughput of the conversation.</description>
    </item>
    
    <item>
      <title>Wireshark plugin LNK2019</title>
      <link>/questions/25703/wireshark-plugin-lnk2019/</link>
      <pubDate>Mon, 07 Oct 2013 03:33:00 +0000</pubDate>
      
      <guid>/questions/25703/wireshark-plugin-lnk2019/</guid>
      <description>Wireshark plugin LNK2019  0 Dear Wireshark-Community,
I&#39;ve developed a basic dissector for a protocol. I implemented it as a standard dissector in wireshark. Everything worked pretty well, but now I want to implement this source-code as a plugin. But then I always get this error-message:
packet-rasta.obj : error LNK2019: unresolved external symbol _imp_register_dissector referenced in funktion _proto_register_rasta
packet-rasta.obj : error LNK2019: unresolved external symbol _imp_proto_register_subtree_array referenced in funktion _proto_register_rasta</description>
    </item>
    
    <item>
      <title>Finding an intruder&amp;#x27;s Operating system</title>
      <link>/questions/25704/finding-an-intruders-operating-system/</link>
      <pubDate>Mon, 07 Oct 2013 06:36:00 +0000</pubDate>
      
      <guid>/questions/25704/finding-an-intruders-operating-system/</guid>
      <description>Finding an intruder&amp;rsquo;s Operating system  0 Hello all, I am very new to Wireshark, and I have been told that its possible to find an intruder&#39;s operating system in my packet capture. I have the capture, but I&#39;m not exactly sure what to look for, regarding the operating systems. Can anyone offer some advice?
detection operating systemasked 07 Oct &#39;13, 06:36
Ruinzifra
11●2●2●6
accept rate: 0% 
 edited 07 Oct &#39;13, 06:42</description>
    </item>
    
    <item>
      <title>Minimum Interframe gap time</title>
      <link>/questions/25705/minimum-interframe-gap-time/</link>
      <pubDate>Mon, 07 Oct 2013 06:54:00 +0000</pubDate>
      
      <guid>/questions/25705/minimum-interframe-gap-time/</guid>
      <description>Minimum Interframe gap time  0 Is it possible for Wireshark to indicate that the interframe gap on a network does meet the minimum time of 96 bit times?
interframegapasked 07 Oct &#39;13, 06:54
CGooden
11●1●1●3
accept rate: 0%
  
One Answer:
  
2Well, you can obviously look at the time stamps and check if the delta is smaller that the interframe gap (0.096 µs for 1Gig/s).</description>
    </item>
    
    <item>
      <title>s6a interace Supported Features AVP (628) Feature-List(630) is decoded wrongly</title>
      <link>/questions/25706/s6a-interace-supported-features-avp-628-feature-list630-is-decoded-wrongly/</link>
      <pubDate>Mon, 07 Oct 2013 06:58:00 +0000</pubDate>
      
      <guid>/questions/25706/s6a-interace-supported-features-avp-628-feature-list630-is-decoded-wrongly/</guid>
      <description>s6a interace Supported Features AVP (628) Feature-List(630) is decoded wrongly  0 s6a interace Supported-Features AVP (628) Feature-List(630) is decoded wrongly. Always decodes the Cx interface feature-list flags ...
diameter 3gpp s6aasked 07 Oct &#39;13, 06:58
MANDALIC
11●1●1●2
accept rate: 0%
 edited 07 Oct &#39;13, 10:40 
JeffMorriss ♦
6.2k●5●72
  
One Answer:
  
0The decoding of the S6 Feature-List was added in revision 50796. If you want to see the proper decode you&#39;ll need to use an automated development build at least until the next major release (1.</description>
    </item>
    
    <item>
      <title>Vmware pcoip</title>
      <link>/questions/25717/vmware-pcoip/</link>
      <pubDate>Mon, 07 Oct 2013 08:27:00 +0000</pubDate>
      
      <guid>/questions/25717/vmware-pcoip/</guid>
      <description>Vmware pcoip  0 Hi
I am trying to access vmware pcoip through asa ipsec tunnel but unable to go through , i am unable to figure this out what is happening, here is the capture on ASA internal interface http://cloudshark.org/captures/dcf23d2c73bd
thnks
pcoip vmwareasked 07 Oct &#39;13, 08:27
imrans
1●2●2●3
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Error loading table &amp;#x27;GeoIP Database Paths&amp;#x27;: geoip_db_paths:5: unexpected char while looking for end of line</title>
      <link>/questions/25718/error-loading-table-geoip-database-paths-geoip_db_paths5-unexpected-char-while-looking-for-end-of-line/</link>
      <pubDate>Mon, 07 Oct 2013 09:36:00 +0000</pubDate>
      
      <guid>/questions/25718/error-loading-table-geoip-database-paths-geoip_db_paths5-unexpected-char-while-looking-for-end-of-line/</guid>
      <description>Error loading table &amp;lsquo;GeoIP Database Paths&amp;rsquo;: geoip_db_paths:5: unexpected char while looking for end of line  0 Suddenly today I open wireshark and get this error.. Can i fix this. I dont need GeoIP datbase for my testing ..It is preventing the full loading of the pcap file.
Error loading table &#39;GeoIP Database Paths&#39;: geoip_db_paths:5: unexpected char while looking for end of line
Please help
geoip errorsasked 07 Oct &#39;13, 09:36</description>
    </item>
    
    <item>
      <title>Internal or external source?</title>
      <link>/questions/25724/internal-or-external-source/</link>
      <pubDate>Mon, 07 Oct 2013 11:34:00 +0000</pubDate>
      
      <guid>/questions/25724/internal-or-external-source/</guid>
      <description>Internal or external source?  0 Hello all,
I am still very new to wireshark, and I am curious if someone can guide me in the right direction. I have a packet captured, and we know there is an intruder, but I do not know if there is a way to tell if they are coming from within the network or an outside source. Does Wireshark tell us that information?</description>
    </item>
    
    <item>
      <title>How to apply filter to view tcp connection timeout</title>
      <link>/questions/25727/how-to-apply-filter-to-view-tcp-connection-timeout/</link>
      <pubDate>Mon, 07 Oct 2013 13:34:00 +0000</pubDate>
      
      <guid>/questions/25727/how-to-apply-filter-to-view-tcp-connection-timeout/</guid>
      <description>How to apply filter to view tcp connection timeout  0 need to apply filter is to identify any tcp connection timeout
connection timeoutasked 07 Oct &#39;13, 13:34
KT1979
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0It depends on the kind of timeout you talk about. If you mean an application timeout where it shuts down the socket you&#39;ll see a reset packet. You can filter for that by using &#34;</description>
    </item>
    
    <item>
      <title>WireShark does not capture all jar files in java web start ?</title>
      <link>/questions/25740/wireshark-does-not-capture-all-jar-files-in-java-web-start/</link>
      <pubDate>Mon, 07 Oct 2013 21:24:00 +0000</pubDate>
      
      <guid>/questions/25740/wireshark-does-not-capture-all-jar-files-in-java-web-start/</guid>
      <description>WireShark does not capture all jar files in java web start ?  0 I am currently using WireShark to analyze the java web start. When the jnlp is running, it requires some jar files. When I open Java Control Panel -&amp;gt; Java Cache Viewer -&amp;gt; Resources, I see there are (e.g) 20 jar files is downloaded (the cache is cleared before launching the jnlp).
But in WireShark display, I just find out (e.</description>
    </item>
    
    <item>
      <title>DIS PDU data extraction with tshark</title>
      <link>/questions/25743/dis-pdu-data-extraction-with-tshark/</link>
      <pubDate>Tue, 08 Oct 2013 06:49:00 +0000</pubDate>
      
      <guid>/questions/25743/dis-pdu-data-extraction-with-tshark/</guid>
      <description>DIS PDU data extraction with tshark  0 I need to extract just the data from a capture file, something like using &#39;Follow Stream&#39; and then saving that as a file, but using tshark. I&#39;ve discovered that, for other protocols using TCP, I can filter using -e tcp.sequence_data, but there doesn&#39;t appear to be an equivalent for UDP. (I saw an answer to another question that suggested -e udp.data but that threw up an error.</description>
    </item>
    
    <item>
      <title>Help analyzing SSL</title>
      <link>/questions/25746/help-analyzing-ssl/</link>
      <pubDate>Tue, 08 Oct 2013 09:12:00 +0000</pubDate>
      
      <guid>/questions/25746/help-analyzing-ssl/</guid>
      <description>Help analyzing SSL  0 Hi,
I have an intermittent problem with SSL on our local network. We have a proxy on the network but all ssl traffic should be untouched.
The hand-off of http traffic is achieved through these iptable rules (where .23 is the proxy):
iptables -t mangle -A PREROUTING -p tcp --dport 80 -j MARK --set-mark 3 ip rule add fwmark 3 table 2 ip route add default via 192.</description>
    </item>
    
    <item>
      <title>Blocked Port 80 URLs</title>
      <link>/questions/25751/blocked-port-80-urls/</link>
      <pubDate>Tue, 08 Oct 2013 10:29:00 +0000</pubDate>
      
      <guid>/questions/25751/blocked-port-80-urls/</guid>
      <description>Blocked Port 80 URLs  0 When at a customers review my team did some captures for many users dispersed geographically. Some users tried accessing port 80 sites that were blocked by our network proxies. How can I find all requested HTTP URLs?
httpasked 08 Oct &#39;13, 10:29
karl
16●2●2●5
accept rate: 0%
  
2 Answers:
  
0 Assuming you have a capture file, you can use tshark as follows:</description>
    </item>
    
    <item>
      <title>clang: error: argument unused during compilation: &amp;#x27;-g&amp;#x27;</title>
      <link>/questions/25759/clang-error-argument-unused-during-compilation-g/</link>
      <pubDate>Tue, 08 Oct 2013 13:14:00 +0000</pubDate>
      
      <guid>/questions/25759/clang-error-argument-unused-during-compilation-g/</guid>
      <description>clang: error: argument unused during compilation: &amp;lsquo;-g&amp;rsquo;  0 I am on FreeBSD 6.3 using clang 3.1 to build wireshark 1.11.0-SVN-52370.
gmake[3]: Entering directory /usr/home/timpr/workspace/wireshark-1.11.0-SVN-52370/epan/wmem&#39; CCLD wmem_test clang: error: argument unused during compilation: &#39;-g&#39; gmake[3]: *** [wmem_test] Error 1 gmake[3]: Leaving directory/usr/home/timpr/workspace/wireshark-1.11.0-SVN-52370/epan/wmem&#39;
I assume the root cause of the problem is how LINK is defined, using a couple CFLAGS. Removing them resolves that problem.
LINK = $(LIBTOOL) $(AM_V_lt) --tag=CC $(AM_LIBTOOLFLAGS) \ $(LIBTOOLFLAGS) --mode=link $(CCLD) $(AM_CFLAGS) $(CFLAGS) \ $(AM_LDFLAGS) $(LDFLAGS) -o [email protected]</description>
    </item>
    
    <item>
      <title>clang: -Wc&#43;&#43;-compat fails</title>
      <link>/questions/25761/clang-wc-compat-fails/</link>
      <pubDate>Tue, 08 Oct 2013 13:25:00 +0000</pubDate>
      
      <guid>/questions/25761/clang-wc-compat-fails/</guid>
      <description>clang: -Wc++-compat fails  0 I am on FreeBSD 6.3, using clang 3.1 to build wireshark.
I am getting the following error during compile. The question is, what purpose is -Wc++-compat playing? Should it really be turned on here?
I am actually tempted to remove &#34;#ifndef __GNUC__&#34; from smi.h.
 CC libwireshark_la-epan.lo In file included from epan.c:31: In file included from ../wsutil/wsgcrypt.h:63: ... In file included from epan.c:63: /usr/local/include/smi.h:319:1: error: empty struct has size 0 in C, size 1 in C++ [-Werror,-Wc++-compat] } SmiElement; ^ 6 warnings and 1 error generated.</description>
    </item>
    
    <item>
      <title>Editcap [and tshark] performance</title>
      <link>/questions/25765/editcap-and-tshark-performance/</link>
      <pubDate>Tue, 08 Oct 2013 14:50:00 +0000</pubDate>
      
      <guid>/questions/25765/editcap-and-tshark-performance/</guid>
      <description>Editcap [and tshark] performance  0 I have a 9.59GB pcap that I am running editcap -D from 1 to 1000000 exponentially. There are 13751611 packets in the file. I have a dedicated Win 7 Ent. VM on an ESXi server with 26GB RAM with 2 dual-core 3GHz CPUs. It took 234991 seconds to process the command with a window of 1000000. The command took only 1.5 GB of RAM and the CPUs didn&#39;t seem very taxed.</description>
    </item>
    
    <item>
      <title>Searching for content inside packets ?</title>
      <link>/questions/25767/searching-for-content-inside-packets/</link>
      <pubDate>Tue, 08 Oct 2013 15:35:00 +0000</pubDate>
      
      <guid>/questions/25767/searching-for-content-inside-packets/</guid>
      <description>Searching for content inside packets ?  0 1Hello,
I want to find packets that have a specific string inside. Is this possible ? for example : find packets which have a &#34;Content-type:audio/mpeg&#34;.
searchasked 08 Oct &#39;13, 15:35
ychaouche
31●5●6●10
accept rate: 100%
1Hi. I&#39;d just like to add that the Find dialog box can be easily mis-understood if you don&#39;t pay attention to the radio buttons that are selected by default.</description>
    </item>
    
    <item>
      <title>Unable to add link to other Q&amp;amp;A</title>
      <link>/questions/25782/unable-to-add-link-to-other-qa/</link>
      <pubDate>Wed, 09 Oct 2013 01:31:00 +0000</pubDate>
      
      <guid>/questions/25782/unable-to-add-link-to-other-qa/</guid>
      <description>Unable to add link to other Q&amp;amp;A  0 When I try to include a link to another answer I get a message telling my &#39;Askimet thinks this is spam&#39;. How can a link to another question on the same site be spam?
linksasked 09 Oct &#39;13, 01:31
wiggers
31●5●5●11
accept rate: 0%
  
One Answer:
  
0 I believe Gerald made a change recently that may have corrected this.</description>
    </item>
    
    <item>
      <title>SMB2 Negotiate Protocol Request Decode / Possible feature request</title>
      <link>/questions/25790/smb2-negotiate-protocol-request-decode-possible-feature-request/</link>
      <pubDate>Wed, 09 Oct 2013 02:10:00 +0000</pubDate>
      
      <guid>/questions/25790/smb2-negotiate-protocol-request-decode-possible-feature-request/</guid>
      <description>SMB2 Negotiate Protocol Request Decode / Possible feature request  0 I notice that the decode for an SMB2 Negotiate Protocol Request is fairly sparse compared to the decode used for the equivalent SMB1 Request
SMB1 Dialect: PC Network Program 1.0 Dialect: LANMAN1.0 Dialect: Windows for Workgroups 3.1a Dialect: LM1.2x002 Dialect: LANMAN2.1 Dialect: NT LM 0.12 Dialect: SMB 2.002 Dialect: SMB 2.???
SMB2 Dialect: 0x0202 Dialect: 0x0210
In the SMB2 decode, I would prefer to see something like: Dialect: SMB 2.</description>
    </item>
    
    <item>
      <title>Unable to decrypt HTTP Post and Application Data frames</title>
      <link>/questions/25791/unable-to-decrypt-http-post-and-application-data-frames/</link>
      <pubDate>Wed, 09 Oct 2013 02:41:00 +0000</pubDate>
      
      <guid>/questions/25791/unable-to-decrypt-http-post-and-application-data-frames/</guid>
      <description>Unable to decrypt HTTP Post and Application Data frames  0 Hi, I get &#39;Internal Error 500&#39; for the first message that goes from Siebel to Datapower, after a Siebel server restart.
The Siebel logs looks fine. Datapower is not able to give detailed logs. Also they see two transactions from Siebel during the failure case. So we were left with no option other than to check network trace.
I need your help to understand from network logs on what is happening in the failure case.</description>
    </item>
    
    <item>
      <title>Tshark generate core dump</title>
      <link>/questions/25794/tshark-generate-core-dump/</link>
      <pubDate>Wed, 09 Oct 2013 03:03:00 +0000</pubDate>
      
      <guid>/questions/25794/tshark-generate-core-dump/</guid>
      <description>Tshark generate core dump  0 Hi all, I&#39;m using wireshark to capture data in real time system. I use the command
tshark -i 5 -P -w /tmp/oh.pcap -b filesize:65535 -b files:5But after few hours, I got a core dump. So I think the first of 5 rotation files was deleted so that tshark stopped running and generated core dump. So I tried again with a very small size
 tshark -i 5 -P -w /tmp/oh.</description>
    </item>
    
    <item>
      <title>Can malware or virus disable or bypass WireShark&amp;#x27;s ability to monitor the network traffic?</title>
      <link>/questions/25801/can-malware-or-virus-disable-or-bypass-wiresharks-ability-to-monitor-the-network-traffic/</link>
      <pubDate>Wed, 09 Oct 2013 04:40:00 +0000</pubDate>
      
      <guid>/questions/25801/can-malware-or-virus-disable-or-bypass-wiresharks-ability-to-monitor-the-network-traffic/</guid>
      <description>Can malware or virus disable or bypass WireShark&amp;rsquo;s ability to monitor the network traffic?  0 I was told recently that certain malware or virus could bypass WireShark making their activity invisible. Is this claim correct? If it is correct, is there a list of the known malware?
malware monitor bypassasked 09 Oct &#39;13, 04:40
TimRC
16●1●1●3
accept rate: 0%
  
2 Answers:
  
0 I was told recently that certain malware or virus could bypass WireShark m</description>
    </item>
    
    <item>
      <title>Decrypt SSL with exported SSL Session Keys</title>
      <link>/questions/25803/decrypt-ssl-with-exported-ssl-session-keys/</link>
      <pubDate>Wed, 09 Oct 2013 05:13:00 +0000</pubDate>
      
      <guid>/questions/25803/decrypt-ssl-with-exported-ssl-session-keys/</guid>
      <description>Decrypt SSL with exported SSL Session Keys  0 Hi all,
I am new to Wireshark, I run v1.6.7 on Ubuntu Desktop. I can decrypt HTTPS Traffic with my private key, works fine. I can see decrypted traffic as http.
In order to send the capture to a vendor, I export the SSL Session Keys to file. Before sending the Session Keys and capture to the 3rd party, I want to test the decryption with the exported SessionKeys.</description>
    </item>
    
    <item>
      <title>Malformed Packet: TFTP</title>
      <link>/questions/25810/malformed-packet-tftp/</link>
      <pubDate>Wed, 09 Oct 2013 06:29:00 +0000</pubDate>
      
      <guid>/questions/25810/malformed-packet-tftp/</guid>
      <description>Malformed Packet: TFTP  0 Hi,
I try to send 0x80200000 data over udp socket. I got this error. when i change data to 0x80200001 or 0x10100000 i can send it without problem. Didnt understand why i got this error...
Internet Protocol Version 4, Src: 192.168.0.202 (192.168.0.202), Dst: 192.168.0.80 (192.168.0.80) User Datagram Protocol, Src Port: hpvmmagent (1125), Dst Port: danf-ak2 (1041) [Malformed Packet: TFTP] Expert Info (Error/Malformed): Malformed Packet (Exception occurred) Message: Malformed Packet (Exception occurred) Severity level: Error Group: MalformedI need your suggestions.</description>
    </item>
    
    <item>
      <title>Captured IP address but which application using it in PC ?</title>
      <link>/questions/25838/captured-ip-address-but-which-application-using-it-in-pc/</link>
      <pubDate>Wed, 09 Oct 2013 09:00:00 +0000</pubDate>
      
      <guid>/questions/25838/captured-ip-address-but-which-application-using-it-in-pc/</guid>
      <description>Captured IP address but which application using it in PC ?  0 Hi ,
I&#39;m getting unwanted packet from particular PC which is getting denied on firewall due to policy, So we used packet capture in that PC which application or resource from PC trying to generate the packet. We found the destination IP which is microsoft IP. But still though we dont know which application trying to generate that Traffic from that PC.</description>
    </item>
    
    <item>
      <title>Configuration file &amp;quot;disabled_protos&amp;quot; NOT Found</title>
      <link>/questions/25856/configuration-file-disabled_protos-not-found/</link>
      <pubDate>Thu, 10 Oct 2013 00:27:00 +0000</pubDate>
      
      <guid>/questions/25856/configuration-file-disabled_protos-not-found/</guid>
      <description>Configuration file &amp;ldquo;disabled_protos&amp;rdquo; NOT Found  0 Hi all, I&#39;m reading an introduction of tshark . In which, I see there is a globla and personal configuration file &#34;disabled_protos&#34; to disable some protocols. Then I find global preference on my Windows 7 at
&#34;C:\Program Files\Wireshark\preferences&#34;
but the directory &#34;preferences&#34; not found . And i check on my server which install Linux with root user at
/usr/local/share/wireshark/preferences
but the directory &#34;preferences&#34; also not found.</description>
    </item>
    
    <item>
      <title>Identifying traffic of cloud-services</title>
      <link>/questions/25859/identifying-traffic-of-cloud-services/</link>
      <pubDate>Thu, 10 Oct 2013 01:15:00 +0000</pubDate>
      
      <guid>/questions/25859/identifying-traffic-of-cloud-services/</guid>
      <description>Identifying traffic of cloud-services  0 Hi all,
I&#39;m working on my master thesis about computer forensic and cloud-computing. Actually I&#39;m trying to identify cloud-related traffic in pcap-files, e.g. dropbox-sync or the usage of Google Drive. My first idea was to extract relevant information like Dest-IP, FQDN or ports out of the pcap-stream. Does anybody know other solutions? For forensic work the usage of encrypted traffic is not as good as it is for &#34;</description>
    </item>
    
    <item>
      <title>Decoding a IEEE802.11 Frame Subtype as Aruba Management</title>
      <link>/questions/25866/decoding-a-ieee80211-frame-subtype-as-aruba-management/</link>
      <pubDate>Thu, 10 Oct 2013 05:25:00 +0000</pubDate>
      
      <guid>/questions/25866/decoding-a-ieee80211-frame-subtype-as-aruba-management/</guid>
      <description>Decoding a IEEE802.11 Frame Subtype as Aruba Management  0 Recently while decoding a IEEE802.11 frame using Wireshark I notice it being detected as an Aruba Management Frame.
As per IEEE standard Frame Subtype value 0x0f in 802.11 Frame is a reserved value. So why does wireshark decode it as Aruba Management. Am I missing something mentioned in the standard.
subtype frame arubaasked 10 Oct &#39;13, 05:25
Nikunj
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>tshark and uat:user_dlts</title>
      <link>/questions/25869/tshark-and-uatuser_dlts/</link>
      <pubDate>Thu, 10 Oct 2013 05:33:00 +0000</pubDate>
      
      <guid>/questions/25869/tshark-and-uatuser_dlts/</guid>
      <description>tshark and uat:user_dlts  0 Hi all, according with link text, I&#39;m trying to parse a .pcap.uat file
tshark -o &amp;quot;uat:user_dlts:\&amp;quot;User 15 (DLT=162)\&amp;quot;,\&amp;quot;pcap\&amp;quot;,\&amp;quot;0\&amp;quot;,\&amp;quot;\&amp;quot;,\&amp;quot;0\&amp;quot;,\&amp;quot;\&amp;quot;&amp;quot; \ -o &amp;quot;uat:user_dlts:\&amp;quot;User 15 (DLT=162)\&amp;quot;,\&amp;quot;mtp3\&amp;quot;,\&amp;quot;12\&amp;quot;,\&amp;quot;\&amp;quot;,\&amp;quot;0\&amp;quot;,\&amp;quot;\&amp;quot;&amp;quot; -nr test.pcap.uat -T pdml &amp;gt; test.xmlFILE: link text
The result is  &amp;lt;packet&amp;gt; &amp;lt;proto name=&#34;geninfo&#34; pos=&#34;0&#34; showname=&#34;General information&#34; size=&#34;106&#34;&amp;gt; &amp;lt;field name=&#34;num&#34; pos=&#34;0&#34; show=&#34;1&#34; showname=&#34;Number&#34; value=&#34;1&#34; size=&#34;106&#34;/&amp;gt; &amp;lt;field name=&#34;len&#34; pos=&#34;0&#34; show=&#34;106&#34; showname=&#34;Frame Length&#34; value=&#34;6a&#34; size=&#34;106&#34;/&amp;gt; &amp;lt;field name=&#34;caplen&#34; pos=&#34;0&#34; show=&#34;106&#34; showname=&#34;Captured Length&#34; value=&#34;6a&#34; size=&#34;106&#34;/&amp;gt; &amp;lt;field name=&#34;</description>
    </item>
    
    <item>
      <title>unicast frame not seen by Wireshark</title>
      <link>/questions/25873/unicast-frame-not-seen-by-wireshark/</link>
      <pubDate>Thu, 10 Oct 2013 06:00:00 +0000</pubDate>
      
      <guid>/questions/25873/unicast-frame-not-seen-by-wireshark/</guid>
      <description>unicast frame not seen by Wireshark  0 In which condition Wireshark does not see 64 - 127 byte unicast frames? I have a specific converter connected to PC and according to egress interface counters of this converter, it sends 64 - 127 byte unicast frames towards the PC, but Wireshark running in PC does not see those frames. I am aware that those packets are malformed. Is it possible that certain NIC&#39;s drop unicast frames targeted to some other destination MAC address other than the one they have?</description>
    </item>
    
    <item>
      <title>Decoder for BT IUP</title>
      <link>/questions/25877/decoder-for-bt-iup/</link>
      <pubDate>Thu, 10 Oct 2013 06:49:00 +0000</pubDate>
      
      <guid>/questions/25877/decoder-for-bt-iup/</guid>
      <description>Decoder for BT IUP  0 I am currently adding the legacy BT IUP protocol (ND1006:2007/05 and ND1104:2004/11) to our switch. I realize that this is an older protocol but it is still prevalent in the U.K. I use Wireshark for other protocol developments and wondered if you have a plug-in for this protocol.
bt iupasked 10 Oct &#39;13, 06:49
britdave
1●2●2●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How to save reassembled TCP packets to a file ?</title>
      <link>/questions/25882/how-to-save-reassembled-tcp-packets-to-a-file/</link>
      <pubDate>Thu, 10 Oct 2013 07:36:00 +0000</pubDate>
      
      <guid>/questions/25882/how-to-save-reassembled-tcp-packets-to-a-file/</guid>
      <description>How to save reassembled TCP packets to a file ?  0 Right-clicking on the bottom pane gave me two choices in the contextual menu : hex view and bits view. I wish to save the packets to a file how can I do that ?
thanks :)
reassembled saveasked 10 Oct &#39;13, 07:36
ychaouche
31●5●6●10
accept rate: 100%
  
One Answer:
  
0 Oh, simple :) so just go on second pane, select 5th element on the stack (Reassemebled TCP Segments), right-click on that item then Export select Packet bytes.</description>
    </item>
    
    <item>
      <title>Is it possible to display the program that is generating the network I/O?</title>
      <link>/questions/25885/is-it-possible-to-display-the-program-that-is-generating-the-network-io/</link>
      <pubDate>Thu, 10 Oct 2013 08:10:00 +0000</pubDate>
      
      <guid>/questions/25885/is-it-possible-to-display-the-program-that-is-generating-the-network-io/</guid>
      <description>Is it possible to display the program that is generating the network I/O?  0 First of all, thank you. Wireshark is an incredible tool. I use it way too much. My wife thinks she is a computer widow...
One thing that would be a nice-to-have. For the packets originating on my computer, is there a way to determine which program (binary) is actually requesting the I/O, and displaying that along with the normal Wireshark output?</description>
    </item>
    
    <item>
      <title>Granularity missing in latest wireshark for WMM parameters?</title>
      <link>/questions/25892/granularity-missing-in-latest-wireshark-for-wmm-parameters/</link>
      <pubDate>Thu, 10 Oct 2013 11:30:00 +0000</pubDate>
      
      <guid>/questions/25892/granularity-missing-in-latest-wireshark-for-wmm-parameters/</guid>
      <description>Granularity missing in latest wireshark for WMM parameters?  0 In wireshark 1.2 version, we had display filters such as
wlan_mgt.wme.be.ac_param.ecwmin==7, i.e. you could filter packets based on WMM parameters for a specific access category.
But in latest wireshark, we can&#39;t do that. i.e. , if I want packets which has ECWMIN for Best Effort is equal to 7, I can&#39;t do that. What I can do is, packets maching ECWMIN to 7.</description>
    </item>
    
    <item>
      <title>TCP persist timer and probe packet&amp;#x27;s data</title>
      <link>/questions/25898/tcp-persist-timer-and-probe-packets-data/</link>
      <pubDate>Thu, 10 Oct 2013 18:27:00 +0000</pubDate>
      
      <guid>/questions/25898/tcp-persist-timer-and-probe-packets-data/</guid>
      <description>TCP persist timer and probe packet&amp;rsquo;s data  0 I have a doubt regarding the persist timer and the associated probe packets.
Lets say the receiver has sent out an ACK with window set to 0.As a result, the sender starts its persist timer.Now, the receiver sends an ACK with window set to 1000 and lets assume this ACK is lost in transit.So, when the persist timer pops off, the sender sends a probe packet to the receiver with a random byte in the data field.</description>
    </item>
    
    <item>
      <title>wireshark capture filter syntax</title>
      <link>/questions/25901/wireshark-capture-filter-syntax/</link>
      <pubDate>Thu, 10 Oct 2013 23:07:00 +0000</pubDate>
      
      <guid>/questions/25901/wireshark-capture-filter-syntax/</guid>
      <description>wireshark capture filter syntax  0 HI,
I am trying to set a capture filter to capture only DHCP packets and also a display filter for the same.
I know we can use -f option with tshark for capture filter and normally DHCP packets come on port 67 or port 68. I apply the same capture filter in wireshark GUI and it captures fine.
But when i try through Command Prompt its gives wrong syntax errors command: tshark -i 2 -f &#34;</description>
    </item>
    
    <item>
      <title>sequence numbers</title>
      <link>/questions/25915/sequence-numbers/</link>
      <pubDate>Fri, 11 Oct 2013 06:31:00 +0000</pubDate>
      
      <guid>/questions/25915/sequence-numbers/</guid>
      <description>sequence numbers  0 hi,
ive capture a http download with: tcpdump host x.x.x.x -c 100
wireshark shows me these sequence numbers for the first 5 packets:
0 0 1 1 1but tcpdump shows:
1636902786 1161722083 1 1:192 1tcpdump -vvr http-download.pcap | sed &#39;s/1.2.3.4/myprivateip/g&#39; | head -10
reading from file http-download.pcap, link-type EN10MB (Ethernet) 21:26:33.318368 IP (tos 0x0, ttl 64, id 64732, offset 0, flags [DF], proto TCP (6), length 60) myprivateip.</description>
    </item>
    
    <item>
      <title>QinQ frame size showed is 1522 and is supposed to  be 1526....</title>
      <link>/questions/25921/qinq-frame-size-showed-is-1522-and-is-supposed-to-be-1526/</link>
      <pubDate>Fri, 11 Oct 2013 14:06:00 +0000</pubDate>
      
      <guid>/questions/25921/qinq-frame-size-showed-is-1522-and-is-supposed-to-be-1526/</guid>
      <description>QinQ frame size showed is 1522 and is supposed to be 1526&amp;hellip;.  0 Hi: I&#39;m capturing some QinQ frames and I&#39;m seeing the frame size showed is 1522 and it was supposed to be 1526. BTW I can see both tags (inner and outer). Any ideas?
frame qinq sizeasked 11 Oct &#39;13, 14:06
JG73
1●1●1●1
accept rate: 0%
If by &#34;frame size&#34; you mean the &#34;Frame Length&#34; field in the packet dissection, note that the captured packet might not include the FCS, in which case it would be 4 bytes shorter than you&#39;d expect for a frame length that includes the FCS.</description>
    </item>
    
    <item>
      <title>why does wireshark crash constantly on a particular PC?</title>
      <link>/questions/25922/why-does-wireshark-crash-constantly-on-a-particular-pc/</link>
      <pubDate>Fri, 11 Oct 2013 14:49:00 +0000</pubDate>
      
      <guid>/questions/25922/why-does-wireshark-crash-constantly-on-a-particular-pc/</guid>
      <description>why does wireshark crash constantly on a particular PC?  0 Hello,
I use wireshark on several computers, and for some reason I can&#39;t get it to work for more than a few minutes on a particular PC running XP, service pack 3. I tried 1.66 and today I installed 1.10.2, with the same results.
Thanks, Victor
wireshark_crashedasked 11 Oct &#39;13, 14:49
vsabino
16●1●1●4
accept rate: 0%
 edited 11 Oct &#39;13, 14:50</description>
    </item>
    
    <item>
      <title>Wireshark not seeing packets from NIC on shut-down computer</title>
      <link>/questions/25923/wireshark-not-seeing-packets-from-nic-on-shut-down-computer/</link>
      <pubDate>Fri, 11 Oct 2013 15:06:00 +0000</pubDate>
      
      <guid>/questions/25923/wireshark-not-seeing-packets-from-nic-on-shut-down-computer/</guid>
      <description>Wireshark not seeing packets from NIC on shut-down computer  0 I have found a situation where WireShark seems to be ignoring packets. I have noticed that after shutting off a computer of mine, and turning off the power to the node as well! ... that the NIC is still active on the network. The communication the NIC is making with the router in this condition is being completely ignored by WireShark.</description>
    </item>
    
    <item>
      <title>two interfaces on router with NAT</title>
      <link>/questions/25924/two-interfaces-on-router-with-nat/</link>
      <pubDate>Fri, 11 Oct 2013 15:54:00 +0000</pubDate>
      
      <guid>/questions/25924/two-interfaces-on-router-with-nat/</guid>
      <description>two interfaces on router with NAT  0 Dear friends, it seems to be simple problem but I cannot deal with it. I have captured packets on the Linux router with NAT on the two interfaces at the same time:
tcpdump -i eth1 -w lan.pcap
tcpdump -i eth0 -w wan.pcap
during two sessions SSH and enter&amp;amp;stop commands almost simultaneously. I need to filter incoming packets to eth1 from 192.168.1.2 IP address and the same packets on the outcoming interface of router (eth0) from these files.</description>
    </item>
    
    <item>
      <title>TCP urgent pointer and urgent data</title>
      <link>/questions/25929/tcp-urgent-pointer-and-urgent-data/</link>
      <pubDate>Fri, 11 Oct 2013 22:56:00 +0000</pubDate>
      
      <guid>/questions/25929/tcp-urgent-pointer-and-urgent-data/</guid>
      <description>TCP urgent pointer and urgent data  0 Hi,
In the TCP header, the urgent pointer points to the last byte of the urgent data, if present.
I couldn&#39;t understand what&#39;s the idea behind this. What could this be possibly used for? I think that beginning of the urgent data might be more useful as it would help TCP (on the receiving end) know where exactly the urgent data begins and ends.</description>
    </item>
    
    <item>
      <title>Xbox live unauthorised access</title>
      <link>/questions/25930/xbox-live-unauthorised-access/</link>
      <pubDate>Sat, 12 Oct 2013 01:24:00 +0000</pubDate>
      
      <guid>/questions/25930/xbox-live-unauthorised-access/</guid>
      <description>Xbox live unauthorised access  0 Can anyone help me? My son&#39;s Xbox live account was accessed by another person who violated their terms of use. They insist the messages were sent from his IP Address but we know they weren&#39;t. I asked them to verify the MAC of the PC used to access the account but they say they can&#39;t do that. Surely they can?
mac-addressasked 12 Oct &#39;13, 01:24</description>
    </item>
    
    <item>
      <title>Airplay why is it so flakey?  anyone have a packet capture?</title>
      <link>/questions/25934/airplay-why-is-it-so-flakey-anyone-have-a-packet-capture/</link>
      <pubDate>Sat, 12 Oct 2013 07:14:00 +0000</pubDate>
      
      <guid>/questions/25934/airplay-why-is-it-so-flakey-anyone-have-a-packet-capture/</guid>
      <description>Airplay why is it so flakey? anyone have a packet capture?  0 Before I bust out my switch capable of doing spans, does anyone have packet captures of IPAD/IPHONE/etc. connecting to receivers for airplay? I&#39;m thinking it uses some type of multicast to find each other, but I wasn&#39;t sure. And not being tied to the Apple ecosystem, too lazy to go ready docs.
If anyone has such a trace, I&#39;d love to take a look.</description>
    </item>
    
    <item>
      <title>How to export packet summary to text file?</title>
      <link>/questions/25936/how-to-export-packet-summary-to-text-file/</link>
      <pubDate>Sat, 12 Oct 2013 08:11:00 +0000</pubDate>
      
      <guid>/questions/25936/how-to-export-packet-summary-to-text-file/</guid>
      <description>How to export packet summary to text file?  1 I have a capture of HTTP traffic that I need to extract values of Info field from. If I right click on each packet, select Copy -&amp;gt; Summary (Text) and then paste it in notepad I would eventually get all the values, but it would take me hours to do. Is there a quicker way to do it? None of the exports I tried worked for me.</description>
    </item>
    
    <item>
      <title>How do you capture port</title>
      <link>/questions/25975/how-do-you-capture-port/</link>
      <pubDate>Mon, 14 Oct 2013 11:28:00 +0000</pubDate>
      
      <guid>/questions/25975/how-do-you-capture-port/</guid>
      <description>How do you capture port  0 I want to capture activities between 192.168.1.10 port 9600(2008 server) and 192.168.1.35 port 9030(Canon copier print server).
In Wireshark 1.10.2, under the caption options, then capture filter, what should I type in there?
Thanks,
Paul
whatasked 14 Oct &#39;13, 11:28
CSA
1●1●1●1
accept rate: 0%
  
One Answer:
  
1If you want to exactly filter on that 4-tuple, the filter would be:</description>
    </item>
    
    <item>
      <title>TCP Reassembly error while capturing Cisco VPN client traffic</title>
      <link>/questions/25977/tcp-reassembly-error-while-capturing-cisco-vpn-client-traffic/</link>
      <pubDate>Mon, 14 Oct 2013 12:34:00 +0000</pubDate>
      
      <guid>/questions/25977/tcp-reassembly-error-while-capturing-cisco-vpn-client-traffic/</guid>
      <description>TCP Reassembly error while capturing Cisco VPN client traffic  0 I am getting the same error. We have a few users who connect to the corporate network using Cisco VPN Client software. They open up two Explorer windows, each with a UNC path to two different shares on the same file server. When they try to copy a file from one share to another while VPN&#39;d in from home, it just sits there saying &#34;</description>
    </item>
    
    <item>
      <title>What does processing speed of Dissectors depend on?</title>
      <link>/questions/25984/what-does-processing-speed-of-dissectors-depend-on/</link>
      <pubDate>Mon, 14 Oct 2013 19:20:00 +0000</pubDate>
      
      <guid>/questions/25984/what-does-processing-speed-of-dissectors-depend-on/</guid>
      <description>What does processing speed of Dissectors depend on?  0 Hi guys, I&#39;m analyzing the processing speed of incoming data and dissector in order to know how they are different. I use the tshark command on Windows and surf Youtube to increase network speed rate :
tshark -i 1 -P -w D:/sonnh.pcap -b filesize:1000 -b files:4I change the code to print out the number of incoming packet (which are written to .</description>
    </item>
    
    <item>
      <title>TSU Notification</title>
      <link>/questions/25987/tsu-notification/</link>
      <pubDate>Tue, 15 Oct 2013 01:01:00 +0000</pubDate>
      
      <guid>/questions/25987/tsu-notification/</guid>
      <description>TSU Notification  0 Dear Wireshark Community,
I have a question regarding EAR compliance for wireshark community mentioned at http://www.wireshark.org/export.html. Am I correct in assuming that TSU notification(s) have been submitted to [email protected] and to [email protected] so that Wireshark&#39;s encryption source code classified under ECCN 5D002 can be eligible for license exception TSU?
Regards, Makoto
export-controlasked 15 Oct &#39;13, 01:01
arf193nm
11●1●1●3
accept rate: 0%
 edited 16 Oct &#39;13, 05:11</description>
    </item>
    
    <item>
      <title>removing duplicate packets from pcap</title>
      <link>/questions/25998/removing-duplicate-packets-from-pcap/</link>
      <pubDate>Tue, 15 Oct 2013 06:43:00 +0000</pubDate>
      
      <guid>/questions/25998/removing-duplicate-packets-from-pcap/</guid>
      <description>removing duplicate packets from pcap  0 I want to analyze packet capture file, but it has some duplicate packets.
For e.g., I am setting packet count to 10000 and seeing 11085 count in wireshark. So the goal is to remove duplicate packets which are 1085 in count. I am using latest wireshark version 1.10.2.
I would like to know if there is any way (command line option) using which I can discard duplicate packets and make new pcap with all unique packets.</description>
    </item>
    
    <item>
      <title>Show untranslated and translated mac addresses in different columns at the time</title>
      <link>/questions/26001/show-untranslated-and-translated-mac-addresses-in-different-columns-at-the-time/</link>
      <pubDate>Tue, 15 Oct 2013 06:59:00 +0000</pubDate>
      
      <guid>/questions/26001/show-untranslated-and-translated-mac-addresses-in-different-columns-at-the-time/</guid>
      <description>Show untranslated and translated mac addresses in different columns at the time  0 Hi all,
Tshark mac address translation works pretty fine, but somehow if i wanna get translated &amp;amp;&amp;amp; untranslated mac addresses in 2 different columns (as SYN-bit within the below link) it doesn&#39;t work.
Related link
On one hand it shows only mac untranslated mac addresses:
$ ./tshark -i wlan1 -Nn -o column.format:&amp;#39;&amp;quot;Unres&amp;quot;,&amp;quot;%us&amp;quot;,&amp;quot;Res&amp;quot;,&amp;quot;%rs&amp;quot;&amp;#39; 74:de:2b:94:b4:cf 74:de:2b:94:b4:cf
c8:d7:19:ed:d5:38 c8:d7:19:ed:d5:38</description>
    </item>
    
    <item>
      <title>Time zone used by wireshark</title>
      <link>/questions/26014/time-zone-used-by-wireshark/</link>
      <pubDate>Tue, 15 Oct 2013 10:23:00 +0000</pubDate>
      
      <guid>/questions/26014/time-zone-used-by-wireshark/</guid>
      <description>Time zone used by wireshark  0 When looking at a packet capture, is it possible to set the time zone used by Wireshark to a time zone other than the system time? My colleagues and I are a occasionally tripped up when working with each other from different time zones (east coast and west coast).
timezoneasked 15 Oct &#39;13, 10:23
syzdek
11●2●2●3
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>WLAN sniff chat</title>
      <link>/questions/26018/wlan-sniff-chat/</link>
      <pubDate>Tue, 15 Oct 2013 11:13:00 +0000</pubDate>
      
      <guid>/questions/26018/wlan-sniff-chat/</guid>
      <description>WLAN sniff chat  0 How to sniff IP messenger chat in wireless? I found packets but encrypted like shown some numbers... then how to decrypt that pcap file? And what is particular way for sniff IP messenger chats?
wireless chatasked 15 Oct &#39;13, 11:13
john6
7●8●8●10
accept rate: 0%
 edited 15 Oct &#39;13, 11:28 
Jasper ♦♦
23.8k●5●51●284
   </description>
    </item>
    
    <item>
      <title>filter traffic by protocol</title>
      <link>/questions/26021/filter-traffic-by-protocol/</link>
      <pubDate>Tue, 15 Oct 2013 13:45:00 +0000</pubDate>
      
      <guid>/questions/26021/filter-traffic-by-protocol/</guid>
      <description>filter traffic by protocol  0 I want to use a command line filter to sort out the traffic by protocol. For example, how can I show other traffic aside from http? Also how can I then get a count of how many TCP sessions exist my packet capture?
protocolasked 15 Oct &#39;13, 13:45
jayhawk100
11●1●1●2
accept rate: 0%
  
One Answer:
  
1There are several ways of doing this.</description>
    </item>
    
    <item>
      <title>Java SSL Problem</title>
      <link>/questions/26035/java-ssl-problem/</link>
      <pubDate>Tue, 15 Oct 2013 17:51:00 +0000</pubDate>
      
      <guid>/questions/26035/java-ssl-problem/</guid>
      <description>Java SSL Problem  0 Can someone help me interpret what&#39;s going on this session? It&#39;s posted here:
http://cloudshark.org/captures/ded1b1cab975 line 229 - 238 is an example but there are others in the capture. I&#39;m wondering if the SSL is being fragmented given that it&#39;s running over a VPN.
I am having app problems where I get a flood of disconnects throughout the day. Java debug that I get: Error SSL connecting to host:8444: java.</description>
    </item>
    
    <item>
      <title>TCP window sizes</title>
      <link>/questions/26044/tcp-window-sizes/</link>
      <pubDate>Wed, 16 Oct 2013 01:46:00 +0000</pubDate>
      
      <guid>/questions/26044/tcp-window-sizes/</guid>
      <description>TCP window sizes  0 1) if tcp syn request wants a 1576 byte &#34;put/write&#34; transfer, will it be sent along with syn request or must send data transfer wait until the syn recieves an ack?
2) does the answer change if the syn request needs a 1576 byte &#34;get/read&#34; transfer?
3) can tcp syn be rejected due to a syn window parameter that isnt supported by the other side?</description>
    </item>
    
    <item>
      <title>Performance Windows vs Linux capture only</title>
      <link>/questions/26050/performance-windows-vs-linux-capture-only/</link>
      <pubDate>Wed, 16 Oct 2013 03:49:00 +0000</pubDate>
      
      <guid>/questions/26050/performance-windows-vs-linux-capture-only/</guid>
      <description>Performance Windows vs Linux capture only  0 At work I&#39;ve been trying to setup a machine with the sole purpose of capturing traffic for later analysis.
Linux seemed like the best option since it required very little resources. I&#39;ve tried tshark, dumpcap and tcpdump. With all 3 command line tools it displays packet drops as high as 20% (I&#39;m assuming because the hardware can&#39;t handle the amount of traffic). So I tried with Windows and the number of dropped packets was 0.</description>
    </item>
    
    <item>
      <title>Verification of counters in a particular range in a packet capture</title>
      <link>/questions/26051/verification-of-counters-in-a-particular-range-in-a-packet-capture/</link>
      <pubDate>Wed, 16 Oct 2013 03:52:00 +0000</pubDate>
      
      <guid>/questions/26051/verification-of-counters-in-a-particular-range-in-a-packet-capture/</guid>
      <description>Verification of counters in a particular range in a packet capture  0 I have got counters based on 2 sec interval.
I need to verify that the count should be in range 1200 to 1600. Is there any way we can do it without parsing whole output?
If for any particular time interval, the count doesn&#39;t fall into matching range, some error/warning message should get printed.
Is there any method to get average for this counters?</description>
    </item>
    
    <item>
      <title>Time Shift feature</title>
      <link>/questions/26084/time-shift-feature/</link>
      <pubDate>Wed, 16 Oct 2013 13:48:00 +0000</pubDate>
      
      <guid>/questions/26084/time-shift-feature/</guid>
      <description>Time Shift feature  1 Do you know some bug with Time Shift feature? When I right-click on the first packet in the trace file, I choose Time Shift... and write -0.000235 it does not work (uoy can user Reload button on the toolbar). I can use only full second for example +3.0. Miliseconds, and other, do not work. It is normal? Or I should set something more?
time_shift featuresasked 16 Oct &#39;13, 13:48</description>
    </item>
    
    <item>
      <title>Wireshark crashes on OSX 10.6.8 on startup</title>
      <link>/questions/26086/wireshark-crashes-on-osx-1068-on-startup/</link>
      <pubDate>Wed, 16 Oct 2013 14:09:00 +0000</pubDate>
      
      <guid>/questions/26086/wireshark-crashes-on-osx-1068-on-startup/</guid>
      <description>Wireshark crashes on OSX 10.6.8 on startup  1 Hello
I found this post: http://ask.wireshark.org/questions/22081/1100-trying-to-run-on-osx1058-but-crashes-on-load where someone had a problem starting Wireshark 1.10 on Mac OSX 10.5, but I have maybe the same problem with my MacBook Pro 10.6.8 (from 2009) and Wireshark 1.8.10 Intel 64 or 1.10.2 Intel 64 or 1.11.0 Intel 64. I start it and immediately I get the crash with this error:
Exception Type: EXC_BREAKPOINT (SIGTRAP) Exception Codes: 0x0000000000000002, 0x0000000000000000 Crashed Thread: 0</description>
    </item>
    
    <item>
      <title>calculating ping time for a game</title>
      <link>/questions/26090/calculating-ping-time-for-a-game/</link>
      <pubDate>Wed, 16 Oct 2013 15:43:00 +0000</pubDate>
      
      <guid>/questions/26090/calculating-ping-time-for-a-game/</guid>
      <description>calculating ping time for a game  0 hi,
i need to graph the packet delay for a game called league of legends, the game uses udp and a port range between 5000-5500. im pretty sure that the delay time is calculated from the udp stream, see explanation in the link at the end. inside the game you can see what they call ping time in ms, but how they measure that im not sure.</description>
    </item>
    
    <item>
      <title>how to display s1ap.gTP_TEID as decimal format?</title>
      <link>/questions/26091/how-to-display-s1apgtp_teid-as-decimal-format/</link>
      <pubDate>Wed, 16 Oct 2013 16:01:00 +0000</pubDate>
      
      <guid>/questions/26091/how-to-display-s1apgtp_teid-as-decimal-format/</guid>
      <description>how to display s1ap.gTP_TEID as decimal format?  0 how to display gtp-teid as decimal format? s1ap.gTP-TEID: d7e29a65
decimal s1ap.gtp_teidasked 16 Oct &#39;13, 16:01
ertsali
11●1●1●3
accept rate: 0%
 edited 18 Oct &#39;13, 03:13 
Kurt Knochner ♦
24.8k●10●39●237
  
2 Answers:
  
3how to display gtp-teid as decimal format? gTP-TEID: d7e29a65
for that single value: 3621952101
In General: By adding a Lua post dissector that takes the original value and adds a new field for the decimal value.</description>
    </item>
    
    <item>
      <title>Supported Codec List not shown on setup message</title>
      <link>/questions/26102/supported-codec-list-not-shown-on-setup-message/</link>
      <pubDate>Thu, 17 Oct 2013 00:10:00 +0000</pubDate>
      
      <guid>/questions/26102/supported-codec-list-not-shown-on-setup-message/</guid>
      <description>Supported Codec List not shown on setup message  0 hi, Normally supported codec list is displayed on the setup message (A interface). But on some phone models (eg : NOKIA E72 )supported codec list is not displayed on the wire shark trace. Can you please explain the reason for this ?
codecasked 17 Oct &#39;13, 00:10
kotagodahetti
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Tick intervals</title>
      <link>/questions/26112/tick-intervals/</link>
      <pubDate>Thu, 17 Oct 2013 02:35:00 +0000</pubDate>
      
      <guid>/questions/26112/tick-intervals/</guid>
      <description>Tick intervals  0 Hello, in Statistics-&amp;gt;IO Graph the smallest Tick interval is 0.001s. It is possible to take data to CSV in smaller intervals? It is needed to analising on microsecond field. Could you help me?
intervals tick_intervalasked 17 Oct &#39;13, 02:35
net16
46●6●7●12
accept rate: 0%
  
One Answer:
  
1 See my answer for a similar question:
http://ask.wireshark.org/questions/13084/customizing-tick-interval-in-io-graph
Regards
Kurt
answered 17 Oct &#39;13, 02:46</description>
    </item>
    
    <item>
      <title>MIPv6 protocol: wireshark is showing malformed packet for mobility option - &amp;quot;3GPP Specific PMIPv6 error code&amp;quot;</title>
      <link>/questions/26124/mipv6-protocol-wireshark-is-showing-malformed-packet-for-mobility-option-3gpp-specific-pmipv6-error-code/</link>
      <pubDate>Thu, 17 Oct 2013 05:33:00 +0000</pubDate>
      
      <guid>/questions/26124/mipv6-protocol-wireshark-is-showing-malformed-packet-for-mobility-option-3gpp-specific-pmipv6-error-code/</guid>
      <description>MIPv6 protocol: wireshark is showing malformed packet for mobility option - &amp;ldquo;3GPP Specific PMIPv6 error code&amp;rdquo;  0 For MIPv6 protocol, wireshark is showing malformed packet when I try to send the mobility option - &#34;3GPP Specific PMIPv6 error code&#34; according to the specification: 3GPP TS 29.275 V10.7.0 (2013-03), Page 68 in any of the following messages: Proxy Binding Acknowledgement (PBA) or Binding Revocation Acknowledgment (BRA). The packet is encoded exactly as described in the specification, but wireshark is showing the aforementioned mobility option as &#34;</description>
    </item>
    
    <item>
      <title>TCP previous segment lost when opening from file</title>
      <link>/questions/26129/tcp-previous-segment-lost-when-opening-from-file/</link>
      <pubDate>Thu, 17 Oct 2013 07:21:00 +0000</pubDate>
      
      <guid>/questions/26129/tcp-previous-segment-lost-when-opening-from-file/</guid>
      <description>TCP previous segment lost when opening from file  0 I am trying to save a dump, and load it on a similar wireshark. I am also copying the .wireshark directory to the other machine. However, HTTP/XML packets are transformed to &#34;Continuation or non-HTTP traffic&#34;. Any ideas?
editSaved packets were saved in the following way:
marked packets of interestsave -&amp;gt; Marked packets onlySaving displayed packets also does not work as expected.</description>
    </item>
    
    <item>
      <title>Decrypting WLAN packets when capture has multiple EAPOL Key changes</title>
      <link>/questions/26146/decrypting-wlan-packets-when-capture-has-multiple-eapol-key-changes/</link>
      <pubDate>Thu, 17 Oct 2013 13:17:00 +0000</pubDate>
      
      <guid>/questions/26146/decrypting-wlan-packets-when-capture-has-multiple-eapol-key-changes/</guid>
      <description>Decrypting WLAN packets when capture has multiple EAPOL Key changes  0 Issue: During a WLAN capture, the EAP keys between the Station and AP change due to an attack. After the keys are modified, decryption no longer occurs on subsequent packets. The WLAN packets are encrypted using WPA/WPA2-PSK
Is it possible for Wireshark to determine that the EAP keys have changed and decrypt the subsequent packets using the new keys?</description>
    </item>
    
    <item>
      <title>I see only HTTP/1.1 200 OK response packets</title>
      <link>/questions/26150/i-see-only-http11-200-ok-response-packets/</link>
      <pubDate>Thu, 17 Oct 2013 17:11:00 +0000</pubDate>
      
      <guid>/questions/26150/i-see-only-http11-200-ok-response-packets/</guid>
      <description>I see only HTTP/1.1 200 OK response packets  0 Suddenly my wireshark is only showing packets from Source IP to Destination IP only. e.g. My source IP is 10.10.23.234 and destination IP is 10.10.23.236. Then my wiereshark should show packets originating from Source and Destination IP but instead it is only showing one direction responses. It is not showing request packets.
What went wrong with wireshark suddenly? Appreciate any help.</description>
    </item>
    
    <item>
      <title>Local Network sluggish/slow between clients and server</title>
      <link>/questions/26161/local-network-sluggishslow-between-clients-and-server/</link>
      <pubDate>Fri, 18 Oct 2013 03:28:00 +0000</pubDate>
      
      <guid>/questions/26161/local-network-sluggishslow-between-clients-and-server/</guid>
      <description>Local Network sluggish/slow between clients and server  0 Local Network (12 Users) lag and general poor performance on SBS2011 SP1 running on a HP ML350 G8 12GB RAM (soon to become 32GB) 4 x 600GB SAS in Raid 5. Users experience the green bar when trying to open or save documents (small and large) also read only errors when opening documents. Its intermittent but reproduceable by creating a word doc on the server from a client machine I can make minor changes and save.</description>
    </item>
    
    <item>
      <title>Automation</title>
      <link>/questions/26164/automation/</link>
      <pubDate>Fri, 18 Oct 2013 03:47:00 +0000</pubDate>
      
      <guid>/questions/26164/automation/</guid>
      <description>Automation  0 Hi,
We have wireshark in our lab. We have encoders,set boxes in our company and we used capture the packets using UDP multicast.
We are trying to automate T-shark using AutoIT Language?  Tshark –V –R “ip.addr == 233.1.1.202” –i 1 –c 1
Do you have any idea on T-shark Automation? is it possible?
wiresharkasked 18 Oct &#39;13, 03:47
vaish
1●1●1●1
accept rate: 0%
Do you have any idea on T-shark Automation?</description>
    </item>
    
    <item>
      <title>TCP Port numbers reused blast?</title>
      <link>/questions/26165/tcp-port-numbers-reused-blast/</link>
      <pubDate>Fri, 18 Oct 2013 05:04:00 +0000</pubDate>
      
      <guid>/questions/26165/tcp-port-numbers-reused-blast/</guid>
      <description>TCP Port numbers reused blast?  0 Hey there,
I am rather new to Wireshark and we are currently experiencing a problem where one of our HP Pro Curve 48 port switches is showing all solid lights. We have a rather large network over a small city and I&#39;m having to find myself power cycle a firewall in order to have full connectivity for only 3-4 hours until the problem persists.</description>
    </item>
    
    <item>
      <title>dissector support sources</title>
      <link>/questions/26168/dissector-support-sources/</link>
      <pubDate>Fri, 18 Oct 2013 07:58:00 +0000</pubDate>
      
      <guid>/questions/26168/dissector-support-sources/</guid>
      <description>dissector support sources  0 Hi all. I&#39;ve finished my dissector plugin. Now I want to &#34;beautify&#34; it. Currently my plugin uses some helper files e.g. &#34;verifier.h&#34;. These helper files don&#39;t point to a .c file at the moment, though. Both declerations and definitions are located in the .h files. That&#39;s because I couldn&#39;t manage to seperate declerations and definitions when developing my plugin. When I add the include/verifier.c to the DISSECTOR_SUPPORT_SRC variable in my plugin&#39;s Makefile, I get an error when starting wireshark: &#34;</description>
    </item>
    
    <item>
      <title>Wireshark101:  Adding nonstandard port to dissector not working?</title>
      <link>/questions/26169/wireshark101-adding-nonstandard-port-to-dissector-not-working/</link>
      <pubDate>Fri, 18 Oct 2013 08:30:00 +0000</pubDate>
      
      <guid>/questions/26169/wireshark101-adding-nonstandard-port-to-dissector-not-working/</guid>
      <description>Wireshark101: Adding nonstandard port to dissector not working?  0 I am going through the &#34;Wireshark101&#34; book and Lab 5 has the reader add port 81 to the list of ports to be dissected as HTTP (under &#34;Preferences, Protocols, HTTP&#34;). I added port 81 to the list of ports to be dissected as HTTP but nothing has changed in the screen output. The sample file is &#34;http-nonstandard101.pcapng&#34;, which has an HTTP session over port 81.</description>
    </item>
    
    <item>
      <title>How can I determine which application is sending DNS queries to my Bind server?</title>
      <link>/questions/26171/how-can-i-determine-which-application-is-sending-dns-queries-to-my-bind-server/</link>
      <pubDate>Fri, 18 Oct 2013 08:41:00 +0000</pubDate>
      
      <guid>/questions/26171/how-can-i-determine-which-application-is-sending-dns-queries-to-my-bind-server/</guid>
      <description>How can I determine which application is sending DNS queries to my Bind server?  0 1I&#39;m trying to figure out how one would go about determining which application on my Linux box is sending a particular DNS query to my Bind server. I&#39;ve been toying with the following command:
$ tshark -i wlan0 -nn -e ip.src -e dns.qry.name -E separator=&amp;quot;;&amp;quot; -T fields port 53 192.168.1.20;ajax.googleapis.com 192.168.1.101;ajax.googleapis.com 192.168.1.20;pop.bizmail.yahoo.comHow can I get this to show me the actual application (port and possibly PID)?</description>
    </item>
    
    <item>
      <title>Filter for detecting the third packet in a 3-way handshake</title>
      <link>/questions/26174/filter-for-detecting-the-third-packet-in-a-3-way-handshake/</link>
      <pubDate>Fri, 18 Oct 2013 09:29:00 +0000</pubDate>
      
      <guid>/questions/26174/filter-for-detecting-the-third-packet-in-a-3-way-handshake/</guid>
      <description>Filter for detecting the third packet in a 3-way handshake  0 Hello,
I am working on putting together a training for my team on recognizing a SYN flood attack.
There are many ways to recognize one, for sure. The high volume of SYNs, sessions in SYN_SENT, etc.
What I would like to do, however, is provide three filters for use with the I/O graphs to show, without question, that the SYN,ACK is not being honored.</description>
    </item>
    
    <item>
      <title>GUI shows no text on OS X 10.8</title>
      <link>/questions/26176/gui-shows-no-text-on-os-x-108/</link>
      <pubDate>Fri, 18 Oct 2013 09:44:00 +0000</pubDate>
      
      <guid>/questions/26176/gui-shows-no-text-on-os-x-108/</guid>
      <description>GUI shows no text on OS X 10.8  0 Hi,
Last night I downloaded the latest Wireshark dmg for OSX and installed it. After launching wireshark, I found that all text in the GUI are not shown, the menu bars, menu items, dialogs, everything. Only icons are shown in the UI. I deleted all directions like .config, .gtk, .wireshark, rerun fc-cache, and the problem still persist. Can anyone give me some hint on what might go wrong here?</description>
    </item>
    
    <item>
      <title>Wireshark 1.10 heur_dissector_t has an extra parameter void*</title>
      <link>/questions/26203/wireshark-110-heur_dissector_t-has-an-extra-parameter-void/</link>
      <pubDate>Fri, 18 Oct 2013 15:23:00 +0000</pubDate>
      
      <guid>/questions/26203/wireshark-110-heur_dissector_t-has-an-extra-parameter-void/</guid>
      <description>Wireshark 1.10 heur_dissector_t has an extra parameter void*  1 I have a plugin dissector and I&#39;m upgrading to 1.10.
I ran across a compile warning where the definition of heur_dissector_t now has an extra parameter void* The header file doesn&#39;t have any documentation for the parameter. What is it for?
I grepped the other plugins and see that packet-esl.c as well as all the others that have heur_dissector_add which doesn&#39;t have the 4th parameter void*</description>
    </item>
    
    <item>
      <title>STATUS_ACCESS_VIOLATION: dissector accessed an invalid memory address when calling g_free</title>
      <link>/questions/26204/status_access_violation-dissector-accessed-an-invalid-memory-address-when-calling-g_free/</link>
      <pubDate>Fri, 18 Oct 2013 16:38:00 +0000</pubDate>
      
      <guid>/questions/26204/status_access_violation-dissector-accessed-an-invalid-memory-address-when-calling-g_free/</guid>
      <description>STATUS_ACCESS_VIOLATION: dissector accessed an invalid memory address when calling g_free  0 I have the following lines in a plugin dissector. The call to g_free below results in a &#34;STATUS_ACCESS_VIOLATION: dissector accessed an invalid memory address.&#34; Looking at the memory address of pchar1 it looks valid and holds a a short string string.
Looking deeper into get_CDR_octet_seq I can see that it allocates memory using ep_alloc_array0. However, the documentation of this function states &#34;</description>
    </item>
    
    <item>
      <title>OSX Mavericks</title>
      <link>/questions/26209/osx-mavericks/</link>
      <pubDate>Sat, 19 Oct 2013 02:30:00 +0000</pubDate>
      
      <guid>/questions/26209/osx-mavericks/</guid>
      <description>OSX Mavericks  0 Hi,
Where can i find updates for Wireshark running under OSX Mavericks? Current version is: 1.11.0 r52474 Qt 5.1.1
Thnx Loe
mavericksasked 19 Oct &#39;13, 02:30
Loe Walter
41●3●3●6
accept rate: 0%
  
One Answer:
  
0We do not guarantee that 1.11.0 - or any development build - will work properly on all versions of the OSes we support. There are currently some issues with Qt 5.</description>
    </item>
    
    <item>
      <title>tshark smb,srt filter error</title>
      <link>/questions/26215/tshark-smbsrt-filter-error/</link>
      <pubDate>Sat, 19 Oct 2013 10:22:00 +0000</pubDate>
      
      <guid>/questions/26215/tshark-smbsrt-filter-error/</guid>
      <description>tshark smb,srt filter error  0 Hi All,
i am trying to get some smb statistics for certain file using tshark , i think i am using the correct syntax but still getting errors as follows below even if i remove the \ i get invalid - &#34;New&#34; was unexpected in this context. Please advice Thanks
C:\traces_test&amp;gt;&amp;quot;c:\Program Files\Wireshark\tshark.exe&amp;quot; -n -r tracesmb_fileop1.pcap -q -z &amp;quot;smb,srt,smb.file==\\New Video 12_20196.xml&amp;quot;tshark: Couldn&#39;t register smb,srt tap: Filter &#34;</description>
    </item>
    
    <item>
      <title>How to play RTP payload which is in AMR codec</title>
      <link>/questions/26222/how-to-play-rtp-payload-which-is-in-amr-codec/</link>
      <pubDate>Sun, 20 Oct 2013 00:04:00 +0000</pubDate>
      
      <guid>/questions/26222/how-to-play-rtp-payload-which-is-in-amr-codec/</guid>
      <description>How to play RTP payload which is in AMR codec  0 Hello Expert,
I would like a question about AMR codec in RTP. With a pcap of sip call, I have known that the payload can be played in Wireshark if tht codec is PCMU.
But it seems like the original wireshark does not support AMR very well. Is it possibe to make wireshark to play AMR payload?
Thanks a lot.</description>
    </item>
    
    <item>
      <title>plain text automatic save</title>
      <link>/questions/26224/plain-text-automatic-save/</link>
      <pubDate>Sun, 20 Oct 2013 10:41:00 +0000</pubDate>
      
      <guid>/questions/26224/plain-text-automatic-save/</guid>
      <description>plain text automatic save  0 is there a possibility &#34;plain text objects&#34; automatically export and in real time? I need the data in real time as individual files.
thx
real plain save time textasked 20 Oct &#39;13, 10:41
sub2k
11●1●1●2
accept rate: 0%
  
One Answer:
  
0I need the data in real time as individual files.
Unfortunately that&#39;s not possible with tshark/Wireshark. You can extract the TCP payload with tshark, however not in real time and not automatically as separate files.</description>
    </item>
    
    <item>
      <title>what is (RA) &amp;amp; (TA) means?</title>
      <link>/questions/26225/what-is-ra-ta-means/</link>
      <pubDate>Sun, 20 Oct 2013 12:25:00 +0000</pubDate>
      
      <guid>/questions/26225/what-is-ra-ta-means/</guid>
      <description>what is (RA) &amp;amp; (TA) means?  0 Hi There,
I have some questions:
In my wireshare result, the source column sometimes showing (TA) and destination (RA). are these means Transmission Address and Recipient Address?
I did a tcpdump with limit -s 60, and the source column come out blank. But when I did not set any limit the some source line showed MAC address (TA) and some line are showing blank.</description>
    </item>
    
    <item>
      <title>Capture and decrypt WiFi of another device on a Mac 10.6</title>
      <link>/questions/26227/capture-and-decrypt-wifi-of-another-device-on-a-mac-106/</link>
      <pubDate>Mon, 21 Oct 2013 00:29:00 +0000</pubDate>
      
      <guid>/questions/26227/capture-and-decrypt-wifi-of-another-device-on-a-mac-106/</guid>
      <description>Capture and decrypt WiFi of another device on a Mac 10.6  1 Hello
I want to sniff the data traffic of my Android Phone (SGS2) with my MacBook OS !0.6.8
So I read all the documentation here:
http://wiki.wireshark.org/HowToDecrypt802.11
and here:
http://wiki.wireshark.org/CaptureSetup/WLAN
how I can set my Airport NIC on my MacBook with 10.6.8 on Wireshark 1.10.2 to monitor mode in:
Edit / Preferences / User Interface / Capture / Interfaces: / Edit / Device: en1 [x] Monitor Mode / Default link-layer header type: 802.</description>
    </item>
    
    <item>
      <title>Profinet: PNIO-CM messages are not visible</title>
      <link>/questions/26236/profinet-pnio-cm-messages-are-not-visible/</link>
      <pubDate>Mon, 21 Oct 2013 04:41:00 +0000</pubDate>
      
      <guid>/questions/26236/profinet-pnio-cm-messages-are-not-visible/</guid>
      <description>Profinet: PNIO-CM messages are not visible  0 Dear Sir/Madam,
I found the following problem, though i cannot find a possible solution to fix it. When trying to measure the startup of a Profinet Device, the IO controller will set a connection to the IO Device using application and communication relations. With the newest build of Wireshark (Version 1.10.2 (SVN Rev 51934 from /trunk-1.10)) and WinPcap 4.1.3 i cannot seem to measure these messages.</description>
    </item>
    
    <item>
      <title>UCI IE is not decoded correctly in CSR message of GTPv2C</title>
      <link>/questions/26237/uci-ie-is-not-decoded-correctly-in-csr-message-of-gtpv2c/</link>
      <pubDate>Mon, 21 Oct 2013 04:52:00 +0000</pubDate>
      
      <guid>/questions/26237/uci-ie-is-not-decoded-correctly-in-csr-message-of-gtpv2c/</guid>
      <description>UCI IE is not decoded correctly in CSR message of GTPv2C  0 In Wireshark Version 1.10.1 the User CSG Information IE is not decoded in Create session Request message.
gtpv2casked 21 Oct &#39;13, 04:52
Pikan
1●1●1●2
accept rate: 0%
Is this a question or a bug report?
If it is supposed to be question, please change your text to actually ask something.
If bug report, go to http://bugs.wireshark.org and file it over there, please.</description>
    </item>
    
    <item>
      <title>Dissect data using Lua post-dissector</title>
      <link>/questions/26247/dissect-data-using-lua-post-dissector/</link>
      <pubDate>Mon, 21 Oct 2013 06:32:00 +0000</pubDate>
      
      <guid>/questions/26247/dissect-data-using-lua-post-dissector/</guid>
      <description>Dissect data using Lua post-dissector  0 I have an existing dissector that ends up leaving some of the payload of the packet undissected. The remaining bytes are handled by the generic &#34;data&#34; dissector, and are in a field simply called &#34;data.data&#34;. I would like to use Lua to play around with dissecting these bytes. Reading around, it would appear that writing a post-dissector is the easiest way to achieve this.</description>
    </item>
    
    <item>
      <title>How to identify high throughput applications</title>
      <link>/questions/26256/how-to-identify-high-throughput-applications/</link>
      <pubDate>Mon, 21 Oct 2013 09:49:00 +0000</pubDate>
      
      <guid>/questions/26256/how-to-identify-high-throughput-applications/</guid>
      <description>How to identify high throughput applications  0 Yep, I’m a Newbie and I don’t even have a clue.
System: Windows 7 64bit
Wireshark is a fantastic program with very powerful features and I like it a lot; but, because of its extensive capabilities it does seem to have a steep learning curve and that’s OK I just need time to learn it.
However, I have a pressing issue with some unknown application that is consuming huge quantities of bandwidth (4GB, 2 days, 40% of monthly allotment).</description>
    </item>
    
    <item>
      <title>Streaming audio (radiostation)</title>
      <link>/questions/26258/streaming-audio-radiostation/</link>
      <pubDate>Mon, 21 Oct 2013 11:28:00 +0000</pubDate>
      
      <guid>/questions/26258/streaming-audio-radiostation/</guid>
      <description>Streaming audio (radiostation)  0 Hi, I am writing down a research based on protocols used for audio streaming, such as radio-stations for example.I&#39;ve noticed that TCP and HTTP protocols are used, but i cant figure out how are they implemented? HTTP works on application layer, while TCP works on transport layer. Also where can i find which coding is being used?
streaming audio http tcp rado-stationasked 21 Oct &#39;13, 11:28</description>
    </item>
    
    <item>
      <title>LLDP unable to decode PFC and Congestion Notification TLV&amp;#x27;s</title>
      <link>/questions/26259/lldp-unable-to-decode-pfc-and-congestion-notification-tlvs/</link>
      <pubDate>Mon, 21 Oct 2013 12:59:00 +0000</pubDate>
      
      <guid>/questions/26259/lldp-unable-to-decode-pfc-and-congestion-notification-tlvs/</guid>
      <description>LLDP unable to decode PFC and Congestion Notification TLV&amp;rsquo;s  0 Hello all,
I am currently running the latest release for Wireshark Version 1.10.2.
My problem is both the PFC TLV and the Congestion Notification TLV are not properly decoded e.g.
I am seeing unknown subtype 0xb and 0x8 respectively and as a result there is configuration present in either TLV.
lldpasked 21 Oct &#39;13, 12:59
MKelly765
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to fix Bad TCP - Retransmission &amp;amp; Dup ACKs - Bad First Byte.</title>
      <link>/questions/26260/how-to-fix-bad-tcp-retransmission-dup-acks-bad-first-byte/</link>
      <pubDate>Mon, 21 Oct 2013 14:39:00 +0000</pubDate>
      
      <guid>/questions/26260/how-to-fix-bad-tcp-retransmission-dup-acks-bad-first-byte/</guid>
      <description>How to fix Bad TCP - Retransmission &amp;amp; Dup ACKs - Bad First Byte.  0 My website has seen ever decreasing traffic, so I&#39;ve been working to increase speed and usability. On WebPageTest.org I&#39;ve worked most of my grades up but First Byte is still horrible.
F First Byte TimeA Keep-alive EnabledA Compress TransferA Compress ImagesA Progressive JPEGsB Cache staticFirst Byte Time (back-end processing): 0/100
1081 ms First Byte Time 90 ms Target First Byte Time</description>
    </item>
    
    <item>
      <title>radius 3GPP_User_Location_Info</title>
      <link>/questions/26261/radius-3gpp_user_location_info/</link>
      <pubDate>Mon, 21 Oct 2013 15:34:00 +0000</pubDate>
      
      <guid>/questions/26261/radius-3gpp_user_location_info/</guid>
      <description>radius 3GPP_User_Location_Info  0 Hello Guys,
I am trying to extract 3GPP_User_Location_Info from Radius messages. However in this instance it is not extracting info correctly
$ tshark -v TShark 1.10.2 (SVN Rev 51934 from /trunk-1.10)
tshark -T fields -e radius.Calling_Station_Id -e radius.3GPP_User_Location_Info -e radius.3GPP_IMEISV -e radius.Framed-IP-Address -E header=y -E separator=, -E quote=d -r Nikola_TEST_cap.pcap | head
radius.Calling_Station_Id,radius.3GPP_User_Location_Info,radius.3GPP_IMEISV,radius.Framed-IP-Address &#34;6149891xxxx&#34;,,&#34;3598220413753808&#34;,&#34;144.131.70.63&#34; &#34;6145563xxxx&#34;,,&#34;3598220423540908&#34;,&#34;101.175.33.128&#34;
For some reason the 3GPP-User-Location-Id AVP doesn’t get extracted by tshark, although Wireshark shows/decodes the AVP just file.</description>
    </item>
    
    <item>
      <title>Extract files using tshark to save locally</title>
      <link>/questions/26266/extract-files-using-tshark-to-save-locally/</link>
      <pubDate>Mon, 21 Oct 2013 18:02:00 +0000</pubDate>
      
      <guid>/questions/26266/extract-files-using-tshark-to-save-locally/</guid>
      <description>Extract files using tshark to save locally  0 Is there a way to use TSHARK to extract files so they can be stored in a directory? I know how to do it with the GUI....
Thanks
files tsharkasked 21 Oct &#39;13, 18:02
mlow1223
1●1●1●2
accept rate: 0%
 edited 21 Oct &#39;13, 18:03 
  
One Answer:
  
1I don&#39;t believe this is current something that can be done through tshark, though it would be great if it could!</description>
    </item>
    
    <item>
      <title>libwiretap.so.3 not found</title>
      <link>/questions/26267/libwiretapso3-not-found/</link>
      <pubDate>Mon, 21 Oct 2013 18:06:00 +0000</pubDate>
      
      <guid>/questions/26267/libwiretapso3-not-found/</guid>
      <description>libwiretap.so.3 not found  0 I was trying to install wireshark 1.10.2 under Ubuntu 12.04 and encountered an error saying that libwiretap.so.3 can not open shared object file : No such file or directory. How shall I fix it?
installasked 21 Oct &#39;13, 18:06
zeki88
36●1●1●2
accept rate: 100%
How did you install wireshark 1.10.2?
(22 Oct &#39;13, 00:24) Kurt Knochner ♦  
One Answer:
  
0 Problem solved!</description>
    </item>
    
    <item>
      <title>How to turn on monitor mode on Mac OS X</title>
      <link>/questions/26270/how-to-turn-on-monitor-mode-on-mac-os-x/</link>
      <pubDate>Mon, 21 Oct 2013 18:33:00 +0000</pubDate>
      
      <guid>/questions/26270/how-to-turn-on-monitor-mode-on-mac-os-x/</guid>
      <description>How to turn on monitor mode on Mac OS X  1 Hello,
I just downloaded wireshark 1.10.2 on my Mac OSX 10.7.5 and I&#39;m trying to capture packets on my home wifi network in monitor mode. I&#39;ve selected my wifi network (en1) in the interface list and from what I&#39;ve read so far in other threads and the wireshark wiki I should have an option to check off a &#34;</description>
    </item>
    
    <item>
      <title>how to read the icmpv6 flags for router advertisement</title>
      <link>/questions/26274/how-to-read-the-icmpv6-flags-for-router-advertisement/</link>
      <pubDate>Mon, 21 Oct 2013 21:42:00 +0000</pubDate>
      
      <guid>/questions/26274/how-to-read-the-icmpv6-flags-for-router-advertisement/</guid>
      <description>how to read the icmpv6 flags for router advertisement  0 Hi,
I am running a wireshark capture on the LAN cape side i.e 192.168.0.x router side. I am looking for Router advertisement packets . I am running a display filter &#34;icmpv6.type == 134&#34;. I want to read the &#39;M&#39;(managed address configuration) bit, &#39;O&#39;(other stateful configuration) bit, &#39;L&#39; bit and &#39;A&#39; bit from the captured file.
I am using Tshark command line as i am doing this for automation and cannot use wireshark GUI for reading these flags.</description>
    </item>
    
    <item>
      <title>Phone over Wireless - Having issues</title>
      <link>/questions/26275/phone-over-wireless-having-issues/</link>
      <pubDate>Mon, 21 Oct 2013 23:42:00 +0000</pubDate>
      
      <guid>/questions/26275/phone-over-wireless-having-issues/</guid>
      <description>Phone over Wireless - Having issues  0 Currently, I am trying to examine the packets my phone sends for certain applications.
My phone is a Galaxy S3, and it is set up so that it only uses my wireless network, but I cannot find any packets to/from the phone, even when I browse the web on it.
Am I chasing a dream here, or can this actually be done?</description>
    </item>
    
    <item>
      <title>tcp packet not seen in wireshark</title>
      <link>/questions/26283/tcp-packet-not-seen-in-wireshark/</link>
      <pubDate>Tue, 22 Oct 2013 02:24:00 +0000</pubDate>
      
      <guid>/questions/26283/tcp-packet-not-seen-in-wireshark/</guid>
      <description>tcp packet not seen in wireshark  0 The code of tcp client can send the tcp packet. But the sent packet is not seen in wireshark. Also the sent packet is received by tcp server. I couldnot display the code here properly. also i cannot upload the code. please suggest how to share the code in this blog.
tcp packet wiresharkThis question is marked &#34;community wiki&#34;.asked 22 Oct &#39;13, 02:24</description>
    </item>
    
    <item>
      <title>display-filter out packets that are not to or from my IP</title>
      <link>/questions/26284/display-filter-out-packets-that-are-not-to-or-from-my-ip/</link>
      <pubDate>Tue, 22 Oct 2013 02:40:00 +0000</pubDate>
      
      <guid>/questions/26284/display-filter-out-packets-that-are-not-to-or-from-my-ip/</guid>
      <description>display-filter out packets that are not to or from my IP  0 I should also mention that I am connected to a wifi router and so maybe I won&#39;t be able to see traffic that is not intended for my machine ?
to router from display-filterasked 22 Oct &#39;13, 02:40
ychaouche
31●5●6●10
accept rate: 100%
  
One Answer:
  
0This works for me:
!ip.addr==192.168.1.100
Replace IP addr with your current IP ;)</description>
    </item>
    
    <item>
      <title>dumpcap and wireshark only capture the first three packets of every tcp stream</title>
      <link>/questions/26288/dumpcap-and-wireshark-only-capture-the-first-three-packets-of-every-tcp-stream/</link>
      <pubDate>Tue, 22 Oct 2013 08:22:00 +0000</pubDate>
      
      <guid>/questions/26288/dumpcap-and-wireshark-only-capture-the-first-three-packets-of-every-tcp-stream/</guid>
      <description>dumpcap and wireshark only capture the first three packets of every tcp stream  0 I have a win2003 server with two HP NC382i DP network controllers [v5.2.17.0] working as a team (Network Teaming Intermediate Driver NTID) [CPQTEAM.sys v9.90.1.0)
I execute a web service test from a Win7 client.
If I capture on the server (with wireshark or with dumpcap) I only capture the first 3 packets of every TCP socket.</description>
    </item>
    
    <item>
      <title>Updating COL_INFO column after packet visited</title>
      <link>/questions/26290/updating-col_info-column-after-packet-visited/</link>
      <pubDate>Tue, 22 Oct 2013 08:32:00 +0000</pubDate>
      
      <guid>/questions/26290/updating-col_info-column-after-packet-visited/</guid>
      <description>Updating COL_INFO column after packet visited  1 I am writing a custom protocol dissector for our protocol layered on top of UDP. From the protocol header I can determine various packet attributes which allows me to group the packets into conversations of related data and ack packets.
As part of the protocol header I have a source channel ID which I extract and store in the conversation. The source channel ID from the first data packet and return ack can be used to create a source / destination channel pair which I want to use in the COL_INFO info column, for example &#34;</description>
    </item>
    
    <item>
      <title>Time format on Graph Analysis window</title>
      <link>/questions/26291/time-format-on-graph-analysis-window/</link>
      <pubDate>Tue, 22 Oct 2013 09:49:00 +0000</pubDate>
      
      <guid>/questions/26291/time-format-on-graph-analysis-window/</guid>
      <description>Time format on Graph Analysis window  0 Hi Can you explain to me how do I can change the time format on the window &#34;Graph Analysis&#34; to absolute time or something like that? This window appears when I choose &#34;Flow&#34; in the VoIP Calls window.
Thank you.
Juan David.
absolute_time format flow voip timeasked 22 Oct &#39;13, 09:49
jdtami
11●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark captures only one direction of traffic</title>
      <link>/questions/26299/wireshark-captures-only-one-direction-of-traffic/</link>
      <pubDate>Tue, 22 Oct 2013 16:10:00 +0000</pubDate>
      
      <guid>/questions/26299/wireshark-captures-only-one-direction-of-traffic/</guid>
      <description>Wireshark captures only one direction of traffic  0 hi , I am using wireshark 1.10.2 with the latest winPcap 4.1.3 all 64 bit with windows 7 64 bit however , the only stream the wireshark capture is the incoming direction but all the outgong are not , no capture filter applied . I uninstalled the whole program with it&#39;s dependencies and reinstall it back again with no diffrence . other tools like network monitor tool for microsoft can capture both direction on the same Laptop .</description>
    </item>
    
    <item>
      <title>Wireshark TZSP to regular 802.11 ?</title>
      <link>/questions/26300/wireshark-tzsp-to-regular-80211/</link>
      <pubDate>Tue, 22 Oct 2013 17:00:00 +0000</pubDate>
      
      <guid>/questions/26300/wireshark-tzsp-to-regular-80211/</guid>
      <description>Wireshark TZSP to regular 802.11 ?  0 Hello, as you know , the captured files with TZSP is not usefull for Aircrack-NG. is there anyway to convert TZSP to something that Aircrack can use it.
when i want use tzsp captured files in aircrack it give me this error
This file is not a regular 802.11 (wireless) capture. Read 0 packets. No networks found, exiting.
http://i.imgur.com/np3Au6E.png
tzsp wiresharkasked 22 Oct &#39;13, 17:00</description>
    </item>
    
    <item>
      <title>how do you interpret wireshark trace for application slowness between 2 servers</title>
      <link>/questions/26301/how-do-you-interpret-wireshark-trace-for-application-slowness-between-2-servers/</link>
      <pubDate>Tue, 22 Oct 2013 17:17:00 +0000</pubDate>
      
      <guid>/questions/26301/how-do-you-interpret-wireshark-trace-for-application-slowness-between-2-servers/</guid>
      <description>how do you interpret wireshark trace for application slowness between 2 servers  0 I am new to wireshark trace analysis and needs pointers in interpreting a wireshark trace for application slowness between 2 servers. What specific parameters I would look for in the trace as a cause of the slowness to occur? Would it be window extremely small TCP window size (500+)
window sizeasked 22 Oct &#39;13, 17:17
wshark</description>
    </item>
    
    <item>
      <title>Bandwidth I/O graph and packet capture mode</title>
      <link>/questions/26307/bandwidth-io-graph-and-packet-capture-mode/</link>
      <pubDate>Tue, 22 Oct 2013 20:08:00 +0000</pubDate>
      
      <guid>/questions/26307/bandwidth-io-graph-and-packet-capture-mode/</guid>
      <description>Bandwidth I/O graph and packet capture mode  0 Dear all,
Is it possible to get an accurate and correct Bandwidth I/O graph without capturing full packet?
In addition, if there is need for long capture time required, do you have recommendation or precaution?
Thanks.
bandwidth packet-captureasked 22 Oct &#39;13, 20:08
Applepie2
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Is it possible to get an accurate and correct Bandwidth I/O graph without capturing full packet?</description>
    </item>
    
    <item>
      <title>Grab URL stream from UDP packets [&#43;screenshot]</title>
      <link>/questions/26308/grab-url-stream-from-udp-packets-screenshot/</link>
      <pubDate>Tue, 22 Oct 2013 20:31:00 +0000</pubDate>
      
      <guid>/questions/26308/grab-url-stream-from-udp-packets-screenshot/</guid>
      <description>Grab URL stream from UDP packets [+screenshot]  0 I&#39;m trying to grab the stream url from a Mixlr.com channel using Wireshark. It seems to send UDP packets, but I don&#39;t know how to proceed. Here&#39;s a screenshot.
http://prntscr.com/1z4gx5/direct
My aim is to play the audio stream within foobar2000 or winamp.
udp audio packets streamasked 22 Oct &#39;13, 20:31
redraw
1●2●2●3
accept rate: 0%
 edited 22 Oct &#39;13, 20:32</description>
    </item>
    
    <item>
      <title>WireShark on cloud -Azure</title>
      <link>/questions/26314/wireshark-on-cloud-azure/</link>
      <pubDate>Wed, 23 Oct 2013 01:53:00 +0000</pubDate>
      
      <guid>/questions/26314/wireshark-on-cloud-azure/</guid>
      <description>WireShark on cloud -Azure  0 can i run it on microsoft cloud - azure?
azure cloudasked 23 Oct &#39;13, 01:53
Shruthi
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Azure is just a &#39;framework&#39; for virtual machines hosted by Microsoft. You can run Windows or Linux in those virtual machines and you can install whatever software you want (maybe with some exceptions - check the Azure docs).</description>
    </item>
    
    <item>
      <title>How to add mac-addresses into -T text ?</title>
      <link>/questions/26315/how-to-add-mac-addresses-into-t-text/</link>
      <pubDate>Wed, 23 Oct 2013 02:15:00 +0000</pubDate>
      
      <guid>/questions/26315/how-to-add-mac-addresses-into-t-text/</guid>
      <description>How to add mac-addresses into -T text ?  0 Hu, guys!
Is it possible to add mac-addresses into default output format for tshark?
output tsharkasked 23 Oct &#39;13, 02:15
itonohito
11●1●1●3
accept rate: 0%
  
One Answer:
  
2The default columns that Wireshark uses are specified by the following in tshark:
Windows:
tshark -o &#34;column.format:\&#34;No.\&#34;,\&#34;%Cus:frame.number:0:R\&#34;,\&#34;Time\&#34;,\&#34;%t\&#34;,\&#34;Source\&#34;,\&#34;%s\&#34;,\&#34;Destination\&#34;,\&#34;%d\&#34;,\&#34;Protocol\&#34;,\&#34;%p\&#34;,\&#34;Length\&#34;,\&#34;%L\&#34;,\&#34;Info\&#34;,\&#34;%i\&#34;&#34;
*Nix:
tshark -o &#39;column.format:&#34;No.&#34;,&#34;%Cus:frame.number:0:R&#34;,&#34;Time&#34;,&#34;%t&#34;,&#34;Source&#34;,&#34;%s&#34;,&#34;Destination&#34;,&#34;%d&#34;,&#34;Protocol&#34;,&#34;%p&#34;,&#34;Length&#34;,&#34;%L&#34;,&#34;Info&#34;,&#34;%i&#34;&#39;
If you want to display the mac addresses, you can modify that to use one or more of the following, giving any name you want for the format:</description>
    </item>
    
    <item>
      <title>Dumpcap access violation with remote capture</title>
      <link>/questions/26318/dumpcap-access-violation-with-remote-capture/</link>
      <pubDate>Wed, 23 Oct 2013 04:19:00 +0000</pubDate>
      
      <guid>/questions/26318/dumpcap-access-violation-with-remote-capture/</guid>
      <description>Dumpcap access violation with remote capture  0 Hello everyone,
I&#39;ve implemented a remote capture server based on the Remote Packet Capture Protocol v.0 (actually based on the communication supported by the RPCAP daemon from WinPcap) with some virtual interfaces which are specifically managed on the server.
The server can communicate with Wireshark and deliver a list of interfaces and start a capture with devices present in the list (no devices are currently delivering data, so the capture is empty).</description>
    </item>
    
    <item>
      <title>Wireshark 1.10.2 on Windows XP is not showing 802.11 control frames and management frame informations.</title>
      <link>/questions/26320/wireshark-1102-on-windows-xp-is-not-showing-80211-control-frames-and-management-frame-informations/</link>
      <pubDate>Wed, 23 Oct 2013 05:40:00 +0000</pubDate>
      
      <guid>/questions/26320/wireshark-1102-on-windows-xp-is-not-showing-80211-control-frames-and-management-frame-informations/</guid>
      <description>Wireshark 1.10.2 on Windows XP is not showing 802.11 control frames and management frame informations.  0 Hi,
In the packet details i am not seeing any 802.11 related IEs and informations While capturing WLAN packets using the latest versions of Wireshark on Windows XP. But it is able to decode and display 802.11 IEs when we are opening a sniffer file which was captured using older development versions of Wireshark.</description>
    </item>
    
    <item>
      <title>How to filter GSM messages in Wireshark?</title>
      <link>/questions/26321/how-to-filter-gsm-messages-in-wireshark/</link>
      <pubDate>Wed, 23 Oct 2013 05:43:00 +0000</pubDate>
      
      <guid>/questions/26321/how-to-filter-gsm-messages-in-wireshark/</guid>
      <description>How to filter GSM messages in Wireshark?  0 In my Wireshark Network traffic I get both 2G and 3G data packets (gsm_map). How to filter only 2g or only 3g data packets?
We usually concern about AnyTimeInterrogation message in GSM.
filter packet-display packet display-filterasked 23 Oct &#39;13, 05:43
pranitkothari
51●5●6●10
accept rate: 100%
  
3 Answers:
  
0 I found answer myself.
In display filter, I need to use,</description>
    </item>
    
    <item>
      <title>Unable to install Wireshark on OS X Mavericks</title>
      <link>/questions/26325/unable-to-install-wireshark-on-os-x-mavericks/</link>
      <pubDate>Wed, 23 Oct 2013 08:48:00 +0000</pubDate>
      
      <guid>/questions/26325/unable-to-install-wireshark-on-os-x-mavericks/</guid>
      <description>Unable to install Wireshark on OS X Mavericks  0 I am unable to install Wireshark on Mavericks.
mavericksasked 23 Oct &#39;13, 08:48
tgreen
1●1●1●1
accept rate: 0%
 edited 23 Oct &#39;13, 12:05 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
0Which version of Wireshark?
1.11.0 doesn&#39;t work on Mavericks, due to a problem with Qt.
1.10.2 does work (I just tried it), but the initial installation process is a bit of a pain:</description>
    </item>
    
    <item>
      <title>Apple Maverick and X11</title>
      <link>/questions/26326/apple-maverick-and-x11/</link>
      <pubDate>Wed, 23 Oct 2013 09:02:00 +0000</pubDate>
      
      <guid>/questions/26326/apple-maverick-and-x11/</guid>
      <description>Apple Maverick and X11  3 Hi seems that after the new Apple update Maverick. wireshark is not working. Anyone else noticing it ?, better know how to fix it ?. Error To open &#34;wireshark-bin&#34;you need isntall X11 Would likt ot install X11 now? 2 options 1) cancel 2) Continue --&amp;gt; http://support.apple.com/kb/HT5293
either via the app or command line same issue mac book pro 10.9
Wireshark 1.10.2 XQuartz 2.7.4 (xorg-server 1.</description>
    </item>
    
    <item>
      <title>graph time on the x axis vs, time between frames on y axis</title>
      <link>/questions/26329/graph-time-on-the-x-axis-vs-time-between-frames-on-y-axis/</link>
      <pubDate>Wed, 23 Oct 2013 11:32:00 +0000</pubDate>
      
      <guid>/questions/26329/graph-time-on-the-x-axis-vs-time-between-frames-on-y-axis/</guid>
      <description>graph time on the x axis vs, time between frames on y axis  0 How can I graph time on the x axis vs, time between frames on y axis? I will filter my display on only 1 side of the conversation, A -&amp;gt; B Then I want to see when the time between frames spikes up. It will allow me to see when the Source has &#39;paused&#39; so to speak.</description>
    </item>
    
    <item>
      <title>texts through home router</title>
      <link>/questions/26333/texts-through-home-router/</link>
      <pubDate>Wed, 23 Oct 2013 12:15:00 +0000</pubDate>
      
      <guid>/questions/26333/texts-through-home-router/</guid>
      <description>texts through home router  0 Is it possible to capture the content of texts (iMessage, SMS, etc.) sent through my home router?
texts router homeasked 23 Oct &#39;13, 12:15
ridehrd
11●1●1●2
accept rate: 0%
Idon&#39;t know what iMessage is but SMS is probably not sent trough your home router but rather trough the Mobile network.
(23 Oct &#39;13, 13:25) Anders ♦iMessage is the Apple instant messaging app which will be going over your home LAN.</description>
    </item>
    
    <item>
      <title>Wireshark is just capturing local traffic</title>
      <link>/questions/26334/wireshark-is-just-capturing-local-traffic/</link>
      <pubDate>Wed, 23 Oct 2013 13:19:00 +0000</pubDate>
      
      <guid>/questions/26334/wireshark-is-just-capturing-local-traffic/</guid>
      <description>Wireshark is just capturing local traffic  0 Hi,
I am using Wireshark on Mac OSX and it is justing capturing the local traffic (so, what happening on my computer, not on the others). I have tried it with Ethernet (LAN) Connection and with a WiFi Connection. It is still not working...
Thank you Florian Traun
not traffic local external loopbackasked 23 Oct &#39;13, 13:19
Florian Traun
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Setup network card for wireshark</title>
      <link>/questions/26340/setup-network-card-for-wireshark/</link>
      <pubDate>Wed, 23 Oct 2013 16:07:00 +0000</pubDate>
      
      <guid>/questions/26340/setup-network-card-for-wireshark/</guid>
      <description>Setup network card for wireshark  0 I have two network card installed in my PC, one network card is connected to cooperation LAN, another is connected to my development system for sniffer the Ethernet data, anyone knows how to configure this card?
networkasked 23 Oct &#39;13, 16:07
rabbit
1●4●4●5
accept rate: 0%
  
2 Answers:
  
0Normally, no special configuration is necessary to be able to capture, but it would be wise to disable all protocols on the card.</description>
    </item>
    
    <item>
      <title>Unable to capture wireless traffic on monitor mode on Ubuntu 10.04 version</title>
      <link>/questions/26347/unable-to-capture-wireless-traffic-on-monitor-mode-on-ubuntu-1004-version/</link>
      <pubDate>Wed, 23 Oct 2013 23:53:00 +0000</pubDate>
      
      <guid>/questions/26347/unable-to-capture-wireless-traffic-on-monitor-mode-on-ubuntu-1004-version/</guid>
      <description>Unable to capture wireless traffic on monitor mode on Ubuntu 10.04 version  0 I have been trying to capture the wireless traffic using old wireless cards (Trendnet, TP-Link) etc. But am unable to capture the traffic other than my own. Can someone please guide as to how to set up the wireshark to capture on monitor mode (including how to set up the wireless card). I have tried implementing suggestion from various bogs and forums and am yet to get the required results.</description>
    </item>
    
    <item>
      <title>How to filter LWAPP-encapsulated wlan traffic with a capture filter</title>
      <link>/questions/26350/how-to-filter-lwapp-encapsulated-wlan-traffic-with-a-capture-filter/</link>
      <pubDate>Thu, 24 Oct 2013 00:50:00 +0000</pubDate>
      
      <guid>/questions/26350/how-to-filter-lwapp-encapsulated-wlan-traffic-with-a-capture-filter/</guid>
      <description>How to filter LWAPP-encapsulated wlan traffic with a capture filter  0 As we known, &#34;wlan&#34; is a display filter for wireless network, then I need a capture filter do the same thing, &#34;wlan&#34; just don&#39;t work with dumpcap. Any reply will be appreciated.
capture-filter wlan lwappasked 24 Oct &#39;13, 00:50
metamatrix
56●16●16●19
accept rate: 100%
 edited 27 Oct &#39;13, 19:08 
Guy Harris ♦♦
17.4k●3●35●196
If you&#39;re capturing on a wireless network (and not getting pseudo-Ethernet frames), all frames would match &#34;</description>
    </item>
    
    <item>
      <title>tshark -H -W n name resolution using hosts file</title>
      <link>/questions/26359/tshark-h-w-n-name-resolution-using-hosts-file/</link>
      <pubDate>Thu, 24 Oct 2013 05:29:00 +0000</pubDate>
      
      <guid>/questions/26359/tshark-h-w-n-name-resolution-using-hosts-file/</guid>
      <description>tshark -H -W n name resolution using hosts file  0 I&#39;m trying to resolve ip addresses using a hosts file and it works well with the wireshark GUI (1.8.7) when the hosts file is in my Personal Configuration folder. Now I came across the tshark -H &amp;lt;hosts file&amp;gt; which seemed quite interesting
 -H &amp;lt;hosts file&amp;gt; read a list of entries from a hosts file, which will then be written to a capture file.</description>
    </item>
    
    <item>
      <title>Navigating Wireshark GUI</title>
      <link>/questions/26360/navigating-wireshark-gui/</link>
      <pubDate>Thu, 24 Oct 2013 05:38:00 +0000</pubDate>
      
      <guid>/questions/26360/navigating-wireshark-gui/</guid>
      <description>Navigating Wireshark GUI  0 I find really a pain when browsing the &#34;Packet List&#34; pane the indication of the current selected packet. It is not really contrasting and it completely disappears when I click on the &#34;Packet detail&#34; pane. This makes virtually impossible going back to the &#34;Packet List&#34; pane over the same packet I was just analyzing in detail.
Is there a way to solve this? what am I doing wrong?</description>
    </item>
    
    <item>
      <title>Loading configuration files</title>
      <link>/questions/26361/loading-configuration-files/</link>
      <pubDate>Thu, 24 Oct 2013 05:46:00 +0000</pubDate>
      
      <guid>/questions/26361/loading-configuration-files/</guid>
      <description>Loading configuration files  2 Hello,
i currently have the problem that Wireshark won&#39;t startup at all. This morning i used wireshark without problems but now it just hangs in the splash screen at 100% saying &#34;Loading configuration files...&#34;.
I can terminate the wireshark task but dumpcap keeps running and i cannot shut it down at all.
Is there anything i can do?
Best regards Ben
splash configuration startup splashscreen wiresharkasked 24 Oct &#39;13, 05:46</description>
    </item>
    
    <item>
      <title>SMTP Info Displaying | | | | | |</title>
      <link>/questions/26367/smtp-info-displaying/</link>
      <pubDate>Thu, 24 Oct 2013 09:01:00 +0000</pubDate>
      
      <guid>/questions/26367/smtp-info-displaying/</guid>
      <description>SMTP Info Displaying | | | | | |  0 I have trace that is displaying something that I have never seen before in Wireshark. The traffic is all SMTP but the reassembled packets that include multiple previous frames show up in the Wireshark info as:
S: | | | | | | | | | | |
Has anyone ever seen this before?
smtp displayasked 24 Oct &#39;13, 09:01</description>
    </item>
    
    <item>
      <title>discrepancy between linux capture and windows capture</title>
      <link>/questions/26370/discrepancy-between-linux-capture-and-windows-capture/</link>
      <pubDate>Thu, 24 Oct 2013 10:33:00 +0000</pubDate>
      
      <guid>/questions/26370/discrepancy-between-linux-capture-and-windows-capture/</guid>
      <description>discrepancy between linux capture and windows capture  0 Wireshark 1.10.2 (64 bit) on Windows 7, Wireshark 1.10 on Ubuntu 13.04 (compiled from source)
I have been troubleshooting a network that contains several Windows Embedded Std 7 POS systems and a back office PC that runs Win 7 Pro. When I first looked at the network I was amazed at the volume of errors (dup ack, retrans, tcp out of order).</description>
    </item>
    
    <item>
      <title>Deleting Display Filters</title>
      <link>/questions/26372/deleting-display-filters/</link>
      <pubDate>Thu, 24 Oct 2013 11:36:00 +0000</pubDate>
      
      <guid>/questions/26372/deleting-display-filters/</guid>
      <description>Deleting Display Filters  0 How do I delete a display filter?
displsyasked 24 Oct &#39;13, 11:36
JJH54
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Steps to delete a display filter from the drop-down list of display filters:
Start Wireshark.Choose Help -&amp;gt; About Wireshark -&amp;gt; Folders -&amp;gt; Personal configuration -&amp;gt; [double-click folder]. This will open the folder containing the recent_common file.Quit Wireshark.Open the recent_common file using your editor of choice.</description>
    </item>
    
    <item>
      <title>Help with a tshark cmd</title>
      <link>/questions/26374/help-with-a-tshark-cmd/</link>
      <pubDate>Thu, 24 Oct 2013 12:37:00 +0000</pubDate>
      
      <guid>/questions/26374/help-with-a-tshark-cmd/</guid>
      <description>Help with a tshark cmd  0 Hey guys, Im not new to tshark but I&#39;m trying to make my life quite a bit easier with command lines and Im having quite a bit of difficulty.
I can convert .pcap&#39;s to .txt&#39;s just fine, but the summary information isn&#39;t enough. What I was hoping to get is [SEQ/ACK Analysis] that are located in the TCP files and the [Domain Name System Query] information in the DNS files.</description>
    </item>
    
    <item>
      <title>Checking the flow duration in Wireshark</title>
      <link>/questions/26387/checking-the-flow-duration-in-wireshark/</link>
      <pubDate>Thu, 24 Oct 2013 20:07:00 +0000</pubDate>
      
      <guid>/questions/26387/checking-the-flow-duration-in-wireshark/</guid>
      <description>Checking the flow duration in Wireshark  0 I have collected 2 traces, 1 for a web page: aftonbladet.se and other for a video from youtube. I had read in an IEEE paper that for the web page the flow duration is shorter as compared to the flow duration for a video. My question is how do I check the flow duration from the 2 traces I have collected in Wireshark?</description>
    </item>
    
    <item>
      <title>Problem with BSSAP&#43; protocol.</title>
      <link>/questions/26397/problem-with-bssap-protocol/</link>
      <pubDate>Fri, 25 Oct 2013 01:20:00 +0000</pubDate>
      
      <guid>/questions/26397/problem-with-bssap-protocol/</guid>
      <description>Problem with BSSAP+ protocol.  0 I capture both GSM and GPRS but wireshark not able to decode the traffic when the protocol is BSSAP+ (GPRS). all the packets marked as &#34;Message Type: Unassigned: treated as an unknown Message type. (0)&#34;. does anyone no about a problem with this protocol on version 1.10.2?
shimiasked 25 Oct &#39;13, 01:20
shim
11●1●1●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>excel _file_looking_the_computer</title>
      <link>/questions/26413/excel-_file_looking_the_computer/</link>
      <pubDate>Fri, 25 Oct 2013 13:06:00 +0000</pubDate>
      
      <guid>/questions/26413/excel-_file_looking_the_computer/</guid>
      <description>excel _file_looking_the_computer  0 https://www.cloudshark.org/captures/2daa822a7a25
I have a user that who states that see is attempting to attach a Excel file to here e-mail outlook The user states that the computer just clocks an sh can’t do anything.
The folder where the attachment is on a folder in a datacenter, and this is a V-filer on the storage device.
I have uploaded a copy of the trace, and I have looked through this track and can’t find anything that would cause this in the trace.</description>
    </item>
    
    <item>
      <title>Mavericks - runs but does not capture on all interfaces</title>
      <link>/questions/26423/mavericks-runs-but-does-not-capture-on-all-interfaces/</link>
      <pubDate>Sat, 26 Oct 2013 10:06:00 +0000</pubDate>
      
      <guid>/questions/26423/mavericks-runs-but-does-not-capture-on-all-interfaces/</guid>
      <description>Mavericks - runs but does not capture on all interfaces  0 Upgraded from Mountain Lion to Mavericks. Reinstalled XQuartz and then reinstalled Wireshark 1.10.2. Wireshark runs correctly, and in the list of available interfaces it lists them all.
However only traffic on the WiFi connection (en0) is being detected and captured. Traffic on the ethernets that are connected to my thunderbolt-to-ethernet adapter (en3) or on my Apple Display (en4) is not being detected.</description>
    </item>
    
    <item>
      <title>Packet annotation / comments - v1.10.2 - Not Working</title>
      <link>/questions/26424/packet-annotation-comments-v1102-not-working/</link>
      <pubDate>Sat, 26 Oct 2013 10:27:00 +0000</pubDate>
      
      <guid>/questions/26424/packet-annotation-comments-v1102-not-working/</guid>
      <description>Packet annotation / comments - v1.10.2 - Not Working  0 I am running Wireshark 1.10.2 on Windows 7 and have found a problem. This happens on two different computers running those versions.
When I place an annotation on any packet - that comment is on every packet. If I edit the comment on one packet, it is edited in all the others.
For example: If I click on packet #3 and add the annotation &#34;</description>
    </item>
    
    <item>
      <title>Trying to understand Nagle</title>
      <link>/questions/26431/trying-to-understand-nagle/</link>
      <pubDate>Sat, 26 Oct 2013 17:14:00 +0000</pubDate>
      
      <guid>/questions/26431/trying-to-understand-nagle/</guid>
      <description>Trying to understand Nagle  0 I&#39;ve been going thru some information about Nagle and Delayed ACKs and looking at some trace files of my own to see the the concepts in play. Here&#39;s a partial of the trace I&#39;ve been looking at. What I don&#39;t understand is how packet 345 is getting put on the wire.
Packet 344 went out because it is full MSS, but why did 345 go out before the ACK was received for 344?</description>
    </item>
    
    <item>
      <title>Standardized link type code for unix sockets/file handles</title>
      <link>/questions/26432/standardized-link-type-code-for-unix-socketsfile-handles/</link>
      <pubDate>Sat, 26 Oct 2013 21:48:00 +0000</pubDate>
      
      <guid>/questions/26432/standardized-link-type-code-for-unix-socketsfile-handles/</guid>
      <description>Standardized link type code for unix sockets/file handles  0 I&#39;m writing a utility which uses SSH as the transport, much like Git uses SSH for pushes. Additionally I wrote a utility which executes a command and then captures the STDIN, STDOUT, and STDERR to the executed command. The capture utility currently writes the dump file so that it appears as a RAW link type and UDP packets.
Is it possible to create a new link type code for raw file handles?</description>
    </item>
    
    <item>
      <title>sound alert?</title>
      <link>/questions/26434/sound-alert/</link>
      <pubDate>Sun, 27 Oct 2013 06:45:00 +0000</pubDate>
      
      <guid>/questions/26434/sound-alert/</guid>
      <description>sound alert?  0 OK, wireshark is working perfectly, but is it possible to configure it to make a sound when a packet goes through pre defined filter?
sound filter alertasked 27 Oct &#39;13, 06:45
myrddin
11●7●8●10
accept rate: 0%
  
3 Answers:
  
1No. Personally I would find this extremely annoying, but if you want this in Wireshark please create an item in the Wireshark Bugzilla and mark it as an enhancement.</description>
    </item>
    
    <item>
      <title>Why is wireshark not identified as a safe developer on OS X</title>
      <link>/questions/26440/why-is-wireshark-not-identified-as-a-safe-developer-on-os-x/</link>
      <pubDate>Sun, 27 Oct 2013 09:34:00 +0000</pubDate>
      
      <guid>/questions/26440/why-is-wireshark-not-identified-as-a-safe-developer-on-os-x/</guid>
      <description>Why is wireshark not identified as a safe developer on OS X  0 When i try to install the last Wireshark 1.10.2 Intel 64.pkg on a fresh copy of Maverick OSX I get:
can’t be opened because it is from an unidentified developer.
I know that this can be by-passed by going to System Preferences -&amp;gt; Security &amp;amp; Privacy -&amp;gt; General -&amp;gt; Allow apps downloaded from: Anywhere
Anyone knows the reason of it?</description>
    </item>
    
    <item>
      <title>Which application is sending UDP packets</title>
      <link>/questions/26459/which-application-is-sending-udp-packets/</link>
      <pubDate>Mon, 28 Oct 2013 02:44:00 +0000</pubDate>
      
      <guid>/questions/26459/which-application-is-sending-udp-packets/</guid>
      <description>Which application is sending UDP packets  0 How to know which application is sending udp data packet using wire shark?please help. i want to track which application is sending or receiving udp data packets in my pc, i tried filtering udp packets, but i am not able to track the root application .please give me a solution for this.
udp pidThis question is marked &#34;community wiki&#34;.asked 28 Oct &#39;13, 02:44</description>
    </item>
    
    <item>
      <title>DNS query to non local and non routable IP</title>
      <link>/questions/26466/dns-query-to-non-local-and-non-routable-ip/</link>
      <pubDate>Mon, 28 Oct 2013 07:54:00 +0000</pubDate>
      
      <guid>/questions/26466/dns-query-to-non-local-and-non-routable-ip/</guid>
      <description>DNS query to non local and non routable IP  0 I noticed by accident my computer is sending DNS queries to 192.168.1.1 despite it&#39;s on a class A internal network (10.0.0.0).
The queries goes to the firewalls mac-adress, the firewalls IP i 10.0.0.1.
I don&#39;t have 192.168.1.1 registered as a dns server in my network settings.
I guess the query goes to the firewall because it&#39;s the default gateway and there&#39;s no static route to a 192.</description>
    </item>
    
    <item>
      <title>Strange results from Statistics</title>
      <link>/questions/26469/strange-results-from-statistics/</link>
      <pubDate>Mon, 28 Oct 2013 08:32:00 +0000</pubDate>
      
      <guid>/questions/26469/strange-results-from-statistics/</guid>
      <description>Strange results from Statistics  0 Hi,
I need to have a graph for bandwith usage while the client uses a webapp. I captured all packets from the client to the proxy (on the proxy).
But the graph in IO Graph show much more traffic for the one client as the router, between all clients and the proxy, for the whole net.
Then I tried to get the usage per second from tshark</description>
    </item>
    
    <item>
      <title>Wireshark changing my viewing webpage?</title>
      <link>/questions/26482/wireshark-changing-my-viewing-webpage/</link>
      <pubDate>Mon, 28 Oct 2013 09:27:00 +0000</pubDate>
      
      <guid>/questions/26482/wireshark-changing-my-viewing-webpage/</guid>
      <description>Wireshark changing my viewing webpage?  0 When I access a specified site, http://zj.189.cn, well a Chinese-based site, I found the company name in all the pages is changed to its competitor. I first thought the site was hacked. But then I found it&#39;s correct on my mobile phone. So it&#39;s my computer&#39;s problem. Sorry, the first software is wireshark. Now it come back normal. I don&#39;t know why, but it&#39;s changing the webpages.</description>
    </item>
    
    <item>
      <title>Bandwidth usage</title>
      <link>/questions/26483/bandwidth-usage/</link>
      <pubDate>Mon, 28 Oct 2013 09:29:00 +0000</pubDate>
      
      <guid>/questions/26483/bandwidth-usage/</guid>
      <description>Bandwidth usage  0 I ran Wireshark overnight so I could see the traffic. Is there a way I can break this information down by time (time of Day) and bandwidth?
thanks
bandwidth real-timeasked 28 Oct &#39;13, 09:29
rweston
1●1●1●1
accept rate: 0%
  
One Answer:
  
0You could try:
Statistics -&amp;gt; IO Graph -&amp;gt; X Axis:View as time of day:TRUE, Y Axis:Unit:Bytes/Tick (or Bits/Tick)answered 28 Oct &#39;13, 09:50</description>
    </item>
    
    <item>
      <title>Building customized filters</title>
      <link>/questions/26488/building-customized-filters/</link>
      <pubDate>Mon, 28 Oct 2013 14:11:00 +0000</pubDate>
      
      <guid>/questions/26488/building-customized-filters/</guid>
      <description>Building customized filters  0 Hi, How can I create/customize display-filters depending on coming packets in away that is (automatically) applied every time I start capturing filters. Lets say I want to filter all packets that are coming to the network from IP: 216.27.61.137 Thank you in advance,
osx api display-filterasked 28 Oct &#39;13, 14:11
OhudSaud
11●1●1●2
accept rate: 0%
Could you elaborate a bit, especially with your example, because I don&#39;t understand what it is you&#39;re asking for exactly.</description>
    </item>
    
    <item>
      <title>Capture packets from HP H3C switch</title>
      <link>/questions/26489/capture-packets-from-hp-h3c-switch/</link>
      <pubDate>Mon, 28 Oct 2013 14:12:00 +0000</pubDate>
      
      <guid>/questions/26489/capture-packets-from-hp-h3c-switch/</guid>
      <description>Capture packets from HP H3C switch  0 Hello, I want to configure a source port on a HP H3C switch and a destination port on a Cisco C60 endpoint to be able to capture packets with WireShark. Any ideas?
packetsasked 28 Oct &#39;13, 14:12
willJ
1●1●1●1
accept rate: 0%
  
One Answer:
  
0You need to configure port mirroring on your H3C switch
http://www.h3c.com/portal/Products___Solutions/Technology/LAN/Configuration_Example/200805/605777_57_0.htm
Basically, you need to mirror the port of your C60 to the port of your Wireshark PC.</description>
    </item>
    
    <item>
      <title>virtual hosts and smb2 transfers</title>
      <link>/questions/26496/virtual-hosts-and-smb2-transfers/</link>
      <pubDate>Mon, 28 Oct 2013 19:09:00 +0000</pubDate>
      
      <guid>/questions/26496/virtual-hosts-and-smb2-transfers/</guid>
      <description>virtual hosts and smb2 transfers  0 I&#39;m trying to understand the captures I&#39;ve done. I&#39;m getting an enormous number of &#34;previous packet&#34; and &#34;ack&#39;d lost packet&#34;. I&#39;ve done my captures on two windows 2012 virtual hosts simultaneously with Wireshark installed on the VMs and the expert infos results are radically different. These hosts have 10G interfaces. Wireshark doesn&#39;t show any dropped packets in the gui while capturing and the file comes over without a problem.</description>
    </item>
    
    <item>
      <title>Capture Android WLAN traffic</title>
      <link>/questions/26512/capture-android-wlan-traffic/</link>
      <pubDate>Tue, 29 Oct 2013 07:41:00 +0000</pubDate>
      
      <guid>/questions/26512/capture-android-wlan-traffic/</guid>
      <description>Capture Android WLAN traffic  0 Hello! I need to capture WLAN traffic on an Android tablet. I&#39;m running Wireshark on a Windows 7 laptop. Can I capture this traffic using an AirPcap adapter, or is there a better solution?
androidasked 29 Oct &#39;13, 07:41
bluskies58
11●1●1●2
accept rate: 0%
  
2 Answers:
  
0You can indeed capture this traffic when using an AirPcap adapter. You can also boot your laptop into a linux live distribution (like Kali linux) to capture wlan traffic in monitor mode.</description>
    </item>
    
    <item>
      <title>Wireshark setup Linux for nonroot user in Amazon Ec2</title>
      <link>/questions/26515/wireshark-setup-linux-for-nonroot-user-in-amazon-ec2/</link>
      <pubDate>Tue, 29 Oct 2013 08:52:00 +0000</pubDate>
      
      <guid>/questions/26515/wireshark-setup-linux-for-nonroot-user-in-amazon-ec2/</guid>
      <description>Wireshark setup Linux for nonroot user in Amazon Ec2  0 My goal is to capture packets with tshark in Amazon Linux AMI. While typing tshark in the command line there&#39;s an error: &#34;tshark: There are no interfaces on which a capture can be done&#34;
How to implement the solution :
&amp;gt; $ sudo apt-get install wireshark $ &amp;gt; sudo dpkg-reconfigure wireshark-common &amp;gt; $ sudo usermod -a -G wireshark $USER $ &amp;gt; gnome-session-quit --logout --no-promptin Amazon Linux AMI (it&#39;s not Ubuntu)?</description>
    </item>
    
    <item>
      <title>Rewrite the inner IP addresses of a GTP packet</title>
      <link>/questions/26516/rewrite-the-inner-ip-addresses-of-a-gtp-packet/</link>
      <pubDate>Tue, 29 Oct 2013 09:08:00 +0000</pubDate>
      
      <guid>/questions/26516/rewrite-the-inner-ip-addresses-of-a-gtp-packet/</guid>
      <description>Rewrite the inner IP addresses of a GTP packet  0 I have a capture (pcap) file with GTP-C and GTP-U traffic. I need to edit the inner source and destination IP address of the GTP packet. These would be the IP addresses related the actual subscriber&#39;s traffic flow. I was trying to achieve this using tcpprep and tcprewrite, but I am only able rewrite the outer (GGSN and SGSN) IP addresses.</description>
    </item>
    
    <item>
      <title>Winpcap seems to crash on Win8.1</title>
      <link>/questions/26517/winpcap-seems-to-crash-on-win81/</link>
      <pubDate>Tue, 29 Oct 2013 09:14:00 +0000</pubDate>
      
      <guid>/questions/26517/winpcap-seems-to-crash-on-win81/</guid>
      <description>Winpcap seems to crash on Win8.1  0 Hi all,
I recently upgraded my HP Envy laptop (1 month old version) to Win8.1. Following that upgrade launching Wireshark would hang and not be able to close properly. A background file call dump was running and I actually had to reboot the system in order to close it.
It seems the winpcap was causing problems so I deinstalled it and then reinstalled Wireshark.</description>
    </item>
    
    <item>
      <title>Does tshark -w output file have valid libpcap header?</title>
      <link>/questions/26518/does-tshark-w-output-file-have-valid-libpcap-header/</link>
      <pubDate>Tue, 29 Oct 2013 09:33:00 +0000</pubDate>
      
      <guid>/questions/26518/does-tshark-w-output-file-have-valid-libpcap-header/</guid>
      <description>Does tshark -w output file have valid libpcap header?  0 Having written a file using tshark -w option, I find when I read the file the libpcap header has key values set to null:  magic 0 version_major 0 version_minor 0 thiszone 0
I was expecting values as given in this spec.
tshark libpcapasked 29 Oct &#39;13, 09:33
wiggers
31●5●5●11
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark named pipes disconnect</title>
      <link>/questions/26523/wireshark-named-pipes-disconnect/</link>
      <pubDate>Tue, 29 Oct 2013 10:49:00 +0000</pubDate>
      
      <guid>/questions/26523/wireshark-named-pipes-disconnect/</guid>
      <description>Wireshark named pipes disconnect  0 I have managed to make a program that feeds packets to Wireshark through a named pipe. It can detect that Wireshark has stopped/restarted the capture, because writing fails. It can then reopen the pipe, so Wireshark can receive packets when it starts capturing again.
What I want is the same, but for when my application restarts. My question is:
What does Wireshark do when a named pipe is closed from the server side.</description>
    </item>
    
    <item>
      <title>Mavericks - can not capture from iPhone using RVI</title>
      <link>/questions/26524/mavericks-can-not-capture-from-iphone-using-rvi/</link>
      <pubDate>Tue, 29 Oct 2013 11:13:00 +0000</pubDate>
      
      <guid>/questions/26524/mavericks-can-not-capture-from-iphone-using-rvi/</guid>
      <description>Mavericks - can not capture from iPhone using RVI  2 1After updating my macbook to Mavericks, Wireshark can still capture data from my iPhone using RVI(remote virtual interface). But it cannot analyze and show packets right. it only tells about packets that they are &#34;User encapsulation not handled: DLT=149, check your Preferences-&amp;gt;Protocols-&amp;gt;DLT_USER&#34;.
This problem only occurs when capturing lively. If I capture and save using tcpdump, Wireshark analyzes them right.</description>
    </item>
    
    <item>
      <title>How to monitor traffic in load balance webservers?</title>
      <link>/questions/26532/how-to-monitor-traffic-in-load-balance-webservers/</link>
      <pubDate>Wed, 30 Oct 2013 04:06:00 +0000</pubDate>
      
      <guid>/questions/26532/how-to-monitor-traffic-in-load-balance-webservers/</guid>
      <description>How to monitor traffic in load balance webservers?  0 We have 8 webservers that manage in load balancing mode. I install wireshark on one webserver to monitor traffic in my network..I wonder if wireshark can monitor also the traffic to other webservers and how to analyze traffic in webserver.
webserverThis question is marked &#34;community wiki&#34;.asked 30 Oct &#39;13, 04:06
rayden
11●2●2●3
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Telnet messages are being dropped</title>
      <link>/questions/26533/telnet-messages-are-being-dropped/</link>
      <pubDate>Wed, 30 Oct 2013 04:30:00 +0000</pubDate>
      
      <guid>/questions/26533/telnet-messages-are-being-dropped/</guid>
      <description>Telnet messages are being dropped  0 Hello. I am using a Python3.3 script that uses a telnet connection from telnetlib library.
Now, I am using the write(command) and read() functions of this connection.
So, after wiresharking this simple code:
import telnetlib import sys def func1(IP,user,passw): t=telnetlib.Telnet(IP) t.write(user.encode(&amp;#39;ascii&amp;#39;)+b&amp;#39;\n&amp;#39;) t.write(passw.encode(&amp;#39;ascii&amp;#39;)+b&amp;#39;\n&amp;#39;) return t def func2(t,command): t.write(command.encode(&#39;ascii&#39;)+b&#39;\n&#39;) print(command)
user=sys.argv[1] passw=sys.argv[2] IP=sys.argv[3] t=func1(IP,user,passw) for i in range(6): func2(t, &amp;quot;message &amp;quot;+str(i))I saw a weird behavior on Wireshark.</description>
    </item>
    
    <item>
      <title>How to determine server with very high bandwidth consumption in VLAN network.</title>
      <link>/questions/26534/how-to-determine-server-with-very-high-bandwidth-consumption-in-vlan-network/</link>
      <pubDate>Wed, 30 Oct 2013 04:51:00 +0000</pubDate>
      
      <guid>/questions/26534/how-to-determine-server-with-very-high-bandwidth-consumption-in-vlan-network/</guid>
      <description>How to determine server with very high bandwidth consumption in VLAN network.  0 Wireshark is very helpful in terms of troubleshooting network. I have encountered one time an intermittent connection over my network. I begin troubleshooting from top to toe but I can not find the source of problem. We&#39;re using fortigate firewall and I trace the source of problem by looking to fortigate monitoring where you can view server with more bandwidth used.</description>
    </item>
    
    <item>
      <title>Where can I find a list of file formats by extension?</title>
      <link>/questions/26539/where-can-i-find-a-list-of-file-formats-by-extension/</link>
      <pubDate>Wed, 30 Oct 2013 07:33:00 +0000</pubDate>
      
      <guid>/questions/26539/where-can-i-find-a-list-of-file-formats-by-extension/</guid>
      <description>Where can I find a list of file formats by extension?  0 I&#39;ve come across various lists of file formats that Wireshark can open, but is there a list of the associated file extensions anywhere? (E.g. .cap, .pcap, .pcapng, .dmp, etc.)
file-format wiresharkasked 30 Oct &#39;13, 07:33
wiggers
31●5●5●11
accept rate: 0%
  
4 Answers:
  
1Wireshark does not use file extensions to determine the type of a capture file.</description>
    </item>
    
    <item>
      <title>how can I filter activity that is just between a PC and server, or between two servers?</title>
      <link>/questions/26550/how-can-i-filter-activity-that-is-just-between-a-pc-and-server-or-between-two-servers/</link>
      <pubDate>Wed, 30 Oct 2013 13:14:00 +0000</pubDate>
      
      <guid>/questions/26550/how-can-i-filter-activity-that-is-just-between-a-pc-and-server-or-between-two-servers/</guid>
      <description>how can I filter activity that is just between a PC and server, or between two servers?  0 I&#39;m brand new to WireShark. I simply want to evaluate the network activity between one user&#39;s PC, and the application and data servers their session is communicating with. I have, or can get, the IP addresses for all.
capture-filter-wlanasked 30 Oct &#39;13, 13:14
Zorro
11●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>OSPF Hello &amp;amp; Dead Intervals</title>
      <link>/questions/26553/ospf-hello-dead-intervals/</link>
      <pubDate>Wed, 30 Oct 2013 14:43:00 +0000</pubDate>
      
      <guid>/questions/26553/ospf-hello-dead-intervals/</guid>
      <description>OSPF Hello &amp;amp; Dead Intervals  0 Hello
I have a pcap file and am parsing it using tshark and wish dump the OSPF hello and dead intervals but there are no display filter names for these two attribtues (or many other OSPF attribtues). Dumping the hex value would be fine but I can&#39;t seem to find a filter that will give me these results. I was fiddling around with &#34;</description>
    </item>
    
    <item>
      <title>&amp;quot;Smaller tshark&amp;quot; for specific protocol</title>
      <link>/questions/26563/smaller-tshark-for-specific-protocol/</link>
      <pubDate>Thu, 31 Oct 2013 01:02:00 +0000</pubDate>
      
      <guid>/questions/26563/smaller-tshark-for-specific-protocol/</guid>
      <description>&amp;ldquo;Smaller tshark&amp;rdquo; for specific protocol  0 Hi all, as we know, wireshark is a big open source project with contributions from many developers. It is able to decode many, many protocols and this number is increasing day by day. But actually in some specific tasks, we just need to use to decode very few protocol, for example in my case, i use CAMEL only. I&#39;m using a big wireshark to build, to run for a very small objective.</description>
    </item>
    
    <item>
      <title>Is there an equivalent to tshark -z follow... for use with -w?</title>
      <link>/questions/26587/is-there-an-equivalent-to-tshark-z-follow-for-use-with-w/</link>
      <pubDate>Thu, 31 Oct 2013 06:13:00 +0000</pubDate>
      
      <guid>/questions/26587/is-there-an-equivalent-to-tshark-z-follow-for-use-with-w/</guid>
      <description>Is there an equivalent to tshark -z follow&amp;hellip; for use with -w?  0 I would like to output the raw packets for just one thread. E.g. something like:
tshark -r in.cap -z&#34;follow,tcp,hex,1.2.3.4:2000,1.2.3.9:2001&#34; -F pcap -w out.cap
The -z follow... switch does the job in principle but only seems to do text output. Adding -w gives no output. Is there an equivalent filter for -R or -Y?
follow tsharkasked 31 Oct &#39;13, 06:13</description>
    </item>
    
    <item>
      <title>RTP out of seq/wrong timestamp</title>
      <link>/questions/26596/rtp-out-of-seqwrong-timestamp/</link>
      <pubDate>Thu, 31 Oct 2013 11:10:00 +0000</pubDate>
      
      <guid>/questions/26596/rtp-out-of-seqwrong-timestamp/</guid>
      <description>RTP out of seq/wrong timestamp  0 I have a co-worker setting up a paging system via SIP/RTP and they are seeing/hearing issues with a delay between the page beep and when the voice is heard. They wiresharked it and saw a small amount of wrong timestamp errors on their RTP stream analysis. e.g. 2 packets (1.9%)out of a 5 second call. They are concerned about this and think the network is at fault.</description>
    </item>
    
    <item>
      <title>Why do I see TCP packets on the network?</title>
      <link>/questions/26597/why-do-i-see-tcp-packets-on-the-network/</link>
      <pubDate>Thu, 31 Oct 2013 11:20:00 +0000</pubDate>
      
      <guid>/questions/26597/why-do-i-see-tcp-packets-on-the-network/</guid>
      <description>Why do I see TCP packets on the network?  0 This is a question more related to the fundamentals of networking rather than wireshark itself. I&#39;ve been trying to learn networking from some videos on the internet and if I understand correctly each layer of the network model is encapsulated by the layer below it. Why do I see TCP and UDP packets on the network then? Shouldn&#39;t they be encapsulated by IP packets?</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t decode SIP calls</title>
      <link>/questions/26602/cant-decode-sip-calls/</link>
      <pubDate>Thu, 31 Oct 2013 13:47:00 +0000</pubDate>
      
      <guid>/questions/26602/cant-decode-sip-calls/</guid>
      <description>Can&amp;rsquo;t decode SIP calls  0 I have captured several voip calls, but I can&#39;t decode them using the telephony option to listen to them. Is there another way to listen to SIP calls? Thanks.
decode sipasked 31 Oct &#39;13, 13:47
HunterM4
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Wireshark only plays rtp streams using the G711 codec. Other codecs are proprietary and would need payment for inclusion in Wireshark.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t capture packets on Wi-Fi</title>
      <link>/questions/26603/cant-capture-packets-on-wi-fi/</link>
      <pubDate>Thu, 31 Oct 2013 13:51:00 +0000</pubDate>
      
      <guid>/questions/26603/cant-capture-packets-on-wi-fi/</guid>
      <description>Can&amp;rsquo;t capture packets on Wi-Fi  0 Hi, I have a problem capturing packets on my wi-fi device.
I have 2 computers - the first one is an access point and it sends a signal to the second computer. The signal is protected with wpa-psk password. Wireshark is installed on the first computer on which I want to see packets from the second computer. But I don&#39;t see them and I don&#39;t know why.</description>
    </item>
    
    <item>
      <title>WAN Capture Hardware for WireShark (DSL Modem to Router via Cat5)</title>
      <link>/questions/26606/wan-capture-hardware-for-wireshark-dsl-modem-to-router-via-cat5/</link>
      <pubDate>Thu, 31 Oct 2013 18:54:00 +0000</pubDate>
      
      <guid>/questions/26606/wan-capture-hardware-for-wireshark-dsl-modem-to-router-via-cat5/</guid>
      <description>WAN Capture Hardware for WireShark (DSL Modem to Router via Cat5)  0 Hello,
I am looking at the feasibilty of using Wireshark to passively monitor my WAN traffic. I am particularly interested in seeing if I have traffic going to US states (or even foreign destinations) where we have no reason to be comunicating with. I have not used Wireshark before, but a quick study shows it will easily give me the endpoint addresses I seek.</description>
    </item>
    
    <item>
      <title>Coverting G722 payload to wav</title>
      <link>/questions/26607/coverting-g722-payload-to-wav/</link>
      <pubDate>Thu, 31 Oct 2013 20:54:00 +0000</pubDate>
      
      <guid>/questions/26607/coverting-g722-payload-to-wav/</guid>
      <description>Coverting G722 payload to wav  0 Is there a tools to convert G722 rtp to .wav file??
loslasked 31 Oct &#39;13, 20:54
skorpios78
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Is there a tools to convert G722 rtp to .wav file??
well, actually not a Wireshark question....
However, as we have had similar questions, here is what you can do
extract the RTP payload: http://ask.</description>
    </item>
    
    <item>
      <title>How to use lua to parse multi frames for one package?</title>
      <link>/questions/26608/how-to-use-lua-to-parse-multi-frames-for-one-package/</link>
      <pubDate>Fri, 01 Nov 2013 02:48:00 +0000</pubDate>
      
      <guid>/questions/26608/how-to-use-lua-to-parse-multi-frames-for-one-package/</guid>
      <description>How to use lua to parse multi frames for one package?  0 I want to write a lua plugin to parse my private protocol. In my protocol, a package size often bigger then MTU, so I need parse many TCP frames for one package.
luaasked 01 Nov &#39;13, 02:48
zhang
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Please read the first few comments in the Wiki</description>
    </item>
    
    <item>
      <title>Port Mirroring on IP Phone</title>
      <link>/questions/26619/port-mirroring-on-ip-phone/</link>
      <pubDate>Fri, 01 Nov 2013 07:39:00 +0000</pubDate>
      
      <guid>/questions/26619/port-mirroring-on-ip-phone/</guid>
      <description>Port Mirroring on IP Phone  0 I have IP Phone set of Huawei made. One of the Ethernet port is connected to Modem for connectivity with service provider. It has another LAN port with label PC. If I want to capture the packets of SIP between my IP Phone and Modem can I mirror the Ethernet Port to PC port and capture the SIP Packets. My IP Phone is not able to register on network and I have to analyse its call setup trace.</description>
    </item>
    
    <item>
      <title>How to add delta time I/O graph in wireshark source code ?</title>
      <link>/questions/26620/how-to-add-delta-time-io-graph-in-wireshark-source-code/</link>
      <pubDate>Fri, 01 Nov 2013 07:55:00 +0000</pubDate>
      
      <guid>/questions/26620/how-to-add-delta-time-io-graph-in-wireshark-source-code/</guid>
      <description>How to add delta time I/O graph in wireshark source code ?  0 Hi all. How to add delta time I/O graph in wireshark source code ? and How to add delta time dissector in wireshark source code? please give information.
04176asked 01 Nov &#39;13, 07:55
Emily
1●1●1●1
accept rate: 0%
  
One Answer:
  
0There is already delta time in many places in wireshark. What kind of delta time do you want to need?</description>
    </item>
    
    <item>
      <title>How to view (read) Viber messages over WLAN</title>
      <link>/questions/26621/how-to-view-read-viber-messages-over-wlan/</link>
      <pubDate>Fri, 01 Nov 2013 08:42:00 +0000</pubDate>
      
      <guid>/questions/26621/how-to-view-read-viber-messages-over-wlan/</guid>
      <description>How to view (read) Viber messages over WLAN  0 How can I view/read messages sent over a mobile phone with Viber in a local WLAN?
capture viber wlan viewasked 01 Nov &#39;13, 08:42
UnluckyCakes
11●1●1●2
accept rate: 0%
  
One Answer:
  
0See my answer to a similar question.
http://ask.wireshark.org/questions/17291/help-recording-voip-calls
Regards
Kurt
answered 02 Nov &#39;13, 16:50
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15%</description>
    </item>
    
    <item>
      <title>Could someone explain me differences in HTTP protocol&amp;#x27;s info?</title>
      <link>/questions/26622/could-someone-explain-me-differences-in-http-protocols-info/</link>
      <pubDate>Fri, 01 Nov 2013 12:42:00 +0000</pubDate>
      
      <guid>/questions/26622/could-someone-explain-me-differences-in-http-protocols-info/</guid>
      <description>Could someone explain me differences in HTTP protocol&amp;rsquo;s info?  0 Excuse me, if this question will be totally &#34;noob&#34; , but I am actually a newbie in capturing packets with Wireshark. But back to my question. I&#39;m currently capturing packets ingoing and outgoing from my iPad. I filtered them to show only HTTP protocols. And now I get hundreds of different protocols with info. And the info tab near this protocols says it&#39;s &#39;POST&#39;, &#39;NOTIFY&#39; or &#39;GET&#39; .</description>
    </item>
    
    <item>
      <title>How to see exact communication in wireshark?</title>
      <link>/questions/26627/how-to-see-exact-communication-in-wireshark/</link>
      <pubDate>Sat, 02 Nov 2013 21:45:00 +0000</pubDate>
      
      <guid>/questions/26627/how-to-see-exact-communication-in-wireshark/</guid>
      <description>How to see exact communication in wireshark?  0 We have installed a proxy inbetween host and internet. when i make a request google.com and if i see the communication in wireshark, i can just see the communication to proxy and reply from proxy, since proxy makes the actual request and reply to host.
in this case, how do we see the actual communication even if proxy is in intermediate,</description>
    </item>
    
    <item>
      <title>Can I use this to detect if I have spyware on my PC?</title>
      <link>/questions/26628/can-i-use-this-to-detect-if-i-have-spyware-on-my-pc/</link>
      <pubDate>Sun, 03 Nov 2013 02:06:00 +0000</pubDate>
      
      <guid>/questions/26628/can-i-use-this-to-detect-if-i-have-spyware-on-my-pc/</guid>
      <description>Can I use this to detect if I have spyware on my PC?  0 And if so, can I see exactly what data is being transmitted and to what IP? Also, can I get additional info on the IP, like country and service provider, and have the option to block any further communication?
securityasked 03 Nov &#39;13, 02:06
leebonolo
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>capture packets on one channel</title>
      <link>/questions/26638/capture-packets-on-one-channel/</link>
      <pubDate>Sun, 03 Nov 2013 05:31:00 +0000</pubDate>
      
      <guid>/questions/26638/capture-packets-on-one-channel/</guid>
      <description>capture packets on one channel  0 Hi, how can I configure Wireshark to capture packets on only one channel? I can&#39;t seem to find that option.
capture packets channel oneasked 03 Nov &#39;13, 05:31
myrddin
11●7●8●10
accept rate: 0%
 edited 03 Nov &#39;13, 08:57 
What do you mean by &#34;channel&#34;? Network card? Transmit/Receive?
(03 Nov &#39;13, 12:15) Jasper ♦♦Wi-Fi channel?
(03 Nov &#39;13, 14:26) Guy Harris ♦♦Yes, I wanted to use only one Wi-Fi channel because there are some open networks that interfere with my own, so I wanted to avoid them, but then I found out how to filter out what I need, so i don&#39;t need it any more</description>
    </item>
    
    <item>
      <title>Decode As (DHCP)</title>
      <link>/questions/26639/decode-as-dhcp/</link>
      <pubDate>Sun, 03 Nov 2013 06:50:00 +0000</pubDate>
      
      <guid>/questions/26639/decode-as-dhcp/</guid>
      <description>Decode As (DHCP)  0 I tried to decode UDP packets on port 4011 as DHCP. But the Decode As dialog box shows DHCPv6 twice without DHCP option. I&#39;m wondering if this is a bug?
dhcpasked 03 Nov &#39;13, 06:50
orion
6●1●1●3
accept rate: 0%
  
One Answer:
  
3 It&#39;s not a bug. DHCPv4 decoding is done by the BootP disector, so the filter and decoder name is &#34;</description>
    </item>
    
    <item>
      <title>Realtek PCIe GBE vlan stripping</title>
      <link>/questions/26641/realtek-pcie-gbe-vlan-stripping/</link>
      <pubDate>Sun, 03 Nov 2013 11:47:00 +0000</pubDate>
      
      <guid>/questions/26641/realtek-pcie-gbe-vlan-stripping/</guid>
      <description>Realtek PCIe GBE vlan stripping  0 I am trying to turn off vlan stripping on my Realtek PCIe GBE Family Controller, although not for Wireshark. I am working on INE labs and using the cloud connector to bridge from my GNS3 routers to my physical switches. I followed prior instructions and set the &#34;Priority &amp;amp; VLAN disabled&#34; option on the NIC driver. Was monitoring the registry key for the device and noticed the registry DWORD &#34;</description>
    </item>
    
    <item>
      <title>Excessive duplicate acknowledgements - what does it mean?</title>
      <link>/questions/26651/excessive-duplicate-acknowledgements-what-does-it-mean/</link>
      <pubDate>Mon, 04 Nov 2013 00:39:00 +0000</pubDate>
      
      <guid>/questions/26651/excessive-duplicate-acknowledgements-what-does-it-mean/</guid>
      <description>Excessive duplicate acknowledgements - what does it mean?  0 I have a situation where when I transfer the same file bewteen two offices it takes three times longer in one direction when compared to the other direction. So in the slow direction Office A to Office B in my traces I can see an excessive number of duplicate acknowlegements occuring at different times of the tarnsfer. I&#39;m guessing this is causing my transfers to run slower in that direction.</description>
    </item>
    
    <item>
      <title>ESMC message read for ST3E clock quality</title>
      <link>/questions/26664/esmc-message-read-for-st3e-clock-quality/</link>
      <pubDate>Mon, 04 Nov 2013 10:06:00 +0000</pubDate>
      
      <guid>/questions/26664/esmc-message-read-for-st3e-clock-quality/</guid>
      <description>ESMC message read for ST3E clock quality  0 When I use Wireshark to decode an ESMC packet (Ethernet Sync Messaging Channel), it sees the quality level of stratum 3E as an invalid SSM message (1101 = SSM Code: QL-INV13) instead of QL-ST3E (1101 = SSM Code: QL-ST3E)
esmcasked 04 Nov &#39;13, 10:06
Marc Lefebvre
1●1●1●1
accept rate: 0%
2If you think it&#39;s a bug you should file it at http://bugs.</description>
    </item>
    
    <item>
      <title>Have packet capture, somethings wrong</title>
      <link>/questions/26667/have-packet-capture-somethings-wrong/</link>
      <pubDate>Mon, 04 Nov 2013 15:09:00 +0000</pubDate>
      
      <guid>/questions/26667/have-packet-capture-somethings-wrong/</guid>
      <description>Have packet capture, somethings wrong  0 Hey all, I have a packet (dont know where I can attach it, but I have a link below) that has a t1 connection to the internet that is &#34;not working&#34;
If anyone can help me as to why on line 94, destination host unreachable is displaying, that would be awesome. Thank you.
Here is the packet link:
https://www.dropbox.com/s/5eqli7z84taa9au/jp-capture-tdc376.pcap
problem t1asked 04 Nov &#39;13, 15:09</description>
    </item>
    
    <item>
      <title>Capturing Packets on Mobile</title>
      <link>/questions/26672/capturing-packets-on-mobile/</link>
      <pubDate>Mon, 04 Nov 2013 23:39:00 +0000</pubDate>
      
      <guid>/questions/26672/capturing-packets-on-mobile/</guid>
      <description>Capturing Packets on Mobile  0 I would like to capture packets of the internet traffic of my mobile. I would like to ask that if I install wire shark on my desktop machine, and then make my desktop a wifi hot spot, connect my mobile phone with this desktop powered wifi then Would I be able to capture/analyse packets of my internet traffic of mobile on wire shark at desktop?</description>
    </item>
    
    <item>
      <title>Problem with Absolute Time</title>
      <link>/questions/26673/problem-with-absolute-time/</link>
      <pubDate>Tue, 05 Nov 2013 00:44:00 +0000</pubDate>
      
      <guid>/questions/26673/problem-with-absolute-time/</guid>
      <description>Problem with Absolute Time  0 Hello everybody! I have a &#34;little&#34; problem with Wireshark timestamps. I have one column with &#34;Time&#34;, which starts at 0.0, but I want to get the absolute time (=system time) like &#34;2013-11-05 09:39:02&#34;. I have selected &#34;Absolute date and time&#34; option for a new column and I get something like &#34;1970-01-01 1:00:10&#34; -&amp;gt; Epoch time :( How can I change this date-time?
Thank you in advance!</description>
    </item>
    
    <item>
      <title>In  wnpa-sec-2013-64 · ActiveMQ OpenWire dissector large loop :platform :x86 windows 7.</title>
      <link>/questions/26674/in-wnpa-sec-2013-64-activemq-openwire-dissector-large-loop-platform-x86-windows-7/</link>
      <pubDate>Tue, 05 Nov 2013 00:55:00 +0000</pubDate>
      
      <guid>/questions/26674/in-wnpa-sec-2013-64-activemq-openwire-dissector-large-loop-platform-x86-windows-7/</guid>
      <description>In wnpa-sec-2013-64 · ActiveMQ OpenWire dissector large loop :platform :x86 windows 7.  0 In wnpa-sec-2013-64 · ActiveMQ OpenWire dissector large loop :platform :x86 windows 7.
So ,i would like to get information about is x86 related to 32-bit OS or 32 bit and 64 bit OS. -&amp;gt;does x86 relate to architecthure?
wnpa-sec-2013-64asked 05 Nov &#39;13, 00:55
ganesh
1●1●1●2
accept rate: 0%
 edited 05 Nov &#39;13, 00:56</description>
    </item>
    
    <item>
      <title>I have installed wireshark on Ubuntu, i need to store all the packets that wireshark detects into a database. is that possible? and how?</title>
      <link>/questions/26676/i-have-installed-wireshark-on-ubuntu-i-need-to-store-all-the-packets-that-wireshark-detects-into-a-database-is-that-possible-and-how/</link>
      <pubDate>Tue, 05 Nov 2013 05:06:00 +0000</pubDate>
      
      <guid>/questions/26676/i-have-installed-wireshark-on-ubuntu-i-need-to-store-all-the-packets-that-wireshark-detects-into-a-database-is-that-possible-and-how/</guid>
      <description>I have installed wireshark on Ubuntu, i need to store all the packets that wireshark detects into a database. is that possible? and how?  0 I have installed wireshar on Ubuntu, i need to store all the packets that wireshark detects into a database. is that possible? and how?
databaseasked 05 Nov &#39;13, 05:06
Nolan Antấo
1●1●1●1
accept rate: 0%
 edited 05 Nov &#39;13, 05:19 
grahamb ♦</description>
    </item>
    
    <item>
      <title>How to find fps / fpm using wireshark?</title>
      <link>/questions/26680/how-to-find-fps-fpm-using-wireshark/</link>
      <pubDate>Tue, 05 Nov 2013 08:07:00 +0000</pubDate>
      
      <guid>/questions/26680/how-to-find-fps-fpm-using-wireshark/</guid>
      <description>How to find fps / fpm using wireshark?  0 In my enviroment we have cisco nexsus 7k which is configured to send flow records (netflows v9) to flow collector / analyzer. Due to how cisco iso is written, there is not a command (at least in my knowledge) which lets me pull flow record based upon interval (seconds etc).
This is important to me as I want to do licensing for the flow exporter/collector.</description>
    </item>
    
    <item>
      <title>IP address issues</title>
      <link>/questions/26681/ip-address-issues/</link>
      <pubDate>Tue, 05 Nov 2013 10:16:00 +0000</pubDate>
      
      <guid>/questions/26681/ip-address-issues/</guid>
      <description>IP address issues  0 Hello,
Can you tell me if Wireshark will allow me to plug into a CAT5 line and show me the details on how that data connection goes to IP addresses?
I having an issue with changing over a machine that needs to point to another server and it takes fore ever to go to the new one.
Does Wireshark show DNS issues, hops, routes etc.</description>
    </item>
    
    <item>
      <title>3GPP timezone decoding logic</title>
      <link>/questions/26682/3gpp-timezone-decoding-logic/</link>
      <pubDate>Tue, 05 Nov 2013 11:22:00 +0000</pubDate>
      
      <guid>/questions/26682/3gpp-timezone-decoding-logic/</guid>
      <description>3GPP timezone decoding logic  1 Hi Team,
3GPP-MS-TimeZone: 4a00 Timezone: GMT - 6 hours 0 minutes No adjustment Padding: 0000
please let me how hex value 4a was decoded as GMT-6.can you please share the logic of decoding that.
dint find much info in 3gpp docs
Best Regards Anand.R
timezoneasked 05 Nov &#39;13, 11:22
AnandRoni
16●2●2●3
accept rate: 0%
  
2 Answers:
  
2Hi,
have a look at 3GPP TS 23.</description>
    </item>
    
    <item>
      <title>How can I compare 2 captured file with each other</title>
      <link>/questions/26693/how-can-i-compare-2-captured-file-with-each-other/</link>
      <pubDate>Wed, 06 Nov 2013 00:16:00 +0000</pubDate>
      
      <guid>/questions/26693/how-can-i-compare-2-captured-file-with-each-other/</guid>
      <description>How can I compare 2 captured file with each other  0 I have two captured files ( server side and client side)and i want to compare these 2 files in order to detect their differences. How can i do that with wireshark?
tnx.
diff compare differenceasked 06 Nov &#39;13, 00:16
amir
1●1●1●1
accept rate: 0%
 edited 06 Nov &#39;13, 04:01 
Kurt Knochner ♦
24.8k●10●39●237</description>
    </item>
    
    <item>
      <title>Wireshark wireless capture on wlan0(mon0) does not seem to capturing any packets</title>
      <link>/questions/26696/wireshark-wireless-capture-on-wlan0mon0-does-not-seem-to-capturing-any-packets/</link>
      <pubDate>Wed, 06 Nov 2013 06:48:00 +0000</pubDate>
      
      <guid>/questions/26696/wireshark-wireless-capture-on-wlan0mon0-does-not-seem-to-capturing-any-packets/</guid>
      <description>Wireshark wireless capture on wlan0(mon0) does not seem to capturing any packets  0 A new user of wireshark here. I use Wireshark on Kali Linux- I have one network adapter and a wireless usb adapter- Alfa Network. I am able to enable the alfa card for monitor mode. It is a card that is capable of monitoring and injection. However, when I select the capture interface on Wireshark as mon0 or wlan0, it captures the broadcast traffic that other wireless network is sending( not quite sure what the right term here is).</description>
    </item>
    
    <item>
      <title>Detect dropped packets in Windows VM</title>
      <link>/questions/26698/detect-dropped-packets-in-windows-vm/</link>
      <pubDate>Wed, 06 Nov 2013 10:50:00 +0000</pubDate>
      
      <guid>/questions/26698/detect-dropped-packets-in-windows-vm/</guid>
      <description>Detect dropped packets in Windows VM  0 We have about 30 Windows VMs under vSphere 5.1. I am using esxtop to monitor the network and I see some odd behavior. Under the %DroppedPacketsReceived (%DRPRX) column you can see the problem. This column will show zeros for all VMs for a few seconds then all the VMs will show packet loss for a few seconds, then back to zero. I have a Win7 machine with Wireshark installed on this host, you can see it at the bottom of the screen shot.</description>
    </item>
    
    <item>
      <title>Don&amp;#x27;t receive eapol handshakes from other computers</title>
      <link>/questions/26700/dont-receive-eapol-handshakes-from-other-computers/</link>
      <pubDate>Wed, 06 Nov 2013 15:07:00 +0000</pubDate>
      
      <guid>/questions/26700/dont-receive-eapol-handshakes-from-other-computers/</guid>
      <description>Don&amp;rsquo;t receive eapol handshakes from other computers  0 Hello!
I am using wireshark at MacOSX with a Tenda W311M (802.11n) on a WPA2 network. I can see the traffic from my test system (like UDP), but I don&#39;t monitor any eapol hand shakes (except for my own two way handshakes that come along time to time). I can see the gratuitious arp when I connect another computer, everything as expected, but no eapol hand shakes.</description>
    </item>
    
    <item>
      <title>Enhancement: Place File Set Prev/Next File buttons on toolbar</title>
      <link>/questions/26701/enhancement-place-file-set-prevnext-file-buttons-on-toolbar/</link>
      <pubDate>Wed, 06 Nov 2013 16:09:00 +0000</pubDate>
      
      <guid>/questions/26701/enhancement-place-file-set-prevnext-file-buttons-on-toolbar/</guid>
      <description>Enhancement: Place File Set Prev/Next File buttons on toolbar  0 I almost always divide captures into 100MB files to make then small enough to examine quickly. It would be great if I could have a toolbar button or shortcut key to load the prev/next file in the current file list. Pretty please?
multiple-files enhancement filelistasked 06 Nov &#39;13, 16:09
MarkE
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t decode 802.11 ping reply</title>
      <link>/questions/26703/cant-decode-80211-ping-reply/</link>
      <pubDate>Wed, 06 Nov 2013 17:26:00 +0000</pubDate>
      
      <guid>/questions/26703/cant-decode-80211-ping-reply/</guid>
      <description>Can&amp;rsquo;t decode 802.11 ping reply  1 Hello, Perhaps this question had been asked before but I&#39;ve been searching and could not find answer. I performed a ping from wifi client (laptop) and captured raw 802.11 packet via wireless nic interface. I used to WS to decode the packet and was able to see ping request clearly (802.11header, LLC, IP, ICMP, etc):
However it seemed that WS cannot decoded a ping reply when it is an 802.</description>
    </item>
    
    <item>
      <title>Why am I getting RSTACK packet after SYN ?</title>
      <link>/questions/26721/why-am-i-getting-rstack-packet-after-syn/</link>
      <pubDate>Thu, 07 Nov 2013 08:16:00 +0000</pubDate>
      
      <guid>/questions/26721/why-am-i-getting-rstack-packet-after-syn/</guid>
      <description>Why am I getting RSTACK packet after SYN ?  0 I am running a scanner against my server. I am trying to understand why TCP conversations (12-17) below have a SYN (sent by the scanner) with a RSTACK response sent by my server. Does anyone know why? Thanks in Advance.
I am sorry that the data below seems to get reformatted. It should be 4 values per line where the value is null for the column representing the receiver.</description>
    </item>
    
    <item>
      <title>Filter for packets containing &amp;quot;If-Modified-Since&amp;quot;</title>
      <link>/questions/26723/filter-for-packets-containing-if-modified-since/</link>
      <pubDate>Thu, 07 Nov 2013 08:45:00 +0000</pubDate>
      
      <guid>/questions/26723/filter-for-packets-containing-if-modified-since/</guid>
      <description>Filter for packets containing &amp;ldquo;If-Modified-Since&amp;rdquo;  0 I am trying to figure out a display filter to find any packets containing &#34;If-Modified-Since&#34; indicating they have the element they are looking for in cache. I did a right-click, Aplly as Filter, Selected, but this is ineffective since it applies a very long filter looking for the If-Modified-Since and the full time-stamp. An example looks like:
frame[804:50] == 49:66:2d:4d:6f:64:69:66:69:65:64:2d:53:69:6e:63:65:3a:20:54:75:65:2c:20:30:34:20:41:75:67:20:32:30:30:39:20:32:31:3a:32:33:3a:30:39:20:47:4d:54:0d:0aOther display filters I have tried:</description>
    </item>
    
    <item>
      <title>How to find HTTP content encoding</title>
      <link>/questions/26724/how-to-find-http-content-encoding/</link>
      <pubDate>Thu, 07 Nov 2013 09:23:00 +0000</pubDate>
      
      <guid>/questions/26724/how-to-find-http-content-encoding/</guid>
      <description>How to find HTTP content encoding  0 I know it is an old post, but I need to know if there is a way to tell from wireshark what the content encoding is? How should I know if it is gzip encoded? Is it in the TCP header somewhere?
content http encodingasked 07 Nov &#39;13, 09:23
doodlekana
11●1●1●2
accept rate: 0%
 converted to question 07 Nov &#39;13, 15:13</description>
    </item>
    
    <item>
      <title>How to install Mac X 10.6.8</title>
      <link>/questions/26725/how-to-install-mac-x-1068/</link>
      <pubDate>Thu, 07 Nov 2013 09:43:00 +0000</pubDate>
      
      <guid>/questions/26725/how-to-install-mac-x-1068/</guid>
      <description>How to install Mac X 10.6.8  0 I&#39;m taking a college class. Have an assignment to install Wireshark and report on results as a learning experience. Have a Macbook with X 10.6.8. Tried to run the 64-bit version, and knocked out my modem. Will next try the 32-bit version, old stable version. Need some coaching so I don&#39;t knock out the modem again. If this has to be run in binary only, then I&#39;ll probably not be able to complete the assignment.</description>
    </item>
    
    <item>
      <title>non-shared tshark preferences</title>
      <link>/questions/26726/non-shared-tshark-preferences/</link>
      <pubDate>Thu, 07 Nov 2013 10:05:00 +0000</pubDate>
      
      <guid>/questions/26726/non-shared-tshark-preferences/</guid>
      <description>non-shared tshark preferences  0 Hi, Tshark uses the same search path as Wireshark to look for preferences. But sometimes I&#39;d like to let Tshark use a completely different setting, typically prepared in a temporary file, without interfering with the system- or user-wide Wireshark setting. Is that doable ? (one would expect an environment var or an option for this; none seem to be documented)
Thanks in advance,
-Alex
preferencesasked 07 Nov &#39;13, 10:05</description>
    </item>
    
    <item>
      <title>Wireshark core dumped on capture start</title>
      <link>/questions/26730/wireshark-core-dumped-on-capture-start/</link>
      <pubDate>Thu, 07 Nov 2013 11:41:00 +0000</pubDate>
      
      <guid>/questions/26730/wireshark-core-dumped-on-capture-start/</guid>
      <description>Wireshark core dumped on capture start  0 Hi everyone,
I&#39;ve been using wireshark for a long time and all went perfectly until a week ago I tried to sniff my network traffic and it crashed when I hit the start button. It does not matter what interface I pick, it always crashes when trying to capture packets. It seems like problems came along with the new version (1.10). I do not remember what version I was using before (last time I used wireshark was one year ago or so).</description>
    </item>
    
    <item>
      <title>Incoming UDP only works while capturing packages with Wireshark</title>
      <link>/questions/26732/incoming-udp-only-works-while-capturing-packages-with-wireshark/</link>
      <pubDate>Thu, 07 Nov 2013 13:39:00 +0000</pubDate>
      
      <guid>/questions/26732/incoming-udp-only-works-while-capturing-packages-with-wireshark/</guid>
      <description>Incoming UDP only works while capturing packages with Wireshark  0 I was transmitting UDP packets from an Arduino with out being able to detect them. When I used Wireshark to capture the packages, they started coming into my receiving program they way they should.
As soon as I closed Wireshark the packages were no longer received.
Any ideas on why this is and what I need to change to my settings?</description>
    </item>
    
    <item>
      <title>A bit advanced filter</title>
      <link>/questions/26733/a-bit-advanced-filter/</link>
      <pubDate>Thu, 07 Nov 2013 14:49:00 +0000</pubDate>
      
      <guid>/questions/26733/a-bit-advanced-filter/</guid>
      <description>A bit advanced filter  0 Hello, in the Wireshark filter I can display all packets destined to 10.0.0.1 address:
ip.dst == 10.0.0.1
After that Wireshark will show a lot of packets with different IP source addresses. It is clear.
But how can I display pakets with other IP destinations with exactly above IP sources (if there are)? I can check each IP source but it is long and time consuming process.</description>
    </item>
    
    <item>
      <title>Problems to find rtmp</title>
      <link>/questions/26738/problems-to-find-rtmp/</link>
      <pubDate>Thu, 07 Nov 2013 15:16:00 +0000</pubDate>
      
      <guid>/questions/26738/problems-to-find-rtmp/</guid>
      <description>Problems to find rtmp  0 I can&#39;t meet the URL to download a video, i could like to know how see the rtmp for this link http://www.alfaconcursos.com.br/cursos/detalhe/329/caixa_economica_federal_caixa.html
how i can see the paramenters by this movie with wireshark? i am trying to down with rtmpdump... any idea?
rtmp wiresharkasked 07 Nov &#39;13, 15:16
Sm86
1●1●1●1
accept rate: 0%
  
One Answer:
  
0There is no cleartext RTMP involved.</description>
    </item>
    
    <item>
      <title>Is YMSG for Android Encrypted?</title>
      <link>/questions/26745/is-ymsg-for-android-encrypted/</link>
      <pubDate>Thu, 07 Nov 2013 15:50:00 +0000</pubDate>
      
      <guid>/questions/26745/is-ymsg-for-android-encrypted/</guid>
      <description>Is YMSG for Android Encrypted?  0 I&#39;ve been able to find YMSG packets from all devices on our subnet that use Yahoo IM, except for Android tablets. I have verified this by using the MAC of one of the tablets as a capture filter, verifying that Wireshark is capturing packets, then applying the YMSG display filter during a chat session initiated by me. No packets make it through the filter!</description>
    </item>
    
    <item>
      <title>Alternatives to Network Instruments Gigastor</title>
      <link>/questions/26758/alternatives-to-network-instruments-gigastor/</link>
      <pubDate>Thu, 07 Nov 2013 17:21:00 +0000</pubDate>
      
      <guid>/questions/26758/alternatives-to-network-instruments-gigastor/</guid>
      <description>Alternatives to Network Instruments Gigastor  0 All My company uses NI gigastor to mine packets from our network so that we can go back in time to troubleshoot issues found. I know of 2 products; NI&#39;s Gigastor and Wild Packets, are there any other producsts I may not know about? My primary client for packet inspection is Wireshark. Can anyone help? Thank you,
houric mandedasked 07 Nov &#39;13, 17:21</description>
    </item>
    
    <item>
      <title>Wireshark is Phoning Home (checking for updates)</title>
      <link>/questions/26761/wireshark-is-phoning-home-checking-for-updates/</link>
      <pubDate>Thu, 07 Nov 2013 17:45:00 +0000</pubDate>
      
      <guid>/questions/26761/wireshark-is-phoning-home-checking-for-updates/</guid>
      <description>Wireshark is Phoning Home (checking for updates)  1 Lately I&#39;ve been putting up a quarantine on the Windows desktop when I step away to see if any spyware/malware lurks within.
Part of the exercise is to run Wireshark to capture suspicious traffic on one particular path.
Immediately upon starting Wireshark, I saw this:
Nov 8 00:51:23 asa5505 %ASA-4-106100: access-list forward-inside denied tcp inside/10.29.87.10(54796) -&amp;gt; outside/108.162.204.234(443) hit-cnt 1 first hit [0x2b7f3f90, 0x0]</description>
    </item>
    
    <item>
      <title>Why Wireshark display filter does not show http packets?</title>
      <link>/questions/26768/why-wireshark-display-filter-does-not-show-http-packets/</link>
      <pubDate>Thu, 07 Nov 2013 22:22:00 +0000</pubDate>
      
      <guid>/questions/26768/why-wireshark-display-filter-does-not-show-http-packets/</guid>
      <description>Why Wireshark display filter does not show http packets?  2 1Hi,
When I use display filter for HTTP it shows only HTTP packets when HTTP message is on standard port i.e. on port 80. But, when message is not using standard port, then display filter not works for HTTP and I need to filter for TCP and then need to find out HTTP packets manually.
I want to know why this happen?</description>
    </item>
    
    <item>
      <title>Why Protocol UPP is replaced by UMA in wireshark 1.10.3</title>
      <link>/questions/26776/why-protocol-upp-is-replaced-by-uma-in-wireshark-1103/</link>
      <pubDate>Fri, 08 Nov 2013 06:32:00 +0000</pubDate>
      
      <guid>/questions/26776/why-protocol-upp-is-replaced-by-uma-in-wireshark-1103/</guid>
      <description>Why Protocol UPP is replaced by UMA in wireshark 1.10.3  0 hi team
I have installed wireshark 1.10.3 and am not getting UPP ptotocol here. While analyzing logs, i found that all logs for upp are presented here but the protocol is showing &#34;UMA&#34;.
Please find the error if it there and also confirm to me.
Thanks manish
about_wiresharkasked 08 Nov &#39;13, 06:32
Metalica Loo...
21●2●2●5
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Capture Packets from 10Gb interface</title>
      <link>/questions/26778/capture-packets-from-10gb-interface/</link>
      <pubDate>Fri, 08 Nov 2013 07:59:00 +0000</pubDate>
      
      <guid>/questions/26778/capture-packets-from-10gb-interface/</guid>
      <description>Capture Packets from 10Gb interface  0 Good day,
I have an network issue with some unbalanced traffic using ECMP, i need to take packet captures from a 10GB interface in a mirror port. I would like to know if its possible and how or either how can i make this packets on a 10G switch interface from my laptop.
10gbeasked 08 Nov &#39;13, 07:59
RodrigoMorales
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>MAP invoke inside a TC_cont not recognised as such</title>
      <link>/questions/26780/map-invoke-inside-a-tc_cont-not-recognised-as-such/</link>
      <pubDate>Fri, 08 Nov 2013 09:40:00 +0000</pubDate>
      
      <guid>/questions/26780/map-invoke-inside-a-tc_cont-not-recognised-as-such/</guid>
      <description>MAP invoke inside a TC_cont not recognised as such  0 MAP message (ISD) is too long for one MTP frame, so it is segmented at MAP level into multiple TC messages WS successfully recognises the first, inside TC_begin, both in - Packet List Frame - with protocol as GSM MAP and name of operation in info column - Dacket Setails - with correct analysis of structure But the MAP invoke inside the tc_cont is not recognised (it&#39;s valid - I analyzed the BER by hand!</description>
    </item>
    
    <item>
      <title>Time Machine to Network drive doesn&amp;#x27;t finish</title>
      <link>/questions/26783/time-machine-to-network-drive-doesnt-finish/</link>
      <pubDate>Fri, 08 Nov 2013 10:56:00 +0000</pubDate>
      
      <guid>/questions/26783/time-machine-to-network-drive-doesnt-finish/</guid>
      <description>Time Machine to Network drive doesn&amp;rsquo;t finish  0 Hi Guys,
We are trying to backup a macbook air to a Synology diskstation over wireless using Time Machine. We are able to backup on a wired connection but on wireless the Mac says &#34;Preparing backup&#34; and never starts the backup. I took a capture from our router and saw that there are a lot of &#34;TCP Retransmission&#34; and &#34;TCP Out of Order&#34;</description>
    </item>
    
    <item>
      <title>tcp duplicate ack in MPTCP iscsi traffic</title>
      <link>/questions/26784/tcp-duplicate-ack-in-mptcp-iscsi-traffic/</link>
      <pubDate>Fri, 08 Nov 2013 11:22:00 +0000</pubDate>
      
      <guid>/questions/26784/tcp-duplicate-ack-in-mptcp-iscsi-traffic/</guid>
      <description>tcp duplicate ack in MPTCP iscsi traffic  0 I am looking at the multi-path iscsi traffic trace and seeing occasional tcp duplicate acks.
3706 2013-11-08 14:02:09.353893 192.168.1.1 192.168.1.250 TCP [TCP Dup ACK 3704#1] 59969 &amp;gt; iscsi-target [ACK] Seq=11134753 Ack=5166528 Win=65535 Len=0 SLE=5175488 SRE=5193408
3708 2013-11-08 14:02:09.353927 192.168.1.1 192.168.1.250 TCP [TCP Dup ACK 3704#2] 59969 &amp;gt; iscsi-target [ACK] Seq=11134753 Ack=5166528 Win=65535 Len=0 SLE=5175488 SRE=5202368
3710 2013-11-08 14:02:09.353955 192.168.1.1 192.168.1.250 TCP [TCP Dup ACK 3704#3] 59969 &amp;gt; iscsi-target [ACK] Seq=11134753 Ack=5166528 Win=65535 Len=0 SLE=5175488 SRE=5205232</description>
    </item>
    
    <item>
      <title>Outgoing packets of IPsec VPN tunnel establishment not visible</title>
      <link>/questions/26785/outgoing-packets-of-ipsec-vpn-tunnel-establishment-not-visible/</link>
      <pubDate>Fri, 08 Nov 2013 11:51:00 +0000</pubDate>
      
      <guid>/questions/26785/outgoing-packets-of-ipsec-vpn-tunnel-establishment-not-visible/</guid>
      <description>Outgoing packets of IPsec VPN tunnel establishment not visible  0 Hi Guys,
I am trying to capture a VPN tunnel establishment between 2 firewalls. While I am able to get the trace on TCPDUMP, however when I write it to a pcap file, the outgoing packets are not present. What could I be doing wrong or is there something else I need to do while I do the capture?</description>
    </item>
    
    <item>
      <title>grouping by conversations</title>
      <link>/questions/26786/grouping-by-conversations/</link>
      <pubDate>Fri, 08 Nov 2013 13:29:00 +0000</pubDate>
      
      <guid>/questions/26786/grouping-by-conversations/</guid>
      <description>grouping by conversations  0 I have a very big TCP dump between two servers. There are only two IP addresses so each conversation is defined by the TCP ports used. My question is how do I group the the data by conversations such that all the output is still there just grouped by unique conversation
conversation tcpasked 08 Nov &#39;13, 13:29
mrw_1955
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>undefined symbol</title>
      <link>/questions/26797/undefined-symbol/</link>
      <pubDate>Fri, 08 Nov 2013 22:58:00 +0000</pubDate>
      
      <guid>/questions/26797/undefined-symbol/</guid>
      <description>undefined symbol  0 hi, when i am trying to add open-flow plugin in wireshark it gives me an error, packet-openflow.so: undefined symbol: match_strval
match_strvalasked 08 Nov &#39;13, 22:58
chougulepavan
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Plugins are only guaranteed to work with the Wireshark version for which they are compiled check if your Wireshark version is the same as the one the plugin was compiled for.</description>
    </item>
    
    <item>
      <title>regarding capture probe request</title>
      <link>/questions/26798/regarding-capture-probe-request/</link>
      <pubDate>Sat, 09 Nov 2013 01:55:00 +0000</pubDate>
      
      <guid>/questions/26798/regarding-capture-probe-request/</guid>
      <description>regarding capture probe request  0 I have a question regarding capture probe request on a single specific channel between access point and client
packet-capture wiresharkThis question is marked &#34;community wiki&#34;.asked 09 Nov &#39;13, 01:55
manish26
11●1●1●2
accept rate: 0%
and your question is...?
(09 Nov &#39;13, 14:46) Kurt Knochner ♦how to capture??
(10 Nov &#39;13, 00:18) manish26  
One Answer:
  
0O.K. I understand it like this:</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t install wireshark on Mac - OS X says it&amp;#x27;s from an unidentified developer</title>
      <link>/questions/26804/cant-install-wireshark-on-mac-os-x-says-its-from-an-unidentified-developer/</link>
      <pubDate>Sat, 09 Nov 2013 08:05:00 +0000</pubDate>
      
      <guid>/questions/26804/cant-install-wireshark-on-mac-os-x-says-its-from-an-unidentified-developer/</guid>
      <description>Can&amp;rsquo;t install wireshark on Mac - OS X says it&amp;rsquo;s from an unidentified developer  0 I downloaded wireshark for my MacBook Pro but when i double click to install it i get the following message:
Wireshark 1.10.3 Intel 64.pkg” can’t be opened because it is from an unidentified developer. “Wireshark 1.10.3 Intel 64.pkg” is on the disk image “Wireshark 1.10.3 Intel 64.dmg”. Safari downloaded this disk image yesterday at 3:55 PM from www.</description>
    </item>
    
    <item>
      <title>Chart network traffic</title>
      <link>/questions/26805/chart-network-traffic/</link>
      <pubDate>Sat, 09 Nov 2013 13:07:00 +0000</pubDate>
      
      <guid>/questions/26805/chart-network-traffic/</guid>
      <description>Chart network traffic  0 I&#39;m brand new to wireshark. Is there a chart that will show me the volume of network activity by LAN IP address? I&#39;d like to see which computers have the most traffic.
chartasked 09 Nov &#39;13, 13:07
Scott216
11●1●1●2
accept rate: 0%
  
One Answer:
  
0There are several methods.
Statistics -&amp;gt; Endpoints -&amp;gt; IPv4 (sort for Bytes or Packets)
Statistics -&amp;gt; Conversations -&amp;gt; IPv4 (or TCP)</description>
    </item>
    
    <item>
      <title>statistics - time interval problem</title>
      <link>/questions/26810/statistics-time-interval-problem/</link>
      <pubDate>Sat, 09 Nov 2013 16:47:00 +0000</pubDate>
      
      <guid>/questions/26810/statistics-time-interval-problem/</guid>
      <description>statistics - time interval problem  0 Hello, I have 16 seconds trace file. I need see packets during 1 second. I use the following display filter:
frame.time &amp;gt;= &#34;Nov 10, 2013 11:22:09.000000000&#34; and frame.time &amp;lt; &#34;Nov 10, 2013 11:22:10.000000000&#34;
I verify the operation, I check first and last packets on the filtered list and I see correct Arrival Times:
First packet: Nov 10, 2013 11:22:09.002234000
Last packet: Nov 10, 2013 11:22:09.</description>
    </item>
    
    <item>
      <title>I have a question regarding ip sniffing</title>
      <link>/questions/26811/i-have-a-question-regarding-ip-sniffing/</link>
      <pubDate>Sat, 09 Nov 2013 21:54:00 +0000</pubDate>
      
      <guid>/questions/26811/i-have-a-question-regarding-ip-sniffing/</guid>
      <description>I have a question regarding ip sniffing  0 When trying to sniff ips on my network, I am not displayed with their ips, but the names of the network instead. Here is a picture --&amp;gt; http://tinypic.com/r/5ww2n9/5 if anyone can help me make it so that i can see the different ips, that would be awesome. Im sniffing through En1 (wirelessly) i had it working a while back, but i assume i accidentally did something to screw it up.</description>
    </item>
    
    <item>
      <title>Windows 7 64-bit Installation Problem</title>
      <link>/questions/26820/windows-7-64-bit-installation-problem/</link>
      <pubDate>Sun, 10 Nov 2013 13:03:00 +0000</pubDate>
      
      <guid>/questions/26820/windows-7-64-bit-installation-problem/</guid>
      <description>Windows 7 64-bit Installation Problem  0 I have run the 64-bit version on my Windows 7 64-bit desktop. However, I am now receiving a 0xc000007b error when trying to start Wireshark. I downloaded both the 64-bit and 32-bit installation packages. The error is received any time I try to run the 64-bit version, but the 32-bit version will install and run. I wonder if this s a dll problem with the correct one not being installed.</description>
    </item>
    
    <item>
      <title>What&amp;#x27;s the capture filter for a DHCP option?</title>
      <link>/questions/26828/whats-the-capture-filter-for-a-dhcp-option/</link>
      <pubDate>Sun, 10 Nov 2013 18:25:00 +0000</pubDate>
      
      <guid>/questions/26828/whats-the-capture-filter-for-a-dhcp-option/</guid>
      <description>What&amp;rsquo;s the capture filter for a DHCP option?  0 What&#39;s the capture filter equivalent to the display filter &#34;(bootp.option.type == 53)&#34; for DHCP?
filter dhcpasked 10 Nov &#39;13, 18:25
metamatrix
56●16●16●19
accept rate: 100%
 edited 11 Nov &#39;13, 07:52 
Kurt Knochner ♦
24.8k●10●39●237
  
One Answer:
  
1 The order of option 53 in the frame, and with that the position, is unknown. As capture filters don&#39;t have any protocol intelligence, you can&#39;t define a capture filter for a certain DHCP option.</description>
    </item>
    
    <item>
      <title>what will broadcast when i will change the ip address</title>
      <link>/questions/26830/what-will-broadcast-when-i-will-change-the-ip-address/</link>
      <pubDate>Sun, 10 Nov 2013 21:13:00 +0000</pubDate>
      
      <guid>/questions/26830/what-will-broadcast-when-i-will-change-the-ip-address/</guid>
      <description>what will broadcast when i will change the ip address  0 What will capture when i change the ip address.
I install wireshark and i change the ip address of that pc.
From otherside if i change the pc ip address how do i know that pc has change the ip address.
Scenario-1: One pc that i have with wireshark. Ip address is 172.16.15.2 Wireshark is running. Now i change the ip address 172.</description>
    </item>
    
    <item>
      <title>extend existing dissector</title>
      <link>/questions/26833/extend-existing-dissector/</link>
      <pubDate>Mon, 11 Nov 2013 00:27:00 +0000</pubDate>
      
      <guid>/questions/26833/extend-existing-dissector/</guid>
      <description>extend existing dissector  0 I&#39;d like to extend an existing dissector. Current dissector display the field as a string and I would like to parse this string into tokens. Finding the handler is easy - method find_dissector, I know the field name that needs extension. How do I take over current handling?
dissectorasked 11 Nov &#39;13, 00:27
yosefk
11●1●1●2
accept rate: 0%
Are you trying to do this with LUA?</description>
    </item>
    
    <item>
      <title>sniffing in promiscuous mode</title>
      <link>/questions/26835/sniffing-in-promiscuous-mode/</link>
      <pubDate>Mon, 11 Nov 2013 05:49:00 +0000</pubDate>
      
      <guid>/questions/26835/sniffing-in-promiscuous-mode/</guid>
      <description>sniffing in promiscuous mode  0 I have a HP laptop with a 5100 AGN wifi adaptor with XP. I am not able to set de promiscuous mode on the adaptor to sniffer in de promiscuous mode. Can someone help me how to sniffer in the promiscuous mode? Thanks in advance Regards,
promiscuousasked 11 Nov &#39;13, 05:49
abdulkadir
11●1●1●2
accept rate: 0%
 edited 11 Nov &#39;13, 05:54 
grahamb ♦</description>
    </item>
    
    <item>
      <title>Red Hat Enterprise linux for work station version 6.2</title>
      <link>/questions/26854/red-hat-enterprise-linux-for-work-station-version-62/</link>
      <pubDate>Mon, 11 Nov 2013 12:34:00 +0000</pubDate>
      
      <guid>/questions/26854/red-hat-enterprise-linux-for-work-station-version-62/</guid>
      <description>Red Hat Enterprise linux for work station version 6.2  0 Hello,
I have Red Hat Enterprise linux for work station version 6.2 OS in my computer and I want to install Wireshark in it. I am not a linux guy, I did see some people say to try these
yum install wireshark
yum install wireshark-gnome
I did but I got wireshark package is not available.
Can someone please advise me?</description>
    </item>
    
    <item>
      <title>Sniffing android application webservice</title>
      <link>/questions/26856/sniffing-android-application-webservice/</link>
      <pubDate>Mon, 11 Nov 2013 14:19:00 +0000</pubDate>
      
      <guid>/questions/26856/sniffing-android-application-webservice/</guid>
      <description>Sniffing android application webservice  0 Hello,
I have my phone using PC wi-fi connection in Promiscuous mode enabled, i want to sniff the HTTP webrequest some apps are performing to retrieve data from the web. I would like to aks if there is a specific guide, in particular how do i filter packets from a specific application? How do I read the data if encrypted and i do not know what hash is being used?</description>
    </item>
    
    <item>
      <title>Command line option for &amp;quot;save as&amp;quot;</title>
      <link>/questions/26857/command-line-option-for-save-as/</link>
      <pubDate>Mon, 11 Nov 2013 15:03:00 +0000</pubDate>
      
      <guid>/questions/26857/command-line-option-for-save-as/</guid>
      <description>Command line option for &amp;ldquo;save as&amp;rdquo;  0 Wireshark -w command line option defaults to pcap format. Need to save a Wireshark capture to a specific file with a specific format. Possible example: -w &#34;filename&#34; -F &#34;format&#34; where &#34;format&#34; defines the save as type. Is this possible? Thanks
command-lineasked 11 Nov &#39;13, 15:03
JerryCape
11●1●1●2
accept rate: 0%
  
One Answer:
  
1If you&#39;re doing a live capture, either with Wireshark or with TShark, it can only be saved in pcap or pcap-ng format.</description>
    </item>
    
    <item>
      <title>Capturing HTTP packets from other computers</title>
      <link>/questions/26858/capturing-http-packets-from-other-computers/</link>
      <pubDate>Mon, 11 Nov 2013 16:23:00 +0000</pubDate>
      
      <guid>/questions/26858/capturing-http-packets-from-other-computers/</guid>
      <description>Capturing HTTP packets from other computers  0 Hi I was wondering how you view HTTP packets from other computers that are on the same network as you. I&#39;ve been reading around and can not figure it out. I can view my http traffic but not other computers. If you could respond back with an answer it would be greatly appreciated.
httpsasked 11 Nov &#39;13, 16:23
brad
1●2●2●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Client opening Multiple TCP connections to an application?</title>
      <link>/questions/26861/client-opening-multiple-tcp-connections-to-an-application/</link>
      <pubDate>Mon, 11 Nov 2013 20:32:00 +0000</pubDate>
      
      <guid>/questions/26861/client-opening-multiple-tcp-connections-to-an-application/</guid>
      <description>Client opening Multiple TCP connections to an application?  0 Hi guys,
I have been using wireshark to troubleshoot this network issue we have been facing. Client iniitates a tcp connection from a server to a third part application and on odd occasions more than one TCP connections are formed between the server and the application. From the TCP traces on wireshark, I can see the handshaking for these connections, but cannot get my head around why is this happening?</description>
    </item>
    
    <item>
      <title>Decode for T1-data-over-raw-Ethernet</title>
      <link>/questions/26865/decode-for-t1-data-over-raw-ethernet/</link>
      <pubDate>Mon, 11 Nov 2013 23:29:00 +0000</pubDate>
      
      <guid>/questions/26865/decode-for-t1-data-over-raw-ethernet/</guid>
      <description>Decode for T1-data-over-raw-Ethernet  0 Guisys has developed for me an output from a T1 mapped as ethernet payload to a target laptop. The only relation to the data on the T1 is the packet payload. Is there a Wireshark decode for this, or a way to script out the IP addresses and other details in the payload, please?
Data is sent by a Cisco 10k PE router over DS3, inside which channel 16 is the circuit of interest, delivered to another Cisco router as a T1, using Frame-Relay at layer 2, LMI ANSI Annex D.</description>
    </item>
    
    <item>
      <title>Follow TCP Stream in Wireshark.</title>
      <link>/questions/26866/follow-tcp-stream-in-wireshark/</link>
      <pubDate>Mon, 11 Nov 2013 23:33:00 +0000</pubDate>
      
      <guid>/questions/26866/follow-tcp-stream-in-wireshark/</guid>
      <description>Follow TCP Stream in Wireshark.  0 when i filter the pcap file i seen one error which i never seen before ie: (Error creating filter for this stream. A transport or network layer header is needed) what does that mean could you please tel me.. And how can i rectify this for further assistance.. Thanks
wiresharkasked 11 Nov &#39;13, 23:33
eva
11●1●1●3
accept rate: 0% 
 edited 11 Nov &#39;13, 23:34</description>
    </item>
    
    <item>
      <title>Outer vlan tag removed (Windows 7)</title>
      <link>/questions/26867/outer-vlan-tag-removed-windows-7/</link>
      <pubDate>Tue, 12 Nov 2013 00:28:00 +0000</pubDate>
      
      <guid>/questions/26867/outer-vlan-tag-removed-windows-7/</guid>
      <description>Outer vlan tag removed (Windows 7)  0 Hello, When I capture VLAN-tagged packets with wireshark, I don&#39;t see VLAN tags. My OS is Windows 7 and my ethernet card is TP-LINK TG-3468 (I installed the last driver and I disabled &#34;VLAN &amp;amp; priority function&#34; in the properies in the Ethernet card driver). With Unbuntu, I can see VLAN tags with wireshark. How can I do to capture VLAN tags ?</description>
    </item>
    
    <item>
      <title>how do I extract an MPEG stream from a wireshark capture file (.pcap) and convert that data to &amp;quot;.ts&amp;quot; format (transport stream)</title>
      <link>/questions/26868/how-do-i-extract-an-mpeg-stream-from-a-wireshark-capture-file-pcap-and-convert-that-data-to-ts-format-transport-stream/</link>
      <pubDate>Tue, 12 Nov 2013 01:37:00 +0000</pubDate>
      
      <guid>/questions/26868/how-do-i-extract-an-mpeg-stream-from-a-wireshark-capture-file-pcap-and-convert-that-data-to-ts-format-transport-stream/</guid>
      <description>how do I extract an MPEG stream from a wireshark capture file (.pcap) and convert that data to &amp;ldquo;.ts&amp;rdquo; format (transport stream)  0 hi i have captured network stream via wireshark tool and this stream is in .pcap file format and i want to convert this format to Ts format. how i will convert.
captureasked 12 Nov &#39;13, 01:37
COOLpa
11●1●1●2
accept rate: 0%
 edited 12 Nov &#39;13, 04:45</description>
    </item>
    
    <item>
      <title>see other packages HTTP</title>
      <link>/questions/26869/see-other-packages-http/</link>
      <pubDate>Tue, 12 Nov 2013 01:53:00 +0000</pubDate>
      
      <guid>/questions/26869/see-other-packages-http/</guid>
      <description>see other packages HTTP  0 Please tell me what to do (preferably detailed instructions) to see other packages HTTP in the same wi-fi, it shows me only my traffic.
httpasked 12 Nov &#39;13, 01:53
Sokolov Andrey
1●5●5●6
accept rate: 0%
  
One Answer:
  
0You&#39;ll need to read and understand how to setup your captures. Start at the Wiki page on Capture Setup, and then look at the page for the media type used by your network, most likely 802.</description>
    </item>
    
    <item>
      <title>Does Wireshark have an Encoder Tool?</title>
      <link>/questions/26894/does-wireshark-have-an-encoder-tool/</link>
      <pubDate>Tue, 12 Nov 2013 06:26:00 +0000</pubDate>
      
      <guid>/questions/26894/does-wireshark-have-an-encoder-tool/</guid>
      <description>Does Wireshark have an Encoder Tool?  0 I want to generate a packet for say, an SMS-Submit in GSM SMS. Does Wireshark provide any tools for me to do that?
Thanks in advance.
tools encoderasked 12 Nov &#39;13, 06:26
tongerny
16●2●2●5
accept rate: 0%
  
One Answer:
  
0No Wireshark does not have such a tool.
answered 12 Nov &#39;13, 07:06
Anders ♦
4.6k●9●52
accept rate: 17%</description>
    </item>
    
    <item>
      <title>Using Wireshark to detect traffic shaping</title>
      <link>/questions/26904/using-wireshark-to-detect-traffic-shaping/</link>
      <pubDate>Tue, 12 Nov 2013 13:37:00 +0000</pubDate>
      
      <guid>/questions/26904/using-wireshark-to-detect-traffic-shaping/</guid>
      <description>Using Wireshark to detect traffic shaping  0 i&#39;m new to wireshark, i have a question for the wireshark pros:
i believe that my provider slows down/shapes my download speed if i use certain services / ports.
lets say if i use ftp i have full 18mb/s, if i try to download something from the usenet, it seesms that my max. speed is throttled to max 10mb/s.
is there a difference how the packets look like when throttled/not throttled ?</description>
    </item>
    
    <item>
      <title>Coap 7-Coap 8 Disector problems</title>
      <link>/questions/26917/coap-7-coap-8-disector-problems/</link>
      <pubDate>Tue, 12 Nov 2013 19:06:00 +0000</pubDate>
      
      <guid>/questions/26917/coap-7-coap-8-disector-problems/</guid>
      <description>Coap 7-Coap 8 Disector problems  0 Hello everyone,
I recently upgraded to version Version 1.10.3 (SVN Rev 53022 from /trunk-1.10) from version 1.7.1 and have noticed that the when dissecting coap7-coap8 messages are not being decoded correctly. Specifically I am referring to the first option of all COAP messages [coap-problem.pcapng].
Is there a way to &#34;downgrade&#34; the dissector?
I imagine the right way to go about it is to update/fix the dissector.</description>
    </item>
    
    <item>
      <title>how to fix the error &amp;quot;The capabilities of The capture device &amp;quot;wlan0&amp;quot; could not be obtained (That device doesn&amp;#x27;t support monitor mode)&amp;quot;</title>
      <link>/questions/26919/how-to-fix-the-error-the-capabilities-of-the-capture-device-wlan0-could-not-be-obtained-that-device-doesnt-support-monitor-mode/</link>
      <pubDate>Tue, 12 Nov 2013 19:43:00 +0000</pubDate>
      
      <guid>/questions/26919/how-to-fix-the-error-the-capabilities-of-the-capture-device-wlan0-could-not-be-obtained-that-device-doesnt-support-monitor-mode/</guid>
      <description>how to fix the error &amp;ldquo;The capabilities of The capture device &amp;ldquo;wlan0&amp;rdquo; could not be obtained (That device doesn&amp;rsquo;t support monitor mode)&amp;quot;  0 how to fix the error &#34;The capabilities of The capture device &#34;wlan0&#34; could not be obtained (That device doesn&#39;t support monitor mode). Please check to make sure you have sufficient permissions, and that you have the proper interface or pipe specified.
Try using airmon-ng, as suggested by CaptureSetup/WLAN in the Wireshark Wiki.</description>
    </item>
    
    <item>
      <title>how else can I fix this error?</title>
      <link>/questions/26925/how-else-can-i-fix-this-error/</link>
      <pubDate>Tue, 12 Nov 2013 21:18:00 +0000</pubDate>
      
      <guid>/questions/26925/how-else-can-i-fix-this-error/</guid>
      <description>how else can I fix this error?  0 I have wireshark shows error
&#34;The capabilities of The capture device &#34;mon0&#34; could not be obtained (That device doesn&#39;t support monitor mode). Please check to make sure you have sufficient permissions, and that you have the proper interface or pipe specified.
Try using airmon-ng, as suggested by CaptureSetup/WLAN in the Wireshark Wiki.&#34;
I did airmon-ng start wlan0, the error appears again, I killed all the processes, only &#34;</description>
    </item>
    
    <item>
      <title>Monitor port usage</title>
      <link>/questions/26929/monitor-port-usage/</link>
      <pubDate>Wed, 13 Nov 2013 02:17:00 +0000</pubDate>
      
      <guid>/questions/26929/monitor-port-usage/</guid>
      <description>Monitor port usage  0 Hi guys, i need you help. I would like to monitor three tcp ports and receive an email alert if there is no traffic on these ports. It&#39;s possibile with wireshark?
Thank you very much. Regards
Stefano
alertasked 13 Nov &#39;13, 02:17
Stefo G
11●1●1●2
accept rate: 0%
  
One Answer:
  
1Wireshark isn&#39;t really the tool for this, it&#39;s a packet analysis tool, not a Network Monitoring tool.</description>
    </item>
    
    <item>
      <title>Capture packets on startup automatically</title>
      <link>/questions/26932/capture-packets-on-startup-automatically/</link>
      <pubDate>Wed, 13 Nov 2013 03:17:00 +0000</pubDate>
      
      <guid>/questions/26932/capture-packets-on-startup-automatically/</guid>
      <description>Capture packets on startup automatically  0 Is there any way to make the Wireshark capture packets automatically and save it in a file on startup of Windows? Kindly help me to fix this.
Thanks
windows capture startup packetasked 13 Nov &#39;13, 03:17
bala92n
1●2●2●2
accept rate: 0%
 edited 13 Nov &#39;13, 05:42 
grahamb ♦
19.8k●3●30●206
Is there any way to make the Wireshark capture packets automatically and save it in a file on startup of Windows?</description>
    </item>
    
    <item>
      <title>what is the open source license for Wireshark?</title>
      <link>/questions/26940/what-is-the-open-source-license-for-wireshark/</link>
      <pubDate>Wed, 13 Nov 2013 06:18:00 +0000</pubDate>
      
      <guid>/questions/26940/what-is-the-open-source-license-for-wireshark/</guid>
      <description>what is the open source license for Wireshark?  0 Hi,
We are a legal firm and preparing for a client an open source compliance document. According to your website the components is subjected to GPL 3, however when we asked the client to provide us the notice we received the following:
&#34;Wireshark is distributed under the GNU GPLv2. There are no restrictions on its use. There are restrictions on its distribution in source or binary form.</description>
    </item>
    
    <item>
      <title>How to capture a packet when field name redbackli.label is tagged on the packet</title>
      <link>/questions/26941/how-to-capture-a-packet-when-field-name-redbacklilabel-is-tagged-on-the-packet/</link>
      <pubDate>Wed, 13 Nov 2013 06:19:00 +0000</pubDate>
      
      <guid>/questions/26941/how-to-capture-a-packet-when-field-name-redbacklilabel-is-tagged-on-the-packet/</guid>
      <description>How to capture a packet when field name redbackli.label is tagged on the packet  0 How to capture a packet when field name redbackli.label is tagged on the packet. through tshark command, i knew how to find out in wireshark, pls let me know using tshark comamnd with example.
capture-filter lawfulinterceptasked 13 Nov &#39;13, 06:19
Velpandian
11●1●1●3
accept rate: 0%
  
One Answer:
  
1Capture filters are limited in their ability to decode protocols, so can&#39;t capture on most protocol fields unlike display filters.</description>
    </item>
    
    <item>
      <title>Create plugin on Windows and Linux platforms</title>
      <link>/questions/26943/create-plugin-on-windows-and-linux-platforms/</link>
      <pubDate>Wed, 13 Nov 2013 06:48:00 +0000</pubDate>
      
      <guid>/questions/26943/create-plugin-on-windows-and-linux-platforms/</guid>
      <description>Create plugin on Windows and Linux platforms  0 Hello,
I need to add a new plugin dissector to Wireshark and create a version for windows an linux. Is the source code the same for Windows and Linux ? Can I develop and compil under Windows, then cross compil for linux (or i need to install source code, tools on linux OS, then compil) ?
Edd
windows plugin linuxasked 13 Nov &#39;13, 06:48</description>
    </item>
    
    <item>
      <title>analyzing packets</title>
      <link>/questions/26953/analyzing-packets/</link>
      <pubDate>Wed, 13 Nov 2013 08:54:00 +0000</pubDate>
      
      <guid>/questions/26953/analyzing-packets/</guid>
      <description>analyzing packets  0 I just installed wireshark and need to know what to look for on the network that might be slowing it down - many broadcasts?, rogue dhcp server? etc? What should I look for specifically? Is there a quick simple guide for this? Thanks.
networkasked 13 Nov &#39;13, 08:54
tolinrome
11●2●2●3
accept rate: 0%
  
One Answer:
  
0I don&#39;t want to offend you but the answer to your question</description>
    </item>
    
    <item>
      <title>If tshark can support &amp;quot;export objects&amp;quot; like wireshark for GUI</title>
      <link>/questions/26959/if-tshark-can-support-export-objects-like-wireshark-for-gui/</link>
      <pubDate>Wed, 13 Nov 2013 11:59:00 +0000</pubDate>
      
      <guid>/questions/26959/if-tshark-can-support-export-objects-like-wireshark-for-gui/</guid>
      <description>If tshark can support &amp;ldquo;export objects&amp;rdquo; like wireshark for GUI  0 Dear All.
I have a question about tshark. Could you explain me why tshark doesn&#39;t support &#34;export objects&#34; like wireshark? I couldn&#39;t find anything comment related to my question. Please, advice me.
Thank you
tsharkasked 13 Nov &#39;13, 11:59
honeycap78
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1Could you explain me why tshark doesn&#39;t support &#34;</description>
    </item>
    
    <item>
      <title>See protocols other than http</title>
      <link>/questions/26970/see-protocols-other-than-http/</link>
      <pubDate>Wed, 13 Nov 2013 15:02:00 +0000</pubDate>
      
      <guid>/questions/26970/see-protocols-other-than-http/</guid>
      <description>See protocols other than http  0 I am looking to view the https from other computers connected to my network through an ethernet connection. It is showing other protocols such as udp, ssdp, and other random ones. I can view my https though. Anyone know how to fix this?
ethernet http protocolasked 13 Nov &#39;13, 15:02
brad
1●2●2●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>[closed] Batch file to capture automatically on startup</title>
      <link>/questions/26980/batch-file-to-capture-automatically-on-startup/</link>
      <pubDate>Wed, 13 Nov 2013 21:46:00 +0000</pubDate>
      
      <guid>/questions/26980/batch-file-to-capture-automatically-on-startup/</guid>
      <description>[closed] Batch file to capture automatically on startup  0 How to write a batch file that will help me to start capturing packets automatically and save it in a file on Windows startup?
packet-capture startupasked 13 Nov &#39;13, 21:46
bala92n
1●2●2●2
accept rate: 0%
 closed 14 Nov &#39;13, 00:47 
grahamb ♦
19.8k●3●30●206
Already asked here: http://ask.wireshark.org/questions/26932/capture-packets-on-startup-automatically, and some answers were provided. Please post a comment there if you need more help, not another question.</description>
    </item>
    
    <item>
      <title>Monitor wifi traffic.</title>
      <link>/questions/26987/monitor-wifi-traffic/</link>
      <pubDate>Thu, 14 Nov 2013 02:07:00 +0000</pubDate>
      
      <guid>/questions/26987/monitor-wifi-traffic/</guid>
      <description>Monitor wifi traffic.  0 Hi, I have Dlink-600L, Firmware Version 2.00, would I be able to monitor all the wifi traffic including the traffic from my cell phone using wifi, If yes then would wireshark installed on win7 be enough to achieve this thing, please let me know.
wifiasked 14 Nov &#39;13, 02:07
faisal
1●1●1●1
accept rate: 0%
 converted to question 14 Nov &#39;13, 02:22 
grahamb ♦</description>
    </item>
    
    <item>
      <title>Does Intel Centrino Wireless-N 2200 (2x2 BGN) support wireshark sniffing</title>
      <link>/questions/27004/does-intel-centrino-wireless-n-2200-2x2-bgn-support-wireshark-sniffing/</link>
      <pubDate>Thu, 14 Nov 2013 07:08:00 +0000</pubDate>
      
      <guid>/questions/27004/does-intel-centrino-wireless-n-2200-2x2-bgn-support-wireshark-sniffing/</guid>
      <description>Does Intel Centrino Wireless-N 2200 (2x2 BGN) support wireshark sniffing  0 Hi
Am using Lenovo Thinkpad T430 with Intel Centrino Wireless-N 2200 (2x2 BGN) as built in WLAN card. Ubuntu OS is running on this.
Want to use WLAN card as WLAN sniffer. Does this WLAN card support monitor mode ?
sudo ifconfig wlan0 downsudo iwconfig wlan0 mode monitorsudo iwconfig wlan0 channel 1sudo ifconfig wlan0 upsudo wireshark &amp;amp;Unfortunately following error is coming after step 3 :: Error for wireless request “set frequency” (8B04) : Set failed on device wlan0 ; Device or resource busy</description>
    </item>
    
    <item>
      <title>Why are Wireshark downloads unreasonably slow?</title>
      <link>/questions/27010/why-are-wireshark-downloads-unreasonably-slow/</link>
      <pubDate>Thu, 14 Nov 2013 08:21:00 +0000</pubDate>
      
      <guid>/questions/27010/why-are-wireshark-downloads-unreasonably-slow/</guid>
      <description>Why are Wireshark downloads unreasonably slow?  -1 20kbps is way too slow. Can this bandwidth be increased some alternate download sites setup?
download bandwidth throttlingasked 14 Nov &#39;13, 08:21
YouNeedMoreB...
14●1●1●1
accept rate: 0%
 edited 05 Dec &#39;13, 11:21 
multipleinte...
1.3k●15●23●40
  
2 Answers:
  
4Which download server did you happen to use? The download page generates URLs using a weighted random selection from the list that Graham posted.</description>
    </item>
    
    <item>
      <title>copying Preferences from Windows to Linux</title>
      <link>/questions/27013/copying-preferences-from-windows-to-linux/</link>
      <pubDate>Thu, 14 Nov 2013 10:14:00 +0000</pubDate>
      
      <guid>/questions/27013/copying-preferences-from-windows-to-linux/</guid>
      <description>copying Preferences from Windows to Linux  0 I can open Wireshark fine on my newly minted Linux box, capture, analyze, looks good.
When I exit Wireshark, copy my .preferences directory from Windows to Linux, and then load Wireshark once more ... things most look good: The title bar: The Wireshark Network Analyzer [Wireshark 1.10.2 (SVN Rev Unknown from unknown)] The menu bar: File Edit View Go Capture Statistics Telephony Tools Internals Help And the various panels, in brilliant color .</description>
    </item>
    
    <item>
      <title>Constructing the HF declarations dynamically</title>
      <link>/questions/27014/constructing-the-hf-declarations-dynamically/</link>
      <pubDate>Thu, 14 Nov 2013 10:22:00 +0000</pubDate>
      
      <guid>/questions/27014/constructing-the-hf-declarations-dynamically/</guid>
      <description>Constructing the HF declarations dynamically  0 Hi all,
I have a requirement to build some of the Wireshark data structures dynamically, like the HF Info data. I tried to do this and build the data structure and passed the same while registering the protocol. Everything went fine, compilation and installation as well. But, when i execute i could see the dissection happening, but when the select the fields under that protocol Wireshark crashes.</description>
    </item>
    
    <item>
      <title>EDITCAP supported format for input files</title>
      <link>/questions/27015/editcap-supported-format-for-input-files/</link>
      <pubDate>Thu, 14 Nov 2013 11:03:00 +0000</pubDate>
      
      <guid>/questions/27015/editcap-supported-format-for-input-files/</guid>
      <description>EDITCAP supported format for input files  0 Hello Experts,
I am trying to split a large BFR (NI Observer Capture file) to a pcap file. When I use editcap, it gives me error that file format is not supported.
Can somebody please tell me what are supported filetypes for input for editcap.
And also is there a good way to convert or split large BFR file.
Thanks.
bfr editcapasked 14 Nov &#39;13, 11:03</description>
    </item>
    
    <item>
      <title>tshark SIP Statistics</title>
      <link>/questions/27018/tshark-sip-statistics/</link>
      <pubDate>Thu, 14 Nov 2013 13:44:00 +0000</pubDate>
      
      <guid>/questions/27018/tshark-sip-statistics/</guid>
      <description>tshark SIP Statistics  0 Folks,
Is there to way to get successful vs unsuccessful calls in a given pcap using tshark command line? I am using the example below and get some stats, but would need more. Also, no matter which pcap I use, the average set up is always showing up as 0, what am i missing?(there are definitely a lot of successfull calls in the files i am reading)</description>
    </item>
    
    <item>
      <title>Interpreting Packets displayed with ip filter set to xyz.com</title>
      <link>/questions/27023/interpreting-packets-displayed-with-ip-filter-set-to-xyzcom/</link>
      <pubDate>Thu, 14 Nov 2013 16:58:00 +0000</pubDate>
      
      <guid>/questions/27023/interpreting-packets-displayed-with-ip-filter-set-to-xyzcom/</guid>
      <description>Interpreting Packets displayed with ip filter set to xyz.com  0 I&#39;ve set my filter to display packets sent to and from xyz.com and i get a bunch of info with TCP and TLS packets. I&#39;m very very new to networking and basically using wireshark for a project. I&#39;d be grateful if you could throw light on this question.
The TCP and TLS packets being shown on wireshark, are they the ones which are ACTUALLY sent over the internet to the destination ip address or is there much more to it?</description>
    </item>
    
    <item>
      <title>TDLS and Hotspot2.0 support in Wireshark</title>
      <link>/questions/27028/tdls-and-hotspot20-support-in-wireshark/</link>
      <pubDate>Fri, 15 Nov 2013 01:17:00 +0000</pubDate>
      
      <guid>/questions/27028/tdls-and-hotspot20-support-in-wireshark/</guid>
      <description>TDLS and Hotspot2.0 support in Wireshark  0 Hi ,
Could you please let me know that from which version onward TDLS and Hotspot2.0 ( ANQP) support is available ?
Regards Dhanajit
tdls-hotspot2.0asked 15 Nov &#39;13, 01:17
Dhanajit
11●1●1●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>capturing Fibre Channel frames</title>
      <link>/questions/27036/capturing-fibre-channel-frames/</link>
      <pubDate>Fri, 15 Nov 2013 08:33:00 +0000</pubDate>
      
      <guid>/questions/27036/capturing-fibre-channel-frames/</guid>
      <description>capturing Fibre Channel frames  0 Any rumors around supporting capture on Fibre Channel HBAs?
--sk
fibre channel captureasked 15 Nov &#39;13, 08:33
skendric
11●11●11●13
accept rate: 0%
  
One Answer:
  
2No rumors I&#39;ve heard of lately.
So, the answer of @Guy Harris in the following question is still valid.
http://ask.wireshark.org/questions/9687/about-capturing-of-fibre-channel-packets
A possible way was discussed here
http://www.wireshark.org/lists/wireshark-users/201109/msg00099.html
By using a Cisco MDS Port Analyzer Adapter (not sure if that thing is still available - maybe eBay), you can encapsulate Fibre Channel traffic into an ethernet frame which can then be analyzed with Wireshark.</description>
    </item>
    
    <item>
      <title>MAC conversation filter</title>
      <link>/questions/27044/mac-conversation-filter/</link>
      <pubDate>Fri, 15 Nov 2013 15:37:00 +0000</pubDate>
      
      <guid>/questions/27044/mac-conversation-filter/</guid>
      <description>MAC conversation filter  0 I have been working with Wireshark, AirPcap and Cascade for a few years now. One thing I frequently spend time on when I analyze a log is setting up what I’ll call a “MAC level conversation” filter. This is similar to the TCP/IP conversation filter except of course it is at the lowest level. For example, if I want to restrict the display to show only packets going to/from an AP and STA, my filter looks like this:</description>
    </item>
    
    <item>
      <title>HEX string to payload text</title>
      <link>/questions/27045/hex-string-to-payload-text/</link>
      <pubDate>Sat, 16 Nov 2013 02:42:00 +0000</pubDate>
      
      <guid>/questions/27045/hex-string-to-payload-text/</guid>
      <description>HEX string to payload text  0 Hi, i have a hex string which is S1AP/X2AP/RRC payload. I need to covert it to text for example :
HEX STRING : 401D004C5DD80000
OUT PUT : UL-CCCH-Message
message: c1 (0) c1: rrcConnectionRequest (1) rrcConnectionRequest criticalExtensions: rrcConnectionRequest-r8 (0) rrcConnectionRequest-r8 ue-Identity: s-TMSI (0) s-TMSI mmec: 01 [bit length 8, 0000 0001 decimal value 1] m-TMSI: d004c5dd [bit length 32, 1101 0000 0000 0100 1100 0101 1101 1101 decimal value 3489973725] establishmentCause: mo-Data (4) spare: 00 [bit length 1, 7 LSB pad bits, 0.</description>
    </item>
    
    <item>
      <title>how to check out the usage done by several people in wifi router?</title>
      <link>/questions/27053/how-to-check-out-the-usage-done-by-several-people-in-wifi-router/</link>
      <pubDate>Sat, 16 Nov 2013 07:02:00 +0000</pubDate>
      
      <guid>/questions/27053/how-to-check-out-the-usage-done-by-several-people-in-wifi-router/</guid>
      <description>how to check out the usage done by several people in wifi router?  0 we are using beetel router. with my 3 room mates. since all of us sing i would like to how to do these following things 1) how to limit the connection to few mac addresses 2)how to check out the usage done by each mac addreese.
would be great if somebody help me out.
thanks</description>
    </item>
    
    <item>
      <title>Capturing all the traffic on a Cisco 6509E (switch/router)</title>
      <link>/questions/27057/capturing-all-the-traffic-on-a-cisco-6509e-switchrouter/</link>
      <pubDate>Sun, 17 Nov 2013 10:33:00 +0000</pubDate>
      
      <guid>/questions/27057/capturing-all-the-traffic-on-a-cisco-6509e-switchrouter/</guid>
      <description>Capturing all the traffic on a Cisco 6509E (switch/router)  0 I have a CISCO 6509E switch/router and I would like to capture ALL the traffic that is passing through it. This is a very common switch/router. It is dedicated and acting like a load balancer to three Apache web servers. The traffic is not terribly heavy. I could mirror the three switch ports which feed off the 6509E and set up wireshark on each.</description>
    </item>
    
    <item>
      <title>How to on the gateway differ source IP of HTTP packets from different computers from the nat network?</title>
      <link>/questions/27059/how-to-on-the-gateway-differ-source-ip-of-http-packets-from-different-computers-from-the-nat-network/</link>
      <pubDate>Sun, 17 Nov 2013 11:51:00 +0000</pubDate>
      
      <guid>/questions/27059/how-to-on-the-gateway-differ-source-ip-of-http-packets-from-different-computers-from-the-nat-network/</guid>
      <description>How to on the gateway differ source IP of HTTP packets from different computers from the nat network?  0 Hi to all!
I have next situation. My home computer has 100 Mbit cabel internet connection. Cabel from internet provider connected to network card in my PC. I have real IP address (for example 150.140.130.120) Also I have simple USB wifi modem witch can work as access point. I use Connectify Hotspot software to share my internet connection via wifi to other people and for my mobile devices also.</description>
    </item>
    
    <item>
      <title>network type 12 unknown or unsupported</title>
      <link>/questions/27066/network-type-12-unknown-or-unsupported/</link>
      <pubDate>Mon, 18 Nov 2013 03:54:00 +0000</pubDate>
      
      <guid>/questions/27066/network-type-12-unknown-or-unsupported/</guid>
      <description>network type 12 unknown or unsupported  0 The file &#34;test.cap&#34; is a capture for a network type that Wire shark doesn&#39;t support. (snoop: network type 12 unknown or unsupported) I tried to read test.cap file but i am not able to read it. could anyone help me on this?
capture-fileasked 18 Nov &#39;13, 03:54
Muthu Kumar
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Apparently you have a snoop-like capture file with a format that is not (yet) supported by Wireshark.</description>
    </item>
    
    <item>
      <title>&amp;quot;wireshark had stopped working when filter</title>
      <link>/questions/27067/wireshark-had-stopped-working-when-filter/</link>
      <pubDate>Mon, 18 Nov 2013 04:55:00 +0000</pubDate>
      
      <guid>/questions/27067/wireshark-had-stopped-working-when-filter/</guid>
      <description>&amp;ldquo;wireshark had stopped working when filter  0 Hi, I am using wireshark version 1.6.2 with some custom plug ins. many times when i try to apply a filer I receive &#34;wireshark had stopped working&#34;
wireshark_crashedasked 18 Nov &#39;13, 04:55
ItamarL
1●1●1●1
accept rate: 0%
Some questions:
did have that problem with plugin all the time or just recently?are the filters related to the functionality of the plugins or does it happen with simple standard filters (tcp.</description>
    </item>
    
    <item>
      <title>Wireshark and OpenBTS configuration</title>
      <link>/questions/27078/wireshark-and-openbts-configuration/</link>
      <pubDate>Mon, 18 Nov 2013 14:27:00 +0000</pubDate>
      
      <guid>/questions/27078/wireshark-and-openbts-configuration/</guid>
      <description>Wireshark and OpenBTS configuration  0 Hi. I am using a Range Networks Dev. Kit (pretty similar to USRP from Ettus Research) which is running OpenBTS suite (OpenBTS itself, Sipauthserve, Smqueue, etc), and I need to configure Wireshark for packet sniffing tests. More precisely I need to view MOSMS in plain text (messages coming from provisioned cell phones, sent to the &#34;outside world&#34;). Please note that OpenBTS is running on Dev Kit (Ubuntu), I&#39;m using Putty from my PC in order to control OpenBTS via Ethernet port (RJ45), and Wireshark is installed and running on my PC.</description>
    </item>
    
    <item>
      <title>wireshark and server processing time</title>
      <link>/questions/27081/wireshark-and-server-processing-time/</link>
      <pubDate>Mon, 18 Nov 2013 19:39:00 +0000</pubDate>
      
      <guid>/questions/27081/wireshark-and-server-processing-time/</guid>
      <description>wireshark and server processing time  0 I&#39;d like to capture the time it takes for the server to process the request. Below is my setup:
server &amp;lt;--&amp;gt;switch1&amp;lt;--&amp;gt;WAN&amp;lt;--&amp;gt;switch2&amp;lt;--&amp;gt;client
Now the client is accessing the application reside on the server. My plan is to setup Wireshark on switch2 and switch1.
My questions are as follow: - Will the time, that I capture on switch1 when the server sends the response back, be the processing time of the server.</description>
    </item>
    
    <item>
      <title>about the filter of all tcp SYN and RST packet</title>
      <link>/questions/27082/about-the-filter-of-all-tcp-syn-and-rst-packet/</link>
      <pubDate>Mon, 18 Nov 2013 20:30:00 +0000</pubDate>
      
      <guid>/questions/27082/about-the-filter-of-all-tcp-syn-and-rst-packet/</guid>
      <description>about the filter of all tcp SYN and RST packet  0 Hi, I found a display filter expression &#34;tcp[13]&amp;amp;6&#34; which can filter out all the tcp SYN and RST packet, but I don&#39;t understand how does it work. I know the 13 is a offset and &#34;&amp;amp;&#34; is the bit_wise operator, what is the &#34;6&#34;? Why can this expression filter out the result mentioned above?
thank you
bit_wiseasked 18 Nov &#39;13, 20:30</description>
    </item>
    
    <item>
      <title>Triggering-Event IE errored in Trace-Information IE</title>
      <link>/questions/27086/triggering-event-ie-errored-in-trace-information-ie/</link>
      <pubDate>Mon, 18 Nov 2013 23:46:00 +0000</pubDate>
      
      <guid>/questions/27086/triggering-event-ie-errored-in-trace-information-ie/</guid>
      <description>Triggering-Event IE errored in Trace-Information IE  0 I am using wireshark version 1.11.0. I am facing problem while decoding the Triggering-Events IE sent in Create Session Request in GTPv2 protocol. The size of the decoded IE by Wireshark is 8 bytes long but as per specification-32.422-ab0 the size should be 9 bytes long.
Can any one have a look and please let me know.
Hope for your cooperation. Thanks in advance.</description>
    </item>
    
    <item>
      <title>C# Dissector Plugin</title>
      <link>/questions/27091/c-dissector-plugin/</link>
      <pubDate>Tue, 19 Nov 2013 02:13:00 +0000</pubDate>
      
      <guid>/questions/27091/c-dissector-plugin/</guid>
      <description>C# Dissector Plugin  0 I would like to write a .NET dissector plugin to decode my own protocols. Can wireshark read managed dlls (C# or managed C++), or does it have to be only native code or python script? I have decoders written in C# already, and would like to reuse them if possible. Any ideas how this can be done?
Thanks
dissector wireshark pluginasked 19 Nov &#39;13, 02:13</description>
    </item>
    
    <item>
      <title>rf5 file (k18)</title>
      <link>/questions/27092/rf5-file-k18/</link>
      <pubDate>Tue, 19 Nov 2013 02:19:00 +0000</pubDate>
      
      <guid>/questions/27092/rf5-file-k18/</guid>
      <description>rf5 file (k18)  0 Hi everybody ,
I need to open a rf5 file (k18) of tektronix by Wireshark, but an error &#34;rf5 file may be corrupt or damaged&#34; appears.
Please could you suggest a way to dissect this capture (with a programming language , wireshark tool, ......).
Thank you Yours Sincerely
k18 rf5 tektronixasked 19 Nov &#39;13, 02:19
niamat
1●1●1●1
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>PC don&amp;#x27;t response after [SYN, ACK] is received</title>
      <link>/questions/27094/pc-dont-response-after-syn-ack-is-received/</link>
      <pubDate>Tue, 19 Nov 2013 03:26:00 +0000</pubDate>
      
      <guid>/questions/27094/pc-dont-response-after-syn-ack-is-received/</guid>
      <description>PC don&amp;rsquo;t response after [SYN, ACK] is received  0 Hi,
I am trying to port a web server from 8051 to ARM but found some problem after PC received an [SYN, ACK] packet (use web browser to test my server).
PC -&amp;gt; [SYN] My server-&amp;gt; [SYN, ACK] PC -&amp;gt; Can&#39;t see my sever response and just re-transmit the [SYN] again.
I look into the wireshark trace of both working (8051 server) and not working (ARM server) scenario.</description>
    </item>
    
    <item>
      <title>unable to add semi-colon to filter for tshark</title>
      <link>/questions/27095/unable-to-add-semi-colon-to-filter-for-tshark/</link>
      <pubDate>Tue, 19 Nov 2013 03:31:00 +0000</pubDate>
      
      <guid>/questions/27095/unable-to-add-semi-colon-to-filter-for-tshark/</guid>
      <description>unable to add semi-colon to filter for tshark  0 Hello,
I also have some troubles to use diameter.Session-Id filters. For my part the semi-colon is not allowed by tshark in the command line.
-R diameter.Subsession-Id==&#34;65847;53642;517-02&#34; returns : tshark: &#34;;&#34; was unexpected in this context.
REGEXs, contains, matches, don&#39;t seem to be allowed as well ...
Any idea to filter this AVP value ??
Thx
filter semi-colon tsharkasked 19 Nov &#39;13, 03:31</description>
    </item>
    
    <item>
      <title>&amp;quot;Continuation&amp;quot; in info column of SIP traffic</title>
      <link>/questions/27098/continuation-in-info-column-of-sip-traffic/</link>
      <pubDate>Tue, 19 Nov 2013 05:44:00 +0000</pubDate>
      
      <guid>/questions/27098/continuation-in-info-column-of-sip-traffic/</guid>
      <description>&amp;ldquo;Continuation&amp;rdquo; in info column of SIP traffic  0 In collected traces, we are seeing that Continuation message in sip protocol.There are continuation line and continuation protocol which are empty in this sip message. According to the wireshark logs,soft client VOIP program is sending this,however we are not facing any sip message which has contination name. when we investigate this soft clients logs. Can you explain why Wireshark is showing a message like that.</description>
    </item>
    
    <item>
      <title>reassembling data from two or more packages for c dissector</title>
      <link>/questions/27106/reassembling-data-from-two-or-more-packages-for-c-dissector/</link>
      <pubDate>Tue, 19 Nov 2013 10:05:00 +0000</pubDate>
      
      <guid>/questions/27106/reassembling-data-from-two-or-more-packages-for-c-dissector/</guid>
      <description>reassembling data from two or more packages for c dissector  0 Hello,
I have a problem to reassemble data of my dissector in c. My protocols is above the Ethernet. The dissector is called with dissector_add_uint on a &#34;ethertype&#34;
The protocol contains of a header and a payload area. An here comes the problem, the data can be split in more than one package.
What I want is that I collect all the data and then send it to another dissector.</description>
    </item>
    
    <item>
      <title>[closed] Facebook cookie</title>
      <link>/questions/27112/facebook-cookie/</link>
      <pubDate>Tue, 19 Nov 2013 12:54:00 +0000</pubDate>
      
      <guid>/questions/27112/facebook-cookie/</guid>
      <description>[closed] Facebook cookie  0 Hi
I want a working way to steal facebook cookies and use it to hack facebook account
thank you
facebookasked 19 Nov &#39;13, 12:54
Mahmoud Qeshreh
1●1●1●2
accept rate: 0%
 closed 19 Nov &#39;13, 13:03 
Jasper ♦♦
23.8k●5●51●284
1and use it to hack facebook account
you won&#39;t be able to do that!
Reason: You have to ask how to get a cookie out of a HTTP(S) stream.</description>
    </item>
    
    <item>
      <title>How to read/search wireshark logs for ports</title>
      <link>/questions/27116/how-to-readsearch-wireshark-logs-for-ports/</link>
      <pubDate>Tue, 19 Nov 2013 13:59:00 +0000</pubDate>
      
      <guid>/questions/27116/how-to-readsearch-wireshark-logs-for-ports/</guid>
      <description>How to read/search wireshark logs for ports  0 Hello,
I&#39;m trying to search for a specific product and/or port in a wireshark log that i pulled. I tried to use the filter system but typing the port didnt result in a search, instead i got an error: &#34;6502&#34; isn&#39;t a valid display filter: &#34;6502&#34; is neither a field nor a protocol name.
is there a way to search for key words or ports?</description>
    </item>
    
    <item>
      <title>Tshark closing without completing the write</title>
      <link>/questions/27131/tshark-closing-without-completing-the-write/</link>
      <pubDate>Tue, 19 Nov 2013 21:23:00 +0000</pubDate>
      
      <guid>/questions/27131/tshark-closing-without-completing-the-write/</guid>
      <description>Tshark closing without completing the write  0 I have a pcap file of size 16 GB and I am using the following tshark command
tshark -T fields -n -r testbed.pcap -E separator=, -e ip.proto -e ip.src -e tcp.srcport -e ip.dst -e tcp.dstport -e frame.number -e frame.time_epoch -e tcp.flags.urg -e tcp.checksum_bad &amp;gt;file.txt&#34;
But after writing for only 222MB, tshark is closing.
Please suggest how to write the entire content.
Your help will be highly appreciated.</description>
    </item>
    
    <item>
      <title>Does wireshark-1.10 support Camel v-3 and v-4?</title>
      <link>/questions/27137/does-wireshark-110-support-camel-v-3-and-v-4/</link>
      <pubDate>Wed, 20 Nov 2013 00:48:00 +0000</pubDate>
      
      <guid>/questions/27137/does-wireshark-110-support-camel-v-3-and-v-4/</guid>
      <description>Does wireshark-1.10 support Camel v-3 and v-4?  0 Hi all, I&#39;m dissecting Camel packet by using wireshark. I see most of my packet are &#34;Camel-v1&#34; or &#34;Camel-v2&#34; or &#34;Camel&#34; and nothing else. So:
Does this mean my camel packets are version 1, version 2 ?How can I know the version of Camel packet if it is unknown (Protocol = &#34;Camel&#34; on GUI)?I check the code (branch trunk-1.10) and don&#39;t see other versions (Camel-v3, Camel-v4.</description>
    </item>
    
    <item>
      <title>how to know how many TCP streams are there in a trace file?</title>
      <link>/questions/27138/how-to-know-how-many-tcp-streams-are-there-in-a-trace-file/</link>
      <pubDate>Wed, 20 Nov 2013 01:10:00 +0000</pubDate>
      
      <guid>/questions/27138/how-to-know-how-many-tcp-streams-are-there-in-a-trace-file/</guid>
      <description>how to know how many TCP streams are there in a trace file?  0 I would like to know how many TCP streams are there in a trace file? could anyone help on this?
thank you!
tcp_streamasked 20 Nov &#39;13, 01:10
SteveZhou
191●27●30●34
accept rate: 0%
  
One Answer:
  
0 Have you tried the Statistics menu -&amp;gt; Conversations -&amp;gt; TCP Tab? It lists all TCP connections.</description>
    </item>
    
    <item>
      <title>Linking problem when add an extra lib to wireshark</title>
      <link>/questions/27139/linking-problem-when-add-an-extra-lib-to-wireshark/</link>
      <pubDate>Wed, 20 Nov 2013 01:28:00 +0000</pubDate>
      
      <guid>/questions/27139/linking-problem-when-add-an-extra-lib-to-wireshark/</guid>
      <description>Linking problem when add an extra lib to wireshark  0 I&#39;ve added libcstl to wireshark project.When I compile, problems occur: a lot of unresolved external symbols e.g. dissectors.lib(packet-http.obj) : error LNK2019: unresolved external symbol _set_init
I think I should add libcstl.lib to the dependent library list, but I don&#39;t know where to add it.Anybody knows?
Any reply will be appreciated.
problem add lib linkingasked 20 Nov &#39;13, 01:28
metamatrix</description>
    </item>
    
    <item>
      <title>How to get the iostats near realtime from tshark ?</title>
      <link>/questions/27145/how-to-get-the-iostats-near-realtime-from-tshark/</link>
      <pubDate>Wed, 20 Nov 2013 02:25:00 +0000</pubDate>
      
      <guid>/questions/27145/how-to-get-the-iostats-near-realtime-from-tshark/</guid>
      <description>How to get the iostats near realtime from tshark ?  0 Hi All,
 I am trying to plot the stats output from tshark. I want to know if there is a way i can print the stats every few seconds rather than printing at the end. It will be of great help for me.Thanks is advance
tsharkThis question is marked &#34;community wiki&#34;.asked 20 Nov &#39;13, 02:25
Kiran
16●1●1●3</description>
    </item>
    
    <item>
      <title>Generate pcap file for foo dissector protocol</title>
      <link>/questions/27155/generate-pcap-file-for-foo-dissector-protocol/</link>
      <pubDate>Wed, 20 Nov 2013 03:52:00 +0000</pubDate>
      
      <guid>/questions/27155/generate-pcap-file-for-foo-dissector-protocol/</guid>
      <description>Generate pcap file for foo dissector protocol  0 Hey, Where can I get a foo.pcap file to test with the dissector? I couldn&#39;t find an example file in the Developer Guide, if there isn&#39;t one how can I generate a pcap file?
I tried serializing a struct conforming to the foo protocol in C++ but wireshark won&#39;t open it.
Any ideas?
dissector pcap wiresharkasked 20 Nov &#39;13, 03:52
Lews Therin</description>
    </item>
    
    <item>
      <title>Failed uninstall</title>
      <link>/questions/27158/failed-uninstall/</link>
      <pubDate>Wed, 20 Nov 2013 06:41:00 +0000</pubDate>
      
      <guid>/questions/27158/failed-uninstall/</guid>
      <description>Failed uninstall  0 I am trying to remove Wireshark from my computer, but upon uninstalling, I immediately receive an error message &#34;rawshark.exe could not be removed. Is it in use?&#34; I am having difficulty finding a way to end the rawshark.exe process - no rawshark.exe process shown in task manager.
I am running Windows 7. Thanks in advance.
Tom
rawshark rawshark.exe uninstallasked 20 Nov &#39;13, 06:41
tjenks2
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>make error Solaris 10 x86</title>
      <link>/questions/27165/make-error-solaris-10-x86/</link>
      <pubDate>Wed, 20 Nov 2013 08:00:00 +0000</pubDate>
      
      <guid>/questions/27165/make-error-solaris-10-x86/</guid>
      <description>make error Solaris 10 x86  0 I&#39;m trying to compile wireshark 1.8.11 on a solaris 10 x86 system. I have successfully run the ./configure command but when I run make the following errors occur. I do not have a lot of experience with compiling from source code so any help would be great.
libtool: compile: gcc -DHAVE_CONFIG_H -I. -I../.. -I./../.. -I./.. -DINET6 -DG_ DISABLE_DEPRECATED -DG_DISABLE_SINGLE_INCLUDES -DGTK_DISABLE_DEPRECATED -DGTK_DI SABLE_SINGLE_INCLUDES -D_FORTIFY_SOURCE=2 &amp;quot;-D_U_=attribute((unused))&amp;quot; -DFUNC PROTO=15 -I/usr/local/include -I/usr/local/include -I/usr/include/kerberosv5 -DP LUGIN_DIR=\&amp;quot;/usr/local/lib/wireshark/plugins/1.</description>
    </item>
    
    <item>
      <title>multicast-mac = the virtual MAC address that belongs to the NLB</title>
      <link>/questions/27170/multicast-mac-the-virtual-mac-address-that-belongs-to-the-nlb/</link>
      <pubDate>Wed, 20 Nov 2013 08:19:00 +0000</pubDate>
      
      <guid>/questions/27170/multicast-mac-the-virtual-mac-address-that-belongs-to-the-nlb/</guid>
      <description>multicast-mac = the virtual MAC address that belongs to the NLB  0 NLB is configured using multicast, on SRX device as follows:
set interfaces ge-0/0/1 unit 0 family inet address 1.1.1.1/24 arp 1.1.1.10 multicast-mac 01:00:5e:00:00:04
Where the parameters are as follows:
1.1.1.1 = the JSRX interface IP address arp = the NLB address multicast-mac = the virtual MAC address that belongs to the NLBSo,the packets being captured on Wireshark with target IP 1.</description>
    </item>
    
    <item>
      <title>Wireshark Crashes on Win7, Server 2008r2, Server 2012r2...etc</title>
      <link>/questions/27175/wireshark-crashes-on-win7-server-2008r2-server-2012r2etc/</link>
      <pubDate>Wed, 20 Nov 2013 09:43:00 +0000</pubDate>
      
      <guid>/questions/27175/wireshark-crashes-on-win7-server-2008r2-server-2012r2etc/</guid>
      <description>Wireshark Crashes on Win7, Server 2008r2, Server 2012r2&amp;hellip;etc  0 Yes, this is another WireShark Crash Question....
So, I&#39;ve used Wireshark in the following OS&#39;s:
Win7 x64Server 2008r2 (x64)Server 2012r2 (x64)I&#39;m testing software in an environment consisting of multiple instances of the aforementioned OS&#39;s.
My filter is ip.addr == 192.168.1.1.
(I can&#39;t give the actual IP for security purposes).
I have an SNMP Trap set up on 192.168.1.1 and am using wireshark to make sure errors are sent to the Trap.</description>
    </item>
    
    <item>
      <title>Does wireshark have a BSON dissector?</title>
      <link>/questions/27178/does-wireshark-have-a-bson-dissector/</link>
      <pubDate>Wed, 20 Nov 2013 12:16:00 +0000</pubDate>
      
      <guid>/questions/27178/does-wireshark-have-a-bson-dissector/</guid>
      <description>Does wireshark have a BSON dissector?  0 I&#39;ve got a network protocol that uses BSON over TLS, and I&#39;d like to dissect the BSON. I can decrypt the TLS session correctly, but the only protocol option I can use successfully is &#34;data&#34;, which displays just the hex.
Is there a BSON dissector that I can use to decrypt the &#34;Application Data&#34; inside a TLS session?
dissectorasked 20 Nov &#39;13, 12:16</description>
    </item>
    
    <item>
      <title>Active Directory User Account Capture</title>
      <link>/questions/27192/active-directory-user-account-capture/</link>
      <pubDate>Wed, 20 Nov 2013 20:22:00 +0000</pubDate>
      
      <guid>/questions/27192/active-directory-user-account-capture/</guid>
      <description>Active Directory User Account Capture  0 How to trace an AD account lockout issue using wireshark.How to trace the caller computer inside my network
active directory rogue passwordasked 20 Nov &#39;13, 20:22
Anand Giri
11●1●1●2
accept rate: 0%
  
One Answer:
  
0How to trace an AD account lockout issue using wireshark.How to trace the caller computer inside my network
Well, that&#39;s not really easy with a network trace, as the account lockout could have a range of possible reasons and the offending system could use LDAP (plaintext) or LDAPS (encrypted via TLS) or Kerberos.</description>
    </item>
    
    <item>
      <title>Multiple ip in single live capture</title>
      <link>/questions/27193/multiple-ip-in-single-live-capture/</link>
      <pubDate>Wed, 20 Nov 2013 21:54:00 +0000</pubDate>
      
      <guid>/questions/27193/multiple-ip-in-single-live-capture/</guid>
      <description>Multiple ip in single live capture  0 1Hi There,
I would like to capture &#34;multiple host&#34; tcp trace in wireshark. An Example, I am getting a request from ip host &#34;a.b.c.d&#34; on port 15900 (of my server). processing this request and forward request to host &#34;w.x.y.z&#34; and listing reply on port 15122 (of my server). Processing response from host &#34;w.x.y.z&#34; and reply back to host &#34;a.b.c.d&#34;.
My question is, how to capture these tcp trace in single live capture.</description>
    </item>
    
    <item>
      <title>don&amp;#x27;t want to work in monitoring mode</title>
      <link>/questions/27201/dont-want-to-work-in-monitoring-mode/</link>
      <pubDate>Thu, 21 Nov 2013 00:59:00 +0000</pubDate>
      
      <guid>/questions/27201/dont-want-to-work-in-monitoring-mode/</guid>
      <description>don&amp;rsquo;t want to work in monitoring mode  0 I have this problem. tried wiershark on two ubuntu OS and linux. And on both OS inactive monitoring what the problem is? WI-FI - ALFA AWUS036 Notebook Acer E1-351 Just saying, in monitoring mode, the map translated.
monitorasked 21 Nov &#39;13, 00:59
Sokolov Andrey
1●5●5●6
accept rate: 0%
And on both OS inactive monitoring
what does that mean??
(21 Nov &#39;13, 07:40) Kurt Knochner ♦Do you mean that you want to capture in monitor mode on your laptop, but on both Ubuntu Linux and whatever other Linux you&#39;re using monitor mode doesn&#39;t work?</description>
    </item>
    
    <item>
      <title>export SIP data packets from wireshark to excel</title>
      <link>/questions/27202/export-sip-data-packets-from-wireshark-to-excel/</link>
      <pubDate>Thu, 21 Nov 2013 01:06:00 +0000</pubDate>
      
      <guid>/questions/27202/export-sip-data-packets-from-wireshark-to-excel/</guid>
      <description>export SIP data packets from wireshark to excel  0 we need someone can give us solution (no issue if paid) to we can export all SIP data packets from wireshark to excel because we need to compare difference between packets, we need export each packet to one row in excel to sort it and can see where is the difference in SIP packets.
Thank you
wireshart export excelasked 21 Nov &#39;13, 01:06</description>
    </item>
    
    <item>
      <title>SMPP, tshark</title>
      <link>/questions/27208/smpp-tshark/</link>
      <pubDate>Thu, 21 Nov 2013 04:51:00 +0000</pubDate>
      
      <guid>/questions/27208/smpp-tshark/</guid>
      <description>SMPP, tshark  0 Hi, Our application receives an SMPP messages and sends Acknowledge to the network. We want to measure the time from SMPP Submit SM request till Submit SM response by using tshark. For this I want to extract all Submit SM requests and Submit SM responses with Sequence number and calculate an average of time differences for each pair. Because we need to send about 500 SMPP requests per second each tshark frame contains a few SMPP requests and not one.</description>
    </item>
    
    <item>
      <title>Build on Windows fails to find a file</title>
      <link>/questions/27209/build-on-windows-fails-to-find-a-file/</link>
      <pubDate>Thu, 21 Nov 2013 05:40:00 +0000</pubDate>
      
      <guid>/questions/27209/build-on-windows-fails-to-find-a-file/</guid>
      <description>Build on Windows fails to find a file  0 Hello,
I&#39;m trying to build Wireshark on a Windows 7 machine, but the build fails when I try to run the nmake -f Makefile.nmake all command. The error message is:
sed -e s/@[email protected]/1.10.3kp/ -e s/@[email protected]/1/ -e s/@[email protected]/10/ -e s/@[email protected]/3/ -e &amp;quot;s/@[email protected]/#define HAVE_C_ARES 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBZ 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBPCAP 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_FINDALLDEVS 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_DATALINK_NAME_TO_VAL 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_DATALINK_VAL_TO_NAME 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_DATALINK_VAL_TO_DESCRIPTION 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_REMOTE 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_REMOTE 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_OPEN 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_OPEN_DEAD 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_LIST_DATALINKS 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_FREE_DATALINKS 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_SET_DATALINK 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_PCAP_SETSAMPLING 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_BPF_IMAGE 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBGNUTLS 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBGCRYPT 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LUA1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LUA 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_AIRPCAP 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBPORTAUDIO 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_LIBSMI 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_GEOIP 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_GEOIP_V6 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_SOFTWARE_UPDATE 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define INET6 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define HAVE_NTDDNDIS_H 1/&amp;quot; -e &amp;quot;s/@[email protected]/#define PCAP_NG_DEFAULT 1/&amp;quot; -e &amp;quot;s/@[email protected]//&amp;quot; &amp;lt; config.</description>
    </item>
    
    <item>
      <title>capture ipad tcp udp traffic with wireshark</title>
      <link>/questions/27216/capture-ipad-tcp-udp-traffic-with-wireshark/</link>
      <pubDate>Thu, 21 Nov 2013 06:12:00 +0000</pubDate>
      
      <guid>/questions/27216/capture-ipad-tcp-udp-traffic-with-wireshark/</guid>
      <description>capture ipad tcp udp traffic with wireshark  0 hi
is it possible to capture ipad tcp udp traffic with wireshark
wiresharkasked 21 Nov &#39;13, 06:12
scara
31●9●9●14
accept rate: 0%
  
One Answer:
  
0yes
Regards
Kurt
answered 21 Nov &#39;13, 06:28
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15% 
May i know how for ipad
(21 Nov &#39;13, 06:51) scaraMay I know how your iPad is connected to the network (wifi, GSM/3G, etc.</description>
    </item>
    
    <item>
      <title>MAPI Unknown Operation 10 &amp;amp; 11 Request / Response</title>
      <link>/questions/27244/mapi-unknown-operation-10-11-request-response/</link>
      <pubDate>Thu, 21 Nov 2013 15:29:00 +0000</pubDate>
      
      <guid>/questions/27244/mapi-unknown-operation-10-11-request-response/</guid>
      <description>MAPI Unknown Operation 10 &amp;amp; 11 Request / Response  0 Hi Guys, I&#39;m trying to diagnose some performance issues on my network and I have captured a heap of unknown packets using WireShark. Google didn&#39;t reveal much apart from &#34;Wireshark might not know how to decode those packets&#34;
I did the capture on both the source and destination server to rule out corrupted packets. Source server has wireshark 1.10.3 and Destination server has wireshark 1.</description>
    </item>
    
    <item>
      <title>Understanding IP packet flow during a login process</title>
      <link>/questions/27251/understanding-ip-packet-flow-during-a-login-process/</link>
      <pubDate>Thu, 21 Nov 2013 22:13:00 +0000</pubDate>
      
      <guid>/questions/27251/understanding-ip-packet-flow-during-a-login-process/</guid>
      <description>Understanding IP packet flow during a login process  0 When analyzing a capture of a login, how do you determine how many IP packets were generated during the process of the login? I guess part of the answer would need to address how to determine which packets were part of the process so the question is probably better worded as: how are IP packets identified as part of the login?</description>
    </item>
    
    <item>
      <title>Under what conditions Wireshark marks a packet as TCP Window Update packet</title>
      <link>/questions/27253/under-what-conditions-wireshark-marks-a-packet-as-tcp-window-update-packet/</link>
      <pubDate>Thu, 21 Nov 2013 22:31:00 +0000</pubDate>
      
      <guid>/questions/27253/under-what-conditions-wireshark-marks-a-packet-as-tcp-window-update-packet/</guid>
      <description>Under what conditions Wireshark marks a packet as TCP Window Update packet  0 I understand the TCP window mechanism and that all ACK packets contain advertized Window size which keeps fluctuating. If so, why Wireshark marks certain packets as Window update packet and why is it important to observe? Changing Window sizes is not normal?
tcp_window_updateasked 21 Nov &#39;13, 22:31
xkgt
6●3●3●6
accept rate: 0%
 edited 22 Nov &#39;13, 02:45</description>
    </item>
    
    <item>
      <title>AMQP 1.0 dissector?</title>
      <link>/questions/27275/amqp-10-dissector/</link>
      <pubDate>Fri, 22 Nov 2013 06:01:00 +0000</pubDate>
      
      <guid>/questions/27275/amqp-10-dissector/</guid>
      <description>AMQP 1.0 dissector?  1 Hello, are there some plans to update AMQP dissector to be able to decode AMQP 1.0 version? That version has been accepted as OASIS standard year ago and it is supposed to be the industry standard in its area.
If there are no plans, could you please estimate how many mandays/manhours it might take to implement it? I might voluntee for it, knowing the protocol (up to some level) and knowing ANSI C.</description>
    </item>
    
    <item>
      <title>Encapsulation type value</title>
      <link>/questions/27279/encapsulation-type-value/</link>
      <pubDate>Fri, 22 Nov 2013 06:34:00 +0000</pubDate>
      
      <guid>/questions/27279/encapsulation-type-value/</guid>
      <description>Encapsulation type value  0 Hi,
I am trying to add my own Encapsulation type. I&#39;ve already wrote my dissector and done all steps needed to add an encapsulation value (as described here : http://ask.wireshark.org/questions/12660/where-to-find-documentation-of-writing-an-encapsulated-file-reader). Now what I want to know is frome where and who send the encapsulation value ?
Thanks
encapsulation typeasked 22 Nov &#39;13, 06:34
Afrim
160●10●11●16
accept rate: 22%
Thank you both for your answers.
Is there a way to avoid the call of any encapsulation and, instead, to call my dissector ?</description>
    </item>
    
    <item>
      <title>how to retrieve file from FTP</title>
      <link>/questions/27284/how-to-retrieve-file-from-ftp/</link>
      <pubDate>Fri, 22 Nov 2013 09:14:00 +0000</pubDate>
      
      <guid>/questions/27284/how-to-retrieve-file-from-ftp/</guid>
      <description>how to retrieve file from FTP  0 there is trace file that has captured some FTP traffic between a server and a host. i need to retrieve the files that were transferred during this FTP communication. i have found the files but i don&#39;t know how to retrieve them. Its a assignment :)
ftp capture wiresharkasked 22 Nov &#39;13, 09:14
lovey
1●1●1●1
accept rate: 0%
Its a assignment :)</description>
    </item>
    
    <item>
      <title>How to embed wireshark in a web browser</title>
      <link>/questions/27285/how-to-embed-wireshark-in-a-web-browser/</link>
      <pubDate>Fri, 22 Nov 2013 09:25:00 +0000</pubDate>
      
      <guid>/questions/27285/how-to-embed-wireshark-in-a-web-browser/</guid>
      <description>How to embed wireshark in a web browser  0 I would like to embed wireshark in a web browser in order to view message exchange on my webpage (running on a local machine) with packet filtering.
The basic aim is to integrate Operations and Management Webpage which controls a LTE eNodeB &amp;amp; wireshark.
embed firefox lteasked 22 Nov &#39;13, 09:25
Anish
11●1●1●2
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Conversations with DUP or Retransmission</title>
      <link>/questions/27294/conversations-with-dup-or-retransmission/</link>
      <pubDate>Fri, 22 Nov 2013 13:43:00 +0000</pubDate>
      
      <guid>/questions/27294/conversations-with-dup-or-retransmission/</guid>
      <description>Conversations with DUP or Retransmission  0 I read how to get a count of conversations - my next question is is there a way to count how many different conversations have DUP or TCP Retransmission packets in them?
dup-ack conversation retransmissionsasked 22 Nov &#39;13, 13:43
Platzen
11●1●1●3
accept rate: 0%
  
One Answer:
  
2There are several ways to do that. One fast and simple method is this:</description>
    </item>
    
    <item>
      <title>Wireshark only capturing incoming packets</title>
      <link>/questions/27296/wireshark-only-capturing-incoming-packets/</link>
      <pubDate>Fri, 22 Nov 2013 15:03:00 +0000</pubDate>
      
      <guid>/questions/27296/wireshark-only-capturing-incoming-packets/</guid>
      <description>Wireshark only capturing incoming packets  2 1On my Windows 7 laptop I can only capture incoming packets, nothing shows up in the outbound direction. I&#39;ve remove all firewall and VPN software installed on my system but it hasn&#39;t made any difference.
I get the same behaviour using wired or wireless NIC. Anyone have any suggestion of what I can try next?
inbound capture outgoing outboundasked 22 Nov &#39;13, 15:03</description>
    </item>
    
    <item>
      <title>Get packets byte from filter using command line</title>
      <link>/questions/27308/get-packets-byte-from-filter-using-command-line/</link>
      <pubDate>Sun, 24 Nov 2013 04:13:00 +0000</pubDate>
      
      <guid>/questions/27308/get-packets-byte-from-filter-using-command-line/</guid>
      <description>Get packets byte from filter using command line  0 I looking for command that after search for specific filter for example: tcp.port==80 the output will be the packet in byte.
until now i am using this command : tshark.exe -Y tcp.port==80 -n -r file.pcap and the output is only the packet details:
packet number 28.853596 192.0.16.37 -&amp;gt; 66.196.114.114 TCP 66 50580 &amp;gt; 5050 [SYN] Seq=0 Win=8192 Len=0 MSS=1460 WS=4 SACK_PERM=1tsharkasked 24 Nov &#39;13, 04:13</description>
    </item>
    
    <item>
      <title>I have a pcap file. how can I filter out those dropped package by the linux kernel?</title>
      <link>/questions/27309/i-have-a-pcap-file-how-can-i-filter-out-those-dropped-package-by-the-linux-kernel/</link>
      <pubDate>Sun, 24 Nov 2013 08:14:00 +0000</pubDate>
      
      <guid>/questions/27309/i-have-a-pcap-file-how-can-i-filter-out-those-dropped-package-by-the-linux-kernel/</guid>
      <description>I have a pcap file. how can I filter out those dropped package by the linux kernel?  0 Recently, I find one of my server face a drop package problem in a specific minute
netstat -in Kernel Interface table Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg bond0 1500 0 1418046670 0 743 0 1047132418 0 0 0 BMmRU bond1 1500 0 92980025302 3 79 0 54995070900 0 0 0 BMmRU eth0 1500 0 924882226 0 0 0 761949059 0 0 0 BMsRU eth1 1500 0 493164444 0 743 0 285183359 0 0 0 BMsRU eth4 1500 0 92979828163 3 79 0 54995070878 0 0 0 BMsRU eth5 1500 0 197139 0 0 0 22 0 0 0 BMsRU lo 16436 0 37524597 0 0 0 37524597 0 0 0 LRUI have use following tcpdump to capture the the eth1 traffic during that minute.</description>
    </item>
    
    <item>
      <title>sequence number in zero_window_probe</title>
      <link>/questions/27314/sequence-number-in-zero_window_probe/</link>
      <pubDate>Sun, 24 Nov 2013 10:01:00 +0000</pubDate>
      
      <guid>/questions/27314/sequence-number-in-zero_window_probe/</guid>
      <description>sequence number in zero_window_probe  0 Hello, need to have some experts look at this trace snippet showing a server sending a zero-window and the client sending probes with a 1 byte &#39;garbage&#39;.
I wonder whether the client sends a &#39;correct&#39; tcp.seq in its probes.
Here&#39;s the trace: zero_window_probe.pcapng sequencenumber zero-window tcp garbage zerowindowprobeasked 24 Nov &#39;13, 10:01
mrEEde
3.9k●15●22●70
accept rate: 20%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Performance Testing iperf</title>
      <link>/questions/27319/performance-testing-iperf/</link>
      <pubDate>Sun, 24 Nov 2013 11:41:00 +0000</pubDate>
      
      <guid>/questions/27319/performance-testing-iperf/</guid>
      <description>Performance Testing iperf  0 I am doing some performance testing using iperf between 2 Windows 2008 servers with a latency of around 80ms and a minimum available bandwidth of 200Mbps.
According to the following URL http://www.switch.ch/network/tools/tcp_throughput/ the optimal TCP window size should be around 2MB
required tcp buffer to reach 200 Mbps with RTT of 80.0 ms &amp;gt;= 2048.0 KByte
What throughput should I expect to see with this setting?</description>
    </item>
    
    <item>
      <title>Can I use Wireshark to monitor simple traffic usage?</title>
      <link>/questions/27322/can-i-use-wireshark-to-monitor-simple-traffic-usage/</link>
      <pubDate>Sun, 24 Nov 2013 12:32:00 +0000</pubDate>
      
      <guid>/questions/27322/can-i-use-wireshark-to-monitor-simple-traffic-usage/</guid>
      <description>Can I use Wireshark to monitor simple traffic usage?  0 My ISP provides a very questionable data usage tracking on it&#39;s website and I have been searching for alternatives, but so far have not been able to find one that is free and suitable for me.
With all the features of wireshark, is it possible to use it to simply monitor how much data I use up when I&#39;m online?</description>
    </item>
    
    <item>
      <title>SHUTR Protocol (Suppressed Headers for Uplink Traffic Reduction)</title>
      <link>/questions/27328/shutr-protocol-suppressed-headers-for-uplink-traffic-reduction/</link>
      <pubDate>Sun, 24 Nov 2013 17:07:00 +0000</pubDate>
      
      <guid>/questions/27328/shutr-protocol-suppressed-headers-for-uplink-traffic-reduction/</guid>
      <description>SHUTR Protocol (Suppressed Headers for Uplink Traffic Reduction)  0 Hello forum, I was trying to gather some info about Qualcomm&#39;s SHUTR protocol, and this is the only thing google threw back:
&#34;SHUTR is a HTTP protocol extension designed to reduce the size of HTTP request headers sent by a mobile user agent. SHUTR speeds up page downloads and reduces network data traffic, overall improving the mobile Web experience on Snapdragon processor-based devices.</description>
    </item>
    
    <item>
      <title>How to monitor trafic to google servers?</title>
      <link>/questions/27332/how-to-monitor-trafic-to-google-servers/</link>
      <pubDate>Mon, 25 Nov 2013 01:41:00 +0000</pubDate>
      
      <guid>/questions/27332/how-to-monitor-trafic-to-google-servers/</guid>
      <description>How to monitor trafic to google servers?  1 I can no longer use google search . It says that my network is sending automatic requests. I discovered wireshark and I want to ask if I can use it to know what computer (lan ip) is sending all this queries to google. Maybe it has a virus or something.
If It&#39;s possible to do this, how do I do it ?</description>
    </item>
    
    <item>
      <title>Is there a way to group ProtoFields In Lua?</title>
      <link>/questions/27334/is-there-a-way-to-group-protofields-in-lua/</link>
      <pubDate>Mon, 25 Nov 2013 02:12:00 +0000</pubDate>
      
      <guid>/questions/27334/is-there-a-way-to-group-protofields-in-lua/</guid>
      <description>Is there a way to group ProtoFields In Lua?  0 Given:
local foo_proto = Proto(,) local foo_fields = foo_proto.fieldsfoo_fields is a ProtoField[] (at least that is how I think of it)
Is there a way to define
foo_proto.messages where messages is a Message[]
And for each Message have Message.ProtoField[] fields
In other words I would like to structure field definitions, instead of having a flat/linear ProtoField definition
lua dissector protofieldasked 25 Nov &amp;lsquo;13, 02:12</description>
    </item>
    
    <item>
      <title>How are re-transmission and SACK packets displayed in tcptrace graph?</title>
      <link>/questions/27336/how-are-re-transmission-and-sack-packets-displayed-in-tcptrace-graph/</link>
      <pubDate>Mon, 25 Nov 2013 02:34:00 +0000</pubDate>
      
      <guid>/questions/27336/how-are-re-transmission-and-sack-packets-displayed-in-tcptrace-graph/</guid>
      <description>How are re-transmission and SACK packets displayed in tcptrace graph?  0 I have two captures (one with SACK and other one without SACK ). From tcptrace graph it is not clear how SACK feature affects the progress of sequence numbers. The graph is very hard to comprehend without any legends. And what are those dark black lines?
SACK enabled: Without SACK: P.S: The pictures are zoomed in versions of a larger capture file.</description>
    </item>
    
    <item>
      <title>Call_dissector?</title>
      <link>/questions/27337/call_dissector/</link>
      <pubDate>Mon, 25 Nov 2013 02:40:00 +0000</pubDate>
      
      <guid>/questions/27337/call_dissector/</guid>
      <description>Call_dissector?  0 Hello,
I&#39;m developing a plugin for Wireshark. I&#39;m trying to understand the 802.15.4 dissector and I would like to know, where is &#34;call_dissector&#34; function defined? And if it&#39;s possible to have a reference of the functions that Wireshark implements and where are defined?
Thanks,
802.15.4 dissector call wiresharkasked 25 Nov &#39;13, 02:40
lina
11●3●3●5
accept rate: 0%
 edited 25 Nov &#39;13, 06:23 
cmaynard ♦♦
9.4k●10●38●142</description>
    </item>
    
    <item>
      <title>Site changes: CAPTCHA ?</title>
      <link>/questions/27341/site-changes-captcha/</link>
      <pubDate>Mon, 25 Nov 2013 05:38:00 +0000</pubDate>
      
      <guid>/questions/27341/site-changes-captcha/</guid>
      <description>Site changes: CAPTCHA ?  1 I just had to fill in a CAPTCHA to be allowed to edit one of my answers (I was logged in)? Is this intentional? It kind of disturbs the workflow.
UPDATE: Strange. It only happens for the answer in one question !?!?
http://ask.wireshark.org/questions/27328/shutr-protocol-suppressed-headers-for-uplink-traffic-reduction
UPDATE
The CAPTCHA accepts even parts of the numbers !?! Looks like a bug in the CAPTCHA checking routine...
Anyway, if someone of the Admins could please check why there is a CAPTCHA only for that single answer of the following question, I would be thankful:</description>
    </item>
    
    <item>
      <title>Packet Loss? Upload problem?</title>
      <link>/questions/27342/packet-loss-upload-problem/</link>
      <pubDate>Mon, 25 Nov 2013 06:03:00 +0000</pubDate>
      
      <guid>/questions/27342/packet-loss-upload-problem/</guid>
      <description>Packet Loss? Upload problem?  0 Hi guys, I am not a expert in the subject but tomorrow I will meet up with the technicians of the internet provider where I live... There are more than 300 apartments in the same building over here and we used wired connection. The problem is the instability of our internet, it keeps going down every 5-10 min , it&#39;s terrible!! We complained about that and they said that it was because we are using Wi-Fi routers, which I believe it&#39;s not the case, so, everybody removed the routers and the Internet still terrible!</description>
    </item>
    
    <item>
      <title>Does Wireshark capture keystrokes across wifi network</title>
      <link>/questions/27347/does-wireshark-capture-keystrokes-across-wifi-network/</link>
      <pubDate>Mon, 25 Nov 2013 06:34:00 +0000</pubDate>
      
      <guid>/questions/27347/does-wireshark-capture-keystrokes-across-wifi-network/</guid>
      <description>Does Wireshark capture keystrokes across wifi network  0 Can wireshark be used as a keystroke logger for devices connected by wifi across the network
keystrokeasked 25 Nov &#39;13, 06:34
nathaniel
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Keystrokes are primarily transmitted between your keyboard and the chipset on your motherboard (keyboard controller).
There are only a few protocols where you actually transmit keystrokes over the network.</description>
    </item>
    
    <item>
      <title>How to use conversation without any port_type defined ports</title>
      <link>/questions/27354/how-to-use-conversation-without-any-port_type-defined-ports/</link>
      <pubDate>Mon, 25 Nov 2013 07:55:00 +0000</pubDate>
      
      <guid>/questions/27354/how-to-use-conversation-without-any-port_type-defined-ports/</guid>
      <description>How to use conversation without any port_type defined ports  0 Hello all,
I have my own protocol what lays direct over ethernet. My dissector gets called over an defined ethertype and here is the problem.
My protocol has a 4 x 8 bit header ... one field is a unique number.
The header looks like this ethernet [destination address(6)][source address(6)][ethertype(2)] my protocol [my protocol field one(1)][my protocol field two(1)][my protocol number(1)] [my protocol field four(1)]</description>
    </item>
    
    <item>
      <title>ask about lua scripting</title>
      <link>/questions/27356/ask-about-lua-scripting/</link>
      <pubDate>Mon, 25 Nov 2013 09:25:00 +0000</pubDate>
      
      <guid>/questions/27356/ask-about-lua-scripting/</guid>
      <description>ask about lua scripting  0 Hi guys, i have been working in a lua dissector for a private protocol
the protocol in the dump has a section with the return of the window&#39;s API GetSystemTimeAsFileTime in the form
6a 0e 2e c2 0c e2 ce 01
this is the value of the structure FILETIME
in the serve is decoded with
import datetime datetime.datetime.fromtimestamp((0xc22e0e6a + (0x01cee20c &amp;lt;&amp;lt; 32)) / 10000000.0 - 11644473600)</description>
    </item>
    
    <item>
      <title>How to pipe tshark output in realtime?</title>
      <link>/questions/27357/how-to-pipe-tshark-output-in-realtime/</link>
      <pubDate>Mon, 25 Nov 2013 10:56:00 +0000</pubDate>
      
      <guid>/questions/27357/how-to-pipe-tshark-output-in-realtime/</guid>
      <description>How to pipe tshark output in realtime?  0 Hi everyone,
I am monitoring wifi traffic and want to process every output line in real time.
Monitoring works:
sudo tshark -i mon0 subtype probereqSaving to a file works:
sudo tshark -i mon0 subtype probereq &amp;gt; pcap.logPiping file for processing works:
cat pcap.log | while read -r line; do echo &amp;quot;$line&amp;quot;; doneBut piping thark output directly just doesn&#39;t work:
sudo tshark -i mon0 subtype probereq | while read -r line; do echo &amp;quot;$line&amp;quot;; doneWhat&#39;s the problem?</description>
    </item>
    
    <item>
      <title>Remote Capture</title>
      <link>/questions/27358/remote-capture/</link>
      <pubDate>Mon, 25 Nov 2013 11:02:00 +0000</pubDate>
      
      <guid>/questions/27358/remote-capture/</guid>
      <description>Remote Capture  0 Does anyone know why Remote Capture will not work.
remote-captureasked 25 Nov &#39;13, 11:02
ScoRay
11●1●1●2
accept rate: 0%
To get any help other than &#34;it works for me&#34;, you&#39;ll need to give lots more details on what you&#39;re trying to do. Local Wireshark version and host OS, remote OS etc, and what errors if any you see.
(26 Nov &#39;13, 02:00) grahamb ♦It works for me ;-)</description>
    </item>
    
    <item>
      <title>Splitting conversations</title>
      <link>/questions/27363/splitting-conversations/</link>
      <pubDate>Mon, 25 Nov 2013 13:40:00 +0000</pubDate>
      
      <guid>/questions/27363/splitting-conversations/</guid>
      <description>Splitting conversations  0 Beside writing a script using tshark, what would you recommend to split a capture to have one capture per conversation, e.g. UDP, TCP, or Ethernet? Would it be possible to create a feature to split the opened capture into each of the conversations?
conversationasked 25 Nov &#39;13, 13:40
wnatter
1●1●1●2
accept rate: 0%
  
One Answer:
  
1If you insist on an unscripted, manual method through the GUI, easiest way right now would probably be:</description>
    </item>
    
    <item>
      <title>Capturing TCP Packets from another computer</title>
      <link>/questions/27367/capturing-tcp-packets-from-another-computer/</link>
      <pubDate>Mon, 25 Nov 2013 15:55:00 +0000</pubDate>
      
      <guid>/questions/27367/capturing-tcp-packets-from-another-computer/</guid>
      <description>Capturing TCP Packets from another computer  0 I&#39;m having a lot of trouble capturing TCP packets from another computer. I can see my TCP packets but not the packets from the other computers on my network. I have promiscuous mode on and feel like everything is up. Please don&#39;t send me a link to the page that shows the different switches. I&#39;ve gotten that so many times but I don&#39;t quite understand it.</description>
    </item>
    
    <item>
      <title>NBNS or LLMNR</title>
      <link>/questions/27368/nbns-or-llmnr/</link>
      <pubDate>Mon, 25 Nov 2013 16:16:00 +0000</pubDate>
      
      <guid>/questions/27368/nbns-or-llmnr/</guid>
      <description>NBNS or LLMNR  0 Is there a way to view what website was visited with either of these protocols?
llmnr nbnsasked 25 Nov &#39;13, 16:16
Brad6547884
11●2●2●3
accept rate: 0%
&#34;view what website was visited with either of these protocols?&#34; in what sense?
As per my comment below, there are a couple of different ways to interpret that, with different answers.
(28 Nov &#39;13, 13:53) Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>Export packets in &amp;quot;Decode as&amp;quot; format</title>
      <link>/questions/27371/export-packets-in-decode-as-format/</link>
      <pubDate>Mon, 25 Nov 2013 21:05:00 +0000</pubDate>
      
      <guid>/questions/27371/export-packets-in-decode-as-format/</guid>
      <description>Export packets in &amp;ldquo;Decode as&amp;rdquo; format  0 I&#39;m trying to export a packet capture, which is decoded as &#34;PEEKREMOTE&#34;. For example: tshark -r -d udp.port==5000,peekremote &amp;lt;file.pcap&amp;gt; ...and I&#39;d like to save/export the &#39;decoded version&#39; of file.pcap. Is that possible in either tshark or wireshark?
decode asasked 25 Nov &#39;13, 21:05
mike909
15●2●3●6
accept rate: 0%
  
2 Answers:
  
1 Is that possible in either tshark or wireshark?</description>
    </item>
    
    <item>
      <title>Two IP headers before data -- using jpcap</title>
      <link>/questions/27372/two-ip-headers-before-data-using-jpcap/</link>
      <pubDate>Tue, 26 Nov 2013 00:13:00 +0000</pubDate>
      
      <guid>/questions/27372/two-ip-headers-before-data-using-jpcap/</guid>
      <description>Two IP headers before data &amp;ndash; using jpcap  0 I am creating IP packets and sending them over ethernet. I am using jpcap library for it. When I analyze the packet using wireshark, it shows the protocol as eth:ip:ip, i.e. two IP headers followed by the data. So some of my data following the 1st IP header is treated as header itself!! This is creating a lot of trouble. This is bizzare, and I am not able to understand the reason behind it.</description>
    </item>
    
    <item>
      <title>How do I run a makefile such that it doesn&amp;#x27;t exit on error and continues the compilation of remaining files?</title>
      <link>/questions/27373/how-do-i-run-a-makefile-such-that-it-doesnt-exit-on-error-and-continues-the-compilation-of-remaining-files/</link>
      <pubDate>Tue, 26 Nov 2013 00:25:00 +0000</pubDate>
      
      <guid>/questions/27373/how-do-i-run-a-makefile-such-that-it-doesnt-exit-on-error-and-continues-the-compilation-of-remaining-files/</guid>
      <description>How do I run a makefile such that it doesn&amp;rsquo;t exit on error and continues the compilation of remaining files?  0 I have a makefile that I run and I do not want it to exit if there is an error during the compilation of a particular file. I want it to continue compiling other files. Is this possible? If yes how?
make makefile build linuxasked 26 Nov &#39;13, 00:25</description>
    </item>
    
    <item>
      <title>LUA Dissector is not run on retransmitted TCP segments</title>
      <link>/questions/27374/lua-dissector-is-not-run-on-retransmitted-tcp-segments/</link>
      <pubDate>Tue, 26 Nov 2013 01:18:00 +0000</pubDate>
      
      <guid>/questions/27374/lua-dissector-is-not-run-on-retransmitted-tcp-segments/</guid>
      <description>LUA Dissector is not run on retransmitted TCP segments  0 Hi,
I&#39;ve written a LUA dissector for a custom protocol which is working great, but I&#39;ve encountered an issue where if a packet is detected as a retransmission by Wireshark the dissector is not called, so these packets are not decoded and therefore missed when filtering for my protocol - despite the fact that they have been transmitted.
All the packets which are not decoded say &#34;</description>
    </item>
    
    <item>
      <title>How to make Wireshark tool support Protocol Buffers?</title>
      <link>/questions/27378/how-to-make-wireshark-tool-support-protocol-buffers/</link>
      <pubDate>Tue, 26 Nov 2013 01:34:00 +0000</pubDate>
      
      <guid>/questions/27378/how-to-make-wireshark-tool-support-protocol-buffers/</guid>
      <description>How to make Wireshark tool support Protocol Buffers?  0 Hello Sir, How to make Wireshark tool support Protocol Buffers? How to add my protobuf decoder into wireshark tool &amp;gt;&amp;gt; Analyze menu &amp;gt;&amp;gt; “Enabled Protocls&#34; dialog?
protocol buffers wiresharkasked 26 Nov &#39;13, 01:34
MartinXie
1●1●1●2
accept rate: 0%
  
2 Answers:
  
4From your many similar questions I assume you are talking about google protocol buffers. As thet project never aproched Wireshark or offered their code to us we have no knowledge of the dissector but in general if you have a plugin or a builtin dissector you nedd to complie it agains your verion of Wireshark or put the ready made plugin executable in the plugins directory (See help-Aabout-&amp;gt;folders) Not thet a plugin is only garanteed to work with the version of Wireshark it was built against.</description>
    </item>
    
    <item>
      <title>error: invalid use of incomplete type &amp;#x27;tvbuff_t</title>
      <link>/questions/27388/error-invalid-use-of-incomplete-type-tvbuff_t/</link>
      <pubDate>Tue, 26 Nov 2013 02:05:00 +0000</pubDate>
      
      <guid>/questions/27388/error-invalid-use-of-incomplete-type-tvbuff_t/</guid>
      <description>error: invalid use of incomplete type &amp;lsquo;tvbuff_t  0 I&#39;m trying to build an old dissector with the new wireshark source and I&#39;m facing this compilation problem and am not able to resolve it.
More log: packet-xxx.cpp:467:7: error: invalid use of incomplete type &#39;tvbuff_t {aka struct tvbuff}&#39; In file included from ../../epan/proto.h:51:0, from ../../epan/packet.h:29, from packet-xxx.cpp:51: ../../epan/tvbuff.h:64:8: error: forward declaration of &#39;tvbuff_t {aka struct tvbuff}&#39; make: *** [packet-xxx.lo] Error 1</description>
    </item>
    
    <item>
      <title>For what purpose the length field in Radius msg is shown in packet info</title>
      <link>/questions/27391/for-what-purpose-the-length-field-in-radius-msg-is-shown-in-packet-info/</link>
      <pubDate>Tue, 26 Nov 2013 02:18:00 +0000</pubDate>
      
      <guid>/questions/27391/for-what-purpose-the-length-field-in-radius-msg-is-shown-in-packet-info/</guid>
      <description>For what purpose the length field in Radius msg is shown in packet info  0 For Radius messages, the &#34;Info&#34; column shows the packet ID and length in packet list window, like: So just curious: Why is the length field displayed here? Is it of any special purpose to be here?
length radius displayasked 26 Nov &#39;13, 02:18
Weller
21●2●2●6
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Silent install/uninstal</title>
      <link>/questions/27392/silent-installuninstal/</link>
      <pubDate>Tue, 26 Nov 2013 02:33:00 +0000</pubDate>
      
      <guid>/questions/27392/silent-installuninstal/</guid>
      <description>Silent install/uninstal  0 How to do silent install/uninstall in a production environment of this application?
silentasked 26 Nov &#39;13, 02:33
Nitin
1●1●1●1
accept rate: 0%
  
One Answer:
  
0See the answer to a similar question
http://ask.wireshark.org/questions/1902/unable-to-install-uninstall-wireshark-silently
Solution: use the cli switch /S
Regards
Kurt
answered 26 Nov &#39;13, 02:54
Kurt Knochner ♦
24.8k●10●39●237
accept rate: 15% 
 edited 26 Nov &#39;13, 04:48</description>
    </item>
    
    <item>
      <title>Can Wireshark be made to analyze custom-created packets for an application?</title>
      <link>/questions/27393/can-wireshark-be-made-to-analyze-custom-created-packets-for-an-application/</link>
      <pubDate>Tue, 26 Nov 2013 02:42:00 +0000</pubDate>
      
      <guid>/questions/27393/can-wireshark-be-made-to-analyze-custom-created-packets-for-an-application/</guid>
      <description>Can Wireshark be made to analyze custom-created packets for an application?  0 I have created custom IP packets using Java jpcap library. The packet header and data are assigned 20 and 26 respectively. As data I am sending &#34;ABCDEFGHIJKLMNOPQRSTUVWXYZ&#34;. But when I analyze the packets using wireshark, it reads the 1st byte of the data, and treats it as a part of some upper layer header (say TCP!). Say the 1st IP data byte is 0x41 , i.</description>
    </item>
    
    <item>
      <title>Bad audio for alaw RTP</title>
      <link>/questions/27421/bad-audio-for-alaw-rtp/</link>
      <pubDate>Tue, 26 Nov 2013 05:57:00 +0000</pubDate>
      
      <guid>/questions/27421/bad-audio-for-alaw-rtp/</guid>
      <description>Bad audio for alaw RTP  0 Hi, I use Wireshark for SIP/RTP debugging and the player under Telephony menu reproduce alas RTP streams very bad. I&#39;m running Wireshark on OSX and tested all the releases, the issue started some month ago but I don&#39;t know after what.
Do someone have the same problem and a solution for that?
Thank you very Much
Matteo
player rtpasked 26 Nov &#39;13, 05:57</description>
    </item>
    
    <item>
      <title>Request Timed Out</title>
      <link>/questions/27431/request-timed-out/</link>
      <pubDate>Tue, 26 Nov 2013 07:16:00 +0000</pubDate>
      
      <guid>/questions/27431/request-timed-out/</guid>
      <description>Request Timed Out  0 Hello everyone. I am new to wireshark and i need help figuring some things out. i pinged www.mit.edu and i wrote down the details that appeared. Then i opened Wireshark, went to Analyze-&amp;gt;Display Filters and chose IP ADDRESS option. Then i wrote on &#39;&#39;filter string&#39;&#39; section the ip adress that appeared when i pinged www.mit.edu Then i pinged www.mit.edu again and i saw on wireshark the source, destination, protocol used etc.</description>
    </item>
    
    <item>
      <title>Foundry FDP Capture Filter</title>
      <link>/questions/27436/foundry-fdp-capture-filter/</link>
      <pubDate>Tue, 26 Nov 2013 09:56:00 +0000</pubDate>
      
      <guid>/questions/27436/foundry-fdp-capture-filter/</guid>
      <description>Foundry FDP Capture Filter  0 I have found a capture filter for CDP and was hoping this would work for FDP too. Can you help me find one that will work for FDP please. The CDP one which works is : ether[12:2] &amp;lt;= 1500 &amp;amp;&amp;amp; ether[14:2] == 0xAAAA &amp;amp;&amp;amp; ether[16:1] == 0x03 &amp;amp;&amp;amp; ether[17:2] == 0x0000 &amp;amp;&amp;amp; ether[19:1] == 0x0C &amp;amp;&amp;amp; ether[20:2] == 0x2000
thanks
Chris Chambers BBC London</description>
    </item>
    
    <item>
      <title>Problem with call_dissector() on fix?</title>
      <link>/questions/27437/problem-with-call_dissector-on-fix/</link>
      <pubDate>Tue, 26 Nov 2013 10:00:00 +0000</pubDate>
      
      <guid>/questions/27437/problem-with-call_dissector-on-fix/</guid>
      <description>Problem with call_dissector() on fix?  0 Hello,
from my protocol I call, depending on the data other protocols ... most of it eth or fix.
I made dissector handle
static dissector_handle_t data_handle_eth; static dissector_handle_t data_handle_fix;and used find_dissector on it.
data_handle_eth = find_dissector(&amp;quot;eth&amp;quot;); data_handle_fix = find_dissector(&amp;quot;fix&amp;quot;);when I do
 call_dissector(data_handle_eth, next_tvb, pinfo, tree)everything is fine. The data is decoded as eth. But when I do
 call_dissector(data_handle_fix, next_tvb, pinfo, tree)wireshark crashes with</description>
    </item>
    
    <item>
      <title>dumpcap invalid argument for port number</title>
      <link>/questions/27450/dumpcap-invalid-argument-for-port-number/</link>
      <pubDate>Tue, 26 Nov 2013 14:24:00 +0000</pubDate>
      
      <guid>/questions/27450/dumpcap-invalid-argument-for-port-number/</guid>
      <description>dumpcap invalid argument for port number  0 I&#39;ve tried this in different variations but every time it comes up with the same message &#34;Invalid argument: 5003&#34;
dumpcap -i en0 -f “dst port 5003 and src port 5003” -b duration:3600 -b files:25 -w fmpackets.cap
using in Mac OSX terminal.
capture-filter dumpcapasked 26 Nov &#39;13, 14:24
Dumpy
11●1●1●4
accept rate: 0%
 edited 26 Nov &#39;13, 14:33</description>
    </item>
    
    <item>
      <title>TCP Modbus RTU Data</title>
      <link>/questions/27452/tcp-modbus-rtu-data/</link>
      <pubDate>Tue, 26 Nov 2013 14:28:00 +0000</pubDate>
      
      <guid>/questions/27452/tcp-modbus-rtu-data/</guid>
      <description>TCP Modbus RTU Data  0 When monitoring Modbus TCP, Wireshark seems to attempt to break down the data. It incorrectly interprets an ieee float as two UINT16 values. What configuration controls how the datagram is dissected? Likewise when monitoring encapsulated or wrapped Modbus Rtu, the datagram shows the raw data. I have not figured out how to apply the correct data intrepretation within TCP.
Thanks
modbus datagram tcpasked 26 Nov &#39;13, 14:28</description>
    </item>
    
    <item>
      <title>How to Capture wireless traffic on a particular channel and access point?</title>
      <link>/questions/27463/how-to-capture-wireless-traffic-on-a-particular-channel-and-access-point/</link>
      <pubDate>Tue, 26 Nov 2013 22:52:00 +0000</pubDate>
      
      <guid>/questions/27463/how-to-capture-wireless-traffic-on-a-particular-channel-and-access-point/</guid>
      <description>How to Capture wireless traffic on a particular channel and access point?  0 I have been successful in capturing wireless traffic in monitor mode using the tcpdump -ni option and even decrypt the WEP traffic, using wireshark, on my network that I was monitoring. But my router was configured to AUTO option for the channel. While capturing this mode, am able to various other traffic along with mine. How do I capture traffic from only the AP that I want to monitor and also monitor a particular channel of it?</description>
    </item>
    
    <item>
      <title>How to decrypt WPA2-PSK captured traffic on Wireshark? What is the expected traffic to be captured in WPA2-PSK setup?</title>
      <link>/questions/27464/how-to-decrypt-wpa2-psk-captured-traffic-on-wireshark-what-is-the-expected-traffic-to-be-captured-in-wpa2-psk-setup/</link>
      <pubDate>Tue, 26 Nov 2013 22:58:00 +0000</pubDate>
      
      <guid>/questions/27464/how-to-decrypt-wpa2-psk-captured-traffic-on-wireshark-what-is-the-expected-traffic-to-be-captured-in-wpa2-psk-setup/</guid>
      <description>How to decrypt WPA2-PSK captured traffic on Wireshark? What is the expected traffic to be captured in WPA2-PSK setup?  0 HI,
I captured WPA2-PSK traffic on monitor mode on a Linux machine and tried decrypting the same on wireshark. I got the key giving the required credentials using the following link: http://www.wireshark.org/tools/wpa-psk.html. But still I dont see my trace file being decrypted.
wireless wpa-psk capture monitor-mode wiresharkasked 26 Nov &#39;13, 22:58</description>
    </item>
    
    <item>
      <title>2-way handshake</title>
      <link>/questions/27466/2-way-handshake/</link>
      <pubDate>Tue, 26 Nov 2013 23:05:00 +0000</pubDate>
      
      <guid>/questions/27466/2-way-handshake/</guid>
      <description>2-way handshake  0 While looking at packet captured from netscalar device found a strange 2 way handshake where first packet was syn followed by syn-ack but third packet was ack with psh bit set and had data in it.Can anyone explain this?
tcpasked 26 Nov &#39;13, 23:05
kishan pandey
221●28●29●36
accept rate: 28%
  
2 Answers:
  
3This is allowed for TCP. Depends on the specific application implementation, the 3rd packet is allowed to carry application level data.</description>
    </item>
    
    <item>
      <title>Dissector: calculate difference between timestamps in packets</title>
      <link>/questions/27471/dissector-calculate-difference-between-timestamps-in-packets/</link>
      <pubDate>Wed, 27 Nov 2013 00:42:00 +0000</pubDate>
      
      <guid>/questions/27471/dissector-calculate-difference-between-timestamps-in-packets/</guid>
      <description>Dissector: calculate difference between timestamps in packets  0 Hello guys,
My task is as following: i want to extend a custom dissector with the ability to calculate the difference between timestamps. Some packets contain a TLV containing a timestamp and whenever a timestamp TLV occurs after the first timestamp, the difference to the last timestamp should calculated and displayed.
I do not know yet how to store the values I am retrieving from packets so that i can reuse them at a later point of time.</description>
    </item>
    
    <item>
      <title>eth.addr filter ?</title>
      <link>/questions/27472/ethaddr-filter/</link>
      <pubDate>Wed, 27 Nov 2013 00:47:00 +0000</pubDate>
      
      <guid>/questions/27472/ethaddr-filter/</guid>
      <description>eth.addr filter ?  0 Hi, I am trying to use the eth.addr filter, i need to see only the comunication from and to this mac address i use the filter eth.addr==2c:39:96:54:89:48 but blank page... i have 2c:39:96:54:89:48 traffic, when i use sll.src.eth == 2c:39:96:54:89:48 i have a lot of packet.
I am using the version 1.10.3 of wireshark.
eth.addr ethernet sll cooked display-filterasked 27 Nov &#39;13, 00:47
Pouet-Lord
16●1●1●4</description>
    </item>
    
    <item>
      <title>filter on tcp stream duration</title>
      <link>/questions/27475/filter-on-tcp-stream-duration/</link>
      <pubDate>Wed, 27 Nov 2013 02:29:00 +0000</pubDate>
      
      <guid>/questions/27475/filter-on-tcp-stream-duration/</guid>
      <description>filter on tcp stream duration  0 Hi experts, Can we found out all tcp stream with total conversation duration of more than 10 seconds.
follow.tcp.stream tcpasked 27 Nov &#39;13, 02:29
kishan pandey
221●28●29●36
accept rate: 28%
  
One Answer:
  
1You could use the Statistics -&amp;gt; Conversations menu option, go to the TCP tab and sort by &#34;Duration&#34; column to see the long ones. Then use the popup menu on each row to filter on it if you like, or use the &#34;</description>
    </item>
    
    <item>
      <title>How to graph the modulation scheme of an AP</title>
      <link>/questions/27481/how-to-graph-the-modulation-scheme-of-an-ap/</link>
      <pubDate>Wed, 27 Nov 2013 03:41:00 +0000</pubDate>
      
      <guid>/questions/27481/how-to-graph-the-modulation-scheme-of-an-ap/</guid>
      <description>How to graph the modulation scheme of an AP  0 So I have crated a network on ns-3 as part of a college assignment, this network consists of a node that moves at 1m/s and an access point, the application writes a pcap file for me that captures all the traffic. I have been able to graph the evolution of the throughput received by the client vs. time but the final part of the assignment is to graph how the modulation scheme of the AP changes through time.</description>
    </item>
    
    <item>
      <title>add error with bignumbers in lua</title>
      <link>/questions/27489/add-error-with-bignumbers-in-lua/</link>
      <pubDate>Wed, 27 Nov 2013 06:24:00 +0000</pubDate>
      
      <guid>/questions/27489/add-error-with-bignumbers-in-lua/</guid>
      <description>add error with bignumbers in lua  0 Hi guys, i have a problems doing the operation add with numbers of 64 bits
the following code return a incorrect value:
report_failure(string.format(&amp;quot;%16x&amp;quot;, ((0xfefefefe * math.pow(2,32))+0xabababab)))this code should be return a window with the value fefefefeabababab, but return fefefefeababa800
any idea?
lua math errorasked 27 Nov &#39;13, 06:24
Javier Aguinaga
11●2●2●4
accept rate: 0%
 edited 27 Nov &#39;13, 06:34</description>
    </item>
    
    <item>
      <title>Can Wireshark be installed on multiple computers with the license it comes with</title>
      <link>/questions/27500/can-wireshark-be-installed-on-multiple-computers-with-the-license-it-comes-with/</link>
      <pubDate>Wed, 27 Nov 2013 07:57:00 +0000</pubDate>
      
      <guid>/questions/27500/can-wireshark-be-installed-on-multiple-computers-with-the-license-it-comes-with/</guid>
      <description>Can Wireshark be installed on multiple computers with the license it comes with  0 I&#39;m testing Wireshark and before I buy it I want to make sure I can use it at our multiple locations. Does the license allow this?
licenseasked 27 Nov &#39;13, 07:57
jrsitman
11●1●1●2
accept rate: 0%
 edited 27 Nov &#39;13, 08:18 
Gerald Combs ♦♦
3.3k●9●22●58
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Wireshark doesn&amp;#x27;t show outbound traffic</title>
      <link>/questions/27505/wireshark-doesnt-show-outbound-traffic/</link>
      <pubDate>Wed, 27 Nov 2013 10:48:00 +0000</pubDate>
      
      <guid>/questions/27505/wireshark-doesnt-show-outbound-traffic/</guid>
      <description>Wireshark doesn&amp;rsquo;t show outbound traffic  0 Hi All,
My wireshark, for somne reason, is not showing the outbound traffic of m machine. I can see the answers coming from the destinations.
Do you have any idea?
Best Regards, Karl Müller
outgoing outboundasked 27 Nov &#39;13, 10:48
Karl Rogers ...
1●1●1●1
accept rate: 0%
 edited 15 Jan &#39;14, 07:09 
Kurt Knochner ♦
24.8k●10●39●237
Wired or wireless, which OS?</description>
    </item>
    
    <item>
      <title>How do I view a raw HTTP request/response?</title>
      <link>/questions/27515/how-do-i-view-a-raw-http-requestresponse/</link>
      <pubDate>Wed, 27 Nov 2013 15:43:00 +0000</pubDate>
      
      <guid>/questions/27515/how-do-i-view-a-raw-http-requestresponse/</guid>
      <description>How do I view a raw HTTP request/response?  0 Given an HTTP request/response in the packet list, how do I copy the raw data for it?
I can see that I can click on it, and the &#34;packet bytes&#34; shows me some stuff, but it&#39;s not what I want. It shows me a hex representation of the bytes, and the textual representation in another two columns. I can&#39;t use a simple regex to filter out the useless hex representation, since the textual representation is incomplete: some characters, such as newlines, are replaced with periods.</description>
    </item>
    
    <item>
      <title>Capture traffic on iPhone connected to PC thru USB hotspot interface</title>
      <link>/questions/27519/capture-traffic-on-iphone-connected-to-pc-thru-usb-hotspot-interface/</link>
      <pubDate>Wed, 27 Nov 2013 21:39:00 +0000</pubDate>
      
      <guid>/questions/27519/capture-traffic-on-iphone-connected-to-pc-thru-usb-hotspot-interface/</guid>
      <description>Capture traffic on iPhone connected to PC thru USB hotspot interface  0 I want to monitor network traffic on a laptop connected to an iPhone via iPhone&#39;s hotspot USB interface. Is Wireshark up to the job and in that case: how do I configure the interface in the Wireshark application?
usb traffic network hotspot iphoneasked 27 Nov &#39;13, 21:39
Caragoli
11●1●1●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Where I should start to learn WIRESHARK ? [Basic Question]</title>
      <link>/questions/27522/where-i-should-start-to-learn-wireshark-basic-question/</link>
      <pubDate>Thu, 28 Nov 2013 01:04:00 +0000</pubDate>
      
      <guid>/questions/27522/where-i-should-start-to-learn-wireshark-basic-question/</guid>
      <description>Where I should start to learn WIRESHARK ? [Basic Question]  0 Where I should start to learn WireShark ?
What all are I should want know to learn WireShark ?
beginner wiresharkasked 28 Nov &#39;13, 01:04
Kumar P
11●1●1●3
accept rate: 0%
 edited 28 Nov &#39;13, 01:05 
  
One Answer:
  
0Take a look here: http://ask.wireshark.org/questions/19980/how-to-study-to-use-wireshark
answered 28 Nov &#39;13, 02:15
Jasper ♦♦</description>
    </item>
    
    <item>
      <title>i&amp;#x27;am use libwireshark 1.10.3,i find memory leak</title>
      <link>/questions/27523/iam-use-libwireshark-1103i-find-memory-leak/</link>
      <pubDate>Thu, 28 Nov 2013 01:18:00 +0000</pubDate>
      
      <guid>/questions/27523/iam-use-libwireshark-1103i-find-memory-leak/</guid>
      <description>i&amp;rsquo;am use libwireshark 1.10.3,i find memory leak  0 i&#39;am use libwireshark 1.10.3,i find memory leak，is it any question with my program
XJ_DISSECT_PKT* xj_dissect_packet() { #ifdef XJ_DISSECT_PACKET_LINUX_DEF if (!g_xj_process_policies_called) { init_process_policies();//初始化本地权限 g_xj_process_policies_called = true; } #endif if(!g_binitepan) { epan_init(register_all_protocols, register_all_protocol_handoffs, NULL, NULL, NULL, NULL, NULL, NULL); cleanup_dissection();//clean up environment init_dissection();//init dissect environment g_binitepan = true; //tap_queue_init(&amp;amp;amp;edt);//队列 } frame_data *fdata; epan_dissect_t *edt; wtap_pkthdr pseudo_header; pseudo_header.interface_id = 0; pseudo_header.caplen = 0; pseudo_header.len = -1; pseudo_header.</description>
    </item>
    
    <item>
      <title>not included monitor mode</title>
      <link>/questions/27524/not-included-monitor-mode/</link>
      <pubDate>Thu, 28 Nov 2013 02:06:00 +0000</pubDate>
      
      <guid>/questions/27524/not-included-monitor-mode/</guid>
      <description>not included monitor mode  0 now, here by-step instruction on how I do it
wi-fi:alfa awus036h
step 1: catch the traffic going through wlan1
-iwconfig
-airmon-ng start wlan1
http://savepic.net/3980106.htm
step 2: due to the fact that under the root wireshark wrote a mistake made the following
http://securityblog.gr/1195/run-wireshark-as-a-user-rather-than-root-ubuntu/
step 3: -wiershark (run from normal user)
when I choose the mon0 or wlan1 generates an error:
http://savepic.net/3950410.htm http://savepic.net/3970890.htm
then try to turn on the monitor mode it gives me an error(see screenshot 2)</description>
    </item>
    
    <item>
      <title>In which layer wireshark exactly captures the packets ?</title>
      <link>/questions/27546/in-which-layer-wireshark-exactly-captures-the-packets/</link>
      <pubDate>Thu, 28 Nov 2013 21:03:00 +0000</pubDate>
      
      <guid>/questions/27546/in-which-layer-wireshark-exactly-captures-the-packets/</guid>
      <description>In which layer wireshark exactly captures the packets ?  0 I am having a small question regarding wireshark , In which Layer wireshark works.
I.e , on which Layer wireshark capturing the data ?
Because I am not getting Ethernet header checksum in my capture , Any Idea ?
Thanks
ethernet captureasked 28 Nov &#39;13, 21:03
si98765
11●1●1●5
accept rate: 0%
 edited 28 Nov &#39;13, 21:07</description>
    </item>
    
    <item>
      <title>Win7: Network traffic blocked although firewall off?</title>
      <link>/questions/27549/win7-network-traffic-blocked-although-firewall-off/</link>
      <pubDate>Fri, 29 Nov 2013 00:47:00 +0000</pubDate>
      
      <guid>/questions/27549/win7-network-traffic-blocked-although-firewall-off/</guid>
      <description>Win7: Network traffic blocked although firewall off?  0 Hi,
I&#39;ve been using an application for receiving UDP packets from a network device. The app is written by myself. It&#39;s been working fine on Windows XP for years. I had to switch to Win7 a couple of weeks ago. Suddenly receiving those packets does not work that well anymore. I mean it does now and then, but not at 100%. Lots of packets seem to get lost or blocked by something.</description>
    </item>
    
    <item>
      <title>IPP request [Malformed Packet]</title>
      <link>/questions/27553/ipp-request-malformed-packet/</link>
      <pubDate>Fri, 29 Nov 2013 03:34:00 +0000</pubDate>
      
      <guid>/questions/27553/ipp-request-malformed-packet/</guid>
      <description>IPP request [Malformed Packet]  0 Hello,
I have this problem. When I&#39;m capturing my wlan0 interface with Wireshark(I&#39;m sending print job with IPP protocol), IPP comunication is normal except sending print job (all requests/responses are normal (Get-Job-Attributes, Get-Printer-Attributes, Create-Job) except sending data file (print job)). I can&#39;t see (in this entry) content of the print job, version of IPP is 90.100, Operation-id: Unknown (0x656c) and Request ID: 1869894446. I have in Wireshark more then 20 entries like this (IPP request [Malformed Packet] entries with these wrong values).</description>
    </item>
    
    <item>
      <title>Relation between window full, Zero window and PUSH?</title>
      <link>/questions/27556/relation-between-window-full-zero-window-and-push/</link>
      <pubDate>Fri, 29 Nov 2013 04:38:00 +0000</pubDate>
      
      <guid>/questions/27556/relation-between-window-full-zero-window-and-push/</guid>
      <description>Relation between window full, Zero window and PUSH?  0 Hi all
First question here :-)
I have been struggling with a capture that I do not fully understand.
I see quite a few &#34;window is full&#34; and &#34;zero window&#34; in the expert info, and a lot of PSH flags set in the trace itself, and I am wondering if there is a connection between the observations. (see attached screen dump)</description>
    </item>
    
    <item>
      <title>CDR app ID support</title>
      <link>/questions/27575/cdr-app-id-support/</link>
      <pubDate>Fri, 29 Nov 2013 12:53:00 +0000</pubDate>
      
      <guid>/questions/27575/cdr-app-id-support/</guid>
      <description>CDR app ID support  0 Hi,
In the development version (1.11.2) CDR decoding for &#34;Data record format version: AppId 1 Rel 10.7.0&#34; does not decode properly. CDRs under AppId Rel 9.5.0 are decoded correctly.
Is this a bug? or AppId 10.7.0 not supported?
Thx
Jean.-
gtp prime cdrasked 29 Nov &#39;13, 12:53
jsarante
1●2●2●2
accept rate: 0%
Does the current 1.10 version decode them correctly?
(29 Nov &#39;13, 18:52) Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>How to see IP to MAC mapping from a trace</title>
      <link>/questions/27577/how-to-see-ip-to-mac-mapping-from-a-trace/</link>
      <pubDate>Fri, 29 Nov 2013 16:26:00 +0000</pubDate>
      
      <guid>/questions/27577/how-to-see-ip-to-mac-mapping-from-a-trace/</guid>
      <description>How to see IP to MAC mapping from a trace  0 Hi, this is my first post here.
I have a trace I&#39;m analyzing, and I need to extract a list of all ip addresses with the corresponding mac addresses. Or the other way around, either way is fine.
Thank you, Michael
ip mac mapping toasked 29 Nov &#39;13, 16:26
MichaelSB
16●1●1●4
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>What should I do to transform the captured pcap data into the CSV format including Timestamp, protocol and packet_length?</title>
      <link>/questions/27583/what-should-i-do-to-transform-the-captured-pcap-data-into-the-csv-format-including-timestamp-protocol-and-packet_length/</link>
      <pubDate>Fri, 29 Nov 2013 22:58:00 +0000</pubDate>
      
      <guid>/questions/27583/what-should-i-do-to-transform-the-captured-pcap-data-into-the-csv-format-including-timestamp-protocol-and-packet_length/</guid>
      <description>What should I do to transform the captured pcap data into the CSV format including Timestamp, protocol and packet_length?  0 Please help me. Thanks in advance!!!
tsharkasked 29 Nov &#39;13, 22:58
Eliza Rana
11●4●5●8
accept rate: 0%
  
One Answer:
  
2If you only want the timestamp, protocol and packet length, then one way would be to first configure your columns so that only those columns of interest are shown (done via Edit -&amp;gt; Preferences -&amp;gt; Columns), and then use File -&amp;gt; Export Packet Dissections -&amp;gt; as &#34;</description>
    </item>
    
    <item>
      <title>Plot time-series graph for number of TCP packets per 1 second. The X-axis should start with zero.</title>
      <link>/questions/27584/plot-time-series-graph-for-number-of-tcp-packets-per-1-second-the-x-axis-should-start-with-zero/</link>
      <pubDate>Fri, 29 Nov 2013 23:20:00 +0000</pubDate>
      
      <guid>/questions/27584/plot-time-series-graph-for-number-of-tcp-packets-per-1-second-the-x-axis-should-start-with-zero/</guid>
      <description>Plot time-series graph for number of TCP packets per 1 second. The X-axis should start with zero.  0 Anyone know how to do this, please help me. You can answer with any programming language such as Java, or programming R. Thank you in advance!!!
rasked 29 Nov &#39;13, 23:20
Eliza Rana
11●4●5●8
accept rate: 0%
  
One Answer:
  
2You can answer with any programming language</description>
    </item>
    
    <item>
      <title>wireshark in linux and ubuntu</title>
      <link>/questions/27586/wireshark-in-linux-and-ubuntu/</link>
      <pubDate>Sat, 30 Nov 2013 09:16:00 +0000</pubDate>
      
      <guid>/questions/27586/wireshark-in-linux-and-ubuntu/</guid>
      <description>wireshark in linux and ubuntu  0 sir i want to capture traffic using wireshark and i dnt know how to install or start it in linux or ubuntu
linuxasked 30 Nov &#39;13, 09:16
shaziya islam
11●4●4●5
accept rate: 0%
  
One Answer:
  
0Installing Wireshark may be different on different Linux flavors, depending on their packet management. With Ubuntu, you could use the Software Management tool, or install as root from a command line by entering</description>
    </item>
    
    <item>
      <title>decrypting SIP packets sometimes not shown packets from/to endpoint</title>
      <link>/questions/27590/decrypting-sip-packets-sometimes-not-shown-packets-fromto-endpoint/</link>
      <pubDate>Sat, 30 Nov 2013 15:02:00 +0000</pubDate>
      
      <guid>/questions/27590/decrypting-sip-packets-sometimes-not-shown-packets-fromto-endpoint/</guid>
      <description>decrypting SIP packets sometimes not shown packets from/to endpoint  0 Hi All,
I have a problem when time to time wireshark decrypted only partial sip flow. And sometimes decrypted full flow. Such change in decryption happens randomly and I need to know what is wrong when wireshark can&#39;t decrypt full flow. For example on following capture sip session (call) started from 4418 packet - on this packet Originator sent INVITE to SIP PROXY but INVITE from SIP PROXY to Terminator wasn&#39;t decrypted.</description>
    </item>
    
    <item>
      <title>Decoding LTE (RRC, PDCP, etc)</title>
      <link>/questions/27602/decoding-lte-rrc-pdcp-etc/</link>
      <pubDate>Sun, 01 Dec 2013 04:29:00 +0000</pubDate>
      
      <guid>/questions/27602/decoding-lte-rrc-pdcp-etc/</guid>
      <description>Decoding LTE (RRC, PDCP, etc)  0 I&#39;m new to Wireshark and I hope that someone can tell me what I shall do to be able to decode LTE control signaling (headers: RRC, PDCP, etc).
I like to use Wireshark to decode the LTE signaling between eNodeB and UE for which I develope the software myself (i.e. I&#39;m not sending data via the air interface. The signaling from eNodeB to UE is going from one network card to another using two Linux machines).</description>
    </item>
    
    <item>
      <title>JSON response full of dots &amp;quot;.&amp;quot; after &amp;#x27;Follow TCP Stream&amp;#x27;</title>
      <link>/questions/27607/json-response-full-of-dots-after-follow-tcp-stream/</link>
      <pubDate>Sun, 01 Dec 2013 08:32:00 +0000</pubDate>
      
      <guid>/questions/27607/json-response-full-of-dots-after-follow-tcp-stream/</guid>
      <description>JSON response full of dots &amp;ldquo;.&amp;rdquo; after &amp;lsquo;Follow TCP Stream&amp;rsquo;  0 I&#39;m trying to follow a JSON response but it shows it offuscated, this is the full Raw TCP Stream Wireshark is showing me:
GET /api/v1/dependencies?gems=boolean_class,bundler,rake HTTP/1.1 Accept-Encoding: gzip;q=1.0,deflate;q=0.6,identity;q=0.3 Accept: */* User-Agent: bundler/1.5.0.rc.1 rubygems/2.1.11 ruby/2.0.0 (x86_64-unknown-linux-gnu) command/install 273d73b77583ab06 Connection: keep-alive Keep-Alive: 30 Host: 127.0.1.1:3132 HTTP/1.1 200 OK Content-Type: text/html;charset=utf-8 X-Powered-By: geminabox 0.12.1 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Content-Length: 750</description>
    </item>
    
    <item>
      <title>Follow HTTP redirects automatically (HTTP status codes 301/302)</title>
      <link>/questions/27616/follow-http-redirects-automatically-http-status-codes-301302/</link>
      <pubDate>Sun, 01 Dec 2013 11:31:00 +0000</pubDate>
      
      <guid>/questions/27616/follow-http-redirects-automatically-http-status-codes-301302/</guid>
      <description>Follow HTTP redirects automatically (HTTP status codes 301/302)  0 In the same way &#34;Follow TCP Stream&#34; joins packets for easier analysis.
Is there a way to follow HTTP redirects without doing it manually?
redirects httpasked 01 Dec &#39;13, 11:31
elgalu
21●2●2●7
accept rate: 0%
 edited 01 Dec &#39;13, 11:32 
  
One Answer:
  
1 Is there a way to follow HTTP redirects without doing it manually?</description>
    </item>
    
    <item>
      <title>Suspected retransmission with differently sized segment</title>
      <link>/questions/27617/suspected-retransmission-with-differently-sized-segment/</link>
      <pubDate>Sun, 01 Dec 2013 12:46:00 +0000</pubDate>
      
      <guid>/questions/27617/suspected-retransmission-with-differently-sized-segment/</guid>
      <description>Suspected retransmission with differently sized segment  0 Is TCP allowed to retransmit, using a segment that is different (larger) from the original segment?
From a Wireshark capture I see a TCP segment which presumably is not ACK:ed within time so a retransmission is made but this time with a slightly larger payload?!? Both segments are ACK:ed separetly (one with SACK). I&#39;m pretty sure that it is only the larger packet that is picked up at the application layer.</description>
    </item>
    
    <item>
      <title>All packets received are tagged with errors</title>
      <link>/questions/27619/all-packets-received-are-tagged-with-errors/</link>
      <pubDate>Sun, 01 Dec 2013 14:42:00 +0000</pubDate>
      
      <guid>/questions/27619/all-packets-received-are-tagged-with-errors/</guid>
      <description>All packets received are tagged with errors  0 Hi, I&#39;m trying to examine packet loss of tcp of wireless. I start a capture and filter the results with the express &#34;ip.addr=={my ip address} and tcp&#34;. This works, but every packet displayed shows some sort of error in it (TCP checksum incorrect, Malformed packet, TCP previous segment not captured, etc). I have yet to see a packet come through with out any of these tags.</description>
    </item>
    
    <item>
      <title>What is the filter to extract TCP packets? (in wireshark)</title>
      <link>/questions/27637/what-is-the-filter-to-extract-tcp-packets-in-wireshark/</link>
      <pubDate>Sun, 01 Dec 2013 22:10:00 +0000</pubDate>
      
      <guid>/questions/27637/what-is-the-filter-to-extract-tcp-packets-in-wireshark/</guid>
      <description>What is the filter to extract TCP packets? (in wireshark)  0 Anyone knows, please tell me. Your help is highly appreciated.
tcppackets tshark tcp wiresharkasked 01 Dec &#39;13, 22:10
Eliza Rana
11●4●5●8
accept rate: 0%
 edited 01 Dec &#39;13, 22:19 
  
2 Answers:
  
1You can use tshark as following on Linux/OSX:
tshark -R &amp;quot;tcp&amp;quot; -r [path-to-file]or if your on Windwos and tshark is not in your path open Command Prompt aka CMD:</description>
    </item>
    
    <item>
      <title>How to debug tshark with exception offset</title>
      <link>/questions/27645/how-to-debug-tshark-with-exception-offset/</link>
      <pubDate>Sun, 01 Dec 2013 23:38:00 +0000</pubDate>
      
      <guid>/questions/27645/how-to-debug-tshark-with-exception-offset/</guid>
      <description>How to debug tshark with exception offset  0 When I debug my version of tshark, warnings showed as below.I want to find the line of code where warnings come out, and wonder know how to do?
** (tshark.exe:22940): WARNING **: Dissector bug, protocol HTTP, in packet 64084 : STATUS_ACCESS_VIOLATION: dissector accessed an invalid memory address 140790 ** (tshark.exe:22940): WARNING **: Dissector bug, protocol HTTP, in packet 14106 3: STATUS_ACCESS_VIOLATION: dissector accessed an invalid memory address 149454 ** (tshark.</description>
    </item>
    
    <item>
      <title>A Question regarding weird Duplicate ICMP response</title>
      <link>/questions/27647/a-question-regarding-weird-duplicate-icmp-response/</link>
      <pubDate>Mon, 02 Dec 2013 00:53:00 +0000</pubDate>
      
      <guid>/questions/27647/a-question-regarding-weird-duplicate-icmp-response/</guid>
      <description>A Question regarding weird Duplicate ICMP response  0 Hi Guys,
I tried to use winpcap to write a software running on PC (with 2 ethernet cards) to emulate a NAT. In that way, I could use a pesudo external IP address to access an internal IP. The architecture is as attached graph. However when I tried to ping the pesudo external IP address, I always get a lot of DUPLICATE ICMP response, does anyone knows why is that?</description>
    </item>
    
    <item>
      <title>how can i get congestion window from traces</title>
      <link>/questions/27648/how-can-i-get-congestion-window-from-traces/</link>
      <pubDate>Mon, 02 Dec 2013 01:07:00 +0000</pubDate>
      
      <guid>/questions/27648/how-can-i-get-congestion-window-from-traces/</guid>
      <description>how can i get congestion window from traces  0 i have wireshark trace of uploading a file and i want to know congestion window at different times how can i know this??
network tcpasked 02 Dec &#39;13, 01:07
sync2013
11●1●1●4
accept rate: 0%
  
2 Answers:
  
1If you mean CWND by &#39;congestion window&#39; as defined in RFC 2581, the answer to your question is: You can&#39;t &#39;get&#39; that value directly from the capture file, as it is not advertized.</description>
    </item>
    
    <item>
      <title>how to understand out-of-order TCP segments?</title>
      <link>/questions/27662/how-to-understand-out-of-order-tcp-segments/</link>
      <pubDate>Mon, 02 Dec 2013 07:29:00 +0000</pubDate>
      
      <guid>/questions/27662/how-to-understand-out-of-order-tcp-segments/</guid>
      <description>how to understand out-of-order TCP segments?  1 1Hi, I would like to know the meaning of out-of-order TCP segments in wireshark with the following question
What would make wireshark mark a segment as out-of-order?IP layer should re-order IP packets correctly and then give them to TCP, why could out-of-order occur?Does out-of-order always mean bad things?What should we do when we see out-of-order TCP segments, especially when there are lots of them.</description>
    </item>
    
    <item>
      <title>How to present dissected packet information on the Wireshark GUI?</title>
      <link>/questions/27667/how-to-present-dissected-packet-information-on-the-wireshark-gui/</link>
      <pubDate>Mon, 02 Dec 2013 10:03:00 +0000</pubDate>
      
      <guid>/questions/27667/how-to-present-dissected-packet-information-on-the-wireshark-gui/</guid>
      <description>How to present dissected packet information on the Wireshark GUI?  0 I would like to write a dissector to capture and parse a particular protocol, and update information on the Wireshark main window display; e.g., Source, Destination, and Info columns, and expand information in the Packet Details pane. How do I present the dissected packet information on the Wireshark GUI?
gui dissectorasked 02 Dec &#39;13, 10:03
Tinker
21●3●3●7
accept rate: 100%</description>
    </item>
    
    <item>
      <title>wireshark 1.10 Compile error in windows 7 x64</title>
      <link>/questions/27681/wireshark-110-compile-error-in-windows-7-x64/</link>
      <pubDate>Mon, 02 Dec 2013 17:05:00 +0000</pubDate>
      
      <guid>/questions/27681/wireshark-110-compile-error-in-windows-7-x64/</guid>
      <description>wireshark 1.10 Compile error in windows 7 x64  0 Hello everyone, I&#39;d been trying to build the wireshark 1.10 release in windows 7 x64 following the Step-by-Step Guide in order to (later) apply a patch for a USB dissector that I have found in the web.
Before I even applied the patch I tried to compile from the clean sources just to see if it works, which unfortunately didn&#39;t. The first error encountered is from the CRLF behavior of cygwin bash.</description>
    </item>
    
    <item>
      <title>Cannot run Wireshark on Mac OS Mavericks</title>
      <link>/questions/27683/cannot-run-wireshark-on-mac-os-mavericks/</link>
      <pubDate>Mon, 02 Dec 2013 18:35:00 +0000</pubDate>
      
      <guid>/questions/27683/cannot-run-wireshark-on-mac-os-mavericks/</guid>
      <description>Cannot run Wireshark on Mac OS Mavericks  0 I&#39;ve installed Wireshark on Mac OS Maverics and cannot run it - it displays the window which asks for the X11 the list does not contain anything similar to it. There is the button &#34;Browse&#34; but I do not know what should I browse for.
I&#39;ve installed Wireshark, then XQuarz, then reinstalled both and still have this issue.
macosx mavericksasked 02 Dec &#39;13, 18:35</description>
    </item>
    
    <item>
      <title>Tshark stops output redirection on Linux</title>
      <link>/questions/27688/tshark-stops-output-redirection-on-linux/</link>
      <pubDate>Mon, 02 Dec 2013 23:03:00 +0000</pubDate>
      
      <guid>/questions/27688/tshark-stops-output-redirection-on-linux/</guid>
      <description>Tshark stops output redirection on Linux  0 Hello!
I&#39;m trying to capture traffic with applying tshark filters in realtime.
#Capturing command is the following: tshark -i eth6 -i eth7 -R &amp;#39;(tcp.analysis.retransmission or tcp.analysis.fast_retransmission or tcp.analysis.duplicate_ack_frame)&amp;#39; -Tfields -Eseparator=&amp;quot;|&amp;quot; -Eoccurrence=l -e frame.time -e ip.src -e tcp.srcport -e ip.dst -e tcp.dstport -e expert | sed &amp;quot;...&amp;quot; &amp;gt; /tmp/retransmissions.txtAfter the some time odd situation occurs: file /tmp/retransmissions.txt stop grows, but wireshark temporary file still grows (looks like everything is fine and that traffic still captures).</description>
    </item>
    
    <item>
      <title>How to convert format of frame.time_relative to this format &amp;quot;hour:minute:second&amp;quot;?</title>
      <link>/questions/27689/how-to-convert-format-of-frametime_relative-to-this-format-hourminutesecond/</link>
      <pubDate>Mon, 02 Dec 2013 23:28:00 +0000</pubDate>
      
      <guid>/questions/27689/how-to-convert-format-of-frametime_relative-to-this-format-hourminutesecond/</guid>
      <description>How to convert format of frame.time_relative to this format &amp;ldquo;hour:minute:second&amp;rdquo;?  0 Here is what I tried:
tshark -r test.pcap -T fields -e frame.time_relative &amp;gt; file.csv
And here is the csv file I got:frame.time_relative00.0001280.0003150.0004070.010027I want this format to be a real time format. for example: 16:20:35 (hour:minute:second)
Any idea please...
timestamp tshark wiresharkasked 02 Dec &#39;13, 23:28
Eliza Rana
11●4●5●8
accept rate: 0%
 edited 03 Dec &#39;13, 08:12</description>
    </item>
    
    <item>
      <title>how to create a capture filter for TCAP/MAP/ISUP e.t.c protocols</title>
      <link>/questions/27696/how-to-create-a-capture-filter-for-tcapmapisup-etc-protocols/</link>
      <pubDate>Tue, 03 Dec 2013 04:08:00 +0000</pubDate>
      
      <guid>/questions/27696/how-to-create-a-capture-filter-for-tcapmapisup-etc-protocols/</guid>
      <description>how to create a capture filter for TCAP/MAP/ISUP e.t.c protocols  0 Hello everyone ! Tell me, can I create сapture-filter according to any protocol required me? Signal exchange large, want to reduce the load and file size. Or other suitable - record only those frames in which an occurrence of TCAP ?
capture-filterasked 03 Dec &#39;13, 04:08
Larush
1●2●2●3
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How parse raw files of wireshark to own GUI ?</title>
      <link>/questions/27697/how-parse-raw-files-of-wireshark-to-own-gui/</link>
      <pubDate>Tue, 03 Dec 2013 04:15:00 +0000</pubDate>
      
      <guid>/questions/27697/how-parse-raw-files-of-wireshark-to-own-gui/</guid>
      <description>How parse raw files of wireshark to own GUI ?  0 Hi everyone! Somebody tried to parse raw files of wireshark? You can read and parse the file and display the most?
parsingasked 03 Dec &#39;13, 04:15
Larush
1●2●2●3
accept rate: 0%
  
One Answer:
  
1The &#34;raw&#34; file is pcap or pcap-ng a binary format containing the raw frame as seen by the capture device roughly speaking.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t decrypt SSL using wireshark</title>
      <link>/questions/27699/cant-decrypt-ssl-using-wireshark/</link>
      <pubDate>Tue, 03 Dec 2013 04:44:00 +0000</pubDate>
      
      <guid>/questions/27699/cant-decrypt-ssl-using-wireshark/</guid>
      <description>Can&amp;rsquo;t decrypt SSL using wireshark  0 Recently I try to decrypt my dropbox connection which is in TLS format.
I use the squid as a middle man in Ubuntu13.10, I configure the /etc/squid3.conf as follow, the squid proxy is running at port 3128 and I set the chrome to use the squid proxy running at 127.0.0.1:3128:
# Squid normally listens to port 3128 always_direct allow all
http_port 3128 ssl-bump cert=/home/lzq-ubuntu/Desktop/cert/sslcerts/127.</description>
    </item>
    
    <item>
      <title>Client-authenticated TLS handshake</title>
      <link>/questions/27715/client-authenticated-tls-handshake/</link>
      <pubDate>Tue, 03 Dec 2013 07:37:00 +0000</pubDate>
      
      <guid>/questions/27715/client-authenticated-tls-handshake/</guid>
      <description>Client-authenticated TLS handshake  0 Hi guys,
I am trying to connect to a public webservice, which requires from its clients to have their own certificate. The whole communication is secure. So I think we could talk about the Client-authenticated TLS handshake.
The certificate is installed on the machine (Local Computer and User). It is verified from a CA. But it seems to me, that the client does not send any client certificate, I have tried it in a browser and programatically:</description>
    </item>
    
    <item>
      <title>wireshark coredumps during load</title>
      <link>/questions/27721/wireshark-coredumps-during-load/</link>
      <pubDate>Tue, 03 Dec 2013 08:40:00 +0000</pubDate>
      
      <guid>/questions/27721/wireshark-coredumps-during-load/</guid>
      <description>wireshark coredumps during load  0 I have a wireshark dissector plugin. I also have a wireshark installed from apt-get.
The wireshark loads fine without the plugin inserted in the right place. When I include the plugin .so file and try to run wireshark, I get the following error:
$ wireshark 08:23:45 Err register_subtree_array: subtree item type (ett_...) not -1 ! This is a development error: Either the subtree item type has already been assigned or was not initialized to -1.</description>
    </item>
    
    <item>
      <title>wireshark on android: wireshark can&amp;#x27;t postprocess tPacketCapture</title>
      <link>/questions/27734/wireshark-on-android-wireshark-cant-postprocess-tpacketcapture/</link>
      <pubDate>Tue, 03 Dec 2013 12:41:00 +0000</pubDate>
      
      <guid>/questions/27734/wireshark-on-android-wireshark-cant-postprocess-tpacketcapture/</guid>
      <description>wireshark on android: wireshark can&amp;rsquo;t postprocess tPacketCapture  0 I have installed tPacketCapture on my Android phone (Nexus Phone Android kitkat). I transferred the file to my laptop and launched wireshark. Wireshark was consuming all the availlabe RAM (more than 6GB) when loading a 27MB file. I had to kill the wireshark process. Anyone aware of this issue? And do you know if tPacketCapture works properly.. when it does not crash wireshark?</description>
    </item>
    
    <item>
      <title>How to dissect wlan challenge info packets?</title>
      <link>/questions/27737/how-to-dissect-wlan-challenge-info-packets/</link>
      <pubDate>Tue, 03 Dec 2013 17:43:00 +0000</pubDate>
      
      <guid>/questions/27737/how-to-dissect-wlan-challenge-info-packets/</guid>
      <description>How to dissect wlan challenge info packets?  0 I want to dissect challenge and auth process as below. After analyzing, I find packets 16806~16814 in the file, but how to dissect them with tshark/wireshark? Are they sccp packages?
The processes 8~13 are what I concerned. The file: http://www.cloudshark.org/captures/689877c7f961?filter=ip.addr%20eq%20192.168.1.21
challenge wlanasked 03 Dec &#39;13, 17:43
metamatrix
56●16●16●19
accept rate: 100%
Any one have ideas?
(09 Dec &#39;13, 21:53) metamatrix</description>
    </item>
    
    <item>
      <title>Zebra Printer responding with TCP ZeroWindow Probe</title>
      <link>/questions/27741/zebra-printer-responding-with-tcp-zerowindow-probe/</link>
      <pubDate>Tue, 03 Dec 2013 19:49:00 +0000</pubDate>
      
      <guid>/questions/27741/zebra-printer-responding-with-tcp-zerowindow-probe/</guid>
      <description>Zebra Printer responding with TCP ZeroWindow Probe  0 We are having some issues with several zebra printers that are printers that continue to release labels as they are sent. What we are seeing is that printer will error out in the windows print queue. These jobs are sent from a unix server to a unix/samba share that hands off to the windows print queue. Windows is to manage all the print queue.</description>
    </item>
    
    <item>
      <title>Editing User-Agent string in the HTTP header</title>
      <link>/questions/27756/editing-user-agent-string-in-the-http-header/</link>
      <pubDate>Wed, 04 Dec 2013 03:51:00 +0000</pubDate>
      
      <guid>/questions/27756/editing-user-agent-string-in-the-http-header/</guid>
      <description>Editing User-Agent string in the HTTP header  0 Hi All,
How does one edit the User-Agent string in the HTTP header from data captured by Wireshark. Is it possible?
Thanks :)
anyasked 04 Dec &#39;13, 03:51
Jhonny
1●1●1●2
accept rate: 0%
 edited 04 Dec &#39;13, 04:24 
   </description>
    </item>
    
    <item>
      <title>Remote capture</title>
      <link>/questions/27763/remote-capture/</link>
      <pubDate>Wed, 04 Dec 2013 06:02:00 +0000</pubDate>
      
      <guid>/questions/27763/remote-capture/</guid>
      <description>Remote capture  0 Does wireshark have the capability to use remote capture agents in order to get an n-tier view of network traffic? i.e Client-&amp;gt; Web Server-&amp;gt; App server-&amp;gt; DB Server -&amp;gt; Mainframe... There are a number of non-Opensource tools that do this very well (Compuwares GTTA product is particularly good in this area.) It would be cool if you could do similar with Wireshark.(Or maybe you already can?)</description>
    </item>
    
    <item>
      <title>statistics in Wireshark</title>
      <link>/questions/27765/statistics-in-wireshark/</link>
      <pubDate>Wed, 04 Dec 2013 06:34:00 +0000</pubDate>
      
      <guid>/questions/27765/statistics-in-wireshark/</guid>
      <description>statistics in Wireshark  0 Hi,
Is there a way to perform statistic analysis for MS IP Addresses taken from GTP layer?
BR, Diana.
statisticsasked 04 Dec &#39;13, 06:34
Dianalab9
26●16●16●20
accept rate: 0%
I mean in the same way Wireshark does statistics for SRC DST IP
(04 Dec &#39;13, 07:11) Dianalab9maybe it simply cannot be done?
(05 Dec &#39;13, 02:01) Dianalab9what kind of &#39;statistic analysis&#39;?
(05 Dec &#39;13, 05:50) Kurt Knochner ♦a list of all available MS IPs and the number of frames it appears in.</description>
    </item>
    
    <item>
      <title>How to read a pcap file</title>
      <link>/questions/27769/how-to-read-a-pcap-file/</link>
      <pubDate>Wed, 04 Dec 2013 07:32:00 +0000</pubDate>
      
      <guid>/questions/27769/how-to-read-a-pcap-file/</guid>
      <description>How to read a pcap file  0 My major is business and ICT course is mandatory. I did not understand much from the whole course. I have a TMA that involve reading a pcap file and answering questions. I opened the file with wireshark but i do not know where to look for in order to answer the question. Can someone help me? Email me at [email protected]
pcapasked 04 Dec &#39;13, 07:32</description>
    </item>
    
    <item>
      <title>What is the classification of protocol program?</title>
      <link>/questions/27771/what-is-the-classification-of-protocol-program/</link>
      <pubDate>Wed, 04 Dec 2013 10:52:00 +0000</pubDate>
      
      <guid>/questions/27771/what-is-the-classification-of-protocol-program/</guid>
      <description>What is the classification of protocol program?  0 My question is &#34;what is the classification of protocol program?&#34; Can u please tell me the correct answer this question.
protocolasked 04 Dec &#39;13, 10:52
Sweety
1●1●1●1
accept rate: 0%
 converted to question 04 Dec &#39;13, 13:28 
Guy Harris ♦♦
17.4k●3●35●196
I don&#39;t know what the question is asking, so I don&#39;t know what the answer would be. What do you mean by &#34;</description>
    </item>
    
    <item>
      <title>How to rewrite io_stat.c</title>
      <link>/questions/27772/how-to-rewrite-io_statc/</link>
      <pubDate>Wed, 04 Dec 2013 11:53:00 +0000</pubDate>
      
      <guid>/questions/27772/how-to-rewrite-io_statc/</guid>
      <description>How to rewrite io_stat.c  0 Hello, i need to rewrite code io_stat.c to get in io_graph to get 2 more values (0,0001 and 0,00001). I try but i get values 5 sec and 0,3 sec ... can someone help? Here my rewrite file : http://www.sendspace.com/file/2dz8yc
io_stat.c rewriteasked 04 Dec &#39;13, 11:53
Yszty
1●1●1●1
accept rate: 0%
I will try again. I need additional values of Tick interval in IO Graph.</description>
    </item>
    
    <item>
      <title>TLSV1 &amp;quot;Ignored Unknown Record&amp;quot;</title>
      <link>/questions/27773/tlsv1-ignored-unknown-record/</link>
      <pubDate>Wed, 04 Dec 2013 11:54:00 +0000</pubDate>
      
      <guid>/questions/27773/tlsv1-ignored-unknown-record/</guid>
      <description>TLSV1 &amp;ldquo;Ignored Unknown Record&amp;rdquo;  0 A wireshark trace of a TLS mailflow has packets with &#34;Ignored Unknown Record&#34; and I can&#39;t seem to find a solution to display them.
Allow Subdissector to Reassemble TCP Streams as suggested by Laura&#39;s is already checked.
http://ask.wireshark.org/questions/703/ssl-and-tls-ignored-unknown-record
What else may cause Ignored Unknown Record ?
tls ignored record smtp unknownasked 04 Dec &#39;13, 11:54
net_tech
116●30●33●37
accept rate: 13%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>broadcast to network addresses</title>
      <link>/questions/27776/broadcast-to-network-addresses/</link>
      <pubDate>Wed, 04 Dec 2013 14:06:00 +0000</pubDate>
      
      <guid>/questions/27776/broadcast-to-network-addresses/</guid>
      <description>broadcast to network addresses  0 appology for my previous mail..the pad got messed up here is the trace. Can someone explain it to me please?? I dont undrestand why the reply from the server is an ip broadcast and at the same time as hardware broadcast 255.255.255.255
Many thanks
udpasked 04 Dec &#39;13, 14:06
Mehran
11●2●2●3
accept rate: 0%
  
One Answer:
  
0a quick google search (I&#39;m sure you did that too!</description>
    </item>
    
    <item>
      <title>Packet Loss, retransmissions but no switch port errors.</title>
      <link>/questions/27783/packet-loss-retransmissions-but-no-switch-port-errors/</link>
      <pubDate>Wed, 04 Dec 2013 14:48:00 +0000</pubDate>
      
      <guid>/questions/27783/packet-loss-retransmissions-but-no-switch-port-errors/</guid>
      <description>Packet Loss, retransmissions but no switch port errors.  0 This is a general question. We have an WAN based enterprise application where most sites traverse 8-12 hops before getting to a data center load balancer (CISCO 6509E) which sprays to a web server cluster. Using WireShark we are getting lost of re-transamissions (4%) coming from the load balancer at the TCP level, but when we look at the devices along the path, we are not seeing any switch port errors along the way.</description>
    </item>
    
    <item>
      <title>security and encryption</title>
      <link>/questions/27793/security-and-encryption/</link>
      <pubDate>Wed, 04 Dec 2013 17:08:00 +0000</pubDate>
      
      <guid>/questions/27793/security-and-encryption/</guid>
      <description>security and encryption  0 for Example, Tom is a Computer science student. He likes to learn new things about networking and security. He wants to see whether the passwords that he logged in to certain websites are being secured or not. He tried to log in to certain websites such as Yahoo Mail, Facebook, Twitter, Gmail and Online Banking sites.
By using Wireshark tool, how can he trace whether the password has been encrypted or not?</description>
    </item>
    
    <item>
      <title>[closed] Make a CCDF graph for a data</title>
      <link>/questions/27795/make-a-ccdf-graph-for-a-data/</link>
      <pubDate>Wed, 04 Dec 2013 20:52:00 +0000</pubDate>
      
      <guid>/questions/27795/make-a-ccdf-graph-for-a-data/</guid>
      <description>[closed] Make a CCDF graph for a data  0 I want to make a CCDF graph by reading data from the following text file(file.txt).
CCDF means Complementary Cumulative Distribution Function
I have tried to search about CCDF, but I do not really understand about it.
So I don&#39;t know how to plot a CCDF graph.
Here is the data(file.txt), which is the inter-arrival times(seconds):
2.824562000 7.914959000 15.838087000 1.013451000 2.813006000 0.</description>
    </item>
    
    <item>
      <title>[closed] Ubuntu software</title>
      <link>/questions/27797/ubuntu-software/</link>
      <pubDate>Thu, 05 Dec 2013 01:18:00 +0000</pubDate>
      
      <guid>/questions/27797/ubuntu-software/</guid>
      <description>[closed] Ubuntu software  0 which version of wireshark is for ubuntu
ubuntuasked 05 Dec &#39;13, 01:18
shaziya islam
11●4●4●5
accept rate: 0%
 closed 05 Dec &#39;13, 01:56 
Kurt Knochner ♦
24.8k●10●39●237
 The question has been closed for the following reason &amp;ldquo;Duplicate Question: http://ask.wireshark.org/questions/27586/wireshark-in-linux-and-ubuntu&amp;quot; by Kurt Knochner 05 Dec &amp;lsquo;13, 01:56   
One Answer:
  
0The one you get with
sudo apt-get install wireshark</description>
    </item>
    
    <item>
      <title>the link type of interface X was not specified</title>
      <link>/questions/27801/the-link-type-of-interface-x-was-not-specified/</link>
      <pubDate>Thu, 05 Dec 2013 02:28:00 +0000</pubDate>
      
      <guid>/questions/27801/the-link-type-of-interface-x-was-not-specified/</guid>
      <description>the link type of interface X was not specified  0 I just installed 1.11.2 (SVN Rev 53411 from /trunk) for Windows from the download page and when trying to set a capture filter I get a popup with this message. A bit of searching seems to suggest this is bug 9473, which is fixed in revision 53581.
Has this bug fix been incorporated into the Windows version yet?
thanks, Greg Choules</description>
    </item>
    
    <item>
      <title>Who has a pcap file with RARP-reply packet?</title>
      <link>/questions/27804/who-has-a-pcap-file-with-rarp-reply-packet/</link>
      <pubDate>Thu, 05 Dec 2013 05:11:00 +0000</pubDate>
      
      <guid>/questions/27804/who-has-a-pcap-file-with-rarp-reply-packet/</guid>
      <description>Who has a pcap file with RARP-reply packet?  0 I try to find it, but I can&#39;t. There is only RARP-request.
rarpasked 05 Dec &#39;13, 05:11
DariaS
11●3●3●6
accept rate: 0%
  
One Answer:
  
0Here we go
http://cloudshark.org/captures/c6729d0fc558
As I did not have such a capture file and no working rarp daemon, I created the file with a Hex editor, according to RFC 903. It should be correct, at least Wireshark shows the reply correctly ;-)) Have fun!</description>
    </item>
    
    <item>
      <title>sip for only calls capture required and IPV6 capture filter not working</title>
      <link>/questions/27805/sip-for-only-calls-capture-required-and-ipv6-capture-filter-not-working/</link>
      <pubDate>Thu, 05 Dec 2013 05:19:00 +0000</pubDate>
      
      <guid>/questions/27805/sip-for-only-calls-capture-required-and-ipv6-capture-filter-not-working/</guid>
      <description>sip for only calls capture required and IPV6 capture filter not working  0 In wireshark telephony --&amp;gt; VOIP calls will show only calls. We are running performance with 100 calls per second. File size is huge and contains register, subscriber other messages.Is there any capture filter to get only VOIP calls ? capturefilter sip takes everything
Another issue in Linux im using below filter to avoid traffic capture from below network range.</description>
    </item>
    
    <item>
      <title>What is ChmodBPF folder in startup items - MacBook Pro running Mavericks</title>
      <link>/questions/27806/what-is-chmodbpf-folder-in-startup-items-macbook-pro-running-mavericks/</link>
      <pubDate>Thu, 05 Dec 2013 05:33:00 +0000</pubDate>
      
      <guid>/questions/27806/what-is-chmodbpf-folder-in-startup-items-macbook-pro-running-mavericks/</guid>
      <description>What is ChmodBPF folder in startup items - MacBook Pro running Mavericks  0 I am having a console error appear every 5 seconds. The error is:
12/5/13 8:12:13.233 AM Wireless Network Utility[415]: Model -ioClassRef error
Apple has no idea what this error is but in the course of investigating things I discovered the directory in my startupitems directory
ChmodBPF
That directory contains two items
ChmodBPF StartupParameters.plist
StartupParameter.plist contains
{ Description = iNetGet; Provides = ( iNetGet, ); Requires = ( Resolver, ); }</description>
    </item>
    
    <item>
      <title>NBNS entries</title>
      <link>/questions/27811/nbns-entries/</link>
      <pubDate>Thu, 05 Dec 2013 06:21:00 +0000</pubDate>
      
      <guid>/questions/27811/nbns-entries/</guid>
      <description>NBNS entries  0 HI,
We recently replaced 2 old windows 2003 dc&#39;S with windows 2008r2 dc&#39;S. All is working ok except on odd occasions when query the AD i get errors such as &#34;Server not operational&#34; or &#34;Domain does not exist&#34; Everything looks correct on DNS and there are no entries for the old servers so i am looking at alternatives. If i run wireshark i get entries such as</description>
    </item>
    
    <item>
      <title>syslog traffic</title>
      <link>/questions/27818/syslog-traffic/</link>
      <pubDate>Thu, 05 Dec 2013 07:45:00 +0000</pubDate>
      
      <guid>/questions/27818/syslog-traffic/</guid>
      <description>syslog traffic  0 If I am capturing with wireshark on 192.168.2.10/22 computer, which is connected to a non-mirrored port of the switch, should I be seeing Syslog traffic sourced from 192.168.5.1/24 which has 192.168.3.100/22 as destination? Inter vlan routing is allowed between subnets.
syslogasked 05 Dec &#39;13, 07:45
net_tech
116●30●33●37
accept rate: 13%
 edited 05 Dec &#39;13, 08:10 
  
One Answer:
  
2 should I be seeing Syslog traffic</description>
    </item>
    
    <item>
      <title>Converting 1.6.2 propietary plugins to latest Wireshark release.</title>
      <link>/questions/27826/converting-162-propietary-plugins-to-latest-wireshark-release/</link>
      <pubDate>Thu, 05 Dec 2013 08:51:00 +0000</pubDate>
      
      <guid>/questions/27826/converting-162-propietary-plugins-to-latest-wireshark-release/</guid>
      <description>Converting 1.6.2 propietary plugins to latest Wireshark release.  0 Is there a way to decompile propietary plugins from a 32bit platform version 1.6.2 and compile them AGAIN to a 64 bit 1.10.3 release or even 32 bit?
This is what I have:
Version 1.6.2 (SVN Rev 38931 from /trunk-1.6)
Copyright 1998-2011 Gerald Combs [email protected] and contributors. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.</description>
    </item>
    
    <item>
      <title>Why am I getting an RST packet after a complete and successful fin/ack in both directions?</title>
      <link>/questions/27838/why-am-i-getting-an-rst-packet-after-a-complete-and-successful-finack-in-both-directions/</link>
      <pubDate>Thu, 05 Dec 2013 10:44:00 +0000</pubDate>
      
      <guid>/questions/27838/why-am-i-getting-an-rst-packet-after-a-complete-and-successful-finack-in-both-directions/</guid>
      <description>Why am I getting an RST packet after a complete and successful fin/ack in both directions?  0 I have a client device requesting data from a server device, periodically following a fin/ack, ack, fin/ack, ack, the server device proceeds to send an RST packet... why would this happen? this packet should never happen right? the session is closed, why send an RST?
rstasked 05 Dec &#39;13, 10:44
jwolf
1●1●1●1</description>
    </item>
    
    <item>
      <title>Format of data</title>
      <link>/questions/27839/format-of-data/</link>
      <pubDate>Thu, 05 Dec 2013 11:55:00 +0000</pubDate>
      
      <guid>/questions/27839/format-of-data/</guid>
      <description>Format of data  0 What is the format of data in wireshark capture file? The data is 18 bytes in my file. How to find another data with the help of this.
data formatasked 05 Dec &#39;13, 11:55
Rìýà ÐashöRìýã
1●1●1●1
accept rate: 0%
Not sure I understand your question. You want to programmatically extract &#39;data&#39; from a packet capture file? And you need the layout of the pcap file format?</description>
    </item>
    
    <item>
      <title>SMS wireshark logs in 3g</title>
      <link>/questions/27847/sms-wireshark-logs-in-3g/</link>
      <pubDate>Fri, 06 Dec 2013 00:28:00 +0000</pubDate>
      
      <guid>/questions/27847/sms-wireshark-logs-in-3g/</guid>
      <description>SMS wireshark logs in 3g  0 Hi ALL,
Can anyone please provide me the successfull logs for SMS, MMS and location update... I need these on urjent basis.
Thanks in advance.
Manish Singla [email protected]
sms logs mmsasked 06 Dec &#39;13, 00:28
Metalica Loo...
21●2●2●5
accept rate: 0%
 edited 15 Sep &#39;14, 22:36 
Guy Harris ♦♦
17.4k●3●35●196
  
One Answer:
  
1I doubt anyone will have those kind of traces for you as they are what I would call a perfect example for sensitive packets that can&#39;t be shared for privacy reasons.</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t uninstall wireshark on win8 64bit</title>
      <link>/questions/27855/cant-uninstall-wireshark-on-win8-64bit/</link>
      <pubDate>Fri, 06 Dec 2013 02:48:00 +0000</pubDate>
      
      <guid>/questions/27855/cant-uninstall-wireshark-on-win8-64bit/</guid>
      <description>Can&amp;rsquo;t uninstall wireshark on win8 64bit  1 Hi,
I installed wireshark on windows 8 64bit. Everytime I try to run it, it crashes. So I tried to uninstall it, but doesn&#39;t allow it as some resources are in use.
From processes I see there is 2 instances running even though I just powered computer on; wireshark.exe and dumpcap.exe.
I can&#39;t taskkill them even with administrator rights. There is something weird going with the taskkill command in windows 8 64bit (I can&#39;t kill anything that isn&#39;t running all right - if that makes any sense).</description>
    </item>
    
    <item>
      <title>dvb-s2_bb dissector not found</title>
      <link>/questions/27857/dvb-s2_bb-dissector-not-found/</link>
      <pubDate>Fri, 06 Dec 2013 03:37:00 +0000</pubDate>
      
      <guid>/questions/27857/dvb-s2_bb-dissector-not-found/</guid>
      <description>dvb-s2_bb dissector not found  0 Hello. I&#39;m trying to make wireshark analyze the file with a pure dvb-s2 stream (without encapsulation in ethernet header). I didn&#39;t find such a type for the libpcap or pcap-ng header. So I generated a file with a type 147 (DLT USER 0) and then tried to represent this type as dvb-s2-bb in wireshark. If I&#39;ve got it right, I must enter the dissector name in the &#34;</description>
    </item>
    
    <item>
      <title>Extra octets in packets in a capture file</title>
      <link>/questions/27862/extra-octets-in-packets-in-a-capture-file/</link>
      <pubDate>Fri, 06 Dec 2013 04:51:00 +0000</pubDate>
      
      <guid>/questions/27862/extra-octets-in-packets-in-a-capture-file/</guid>
      <description>Extra octets in packets in a capture file  0 Greetings,
Let me explain the context first. I have an application that filters pcap files in bulk. And then I got some pcap files from a third part, and the application just would not work.
After analyzing this pcap file, I found out that there are 4 extra octets in the beginning of every packet in the file (analysis made by extracting the raw data from the pcap file).</description>
    </item>
    
    <item>
      <title>Are Lua dissector fields filterable?</title>
      <link>/questions/27868/are-lua-dissector-fields-filterable/</link>
      <pubDate>Fri, 06 Dec 2013 06:17:00 +0000</pubDate>
      
      <guid>/questions/27868/are-lua-dissector-fields-filterable/</guid>
      <description>Are Lua dissector fields filterable?  0 I&#39;m wondering how to get the fields declared in a Lua dissector searchable in the filter bar. When trying to declare fields the same way as in various tutorials/samples, despite the fact that the dissector works fine, packets are recognized and decoded, the fields are unavailable to search.
Example :
p_myproto = Proto (&amp;quot;myproto&amp;quot;,&amp;quot;My Protocol&amp;quot;) local f_command = ProtoField.uint16(&amp;quot;myproto.command&amp;quot;, &amp;quot;Command&amp;quot;, base.HEX) local f_data = ProtoField.</description>
    </item>
    
    <item>
      <title>Understanding the RTP Stream Analysis</title>
      <link>/questions/27870/understanding-the-rtp-stream-analysis/</link>
      <pubDate>Fri, 06 Dec 2013 06:36:00 +0000</pubDate>
      
      <guid>/questions/27870/understanding-the-rtp-stream-analysis/</guid>
      <description>Understanding the RTP Stream Analysis  0 Hi
I would like to understand the the output of the RTP Streams Analysis
I get here by going to: Telephony &amp;gt; RTP &amp;gt; Show All Streams.
In the output, under the &#39;Lost Column&#39; I have -1722(-100.0%).
Also seen when you click the Analyze Button, the bottom reads: Total RTP packets = 1722 (expected 1722) Lost RTP packets = -1722 (-100.00%) Sequence errors = 1722</description>
    </item>
    
    <item>
      <title>client sends ACKS very late and gets RST</title>
      <link>/questions/27872/client-sends-acks-very-late-and-gets-rst/</link>
      <pubDate>Fri, 06 Dec 2013 07:49:00 +0000</pubDate>
      
      <guid>/questions/27872/client-sends-acks-very-late-and-gets-rst/</guid>
      <description>client sends ACKS very late and gets RST  0 This is a dump captured at the client (this is a web traffic generator tool) in a customer test environment. We were told that the client (.42) is not sending ACKs and this results in the test getting terminated. I am not an expert on networking or trace analysis and am having a tough time figuring out if the answer to why the client is not sending an ACK is hidden somewhere in the dump.</description>
    </item>
    
    <item>
      <title>Capturing interface-local multicast</title>
      <link>/questions/27875/capturing-interface-local-multicast/</link>
      <pubDate>Fri, 06 Dec 2013 09:27:00 +0000</pubDate>
      
      <guid>/questions/27875/capturing-interface-local-multicast/</guid>
      <description>Capturing interface-local multicast  0 I have recently upgraded to Wireshark from 1.8.11 to the 1.10.3, and Winpcap from 4.1.2 to 4.1.3, on Windows 7, 64 bit. I used to be able to see interface-local multicast packets that my applications use to transmit data to each other i.e. addresses ff01:... I no longer can. Can anyone suggest why not or what is needed to do so? (Or is it a figment of my imagination that it used to work!</description>
    </item>
    
    <item>
      <title>LLC TEST packets?</title>
      <link>/questions/27878/llc-test-packets/</link>
      <pubDate>Fri, 06 Dec 2013 12:02:00 +0000</pubDate>
      
      <guid>/questions/27878/llc-test-packets/</guid>
      <description>LLC TEST packets?  0 So I noticed in my packet captures that something on the lan is broadcasting LLC TEST packets. I read the 802.2 standard and it sounds like it is essentially a layer 2 PING function and it is required. I thought this is great! I can broadcast an L2 ping and get a reply from every node on the lan, whether it is running IP or not.</description>
    </item>
    
    <item>
      <title>What is the window scaling graph showing exactly and how to use it</title>
      <link>/questions/27883/what-is-the-window-scaling-graph-showing-exactly-and-how-to-use-it/</link>
      <pubDate>Fri, 06 Dec 2013 22:27:00 +0000</pubDate>
      
      <guid>/questions/27883/what-is-the-window-scaling-graph-showing-exactly-and-how-to-use-it/</guid>
      <description>What is the window scaling graph showing exactly and how to use it  0 This question focuses on the graph produced by:
Statistics -&amp;gt; TCP StreamGraph -&amp;gt; Window Scaling Graph
I&#39;m sure this should be simple, but I&#39;m confused by what this graph is showing me and I can&#39;t find documentation explicitly stating what the graph displays. Is this a graph of:
a) The size of the receive window regardless of the number of unacked bytes.</description>
    </item>
    
    <item>
      <title>How to interpret the data ?</title>
      <link>/questions/27887/how-to-interpret-the-data/</link>
      <pubDate>Sat, 07 Dec 2013 06:22:00 +0000</pubDate>
      
      <guid>/questions/27887/how-to-interpret-the-data/</guid>
      <description>How to interpret the data ?  0 Hi, this may be a very naive question, but I&#39;ve just installed wireshark, and I&#39;m not sure at all about how to interpret the data. Is there a forum on the net dedicated for wireshark (or other sniffer) data interpretation ?
interpretationasked 07 Dec &#39;13, 06:22
Ling talfi
16●1●1●4
accept rate: 0%
  
One Answer:
  
1 There are a few good resources out there for learning how to use the program in general.</description>
    </item>
    
    <item>
      <title>TCP zero window</title>
      <link>/questions/27889/tcp-zero-window/</link>
      <pubDate>Sat, 07 Dec 2013 07:00:00 +0000</pubDate>
      
      <guid>/questions/27889/tcp-zero-window/</guid>
      <description>TCP zero window  0 While transfering the data from primary to Data recovery (DR)through replication router we are geting the error message of TCP zero window.Please help to find the issue whether issue at replication router that is in network or server.
zero tcp tcpwindowsizeasked 07 Dec &#39;13, 07:00
Aathiinfy
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Zero window is reported by the receiver, so the problem is on the receiver side, which indicates that the receiver does not have enough processing power on handling more data.</description>
    </item>
    
    <item>
      <title>Tracing packet to receiving or transmitting file/program</title>
      <link>/questions/27895/tracing-packet-to-receiving-or-transmitting-fileprogram/</link>
      <pubDate>Sat, 07 Dec 2013 10:24:00 +0000</pubDate>
      
      <guid>/questions/27895/tracing-packet-to-receiving-or-transmitting-fileprogram/</guid>
      <description>Tracing packet to receiving or transmitting file/program  0 Is it possible to trace a packet to the source of its destination within the host machine?
AKA Packet 7642 OUTBOUND from HOST(wow.exe) to IP-ADDRESS. Packet 7643 INBOUND from IP-ADDRESS to HOST(Chrome.exe)
receive tracing identify source programsasked 07 Dec &#39;13, 10:24
JourneyJay
11●2●2●4
accept rate: 0%
  
One Answer:
  
0I&#39;m not sure I understand the question. Applications don&#39;t communicate to each other within the host via IP packets in this way unless you&#39;re talking about virtual machines within the host.</description>
    </item>
    
    <item>
      <title>Expression: Display all data coming in AND out of port A on ALL protocols</title>
      <link>/questions/27896/expression-display-all-data-coming-in-and-out-of-port-a-on-all-protocols/</link>
      <pubDate>Sat, 07 Dec 2013 11:12:00 +0000</pubDate>
      
      <guid>/questions/27896/expression-display-all-data-coming-in-and-out-of-port-a-on-all-protocols/</guid>
      <description>Expression: Display all data coming in AND out of port A on ALL protocols  0 I&#39;m having a devil of a time discovering an expression for displaying only packets which have come to from one particular port using any protocol. Any help?
any expressions data port allasked 07 Dec &#39;13, 11:12
JourneyJay
11●2●2●4
accept rate: 0%
  
One Answer:
  
0A port is generally associated with tcp or udp so tcp.</description>
    </item>
    
    <item>
      <title>Simple function question</title>
      <link>/questions/27899/simple-function-question/</link>
      <pubDate>Sat, 07 Dec 2013 15:25:00 +0000</pubDate>
      
      <guid>/questions/27899/simple-function-question/</guid>
      <description>Simple function question  0 Ok, here is the short version... I have a small home network. Very basic setup. 3 wireless devices in &#34;my&#34; environment going through a Linksys E1500. The modem is going into said Linksys. I share internet with a couple of people upstairs. I have run a CAT5 cable upstairs to them. They have a DLink router and 3 or 4 wireless devices in their environment. (Only accessing the internet from their Dlink router) All I want to do is be able to monitor the amount of the downloads in gigs going thru the ethernet cable to them upstairs.</description>
    </item>
    
    <item>
      <title>replacing a real IP by a false IP</title>
      <link>/questions/27900/replacing-a-real-ip-by-a-false-ip/</link>
      <pubDate>Sat, 07 Dec 2013 16:01:00 +0000</pubDate>
      
      <guid>/questions/27900/replacing-a-real-ip-by-a-false-ip/</guid>
      <description>replacing a real IP by a false IP  0 Hello,
Thank you all first for this good job.
I wan to make Wireshark showing and saving a false IP address in a replacement in a real one. In some words, we assume that Wireshark is sniffing traffic between my PC (IP1) and a server (IP2).
So is there a manner, in a low level file for example (winpcap? because I&#39;m on Windows bad thinks.</description>
    </item>
    
    <item>
      <title>bandwidth consumption</title>
      <link>/questions/27907/bandwidth-consumption/</link>
      <pubDate>Sat, 07 Dec 2013 20:38:00 +0000</pubDate>
      
      <guid>/questions/27907/bandwidth-consumption/</guid>
      <description>bandwidth consumption  1 I got some data from wireshark for the conversation between the client (B) and the server (A) and I am trying to do some analysis as far as the bandwidth consumption is concerned.
The WAN link on the client side is a T1 and the link on the server side is 3MB. I have Wireshark captured on both ends.
Here it goes... This is the data from the statistic-&amp;gt;conversation in Wireshark on the server side (3MB link).</description>
    </item>
    
    <item>
      <title>No interface - Windows XP Service Pack 3</title>
      <link>/questions/27915/no-interface-windows-xp-service-pack-3/</link>
      <pubDate>Sun, 08 Dec 2013 06:40:00 +0000</pubDate>
      
      <guid>/questions/27915/no-interface-windows-xp-service-pack-3/</guid>
      <description>No interface - Windows XP Service Pack 3  0 I installed WireShark 3.10.3, which has WinPcap 4.1.3 installed. The only interface displayed is &#34;\Device\NPF_GenericDialupAdapter&#34;. I a NIC card using the &#34;Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC&#34;. The driver is located in &#34;C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys&#34;. And the file version is 5.690.0307.2008 built by: WinDDk. How do I get my NIC interface listed, so that I can capture packets?
interfaceasked 08 Dec &#39;13, 06:40</description>
    </item>
    
    <item>
      <title>Lua doesn&amp;#x27;t appear in the menu although wireshark is built with --with-lua</title>
      <link>/questions/27917/lua-doesnt-appear-in-the-menu-although-wireshark-is-built-with-with-lua/</link>
      <pubDate>Sun, 08 Dec 2013 07:05:00 +0000</pubDate>
      
      <guid>/questions/27917/lua-doesnt-appear-in-the-menu-although-wireshark-is-built-with-with-lua/</guid>
      <description>Lua doesn&amp;rsquo;t appear in the menu although wireshark is built with &amp;ndash;with-lua  0 Hello,
I&#39;m quite new at wireshark and I have built wireshark from the source on my ubuntu 13.10 (64bits). All went fine, but when I start wireshark, I do not see the &#34;LUA&#34; support added into the menu. I have built wireshark 1.8.11 with &#34;--with-lua&#34;.
Any idea why?
Thanks in advance, /maghrebi
luaasked 08 Dec &#39;13, 07:05</description>
    </item>
    
    <item>
      <title>I wish to monitor android data traffic to find IP of proxies used</title>
      <link>/questions/27923/i-wish-to-monitor-android-data-traffic-to-find-ip-of-proxies-used/</link>
      <pubDate>Sun, 08 Dec 2013 12:25:00 +0000</pubDate>
      
      <guid>/questions/27923/i-wish-to-monitor-android-data-traffic-to-find-ip-of-proxies-used/</guid>
      <description>I wish to monitor android data traffic to find IP of proxies used  0 Hello,
I have an android phone and I am running this app on it https://play.google.com/store/apps/details?id=com.proxyBrowser
This app uses proxies to access any website, I wish to know the IP addresses of the proxies used.
I have wireshark running on pc and I can connect it to the router using ethernet or wifi. The android phone is running on the same wifi network.</description>
    </item>
    
    <item>
      <title>tshark statistics</title>
      <link>/questions/27924/tshark-statistics/</link>
      <pubDate>Sun, 08 Dec 2013 12:50:00 +0000</pubDate>
      
      <guid>/questions/27924/tshark-statistics/</guid>
      <description>tshark statistics  0 Hello, on tshark statistics I see that a whole packet 1514 bytes is in the time interval of 1 microsecond. It is proper behaviour?
|----------------------------------------
| Interval | Frames | Bytes |
|----------------------------------------
| 0.000000 &amp;lt;&amp;gt; 0.000001 | 1 | 1514 |
| 0.000001 &amp;lt;&amp;gt; 0.000002 | 0 | 0 |
| 0.000002 &amp;lt;&amp;gt; 0.000003 | 0 | 0 |
| 0.000003 &amp;lt;&amp;gt; 0.000004 | 0 | 0 |</description>
    </item>
    
    <item>
      <title>Retrieving information inside the dissection tree?</title>
      <link>/questions/27926/retrieving-information-inside-the-dissection-tree/</link>
      <pubDate>Sun, 08 Dec 2013 13:33:00 +0000</pubDate>
      
      <guid>/questions/27926/retrieving-information-inside-the-dissection-tree/</guid>
      <description>Retrieving information inside the dissection tree?  0 I need the uncompressed text of a http response, however with lua it&#39;s a little tricky to process the compressed data. I think I can use the existing data within the dissection tree, because there is already a dissector done that. But the documentation doesn&#39;t seem to provide that function. Is this potentially possible?
dissectorasked 08 Dec &#39;13, 13:33
Jacul
6●2●2●4
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Capture Filter ether dst not working</title>
      <link>/questions/27935/capture-filter-ether-dst-not-working/</link>
      <pubDate>Sun, 08 Dec 2013 19:40:00 +0000</pubDate>
      
      <guid>/questions/27935/capture-filter-ether-dst-not-working/</guid>
      <description>Capture Filter ether dst not working  0 Hi, I have the following assignment. My problem is that when I type in ether in the filter, it turns red. Is that supposed to happen? When I type in ether src and then my mac address, it still doesn&#39;t work. Am I doing something wrong? Any help is appreciated. Thanks.
Find out which network interface is the active interface using Wireshark, and then use that interface to complete the rest of the activities.</description>
    </item>
    
    <item>
      <title>Decode as my protocol</title>
      <link>/questions/27943/decode-as-my-protocol/</link>
      <pubDate>Sun, 08 Dec 2013 23:38:00 +0000</pubDate>
      
      <guid>/questions/27943/decode-as-my-protocol/</guid>
      <description>Decode as my protocol  0 Hi,
Is there any way to say Wireshark to decode as &#39;my protocol&#39; all the payloads of 802.15.4?
Thanks
decode 802.15.4 as wireshark pluginasked 08 Dec &#39;13, 23:38
lina
11●3●3●5
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>RTP Packets - 96 Bytes</title>
      <link>/questions/27946/rtp-packets-96-bytes/</link>
      <pubDate>Mon, 09 Dec 2013 03:50:00 +0000</pubDate>
      
      <guid>/questions/27946/rtp-packets-96-bytes/</guid>
      <description>RTP Packets - 96 Bytes  0 Hi I&#39;ve received a trace that has RTP Packets which are 96 bytes.
eg: Frame 34: 214 bytes on wire (1712 bits), 96 bytes captured (768 bits)
Can anyone advise how I can decode these packets, so I can listen to the stream.
Thanks
decode_rtp rtpasked 09 Dec &#39;13, 03:50
MaCMan
6●1●1●3
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Decode as SIMPLE</title>
      <link>/questions/27947/decode-as-simple/</link>
      <pubDate>Mon, 09 Dec 2013 05:12:00 +0000</pubDate>
      
      <guid>/questions/27947/decode-as-simple/</guid>
      <description>Decode as SIMPLE  0 Hi, I would like to decode packets as SIMPLE (Standard Interface for Multiple Platform Link Evaluation) but I cannot find any support for this. The SIMPLE format is included in a formal NATO Standardization Agreement called STANAG 5602. It allows for SIMPLE packets to be transmitted as either TCP or UDP (multicast or broadcast).
Does anyone know if this &#34;decode as&#34; capability is available anywhere? Many thanks.</description>
    </item>
    
    <item>
      <title>Dissector / Create subtree of non-consecutive fields</title>
      <link>/questions/27948/dissector-create-subtree-of-non-consecutive-fields/</link>
      <pubDate>Mon, 09 Dec 2013 06:08:00 +0000</pubDate>
      
      <guid>/questions/27948/dissector-create-subtree-of-non-consecutive-fields/</guid>
      <description>Dissector / Create subtree of non-consecutive fields  0 Hi all,
I&#39;m writing a dissector (over UDP) which has header fields (32 bytes) but also footer fields (padding of 8 bytes). The remaining data (between my protocol header and protocol footer) are passed to the usual &#34;data&#34; dissector.
When creating my dissector subtree I do not success to highlight just the header and the footer.
With the following code I highlight the full UDP payload (my protocol header + the data + my protocol footer): amin_item = proto_tree_add_item(tree, proto_amin, tvb, 0, -1, FALSE); amin_tree = proto_item_add_subtree(amin_item, ett_amin);</description>
    </item>
    
    <item>
      <title>Wan ip tracing tools</title>
      <link>/questions/27955/wan-ip-tracing-tools/</link>
      <pubDate>Mon, 09 Dec 2013 09:25:00 +0000</pubDate>
      
      <guid>/questions/27955/wan-ip-tracing-tools/</guid>
      <description>Wan ip tracing tools  0 Hello my name is butchmon I am seeking were I can find free ip tracing tools that are decent. I have used ipinfo its great although I am seeking more advanced tools.
wan lan tracing toasked 09 Dec &#39;13, 09:25
Vinnymon
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Wireless toolbar options greyed out</title>
      <link>/questions/27958/wireless-toolbar-options-greyed-out/</link>
      <pubDate>Mon, 09 Dec 2013 10:56:00 +0000</pubDate>
      
      <guid>/questions/27958/wireless-toolbar-options-greyed-out/</guid>
      <description>Wireless toolbar options greyed out  0 I used airmon-ng to create a monitor interface on my wireless card, and airodump-ng to capture some packets. However, when I load the capture file into wireshark to decrypt it, I am not able to do so. have enabled wireless decryption in the preferences, and added wpa keys. However, the wireless toolbar options are all greyed out except for the button that switches between &#34;</description>
    </item>
    
    <item>
      <title>Windows build fails with return code &amp;#x27;0xc0000135&amp;#x27;</title>
      <link>/questions/27964/windows-build-fails-with-return-code-0xc0000135/</link>
      <pubDate>Mon, 09 Dec 2013 16:52:00 +0000</pubDate>
      
      <guid>/questions/27964/windows-build-fails-with-return-code-0xc0000135/</guid>
      <description>Windows build fails with return code &amp;lsquo;0xc0000135&amp;rsquo;  0 I&#39;m trying to build wireshark 1.8.3 release from source to build a plugin that isn&#39;t distributed with it. I&#39;m getting the below error.
The error happens whether I build from the command line or VS2010.
Googling the error brings me this which leads me to believe it isn&#39;t able to find the compiler. But I&#39;ve ran vcvars32.bat and I can execute cl.</description>
    </item>
    
    <item>
      <title>Missing RSA session ID</title>
      <link>/questions/27976/missing-rsa-session-id/</link>
      <pubDate>Tue, 10 Dec 2013 09:54:00 +0000</pubDate>
      
      <guid>/questions/27976/missing-rsa-session-id/</guid>
      <description>Missing RSA session ID  0 Hello, I&#39;ve come across this a few times at work and am wondering if anyone has a possible explanation. When trying to decrypt traces with Wireshark, decryption works fine, but when exporting the session keys from the file menu, the RSA-Session ID comes up as empty.
empty id rsa-sessionasked 10 Dec &#39;13, 09:54
voiper
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Monitoring WAN Traffic</title>
      <link>/questions/27979/monitoring-wan-traffic/</link>
      <pubDate>Tue, 10 Dec 2013 11:51:00 +0000</pubDate>
      
      <guid>/questions/27979/monitoring-wan-traffic/</guid>
      <description>Monitoring WAN Traffic  0 I have an Adtran provided by my ISP (telepacific) for our two bonned T1s. Off of that Adran, they hand us a single Ethernet cable that is plugged into an unmanaged switch which provided a link to our three devices with static IPs. Our Sonicwall, Our Webstream Computer, and Test webserver. We have noticed that our webstream on this bonded T1 is buffering the users end.</description>
    </item>
    
    <item>
      <title>How to get LPD data content</title>
      <link>/questions/27981/how-to-get-lpd-data-content/</link>
      <pubDate>Tue, 10 Dec 2013 15:05:00 +0000</pubDate>
      
      <guid>/questions/27981/how-to-get-lpd-data-content/</guid>
      <description>How to get LPD data content  0 Hello,
can you help me please, how to get LPD data file from my capture file? I know hot to get data file from IPP protocol, but I have problems with LPD (data file is divided into more frames - IPP data file is in one frame so I can just export it easily). Here is my printcap file: http://speedy.sh/9ZEV7/LPDtext.pcapng
Thank you! :)</description>
    </item>
    
    <item>
      <title>Monitoring Ethernet II frames in Ubuntu; with and without a local network</title>
      <link>/questions/27983/monitoring-ethernet-ii-frames-in-ubuntu-with-and-without-a-local-network/</link>
      <pubDate>Tue, 10 Dec 2013 17:15:00 +0000</pubDate>
      
      <guid>/questions/27983/monitoring-ethernet-ii-frames-in-ubuntu-with-and-without-a-local-network/</guid>
      <description>Monitoring Ethernet II frames in Ubuntu; with and without a local network  0 Hi,
I&#39;m trying to send raw &#39;Ethernet II&#39; frames from my ethernet interface (eth0) using Ubuntu, to some embedded electronics (I&#39;m trying to get my head around low level networking). I would like to only use &#39;Ethernet&#39; (layer 2), and not use &#39;IP&#39; (layer 3) or any higher protocols, to keep things simple for the electronics.</description>
    </item>
    
    <item>
      <title>How to Automate Export Object?</title>
      <link>/questions/27984/how-to-automate-export-object/</link>
      <pubDate>Tue, 10 Dec 2013 18:28:00 +0000</pubDate>
      
      <guid>/questions/27984/how-to-automate-export-object/</guid>
      <description>How to Automate Export Object?  0 Hi All,
I am a newbie in using Wireshark.
I have captured some DICOM packets and I can export the original DICOM files using Wireshark.
Can I make it become a scheduled task? Seems tShark do not have the &#34;Export Object&#34; function.
Is there any library I can use the &#34;Export Object&#34;, not by the UI? Thanks!
exportasked 10 Dec &#39;13, 18:28
jacky</description>
    </item>
    
    <item>
      <title>tcpdump -ni utun0  doesn&amp;#x27;t capture traffic</title>
      <link>/questions/27986/tcpdump-ni-utun0-doesnt-capture-traffic/</link>
      <pubDate>Tue, 10 Dec 2013 21:25:00 +0000</pubDate>
      
      <guid>/questions/27986/tcpdump-ni-utun0-doesnt-capture-traffic/</guid>
      <description>tcpdump -ni utun0 doesn&amp;rsquo;t capture traffic  0 Hi there! I&#39;m using OS X 10.9 and standard apple ipsec connection. After connection I see utun0 interface is active. But when I use command &#34;tcpdump -ni utun0&#34; i haven&#39;t see any captured traffic. If I use standard L2TP connection and interface ppp0, I see a traffic and it&#39;s work perfect. Why it doesn&#39;t work with tunnel interfaces?
Thanks!
utun0asked 10 Dec &#39;13, 21:25</description>
    </item>
    
    <item>
      <title>How to measure duration time between two packets via command or API</title>
      <link>/questions/27989/how-to-measure-duration-time-between-two-packets-via-command-or-api/</link>
      <pubDate>Tue, 10 Dec 2013 22:06:00 +0000</pubDate>
      
      <guid>/questions/27989/how-to-measure-duration-time-between-two-packets-via-command-or-api/</guid>
      <description>How to measure duration time between two packets via command or API  0 I use a notebook to browse web. How to measure duration from packet A tcp SYN to packet B tcp ACK. I can see it from wireshark GUI through filter. If I want to measure duration so many times, maybe 1000 times. Anyone know whether API or command can do this thing?
Thanks Shown [email protected]</description>
    </item>
    
    <item>
      <title>Difference between Wireshark and Snort</title>
      <link>/questions/27990/difference-between-wireshark-and-snort/</link>
      <pubDate>Tue, 10 Dec 2013 22:08:00 +0000</pubDate>
      
      <guid>/questions/27990/difference-between-wireshark-and-snort/</guid>
      <description>Difference between Wireshark and Snort  0 Hi All,
I am very new to security field and exploring various tools. i came across two great tools Wireshark and Snort... i found we can set filters in both tools. Can any one please explain the difference between both the tools...
Thank you in advance..
snort wiresharkasked 10 Dec &#39;13, 22:08
Aditi
16●4●4●6
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Captured data into MySQL</title>
      <link>/questions/27991/captured-data-into-mysql/</link>
      <pubDate>Tue, 10 Dec 2013 22:38:00 +0000</pubDate>
      
      <guid>/questions/27991/captured-data-into-mysql/</guid>
      <description>Captured data into MySQL  0 Hello,
I am building HTTP analyzer (based on captured data) and I need to get access to HTTP fields. How to put this data to MySQL? I can parse XML, so XML is also fine.
Wireshark has an excellent ability to divide raw data into HTTP headers. Is there any kind of API to perform same but with function calls.
Thank you.
xml capture-filter database http mysqlasked 10 Dec &#39;13, 22:38</description>
    </item>
    
    <item>
      <title>isatap protocol traffic</title>
      <link>/questions/27992/isatap-protocol-traffic/</link>
      <pubDate>Wed, 11 Dec 2013 00:07:00 +0000</pubDate>
      
      <guid>/questions/27992/isatap-protocol-traffic/</guid>
      <description>isatap protocol traffic  0 Hi
I&#39;m looking for some Pcaps of isatap . i tried at www.pcapr.net but i cant find it there. is there any chance someone has it ? it will be very helpful !
Thanks, Barak
tunnel ipv6asked 11 Dec &#39;13, 00:07
Barak_A
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Finding RTMP</title>
      <link>/questions/27994/finding-rtmp/</link>
      <pubDate>Wed, 11 Dec 2013 01:06:00 +0000</pubDate>
      
      <guid>/questions/27994/finding-rtmp/</guid>
      <description>Finding RTMP  0 Hello!I can&#39;t find RTMP url. When i want to find broadcast channel for example http://canli.kanald.com.tr/ &#39;s rtmp,i didn&#39;t find it&#39;s rtmp url.Please help me.
url rtmpasked 11 Dec &#39;13, 01:06
sonereser
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>show ICMP RTTs</title>
      <link>/questions/28007/show-icmp-rtts/</link>
      <pubDate>Wed, 11 Dec 2013 09:08:00 +0000</pubDate>
      
      <guid>/questions/28007/show-icmp-rtts/</guid>
      <description>show ICMP RTTs  1 I have a packet trace consisting solely of ICMP echo requests (probes) with a low ttl and corresponding ICMP time-exceeded messages (replies).
Is there a way for Wireshark to show the round-trip time (RTT) for each probe packet that I sent?
rtt icmpasked 11 Dec &#39;13, 09:08
rick_r
21●1●1●5
accept rate: 0%
  
2 Answers:
  
2 Option #1:
Take a look at the following output of tshark</description>
    </item>
    
    <item>
      <title>Can wireshark help me with my home wlan problem?(Cant login or post things on forums)</title>
      <link>/questions/28028/can-wireshark-help-me-with-my-home-wlan-problemcant-login-or-post-things-on-forums/</link>
      <pubDate>Wed, 11 Dec 2013 16:37:00 +0000</pubDate>
      
      <guid>/questions/28028/can-wireshark-help-me-with-my-home-wlan-problemcant-login-or-post-things-on-forums/</guid>
      <description>Can wireshark help me with my home wlan problem?(Cant login or post things on forums)  0 I made the following quesiton on superuser, please give it a look:
http://superuser.com/questions/686738/home-wlan-wont-let-me-do-very-specific-thingslog-in-facebook-post-on-some-for
And put a similar on ubuntuforuns.org . But got no answer yet.
Its strange because I don&#39;t get a &#39;page not found&#39; or &#39;timeout&#39; the page simply does not load.
I installed wireshark to see if I can get a clue on whats happening, but I don&#39;t know even what to look for.</description>
    </item>
    
    <item>
      <title>How to create a Protofield sub array in Lua</title>
      <link>/questions/28038/how-to-create-a-protofield-sub-array-in-lua/</link>
      <pubDate>Thu, 12 Dec 2013 01:14:00 +0000</pubDate>
      
      <guid>/questions/28038/how-to-create-a-protofield-sub-array-in-lua/</guid>
      <description>How to create a Protofield sub array in Lua  0 Hi, Given the following example:
local f= mycoolprotocol.fields f.Length = ProtoField.uint32(&amp;quot;MCP.Length&amp;quot;,&amp;quot;Length&amp;quot;,base.DEC) f.MsgType = ProtoField.uint16(&amp;quot;MCP.MsgType&amp;quot;,&amp;quot;MsgType&amp;quot;,base.DEC)I have declared 2 Protofields. But imagine I have a repeating group or an array of items:
And the message body looks like so:
struct person { int16 age; string name; } person[] p = new person[2];Ideally, I would like to create a subtree in Wireshark for that group</description>
    </item>
    
    <item>
      <title>How to write SCTP chunk flags, type, PPI, etc into the info column and how to add an info2 column??</title>
      <link>/questions/28044/how-to-write-sctp-chunk-flags-type-ppi-etc-into-the-info-column-and-how-to-add-an-info2-column/</link>
      <pubDate>Thu, 12 Dec 2013 02:25:00 +0000</pubDate>
      
      <guid>/questions/28044/how-to-write-sctp-chunk-flags-type-ppi-etc-into-the-info-column-and-how-to-add-an-info2-column/</guid>
      <description>How to write SCTP chunk flags, type, PPI, etc into the info column and how to add an info2 column??  0 Hi,
I was able to make a dissector for the chunk data itself (via PPI) but I would like to write some info about the chunk itself to the Info column if it is possible. Or even better: add a new column and write some bytes from the chunk info into it.</description>
    </item>
    
    <item>
      <title>Tshark doesn&amp;#x27;t display the longer data fields (mbtcp)</title>
      <link>/questions/28050/tshark-doesnt-display-the-longer-data-fields-mbtcp/</link>
      <pubDate>Thu, 12 Dec 2013 05:58:00 +0000</pubDate>
      
      <guid>/questions/28050/tshark-doesnt-display-the-longer-data-fields-mbtcp/</guid>
      <description>Tshark doesn&amp;rsquo;t display the longer data fields (mbtcp)  0 Hello,
I&#39;m using tshark to get some packets from a pcap file, and some of the data fields (the longer ones) are not displayed. For example:
10.0.100.211 10.0.2.234 68 126 05:03:01:00:00:30 10.0.2.234 10.0.100.211 70 126 07:03:01:00:00:30:08:83 10.0.100.211 10.0.2.234 68 126 05:03:10:00:00:30 10.0.2.234 10.0.100.211 100 126 10.0.100.211 10.0.2.234 68 126 05:03:01:0f:ff:51 10.0.2.234 10.0.100.211 70 126 07:03:01:0f:ff:51:00:01 10.0.100.211 10.0.2.234 68 126 05:03:08:00:01:51As you can see - the 4th packets&#39; data isn&#39;t displayed.</description>
    </item>
    
    <item>
      <title>Malformed packets with using encryption?</title>
      <link>/questions/28051/malformed-packets-with-using-encryption/</link>
      <pubDate>Thu, 12 Dec 2013 05:59:00 +0000</pubDate>
      
      <guid>/questions/28051/malformed-packets-with-using-encryption/</guid>
      <description>Malformed packets with using encryption?  0 Hello,
I sent a document with IPP - using https://address:631/printers/XXX or with IPP+TLS - using ipp://address:631/printers/XXX??encryption=required. Then I looked into capture file and IPP packets were malformed (printer output was correct). Is it normal (because of TLS) or is something wrong with it? When I try normal ipp://address:631/printers/XXX everything is OK.
Thank you.
tls ipp cups packet malformedasked 12 Dec &#39;13, 05:59
Andyn</description>
    </item>
    
    <item>
      <title>Capture only TZSP</title>
      <link>/questions/28053/capture-only-tzsp/</link>
      <pubDate>Thu, 12 Dec 2013 06:45:00 +0000</pubDate>
      
      <guid>/questions/28053/capture-only-tzsp/</guid>
      <description>Capture only TZSP  0 I want to capture a remote stream from a router. Normally I just capture everything and later deal with it, but there will be a ton of data, so might as well capture the minimum than I can.
What filter would I enter to capture only TZSP? Just entering tzsp in the filter field isn&#39;t valid syntax.
tzspasked 12 Dec &#39;13, 06:45
MHammett
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>TCP window full message after receiving ACK?</title>
      <link>/questions/28056/tcp-window-full-message-after-receiving-ack/</link>
      <pubDate>Thu, 12 Dec 2013 09:18:00 +0000</pubDate>
      
      <guid>/questions/28056/tcp-window-full-message-after-receiving-ack/</guid>
      <description>TCP window full message after receiving ACK?  0 link textThe client&#39;s window size is 2836, the client requested http on frame 4. The server start sending data on frame 5, my question is on frame 8, why wireshark says TCP window full given the client already acked on frame 6? my understanding is that tcp window full only displays when the server send the amount of data equal to client&#39;s window size without getting an ack back, in my case, the ack was received on frame 6.</description>
    </item>
    
    <item>
      <title>what is the purpose of server sending a [TCP Dup ACK] after sending data?</title>
      <link>/questions/28059/what-is-the-purpose-of-server-sending-a-tcp-dup-ack-after-sending-data/</link>
      <pubDate>Thu, 12 Dec 2013 10:25:00 +0000</pubDate>
      
      <guid>/questions/28059/what-is-the-purpose-of-server-sending-a-tcp-dup-ack-after-sending-data/</guid>
      <description>what is the purpose of server sending a [TCP Dup ACK] after sending data?  0 Did some search but couldn&#39;t find a good answer about the tcp dup ack. The server sent data on frame 4, immediately after that on frame 5, server sends a [TCP Dup ACK], the difference is between frame 4 and 5 is the seq number, what is the purpose of this ack from server?</description>
    </item>
    
    <item>
      <title>Delay in HTTP Status Packet and First TCP Segment</title>
      <link>/questions/28060/delay-in-http-status-packet-and-first-tcp-segment/</link>
      <pubDate>Thu, 12 Dec 2013 11:17:00 +0000</pubDate>
      
      <guid>/questions/28060/delay-in-http-status-packet-and-first-tcp-segment/</guid>
      <description>Delay in HTTP Status Packet and First TCP Segment  0 Hi,
I need help... can&#39;t figure out what is the cause of a Web Application Slowness Issue.
Can&#39;t think of what else to check anymore.
Web Application Server in Site A.
Users in Site B &amp;amp; C tries to access the Web Application.
Site A, B &amp;amp; C uses Riverbed WANX, however the traffic for this application is &#34;Passthrough Intentional&#34;</description>
    </item>
    
    <item>
      <title>SSL Handshake - only the Client Hello shows in the trace</title>
      <link>/questions/28061/ssl-handshake-only-the-client-hello-shows-in-the-trace/</link>
      <pubDate>Thu, 12 Dec 2013 11:22:00 +0000</pubDate>
      
      <guid>/questions/28061/ssl-handshake-only-the-client-hello-shows-in-the-trace/</guid>
      <description>SSL Handshake - only the Client Hello shows in the trace  0 I am tracing traffic between an iPhone and our Exchange server. When the iPhone syncs, Wireshark shows only the Client Hello. The remainder of the handshake does not show. I know the handshake is successful and that encrypted data is passed because email is synced, and Schannel Event ID 36880 &#34;An SSL server handshake completed successfully&#34; is generated soon after the Client Hello.</description>
    </item>
    
    <item>
      <title>SSL Decrypt works on my station but not those captured elsewhere on others</title>
      <link>/questions/28063/ssl-decrypt-works-on-my-station-but-not-those-captured-elsewhere-on-others/</link>
      <pubDate>Thu, 12 Dec 2013 11:56:00 +0000</pubDate>
      
      <guid>/questions/28063/ssl-decrypt-works-on-my-station-but-not-those-captured-elsewhere-on-others/</guid>
      <description>SSL Decrypt works on my station but not those captured elsewhere on others  0 I&#39;ve successfully set up ssl decrypt to work on my systems sessions with an ssl server by getting the private key. Works!
I have traces of other stations traffic that I need to analyze. I can&#39;t get those other stations traffic to decode. What&#39;s the unknown I&#39;m missing?
Thanks!
sslasked 12 Dec &#39;13, 11:56
packetman007</description>
    </item>
    
    <item>
      <title>Troubleshooting SQL Server Connection Latency</title>
      <link>/questions/28068/troubleshooting-sql-server-connection-latency/</link>
      <pubDate>Thu, 12 Dec 2013 23:51:00 +0000</pubDate>
      
      <guid>/questions/28068/troubleshooting-sql-server-connection-latency/</guid>
      <description>Troubleshooting SQL Server Connection Latency  0 We have a web app that is connecting to a remote SQL Server DB and is experiencing performance issues. To narrow the culprit down, we ruled out the network from the client to the webserver (webapp) and we did a DB trace of a typical function in the web app where users were seeing delays of up to 1 min -- and saw that the query only took 5 seconds once it was received by SQL Server.</description>
    </item>
    
    <item>
      <title>PDU reassembly over UDP within a lua dissector</title>
      <link>/questions/28076/pdu-reassembly-over-udp-within-a-lua-dissector/</link>
      <pubDate>Fri, 13 Dec 2013 05:39:00 +0000</pubDate>
      
      <guid>/questions/28076/pdu-reassembly-over-udp-within-a-lua-dissector/</guid>
      <description>PDU reassembly over UDP within a lua dissector  1 Hi,
I&#39;m willing to build a dissector able to reassemble PDUs spanned accross multiple UDP packets. My protocol have sequence/fragment IDs/total length, so there&#39;s everything needed to reassemble properly.
If i&#39;m not mistaken there&#39;s no automated assembly mechanism like for TCP within the API ( pinfo.desegment_len etc). So I take it I would have to implement a manual re-assembly.
But how can I pass data between 2 frames / dissector calls ?</description>
    </item>
    
    <item>
      <title>Frame Header 802.3 vs 802.11</title>
      <link>/questions/28084/frame-header-8023-vs-80211/</link>
      <pubDate>Fri, 13 Dec 2013 10:20:00 +0000</pubDate>
      
      <guid>/questions/28084/frame-header-8023-vs-80211/</guid>
      <description>Frame Header 802.3 vs 802.11  0 Where can I see the difference of wired vs wireless in the frame header structure in wireshark? And what describes the physical setup in both 802.3 &amp;amp; 802.11?
Thanks!
802.11 802.3asked 13 Dec &#39;13, 10:20
John92
11●1●1●2
accept rate: 0%
  
One Answer:
  
0This sounds suspiciously like a HomeWork assignment. Anyway - wireless frames have an additional radio layer that is followed by the ethernet header that you will see on the wire.</description>
    </item>
    
    <item>
      <title>Where can I find the parameters that can be specified in a .Ini for RPCAPD?</title>
      <link>/questions/28089/where-can-i-find-the-parameters-that-can-be-specified-in-a-ini-for-rpcapd/</link>
      <pubDate>Fri, 13 Dec 2013 11:51:00 +0000</pubDate>
      
      <guid>/questions/28089/where-can-i-find-the-parameters-that-can-be-specified-in-a-ini-for-rpcapd/</guid>
      <description>Where can I find the parameters that can be specified in a .Ini for RPCAPD?  0 I am attempting to use rpcapd &amp;amp; wireshark to gather some data remotely. I have been able to use the parameters displayed using the -h parameter from the command line. But I have not been able to locate the parameters and their syntax for use in a .ini file specified using the -f parameter.</description>
    </item>
    
    <item>
      <title>Wireshark stops saving capture</title>
      <link>/questions/28091/wireshark-stops-saving-capture/</link>
      <pubDate>Fri, 13 Dec 2013 15:48:00 +0000</pubDate>
      
      <guid>/questions/28091/wireshark-stops-saving-capture/</guid>
      <description>Wireshark stops saving capture  0 I have a dedicated VM on ESXi running Wireshark capturing one interface to multiple files. Looking at the data directory it will go along for a while and just quit after about 15 files, saving a new file every 1-2 minutes. It looks like it is capturing on the screen, in fact when I look at it and have it move to the bottom of the captures it seems to restart saving.</description>
    </item>
    
    <item>
      <title>How do you capture RTP packets?</title>
      <link>/questions/28104/how-do-you-capture-rtp-packets/</link>
      <pubDate>Sat, 14 Dec 2013 04:24:00 +0000</pubDate>
      
      <guid>/questions/28104/how-do-you-capture-rtp-packets/</guid>
      <description>How do you capture RTP packets?  0 how to see the higher-level protocol carried by a packet
livecapturetcpasked 14 Dec &#39;13, 04:24
Mauricio
11●1●1●2
accept rate: 0%
Could you elaborate on exactly what you&#39;re trying to see or do? Capturing RTP packets is the same as capturing any other. When you ask how to see higher level protocols, in general wireshark will dissect/display every layer it knows how to. What specifically are you trying to accomplish?</description>
    </item>
    
    <item>
      <title>Qt not available error?</title>
      <link>/questions/28105/qt-not-available-error/</link>
      <pubDate>Sat, 14 Dec 2013 10:56:00 +0000</pubDate>
      
      <guid>/questions/28105/qt-not-available-error/</guid>
      <description>Qt not available error?  0 This might be a dumb question since no one asked before.
I used git to clone the code base. And I am on Mac, so I run macosx-setup script to setup the environment. Everything went OK except there is a CURL error with libsmi. I found that it&#39;s an optional package so I commented out this line and installed libsmi with &#39;port install libsmi&#39;. Then I tried to configure, it gives me this message:</description>
    </item>
    
    <item>
      <title>How to draw graphs for two or more capture files in a single IO graph?</title>
      <link>/questions/28106/how-to-draw-graphs-for-two-or-more-capture-files-in-a-single-io-graph/</link>
      <pubDate>Sat, 14 Dec 2013 11:14:00 +0000</pubDate>
      
      <guid>/questions/28106/how-to-draw-graphs-for-two-or-more-capture-files-in-a-single-io-graph/</guid>
      <description>How to draw graphs for two or more capture files in a single IO graph?  0 Hi,
I would like to know if it is possible to draw graphs for two or more capture files in a single IO graph. I could find only &#39;compare&#39; tool but thats not what I am looking for. I just want to plot IO graphs of more than two capture files in a single IO graph.</description>
    </item>
    
    <item>
      <title>TCP StreamGraph Throughput</title>
      <link>/questions/28110/tcp-streamgraph-throughput/</link>
      <pubDate>Sat, 14 Dec 2013 13:13:00 +0000</pubDate>
      
      <guid>/questions/28110/tcp-streamgraph-throughput/</guid>
      <description>TCP StreamGraph Throughput  0 If I run a TCP throughput graph I see that there are plots placed at around 450,000,000 bytes. However if I add up the bytes from the total bytes column from the statistics of the same capture via tshark I get a total of 163,672,972 bytes.
The Tshark command is : &#34;C:\Program Files\Wireshark\tshark.exe&#34; -q -z conv,ip -r C:\capture.pcap
Can anyone explain how the TCP throughput graph is calculated , and why this difference is occuring.</description>
    </item>
    
    <item>
      <title>How to copy IO graph from wireshark to LibreOffice Calc?</title>
      <link>/questions/28111/how-to-copy-io-graph-from-wireshark-to-libreoffice-calc/</link>
      <pubDate>Sat, 14 Dec 2013 17:00:00 +0000</pubDate>
      
      <guid>/questions/28111/how-to-copy-io-graph-from-wireshark-to-libreoffice-calc/</guid>
      <description>How to copy IO graph from wireshark to LibreOffice Calc?  0 I am working with Wireshark on Ubuntu. I have collected packets and I am trying to copy IO graph from the IO graph window using &#39;Copy&#39; button and paste it into &#39;LibraOffice Calc&#39; the excel of Ubuntu. But it is not getting pasted at all. There are only few values getting pasted but not the graph. Could anyone please let me know how to do this?</description>
    </item>
    
    <item>
      <title>How to unpack a sniff file</title>
      <link>/questions/28116/how-to-unpack-a-sniff-file/</link>
      <pubDate>Sun, 15 Dec 2013 04:26:00 +0000</pubDate>
      
      <guid>/questions/28116/how-to-unpack-a-sniff-file/</guid>
      <description>How to unpack a sniff file  0 Hello, I have catched 2 files with wireshark but I have no idea, how to unpack, or filter the sniff, to get the files.
http://forum.ican3800.zajsoft.net/download/ADB3800TW-Italy/capture1_win.pcap
http://forum.ican3800.zajsoft.net/download/ADB3800TW-Italy/capture1.pcap
Can somebody help me please?
firmware unpack sniffasked 15 Dec &#39;13, 04:26
joseff
11●1●1●3
accept rate: 0%
 edited 15 Dec &#39;13, 04:28 
What kind of files?
(15 Dec &#39;13, 06:48) Kurt Knochner ♦It is a Firmware update by using a TFTP transfer.</description>
    </item>
    
    <item>
      <title>filter: opposite of &amp;quot;contains&amp;quot;?</title>
      <link>/questions/28133/filter-opposite-of-contains/</link>
      <pubDate>Sun, 15 Dec 2013 13:48:00 +0000</pubDate>
      
      <guid>/questions/28133/filter-opposite-of-contains/</guid>
      <description>filter: opposite of &amp;ldquo;contains&amp;rdquo;?  0 OK, I know when I want to filter out HTTPs which have wanted text in them i type:
http.referer contains &#34;text&#34;
but what is the command to display all HTTPs except the ones which have certain text in them (which is now unwanted)?
filter contains httpasked 15 Dec &#39;13, 13:48
myrddin
11●7●8●10
accept rate: 0%
  
2 Answers:
  
2Try</description>
    </item>
    
    <item>
      <title>Decoding Ethernet Encapsulated In TCP or UDP?</title>
      <link>/questions/28138/decoding-ethernet-encapsulated-in-tcp-or-udp/</link>
      <pubDate>Sun, 15 Dec 2013 15:20:00 +0000</pubDate>
      
      <guid>/questions/28138/decoding-ethernet-encapsulated-in-tcp-or-udp/</guid>
      <description>Decoding Ethernet Encapsulated In TCP or UDP?  0 Is there any way to get Wireshark to decode Ethernet frames that have been encapsulated/tunneled in a TCP (or UDP if that as easier) stream? I played around a bit with the &#34;Decode As...&#34; functionality but didn&#39;t have any luck.
tunnel decode decode_asasked 15 Dec &#39;13, 15:20
Teddy P
26●1●1●5
accept rate: 0%
 edited 15 Dec &#39;13, 15:22 
what kind of encapsulation is this?</description>
    </item>
    
    <item>
      <title>Can&amp;#x27;t decrypt ssl in capture from windump</title>
      <link>/questions/28145/cant-decrypt-ssl-in-capture-from-windump/</link>
      <pubDate>Mon, 16 Dec 2013 04:19:00 +0000</pubDate>
      
      <guid>/questions/28145/cant-decrypt-ssl-in-capture-from-windump/</guid>
      <description>Can&amp;rsquo;t decrypt ssl in capture from windump  0 having trouble decrypting ssl; I am trying to analyze a capture file created by windump.
Someone else had a similar question, and the response was to check three things: a) private key b) ssl handshake c) encryption type
I have exported the server cert, converted to pem and separated out the private key. In the file, it says &#39;rsa&#39;, and there is no reference to &#39;ephemeral&#39;</description>
    </item>
    
    <item>
      <title>Error: Can&amp;#x27;t get list of interfaces: Incompatiable version number: message discarded</title>
      <link>/questions/28147/error-cant-get-list-of-interfaces-incompatiable-version-number-message-discarded/</link>
      <pubDate>Mon, 16 Dec 2013 04:29:00 +0000</pubDate>
      
      <guid>/questions/28147/error-cant-get-list-of-interfaces-incompatiable-version-number-message-discarded/</guid>
      <description>Error: Can&amp;rsquo;t get list of interfaces: Incompatiable version number: message discarded  0 Hi,
I have installed Wireshark 1.10.3 and winpcap 4.1.3 in my local windows machine. Tried to add remote interfaces for the specific host name by specifying host name for host , port number for port, and username. password for password authentication. i am getting the error &#34;can&#39;t get list of interfaces:incompatiable version number: message discarded.
I verified that remote host name is accesible from my local windows machine.</description>
    </item>
    
    <item>
      <title>Monitor UDP</title>
      <link>/questions/28159/monitor-udp/</link>
      <pubDate>Mon, 16 Dec 2013 07:20:00 +0000</pubDate>
      
      <guid>/questions/28159/monitor-udp/</guid>
      <description>Monitor UDP  0 How do I setup wireshark to monitor UDP port 514 from a IP phone?
udpasked 16 Dec &#39;13, 07:20
tpodlak
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Assuming the IP phone is connected to a switch, you need to configure a monitor port that will copy all traffic from the port of the IP phone to a port on which you have connected your system with wireshark.</description>
    </item>
    
    <item>
      <title>Bad Header Checksum</title>
      <link>/questions/28176/bad-header-checksum/</link>
      <pubDate>Mon, 16 Dec 2013 11:50:00 +0000</pubDate>
      
      <guid>/questions/28176/bad-header-checksum/</guid>
      <description>Bad Header Checksum  0 Help !!! 3.4% of my traffic are Checksum Errors all eminating from a single IP address. How significant is this? What is checksum offload? Header checksum: 0x0000 [incorrect, should be 0x7d7d (may be caused by &#34;IP checksum offload&#34;?)]
badchecksumasked 16 Dec &#39;13, 11:50
Zoberist
0●7●7●8
accept rate: 0%
  
One Answer:
  
0You can most likely ignore it. Check the IP, it&#39;s your own.</description>
    </item>
    
    <item>
      <title>Filter current nearby wifi devices</title>
      <link>/questions/28178/filter-current-nearby-wifi-devices/</link>
      <pubDate>Mon, 16 Dec 2013 12:04:00 +0000</pubDate>
      
      <guid>/questions/28178/filter-current-nearby-wifi-devices/</guid>
      <description>Filter current nearby wifi devices  0 I&#39;m trying to get a list of all the nearby devices with wifi turned on. I&#39;m currently using the filter &#39;wlan.fc.type_subtype == 0x04&#39; but it&#39;s filling up too quickly, causing loss of overview. Does Wireshark have the ability only show frames from the last 20 seconds? And is it possible to tag frames from a certain mac-address so I can easily identify known phones?</description>
    </item>
    
    <item>
      <title>Configuration Profile Confusion</title>
      <link>/questions/28180/configuration-profile-confusion/</link>
      <pubDate>Mon, 16 Dec 2013 13:05:00 +0000</pubDate>
      
      <guid>/questions/28180/configuration-profile-confusion/</guid>
      <description>Configuration Profile Confusion  0 This is embarrassing, but does anyone else find setting and saving the Wireshark configuration profiles confusing?
Here&#39;s the use cases I&#39;d like enumerated:
1) I have my columns set just the way I want them. I now want to save the setup as a configuration profile so I can reapply them later.
This is what I currently do:
Under configuration profiles, hit new for a new profile.</description>
    </item>
    
    <item>
      <title>Wireshark Development Support Library Directory-structure, and Configure, Dependencies</title>
      <link>/questions/28185/wireshark-development-support-library-directory-structure-and-configure-dependencies/</link>
      <pubDate>Mon, 16 Dec 2013 13:39:00 +0000</pubDate>
      
      <guid>/questions/28185/wireshark-development-support-library-directory-structure-and-configure-dependencies/</guid>
      <description>Wireshark Development Support Library Directory-structure, and Configure, Dependencies  0 The Wireshark development environment needs GTK (which needs Glib, and some others) and Libpcap; however, I cannot find information on the directory-structure dependencies (e.g., directory names, and where the parent directory should be located) and the order of running &#34;configure&#34; for each library.
So: [1] should the support libraries be untar&#39;ed to particular directory names? [2] is there an order sequence to follow in running the configure script within each support library directory structure?</description>
    </item>
    
    <item>
      <title>home router repetitive ARP request</title>
      <link>/questions/28192/home-router-repetitive-arp-request/</link>
      <pubDate>Tue, 17 Dec 2013 00:08:00 +0000</pubDate>
      
      <guid>/questions/28192/home-router-repetitive-arp-request/</guid>
      <description>home router repetitive ARP request  0 hi, I am wondering why my router (also DHCP server) keeps ARP requesting non-stop to my home PC
my rounter is D-Link N600: http://www.dlink.com/ca/en/home-solutions/connect/routers/dir-826l-cloud-gigabit-router-n600
here&#39;s a picture of the traffic: http://i.imgur.com/4zTiu6V.jpg
arp router requestasked 17 Dec &#39;13, 00:08
thisistherun
1●1●1●2
accept rate: 0%
  
One Answer:
  
2why my router (also DHCP server) keeps ARP requesting non-stop to my home PC</description>
    </item>
    
    <item>
      <title>v4 vs v6 packets</title>
      <link>/questions/28196/v4-vs-v6-packets/</link>
      <pubDate>Tue, 17 Dec 2013 01:23:00 +0000</pubDate>
      
      <guid>/questions/28196/v4-vs-v6-packets/</guid>
      <description>v4 vs v6 packets  0 Hi, If I am sending some payload both using v4 and v6 then how it&#39;ll differ exactly? I observed the payload difference in both v4 and v6 traffic.
Please clarify on this.
v4v6asked 17 Dec &#39;13, 01:23
sspallai
11●1●1●2
accept rate: 0%
  
One Answer:
  
0The payload should be identical if you choose a different protocol, if the code is really the same.</description>
    </item>
    
    <item>
      <title>extract specific number of packets to text and csv.</title>
      <link>/questions/28211/extract-specific-number-of-packets-to-text-and-csv/</link>
      <pubDate>Tue, 17 Dec 2013 05:15:00 +0000</pubDate>
      
      <guid>/questions/28211/extract-specific-number-of-packets-to-text-and-csv/</guid>
      <description>extract specific number of packets to text and csv.  0 Hi,
I have a traffic sample in pcap format, I want to export the data as txt and csv files. Here is the code which I am using:
for CSV:
tshark -Y &#34;ip&#34; -r a.pcap -T fields -e frame.number -e ip.proto -e ip.src -e tcp.srcport -e udp.srcport -e ip.dst -e tcp.dstport -e udp.dstport -e frame.len -e frame.time_delta -e tcp.flags -e frame.</description>
    </item>
    
    <item>
      <title>Sending Captured IP Commands</title>
      <link>/questions/28221/sending-captured-ip-commands/</link>
      <pubDate>Tue, 17 Dec 2013 11:59:00 +0000</pubDate>
      
      <guid>/questions/28221/sending-captured-ip-commands/</guid>
      <description>Sending Captured IP Commands  0 Hi Guys,
I am trying to figure out the commands that various AV devices use to perform functions (volume up, down, mute.) etc. so I can put them in another app (not from the manufacturer) and combine to control lots of devices from one app.
I have so far captured the dump and found AAAAAQAAAAEAAAAUAw== means mute, but there is a bit more involved like the HTTP PORT command.</description>
    </item>
    
    <item>
      <title>tshark crashed without any reason in output log</title>
      <link>/questions/28224/tshark-crashed-without-any-reason-in-output-log/</link>
      <pubDate>Tue, 17 Dec 2013 18:00:00 +0000</pubDate>
      
      <guid>/questions/28224/tshark-crashed-without-any-reason-in-output-log/</guid>
      <description>tshark crashed without any reason in output log  0 Hi all, I&#39;m using tshark to capture data. Normally, my tshark can run in 12 days but yesterday, it suddenly crashed after 2 days of running. On the screen displayed, I didn&#39;t see any error. Here is my command:
nohup tshark -i 5 -P -w /tmp/Log.pcap -b filesize:655350|split -b 655350000 - /tmp/log/log- &amp;amp;About the cronjob, I use 2 cronjob to delete old files:</description>
    </item>
    
    <item>
      <title>[closed] How to reestablish Security on Wireless Router?</title>
      <link>/questions/28225/how-to-reestablish-security-on-wireless-router/</link>
      <pubDate>Tue, 17 Dec 2013 19:05:00 +0000</pubDate>
      
      <guid>/questions/28225/how-to-reestablish-security-on-wireless-router/</guid>
      <description>[closed] How to reestablish Security on Wireless Router?  0 Using windows XP and have a D-Link Wireless Router Model # wbr-1310. Notified by neighbor that my internet was not secure. Please tell me step by step way to reestablish password protection again? Also, Is there a way that I can find out if I was high jacked? Thanks
geoteksasked 17 Dec &#39;13, 19:05
geoteks
1●1●1●1
accept rate: 0%
 closed 18 Dec &#39;13, 00:23</description>
    </item>
    
    <item>
      <title>Learning to hack my own network</title>
      <link>/questions/28226/learning-to-hack-my-own-network/</link>
      <pubDate>Tue, 17 Dec 2013 19:07:00 +0000</pubDate>
      
      <guid>/questions/28226/learning-to-hack-my-own-network/</guid>
      <description>Learning to hack my own network  0 I honestly am completely new to this, I want to learn and this was my first project.
How do I know which packets are important to me? This is a WEPA2 Secure network with a complex random password.
password networkasked 17 Dec &#39;13, 19:07
Takashi Hand
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1Do you mean WEP, or WPA2?</description>
    </item>
    
    <item>
      <title>Isolating the Subnet</title>
      <link>/questions/28227/isolating-the-subnet/</link>
      <pubDate>Tue, 17 Dec 2013 20:21:00 +0000</pubDate>
      
      <guid>/questions/28227/isolating-the-subnet/</guid>
      <description>Isolating the Subnet  0 I&#39;ve gone ahead and created the filter [ip.addr == 192.168.0.1/24], with the hope of only monitoring my local subnet in the Endpoints/ IPv4 window, but am still getting all the other IP addresses popping up. Any suggestions on only capturing my local network (192.168.0.1-254)?
ipv4 filtersasked 17 Dec &#39;13, 20:21
johncalvinhall
11●1●1●3
accept rate: 0%
 converted to question 17 Dec &#39;13, 20:30</description>
    </item>
    
    <item>
      <title>Flooded network due to [TCP Retransmission] localinfosrvr &amp;gt; hp-pdl-datastr [SYN] packets</title>
      <link>/questions/28241/flooded-network-due-to-tcp-retransmission-localinfosrvr-hp-pdl-datastr-syn-packets/</link>
      <pubDate>Wed, 18 Dec 2013 02:10:00 +0000</pubDate>
      
      <guid>/questions/28241/flooded-network-due-to-tcp-retransmission-localinfosrvr-hp-pdl-datastr-syn-packets/</guid>
      <description>Flooded network due to [TCP Retransmission] localinfosrvr &amp;gt; hp-pdl-datastr [SYN] packets  0 Hi all:
I have a LAN (~100 PC&#39;s, 10 servers, 6 Enterasys B3G124-48) that is having 3/4 blackouts a day; blackout meaning all switches ports blinking at the same time, big latency, and hughe packet loss, with no other solution rather than turning switches and routers off, wait, turn them on, and OK.
My first approach (quite newbie to this), is to &#34;</description>
    </item>
    
    <item>
      <title>Mac OS 10.9 Mavericks: Wireshark always crash right after I started the capture</title>
      <link>/questions/28244/mac-os-109-mavericks-wireshark-always-crash-right-after-i-started-the-capture/</link>
      <pubDate>Wed, 18 Dec 2013 02:58:00 +0000</pubDate>
      
      <guid>/questions/28244/mac-os-109-mavericks-wireshark-always-crash-right-after-i-started-the-capture/</guid>
      <description>Mac OS 10.9 Mavericks: Wireshark always crash right after I started the capture  0 Hello everyone, I&#39;ve been desperate trying to start my Wireshark app (1.10.4) on my macbook air (mid 2012 model) with no luck in the past one month.
Before upgrading my OS, my wireshark has been working great with Mac OS 10.8 (mountain lion).
I already updated my X11 to the latest 2.7.5 and using the stable wireshark 1.</description>
    </item>
    
    <item>
      <title>Validate Wireshark, as per US Food and Drug Administration requirements, for small tcp/ip system</title>
      <link>/questions/28256/validate-wireshark-as-per-us-food-and-drug-administration-requirements-for-small-tcpip-system/</link>
      <pubDate>Wed, 18 Dec 2013 07:59:00 +0000</pubDate>
      
      <guid>/questions/28256/validate-wireshark-as-per-us-food-and-drug-administration-requirements-for-small-tcpip-system/</guid>
      <description>Validate Wireshark, as per US Food and Drug Administration requirements, for small tcp/ip system  0 I am using Wireshark to validate the tcp/ip protocols of a small system. However, I must first validate Wireshark itself for tcp/ip protocols before I can use it to validate another system. Anyone have any simple solutions?
validate tcp_ipasked 18 Dec &#39;13, 07:59
cgoogins
11●1●1●2
accept rate: 0%
 edited 18 Dec &#39;13, 12:52</description>
    </item>
    
    <item>
      <title>revive/continue ring buffer</title>
      <link>/questions/28273/revivecontinue-ring-buffer/</link>
      <pubDate>Wed, 18 Dec 2013 12:55:00 +0000</pubDate>
      
      <guid>/questions/28273/revivecontinue-ring-buffer/</guid>
      <description>revive/continue ring buffer  0 Hi,
for reconstruction of network attacks or failures I am currently working on a system that stores all incoming network-traffic on a harddrive. So far this works completely fine, also due to the ring buffer feature. But: After shutdown I would very much like to continue my existing ring buffer without having to manually delete the old files. Unfortunately I did not yet find any hint on how to achieve this.</description>
    </item>
    
    <item>
      <title>Capture HTTP requests from my iPhone (Analyzing an app)</title>
      <link>/questions/28279/capture-http-requests-from-my-iphone-analyzing-an-app/</link>
      <pubDate>Wed, 18 Dec 2013 21:37:00 +0000</pubDate>
      
      <guid>/questions/28279/capture-http-requests-from-my-iphone-analyzing-an-app/</guid>
      <description>Capture HTTP requests from my iPhone (Analyzing an app)  0 Hi,
what i want to achieve is to analyze an iPhone app. I have Backtrack installed and a monitor mode enabled wireless device. I can set my iPhone as well as the device to join the same wireless network if needed.
So far i tried to capture all packets floating around with my device and filtering out packets sent from the iPhone, without much success.</description>
    </item>
    
    <item>
      <title>does wireshark support decrypting ssl sessions with &amp;#x27;tls session tickets&amp;#x27;?</title>
      <link>/questions/28282/does-wireshark-support-decrypting-ssl-sessions-with-tls-session-tickets/</link>
      <pubDate>Wed, 18 Dec 2013 23:51:00 +0000</pubDate>
      
      <guid>/questions/28282/does-wireshark-support-decrypting-ssl-sessions-with-tls-session-tickets/</guid>
      <description>does wireshark support decrypting ssl sessions with &amp;lsquo;tls session tickets&amp;rsquo;?  0 I&#39;m pretty sure i&#39;ve finally configured ssl to correctly decrypt my ssl packets, from a capture of and ssl session on and IIS 7.5 server.
I say this, because when i use the filter &#39;ssl&#39; in wireshark, i occasionally see a green http packet, and when inspecting the packet, i can see the ssl section in the detail window, followed by the decrypted http packet information.</description>
    </item>
    
    <item>
      <title>Mac adress of the IP</title>
      <link>/questions/28286/mac-adress-of-the-ip/</link>
      <pubDate>Thu, 19 Dec 2013 04:23:00 +0000</pubDate>
      
      <guid>/questions/28286/mac-adress-of-the-ip/</guid>
      <description>Mac adress of the IP  0 Hi, I have this captured packet file and I need to find the mac adress of 192.168.1.13 I find it difficult. Can anyone help please?
wiresharkThis question is marked &#34;community wiki&#34;.asked 19 Dec &#39;13, 04:23
saanwer
1●1●1●1
accept rate: 0%
  
One Answer:
  
1maybe this can help you
answered 19 Dec &#39;13, 05:24
straw
31●1●1●6
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Not capturing in promiscuous mode in Windows 7 x64</title>
      <link>/questions/28294/not-capturing-in-promiscuous-mode-in-windows-7-x64/</link>
      <pubDate>Thu, 19 Dec 2013 09:45:00 +0000</pubDate>
      
      <guid>/questions/28294/not-capturing-in-promiscuous-mode-in-windows-7-x64/</guid>
      <description>Not capturing in promiscuous mode in Windows 7 x64  0 It appears that setting promiscuous mode in windows 7 enterprise x64, is not really setting promiscuous mode at all. I am trying to capture raw ethernet packets, ie not TCP/IP or any other format, it is debugging information. I have it directly connected, no switches. All drivers, winpcpap, and wireshark are up to date. When I start the capture, if I look at the &#34;</description>
    </item>
    
    <item>
      <title>Questions on packet-kafka.c</title>
      <link>/questions/28304/questions-on-packet-kafkac/</link>
      <pubDate>Fri, 20 Dec 2013 04:09:00 +0000</pubDate>
      
      <guid>/questions/28304/questions-on-packet-kafkac/</guid>
      <description>Questions on packet-kafka.c  0 Hello,
I have some observations on packet-kafka.c, that do not look correct to me. Can somebody comment on them ? (I am very new to this so please forgive me if this question is trivial).
1) No attempt to call proto_item_add_subtree(ti, ett_kafka_metadata_topics); yet &amp;quot;ett_kafka_metadata_topics&amp;quot; is contained in an array that is passed to proto_register_subtree_array(..);  There are multiple invocations of the following where the second argument is not unique.</description>
    </item>
    
    <item>
      <title>Is there a more complete example about how to add a new capture type to libpcap?</title>
      <link>/questions/28308/is-there-a-more-complete-example-about-how-to-add-a-new-capture-type-to-libpcap/</link>
      <pubDate>Fri, 20 Dec 2013 10:12:00 +0000</pubDate>
      
      <guid>/questions/28308/is-there-a-more-complete-example-about-how-to-add-a-new-capture-type-to-libpcap/</guid>
      <description>Is there a more complete example about how to add a new capture type to libpcap?  0 In the Wireshark Developer&#39;s Guide, section 8 (http://www.wireshark.org/docs/wsdg_html/#ChCaptureAddLibpcap) briefly describes &#34;How to add a new capture type to libpcap&#34;. I am developing a dissector for a unique protocol whose traffic has been captured into a pcap file. Is there a more complete example on how to determine a DLT_ value (DLT_user?), modify the wtap.</description>
    </item>
    
    <item>
      <title>Hardware for Capture USB data packet</title>
      <link>/questions/28310/hardware-for-capture-usb-data-packet/</link>
      <pubDate>Fri, 20 Dec 2013 23:58:00 +0000</pubDate>
      
      <guid>/questions/28310/hardware-for-capture-usb-data-packet/</guid>
      <description>Hardware for Capture USB data packet  0 I would like to monitor the USB data traffic by using Wireshark,
I am seeking for hardware to capture the data signal and send to PC, then analyse by wireshark. What kinds of hardware are available?
protocol usbasked 20 Dec &#39;13, 23:58
rabbit
1●4●4●5
accept rate: 0%
  
2 Answers:
  
0Do you really need special hardware? Take a look at http://wiki.</description>
    </item>
    
    <item>
      <title>SSL Decryption: only for http and few other protocols</title>
      <link>/questions/28311/ssl-decryption-only-for-http-and-few-other-protocols/</link>
      <pubDate>Sat, 21 Dec 2013 03:19:00 +0000</pubDate>
      
      <guid>/questions/28311/ssl-decryption-only-for-http-and-few-other-protocols/</guid>
      <description>SSL Decryption: only for http and few other protocols  0 Hello Team,
I can decrypt SSL inside TCP on different ports. That works fine as long at that is typical protocol like http or smtp or ldap...
But i have custom/prioprietary protocol inside that SSL. In the past i did not have any problems with that, i could see binary MSCHAPv2 session inside SSL: https://supportforums.cisco.com/servlet/JiveServlet/showImage/38-2724-125782/packet11-mod.png
But right now with version 1.</description>
    </item>
    
    <item>
      <title>Has anyone used Wireshark to troubleshoot ICEfaces?</title>
      <link>/questions/28315/has-anyone-used-wireshark-to-troubleshoot-icefaces/</link>
      <pubDate>Sat, 21 Dec 2013 12:36:00 +0000</pubDate>
      
      <guid>/questions/28315/has-anyone-used-wireshark-to-troubleshoot-icefaces/</guid>
      <description>Has anyone used Wireshark to troubleshoot ICEfaces?  0 I am in the process of troubleshooting a latency issue. The application is written using ICEfaces and is using SSO. I am wondering if there is a better filter to use other than ip.addr of the workstation and server. I can see a lot of pauses between packets coming from the server. I am not sure if this is due to lack of user input or actual slowness of the server to respond.</description>
    </item>
    
    <item>
      <title>I would like to get hold of the owner of the ethereal.net domain, can anyone help?</title>
      <link>/questions/28316/i-would-like-to-get-hold-of-the-owner-of-the-etherealnet-domain-can-anyone-help/</link>
      <pubDate>Sat, 21 Dec 2013 14:30:00 +0000</pubDate>
      
      <guid>/questions/28316/i-would-like-to-get-hold-of-the-owner-of-the-etherealnet-domain-can-anyone-help/</guid>
      <description>I would like to get hold of the owner of the ethereal.net domain, can anyone help?  -1 Hi There,
I&#39;ve been trying to get hold of the owner for a couple of weeks now and have been unable to find any contact information.
Ive resorted to asking on the forums in case someone might be able to point me the right way.
Thanks.
owner contactasked 21 Dec &#39;13, 14:30</description>
    </item>
    
    <item>
      <title>capture commands over LAN from laptop to wireless speakers</title>
      <link>/questions/28320/capture-commands-over-lan-from-laptop-to-wireless-speakers/</link>
      <pubDate>Sun, 22 Dec 2013 05:09:00 +0000</pubDate>
      
      <guid>/questions/28320/capture-commands-over-lan-from-laptop-to-wireless-speakers/</guid>
      <description>capture commands over LAN from laptop to wireless speakers  0 I&#39;ve got some tasty Philips speakers connected to my network and want to bypass the dodgy Philips software and send commands directly from my OpenRemote app. I&#39;ve requested an API or developers pack from Philips but they seem reluctant...well the reply was a flat &#39;no&#39;!
I&#39;m looking at the traffic between my laptop and speakers and guessing most of it is streaming mp3.</description>
    </item>
    
    <item>
      <title>[closed] Search for Client Controller (botnet) in WireShark</title>
      <link>/questions/28321/search-for-client-controller-botnet-in-wireshark/</link>
      <pubDate>Sun, 22 Dec 2013 06:05:00 +0000</pubDate>
      
      <guid>/questions/28321/search-for-client-controller-botnet-in-wireshark/</guid>
      <description>[closed] Search for Client Controller (botnet) in WireShark  0 Hello guys,
Iam searching for a client controller from a botnet in a PCAP file. Is there somebody who knows where and how I am able to find the client controller. The PCAP file is about 75mb with all kinds of different ip addresses.
I am not familiar with WireShark yet.
Any help will be appreciated.
Thanks in advance.
Regards,</description>
    </item>
    
    <item>
      <title>Has anyone got the ethers file to work in version 1.10.5?</title>
      <link>/questions/28322/has-anyone-got-the-ethers-file-to-work-in-version-1105/</link>
      <pubDate>Sun, 22 Dec 2013 09:29:00 +0000</pubDate>
      
      <guid>/questions/28322/has-anyone-got-the-ethers-file-to-work-in-version-1105/</guid>
      <description>Has anyone got the ethers file to work in version 1.10.5?  0 I am slowly working my way through the Wireshark Network Analysis book. I am trying to replicate the example on page 166 Chapter 5. The example figure 98 shows ethers.txt I created both files one without and one with a file extension. Both in my profiles directory. I have tried restarting Wireshark but I am unable to get Wireshark to recognize the name of my NIC.</description>
    </item>
    
    <item>
      <title>Troubleshooting SCTP packets on IPSec Tunnels</title>
      <link>/questions/28333/troubleshooting-sctp-packets-on-ipsec-tunnels/</link>
      <pubDate>Sun, 22 Dec 2013 20:23:00 +0000</pubDate>
      
      <guid>/questions/28333/troubleshooting-sctp-packets-on-ipsec-tunnels/</guid>
      <description>Troubleshooting SCTP packets on IPSec Tunnels  1 Hi,
I would like to know if there is any mechanism to decrypt and analyze the SCTP packets exchanged over IPSec tunnels between two end nodes, for troubleshooting using Wireshark or tshark?
Please advise.
Regards, SC
sctp ipsec decrypt wiresharkasked 22 Dec &#39;13, 20:23
tintin
26●1●1●3
accept rate: 0%
  
One Answer:
  
0Try it by setting preferences for ESP option.</description>
    </item>
    
    <item>
      <title>Wireshark not opening?</title>
      <link>/questions/28334/wireshark-not-opening/</link>
      <pubDate>Sun, 22 Dec 2013 22:44:00 +0000</pubDate>
      
      <guid>/questions/28334/wireshark-not-opening/</guid>
      <description>Wireshark not opening?  0 Hello i am using MAC Mavericks system.i have installed wireshark .dmg and x11 .dmg .but in Xterm when I&#39;m trying to open wireshark ,using the command
bash-3.2$ open/Applications/Wireshark.app/ i get the following message. bash: open/Applications/Wireshark.app/: No such file or directory.
I am a newbie in wireshark.please help me .I am trying to open wireshark actually
osx wiresharkasked 22 Dec &#39;13, 22:44
surajkthomas
16●2●2●5
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to Analyse Connectivity status between Two Hosts.</title>
      <link>/questions/28335/how-to-analyse-connectivity-status-between-two-hosts/</link>
      <pubDate>Sun, 22 Dec 2013 22:49:00 +0000</pubDate>
      
      <guid>/questions/28335/how-to-analyse-connectivity-status-between-two-hosts/</guid>
      <description>How to Analyse Connectivity status between Two Hosts.  0 Hi Forum, I want to analyse the connectivity between two hosts. Collected pcap trace for the same. Now need to check whether connection has been established or not.
Can someone help how do i track this?
Thank you, Br: Srinivas Vandanapu.
connectivityasked 22 Dec &#39;13, 22:49
vandanap
11●1●1●2
accept rate: 0%
  
One Answer:
  
1Now need to check whether connection has been established or not.</description>
    </item>
    
    <item>
      <title>Can someone explain this packet sequence?</title>
      <link>/questions/28338/can-someone-explain-this-packet-sequence/</link>
      <pubDate>Mon, 23 Dec 2013 06:21:00 +0000</pubDate>
      
      <guid>/questions/28338/can-someone-explain-this-packet-sequence/</guid>
      <description>Can someone explain this packet sequence?  0 I am debugging intermittent connection issues between a client and server application and when running WireShark the following packet sequence occurs:
 Server -&amp;gt; Client [FIN, PSH, ACK] Client -&amp;gt; Server [ACK] Client -&amp;gt; Server [PSH, ACK] Server -&amp;gt; Client [RST, ACK] Client -&amp;gt; Server [FIN, PSH, ACK] Server -&amp;gt; Client [RST] Client -&amp;gt; Server [SYN] //start of new connectionCan anyone help explain what is going on here?</description>
    </item>
    
    <item>
      <title>[closed] Spying on me?</title>
      <link>/questions/28340/spying-on-me/</link>
      <pubDate>Mon, 23 Dec 2013 07:32:00 +0000</pubDate>
      
      <guid>/questions/28340/spying-on-me/</guid>
      <description>[closed] Spying on me?  0 Can anyone tell me, in simple terms, how I can tell if wifi monitoring software has been installed on my pc? I&#39;ve read about Gargoyle and colasoft etc. I just want to know if what happens on my tablet is private, or if someone is snooping on my wifi usage. There is someone in the house that has access to the PC and is very computer savy.</description>
    </item>
    
    <item>
      <title>&amp;quot;Export specific packets&amp;quot; bug ?</title>
      <link>/questions/28341/export-specific-packets-bug/</link>
      <pubDate>Mon, 23 Dec 2013 07:35:00 +0000</pubDate>
      
      <guid>/questions/28341/export-specific-packets-bug/</guid>
      <description>&amp;ldquo;Export specific packets&amp;rdquo; bug ?  0 Hi,
I can&#39;t use export specific packets, whenever I try to save a filtred packet wireshark is closed and nothing is saved. I&#39;ve tried with marked packet, range and only displayed but nothing work.
The thing is that I&#39;ve already used this tool and it worked. Since that time I Upgraded my version of Wireshark ( revision=52637 ).
Any idea on how to fix it ?</description>
    </item>
    
    <item>
      <title>How to verify sequence number order in the RTP stream</title>
      <link>/questions/28349/how-to-verify-sequence-number-order-in-the-rtp-stream/</link>
      <pubDate>Mon, 23 Dec 2013 13:09:00 +0000</pubDate>
      
      <guid>/questions/28349/how-to-verify-sequence-number-order-in-the-rtp-stream/</guid>
      <description>How to verify sequence number order in the RTP stream  0 I have a file capture of 5000 RTP packets. I need to verify if the packets are recieved in the same sequence as sent. How do i check if there is any out of sequence packet. If i have to check it manually, then i have to look into the sequence number if each packet to find out the out of seq packet.</description>
    </item>
    
    <item>
      <title>Is there any way to see the codecs used in voip application in wireshark(G729,AMR...)</title>
      <link>/questions/28355/is-there-any-way-to-see-the-codecs-used-in-voip-application-in-wiresharkg729amr/</link>
      <pubDate>Tue, 24 Dec 2013 00:50:00 +0000</pubDate>
      
      <guid>/questions/28355/is-there-any-way-to-see-the-codecs-used-in-voip-application-in-wiresharkg729amr/</guid>
      <description>Is there any way to see the codecs used in voip application in wireshark(G729,AMR&amp;hellip;)  0 Hello, Is there any way to see the codecs used in VOIP application in wireshark(G729,AMR…).
I want to analyse a VOIP appliocation ,in which i can see SIP methods only.I didn&#39;t find a way to see any codecs used.Also i tried to see RTP packets,which i couldn&#39;t find(i searched for rtp for filtering)find.I actuallally made a call from VOIP application and was only able to see SIP protocol.</description>
    </item>
    
    <item>
      <title>Difference between using src and dst in tcpdump commands</title>
      <link>/questions/28356/difference-between-using-src-and-dst-in-tcpdump-commands/</link>
      <pubDate>Tue, 24 Dec 2013 01:23:00 +0000</pubDate>
      
      <guid>/questions/28356/difference-between-using-src-and-dst-in-tcpdump-commands/</guid>
      <description>Difference between using src and dst in tcpdump commands  0 Hi,
Could you please explain the difference between working nature of below two commands.
tcpdump -w xpackets2.pcap -i eth0 src host-name
tcpdump -w xpackets2.pcap -i eth0 dst host-name
Thanks in advance.
commands tcpdumpasked 24 Dec &#39;13, 01:23
Manivas
1●2●2●2
accept rate: 0%
i telnet to the particular ip address from putty and executing some commands on that. I need to capture the packets for both sending commands to that particular ip address from putty and responses from that same ip address for these commands.</description>
    </item>
    
    <item>
      <title>wireshark not updating capture file modification time</title>
      <link>/questions/28360/wireshark-not-updating-capture-file-modification-time/</link>
      <pubDate>Tue, 24 Dec 2013 02:03:00 +0000</pubDate>
      
      <guid>/questions/28360/wireshark-not-updating-capture-file-modification-time/</guid>
      <description>wireshark not updating capture file modification time  0 I have just installed Wireshark 1.10.1 on Windows XP (Home) SP3. Previously I have been using Ethereal and during live capturing the capture file modification timestamp changed in every time the capture file was written to. This does not appear to happen with Wireshark. The size of the file changes, but not its modification timestamp, which I make reference to in a bespoke application to test that it hasn&#39;t frozen/aborted.</description>
    </item>
    
    <item>
      <title>how to monitor multiple route</title>
      <link>/questions/28362/how-to-monitor-multiple-route/</link>
      <pubDate>Tue, 24 Dec 2013 02:59:00 +0000</pubDate>
      
      <guid>/questions/28362/how-to-monitor-multiple-route/</guid>
      <description>how to monitor multiple route  0 hello i am using fortigate firewall for my office network. i am using both WAN interface WAN1 is for secure site to site vpn connection with my head office and WAN2 for Internet use with ACL at the same time. how do i monitor WAN2 port because wireshark always monitor WAN1 port. your suggestion is very much needed.
mutlipleasked 24 Dec &#39;13, 02:59</description>
    </item>
    
    <item>
      <title>filter application/pdf media type</title>
      <link>/questions/28365/filter-applicationpdf-media-type/</link>
      <pubDate>Tue, 24 Dec 2013 05:44:00 +0000</pubDate>
      
      <guid>/questions/28365/filter-applicationpdf-media-type/</guid>
      <description>filter application/pdf media type  0 I&#39;m trying to build a filter that will show me HTTP packets that have the Media Type as application/pdf. So far, &#34;media contains application&#34; is not bringing them up; however it will bring up other packets in the capture such as javascript, octect-stream, and x-msdownload. Simply using &#34;media&#34; will gain me these packets, but I&#39;d like to be more precise. Thanks!
filtersasked 24 Dec &#39;13, 05:44</description>
    </item>
    
    <item>
      <title>Wireshark does not start. Error 0xC0000005</title>
      <link>/questions/28366/wireshark-does-not-start-error-0xc0000005/</link>
      <pubDate>Tue, 24 Dec 2013 06:05:00 +0000</pubDate>
      
      <guid>/questions/28366/wireshark-does-not-start-error-0xc0000005/</guid>
      <description>Wireshark does not start. Error 0xC0000005  0 Hi,
I recently updated my local copy, i fixed all conflict I had but now wireshark does not start. When I debug the code the program stops at test_if_on() function (airpcap_loader.c).
The message error is &#34;Unhandled exception at 0x0108add4 in wireshark.exe: 0xC0000005: Access violation reading location 0xbaadf00d.&#34;
Thanks
start 0xc0000005 wiresharkasked 24 Dec &#39;13, 06:05
Afrim
160●10●11●16
accept rate: 22%
 edited 24 Dec &#39;13, 06:06</description>
    </item>
    
    <item>
      <title>Other LAN IP addresses captured. Why?</title>
      <link>/questions/28367/other-lan-ip-addresses-captured-why/</link>
      <pubDate>Tue, 24 Dec 2013 06:07:00 +0000</pubDate>
      
      <guid>/questions/28367/other-lan-ip-addresses-captured-why/</guid>
      <description>Other LAN IP addresses captured. Why?  0 I conducted a capture from a workstation to troubleshoot an application. I built a filter to drop all traffic from the workstation and only show me TCP traffic. What I am seeing is the switch is forwarding TCP packets from the WAN to the workstation. I reviewed the configuration for the switchport and it is NOT trunked but rather configured for switchport mode access.</description>
    </item>
    
    <item>
      <title>large length tcp field during SMB2 copy</title>
      <link>/questions/28379/large-length-tcp-field-during-smb2-copy/</link>
      <pubDate>Tue, 24 Dec 2013 22:09:00 +0000</pubDate>
      
      <guid>/questions/28379/large-length-tcp-field-during-smb2-copy/</guid>
      <description>large length tcp field during SMB2 copy  0 Hi,
I have a trace for SMB2 file copying. When I check this trace, I saw traffic pattern like this during the transfer.
(the trace is captured from the server, clients are copying data from the server)
---------- [server -&amp;gt; client, length = 62823bytes] [server -&amp;gt; client, length = 2788bytes] [client -&amp;gt; server, length = 0, tcp ACK] [client -&amp;gt; server, length = 0, tcp ACK] [&amp;hellip;.</description>
    </item>
    
    <item>
      <title>Packet missing issue at peak of network flow in dumpcap.</title>
      <link>/questions/28392/packet-missing-issue-at-peak-of-network-flow-in-dumpcap/</link>
      <pubDate>Wed, 25 Dec 2013 21:04:00 +0000</pubDate>
      
      <guid>/questions/28392/packet-missing-issue-at-peak-of-network-flow-in-dumpcap/</guid>
      <description>Packet missing issue at peak of network flow in dumpcap.  0 Hi all,
I have used dumpcap.exe for dumping the VOIP traffic to the disc. And it is showing packet dropped on network as 0 when it stops. But with testing a sip call there i found some packets missed in the dumped files in Wireshark.
The dumpcap command used is below, and the ethernet card speed is 1Gbps.</description>
    </item>
    
    <item>
      <title>6lowpan in contiki</title>
      <link>/questions/28393/6lowpan-in-contiki/</link>
      <pubDate>Wed, 25 Dec 2013 21:58:00 +0000</pubDate>
      
      <guid>/questions/28393/6lowpan-in-contiki/</guid>
      <description>6lowpan in contiki  0 Hello Guys I want to capture 6lowpan packets transferring between UDP IPv6 client and UDP IPv6 server , both running on contiki OS on the same system.
6lowpanasked 25 Dec &#39;13, 21:58
Devesh
1●1●1●1
accept rate: 0%
  
One Answer:
  
0If your question is &#39;how to capture network traffic on contiki&#39;, my answer is: try using tcpdump. It should be available on contiki, or at least you can install it.</description>
    </item>
    
    <item>
      <title>how to regain loss packet</title>
      <link>/questions/28394/how-to-regain-loss-packet/</link>
      <pubDate>Thu, 26 Dec 2013 00:07:00 +0000</pubDate>
      
      <guid>/questions/28394/how-to-regain-loss-packet/</guid>
      <description>how to regain loss packet  0 Hello Sir, i have one dummy router format in extension .pkt is that possible i can see the sending &amp;amp; receiving of packet &amp;amp; if any how loss occur in sending packet how i re-transmit or resend that packet.
regain of wireshark packet usingasked 26 Dec &#39;13, 00:07
mohit11282
11●1●1●2
accept rate: 0%
  
One Answer:
  
0if any how loss occur in sending packet how i re-transmit or resend that packet.</description>
    </item>
    
    <item>
      <title>IEC 61850 MMS parser</title>
      <link>/questions/28402/iec-61850-mms-parser/</link>
      <pubDate>Thu, 26 Dec 2013 05:09:00 +0000</pubDate>
      
      <guid>/questions/28402/iec-61850-mms-parser/</guid>
      <description>IEC 61850 MMS parser  0 Hello All We need to develop code in order to parse IEC 61850 messages,including MMS. I understand that we can reduce the source code to what we need, but it could take a lot of time to do it in accurate manner. What is a preferable way to build/receive such a parser?
Thank you in advance Best Regards
iec 61850asked 26 Dec &#39;13, 05:09</description>
    </item>
    
    <item>
      <title>How can i contribute to Wireshark if i know C &amp;amp; C&#43;&#43; languages</title>
      <link>/questions/28412/how-can-i-contribute-to-wireshark-if-i-know-c-c-languages/</link>
      <pubDate>Thu, 26 Dec 2013 11:13:00 +0000</pubDate>
      
      <guid>/questions/28412/how-can-i-contribute-to-wireshark-if-i-know-c-c-languages/</guid>
      <description>How can i contribute to Wireshark if i know C &amp;amp; C++ languages  0 Hello, Myself a Computer Science Engineering student willing to work with Wireshark, just to enhance my knowledge and know more about industrial coding levels.I had done coding in C and C++ language and also have knowledge about protocols.I&#39;m willing to work with you,hope you will consider my request.
Shubhra Malhotra [email protected]
India
c++asked 26 Dec &#39;13, 11:13</description>
    </item>
    
    <item>
      <title>how to separate a trace file?</title>
      <link>/questions/28419/how-to-separate-a-trace-file/</link>
      <pubDate>Thu, 26 Dec 2013 23:19:00 +0000</pubDate>
      
      <guid>/questions/28419/how-to-separate-a-trace-file/</guid>
      <description>how to separate a trace file?  0 I have a large trace file of several GBs, but not all of traffic is needed. I would like to save the interesting traffic into a separate file in two ways:
filter out the interesting packets and save as a new filemultiselect the interesting packets and save as a new fileHow to achieve that? thank you!
separate_traceasked 26 Dec &#39;13, 23:19
SteveZhou</description>
    </item>
    
    <item>
      <title>Why I can&amp;#x27;t add window size as column in Wireshark 1.2.9</title>
      <link>/questions/28438/why-i-cant-add-window-size-as-column-in-wireshark-129/</link>
      <pubDate>Fri, 27 Dec 2013 06:35:00 +0000</pubDate>
      
      <guid>/questions/28438/why-i-cant-add-window-size-as-column-in-wireshark-129/</guid>
      <description>Why I can&amp;rsquo;t add window size as column in Wireshark 1.2.9  0 I am trying to add new column Window size and I can&#39;t see it in listed columns. I know that in older version it was possible to simply add new column just with right click on the row in packet details. Why it is removed now as an option?
Thank you in advance for reply
Regards Sanja Petric</description>
    </item>
    
    <item>
      <title>LTE Diameter Sh interface message not Decoding XML Data</title>
      <link>/questions/28439/lte-diameter-sh-interface-message-not-decoding-xml-data/</link>
      <pubDate>Fri, 27 Dec 2013 06:41:00 +0000</pubDate>
      
      <guid>/questions/28439/lte-diameter-sh-interface-message-not-decoding-xml-data/</guid>
      <description>LTE Diameter Sh interface message not Decoding XML Data  0 Im not able to view the user Data which comes as XML in Diameter messages between PCRF and SPR on diameter Sh interface for eg PUR,UDA messages of Diameter,only third window shows that info which is difficult to view.
xml diameterasked 27 Dec &#39;13, 06:41
mayoor
11●1●1●3
accept rate: 0%
What version of Wireshark are you using? It might work in 1.</description>
    </item>
    
    <item>
      <title>How to sniff packets from other pc on same network ? [Wireless conection]</title>
      <link>/questions/28449/how-to-sniff-packets-from-other-pc-on-same-network-wireless-conection/</link>
      <pubDate>Fri, 27 Dec 2013 09:30:00 +0000</pubDate>
      
      <guid>/questions/28449/how-to-sniff-packets-from-other-pc-on-same-network-wireless-conection/</guid>
      <description>How to sniff packets from other pc on same network ? [Wireless conection]  0 Hello , Im connected by wireless on the same network as my phone , and my 2 other computers. But when i start sniffing network, I can only get my Computer&#39;s packets , and not other&#39;s computers packets.
How can i do? Thanks.
help network wiresharkasked 27 Dec &#39;13, 09:30
DZhelp
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>permanent capture &amp;amp; analysis on linux  [not Wireshark-specific]</title>
      <link>/questions/28454/permanent-capture-analysis-on-linux-not-wireshark-specific/</link>
      <pubDate>Fri, 27 Dec 2013 16:05:00 +0000</pubDate>
      
      <guid>/questions/28454/permanent-capture-analysis-on-linux-not-wireshark-specific/</guid>
      <description>permanent capture &amp;amp; analysis on linux [not Wireshark-specific]  0 This is not exactly a Wireshark question, but I wasn&#39;t sure where to ask. If you have an idea for a community where to turn to, let me know. In the mean time...
I&#39;m setting up a server/gateway machine (a linux desktop) that is supposed to capture all traffic coming through it via LAN or VPN. And by that I mean write to disk every single bit of network traffic content.</description>
    </item>
    
    <item>
      <title>Capture Mobile Phone / tablet Packets</title>
      <link>/questions/28469/capture-mobile-phone-tablet-packets/</link>
      <pubDate>Sat, 28 Dec 2013 23:38:00 +0000</pubDate>
      
      <guid>/questions/28469/capture-mobile-phone-tablet-packets/</guid>
      <description>Capture Mobile Phone / tablet Packets  0 Hello there, i would like to know if there is any way to capture cellphone and tablet packets using wireshark. Im running wireshark on win7, and both my cellphone (android) and my tablet (ipad) are connected to the same wifi as my computer. However, i only see my computer&#39;s packets and overal activity. Everytime i use my ipad or cellphone, wireshark indicates: bogus IP header length.</description>
    </item>
    
    <item>
      <title>No H.225 in packet &amp;quot;decode as&amp;quot;</title>
      <link>/questions/28472/no-h225-in-packet-decode-as/</link>
      <pubDate>Sun, 29 Dec 2013 07:55:00 +0000</pubDate>
      
      <guid>/questions/28472/no-h225-in-packet-decode-as/</guid>
      <description>No H.225 in packet &amp;ldquo;decode as&amp;rdquo;  1 Hi,
When trying to decode a packet, H.225 is not on the list. (H.223 appears twice). How can I decode a packet as H.225?
Thanks, Chicco
h.225asked 29 Dec &#39;13, 07:55
chicco
26●1●1●3
accept rate: 0%
  
One Answer:
  
0AFIAK the &#39;decode as&#39; feature for the transport layer (TCP/UDP) only works if a dissector adds itself to the UDP/TCP port dissector table.</description>
    </item>
    
    <item>
      <title>Calling a Lua Dissector on a file</title>
      <link>/questions/28474/calling-a-lua-dissector-on-a-file/</link>
      <pubDate>Mon, 30 Dec 2013 02:42:00 +0000</pubDate>
      
      <guid>/questions/28474/calling-a-lua-dissector-on-a-file/</guid>
      <description>Calling a Lua Dissector on a file  0 Hi all,
I&#39;ve been using Wireshark for a while and also building LUA dissectors for some proprietary protocols. Before you can use a dissector, you need to add it to the appropriate dissector table. I would like to use the abilities from Wireshark to represent the contents of a binary file, similar to &#34;ASN.1 Basic Encoding Rules(.)&#34; however I do not know if it is possible to register a dissector for use as file dissector.</description>
    </item>
    
    <item>
      <title>filter by field value</title>
      <link>/questions/28475/filter-by-field-value/</link>
      <pubDate>Mon, 30 Dec 2013 08:22:00 +0000</pubDate>
      
      <guid>/questions/28475/filter-by-field-value/</guid>
      <description>filter by field value  0 I&#39;ve used the following to filter by field value - udp port 8003 and udp[10] = 200; udp port 8002 and udp[8:4] = 1049.
I recently attempted these with a newer version of Wireshark and they were disallowed. Can you help me update these?
filterbyfieldasked 30 Dec &#39;13, 08:22
mmaloney
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Are you entering them as capture filters or as display filters?</description>
    </item>
    
    <item>
      <title>TCP ZeroWindow when printing</title>
      <link>/questions/28478/tcp-zerowindow-when-printing/</link>
      <pubDate>Mon, 30 Dec 2013 11:35:00 +0000</pubDate>
      
      <guid>/questions/28478/tcp-zerowindow-when-printing/</guid>
      <description>TCP ZeroWindow when printing  0 We&#39;ve been having on/off issues all day with some of our Ricoh copiers and multiple PCs. Documents will take anywhere from 1-5 minutes to begin printing. I mirrored the switchport of one of the printers to the second NIC on my PC and ran a capture while sending a test page, and it looks like we&#39;re filling the TCP Window which is causing the delays, in the linked image .</description>
    </item>
    
    <item>
      <title>how to fully understand a specific display filter?</title>
      <link>/questions/28491/how-to-fully-understand-a-specific-display-filter/</link>
      <pubDate>Mon, 30 Dec 2013 18:57:00 +0000</pubDate>
      
      <guid>/questions/28491/how-to-fully-understand-a-specific-display-filter/</guid>
      <description>how to fully understand a specific display filter?  0 Hi,
As we know, we have lots of display filter based on tcp fields or wireshark specific fields. For example, tcp.analysis.flags. But I don&#39;t where to find the detailed explanation of this display filter.
I can find the description here: http://www.wireshark.org/docs/dfref/t/tcp.html. But it still doesn&#39;t tell me what exactly does tcp.analysis.flags mean. This applies to all of the other display filters or fields.</description>
    </item>
    
    <item>
      <title>Unable to capture packets on interface.</title>
      <link>/questions/28492/unable-to-capture-packets-on-interface/</link>
      <pubDate>Mon, 30 Dec 2013 21:05:00 +0000</pubDate>
      
      <guid>/questions/28492/unable-to-capture-packets-on-interface/</guid>
      <description>Unable to capture packets on interface.  0 Hi
I have following 3 interfaces
[email protected]:~$ ifconfig eth0 Link encap:Ethernet HWaddr 00:11:43:e1:79:03 inet addr:155.98.39.121 Bcast:155.98.39.255 Mask:255.255.252.0 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:225209 errors:0 dropped:0 overruns:0 frame:0 TX packets:212227 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:211193409 (211.1 MB) TX bytes:41723043 (41.7 MB)
eth4 Link encap:Ethernet HWaddr 00:04:23:a8:fc:0e inet addr:10.10.1.1 Bcast:10.10.1.255 Mask:255.255.255.0 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:14 errors:0 dropped:0 overruns:0 frame:0 TX packets:15 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:1068 (1.</description>
    </item>
    
    <item>
      <title>wrong behavior for TCP-Delayed Ack</title>
      <link>/questions/28494/wrong-behavior-for-tcp-delayed-ack/</link>
      <pubDate>Mon, 30 Dec 2013 22:32:00 +0000</pubDate>
      
      <guid>/questions/28494/wrong-behavior-for-tcp-delayed-ack/</guid>
      <description>wrong behavior for TCP-Delayed Ack  0 Hi,
I have a trace file which makes me be confused on the behavior of tcp-delayed Ack. As you can see, 192. send 7 tcp segments to 10., but where is the Ack for packet #3 and #4.Shouldn&#39;t we expect to see an Ack for those two packets according to the rule of tcp-delayed Ack? We see the Ack from 10. at packet #10, which acked all of the bytes including #8.</description>
    </item>
    
    <item>
      <title>how to understand odd number packets are evil?</title>
      <link>/questions/28497/how-to-understand-odd-number-packets-are-evil/</link>
      <pubDate>Tue, 31 Dec 2013 00:08:00 +0000</pubDate>
      
      <guid>/questions/28497/how-to-understand-odd-number-packets-are-evil/</guid>
      <description>how to understand odd number packets are evil?  0 Hi,
I&#39;m looking at some of the sharkfest sessions on Youtube. For the sessions presented by Hansang Bae, I noticed an interesting topic which is about &#34;Odd Numbers are Evil&#34;. I don&#39;t really understand what does it mean,guess the expert here do understand what I mean here.
So, could you please explain what does this kind of issue mean? Is there any document, video that can be referred to?</description>
    </item>
    
    <item>
      <title>Decrypt SSL using wildcard IP address</title>
      <link>/questions/28503/decrypt-ssl-using-wildcard-ip-address/</link>
      <pubDate>Tue, 31 Dec 2013 08:26:00 +0000</pubDate>
      
      <guid>/questions/28503/decrypt-ssl-using-wildcard-ip-address/</guid>
      <description>Decrypt SSL using wildcard IP address  0 Is it possible to consistently use a wildcard IP address 0.0.0.0 to decrypt SSL traffic for a specific RSA key. I have wildcard SSL certs applied to multiple VIPs in our test environment and I&#39;m tired of adding each VIP&#39;s IP address every time I need to decrypt that conversation.
I had some luck initially in version in 1.10.1 but for reasons unknown it stopped working.</description>
    </item>
    
    <item>
      <title>SFTP troubleshooting bad client public key in pcap</title>
      <link>/questions/28504/sftp-troubleshooting-bad-client-public-key-in-pcap/</link>
      <pubDate>Tue, 31 Dec 2013 13:24:00 +0000</pubDate>
      
      <guid>/questions/28504/sftp-troubleshooting-bad-client-public-key-in-pcap/</guid>
      <description>SFTP troubleshooting bad client public key in pcap  0 Is there a way to determine a bad public key presented to an SFTP server configured for public key authentication? I am comparing two pcap files next to each other one is a success and the other I know is failure with client presenting wrong key for public key authentication attempt. They look very similar except the successfull connection obviously has more encrypted packets back/forth.</description>
    </item>
    
    <item>
      <title>Finding source with DDD</title>
      <link>/questions/28505/finding-source-with-ddd/</link>
      <pubDate>Tue, 31 Dec 2013 13:49:00 +0000</pubDate>
      
      <guid>/questions/28505/finding-source-with-ddd/</guid>
      <description>Finding source with DDD  0 I&#39;ve build wireshark, and can start it up using ddd using the recommended method through libtool &#34;libtool --mode=execute ddd ./wireshark&#34;. If I click File &amp;gt; Open Source, it displays a list of .c and .h files, but not all of the files in the project. In particular, I&#39;m looking to debug a dissector. I&#39;ve tried to add ./epan/dissectors/ to the search path, but that has not helped.</description>
    </item>
    
    <item>
      <title>How to install wireshark in linux to support lua?</title>
      <link>/questions/28507/how-to-install-wireshark-in-linux-to-support-lua/</link>
      <pubDate>Tue, 31 Dec 2013 23:30:00 +0000</pubDate>
      
      <guid>/questions/28507/how-to-install-wireshark-in-linux-to-support-lua/</guid>
      <description>How to install wireshark in linux to support lua?  0 Hi All,
I want to use wireshark in linux to parse self-define protocol. So I write a lua plugin. Bug I am not sure if wireshark in linux can support lua.
I download wireshark-1.5.0.tar.bz2,
tar -xvjf wireshark-1.5.0.tar.bz2
cd wireshark-1.5.0
./configure
but i got following message:
Install dumpcap with capabilities : no
Install dumpcap setuid : no
Use dumpcap group : (none)</description>
    </item>
    
    <item>
      <title>gmail password sniffing</title>
      <link>/questions/28508/gmail-password-sniffing/</link>
      <pubDate>Wed, 01 Jan 2014 06:31:00 +0000</pubDate>
      
      <guid>/questions/28508/gmail-password-sniffing/</guid>
      <description>gmail password sniffing  0 how to sniff gmail password???
password sniff gmailasked 01 Jan &#39;14, 06:31
john6
7●8●8●10
accept rate: 0%
 edited 01 Jan &#39;14, 09:11 
grahamb ♦
19.8k●3●30●206
  
3 Answers:
  
0Your own, or someone else&#39;s?
Not easily as it will be encrypted using https, e.g. see the bottom half of this web page: http://samsclass.info/120/proj/p3-wireshark.htm.
If you can manage a mitm attack then you should be able to capture it, or use a proxy, e.</description>
    </item>
    
    <item>
      <title>Unknown UDP traffic from unknown process on port 60129</title>
      <link>/questions/28516/unknown-udp-traffic-from-unknown-process-on-port-60129/</link>
      <pubDate>Wed, 01 Jan 2014 18:40:00 +0000</pubDate>
      
      <guid>/questions/28516/unknown-udp-traffic-from-unknown-process-on-port-60129/</guid>
      <description>Unknown UDP traffic from unknown process on port 60129  0 I have some strange UDP traffics on one Win 7 machine on local port 60129 with a huge amount of connection to random computers. What I can&#39;t figure out from what process it&#39;s generated. Have used nestat -a -o -p UDP 1 &amp;gt;log.out for a long time but never seen port 60129 in the log file. I have also used ProcessMonitor and TCPView but have never seen any hits and at the same time captured traffic with Wireshark.</description>
    </item>
    
    <item>
      <title>Could not install wireshark on windows xp</title>
      <link>/questions/28521/could-not-install-wireshark-on-windows-xp/</link>
      <pubDate>Thu, 02 Jan 2014 02:23:00 +0000</pubDate>
      
      <guid>/questions/28521/could-not-install-wireshark-on-windows-xp/</guid>
      <description>Could not install wireshark on windows xp  0 Hi
I&#39;m trying to run a binary wireshark package (build with NSIS) in windows XP. The installation works fine but when I try to run wireshark &#34;wireshark is not a valide win32 application&#34;.
The binary package is build on windows 7 and it&#39;s first time I get this error. I&#39;ve already done this before so maybe something in new version have changed ?</description>
    </item>
    
    <item>
      <title>TCP dissector being called on UDP</title>
      <link>/questions/28524/tcp-dissector-being-called-on-udp/</link>
      <pubDate>Thu, 02 Jan 2014 03:54:00 +0000</pubDate>
      
      <guid>/questions/28524/tcp-dissector-being-called-on-udp/</guid>
      <description>TCP dissector being called on UDP  0 Hi,
I have two dissectors specified in different files. One TCP and the other UDP. The protocols I am dissecting both use the same magic, in TCP or in UDP. When opening a cap, during packet dissection it seems both dissectors are called on a UDP packet. In the output I get informations from the UDP dissector....and the TCP dissector.
How is that possible ?</description>
    </item>
    
    <item>
      <title>wlan/wifi adapters that support hardware timestamp</title>
      <link>/questions/28525/wlanwifi-adapters-that-support-hardware-timestamp/</link>
      <pubDate>Thu, 02 Jan 2014 08:02:00 +0000</pubDate>
      
      <guid>/questions/28525/wlanwifi-adapters-that-support-hardware-timestamp/</guid>
      <description>wlan/wifi adapters that support hardware timestamp  0 Hi,
Im current working in a indoor location system and want to use the TDOA approach. The main problem today is the timestamp that is generated by the kernel and not by the adapter. I need a wifi adapter that support hardware timestamping.
Searching around the internet i found some people saying that atheros adapters support hardware timestamp, can anyone confirm this?</description>
    </item>
    
    <item>
      <title>How can the configuration files created -Router configuration-</title>
      <link>/questions/28528/how-can-the-configuration-files-created-router-configuration-/</link>
      <pubDate>Thu, 02 Jan 2014 10:55:00 +0000</pubDate>
      
      <guid>/questions/28528/how-can-the-configuration-files-created-router-configuration-/</guid>
      <description>How can the configuration files created -Router configuration-  0 I wonder how to create a configuration file and how I can save it?
save configuration creat file roterasked 02 Jan &#39;14, 10:55
ALwrad
1●1●1●1
accept rate: 0%
This appears to be a router related question and not related to Wireshark. I suggest you ask your question on a forum or support area for the manufacturer of your router.
(02 Jan &#39;14, 13:55) Bill Meier ♦♦Or maybe a question on an ACL, which is possible.</description>
    </item>
    
    <item>
      <title>Terminate in an unusual way, server 2008 R2 SP1</title>
      <link>/questions/28538/terminate-in-an-unusual-way-server-2008-r2-sp1/</link>
      <pubDate>Thu, 02 Jan 2014 16:52:00 +0000</pubDate>
      
      <guid>/questions/28538/terminate-in-an-unusual-way-server-2008-r2-sp1/</guid>
      <description>Terminate in an unusual way, server 2008 R2 SP1  0 I have two installs of Wireshark 1.0.5 running, 1 instance in on a Windows 7 32bit machine and runs without any issues for as long as I need, my 2nd instance is the problem: Running on a Windows Server 2008 R2 SP1 64-bit and crashes with Visual Studio error that caused the program to terminate in an unusual way (every 30-40 minutes), this locks the software and forces you to close Wireshark.</description>
    </item>
    
    <item>
      <title>Converting multiple pcap files to csv</title>
      <link>/questions/28542/converting-multiple-pcap-files-to-csv/</link>
      <pubDate>Thu, 02 Jan 2014 19:14:00 +0000</pubDate>
      
      <guid>/questions/28542/converting-multiple-pcap-files-to-csv/</guid>
      <description>Converting multiple pcap files to csv  0 I already found a post that does this, but in windows, and I&#39;d like to make the same for linux, but I&#39;m kind of a newbie when it comes to the shell environment. I&#39;d like it to work on .gz files, more than .cap files, as the windows topic suggests.
Could someone hint me on how to do this?
http://ask.wireshark.org/questions/12799/how-to-convert-multiple-pcap-files-to-csv
That is the windows topic for it.</description>
    </item>
    
    <item>
      <title>[closed] How to recognize an botnet client controller?</title>
      <link>/questions/28546/how-to-recognize-an-botnet-client-controller/</link>
      <pubDate>Fri, 03 Jan 2014 00:24:00 +0000</pubDate>
      
      <guid>/questions/28546/how-to-recognize-an-botnet-client-controller/</guid>
      <description>[closed] How to recognize an botnet client controller?  0 Hello,
I am busy with an challenge and i try to learn to work with wireshark. I have an capturefile where i isolated this peace from : http://www.cloudshark.org/captures/11462ea19f2b
Here i found an address to the Command and Control interface of the botnet. Question: is this the client-controller or is this the botnet master (server).
How do i recognize a client-controller?</description>
    </item>
    
    <item>
      <title>SSL request hangs intermittently with Amazon LB SSL (Capture Included)</title>
      <link>/questions/28548/ssl-request-hangs-intermittently-with-amazon-lb-ssl-capture-included/</link>
      <pubDate>Fri, 03 Jan 2014 06:42:00 +0000</pubDate>
      
      <guid>/questions/28548/ssl-request-hangs-intermittently-with-amazon-lb-ssl-capture-included/</guid>
      <description>SSL request hangs intermittently with Amazon LB SSL (Capture Included)  0 Greetings,
I&#39;ve been trying very desperately to track down the source of an issue I&#39;m having with a large SSL request to my Apache server (75K-100K). Every 20 requests or so, when issuing the request in FF, the request hangs. The server is Apache running in Amazon EC2 behind a LB that handles the SSL. (us-east-1)
I&#39;m able to capture the wireshark trace (see http://cloudshark.</description>
    </item>
    
    <item>
      <title>Hearing audio (RTP) using Wireshark capture.</title>
      <link>/questions/28553/hearing-audio-rtp-using-wireshark-capture/</link>
      <pubDate>Fri, 03 Jan 2014 09:06:00 +0000</pubDate>
      
      <guid>/questions/28553/hearing-audio-rtp-using-wireshark-capture/</guid>
      <description>Hearing audio (RTP) using Wireshark capture.  0 I already have wireshark trace files that include SIP for messaging and also the RTP packets. What option / setting should I turn ON, to hear the audio stream?
audioasked 03 Jan &#39;14, 09:06
VeeGee
11●1●1●2
accept rate: 0%
  
2 Answers:
  
0With the trace file loaded, go to Telephony -&amp;gt; RTP -&amp;gt; Stream Analysis. Pick the stream you want to hear and hit Player.</description>
    </item>
    
    <item>
      <title>Server sends tons of SYN ACK packets in answer to a single SYN packet</title>
      <link>/questions/28561/server-sends-tons-of-syn-ack-packets-in-answer-to-a-single-syn-packet/</link>
      <pubDate>Fri, 03 Jan 2014 20:54:00 +0000</pubDate>
      
      <guid>/questions/28561/server-sends-tons-of-syn-ack-packets-in-answer-to-a-single-syn-packet/</guid>
      <description>Server sends tons of SYN ACK packets in answer to a single SYN packet  0 Hi. looking at suspicious traffic I found that a lab Windows Domain Controller with DNS enabled was sending, in a single second, over 100 SYN,ACK packets in response to a single SYN packet. The SYN packet was sent by a workstation joined to the server&#39;s domain.
The SYN,ACK packet&#39;s data part cannot be read in clear text, but It looks like there are only two variations of this packet.</description>
    </item>
    
    <item>
      <title>DTMF is not showing in wireshark Please help.</title>
      <link>/questions/28562/dtmf-is-not-showing-in-wireshark-please-help/</link>
      <pubDate>Fri, 03 Jan 2014 21:34:00 +0000</pubDate>
      
      <guid>/questions/28562/dtmf-is-not-showing-in-wireshark-please-help/</guid>
      <description>DTMF is not showing in wireshark Please help.  0 Hi, I have configured CCT with our MSC. But while calling to IVR phone DTMF is not showing in wireshark. How to resolve this issue ? please help.
dtmfasked 03 Jan &#39;14, 21:34
AMITAG
11●1●1●2
accept rate: 0%
This question reminds me of this clip from &#34;Good Morning, Vietnam&#34;.
(04 Jan &#39;14, 07:35) cmaynard ♦♦why ??? Is that song related with DTMF ?</description>
    </item>
    
    <item>
      <title>Wireshark cannot decrypt wireless packets</title>
      <link>/questions/28565/wireshark-cannot-decrypt-wireless-packets/</link>
      <pubDate>Sat, 04 Jan 2014 00:04:00 +0000</pubDate>
      
      <guid>/questions/28565/wireshark-cannot-decrypt-wireless-packets/</guid>
      <description>Wireshark cannot decrypt wireless packets  0 Wireshark cannot decrypt WEP packets with 64-bit (10 digits) WEP key given.
What it shows is just a bunch of 802.11 packets and LLC packets, and IP addresses are even not visible.
Is it because Wireshark detects my key as invalid, or is it because the captured packets are corrupted?
linux decryption wep 802.11 ubuntuasked 04 Jan &#39;14, 00:04
jinoh67
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Reading tcpdump capture: Complex interface configuration</title>
      <link>/questions/28569/reading-tcpdump-capture-complex-interface-configuration/</link>
      <pubDate>Sat, 04 Jan 2014 09:59:00 +0000</pubDate>
      
      <guid>/questions/28569/reading-tcpdump-capture-complex-interface-configuration/</guid>
      <description>Reading tcpdump capture: Complex interface configuration  0 I&#39;m trying to read a tcpdump capture with Wireshark, but getting pcap: network type 1146433328 unknown or unsupported
This box is using 803.1Q vlan tagging over 803.3ad link aggravation and I have not had a problem with that in the past. However, this one also has an alias defined and that seems to be what&#39;s causing the problem. So the interfaces look like:</description>
    </item>
    
    <item>
      <title>IEC 60870-5-104-Asdu IO reading</title>
      <link>/questions/28571/iec-60870-5-104-asdu-io-reading/</link>
      <pubDate>Sat, 04 Jan 2014 10:17:00 +0000</pubDate>
      
      <guid>/questions/28571/iec-60870-5-104-asdu-io-reading/</guid>
      <description>IEC 60870-5-104-Asdu IO reading  0 A month ago, I could not determine how close I was to stablish communication in a IEC 60870-5-104 link, can someone help?, in my wireshark file I can see:
104apci&amp;lt;-U (STARTDT act) (Master) 104apci-&amp;gt;U STARTDT con (Slave) 104apcu 1,0&amp;lt;-0 C_IC_NA_1 Act 104apcu 1,0-&amp;gt;0 C_IC_NA_1 UkComAdrASDU_NEGA IOA=0 . . 104apcu 2,0-&amp;gt;0 M_SP_NA_1(1) Spont IOA=32 &amp;#39;Single point information&amp;#39; -- IEC 60870-5-104-Asdu: 2,0-&amp;gt;0 M_SP_NA_1 Spont IOA=32 &amp;#39;single-point information&amp;#39; TypeId: M_SP_NA_1 (1) .</description>
    </item>
    
    <item>
      <title>Why did this connection reset while downloading a file over HTTP?</title>
      <link>/questions/28580/why-did-this-connection-reset-while-downloading-a-file-over-http/</link>
      <pubDate>Sat, 04 Jan 2014 18:45:00 +0000</pubDate>
      
      <guid>/questions/28580/why-did-this-connection-reset-while-downloading-a-file-over-http/</guid>
      <description>Why did this connection reset while downloading a file over HTTP?  0 I host a couple of sites dealing with many file uploads/downloads. Every now and then I see failures in my log files, for reasons I only wish I knew. My visitors are mostly anonymous to me, but today I managed to capture one failed download with tcpdump and I&#39;m asking for help understanding it better.
The client (67.</description>
    </item>
    
    <item>
      <title>How to write http layer sniffer</title>
      <link>/questions/28583/how-to-write-http-layer-sniffer/</link>
      <pubDate>Sun, 05 Jan 2014 05:03:00 +0000</pubDate>
      
      <guid>/questions/28583/how-to-write-http-layer-sniffer/</guid>
      <description>How to write http layer sniffer  0 I asked similar question at StackOverflow.
I want to write an application layer sniffer (SMTP/ftp/http).
Based on my searchs, first (and perhaps hardest!) step is to reassemble the tcp stream of the sniffed connections.
Indeed, what I need is something like the &#34;follow TCP stream&#34; option of wireshark, but I need a tool which do it on live interface and automatically. As I know, Tshark can extract TCP streams data from the saved pcap files automatically (link) but not from live interfaces.</description>
    </item>
    
    <item>
      <title>How is the &amp;quot;guid handle file&amp;quot; set in SMB2 dissector with multiple netbios parts?</title>
      <link>/questions/28586/how-is-the-guid-handle-file-set-in-smb2-dissector-with-multiple-netbios-parts/</link>
      <pubDate>Sun, 05 Jan 2014 08:05:00 +0000</pubDate>
      
      <guid>/questions/28586/how-is-the-guid-handle-file-set-in-smb2-dissector-with-multiple-netbios-parts/</guid>
      <description>How is the &amp;ldquo;guid handle file&amp;rdquo; set in SMB2 dissector with multiple netbios parts?  0 Hello,
I stumbled upon a strange packet in a SMB2 conversion. The packets contains 3 Netbios parts, each containing 1 SMB2 part. Looks to me like something Rolf Leutert described in the SMB troubleshooting session at the Sharkfest 2013. The packet is a response to 3 separate commands. When looking at &#34;smb2.seq_num&#34;, &#34;smb2.cmd&#34; and &#34;</description>
    </item>
    
    <item>
      <title>Using wireshark for packet capture on wireless network</title>
      <link>/questions/28589/using-wireshark-for-packet-capture-on-wireless-network/</link>
      <pubDate>Sun, 05 Jan 2014 16:58:00 +0000</pubDate>
      
      <guid>/questions/28589/using-wireshark-for-packet-capture-on-wireless-network/</guid>
      <description>Using wireshark for packet capture on wireless network  0 Hi guys,
I am trying to sniff traffic between an embedded wifi module and the router. I want to know how I can use wireshark to capture all wireless traffic around me. It is my wifi network so I am just trying to find out what packet my embedded device is actually sending. Is there any way in which I can achieve this?</description>
    </item>
    
    <item>
      <title>[closed] ad.internal conversations traffic in windows  2008 domain Win 7 clients</title>
      <link>/questions/28591/adinternal-conversations-traffic-in-windows-2008-domain-win-7-clients/</link>
      <pubDate>Sun, 05 Jan 2014 17:29:00 +0000</pubDate>
      
      <guid>/questions/28591/adinternal-conversations-traffic-in-windows-2008-domain-win-7-clients/</guid>
      <description>[closed] ad.internal conversations traffic in windows 2008 domain Win 7 clients  0 We use Quest foglight and we see the following &#34;ad.internal&#34; conversations traffic We are using windows 2008 domain with Win 7 clients
does anyone know what it is?
ad.internalasked 05 Jan &#39;14, 17:29
RIA
1●1●1●1
accept rate: 0%
 closed 08 Jan &#39;14, 09:16 
Kurt Knochner ♦
24.8k●10●39●237
Why do you ask this on a Wireshark site?</description>
    </item>
    
    <item>
      <title>Tracking a conversation across a source port change</title>
      <link>/questions/28592/tracking-a-conversation-across-a-source-port-change/</link>
      <pubDate>Sun, 05 Jan 2014 18:10:00 +0000</pubDate>
      
      <guid>/questions/28592/tracking-a-conversation-across-a-source-port-change/</guid>
      <description>Tracking a conversation across a source port change  0 I have a protocol in which the client changes source ports regularly (the server has a single well known port). I&#39;m trying to maintain a single conversation through this (each host can only have a single instance of the client). For example, I would expect this kind of traffic (52230 is the well known port):
client:12345 -&amp;gt; server:52230 server:52230 -&amp;gt; client:12345 client:23456 -&amp;gt; server:52230 server:55230 -&amp;gt; client:23456This is one conversation.</description>
    </item>
    
    <item>
      <title>Get user&amp;#x27;s direct intention from &amp;#x27;.pcap&amp;#x27; file.</title>
      <link>/questions/28594/get-users-direct-intention-from-pcap-file/</link>
      <pubDate>Sun, 05 Jan 2014 22:31:00 +0000</pubDate>
      
      <guid>/questions/28594/get-users-direct-intention-from-pcap-file/</guid>
      <description>Get user&amp;rsquo;s direct intention from &amp;lsquo;.pcap&amp;rsquo; file.  0 Hy everyone, I have a lot of &#39;.pcap&#39; files, I want to scan a packets and get a target URL, that mean for example if I run in background Wireshark and i go to www.cnn.com(i get 3000 packets approximately - only for load the home-page), after i click for get one of the article of CNN i get 1500 packets (approximately).</description>
    </item>
    
    <item>
      <title>LUA dissector field in display filter</title>
      <link>/questions/28595/lua-dissector-field-in-display-filter/</link>
      <pubDate>Mon, 06 Jan 2014 02:50:00 +0000</pubDate>
      
      <guid>/questions/28595/lua-dissector-field-in-display-filter/</guid>
      <description>LUA dissector field in display filter  0 Hi,
I&#39;m trying to register some fields within a dissector, to be able to use them in the display filter. Tried different things but none of them worked, a simple example below :
DUMMYPROTOCOL = Proto (&amp;quot;DUMMYPROTOCOL&amp;quot;, &amp;quot;B tcp Protocol&amp;quot;) magic = ProtoField.uint32 (&amp;quot;DUMMYPROTOCOL.magic&amp;quot;, &amp;quot;Magic&amp;quot;) DUMMYPROTOCOL.fields = { magic } function DUMMYPROTOCOL.dissector (buffer, pinfo, tree) subtree = tree:add (DUMMYPROTOCOL, buffer()) &amp;ndash; Modify columns pinfo.</description>
    </item>
    
    <item>
      <title>unrecognized libpcap format</title>
      <link>/questions/28600/unrecognized-libpcap-format/</link>
      <pubDate>Mon, 06 Jan 2014 06:49:00 +0000</pubDate>
      
      <guid>/questions/28600/unrecognized-libpcap-format/</guid>
      <description>unrecognized libpcap format  0 Hello,
I&#39;m running this command to display traffic in the remote host :
ssh [email protected]_adress &amp;#39;tshark -f &amp;quot;port !22&amp;quot; -w -&amp;#39; | wireshark -k -i -with some hosts it works fine but with some other hosts it returns this error :
unrecognized libpcap formatCould you help me please?
Thank you.
ssh tsharkasked 06 Jan &#39;14, 06:49
Manou
1●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Recent trace - Expert info warning reporting 20% Out-Of-Order</title>
      <link>/questions/28601/recent-trace-expert-info-warning-reporting-20-out-of-order/</link>
      <pubDate>Mon, 06 Jan 2014 08:00:00 +0000</pubDate>
      
      <guid>/questions/28601/recent-trace-expert-info-warning-reporting-20-out-of-order/</guid>
      <description>Recent trace - Expert info warning reporting 20% Out-Of-Order  0 We have a manufacturing warehouse facility that is complaining of wireless network slowness and disconnects thru-out the facility.
I have been tasked to do a packet analysis of the problem using wireshark. I installed wireshark on a dell desktop that is inside a stainless steel manufacturing cart.
In any case, the dry mix operators use a Intermec SR61B Cordless Scanner that uses Bluetooth radio for RF communications to scan ingredients before mixing.</description>
    </item>
    
    <item>
      <title>SIP CID tracking</title>
      <link>/questions/28606/sip-cid-tracking/</link>
      <pubDate>Mon, 06 Jan 2014 12:00:00 +0000</pubDate>
      
      <guid>/questions/28606/sip-cid-tracking/</guid>
      <description>SIP CID tracking  0 I would like to sniff the WAN for a SIP trunk that is sending CID information to my customer. I have downloaded the Sniffer and have a HUB that I can capture the packets. What should I look for and how can I read the information that I receive? Is there a program routine that would help me?
sipcidasked 06 Jan &#39;14, 12:00
Fonedoc
1●1●1●1</description>
    </item>
    
    <item>
      <title>Lua: Error during loading mpeg_packets_dump.lua</title>
      <link>/questions/28617/lua-error-during-loading-mpeg_packets_dumplua/</link>
      <pubDate>Tue, 07 Jan 2014 02:22:00 +0000</pubDate>
      
      <guid>/questions/28617/lua-error-during-loading-mpeg_packets_dumplua/</guid>
      <description>Lua: Error during loading mpeg_packets_dump.lua  0 Hello,
I just put this file to /usr/local/lib/wireshark.plugins/1.10.2/, then had this error right at the start of wireshark :
Lua: Error during loading: [string &#34;/usr/local/lib/wireshark/plugins/1.10.2/mpe...&#34;]:30: bad argument #1 to &#39;new&#39; (Field_new: a field with this name must exist)
A little help ?
lua tools mpeg_dump pluginsasked 07 Jan &#39;14, 02:22
ychaouche
31●5●6●10
accept rate: 100%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Mergecap not working</title>
      <link>/questions/28620/mergecap-not-working/</link>
      <pubDate>Tue, 07 Jan 2014 03:41:00 +0000</pubDate>
      
      <guid>/questions/28620/mergecap-not-working/</guid>
      <description>Mergecap not working  0 Good Morning,
I was trying to capture several pcap files into one. I placed/saved the files on the desktop. Now on the recommendation of the book i entered the book verbatim, but i could not get it to work.Would you mind telling me how it works.
What do you think could be the reason.
1) Do i have to save the files in a different directory.</description>
    </item>
    
    <item>
      <title>jumbo frame mtu setting</title>
      <link>/questions/28624/jumbo-frame-mtu-setting/</link>
      <pubDate>Tue, 07 Jan 2014 04:37:00 +0000</pubDate>
      
      <guid>/questions/28624/jumbo-frame-mtu-setting/</guid>
      <description>jumbo frame mtu setting  0 Once If I set jumbo frame on a specific interface like:
ifconfig eth0 mtu 9000
what will be the minimum and maximum packet size ?
Say for example, if I send a 1 byte packet, whether padding happens till 64 byte frame size(minimum required) will be done (OR) some other minimum size ?
Also, If I set packet size as 100, what will be the frame size ?</description>
    </item>
    
    <item>
      <title>How do you capture packets in a database</title>
      <link>/questions/28628/how-do-you-capture-packets-in-a-database/</link>
      <pubDate>Tue, 07 Jan 2014 06:02:00 +0000</pubDate>
      
      <guid>/questions/28628/how-do-you-capture-packets-in-a-database/</guid>
      <description>How do you capture packets in a database  0 Hi! How do I capture packets whit wireshark and storege in a database. HELP ME PLEASE!
wireshark databaseasked 07 Jan &#39;14, 06:02
sebgang
1●1●1●1
accept rate: 0%
  
2 Answers:
  
1Wireshark can&#39;t store packets into databases. If you want to do something like that you&#39;ll have to find a different solution or code something that reads the capture files and pushes the frames into a database.</description>
    </item>
    
    <item>
      <title>can wireshark pick up data from a mobile</title>
      <link>/questions/28634/can-wireshark-pick-up-data-from-a-mobile/</link>
      <pubDate>Tue, 07 Jan 2014 07:55:00 +0000</pubDate>
      
      <guid>/questions/28634/can-wireshark-pick-up-data-from-a-mobile/</guid>
      <description>can wireshark pick up data from a mobile  0 hi
can wireshark sniff the data directly from a mobile phone or does does the phone have to go through my router for it to pick up the packets??
many thanks
mobileasked 07 Jan &#39;14, 07:55
bobsta
11●2●2●4
accept rate: 0%
  
2 Answers:
  
1What kind of traffic are you trying to catch? if its 802.</description>
    </item>
    
    <item>
      <title>sniffing whatsapp chat</title>
      <link>/questions/28636/sniffing-whatsapp-chat/</link>
      <pubDate>Tue, 07 Jan 2014 08:05:00 +0000</pubDate>
      
      <guid>/questions/28636/sniffing-whatsapp-chat/</guid>
      <description>sniffing whatsapp chat  0 is it possible sniff whatsapp voice chat in wireshark??
whatsappasked 07 Jan &#39;14, 08:05
john6
7●8●8●10
accept rate: 0%
 edited 07 Jan &#39;14, 12:03 
Kurt Knochner ♦
24.8k●10●39●237
1When your were busy decorating your question title to make it stand out did you even think to try typing whatsapp into the search box?
(07 Jan &#39;14, 08:38) grahamb ♦Or simply click on the tag you added yourself (&#39;whatsapp&#39;).</description>
    </item>
    
    <item>
      <title>help with .cap file deciphering errors and or issues</title>
      <link>/questions/28640/help-with-cap-file-deciphering-errors-and-or-issues/</link>
      <pubDate>Tue, 07 Jan 2014 08:47:00 +0000</pubDate>
      
      <guid>/questions/28640/help-with-cap-file-deciphering-errors-and-or-issues/</guid>
      <description>help with .cap file deciphering errors and or issues  0 I have a .cap file that needs to be looked at and im kind of running into a wall in finding what may be errors or traffic that is not suppose to occur or have issues with. i have attached the .cap file please provide me with any assistance thank you! oops how do i attach the .cap file ?</description>
    </item>
    
    <item>
      <title>Decrypting SSL in dissector</title>
      <link>/questions/28642/decrypting-ssl-in-dissector/</link>
      <pubDate>Tue, 07 Jan 2014 09:38:00 +0000</pubDate>
      
      <guid>/questions/28642/decrypting-ssl-in-dissector/</guid>
      <description>Decrypting SSL in dissector  1 I&#39;m writing a new dissector for a protocol that can include SSL traffic. It is somewhat similar to LDAP in that it can start a session unencrypted and switch to SSL on the same port when a certain message is received, so I&#39;ve based my code on packet-ldap. I&#39;ve also referred to packet-pop, packet-http, and packet-xmpp, which all have various forms of this code.</description>
    </item>
    
    <item>
      <title>sniff a facebook password</title>
      <link>/questions/28647/sniff-a-facebook-password/</link>
      <pubDate>Tue, 07 Jan 2014 12:05:00 +0000</pubDate>
      
      <guid>/questions/28647/sniff-a-facebook-password/</guid>
      <description>sniff a facebook password  0 can i sniff a Facebook password or hotmail password???
thanks
facebookasked 07 Jan &#39;14, 12:05
bobsta
11●2●2●4
accept rate: 0%
  
3 Answers:
  
1Yes. But you probably can&#39;t read it because it is usually encrypted in an HTTPS conversation. If you have the decryption key for SSL you could have Wireshark decode the communication after capture.
answered 07 Jan &#39;14, 12:41</description>
    </item>
    
    <item>
      <title>GPS position together with timestamp</title>
      <link>/questions/28652/gps-position-together-with-timestamp/</link>
      <pubDate>Tue, 07 Jan 2014 13:01:00 +0000</pubDate>
      
      <guid>/questions/28652/gps-position-together-with-timestamp/</guid>
      <description>GPS position together with timestamp  0 Hello,
I am looking for simple way, how to add realtime gps location (longitude and latitude) readed from serial port, to information line of captured packet and to field ie. Location of captured packet, for information, on which place this packet was captured and with possibility to export basic information about SRC mac adress and DST mac adress to google earth. It will be used for vehicle monitoring of wifi devices and for information, where and which device communicate with other.</description>
    </item>
    
    <item>
      <title>Why Wireshark has stopped working when I open a 104MByte pcap file</title>
      <link>/questions/28672/why-wireshark-has-stopped-working-when-i-open-a-104mbyte-pcap-file/</link>
      <pubDate>Wed, 08 Jan 2014 08:53:00 +0000</pubDate>
      
      <guid>/questions/28672/why-wireshark-has-stopped-working-when-i-open-a-104mbyte-pcap-file/</guid>
      <description>Why Wireshark has stopped working when I open a 104MByte pcap file  0 Why Wireshark has stopped working when I open a 104 MByte pcap file. But no problem to open a smaller file e.g. 5 MByte.
large stop file workingasked 08 Jan &#39;14, 08:53
Bob1668
1●2●2●3
accept rate: 0%
  
One Answer:
  
1You may run out of memory - see this wiki for more information: Out of Memory</description>
    </item>
    
    <item>
      <title>Recommended wireless adapter (USB) with Linux wireshark that reports mactime in Radiotap header</title>
      <link>/questions/28683/recommended-wireless-adapter-usb-with-linux-wireshark-that-reports-mactime-in-radiotap-header/</link>
      <pubDate>Wed, 08 Jan 2014 11:35:00 +0000</pubDate>
      
      <guid>/questions/28683/recommended-wireless-adapter-usb-with-linux-wireshark-that-reports-mactime-in-radiotap-header/</guid>
      <description>Recommended wireless adapter (USB) with Linux wireshark that reports mactime in Radiotap header  0 I have tried with Dlink-DWA-160-A2 card with AR9170 but do not see mac timestamp and also TSFT flag is 0.
mactimeasked 08 Jan &#39;14, 11:35
Sudheer
16●4●4●8
accept rate: 0%
  
One Answer:
  
2 I did a quick test with my TP-Link TL-WN822N v2 on Kali 1.0.4. Here are the results.</description>
    </item>
    
    <item>
      <title>[TCP Previous segment not captured] something is lost in communication</title>
      <link>/questions/28704/tcp-previous-segment-not-captured-something-is-lost-in-communication/</link>
      <pubDate>Thu, 09 Jan 2014 01:57:00 +0000</pubDate>
      
      <guid>/questions/28704/tcp-previous-segment-not-captured-something-is-lost-in-communication/</guid>
      <description>[TCP Previous segment not captured] something is lost in communication  0 Hello,
I am investigating strange behavior of one application. The problem from user point of view is described as follow: &#34;There is web application with some form which has two buttons. When user is pressing one of them s(he) suppose to see some dialog. And in some scenario the problem is that it doesn&#39;t happen. Form just does not appear.</description>
    </item>
    
    <item>
      <title>LDAP SSL malformed packet causing error in decoding</title>
      <link>/questions/28720/ldap-ssl-malformed-packet-causing-error-in-decoding/</link>
      <pubDate>Thu, 09 Jan 2014 03:33:00 +0000</pubDate>
      
      <guid>/questions/28720/ldap-ssl-malformed-packet-causing-error-in-decoding/</guid>
      <description>LDAP SSL malformed packet causing error in decoding  0 Hi everybody,
I&#39;m trying to debug LDAP SSL communication and experience a problem with SSL decryption. After a malformed packet is seen from the client, all the client data are no longer decoded by wireshark. Kindly note that the server data is still decoded by wireshark and the SSL debug file shows some information of the data that was no decrypted in wireshark.</description>
    </item>
    
    <item>
      <title>Bluetooth capturing file format</title>
      <link>/questions/28724/bluetooth-capturing-file-format/</link>
      <pubDate>Thu, 09 Jan 2014 05:10:00 +0000</pubDate>
      
      <guid>/questions/28724/bluetooth-capturing-file-format/</guid>
      <description>Bluetooth capturing file format  0 i want to capture a bluetooth HCI layer log in my platfrom（not linux）. In order to read the log in wireshark,I want the log file have the same format as blueZ hcidump log. so, What&#39;s the wireshark bluetooth capture file format rules?
bluetoothasked 09 Jan &#39;14, 05:10
Yuan
1●1●1●1
accept rate: 0%
  
One Answer:
  
0I want the log file have the same format as blueZ hcidump log.</description>
    </item>
    
    <item>
      <title>I have a virtual machine with VPN - how can i split traffic in wireshark between my host and VM?</title>
      <link>/questions/28730/i-have-a-virtual-machine-with-vpn-how-can-i-split-traffic-in-wireshark-between-my-host-and-vm/</link>
      <pubDate>Thu, 09 Jan 2014 06:49:00 +0000</pubDate>
      
      <guid>/questions/28730/i-have-a-virtual-machine-with-vpn-how-can-i-split-traffic-in-wireshark-between-my-host-and-vm/</guid>
      <description>I have a virtual machine with VPN - how can i split traffic in wireshark between my host and VM?  0 So i have a virtual machine and a VPN installed on it. Network is set to NAT. To see that everything works as intended and that my VM with my real IP isn&#39;t connecting anywhere but VPN, i want to check traffic with in host wireshark, but because there are 2 machines connecting with my IP(host and VM)source IP is the same.</description>
    </item>
    
    <item>
      <title>Wireshark is not displaying IPv4 frames with worng IHL</title>
      <link>/questions/28731/wireshark-is-not-displaying-ipv4-frames-with-worng-ihl/</link>
      <pubDate>Thu, 09 Jan 2014 06:58:00 +0000</pubDate>
      
      <guid>/questions/28731/wireshark-is-not-displaying-ipv4-frames-with-worng-ihl/</guid>
      <description>Wireshark is not displaying IPv4 frames with worng IHL  0 Wireshark is unable to capture IPv4 packets with worng IHL or is Windows drop them before sending?
ipv4 ihlasked 09 Jan &#39;14, 06:58
dragos
11●1●1●4
accept rate: 0%
 edited 09 Jan &#39;14, 06:59 
  
One Answer:
  
1If you mean the IP header length by IHL, then yes: the capturing OS could have dropped the frames before Wireshark had a chance to see them.</description>
    </item>
    
    <item>
      <title>Decode SMS Bearer Data Hex String</title>
      <link>/questions/28735/decode-sms-bearer-data-hex-string/</link>
      <pubDate>Thu, 09 Jan 2014 08:53:00 +0000</pubDate>
      
      <guid>/questions/28735/decode-sms-bearer-data-hex-string/</guid>
      <description>Decode SMS Bearer Data Hex String  0 I have the hex string for the SMS bearer data, GSM MAP, etc part of a network capture. Rather than providing an entire capture file to the Wireshark application, I just want to provide the hex stream of the SMS bearer data for decoding. Does Wireshark provide tools or an API for such a task?
For example, below I have provided the hex string for the GSM Mobile Application and GSM SMS TPDU parts of a packet capture.</description>
    </item>
    
    <item>
      <title>Tracking udp game latency</title>
      <link>/questions/28737/tracking-udp-game-latency/</link>
      <pubDate>Thu, 09 Jan 2014 09:07:00 +0000</pubDate>
      
      <guid>/questions/28737/tracking-udp-game-latency/</guid>
      <description>Tracking udp game latency  0 Hello,
complete wireshark rookie here.
i experienced some issues with an online game i play and would like to use wireshark to plot my latency. i tried to track the udp filter on frame.time_delta_displayed but the data generated can&#39;t be what im looking for.
Can someone guide me in the right direction?
latency udpasked 09 Jan &#39;14, 09:07
Nick SB
6●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>802.11 packets converted to &amp;quot;fake&amp;quot; Ethernet packets</title>
      <link>/questions/28742/80211-packets-converted-to-fake-ethernet-packets/</link>
      <pubDate>Thu, 09 Jan 2014 10:56:00 +0000</pubDate>
      
      <guid>/questions/28742/80211-packets-converted-to-fake-ethernet-packets/</guid>
      <description>802.11 packets converted to &amp;ldquo;fake&amp;rdquo; Ethernet packets  1 2The Wi-Fi Wiki page ( http://wiki.wireshark.org/Wi-Fi ) says that sometimes the hardware/driver translates 802.11 headers into Ethernet headers.
Can someone please give me an example of such differences? Or maybe two packets - the proper 802.11 one, and how the translated Ethernet packet would look like? Wireshark screenshots would also be really helpful.
Thank you to anyone who replies, or even attempts to help.</description>
    </item>
    
    <item>
      <title>WinPCAP crashes on Windows 8.1</title>
      <link>/questions/28746/winpcap-crashes-on-windows-81/</link>
      <pubDate>Thu, 09 Jan 2014 13:45:00 +0000</pubDate>
      
      <guid>/questions/28746/winpcap-crashes-on-windows-81/</guid>
      <description>WinPCAP crashes on Windows 8.1  0 Any word on WinPCAP 4.1.3 crashing Windows 8.1 systems?
windows8.1 winpcap crashasked 09 Jan &#39;14, 13:45
ahusmc
11●1●1●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Ssh display filter doesn&amp;#x27;t match TCP port 22 packets?</title>
      <link>/questions/28760/ssh-display-filter-doesnt-match-tcp-port-22-packets/</link>
      <pubDate>Thu, 09 Jan 2014 21:17:00 +0000</pubDate>
      
      <guid>/questions/28760/ssh-display-filter-doesnt-match-tcp-port-22-packets/</guid>
      <description>Ssh display filter doesn&amp;rsquo;t match TCP port 22 packets?  0 While analyzing packets for an ssl issue today, I entered &#34;ssl&#34; into the Display Filter, and no packets were found. Further inspection showed that there WERE TCP packets using port 22 in this trace. I was very surprised that my filter didn&#39;t find them.
Some more experimentation showed the following Wireshark behavior for packets using TCP port 22...
If a successful SSL connection was established (3-way handshake completed), the ssh filter found those ssl packets.</description>
    </item>
    
    <item>
      <title>Outbound Packets not captured</title>
      <link>/questions/28762/outbound-packets-not-captured/</link>
      <pubDate>Fri, 10 Jan 2014 00:14:00 +0000</pubDate>
      
      <guid>/questions/28762/outbound-packets-not-captured/</guid>
      <description>Outbound Packets not captured  0 I know this question has been asked here many times but I found no convincing answer as to the root cause of it. When capturing, outbound packets are not captured when the NIC has DNE LightWeight Filter enabled. DNE is required for my SonicWALL VPN client. My question is 1) What is the reason for this 2) Is there a workaround to capture outbound packets without disabling DNE LightWeight Filter.</description>
    </item>
    
    <item>
      <title>Miscommunication Acqknowledge software and Vizard Lite</title>
      <link>/questions/28765/miscommunication-acqknowledge-software-and-vizard-lite/</link>
      <pubDate>Fri, 10 Jan 2014 03:14:00 +0000</pubDate>
      
      <guid>/questions/28765/miscommunication-acqknowledge-software-and-vizard-lite/</guid>
      <description>Miscommunication Acqknowledge software and Vizard Lite  0 Hi all,
I&#39;m a PhD student in neuroscience, looking into the effects of stress on risk-taking. To this end we measure physiological signals such as heart rate and blood pressure. This measurement data is gathered by a software package called Acqknowledge, which sends it over a LAN to another pc, on which a Python script runs. And this is where the trouble starts: at some point, sometimes after a minute, sometimes after 30 minutes, the connection is lost between Acqknowledge and the python script.</description>
    </item>
    
    <item>
      <title>Is private_data working correctly ?</title>
      <link>/questions/28770/is-private_data-working-correctly/</link>
      <pubDate>Fri, 10 Jan 2014 07:28:00 +0000</pubDate>
      
      <guid>/questions/28770/is-private_data-working-correctly/</guid>
      <description>Is private_data working correctly ?  0 Hi,
I&#39;m having some issues with pinfo-&amp;gt;private_data method , I think I&#39;m using it correctly and I&#39;v seen in some revision that private_data is removed. So is private_data working ? Is there another method to pass data to a sub-dissector ?
pinfo privata dataasked 10 Jan &#39;14, 07:28
Afrim
160●10●11●16
accept rate: 22%
  
One Answer:
  
2 Passing data between dissectors using pinfo-&amp;gt;private_data still mostly works (for example, there can be problems if exceptions occur), but it is not the recommended method and one day this method may disappear altogether.</description>
    </item>
    
    <item>
      <title>Connection reset after &amp;quot;Previous segment not captured&amp;quot;</title>
      <link>/questions/28772/connection-reset-after-previous-segment-not-captured/</link>
      <pubDate>Fri, 10 Jan 2014 08:11:00 +0000</pubDate>
      
      <guid>/questions/28772/connection-reset-after-previous-segment-not-captured/</guid>
      <description>Connection reset after &amp;ldquo;Previous segment not captured&amp;rdquo;  0 I have a Docker container running on a virtual machine and I&#39;m trying to upload a file to S3 (or Google Cloud Storage, both with the same result) from inside it.
While there are no problems for small files (&amp;lt;1MB), with larger ones the connection is reset by the remote end in the middle of the transfer and a Broken Pipe or Connection reset error is raised by the application.</description>
    </item>
    
    <item>
      <title>block an ip with iptables</title>
      <link>/questions/28775/block-an-ip-with-iptables/</link>
      <pubDate>Fri, 10 Jan 2014 10:12:00 +0000</pubDate>
      
      <guid>/questions/28775/block-an-ip-with-iptables/</guid>
      <description>block an ip with iptables  0 hi, for school i have to block an ip with iptables and monitor that with wireshark.
the result shoul be like this on the terminal: ping 130.136.4.145 PING 130.136.4.145 (130.136.4.145) 56(84) bytes of data. Destination host unreachable
and on wireshark and log http://imageshack.com/a/img823/7972/tqf9.jpg
the question is: what&#39;s the command that blocks the ip?? I tried some command but nothing happened. Thanks for the answer</description>
    </item>
    
    <item>
      <title>Wireshark 1.10.5 consuming memory until it crashes on windows</title>
      <link>/questions/28778/wireshark-1105-consuming-memory-until-it-crashes-on-windows/</link>
      <pubDate>Fri, 10 Jan 2014 11:51:00 +0000</pubDate>
      
      <guid>/questions/28778/wireshark-1105-consuming-memory-until-it-crashes-on-windows/</guid>
      <description>Wireshark 1.10.5 consuming memory until it crashes on windows  0 Wireshark 1.10.5, installed just today on w2k8 r2 system.
Normally I run Wireshark on Linux (openSUSE 12.x still, x86_64) and use it for hours on end and it&#39;s just fine. Today I needed to do some SSL decryption so I had to fire up a VM and install Wireshark there. Getting the latest and installing it everything is fine, I can filter into the stream I want (tcp.</description>
    </item>
    
    <item>
      <title>wirehark can&amp;#x27;t recognize GSM-MAP command SearchForMS</title>
      <link>/questions/28789/wirehark-cant-recognize-gsm-map-command-searchforms/</link>
      <pubDate>Fri, 10 Jan 2014 17:28:00 +0000</pubDate>
      
      <guid>/questions/28789/wirehark-cant-recognize-gsm-map-command-searchforms/</guid>
      <description>wirehark can&amp;rsquo;t recognize GSM-MAP command SearchForMS  0 Dear All, I would like to ask about GSM MAP command like &#34;SearchForMS, &#34;SetCipheringMode&#34;, &#34;Paging&#34;, &#34;ForwardNewTMSI&#34;,&#34;ObtainIMEI&#34;, why it&#39;s so difficult to find a complete reference, even in 3gpp 29.002 document or ETSI, and why wireshark can&#39;t recognize all the commands??
Thank you,
searchforms gsm-mapasked 10 Jan &#39;14, 17:28
andry sunandar
1●1●1●2
accept rate: 0%
 edited 10 Jan &#39;14, 18:04 
Possibly because it&#39;s some proprietary extensions (or not GSM MAP)and not part of the standard?</description>
    </item>
    
    <item>
      <title>Packet Analyzer</title>
      <link>/questions/28792/packet-analyzer/</link>
      <pubDate>Sat, 11 Jan 2014 02:09:00 +0000</pubDate>
      
      <guid>/questions/28792/packet-analyzer/</guid>
      <description>Packet Analyzer  0 Hello to everyone, I would like to ask the Pro a question. I am looking for a software which can intercept packets sent from program to http server.I have a program that sends packets to a web server and also receives packets back.I would like to intercept the ones that are comming back and analyze them.Do you think Shark can do that for me? Thanks
packetanalyzerasked 11 Jan &#39;14, 02:09</description>
    </item>
    
    <item>
      <title>Convert .pcap into .txt format</title>
      <link>/questions/28794/convert-pcap-into-txt-format/</link>
      <pubDate>Sat, 11 Jan 2014 05:28:00 +0000</pubDate>
      
      <guid>/questions/28794/convert-pcap-into-txt-format/</guid>
      <description>Convert .pcap into .txt format  1 Hello ,
I would like to know the procedure for converting a .pcap wireshark trace into .txt format and it should be in readable format. I have looked some procedures but it is still not clear to me. Do i need to install any other .exe other then wireshark to do so ?
Thanks, Manoj
conversion packetasked 11 Jan &#39;14, 05:28
Manoj Singh</description>
    </item>
    
    <item>
      <title>Is it allowed to have wireshark screenshots on the company homepage?</title>
      <link>/questions/28795/is-it-allowed-to-have-wireshark-screenshots-on-the-company-homepage/</link>
      <pubDate>Sat, 11 Jan 2014 07:20:00 +0000</pubDate>
      
      <guid>/questions/28795/is-it-allowed-to-have-wireshark-screenshots-on-the-company-homepage/</guid>
      <description>Is it allowed to have wireshark screenshots on the company homepage?  0 Hello Sirs,
is it allowed to make screenshots from traces captured and displayed with wireshark and put them on a company&#39;s homepage? And is it okay to use screenshots from wireshark logs/traces in some training material?
Please advise.
kind regards,
Stefan B.
published screeenshots wiresharkasked 11 Jan &#39;14, 07:20
stefanblomeier
16●1●1●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>[closed] what is requirment of microsoft packet scheduler ?</title>
      <link>/questions/28799/what-is-requirment-of-microsoft-packet-scheduler/</link>
      <pubDate>Sat, 11 Jan 2014 09:34:00 +0000</pubDate>
      
      <guid>/questions/28799/what-is-requirment-of-microsoft-packet-scheduler/</guid>
      <description>[closed] what is requirment of microsoft packet scheduler ?  0 what is requirment of Broadcom NetXtreme Gigabit Ethernet Driver in wireshark?
i m the bigginer user of wireshark
wireshrkasked 11 Jan &#39;14, 09:34
kukku8045
11●1●1●2
accept rate: 0%
 closed 11 Jan &#39;14, 11:39 
Kurt Knochner ♦
24.8k●10●39●237
requirement in terms of what? And how is the Microsoft packet scheduler involved?
(11 Jan &#39;14, 11:11) Kurt Knochner ♦I m the new user of thos and i show lot of tutorial of wireshark coockies stealing but when ever i try it i cant inject cookies in chrome .</description>
    </item>
    
    <item>
      <title>How to export raw data from all captured packets?</title>
      <link>/questions/28814/how-to-export-raw-data-from-all-captured-packets/</link>
      <pubDate>Sun, 12 Jan 2014 04:40:00 +0000</pubDate>
      
      <guid>/questions/28814/how-to-export-raw-data-from-all-captured-packets/</guid>
      <description>How to export raw data from all captured packets?  0 Hi, I have a lot of UDP packets captured where I want to save the raw data (bytes) of each packet in a separate file.
The way I&#39;m doing it currently is that I select the packet, select the data bytes and do Strg+H (Export selected packet bytes). But since there are a lot of packets this is of course not a good solution for me.</description>
    </item>
    
    <item>
      <title>[closed] Help needed on deep analysing PCAP file</title>
      <link>/questions/28818/help-needed-on-deep-analysing-pcap-file/</link>
      <pubDate>Sun, 12 Jan 2014 07:22:00 +0000</pubDate>
      
      <guid>/questions/28818/help-needed-on-deep-analysing-pcap-file/</guid>
      <description>[closed] Help needed on deep analysing PCAP file  0 I got a pcap and need to have it deep analysed to find a netbot, how do i do this with wireshark??
encrypted pcap botnetasked 12 Jan &#39;14, 07:22
MarkV
1●1●1●1
accept rate: 0%
 closed 12 Jan &#39;14, 07:29 
Kurt Knochner ♦
24.8k●10●39●237
Again the same question??
(12 Jan &#39;14, 07:27) Kurt Knochner ♦No, not the same i got a several parts analysed but still it&#39;s not the solution, so clearly, me as a first timer, am doing something wrong.</description>
    </item>
    
    <item>
      <title>Decryption with SSL/TLS pre-master</title>
      <link>/questions/28823/decryption-with-ssltls-pre-master/</link>
      <pubDate>Sun, 12 Jan 2014 09:33:00 +0000</pubDate>
      
      <guid>/questions/28823/decryption-with-ssltls-pre-master/</guid>
      <description>Decryption with SSL/TLS pre-master  0 Hey All,
I am looking for a way to decrypt non-browser based traffic (i.e. e-mail, Citrix ICA, SFTP) on my local machine utilizing pre-master secrets. I know this is possible when utilizing the SSLKEYLOGFILE as described here, http://www.root9.net/2012/11/ssl-decryption-with-wireshark-private.html.
The above link only appears to work for browser based traffic. My question is, how can I do the same level of decryption using Wireshark and pre-master secrets for non-browser based traffic?</description>
    </item>
    
    <item>
      <title>tshark writing 1st jan 1970 as packet time stamps after writing to new file using -w option</title>
      <link>/questions/28835/tshark-writing-1st-jan-1970-as-packet-time-stamps-after-writing-to-new-file-using-w-option/</link>
      <pubDate>Mon, 13 Jan 2014 02:41:00 +0000</pubDate>
      
      <guid>/questions/28835/tshark-writing-1st-jan-1970-as-packet-time-stamps-after-writing-to-new-file-using-w-option/</guid>
      <description>tshark writing 1st jan 1970 as packet time stamps after writing to new file using -w option  0 Hi All, Iam getting strange issue, when iam trying to split file using -R filter and writing to a new file, all packets for time stamp are marked as 1st Jan 1970. Below is the command iam using. ./tshark.exe -n -r time_issue.pcapng -2 -R &#39;!gtp&amp;amp;&amp;amp;!icmp&amp;amp;&amp;amp;dns&#39; -w time_issueSplit2.pcapng
Iam Using TShark 1.10.5 (SVN Rev 54262 from /trunk-1.</description>
    </item>
    
    <item>
      <title>init.lua gets overwritten during an upgrade. How can I prevent that?</title>
      <link>/questions/28838/initlua-gets-overwritten-during-an-upgrade-how-can-i-prevent-that/</link>
      <pubDate>Mon, 13 Jan 2014 05:40:00 +0000</pubDate>
      
      <guid>/questions/28838/initlua-gets-overwritten-during-an-upgrade-how-can-i-prevent-that/</guid>
      <description>init.lua gets overwritten during an upgrade. How can I prevent that?  0 Currently, a Wireshark upgrade overwrites the system init.lua without checking for user modifications. If would be nice if there was a way to keep the custom entries there.
luaasked 13 Jan &#39;14, 05:40
MattKnepp
1●1●1●1
accept rate: 0%
 edited 02 Feb &#39;14, 13:56 
helloworld
3.1k●4●20●41
  
One Answer:
  
3Just place your version of init.</description>
    </item>
    
    <item>
      <title>Wireshark build fails when trying to compile plugin</title>
      <link>/questions/28843/wireshark-build-fails-when-trying-to-compile-plugin/</link>
      <pubDate>Mon, 13 Jan 2014 08:07:00 +0000</pubDate>
      
      <guid>/questions/28843/wireshark-build-fails-when-trying-to-compile-plugin/</guid>
      <description>Wireshark build fails when trying to compile plugin  1 Hi,
I&#39;m trying to compile a plugin for Wireshark version 1.10.5 and am getting the following error:
c:\wireshark\epan\except.h(97) : error C2054: expected &amp;#39;(&amp;#39; to follow &amp;#39;WS_MSVC_NORETURN&amp;#39; c:\wireshark\epan\except.h(97) : error C2085: &amp;#39;except_rethrow&amp;#39; : not in formal parameter list c:\wireshark\epan\except.h(98) : error C2082: redefinition of formal parameter &amp;#39;WS_MSVC_NORETURN&amp;#39; c:\wireshark\epan\except.h(98) : error C2143: syntax error : missing &amp;#39;;&amp;#39; before &amp;#39;type&amp;#39; c:\wireshark\epan\except.h(98) : error C2085: &amp;#39;except_throw&amp;#39; : not in formal parameter list c:\wireshark\epan\except.</description>
    </item>
    
    <item>
      <title>How to see the E-DCH UL DATA FRAME</title>
      <link>/questions/28844/how-to-see-the-e-dch-ul-data-frame/</link>
      <pubDate>Mon, 13 Jan 2014 09:42:00 +0000</pubDate>
      
      <guid>/questions/28844/how-to-see-the-e-dch-ul-data-frame/</guid>
      <description>How to see the E-DCH UL DATA FRAME  0 I have a pcap trace file. How to see the E-DCH UL DATA FRAME? Should I load some special protocol stack to Wireshark, or just configure the filters properly?
e-dch data frameasked 13 Jan &#39;14, 09:42
Bob1668
1●2●2●3
accept rate: 0%
What protocol are you refering to (RANAP, NBAP , RNSAP...)? How is the protocol transported,? Which layers do you see in the trace?</description>
    </item>
    
    <item>
      <title>rfc 2833 in H.323</title>
      <link>/questions/28845/rfc-2833-in-h323/</link>
      <pubDate>Mon, 13 Jan 2014 09:45:00 +0000</pubDate>
      
      <guid>/questions/28845/rfc-2833-in-h323/</guid>
      <description>rfc 2833 in H.323  0 I&#39;m trying to find DTMF digits in wireshark in H.323 protocol, however I can&#39;t find it. Does anybody know what can be done and which filter I should use?
rfc2833 dtmf h323asked 13 Jan &#39;14, 09:45
markkarp
1●2●2●3
accept rate: 0%
Do any of the other questions that come up with a search for dtmf help?
(13 Jan &#39;14, 10:05) grahamb ♦Not yet. Once step at the time ))</description>
    </item>
    
    <item>
      <title>Verify_tools setup issue</title>
      <link>/questions/28847/verify_tools-setup-issue/</link>
      <pubDate>Mon, 13 Jan 2014 12:29:00 +0000</pubDate>
      
      <guid>/questions/28847/verify_tools-setup-issue/</guid>
      <description>Verify_tools setup issue  0 Hello I have followed the steps to hopefully build but I hit an issue when running nmake -f Makefile.nmake verify_tools
The issue is ERROR: Can&#39;t find &#39;which&#39;. Unable to proceed.
NMAKE : fatal error U1077: &#39;C:\cygwin\bin\bash.EXE&#39; : return code &#39;0x1&#39; Stop.
However the which.exe is found in c:\cygwin\bin and can be called from the command line. Has this issue been seen before?
Thanks
setup verify_tool cygwinasked 13 Jan &#39;14, 12:29</description>
    </item>
    
    <item>
      <title>strange web download behavior</title>
      <link>/questions/28850/strange-web-download-behavior/</link>
      <pubDate>Mon, 13 Jan 2014 15:26:00 +0000</pubDate>
      
      <guid>/questions/28850/strange-web-download-behavior/</guid>
      <description>strange web download behavior  0 When downloading sql developer tools from oracle.com(using IE or Chrome) users are experiencing an issue where the download will start and just die at about 520k. From the captures i can see the client ACKing at about the 520K mark and then nothing from the server, followed up by several keep-alives from the client to the server. Since I have no way of doing a capture at the server, i can&#39;t tell if the server is sending more data after the ACK or if the ACK ever gets to the server.</description>
    </item>
    
    <item>
      <title>How to use tshark to dissect multiple pcap files at one time</title>
      <link>/questions/28854/how-to-use-tshark-to-dissect-multiple-pcap-files-at-one-time/</link>
      <pubDate>Mon, 13 Jan 2014 21:46:00 +0000</pubDate>
      
      <guid>/questions/28854/how-to-use-tshark-to-dissect-multiple-pcap-files-at-one-time/</guid>
      <description>How to use tshark to dissect multiple pcap files at one time  0 There&#39;re multiple pcap files, I want to use tshark to dissect them at one time, how to config the input parameters?
files dissect multiple tsharkasked 13 Jan &#39;14, 21:46
metamatrix
56●16●16●19
accept rate: 100%
  
2 Answers:
  
1 I don&#39;t see how with tshark alone this can be achieved but you could run a mergecap before and then process the resulting file.</description>
    </item>
    
    <item>
      <title>Graphing an effective forwarding rate</title>
      <link>/questions/28859/graphing-an-effective-forwarding-rate/</link>
      <pubDate>Tue, 14 Jan 2014 06:40:00 +0000</pubDate>
      
      <guid>/questions/28859/graphing-an-effective-forwarding-rate/</guid>
      <description>Graphing an effective forwarding rate  0 A dlink switch (DGS-1100-24) is being used for iscsi traffic. The switch has a max. forwarding rate of 35.71 Mpps (assuming with 64 byte packets). Jumbo frames are enabled on the switch. Is there a way to graph an effective forwarding rate on any given port from a wireshark capture?
Thanks
rate forwarding switch iscsiasked 14 Jan &#39;14, 06:40
net_tech
116●30●33●37
accept rate: 13%</description>
    </item>
    
    <item>
      <title>Application sends RSTs abruptly and thus fails to complete.</title>
      <link>/questions/28891/application-sends-rsts-abruptly-and-thus-fails-to-complete/</link>
      <pubDate>Tue, 14 Jan 2014 18:11:00 +0000</pubDate>
      
      <guid>/questions/28891/application-sends-rsts-abruptly-and-thus-fails-to-complete/</guid>
      <description>Application sends RSTs abruptly and thus fails to complete.  0 This is happening always for a particular application on a specific client.
The application is unable to complete and &#34;network communication error&#34; pops up. In one run log shows: &#34;java.net.SocketException: recvfrom failed: ECONNRESET (Connection reset by peer)&#34; Corresponding pcap shows client sending RSTs after sending 15 Dup Acks for the same packet.
In another run log shows : &#34;java.io.IOException: unexpected end of stream&#34;</description>
    </item>
    
    <item>
      <title>How to compile release version of wireshark?</title>
      <link>/questions/28892/how-to-compile-release-version-of-wireshark/</link>
      <pubDate>Tue, 14 Jan 2014 18:28:00 +0000</pubDate>
      
      <guid>/questions/28892/how-to-compile-release-version-of-wireshark/</guid>
      <description>How to compile release version of wireshark?  0 I want to compile the release version of Wireshark, what config should I modify?
release wiresharkasked 14 Jan &#39;14, 18:28
metamatrix
56●16●16●19
accept rate: 100%
???
according to another question, you have already compiled Wireshark
http://ask.wireshark.org/questions/27139/linking-problem-when-add-an-extra-lib-to-wireshark
So, what exactly is your question?
(15 Jan &#39;14, 00:42) Kurt Knochner ♦I think it&#39;s the debug version, then is there any release version to compile?</description>
    </item>
    
    <item>
      <title>Packet length varies a lot between 2 iscsi adapter cards</title>
      <link>/questions/28895/packet-length-varies-a-lot-between-2-iscsi-adapter-cards/</link>
      <pubDate>Tue, 14 Jan 2014 20:01:00 +0000</pubDate>
      
      <guid>/questions/28895/packet-length-varies-a-lot-between-2-iscsi-adapter-cards/</guid>
      <description>Packet length varies a lot between 2 iscsi adapter cards  0 I am running tests on 2 different types of iscsi adapter cards on linux. The test method is to call rsync to copy a folder with large amount of data files from the data center to a local hard drive. The wireshark shows that one test transfers TCP packets of 12 to 14 KBytes in the &#34;length&#34; column, the other only shows 1KBytes.</description>
    </item>
    
    <item>
      <title>why dfilter_apply_edt() returning false every time.</title>
      <link>/questions/28899/why-dfilter_apply_edt-returning-false-every-time/</link>
      <pubDate>Wed, 15 Jan 2014 00:29:00 +0000</pubDate>
      
      <guid>/questions/28899/why-dfilter_apply_edt-returning-false-every-time/</guid>
      <description>why dfilter_apply_edt() returning false every time.  0 so I am trying to dissect diameter packets using wireshark library,
when i apply filter &#39;diameter&#39;, and then call dfilter_apply_edt , it always returning false.
what could be the reason behind this.
thanks.
code libwireshark dissection pcap diameterasked 15 Jan &#39;14, 00:29
Sanny_D
0●18●20●21
accept rate: 50%
Perhaps the packets are not recognised as Diameter? what&#39;s in the frame you are trying to dissect?</description>
    </item>
    
    <item>
      <title>Win7 Power Save Mode &amp;amp; Wireshark</title>
      <link>/questions/28901/win7-power-save-mode-wireshark/</link>
      <pubDate>Wed, 15 Jan 2014 02:30:00 +0000</pubDate>
      
      <guid>/questions/28901/win7-power-save-mode-wireshark/</guid>
      <description>Win7 Power Save Mode &amp;amp; Wireshark  0 While capture the PC mode is turned to Power Saving. Turning the PC ON again Wireshark comes along with following Error :&#34;The network adapter on which the capture was being done is no longer running; the capture has stopped.&#34;
I need to capture frames immediately after waking up the PC, so why is connection lost, and what can I do against it. Is this behaviour dokumented somewhere?</description>
    </item>
    
    <item>
      <title>Why RTP Packets are missing in RTP Stream Analysis</title>
      <link>/questions/28902/why-rtp-packets-are-missing-in-rtp-stream-analysis/</link>
      <pubDate>Wed, 15 Jan 2014 03:52:00 +0000</pubDate>
      
      <guid>/questions/28902/why-rtp-packets-are-missing-in-rtp-stream-analysis/</guid>
      <description>Why RTP Packets are missing in RTP Stream Analysis  1 Why all RTP Packets dont show up in RTP Analysis Stream window?
Since RTP uses UDP, Can we consider UDP packets as RTP Packets?
rtpasked 15 Jan &#39;14, 03:52
lte007
41●6●6●8
accept rate: 100%
  
2 Answers:
  
0 Please dont worry about it...i figured out the problem... While analyzing wireshark considers 1 source &amp;amp; 1 destination at a time.</description>
    </item>
    
    <item>
      <title>VoIP calls List From Command Line</title>
      <link>/questions/28906/voip-calls-list-from-command-line/</link>
      <pubDate>Wed, 15 Jan 2014 04:29:00 +0000</pubDate>
      
      <guid>/questions/28906/voip-calls-list-from-command-line/</guid>
      <description>VoIP calls List From Command Line  0 Hi,
I&#39;m using Wireshark to sniff the network and detect the VoIP calls. Detected VoIP calls can be seen from GUI (Telephony-&amp;gt;VoIP Calls).
Now I want to get this list from command line. I searched through wireshark documents, but couldn&#39;t find a command to do that.
I&#39;m using the commands like
tshark -r myFile -R &#34;sip.CSeq.method eq INVITE&#34;
Is there a command to show that voip call list from command line, or do i have to parse the outputs and create my own list?</description>
    </item>
    
    <item>
      <title>No outgoing packets</title>
      <link>/questions/28909/no-outgoing-packets/</link>
      <pubDate>Wed, 15 Jan 2014 06:40:00 +0000</pubDate>
      
      <guid>/questions/28909/no-outgoing-packets/</guid>
      <description>No outgoing packets  0 Hello,
I&#39;m currently facing issue when tryin to capture network communications from Win 7 X64 stations. When I start a capture from a client, in the capture I most of the time I don&#39;t see packets sent by the client.
Strangely it&#39;s quite random. Sometines I see packets from the client at the begining of the communication but after a short while I see only packets from server.</description>
    </item>
    
    <item>
      <title>compile error with v. 1.10.5 on fedora 17</title>
      <link>/questions/28910/compile-error-with-v-1105-on-fedora-17/</link>
      <pubDate>Wed, 15 Jan 2014 06:51:00 +0000</pubDate>
      
      <guid>/questions/28910/compile-error-with-v-1105-on-fedora-17/</guid>
      <description>compile error with v. 1.10.5 on fedora 17  0 I downloaded v. 1.10.5 and the build failed. I simply ran ./configure without any options. The error was:
 CC wireshark-capture-pcap-util.o capture-pcap-util.c:569:1: error: static declaration of ‘pcap_datalink_name_to_val’ follows non-static declaration In file included from /usr/include/pcap.h:45:0, from capture-pcap-util.h:30, from capture-pcap-util.c:48: /usr/include/pcap/pcap.h:380:5: note: previous declaration of ‘pcap_datalink_name_to_val’ was here capture-pcap-util.c:584:1: error: static declaration of ‘pcap_datalink_val_to_name’ follows non-static declaration In file included from /usr/include/pcap.</description>
    </item>
    
    <item>
      <title>problem decoding h264/RTP</title>
      <link>/questions/28912/problem-decoding-h264rtp/</link>
      <pubDate>Wed, 15 Jan 2014 07:02:00 +0000</pubDate>
      
      <guid>/questions/28912/problem-decoding-h264rtp/</guid>
      <description>problem decoding h264/RTP  0 I am trying to analyse a problem with H264 data over RTP when using FU-A fragmentation. Sometimes wireshark can decode the first 3 fields in the packets and sometimes it can&#39;t. I think that the problem is likely in my data, not wireshark because all of the h264 packets in a given file with either decode or not. I have manually decoded several of the fields in packets that fail to decode and they seem correct.</description>
    </item>
    
    <item>
      <title>Packet size</title>
      <link>/questions/28913/packet-size/</link>
      <pubDate>Wed, 15 Jan 2014 07:03:00 +0000</pubDate>
      
      <guid>/questions/28913/packet-size/</guid>
      <description>Packet size  0 Can Wireshark provide you with network traffic packet size counts? How and where ? Are you able to distinguish how many of each packet size was transmitted on your LAN segment?
homework packet sizeasked 15 Jan &#39;14, 07:03
jw123
11●3●3●4
accept rate: 0%
 edited 15 Jan &#39;14, 07:25 
Kurt Knochner ♦
24.8k●10●39●237
2The answer might be a bit longer. By when do you have to submit the homework?</description>
    </item>
    
    <item>
      <title>Data reconstruction</title>
      <link>/questions/28915/data-reconstruction/</link>
      <pubDate>Wed, 15 Jan 2014 07:04:00 +0000</pubDate>
      
      <guid>/questions/28915/data-reconstruction/</guid>
      <description>Data reconstruction  0 Is FTP data able to be replayed and reconstructed if the packets are captured on the wire? If an attack were to occur between the source and destination IP host with data replayed that has been altered, what kind of attack is this called?
data homework reconstructionasked 15 Jan &#39;14, 07:04
jw123
11●3●3●4
accept rate: 0%
 edited 15 Jan &#39;14, 07:24 
Kurt Knochner ♦</description>
    </item>
    
    <item>
      <title>Protocol breakdown</title>
      <link>/questions/28921/protocol-breakdown/</link>
      <pubDate>Wed, 15 Jan 2014 07:20:00 +0000</pubDate>
      
      <guid>/questions/28921/protocol-breakdown/</guid>
      <description>Protocol breakdown  0 What function in Wireshark provides you with a breakdown of the different protocol types on the LAN segment?
protocol homeworkasked 15 Jan &#39;14, 07:20
jw123
11●3●3●4
accept rate: 0%
 edited 15 Jan &#39;14, 07:24 
Kurt Knochner ♦
24.8k●10●39●237
  
One Answer:
  
0See my other answer. It&#39;s the same.
answered 15 Jan &#39;14, 13:33
Jasper ♦♦
23.8k●5●51●284
accept rate: 18%</description>
    </item>
    
    <item>
      <title>Help with capturing wireless data</title>
      <link>/questions/28931/help-with-capturing-wireless-data/</link>
      <pubDate>Wed, 15 Jan 2014 11:40:00 +0000</pubDate>
      
      <guid>/questions/28931/help-with-capturing-wireless-data/</guid>
      <description>Help with capturing wireless data  0 Are you able to capture packets &#39;in the air&#39;? As in, not joined to the network or do you have to be joined to the network? I could have sworn there was a way in Linux to capture wireless packets without having to be joined on to the network.
wirelessasked 15 Jan &#39;14, 11:40
Chris Hinton
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>build issue on windows 7, 32bits with VS2010</title>
      <link>/questions/28941/build-issue-on-windows-7-32bits-with-vs2010/</link>
      <pubDate>Wed, 15 Jan 2014 17:53:00 +0000</pubDate>
      
      <guid>/questions/28941/build-issue-on-windows-7-32bits-with-vs2010/</guid>
      <description>build issue on windows 7, 32bits with VS2010  0 Hi all, I got a issue on compiling.
after &#39;nmake -f Makefile.nmake setup&#39;, the following message was displayed and failed.
...
****** WinPcap_4_1_3.exe ****** No HTTP proxy specified (http_proxy and HTTP_PROXY are empty). Downloading WinPcap_4_1_3.exe into &amp;#39;/cygdrive/c/Wireshark-win32-libs-1.10&amp;#39;, installing into . --2014-01-16 10:40:16-- http://anonsvn.wireshark.org/wireshark-win32-libs/tags/2013-04-22/packages//WinPcap_4_1_3.exe Resolving anonsvn.wireshark.org (anonsvn.wireshark.org)... 174.137.42.70 Connecting to anonsvn.wireshark.org (anonsvn.wireshark.org)|174.137.42.70|:80... failed: Connection timed out. Retrying. &amp;ndash;2014-01-16 10:40:38&amp;ndash; (try: 2) http://anonsvn.</description>
    </item>
    
    <item>
      <title>How to add packettime in pcap header ?</title>
      <link>/questions/28948/how-to-add-packettime-in-pcap-header/</link>
      <pubDate>Wed, 15 Jan 2014 22:44:00 +0000</pubDate>
      
      <guid>/questions/28948/how-to-add-packettime-in-pcap-header/</guid>
      <description>How to add packettime in pcap header ?  0 Hi,
i am trying to generate pcap files from a collection of packet data. I put the global header and packet data correctly and it appeared correctly in wireshark. But the problem is with the arrival time of the packet, which is not getting as expected;
Can someone please describe how to create the first 8 bytes in the pcap header ?</description>
    </item>
    
    <item>
      <title>CESOPSN and SATOP decoding with RTP support</title>
      <link>/questions/28954/cesopsn-and-satop-decoding-with-rtp-support/</link>
      <pubDate>Thu, 16 Jan 2014 01:53:00 +0000</pubDate>
      
      <guid>/questions/28954/cesopsn-and-satop-decoding-with-rtp-support/</guid>
      <description>CESOPSN and SATOP decoding with RTP support  0 Is there any way to decode CESOPSN andn SATOP packets tah includes RTP headres? The option showed in the &#34;decode as&#34; menu is CSOPSN (no RTp support) and SATOP (no RTP support). How can I see the structure of one of these types of packets with wireshark?
pseudowiresasked 16 Jan &#39;14, 01:53
123wshark
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Modbus/tcp</title>
      <link>/questions/28962/modbustcp/</link>
      <pubDate>Thu, 16 Jan 2014 05:45:00 +0000</pubDate>
      
      <guid>/questions/28962/modbustcp/</guid>
      <description>Modbus/tcp  0 Hello I have develop a electronic card (client) for connect to a commercial controler(server) in modbus TCP. Can you tell me why the server don&#39;t answer, to modbus tcp, my ip is 192.164.0.34. Thanks
http://cloudshark.org/captures/4b8f9f3579b3
modbus tcpasked 16 Jan &#39;14, 05:45
gregoire
26●1●1●4
accept rate: 100%
  
2 Answers:
  
1 I have found the problem, i have not the same source port between the 7 (SYN) and 8(modbus) frame , but wireshark have not detect the problem!</description>
    </item>
    
    <item>
      <title>reading pcap file in C# or C&#43;&#43;</title>
      <link>/questions/28965/reading-pcap-file-in-c-or-c/</link>
      <pubDate>Thu, 16 Jan 2014 08:22:00 +0000</pubDate>
      
      <guid>/questions/28965/reading-pcap-file-in-c-or-c/</guid>
      <description>reading pcap file in C# or C++  0 in general, I want to analyze a tcp packet ,first I should read the pcap file in c++(this is my first problem), after that I want to analyze just the tcp packets in the flow of packets, and find it&#39;s header details such that &#34;syn&#34;,&#34;ack&#34;,&#34;fin&#34;,&#34;source ip&#34;,&#34;destination ip&#34; and etc ,for this I read something a bout &#34;pcap&#34; that I found it here, but it doesn&#39;t give me enough information, it doesn&#39;t give me any thing about &#34;</description>
    </item>
    
    <item>
      <title>Obtain a patch</title>
      <link>/questions/28968/obtain-a-patch/</link>
      <pubDate>Thu, 16 Jan 2014 11:31:00 +0000</pubDate>
      
      <guid>/questions/28968/obtain-a-patch/</guid>
      <description>Obtain a patch  0 Hello
I want to obtain this patch: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4814 But I have no idea how to do this :/
Thanks in advance for your reply !
patchasked 16 Jan &#39;14, 11:31
Rofghl
6●1●1●3
accept rate: 0%
  
One Answer:
  
2 You can download automated builds from http://www.wireshark.org/download/automated/ . We&#39;re in the process of migrating from Subversion, which uses monotonically increasing revision numbers such as &#34;</description>
    </item>
    
    <item>
      <title>Seeing frames destined for other machines, why?</title>
      <link>/questions/28974/seeing-frames-destined-for-other-machines-why/</link>
      <pubDate>Thu, 16 Jan 2014 13:59:00 +0000</pubDate>
      
      <guid>/questions/28974/seeing-frames-destined-for-other-machines-why/</guid>
      <description>Seeing frames destined for other machines, why?  0 This is not a wireshark question but a general networking question. My machine running wireshark on the adapter in promiscuous mode sometimes receives frames destined for another machine on the subnet even though the network is fully switched, why?
my machine&#39;s mac address is :aa:bb:cc:xx:yy:zz, in promiscuous mode, no ip other machine&#39;s mac address is : aa:bb:cc:kk:ll:mm, ip:192.168.101.2 Internet server : ip:64.</description>
    </item>
    
    <item>
      <title>Header Offset on packet details</title>
      <link>/questions/28978/header-offset-on-packet-details/</link>
      <pubDate>Thu, 16 Jan 2014 20:25:00 +0000</pubDate>
      
      <guid>/questions/28978/header-offset-on-packet-details/</guid>
      <description>Header Offset on packet details  0 I&#39;m a visual learner. Is there a way to have it show the header offsets in the packet details? See example shot where I added the first 4 offsets of the IP header.
http://imgur.com/aUNHeIL
header offsetasked 16 Jan &#39;14, 20:25
BeauGalbraith
11●1●1●3
accept rate: 0%
 edited 16 Jan &#39;14, 20:25 
  
One Answer:
  
0The only way to do that is to modify Wireshark&#39;s source code so that it does so.</description>
    </item>
    
    <item>
      <title>Can we generate customized packets using Wireshark?</title>
      <link>/questions/28987/can-we-generate-customized-packets-using-wireshark/</link>
      <pubDate>Fri, 17 Jan 2014 02:06:00 +0000</pubDate>
      
      <guid>/questions/28987/can-we-generate-customized-packets-using-wireshark/</guid>
      <description>Can we generate customized packets using Wireshark?  0 We need to test CIFS protocol with negative test scenarios to check the system behavior from Server to Host. Would it be possible to generate the packets with wrong Data using Wireshark?
packet-modificationasked 17 Jan &#39;14, 02:06
Hari Kapparapu
1●1●1●1
accept rate: 0%
  
One Answer:
  
2No. Wireshark is not a packet generator. Take a look at scapy instead to craft packets, or Ostinato to replay traces you already have.</description>
    </item>
    
    <item>
      <title>not able to decrypt ssl traffic in wireshark using SessionID and MasterKey</title>
      <link>/questions/28989/not-able-to-decrypt-ssl-traffic-in-wireshark-using-sessionid-and-masterkey/</link>
      <pubDate>Fri, 17 Jan 2014 02:30:00 +0000</pubDate>
      
      <guid>/questions/28989/not-able-to-decrypt-ssl-traffic-in-wireshark-using-sessionid-and-masterkey/</guid>
      <description>not able to decrypt ssl traffic in wireshark using SessionID and MasterKey  1 1Hi,
I am trying to decrypt SSL traffic in wireshark . I dont have server given private key but instead I am trying with SessionID and Master key. I have exported the key file under Edit-&amp;gt;Preferences-&amp;gt;Protocols-&amp;gt;SSL -&amp;gt; (Pre)-Master-Secret log filename option. Still Wireshark is not able to decrypt SSL traffic. Need help on this. I am using wireshark 1.</description>
    </item>
    
    <item>
      <title>UDP vs RTP [How wireshark understands if UDP packet has to be considered as RTP packet?]</title>
      <link>/questions/28990/udp-vs-rtp-how-wireshark-understands-if-udp-packet-has-to-be-considered-as-rtp-packet/</link>
      <pubDate>Fri, 17 Jan 2014 02:54:00 +0000</pubDate>
      
      <guid>/questions/28990/udp-vs-rtp-how-wireshark-understands-if-udp-packet-has-to-be-considered-as-rtp-packet/</guid>
      <description>UDP vs RTP [How wireshark understands if UDP packet has to be considered as RTP packet?]  0 How wireshark understands if UDP packet has to be considered as RTP packet? For instance... when i select &#34;Try to decode RTP outside of conversations&#34; [Edit -&amp;gt;Preferences -&amp;gt; RTP -&amp;gt; Try to decode RTP outside of conversations, only few UDP packets turn into RTP Packets.
What information [i.e. payload, version etc..] wireshark checks in UDP Packets?</description>
    </item>
    
    <item>
      <title>Ubuntu Install</title>
      <link>/questions/28993/ubuntu-install/</link>
      <pubDate>Fri, 17 Jan 2014 08:43:00 +0000</pubDate>
      
      <guid>/questions/28993/ubuntu-install/</guid>
      <description>Ubuntu Install  1 Installed as recommended and when Wireshark starts up get:
Couldn&#39;t run /usr/bin/dumpcap in child process: Permission denied
~$ lsb_release -a No LSB modules are available. Distributor ID: Ubuntu Description: Ubuntu 12.04.4 LTS Release: 12.04 Codename: preciseubuntuasked 17 Jan &#39;14, 08:43
ChiefDnd
26●1●1●4
accept rate: 0%
 edited 13 Nov &#39;15, 16:42 
Guy Harris ♦♦
17.4k●3●35●196
What does ls -l /usr/bin/dumpcap print?
(13 Nov &#39;15, 16:42) Guy Harris ♦♦</description>
    </item>
    
    <item>
      <title>VLAN capture filter with DumpCap</title>
      <link>/questions/28995/vlan-capture-filter-with-dumpcap/</link>
      <pubDate>Fri, 17 Jan 2014 08:58:00 +0000</pubDate>
      
      <guid>/questions/28995/vlan-capture-filter-with-dumpcap/</guid>
      <description>VLAN capture filter with DumpCap  0 I&#39;ve been trying to sniff a trunk running multiple VLANs with DumpCap, and would like to filter out all VLAN traffic except the VoIP VLAN, which is VLAN 11. I have tried using the filter qualifier such as -f vlan 11 or -f &#34;vlan 11&#34; or -f vlan:11 None of these permutations have worked. Anyone out there had any success with using a VLAN capture filter?</description>
    </item>
    
    <item>
      <title>Decrypt SSL traffic inside 802.1x/EAP-PEAP packets</title>
      <link>/questions/28998/decrypt-ssl-traffic-inside-8021xeap-peap-packets/</link>
      <pubDate>Fri, 17 Jan 2014 10:59:00 +0000</pubDate>
      
      <guid>/questions/28998/decrypt-ssl-traffic-inside-8021xeap-peap-packets/</guid>
      <description>Decrypt SSL traffic inside 802.1x/EAP-PEAP packets  1 Hi,
I want to decrypt SSL traffic inside 802.1x/EAP-PEAP packets. Does anyone know how I can do this? Is there a Wireshark plugin?
eap-peap 802.1xasked 17 Jan &#39;14, 10:59
Mesh
26●1●1●3
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>windows 7 problem tshark</title>
      <link>/questions/29000/windows-7-problem-tshark/</link>
      <pubDate>Fri, 17 Jan 2014 11:46:00 +0000</pubDate>
      
      <guid>/questions/29000/windows-7-problem-tshark/</guid>
      <description>windows 7 problem tshark  0 Hi
I had the current version of Wireshark1.10.2 on my laptop (Mac Os) and desktop (windows 7) I tried this script in terminal and it is working on Mac Os, but whenever I try it in Windows 7 command terminal, I get this error:
tshark: Invalid -o flag &#34;column.format:&#39;No.,%m,&#34;
Why it is working in Mac os but not in windows !!!!!
Please Help me :)</description>
    </item>
    
    <item>
      <title>Sniffing tracking pixels?</title>
      <link>/questions/29003/sniffing-tracking-pixels/</link>
      <pubDate>Fri, 17 Jan 2014 13:29:00 +0000</pubDate>
      
      <guid>/questions/29003/sniffing-tracking-pixels/</guid>
      <description>Sniffing tracking pixels?  0 Problem: I&#39;m trying to check if a tracking pixel is firing on a page. We installed third party tracking mechanism (Mediaplex) and I need to make sure it&#39;s working properly. This mechanism is just a bit of code that looks something like this:
&amp;lt;iframe src=&#34;https://secure.img-cdn.mediaplex.com/0/1236/universal.html?page_name=sitepage &amp;amp;amp;Value=PASS_VALUE &amp;amp;amp;Value1=PASS_VALUE &amp;amp;amp;mpuid=additionainfo#&#34; height=&#34;1&#34; width=&#34;1&#34; frameborder=&#34;0&#34;&amp;gt;&amp;lt;/iframe&amp;gt;This bit of code sits inside a body tag.
Question: Can Wireshark help me see if the Mediaplex tag is sending data out?</description>
    </item>
    
    <item>
      <title>Flow visualization of third parties web sites using wireshark</title>
      <link>/questions/29007/flow-visualization-of-third-parties-web-sites-using-wireshark/</link>
      <pubDate>Sat, 18 Jan 2014 06:46:00 +0000</pubDate>
      
      <guid>/questions/29007/flow-visualization-of-third-parties-web-sites-using-wireshark/</guid>
      <description>Flow visualization of third parties web sites using wireshark  0 I am currently undertaking a project on computer science using wireshark.I want to know if is possible to create a plugin that allows me visualize the third parties websites(google ads and more) ???
using wireshar viewasked 18 Jan &#39;14, 06:46
Astrokilla
6●1●1●2
accept rate: 0%
  
One Answer:
  
0 want to know if is possible to create a plugin that allows me visualize the third parties websites</description>
    </item>
    
    <item>
      <title>What are “Difference” and “Delta” in Wireshark RTP Analysis?</title>
      <link>/questions/29008/what-are-difference-and-delta-in-wireshark-rtp-analysis/</link>
      <pubDate>Sat, 18 Jan 2014 12:26:00 +0000</pubDate>
      
      <guid>/questions/29008/what-are-difference-and-delta-in-wireshark-rtp-analysis/</guid>
      <description>What are “Difference” and “Delta” in Wireshark RTP Analysis?  1 1I tried to find this in the documentation, but had no luck. I would love to dig the sources to find out, but I honestly don&#39;t have the time. I tried to google this, but either people do not get any reply (like this one or that one) or they look at the sources and the epiphany they get prevents them from sharing their newfound knowledge with the mere mortals we are (like here or there).</description>
    </item>
    
    <item>
      <title>GSM SMS Call Flow invoke forwardSM</title>
      <link>/questions/29010/gsm-sms-call-flow-invoke-forwardsm/</link>
      <pubDate>Sat, 18 Jan 2014 22:40:00 +0000</pubDate>
      
      <guid>/questions/29010/gsm-sms-call-flow-invoke-forwardsm/</guid>
      <description>GSM SMS Call Flow invoke forwardSM  0 Hi i have taken a SMS trace at STP side. I have seen 2 invoke forwardSM Packet and and check the OPCODE for both one of them have opcode 44 which is mt-forwardSM and one contain OPCODE 46 -mo-forwardSM . i want to know how this is possible in single invoke forwardSM packet.
sms - gsm flow callasked 18 Jan &#39;14, 22:40</description>
    </item>
    
    <item>
      <title>No WIreless interfaces present in the Capture Options window</title>
      <link>/questions/29011/no-wireless-interfaces-present-in-the-capture-options-window/</link>
      <pubDate>Sun, 19 Jan 2014 05:51:00 +0000</pubDate>
      
      <guid>/questions/29011/no-wireless-interfaces-present-in-the-capture-options-window/</guid>
      <description>No WIreless interfaces present in the Capture Options window  0 Hi
I am running Wireshark on the machine connected to wifi router via wire. Except for that there are 2-3 other machines in LAN present on wifi. However no wifi interface is available to capture from in the Wireshark. Anyone knows why?
Cheers
interface capture wifiasked 19 Jan &#39;14, 05:51
Jluke
1●2●2●3
accept rate: 0%
What version of what operating system is on the machine running Wireshark?</description>
    </item>
    
    <item>
      <title>Wireshark crashes while building Capture Filter</title>
      <link>/questions/29012/wireshark-crashes-while-building-capture-filter/</link>
      <pubDate>Sun, 19 Jan 2014 08:41:00 +0000</pubDate>
      
      <guid>/questions/29012/wireshark-crashes-while-building-capture-filter/</guid>
      <description>Wireshark crashes while building Capture Filter  0 Every time I try to build this Capture Filter Wireshark crashes with this error from Windows 7: The Filter is:&#34; not ether host xx.xx.xx.xx.xx.xx &#34; where the x&#39;s are my ipv6 address. The crash always happens when I reach this point: &#34;not ether host xxxx::&#34; entering the second colon. The error I get from Windows 7 64bit is:&#34;Runtime Error Program:C:\Progam Files\Wireshark\Wireshark.exe. This program has requested the Runtime to terminate in an unusual way.</description>
    </item>
    
    <item>
      <title>Wifi adapters</title>
      <link>/questions/29015/wifi-adapters/</link>
      <pubDate>Sun, 19 Jan 2014 09:28:00 +0000</pubDate>
      
      <guid>/questions/29015/wifi-adapters/</guid>
      <description>Wifi adapters  0 Will all wifi adapters, including the cheep ones work with Wireshark? I&#39;m running windows vista.
adapter wifiasked 19 Jan &#39;14, 09:28
Jluke
1●2●2●3
accept rate: 0%
  
One Answer:
  
1If you only want to capture your own traffic, then you&#39;ll probably manage OK. If you want to capture WiFi management traffic or WiFi traffic from other machines then life becomes much more difficult on Windows unfortunately.</description>
    </item>
    
    <item>
      <title>Compiled wireshark does not color the packets by default</title>
      <link>/questions/29024/compiled-wireshark-does-not-color-the-packets-by-default/</link>
      <pubDate>Sun, 19 Jan 2014 17:06:00 +0000</pubDate>
      
      <guid>/questions/29024/compiled-wireshark-does-not-color-the-packets-by-default/</guid>
      <description>Compiled wireshark does not color the packets by default  0 After compiling Wireshark on my own on Ubuntu 13.10 (x64) with following configure script :
./configure --prefix=/home/user/Downloads/wireshark-1.10.5/build_dir --with-adns --with-pcap --with-lua --with-libsmi --with-c-ares --with-portaudio --enable-setcap-install --enable-setuid-install --with-gtk3 --with-sslThe Wireshark package has been configured with the following options. Build wireshark : yes (with GTK+ 3) Build tshark : yes Build capinfos : yes Build editcap : yes Build dumpcap : yes Build mergecap : yes Build reordercap : yes Build text2pcap : yes Build randpkt : yes Build dftest : yes Build rawshark : yes Save files as pcap-ng by default : yes Install dumpcap with capabilities : yes Install dumpcap setuid : no Use dumpcap group : (none) Use plugins : yes Use Lua library : yes Use Python binding : no Build rtp_player : yes Build profile binaries : no Use pcap library : yes Use zlib library : yes Use kerberos library : yes (MIT) Use c-ares library : yes Use GNU ADNS library : no (using c-ares instead) Use SMI MIB library : yes Use GNU crypto library : yes Use SSL crypto library : yes Use IPv6 name resolution : yes Use gnutls library : yes Use POSIX capabilities library : yes Use GeoIP library : no Use nl library : noYet when installed from package manager it does color the packets by default.</description>
    </item>
    
    <item>
      <title>Question about fragmentation packets</title>
      <link>/questions/29028/question-about-fragmentation-packets/</link>
      <pubDate>Mon, 20 Jan 2014 07:25:00 +0000</pubDate>
      
      <guid>/questions/29028/question-about-fragmentation-packets/</guid>
      <description>Question about fragmentation packets  0 Hi all, I&#39;m posting to know a header structure of fragmented packets.
and don&#39;t know how can i upload image and wireshark files so link my question as the below. (it&#39;s my blog and image, wireshark includes) http://blog.daum.net/bungbung77/16781142
1~2 : fragmented packets
3~4 : fragmented packets
Header structure
1: IP/UDP/SIP (1500bytes = ip header 20bytes + payload 1480bytes)
2: IP/Data
3: IP/Data (1444bytes = ip header 20bytes + payload 1424bytes)</description>
    </item>
    
    <item>
      <title>Wireshark position in stack versus local firewall</title>
      <link>/questions/29031/wireshark-position-in-stack-versus-local-firewall/</link>
      <pubDate>Mon, 20 Jan 2014 08:54:00 +0000</pubDate>
      
      <guid>/questions/29031/wireshark-position-in-stack-versus-local-firewall/</guid>
      <description>Wireshark position in stack versus local firewall  0 On Windows2008R2, 64 bit with HP Teaming interfaces I watch the UDP requests for my application coming to the interface, but the aplication never responds although correctly configured. There is a local firewall running on the server which is controlled by ActiveDirectory profile Administrators, I cannot disable it (temporarily), I only have local admin rights. I&#39;m running Wireshark in Portable mode. The question is, if I see the datagram in Wireshark on the local machine, can I be confident it is passed up all the way the IP stack to the application ?</description>
    </item>
    
    <item>
      <title>Is it possible to run a network tap on a Port Channel?</title>
      <link>/questions/29034/is-it-possible-to-run-a-network-tap-on-a-port-channel/</link>
      <pubDate>Mon, 20 Jan 2014 11:05:00 +0000</pubDate>
      
      <guid>/questions/29034/is-it-possible-to-run-a-network-tap-on-a-port-channel/</guid>
      <description>Is it possible to run a network tap on a Port Channel?  0 Hi all,
Whilst this is not strictly Wireshark related, I wondered if anyone would know whether it would be possible to run a network tap on a single logical Port Channel comprise of multiple physical Ethernet links?
Many thanks
Chris
port_channel tapasked 20 Jan &#39;14, 11:05
swinster
26●2●2●6
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>How to change wireshark temp files&amp;#x27; directory</title>
      <link>/questions/29036/how-to-change-wireshark-temp-files-directory/</link>
      <pubDate>Mon, 20 Jan 2014 17:09:00 +0000</pubDate>
      
      <guid>/questions/29036/how-to-change-wireshark-temp-files-directory/</guid>
      <description>How to change wireshark temp files&#39; directory  0 I want to change wireshark &#34;.pcapng&#34; temp files&#39; directory, how to config or where to modify the source code?
files directory temp wiresharkasked 20 Jan &#39;14, 17:09
metamatrix
56●16●16●19
accept rate: 100%
  
One Answer:
  
1 Presumably you mean the directory in which it writes temporary capture files.
On UN*X, you can set the TMPDIR environment variable to the directory you want the temporary files (which may be difficult if you&#39;re launching it from the GUI rather than the command line); on Windows, you can set the TEMP environment variable.</description>
    </item>
    
    <item>
      <title>PACKET CAPTURE with IPSEC ENABLED</title>
      <link>/questions/29043/packet-capture-with-ipsec-enabled/</link>
      <pubDate>Mon, 20 Jan 2014 22:36:00 +0000</pubDate>
      
      <guid>/questions/29043/packet-capture-with-ipsec-enabled/</guid>
      <description>PACKET CAPTURE with IPSEC ENABLED  0 Hi, If IPSEC is enabled , can PCAP traces be captured and decoded using wireshark? Thanks
pcap ipsecasked 20 Jan &#39;14, 22:36
Surajitm
11●3●3●4
accept rate: 0%
  
One Answer:
  
0well, it depends....
.... on the OS and the way the IPSEC subsystem is integrated into the kernel. On some systems there is a virtual ipsec interface (like Linux KLIPS).</description>
    </item>
    
    <item>
      <title>Wireshark &amp;amp; Iphone</title>
      <link>/questions/29048/wireshark-iphone/</link>
      <pubDate>Tue, 21 Jan 2014 02:24:00 +0000</pubDate>
      
      <guid>/questions/29048/wireshark-iphone/</guid>
      <description>Wireshark &amp;amp; Iphone  0 Will wireshark be able to tell me what websites or apps my wife is looking at on her iphone
surveilance iphone wifeasked 21 Jan &#39;14, 02:24
James Thompson
1●1●1●1
accept rate: 0%
 edited 21 Jan &#39;14, 02:31 
Jasper ♦♦
23.8k●5●51●284
Sure, see the answer of @Jasper:
But I think your wife will be able to tell you that in much more detail and she would also be able to give you an explanation why she is doing.</description>
    </item>
    
    <item>
      <title>file save as... commview ncf file format error</title>
      <link>/questions/29061/file-save-as-commview-ncf-file-format-error/</link>
      <pubDate>Tue, 21 Jan 2014 08:54:00 +0000</pubDate>
      
      <guid>/questions/29061/file-save-as-commview-ncf-file-format-error/</guid>
      <description>file save as&amp;hellip; commview ncf file format error  0 Dear Gentlemen,
Whenever I try to save my network Wireshark captures in Commview ncf file format, Wireshark raises an error message: &#34;The capture file appears to be damaged or corrupt. (commview: unsupported encap:15)&#34;
Wireshark is version 1.10.5
The OS I&#39;m using is WIN7 X64, but I also tried the latest UBUNTU release, X64 version too, and got the same error.</description>
    </item>
    
    <item>
      <title>connection to google</title>
      <link>/questions/29062/connection-to-google/</link>
      <pubDate>Tue, 21 Jan 2014 10:01:00 +0000</pubDate>
      
      <guid>/questions/29062/connection-to-google/</guid>
      <description>connection to google  0 hi i use Firefox chrome never been installed on machine once windows starts i opened wireshark and saw tcp connection to 173.194.70.99 syn syn ack ack fin ack fin ack also in cmd ipconfig /displaydns there is already
www.google.comRecord Name . . . . . : www.google.com Record Type . . . . . : 1 Time To Live . . . . : 85 Data Length .</description>
    </item>
    
    <item>
      <title>Already logged wireshark</title>
      <link>/questions/29064/already-logged-wireshark/</link>
      <pubDate>Tue, 21 Jan 2014 10:10:00 +0000</pubDate>
      
      <guid>/questions/29064/already-logged-wireshark/</guid>
      <description>Already logged wireshark  0 It is possible to find out the password and username when entering a page already logged in?
logged wiresharkasked 21 Jan &#39;14, 10:10
odo
11●1●1●3
accept rate: 0%
  
One Answer:
  
2In general no, as the credentials will (should) be transmitted only once. The browser might store them somewhere, but that&#39;s not a problem you can analyze with Wireshark.
Regards</description>
    </item>
    
    <item>
      <title>Applying display filter on float data type values not working in 1.6.1</title>
      <link>/questions/29065/applying-display-filter-on-float-data-type-values-not-working-in-161/</link>
      <pubDate>Tue, 21 Jan 2014 10:21:00 +0000</pubDate>
      
      <guid>/questions/29065/applying-display-filter-on-float-data-type-values-not-working-in-161/</guid>
      <description>Applying display filter on float data type values not working in 1.6.1  0 I have a pcap which contains messages having data of type float. I tried applying display filter on this field, but it is not working, not able to see the messages being filtered.
Wanted to know whether Wireshark supports display filter option on float data type values. I am using Wireshark version 1.6.1.
Thanks in advance. Kiran Kumar G</description>
    </item>
    
    <item>
      <title>Follow TCP Stream troubleshooting</title>
      <link>/questions/29075/follow-tcp-stream-troubleshooting/</link>
      <pubDate>Tue, 21 Jan 2014 16:18:00 +0000</pubDate>
      
      <guid>/questions/29075/follow-tcp-stream-troubleshooting/</guid>
      <description>Follow TCP Stream troubleshooting  0 I have just installed the latest Wireshark on my Macbook Pro. I want to analyze some pcaps that were sent to me. I can open the pcap files just fine, and all looks normal on the screen. However, when I go to filter on &#39;TCP&#39; and apply the filter, nothing happens. Moreover, when I right-click on the row/packet I am interested in, nothing happens.</description>
    </item>
    
    <item>
      <title>How do you cross compile wireshark on Linux for Windows?</title>
      <link>/questions/29077/how-do-you-cross-compile-wireshark-on-linux-for-windows/</link>
      <pubDate>Tue, 21 Jan 2014 17:56:00 +0000</pubDate>
      
      <guid>/questions/29077/how-do-you-cross-compile-wireshark-on-linux-for-windows/</guid>
      <description>How do you cross compile wireshark on Linux for Windows?  0 Someone else recently asked this question, and the answer was to file a bug. Unfortunately, no link to the bug was posted, so here I am with the same question. Here is the basic info:
./configure --build=x86-pc-linux-gnu --host=i586-mingw32msvc[...]
 checking for connect in -lsocket... no configure: error: Function &amp;#39;socket&amp;#39; not found.config.log:
 configure:24681: checking for connect in -lsocket configure:24706: i586-mingw32msvc-gcc -o conftest.</description>
    </item>
    
    <item>
      <title>How do I interpret the mactime in case of aggregated data packets and block ack ?</title>
      <link>/questions/29078/how-do-i-interpret-the-mactime-in-case-of-aggregated-data-packets-and-block-ack/</link>
      <pubDate>Tue, 21 Jan 2014 18:30:00 +0000</pubDate>
      
      <guid>/questions/29078/how-do-i-interpret-the-mactime-in-case-of-aggregated-data-packets-and-block-ack/</guid>
      <description>How do I interpret the mactime in case of aggregated data packets and block ack ?  0 In the sample capture output below following are my questions: 1) Packet #1 to #16 belong to same AMPDU but why does !16 have different mactime ? 2) The mactime increases from data pkt #16 to Ack #17, but after that decreases for the subsequent data pkt#18.
I have added the mactime delta column after calculation for reference.</description>
    </item>
    
    <item>
      <title>Wireshark Trademark Use on Research/Personal Website</title>
      <link>/questions/29080/wireshark-trademark-use-on-researchpersonal-website/</link>
      <pubDate>Tue, 21 Jan 2014 20:11:00 +0000</pubDate>
      
      <guid>/questions/29080/wireshark-trademark-use-on-researchpersonal-website/</guid>
      <description>Wireshark Trademark Use on Research/Personal Website  1 Good Day,
I&#39;m working on a school project that is being displayed on a public website. I would like to display the Wireshark logo on a section regarding my research. I&#39;ve been trying to locate the Wireshark Trademark policy/rules to ensure that I abide by them, however I have been unable to locate anything.
I found this post: http://ask.wireshark.org/questions/28795/is-it-allowed-to-have-wireshark-screenshots-on-the-company-homepage
It does state that if the logo is in a screenshot to ensure to give credit to wireshark.</description>
    </item>
    
    <item>
      <title>Wireshark not launching in Win 8.1 OS</title>
      <link>/questions/29081/wireshark-not-launching-in-win-81-os/</link>
      <pubDate>Wed, 22 Jan 2014 00:30:00 +0000</pubDate>
      
      <guid>/questions/29081/wireshark-not-launching-in-win-81-os/</guid>
      <description>Wireshark not launching in Win 8.1 OS  0 Wireshark (Wireshark-win64-1.10.1) &amp;amp; Wincap 4.1.3 installed succesfully, but not getting launched. Getting hanged while loading configuration files for wireshark at 100%.
wiresharkasked 22 Jan &#39;14, 00:30
DIGSI
11●1●1●2
accept rate: 0%
AV, VPN software?
(22 Jan &#39;14, 02:40) grahamb ♦  
One Answer:
  
0That seems to be a yet unresolved problem.
See here: http://ask.wireshark.org/questions/26361/loading-configuration-files
Regards
Kurt
answered 22 Jan &#39;14, 01:17</description>
    </item>
    
    <item>
      <title>Cannot capture network latency of HTTP request.</title>
      <link>/questions/29084/cannot-capture-network-latency-of-http-request/</link>
      <pubDate>Wed, 22 Jan 2014 01:49:00 +0000</pubDate>
      
      <guid>/questions/29084/cannot-capture-network-latency-of-http-request/</guid>
      <description>Cannot capture network latency of HTTP request.  0 Hi,
I&#39;m trying to capture the latency of a simple HTTP request over the network (internet). I&#39;ve tried delta, delta conversion, relative time etc. ... Nothing seems to give me the RTT (round trip time) over the network.
I used a simple HTTP request with screenshot of Google chrome with debugger. See Also see screenshot of Wireshark capture Thanks, Kapil
latency networkasked 22 Jan &#39;14, 01:49</description>
    </item>
    
    <item>
      <title>Link error on Windows 7 32 bits</title>
      <link>/questions/29085/link-error-on-windows-7-32-bits/</link>
      <pubDate>Wed, 22 Jan 2014 01:54:00 +0000</pubDate>
      
      <guid>/questions/29085/link-error-on-windows-7-32-bits/</guid>
      <description>Link error on Windows 7 32 bits  0 Hi all, the link error happened on Win 7, 32 bits as following...
Linking libwireshark.dll link /INCREMENTAL:NO /NOLOGO -entry:[email protected] -dll kernel32.lib ws2_32.lib mswsock.lib advapi32.lib shell32.lib psapi.lib /DEBUG /MACHINE:x86 /SafeSEH /DYNAMICBASE /FIXED:no /OUT:libwireshark.dll /IMPLIB:libwireshark.lib addr_and_mask.obj addr_resolv.obj address_to_str.obj afn.obj aftypes.obj app_mem_usage.obj asn1.obj atalk-utils.obj charsets.obj circuit.obj column.obj column-utils.obj conversation.obj crc16-tvb.obj crc32-tvb.obj crc8-tvb.obj decode_as.obj disabled_protos.obj dissector_filters.obj dvb_chartbl.obj dwarf.obj emem.obj epan.obj ex-opt.obj except.obj expert.obj exported_pdu.obj filter_expressions.</description>
    </item>
    
    <item>
      <title>Server stops reading TCP stream after it sends a TCP Window update</title>
      <link>/questions/29095/server-stops-reading-tcp-stream-after-it-sends-a-tcp-window-update/</link>
      <pubDate>Wed, 22 Jan 2014 07:16:00 +0000</pubDate>
      
      <guid>/questions/29095/server-stops-reading-tcp-stream-after-it-sends-a-tcp-window-update/</guid>
      <description>Server stops reading TCP stream after it sends a TCP Window update  0 Hello all,
we have very strange behaviour with our web application. When certain clients do a HTTP POST request to our JBOSS 4.2 application server (running behind an apache), they sometimes(!) never get a reply from the server. In all these cases, the wireshark dumpfile shows that a TCP Window Update is sent from server to client while the client sends the POST data.</description>
    </item>
    
    <item>
      <title>Can you specify the MAC manufacturer in an output field ?</title>
      <link>/questions/29099/can-you-specify-the-mac-manufacturer-in-an-output-field/</link>
      <pubDate>Wed, 22 Jan 2014 08:21:00 +0000</pubDate>
      
      <guid>/questions/29099/can-you-specify-the-mac-manufacturer-in-an-output-field/</guid>
      <description>Can you specify the MAC manufacturer in an output field ?  0 I&#39;m outputting MAC addresses and other fields using the -T option:
-T fields -e wlan.sa
that works fine, but in addition I&#39;d like the manufacturer information e.g.
e0:f5:c6:12:34 Intel
manuf mac-addressasked 22 Jan &#39;14, 08:21
mikerr
11●1●1●3
accept rate: 0%
  
One Answer:
  
1Try the field name wlan.sa_resolved. You might also need to enable MAC name resolution with a -N m.</description>
    </item>
    
    <item>
      <title>Single RPM instead of wireshark &amp;amp; wireshark-gnome?</title>
      <link>/questions/29102/single-rpm-instead-of-wireshark-wireshark-gnome/</link>
      <pubDate>Wed, 22 Jan 2014 10:41:00 +0000</pubDate>
      
      <guid>/questions/29102/single-rpm-instead-of-wireshark-wireshark-gnome/</guid>
      <description>Single RPM instead of wireshark &amp;amp; wireshark-gnome?  0 Hi all,
I am building from the 1.10 branch for the first time and noticed that the included spec file in this release generates two RPMs like Red Hat normally does with their OS&#39; releases for Wireshark.
I&#39;m looking to have a single RPM for ease of installations. The last time I built an RPM was from 1.8.x and it still had a single RPM.</description>
    </item>
    
    <item>
      <title>Different .so dependencies between normal build and RPM</title>
      <link>/questions/29106/different-so-dependencies-between-normal-build-and-rpm/</link>
      <pubDate>Wed, 22 Jan 2014 12:05:00 +0000</pubDate>
      
      <guid>/questions/29106/different-so-dependencies-between-normal-build-and-rpm/</guid>
      <description>Different .so dependencies between normal build and RPM  0 With 1.10.x, I&#39;m able to build the two RPMs, but when installing, there&#39;s a dependency for libwiretap.so.2 and libwsutil.so.2, even though the build directory contains only the .so.3 varieties. The RPM won&#39;t install without these. If I force the install and do an &#34;ldd wireshark&#34; on the executable, it claims to need both the .so.3 and the .so.2 varieties
When I do a &#34;</description>
    </item>
    
    <item>
      <title>./configure options passed to rpm-package target?</title>
      <link>/questions/29111/configure-options-passed-to-rpm-package-target/</link>
      <pubDate>Wed, 22 Jan 2014 13:05:00 +0000</pubDate>
      
      <guid>/questions/29111/configure-options-passed-to-rpm-package-target/</guid>
      <description>./configure options passed to rpm-package target?  0 I just noticed that the RPM spec file has its own set of ./configure options. This made me question whether support for different options that I run prior to running &#34;make&#34; and &#34;make rpm-package&#34; aren&#39;t being passed to the RPM build process.
I tried to add the same &#34;--with-XXXX&#34; options to the file in its ./configure section manually, but the build process ended prematurely because it said the options were not recognized options.</description>
    </item>
    
    <item>
      <title>tshark: parsing CM Service Request packets</title>
      <link>/questions/29114/tshark-parsing-cm-service-request-packets/</link>
      <pubDate>Wed, 22 Jan 2014 15:56:00 +0000</pubDate>
      
      <guid>/questions/29114/tshark-parsing-cm-service-request-packets/</guid>
      <description>tshark: parsing CM Service Request packets  0 I am using tshark to parse capture files of GSM sessions. For particular CM Service Request packets, I wish to determine and output the CM Service Type. I can currently parse Mobility Management messages by filtering with &#34;gsm_a.dtap_msg_mm_type == 0x24&#34; and get all the CM Service Request packets. However, I have not been able to figure out how to output the specific CM Service type for such packets.</description>
    </item>
    
    <item>
      <title>wireshark crashes when saving RTP packets</title>
      <link>/questions/29115/wireshark-crashes-when-saving-rtp-packets/</link>
      <pubDate>Thu, 23 Jan 2014 03:24:00 +0000</pubDate>
      
      <guid>/questions/29115/wireshark-crashes-when-saving-rtp-packets/</guid>
      <description>wireshark crashes when saving RTP packets  0 I am transmitting video via vlc to the client-pc. in paralel, im capture the rtp packets.
but when I want to save the pcap file, wireshark crashes.
the stream is about 30 seconds.
if someone knows what am I doing wrong, I will be happy for some guidness.
thanks!
wireshark_crashed crash videostream video rtpasked 23 Jan &#39;14, 03:24
dr seuss
1●2●2●3
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to handle a big trace file?</title>
      <link>/questions/29121/how-to-handle-a-big-trace-file/</link>
      <pubDate>Thu, 23 Jan 2014 06:51:00 +0000</pubDate>
      
      <guid>/questions/29121/how-to-handle-a-big-trace-file/</guid>
      <description>How to handle a big trace file?  0 Hi experts,
I know that open a big trace file by wireshark will be slower than opening a relatively small trace file. How would you deal with it generally? Is there any better way to do this?
thanks a lot!
big_trace_fileasked 23 Jan &#39;14, 06:51
SteveZhou
191●27●30●34
accept rate: 0%
  
2 Answers:
  
0 There are two ways</description>
    </item>
    
    <item>
      <title>User Guide for 1.2.15</title>
      <link>/questions/29125/user-guide-for-1215/</link>
      <pubDate>Thu, 23 Jan 2014 11:45:00 +0000</pubDate>
      
      <guid>/questions/29125/user-guide-for-1215/</guid>
      <description>User Guide for 1.2.15  0 Where can I find the user guide (preferably pdf) for version 1.2.15, which is the version installed by yum for CentOS 6.
manual guideasked 23 Jan &#39;14, 11:45
khoranyi
11●1●1●2
accept rate: 0%
  
3 Answers:
  
0There are the man pages, e.g. man wireshark, the html version of the man page, /usr/share/wireshark/wireshark.html and the text help files in /usr/share/wireshark/help.</description>
    </item>
    
    <item>
      <title>DDS - pcap or pcapng</title>
      <link>/questions/29128/dds-pcap-or-pcapng/</link>
      <pubDate>Thu, 23 Jan 2014 13:15:00 +0000</pubDate>
      
      <guid>/questions/29128/dds-pcap-or-pcapng/</guid>
      <description>DDS - pcap or pcapng  0 Hello, I am trying to get a handle on DDS, Are the wireshark versions that are out the built on 1.8 and greater where they capture pcapng. Or are they still on pcap. Doest the expanded metadata of pcapng lend itself to the DDS data like ID, Topic, Type and maybe QOS? - thanks
dds capturesasked 23 Jan &#39;14, 13:15
lostokie
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>STP - source mac</title>
      <link>/questions/29133/stp-source-mac/</link>
      <pubDate>Thu, 23 Jan 2014 21:07:00 +0000</pubDate>
      
      <guid>/questions/29133/stp-source-mac/</guid>
      <description>STP - source mac  0 Sir,
I must Thank to Wireshark team ,For Developing Such a Master Class tool &#34;the wireshark&#34;
Query:
i am Capturing STP (spanning tree) traffic and Surprised about why source mac is Unique not exist In My Network Where Destination and Root bridge mac is Known 2,i capture on another switch this time another Source mac address is not exist on my device neither switch...whosse mac is this</description>
    </item>
    
    <item>
      <title>Decode IuB Trace</title>
      <link>/questions/29135/decode-iub-trace/</link>
      <pubDate>Fri, 24 Jan 2014 03:09:00 +0000</pubDate>
      
      <guid>/questions/29135/decode-iub-trace/</guid>
      <description>Decode IuB Trace  0 Hi,
In the given trace present at pcapr, I was able to decode nbap, but most of the FP/MAC/RLC packets are throwing exceptions. Is it possible to see the RRC packets with any particular settings??
http://www.pcapr.net/view/nos/2011/3/1/13/iub_over_udp_nbap_and_rrc.html
Regards, Vineeth
mac iub rrc rlcasked 24 Jan &#39;14, 03:09
Vineeth
1●1●1●1
accept rate: 0%
  
One Answer:
  
0FP/MAC/RLC are automatically dissected. But beware that UMTS security design is not allowing to see Iub messages after cyphering (i.</description>
    </item>
    
    <item>
      <title>Why is the advertsed MSS 1340 when the configured value is 1380?</title>
      <link>/questions/29146/why-is-the-advertsed-mss-1340-when-the-configured-value-is-1380/</link>
      <pubDate>Fri, 24 Jan 2014 15:10:00 +0000</pubDate>
      
      <guid>/questions/29146/why-is-the-advertsed-mss-1340-when-the-configured-value-is-1380/</guid>
      <description>Why is the advertsed MSS 1340 when the configured value is 1380?  0 During the course of a prolonged mail server performance issue we determined that we needed to make sure the mail server was sending smaller packets to get the best performance. We manually reduced the MSS setting on the server to 1380 but I am seeing in the 3 way handshake that the server is advertising MSS = 1340.</description>
    </item>
    
    <item>
      <title>How to scan network?</title>
      <link>/questions/29150/how-to-scan-network/</link>
      <pubDate>Sat, 25 Jan 2014 07:22:00 +0000</pubDate>
      
      <guid>/questions/29150/how-to-scan-network/</guid>
      <description>How to scan network?  0 Hello
I have a problem. I have to scan whole network with 30 computer in our company. I was searching for some guides, but all i could find was &#34;how to hack password&#34;. I dont want that, i just want to get infromation about : - what sides are visited - is there any attack on our network (hackers, malware etc.) I dont want to block our workers or something i just want to know what sites are they visiting.</description>
    </item>
    
    <item>
      <title>smb2.time calculation</title>
      <link>/questions/29153/smb2time-calculation/</link>
      <pubDate>Sat, 25 Jan 2014 11:30:00 +0000</pubDate>
      
      <guid>/questions/29153/smb2time-calculation/</guid>
      <description>smb2.time calculation  0 Hi!
I am calculating response time of server to check the performance of the smb2. After working with some manual method i found that now smb2.time can be used to determing the response time.
can anyone about it?
Thanks
smb2.time calculationasked 25 Jan &#39;14, 11:30
Capricorn
1●1●1●2
accept rate: 0%
 edited 25 Jan &#39;14, 16:34 
Hi guys!
Can anyone help with this.
thanks
(28 Jan &#39;14, 11:40) CapricornThere are some answers.</description>
    </item>
    
    <item>
      <title>number of selected row</title>
      <link>/questions/29155/number-of-selected-row/</link>
      <pubDate>Sat, 25 Jan 2014 12:29:00 +0000</pubDate>
      
      <guid>/questions/29155/number-of-selected-row/</guid>
      <description>number of selected row  0 Hi. In my results, how can I see the number of the selected row? (the first row being #1, second #2, etc)
number rowasked 25 Jan &#39;14, 12:29
myrddin
11●7●8●10
accept rate: 0%
What exactly do you mean by rows? Database rows, or packet rows? The total number of packets (= rows) can be seen in the status bar.
(25 Jan &#39;14, 12:32) Jasper ♦♦Yes, I meant packet rows, sorry.</description>
    </item>
    
    <item>
      <title>How do I get bluetooth interface accepted</title>
      <link>/questions/29161/how-do-i-get-bluetooth-interface-accepted/</link>
      <pubDate>Sat, 25 Jan 2014 19:27:00 +0000</pubDate>
      
      <guid>/questions/29161/how-do-i-get-bluetooth-interface-accepted/</guid>
      <description>How do I get bluetooth interface accepted  0 How can I get my bluetooth interface accepted by Wireshark?
Get an error message, which I have googled on the internet and searched here in Wireshark.
The capture session could not be initiated (Can&#39;t attach to device 0 22:Invalid argument).
Please check to make sure you have sufficient permissions, and that you have the proper interface or pipe specified.
Running su root at present in PCLinuxOS Mate 64 bit.</description>
    </item>
    
    <item>
      <title>Constant UDP Traffic</title>
      <link>/questions/29164/constant-udp-traffic/</link>
      <pubDate>Sun, 26 Jan 2014 05:46:00 +0000</pubDate>
      
      <guid>/questions/29164/constant-udp-traffic/</guid>
      <description>Constant UDP Traffic  0 1/3 of my captured Packets are UDP packets from the same IP in my Network. Always 72 length and the info is always &#34;Source Port: 58869 Destination port: 8009&#34; The UDP stream consists of
&amp;quot;Big-D-PC|11112|172.16.12.154|2Big-D-PC|11112|172.16.12.154|2Big-D-PC|11112|172.16.12.154|2Big-D-PC|11112|172.16.12.154|2Big-D-PC|11112|172.16.12.154|2Big-D-PC|11112|172.16.12.154|2Big-D-PC|11112|172.16.12.154|2Big-D-PC|11112|172.16.12.154&amp;quot; for the entire conversation. I cringe at the name yes, but what traffic is it? It doesn&#39;t seem to end.I might add the source is a computer name I guess &#34;</description>
    </item>
    
    <item>
      <title>Legal to monitor others internet traffic through router</title>
      <link>/questions/29171/legal-to-monitor-others-internet-traffic-through-router/</link>
      <pubDate>Sun, 26 Jan 2014 14:35:00 +0000</pubDate>
      
      <guid>/questions/29171/legal-to-monitor-others-internet-traffic-through-router/</guid>
      <description>Legal to monitor others internet traffic through router  0 is it legal to monitor internet traffic of what others are browsing through home router using software like wireshark?
monitorasked 26 Jan &#39;14, 14:35
blueknight
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Well, obviously that depends on the laws in your country. Why don&#39;t you go to your local police office and ask them? They will know what to do.</description>
    </item>
    
    <item>
      <title>Follow TCP Stream</title>
      <link>/questions/29173/follow-tcp-stream/</link>
      <pubDate>Sun, 26 Jan 2014 22:00:00 +0000</pubDate>
      
      <guid>/questions/29173/follow-tcp-stream/</guid>
      <description>Follow TCP Stream  0 I want to use Wireshark to capture the TCP Packets. I read about the tcpflow command. Is there any way I can use Follow TCP Stream using command line? I am using windows 7
follow.tcp.streamasked 26 Jan &#39;14, 22:00
prakharmohan
11●1●1●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>OS X tens of BPF devices</title>
      <link>/questions/29174/os-x-tens-of-bpf-devices/</link>
      <pubDate>Mon, 27 Jan 2014 01:56:00 +0000</pubDate>
      
      <guid>/questions/29174/os-x-tens-of-bpf-devices/</guid>
      <description>OS X tens of BPF devices  0 My network pref started to be really slow, so I started poking around.
I found over hundred /dev/pty and /dev/tty files, each. There is also 30 /dev/bpf* files, most of them don&#39;t have rw permission for the group. Seems like chmodBPF is not working anymore, although it&#39;s still in the startup items folder (/Library/StartupItems).
Questions:
does anyone has the network pref freeezing for up to 20s every time you change location (or anything, for that matter, not necessarily the location)?</description>
    </item>
    
    <item>
      <title>Sniffing on 60GHz band</title>
      <link>/questions/29178/sniffing-on-60ghz-band/</link>
      <pubDate>Mon, 27 Jan 2014 05:01:00 +0000</pubDate>
      
      <guid>/questions/29178/sniffing-on-60ghz-band/</guid>
      <description>Sniffing on 60GHz band  0 Is 802.11ad supported in Wireshark? If not, when this feature will be available? Thank you.
802.11adasked 27 Jan &#39;14, 05:01
alexf
11●1●1●2
accept rate: 0%
  
3 Answers:
  
1Wireshark does not access the hardware directly, it&#39;s the capturing library it is using (libpcap or WinPcap), together with certain OS kernel APIs. So, it&#39;s not a question when Wireshark supports 802.</description>
    </item>
    
    <item>
      <title>Malware Analysis In Wireshark help</title>
      <link>/questions/29181/malware-analysis-in-wireshark-help/</link>
      <pubDate>Mon, 27 Jan 2014 07:18:00 +0000</pubDate>
      
      <guid>/questions/29181/malware-analysis-in-wireshark-help/</guid>
      <description>Malware Analysis In Wireshark help  0 Hello ,
I searched on the internet tutorials, on how to analyze and detect the virus on the network using Wireshark . I installed Win7 VM, began to catch packets and then activated malware. After 30 seconds, in the wireshark begin to appear a lot of the packages with informations like
122 ... Standard query 0xd235 A pjplrhpfdeivctxokvxwozcyo.info 123 ... Standard query response 0xd235 No such name .</description>
    </item>
    
    <item>
      <title>How can i do this?</title>
      <link>/questions/29182/how-can-i-do-this/</link>
      <pubDate>Mon, 27 Jan 2014 08:01:00 +0000</pubDate>
      
      <guid>/questions/29182/how-can-i-do-this/</guid>
      <description>How can i do this?  0 How do i connect wireshark to a router, so that i can view the packets that are flowing through the router? Maybe if there is something like this: dst host xxx.xxx.xxx.xxx . Am I on the right way?
routerasked 27 Jan &#39;14, 08:01
Beginer
1●5●5●6
accept rate: 0%
  
One Answer:
  
0You can&#39;t &#34;connect&#34; Wireshark to a router. You can only capture packets on a system that Wireshark runs on, or open a capture file that was already saved to disk by TCPdump or similar tools.</description>
    </item>
    
    <item>
      <title>Network keeps losing connection to internet.</title>
      <link>/questions/29200/network-keeps-losing-connection-to-internet/</link>
      <pubDate>Mon, 27 Jan 2014 09:22:00 +0000</pubDate>
      
      <guid>/questions/29200/network-keeps-losing-connection-to-internet/</guid>
      <description>Network keeps losing connection to internet.  0 Hello,
I&#39;m new to using Wireshark. My issue is that the connection to the internet continues to drop. I have called Comcast and they tell me that all is good on there end. I have begun to capture packets from behind my Comcast modem using a Dualcom port mirroring switch and I&#39;m able to capture that packets. Can someone please offer any advice or suggestions on how to filter my capture to troubleshoot/find the issue?</description>
    </item>
    
    <item>
      <title>Protocol Buffer Wireshark Plugin</title>
      <link>/questions/29203/protocol-buffer-wireshark-plugin/</link>
      <pubDate>Mon, 27 Jan 2014 11:51:00 +0000</pubDate>
      
      <guid>/questions/29203/protocol-buffer-wireshark-plugin/</guid>
      <description>Protocol Buffer Wireshark Plugin  0 1I am looking for a wireshark plugin for google protocol buffer. And I found this GPB Wireshark plugin (http://code.google.com/p/protobuf-wireshark/)
Apparently only UDP….Is there a GPB plugin for wireshark that works for TCP?
buffer protocol wireshark google pluginasked 27 Jan &#39;14, 11:51
user12321
6●1●2●3
accept rate: 0%
 edited 27 Jan &#39;14, 11:53 
  
One Answer:
  
0 The URL you found, hosts pretty much the only (well) known Protobuf dissector.</description>
    </item>
    
    <item>
      <title>Is there a way to make wireshark profile portable?</title>
      <link>/questions/29208/is-there-a-way-to-make-wireshark-profile-portable/</link>
      <pubDate>Mon, 27 Jan 2014 17:23:00 +0000</pubDate>
      
      <guid>/questions/29208/is-there-a-way-to-make-wireshark-profile-portable/</guid>
      <description>Is there a way to make wireshark profile portable?  0 Hi,
I have several computers running wireshark, currently I have to configure each of them with the same profile, especially for the column configuration, which is really laborious.
Is there a way to make the profile portable so that I can just do copy paste from one computer to another.
thanks!
profileasked 27 Jan &#39;14, 17:23
SteveZhou
191●27●30●34
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How can wireshark capture local host traffic on Windows?</title>
      <link>/questions/29211/how-can-wireshark-capture-local-host-traffic-on-windows/</link>
      <pubDate>Mon, 27 Jan 2014 19:54:00 +0000</pubDate>
      
      <guid>/questions/29211/how-can-wireshark-capture-local-host-traffic-on-windows/</guid>
      <description>How can wireshark capture local host traffic on Windows?  1 1I&#39;m using Visual Basic 2010 for client/server authentication. I want the information that is transferred during that time between client and server. Is it possible that Wireshark is able to display it?
windows localhost wiresharkThis question is marked &#34;community wiki&#34;.asked 27 Jan &#39;14, 19:54
vikramd
11●1●2●3
accept rate: 0%
 edited 29 Jan &#39;14, 08:21 
cmaynard ♦♦
9.4k●10●38●142</description>
    </item>
    
    <item>
      <title>I can&amp;#x27;t read camel pcap file correctly on 1.10.5</title>
      <link>/questions/29214/i-cant-read-camel-pcap-file-correctly-on-1105/</link>
      <pubDate>Mon, 27 Jan 2014 23:14:00 +0000</pubDate>
      
      <guid>/questions/29214/i-cant-read-camel-pcap-file-correctly-on-1105/</guid>
      <description>I can&amp;rsquo;t read camel pcap file correctly on 1.10.5  0 Hi,
I can&#39;t read all the param of InitalDP, can you help what are the SSns need to set in the Edit-&amp;gt; preference ?
I tried with CAMEL-&amp;gt;TCAP SSN as 129-254 or INAP-&amp;gt;TCAP SSN as 6-252, but still some reading issues...
Plz help
Thanks,
1.10.5 camelasked 27 Jan &#39;14, 23:14
Hanosh
16●5●5●9
accept rate: 0%
 edited 31 Jan &#39;14, 03:19</description>
    </item>
    
    <item>
      <title>Why are Duplicate TCP Acks being seen in wireshark capture?</title>
      <link>/questions/29216/why-are-duplicate-tcp-acks-being-seen-in-wireshark-capture/</link>
      <pubDate>Mon, 27 Jan 2014 23:26:00 +0000</pubDate>
      
      <guid>/questions/29216/why-are-duplicate-tcp-acks-being-seen-in-wireshark-capture/</guid>
      <description>Why are Duplicate TCP Acks being seen in wireshark capture?  0 I am doing an FTP of a file, the server where the file is placed is being accessed using an LTE dongle. While the while is being transferred I am seeing some duplicate ACKs, from what I have read about duplicate ACKs, I gathered that duplicate ACKs are sent for fast retransmission if some packet gets lost. But in my case I also see the sequence number for which duplicate ACKs are sent is received correctly, what could be the reason for duplicate ACKs then?</description>
    </item>
    
    <item>
      <title>Multicast works when wireshark starts</title>
      <link>/questions/29224/multicast-works-when-wireshark-starts/</link>
      <pubDate>Tue, 28 Jan 2014 01:56:00 +0000</pubDate>
      
      <guid>/questions/29224/multicast-works-when-wireshark-starts/</guid>
      <description>Multicast works when wireshark starts  0 Hello all,
I have a strange behavior in my lab. I have configure an application server to receive a multicast stream from a camera, but nothing is received. So I started wireshark and magically I received the multicast stream. If I stopped wireshark, I do not receive the stream Multicast.
It seems that when wireshark listens to the server NIC, this wake up the nic and allow to receive the multicasts.</description>
    </item>
    
    <item>
      <title>tvb_composite problem</title>
      <link>/questions/29239/tvb_composite-problem/</link>
      <pubDate>Tue, 28 Jan 2014 07:45:00 +0000</pubDate>
      
      <guid>/questions/29239/tvb_composite-problem/</guid>
      <description>tvb_composite problem  0 Hello,
I have the following problem. My dissector needs to rebuild a new tvb. A better description would be, I need to cut out some data and send it to the next dissector.
As Example....
02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 11 11 11 11 11 11 22 22 22 22 22 22 33 33 44 44 I 10 01 00 00 00 aa c2 bc cd ef ed fe 15 18 1d d2 44 44 44 44 44 44 44 44 44 44 44 44 44 44 44 44 II 10 01 00 00 00 aa c2 bc cd ef ed fe 15 18 1d d3 .</description>
    </item>
    
    <item>
      <title>How to silent a network adapter?</title>
      <link>/questions/29263/how-to-silent-a-network-adapter/</link>
      <pubDate>Wed, 29 Jan 2014 00:34:00 +0000</pubDate>
      
      <guid>/questions/29263/how-to-silent-a-network-adapter/</guid>
      <description>How to silent a network adapter?  0 Hello all,
I am using Wireshark on WIN7-64bit. The goal is to spy an Ethernet Powerlink network from my computer. I would then like my network adapter to spy silently. (Powerlink is time triggered and does not like packets transmitted asynchronously by my computer).
I am not a Win7 expert and do not know how to have my network adapter &#34;listen only&#34;.</description>
    </item>
    
    <item>
      <title>10 gig capture dumpcap</title>
      <link>/questions/29265/10-gig-capture-dumpcap/</link>
      <pubDate>Wed, 29 Jan 2014 02:23:00 +0000</pubDate>
      
      <guid>/questions/29265/10-gig-capture-dumpcap/</guid>
      <description>10 gig capture dumpcap  0 We are capturing 10 gig traffic with Dumpcap (the NiC being 10 Gig), is it possible to know if dumpcap is dropping packets while capturing. We are analyzing the saved captures, is there a way to know the statistics of packets dropped by the tool and not by the network (Nic, switch, wire etc) i.e testing the tools capabilities of capturing 10 Gig
gig 10 packets dumpcapasked 29 Jan &#39;14, 02:23</description>
    </item>
    
    <item>
      <title>Regarding the Decrypt Capture File Problem</title>
      <link>/questions/29271/regarding-the-decrypt-capture-file-problem/</link>
      <pubDate>Wed, 29 Jan 2014 08:29:00 +0000</pubDate>
      
      <guid>/questions/29271/regarding-the-decrypt-capture-file-problem/</guid>
      <description>Regarding the Decrypt Capture File Problem  0 Hello Everybody,
I captured some ICMP of 802.11 packets via the AirPcap, and I want to decode and display it from 802.11 to ICMP. I trial this method(http://wiki.wireshark.org/HowToDecrypt802.11), and go to generate Raw PSK(http://www.wireshark.org/tools/wpa-psk.html), put it into Edit -&amp;gt; Preferences -&amp;gt; Protocol -&amp;gt; IEEE 802.11. But the content still do not change. I also referenced this blog(http://www.lovemytool.com/blog/2010/05/wireshark-and-tshark-decrypt-sample-capture-file-by-joke-snelders.html#comment-6a00e008d95770883401a5115e361a970c), but the outcome is the same.</description>
    </item>
    
    <item>
      <title>Help needed to debug a TCP session</title>
      <link>/questions/29274/help-needed-to-debug-a-tcp-session/</link>
      <pubDate>Wed, 29 Jan 2014 09:16:00 +0000</pubDate>
      
      <guid>/questions/29274/help-needed-to-debug-a-tcp-session/</guid>
      <description>Help needed to debug a TCP session  0 Hi
I need some help to debug a simple TCP flow between a client and a server that I have recorded using Wireshark please. How should I post that flow here?
Meanwhile, here is an attempt to show it:
 -&amp;gt; SYN &amp;lt;- SYN, ACK -&amp;gt; ACK -&amp;gt; PSH, ACK Seq=1 Ack=1 -&amp;gt; PSH, ACK Seq=13 Ack=1 -&amp;gt; PSH, ACK Seq=1473 Ack=1 &amp;lt;- ACK Seq=1 Ack=13 -&amp;gt; TCP Retransmission PSH, ACK Seq=13, Ack=1 -&amp;gt; TCP Retransmission PSH, ACK Seq=13, Ack=1 -&amp;gt; TCP Retransmission PSH, ACK Seq=13, Ack=1 &amp;lt;- FIN, ACK Seq=1, Ack=13 -&amp;gt; ACK Seq=549, Ack=2 &amp;lt;snip&amp;gt;I understand the &#39;3-way handshake&#39;.</description>
    </item>
    
    <item>
      <title>How do I apply a capture filter to a file?</title>
      <link>/questions/29279/how-do-i-apply-a-capture-filter-to-a-file/</link>
      <pubDate>Wed, 29 Jan 2014 11:32:00 +0000</pubDate>
      
      <guid>/questions/29279/how-do-i-apply-a-capture-filter-to-a-file/</guid>
      <description>How do I apply a capture filter to a file?  0 Can I apply a capture filter to a file I&#39;ve already saved? Whenever I try this with tshark, I get this:
C:\ws_data&amp;gt;tshark -f &amp;quot;ip host 192.168.0.2&amp;quot; -r input_data.pcap -w output_data.pcap tshark: Only read filters, not capture filters, can be specified when reading a capture file.I&#39;m using TShark 1.8.12-custom-win64 (SVN Rev 53127 from /trunk-1.8). Is there another tool that will do what I want, or do I need to learn how to write an equivalent read filter for my capture filter?</description>
    </item>
    
    <item>
      <title>HTTP Negotiate SPNEGO GSS-API and ASN.1 length encoding</title>
      <link>/questions/29285/http-negotiate-spnego-gss-api-and-asn1-length-encoding/</link>
      <pubDate>Wed, 29 Jan 2014 12:28:00 +0000</pubDate>
      
      <guid>/questions/29285/http-negotiate-spnego-gss-api-and-asn1-length-encoding/</guid>
      <description>HTTP Negotiate SPNEGO GSS-API and ASN.1 length encoding  0 Hi,
Wireshark does not seem to decode the SPNEGO GSS-API tokens correctly when they don&#39;t contain the 0x81 or 0x82 length designator in the ASN.1 DER lengths. If the lengths don&#39;t have the upper bit set - which means it&#39;s just a byte of length than it isn&#39;t decoded.
spnego http gss-apiThis question is marked &#34;community wiki&#34;.asked 29 Jan &#39;14, 12:28</description>
    </item>
    
    <item>
      <title>interface Linkspeed</title>
      <link>/questions/29288/interface-linkspeed/</link>
      <pubDate>Wed, 29 Jan 2014 12:47:00 +0000</pubDate>
      
      <guid>/questions/29288/interface-linkspeed/</guid>
      <description>interface Linkspeed  0 Hi, we have an HP G6 DL380 running window7 SP1, we have the Intel X520D-2 (10GIG NIC) installed, the OS &amp;amp; router both indicated link speed 10g full duplex, but the wireshark interface detail stated it&#39;s only a 1410mbps link speed. we are using wireshark version 1.11.2 Rev 53411 (64 bits) ; WinPcap 4.1.3
any suggestion ??
Thanks in advance Anh
interface speed linkThis question is marked &#34;</description>
    </item>
    
    <item>
      <title>How to get IP level logs from agilent test set E703E version using wireshark tool? please share the setup required for this?</title>
      <link>/questions/29296/how-to-get-ip-level-logs-from-agilent-test-set-e703e-version-using-wireshark-tool-please-share-the-setup-required-for-this/</link>
      <pubDate>Thu, 30 Jan 2014 01:12:00 +0000</pubDate>
      
      <guid>/questions/29296/how-to-get-ip-level-logs-from-agilent-test-set-e703e-version-using-wireshark-tool-please-share-the-setup-required-for-this/</guid>
      <description>How to get IP level logs from agilent test set E703E version using wireshark tool? please share the setup required for this?  0 My test phone is connected via RF cable to agilent test set. wireshark is installed in another PC. agilent test set has one LAN port and one DATA port. how to make a setup where I can trace my test phone IP level information using wireshark?</description>
    </item>
    
    <item>
      <title>Capturing traffic from Loopback adapter on Windows 7 64 bit</title>
      <link>/questions/29298/capturing-traffic-from-loopback-adapter-on-windows-7-64-bit/</link>
      <pubDate>Thu, 30 Jan 2014 02:25:00 +0000</pubDate>
      
      <guid>/questions/29298/capturing-traffic-from-loopback-adapter-on-windows-7-64-bit/</guid>
      <description>Capturing traffic from Loopback adapter on Windows 7 64 bit  0 N.B. I&#39;ve already read this one - http://ask.wireshark.org/questions/29211/how-can-wireshark-capture-local-host-traffic-on-windows
I&#39;m running Windows 7 65bit SP1 under VMWare Fusion and I&#39;ve two applications that communicating via HTTP over 127.0.0.1:8888
Try as I might I seem unable to capture the traffic between the two applications (using winpcap 4.1.3 and Wireshark 1.10.5)
I&#39;ve installed an configured the Loopback adapter as per VMWare&#39;s instructions - http://kb.</description>
    </item>
    
    <item>
      <title>turbocap / not visible</title>
      <link>/questions/29313/turbocap-not-visible/</link>
      <pubDate>Thu, 30 Jan 2014 06:21:00 +0000</pubDate>
      
      <guid>/questions/29313/turbocap-not-visible/</guid>
      <description>turbocap / not visible  0 I&#39;ve employed several Turbocap boards, under Win7, and they just work: slide the card in, power on the machine, run the installer, and presto: both dumpcap and Wireshark see three additional ports (A, B, and the Aggregating function).
But I&#39;m stumbling on my latest install.
TurboCap-1.4.1843.846 TurboCap2 board Win7 64-bit Winpcap 4.1.3
The installation log reports success:
[000007D0] 2014-01-30 06:11:48 LOG Event: 1, ENTER: DriverPackageInstallW [000007D0] 2014-01-30 06:11:48 LOG Event: 2, DRIVER_PACKAGE_LEGACY_MODE flag set but not supported on Plug and Play driver on VISTA.</description>
    </item>
    
    <item>
      <title>[closed] Local network</title>
      <link>/questions/29319/local-network/</link>
      <pubDate>Thu, 30 Jan 2014 07:48:00 +0000</pubDate>
      
      <guid>/questions/29319/local-network/</guid>
      <description>[closed] Local network  0 Hi i have a question. How can i scan local network? which sites are visited the most is my goal. So which command do i have to use? If you can answer my question. Thanks for your help.
local networkasked 30 Jan &#39;14, 07:48
Beginer
1●5●5●6
accept rate: 0%
 closed 30 Jan &#39;14, 08:28 
Kurt Knochner ♦
24.8k●10●39●237
 The question has been closed for the following reason &amp;ldquo;You have already asked (almost) the same thing here: http://ask.</description>
    </item>
    
    <item>
      <title>TCP window size reducing</title>
      <link>/questions/29339/tcp-window-size-reducing/</link>
      <pubDate>Fri, 31 Jan 2014 02:00:00 +0000</pubDate>
      
      <guid>/questions/29339/tcp-window-size-reducing/</guid>
      <description>TCP window size reducing  0 Background: I am trying to work out why LiveDrive, on my newly installed 80/20 connection is only uploading at a suspiciously round 256 KB/s. SpeedTest.Net shows ~60Mbps download and 19.2Mbps upload. My provider, PlusNet, suggested using Wireshark to check what packets are being transmitted to see if their traffic management system is throttling transmission.
Wireshark is showing that I am receiving a lot of &#39;batched&#39; ACKs from the LiveDrive server where the Win value is reducing from, as an example, 64256 down to 1024 in 25 ACKs.</description>
    </item>
    
    <item>
      <title>Reporting based off mac addresses</title>
      <link>/questions/29342/reporting-based-off-mac-addresses/</link>
      <pubDate>Fri, 31 Jan 2014 04:12:00 +0000</pubDate>
      
      <guid>/questions/29342/reporting-based-off-mac-addresses/</guid>
      <description>Reporting based off mac addresses  0 Wireshark newbie - I want to see which mac addresses are hogging the traffic in our network. Is there a way to get a report that gives traffic stats over time grouped by mac address.
mac-addressasked 31 Jan &#39;14, 04:12
mannymisc
1●1●1●1
accept rate: 0%
  
One Answer:
  
2Yes, go to:
Statistics -&amp;gt; Conversations -&amp;gt; Ethernet [a Tab]</description>
    </item>
    
    <item>
      <title>Wrong start file chosen for X11 on OSX</title>
      <link>/questions/29345/wrong-start-file-chosen-for-x11-on-osx/</link>
      <pubDate>Fri, 31 Jan 2014 05:06:00 +0000</pubDate>
      
      <guid>/questions/29345/wrong-start-file-chosen-for-x11-on-osx/</guid>
      <description>Wrong start file chosen for X11 on OSX  0 Hi i use Mac os X mavericks and when i originally installed wireshark i had to tell the program were X11 was i chose the wrong programe the mac thinks Apple script editor is X11 so wireshark doesn&#39;t run does start up X11 but doesn&#39;t function ive tryd to reinstall but that doesn&#39;t work and Apple script editor can&#39;t be removed.</description>
    </item>
    
    <item>
      <title>Old Fashion Fax</title>
      <link>/questions/29354/old-fashion-fax/</link>
      <pubDate>Fri, 31 Jan 2014 08:57:00 +0000</pubDate>
      
      <guid>/questions/29354/old-fashion-fax/</guid>
      <description>Old Fashion Fax  0 Does anyone know of a tool to use to analyze analog fax transmissions - T30.
analyze fax t.30 t30asked 31 Jan &#39;14, 08:57
fax
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Well, this is really not related to Wireshark!
Why? Because you want to capture and analyze ISDN or analog signals, carrying the T.30 protocol.
So, you need a hardware T.</description>
    </item>
    
    <item>
      <title>Capture filter for WLAN</title>
      <link>/questions/29361/capture-filter-for-wlan/</link>
      <pubDate>Fri, 31 Jan 2014 18:45:00 +0000</pubDate>
      
      <guid>/questions/29361/capture-filter-for-wlan/</guid>
      <description>Capture filter for WLAN  0 I am doing analysis of WiFi traffic between my device and the AP. I let wireshark run overnight, but my disk fills up and wireshark crashes. I was hoping someone could tell me how to build a filter that filters the capture for any traffic to/from a particular MAC?
Thanks Anon
wifiasked 31 Jan &#39;14, 18:45
YIleKu
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Windows sends RST after SYN-ACK on a TCP connection</title>
      <link>/questions/29366/windows-sends-rst-after-syn-ack-on-a-tcp-connection/</link>
      <pubDate>Sat, 01 Feb 2014 07:40:00 +0000</pubDate>
      
      <guid>/questions/29366/windows-sends-rst-after-syn-ack-on-a-tcp-connection/</guid>
      <description>Windows sends RST after SYN-ACK on a TCP connection  0 I&#39;m developing an Windows application that performs NAT between a virtual TAP interface and a physical Ethernet interface (with the purpose of achieving load balancing), using WinPcap. The test setup looks something like this:
I ran the test on two machines with Windows 7 64-bit, and on one of them everything works as expected, but on the other one, after SYN-ACK is received Windows sends a RST, and I don&#39;t understand why.</description>
    </item>
    
    <item>
      <title>12 second to load a page for the Server</title>
      <link>/questions/29376/12-second-to-load-a-page-for-the-server/</link>
      <pubDate>Sat, 01 Feb 2014 21:23:00 +0000</pubDate>
      
      <guid>/questions/29376/12-second-to-load-a-page-for-the-server/</guid>
      <description>12 second to load a page for the Server  1 Dose anyone see and issue with the trace below other the 35 second FIN ACK, if there is a issue is the trace can you please enplane to me what i am missing please
https://www.cloudshark.org/captures/e42f2386a047
your complaining of the browser takes to long to open the file on the server.
delay_pageasked 01 Feb &#39;14, 21:23
Ernest Johnson
26●6●6●12
accept rate: 0%</description>
    </item>
    
    <item>
      <title>info about this UDP stream</title>
      <link>/questions/29380/info-about-this-udp-stream/</link>
      <pubDate>Sun, 02 Feb 2014 05:04:00 +0000</pubDate>
      
      <guid>/questions/29380/info-about-this-udp-stream/</guid>
      <description>info about this UDP stream  0 I took a sample malware to analyze with a wireshark. This malware is a Zeus Bot. So I was taking a look at this UDP stream, why it didn&#39;t give me some more clear information? Here you can download a PCAP file
malware analysis wiresharkasked 02 Feb &#39;14, 05:04
Espen
21●2●2●6
accept rate: 0%
 edited 02 Feb &#39;14, 05:05</description>
    </item>
    
    <item>
      <title>empty json response?</title>
      <link>/questions/29383/empty-json-response/</link>
      <pubDate>Sun, 02 Feb 2014 19:17:00 +0000</pubDate>
      
      <guid>/questions/29383/empty-json-response/</guid>
      <description>empty json response?  0 I am learning wireshark while trying to learn how ajax works... using 500px as example, and picking a random portfolio, http://500px.com/Pop315, I see this traffic...
browser requests page from 209.15.228.200, gets the page, which essentially contains just javascripts and div place holders.browser requests external javascript and an image from 72.21.91.19, gets bothbrowser sends a &#34;GET /event?a=...&#34; to 50.17.242.3050.17.242.30 returns a json object consists of just &#34;</description>
    </item>
    
    <item>
      <title>audio synchronization</title>
      <link>/questions/29385/audio-synchronization/</link>
      <pubDate>Sun, 02 Feb 2014 21:16:00 +0000</pubDate>
      
      <guid>/questions/29385/audio-synchronization/</guid>
      <description>audio synchronization  0 I am trying to reconstruct two rtp streams (audio). I was using rtp timestamp as a clock rate to reconstruct and synchronization. But for few instances i see that the rtp timestamp is not linear. So how do i calculate the actual time? Is there any formula for this?
thanks rahul
timestamp rtpasked 02 Feb &#39;14, 21:16
rahulhgowda
1●2●2●2
accept rate: 0%
What does the RTP timestamp do it it&#39;s not linear?</description>
    </item>
    
    <item>
      <title>Telnet is not passing for specific IP</title>
      <link>/questions/29386/telnet-is-not-passing-for-specific-ip/</link>
      <pubDate>Mon, 03 Feb 2014 00:46:00 +0000</pubDate>
      
      <guid>/questions/29386/telnet-is-not-passing-for-specific-ip/</guid>
      <description>Telnet is not passing for specific IP  0 Hi there I&#39;m having a time reader device connect to the network which works fine unless for specific IP addresses it doen&#39;t alow telnet but it still relply to the ping. The out put shows my laptop IP address 10.6.80.135 and the problem is with IP address 10.6.80.120
While the IP address 10.6.80.83 is working fine.
78 22.937534000 10.6.80.135 10.6.5.118 TCP 54 49439 &amp;gt; http [RST, ACK] Seq=1 Ack=1 Win=0 Len=0 83 23.</description>
    </item>
    
    <item>
      <title>TCP Window</title>
      <link>/questions/29387/tcp-window/</link>
      <pubDate>Mon, 03 Feb 2014 01:05:00 +0000</pubDate>
      
      <guid>/questions/29387/tcp-window/</guid>
      <description>TCP Window  0 Hi,
Wanted to understand the Behaviour of TCP reception when The Window Size is Increased. Should The Speed at which the Packets are Transmitted by the Server increase??? Assuming that there is processing the Packets very fast.
tcppacketsasked 03 Feb &#39;14, 01:05
Amin Khan
11●1●1●2
accept rate: 0%
  
One Answer:
  
1The speed can do three things when the window size is increased: it can go up, it can stay the same, and it can go down.</description>
    </item>
    
    <item>
      <title>Source Problem</title>
      <link>/questions/29397/source-problem/</link>
      <pubDate>Mon, 03 Feb 2014 08:21:00 +0000</pubDate>
      
      <guid>/questions/29397/source-problem/</guid>
      <description>Source Problem  0 Hey guys, I am new to wireshark and having some problems.
I am trying to capture some packets on my personal computer and i go to url and type int a web address like facebook.com and when i go to look for syn packets i cant find just the syn packet. It has syn,ack and there is non with the source as my ip. I know there has to be one.</description>
    </item>
    
    <item>
      <title>Decode value of an OID in snmp frame</title>
      <link>/questions/29401/decode-value-of-an-oid-in-snmp-frame/</link>
      <pubDate>Mon, 03 Feb 2014 09:42:00 +0000</pubDate>
      
      <guid>/questions/29401/decode-value-of-an-oid-in-snmp-frame/</guid>
      <description>Decode value of an OID in snmp frame  0 The OID values ​​are not decoded, is always shown in decimal.
IF-MIB :: ifOperStatus.14 (1.3.6.1.2.1.2.2.1.8.14): Object Name: 1.3.6.1.2.1.2.2.1.8.14 (IF-MIB :: ifOperStatus.14) Value (Integer32): 2 &amp;lt;- should interpret and say DOWN
IF-MIB :: ifDescr.14 (1.3.6.1.2.1.2.2.1.2.14) 4e4f4e4500 &amp;lt;- should interpret and say NONE Object Name: 1.3.6.1.2.1.2.2.1.2.14 (IF-MIB :: ifDescr.14) Value (OctetString): 4e4f4e4500 &amp;lt;- should interpret and say NONE Please if you can tell me as I do to decode the values ​​of the OID</description>
    </item>
    
    <item>
      <title>TCP windows full - FTP transfer</title>
      <link>/questions/29402/tcp-windows-full-ftp-transfer/</link>
      <pubDate>Mon, 03 Feb 2014 09:48:00 +0000</pubDate>
      
      <guid>/questions/29402/tcp-windows-full-ftp-transfer/</guid>
      <description>TCP windows full - FTP transfer  0 Hello all,
I would some assistance to understand a strange behavior. I did a network capture during a FTP transfer between a client and a server client = 10.212.44.10 Server = 131.97.141.59
The transfer of data is from the client to the server. During the capture I see some packets from the client with the information &#34;TCP window full&#34;. I understand what means this message, but I don&#39;t understand why I see it since the Windows size of server doesn&#39;t seems full.</description>
    </item>
    
    <item>
      <title>SSL Record Layer vs TLS Record Layer</title>
      <link>/questions/29404/ssl-record-layer-vs-tls-record-layer/</link>
      <pubDate>Mon, 03 Feb 2014 10:17:00 +0000</pubDate>
      
      <guid>/questions/29404/ssl-record-layer-vs-tls-record-layer/</guid>
      <description>SSL Record Layer vs TLS Record Layer  0 Hello,
I have a question about SSL and the Record Layer. In establishing an SSL connection to a vendor site, I consistently get a failure on the first client hello message. But after 15 seconds a second client hello message is resent and I receive the corresponding server hello message.
The usual SYN, SYN-ACK, ACK process never changes. In the first client hello message, I see that the Record Layer is labeled as an SSL Record Layer: Handshake Protocol: Client Hello, Content Type Handshake (22), Version TLS 1.</description>
    </item>
    
    <item>
      <title>Computers with LAN?</title>
      <link>/questions/29412/computers-with-lan/</link>
      <pubDate>Mon, 03 Feb 2014 13:35:00 +0000</pubDate>
      
      <guid>/questions/29412/computers-with-lan/</guid>
      <description>Computers with LAN?  0 I have two computers connected to a 5port switch in my room. Both computers have the same IP and MAC. Now I also connected the switch to the internet.
 _____ ________ | | MAC: AA:CC | |-----| PC1 | IP: 94.94.94.94 | | |_____| INTERNET ------| SWITCH | | | _____ | | | | MAC: AA:CC |________|-----| PC2 | IP: 94.94.94.94 |_____|Info:
MACs are clonedInternet works on both computersQuestion:</description>
    </item>
    
    <item>
      <title>Bad TCP Connection closure detection</title>
      <link>/questions/29417/bad-tcp-connection-closure-detection/</link>
      <pubDate>Tue, 04 Feb 2014 01:04:00 +0000</pubDate>
      
      <guid>/questions/29417/bad-tcp-connection-closure-detection/</guid>
      <description>Bad TCP Connection closure detection  0 I am investigating an issue on a network at the moment and although I have found the issue, it has highlighted a behavior in Wireshark that I hope someone can explain to me. I can&#39;t post the pcap as its quite large and contains sensitive data, but the sttached screenshot of the TCP information should help. On this, we are looking at treams with index 0 &amp;amp; 1.</description>
    </item>
    
    <item>
      <title>How to hide the count of captured packets with tshark</title>
      <link>/questions/29424/how-to-hide-the-count-of-captured-packets-with-tshark/</link>
      <pubDate>Tue, 04 Feb 2014 04:34:00 +0000</pubDate>
      
      <guid>/questions/29424/how-to-hide-the-count-of-captured-packets-with-tshark/</guid>
      <description>How to hide the count of captured packets with tshark  0 Hi, I would like to know how I could hide the count of the packets that tshark captured. I tried the options -q and -Q but it display only the count wheras I would like to display only the packets. I read the doc, but I didn&#39;t find how to do this. Can somebody help me ?
Thank you.</description>
    </item>
    
    <item>
      <title>How to build a dissector based on cip.class (using dissector_add_uint) ?</title>
      <link>/questions/29430/how-to-build-a-dissector-based-on-cipclass-using-dissector_add_uint/</link>
      <pubDate>Tue, 04 Feb 2014 07:06:00 +0000</pubDate>
      
      <guid>/questions/29430/how-to-build-a-dissector-based-on-cipclass-using-dissector_add_uint/</guid>
      <description>How to build a dissector based on cip.class (using dissector_add_uint) ?  0 Hi,
I would like to build my own dissector based on the parameter severals values of cip.class. I used the function dissector_add_uint(&#34;cip.class&#34;,VALUE,handle), but it is not working. My dissector is never called.
After research, I think it is because cip.class is not registered, right ? How can I do for use this parameter ?
I see (by trying) that I can use cip.</description>
    </item>
    
    <item>
      <title>Recursive XML DTD</title>
      <link>/questions/29435/recursive-xml-dtd/</link>
      <pubDate>Tue, 04 Feb 2014 10:00:00 +0000</pubDate>
      
      <guid>/questions/29435/recursive-xml-dtd/</guid>
      <description>Recursive XML DTD  0 I have some proprietary HTTP/XML that I was wanting Wireshark to be able to parse and use as a display filter, so I started writing a DTD that Wireshark could deal with. It seems to work until I get to the second instance of an element in the filter, at which point it claims that the filter is invalid.
This is the DTD I&#39;ve generated:</description>
    </item>
    
    <item>
      <title>Get hostnames from a trace in wireshark</title>
      <link>/questions/29438/get-hostnames-from-a-trace-in-wireshark/</link>
      <pubDate>Tue, 04 Feb 2014 13:51:00 +0000</pubDate>
      
      <guid>/questions/29438/get-hostnames-from-a-trace-in-wireshark/</guid>
      <description>Get hostnames from a trace in wireshark  0 Hi, I need to get all the hostnames from a trace that i opened using wireshark that it already have alot of data.Is there any filter that i can use in wireshark? Otherwiese what should i do to get the hostnames ? Any help will be appreciated.
filter hostname wiresharkasked 04 Feb &#39;14, 13:51
FalaG
11●1●1●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Merging PCAP files</title>
      <link>/questions/29439/merging-pcap-files/</link>
      <pubDate>Tue, 04 Feb 2014 21:50:00 +0000</pubDate>
      
      <guid>/questions/29439/merging-pcap-files/</guid>
      <description>Merging PCAP files  0 I know it is possible to merge 2 pcap files by selecting File-&amp;gt;Merge, but is it possible to merge more than 2 PCAP file using command line interface of Wireshark ?
merge command-lineasked 04 Feb &#39;14, 21:50
Ashiq
16●2●2●5
accept rate: 0%
  
One Answer:
  
2 You can use mergecap to achieve this
mergecap -w merged.pcapng input_traces*answered 04 Feb &#39;14, 22:17</description>
    </item>
    
    <item>
      <title>Not able to dissect rrcConnectionRequest in wireshark v1.10.5</title>
      <link>/questions/29444/not-able-to-dissect-rrcconnectionrequest-in-wireshark-v1105/</link>
      <pubDate>Tue, 04 Feb 2014 23:15:00 +0000</pubDate>
      
      <guid>/questions/29444/not-able-to-dissect-rrcconnectionrequest-in-wireshark-v1105/</guid>
      <description>Not able to dissect rrcConnectionRequest in wireshark v1.10.5  0 Hi, I am not able to dissect rrcConnectionRequest/Setup in wireshark version 1.10.5 while I was able to dissect rrcConnectionSetupcomplete and other RRC messages. can anybody help me out or suggest that any settings need to correct or the dissector itself is buggy? there is an dissecting problem in all rrc.ul.ccch and rrc.dl.ccch messages.
I can provide the pcap file as well if any body interested.</description>
    </item>
    
    <item>
      <title>Ip address from Bandwidth.com text</title>
      <link>/questions/29446/ip-address-from-bandwidthcom-text/</link>
      <pubDate>Wed, 05 Feb 2014 00:15:00 +0000</pubDate>
      
      <guid>/questions/29446/ip-address-from-bandwidthcom-text/</guid>
      <description>Ip address from Bandwidth.com text  0 Any chance I can locate the ip address from a text received through voip?
voipasked 05 Feb &#39;14, 00:15
jd421
11●1●1●2
accept rate: 0%
Voip, text, IP address? What is the relationship between all these things? Could you please be more specific, because I don&#39;t understand what you are looking for....
(05 Feb &#39;14, 01:11) Kurt Knochner ♦If somebody sends a text message through bandwidth.</description>
    </item>
    
    <item>
      <title>Unable to see VLAN tags using Intel 82579LM</title>
      <link>/questions/29447/unable-to-see-vlan-tags-using-intel-82579lm/</link>
      <pubDate>Wed, 05 Feb 2014 00:30:00 +0000</pubDate>
      
      <guid>/questions/29447/unable-to-see-vlan-tags-using-intel-82579lm/</guid>
      <description>Unable to see VLAN tags using Intel 82579LM  0 Hi all
My system configuration as follows
PC OS windows 7 ent. 64 bit
Switch config
monitor session x source interface Gi 0/x
monitor session x destination interface fa0/x encapsulation dot1q
registry monitormode is 1 i seen vlan information but only STP packet
registry monitormode is 0 i dont see vlan information only tcp/ip and more l2 information MAC etc</description>
    </item>
    
    <item>
      <title>Capture my wireless (iPhone &amp;amp; iPad) traffic</title>
      <link>/questions/29453/capture-my-wireless-iphone-ipad-traffic/</link>
      <pubDate>Wed, 05 Feb 2014 03:10:00 +0000</pubDate>
      
      <guid>/questions/29453/capture-my-wireless-iphone-ipad-traffic/</guid>
      <description>Capture my wireless (iPhone &amp;amp; iPad) traffic  0 I captured some iphone packets using shark for root on my android, is there a way to decrypt the messages using wireshark? Thanks.
shark root iphone forasked 05 Feb &#39;14, 03:10
Hozz
11●1●1●2
accept rate: 0%
  
One Answer:
  
0is there a way to decrypt the messages using wireshark?
If you really mean to decrypt wifi traffic, please see the WLAN decryption wiki.</description>
    </item>
    
    <item>
      <title>How can a business use Wireshark and disable Live Packet Sniffing?</title>
      <link>/questions/29455/how-can-a-business-use-wireshark-and-disable-live-packet-sniffing/</link>
      <pubDate>Wed, 05 Feb 2014 05:07:00 +0000</pubDate>
      
      <guid>/questions/29455/how-can-a-business-use-wireshark-and-disable-live-packet-sniffing/</guid>
      <description>How can a business use Wireshark and disable Live Packet Sniffing?  0 Our business may need to use Wire Shark for looking at packet data for a client, However, with this program being shared with all employees in the company. We don&#39;t want anyone to actually look at our internal data.
Is there a way that we can disable the Live Packet Sniff part of the program?
sniffing packet wiresharkasked 05 Feb &#39;14, 05:07</description>
    </item>
    
    <item>
      <title>is it possible to capture traffic within a box</title>
      <link>/questions/29460/is-it-possible-to-capture-traffic-within-a-box/</link>
      <pubDate>Wed, 05 Feb 2014 06:41:00 +0000</pubDate>
      
      <guid>/questions/29460/is-it-possible-to-capture-traffic-within-a-box/</guid>
      <description>is it possible to capture traffic within a box  0 Hi
I have a services talking to another services which is hosted on the same box. I am not able to capture the traffic between them. How can i make wireshark capture the traffic between them
thanks scara
captureasked 05 Feb &#39;14, 06:41
scara
31●9●9●14
accept rate: 0%
  
One Answer:
  
2 If you&#39;re using Windows, then it&#39;s not very easy.</description>
    </item>
    
    <item>
      <title>Is there any xml file available to decode Ericsson Gy&#43; Diameter variant?</title>
      <link>/questions/29464/is-there-any-xml-file-available-to-decode-ericsson-gy-diameter-variant/</link>
      <pubDate>Wed, 05 Feb 2014 08:45:00 +0000</pubDate>
      
      <guid>/questions/29464/is-there-any-xml-file-available-to-decode-ericsson-gy-diameter-variant/</guid>
      <description>Is there any xml file available to decode Ericsson Gy+ Diameter variant?  0 Hello,
Is there any xml file available to decode Ericsson Gy+ Diameter variant?
I have some traces but can&#39;t decode them.
Best regards
ericsson gy+asked 05 Feb &#39;14, 08:45
lolodub
11●1●1●2
accept rate: 0%
 edited 20 Jul &#39;16, 08:06 
cmaynard ♦♦
9.4k●10●38●142
I am also looking for custom dictionaries to read custom AVPs for Gx+, Gy+, ESy developed by Ericsson.</description>
    </item>
    
    <item>
      <title>MTU question</title>
      <link>/questions/29466/mtu-question/</link>
      <pubDate>Wed, 05 Feb 2014 09:58:00 +0000</pubDate>
      
      <guid>/questions/29466/mtu-question/</guid>
      <description>MTU question  0 If a router&#39;s WAN interface is configured for an MTU of 1500, I should not be able to send an non-fragmented packet over 1500 outside, but it gets through.
where does it find room for another 14 bytes?
Thanks
http://www.cloudshark.org/captures/a00ef83e9e99
ping 8.8.8.8 -l 1472 -f
Pinging 8.8.8.8 with 1472 bytes of data:
Reply from 8.8.8.8: bytes=64 (sent 1472) time=43ms TTL=46
Reply from 8.8.8.8: bytes=64 (sent 1472) time=34ms TTL=46</description>
    </item>
    
    <item>
      <title>Efficient way of Merging PCAP</title>
      <link>/questions/29467/efficient-way-of-merging-pcap/</link>
      <pubDate>Wed, 05 Feb 2014 10:08:00 +0000</pubDate>
      
      <guid>/questions/29467/efficient-way-of-merging-pcap/</guid>
      <description>Efficient way of Merging PCAP  0 I have nearly 20 PCAP files inside a directory which needs to be merged, so what I do is this
$ls | tee list.txt $mergecap -w Merged.pcap $(cat list.txt)
Is there a better way of doing this ???
merge ubuntuasked 05 Feb &#39;14, 10:08
Ashiq
16●2●2●5
accept rate: 0%
  
One Answer:
  
0what about this:
mergecap -w Merged.pcap `ls`</description>
    </item>
    
    <item>
      <title>RDP Sessions Slow down in the afternoon</title>
      <link>/questions/29471/rdp-sessions-slow-down-in-the-afternoon/</link>
      <pubDate>Wed, 05 Feb 2014 13:14:00 +0000</pubDate>
      
      <guid>/questions/29471/rdp-sessions-slow-down-in-the-afternoon/</guid>
      <description>RDP Sessions Slow down in the afternoon  0 Hello - this one has been puzzling me for some time. I frequently RDP to the office from home via 3 different methods: site to site VPN, client VPN, and Citrix RDP. There is no difference in behavior between the three methods, nor is there a difference in behavior if I RDP from different home machines, or target different machines at the office (even on different subnets.</description>
    </item>
    
    <item>
      <title>Netbios Name Service packet - &amp;quot;Net Query NB ##JABBERID##&amp;quot;</title>
      <link>/questions/29476/netbios-name-service-packet-net-query-nb-jabberid/</link>
      <pubDate>Wed, 05 Feb 2014 17:17:00 +0000</pubDate>
      
      <guid>/questions/29476/netbios-name-service-packet-net-query-nb-jabberid/</guid>
      <description>Netbios Name Service packet - &amp;ldquo;Net Query NB ##JABBERID##&amp;quot;  0 So Im having network bogging down issues. Upon capturing 30 minutes worth of packets, I have come across quite a few (afew thounsand) packets like the following:
# Time Src Dest Protocol Length info
&#34;5227 200.570462000 10.42.91.105 10.42.91.255 NBNS 92 Name query NB ##JABBERID##&amp;lt;00&amp;gt;&#34;
Does anyone know what the ##JABBERID## means? I cant find any documentation on it anywhere...</description>
    </item>
    
    <item>
      <title>Are user preferences supported for plugins?</title>
      <link>/questions/29484/are-user-preferences-supported-for-plugins/</link>
      <pubDate>Thu, 06 Feb 2014 03:29:00 +0000</pubDate>
      
      <guid>/questions/29484/are-user-preferences-supported-for-plugins/</guid>
      <description>Are user preferences supported for plugins?  0 I have written a simple dissector plugin and now I would like to make port ranges configurable for the user. I have not found how to do this.
Is it possible to have user preferences for a dissector plugin?
/Michael
preferences pluginasked 06 Feb &#39;14, 03:29
michla
11●1●1●4
accept rate: 0%
  
One Answer:
  
2 Sure, a number of the &#34;</description>
    </item>
    
    <item>
      <title>Installing 64 bit on 2012 R2 VM -causes obsolete driver install??</title>
      <link>/questions/29487/installing-64-bit-on-2012-r2-vm-causes-obsolete-driver-install/</link>
      <pubDate>Thu, 06 Feb 2014 04:21:00 +0000</pubDate>
      
      <guid>/questions/29487/installing-64-bit-on-2012-r2-vm-causes-obsolete-driver-install/</guid>
      <description>Installing 64 bit on 2012 R2 VM -causes obsolete driver install??  0 Hi New to Wireshark. I have installed the latest 64bit version on a Citrix 6.0 VM Xen running a fully patched Win 2012 R2 64 bit server with windows auto update. The host for the VM is suggesting this has caused/triggered installation of citrix 5.5 drivers and other obsolete stuff. This then cause the VM to stop talking to the world in a big way.</description>
    </item>
    
    <item>
      <title>CAPWAP Malformed Packet (Exception occurred)</title>
      <link>/questions/29494/capwap-malformed-packet-exception-occurred/</link>
      <pubDate>Thu, 06 Feb 2014 12:01:00 +0000</pubDate>
      
      <guid>/questions/29494/capwap-malformed-packet-exception-occurred/</guid>
      <description>CAPWAP Malformed Packet (Exception occurred)  0 1I keep getting these packets and haven&#39;t found a reason for it, or a solution. Does anyone have an advice? Thanks.
capwapasked 06 Feb &#39;14, 12:01
bt425
1●1●2●3
accept rate: 0%
 edited 06 Feb &#39;14, 12:02 
Do you wonder that you see CAPWAP frames, or that they are malformed?
(06 Feb &#39;14, 12:05) Kurt Knochner ♦I am getting malformed capwap packets and needed to know how to resolve them.</description>
    </item>
    
    <item>
      <title>Any way to merge preexisting local account with Twitter/Facebook/OpenID?</title>
      <link>/questions/29498/any-way-to-merge-preexisting-local-account-with-twitterfacebookopenid/</link>
      <pubDate>Thu, 06 Feb 2014 13:37:00 +0000</pubDate>
      
      <guid>/questions/29498/any-way-to-merge-preexisting-local-account-with-twitterfacebookopenid/</guid>
      <description>Any way to merge preexisting local account with Twitter/Facebook/OpenID?  0 I started participating here before the site implemented OAUTH support (e.g. login with Twitter, Facebook, OpenID identity, etc.)...
Is there any way to associate/merge my preexisting local username (wesmorgan1) with my Twitter handle (also wesmorgan1)? When I try to log in with Twitter, I get an HTTP 500 error code...
I&#39;d like to keep my identity, history, badges, etc...</description>
    </item>
    
    <item>
      <title>Readout CSV trace</title>
      <link>/questions/29500/readout-csv-trace/</link>
      <pubDate>Thu, 06 Feb 2014 14:29:00 +0000</pubDate>
      
      <guid>/questions/29500/readout-csv-trace/</guid>
      <description>Readout CSV trace  0 Hello, I would like to readout a Wireshark CSV file and detect the received and lost RTP packets. Is that even possible with Wireshark? Many thanks in advance. :)
wiresharkasked 06 Feb &#39;14, 14:29
kvmannila
16●1●1●3
accept rate: 0%
What is a Wireshark CSV file?
(06 Feb &#39;14, 23:53) Kurt Knochner ♦It&#39;s a trace exported as a csv file. But any &#34;readable&#34; file format would be OK.</description>
    </item>
    
    <item>
      <title>EVRC dissector is not recognizing RTP Payload Type-97 EVRC payloads</title>
      <link>/questions/29501/evrc-dissector-is-not-recognizing-rtp-payload-type-97-evrc-payloads/</link>
      <pubDate>Thu, 06 Feb 2014 14:56:00 +0000</pubDate>
      
      <guid>/questions/29501/evrc-dissector-is-not-recognizing-rtp-payload-type-97-evrc-payloads/</guid>
      <description>EVRC dissector is not recognizing RTP Payload Type-97 EVRC payloads  0 I have Wireshark 1.10.5 and it is not decoding the EVRC payload in RTP dynamic payload type 97 packets as per RFC3558. My search results seem to indicate Wireshark should automagically detect and decode this but it does not. There are no settings on the EVRC protocol preferences to instruct the dissector which RTP payload type to use. How do I get Wireshark to perform this function?</description>
    </item>
    
    <item>
      <title>Is it safe to follow the TCP stream on a malware packet I have captured?</title>
      <link>/questions/29504/is-it-safe-to-follow-the-tcp-stream-on-a-malware-packet-i-have-captured/</link>
      <pubDate>Thu, 06 Feb 2014 17:07:00 +0000</pubDate>
      
      <guid>/questions/29504/is-it-safe-to-follow-the-tcp-stream-on-a-malware-packet-i-have-captured/</guid>
      <description>Is it safe to follow the TCP stream on a malware packet I have captured?  0 The title says it all. It&#39;s been a while since I&#39;ve looked at malicious packets and I wanted to make sure that it is ok to follow the TCP stream of malware I have captured on wireshark.
Thanks.
malware packets tcpasked 06 Feb &#39;14, 17:07
clope070
1●1●1●3
accept rate: 0%
 edited 06 Feb &#39;14, 17:17</description>
    </item>
    
    <item>
      <title>How to carture One pc on the network</title>
      <link>/questions/29505/how-to-carture-one-pc-on-the-network/</link>
      <pubDate>Thu, 06 Feb 2014 19:33:00 +0000</pubDate>
      
      <guid>/questions/29505/how-to-carture-one-pc-on-the-network/</guid>
      <description>How to carture One pc on the network  0 How to carture One pc on the network
my network ranage is 192.168.10.0/24
I install wireshark in 192.168.10.6 I have another pc 192.168.10.25
Now I want using 192.168.10.6 pc wireshark app scan 192.168.10.25 How to do this? please help me
ip addressasked 06 Feb &#39;14, 19:33
nature
11●1●1●2
accept rate: 0%
  
One Answer:
  
0See Capture Setup/Ethernet for lots of information.</description>
    </item>
    
    <item>
      <title>difference between seconds since previous captured packet vs seconds since previous Display packet</title>
      <link>/questions/29507/difference-between-seconds-since-previous-captured-packet-vs-seconds-since-previous-display-packet/</link>
      <pubDate>Thu, 06 Feb 2014 21:57:00 +0000</pubDate>
      
      <guid>/questions/29507/difference-between-seconds-since-previous-captured-packet-vs-seconds-since-previous-display-packet/</guid>
      <description>difference between seconds since previous captured packet vs seconds since previous Display packet  0 Hi
What is the difference between seconds since previous captured packet vs seconds since previous Display packet. what does it mean captured packet and display packet.
thanks
timestampasked 06 Feb &#39;14, 21:57
scara
31●9●9●14
accept rate: 0%
  
One Answer:
  
1Simply the following:
If you&#39;ve applied a display filter so that not all of the frames are being displayed in the summary pane, then the &#34;</description>
    </item>
    
    <item>
      <title>Filter for a single http request response</title>
      <link>/questions/29523/filter-for-a-single-http-request-response/</link>
      <pubDate>Fri, 07 Feb 2014 03:45:00 +0000</pubDate>
      
      <guid>/questions/29523/filter-for-a-single-http-request-response/</guid>
      <description>Filter for a single http request response  0 Hi
In Wireshark it is possible to filter out a single request and response. I have tried both &#34;Follow tcp stream&#34; option and also &#34;conversation filter&amp;gt;tcp&#34;. In both case they show multiple http request response. I am only interested in one single request response in that list.
I am monitoring web services request response.
filter httpasked 07 Feb &#39;14, 03:45
scara</description>
    </item>
    
    <item>
      <title>Monitor TCP port 1 between computer and printer over ethernet</title>
      <link>/questions/29526/monitor-tcp-port-1-between-computer-and-printer-over-ethernet/</link>
      <pubDate>Fri, 07 Feb 2014 05:15:00 +0000</pubDate>
      
      <guid>/questions/29526/monitor-tcp-port-1-between-computer-and-printer-over-ethernet/</guid>
      <description>Monitor TCP port 1 between computer and printer over ethernet  0 Hello,
Please forgive me if Im a bit imprecise in my terminology, I am new to this arena.
Im working with a networked RIP printing software in our University printing lab and we&#39;ve run into a problem where the software sporadically but consistently fails to connect to the networked epson plotter. The company that produces the software informs me that there must be some sort of network issue or software conflict to prevent the connection, and Im trying to diagnose what that conflict might be.</description>
    </item>
    
    <item>
      <title>NIC in Monitor mode used by two program simultaneously</title>
      <link>/questions/29543/nic-in-monitor-mode-used-by-two-program-simultaneously/</link>
      <pubDate>Fri, 07 Feb 2014 19:39:00 +0000</pubDate>
      
      <guid>/questions/29543/nic-in-monitor-mode-used-by-two-program-simultaneously/</guid>
      <description>NIC in Monitor mode used by two program simultaneously  0 Presently I am designing sniifer that is uses NIC in monitor mode but side by side I am also using wireshark ( for which also NIC in monitor mode ). So both this program using monitor mode simultaneously. SO I want to know Does it possible that two program using NIC in monitor mode simultaneosly ? Does it affect on packet capturing?</description>
    </item>
    
    <item>
      <title>Fake Ethernet</title>
      <link>/questions/29545/fake-ethernet/</link>
      <pubDate>Fri, 07 Feb 2014 20:48:00 +0000</pubDate>
      
      <guid>/questions/29545/fake-ethernet/</guid>
      <description>Fake Ethernet  0 I want Wireshark to give me all/at least Data packet into Fake Ethernet format in monitor mode. How Wireshark can be set for converting wireless packet to fake Ethernet packet? and can I use analysis tool of real Ethernet packet on this Fake Ethernet ?
sniffing security wiresharkasked 07 Feb &#39;14, 20:48
WIDS
25●7●7●13
accept rate: 0% 
 edited 07 Feb &#39;14, 21:42</description>
    </item>
    
    <item>
      <title>ssl_decrypt_record: mac failed</title>
      <link>/questions/29546/ssl_decrypt_record-mac-failed/</link>
      <pubDate>Fri, 07 Feb 2014 22:03:00 +0000</pubDate>
      
      <guid>/questions/29546/ssl_decrypt_record-mac-failed/</guid>
      <description>ssl_decrypt_record: mac failed  0 I believe if the capture contains an &#34;unexpected&#34; frame (e.g., TCP Retransmission), then the SSL decryption gets messed up.
Below is an example where the server and client frames start off properly decoded. However, frame 1983 is a TCP Retransmission from the server to client. After this, the client frames are decrypted correctly but the server frames MAC check fails. You can see from the Plaintext array that the decryption is successful.</description>
    </item>
    
    <item>
      <title>SMPP Submit strange</title>
      <link>/questions/29547/smpp-submit-strange/</link>
      <pubDate>Sat, 08 Feb 2014 03:23:00 +0000</pubDate>
      
      <guid>/questions/29547/smpp-submit-strange/</guid>
      <description>SMPP Submit strange  0 Hi !
I cannot explain myself the following case. http://cloudshark.org/captures/4de5550070f7
The SubmitSM packet was sent directly in one session (using Java application) making even socket flush after, but when I examine it in a Wireshark, I can see last 4 bytes (74203430) displayed, but not marked as part of the SubmitSM. However, they are marked as the begining of the next SMPP packet (Unbind). That&#39;s why the SMPP server cannot decode properly Unbind, since the first 4 bytes are wrong.</description>
    </item>
    
    <item>
      <title>How to make ANSI MAP ASN.1 spec compile-able in OSS ASN.1 studio</title>
      <link>/questions/29552/how-to-make-ansi-map-asn1-spec-compile-able-in-oss-asn1-studio/</link>
      <pubDate>Sat, 08 Feb 2014 07:15:00 +0000</pubDate>
      
      <guid>/questions/29552/how-to-make-ansi-map-asn1-spec-compile-able-in-oss-asn1-studio/</guid>
      <description>How to make ANSI MAP ASN.1 spec compile-able in OSS ASN.1 studio  0 I tried to compile ASN.1 spec in asn1/ansi_map /ansi_map.asn in OSS ASN.1 studio but failed. The error indicates there&#39;re duplicated tags in several messages, for example:
AuthenticationFailureReport ::= [PRIVATE 18] SET { ... reportType [44] IMPLICIT ReportType, ... reportType2 [44] IMPLICIT ReportType OPTIONAL, ... }It seems the tags here are used as unique type identifiers, but in my understanding, tag in a complex type (sequence,choice) should be used to mark the order of members.</description>
    </item>
    
    <item>
      <title>No interface can be used</title>
      <link>/questions/29555/no-interface-can-be-used/</link>
      <pubDate>Sat, 08 Feb 2014 09:51:00 +0000</pubDate>
      
      <guid>/questions/29555/no-interface-can-be-used/</guid>
      <description>No interface can be used  0 Couldn&#39;t run /usr/sbin/dumpcap
I added my account as a member to the wireshark group.
interfaces dumpcapasked 08 Feb &#39;14, 09:51
theking2
11●1●1●2
accept rate: 0%
OS, dumpcap version?
(08 Feb &#39;14, 13:55) grahamb ♦For Ubuntu (and derivatives), see http://ask.wireshark.org/questions/7523/ubuntu-machine-no-interfaces-listed
(09 Feb &#39;14, 12:32) helloworldhow to add an account as a member to the wireshark group
(13 Oct &#39;15, 14:04) agwmar  
2 Answers:</description>
    </item>
    
    <item>
      <title>saving packets in wireshark</title>
      <link>/questions/29556/saving-packets-in-wireshark/</link>
      <pubDate>Sat, 08 Feb 2014 12:13:00 +0000</pubDate>
      
      <guid>/questions/29556/saving-packets-in-wireshark/</guid>
      <description>saving packets in wireshark  0 I want to know when wireshark saves WIRELESS packet, it captured using various format( pcap/libpcap )... what it saves exactly complete packet (header and payload ) ? Suppose wireshark captured 1000 wireless packets ( n if we stopped capturing after this 1000 packets )then Is all this packets will be put in one single pcap file ? if it is like that how to retrieve each packet and its contain (at least header information ) ?</description>
    </item>
    
    <item>
      <title>Unable to discover any interface on computer</title>
      <link>/questions/29560/unable-to-discover-any-interface-on-computer/</link>
      <pubDate>Sat, 08 Feb 2014 19:42:00 +0000</pubDate>
      
      <guid>/questions/29560/unable-to-discover-any-interface-on-computer/</guid>
      <description>Unable to discover any interface on computer  0 After intalling Wireshark Ver. 1.62, it can&#39;t discover any interface to capture on my computer. At each start-up it shows a warning that &#39;NPF Driver isn&#39;t Running&#39; and that I won&#39;t be able to capture. How do I get the &#39;NPF Driver&#39; to run? I&#39;m running Wireshark on Windows 7 OS. Thanks, Kay.
not running npfThis question is marked &#34;community wiki&#34;.asked 08 Feb &#39;14, 19:42</description>
    </item>
    
    <item>
      <title>Help in reverse-engineering a protocol running atop TCP</title>
      <link>/questions/29563/help-in-reverse-engineering-a-protocol-running-atop-tcp/</link>
      <pubDate>Sat, 08 Feb 2014 22:53:00 +0000</pubDate>
      
      <guid>/questions/29563/help-in-reverse-engineering-a-protocol-running-atop-tcp/</guid>
      <description>Help in reverse-engineering a protocol running atop TCP  0 Hi all,
I&#39;m having an issue understanding how a program communicates with a device for sending table entries from a database. It can send thousands of entries but it will send them in blocks containing 16 table entries per block which, right now my data equals about 520 blocks before its done sending data.
The problem I&#39;m having is understanding how it verifies that the data in each block is correct (a checksum or crc?</description>
    </item>
    
    <item>
      <title>How to enable LUA in wireshark ?</title>
      <link>/questions/29565/how-to-enable-lua-in-wireshark/</link>
      <pubDate>Sun, 09 Feb 2014 00:33:00 +0000</pubDate>
      
      <guid>/questions/29565/how-to-enable-lua-in-wireshark/</guid>
      <description>How to enable LUA in wireshark ?  0 1This question is for Linux Centos Platform. I am doing a project in which Wireshark Traffic is to to be exported to a .pcap file and later used for further analysis. This Export is to be automatic that is programmatic. I found out that Wireshark process can be automated with LUA scripting Hence i download Wireshark but in the HELP or can say About Tab it displayed &#34;</description>
    </item>
    
    <item>
      <title>What is this? Destination port: cc-tracking</title>
      <link>/questions/29566/what-is-this-destination-port-cc-tracking/</link>
      <pubDate>Sun, 09 Feb 2014 02:14:00 +0000</pubDate>
      
      <guid>/questions/29566/what-is-this-destination-port-cc-tracking/</guid>
      <description>What is this? Destination port: cc-tracking  0 I am trying to test my friends proxy to make sure his IP cant be pulled, and the IP 74.38.140.80 keeps popping up with the destination port cc-tracking. Every other skype IP gives a 5 digit destination port, but this IP and port just lurk around and dont belong to anyone that I know of. Anyone know what the destination port means, or why even with my skype filter on it is getting through everytime?</description>
    </item>
    
    <item>
      <title>Wireshark is not detecting my Wireless interface...</title>
      <link>/questions/29574/wireshark-is-not-detecting-my-wireless-interface/</link>
      <pubDate>Sun, 09 Feb 2014 07:54:00 +0000</pubDate>
      
      <guid>/questions/29574/wireshark-is-not-detecting-my-wireless-interface/</guid>
      <description>Wireshark is not detecting my Wireless interface&amp;hellip;  0 1I&#39;m using a proprietary wireless interface I installed its drivers but Wireshark is not detecting it I&#39;m using UBUNTU
wireless interface ubuntuasked 09 Feb &#39;14, 07:54
mcool4151
1●1●2●1
accept rate: 0%
 edited 09 Feb &#39;14, 07:56 
grahamb ♦
19.8k●3●30●206
What version of Wireshark, what version of Ubuntu and most importantly what is your wireless card and what drivers are being loaded for it?</description>
    </item>
    
    <item>
      <title>MTU size on Windows machine caused retransmissions and eventual hang.</title>
      <link>/questions/29582/mtu-size-on-windows-machine-caused-retransmissions-and-eventual-hang/</link>
      <pubDate>Sun, 09 Feb 2014 12:05:00 +0000</pubDate>
      
      <guid>/questions/29582/mtu-size-on-windows-machine-caused-retransmissions-and-eventual-hang/</guid>
      <description>MTU size on Windows machine caused retransmissions and eventual hang.  0  FIREWALL (Shorewall, &amp;lt;----------&amp;gt;192.168.0.21 [Linux] DSL Modem---&amp;gt;eth0&amp;lt;===&amp;gt; dnsmasq) &amp;lt;==&amp;gt;eth1&amp;lt;===&amp;gt; 16-PORT &amp;lt;----------&amp;gt;192.168.0.22 [Win7] 192.168.0.1 HUB &amp;lt;----------&amp;gt;192.168.0.xx [Linux] [Debian] &amp;lt;==&amp;gt;wlan0 -----------------------&amp;gt; misc. From the configuration above, and the Wireshark output below, please tell me what&#39;s going on with the Win7 box at 192..22.
The Linux boxes work fine with SSH, SCP and the web. Oddly, no problem on the Win7 box with GMAIL.</description>
    </item>
    
    <item>
      <title>outlook issues</title>
      <link>/questions/29589/outlook-issues/</link>
      <pubDate>Sun, 09 Feb 2014 14:22:00 +0000</pubDate>
      
      <guid>/questions/29589/outlook-issues/</guid>
      <description>outlook issues  0 https://www.cloudshark.org/captures/5c7260923ba4 I have some users at a remote site connection to an exchange server, the users are complaining that Outlooks locks up at times requiring them to reboot and it takes and it takes a very long time to open.
In the trace, I am seeing very long Delta time between the server and the client as they attempt to communicate with each, I am not sure if it is the server responding or the Client, can someone who know much more the me about packet analysis review this trace an let me know what could be the issue Please</description>
    </item>
    
    <item>
      <title>How to determine if encryption is symmetric or asymmetric</title>
      <link>/questions/29590/how-to-determine-if-encryption-is-symmetric-or-asymmetric/</link>
      <pubDate>Sun, 09 Feb 2014 20:11:00 +0000</pubDate>
      
      <guid>/questions/29590/how-to-determine-if-encryption-is-symmetric-or-asymmetric/</guid>
      <description>How to determine if encryption is symmetric or asymmetric  0 I was wondering how to determine if an email that is sent is asymmetrically encrypted or symmetrically encrypted?
symmetric encryption asymmetricasked 09 Feb &#39;14, 20:11
ihavenoidea
11●1●1●2
accept rate: 0% 
I am taking a network security class. We are given these packet captures and asked if it is asymmetric or symmetric encryption. I spent a few hours staring at each packet and have come no close to understanding it.</description>
    </item>
    
    <item>
      <title>Decrypting a 802.11 packets on WPA2-PSK</title>
      <link>/questions/29592/decrypting-a-80211-packets-on-wpa2-psk/</link>
      <pubDate>Sun, 09 Feb 2014 21:21:00 +0000</pubDate>
      
      <guid>/questions/29592/decrypting-a-80211-packets-on-wpa2-psk/</guid>
      <description>Decrypting a 802.11 packets on WPA2-PSK  2 Hi everyone,
First off I&#39;d like to thank everyone for providing such great answers on Q&amp;amp;A, it has really helped me get up and running with Wireshark.
I&#39;m currently running Wireshark 1.10.2 on Lubuntu with wireless drivers that support monitor mode. I&#39;ve verified this by running sudo airmon-ng start mon0 and it has started mon0 on device wlan0.
I&#39;ve been using mon0 to capture network traffic for say 5-10 minutes, I&#39;ve verified that the capture has all 4 packets for the EAPOL protocol so it has captured my wireless handshake completely.</description>
    </item>
    
    <item>
      <title>Disable check for updates and downloads for wireshark 1.11.3</title>
      <link>/questions/29595/disable-check-for-updates-and-downloads-for-wireshark-1113/</link>
      <pubDate>Sun, 09 Feb 2014 23:58:00 +0000</pubDate>
      
      <guid>/questions/29595/disable-check-for-updates-and-downloads-for-wireshark-1113/</guid>
      <description>Disable check for updates and downloads for wireshark 1.11.3  0 Hi,How to disable the check for updates and downloads after installation.Is there any Registry to suppress for this.Please provide the solution for this ASAP as it is urgent requirement
updatesasked 09 Feb &#39;14, 23:58
pkumar
1●2●2●3
accept rate: 0%
  
2 Answers:
  
2To disable the Check for Update after installation use either:
The GUI (GTK version); Edit | Preferences.</description>
    </item>
    
    <item>
      <title>latest version of wireshark for redhat linux</title>
      <link>/questions/29601/latest-version-of-wireshark-for-redhat-linux/</link>
      <pubDate>Mon, 10 Feb 2014 01:36:00 +0000</pubDate>
      
      <guid>/questions/29601/latest-version-of-wireshark-for-redhat-linux/</guid>
      <description>latest version of wireshark for redhat linux  0 when i check for the latest version of wireshark in my redhad linux(Red Hat Enterprise Linux Server release 6.2 (Santiago)) system it showed me this yum list wireshark*
wireshark.x86_64 1.2.15-2.el6_2.1 @rhel-x86_64-server-6.4.z wireshark.i686 1.2.15-2.el6_2.1 rhel-x86_64-server-6.4.z
wireshark-devel.i686 1.2.15-2.el6_2.1 rhel-x86_64-server-optional-6.4.z wireshark-devel.x86_64 1.2.15-2.el6_2.1 rhel-x86_64-server-optional-6.4.z wireshark-gnome.x86_64 1.2.15-2.el6_2.1 rhel-x86_64-server-6.4.z
but on the web site it shows 1.10.5 as the latest stable build
how do i installed the latest stable version of wireshark in redhad linux.</description>
    </item>
    
    <item>
      <title>To find a pinpoint in a Network.</title>
      <link>/questions/29602/to-find-a-pinpoint-in-a-network/</link>
      <pubDate>Mon, 10 Feb 2014 02:08:00 +0000</pubDate>
      
      <guid>/questions/29602/to-find-a-pinpoint-in-a-network/</guid>
      <description>To find a pinpoint in a Network.  0 I have 3 sites, in which I am getting some latency accessing the remote server from third location to first server. Just to elaborate. Lets say, I have three site A, B &amp;amp; C. Flow id from C-&amp;gt;B-&amp;gt;A. where C to B is a point to point connection and B to A is MPLS network. My users from C are accessing servers located at A, for which I am getting some issues.</description>
    </item>
    
    <item>
      <title>How to identify/capture relevant information to troubleshoot a network problem</title>
      <link>/questions/29606/how-to-identifycapture-relevant-information-to-troubleshoot-a-network-problem/</link>
      <pubDate>Mon, 10 Feb 2014 02:46:00 +0000</pubDate>
      
      <guid>/questions/29606/how-to-identifycapture-relevant-information-to-troubleshoot-a-network-problem/</guid>
      <description>How to identify/capture relevant information to troubleshoot a network problem  0 Hi, this is not a technical question it is more a management querstion.
Let&#39;s say you work in an Active Directory enviroment, 50 Users, several Exchange Servers, several Domain Controllers, Printservers, Fileservers etc, the whole nine....
If somebody now has a problem lets say, &#34;my outlook client is sooo slow and freezes&#34;.
it could be anything, maybe the DNS resolves not fast enough which generates a timeout at your outlook, so looking at an exchange &amp;lt;-&amp;gt; Outlook thing would be a waste of time.</description>
    </item>
    
    <item>
      <title>Java API to dissect Wireless Packets captured by Wireshark ( .libcap)</title>
      <link>/questions/29624/java-api-to-dissect-wireless-packets-captured-by-wireshark-libcap/</link>
      <pubDate>Mon, 10 Feb 2014 05:47:00 +0000</pubDate>
      
      <guid>/questions/29624/java-api-to-dissect-wireless-packets-captured-by-wireshark-libcap/</guid>
      <description>Java API to dissect Wireless Packets captured by Wireshark ( .libcap)  0 For my project I am capturing WIRELESS traffic using wireshark ( .cap format ) and I want to read packets in that traffic. So anybody knows Java library that can be used to read contain of the packets ( WIRELESS not ETHERNET )
java capture pcap libpcap wiresharkasked 10 Feb &#39;14, 05:47
WIDS
25●7●7●13
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Bluetooth Low Energy (BLE) packets capture and display</title>
      <link>/questions/29635/bluetooth-low-energy-ble-packets-capture-and-display/</link>
      <pubDate>Mon, 10 Feb 2014 07:48:00 +0000</pubDate>
      
      <guid>/questions/29635/bluetooth-low-energy-ble-packets-capture-and-display/</guid>
      <description>Bluetooth Low Energy (BLE) packets capture and display  0 I am using Nordic BLE sniffer and WireShark together. But I cannot see the other packets except Advertisement packets. How do I see ALL BLE packets?
Thanks,
Sam
bd_samasked 10 Feb &#39;14, 07:48
Sam_Su
1●1●1●1
accept rate: 0%
 edited 10 Feb &#39;14, 21:14 
Guy Harris ♦♦
17.4k●3●35●196
can you please post a capture file somewhere (google drive, dropbox, cloudshark.</description>
    </item>
    
    <item>
      <title>Frame xxx too long</title>
      <link>/questions/29644/frame-xxx-too-long/</link>
      <pubDate>Mon, 10 Feb 2014 10:45:00 +0000</pubDate>
      
      <guid>/questions/29644/frame-xxx-too-long/</guid>
      <description>Frame xxx too long  0 Hi, I&#39;m working on wireshark to sniff the channel on which there are associated some nodes to one coordinator (it&#39;s a wireless sensors network). The tx power is set to 0dB, somentimes it appears an error saying &#34;the frame xxx is too long&#34; and there is the payload (sometimes negative, sometimes positive) into round brackts. I&#39;m tx varying the size of the payload from 5 bytes to 50 bytes, with steps of 5 bytes but I do not know which could be the problem.</description>
    </item>
    
    <item>
      <title>What triggers Retransmission (suspected)?</title>
      <link>/questions/29645/what-triggers-retransmission-suspected/</link>
      <pubDate>Mon, 10 Feb 2014 10:47:00 +0000</pubDate>
      
      <guid>/questions/29645/what-triggers-retransmission-suspected/</guid>
      <description>What triggers Retransmission (suspected)?  0 PCAP linkA newbie to Wireshark, I need a glimmer of understanding to debug a LAN.
The PCAP was taken at firebox. (Please see config. at my initial question..)
TIA,
kirby
suspect retransmissionasked 10 Feb &#39;14, 10:47
kirby
0●2●2●5
accept rate: 0% 
Please see config. at my initial question..
you did not answer my comment, so we still don&#39;t know what your problem might be !</description>
    </item>
    
    <item>
      <title>TCP Stream HTTP</title>
      <link>/questions/29650/tcp-stream-http/</link>
      <pubDate>Mon, 10 Feb 2014 12:47:00 +0000</pubDate>
      
      <guid>/questions/29650/tcp-stream-http/</guid>
      <description>TCP Stream HTTP  0 In &#34;Follow TCP Stream&#34; for http what is the numeric identifier after the 1.1.1.1 as shown below. The destination port I am using is 9999 not 96.
GET / HTTP/1.1 Host: 1.1.1.1:96 User-Agent: Mozilla/5.0 Windows; U; Windows NT 5.1; en-US; rv:1.8.1.4) Gecko/20070515 Firefox/2.0.0.4 Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Connection: closefollow follow.tcp.stream tcpasked 10 Feb &#39;14, 12:47
r24481
1●1●1●1
accept rate: 0%
 edited 11 Feb &#39;14, 00:41</description>
    </item>
    
    <item>
      <title>How to preserve timestamps in tshark output file?</title>
      <link>/questions/29656/how-to-preserve-timestamps-in-tshark-output-file/</link>
      <pubDate>Mon, 10 Feb 2014 18:35:00 +0000</pubDate>
      
      <guid>/questions/29656/how-to-preserve-timestamps-in-tshark-output-file/</guid>
      <description>How to preserve timestamps in tshark output file?  0 I&#39;m using tshark to extract specific TCP streams and write that to an output pcap file using the -w option.
But, the frames in the output pcap do not have any timestamps or delta times (they&#39;re all zero while in the original pcap there are timestamps and delta times for the frames).
Is there any way to ensure that the original timestamps (from the original pcap file) are preserved in the output pcap?</description>
    </item>
    
    <item>
      <title>SCTP: &amp;quot;Protocols in frame&amp;quot; problem</title>
      <link>/questions/29660/sctp-protocols-in-frame-problem/</link>
      <pubDate>Mon, 10 Feb 2014 22:18:00 +0000</pubDate>
      
      <guid>/questions/29660/sctp-protocols-in-frame-problem/</guid>
      <description>SCTP: &amp;ldquo;Protocols in frame&amp;rdquo; problem  0 I am analyzing diameter over sctp packets. There are also vendor specific AVPs included which I have added to the diameter dictionary.
My problem is that I get a different analysis result on two different computers. One is running Windows 8 and the other is running Windows 7, but this might not be relevant. On both computers I have installed &#34;Version 1.10.5 (SVN Rev 54262 from /trunk-1.</description>
    </item>
    
    <item>
      <title>how to Disable wireshark updates and downloads in help menu?</title>
      <link>/questions/29661/how-to-disable-wireshark-updates-and-downloads-in-help-menu/</link>
      <pubDate>Mon, 10 Feb 2014 22:43:00 +0000</pubDate>
      
      <guid>/questions/29661/how-to-disable-wireshark-updates-and-downloads-in-help-menu/</guid>
      <description>how to Disable wireshark updates and downloads in help menu?  0 Hi, Can you folks help me out how to grade out or remove check for updates and downloads in the help menu tab for wirshark.Thanks in Advance
downloads disableasked 10 Feb &#39;14, 22:43
pkumar
1●2●2●3
accept rate: 0%
  
One Answer:
  
1As per my answer to your very similar question to do this you will need to compile your own version of Wireshark, after modifying the source code to remove the menu entries.</description>
    </item>
    
    <item>
      <title>Capturing network packets using a device connected through USB</title>
      <link>/questions/29663/capturing-network-packets-using-a-device-connected-through-usb/</link>
      <pubDate>Tue, 11 Feb 2014 00:02:00 +0000</pubDate>
      
      <guid>/questions/29663/capturing-network-packets-using-a-device-connected-through-usb/</guid>
      <description>Capturing network packets using a device connected through USB  0 I need to capture the packets in the network by connecting a USB device such as mobile phone to the PC. Can someone please tell me whether this is possible or not. If Yes how to do so?
mobile packet-capture usbasked 11 Feb &#39;14, 00:02
Swamy
16●2●2●5
accept rate: 0%
  
One Answer:
  
2It depends on the device and your operating system - and the &#34;</description>
    </item>
    
    <item>
      <title>Retransmission even after receiving ack.</title>
      <link>/questions/29672/retransmission-even-after-receiving-ack/</link>
      <pubDate>Tue, 11 Feb 2014 01:47:00 +0000</pubDate>
      
      <guid>/questions/29672/retransmission-even-after-receiving-ack/</guid>
      <description>Retransmission even after receiving ack.  0 Dear All, We are observing disconnections from source to destination,while capturing i found that client is retransmitting a packet even after it has received ack from server.
retransmissions tcpasked 11 Feb &#39;14, 01:47
kishan pandey
221●28●29●36
accept rate: 28%
 edited 11 Feb &#39;14, 02:15 
grahamb ♦
19.8k●3●30●206
  
One Answer:
  
0Did you verify the ACK numbers and whether SACK options are used?</description>
    </item>
    
    <item>
      <title>Support for detailed PHY info(DL/UL)</title>
      <link>/questions/29680/support-for-detailed-phy-infodlul/</link>
      <pubDate>Tue, 11 Feb 2014 03:21:00 +0000</pubDate>
      
      <guid>/questions/29680/support-for-detailed-phy-infodlul/</guid>
      <description>Support for detailed PHY info(DL/UL)  0 Hi, I want to see detail PHY info which is given in structure mac_lte_info in packet-mac-lte.h.
But I came to know that in packet-mac-lte.c : In function it&#39;s by default disable. I want to use it, is it any other way?
gboolean dissect_mac_lte_context_fields(struct mac_lte_info *p_mac_lte_info, tvbuff_t *tvb, gint *p_offset) { gint offset = *p_offset; guint8 tag = 0; /* Read fixed fields */ p_mac_lte_info-&amp;amp;gt;radioType = tvb_get_guint8(tvb, offset++); p_mac_lte_info-&amp;amp;gt;direction = tvb_get_guint8(tvb, offset++); /* TODO: currently no support for detailed PHY info.</description>
    </item>
    
    <item>
      <title>How to exactly analyze a packet?</title>
      <link>/questions/29685/how-to-exactly-analyze-a-packet/</link>
      <pubDate>Tue, 11 Feb 2014 04:20:00 +0000</pubDate>
      
      <guid>/questions/29685/how-to-exactly-analyze-a-packet/</guid>
      <description>How to exactly analyze a packet?  0 Hi guys, so the real purpose of this program is to analyze a packet right? to determine network problems, test network security, and many other more, and i think this is really intended for those who want or is a network analyst. I just want to ask HOW DO YOU EXACTLY ANALYZE A PACKET? Like, i see a UDP or TCP protocol packet, if i open it, what would i read, or what is my aim to understand each of the line?</description>
    </item>
    
    <item>
      <title>Can&amp;#x27; t see http traffic in monitor mode.</title>
      <link>/questions/29691/can-t-see-http-traffic-in-monitor-mode/</link>
      <pubDate>Tue, 11 Feb 2014 06:10:00 +0000</pubDate>
      
      <guid>/questions/29691/can-t-see-http-traffic-in-monitor-mode/</guid>
      <description>Can&#39; t see http traffic in monitor mode.  0 I used airmon to create monitor interface, when i starting interface monitoring in wireshark i can see only probes, beacons and QoS exchanges. I&#39;m actually testing from two laptops.
httpasked 11 Feb &#39;14, 06:10
Emiliano Riva
11●1●1●3
accept rate: 0%
Some questions:
what is your OS and OS version of the Wireshark system?what is your Wireshark version?how do you capture the traffic (with Wireshark, or other tools)?</description>
    </item>
    
    <item>
      <title>export selected packet bytes / how to cut off the payload in a pcap file?</title>
      <link>/questions/29693/export-selected-packet-bytes-how-to-cut-off-the-payload-in-a-pcap-file/</link>
      <pubDate>Tue, 11 Feb 2014 06:31:00 +0000</pubDate>
      
      <guid>/questions/29693/export-selected-packet-bytes-how-to-cut-off-the-payload-in-a-pcap-file/</guid>
      <description>export selected packet bytes / how to cut off the payload in a pcap file?  0 The File menu option &#34;Export Selected Packet Bytes...&#34; is NOT enabled. What do I need to do to enable it?
bytes selected export packet anonimizationasked 11 Feb &#39;14, 06:31
bundgaj
1●1●1●1
accept rate: 0%
 edited 11 Feb &#39;14, 07:38 
Kurt Knochner ♦
24.8k●10●39●237
This problem exists in both 1.10.5 and 1.11.2</description>
    </item>
    
    <item>
      <title>RTP player wave graph messed up</title>
      <link>/questions/29714/rtp-player-wave-graph-messed-up/</link>
      <pubDate>Tue, 11 Feb 2014 12:44:00 +0000</pubDate>
      
      <guid>/questions/29714/rtp-player-wave-graph-messed-up/</guid>
      <description>RTP player wave graph messed up  0 Hello folks!, i have a question: I work in a telecomunications company, and use to work with Wireshark making telephone call analysis. For some time now, with the latests versions of Wireshark, i have kind of a &#34;visual&#34; problem with the RTP Player. When i deploy a call in the RTP player, it seems good, but when i hit the play button, it plays, but as the time position line advances, it starts messing up the wave graph.</description>
    </item>
    
    <item>
      <title>ONC-RPC SRT values</title>
      <link>/questions/29717/onc-rpc-srt-values/</link>
      <pubDate>Tue, 11 Feb 2014 13:46:00 +0000</pubDate>
      
      <guid>/questions/29717/onc-rpc-srt-values/</guid>
      <description>ONC-RPC SRT values  0 I am running Wireshark version 1.10.0 on Mac OS X 10.9.1.
Displaying ONC-RPC Service Response Time statistics for NFS version 3.
What are the displayed values? Microseconds? Seconds? 10 Microseconds?
Thank you very much.
An amazing tool. Jim
srt onc-rpcasked 11 Feb &#39;14, 13:46
mauroj
11●1●1●2
accept rate: 0%
  
One Answer:
  
0I determined that the values are in seconds.</description>
    </item>
    
    <item>
      <title>What is the best way to parse MPEG2 TS packets with Lua</title>
      <link>/questions/29718/what-is-the-best-way-to-parse-mpeg2-ts-packets-with-lua/</link>
      <pubDate>Tue, 11 Feb 2014 13:51:00 +0000</pubDate>
      
      <guid>/questions/29718/what-is-the-best-way-to-parse-mpeg2-ts-packets-with-lua/</guid>
      <description>What is the best way to parse MPEG2 TS packets with Lua  0 I would like to capture IP stream and then parse MPEG2 TS incapsulated in it, i need to findout CC counters/errors, PCR etc. function tap.packet(pinfo,tvb, calls every IP packet, can i change it to every TS packet?
lua mpegtsasked 11 Feb &#39;14, 13:51
vovka_morkovka
11●1●1●3
accept rate: 0%
 retagged 26 Feb &#39;14, 22:03 
Hadriel</description>
    </item>
    
    <item>
      <title>Network Drop both Wireless and Wired</title>
      <link>/questions/29722/network-drop-both-wireless-and-wired/</link>
      <pubDate>Tue, 11 Feb 2014 16:06:00 +0000</pubDate>
      
      <guid>/questions/29722/network-drop-both-wireless-and-wired/</guid>
      <description>Network Drop both Wireless and Wired  0 I&#39;m writing on behalf of a small school district. In early January, a colleague and myself installed 20 Ubiquiti Unifi AP-Pro devices as well as about 20, 10/100/1000 hp procurve switches. Two schools are connected by Cisco Aironet. Towards the end of January we started experiencing high latency and network drop throughout the district. I am in over my head trying to troubleshoot and someone pointed me to Wireshark.</description>
    </item>
    
    <item>
      <title>Promiscuous capture mode not working on OS X</title>
      <link>/questions/29723/promiscuous-capture-mode-not-working-on-os-x/</link>
      <pubDate>Tue, 11 Feb 2014 18:27:00 +0000</pubDate>
      
      <guid>/questions/29723/promiscuous-capture-mode-not-working-on-os-x/</guid>
      <description>Promiscuous capture mode not working on OS X  0 I just downloaded and started using Wireshark 1.10.5 on OS X 10.8.5 (Macbook Pro Retina), but Promiscuous Mode capture doesn&#39;t seem to be working; I only see packets to/from my laptop.
I&#39;ve been consulting the wiki. The Wi-Fi network I&#39;m associated with is what I&#39;m interested in capturing. It uses WPA2 but this question suggests I should still be able to see the physical packets listed, just as encrypted.</description>
    </item>
    
    <item>
      <title>No Query in wireshark packets</title>
      <link>/questions/29724/no-query-in-wireshark-packets/</link>
      <pubDate>Tue, 11 Feb 2014 19:55:00 +0000</pubDate>
      
      <guid>/questions/29724/no-query-in-wireshark-packets/</guid>
      <description>No Query in wireshark packets  0 Hi Team,
I am not able to find the query packets in my wireshark trace, I always get the first packet as response not matter what i do. I flushed the dns, clear the browser cache tried from browser as well as from the cli nslookup option, Still doesnot work.
Thanks Irfan
dns dnsqueryasked 11 Feb &#39;14, 19:55
arshmohd
1●2●2●2
accept rate: 0%</description>
    </item>
    
    <item>
      <title>How to dissect user data from rtps2 protocol?</title>
      <link>/questions/29725/how-to-dissect-user-data-from-rtps2-protocol/</link>
      <pubDate>Tue, 11 Feb 2014 20:28:00 +0000</pubDate>
      
      <guid>/questions/29725/how-to-dissect-user-data-from-rtps2-protocol/</guid>
      <description>How to dissect user data from rtps2 protocol?  0 I am using OpenSplice DDS and wants to retrieve user data from wireshark. Can you please let me know how to retrieve the same?
ddsasked 11 Feb &#39;14, 20:28
Usha
1●1●1●1
accept rate: 0%
  
One Answer:
  
0You can use tshark
tshark -nr input.pcap -Y &#34;rtps&#34; -T fields -e frame.number -e rtps.param.userData
See the Real-Time Publish-Subscribe Wire Protocol display filter reference for more fields.</description>
    </item>
    
    <item>
      <title>How to distinguish optional IEs with the same type in ANSI-MAP message TransferToNumberRequestRes</title>
      <link>/questions/29728/how-to-distinguish-optional-ies-with-the-same-type-in-ansi-map-message-transfertonumberrequestres/</link>
      <pubDate>Tue, 11 Feb 2014 21:33:00 +0000</pubDate>
      
      <guid>/questions/29728/how-to-distinguish-optional-ies-with-the-same-type-in-ansi-map-message-transfertonumberrequestres/</guid>
      <description>How to distinguish optional IEs with the same type in ANSI-MAP message TransferToNumberRequestRes  0 Specially, this message has got two IEs with the same type, and they both are optional:
-- TransferToNumberRequest RETURN RESULT Parameters TransferToNumberRequestRes ::= [PRIVATE 18] SET { digits-Destination [4] IMPLICIT Digits OPTIONAL, -- (Destination) M 6.5.2.58 a ... -- O 6.5.2.25 e, f digits-Carrier [4] IMPLICIT Digits OPTIONAL, ... }Given the nature of ASN.1 set type, the question is:</description>
    </item>
    
    <item>
      <title>wireshark filter for finding url of live stream video</title>
      <link>/questions/29730/wireshark-filter-for-finding-url-of-live-stream-video/</link>
      <pubDate>Tue, 11 Feb 2014 22:15:00 +0000</pubDate>
      
      <guid>/questions/29730/wireshark-filter-for-finding-url-of-live-stream-video/</guid>
      <description>wireshark filter for finding url of live stream video  0 I have an url: http://www.mayapur.tv/newTemples/index.php?stream=Chowpatty/@Chowpatty
If i open in the browser it shows the the streaming video. I cant get the url of the stream video from the http headers or the html code.
I there any way to find the address of the streamvideo comming using wireshark. I dont know how to check tcp things in wireshark
livecapturetcpasked 11 Feb &#39;14, 22:15</description>
    </item>
    
    <item>
      <title>A problem with parsing SCTP chunk with more than 1 Diameter messages</title>
      <link>/questions/29732/a-problem-with-parsing-sctp-chunk-with-more-than-1-diameter-messages/</link>
      <pubDate>Tue, 11 Feb 2014 22:42:00 +0000</pubDate>
      
      <guid>/questions/29732/a-problem-with-parsing-sctp-chunk-with-more-than-1-diameter-messages/</guid>
      <description>A problem with parsing SCTP chunk with more than 1 Diameter messages  0 1Hi all,
I encountered a problem when analyzing a SCTP packet capture file. There are 2 Diameter messages in one SCTP chunk, but wireshark can only parse and display the first one. I can locate the second message in the bottom binary window but can&#39;t see it in the middle packet detail window.
I found some specification say there couldn&#39;t be more than 1 message in one chunk.</description>
    </item>
    
    <item>
      <title>How to handle exceptions on Linux</title>
      <link>/questions/29733/how-to-handle-exceptions-on-linux/</link>
      <pubDate>Tue, 11 Feb 2014 23:28:00 +0000</pubDate>
      
      <guid>/questions/29733/how-to-handle-exceptions-on-linux/</guid>
      <description>How to handle exceptions on Linux  0 Tshark handles exceptions/assertion failures on Windows, but on Linux, it will crash on exceptions/assertion failures, how to do?
exception crashasked 11 Feb &#39;14, 23:28
metamatrix
56●16●16●19
accept rate: 100%
can you please show an example where tshark on Windows fails &#39;in a better/different way&#39; than on Linux?
(12 Feb &#39;14, 00:39) Kurt Knochner ♦e.g. packet-frame.c ln 491
 /* Win32: Visual-C Structured Exception Handling (SEH) to trap hardware exceptions like memory access violations.</description>
    </item>
    
    <item>
      <title>g728 silence bit</title>
      <link>/questions/29738/g728-silence-bit/</link>
      <pubDate>Wed, 12 Feb 2014 01:06:00 +0000</pubDate>
      
      <guid>/questions/29738/g728-silence-bit/</guid>
      <description>g728 silence bit  0 I am trying to insert silence between voice packets for G728 codec. I need help for the silence hex value.
g728 rtpasked 12 Feb &#39;14, 01:06
rahulhgowda
1●2●2●2
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>SMTP Filter over NLB</title>
      <link>/questions/29742/smtp-filter-over-nlb/</link>
      <pubDate>Wed, 12 Feb 2014 01:48:00 +0000</pubDate>
      
      <guid>/questions/29742/smtp-filter-over-nlb/</guid>
      <description>SMTP Filter over NLB  0 Hi,
I am trying to filter packets using Wireshark 1.10.5. but am facing some issues and need help. I have two IIS web servers &#34;A&#34; (Primary) and &#34;B&#34; on NLB which has shared web application hosted on it. These web applications sends out mails to users via a smtp mail server and I need to capture this mails.
I set simple capture filter on both the servers for &#34;</description>
    </item>
    
    <item>
      <title>Using tcprewrite seed only with source IP</title>
      <link>/questions/29743/using-tcprewrite-seed-only-with-source-ip/</link>
      <pubDate>Wed, 12 Feb 2014 01:52:00 +0000</pubDate>
      
      <guid>/questions/29743/using-tcprewrite-seed-only-with-source-ip/</guid>
      <description>Using tcprewrite seed only with source IP  0 Hi, I use tcprewrite command to randomize the IPs of different pcaps:
tcprewrite --seed=$RANDOM --infile=a.pcap --outfile=B.pcap
This changes IPs of both source of destination. Is there anyway I can limit this change to source IPs or destination IPs alone and not both?
tcprewrite tcpdump tcpreplayasked 12 Feb &#39;14, 01:52
rorolia
1●1●1●1
accept rate: 0%
  
2 Answers:</description>
    </item>
    
    <item>
      <title>Syn with ECN flag set on certain port number</title>
      <link>/questions/29758/syn-with-ecn-flag-set-on-certain-port-number/</link>
      <pubDate>Wed, 12 Feb 2014 05:26:00 +0000</pubDate>
      
      <guid>/questions/29758/syn-with-ecn-flag-set-on-certain-port-number/</guid>
      <description>Syn with ECN flag set on certain port number  0 I&#39;m facing issue with an embedded device webpage. Webpage of the device works fine when used directly in local intranet but when its behind one corporate firewall it becomes extensively slow. When i wireshark the packets i found
Client PC sends packets in different source port but embedded devices receives it in different portFirefox opens 6 concurrent connections to the embedded device and those ports open and work normallyafter 1-2 second i see SYN request with ECN flag set.</description>
    </item>
    
    <item>
      <title>How to filter gsm map messages in Tshark</title>
      <link>/questions/29760/how-to-filter-gsm-map-messages-in-tshark/</link>
      <pubDate>Wed, 12 Feb 2014 06:03:00 +0000</pubDate>
      
      <guid>/questions/29760/how-to-filter-gsm-map-messages-in-tshark/</guid>
      <description>How to filter gsm map messages in Tshark  0 Trying GSM_MAP and TCAP filter using tshark but Tshark is not giving any result command used
tshark -r &amp;lt;inputfilename&amp;gt; -T fields -e gsm_old.localValue
Anyone please let me know what filter to use in tshark for gsm_map
soloasked 12 Feb &#39;14, 06:03
Ezhra
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>tshark -z follow stops after missing package</title>
      <link>/questions/29761/tshark-z-follow-stops-after-missing-package/</link>
      <pubDate>Wed, 12 Feb 2014 06:03:00 +0000</pubDate>
      
      <guid>/questions/29761/tshark-z-follow-stops-after-missing-package/</guid>
      <description>tshark -z follow stops after missing package  0 I analyze .pcap and .cap files using tshark&#39;s -z follow option. This works mighty fine on most of the streams, however in some streams I get there can be one or more missing/broken packages. In this case the -z option prints only the content up to the first missing/damaged package and everything after that is skipped. How can I get tshark to continue after the missing packets?</description>
    </item>
    
    <item>
      <title>FIN ACK after sent packet</title>
      <link>/questions/29782/fin-ack-after-sent-packet/</link>
      <pubDate>Wed, 12 Feb 2014 08:47:00 +0000</pubDate>
      
      <guid>/questions/29782/fin-ack-after-sent-packet/</guid>
      <description>FIN ACK after sent packet  0 I&#39;m implementing the ssh ftp protocol to connect to an sftp server on port 22 and I keep getting a FIN ACK from the server after I send either a ssh binary packet SSH_KEX_MSG_DH_GEX_REQUEST or an SSH_MSG_KEXINIT, which seems to close the connection. I want to keep the connection open so that I can establish the server authentication. What could be causing this?</description>
    </item>
    
    <item>
      <title>11ac capture from macbook pro</title>
      <link>/questions/29786/11ac-capture-from-macbook-pro/</link>
      <pubDate>Wed, 12 Feb 2014 09:43:00 +0000</pubDate>
      
      <guid>/questions/29786/11ac-capture-from-macbook-pro/</guid>
      <description>11ac capture from macbook pro  0 I am noticing that phy rates are not always being decoded properly and wondered if there was a fix in the works. iPhone 5S supports and is connected to 40MHz channel but only reports PHY RATE of 72.2, which is not correct. There are also other times when it doesnt report any rates at all.
Thoughts? I have tried PPI and RadioTap.
802.11acasked 12 Feb &#39;14, 09:43</description>
    </item>
    
    <item>
      <title>PcapNg and Wireless Data</title>
      <link>/questions/29788/pcapng-and-wireless-data/</link>
      <pubDate>Wed, 12 Feb 2014 10:09:00 +0000</pubDate>
      
      <guid>/questions/29788/pcapng-and-wireless-data/</guid>
      <description>PcapNg and Wireless Data  0 For my project ( Wireless Envoirment ) I am Capturing traffic using wireshark and saving it in PcapNg format. Later I want to retrieve this information to get network layer and above layer information. But PcapNg man page says { Features not yet in pcap-ng:-&amp;gt; Wireless spectrum information / physical layer meta-data } So as I dont want information about physical layer data. Though Can I get network layer wireless data from pcap-ng file.</description>
    </item>
    
    <item>
      <title>bad argument #1 to &amp;#x27;get_index&amp;#x27; (index out of range) in Wireshark Lua dissector</title>
      <link>/questions/29825/bad-argument-1-to-get_index-index-out-of-range-in-wireshark-lua-dissector/</link>
      <pubDate>Thu, 13 Feb 2014 02:00:00 +0000</pubDate>
      
      <guid>/questions/29825/bad-argument-1-to-get_index-index-out-of-range-in-wireshark-lua-dissector/</guid>
      <description>bad argument #1 to &amp;lsquo;get_index&amp;rsquo; (index out of range) in Wireshark Lua dissector  0 In my dissector I have this code
local defaultdata = data_tvb():bytes() local newdata = ByteArray.new() newdata:set_size(defaultdata:len()) for i=0,defaultdata:len()-2 do local var = bit.band((bit.lshift(defaultdata:get_index(i), 1) + bit.rshift(defaultdata:get_index(i+1), 7)), 0xff) newdata:set_index(i, var) end local var = bit.band((bit.lshift(defaultdata:get_index(defaultdata:len()-1), 1) + bit.rshift(defaultdata:get_index(0), 7)), 0xff) newdata:set_index(defaultdata:len()-1,var) data_tvb = ByteArray.tvb(newdata, &amp;quot;Decoded&amp;quot;) endMy problem is in second bitwise operation in get_index function.</description>
    </item>
    
    <item>
      <title>SCTP and DIAMETER fragmentation issue</title>
      <link>/questions/29827/sctp-and-diameter-fragmentation-issue/</link>
      <pubDate>Thu, 13 Feb 2014 03:19:00 +0000</pubDate>
      
      <guid>/questions/29827/sctp-and-diameter-fragmentation-issue/</guid>
      <description>SCTP and DIAMETER fragmentation issue  0 There is an inter-dependency between SCTP- and DIAMETER-protocol analysis in case of fragmented packets.
When the preferences for SCTP protocl are set to &#34;Reassemble fragmented SCTP user messages&#34; the packet is shown as &#34;SCTP SACK DATA (Message Fragment).
When the &#34;Reassemble fragmented SCTP user messages&#34; is deactivated in the preferences for SCTP protocl then the packet is shown as DIAMETER message, but it cannot be fully presented.</description>
    </item>
    
    <item>
      <title>FIX protocol capturing</title>
      <link>/questions/29829/fix-protocol-capturing/</link>
      <pubDate>Thu, 13 Feb 2014 05:51:00 +0000</pubDate>
      
      <guid>/questions/29829/fix-protocol-capturing/</guid>
      <description>FIX protocol capturing  0 Hello,
Is it possible to capture in tshark the dump which:
contains FIX protocol packets onlycapturing without decodingIf yes, which capture-filter needs to be applied?
Thanks in advance!
fix capture-filter tsharkasked 13 Feb &#39;14, 05:51
mrav
16●4●4●8
accept rate: 0%
 edited 13 Feb &#39;14, 06:10 
  
One Answer:
  
1Every FIX message starts with the string &#39;8=FIX&#39;, followed by a version number.</description>
    </item>
    
    <item>
      <title>How to dissect TCP stream which emits multiple packets</title>
      <link>/questions/29831/how-to-dissect-tcp-stream-which-emits-multiple-packets/</link>
      <pubDate>Thu, 13 Feb 2014 07:41:00 +0000</pubDate>
      
      <guid>/questions/29831/how-to-dissect-tcp-stream-which-emits-multiple-packets/</guid>
      <description>How to dissect TCP stream which emits multiple packets  0 I&#39;am writing dissector for protocol over TCP stream which can emit more than one packet per real TCP frame. For example lets assume that we have ethernet tunnel over TCP stream, and one TCP frame of length 15000 bytes (assume the capture with TSO on) can contain five or ten embedded ethernet packets. So I can successfully dissect this stream, can write info about each packet to frame tree.</description>
    </item>
    
    <item>
      <title>Sort while live capture</title>
      <link>/questions/29832/sort-while-live-capture/</link>
      <pubDate>Thu, 13 Feb 2014 09:04:00 +0000</pubDate>
      
      <guid>/questions/29832/sort-while-live-capture/</guid>
      <description>Sort while live capture  0 Hello,
Is it possible to sort (by any column) while running a live traffic capture ?
sort capture liveasked 13 Feb &#39;14, 09:04
Afrim
160●10●11●16
accept rate: 22%
  
One Answer:
  
2 I don&#39;t think so, at least it never worked for me when I tried. It&#39;s not very wise to do that anyway because more packets are coming in all the time and would require constant resorting.</description>
    </item>
    
    <item>
      <title>disable transport decode</title>
      <link>/questions/29833/disable-transport-decode/</link>
      <pubDate>Thu, 13 Feb 2014 09:43:00 +0000</pubDate>
      
      <guid>/questions/29833/disable-transport-decode/</guid>
      <description>disable transport decode  0 I know how to configure a specific data transport ( say tcpip both( 2255 &amp;lt;-&amp;gt; 9120 ) as some protocol. I just want it disabled so that it doesn&#39;t try to decode something it isn&#39;t supposed to. it&#39;s just raw data.
wiresharkasked 13 Feb &#39;14, 09:43
Joe Florida
1●1●1●1
accept rate: 0%
  
One Answer:
  
0Unfortunately, there&#39;s no way to do that, other than disabling whatever protocols the data is being dissected as, which is not very convenient.</description>
    </item>
    
    <item>
      <title>Lua Dissector.get can&amp;#x27;t find an existing dissector.</title>
      <link>/questions/29841/lua-dissectorget-cant-find-an-existing-dissector/</link>
      <pubDate>Thu, 13 Feb 2014 13:27:00 +0000</pubDate>
      
      <guid>/questions/29841/lua-dissectorget-cant-find-an-existing-dissector/</guid>
      <description>Lua Dissector.get can&amp;rsquo;t find an existing dissector.  0 I&#39;m building a LUA dissector. I want to run another dissector on the data before i continue examining the data but i am failing miserably. I have tried this with 1.10.5 and 1.11.2 and it fails in either case. This line of code is failing, (i am trying to mimic what the docs do, but obviously the docs are less than adequate):</description>
    </item>
    
    <item>
      <title>rtp and sip trafic</title>
      <link>/questions/29842/rtp-and-sip-trafic/</link>
      <pubDate>Thu, 13 Feb 2014 13:32:00 +0000</pubDate>
      
      <guid>/questions/29842/rtp-and-sip-trafic/</guid>
      <description>rtp and sip trafic  0 I sniff the traffic between client machines sip but I click on player decode and then I get no result I do not know where is the problem. knowing that I use sip client installed on a virtual machine and another on the physical machine and the attacker uses a machine back track 4 r1. any one cab help me !
rasadabasked 13 Feb &#39;14, 13:32</description>
    </item>
    
    <item>
      <title>How to set capture-filter for l2tp control packets</title>
      <link>/questions/29853/how-to-set-capture-filter-for-l2tp-control-packets/</link>
      <pubDate>Thu, 13 Feb 2014 21:39:00 +0000</pubDate>
      
      <guid>/questions/29853/how-to-set-capture-filter-for-l2tp-control-packets/</guid>
      <description>How to set capture-filter for l2tp control packets  0 Hello
I&#39;m newbie to Wireshark, not sure if it&#39;s known question or issue. I use &#34;l2tp.sid==0&#34; to set display-filter to filter l2tp control packets and work well. but it was failed to work w/ capture-filter w/ syntax error. Could anybody to let me know if it&#39;s possible to set such capture-filter and how if the answer is yes, thanks in advance!</description>
    </item>
    
    <item>
      <title>user interface, fourth window</title>
      <link>/questions/29865/user-interface-fourth-window/</link>
      <pubDate>Fri, 14 Feb 2014 04:06:00 +0000</pubDate>
      
      <guid>/questions/29865/user-interface-fourth-window/</guid>
      <description>user interface, fourth window  0 I&#39;ve got a simple question about wireshark&#39;s layout. I would like to know if is it possible to insert a fourth window in the user interface. We would like to add a topology of a sensor net and i dont found any reference in internet about it.
interface window add userasked 14 Feb &#39;14, 04:06
lina
11●3●3●5
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Find ip from skype and bluestack</title>
      <link>/questions/29872/find-ip-from-skype-and-bluestack/</link>
      <pubDate>Fri, 14 Feb 2014 11:02:00 +0000</pubDate>
      
      <guid>/questions/29872/find-ip-from-skype-and-bluestack/</guid>
      <description>Find ip from skype and bluestack  0 Hi
Can anyone help me to sort this out, i want to see incoming ip&#39;s when i use those programmes
newbieasked 14 Feb &#39;14, 11:02
mad666
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Is &amp;quot;VLAN double-tagged&amp;quot; the same thing as &amp;#x27;VLAN stacked&amp;#x27;?</title>
      <link>/questions/29875/is-vlan-double-tagged-the-same-thing-as-vlan-stacked/</link>
      <pubDate>Fri, 14 Feb 2014 16:55:00 +0000</pubDate>
      
      <guid>/questions/29875/is-vlan-double-tagged-the-same-thing-as-vlan-stacked/</guid>
      <description>Is &amp;ldquo;VLAN double-tagged&amp;rdquo; the same thing as &amp;lsquo;VLAN stacked&amp;rsquo;?  0 Is a packet having 2 &#39;802.1Q&#39; headers equivalent to that?
Or can anyone provide me an example packet demonstrating double-tagged vs. stacked?
vlanasked 14 Feb &#39;14, 16:55
techynewbie
11●2●2●3
accept rate: 0%
  
One Answer:
  
0Yes it&#39;s the same, also called Q-in-Q, according to the standard 802.1ad.
Is a packet having 2 &#39;802.1Q&#39; headers equivalent to that?</description>
    </item>
    
    <item>
      <title>Manually obtain value string by value</title>
      <link>/questions/29879/manually-obtain-value-string-by-value/</link>
      <pubDate>Fri, 14 Feb 2014 21:08:00 +0000</pubDate>
      
      <guid>/questions/29879/manually-obtain-value-string-by-value/</guid>
      <description>Manually obtain value string by value  0 I would like to obtain the value string for a specific value manually (to display it in the COL_INFO column) by it&#39;s value. I could manually iterate over my value string mapping, however I think there might also be an official API for this task.
dissector value_stringasked 14 Feb &#39;14, 21:08
athre0z
16●1●1●4
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>question on ARP</title>
      <link>/questions/29880/question-on-arp/</link>
      <pubDate>Fri, 14 Feb 2014 22:15:00 +0000</pubDate>
      
      <guid>/questions/29880/question-on-arp/</guid>
      <description>question on ARP  0 Can someone help me, wht this question mean? and how can i get the answer? How many bytes from the very beginning of the Ethernet frame does the ARP opcode field begin?
arpasked 14 Feb &#39;14, 22:15
popo88
1●1●1●1
accept rate: 0% 
1I found the answer to that question here
http://bit.ly/1c91E9t
(15 Feb &#39;14, 03:14) Kurt Knochner ♦  
One Answer:</description>
    </item>
    
    <item>
      <title>wifi wep security</title>
      <link>/questions/29885/wifi-wep-security/</link>
      <pubDate>Sat, 15 Feb 2014 06:00:00 +0000</pubDate>
      
      <guid>/questions/29885/wifi-wep-security/</guid>
      <description>wifi wep security  0 anyone know how to crack a wifi wep security?
wifi wiresharkasked 15 Feb &#39;14, 06:00
serbesamoves
1●1●1●1
accept rate: 0%
  
One Answer:
  
1http://www.wikihow.com/Break-WEP-Encryption
answered 15 Feb &#39;14, 06:02
Jasper ♦♦
23.8k●5●51●284
accept rate: 18%
is this working?
(15 Feb &#39;14, 06:12) serbesamovesSure. The &#34;BackTrack&#34; live CD is now called &#34;Kali&#34;, but breaking WEP is no rocket science.
(15 Feb &#39;14, 09:30) Jasper ♦♦     </description>
    </item>
    
    <item>
      <title>Looking up NFS errors</title>
      <link>/questions/29888/looking-up-nfs-errors/</link>
      <pubDate>Sat, 15 Feb 2014 07:01:00 +0000</pubDate>
      
      <guid>/questions/29888/looking-up-nfs-errors/</guid>
      <description>Looking up NFS errors  0 I would like to know how can I find some specific NFS server error using tcpdump analysis with wireshark. I am specifically interested in finding if the NFS server is returning NFS3ERR_BADHANDLE = 10001 or NFS3ERR_IO = 5 when issuing a read request.
I am also unable to &#34;follow tcp stream&#34; for a NFS READ request to see what the server returned for that request.</description>
    </item>
    
    <item>
      <title>No Right Click When Trying to Copy Cookie</title>
      <link>/questions/29900/no-right-click-when-trying-to-copy-cookie/</link>
      <pubDate>Sat, 15 Feb 2014 21:53:00 +0000</pubDate>
      
      <guid>/questions/29900/no-right-click-when-trying-to-copy-cookie/</guid>
      <description>No Right Click When Trying to Copy Cookie  0 I can&#39;t copy a cookie when I am trying to. No contextual menu pops up. I am using a mac and X11. I am clicking command + click to right click....anything I can do?
asapasked 15 Feb &#39;14, 21:53
QwertyHacker
1●1●1●1
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Export protocol change</title>
      <link>/questions/29901/export-protocol-change/</link>
      <pubDate>Sun, 16 Feb 2014 01:01:00 +0000</pubDate>
      
      <guid>/questions/29901/export-protocol-change/</guid>
      <description>Export protocol change  0 Hi guys,
Strange one; I&#39;ve captured a couple of packets from a windows 7 (embedded) machine, using wireshark for windows. Made an export to analyze the data on my mac, but it strangely &#39;converts&#39; a couple of HTTP packets to TCP and make the /GET unreadable.
Is there an explanation for this, or this is this some sort of bug? (googled and searched here, but couldn&#39;t find related articles.</description>
    </item>
    
    <item>
      <title>Running Wireshark continuously</title>
      <link>/questions/29902/running-wireshark-continuously/</link>
      <pubDate>Sun, 16 Feb 2014 01:27:00 +0000</pubDate>
      
      <guid>/questions/29902/running-wireshark-continuously/</guid>
      <description>Running Wireshark continuously  1 For my project I want Wireshark to directly start saving packets as I start it. I need packets in plain text file format ( 2. is there automatic exporting possible by doing any setting in wireshark ? ) How above two can be done .....save export plain-text wiresharkasked 16 Feb &#39;14, 01:27
WIDS
25●7●7●13
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Is it possible in wireshark and t-shark to capture only data frame ( in monitor mode) for WIRELESS network?</title>
      <link>/questions/29903/is-it-possible-in-wireshark-and-t-shark-to-capture-only-data-frame-in-monitor-mode-for-wireless-network/</link>
      <pubDate>Sun, 16 Feb 2014 02:09:00 +0000</pubDate>
      
      <guid>/questions/29903/is-it-possible-in-wireshark-and-t-shark-to-capture-only-data-frame-in-monitor-mode-for-wireless-network/</guid>
      <description>Is it possible in wireshark and t-shark to capture only data frame ( in monitor mode) for WIRELESS network?  0 Want to capture only data frame on wireless network ( avoiding management and control frame )
wireless frame data tshark wiresharkasked 16 Feb &#39;14, 02:09
WIDS
25●7●7●13
accept rate: 0%
  
One Answer:
  
0Please try this
tcpdump -ni mon0 &#39;wlan type data&#39;
dumpcap -ni mon0 -f &#39;wlan type data&#39;</description>
    </item>
    
    <item>
      <title>Strange TCP RST with sslscan</title>
      <link>/questions/29913/strange-tcp-rst-with-sslscan/</link>
      <pubDate>Sun, 16 Feb 2014 07:47:00 +0000</pubDate>
      
      <guid>/questions/29913/strange-tcp-rst-with-sslscan/</guid>
      <description>Strange TCP RST with sslscan  0 I&#39;m using sslscan to scan a https-site for supported SSL/TLS-versions. If I scan the site via IPv4 I noticed strange pauses between the scans of the different cipher suits. I then scaned the host via IPv6 and no pauses. I then run tcpdump and discovered some strange RST, TCP Retransmission and TCP DUP ACK?!?. Have a look at the capture file, especialy starting at line number 63.</description>
    </item>
    
    <item>
      <title>Total Fields can be exported to CSV file</title>
      <link>/questions/29921/total-fields-can-be-exported-to-csv-file/</link>
      <pubDate>Sun, 16 Feb 2014 21:52:00 +0000</pubDate>
      
      <guid>/questions/29921/total-fields-can-be-exported-to-csv-file/</guid>
      <description>Total Fields can be exported to CSV file  0 Hi All, I am working on tshark -T option to export fields to .csv file. I successfully performed the conversion using tshark -r input.pcap -T fields -e field_name -E separator=,
I have tried field name ip.src , ip.dst and frame.number. I would like to know the all field names which I can use in exporting .csv file.
Thanks,
field csv tsharkasked 16 Feb &#39;14, 21:52</description>
    </item>
    
    <item>
      <title>How to recover the analyzing process after crashing</title>
      <link>/questions/29923/how-to-recover-the-analyzing-process-after-crashing/</link>
      <pubDate>Sun, 16 Feb 2014 23:39:00 +0000</pubDate>
      
      <guid>/questions/29923/how-to-recover-the-analyzing-process-after-crashing/</guid>
      <description>How to recover the analyzing process after crashing  0 I modified a tshark version to filter the packets that I concerned, and record them in files. When tshark crashes or has no response, I want to recover the analyzing process at next tshark start up. How to record and recover the index info in minimum modifies? Any ideas?
recover crashasked 16 Feb &#39;14, 23:39
metamatrix
56●16●16●19
accept rate: 100%</description>
    </item>
    
    <item>
      <title>No Check Box For &amp;quot;Enable Concurrent DNS Name Resolution&amp;quot;</title>
      <link>/questions/29924/no-check-box-for-enable-concurrent-dns-name-resolution/</link>
      <pubDate>Sun, 16 Feb 2014 23:54:00 +0000</pubDate>
      
      <guid>/questions/29924/no-check-box-for-enable-concurrent-dns-name-resolution/</guid>
      <description>No Check Box For &amp;ldquo;Enable Concurrent DNS Name Resolution&amp;rdquo;  0 When I try to click the check box for &#34;Enable Concurrent DNS Name Resolution&#34;, there is no box, it says N/A. How would I go about fixing this?
Enable Concurrent DNS Name Resolution: N/A
That is all I get when attempting to check it.
concurrent enable dns errorasked 16 Feb &#39;14, 23:54
cenbhildress
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Simple HTTP conversation | time breakdown</title>
      <link>/questions/29925/simple-http-conversation-time-breakdown/</link>
      <pubDate>Mon, 17 Feb 2014 01:53:00 +0000</pubDate>
      
      <guid>/questions/29925/simple-http-conversation-time-breakdown/</guid>
      <description>Simple HTTP conversation | time breakdown  0 Hi,
I&#39;m trying to understand the time breakdown for a simple HTTP conversation. I&#39;ve Shared capture file http-png-wireshark.pcapng, uploaded at: https://drive.google.com/file/d/0BwRchYLsDMZiRE5wakNQVmpkODQ/edit?usp=sharing
Please select the first filter: (ip.addr eq 192.168.43.92 and ip.addr eq 162.159.241.165) and (tcp.port eq 50117 and tcp.port eq 80)
The HTTP request is: http://www.wireshark.org/assets/images/hero_sprite.png
Frame 30 is HTTP GET request. Please explain the time spent between: Frame 30-&amp;gt;35 (219ms) - see the DeltaConv column Frame 35-&amp;gt;36 (18ms) Frame 39-41 (196ms)</description>
    </item>
    
    <item>
      <title>Decrypting SSL Traffic in Wireshark processed by sslsniff</title>
      <link>/questions/29936/decrypting-ssl-traffic-in-wireshark-processed-by-sslsniff/</link>
      <pubDate>Mon, 17 Feb 2014 08:24:00 +0000</pubDate>
      
      <guid>/questions/29936/decrypting-ssl-traffic-in-wireshark-processed-by-sslsniff/</guid>
      <description>Decrypting SSL Traffic in Wireshark processed by sslsniff  0 Hi there,
to analyze some application, which are using https to communicate i had set up a little proxy which redirects the traffic to sslsniff and forwards it afterwards.
Currently i&#39;m running sslsniff in authority mode with a self signed CA. In this mode sslsniff automatically generates mathing certificates which are then signed with the own CA.
The tool works fine, unfortunately parsing the output is a little bit nasty, since sslsniff drops the traffic simply as a txt file instead of dumping all traffic in a valid pcap file.</description>
    </item>
    
    <item>
      <title>Follow related connections</title>
      <link>/questions/29938/follow-related-connections/</link>
      <pubDate>Mon, 17 Feb 2014 11:11:00 +0000</pubDate>
      
      <guid>/questions/29938/follow-related-connections/</guid>
      <description>Follow related connections  0 I am somewhat familiar with TCP WireShark, etc. Mediocore I guess. I have a question: Many times I get spam mail from whomever. I am a curious fellow and wonder what the source of it is. Many times I get a link to click on so I can, according the instructions, log in to fix up my userid/password. Yeah, right. I know it&#39;s not probably recommended, but I fire up WireShark and try to follow what happens when I click such a link.</description>
    </item>
    
    <item>
      <title>Please help selecting interface</title>
      <link>/questions/29943/please-help-selecting-interface/</link>
      <pubDate>Mon, 17 Feb 2014 13:44:00 +0000</pubDate>
      
      <guid>/questions/29943/please-help-selecting-interface/</guid>
      <description>Please help selecting interface  0 There is only Ethernet interface. i want windows interface for listen online game packets
i installed and runned it via adminastrator what can be problem ??
this is picture of problem http://postimg.org/image/adgzdk8c9/
interfaceasked 17 Feb &#39;14, 13:44
Ali Anıl Yücel
1●1●1●2
accept rate: 0%
 edited 18 Feb &#39;14, 03:59 
Jaap ♦
11.7k●16●101
  
One Answer:
  
2Ali, There is no problem in the picture - it shows the normal start options dialogue interface.</description>
    </item>
    
    <item>
      <title>tshark string</title>
      <link>/questions/29949/tshark-string/</link>
      <pubDate>Mon, 17 Feb 2014 21:22:00 +0000</pubDate>
      
      <guid>/questions/29949/tshark-string/</guid>
      <description>tshark string  0 hi all, How to extract only tcp streams containing a specific string to single pcap file using tshark.
editsharkasked 17 Feb &#39;14, 21:22
kishan pandey
221●28●29●36
accept rate: 28%
  
One Answer:
  
3tshark on Windows (DOS box):
tshark -nr input.pcap -Y &#34;frame contains &#34;&#34;HTTP/1.0&#34;&#34;&#34; -w output.pcap
Tripple quote (&#34;&#34;&#34;) is intentional!
tshark on Linux:
tshark -nr input.pcap -Y &#39;frame contains &#34;HTTP/1.0&#34;&#39; -w output.</description>
    </item>
    
    <item>
      <title>LAN TO WAN Network Sniffing</title>
      <link>/questions/29950/lan-to-wan-network-sniffing/</link>
      <pubDate>Mon, 17 Feb 2014 22:08:00 +0000</pubDate>
      
      <guid>/questions/29950/lan-to-wan-network-sniffing/</guid>
      <description>LAN TO WAN Network Sniffing  0 So I&#39;m fairly new to packet sniffing, I am tech savvy to an extent.
What I am trying to do is monitor all network traffic between my router and the WAN.
(specifically I&#39;m trying to see if I can sniff iMessage Data off my iPhone when connected to my home wifi)
can I use wireshark connect to the LAN or do I have to route LAN traffic through my computer running wire shark then to the WAN?</description>
    </item>
    
    <item>
      <title>How to get Jitter density and Packet Loss Density out of captured pcap file?</title>
      <link>/questions/29951/how-to-get-jitter-density-and-packet-loss-density-out-of-captured-pcap-file/</link>
      <pubDate>Mon, 17 Feb 2014 22:20:00 +0000</pubDate>
      
      <guid>/questions/29951/how-to-get-jitter-density-and-packet-loss-density-out-of-captured-pcap-file/</guid>
      <description>How to get Jitter density and Packet Loss Density out of captured pcap file?  1 I have captured Pcap files. I want to know what is Jitter Density and Packet Loss Density. Can some one share Method / script to analyze this? Also explain how exactly we can get this.
pcap jitter tsharkasked 17 Feb &#39;14, 22:20
Ravikumar Ma...
26●1●1●3
accept rate: 0%
By jitter density do you mean the statistical density function?</description>
    </item>
    
    <item>
      <title>Sniff facebook  cookie</title>
      <link>/questions/29961/sniff-facebook-cookie/</link>
      <pubDate>Tue, 18 Feb 2014 01:50:00 +0000</pubDate>
      
      <guid>/questions/29961/sniff-facebook-cookie/</guid>
      <description>Sniff facebook cookie  0 Hi i&#34;ve tried the sniffing on facebook and getting the cookie the thing is i dont get any packets that contain it i use the filter http.cookie and i see nothing maybe its not working anymore since facebook is on https no matter what settings you use? everything else is captured ok i see all the packets just not the cookie any idea?
facebookasked 18 Feb &#39;14, 01:50</description>
    </item>
    
    <item>
      <title>Traces GSM USSD messages</title>
      <link>/questions/29964/traces-gsm-ussd-messages/</link>
      <pubDate>Tue, 18 Feb 2014 05:46:00 +0000</pubDate>
      
      <guid>/questions/29964/traces-gsm-ussd-messages/</guid>
      <description>Traces GSM USSD messages  0 Hi All, I work for a GSM operator. I am troubleshooting a USSD issue on my network. I don&#39;t know which filter i should use to see the messages relative to my USSD request. Please help me.
telecomasked 18 Feb &#39;14, 05:46
maximengame
11●1●1●2
accept rate: 0%
If it doesn&#39;t contain sensitive data, could you upload an example packet capture file and post the link (http://cloudshark.</description>
    </item>
    
    <item>
      <title>Speed of capture in monitor mode</title>
      <link>/questions/29967/speed-of-capture-in-monitor-mode/</link>
      <pubDate>Tue, 18 Feb 2014 06:25:00 +0000</pubDate>
      
      <guid>/questions/29967/speed-of-capture-in-monitor-mode/</guid>
      <description>Speed of capture in monitor mode  0 I have one doubt about the speed of packets capture in monitor mode. If i have a 300mbps usb wifi adapter in monitor mode, what is the max speed of packet capture?
The 300mbps of my adapter is associated with the 802.11n network, if i connect in 802.11g network, the speed gonna be lower, but in monitor mode, how this works!?
Thanks!!</description>
    </item>
    
    <item>
      <title>Capture packets before the VPN encryption</title>
      <link>/questions/29969/capture-packets-before-the-vpn-encryption/</link>
      <pubDate>Tue, 18 Feb 2014 07:18:00 +0000</pubDate>
      
      <guid>/questions/29969/capture-packets-before-the-vpn-encryption/</guid>
      <description>Capture packets before the VPN encryption  0 Hi,
I&#39;m using a softphone which registers to a IP PBX using a L2TP/IPSEC VPN. When I try to capture the packets sent, I only see the EPS Packets... But The packets are being sent from my PC, so I should be able to capture them BEFORE the encryption takes place, right? How can I do it?
Is there any alternative solution?</description>
    </item>
    
    <item>
      <title>Monitor Network Device for Drop Outs</title>
      <link>/questions/29970/monitor-network-device-for-drop-outs/</link>
      <pubDate>Tue, 18 Feb 2014 08:22:00 +0000</pubDate>
      
      <guid>/questions/29970/monitor-network-device-for-drop-outs/</guid>
      <description>Monitor Network Device for Drop Outs  0 I would like to set up a watch on a network device to see if it drops of the network. We just installed a new Fiber Converter and I want to make sure the connection is stable.
Thanks
Lee
monitorasked 18 Feb &#39;14, 08:22
LeeV
11●1●1●2
accept rate: 0% 
  
2 Answers:
  
0That is not a question.</description>
    </item>
    
    <item>
      <title>Complete pcap.h with IPv6 support?</title>
      <link>/questions/29971/complete-pcaph-with-ipv6-support/</link>
      <pubDate>Tue, 18 Feb 2014 09:00:00 +0000</pubDate>
      
      <guid>/questions/29971/complete-pcaph-with-ipv6-support/</guid>
      <description>Complete pcap.h with IPv6 support?  0 For manually parsing .pcap files, I have found header files. But, they don&#39;t seem to have the IPv6 structures. I actually did find a place that had the definition of the IPv6 header. But, I&#39;m not sure if that is all I need. I&#39;m not sure if, when using IPv6, the TCP and UDP headers are the same as IPv4. It didn&#39;t look like it, but, it is conceivable that I was in error.</description>
    </item>
    
    <item>
      <title>Custom Dissector using an external library</title>
      <link>/questions/29981/custom-dissector-using-an-external-library/</link>
      <pubDate>Tue, 18 Feb 2014 11:54:00 +0000</pubDate>
      
      <guid>/questions/29981/custom-dissector-using-an-external-library/</guid>
      <description>Custom Dissector using an external library  0 I have built a dissector in the windows os and everything works as planned. I have converted the dissector and the associated libraries to build on RHEL6. I have got it to the point where Wireshark is built and the plugin and everything else is built. When I run Wireshark I get the error message that it &#34;Couldn&#39;t load module /usr/local/lib/wireshark/plugins/1.11.2/mypluginname: undefined symbol functionname&#34;</description>
    </item>
    
    <item>
      <title>keyboard overtyping</title>
      <link>/questions/29987/keyboard-overtyping/</link>
      <pubDate>Tue, 18 Feb 2014 15:24:00 +0000</pubDate>
      
