On Tue, Sep 11, 2007 at 08:12:50PM +0200, Toralf Förster wrote: > > I'm wondering why some UDP packets of the MS messenger protocol (with the > usual > text like "please click at www.we-destroy-your-computer.com") always have > wrong > check sums regardless whether sniffed at ppp0 or eth0 interface.
Maybe your wireshark is broken? I've tried wireshark and tcpdump here and the sums look fine. > and I'm wondering why it is still possible to capture such packets at eth0. tcpdump happens before the packet goes into the IP stack which is whare iptables lives. Cheers, -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt - To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://vger.kernel.org/majordomo-info.html