[prev in list] [next in list] [prev in thread] [next in thread] 

List:       tcpdump-workers
Subject:    [tcpdump-workers] =?gb2312?B?tPC4tDogU3BhbTpSZTogW3RjcGR1bXAtd29ya2Vyc10gbGlicGNhcA==?=
From:       "BinaryChen\(TP/SH\)" <BinaryChen () E28 ! com>
Date:       2005-12-06 2:55:57
Message-ID: 3147C09EB798ED439E023EFBA6E78608026A44 () smailsh ! E28 ! COM
[Download RAW message or body]

It is framed with escape characters.
 
The ethereal can recognize the PPPdump format? Otherwise what should I do next?
 
Binary Chen

________________________________

From: tcpdump-workers-owner@lists.tcpdump.org ´ú±í Guy Harris
Sent: 2005-12-6 (ÐÇÆÚ¶þ) 10:00
To: tcpdump-workers@lists.tcpdump.org
Subject: Spam:Re: [tcpdump-workers] libpcap for PPP raw data problem



(Sent from the wrong address, so it bounced; resent from the right 
address, with extra crud added so that it doesn't get bounced again 
as a duplicate message.)

On Dec 4, 2005, at 8:37 PM, BinaryChen(TP/SH) wrote:

> I have captured some raw PPP data from serial driver, and I want 
> use libpcap to convert to pcap file format so the ethereal can help 
> me do some analyze. Can anyone provide some sample or hints to me?

The first hint is that if it's truly *raw* data - i.e., it's just two 
streams of bytes going to and from the host, not divided into frames, 
and with the framing and escape bytes in the stream - you'd probably 
be better off putting it in pppdump format, which is the format that 
pppd writes out.  See the comments in Ethereal's wiretap/pppdump.c to 
see what that format is like.
-
This is the tcpdump-workers list.
Visit https://lists.sandelman.ca/ to unsubscribe.



["winmail.dat" (application/ms-tnef)]

-
This is the tcpdump-workers list.
Visit https://lists.sandelman.ca/ to unsubscribe.


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic