[prev in list] [next in list] [prev in thread] [next in thread]
List: tcpdump-workers
Subject: [tcpdump-workers] =?gb2312?B?tPC4tDogU3BhbTpSZTogW3RjcGR1bXAtd29ya2Vyc10gbGlicGNhcA==?=
From: "BinaryChen\(TP/SH\)" <BinaryChen () E28 ! com>
Date: 2005-12-06 2:55:57
Message-ID: 3147C09EB798ED439E023EFBA6E78608026A44 () smailsh ! E28 ! COM
[Download RAW message or body]
It is framed with escape characters.
The ethereal can recognize the PPPdump format? Otherwise what should I do next?
Binary Chen
________________________________
From: tcpdump-workers-owner@lists.tcpdump.org ´ú±í Guy Harris
Sent: 2005-12-6 (ÐÇÆÚ¶þ) 10:00
To: tcpdump-workers@lists.tcpdump.org
Subject: Spam:Re: [tcpdump-workers] libpcap for PPP raw data problem
(Sent from the wrong address, so it bounced; resent from the right
address, with extra crud added so that it doesn't get bounced again
as a duplicate message.)
On Dec 4, 2005, at 8:37 PM, BinaryChen(TP/SH) wrote:
> I have captured some raw PPP data from serial driver, and I want
> use libpcap to convert to pcap file format so the ethereal can help
> me do some analyze. Can anyone provide some sample or hints to me?
The first hint is that if it's truly *raw* data - i.e., it's just two
streams of bytes going to and from the host, not divided into frames,
and with the framing and escape bytes in the stream - you'd probably
be better off putting it in pppdump format, which is the format that
pppd writes out. See the comments in Ethereal's wiretap/pppdump.c to
see what that format is like.
-
This is the tcpdump-workers list.
Visit https://lists.sandelman.ca/ to unsubscribe.
["winmail.dat" (application/ms-tnef)]
-
This is the tcpdump-workers list.
Visit https://lists.sandelman.ca/ to unsubscribe.
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic