I want to generate a cap file with bad CRC packets using wireshark. I recorded the traffic I want but: 1. I don't see the CRC in the wireshark GUI and couldn't find where to enable this view 2. I cant find a way to "corrupt" the CRC of all packets in the cap file
thank you in advance!
asked 01 May '13, 00:50
edited 01 May '13, 00:51
Assuming you mean the CRC of the ethernet frame, then you're out of luck with a normal NIC. Most NIC (drivers) strip it before passing the packet to the system. That means wireshark (actually libpcap/WinPcap which does the capturing for wireshark) does not get to see the CRC.
There are capture cards that do not strip the CRC, but I have not used them myself so I can't advice you on that.
answered 01 May '13, 01:49