This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi All,

    This is karun from india(Hyderabad) of Redpine signals.Actually I want to give my own packet inorder to display in wireshark.So i am going through the source code of Wireshark and winpcap(as it is the capturing library,driver).I figured out the peek point where packet.dll is used for packet capturing from nfs driver as described below.

    Wireshark<--wpcap.dll<--packet.dll<--npf.sys(driver where actual capture happens)<-packets.

    pcap_read_win32_npf()->PacketReceivePacket() function in wpcap/libpcap/pcap-win32.c.

    So i hard coded my known packet format after returning from PacketReceivepacket() function in winpcap 4.1.3 source code.And after compilation and copied the packet.dll,wpacp.dll,& ndf.sys to their respective folders,i am able to see my known packet in wireshark application as LLC packet,but along with mine some other packets so called UDP,LMNR,NBNS,SSDP,ARP packets are also coming to the wireshark's application.Can any one tell me where these packets are coming as pcap_read_win32_npf is the only function to capture packets(to best of my knowledge).

asked 29 Jun '15, 22:34

karun256's gravatar image

karun256
6557
accept rate: 0%

edited 29 Jun '15, 22:44


Hi I am getting my hard coded packet,other packets are not coming its because of memory issue i used memset before calling PacketReceivePacket function and copied my packet using memcpy.Now its working fine.I ma able to see my packet ,now challenge is to update timestamp,I am getting the 0.0000 time stamp for my every packet,can any one tell me where i can find the time stamp updation.

Thanks, karun.

permanent link

answered 30 Jun '15, 21:48

karun256's gravatar image

karun256
6557
accept rate: 0%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×72

question asked: 29 Jun '15, 22:34

question was seen: 1,252 times

last updated: 30 Jun '15, 21:48

p​o​w​e​r​e​d by O​S​Q​A