Re: [Wireshark-dev] Wiki problem

2007-08-17 Thread Guy Harris
On Aug 17, 2007, at 7:27 PM, yin sun wrote: > this is the format I found out. [wiki:%23.END #.END] Thanks. I've added the missing links to http://wiki.wireshark.org/Asn2wrsAuxiliary ___ Wireshark-dev mailing list Wireshark-dev@wireshark.org h

Re: [Wireshark-dev] Wiki problem

2007-08-17 Thread yin sun
this is the format I found out. [wiki:%23.END #.END] On 8/17/07, Anders Broman (AL/EAB) <[EMAIL PROTECTED]> wrote: > > Hi, > On Ethereal Wiki page corresponding to * > http://wiki.wireshark.org/Asn2wrs?highlight=%28asn2wrs%29*there > ar

Re: [Wireshark-dev] Add additional SNMP MIBs to the Wireshark distribution?

2007-08-17 Thread Luis EG Ontanon
Does libsmi it load these MIBs anyway? It is OK 4 me if libsmi it rants... I think it has to. It's not OK if it fails to load them. On 8/18/07, Wes Hardaker <[EMAIL PROTECTED]> wrote: > > "AH" == Andrew Hood <[EMAIL PROTECTED]> writes: > > AH> libsmi's parser is MUCH more picky than net-s

Re: [Wireshark-dev] Wireshark-devneed exotic SNMP traces

2007-08-17 Thread Wes Hardaker
> "LEO" == Luis EG Ontanon <[EMAIL PROTECTED]> writes: LEO> As you folks are probably aware I'm in the process of rewriting the LEO> snmp dissector now my collection of snmp is all generated net-snmp LEO> and although it was more than sufficient for snmp decryption is far LEO> from being a com

Re: [Wireshark-dev] Add additional SNMP MIBs to the Wireshark distribution?

2007-08-17 Thread Wes Hardaker
> "LEO" == Luis EG Ontanon <[EMAIL PROTECTED]> writes: LEO> We could ask them whether or not we can redistribute them. Note that a large percentage of those MIBs actually come from IETF RFCs, and the MIBs themselves are copyrighted according to the RFC itself. Thus, you don't necessarily have

Re: [Wireshark-dev] Add additional SNMP MIBs to the Wireshark distribution?

2007-08-17 Thread Wes Hardaker
> "AH" == Andrew Hood <[EMAIL PROTECTED]> writes: AH> libsmi's parser is MUCH more picky than net-snmp's parser. Mostly, FYI: Yep. By design. Libsmi is designed to be a strict parser enforcing the rules of the SMI against the MIBs. This is seen as a benefit since it forces MIB authors to

Re: [Wireshark-dev] Strip Ethernet broadcast / locally administered flags from address before doing manufacturer name resolvings?

2007-08-17 Thread ronnie sahlberg
On 8/17/07, Sake Blok <[EMAIL PROTECTED]> wrote: > On Wed, Aug 15, 2007 at 04:26:23PM +0200, Joerg Mayer wrote: > > On Wed, Aug 15, 2007 at 03:31:08PM +0200, Sake Blok wrote: > > > I can't imagine myself situations where you locally assign an > > > address and still be interested in the manufacturo

Re: [Wireshark-dev] NetXRay 2.2 fileformat

2007-08-17 Thread Guy Harris
Stig Bjørlykke wrote: > They are at the end of each frame. Looks like the same sort of stuff we've seen in other captures. I checked in a change to make the code that handles LAPB packets do the same check for two bytes in the record header to decide whether there's 4 bytes of junk at the end

Re: [Wireshark-dev] NetXRay 2.2 fileformat

2007-08-17 Thread Stig Bjørlykke
Den 17. aug. 2007 kl. 18.43 skrev Guy Harris: Do those 4 bytes show up at the beginning, or the end, of the frame? For some frame types, we find either 4 bytes of FCS or 4 bytes of junk at the end of the frame. They are at the end of each frame. Sometimes they have data and sometimes they a

Re: [Wireshark-dev] NetXRay 2.2 fileformat

2007-08-17 Thread Guy Harris
Stig Bjørlykke wrote: > I have a NetXRay 2.2 capture with some LAPB/X.25 traffic. The data is > shown correct, but all frames have 4 bytes extra which wireshark tries > to dissect without any luck. Can this 4 bytes belong to the capture > format? Do those 4 bytes show up at the beginning, or th

[Wireshark-dev] NetXRay 2.2 fileformat

2007-08-17 Thread Stig Bjørlykke
Hi. I have a NetXRay 2.2 capture with some LAPB/X.25 traffic. The data is shown correct, but all frames have 4 bytes extra which wireshark tries to dissect without any luck. Can this 4 bytes belong to the capture format? -- Stig Bjørlykke ___ Wiresh

Re: [Wireshark-dev] RE : Wireshark launching problem

2007-08-17 Thread Anders Broman (AL/EAB)
Hi, When running Wireshark in the build environment the simplest way is to do: wireshark-gtk2/wireshark from the prompt as the build process will copy all needed files to ../wireshark-gtk2 Regards Anders From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Beha

[Wireshark-dev] RE : Wireshark launching problem

2007-08-17 Thread aziz asniba
Hi Vaibhav, I had the same issue then I put the libgtk-0.dll in the folder where the .exe file is situated.You can found it under ..\wireshark-win32-libs\gtk+\lib\. Hope it will help. best Regards. Aziz [EMAIL PROTECTED] a écrit : Hi, I made new new wireshark.exe. If I run that exe it gives

[Wireshark-dev] Wiki problem

2007-08-17 Thread Anders Broman (AL/EAB)
Hi, On Ethereal Wiki page corresponding to http://wiki.wireshark.org/Asn2wrs?highlight=%28asn2wrs%29 there are some links explaning the Use of some directives like #.END these pages exists on wiresharks Wiki http://wiki.wireshark.org/FindPage?action=fullsearch&context=180&value=% 23.&titlesearch=St

Re: [Wireshark-dev] network card not detected

2007-08-17 Thread Abhik Sarkar
Depending on the OS you are running on, do you have WinPcap or libpcap installed. Wireshark by itself is not capable of capturing packets live. You need to have the above installed. If you do "Help > About" in Wireshark, there is a paragraph starting with "Running on...". This should list libpcap

[Wireshark-dev] review_for_checkin granted: [Bug 1732] Implement desegment for SIGCOMP over TCP

2007-08-17 Thread bugzilla-request-daemon
Sake <[EMAIL PROTECTED]> has granted Daniel Rao <[EMAIL PROTECTED]>'s request for review_for_checkin: Bug 1732: Implement desegment for SIGCOMP over TCP http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1732 --- Additional Comments from Sake <[EMAIL PROTECTED]> This patch was committed as rev

[Wireshark-dev] review_for_checkin granted: [Bug 1717] Add support for the (Juniper) NetScreen snoop file format

2007-08-17 Thread bugzilla-request-daemon
Sake <[EMAIL PROTECTED]> has granted Sake <[EMAIL PROTECTED]>'s request for review_for_checkin: Bug 1717: Add support for the (Juniper) NetScreen snoop file format http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1717 --- Additional Comments from Sake <[EMAIL PROTECTED]> Submitted as SVN-225

[Wireshark-dev] need exotic SNMP traces

2007-08-17 Thread Luis EG Ontanon
I need many and variegated examples of snmp messages to create a test platform. As you folks are probably aware I'm in the process of rewriting the snmp dissector now my collection of snmp is all generated net-snmp and although it was more than sufficient for snmp decryption is far from being a co

[Wireshark-dev] network card not detected

2007-08-17 Thread aziz asniba
Hi all, I have build wireshark then I run it but it does not detect the network card of my computer !! Can any one help to solve this issue. Best regards Aziz - Ne gardez plus qu'une seule adresse mail ! Copiez vos mails vers Yahoo! Mail __

Re: [Wireshark-dev] Strip Ethernet broadcast / locally administered flags from address before doing manufacturer name resolvings?

2007-08-17 Thread Sake Blok
On Wed, Aug 15, 2007 at 04:26:23PM +0200, Joerg Mayer wrote: > On Wed, Aug 15, 2007 at 03:31:08PM +0200, Sake Blok wrote: > > I can't imagine myself situations where you locally assign an > > address and still be interested in the manufacturor of the card > > from which the mac was used as seed. I