      <guid>/questions/29987/keyboard-overtyping/</guid>
      <description>keyboard overtyping  0 Hi - I have a situation where what I am writing is being &#34;over-written&#34; while I am writing it.
Let me give a quick examples: &#34;Hi guys how are you doing?&#34; as I am writing would be perhaps be changed to: &#34;Hi guts hoe are you doimg?&#34; Typically the changes are single-letter mistypes, so they appear like I am making keyboard errors, but I am not making these errors.</description>
    </item>
    
    <item>
      <title>Capture filter for IP address in PPP-over-double-tagged-Ethernet traffic</title>
      <link>/questions/29988/capture-filter-for-ip-address-in-ppp-over-double-tagged-ethernet-traffic/</link>
      <pubDate>Tue, 18 Feb 2014 15:42:00 +0000</pubDate>
      
      <guid>/questions/29988/capture-filter-for-ip-address-in-ppp-over-double-tagged-ethernet-traffic/</guid>
      <description>Capture filter for IP address in PPP-over-double-tagged-Ethernet traffic  0 OK, I give up--been bangin&#39; my head against this one for awhile now. I know how it SHOULD work, but something&#39;s wrong. I am sniffing a trunk carrying double-tagged traffic on a distribution switch with massive amounts of data, so I don&#39;t have the liberty of capturing all packets and then doing a display filter. I need to capture a single IP address (using the WS GUI, not TShark), so I enter &#34;</description>
    </item>
    
    <item>
      <title>capture windows named pipe traffic such as &amp;#92;pipe&amp;#92;lsarpc, &amp;#92;pipe&amp;#92;netlogon, &amp;#92;pipe&amp;#92;samr</title>
      <link>/questions/29991/capture-windows-named-pipe-traffic-such-as-pipelsarpc-pipenetlogon-pipesamr/</link>
      <pubDate>Tue, 18 Feb 2014 17:48:00 +0000</pubDate>
      
      <guid>/questions/29991/capture-windows-named-pipe-traffic-such-as-pipelsarpc-pipenetlogon-pipesamr/</guid>
      <description>capture windows named pipe traffic such as \pipe\lsarpc, \pipe\netlogon, \pipe\samr  0 I have a server that has named pipe such as \pipe\lsarpc, \pipe\netlogon, \pipe\samr,
I need to decommission the server and wanted to know if any clients are still connecting thru those named pipes and which clients are connecting via it and doing what.
And also to see if any clients are still be authenticated thru that server.
Appreciated very much for any assistance.</description>
    </item>
    
    <item>
      <title>Follow stream and realtime display only after entering preferences</title>
      <link>/questions/29994/follow-stream-and-realtime-display-only-after-entering-preferences/</link>
      <pubDate>Wed, 19 Feb 2014 00:47:00 +0000</pubDate>
      
      <guid>/questions/29994/follow-stream-and-realtime-display-only-after-entering-preferences/</guid>
      <description>Follow stream and realtime display only after entering preferences  0 Hi,
I am using WS 1.11.3-1673 etc. When starting capture my details pane doesn&#39;t show realtime packetbytes. Only when I enter &#34;Preferences&#34; and click &#34;Ok&#34; the latest frame and corresponding details and bytes are shown. It makes no difference if my view is &#34;Expanded&#34;.
Kind regards,
Loe
real-timeasked 19 Feb &#39;14, 00:47
Loe Walter
41●3●3●6
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>TCP window size on Windows Server 2008 and FTP transfer</title>
      <link>/questions/29998/tcp-window-size-on-windows-server-2008-and-ftp-transfer/</link>
      <pubDate>Wed, 19 Feb 2014 02:38:00 +0000</pubDate>
      
      <guid>/questions/29998/tcp-window-size-on-windows-server-2008-and-ftp-transfer/</guid>
      <description>TCP window size on Windows Server 2008 and FTP transfer  0 Hello,
I&#39;m currently doing a performance analyis about FTP transfer to two Servers. PROD server : Win 2008 TEST server : Win 2008 R2 Latency between client and server : ~140ms (RTT ~280ms)
Doing several transfer with the TEST server it appears something strange. The TCP Windows size is never the same. I discover the new automatic mechanism on Win 2008 to define the TCP window size by using a factor.</description>
    </item>
    
    <item>
      <title>Bad use of mine WIRESHARK how do do ?</title>
      <link>/questions/29999/bad-use-of-mine-wireshark-how-do-do/</link>
      <pubDate>Wed, 19 Feb 2014 03:02:00 +0000</pubDate>
      
      <guid>/questions/29999/bad-use-of-mine-wireshark-how-do-do/</guid>
      <description>Bad use of mine WIRESHARK how do do ?  0 Hello at all ; Sorry for my english but be not good . But thanks for the translate on the website :) So I used a VNP who on my reseau internet inside my pc a passerelle ! Impossible te delete this .All my antivirus find nothing. Be horified !! i Do a formatage computer again it !I do lots and lots surchs on the web try lots of all .</description>
    </item>
    
    <item>
      <title>NetScaler to Pcap</title>
      <link>/questions/30000/netscaler-to-pcap/</link>
      <pubDate>Wed, 19 Feb 2014 03:38:00 +0000</pubDate>
      
      <guid>/questions/30000/netscaler-to-pcap/</guid>
      <description>NetScaler to Pcap  0 Hi,
I have a script in order to apply a lot of test about one trace that I give in the argument of script. Today, I have to add the feature of support traces of NetScaler and My script work in libpcap format. So I have tried to convert netscaler trace to libcap format with wireshark because I am know that wireshark support this format but, I have been able to change the format.</description>
    </item>
    
    <item>
      <title>dos attack ip</title>
      <link>/questions/30014/dos-attack-ip/</link>
      <pubDate>Wed, 19 Feb 2014 07:30:00 +0000</pubDate>
      
      <guid>/questions/30014/dos-attack-ip/</guid>
      <description>dos attack ip  0 Hello recently my game server is getting dos attacks everyday, so would it be possible to track real IP address of attacker with wireshark? Or it is not possible? Discovered wireshark few days ago :-))
dosasked 19 Feb &#39;14, 07:30
Ignas
1●1●1●2
accept rate: 0%
 edited 19 Feb &#39;14, 07:39 
Kurt Knochner ♦
24.8k●10●39●237
fixed smiley, as discovering Wireshark should make you smile ;-)</description>
    </item>
    
    <item>
      <title>TCP retransmissions with additional payload data?</title>
      <link>/questions/30019/tcp-retransmissions-with-additional-payload-data/</link>
      <pubDate>Wed, 19 Feb 2014 09:23:00 +0000</pubDate>
      
      <guid>/questions/30019/tcp-retransmissions-with-additional-payload-data/</guid>
      <description>TCP retransmissions with additional payload data?  1 I&#39;m seeing exactly what the question suggests - TCP retransmissions in which the retransmitted packet has more payload data than does the original transmission. In other words, packet A has X bytes of data when originally transmitted, but the retransmitted packet A has X+Y bytes of data.
I&#39;ve found one or two references that simply say, &#34;Oh, that&#39;s perfectly acceptable,&#34; but they provide no references to definitive information on the subject.</description>
    </item>
    
    <item>
      <title>How do I monitor disk i/o using wireshark</title>
      <link>/questions/30032/how-do-i-monitor-disk-io-using-wireshark/</link>
      <pubDate>Wed, 19 Feb 2014 13:30:00 +0000</pubDate>
      
      <guid>/questions/30032/how-do-i-monitor-disk-io-using-wireshark/</guid>
      <description>How do I monitor disk i/o using wireshark  0 Can someone provide the exact steps to monitor disk I/o?
I currently have a Server 2003 R2 Server with wireshark installed, about 8pm every day the server freezes for around 5mins, this is the period where everyone logs off in the evening.
disk ioasked 19 Feb &#39;14, 13:30
unrealone
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>HL7 Msgs Capture</title>
      <link>/questions/30037/hl7-msgs-capture/</link>
      <pubDate>Wed, 19 Feb 2014 21:54:00 +0000</pubDate>
      
      <guid>/questions/30037/hl7-msgs-capture/</guid>
      <description>HL7 Msgs Capture  0 I&#39;m trying to capture HL7 msgs on the ip and port but can&#39;t see them in the capture. Any direction on this. thanks tony
hl7 caputureasked 19 Feb &#39;14, 21:54
TVolpe
11●1●1●2
accept rate: 0%
can you please add some details how you tried to capture, meaning your capture setup
OS and Wireshark versioninterfaces LAN, WAN, etc.where did you capture: client, server, switchdid you use any capture filters(20 Feb &#39;14, 00:49) Kurt Knochner ♦Is that &#34;</description>
    </item>
    
    <item>
      <title>using wireshark to find out communication with specific application</title>
      <link>/questions/30040/using-wireshark-to-find-out-communication-with-specific-application/</link>
      <pubDate>Thu, 20 Feb 2014 02:46:00 +0000</pubDate>
      
      <guid>/questions/30040/using-wireshark-to-find-out-communication-with-specific-application/</guid>
      <description>using wireshark to find out communication with specific application  0 for example I have one SAP webclient application running on my box using wireshark I want to find out when client connects to that SAP server and does all communication, which ports it use and all communication process from start to end.
Thanks for help in advance.
sapasked 20 Feb &#39;14, 02:46
m_1607
35●12●13●16
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Decoding UDP packets sent by Cisco AP in real time.</title>
      <link>/questions/30041/decoding-udp-packets-sent-by-cisco-ap-in-real-time/</link>
      <pubDate>Thu, 20 Feb 2014 03:15:00 +0000</pubDate>
      
      <guid>/questions/30041/decoding-udp-packets-sent-by-cisco-ap-in-real-time/</guid>
      <description>Decoding UDP packets sent by Cisco AP in real time.  0 Hello,
We&#39;d like to know if it&#39;s possible to decode UDP packets sent by Cisco APs on port 5555 in command line and also apply a filter for probe requests. If so, what would be the syntax?. Thanks in advance.
Kind Regards, Enrique
peekremoteasked 20 Feb &#39;14, 03:15
eroques
11●1●1●2
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>What OSI layer protocols are examined, layer 4, 3 and 2 or all three?</title>
      <link>/questions/30045/what-osi-layer-protocols-are-examined-layer-4-3-and-2-or-all-three/</link>
      <pubDate>Thu, 20 Feb 2014 08:17:00 +0000</pubDate>
      
      <guid>/questions/30045/what-osi-layer-protocols-are-examined-layer-4-3-and-2-or-all-three/</guid>
      <description>What OSI layer protocols are examined, layer 4, 3 and 2 or all three?  0 I&#39;m a newbie to wireshark, being a networking student at a nearby technical college. What protocols are examined in layers 4 to 2?
protocolsasked 20 Feb &#39;14, 08:17
BreakingBad
11●2●2●3
accept rate: 0%
  
One Answer:
  
2You need to work a bit on your Google Fu. A quick search found lots of hits comparing tcpip and OSI, e.</description>
    </item>
    
    <item>
      <title>Ethernet packets with no L2 information when using Cisco Embedded Packet Capture</title>
      <link>/questions/30049/ethernet-packets-with-no-l2-information-when-using-cisco-embedded-packet-capture/</link>
      <pubDate>Thu, 20 Feb 2014 11:19:00 +0000</pubDate>
      
      <guid>/questions/30049/ethernet-packets-with-no-l2-information-when-using-cisco-embedded-packet-capture/</guid>
      <description>Ethernet packets with no L2 information when using Cisco Embedded Packet Capture  0 Odd activity identified and a packet capture performed in which the packets had not L2 information with minimal L3 information. I was not aware that such a packet would be allowed to traverse ethernet switches. The unit was sending approximately 5,000,000 packets at a rate of 30,000pps within 3 minutes and repeating at a very regular interval of every 30 minutes.</description>
    </item>
    
    <item>
      <title>Extract pcap email attachment - Defcon 2011 Challenge Round 2 help</title>
      <link>/questions/30056/extract-pcap-email-attachment-defcon-2011-challenge-round-2-help/</link>
      <pubDate>Thu, 20 Feb 2014 13:47:00 +0000</pubDate>
      
      <guid>/questions/30056/extract-pcap-email-attachment-defcon-2011-challenge-round-2-help/</guid>
      <description>Extract pcap email attachment - Defcon 2011 Challenge Round 2 help  0 1Hi All,
Before everyone tells me to Google, I have. I have seen write-ups with solutions that say &#34;extract the pcap&#34; and I have seen search results on how to extract word docs etc over smtp. I am still struggling to follow the solution to Round 2 of this challenge(http://forensicscontest.com/contest0...011-Contest.tc). I am new to packet analysis so bear with me please.</description>
    </item>
    
    <item>
      <title>What protocols does wireshark examine?</title>
      <link>/questions/30061/what-protocols-does-wireshark-examine/</link>
      <pubDate>Thu, 20 Feb 2014 16:22:00 +0000</pubDate>
      
      <guid>/questions/30061/what-protocols-does-wireshark-examine/</guid>
      <description>What protocols does wireshark examine?  0 What protocols does wireshark examine and at what layers?
protocolsasked 20 Feb &#39;14, 16:22
BreakingBad
11●2●2●3
accept rate: 0%
  
One Answer:
  
1What protocols does wireshark examine
These. Note that they have parenthetical notes after them indicating which particular versions of Wireshark handle the protocol in question; newer versions add newer protocols.
and at what layers?
OSI layers 2 through 7.</description>
    </item>
    
    <item>
      <title>How to analyze very large pcapng file?</title>
      <link>/questions/30064/how-to-analyze-very-large-pcapng-file/</link>
      <pubDate>Thu, 20 Feb 2014 17:31:00 +0000</pubDate>
      
      <guid>/questions/30064/how-to-analyze-very-large-pcapng-file/</guid>
      <description>How to analyze very large pcapng file?  0 I have a very large pcapng file (about 21GB), and I want to analyze the file in wireshark. Should I split it into small files with editcap? Can editcap handle such a large file? If not, how to do?
very large analyze fileasked 20 Feb &#39;14, 17:31
metamatrix
56●16●16●19
accept rate: 100%
  
2 Answers:
  
1 editcap should be able to handle the file and it think it&#39;s absolutely necessary to split or pre-filter the file, as there is no way to load a 21GB file into wireshark or tshark.</description>
    </item>
    
    <item>
      <title>Why is Wireshark trying to connect to 162.159.242.165 ???</title>
      <link>/questions/30065/why-is-wireshark-trying-to-connect-to-162159242165/</link>
      <pubDate>Thu, 20 Feb 2014 17:56:00 +0000</pubDate>
      
      <guid>/questions/30065/why-is-wireshark-trying-to-connect-to-162159242165/</guid>
      <description>Why is Wireshark trying to connect to 162.159.242.165 ???  0 I have just openend a capture session and looking at the packets go by I get TLS connections to 162.159.242.165. Whois resolves to Cloudfare and blog.wireshark.org. WTF?
http://162.159.242.165.ipaddress.com/ http://blog.wireshark.org.ipaddress.com/ http://www.herdprotect.com/ip-address-162.159.242.165.aspx
162.159.242.165 whois wiresharkasked 20 Feb &#39;14, 17:56
Leinad
11●1●1●2
accept rate: 0%
(20 Feb &#39;14, 17:58) Leinad  
One Answer:
  
1Note that this address is also used by the main site:</description>
    </item>
    
    <item>
      <title>Wireshark on Ubuntu not decrypting Wi-Fi WPA2 packets from AP to station</title>
      <link>/questions/30068/wireshark-on-ubuntu-not-decrypting-wi-fi-wpa2-packets-from-ap-to-station/</link>
      <pubDate>Thu, 20 Feb 2014 19:56:00 +0000</pubDate>
      
      <guid>/questions/30068/wireshark-on-ubuntu-not-decrypting-wi-fi-wpa2-packets-from-ap-to-station/</guid>
      <description>Wireshark on Ubuntu not decrypting Wi-Fi WPA2 packets from AP to station  1 Hi,
I&#39;m been SOMEWHAT SUCCESSFUL in having wireshark on ubuntu decrypt wi-fi packets encrypted with WPA2, but the wi-fi frames FROM THE AP TO THE STATION BEING MONITORED ARE NOT BEING DECRYPTED. The wi-fi frames FROM THE STATION BEING MONITORED TO THE AP ARE BEING DECRYPTED. I have attached a wireshark screenshot of the capture.
Just for clarity, note that I CAN DECRYPT THE SAMPLE CAPTURE FILE mentioned in the wireshark wi-fi wiki decrypt page and I do see 2-way traffic being decrypted.</description>
    </item>
    
    <item>
      <title>Capture HL7 router validation setting errors in a custom table?</title>
      <link>/questions/30074/capture-hl7-router-validation-setting-errors-in-a-custom-table/</link>
      <pubDate>Thu, 20 Feb 2014 23:14:00 +0000</pubDate>
      
      <guid>/questions/30074/capture-hl7-router-validation-setting-errors-in-a-custom-table/</guid>
      <description>Capture HL7 router validation setting errors in a custom table?  0 Capture HL7 router validation setting errors in a custom table?
hl7 routerasked 20 Feb &#39;14, 23:14
bhgetsingh
(suspended)
accept rate: 0%
   </description>
    </item>
    
    <item>
      <title>Export packet to csv</title>
      <link>/questions/30078/export-packet-to-csv/</link>
      <pubDate>Fri, 21 Feb 2014 03:22:00 +0000</pubDate>
      
      <guid>/questions/30078/export-packet-to-csv/</guid>
      <description>Export packet to csv  0 Hi,
When I try to export packet as csv Wireshark crashes.
I haven&#39;t found information in bug list or I missed it. Is there a bug or it only happend to me ? My revision is 54437.
csv export packetasked 21 Feb &#39;14, 03:22
Afrim
160●10●11●16
accept rate: 22%
Can you post the capture file containing the packet(s) that you&#39;re trying to export to CSV?</description>
    </item>
    
    <item>
      <title>Having this code error after installing : 0xc000007b</title>
      <link>/questions/30082/having-this-code-error-after-installing-0xc000007b/</link>
      <pubDate>Fri, 21 Feb 2014 06:24:00 +0000</pubDate>
      
      <guid>/questions/30082/having-this-code-error-after-installing-0xc000007b/</guid>
      <description>Having this code error after installing : 0xc000007b  0 Hello everyone !
First, my computer have Windows 7 64bits. Just after installing Wireshark, when I try to start it, I get an error with the code 0xc000007b. Does anyone know where is the problem ?
EDIT : I forgot to write it down but I downloaded the 64bit version on the website, so that should not be the problem.</description>
    </item>
    
    <item>
      <title>SSL decryption requiring 2 SSL certs, and sequence matters?</title>
      <link>/questions/30085/ssl-decryption-requiring-2-ssl-certs-and-sequence-matters/</link>
      <pubDate>Fri, 21 Feb 2014 09:16:00 +0000</pubDate>
      
      <guid>/questions/30085/ssl-decryption-requiring-2-ssl-certs-and-sequence-matters/</guid>
      <description>SSL decryption requiring 2 SSL certs, and sequence matters?  0 We have an encrypted IIS web server -&amp;gt; IIS app server trace. Encryption is not 2 way, so the cert comes only from the app server side.
In order to decrypt the trace, I have to add the pre-go_live cert ( for &#34;myURL-temp.company.com&#34;) to my SSL preferences first, then add in the post-go_live cert (myURL.company.com ) Then I can decrypt the traffic.</description>
    </item>
    
    <item>
      <title>Merge files &#43; identifying Ip ID&amp;#x27;s</title>
      <link>/questions/30087/merge-files-identifying-ip-ids/</link>
      <pubDate>Fri, 21 Feb 2014 09:40:00 +0000</pubDate>
      
      <guid>/questions/30087/merge-files-identifying-ip-ids/</guid>
      <description>Merge files + identifying Ip ID&amp;rsquo;s  0 Hello,
I have client and server side captures, and I have merged them to find the matching Identification ID&#39;s. I used that as column and tested. There are about 100k of packets where am I have hard time to find the packets matching. I used Statistics &amp;gt; Compare.. but did not get good information.
Needed your inputs to achieve this.
Regards Prabh</description>
    </item>
    
    <item>
      <title>retransmittion timer</title>
      <link>/questions/30097/retransmittion-timer/</link>
      <pubDate>Sat, 22 Feb 2014 04:41:00 +0000</pubDate>
      
      <guid>/questions/30097/retransmittion-timer/</guid>
      <description>retransmittion timer  0 Hello everyone, Yesterday my colleagues bring one issue of slow database response,there were 2 windows application servers and one of them was working fine and one had a problem.after taking capture from both of them i found that server which had no problem was responding in 23 sec and problematic servers was taking 43 seconds,after further drill i found that both server had few retransmittion but in working server retransmittion was happening in 2 sec(constant) whereas in problematic server it was above 4 seconds and 2 of them were above 9 seconds.</description>
    </item>
    
    <item>
      <title>Plotting graphs for network delay</title>
      <link>/questions/30100/plotting-graphs-for-network-delay/</link>
      <pubDate>Sat, 22 Feb 2014 12:03:00 +0000</pubDate>
      
      <guid>/questions/30100/plotting-graphs-for-network-delay/</guid>
      <description>Plotting graphs for network delay  0 Hi, i&#39;m a newbie in wireshark. i have a &#34;.pcap&#34; file that contains a VoIP call. I wana know the network delay of this call for each packet. I can see the delay (the time taken by packets to reach the destination) but i wana plot this data on graph. does wireshark have capability to give me the graph? if NO, then what tool should i use?</description>
    </item>
    
    <item>
      <title>quotation mark within a quotation mark</title>
      <link>/questions/30101/quotation-mark-within-a-quotation-mark/</link>
      <pubDate>Sat, 22 Feb 2014 13:35:00 +0000</pubDate>
      
      <guid>/questions/30101/quotation-mark-within-a-quotation-mark/</guid>
      <description>quotation mark within a quotation mark  0 OK, so I know if I want to search for specific word I type: something contains &#34;wanted word&#34;.
But now I would like to find a word which is within quotations in a packet, but if I put double quotations like this &#34;&#34;wanted word&#34;&#34; the filter turns red as it is invalid command.
So is there a way to find word that is actually within quotation marks?</description>
    </item>
    
    <item>
      <title>the tcp stream analyzing</title>
      <link>/questions/30104/the-tcp-stream-analyzing/</link>
      <pubDate>Sun, 23 Feb 2014 02:48:00 +0000</pubDate>
      
      <guid>/questions/30104/the-tcp-stream-analyzing/</guid>
      <description>the tcp stream analyzing  0 this is a tcp stream for a client(app,not brower),the content is about SSL handshake,but this is no client publickey,why?and what is the &#34;AuthnToken&#34; meaning?is it the client publickey or signatrue?how can i find the clientpravitekey on my computer?
Any help or pointers would be greatly appreciated!
ClientRand:WN39UqcGva4NNtZh0IVBGbIIe4ebdOuWLQqpI6IZyaM=
ServerRand:ZN39Ut8wEybFu7Vsl2RuT6BHaKugXxfxZQmeonItxyA ServerPublicKey:BAAAAAEAAQCAAAAAEUYJdXyMoc6BsY+yp9Sjv3Tx9HIQEOblctoXhbYUrGSosYrTP/RmdwJgzBzX6bT0bNoA9m1A1GNkFoSrqOnRHMN2hPlGTpMhvCvJ4H4GVtf5HW1mlSM2OeqgGSPle4O2aNYDNPR8ejziCizaD1sr7rfbUDr+cTAny0lz/I0b2aA= ServerSignature:eV8xRM7NpjAjzwn4QslI07azcz0gd0QltYvZrXKp3DxxTvvjdpqZ+krjjkTkdCEuFdgI5KPVoKuo4CnS+03r/RaIDiJKvWBfFQwuM2Fevtn7v6F1MoLSmm7bKJTwDakr8qWWhQJIVpT7g0Uuc6IWCPItS+CIoBkkSisoVGY8m9TUQR3WRQt4mxbna0zz7Tl7EgEISpvT5iY677IPoXvk9UV5nXG8sP9mr848s4Lei2ZJbZQl6qkxHkFnfBgc8d0d7qf6bxLOwzu79Tfajkk6HqEV0adGmmw8aQyT2b/+RJtGAyLUNIsXIg1mEc8hepC80Xzx81BT45TNkFNbmPkGLw==
PremasterSecret:zcmUJjgjwnxPSZ3En8EvT4CPB6+g1wGR/05pDGbZDMnSjibiQ8RsCG7LQOnmTsbMo/skZScWxcXpRvsXC/YPH+nD1cZMvTc6Z2r+lv42jYHc0ZK2GYs9IB5uzoVgSdQLHxRdZ3wHHkiIuTivdBII3ZW5J9w8+T7r/c/cXA6nwlY= AuthnToken:Gk8BVW04iJKg/74Awq8LCwiVA0ije/ySVdifqq2zdyIClxwlAXqzkOPrbX6czbOL78IMtlGGWkd/pxVlcEQtEU8C3MECTI2ljMlhkEzklhr9FKDy9vKfaDs15bO3RmT1YRFxgYwY1524uoxXX3Dt1ICePzn1WbUOdj6sIGcoUq375gaobLJTFvH5Re0we+mRM7DYq+cl8Md5u226xGawWarfEl3y9cx9lTrNuOSWJ8h/klkU/lQ7/wApi4Tqxx7HLaDsFXnmgqRJmusQ3lJL+MjUNZ16W1dgRy6fBJTMwSBHtx1qwlcPC4/uOjyL16ctugoEh6WqSzaQLqsqLOx7WnermgmxJ97BfMd1uK58MhlT0/3fGevptRMOlfSdjkkmIcRAxwfk8BY3mP8HWTru++5DZJHTQAS+CbS6L5BSsfNfkVTPKWfDIbK/AfkYvAUTxma0kSHf7RrX2YDXx+cqDDu0pDMUD4dNMpoMcSkZmngocVurbek2nvH99/WJXeEj AppId:b0d42105-0cb6-bc9f-3cb2-be28a0662340
the analyzing stream tcpasked 23 Feb &#39;14, 02:48
barrney
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Adding the Http Referer to the packet summary line</title>
      <link>/questions/30108/adding-the-http-referer-to-the-packet-summary-line/</link>
      <pubDate>Sun, 23 Feb 2014 10:43:00 +0000</pubDate>
      
      <guid>/questions/30108/adding-the-http-referer-to-the-packet-summary-line/</guid>
      <description>Adding the Http Referer to the packet summary line  0 Hey folks, for a project I want to add the Http Referer to the packet summary line and export as plaine text. Is there any possibility to do that? I can only find the &#34;Info Column&#34; in the column prefences and that&#39;s tottaly messing up my table. thanks a lot Max
referer http columns plain-textThis question is marked &#34;community wiki&#34;</description>
    </item>
    
    <item>
      <title>Show IPV4 instead of IPV6 in Wireshark 1.10.xx (Mac)</title>
      <link>/questions/30110/show-ipv4-instead-of-ipv6-in-wireshark-110xx-mac/</link>
      <pubDate>Sun, 23 Feb 2014 17:05:00 +0000</pubDate>
      
      <guid>/questions/30110/show-ipv4-instead-of-ipv6-in-wireshark-110xx-mac/</guid>
      <description>Show IPV4 instead of IPV6 in Wireshark 1.10.xx (Mac)  0 Hi, as the title said, I&#39;d like to see ipv4 instead of ipv6 in my columns. Is there a quick way set it? Also, being new to this particular technology, I was wondering if there is simple way to export the summary list of website names/uri, time, source ip (v4)? Many thanks.
uri ipv4 ipv6asked 23 Feb &#39;14, 17:05</description>
    </item>
    
    <item>
      <title>Display decrypted WLAN traffic that has the Protected bit set</title>
      <link>/questions/30115/display-decrypted-wlan-traffic-that-has-the-protected-bit-set/</link>
      <pubDate>Sun, 23 Feb 2014 19:46:00 +0000</pubDate>
      
      <guid>/questions/30115/display-decrypted-wlan-traffic-that-has-the-protected-bit-set/</guid>
      <description>Display decrypted WLAN traffic that has the Protected bit set  0 I have APs that can capture Radiotap packets before/after encryption/decryption, so they&#39;re in plaintext. Is it possible to have wireshark de-encapsulate the data packets so I can see what protocols are being used?
I&#39;ve uploaded an example capture to Cloudshark, it&#39;s an iPad associating and visiting http://bbcnews.com/. At packet 198 you can see a DNS request, 199 is the response, then 206 is an HTTP request.</description>
    </item>
    
    <item>
      <title>Email function</title>
      <link>/questions/30118/email-function/</link>
      <pubDate>Mon, 24 Feb 2014 00:36:00 +0000</pubDate>
      
      <guid>/questions/30118/email-function/</guid>
      <description>Email function  0 I want to use wireshark to monitor the network of my computer, it should be 7X24. I hope that if wireshark sniffed certain packets thus send the alert email to me. Is it possible to do that? How can I do that?
emailasked 24 Feb &#39;14, 00:36
saiwlam2
1●1●1●1
accept rate: 0%
1Lett&#39;s law in effect here.
(24 Feb &#39;14, 04:30) Jaap ♦  
One Answer:</description>
    </item>
    
    <item>
      <title>How can I measure the delay of system?</title>
      <link>/questions/30119/how-can-i-measure-the-delay-of-system/</link>
      <pubDate>Mon, 24 Feb 2014 00:47:00 +0000</pubDate>
      
      <guid>/questions/30119/how-can-i-measure-the-delay-of-system/</guid>
      <description>How can I measure the delay of system?  0 Hi all I&#39;m posting to know how can I measure the system delay. for the details, please refer to attached picture. delayasked 24 Feb &#39;14, 00:47
Ray_Han
56●6●6●11
accept rate: 0%
  
One Answer:
  
1 If you want &#39;real results&#39;, you should not rely on the mirror functionality of the switch for this, as you will never know how exactly (in which order) the switch copies the frames from 3+2 to the mirror port.</description>
    </item>
    
    <item>
      <title>search a package in specific time</title>
      <link>/questions/30120/search-a-package-in-specific-time/</link>
      <pubDate>Mon, 24 Feb 2014 00:54:00 +0000</pubDate>
      
      <guid>/questions/30120/search-a-package-in-specific-time/</guid>
      <description>search a package in specific time  0 Hi there, i have a problem with Wireshark that i would like to find a package (send/receive) in a specific time (e.g. today is 24Feb, but i would like to find packages on 19Feb). At first sight, i see only Wireshark show the result for today only. Please help, thanks in advance
historyasked 24 Feb &#39;14, 00:54
Nguyen
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Wireshark build gives &amp;quot;Can&amp;#x27;t find Qt. This will become a problem...</title>
      <link>/questions/30127/wireshark-build-gives-cant-find-qt-this-will-become-a-problem/</link>
      <pubDate>Mon, 24 Feb 2014 05:58:00 +0000</pubDate>
      
      <guid>/questions/30127/wireshark-build-gives-cant-find-qt-this-will-become-a-problem/</guid>
      <description>Wireshark build gives &amp;ldquo;Can&amp;rsquo;t find Qt. This will become a problem&amp;hellip;  0 In following the most recent Wireshark build instructions, the following command returns with a warning:
C:&amp;gt;nmake -f Makefile.nmake verify_tools
Can&#39;t find Qt. This will become a problem at some point.
Needless to say, the build will indeed fail. I gather that Wireshark has switched to a new GUI library called Qt. What do I have to download to resolve this?</description>
    </item>
    
    <item>
      <title>How to identify which sites my internal users are visiting</title>
      <link>/questions/30128/how-to-identify-which-sites-my-internal-users-are-visiting/</link>
      <pubDate>Mon, 24 Feb 2014 06:39:00 +0000</pubDate>
      
      <guid>/questions/30128/how-to-identify-which-sites-my-internal-users-are-visiting/</guid>
      <description>How to identify which sites my internal users are visiting  0 I want to look through websites and when I find something they shouldn&#39;t be looking at I want to find what IP address they are so I can tell them to get off the website. Please help
http ipv4 wiresharkThis question is marked &#34;community wiki&#34;.asked 24 Feb &#39;14, 06:39
jbohling
1●1●1●2
accept rate: 0%
 edited 24 Feb &#39;14, 12:18</description>
    </item>
    
    <item>
      <title>DUP ACKs even though no packet was lost</title>
      <link>/questions/30131/dup-acks-even-though-no-packet-was-lost/</link>
      <pubDate>Mon, 24 Feb 2014 07:55:00 +0000</pubDate>
      
      <guid>/questions/30131/dup-acks-even-though-no-packet-was-lost/</guid>
      <description>DUP ACKs even though no packet was lost  0 I have two network devices involved in this wireshark capture
the embedded device, 10.222.156.120the server, 10.222.156.1, which is a Java application on an Ubuntu 12.04 64 bit machineThe capture is done on the server.
The embedded device connects to the server and starts sending data. The server never sends anything.
Everything goes well until packet #108 is sent. The server now starts sending DUP ACKs and does not even stop when a fast retransmission og packet #109 is sent by the embedded device.</description>
    </item>
    
    <item>
      <title>TCP Stream - FIN, ACK question</title>
      <link>/questions/30132/tcp-stream-fin-ack-question/</link>
      <pubDate>Mon, 24 Feb 2014 07:59:00 +0000</pubDate>
      
      <guid>/questions/30132/tcp-stream-fin-ack-question/</guid>
      <description>TCP Stream - FIN, ACK question  0 I have traced a TCP stream sent over my LAN. Everything runs quick until the FIN, ACK from server to client (there is a 2 second delay here). I&#39;m not sure if the issue is server side or client side, any ideas?
http://picthost.net/v.php?id=0e1b3f755b766b166e39822e4d652664
tcpasked 24 Feb &#39;14, 07:59
markc1
11●1●1●3
accept rate: 0%
 edited 24 Feb &#39;14, 08:06</description>
    </item>
    
    <item>
      <title>Unable to open two captures simultaneously for review on MAC OS X</title>
      <link>/questions/30133/unable-to-open-two-captures-simultaneously-for-review-on-mac-os-x/</link>
      <pubDate>Mon, 24 Feb 2014 08:38:00 +0000</pubDate>
      
      <guid>/questions/30133/unable-to-open-two-captures-simultaneously-for-review-on-mac-os-x/</guid>
      <description>Unable to open two captures simultaneously for review on MAC OS X  0 I have checked the various settings / preferences and am unable to determine how to view multiple files at same time on Wireshark 1.11.3. I was able to do this on previous versions. This issue is limited to my MAC OS X 10.9.1 Mavericks.
TYIA
osxasked 24 Feb &#39;14, 08:38
tysonjordanali
1●1●1●1
accept rate: 0%
What do you mean by &#34;</description>
    </item>
    
    <item>
      <title>Is it correct to assume that before learning Wireshark I should learn TCP/IP and other protocols so I can know what I&amp;#x27;m looking for on a trace file?</title>
      <link>/questions/30148/is-it-correct-to-assume-that-before-learning-wireshark-i-should-learn-tcpip-and-other-protocols-so-i-can-know-what-im-looking-for-on-a-trace-file/</link>
      <pubDate>Mon, 24 Feb 2014 11:58:00 +0000</pubDate>
      
      <guid>/questions/30148/is-it-correct-to-assume-that-before-learning-wireshark-i-should-learn-tcpip-and-other-protocols-so-i-can-know-what-im-looking-for-on-a-trace-file/</guid>
      <description>Is it correct to assume that before learning Wireshark I should learn TCP/IP and other protocols so I can know what I&amp;rsquo;m looking for on a trace file?  0 Hey guys!!
Is it correct to assume that before learning Wireshark I should learn TCP/IP and other protocols so I can know what I&#39;m looking for on a trace file?
Because I see in every Wireshark video a lot of &#34;</description>
    </item>
    
    <item>
      <title>Export to a Human Readable Text File</title>
      <link>/questions/30151/export-to-a-human-readable-text-file/</link>
      <pubDate>Mon, 24 Feb 2014 12:20:00 +0000</pubDate>
      
      <guid>/questions/30151/export-to-a-human-readable-text-file/</guid>
      <description>Export to a Human Readable Text File  0 Hi All,
I hope that you can help me to resolve a small issue. While using export feature of Wireshark 1.05 -&amp;gt; Export Specified Packets -&amp;gt; K12 text file (*.txt, txt.gz) I obtained a file with non human Readable content (sample attacked bellow). I hope that you can help me to find a way to export the Wireshark capture (layers 2-7) to a text / csv readable file.</description>
    </item>
    
    <item>
      <title>Question regarding purchasing the T-shooting with wireshark book..</title>
      <link>/questions/30158/question-regarding-purchasing-the-t-shooting-with-wireshark-book/</link>
      <pubDate>Mon, 24 Feb 2014 14:38:00 +0000</pubDate>
      
      <guid>/questions/30158/question-regarding-purchasing-the-t-shooting-with-wireshark-book/</guid>
      <description>Question regarding purchasing the T-shooting with wireshark book..  0 Hello, Today I had attended the WireShark Virtual World Tour, and I could had sworn that I heard Laura Chappell state that if you were to purchase the paperback version of the &#39;Troubleshooting with Wireshark&#39; from Amazon, it would include a code to purchase the Kindle version for $3 .... I was hoping that someone would confirm this.
thanks, chris mayberry</description>
    </item>
    
    <item>
      <title>Control wireshark with my application</title>
      <link>/questions/30169/control-wireshark-with-my-application/</link>
      <pubDate>Tue, 25 Feb 2014 00:05:00 +0000</pubDate>
      
      <guid>/questions/30169/control-wireshark-with-my-application/</guid>
      <description>Control wireshark with my application  0 i am new in wireshark and lua script. I did some research and found that &#34;Wireshark contains a LUA language interpreter. LUA scripts that execute on this interpreter can control Wireshark&#34;. I want to make an application to control wireshark. When i give command &#34;start capture&#34; in my application it should start capturing and same goes with filtering protocol. Is it possible to do that?</description>
    </item>
    
    <item>
      <title>Is it possible to display 802.11 frames?</title>
      <link>/questions/30174/is-it-possible-to-display-80211-frames/</link>
      <pubDate>Tue, 25 Feb 2014 02:56:00 +0000</pubDate>
      
      <guid>/questions/30174/is-it-possible-to-display-80211-frames/</guid>
      <description>Is it possible to display 802.11 frames?  0 Hi,
I am sniffing traffic on a specific channel in monitor mode and I am normally capturing 802.11 frames without a problem. Yet sometimes I see packets from protocols like ICMP, SSDP, ARP etc. which probably come from a open networks in that channel.
What I am trying to do is display only the 802.11 part as though the data portion of all packets would be impossible to &#39;translate&#39;.</description>
    </item>
    
    <item>
      <title>Wireshark decrypts SSL traces just partly</title>
      <link>/questions/30176/wireshark-decrypts-ssl-traces-just-partly/</link>
      <pubDate>Tue, 25 Feb 2014 05:03:00 +0000</pubDate>
      
      <guid>/questions/30176/wireshark-decrypts-ssl-traces-just-partly/</guid>
      <description>Wireshark decrypts SSL traces just partly  0 Hello,
What is the reason why Wireshark was able to decrypt only 60% of SSL (https) packets to only one https-server. The server certificate has been provided in .p12 format with a password one day after pulled the traces from the network.
What can we do to decrypt the remaining 40%?
Is it right that Wireshark can&#39;t save the decrypted packets to a different file by means wireshark can decrypt on the fly (while capturing or reading a tracefile) only?</description>
    </item>
    
    <item>
      <title>How to use wireshark for monitoring Wireless network traffic?</title>
      <link>/questions/30177/how-to-use-wireshark-for-monitoring-wireless-network-traffic/</link>
      <pubDate>Tue, 25 Feb 2014 06:24:00 +0000</pubDate>
      
      <guid>/questions/30177/how-to-use-wireshark-for-monitoring-wireless-network-traffic/</guid>
      <description>How to use wireshark for monitoring Wireless network traffic?  0 Hello,
I have atm. 1 Router, and multiple laptops/phones on the router, Is it possible to figure out who is taking all the bandwidth, with wireshark?
G.
traffic monitoring wiresharkasked 25 Feb &#39;14, 06:24
GuKnowMe
11●1●1●2
accept rate: 0%
  
One Answer:
  
0Is it possible to figure out who is taking all the bandwidth, with wireshark?</description>
    </item>
    
    <item>
      <title>Diameter IPAddress type convert</title>
      <link>/questions/30178/diameter-ipaddress-type-convert/</link>
      <pubDate>Tue, 25 Feb 2014 07:18:00 +0000</pubDate>
      
      <guid>/questions/30178/diameter-ipaddress-type-convert/</guid>
      <description>Diameter IPAddress type convert  0 Hello,
I&#39;m interrested by Diameter Protocol, specially by the way AVP of type IPAddress are encoded: Example: 10.50.54.38 will be (hex) 0a 32 36 26 and octetstring representation will be .26&amp;amp; I would like to know to to convert from xxxx.xxxx.xxxx.xxxx to the octetstring. (I know that the representation must have 12 or 24 long length).
Thank for your share.
diameter conversion ipaddressasked 25 Feb &#39;14, 07:18</description>
    </item>
    
    <item>
      <title>The tcp sequence number altered?</title>
      <link>/questions/30192/the-tcp-sequence-number-altered/</link>
      <pubDate>Tue, 25 Feb 2014 20:53:00 +0000</pubDate>
      
      <guid>/questions/30192/the-tcp-sequence-number-altered/</guid>
      <description>The tcp sequence number altered?  0 Some thing wrong when I was send a file with FTP . I captured the network card stream ,and found packet was Tagged retransmission by wireshark.
client IP:123.160.53.111 sever IP:172.16.8.61was the server SIP and 221.181.100.222 was VIP. I saw that the packet whichTCP sequence number is 70529 retransmissed in the ftp client. But in the ftp server,the sequence number was altered,and does not seems a retransmissed packed.</description>
    </item>
    
    <item>
      <title>how do i capture packets of two hosts</title>
      <link>/questions/30198/how-do-i-capture-packets-of-two-hosts/</link>
      <pubDate>Wed, 26 Feb 2014 00:51:00 +0000</pubDate>
      
      <guid>/questions/30198/how-do-i-capture-packets-of-two-hosts/</guid>
      <description>how do i capture packets of two hosts  0 how do i capture packets between two hosts?
once packets are captured, how do i know the cause of the problem? like email alerts sent from Oracle server to Exchange server sometimes fail. is there something like a reference that i can compare against my captured packets?
oracle exchangeasked 26 Feb &#39;14, 00:51
rino19ny
1●1●1●1
accept rate: 0%</description>
    </item>
    
    <item>
      <title>Would an old mini-hub work as a TAP?</title>
      <link>/questions/30208/would-an-old-mini-hub-work-as-a-tap/</link>
      <pubDate>Wed, 26 Feb 2014 08:29:00 +0000</pubDate>
      
      <guid>/questions/30208/would-an-old-mini-hub-work-as-a-tap/</guid>
      <description>Would an old mini-hub work as a TAP?  0 Happy to join the frenzy. I&#39;ve got 7 switches on my one-segment LAN here, and I&#39;d like to capture some trace files at the gateway. I don&#39;t have a TAP, and was wondering if an old-school hub might work, as hubs don&#39;t forward at the MAC level. It&#39;s a 4-port mini-hub, and I was going to plug my laptop and my daisy-chained switches into it with Wireshark running on my laptop.</description>
    </item>
    
    <item>
      <title>Need help in dumping primitive structure</title>
      <link>/questions/30209/need-help-in-dumping-primitive-structure/</link>
      <pubDate>Wed, 26 Feb 2014 10:13:00 +0000</pubDate>
      
      <guid>/questions/30209/need-help-in-dumping-primitive-structure/</guid>
      <description>Need help in dumping primitive structure  0 Hi All,
I am absolutely new to wireshark. Currently we are planning to use wireshark to capture traces of our communication protocol stack.
We intend to write plugins to dump the primitive structures sent between various components ( interface structures between various layers of our protocol stack ). Are there any sample plugins already available which I can re-use to dump structures ?</description>
    </item>
    
    <item>
      <title>Decrypt ESP packets with out preshared key Using certificates.</title>
      <link>/questions/30215/decrypt-esp-packets-with-out-preshared-key-using-certificates/</link>
      <pubDate>Wed, 26 Feb 2014 13:57:00 +0000</pubDate>
      
      <guid>/questions/30215/decrypt-esp-packets-with-out-preshared-key-using-certificates/</guid>
      <description>Decrypt ESP packets with out preshared key Using certificates.  0 Hello
I would like to decrypt ESP packets. I have reading the forum where most of the people are doing the same with preshared key. But in my case I am using certificates (x509) for authentication. Can you please let me know is there a way to decrypt ESP packets with certificates.
Thanks Rao
esp authrority certificate ipsecasked 26 Feb &#39;14, 13:57</description>
    </item>
    
    <item>
      <title>Issue viewing traffic in WPA Encrypted network</title>
      <link>/questions/30222/issue-viewing-traffic-in-wpa-encrypted-network/</link>
      <pubDate>Wed, 26 Feb 2014 20:07:00 +0000</pubDate>
      
      <guid>/questions/30222/issue-viewing-traffic-in-wpa-encrypted-network/</guid>
      <description>Issue viewing traffic in WPA Encrypted network  0 Hello,
I use Wireshark in Kali Linux, I&#39;ve been having some problems viewing traffic of other computers inside of my own WPA encrypted network. I&#39;ve added the WPA password, collected the EAPOL 4-Way handshake, as well as having the card in promiscuous mode. I can view DNS/ARP, SSDP (I&#39;m unsure as to what this is), EAPoL, and HTTP NOTIFY (Not POST or GET).</description>
    </item>
    
    <item>
      <title>wireshark Ethernet conversation statistics</title>
      <link>/questions/30223/wireshark-ethernet-conversation-statistics/</link>
      <pubDate>Wed, 26 Feb 2014 20:18:00 +0000</pubDate>
      
      <guid>/questions/30223/wireshark-ethernet-conversation-statistics/</guid>
      <description>wireshark Ethernet conversation statistics  0 Can somebody help me out in understanding the statistics for the conversation for Ethernet in Wireshark. I have a Cisco_2d:fa:22 as Address A and Cisco_4d:f3:11 as Address B. So it looks like it is the ID for the Cisco device. I see their MAC addresses in the Ethernet section in Wireshark. But in the IP section, the source and destination IP addresses keep changing from one packet to another.</description>
    </item>
    
    <item>
      <title>Catch all packets going over Windows Hosted Virtual Adapter</title>
      <link>/questions/30227/catch-all-packets-going-over-windows-hosted-virtual-adapter/</link>
      <pubDate>Thu, 27 Feb 2014 01:11:00 +0000</pubDate>
      
      <guid>/questions/30227/catch-all-packets-going-over-windows-hosted-virtual-adapter/</guid>
      <description>Catch all packets going over Windows Hosted Virtual Adapter  0 I created virtual hosted adapter on my notebook (Win 8.1) and conntected iphone and tv to this wi-fi (becouse i need to understand one protocol) than i tryed to catch packets going between them but without success (I used wireshark &amp;amp; RawCap) but i didnt catched any packets (but im sure that some packets are delivered becouse the purpouse of the protocol - app works)</description>
    </item>
    
    <item>
      <title>ModBus TCP communication problem</title>
      <link>/questions/30228/modbus-tcp-communication-problem/</link>
      <pubDate>Thu, 27 Feb 2014 01:39:00 +0000</pubDate>
      
      <guid>/questions/30228/modbus-tcp-communication-problem/</guid>
      <description>ModBus TCP communication problem  0 I have a device (lets call it MovaColor) which communicates with clients connected via modbus tcp. The clients make read/write operations to the movacolor. Client 1 is plc based hardware (B&amp;amp;R PP41), client 2 is IPC based implemented in Labview with modbus library running on windows XP (IPC is also from B&amp;amp;R APC 810). I have reproducible communication problems :
When client 2 (IPC) communicates with movacolor then reading registers is without problem (after connection), but after writing once, the next read response is fragmented, an I get an an error message from client 2, that the network connection was closed by the peer.</description>
    </item>
    
    <item>
      <title>capture Serial port (COM) communications in wireshark</title>
      <link>/questions/30231/capture-serial-port-com-communications-in-wireshark/</link>
      <pubDate>Thu, 27 Feb 2014 05:55:00 +0000</pubDate>
      
      <guid>/questions/30231/capture-serial-port-com-communications-in-wireshark/</guid>
      <description>capture Serial port (COM) communications in wireshark  0 Can wireshark capture the communication between the devices,communication made using serial port emulation program(Terminal v1.9b)? Is it possible to add the feature to capture that communication?
if you need more information send me an email at [email protected]
Any information related could be helpful.
lua serial-port wiresharkasked 27 Feb &#39;14, 05:55
Amrit
11●3●3●6
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Round trip time direction</title>
      <link>/questions/30233/round-trip-time-direction/</link>
      <pubDate>Thu, 27 Feb 2014 06:27:00 +0000</pubDate>
      
      <guid>/questions/30233/round-trip-time-direction/</guid>
      <description>Round trip time direction  0 I have some basic questions about calculating round trip time in wireshark as I have some mis-understandings about it. After filtering my TCP session (http download), to get the RTT time, it looks like we need to select the source port from the server e.g. 80, then plot RTT graph.
If I was tracing from the server I guess I would select destination port of 80?</description>
    </item>
    
    <item>
      <title>Best way to catch all packets between two devices on local network ethernet/wifi</title>
      <link>/questions/30234/best-way-to-catch-all-packets-between-two-devices-on-local-network-ethernetwifi/</link>
      <pubDate>Thu, 27 Feb 2014 06:41:00 +0000</pubDate>
      
      <guid>/questions/30234/best-way-to-catch-all-packets-between-two-devices-on-local-network-ethernetwifi/</guid>
      <description>Best way to catch all packets between two devices on local network ethernet/wifi  0 Im facing problem that i have to catch packets between two devices on local network ethernet/ wifi : tv and iphone. Thats mean none of this devices is my computer. What is the most easy &amp;amp; effective solution ?
ethernet wifi packets network wiresharkasked 27 Feb &#39;14, 06:41
Osel Miko Dř...
11●2●2●4
accept rate: 100%</description>
    </item>
    
    <item>
      <title>Save decrypted WPA packets to a new file?</title>
      <link>/questions/30235/save-decrypted-wpa-packets-to-a-new-file/</link>
      <pubDate>Thu, 27 Feb 2014 07:25:00 +0000</pubDate>
      
      <guid>/questions/30235/save-decrypted-wpa-packets-to-a-new-file/</guid>
      <description>Save decrypted WPA packets to a new file?  0 I captured my own wpa2 wifi traffic and successfully decrypted it following the tutorial But is there a way to save the decrypted version as a new pcap file? so other people can read the pcap without the encrptyion key
decrypted save wpaasked 27 Feb &#39;14, 07:25
Ken
1●1●1●1
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark not detecting udp snmptrap/162 port</title>
      <link>/questions/30237/wireshark-not-detecting-udp-snmptrap162-port/</link>
      <pubDate>Thu, 27 Feb 2014 09:00:00 +0000</pubDate>
      
      <guid>/questions/30237/wireshark-not-detecting-udp-snmptrap162-port/</guid>
      <description>Wireshark not detecting udp snmptrap/162 port  0 Hi
Can someone please advise how I can trace udp snmptrap/162 port on a Windows 7 PRO system using wireshark as I never see anything, using udp.port==162 filter or no filter (capturing everything).
Using Windows sysinternals process monitor I can see the following when monitoring SNMP trap snmptrap.exe service:
Date: 27/02/2014 16:28:58 Thread: 0 Class: Network Operation: UDP Receive Result: SUCCESS Path: FQDN:snmptrap -&amp;gt; FQDN:49589 Duration: 0.</description>
    </item>
    
    <item>
      <title>RTP streams are not visible in the graph.</title>
      <link>/questions/30238/rtp-streams-are-not-visible-in-the-graph/</link>
      <pubDate>Thu, 27 Feb 2014 09:02:00 +0000</pubDate>
      
      <guid>/questions/30238/rtp-streams-are-not-visible-in-the-graph/</guid>
      <description>RTP streams are not visible in the graph.  0 Hi all, I&#39;ve been experiencing the very strange issue. I collect the traces for SIP calls and then review them on my PC. Typically, I click Flow and review the graph. For whatever reason, since about couple days ago, I don&#39;t see any RTP streams in the graph. Only SIP messages are there. Also, some of the streaming IP addresses are not displayed in the graph.</description>
    </item>
    
    <item>
      <title>How not to add a new tab to packet bytes pane with a new tvb?</title>
      <link>/questions/30239/how-not-to-add-a-new-tab-to-packet-bytes-pane-with-a-new-tvb/</link>
      <pubDate>Thu, 27 Feb 2014 09:13:00 +0000</pubDate>
      
      <guid>/questions/30239/how-not-to-add-a-new-tab-to-packet-bytes-pane-with-a-new-tvb/</guid>
      <description>How not to add a new tab to packet bytes pane with a new tvb?  0 Hi,
I&#39;m writing a dissector for a protocol that has many values from disjoint bytes. For example, one 8-byte value can be stored in offset 0-4 and 16-20. I realized that using the byteArray:tvb() to create a new tvb and then apply the tvb:int64() is the best way to get the values. However, whenever I create a new tvb with the ByteArray:tvb() function, a new tab is added to the packet bytes pane in the wireshark GUI.</description>
    </item>
    
    <item>
      <title>Wireshark filter</title>
      <link>/questions/30241/wireshark-filter/</link>
      <pubDate>Thu, 27 Feb 2014 10:51:00 +0000</pubDate>
      
      <guid>/questions/30241/wireshark-filter/</guid>
      <description>Wireshark filter  0 Hey there,
Im currently working on a filter that captures source IP address, visited URL and a timestamp.
So far i&#39;ve been trying: (frame[54:16] == 47:45:54:20:2f:20:48:54:54:50:2f:31:2e:31:0d:0a), which works well on traffic generated from my PC, but I have to change the frame part to frame[66:16] to see traffic generated from apple devices.
Can anybody tell me more about how the frame filter works? I guess It has something to do with location/position in the frame but I dont have a clue why there is 54 for PC traffic and 66 for apple devices.</description>
    </item>
    
    <item>
      <title>In need of filter to see SYN packets not receiving a SYN/ACK</title>
      <link>/questions/30242/in-need-of-filter-to-see-syn-packets-not-receiving-a-synack/</link>
      <pubDate>Thu, 27 Feb 2014 11:30:00 +0000</pubDate>
      
      <guid>/questions/30242/in-need-of-filter-to-see-syn-packets-not-receiving-a-synack/</guid>
      <description>In need of filter to see SYN packets not receiving a SYN/ACK  0 Hi I am trying to filter a packet capture where I can view SYNs not receiving a SYN/ACK back. I am not sure how to accomplish this.
Erik
packet-capture syn wiresharkasked 27 Feb &#39;14, 11:30
protongeek
1●1●1●1
accept rate: 0%
  
2 Answers:
  
0Assuming the client enters retransmission if it is not receiving a SYN-ACK in time a possible filter would be tcp.</description>
    </item>
    
    <item>
      <title>Capture SIP traffic on LYNC</title>
      <link>/questions/30243/capture-sip-traffic-on-lync/</link>
      <pubDate>Thu, 27 Feb 2014 11:51:00 +0000</pubDate>
      
      <guid>/questions/30243/capture-sip-traffic-on-lync/</guid>
      <description>Capture SIP traffic on LYNC  0 I have to run a long-term capture to find a SIP scenario, which causes some issues. I have downloaded the Lync certificate to Wireshark, and restarted the device I want to capture to get the initial handshake. This works fine Now I want to capture to a file instead, with 15 minutes interval. I restart the device again. The first file that gets saved has the initial handshake, and I&#39;m able to see the SIP traffic.</description>
    </item>
    
    <item>
      <title>Performance analysis of a webpage</title>
      <link>/questions/30255/performance-analysis-of-a-webpage/</link>
      <pubDate>Thu, 27 Feb 2014 18:08:00 +0000</pubDate>
      
      <guid>/questions/30255/performance-analysis-of-a-webpage/</guid>
      <description>Performance analysis of a webpage  0 How can I conduct a thorough tcp analysis of a webpage, for performance issues?
i.e. I fire up Wireshark --&amp;gt; I access a webpage --&amp;gt; I navigate around --&amp;gt; I close Wireshark --&amp;gt;
Now I want to analyze.
performance speed latencyasked 27 Feb &#39;14, 18:08
Puneet
11●1●1●3
accept rate: 0%
 edited 27 Feb &#39;14, 18:09 
  
One Answer:</description>
    </item>
    
    <item>
      <title>Alerts in the capture</title>
      <link>/questions/30257/alerts-in-the-capture/</link>
      <pubDate>Thu, 27 Feb 2014 20:34:00 +0000</pubDate>
      
      <guid>/questions/30257/alerts-in-the-capture/</guid>
      <description>Alerts in the capture  0 I have a capture of a website called www.mir3.com And the users are complaining that the application Is running slow, in the capture i see a lot of application alerts and Encryptions alerts.
Can someone shed some light on this issue for me please, can that application TTL (ALERTS) cause a website perform poorly? T Users are used to 12s second delay, now they say it takes about I 15-20sec to go from one page to another or simply to open a page.</description>
    </item>
    
    <item>
      <title>Different outputs in VoIP Calls Analysis for different versions of Wireshark, why?</title>
      <link>/questions/30262/different-outputs-in-voip-calls-analysis-for-different-versions-of-wireshark-why/</link>
      <pubDate>Fri, 28 Feb 2014 01:25:00 +0000</pubDate>
      
      <guid>/questions/30262/different-outputs-in-voip-calls-analysis-for-different-versions-of-wireshark-why/</guid>
      <description>Different outputs in VoIP Calls Analysis for different versions of Wireshark, why?  0 In version 1.2.9 when I use the VoIP Calls analysis I see only protocol H.323. In version 1.10.0, the same capture file, when I use VoIP Calls analysis I see not only protocol H.323 in the output, but also another protocol AC_ISDN. Does anybody know what is different, obviously something changed between the versions. And why the output of the VoIP Calls analysis is so much different?</description>
    </item>
    
    <item>
      <title>Can WS capture packets from a device on a USB port?</title>
      <link>/questions/30273/can-ws-capture-packets-from-a-device-on-a-usb-port/</link>
      <pubDate>Fri, 28 Feb 2014 07:53:00 +0000</pubDate>
      
      <guid>/questions/30273/can-ws-capture-packets-from-a-device-on-a-usb-port/</guid>
      <description>Can WS capture packets from a device on a USB port?  0 I&#39;m trying to figure out how my firewall is blocking my BlackBerry Z10 phone, from mounting as a network drive on my laptop. Is it possible to sniff packaets between the BB device on a USB port and the internal firewall?
I know it&#39;s a firewall issue, as when I turn the firewall off the device works normally.</description>
    </item>
    
    <item>
      <title>Writeups on the effects of normalizing S-ACKs</title>
      <link>/questions/30280/writeups-on-the-effects-of-normalizing-s-acks/</link>
      <pubDate>Fri, 28 Feb 2014 11:28:00 +0000</pubDate>
      
      <guid>/questions/30280/writeups-on-the-effects-of-normalizing-s-acks/</guid>
      <description>Writeups on the effects of normalizing S-ACKs  0 Are there any good write ups on the effects on performance/throughput on normalizing the S-ACK option out at a firewall or IPS? I was trouble shooting some slow SMB2 file copy issues and saw that the SYN had the flag at the sender but by the time it gets to the destination the S-ACK options has been NOOP&#39;d by a sourcefire IPS.</description>
    </item>
    
    <item>
      <title>SMB2 stream being reset</title>
      <link>/questions/30285/smb2-stream-being-reset/</link>
      <pubDate>Fri, 28 Feb 2014 12:30:00 +0000</pubDate>
      
      <guid>/questions/30285/smb2-stream-being-reset/</guid>
      <description>SMB2 stream being reset  0 Initiate file transfer between 2 Win2k8R2 servers (or windows 7)A TCP Stream, say Stream 0 is created and the file starts to transferThe Stream is resetA new stream is created, say stream 1, and the file copy picks up where it left off due to the more robust nature of SMB2 dialect 0x0210 and its ability to recover from errors like a reset.More of the file is copied and the current stream is resetRepeat steps #4 &amp;amp; #5 until file copy completes.</description>
    </item>
    
    <item>
      <title>Decrypting TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA and TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 using SSLKEYLOGFILE</title>
      <link>/questions/30290/decrypting-tls_ecdhe_rsa_with_aes_128_cbc_sha-and-tls_ecdhe_rsa_with_aes_128_gcm_sha256-using-sslkeylogfile/</link>
      <pubDate>Fri, 28 Feb 2014 12:54:00 +0000</pubDate>
      
      <guid>/questions/30290/decrypting-tls_ecdhe_rsa_with_aes_128_cbc_sha-and-tls_ecdhe_rsa_with_aes_128_gcm_sha256-using-sslkeylogfile/</guid>
      <description>Decrypting TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA and TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 using SSLKEYLOGFILE  0 I can decrypt the traffic between my browser (firefox 27.0 running on Fedora 20 linux) and https://www.google.co.uk by
Adding &#34;export SSLKEYLOGFILE=/home/myusername/somewritablefile&#34; on a new line to /home/myusername/.bashrc and then logging out and logging in again. If you use csh you may be able to add &#34;setenv SSLKEYLOGFILE /home/myusername/somewritablefile&#34; to /home/myusername/.cshrc.Adding /home/myusername/somewriteablefile to the Edit-&amp;gt;Preferences-&amp;gt;Protocols-&amp;gt;SSL-&amp;gt;(Pre)-Master-Secret log filename field in Wireshark, clicking on apply and then ok.</description>
    </item>
    
    <item>
      <title>Network Tap</title>
      <link>/questions/30297/network-tap/</link>
      <pubDate>Fri, 28 Feb 2014 19:12:00 +0000</pubDate>
      
      <guid>/questions/30297/network-tap/</guid>
      <description>Network Tap  0 Ok, I have a question on this...I am recommending to my bosses that they invest in a tap. Ok, all is well in the land of milk and honey and I get 3/4 to use in the enterprise. But, I still need a capture tool/pc/laptop to plug into the tap to capture that traffic without dropping packets. What do people use? I&#39;ve seen presentations from sharkfest about how poorly laptops perform, what do people use?</description>
    </item>
    
    <item>
      <title>Wireshark and openflow</title>
      <link>/questions/30305/wireshark-and-openflow/</link>
      <pubDate>Sat, 01 Mar 2014 02:39:00 +0000</pubDate>
      
      <guid>/questions/30305/wireshark-and-openflow/</guid>
      <description>Wireshark and openflow  0 I need to scan openflow packets. I successfully compiled and installed the openflow plugin from sources, anyway on most of packets I get a DISSECTOR_ASSERT_NOT_REACHED on the file proto.c. Those are tcp, icmp and the 90% of packets I scan, just the hellos messages are dissected with no problem.
So I&#39;d like an help..I even heard somewhere that some more recent versions of wireshark already include an openflow dissector.</description>
    </item>
    
    <item>
      <title>TCP Lab question 12?</title>
      <link>/questions/30315/tcp-lab-question-12/</link>
      <pubDate>Sat, 01 Mar 2014 18:35:00 +0000</pubDate>
      
      <guid>/questions/30315/tcp-lab-question-12/</guid>
      <description>TCP Lab question 12?  0 Hey guys, trying to do question 12 here, but I&#39;m a bit stumped.
12 . What is the throughput (bytes transferred per unit time) for the TCP connection? Explain how you calculated this value.
The Computer Networking book states that the increase of w happens when a loss event occurs (which doesn&#39;t in the provided TCP trace, so that can be ignored (I think?)) Is the final formula:</description>
    </item>
    
    <item>
      <title>dissect in bits range</title>
      <link>/questions/30329/dissect-in-bits-range/</link>
      <pubDate>Sun, 02 Mar 2014 09:27:00 +0000</pubDate>
      
      <guid>/questions/30329/dissect-in-bits-range/</guid>
      <description>dissect in bits range  0 Hi,
It seems the normal way of dissecting a packet only goes down to byte level.
What if I have a value that is, say, 10 bits long (with no padding to make it into two bytes), is there a way I can add a tree item for it and highlight the corresponding bits?
Thank you so much,
yxi
lua bitasked 02 Mar &#39;14, 09:27</description>
    </item>
    
    <item>
      <title>Sip trace, can not see B leg</title>
      <link>/questions/30339/sip-trace-can-not-see-b-leg/</link>
      <pubDate>Sun, 02 Mar 2014 23:58:00 +0000</pubDate>
      
      <guid>/questions/30339/sip-trace-can-not-see-b-leg/</guid>
      <description>Sip trace, can not see B leg  0 HI,
strange thing is happaning on my server when I try to trace sip/rtp taffic:)
I am having sip proxy which relays call throught RTP server for media. When I am doing trace on sip proxy I can see bouth legs, when I am doing wireshark trace on RTP proxy I can see only one leg (A). Interesting is that I can see bouth legs on sip proxy (invite from rtp) but on RTP I can not see this invite that was sent to rtp proxy (B leg).</description>
    </item>
    
    <item>
      <title>test internet quality, consistency</title>
      <link>/questions/30343/test-internet-quality-consistency/</link>
      <pubDate>Mon, 03 Mar 2014 03:00:00 +0000</pubDate>
      
      <guid>/questions/30343/test-internet-quality-consistency/</guid>
      <description>test internet quality, consistency  0 hi, i&#39;m a total noob when it comes to wireshark. I&#39;m having issues with my cable connection. my cable provider does quick test (like speedtest) and simply says it&#39;s fine!
Well, there are moments when a 15min. 360p video on youtube takes an hour to watch just because of buffering! I have found a speedtest online (at servers at a local university) But some people tell me they don&#39;t think it is reliable.</description>
    </item>
    
    <item>
      <title>Change this display filter to a capture filter.</title>
      <link>/questions/30348/change-this-display-filter-to-a-capture-filter/</link>
      <pubDate>Mon, 03 Mar 2014 08:50:00 +0000</pubDate>
      
      <guid>/questions/30348/change-this-display-filter-to-a-capture-filter/</guid>
      <description>Change this display filter to a capture filter.  0 Hey there,
I found in an earlier post, the display filter (http.request.method == &#34;GET&#34; and http.request.uri == &#34;/&#34;), which filter out ip address and visited url in a very good way. This filter also &#34;removes&#34; ads and other crap which is really nice. I&#39;m trying to solve this display filter as an capture filter, but I&#39;m having problems.
I found this capture filter at Wireshark Wiki: port 80 and tcp[((tcp[12:1] &amp;amp; 0xf0) &amp;gt;&amp;gt; 2):4] = 0x4745542, but this gives me too much information, ads and other crap.</description>
    </item>
    
    <item>
      <title>Packet with HTTP 302 Redirect decoded as TCP not HTTP</title>
      <link>/questions/30352/packet-with-http-302-redirect-decoded-as-tcp-not-http/</link>
      <pubDate>Mon, 03 Mar 2014 10:48:00 +0000</pubDate>
      
      <guid>/questions/30352/packet-with-http-302-redirect-decoded-as-tcp-not-http/</guid>
      <description>Packet with HTTP 302 Redirect decoded as TCP not HTTP  0 Hi All,
Having a weird issue: a packet with HTTP 302 Redirect is being decoded only as TCP with Info = [TCP segment of a reassembled PDU] (thus hinting at the fact it&#39;s just one of a few packets carrying a large PDU) and not as HTTP despite it seems to contain the whole HTTP message. Here&#39;s this packet:</description>
    </item>
    
    <item>
      <title>performance problem with online game over canopy wireless link</title>
      <link>/questions/30353/performance-problem-with-online-game-over-canopy-wireless-link/</link>
      <pubDate>Mon, 03 Mar 2014 10:51:00 +0000</pubDate>
      
      <guid>/questions/30353/performance-problem-with-online-game-over-canopy-wireless-link/</guid>
      <description>performance problem with online game over canopy wireless link  0 any knowledgeable volunteers to take a quick look at a log for me issues with an online game provider they keep blaming our ISP our ISP blames them
Thanks Andy.
wireless performance canopy gameasked 03 Mar &#39;14, 10:51
Andy Taylor
11●1●1●2
accept rate: 0%
 edited 03 Mar &#39;14, 16:04 
Kurt Knochner ♦
24.8k●10●39●237
what is the problem with the game?</description>
    </item>
    
    <item>
      <title>How to capture ethernet traffic / Modbus TCP</title>
      <link>/questions/30365/how-to-capture-ethernet-traffic-modbus-tcp/</link>
      <pubDate>Mon, 03 Mar 2014 15:13:00 +0000</pubDate>
      
      <guid>/questions/30365/how-to-capture-ethernet-traffic-modbus-tcp/</guid>
      <description>How to capture ethernet traffic / Modbus TCP  0 I installed WS on my computer. I want to see Modbus TCP traffic that is on the same network.
The Modbus TCP traffic is going from a Master PLC to other Slave PLCs, and does not communicate directly with the computer.
WS only seems to show traffic sourcing or sinking to itself (10.0.0.100).
I want to see the traffic between the PLCs (10.</description>
    </item>
    
    <item>
      <title>number bigger than 64 bits</title>
      <link>/questions/30376/number-bigger-than-64-bits/</link>
      <pubDate>Mon, 03 Mar 2014 18:23:00 +0000</pubDate>
      
      <guid>/questions/30376/number-bigger-than-64-bits/</guid>
      <description>number bigger than 64 bits  0 Hi,
Just wondering if anyone has to write a dissector in Lua that contains values bigger than 64 bit. How do you do it.
Thanks.
lua big_numberasked 03 Mar &#39;14, 18:23
YXI
21●18●20●23
accept rate: 0%
 retagged 04 Mar &#39;14, 04:24 
Hadriel
2.7k●2●9●39
  
2 Answers:
  
0To do what with? Just to show it in the display tree?</description>
    </item>
    
    <item>
      <title>How to reduce memory usage in very long-time capture and analyze</title>
      <link>/questions/30379/how-to-reduce-memory-usage-in-very-long-time-capture-and-analyze/</link>
      <pubDate>Mon, 03 Mar 2014 21:19:00 +0000</pubDate>
      
      <guid>/questions/30379/how-to-reduce-memory-usage-in-very-long-time-capture-and-analyze/</guid>
      <description>How to reduce memory usage in very long-time capture and analyze  0 I modify a version of tshark to analyze real-time packages on Gigabytes port, find out the info I concerned, and write them in files. When facing multi-days capture, the memory grows continuously. I shield the output printing, and write temporary pcapng files in multiple ring buffers to reduce the memory cost. However, memory grows at 20 to 30 MB per hour.</description>
    </item>
    
    <item>
      <title>command to replace all different IP addresses in pcap file with single IP address</title>
      <link>/questions/30385/command-to-replace-all-different-ip-addresses-in-pcap-file-with-single-ip-address/</link>
      <pubDate>Tue, 04 Mar 2014 02:20:00 +0000</pubDate>
      
      <guid>/questions/30385/command-to-replace-all-different-ip-addresses-in-pcap-file-with-single-ip-address/</guid>
      <description>command to replace all different IP addresses in pcap file with single IP address  0 I have a pcap file which has multiple IP addresses, I want to replace those multiple IP addresses with single address, is there any command to do so?
tcprewriteasked 04 Mar &#39;14, 02:20
shubhangi
1●1●1●1
accept rate: 0%
 edited 04 Mar &#39;14, 02:32 
grahamb ♦
19.8k●3●30●206
  
One Answer:</description>
    </item>
    
    <item>
      <title>&amp;quot;coap13&amp;quot; isn&amp;#x27;t a valid Capture filter (syntax error)</title>
      <link>/questions/30387/coap13-isnt-a-valid-capture-filter-syntax-error/</link>
      <pubDate>Tue, 04 Mar 2014 02:54:00 +0000</pubDate>
      
      <guid>/questions/30387/coap13-isnt-a-valid-capture-filter-syntax-error/</guid>
      <description>&amp;ldquo;coap13&amp;rdquo; isn&amp;rsquo;t a valid Capture filter (syntax error)  0 I am working with wireshark(tshark). I want to capture specific protocol like ipv6, coap13 etc. i added coap13.lua file.
i tried to capture ipv6 with &#34;tshark.exe&#34; -i 3 -f &#34;ip6&#34; -a duration:400 -a filesize:20480 -a files:512 -w &#34;C:\Packet_Capture.pcap&#34;
it runs well
but when i want to capture CoAP or CoAP13 with
&#34;tshark.exe&#34; -i 3 -f &#34;coap13&#34; -a duration:400 -a filesize:20480 -a files:512 -w &#34;</description>
    </item>
    
    <item>
      <title>tshark - How to output date in ISO format?</title>
      <link>/questions/30393/tshark-how-to-output-date-in-iso-format/</link>
      <pubDate>Tue, 04 Mar 2014 05:18:00 +0000</pubDate>
      
      <guid>/questions/30393/tshark-how-to-output-date-in-iso-format/</guid>
      <description>tshark - How to output date in ISO format?  2 Hi,
in Wireshark 1.10.5 on Windows I can select View | Time Display Format | Date and Time of Day and date is displayed in ISO date format e.g. &#34;2014-02-25 13:20:11 740751000&#34;
How to display the same format in tshark? I tried:
tshark&#34; -r c:\myfile.pcap -T fields -e frame.time
but the output is : &#34;Feb 25, 2014 13:20:11.740751000&#34;
How to display ISO date format in tshark?</description>
    </item>
    
    <item>
      <title>MATE snmp session</title>
      <link>/questions/30394/mate-snmp-session/</link>
      <pubDate>Tue, 04 Mar 2014 06:38:00 +0000</pubDate>
      
      <guid>/questions/30394/mate-snmp-session/</guid>
      <description>MATE snmp session  0 I need to examine snmp session that are longer that 30 seconds
I`m using this mate.config
Pdu snmp_pdu Proto snmp Transport udp/ip { Extract addr From ip.addr; Extract port From udp.port; Extract oid From snmp.name; Extract snmp_data From snmp.data; }; Gop snmp_ses On snmp_pdu Match (addr, addr, port, port){ Start(); Stop(never); }; Done;So in one Gop i have all packets with same addr and ports. But after awhile (2-3 minutes) i have another snmp packets with sames ports, so them got to one Gop and i can`t use mate.</description>
    </item>
    
    <item>
      <title>Is wireshark able to capture / dissect on two interfaces?</title>
      <link>/questions/30395/is-wireshark-able-to-capture-dissect-on-two-interfaces/</link>
      <pubDate>Tue, 04 Mar 2014 07:16:00 +0000</pubDate>
      
      <guid>/questions/30395/is-wireshark-able-to-capture-dissect-on-two-interfaces/</guid>
      <description>Is wireshark able to capture / dissect on two interfaces?  0 Hi, i&#39;m looking for solution, but i was not able to build a capable test case. Is wireshark able to capture and dissect packets in the following scenario: eth0 - this interface receives the &#34;outgoing&#34; packets eth1 - this interface receives the &#34;incoming&#34; packets
basically they build up to one tcp stream, but the &#34;replies&#34; are always separated from the &#34;</description>
    </item>
    
    <item>
      <title>Does Wireshark support INAP CS2?</title>
      <link>/questions/30401/does-wireshark-support-inap-cs2/</link>
      <pubDate>Tue, 04 Mar 2014 08:36:00 +0000</pubDate>
      
      <guid>/questions/30401/does-wireshark-support-inap-cs2/</guid>
      <description>Does Wireshark support INAP CS2?  0 I have a tcap message that I am trying to decode using wireshark that is a connectArg with a BearerCapability parameter. This parameter was added in cs2 and has a tag value that is context specific, is a constructor and has a value of 51. This ID will take up 2 octets. It decodes the tag properly but then gives a BER Error: This field lies beyond the end of the known sequence definition.</description>
    </item>
    
    <item>
      <title>Can Field.new retrieve a field defined previously with ProtoInfo?</title>
      <link>/questions/30403/can-fieldnew-retrieve-a-field-defined-previously-with-protoinfo/</link>
      <pubDate>Tue, 04 Mar 2014 08:51:00 +0000</pubDate>
      
      <guid>/questions/30403/can-fieldnew-retrieve-a-field-defined-previously-with-protoinfo/</guid>
      <description>Can Field.new retrieve a field defined previously with ProtoInfo?  0 For example, if you have the postdissector example, and append the following:
do local f_newfield1 = Field.new(&amp;quot;http.newfield1&amp;quot;) endIt fails to start up with the following error:
tshark: Lua: Error during loading: [string &amp;quot;/home/alastair/.wireshark/plugins/http_extr...&amp;quot;]:38: bad argument #1 to &amp;#39;new&amp;#39; (Field_new: a field with this name must exist).. even though the field was defined previously as a ProtoField.
Is this a bug or feature or something else?</description>
    </item>
    
    <item>
      <title>Apcon Timestamp decoded as &amp;#x27;VSS-Monitoring ethernet trailer&amp;#x27;</title>
      <link>/questions/30421/apcon-timestamp-decoded-as-vss-monitoring-ethernet-trailer/</link>
      <pubDate>Tue, 04 Mar 2014 16:43:00 +0000</pubDate>
      
      <guid>/questions/30421/apcon-timestamp-decoded-as-vss-monitoring-ethernet-trailer/</guid>
      <description>Apcon Timestamp decoded as &amp;lsquo;VSS-Monitoring ethernet trailer&amp;rsquo;  0 I have a capture file that was e-gressed from an Apcon smart-tap but when I view the trace file in Wireshark v 1.10.5, it shows the header as &#34;VSS-Monitoring ethernet trailer&#39;.
Does Wireshark support Apcon timestamp yet? Or is that in same format as VSS-Monitoring?
apcon vss-monitoring timstampasked 04 Mar &#39;14, 16:43
techynewbie
11●2●2●3
accept rate: 0%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Get tshark output in the python</title>
      <link>/questions/30428/get-tshark-output-in-the-python/</link>
      <pubDate>Tue, 04 Mar 2014 23:25:00 +0000</pubDate>
      
      <guid>/questions/30428/get-tshark-output-in-the-python/</guid>
      <description>Get tshark output in the python  0 I have a command which works great at the terminal:
sudo tshark -V -l -i &amp;#39;any&amp;#39; -f &amp;#39;udp port 4729&amp;#39;I trying to read the output from my python script:
import subprocess import shlex output = subprocess.check_output(shlex.split(&amp;quot;&amp;quot;&amp;quot;sudo tshark -V -l -i &amp;quot;any&amp;quot; -f &amp;#39;udp port 4729&amp;#39;&amp;quot;&amp;quot;&amp;quot;)) print outputI receives nothing. But when I press ctrl+c, I receives this:
[email protected]:~/workspace/glade_tests/src$ sudo ./main.py tshark: Lua: Error during loading: [string &amp;quot;/usr/share/wireshark/init.</description>
    </item>
    
    <item>
      <title>client sends delayed FIN ACK (40s) to server</title>
      <link>/questions/30429/client-sends-delayed-fin-ack-40s-to-server/</link>
      <pubDate>Tue, 04 Mar 2014 23:40:00 +0000</pubDate>
      
      <guid>/questions/30429/client-sends-delayed-fin-ack-40s-to-server/</guid>
      <description>client sends delayed FIN ACK (40s) to server  0 Hi, We have one application which uses wininet.dll to communicate to server(192.168.0.155).Client (172.16.20.5) requesting some data from http/tcp service from linux server (192.168.0.155). Client is installed on winXP OS.
Why client sends FIN ACK after 40s? Why so slow? He should send FIN ACK immediately.
Client is using wininet.dll to communicate to server . I tried may options while editing reg_keys also, but no success .</description>
    </item>
    
    <item>
      <title>Reassembled DNP  Application Layer Message</title>
      <link>/questions/30433/reassembled-dnp-application-layer-message/</link>
      <pubDate>Wed, 05 Mar 2014 00:24:00 +0000</pubDate>
      
      <guid>/questions/30433/reassembled-dnp-application-layer-message/</guid>
      <description>Reassembled DNP Application Layer Message  0 Hi ,
when i&#39;m examining DNP 3 packets i noticed that you parsed some packets that in the bytes pane windows there was &#34;Reassamble DNP AL Message&#34;.
how can i know how to parse it? (did you only use the specification?)
thanks ,
dnpasked 05 Mar &#39;14, 00:24
eligator28
11●1●1●3
accept rate: 0% 
  
One Answer:
  
1As a DNP3 datalink layer message body can only be 250 octets long, and as that body only carries 222 octets of payload (2 octet CRC for every 16 octets of data), and as the Transport layer header consumes 1 octet in every data link layer, and as an Application Layer message may be fragmented into multiple parts to ease memory requirements, the dissector extracts all the relevant portions of data from multiple data link messages and reassembles them into the complete application layer message.</description>
    </item>
    
    <item>
      <title>[closed] Problem installing aircrack package on Linux</title>
      <link>/questions/30443/problem-installing-aircrack-package-on-linux/</link>
      <pubDate>Wed, 05 Mar 2014 08:33:00 +0000</pubDate>
      
      <guid>/questions/30443/problem-installing-aircrack-package-on-linux/</guid>
      <description>[closed] Problem installing aircrack package on Linux  0 Hi i have got an error.
sudo: airmon-ng: command not found I tryed to install aircrack packet but i have allready installed &#34;iw&#34; packet but i dont know what that packet is? If someone could help me :)
thanks for help
airmon wlanasked 05 Mar &#39;14, 08:33
Beginer
1●5●5●6
accept rate: 0%
 closed 05 Mar &#39;14, 10:17 
Kurt Knochner ♦</description>
    </item>
    
    <item>
      <title>Windows cannot find &amp;#x27;C:&amp;#92;Program Files (x86)&amp;#92;Wireshark&amp;#92;Wireshark.exe&amp;#x27;</title>
      <link>/questions/30445/windows-cannot-find-cprogram-files-x86wiresharkwiresharkexe/</link>
      <pubDate>Wed, 05 Mar 2014 13:04:00 +0000</pubDate>
      
      <guid>/questions/30445/windows-cannot-find-cprogram-files-x86wiresharkwiresharkexe/</guid>
      <description>Windows cannot find &amp;lsquo;C:\Program Files (x86)\Wireshark\Wireshark.exe&amp;rsquo;  0 When i try to run wireshark, it says that windows cannot find it. If i manually look in the place where it can&#39;t find the exe, i can see it right there! When i click the exe there, it repeats the message... Very annoying, any help appreciated
Windows 7 64bit, tried multiple version with the same result...
windows7 executable find install errorasked 05 Mar &#39;14, 13:04</description>
    </item>
    
    <item>
      <title>What are the display filters for the following situations?</title>
      <link>/questions/30454/what-are-the-display-filters-for-the-following-situations/</link>
      <pubDate>Wed, 05 Mar 2014 20:57:00 +0000</pubDate>
      
      <guid>/questions/30454/what-are-the-display-filters-for-the-following-situations/</guid>
      <description>What are the display filters for the following situations?  0 a) HTTP that includes the text “Malware.exe” in the GET message
b) Traffic on port 80 that is not going to the webserver (webserver IP is 1.2.3.4)
c) Any IP message that includes your name as part of a plain text message.
pahert homework display-filterasked 05 Mar &#39;14, 20:57
mehrumj
11●1●1●2
accept rate: 0%
 edited 09 Mar &#39;14, 11:45</description>
    </item>
    
    <item>
      <title>Could wireshark decode ciphering Iub Userplane</title>
      <link>/questions/30459/could-wireshark-decode-ciphering-iub-userplane/</link>
      <pubDate>Wed, 05 Mar 2014 22:10:00 +0000</pubDate>
      
      <guid>/questions/30459/could-wireshark-decode-ciphering-iub-userplane/</guid>
      <description>Could wireshark decode ciphering Iub Userplane  0 Hi:-
Customer test Ping from UE to server in their WCDMA network. They capture wireshark log in Iub. The question is, can they decode the &#34;ping&#34; in userplane? Please notice ciphering is on in the network.
Many thanks bmo
wcdma ciphering iub pdcpasked 05 Mar &#39;14, 22:10
bmo
1●1●1●1
accept rate: 0%
  
One Answer:
  
0There&#39;s a big difference between decoding and deciphering.</description>
    </item>
    
    <item>
      <title>[Buildbot] Can I obtain scripts of buildbot?</title>
      <link>/questions/30461/buildbot-can-i-obtain-scripts-of-buildbot/</link>
      <pubDate>Wed, 05 Mar 2014 22:47:00 +0000</pubDate>
      
      <guid>/questions/30461/buildbot-can-i-obtain-scripts-of-buildbot/</guid>
      <description>[Buildbot] Can I obtain scripts of buildbot?  0 Hi, I want to setup buildbot server on my computer. Can I obtain scripts of buildbot? Thank You,
buildbotasked 05 Mar &#39;14, 22:47
prosohard
11●1●1●2
accept rate: 0%
  
One Answer:
  
0You can download Buildbot at buildbot.net.
answered 06 Mar &#39;14, 09:58
Gerald Combs ♦♦
3.3k●9●22●58
accept rate: 24%
Oh I mean buildbot scripts of Wireshark. Because I just found source code of Wireshark but not scripts to build Wireshark in Continuous Integration manner.</description>
    </item>
    
    <item>
      <title>Can i use &amp;quot;ask.wireshark.org&amp;quot; as a search provider in my browser?</title>
      <link>/questions/30467/can-i-use-askwiresharkorg-as-a-search-provider-in-my-browser/</link>
      <pubDate>Thu, 06 Mar 2014 01:20:00 +0000</pubDate>
      
      <guid>/questions/30467/can-i-use-askwiresharkorg-as-a-search-provider-in-my-browser/</guid>
      <description>Can i use &amp;ldquo;ask.wireshark.org&amp;rdquo; as a search provider in my browser?  0 Hi all,
i&#39;d like to use &#34;ask.wireshark.org&#34; as a search provider (in IE) or search engine(in FF) in my browser. Now adding it works fine, but no results to my Q&#39;s .. it seems to use a token?
searchengine ask.wireshark.org searchproviderasked 06 Mar &#39;14, 01:20
Marc
147●10●13●16
accept rate: 27%
  
One Answer:</description>
    </item>
    
    <item>
      <title>Wireshark cannot see any interface on Ubuntu 13.10</title>
      <link>/questions/30473/wireshark-cannot-see-any-interface-on-ubuntu-1310/</link>
      <pubDate>Thu, 06 Mar 2014 02:09:00 +0000</pubDate>
      
      <guid>/questions/30473/wireshark-cannot-see-any-interface-on-ubuntu-1310/</guid>
      <description>Wireshark cannot see any interface on Ubuntu 13.10  0 Hello everyone,
I&#39;ve installed Wireshark 1.10.2 through GNS3 (latest release 0.8.6); when I use it outside GNS3, no interface is listed.
What should be done?
interfaceasked 06 Mar &#39;14, 02:09
actionmystique
11●4●4●7
accept rate: 0%
I&#39;ve installed Wireshark 1.10.2 through GNS3
what does that mean: through GNS3
(06 Mar &#39;14, 13:15) Kurt Knochner ♦  
One Answer:</description>
    </item>
    
    <item>
      <title>bit operation returns negative number that doesn&amp;#x27;t make sense</title>
      <link>/questions/30478/bit-operation-returns-negative-number-that-doesnt-make-sense/</link>
      <pubDate>Thu, 06 Mar 2014 09:03:00 +0000</pubDate>
      
      <guid>/questions/30478/bit-operation-returns-negative-number-that-doesnt-make-sense/</guid>
      <description>bit operation returns negative number that doesn&amp;rsquo;t make sense  0 Hi,
This may be a pure Lua question (I&#39;m using Lua to write a dissector). I haven&#39;t got any responses from the Lua forum so I&#39;m here for help.
I have this line of code using bit op which is embedded in the Wireshark Lua tool. This is a regular bitwise and operation, not the 64bit version.
a = bit.</description>
    </item>
    
    <item>
      <title>limiting tags in ask.wireshark.org</title>
      <link>/questions/30484/limiting-tags-in-askwiresharkorg/</link>
      <pubDate>Thu, 06 Mar 2014 10:04:00 +0000</pubDate>
      
      <guid>/questions/30484/limiting-tags-in-askwiresharkorg/</guid>
      <description>limiting tags in ask.wireshark.org  0 A question for the moderators:
Have you ever considered limiting what the tags can be for questions? Like only letting the submitter use one or more tags from a pre-defined list? I don&#39;t know if OSQA can do that, but it might be helpful as there are hundreds of them it seems with numerous permutations, which seems to negate their usefulness.
Or maybe I&#39;m not thinking about them the right way?</description>
    </item>
    
    <item>
      <title>Measure delay and packetloss on HTTP &amp;amp; FTP packet</title>
      <link>/questions/30485/measure-delay-and-packetloss-on-http-ftp-packet/</link>
      <pubDate>Thu, 06 Mar 2014 10:14:00 +0000</pubDate>
      
      <guid>/questions/30485/measure-delay-and-packetloss-on-http-ftp-packet/</guid>
      <description>Measure delay and packetloss on HTTP &amp;amp; FTP packet  0 Hi, I just want to know how to measure delay &amp;amp; packetloss on HTTP &amp;amp; FTP packet? My friend told me to decode them first into RTP then the result would be in Telephony -&amp;gt; RTP -&amp;gt; Summary. But I couldn&#39;t find RTP when I going to decode the HTTP packet. So is there any simple way to do this?</description>
    </item>
    
    <item>
      <title>libz.so.1: no version information available</title>
      <link>/questions/30489/libzso1-no-version-information-available/</link>
      <pubDate>Thu, 06 Mar 2014 12:04:00 +0000</pubDate>
      
      <guid>/questions/30489/libzso1-no-version-information-available/</guid>
      <description>libz.so.1: no version information available  0 I am using wireshark 1.10.x in Linux. If running the following command: tshark -r test.pcap -V &amp;gt;&amp;gt; test.txt The command passed.
But if I call the command in my software, the error is: tshark: /home/my software/bin/libz.so.1: no version information available (required by /usr/local/lib/libwiretap.so.3) libz.so.1 exists in both /lib/libz.so.1 and /home/my software/bin/libz.so.1, and they have the same version number.
Any possible reason for the failure?</description>
    </item>
    
    <item>
      <title>use Wireshark&amp;#x27;s Lua interpreter stand alone</title>
      <link>/questions/30507/use-wiresharks-lua-interpreter-stand-alone/</link>
      <pubDate>Thu, 06 Mar 2014 15:05:00 +0000</pubDate>
      
      <guid>/questions/30507/use-wiresharks-lua-interpreter-stand-alone/</guid>
      <description>use Wireshark&amp;rsquo;s Lua interpreter stand alone  0 When I just want to quickly test some bits of Lua code that doesn&#39;t involve capturing traffic or analyzing a pcap, is there a way I can evoke the Lua interpreter embedded in Wireshark?
I know I can down load Lua itself, but it doesn&#39;t have all the Wireshark specific stuff like the new UInt64 objects. It doesn&#39;t even have bit op.</description>
    </item>
    
    <item>
      <title>Editing Makefiles to add a plugin in linux</title>
      <link>/questions/30511/editing-makefiles-to-add-a-plugin-in-linux/</link>
      <pubDate>Thu, 06 Mar 2014 16:38:00 +0000</pubDate>
      
      <guid>/questions/30511/editing-makefiles-to-add-a-plugin-in-linux/</guid>
      <description>Editing Makefiles to add a plugin in linux  0 I&#39;ve created a plugin using windows and it builds and runs correctly. I&#39;m trying to get the plugin to build on CENTOS6 using Wireshark 1.10.5 and I&#39;m having some issues with the Makefiles. The downloaded source builds fine. The issue starts once I add the plugin. After editing the root, plugins, and my plugin directory Makefiles I keep getting the below error.</description>
    </item>
    
    <item>
      <title>Conversation of tcp analysis problem</title>
      <link>/questions/30512/conversation-of-tcp-analysis-problem/</link>
      <pubDate>Thu, 06 Mar 2014 17:41:00 +0000</pubDate>
      
      <guid>/questions/30512/conversation-of-tcp-analysis-problem/</guid>
      <description>Conversation of tcp analysis problem  0 When I choose local connection or wireless, it is confused that the wireshark can not capture a whole conversion that including packages of two direction. My implements are as follows:
1.double click to start wireshark 2.select local connection and click start 3.select &amp;#39;Statistics-&amp;gt;Conversations&amp;#39; to display conversion window 4.select TCP, then I start analsisThe problem are that I want to watch the conversations displayed in step 4 that including both dirtctions(say both &#34;</description>
    </item>
    
    <item>
      <title>No more &amp;quot;tools&amp;quot; in version 1.11.3 using QT</title>
      <link>/questions/30516/no-more-tools-in-version-1113-using-qt/</link>
      <pubDate>Thu, 06 Mar 2014 20:05:00 +0000</pubDate>
      
      <guid>/questions/30516/no-more-tools-in-version-1113-using-qt/</guid>
      <description>No more &amp;ldquo;tools&amp;rdquo; in version 1.11.3 using QT  0 The &#34;tools&#34; item is gone in the 1.11.3 nightly build of Wireshark (using QT). So I don&#39;t have the Lua options under it anymore. Can we get it back?
menu qt luaasked 06 Mar &#39;14, 20:05
YXI
21●18●20●23
accept rate: 0%
 retagged 06 Mar &#39;14, 21:34 
Hadriel
2.7k●2●9●39
Hmmm... sorry about that - I wasn&#39;t even able to compile the Qt version until a couple days ago, due to changes in Qt 5.</description>
    </item>
    
    <item>
      <title>Does reassembly address multiple PDUs in a single TCP segment?</title>
      <link>/questions/30529/does-reassembly-address-multiple-pdus-in-a-single-tcp-segment/</link>
      <pubDate>Fri, 07 Mar 2014 04:35:00 +0000</pubDate>
      
      <guid>/questions/30529/does-reassembly-address-multiple-pdus-in-a-single-tcp-segment/</guid>
      <description>Does reassembly address multiple PDUs in a single TCP segment?  1 I&#39;m starting to dig into the details of some capture files and have been humbled by the gaps in my knowledge that have been exposed in this process. I am using a Lua dissector for a protocol (call it MYPROTO) that is conveyed via TCP. I was puzzled by some extremely large TCP segments in the capture, but now understand that multiple MYPROTO PDUs can be carried in a single TCP segment.</description>
    </item>
    
    <item>
      <title>Wireshark keeps shutting down...</title>
      <link>/questions/30544/wireshark-keeps-shutting-down/</link>
      <pubDate>Fri, 07 Mar 2014 07:26:00 +0000</pubDate>
      
      <guid>/questions/30544/wireshark-keeps-shutting-down/</guid>
      <description>Wireshark keeps shutting down&amp;hellip;  0 I am new to Wireshark. That being said, I am trying to analyze server packets for a period of time. Wireshark runs for a random period of time -- say 5-10 minutes and then keeps shutting down saying an unexpected error has occurred. I lose my file of captured data, etc. I have tried using multiple file settings as well.
Suggestions? Trying to find my packet errors is hard enough without the tool randomly losing everything.</description>
    </item>
    
    <item>
      <title>How to change wireshark binary package name in Linux?</title>
      <link>/questions/30576/how-to-change-wireshark-binary-package-name-in-linux/</link>
      <pubDate>Fri, 07 Mar 2014 11:35:00 +0000</pubDate>
      
      <guid>/questions/30576/how-to-change-wireshark-binary-package-name-in-linux/</guid>
      <description>How to change wireshark binary package name in Linux?  0 Current name is wireshark-1.x.x-1.i686.rpm. I want to rename the Linux binary package as wireshark-1.x.x-MySoftware-Version.i686.rpm, while -Version is -1, -2, etc. Config.nmake was changed:
VERSION_EXTRA=-MySoftware-2
But it did not work. The name was not changed.
Any other file I should change to put local build information in the binary package?
Thank you.
package name linuxasked 07 Mar &#39;14, 11:35
huang-shi</description>
    </item>
    
    <item>
      <title>Deauthentication - Client specific attacks</title>
      <link>/questions/30586/deauthentication-client-specific-attacks/</link>
      <pubDate>Fri, 07 Mar 2014 15:53:00 +0000</pubDate>
      
      <guid>/questions/30586/deauthentication-client-specific-attacks/</guid>
      <description>Deauthentication - Client specific attacks  0 I noticed that with deauthentication display filter on (wlan.fc.type_subtype eq 12), wireshark can only see broadcast deauthentication (but not client specific deauthentication). This is confirmed as we able to see the client specific deauthentication message with a different software. Can you confirm whether it is a limitation with wireshark and whether it will be fixed in the near future?
Thanks
display_filter displayasked 07 Mar &#39;14, 15:53</description>
    </item>
    
    <item>
      <title>Too many IPs</title>
      <link>/questions/30595/too-many-ips/</link>
      <pubDate>Fri, 07 Mar 2014 23:16:00 +0000</pubDate>
      
      <guid>/questions/30595/too-many-ips/</guid>
      <description>Too many IPs  0 So when I go to run Wireshark and pull an IP address of somebody I am in a call with ON SKYPE, even with a filter on that has worked in the past, it keeps pulling up old IPs of people I am no longer in a call with. I am currently testing it while in a call with NOBODY and it is pulling 6 different IPs repeatedly as if I were in a call with them right now.</description>
    </item>
    
    <item>
      <title>MATE web unable to capture third parties websites DNS IP</title>
      <link>/questions/30599/mate-web-unable-to-capture-third-parties-websites-dns-ip/</link>
      <pubDate>Sat, 08 Mar 2014 05:47:00 +0000</pubDate>
      
      <guid>/questions/30599/mate-web-unable-to-capture-third-parties-websites-dns-ip/</guid>
      <description>MATE web unable to capture third parties websites DNS IP  0 I have been using the configurantion file(web.mate) below to try and capture